Values for content-security-policy-report-only: script-src https: blob: 'unsafe-inline' 'unsafe-eval' 'self';base-uri 'self';report-uri https://reporting-api.gannettinnovation.com;report-to default 224 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://www.awin1.com https://lantern.roeyecdn.com https://tagmanager.google.com https://cdn.trustcommander.net https://www.dwin1.com https://www.googletagmanager.com https://maps.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://bat.bing.com https://*.doubleclick.net https://www.axa-video.de *.visualwebsiteoptimizer.com app.vwo.com https://www.google.com https://platform.commandersact.com https://connect.facebook.net https://*.aklamio.com data.axa.de snap.licdn.com blob: https://ct.pinterest.com https://s.pinimg.com https://acdn.adnxs.com https://ib.adnxs.com ; ;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com https://googletagmanager.com https://www.googletagmanager.com ;frame-src https://www.awin1.com app.vwo.com *.visualwebsiteoptimizer.com https://entry.axa-de.intraxa/ https://entry.axa.de https://www.axa-video.de https://www.axa.de https://inte.axa.de https://*.doubleclick.net https://cdn.trustcommander.net https://www.dwin1.com https://connect.facebook.net https://www.facebook.com https://td.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com https://ct.pinterest.com https://googletagmanager.com https://insight.adsrvr.org 'self' https://www.googletagmanager.com;base-uri 'self';object-src 'none';img-src 'self' data: https://ad.doubleclick.net https://*.ads.linkedin.com data.axa.de *.visualwebsiteoptimizer.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com https://track.adform.net https://ad.doubleclick.net https://www.facebook.com https://bat.bing.com https://www.google.com https://www.google.de https://www.google-analytics.com https://www.google https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://googleads.g.doubleclick.net https://i.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://www.financeads.net https://www.aklamio.com/ https://ct.pinterest.com https://ib.adnxs.com;form-action 'self';default-src 'self' https://assets.faircado.com https://static.preply.com https://fonts.gstatic.com/ blob: data:;connect-src 'self' data.axa.de https://api.vid-adblocker.com https://ad.doubleclick.net/ https://*.google.de https://www.facebook.com/ https://*.ads.linkedin.com https://p.adsymptotic.com https://*.linkedin.oribi.io https://sjs.bizographics.com ad.doubleclick.net *.visualwebsiteoptimizer.com app.vwo.com https://*.googlesyndication.com https://*.google.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://www.googleanalytics.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://bat.bing.com https://privacy.trustcommander.net https://privacy.commander1.net https://privacy.commander1.com https://www.googletagmanager.com https://maps.googleapis.com https://fonts.googleapis.com https://*.axa.de https://cloud.service.aerzteversicherung.de https://mcdyr4395tgnrcnr8bt5wsrgh-11.pub.sfmc-content.com https://*.aklamio.com https://www.googleadservices.com https://ct.pinterest.com https://ib.adnxs.com https://acdn.adnxs.com https://google.com;;report-uri /site/axa-de/cspReportOnly 218 107 script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: *.mpsimg.com *.bdimg.xyz; font-src 'self' data: *.svcasino.art; 101 frame-ancestors 'self'; report-uri /csp_logger?path=/ 82 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 79 frame-ancestors 'self' 61 default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: ; form-action 'none' ; frame-ancestors 'self' ; script-src 'unsafe-eval' 'unsafe-hashes' 'report-sample'; report-uri /csp_report 60 default-src 'self' 'unsafe-eval' 'unsafe-inline' https: blob:; frame-ancestors 'self'; style-src https: 'unsafe-inline'; connect-src https:; frame-src https:; script-src 'unsafe-eval' 'unsafe-inline' 'self' https: blob: data:; font-src https: data:; img-src https: data:; media-src https: blob:; object-src 'none'; report-uri https://o144486.ingest.sentry.io/api/5543380/security/?sentry_key=e66dfe54be8e47219dd8103b4deb2f1a&sentry_environment=policy_reports 48 default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-to blogspot; report-uri https://www.blogger.com/cspreport 36 report-uri /report-csp-violation 29 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://ajax.googleapis.com/ajax/libs/jquery/3.6.4/jquery.min.js https://translate.google.com/translate_a/element.js https://www.google.com/recaptcha/api.js https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/recaptcha/ https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.Ul3L5L4ZTmM.es5.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /v3/signin/_/AccountsSignInUi/cspreport/fine-allowlist 28 block-all-mixed-content; report-uri https://blog.hatena.ne.jp/api/csp_report 25 default-src https: wss: 'unsafe-inline' 'unsafe-eval'; font-src https: data: ; img-src https: data: blob: ; media-src https: blob: ; worker-src https: blob: ; report-uri https://www.netflix.com/log/www/csp/1; 23 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-recaptcha/_/js/k=boq-recaptcha.RecaptchaChallengePageUi.en_US.gdj-Me7uP4w.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /recaptcha/challengepage/_/RecaptchaChallengePageUi/cspreport/fine-allowlist 22 default-src 'self' blob: https: data: mediastream: 'unsafe-eval' 'unsafe-inline';report-uri https://metrics.media-amazon.com/ 21 frame-ancestors 'self' https://skybox.eskypartners.com; report-uri https://esky.report-uri.com/r/t/csp/enforce 18 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 17 font-src www.paypalobjects.com *.googleapis.com *.gstatic.com *.cloudflare.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src https://www.youtube.com/ *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/ bid.g.doubleclick.net *.adyen.com pay.google.com *.paypal.com www.google.com https://www.facebook.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://td.doubleclick.net/ https://www.google.com.ua/ https://www.google.bg/ https://ct.pinterest.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.googleapis.com *.gstatic.com https://www.google.com https://bat.bing.com/ https://www.facebook.com https://cdn.kaffekapslen.be https://www.google.com.ua/ https://www.google.bg/ https://www.google.dk/ https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://kaffekapslen.dk/ https://kaffekapslen.media https://www.googletagmanager.com/ https://app.usercentrics.eu/ https://connect.facebook.net/ https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.jsdelivr.net https://kaffekapslen.media/ https://app.usercentrics.eu/ https://connect.facebook.net/ https://bat.bing.com/ https://www.clarity.ms/ *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.jsdelivr.net *.cloudflare.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.adyen.com *.google.com https://www.google.com payments-eu.amazon.com *.paypal.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com https://www.facebook.com eu.playground.klarnaevt.com https://www.kaffekapslen.dk/ https://az-apim-st-kaffekapslen.azure-api.net/ api.kaffekapslen.com https://googleads.g.doubleclick.net https://bat.bing.com/ https://kaffekapslen.matomo.cloud/ https://api.usercentrics.eu/ https://pagead2.googlesyndication.com/ https://graphql.usercentrics.eu/graphql https://monitor.kaffekapslen.com/ https://google.com/pay https://region1.google-analytics.com https://www.google.bg/ https://capig.kaffekapslen.dk/ https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 17 font-src *.fontawesome.com lampenlicht.nl *.lampenlicht.nl fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com https://plumrocket.com js.mollie.com consentcdn.cookiebot.com gum.criteo.com qlfbrands.my.salesforce.com td.doubleclick.net fledge.eu.criteo.com www.facebook.com static.criteo.net qlflivechat.secure.force.com qlfbrands.my.salesforce-sites.com www.paypalobjects.com gumi.criteo.com www.awin1.com 'self' 'unsafe-inline'; img-src cdn.lampenlicht.nl widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com https://www.mollie.com lampenlicht.nl *.lampenlicht.nl eprel.ec.europa.eu cdn.flbx.io *.cloudfront.net imgsct.cookiebot.com www.keurmerk.info *.fittinq.com bat.bing.com px.ads.linkedin.com *.google.com www.google.de www.google.pl www.google.nl www.google.fr www.google.gr www.google.be www.google.si www.google.hu www.google.ie www.google.lt www.google.ro www.google.se www.google.hr www.google.es www.google.it www.google.rs www.google.lv www.google.bg www.google.ba www.google.ch www.google.sk www.google.pt www.google.ee www.google.cz www.google.at www.google.co.uk www.google.co.in www.google.dk www.google.no www.google.com.ua www.google.fi www.facebook.com *.clarity.ms stats.g.doubleclick.net lantern.roeye.com www.zenaps.com www.instagram.com www.bizrate.com www.wepowerconnections.com www.awin1.com www.webshoptrustmark.be csm.nl3.eu.criteo.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: https: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://maps.googleapis.com *.avada.io js.mollie.com lampenlicht.nl *.lampenlicht.nl *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com consent.cookiebot.com mintminds.fittinq.com cdn.evgnet.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src cdn.flbx.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io lampenlicht.nl *.lampenlicht.nl *.webeyez.com *.evergage.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com *.getflowbox.com eu.api.fpjs.io maps.googleapis.com pagead2.googlesyndication.com consentcdn.cookiebot.com *.clarity.ms p.biano.nl p.biano.hu p.biano.ro p.biano.pt p.biano.it p.biano.sk p.biano.cz www.google.com www.google.nl px.ads.linkedin.com *.criteo.com bat.bing.com cdn.growthbook.io www.facebook.com ct.beslist.nl stats.g.doubleclick.net vc.hotjar.io consent.cookiebot.com the.sciencebehindecommerce.com www.wepowerconnections.com qlfbrands-communities.force.com c.bannerflow.net *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 16 connect-src 'self' wss: ws: consentcdn.cookiebot.eu consent.cookiebot.com urkwvzhzpc.execute-api.eu-west-1.amazonaws.com *.doubleclick.net *.googlesyndication.com *.klaviyo.com *.klarnacdn.net *.cookiebot.com *.termly.io cloudflareinsights.com *.facebook.com *.dojo.tech *.salesfire.co.uk *.onlinesizing.bike *.tawk.to cdn-cookieyes.com *.cookieyes.com *.klaviyo.com *.appspot-preview.com *.bing.com *.clarity.ms *.fontawesome.com *.google-analytics.com *.google.com *.google.co.uk *.googleapis.com *.googletagmanager.com *.hotjar.com *.iubenda.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.luckyorange.net *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.smartlook.cloud *.visitors.live api.getaddress.io bat.bing.com content.hotjar.io eu.klarnaevt.com js.klarna.com live.smartmetrics.co.uk manager.eu.smartlook.cloud maps.googleapis.com metrics.hotjar.io na.klarnaevt.com stats.g.doubleclick.net vc.hotjar.io www.google.se centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com *.googleadservices.com *.google.com; default-src 'self' *.klaviyo.com *.dojo.tech *.salesfire.co.uk *.googleapis.com *.trustpilot.com; font-src 'self' *.klaviyo.com *.dojo.tech *.pushsales.app *.tawk.to *.salesfire.co.uk *.klaviyo.com fonts.gstatic.com *.cloudflare.com *.fontawesome.com *.typekit.net x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consent.cookiebot.com; form-action 'self' *.list-manage.com translate.googleapis.com pay.realexpayments.com *.klaviyo.com *.dojo.tech *.facebook.com *.paypal.com *.sagepay.com *.worldpay.com eu-library.klarnaservices.com gateway.cardstream.com live.opayo.eu.elavon.com mdepayments.epdq.co.uk test.opayo.eu.elavon.com js.stripe.com *.sandbox.paypal.com *.paypal.com *.accounts.google.com; frame-ancestors 'self'; frame-src *.cookiebot.eu *.outfindo.com youtu.be *.klaviyo.com hubtiger.com app.bikerentalmanager.com connect.garmin.com widgets.sociablekit.com *.paypalobjects.com www.googletagmanager.com bikesizing.cube.eu www.paypal.com bookings.hubtiger.com challenges.cloudflare.com *.onlinesizing.bike consentcdn.cookiebot.com *.termly.io *.doubleclick.net *.facebook.com *.google.com *.google.co.uk *.greencommuteinitiative.uk greencommuteinitiative.uk *.instagram.com *.paymentsense.cloud *.sharethis.com *.strava.com *.trustpilot.com *.vimeo.com *.youtube-nocookie.com *.youtube.com www.komoot.com cdn.salesfire.co.uk jejames.checkfront.co.uk js.klarna.com td.doubleclick.net www.cyclescheme.co.uk osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com js.stripe.com forms.office.com ridewithgps.com platform.twitter.com *.webgains.com *.recaptcha.net *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; img-src 'self' 'unsafe-inline' data: https: *.klaviyo.com *.dojo.tech *.google-analytics.com *.googletagmanager.com *.gravatar.com 0.gravatar.com l.sharethis.com www.gravatar.com www.specialized.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' player.vimeo.com platform.twitter.com *.consentprotect.com www.googletagmanager.com www.youtube.com *.livechatinc.com *.kaspersky-labs.com *.googlesyndication.com analytics.tiktok.com *.googleadservices.com *.paypal.com widget.privy.com *.list-manage.com *.amazonaws.com *.mailchimp.com *.klaviyo.com *.checkfront.co.uk *.klarnacdn.net *.pushsales.co.uk challenges.cloudflare.com static.cloudflareinsights.com ajax.cloudflare.com *.dojo.tech *.cube.eu *.klarnaservices.com *.clarity.ms *.hotjar.com *.bing.com *.salesfire.co.uk js.klarna.com *.onlinesizing.bike *.clarity.ms *.tawk.to *.avln.me *.bing.com *.webgains.io *.klaviyo.com cdn-cookieyes.com *.chimpstatic.com chimpstatic.com *.googleapis.com *.getaddress.io *.iubenda.com *.addthis.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.instagram.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.newrelic.com *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.trustpilot.com *.typekit.net *.vimeo.com cdn.jsdelivr.net cdn.salesfire.co.uk cdnjs.cloudflare.com code.jquery.com *.cookiebot.com *.termly.io hit.salesfire.co.uk js.klarna.com kit.fontawesome.com maps.googleapis.com polyfill-fastly.io script.hotjar.com *.elfsight.com static.hotjar.com unpkg.com web-sdk.smartlook.com www.google.com www.gstatic.com x.klarnacdn.net osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' player.vimeo.com platform.twitter.com *.consentprotect.com www.googletagmanager.com www.youtube.com *.livechatinc.com *.kaspersky-labs.com *.googlesyndication.com analytics.tiktok.com *.googleadservices.com *.paypal.com widget.privy.com *.list-manage.com *.amazonaws.com *.mailchimp.com *.klaviyo.com *.checkfront.co.uk *.klarnacdn.net *.pushsales.co.uk challenges.cloudflare.com static.cloudflareinsights.com ajax.cloudflare.com *.dojo.tech *.cube.eu *.klarnaservices.com *.clarity.ms *.hotjar.com *.bing.com *.salesfire.co.uk js.klarna.com *.onlinesizing.bike *.clarity.ms *.tawk.to *.avln.me *.bing.com *.webgains.io *.klaviyo.com cdn-cookieyes.com *.chimpstatic.com chimpstatic.com *.googleapis.com *.getaddress.io *.iubenda.com *.addthis.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.instagram.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.newrelic.com *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.trustpilot.com *.typekit.net *.vimeo.com cdn.jsdelivr.net cdn.salesfire.co.uk cdnjs.cloudflare.com code.jquery.com *.cookiebot.com *.termly.io hit.salesfire.co.uk js.klarna.com kit.fontawesome.com maps.googleapis.com polyfill-fastly.io script.hotjar.com *.elfsight.com static.hotjar.com unpkg.com web-sdk.smartlook.com www.google.com www.gstatic.com x.klarnacdn.net osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; style-src 'self' 'unsafe-inline' *.google.com www.google.com *.mailchimp.com *.klaviyo.com *.dojo.tech *.paymentsense.cloud *.tawk.to *.salesfire.co.uk *.klaviyo.com *.getaddress.io *.googleapis.com *.pushsales.app *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com npkg.com x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com; style-src-elem 'self' 'unsafe-inline' *.google.com www.google.com *.mailchimp.com *.klaviyo.com *.dojo.tech *.paymentsense.cloud *.tawk.to *.salesfire.co.uk *.klaviyo.com *.getaddress.io *.googleapis.com *.pushsales.app *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com npkg.com x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com; report-to csp-endpoint; 16 default-src 'self' 15 default-src 'self'; 15 report-to csp-reports; script-src 'self' https://cdn.shopify.com/shopifycloud/shopify_app_store/ 'report-sample' https://cdn.shopify.com/shopifycloud/dux/ https://*.googletagmanager.com https://apis.google.com/js/client.js https://www.google-analytics.com/plugins/ua/ec.js https://www.google-analytics.com/analytics.js https://ssl.google-analytics.com/ https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://www.google.com https://google.com https://www.youtube.com/s/player/ https://www.youtube.com/iframe_api/ https://analytics.tiktok.com/ https://connect.facebook.net/signals/config/ https://connect.facebook.net/en_US/fbevents.js 15 object-src *.agriaffaires.pro *.machineryzone.pro *.agriaffaires.com *.machineryzone.fr *.machineryzone.com *.truckscorner.fr *.mbcore.io; frame-ancestors 'self' *.agriaffaires.pro *.machineryzone.pro *.agriaffaires.com *.machineryzone.fr *.machineryzone.com *.truckscorner.fr *.mbcore.io; report-uri https://api.leboncoin.fr/api/csp-report/v1/report/; 12 default-src https: 'self' *.facebook.net *.googletagmanager.com *.bizibly.com *.doubleclick.net https://*.intercomcdn.com https://*.datadoghq-browser-agent.com; font-src 'self' https://*.intercomcdn.com *.fontawesome.com data:; base-uri 'none'; object-src data: 'unsafe-eval'; img-src 'self' data: * ; script-src https: 'self' 'unsafe-eval' 'unsafe-inline' http://*.google-analytics.com http://*.gstatic.com http://*.bing.com http://*.googleadservices.com http://*.hs-scripts.com http://*.bizible.com *.facebook.net *.googletagmanager.com http://*.fontawesome.com http://*.outbrain.com blob:; style-src https: 'self' *.fontawesome.com 'unsafe-inline'; report-uri /rest/trackers/csp; 11 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.yieldify-production.com/fonts/100822/e6e8821f-e1ad-4601-aaed-5b3386a4580b.otf https://*.hotjar.io https://*.yieldify-production.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com http://www.facebook.com/tr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://odr.promo.dev/ https://*.yieldify.com https://ohws.prospective.ch/ https://tpc.googlesyndication.com/ https://*.hotjar.io https://www.mainadv.com https://ad.ad-srv.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com http://lindt-hg65tr.your-printq.com https://*.cookiepro.com https://assets-v2.yieldify.com/images/189494/2022/4/8/55c67825-1f9d-438d-815a-43a437f03af2.png https://assets-v2.yieldify.com/images/189494/2022/4/21/54125dc1-8b51-4175-bd53-7d33e427cc41.gif https://www.lindt-spruengli.com/ https://px.ads.linkedin.com/ https://*.seznam.cz https://*.hotjar.io https://*.yieldify.com https://i.cdn.nrholding.net https://*.sendtric.com network-eu-a.bazaarvoice.com assets-v2.yieldify.com *.cookiepro.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://static-eu.payments-amazon.com/checkout.js https://*.yieldify.com https://www.googleoptimize.com/optimize.js https://custom.yieldify.com/v1/100510/100822/3d9a49d0c2/bundle.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://tpc.googlesyndication.com/sodar/1s9mPOHO.js https://*.adform.net https://*.seznam.cz https://analytics.tiktok.com/ https://*.hotjar.io https://*.pinimg.com https://*.daktela.com https://www.dwin1.com maps.google.com https://www.gstatic.com/recaptcha static.r66net.net https://unbxd.s3.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://*.hotjar.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com www.lindt-spruengli.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://*.criteo.com https://*.hotjar.io https://cdn.stickyadstv.com https://*.ads.linkedin.com https://snap.licdn.com *.analytics.google.com https://*.r66net.com https://*.yieldify.com wss://*.hotjar.io https://geolocation.onetrust.com https://*.googleapis.com https://*.daktela.com https://cdn.tailwindcss.com https://sgtm.lindt.se sgtm.lindt.se sgtm.lindt.dk sgtm.lindt.cz sgtm.lindt.de sgtm.lindt.es sgtm.lindt.fr sgtm.lindt.it sgtm.lindt.hu sgtm.lindt.co.uk sgtm.lindt.com.nl sgtm.lindt.pl sgtm.lindt.at geolocation.onetrust.com sgtm.lindt.sk sgtm.lindt.fi 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com https://cdn.tailwindcss.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 11 font-src *.typekit.net fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com 'self' data: *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com *.cdninstagram.com www.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.google.com.pa *.sportline.com.pa *.sportline.com.co *.magentosite.cloud 'self' data: *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.paypal.com *.apptrian.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com beacon-audiences.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.gstatic.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.hotjar.com *.xtento.com *.tiktok.com *.sportline.com.pa *.pangle-ads.com *.adobedtm.com *.googletagmanager.com *.google.com *.google-analytics.com *.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com beacon-audiences.magento-ds.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.googletagmanager.com *.google.com *.typekit.net *.googleapis.com *.gstatic.com *.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io beacon-audiences.magento-ds.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobedc.net *.demdex.net *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ telemetrics.klaviyo.com *.sistecredito.com/* *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com static-tracking.klaviyo.com fast.a.klaviyo.com a.klaviyo.com *.hotjar.com metrics.hotjar.io wss://ws.hotjar.com content.hotjar.io *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.pangle-ads.com assets.adobedtm.com *.adobedtm.com api.mercadopago.com *.google-analytics.com *.paypal.com tm.filter:* maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 11 default-src 'self'; script-src 'self' unpkg.com/react-scan/ acdn.adnxs.com analytics.tiktok.com bat.bing.com bat.bing.net cdn.attn.tv cdn.cookielaw.org cdn.shopify.com cdn-scripts.signifyd.com connect.facebook.net cdn.kustomerapp.com ct.pinterest.com js-agent.newrelic.com googleads.g.doubleclick.net imgs.signifyd.com js.klarna.com lantern.roeyecdn.com maps.googleapis.com pixel.byspotify.com rapid-cdn.yottaa.com s.pinimg.com script.crazyegg.com script.hotjar.com sc-static.net static.klaviyo.com static-tracking.klaviyo.com static.kyc.red str.rise-ai.com static.agentio.com static.hotjar.com tags.creativecdn.com the.sciencebehindecommerce.com tr.snapchat.com track.sv.rkdms.com try.abtasty.com track.securedvisit.com www.dwin1.com www.google.com www.googleadservices.com www.googletagmanager.com www.google-analytics.com www.gstatic.com www.powr.io www.youtube.com *.afterpay.com *.amazon-adsystem.com *.bglobale.com *.forter.com *.cloudfront.net *.contentsquare.net *.global-e.com *.liadm.com *.online-metrix.net *.outbrain.com *.yotpo.com *.kampyle.com *.medallia.com *.abtasty.com *.signifyd.com *.lytics.io *.gotolstoy.com *.contentstack.com 'unsafe-eval' 'unsafe-inline' blob: ; style-src 'self' 'unsafe-inline' fonts.googleapis.com maxcdn.bootstrapcdn.com static.klaviyo.com static-tracking.klaviyo.com x.klarnacdn.net www.gstatic.com *.global-e.com *.bglobale.com *.yotpo.com *.kampyle.com *.medallia.com *.abtasty.com *.lytics.io *.gotolstoy.com; img-src 'self' assets.rise-ai.com bat.bing.com bat.bing.net cdn.bfldr.com cdn.cookielaw.org cdn.kustomerhostedcontent.com cdn.shopify.com events.attentivemobile.com googleads.g.doubleclick.net googleads.g.doubleclick.net i.geistm.com i.ytimg.com images.contentstack.io imgs.signifyd.com ib.adnxs.com kustomer-prod1-attachments.s3.amazonaws.com lantern.roeye.com maps.googleapis.com maps.gstatic.com segment.prod.bidr.io s3.amazonaws.com track.securedvisit.com tr.snapchat.com verifi.podscribe.com vuoriclothing.com www.facebook.com www.googleadservices.com www.googletagmanager.com www.gstatic.com www.wepowerconnections.com www.google.com www.google.co.uk www.google.ae www.google.co.jp www.google.com.sg www.google.nl www.google.com.mx www.google.ie www.google.com.hk www.google.de www.google.fr www.google.ca www.google.co.kr www.google.com.au www.google.co.in www.google.com.pk www.google.com.ph www.powrcdn.com *.afterpay.com *.bglobale.com *.contentsquare.net *.cloudfront.net *.doubleclick.net *.liadm.com *.online-metrix.net *.global-e.com *.yotpo.com *.kampyle.com *.medallia.com *.abtasty.com *.lytics.io *.gotolstoy.com data: blob:; font-src 'self' cdn.kustomerapp.com cdn.honey.io fonts.gstatic.com maxcdn.bootstrapcdn.com cdn.shopify.com static.klaviyo.com use.fontawesome.com x.klarnacdn.net *.kampyle.com *.medallia.com *.cloudfront.net *.s3.us-east-2.amazonaws.com *.gotolstoy.com data:; connect-src 'self' api.nosto.com api-js.datadome.co application.rise-ai.com analytics.google.com analytics.tiktok.com ara.paa-reporting-advertising.amazon bam.nr-data.net bat.bing.com bat.bing.net browser-intake-us5-datadoghq.com cdn.cookielaw.org cdn.shopify.com content.hotjar.io collector.agentio.com ct.pinterest.com events.attentivemobile.com geolocation.onetrust.com google.com gtmss.vuoriclothing.com ib.adnxs.com insights.algolia.io ingesteer.services-prod.nsvcs.net googleads.g.doubleclick.net imgs.signifyd.com ipv4.podscribe.com js.klarna.com metrics.hotjar.io pagead2.googlesyndication.com pixels.spotify.com play.google.com privacyportal.onetrust.com script.crazyegg.com s3.amazonaws.com stats.g.doubleclick.net the.sciencebehindecommerce.com vc.hotjar.io vuori.api.kustomerapp.com www.wepowerconnections.com www.facebook.com www.googleadservices.com www.google.com www.googletagmanager.com www.google.co.in www.google-analytics.com www.powr.io *.abtasty.com *.afterpay.com *.amazon-adsystem.com *.algolianet.com *.algolia.net *.attn.tv *.boldmetrics.io *.bglobale.com *.contentstack.io *.contentstack.com *.cloudfront.net *.cloudflare.com *.contentsquare.net *.crazyegg.com *.forter.com wss://*.forter.com wss://ws.hotjar.com *.googleapis.com *.global-e.com *.browser-intake-datadoghq.com *.jsdelivr.net *.klaviyo.com *.klarnaevt.com *.liadm.com *.myshopify.com *.newrelic.com *.outbrain.com *.pndsn.com *.snapchat.com *.signifyd.com *.tiktokw.us *.telemetry.vaultdcr.com *.yotpo.com *.yottaa.net *.kampyle.com *.medallia.com func-ranger-westus-dev.azurewebsites.net func-ranger-westus-prod.azurewebsites.net func-ranger-westus-stg.azurewebsites.net *.gotolstoy.com apple.com *.apple.com google.com *.google.com; media-src 'self' cdn.bfldr.com kustomer-prod1-attachments.s3.amazonaws.com *.checkout.vuoriclothing.com *.vuoriclothing.com *.gotolstoy.com data blob:; frame-src 'self' app.netlify.com ct.pinterest.com e.issuu.com imgs.signifyd.com geo-ipv6.captcha-delivery.com gtmss.vuoriclothing.com js.klarna.com static.kyc.red str.rise-ai.com td.doubleclick.net tr.snapchat.com www.facebook.com www.google.com www.googletagmanager.com www.powr.io www.youtube.com *.attn.tv *.online-metrix.net *.abtasty.com *.kampyle.com *.medallia.com *.gotolstoy.com; worker-src 'self' https://imgs.signifyd.com blob:; frame-ancestors 'self' https://app.contentstack.com; object-src 'none'; base-uri 'self' *.kampyle.com; report-uri /api/csp-report; 11 default-src 'self'; connect-src 'self' https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.googletagmanager.com; font-src 'self' https://themes.googleusercontent.com fonts.gstatic.com https://cdn.jsdelivr.net data:; frame-src 'self' https://www.youtube.com https://www.vimeo.com; img-src 'self' https://translate.google.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://i.ytimg.com https://www.gstatic.com https://maps.gstatic.com https://maps.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com data:; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net https://*.googletagmanager.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com maps.googleapis.com unpkg.com; script-src-attr 'self'; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com maps.googleapis.com unpkg.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; block-all-mixed-content 10 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.akstat.io p11.techlab-cdn.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net c.go-mpulse.net s.go-mpulse.net *.algolianet.com us5azow6i2-dsn.algolia.net xfoi9ebbhr-dsn.algolia.net secure.adnxs.com bat.bing.com bat.bing.net d.btttag.com pearson3283191z.btttag.com pearson.blueconic.net pearson.sb.blueconic.net api.company-target.com s.company-target.com tag-logger.demandbase.com tag.demandbase.com googleads.g.doubleclick.net ad.doubleclick.net td.doubleclick.net *.fls.doubleclick.net connect.facebook.net analytics.formassembly.com pearson.tfaforms.net ade.googlesyndication.com fonts.gstatic.com pagead2.googlesyndication.com fonts.googleapis.com region1.google-analytics.com static.hotjar.com utt.impactcdn.com cdn.jsdelivr.net app.launchdarkly.com px.ads.linkedin.com snap.licdn.com i.liadm.com cdn.cookielaw.org bam.nr-data.net js-agent.newrelic.com geolocation.onetrust.com privacyportal-de.onetrust.com *.pearson.com pearson.com cdn.pdst.fm a.quora.com q.quora.com tag.rmp.rakuten.com alb.reddit.com pixel-config.reddit.com www.redditstatic.com pi.pardot.com sc-static.sc-static.net tr.snapchat.com tr6.snapchat.com pixels.spotify.com analytics-ipv6.tiktokw.us analytics.tiktok.com insight.adsrvr.org js.adsrvr.org static.ads-twitter.com analytics.twitter.com t.t.co pearson.esaas.inmoment.eu pearson.mcxplatform.de *.visualwebsiteoptimizer.com img.youtube.com pearson--projects.sandbox.my.site.com; frame-ancestors 'none'; 9 default-src https: data: 'unsafe-inline' 'unsafe-eval' 9 upgrade-insecure-requests; 9 default-src 'self';base-uri 'none';frame-ancestors 'self';frame-src 'self' 5164101.fls.doubleclick.net apps.rokt.com audible.demdex.net bs.serving-sys.com s.amazon-adsystem.com td.doubleclick.net tr.snapchat.com www.facebook.com;style-src 'self' 'unsafe-inline' images-na.ssl-images-amazon.com;script-src 'self' 'unsafe-inline' apps.rokt.com audible.sc.omtrdc.net bat.bing.com/bat.js bat.bing.com/p/action/4004590.js bat.bing.com/p/insights/s/0.7.20 bat.bing.com/p/insights/t/4004590 connect.facebook.net d.impactradius-event.com d1g3myji5lplsh.cloudfront.net d2nttevkh1mtzs.cloudfront.net googleads.g.doubleclick.net images-na.ssl-images-amazon.com sc-static.net siteintercept.qualtrics.com tr.snapchat.com www.googleadservices.com/pagead/conversion/ www.googletagmanager.com zn5ygnnjlk4oo0dy1-audible.siteintercept.qualtrics.com;media-src 'self' images-na.ssl-images-amazon.com/images/ m.media-amazon.com samples.audible.co.uk samples.audible.com;object-src 'none';connect-src 'self' adservice.google.com/pagead/regclk api.audible.com audible.sc.omtrdc.net/b/ss/ audible.tt.omtrdc.net/rest/v1/delivery bat.bing.com/p/insights/c/ dpm.demdex.net fls-na.amazon.com m.media-amazon.com pagead2.googlesyndication.com/pagead/buyside_topics/set/ siteintercept.qualtrics.com tr.snapchat.com unagi-na.amazon.com unagi.amazon.com www.audible.com www.facebook.com/tr/ www.google.com/pagead/landing;font-src www.audible.com m.media-amazon.com;img-src 'self' ad.doubleclick.net bat.bing.com/action/0 fls-na.amazon.com googleads.g.doubleclick.net/pagead/viewthroughconversion/ images-eu.ssl-images-amazon.com images-na.ssl-images-amazon.com m.media-amazon.com s.amazon-adsystem.com/iui3 www.facebook.com www.google.ca/pagead/1p-user-list/ www.google.ch/pagead/1p-user-list/ www.google.ee/pagead/1p-user-list/ www.google.pt/pagead/1p-user-list/ www.google.ro/pagead/1p-user-list/ www.google.se/pagead/1p-user-list/ www.google.co.cr/pagead/1p-user-list/ www.google.co.il/pagead/1p-user-list/ www.google.co.in/pagead/1p-user-list/ www.google.co.ke/pagead/1p-user-list/ www.google.co.kr/pagead/1p-user-list/ www.google.co.nz/pagead/1p-user-list/ www.google.co.th/pagead/1p-user-list/ www.google.co.uk/pagead/1p-user-list/ www.google.co.za/pagead/1p-user-list/ www.google.com.ar/pagead/1p-user-list/ www.google.com.br/pagead/1p-user-list/ www.google.com.co/pagead/1p-user-list/ www.google.com.do/pagead/1p-user-list/ www.google.com.ec/pagead/1p-user-list/ www.google.com.hk/pagead/1p-user-list/ www.google.com.jm/pagead/1p-user-list/ www.google.com.mx/pagead/1p-user-list/ www.google.com.my/pagead/1p-user-list/ www.google.com.ng/pagead/1p-user-list/ www.google.com.pa/pagead/1p-user-list/ www.google.com.pe/pagead/1p-user-list/ www.google.com.ph/pagead/1p-user-list/ www.google.com.pk/pagead/1p-user-list/ www.google.com.sg/pagead/1p-user-list/ www.google.com/pagead/1p-user-list/ www.google.de/pagead/1p-user-list/ www.google.dk/pagead/1p-user-list/ www.google.es/pagead/1p-user-list/ www.google.ie/pagead/1p-user-list/ www.google.no/pagead/1p-user-list/ www.googleadservices.com/pagead/conversion/ www.googletagmanager.com 8 base-uri 'none'; child-src blob:; connect-src 'self' https://*.adnxs.com https://*.adsrvr.org https://*.api.cdp.gigya.com https://*.clarity.ms https://*.contentsquare.com https://*.contentsquare.net https://*.creativecdn.com https://*.criteo.com https://*.doubleclick.net https://*.loyjoy.com https://*.onetrust.com https://*.scarabresearch.com https://*.taboola.com https://*.teads.tv https://analytics.tiktok.com https://api.bounce-commerce.de https://bat.bing.com https://cdn.cookielaw.org https://customerfrontenddata.int.dev.hunter.gcp.tchibo.systems https://customerfrontenddata.int.staging.hunter.gcp.tchibo.systems https://heapanalytics.com https://pixels.spotify.com https://px.ads.linkedin.com https://region1.analytics.google.com https://region1.google-analytics.com https://rum.browser-intake-datadoghq.eu https://s.seedtag.com https://sst.eduscho.at https://sst.tchibo.ch https://sst.tchibo.com.tr https://sst.tchibo.cz https://sst.tchibo.de https://sst.tchibo.hu https://sst.tchibo.pl https://sst.tchibo.sk https://tchibo.omq.de https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.google.de https://www.googleadservices.com https://www.googletagmanager.com wss://lpru5mjumh.execute-api.eu-central-1.amazonaws.com; default-src 'self'; font-src 'self' data: https://*.loyjoy.com https://fonts.gstatic.com https://heapanalytics.com https://tchibo.omq.de; form-action 'self'; frame-ancestors 'self'; frame-src https://*.adsrvr.org https://*.creativecdn.com https://*.criteo.com https://*.doubleclick.net https://*.loyjoy.com https://*.taboola.com https://app.contentsquare.com https://csxd.hunter.nexinto.com https://csxd.tchibo.de https://ctagm.eduscho.at https://ctagm.tchibo.ch https://ctagm.tchibo.com.tr https://ctagm.tchibo.cz https://ctagm.tchibo.de https://ctagm.tchibo.hu https://ctagm.tchibo.pl https://ctagm.tchibo.sk https://d.c.cdnsrv.de https://s.uicdn.com https://sst.eduscho.at https://sst.tchibo.ch https://sst.tchibo.com.tr https://sst.tchibo.cz https://sst.tchibo.de https://sst.tchibo.hu https://sst.tchibo.pl https://sst.tchibo.sk https://tagm.tchibo.at https://tagm.tchibo.ch https://tagm.tchibo.com.tr https://tagm.tchibo.cz https://tagm.tchibo.de https://tagm.tchibo.hu https://tagm.tchibo.pl https://tagm.tchibo.sk https://tchibo.omq.de; img-src 'self' blob: data: https://*.adnxs.com https://*.creativecdn.com https://*.doubleclick.net https://*.loyjoy.com https://*.quantserve.com https://*.teads.tv https://ad.360yield.com https://bat.bing.com https://c.seznam.cz https://cdn.cookielaw.org https://ct.pinterest.com https://ctgdm.tchibo.de https://exchange.mediavine.com https://gum.criteo.com https://heapanalytics.com https://id5-sync.com https://jadserve.postrelease.com https://pixel.rubiconproject.com https://px.ads.linkedin.com https://r.casalemedia.com https://rtb-csync.smartadserver.com https://simage2.pubmatic.com https://ssl.gstatic.com https://sync-t1.taboola.com https://sync.outbrain.com https://tchibo.omq.de https://www.eduscho.at https://www.facebook.com https://www.fr.tchibo.ch https://www.glami.com.tr https://www.glami.cz https://www.glami.hu https://www.google-analytics.com https://www.google.com https://www.google.de https://www.googletagmanager.com https://www.tchibo.ch https://www.tchibo.com.tr https://www.tchibo.cz https://www.tchibo.de https://www.tchibo.hu https://www.tchibo.pl https://www.tchibo.sk https://*.tchibo.ch https://*.tchibo.com.tr https://*.tchibo.cz https://*.tchibo.de https://*.tchibo.hu https://*.tchibo.pl https://*.tchibo.sk; media-src blob: data: https://*.loyjoy.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.adform.net https://*.adnxs.com https://*.clarity.ms https://*.contentsquare.net https://*.creativecdn.com https://*.criteo.com https://*.doubleclick.net https://*.getback.ch https://*.loyjoy.com https://*.quantserve.com https://*.scarabresearch.com https://*.taboola.com https://*.teads.tv https://analytics.tiktok.com https://bat.bing.com https://cdn.cookielaw.org https://cdn.heapanalytics.com https://cdn.innkeepr.ai https://cdn.xplosion.de https://connect.facebook.net https://ct.pinterest.com https://d.c.cdnsrv.de https://gtm.adt313.net https://heapanalytics.com https://js.adsrvr.org https://js.cnnx.link https://lib.onet.pl https://pixel.byspotify.com https://pixel.wp.pl https://postback.affiliateport.eu https://rules.quantcount.com https://s.pinimg.com https://s.uicdn.com https://snap.licdn.com https://static.lamoda.pl https://tagm.tchibo.at https://tagm.tchibo.ch https://tagm.tchibo.com.tr https://tagm.tchibo.cz https://tagm.tchibo.de https://tagm.tchibo.hu https://tagm.tchibo.pl https://tagm.tchibo.sk https://tchibo.omq.de https://www.glami.eco https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://www.tchibo.de; script-src-attr 'unsafe-hashes' 'sha256-ivV50ZsPN5Lju7c/JA65LYwvtdlO5c7wqGJ0usau7zI='; style-src 'self' 'unsafe-inline' https: https://*.loyjoy.com https://heapanalytics.com; worker-src blob: 8 default-src * 'self'; style-src * 'self' 'unsafe-inline'; img-src * 'self' data: blob:; script-src * 'self' about: 'unsafe-inline' 'unsafe-eval' data:; worker-src * 'self' data: blob: 'unsafe-eval' 'unsafe-inline'; frame-src * 'self'; media-src 'self' blob: *; font-src * 'self' data:; upgrade-insecure-requests; form-action 'self'; frame-ancestors 'self';report-uri /contentsecuritypolicy/report 8 font-src cash-f.squarecdn.com data: *.gstatic.com *.photoslurp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.facebook.com *.mediquo.com *.hotjar.com *.criteo.com *.google.com *.clic2buy.com *.vimeo.com *.photoslurp.com *.sitescout.com *.criteo.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * cdn.doofinder.com *.cloudfront.net *.amazonaws.com *.bing.com *.facebook.com widget-mediator.zopim.com *.swogo.net *.criteo.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.photoslurp.com *.googleusercontent.com *.clarity.ms *.smartadserver.com *.bidswitch.net *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.mediavine.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.taboola.com *.teads.tv *.3lift.com *.yahoo.com *.adform.net *.omnitagjs.com id5-sync.com *.yieldlab.net *.yieldmo.com *.demdex.net *.krxd.net *.thebrighttag.com *.sitescout.com *.sanity.io cdn.flbx.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cdn.doofinder.com *.naturitas.com naturitas.slgnt.eu static.zdassets.com bat.bing.com connect.facebook.net *.swogo.net *.hotjar.com *.mediquo.com static.criteo.net *.criteo.com *.typeform.com *.clic2buy.com polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.googleoptimize.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.photoslurp.com *.clarity.ms *.pixel.ad *.dwin1.com *.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app *.doofinder.com *.googleapis.com *.photoslurp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.doofinder.com wss://*.doofinder.com *.naturitas.com *.naturitas.es naturitas-atc.zendesk.com ekr.zdassets.com wss://widget-mediator.zopim.com *.swogo.net *.googlesyndication.com *.hotjar.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.adyen.com *.photoslurp.com *.clarity.ms *.apicdn.sanity.io *.api.sanity.io *.getflowbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 8 report-uri /report-csp-violation; upgrade-insecure-requests 8 default-src * 'unsafe-inline' 'unsafe-eval'; style-src 'unsafe-inline'; script-src 'none' 'report-sample'; connect-src 'none'; form-action 'none'; frame-src 'none'; worker-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://csp.threatview.app/report; report-to threatview 8 default-src https:; connect-src https: wss:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' *.google.com fonts.googleapis.com static.pazaruvaj.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net maxcdn.bootstrapcdn.com ssl.ceneo.pl s.kk-resources.com elnino.daktela.com www.wiarygodneopinie.pl ts.tradetracker.net cdn.foxentry.cz www.parfemy-elnino.cz geowidget.inpost.pl www.googletagmanager.com smartsuppcdn.com *.demandware.net; object-src 'self'; img-src 'self' https: data:; font-src https: data:; frame-ancestors 'self' *.creativecdn.com *.hotjar.com *.googletagmanager.com; report-uri https://elnino.report-uri.com/r/d/csp/enforce 8 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://www.awin1.com https://lantern.roeyecdn.com https://tagmanager.google.com https://cdn.trustcommander.net https://www.dwin1.com https://www.googletagmanager.com https://maps.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://bat.bing.com https://*.doubleclick.net https://www.axa-video.de https://*.visualwebsiteoptimizer.com https://app.vwo.com https://www.google.com https://platform.commandersact.com https://connect.facebook.net https://*.aklamio.com blob: https://ct.pinterest.com https://s.pinimg.com https://acdn.adnxs.com https://ib.adnxs.com https://snap.licdn.com https://data.dbv.de ;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.visualwebsiteoptimizer.com https://app.vwo.com https://s3.amazonaws.com https://googletagmanager.com https://www.googletagmanager.com ;base-uri 'self'; object-src 'none'; default-src 'self' blob: data: https://fonts.gstatic.com/; form-action 'self'; frame-src https://www.awin1.com https://app.vwo.com https://*.visualwebsiteoptimizer.com https://entry.axa-de.intraxa/ https://entry.axa.de https://www.axa-video.de https://www.axa.de https://inte.axa.de https://*.doubleclick.net https://cdn.trustcommander.net https://www.dwin1.com https://connect.facebook.net https://www.facebook.com https://td.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com https://ct.pinterest.com https://googletagmanager.com https://insight.adsrvr.org 'self' https://www.googletagmanager.com https://data.dbv.de https://www.youtube.com; img-src 'self' data: https://*.visualwebsiteoptimizer.com https://chart.googleapis.com https://wingify-assets.s3.amazonaws.com https://app.vwo.com https://track.adform.net https://ad.doubleclick.net https://www.facebook.com https://bat.bing.com https://*.google.com https://www.google.de https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://googleads.g.doubleclick.net *.doubleclick.net https://i.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://www.financeads.net https://www.aklamio.com/ https://ct.pinterest.com https://ib.adnxs.com https://*.ads.linkedin.com https://data.dbv.de; connect-src 'self' https://*.visualwebsiteoptimizer.com https://app.vwo.com https://*.googlesyndication.com https://*.google.com https://*.google.de https://*.google-analytics.com https://*.analytics.google.com https://www.google-analytics.com https://*.doubleclick.net https://bat.bing.com https://privacy.trustcommander.net https://privacy.commander1.net https://privacy.commander1.com https://www.googletagmanager.com https://maps.googleapis.com https://fonts.googleapis.com https://*.dbv.de https://cloud.service.aerzteversicherung.de https://mcdyr4395tgnrcnr8bt5wsrgh-11.pub.sfmc-content.com https://*.aklamio.com https://www.googleadservices.com https://ct.pinterest.com https://ib.adnxs.com https://acdn.adnxs.com https://www.facebook.com https://*.ads.linkedin.com https://p.adsymptotic.com https://*.linkedin.oribi.io https://sjs.bizographics.com;;report-uri /site/dbv-de/cspReportOnly 8 default-src 'self' f.vimeocdn.com; connect-src 'self' blob: data: ws: wss: *.6sc.co *.6sense.com *.agora.io *.akamaized.net clientassets.sightera.com.s3.amazonaws.com https://d263mgllkjh2k2.cloudfront.net http://d1ripsxh7es2qp.cloudfront.net https://d3fclmoge30w0w.cloudfront.net cognito-identity.us-east-1.amazonaws.com cognito-identity.us-west-1.amazonaws.com https://s3.amazonaws.com/beast.branding.sightera.com https://s3.amazonaws.com/beast.business.sightera.com https://s3.amazonaws.com/beast.business.sightera.com/ https://s3.amazonaws.com/beast.branding.sightera.com/ https://s3.amazonaws.com/test.sightera.com/ https://s3.amazonaws.com/business.sightera.com/ https://s3.amazonaws.com/sound.sightera.com/ sqs.us-east-1.amazonaws.com sqs.us-west-1.amazonaws.com wirewax.s3.eu-west-1.amazonaws.com *.amplitude.com vimeo.bynder.com bat.bing-int.com bat.bing.com bat.bing.net www.bing.com api.branch.io cdn.builder.io https://d1ripsxh7es2qp.cloudfront.net http://d1oca24q5dwo6d.cloudfront.net media.gettyimages.com d2by6sxflmuwyq.cloudfront.net duysrfiajusdh.cloudfront.net dv7a7fjpjy29e.cloudfront.net cdn.cookielaw.org browser-intake-datadoghq.com ad.doubleclick.net *.g.doubleclick.net *.elfsight.com fp.service.expressplay.com pr.service.expressplay.com wv.service.expressplay.com www.facebook.com api.figma.com *.firebaseio.com tracking-api.g2.com *.getsmartling.com *.google.ae *.google.com *.google.ca *.google.ch *.google.es *.google.fr *.google.ge *.google.iq *.google.is *.google.it *.google.pl *.google.se *.google.si *.google.rs *.google.co.jp *.google.co.kr *.google.co.nz *.google.co.th *.google.co.uk *.google.com.ar *.google.com.au *.google.com.br *.google.com.mx *.google.com.pk *.google.com.sa *.google.com.tr *.google.com.uk *.google.de *.analytics.google.com *.google-analytics.com www.googleadservices.com *.googleapis.com csi.gstatic.com pagead2.googlesyndication.com *.googletagmanager.com api.greenhouse.io *.hivestreaming.com 117151225.intellimizeio.com *.intellimize.co *.kollective.app *.kollective.app:31015 *.kollectivecd.com leatherback-dot-vimeo-prod.appspot.com snap.licdn.com px.ads.linkedin.com linkedin.com *.litix.io *.cdn.magisto.com vimeo.magisto.com *.maze.co 582-gou-684.mktoresp.com js-agent.newrelic.com t.paypal.com data.pendo.io *.pndsn.com privacyportal.onetrust.com privacyportal-cdn.onetrust.com app.qualified.com *.qualtrics.com pixel-config.reddit.com www.redditstatic.com *.riskified.com *.statscollector.ap.sd-rtn.com *.ap.sd-rtn.com *.sd-rtn.com o209747.ingest.us.sentry.io sierra.chat simonsignal.com static.simonsignal.com sdk-api-v1.singular.net web-sdk-cdn.singular.net telemetry.transcend.io transcend-cdn.com https://drm.vhx.com/v2/fairplay/cert collector.vhx.tv *.cloud.vimeo.com interactive.create.vimeo.com *.vimeo.com vimeo.com *.vimeo.work *.vimeocdn.com cdn.widerfunnel.com appds8093.blob.core.windows.net *.wirewax.com *.wirewax.tv *.zdassets.com vimeosupport.zendesk.com *.zoom.us zoom.us ws.zoominfo.com api.box.com public.boxcloud.com; font-src 'self' data: d2by6sxflmuwyq.cloudfront.net dv7a7fjpjy29e.cloudfront.net fonts.gstatic.com *.cdn.magisto.com privacyportal-cdn.onetrust.com www.paypalobjects.com cf-st.sc-cdn.net use.typekit.net f.vimeocdn.com edge-assets.wirewax.com cdn01.boxcdn.net; frame-src *; img-src * blob: data:; media-src 'self' blob: data: *.akamaized.net https://d263mgllkjh2k2.cloudfront.net http://d1oca24q5dwo6d.cloudfront.net duysrfiajusdh.cloudfront.net media.gettyimages.com *.gvt1.com *.cdn.magisto.com *.eu.cloud.vimeo.com live-api.cloud.vimeo.com player.vimeo.com *.vimeocdn.com app.qualified.com https://s3.amazonaws.com/sound.sightera.com/ https://s3.amazonaws.com/test.sightera.com/ https://s3.amazonaws.com/beast.business.sightera.com/ https://s3.amazonaws.com/beast.business.sightera.com https://s3.amazonaws.com/beast.branding.sightera.com/ https://storage.googleapis.com/vimeo-create-prod-files/ http://d1ripsxh7es2qp.cloudfront.net https://d3fclmoge30w0w.cloudfront.net https://storage.googleapis.com/vimeo-prod-upload-create-us-east1/ https://storage.googleapis.com/vimeo-prod-upload-create-europe-west1/ https://storage.googleapis.com/vimeo-storage-dev-upload-create-us-east1/ https://storage.googleapis.com/vimeo-storage-dev-upload-create-europe-west1/ https://captions.vimeo.com https://captions-eu.vimeo.com; object-src 'self' *.vimeocdn.com *.akamaized.net; script-src 'unsafe-inline' 'unsafe-eval' 'self' data: ws: wss: https://s0.2mdn.net/instream/video/ *.6sc.co wirewax.s3.eu-west-1.amazonaws.com app.link bat.bing-int.com bat.bing.com cdnjs.cloudflare.com challenges.cloudflare.com www.datadoghq-browser-agent.com *.g.doubleclick.net www.dropbox.com static.elfsight.com *.elfsightcdn.com connect.facebook.net *.firebaseio.com tracking.g2crowd.com *.google.com www.googleadservices.com www.gstatic.com *.google-analytics.com maps.googleapis.com pendo-io-static.storage.googleapis.com pendo-static-6633483048714240.storage.googleapis.com pagead2.googlesyndication.com www.googletagmanager.com www.googletagservices.com cdn.intellimize.co *.kollective.app snap.licdn.com src.litix.io lp.livestream.com munchkin.marketo.net snippet.maze.co privacyportal-cdn.onetrust.com www.paypalobjects.com cdn.pendo.io js.qualified.com data.pendo.io *.qualtrics.com www.redditstatic.com beacon.riskified.com secured-pixel.com sierra.chat static.simonsignal.com web-sdk-cdn.singular.net transcend-cdn.com vimeo.com *.vimeo.com *.vimeocdn.com cdn.widerfunnel.com edge-assets.wirewax.com embedder-sdk.wirewax.com embedder-sdk.wirewax.tv origin-4.xtlo.net static.zdassets.com *.zoom.us zoom.us ws.zoominfo.com static.zuora.com https://www.dropbox.com/static/api/2/dropins.js cdn01.boxcdn.net; style-src 'self' 'unsafe-inline' *.6sc.co cdn01.boxcdn.net cdnjs.cloudflare.com accounts.google.com fonts.googleapis.com pendo-static-6633483048714240.storage.googleapis.com www.gstatic.com lp.livestream.com privacyportal-cdn.onetrust.com www.paypalobjects.com sierra.chat *.vimeo.com *.vimeocdn.com vimeopro.com transcend-cdn.com cdn.widerfunnel.com edge-assets.wirewax.com edge-player5.wirewax.com origin-4.xtlo.net; worker-src 'self' blob:; report-to csp-endpoint; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=puba92ed04ee7cceea44335c3d8c1ccc173&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Acspreport%2Cenv%3Aproduction 7 frame-ancestors 'self' https://*.yahooinc.com; object-src 'none'; script-src 'none'; report-uri https://csp.yahoo.com/beacon/csp?src=yahooinc; 7 report-uri https://cspr.app.rbb-cloud.de/cspr/;frame-ancestors 'self' https://www.rbb24.de https://*.rbb-online.de https://www.radioeins.de https://www.fritz.de https://www.antennebrandenburg.de https://www.inforadio.de https://www.rbb888.de; 7 default-src https: wss: data: blob:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data: blob:; font-src https: data:; worker-src blob:; report-uri /csp-report 7 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; 7 default-src * 'unsafe-inline' 'unsafe-eval' data: blob: 7 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/marketing_platform 6 require-trusted-types-for 'script';report-uri /cspreport 6 child-src blob: data: https:; connect-src https: wss:; default-src blob: data: https: 'report-sample' 'unsafe-eval' 'unsafe-inline'; font-src data: https:; form-action https:; frame-src data: https:; img-src blob: data: https:; media-src blob: data: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; report-uri https://csp.ffx.io/; report-to csp-endpoint 6 default-src https: 'unsafe-inline' 'unsafe-eval' wss: ;img-src https: data: blob: ; font-src https: data:; form-action https: http://www.last.fm; report-uri https://cbsi.report-uri.io/r/default/csp/enforce 6 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/domain-registry 6 default-src 'self' data: blob: *.verisign.com *.brightcove.net *.cookielaw.org; report-uri /report-csp; img-src 'self' data: *.verisign.com *.siteimproveanalytics.io *.brightcove.com *.prod.boltdns.net *.vrsn.com *.cookielaw.org *.sc.omtrdc.net/; object-src 'none'; script-src 'strict-dynamic' 'sha256-CGpdaFkwpoN/Y4QoqLo0RdJmj5+2hbbSOQshfoM+KXM=' 'sha256-Qlywh04o9RqzY3pRMVETyTW7Jfbg5Tzu4fKM5DsfERo=' 'sha256-kLnArxja6Bs6U2Il+xfeJn8veuH81wPxrw/ixeqvDT8=' 'sha256-Sh79HpVcRWbbh8F4vWgVVkmc5kGu923LZAOeMWUh2w0=' 'sha256-Sh79HpVcRWbbh8F4vWgVVkmc5kGu923LZAOeMWUh2w0=' 'sha256-r0mwgRVPIhWexF7020SoSyg7nS4sUr41+jF0gvQaJV4=' 'sha256-DzahDayNFEoUz+wus3ioBIpoQDQ08i/zH3pCScqWICY=' 'sha256-+qB++cp4k+Izi7u8vVq0ycjxNzwKmKmud31l0gCfwPk=' 'sha256-XfhXbgLiZndw4wQttCtlwRntxTnAXXHXH5oZdlTiCkc=' 'sha256-PkiHtGuW8aOw2cCDmzzFj6UZ7sXa/KVHkqmlnHZ4x4A=' 'sha256-PEpHBwnW8aVL0kXvm2MGm0ZHd5G4cdbN68OeMSY0kYA=' 'sha256-n6xl1kvfuS7pcYrH49v7bpiJWWRtuFNr3avfXq0qFBg=' 'sha256-9cxvFRJs+pkTqyLJYARzDPz1UmNhF2zMtugmVy8FPHM=' 'sha256-TbWeTDEIxBhTCQ/lm4IexwU7qnX1hMXWnZH1JzonFtM=' 'sha256-ZZk/LrH7rKIyCirJiYDdNHSADxzxwez30zDWZ+xtJiE=' 'sha256-truTrv3vESVm1meLN38xeX1+9WwEUJgQ6Y4WEpx2sMA=' 'sha256-SRRUCF20jnbOSMxPsDmSPq4nvKhvMa2yvjk0XJfIsDo=' 'sha256-uYob4RPVS1cIXTQmwb1vAL/CR6mlXAQ5UXmho7aZy9A=' 'sha256-OxCbmFFmF9RBgAD6OYI724tSm1ZPsB4mIefXNuUmYdI=' 'sha256-Odkwiy+kw1IMFIqpLj5CTeKv3UcCpdcKdVi7A0nLw24=' 'sha256-S4i1aR10IfngJLP8iRh9zAWtz3Lyg7IL4wZ1aVb/mcI=' 'sha256-vaIc3Fp4V1Ci4UD6/K3GbaZnei/1jWDKrOQwR23Czb8=' *.onetrust.com assets.adobedtm.com siteimproveanalytics.com players.brightcove.net *.zencdn.net *.salesforceliveagent.com *.verisign.com; style-src 'self' 'unsafe-inline'; connect-src 'self' *.prod.boltdns.net *.brightcove.com *.akamaihd.net *.greenhouse.io *.verisign.com *.vrsn.com *.cookielaw.org *.onetrust.com *.cludo.com *.sc.omtrdc.net dpm.demdex.net; worker-src blob: 6 img-src https: blob: data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.fcl.cloud https://*.flightcentre.com https://*.flightcentre.com.au https://*.flightcentre.co.nz https://*.flightcentre.co.za https://*.flightcentre.ca https://*.flightcentre.co.uk https://www.googletagmanager.com https://*.google-analytics.com https://www.youtube.com https://*.fullstory.com https://vxml4.plavxml.com https://*.nr-data.net https://*.usabilla.com http://*.usabilla.com https://*.newrelic.com https://d6tizftlrpuof.cloudfront.net https://cdnjs.cloudflare.com https://cdn.optimizely.com https://*.outbrain.com https://analytics.tiktok.com https://bat.bing.com https://cdn.abrankings.com https://connect.facebook.net https://edge.fullstory.com https://loader.wisepops.com https://wisepops.net https://s.pinimg.com https://snap.licdn.com https://googleads.g.doubleclick.net https://accounts.google.com https://*.pinterest.com https://*.evergage.com https://js.adsrvr.org https://static.criteo.net https://flightcentre-webchat.gotbot.co.za https://7226714.collect.igodigital.com https://cdn.pdst.fm https://*.hotjar.com https://tr.snapchat.com https://*.feefo.com https://koi-3qn5erhpry.marketingautomation.services https://cdn.jsdelivr.net https://*.stackla.com https://cdn.cookielaw.org https://sc-static.net https://developer.livehelpnow.net https://cdn.evgnet.com https://maps.googleapis.com https://sdk.joinsherpa.io https://cdn.wisepops.com https://*.quantserve.com https://*.livechatinc.com https://flightcentre.r-cubed.co.uk https://rules.quantcount.com https://*.criteo.com https://code.jquery.com https://*.creativecdn.com https://*.rokt.com https://*.mypurecloud.com.au https://s.yimg.com https://sp.analytics.yahoo.com *.feroot.com https://*.taboola.com https://*.redditstatic.com https://*.reddit.com; style-src 'unsafe-inline' 'self' https://fonts.googleapis.com https://register.feefo.com https://cdn.cookielaw.org https://d6tizftlrpuof.cloudfront.net; connect-src https://*.fcl.cloud wss://*.fcl.cloud https://*.flightcentre.com https://*.flightcentre.com.au https://*.flightcentre.co.nz https://*.flightcentre.co.za https://*.flightcentre.ca https://*.flightcentre.co.uk https://*.fclmedia.com https://fcl-sydney-geo-7.ent.ap-southeast-2.aws.found.io https://flowise-dev.dse.fctg.global https://*.launchdarkly.com https://*.optimizely.com *.nr-data.net https://*.fullstory.com https://*.google-analytics.com https://*.google.com https://*.google.com.au https://*.google.ca https://*.google.co.nz https://*.google.co.za https://*.google.co.uk https://*.evergage.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.pangle-ads.com https://*.pinterest.com https://*.linkedin.com https://*.outbrain.com https://*.g.doubleclick.net https://wisepops.net https://*.wisepops.com https://*.feefo.com https://cdn.cookielaw.org https://developer.livehelpnow.net https://*.snapchat.com https://www.facebook.com https://bat.bing.com https://bat.bing.net https://*.onetrust.com https://flightcentre.r-cubed.co.uk https://adservice.google.com https://www.google.com https://analytics.google.com https://www.googleadservices.com https://*.browser-intake-datadoghq.com https://*.criteo.com https://*.usabilla.com https://*.creativecdn.com https://*.mypurecloud.com.au wss://*.mypurecloud.com.au https://*.salesforce.com https://d1nojfewl3tku3.cloudfront.net/assets https://maps.googleapis.com https://s.yimg.com *.feroot.com https://insight.adsrvr.org https://*.taboola.com https://*.reddit.com; default-src https: blob: 'unsafe-inline' 'unsafe-eval' wss://*.flightcentre.com.au:*; font-src https: blob: data:; frame-ancestors 'self'; report-uri /api/csp_report 6 default-src 'self'; connect-src 'self' https://region1.google-analytics.com https://connect.facebook.net https://pagead2.googlesyndication.com; https://region1.google-analytics.com https://connect.facebook.net https://pagead2.googlesyndication.com https://www.facebook.com; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://consentcdn.cookiebot.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://s1-staging-mundijuegos-com.s3.eu-west-1.amazonaws.com; https://cdnjs.cloudflare.com; frame-src 'self' 'unsafe-inline' https://www.google.com https://www.gstatic.com https://www.googletagmanager.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' 'unsafe-inline' data: https://www.google-analytics.com https://connect.facebook.net https://cdn.jsdelivr.net; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; 6 default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; connect-src * data: blob: 'unsafe-inline'; frame-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; object-src * data: blob: 'unsafe-inline'; 6 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://clients2.google.com/gr/gr_full_2.0.6.js https://clients2.google.com/gr/gr_sync.js https://payments.google.com/payments/v4/js/integrator.js https://payments.sandbox.google.com/payments/v4/js/integrator.js https://ssl.gstatic.com/external_hosted/lottie/lottie.js https://translate.google.com/translate_a/element.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.google.com/js/bg/ https://www.gstatic.com/_/boq-play/_/js/k=boq-play.PlayStoreUi.en_US.3W63kwn-PHU.2021.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/ https://payments.youtube.com/payments/v4/js/integrator.js https://payments.cloud.google/payments/v4/js/integrator.js;report-uri /_/PlayStoreUi/cspreport/fine-allowlist 6 default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-to blogspot; report-uri https://draft.blogger.com/cspreport 6 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.nosto.com *.nos.to *.klarna.com js.mollie.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.nosto.com *.nos.to *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.nosto.com *.nos.to *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com js.mollie.com https://www.google.com https://www.gstatic.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.nosto.com *.nos.to *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.nosto.com *.nos.to *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://20a27546-5165-4716-8e1c-c91dee6f68ae.sansec.watch/; report-to report-endpoint; 6 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data: 6 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://www.youtube.com/ 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com/ *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://widget.trustpilot.com/ *.weltpixel.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com https://www.usaskateshop.com/ *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com maps.gstatic.com maps.googleapis.com https://usaskateshop-com.b-cdn.net/ *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.hotjar.com https://static.zdassets.com https://payments.worldpay.com https://cdn.clerk.io https://api.clerk.io https://ss.euroskateshop.de https://ss.euroskateshop.nl https://ss.euroskateshop.ch *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com applepay.cdn-apple.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klarnacdn.net assets.braintreegateway.com *.fontawesome.com applepay.cdn-apple.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.usaskateshop.dk https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 6 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: ws: wss: https:; report-uri https://l.iplsc.com/logger/ 5 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; report-uri /csp-report; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: ivi.ru *.ivi.ru ivi.tv *.ivi.tv turkdizi.com *.turkdizi.com turk.ivi.tv s3.pub.ivi.ru *.dfs.ivi.ru google.com *.google.com gstatic.com *.gstatic.com googletagmanager.com *.googletagmanager.com *.googleapis.com googlesyndication.com *.googlesyndication.com google-analytics.com *.google-analytics.com doubleclick.net *.doubleclick.net cm.g.doubleclick.net *.googleadservices.com www.googlecommerce.com yandex.ru *.yandex.ru yandex.net *.yandex.net yandex.st *.yandex.st yastat.net *.yastat.net yastatic.net *.yastatic.net yandex.com *.yandex.com yandexcloud.net *.yandexcloud.net yandex.by *.yandex.by yandex.kz *.yandex.kz impression.appmetrica.yandex.com mail.ru *.mail.ru tns-counter.ru *.tns-counter.ru doubleverify.com *.doubleverify.com s0.2mdn.net adriver.ru *.adriver.ru statad.ru *.statad.ru targetads.io *.targetads.io flocktory.com *.flocktory.com getshop.tv *.getshop.tv *.clarity.ms *.hotjar.com adfox.ru *.adfox.ru adsafeprotected.com *.adsafeprotected.com 5visions.com *.5visions.com adjust.com *.adjust.com ozon.ru *.ozon.ru bridgertb.tech *.bridgertb.tech serving-sys.ru *.serving-sys.ru cmediahub.ru *.cmediahub.ru weborama-tech.ru *.weborama-tech.ru digitaltarget.ru *.digitaltarget.ru mhverifier.ru *.mhverifier.ru adlooxtracking.ru *.adlooxtracking.ru adlooxtracking.com *.adlooxtracking.com telecid.ru *.telecid.ru tele2.ru *.tele2.ru telecomid.ru *.telecomid.ru teletarget.ru *.teletarget.ru cdnvideo.ru *.cdnvideo.ru beeline.ru *.beeline.ru moe.video *.moe.video otm-r.com *.otm-r.com punchmedia.ru *.punchmedia.ru skwstat.ru *.skwstat.ru stbid.ru *.stbid.ru videonow.ru *.videonow.ru utraff.com *.utraff.com acint.net *.acint.net betweendigital.com *.betweendigital.com betweendigital.ads.com lentainform.com *.lentainform.com code.moviead55.ru moviead55.ru cs-0.moevideo.biz moevideo.biz buzzoola.com *.buzzoola.com uma.media *.uma.media appsflyer.com *.appsflyer.com instreamvideo.ru *.instreamvideo.ru mobilebanner.ru *.mobilebanner.ru admetrica.ru *.admetrica.ru prodmp.ru *.prodmp.ru sync.adspend.space reichelcormier.bid *.reichelcormier.bid secure.adnxs.com adnxs.com ohmy.bid *.ohmy.bid ssl.hurra.com hurra.com bidvol.com *.bidvol.com adstreamer.ru *.adstreamer.ru adkernel.com *.adkernel.com sync.dmp.otm-r.com republer.com sync.republer.com sync.viadata.store viadata.store sync.viavideo.digital viavideo.digital wi-fi.ru *.wi-fi.ru tms.dmp.wi-fi.ru track.rutarget.ru rutarget.ru impressions.onelink.me onelink.me px170.mediahills.ru mediahills.ru mts.ru *.mts.ru sa.rtb.mts.ru digital-alliance.tech *.digital-alliance.tech admon.pro *.admon.pro adhight.net *.adhight.net getads.ru *.getads.ru vk.com *.vk.com connect.facebook.net facebook.com *.facebook.com *.skcrtxr.com api.mindbox.ru simbad.pro taglitics.com creatives.afp.ai cdn.al-adtech.com cdn.jsdelivr.net *.criteo.com image.sendsay.ru snap.licdn.com dap.digitalgov.gov bat.bing.com www.artfut.com cdn.cookielaw.org static.ads-twitter.com s.pinimg.com cdn-cookieyes.com cdn.taboola.com www.redditstatic.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: ivi.ru *.ivi.ru ivi.tv *.ivi.tv turkdizi.com *.turkdizi.com turk.ivi.tv s3.pub.ivi.ru *.dfs.ivi.ru google.com *.google.com gstatic.com *.gstatic.com googletagmanager.com *.googletagmanager.com *.googleapis.com googlesyndication.com *.googlesyndication.com google-analytics.com *.google-analytics.com doubleclick.net *.doubleclick.net cm.g.doubleclick.net *.googleadservices.com www.googlecommerce.com yandex.ru *.yandex.ru yandex.net *.yandex.net yandex.st *.yandex.st yastat.net *.yastat.net yastatic.net *.yastatic.net yandex.com *.yandex.com yandexcloud.net *.yandexcloud.net yandex.by *.yandex.by yandex.kz *.yandex.kz impression.appmetrica.yandex.com mail.ru *.mail.ru tns-counter.ru *.tns-counter.ru doubleverify.com *.doubleverify.com s0.2mdn.net adriver.ru *.adriver.ru statad.ru *.statad.ru targetads.io *.targetads.io flocktory.com *.flocktory.com getshop.tv *.getshop.tv *.clarity.ms *.hotjar.com adfox.ru *.adfox.ru adsafeprotected.com *.adsafeprotected.com 5visions.com *.5visions.com adjust.com *.adjust.com ozon.ru *.ozon.ru bridgertb.tech *.bridgertb.tech serving-sys.ru *.serving-sys.ru cmediahub.ru *.cmediahub.ru weborama-tech.ru *.weborama-tech.ru digitaltarget.ru *.digitaltarget.ru mhverifier.ru *.mhverifier.ru adlooxtracking.ru *.adlooxtracking.ru adlooxtracking.com *.adlooxtracking.com telecid.ru *.telecid.ru tele2.ru *.tele2.ru telecomid.ru *.telecomid.ru teletarget.ru *.teletarget.ru cdnvideo.ru *.cdnvideo.ru beeline.ru *.beeline.ru moe.video *.moe.video otm-r.com *.otm-r.com punchmedia.ru *.punchmedia.ru skwstat.ru *.skwstat.ru stbid.ru *.stbid.ru videonow.ru *.videonow.ru utraff.com *.utraff.com acint.net *.acint.net betweendigital.com *.betweendigital.com betweendigital.ads.com lentainform.com *.lentainform.com code.moviead55.ru moviead55.ru cs-0.moevideo.biz moevideo.biz buzzoola.com *.buzzoola.com uma.media *.uma.media appsflyer.com *.appsflyer.com instreamvideo.ru *.instreamvideo.ru mobilebanner.ru *.mobilebanner.ru admetrica.ru *.admetrica.ru prodmp.ru *.prodmp.ru sync.adspend.space reichelcormier.bid *.reichelcormier.bid secure.adnxs.com adnxs.com ohmy.bid *.ohmy.bid ssl.hurra.com hurra.com bidvol.com *.bidvol.com adstreamer.ru *.adstreamer.ru adkernel.com *.adkernel.com sync.dmp.otm-r.com republer.com sync.republer.com sync.viadata.store viadata.store sync.viavideo.digital viavideo.digital wi-fi.ru *.wi-fi.ru tms.dmp.wi-fi.ru track.rutarget.ru rutarget.ru impressions.onelink.me onelink.me px170.mediahills.ru mediahills.ru mts.ru *.mts.ru sa.rtb.mts.ru digital-alliance.tech *.digital-alliance.tech admon.pro *.admon.pro adhight.net *.adhight.net getads.ru *.getads.ru vk.com *.vk.com connect.facebook.net facebook.com *.facebook.com *.skcrtxr.com api.mindbox.ru simbad.pro taglitics.com creatives.afp.ai cdn.al-adtech.com cdn.jsdelivr.net *.criteo.com image.sendsay.ru snap.licdn.com dap.digitalgov.gov bat.bing.com www.artfut.com cdn.cookielaw.org static.ads-twitter.com s.pinimg.com cdn-cookieyes.com cdn.taboola.com www.redditstatic.com *.ahrefs.com *.alicdn.com *.tiktok.com *.amazonaws.com *.cloudflare.com cdn.amplitude.com cdn.segment.com cdn.branch.io app.usercentrics.eu app.termly.io cdn.walkme.com s.go-mpulse.net cdn.moengage.com cdn.omniconvert.com siteimproveanalytics.com edge.fullstory.com cdn.rutarget.ru sb.scorecardresearch.com secure.quantserve.com c.amazon-adsystem.com cdn.mxpnl.com cdn.userway.org kp.apiget.ru static.pro-bm7.ru rus.glbbars.com api.cpatext.ru widgets.101apis.com images.uc.cn cdn.browsiprod.com unpkg.zhimg.com s.yimg.jp 5 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://dock.ui.bosch.tech https://www.googletagmanager.com https://www.google-analytics.com https://btm.bosch.com https://www.youtube.com https://maps.google.com; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://search.internet.bosch.com https://bosch-i3-caas-api.e-spirit.cloud https://*.google-analytics.com https://www.googletagmanager.com https://endpoint.chatbot-suite.bosch.tech https://maps.googleapis.com https://btm.bosch.com https://cx.bosch-so.com https://dock.ui.bosch.tech; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://crdostaticwebsite337215.z6.web.core.windows.net https://crdopublicationswebsite.z6.web.core.windows.net; img-src 'self' data: https://assets.bosch.com https://www.googletagmanager.com https://www.google-analytics.com https://i.ytimg.com https://maps.google.com https://maps.gstatic.com; manifest-src 'self'; media-src 'self' https://assets.bosch.com; style-src-elem 'self' 'unsafe-inline' https://btm.bosch.com https://fonts.googleapis.com https://webchatplugins.blob.core.windows.net; worker-src 'none'; report-uri https://o4508243129991168.ingest.de.sentry.io/api/4508243155288144/security/?sentry_key=2f9480313f00b63a26560fd685315765; report-to csp-endpoint 5 default-src 'self' *; media-src 'self' * data: ; font-src 'self' * data: ; img-src 'self' data: blob: *; script-src * 'unsafe-inline' 'unsafe-eval' data: *; style-src 'self' 'unsafe-inline' *; worker-src 'self' * blob: ; report-uri /api/csp-violation 5 frame-ancestors 'self'; report-uri https://www.couriermail.com.au/csp-reports 5 object-src 'none'; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval'; style-src * 'report-sample' 'unsafe-inline'; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 5 default-src 'self' 'unsafe-inline' 'unsafe-eval' https://snap.licdn.com *.willistowerswatson *.wtwco.com https://www.google-analytics.com https://cdn.cookielaw.org https://www.googletagmanager.com *.coveo.com https://players.brightcove.net *.doubleclick.net https://munchkin.marketo.net https://bat.bing.com *.facebook.net *.facebook.com https://siteimproveanalytics.com *.linkedin.com *.mktoresp.com *.siteimproveanalytics.io data: blob:;report-uri /custom/api/csp/logviolation 5 script-src 'self' 5 default-src 'self' 'unsafe-inline' data: *.hockeystack.com *.marianatek.com *.cookielaw.org *.chilipiper.com *.googletagmanager.com *.google.com *.gstatic.com *.cloudflare.com *.youtube.com *.youtube-nocookie.com *.vimeo.com *.licdn.com *.facebook.net *.clarity.ms *.google-analytics.com *.hs-scripts.com *.doubleclick.net unpkg.com *.wistia.net;upgrade-insecure-requests; 5 base-uri 'none'; frame-ancestors 'self'; img-src data: 'self' https://www.google-analytics.com https://cdn.rgfstaffing.be https://i.ytimg.com https://maps.googleapis.com https://vumbnail.com https://maps.gstatic.com https://img.youtube.com https://www.google.be https://cdn.startpeople.be; object-src 'none'; script-src 'unsafe-eval' 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval' https://use.fontawesome.coms https://code.jquery.com https://cdn.jsdelivr.net https://consentcdn.cookiebot.com https://*.google-analytics.com https://cdn.startpeople.be https://kit.fontawesome.com https://maps.googleapis.com https://js.monitor.azure.com https://www.googletagmanager.com https://consent.cookiebot.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; report-to csp-endpoint; report-uri https://csp-dxp.rgfstaffing.be/csp 5 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ http://fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com credomatic.compassmerchantsolutions.com https://www.tiendamonge.com/nps-check-out-tlv-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-cr https://www.tiendamonge.com/nps-entrega-tienda-en-linea-el-salvador https://www.tiendamonge.com/nps-entrega-tienda-en-linea-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-honduras https://www.tiendamonge.com/nps-entrega-tienda-en-linea-ni https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta-monge-pay https://www.tiendamonge.com/nps-monge-pay-desembolso-cash https://www.tiendamonge.com/nps-monge-pay-liveness https://www.tiendamonge.com/nps-monge-pay-pago-a-tarjeta-monge https://www.tiendamonge.com/nps-monge-pay-pago-operaciones https://www.tiendamonge.com/nps-monge-pay-registro https://www.tiendamonge.com/nps-service-desk-ti-costa-rica https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.youtube.com *.vimeo.com mongepay.com conway.ddev.site https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ https://adobedtm.com assets.adobedtm.com dpm.demdex.net *.googleapis.com *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni https://www.facebook.com https://www.google.com *.flixcar.com *.flixfacts.com *.cnetcontent.com *.vimeo.com https://widgetapp.ocularsolution.com *.getblue.io *.flipsnack.com https://heyzine.com https://promogallonic.com https://front-notrack.indexado.production.pmbox.cloud https://fichashppervasive.blob.core.windows.net https://www.tiendamonge.com/nps-check-out-tlv-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-cr https://www.tiendamonge.com/nps-entrega-tienda-en-linea-el-salvador https://www.tiendamonge.com/nps-entrega-tienda-en-linea-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-honduras https://www.tiendamonge.com/nps-entrega-tienda-en-linea-ni https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta-monge-pay https://www.tiendamonge.com/nps-monge-pay-desembolso-cash https://www.tiendamonge.com/nps-monge-pay-liveness https://www.tiendamonge.com/nps-monge-pay-pago-a-tarjeta-monge https://www.tiendamonge.com/nps-monge-pay-pago-operaciones https://www.tiendamonge.com/nps-monge-pay-registro https://www.tiendamonge.com/nps-service-desk-ti-costa-rica https://notrack.indexado.pmbox.cloud https://emersya.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://sandbox.migopayments.com/ https://web.migopayments.com/ https://online.fliphtml5.com/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ https://fledge.teads.tv *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.grupomonge.tt.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com widget.ocularsolution.com *.newrelic.com https://bam.nr-data.net *.facebook.com *.connect.facebook.net *.google.com *.google-analytics.com *.googleadservices.com *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.syndigo.com *.syndigo.cloud https://www.google.com https://www.google.com.co https://www.tiendamonge.com https://www.elgallomasgallo.com.ni https://www.prado.com.sv https://www.elgallomasgallo.com.hn https://www.elgallomasgallo.com.gt https://www.verdugotienda.com *.teads.tv *.scene7.com https://fichashppervasive.blob.core.windows.net https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://gmgdocumentos.blob.core.windows.net/ https://gmgecommerceprd.blob.core.windows.net/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com https://www.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://adobedtm.com fast.amc.demdex.net dpm.demdex.net *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni 'unsafe-inline' widget.ocularsolution.com cdn.cs.1worldsync.com https://ws.cs.1worldsync.com *.cloudflare.com https://bam.nr-data.net *.connect.facebook.net *.paypal.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.pingdom.net *.woorank.com *.cnetcontent.com *.syndigo.com *.syndigo.cloud https://event.getblue.io *.getblue.io https://p.teads.tv https://smetrics.verdugotienda.com https://rocio.ocularsolution.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ https://grupomongeecommerceprd.112.2o7.net http://fonts.cdnfonts.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com widget.ocularsolution.com *.facebook.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com rocio.ocularsolution.com https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ http://fonts.cdnfonts.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.flixcar.com widget.ocularsolution.com *.flixfacts.com *.flix360.com *.flix360.io *.syndigo.com *.syndigo.cloud https://emersya.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://gmgdocumentos.blob.core.windows.net/ https://gmgecommerceprd.blob.core.windows.net/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.grupomonge.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://adobedtm.com assets.adobedtm.com *.adobe.com fast.amc.demdex.net *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni wss://tm.filter:1502/ api.ocularsolution.com xml.ssreviewsportal.com *.cloudflare.com https://bam.nr-data.net *.pingdom.net *.woorank.com *.cnetcontent.com *.youtube.com *.syndigo.com *.syndigo.cloud product-feature-service.production.alquimio.cloud api.repositorio.production.alquimio.cloud orchestrator.production.aks.alquimio.cloud *.teads.tv https://ocular-prod.api.rocio.ai *.ocularsolution.com *.flixcar.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://sandbox.migopayments.com/ https://web.migopayments.com/ https://analytics.tiktok.com *.firaonlive.com https://smetrics.verdugotienda.com *.assets.adobedtm.com *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com analytics.google.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com analytics.google.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://live.decidir.com *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com https://developers.decidir.com/ *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com https://live.decidir.com https://developers.decidir.com/ *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; form-action 'self'; img-src 'self' https://www.google-analytics.com data: blob:; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com; frame-src 'self' https://www.google.com; worker-src 'self' blob:; media-src 'self'; upgrade-insecure-requests 5 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://clients2.google.com/gr/gr_full_2.0.6.js https://clients2.google.com/gr/gr_sync.js https://payments.google.com/payments/v4/js/integrator.js https://payments.sandbox.google.com/payments/v4/js/integrator.js https://ssl.gstatic.com/external_hosted/lottie/lottie.js https://translate.google.com/translate_a/element.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.google.com/js/bg/ https://www.gstatic.com/_/boq-play/_/js/k=boq-play.PlayStoreUi.en_US.c2thWgKadWg.2021.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/ https://payments.youtube.com/payments/v4/js/integrator.js https://payments.cloud.google/payments/v4/js/integrator.js;report-uri /_/PlayStoreUi/cspreport/fine-allowlist 5 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com geowidget.easypack24.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com accounts.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.doubleclick.net vars.hotjar.com m.goadservices.com apis.google.com www.google.com *.cookiebot.com ams.creativecdn.com ct.pinterest.com googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com data.imoje.pl https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com static.payu.com trustmate.io www.google.pl csr.onet.pl bbnaut.ibillboard.com rm.em.nscontext.eu mc.yandex.ru rtb-csync.smartadserver.com *.tile.openstreetmap.org geowidget.easypack24.net maps.gstatic.com maps.googleapis.com *.doubleclick.net kodano.pl ade.googlesyndication.com bat.bing.com qon-csts3.quartic.com.pl c.seznam.cz payment.ecommerce.sebgroup.com imgsct.cookiebot.com *.facebook.net pixel.wp.pl *.pinimg.com *.pinterest.com *.bing.com simage2.pubmatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com paywall.imoje.pl sandbox.paywall.imoje.pl accounts.google.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.payu.com secure.snd.payu.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com trustmate.io *.hotjar.com mc.yandex.ru *.goadservices.com geowidget.easypack24.net maps.googleapis.com *.pushpushgo.com apis.google.com js-agent.newrelic.com *.cookiebot.com bat.bing.com *.tiktok.com *.smartsuppcdn.com www.smartsuppchat.com *.crazyegg.com bam.eu01.nr-data.net static.cloudflareinsights.com *.quarticon.it *.quarticon.com *.quartic.com.pl *.ar-labs.io tags.creativecdn.com c.imedia.cz c.seznam.cz *.pinimg.com *.facebook.net pixel.wp.pl *.pinterest.com nominatim.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://accounts.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.fontawesome.com accounts.google.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com trustmate.io geowidget.easypack24.net *.quartic.com.pl widget-v3.smartsuppcdn.com www.googletagmanager.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com accounts.google.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com trustmate.io mc.yandex.ru *.doubleclick.net *.analytics.google.com api-shipx-pl.easypack24.net pagead2.googlesyndication.com maps.googleapis.com *.cookiebot.com *.tiktok.com *.smartsupp.com *.smartsuppcdn.com *.smartsuppchat.com *.crazyegg.com bam.eu01.nr-data.net *.quarticon.it *.ar-labs.io www.google.com ams.creativecdn.com *.pinimg.com *.facebook.net pixel.wp.pl *.pinterest.com *.bing.com nominatim.openstreetmap.org region1.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://szkla0com.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 5 script-src 'none'; form-action 'none'; frame-src 'none'; report-uri https://csp.withgoogle.com/csp/scaffolding/ntdsgswbsc:55:0 5 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data: blob:; font-src https: data:; report-uri /csp-report 5 default-src 'self' data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; child-src 'self' blob: ; connect-src 'self' data: blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; frame-src 'self' blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ android-webview-video-poster: https://player.vimeo.com https://*.ccm.knowbe4.com https://*.internal.knowbe4.com https://*.ccm.internal.knowbe4.com ; font-src 'self' data: fonts.gstatic.com helpimg.s3.amazonaws.com use.fontawesome.com use.typekit.net https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ ; img-src * 'self' blob: cid: data: file: android-webview-video-poster: https://cdn.mxpnl.com/ https://v2assets.zopim.io/ https://static.zdassets.com/ app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6167502888239104.storage.googleapis.com ; media-src 'self' about: blob: data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; object-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ https://unpkg.com/vue@2.6.14 pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net https://cdn.pendo.io/agent/static/365392a9-6608-44ef-443b-572eef771b95/pendo.js ; style-src 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.gstatic.com https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; style-src-elem 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.googleapis.com fonts.gstatic.com helpimg.s3.amazonaws.com cdnjs.cloudflare.com/ajax/libs/font-awesome/ cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ p.typekit.net pendo-static-6167502888239104.storage.googleapis.com s3.amazonaws.com/helpimg/ use.fontawesome.com use.typekit.net www.java.com/ga/css/print.css www.java.com/ga/css/screen.css ; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf27996eb9977f34aa9f3376bd3939adc&dd-evp-origin=content-security-policy&ddsource=csp-report&app=kmsat&env=production-us-east-1 ; worker-src 'self' blob: data: ; 5 script-src 'self' https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com; report-uri /csp-report; 5 default-src 'self' data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; child-src 'self' blob: ; connect-src 'self' data: blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; frame-src 'self' blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ android-webview-video-poster: https://player.vimeo.com https://*.ccm.knowbe4.com https://*.internal.knowbe4.com https://*.ccm.internal.knowbe4.com ; font-src 'self' data: fonts.gstatic.com helpimg.s3.amazonaws.com use.fontawesome.com use.typekit.net https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ ; img-src * 'self' blob: cid: data: file: android-webview-video-poster: https://cdn.mxpnl.com/ https://v2assets.zopim.io/ https://static.zdassets.com/ app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6167502888239104.storage.googleapis.com ; media-src 'self' about: blob: data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; object-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ https://unpkg.com/vue@2.6.14 pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net https://cdn.pendo.io/agent/static/365392a9-6608-44ef-443b-572eef771b95/pendo.js ; style-src 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.gstatic.com https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; style-src-elem 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.googleapis.com fonts.gstatic.com helpimg.s3.amazonaws.com cdnjs.cloudflare.com/ajax/libs/font-awesome/ cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ p.typekit.net pendo-static-6167502888239104.storage.googleapis.com s3.amazonaws.com/helpimg/ use.fontawesome.com use.typekit.net www.java.com/ga/css/print.css www.java.com/ga/css/screen.css ; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf27996eb9977f34aa9f3376bd3939adc&dd-evp-origin=content-security-policy&ddsource=csp-report&app=kmsat&env=production-eu-west-1 ; worker-src 'self' blob: data: ; 5 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.googleapis.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com sandbox.przelewy24.pl secure.przelewy24.pl facebook.com 'self' 'unsafe-inline'; frame-ancestors pay.google.com www.facebook.com *.kinderkraft.fr *.kinderkraft.pl kinderkraft.fr kinderkraft.pl *.trustpilot.com *.criteo.gum *.cookiebot.com kinderkraft.co.uk ecommscript-integrationapp.trustpilot.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentcdn.cookiebot.com consentcdn.cookiebot.eu pay.google.com apm.przelewy24.pl *.klarna.com secure.payu.com merch-prod.snd.payu.com *.trustpilot.com *.facebook.com *.instagram.com *.hotjar.com *.criteo.com *.criteo.net *.kinderkraft.fr kinderkraft.fr kinderkraft.pl *.pinterest.com td.doubleclick.net hal9000.redintelligence.net kinderkraft.co.uk ecommscript-integrationapp.trustpilot.com widget.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com imgsct.cookiebot.com imgsct.cookiebot.eu *.googleapis.com *.ggpht static.przelewy24.pl www.gstatic.com gstatic.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com static.payu.com *.ytimg.com www.google.pl kinderkraft.com pixel.wp.pl *.instagram.com *.payu.com *.hotjar.com *.criteo.com *.adobedtm.com *.doubleclick.net *.outbrain.com *.rubiconproject.com *.yahoo.com *.3lift.com *.smartadserver.com *.adnxs.com *.tapad.com *.casalemedia.com *.360yield.com *.taboola.com *.pubmatic.com *.media.net *.teads.tv *.adform.net *.bidswitch.net *.sharethrough.com *.smaato.net *.socdm.com *.adscale.de *.advertising.com *.dable.io *.co.kr *.stickyadstv.com *.twiago.com *.omnitagjs.com *.liadm.com *.yieldmo.com *.postrelease.com *.addthis.com *.revcontent.com *.mail.ru *.yieldlab.net *.rambler.ru *.bing.com *.openx.net *.nate.com *.mediawallahscript.com id5-sync.com *.rlcdn.com *.adingo.jp *.tremorhub.com *.yandex.ru *.aralego.com/ *.ad-stir.com *.adtdp.com *.meba.kr *.1rx.io *.toast.com *.turn.com *.dmxleo.com *.mediavine.com *.ivitrack.com *.smartclip.net *.krxd.net *.emxdgt.com *.pinterest.com *.bluekai.com *.thebrighttag.com kinderkraft.pl *.user.com *.trustpilot.com *.trustpilot.net *.metaffiliation.com region1.analytics.google.com developers.google.com trk.datnova.com *.facebook.net server-side-tagging-vqegoo7bda-uc.a.run.app bcw.kinderkraft.fr widget.trustpilot.com images-static.trustpilot.com adservice.google.com ade.googlesyndication.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consent.cookiebot.com consent.cookiebot.eu https://browser.sentry-cdn.com *.googleapis.com *.gstatic.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.snrbox.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io secure.payu.com secure.snd.payu.com consentcdn.cookiebot.com *.trustpilot.com *.googletagmanager.com kinderkraft-staging.user.com *.user.com *.g.doubleclick.net *.adyen.com *.facebook.net pixel.wp.pl *.hotjar.com *.criteo.com *.criteo.net *.cloudflare.com *.clickcease.com *.pinimg.com *.googleoptimize.com *.kinderkraft.pl *.kinderkraft.fr *.kinderkraft.de *.kinderkraft.it *.kinderkraft.co.uk *.kinderkraft.es *.metaffiliation.com *.bing.com *.clarity.ms *.cux.io *.taboola.com *.luigisbox.com ct.pinterest.com kng.kinderkraft.at sha.kinderkraft.be tag.facemyads.co bbd-tag.de s.retargeted.co apptracker.stream *.sddan.com trk.datnova.com js.cookieless-data.com bcw.kinderkraft.fr ecommscript-integrationapp.trustpilot.com cdn.cookiehub.eu widget.trustpilot.com invitejs.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com cdn.chatsimple.ai us-assets.i.posthog.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com *.snrcdn.net *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com *.typekit.net *.trustpilot.com *.instagram.com *.cloudflare.com cdn.luigisbox.com widget.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com cdn.cookiehub.eu 'self' 'unsafe-inline'; object-src ecommscript-integrationapp.trustpilot.com 'self' 'unsafe-inline'; media-src *.adobe.com *.googlevideo.com cdn.chatsimple.ai 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentcdn.cookiebot.com consentcdn.cookiebot.eu https://*.ingest.sentry.io sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com *.snrbox.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com ws: *.instagram.com kinderkraft-staging.user.com wss://kinderkraft-staging.user.com *.adyen.com yt2html5.com *.user.com googleads.g.doubleclick.net stats.g.doubleclick.net wss://kinderkraft.user.com *.hotjar.com wss://ws3.hotjar.com https://paypal.com paypal.com *.hotjar.io *.criteo.com wss://ws29.hotjar.com *.pinterest.com wss://ws11.hotjar.com google.pl *.kinderkraft.fr *.metaffiliation.com sentry.io *.clarity.ms *.cux.io *.facebook.com facebook.com *.google.pl wss://* *.openfpcdn.io *.google-analytics.com *.taboola.com *.luigisbox.com *.bing.com server-side-tagging-vqegoo7bda-uc.a.run.app wdg.kinderkraft.pl *.googleapis.com tvw.kinderkraft.co.uk analytics.tiktok.com *.kinderkraft.at *.kinderkraft.be bcw.kinderkraft.fr ecommscript-integrationapp.trustpilot.com widget.trustpilot.com api.trustpilot.com ambcglobal.sc.omtrdc.net region1.analytics.google.com cdn.cookiehub.eu api.expertise.ai pagead2.googlesyndication.com us.i.posthog.com api.ipify.org 'self' 'unsafe-inline'; child-src *.instagram.com http: https: blob: 'self' 'unsafe-inline'; default-src *.adyen.com *.instagram.com *.googleoptimize.com *.bing.com kinderkraft.co.uk kinderkraft.pl ecommscript-integrationapp.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://payments.google.com/payments/v4/js/integrator.js https://payments.sandbox.google.com/payments/v4/js/integrator.js https://translate.google.com/translate_a/element.js https://www.google-analytics.com/analytics.js https://www.google-analytics.com/gtm/js https://www.googleadservices.com/pagead/conversion/ https://www.youtube.com/iframe_api https://youtube.googleapis.com/s/player/ https://youtube.googleapis.com/iframe_api https://ssl.gstatic.com/support/realtime/operator/ https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.google.com/js/bg/ https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://maps.googleapis.com/maps/api/js https://www.gstatic.com/_/mss/boq-gstore/_/js/k=boq-gstore.Gstore.en_US.VRozIuTgjxk.2021.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://maps.googleapis.com/maps-api-v3/api/js/ https://maps.googleapis.com/maps/vt https://maps.googleapis.com/maps/api/js/ https://maps.googleapis.com/maps/api/place/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/ https://payments.youtube.com/payments/v4/js/integrator.js https://payments.cloud.google/payments/v4/js/integrator.js;report-uri /_/Gstore/cspreport/fine-allowlist 4 default-src 'self' https://pref.docusign.com https://apps.docusign.com https://events.docusign.com https://momentum.docusign.com https://dsucustomers.docusign.com https://account.docusign.com https://account-d.docusign.com https://ecom.docusign.com https://support.docusign.com https://developers.docusign.com https://community.docusign.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://sierra.chat:443 https://sierra.chat https://*.cloudfront.net https://cdn.jsdelivr.net https://cdn.prod.website-files.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn4.mxpnl.com https://s.yimg.com https://tags.srv.stackadapt.com:443 https://cdn.yellowmessenger.com https://docusign-api.arkoselabs.com https://trk.techtarget.com https://cdn.optimizely.com https://www.googletagmanager.com https://players.brightcove.net https://cdn3.optimizely.com https://cdn.cookielaw.org https://vjs.zencdn.net https://cdn.sift.com https://tags.srv.stackadapt.com https://js.driftt.com https://connect.facebook.net https://snap.licdn.com https://bat.bing.com https://tag.demandbase.com https://www.knotch-cdn.com https://js.adsrvr.org https://rs.fullstory.com https://edge.fullstory.com https://googleads.g.doubleclick.net https://protect.docusign.net https://protect-d.docusign.net https://app.gatedcontent.com https://img.en25.com https://track.docusign.com https://www.google.com https://www.gstatic.com https://browser.sentry-cdn.com https://app.guideflow.com https://zn0oqzbba3l7g5ph4-docusign.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://80e3c780877f.cdn4.forter.com https://sadmin.brightcove.com https://platform.twitter.com https://bam.nr-data.net https://static.ads-twitter.com https://www.redditstatic.com https://chat.docusign.net https://sdk.inbenta.io https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://cdn.taboola.com https://trc.taboola.com https://www.influ2.com https://t.influ2.com/ https://hermes.docusign.com; style-src 'self' 'unsafe-inline' https://sierra.chat:443 https://sierra.chat https://cdn.prod.website-files.com https://cdn.yellowmessenger.com https://tags.srv.stackadapt.com https://app.gatedcontent.com https://www.gstatic.com https://app.guideflow.com https://sdk.inbenta.io; img-src 'self' data: blob: https://assets-global.website-files.com https://*.cloudfront.net https://sp.analytics.yahoo.com https://ecom.docusign.com https://cdn.prod.website-files.com https://connect.facebook.net https://r4-ym-uploads.s3-us-west-2.amazonaws.com https://r4.app.yellow.ai https://cdn.yellowmessenger.com https://www.google.com.ar https://www.google.co.kr https://www.google.co.nz https://www.google.com.hk https://www.google.com.pe https://translate.google.com https://www.google.co.id https://www.google.co.cr https://www.google.com.my https://www.google.cl https://www.googleadservices.com https://www.google.de https://www.google.it https://www.google.co.jp https://www.google.co.za https://www.google.es https://www.google.com.sg https://www.google.com.co https://www.google.co.uk https://www.google.co.in https://www.google.nl https://www.google.com.ph https://www.google.com.au https://www.google.ca https://www.google.com.br https://www.google.com https://www.google.com.mx https://www.google.fr https://secure.adnxs.com https://attr.ml-api.io https://images.ctfassets.net https://cdn.bfldr.com https://metrics.brightcove.com https://cf-images.us-east-1.prod.boltdns.net https://hexagon-analytics.com https://s.ml-attr.com https://cdn.cookielaw.org https://id.rlcdn.com https://px.ads.linkedin.com https://frontdoor.knotch.it https://dsum-sec.casalemedia.com https://partners.tremorhub.com https://pixel.rubiconproject.com https://www.facebook.com https://segments.company-target.com https://www.linkedin.com https://www.google.com https://px4.ads.linkedin.com https://bat.bing.com https://track.docusign.com https://www.gstatic.com https://storage.googleapis.com https://imagedelivery.net https://app.gatedcontent.com https://images.esign.docusign.com https://www.googletagmanager.com https://t.co https://analytics.twitter.com https://alb.reddit.com https://googleads.g.doubleclick.net https://img-taboola.com https://t.influ2.com; font-src 'self' data: https://sierra.chat:443 https://sierra.chat https://cdn.prod.website-files.com https://images.simplycodes.com https://stylesheets.pixiebrix.com https://cdn.jsdelivr.net https://cdn.yellowmessenger.com https://fonts.gstatic.com https://docucdn-a.akamaihd.net https://cdn.inbenta.io https://use.typekit.net https://api-cdn.usw2.pure.cloud https://api-cdn.usw2.pure.cloud; connect-src 'self' https://api.iterable.com https://sierra.chat:443 https://sierra.chat https://api-js.mixpanel.com https://cdn.prod.website-files.com https://s.yimg.com https://cdn4.forter.com https://a9b3895076a445bdaf9a9aada0ab7287-80e3c780877f.cdn.forter.com https://31ff10b411e04c66a144663da6b34da5-80e3c780877f.cdn.forter.com https://3dcb810e88774d429c6dba71bbee8c34-80e3c780877f.cdn.forter.com https://tag.demandbase.com https://cdn.yellowmessenger.com https://autocomplete.demandbase.com https://segments.company-target.com https://ibc-flow.techtarget.com https://ingesteer.services-prod.nsvcs.net https://www.googletagmanager.com https://www.google.com.co https://www.google.com.mx https://www.google.co.uk https://www.google.es https://www.google.com.br https://www.google.com.sg https://www.google.com.in https://www.google.com.ph https://www.google.ca https://www.google.com.au https://rum.optimizely.com wss://r4.cloud.yellow.ai https://cdn8.forter.com https://12e748c623734740a09ab181abb7a3a1-80e3c780877f.cdn.forter.com https://cdn3.forter.com https://r4.cloud.yellow.ai https://siteperformancetest.net https://wtp.siteperformancetest.net https://privacyportal.onetrust.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://telemetry-s.docusign.net https://telemetry.dev.docusign.net https://www.facebook.com https://www.google-analytics.com https://manifest.prod.boltdns.net https://frontdoor.knotch.it https://bat.bing.com https://bat.bing.net https://ingest.insights.ninetailed.co https://cdn.jsdelivr.net https://assets.ctfassets.net https://edge.api.brightcove.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://cdn.cookielaw.org https://telemetry.docusign.net https://geolocation.onetrust.com https://www.google.com https://experience.ninetailed.co https://edge.fullstory.com https://tags.srv.stackadapt.com https://api.company-target.com https://configs.knotch.com https://px.ads.linkedin.com https://rs.fullstory.com https://tag-logger.demandbase.com https://carddealer.knotch.com https://analytics.google.com https://insight.adsrvr.org https://logx.optimizely.com https://app.gatedcontent.com https://protect.docusign.net https://protect-d.docusign.net https://s566810826.t.eloqua.com https://insights.gatedcontent.com https://siteintercept.qualtrics.com https://cdn0.forter.com https://a.docusign.com https://datacollector.docusign.com https://datacollector-demo.docusign.com https://docusign-api.arkoselabs.com https://account.docusign.com https://account-d.docusign.com https://geo.docusign.com https://syndication.twitter.com https://pixel-config.reddit.com https://www.redditstatic.com https://www.googleadservices.com https://api.inbenta.io https://api-gcu1.inbenta.io https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://psb.taboola.com https://pips.taboola.com https://cds.taboola.com https://trc-events.taboola.com https://t.influ2.com https://www.influ2.com; frame-src 'self' https://www.youtube.com https://players.brightcove.net https://js.driftt.com https://www.googletagmanager.com https://s.company-target.com https://insight.adsrvr.org https://match.adsrvr.org https://pixel.rubiconproject.com https://cm.g.doubleclick.net https://ib.adnxs.com https://td.doubleclick.net https://www.google.com https://app.guideflow.com https://platform.twitter.com https://chat.docusign.net https://a275532918.cdn.optimizely.com https://app.netlify.com https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://hermes.docusign.com; media-src 'self' blob: https://manifest.prod.boltdns.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://videos.ctfassets.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com:443 https://manifest.prod.boltdns.net; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://trial.docusign.com https://ecomservices.docusign.com https://na.account.docusign.com https://app.gatedcontent.com https://datacollector.docusign.com https://datacollector-demo.docusign.com https://docusign-api.arkoselabs.com https://account.docusign.com https://account-d.docusign.com https://protect.docusign.net https://protect-d.docusign.net https://track.docusign.com; object-src 'self' https://players.brightcove.net; upgrade-insecure-requests; report-to csp-endpoint 4 default-src https://www.oreilly.com/UXbZEE/cjMXV/bKzvI/7ujy/z57cLcp8G2StLmE3/MwUVAg/fjhBBi/MTOxk * 'unsafe-inline' 'unsafe-eval' data: blob: android-webview-video-poster: moz-extension: ms-browser-extension: chrome-extension: ios-log:; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubb898c25826db9d251f99fdcece943792&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service:wordpress-prod-cluster; 4 default-src * 'unsafe-eval' 'unsafe-inline' 'unsafe-dynamic' data: filesystem: about: blob: ws: wss: report-uri https://o1151714.ingest.us.sentry.io/api/4509640700461056/security/?sentry_key=74a33d973a69190986eba8f4bca540d2; report-to csp-endpoint; 4 default-src none; script-src 'unsafe-inline' 'unsafe-eval' *.alicdn.com *.aliyun.com ynuf.alipay.com; style-src 'unsafe-inline' *.alicdn.com *.aliyun.com; img-src data: blob: *.alicdn.com *.aliyuncs.com *.aliyun.com *.mmstat.com; connect-src *.aliyun.com wss://*.aliyun.com *.aliyuncs.com *.alicdn.com *.mmstat.com gw.alipayobjects.com ynuf.aliapp.org bdc.alibabachengdun.com ynuf.alipay.com; font-src data: *.alicdn.com *.aliyun.com; frame-src *.aliyun.com *.alicdn.com *.alibabacloud.com; media-src data: blob: *.alicdn.com *.aliyun.com *.taobao.com; report-uri //www.aliyun.com/api/log/csp-report 4 object-src 'none'; connect-src 'self' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.cpggpc.ca https://www.google-analytics.com https://siteintercept.qualtrics.com https://www.facebook.com https://sslstats.canadapost.ca https://*.wistia.com https://dpm.demdex.net https://csi.gstatic.com https://adservice.google.com https://*.googlesyndication.com https://*.g.doubleclick.net https://maps.googleapis.com https://vmss.boldchat.com https://www.linkedin.com https://canadapost.tt.omtrdc.net https://services.postcodeanywhere.co.uk https://embedwistia-a.akamaihd.net https://cdn.cookielaw.org https://geolocation.onetrust.com https://px.ads.linkedin.com https://google.com https://www.google.com; font-src 'self' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://fonts.gstatic.com https://*.arcgis.com; form-action 'self' https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.canadapost.ca https://*.epost.ca https://www.facebook.com https://google.com; frame-ancestors 'self' https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.canadapost.ca; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.epost.ca https://*.cpggpc.ca https://www.adobetag.com https://assets.adobedtm.com https://siteintercept.qualtrics.com https://zn0xleir6swszany9-canadapostdigital.siteintercept.qualtrics.com https://connect.facebook.net https://snap.licdn.com https://z.moatads.com https://static.ads-twitter.com https://www.googletagmanager.com https://www.google.com https://www.googletagservices.com https://*.google-analytics.com https://*.googleadservices.com https://www.gstatic.com https://*.googlesyndication.com https://adservice.google.com https://adservice.google.ca https://maps.googleapis.com https://cdn.ampproject.org https://*.doubleclick.net https://*.twitter.com https://cdn.syndication.twimg.com https://dpm.demdex.net https://*.wistia.com https://*.frontlinesvc.com https://*.arcgis.com https://www.linkedin.com https://vmss.boldchat.com https://sb.scorecardresearch.com https://www.rnengage.com https://sjs.bizographics.com https://www.instagram.com https://secure.adnxs.com https://app.five9.com https://cdn.cookielaw.org; style-src 'self' 'unsafe-inline' https://*.frontlinesvc.com https://fonts.googleapis.com https://translate.googleapis.com https://*.twitter.com https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.epost.ca https://*.arcgis.com https://*.arcgisonline.com https://app.five9.com; report-uri https://www.canadapost-postescanada.ca/cwc/components/rs/csp-reports; 4 block-all-mixed-content; report-uri https://dmgm.report-uri.com/r/t/csp/reportOnly 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.bglobale.com *.global-e.com *.fontawesome.com fonts.googleapis.com https://cdnjs.cloudflare.com 'self' data: *.onestock-retail.io *.cdnfonts.com *.isge49.com *.bocage.fr *.googleusercontent.com s3-eu-west-1.amazonaws.com *.sensefuel.live *.perplexity.ai *.kameleoon.com *.iadvize.com globale-prod.s3-eu-west-1.amazonaws.com ncspublicasset.s3.eu-west-3.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.bglobale.com *.global-e.com *.google.com/ *.onestock-retail.com/ payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.bing.com *.pinterest.com *.criteo.com *.criteo.net *.vimeo.com *.goodays.co *.effiliation.com *.doubleclick.net *.facebook.com *.bocage.eu *.googletagmanager.com *.snapchat.com vimeo.com *.cookiebot.com *.iadvize.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.bglobale.com *.global-e.com *.googleapis.com https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: www.google.gl www.google.com.pe www.google.jo www.google.it *.facebook.net www.google.hu *.google.com www.google.com.pr www.google.is www.google.bi *.batch.com *.criteo.com www.google.mn *.smartadserver.com www.google.com.ec www.google.com.kh www.google.com.vn www.google.com.cy www.google.ge www.google.ro www.google.co.ve www.google.com.bn www.google.com.cu *.kameleoon.eu www.google.com.ni *.adnxs.com *.contentsquare.net www.google.je *.pinterest.com www.google.so www.google.com.sl *.bocage.fr www.google.tn www.google.co.in www.google.ad www.google.at www.google.cm www.google.ae www.google.be www.google.ee www.google.lt www.google.co.ug www.google.tg www.google.lv *.doubleclick.net *.sensefuel.live www.google.dj www.google.ci *.onestock-retail.io *.affilae.com www.google.com.ua www.google.com.my www.google.com.om www.google.nl www.google.ws www.google.com.tr www.google.se www.google.co.ao *.taboola.com www.google.sn www.google.cl www.google.sc www.google.co.nz www.google.com.bz www.google.co.uk *.googleadservices.com www.google.co.ck www.google.mk www.google.st www.google.bf www.google.co.kr www.google.co.bw www.google.com.bh www.google.com.co *.facebook.com www.google.by *.mellowyellow.eu www.google.es www.google.lu www.google.co.ma www.google.dm www.google.co.ls joko-mobile-app-media.s3.eu-west-1.amazonaws.com *.twiago.com *.kameleoon.com www.google.tt www.google.no *.ebuyclub.com www.google.ml www.google.la www.google.com.br www.google.com.mt www.google.mv www.google.co.mz www.google.bg www.google.com.pk *.googletagmanager.com www.google.ie www.google.com.pa www.google.com.kw www.google.com.mx www.google.mu www.google.co.jp www.google.com.do www.google.sk www.google.si www.google.bj www.google.dz www.google.com.ar www.google.fr *.adform.net *.googleusercontent.com www.google.com.uy www.google.com.mm *.googlesyndication.com *.tiktok.com www.google.co.za www.google.gm *.iadvize.com www.google.kz *.criteo.net www.google.az www.google.com.ly www.google.com.gi www.google.gg www.google.com.pg www.google.com.np www.google.co.il www.google.co.zm *.eram.eu www.google.li www.google.am www.google.me www.google.co.th www.google.ps www.google.com.hk *.advalo.com www.google.cv *.bing.net www.google.cd *.teads.tv www.google.ru *.mellowyellow.com www.google.com.eg www.google.com.gt www.google.com.jm us-central1-shopmyinfluens.cloudfunctions.net www.google.com.af *.mmtro.com www.google.gr *.ggpht.com www.google.vu www.google.al *.lgw.io www.google.mw www.google.pl www.google.pt www.google.com.py www.google.iq www.google.ca www.google.sr www.google.de www.google.co.zw www.google.com.ph www.google.ga mmtro.com www.google.com.gh *.bing.com www.google.com.sv *.google-analytics.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.com.bd www.google.tm www.google.cf *.isge49.com *.bocage.eu www.google.co.id www.google.com.qa www.google.lk www.google.hr *.vimeo.com www.google.com.et www.google.ch www.google.md www.google.im www.google.td www.google.com.bo www.google.ba www.google.rw www.google.com.lb www.google.dk www.google.mg www.google.hn www.google.ne d1oco4z2z1fhwp.cloudfront.net www.google.kg www.google.cn mellowyellow.com www.google.com.tw www.google.com.sg d3e54v103j8qbb.cloudfront.net www.google.rs www.google.co.ke google.com www.google.com.fj *.outbrain.com www.google.co.cr www.google.gy www.google.fi www.google.co.tz www.google.com.sa *.eram.fr www.google.co.uz s3-eu-west-1.amazonaws.com www.google.com.ng *.xiti.com *.snapchat.com *.openx.net www.google.com.na *.cookiebot.com www.google.cg www.google.ht www.google.com.au www.google.bs www.google.cz data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com cdn.jsdelivr.net *.bglobale.com *.global-e.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com https://maps.googleapis.com *.hsforms.net *.hsforms.com *.gstatic.com *.addthis.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.snapchat.com *.iadvize.com critizr.com *.kameleoon.eu *.taboola.com *.sensefuel.com *.googleapis.com *.adform.net *.googlesyndication.com *.hotjar.com *.tiktok.com *.batch.com *.lgw.io *.sensefuel.live *.eram.fr dqfw2hlp4tfww.cloudfront.net *.facebook.net *.onestock-retail.io *.doubleclick.net *.bing.com *.cookiebot.com *.mmtro.com *.googleadservices.com *.kameleoon.com *.aticdn.net *.contentsquare.net *.jquery.com *.kameleoon.io *.affilae.com *.criteo.com *.criteo.net sc-static.net d3e54v103j8qbb.cloudfront.net *.pinimg.com *.pinterest.com *.vimeo.com *.googletagmanager.com translate.google.com.hk *.goodays.co mmtro.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.bglobale.com *.global-e.com *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.iadvize.com *.typekit.net *.onestock-retail.io *.kameleoon.com *.sensefuel.live *.googletagmanager.com semji.github.io *.sensefuel.com *.goodays.co 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.fbcdn.net *.bing.com *.mellowyellow.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com maps.googleapis.com https://nominatim.openstreetmap.org https://maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.kameleoon.eu *.merchant-center-analytics.goog *.hotjar.io *.typekit.net *.pinterest.com *.kameleoon.com *.sensefuel.live *.jquery.com www.google.fr www.google.ca *.taboola.com www.google.cn *.cookiebot.com *.iadvize.com *.teads.tv *.contentsquare.net *.hotjar.com *.googleapis.com *.gstatic.com *.batch.com *.criteo.com *.sensefuel.biz *.openx.net *.doubleclick.net *.onestock-retail.io www.google.it *.facebook.com *.aticdn.net *.tiktok.com www.google.co.id *.instagram.com www.google.ge *.bing.net *.snapchat.com *.adnxs.com *.advalo.com *.affilae.com *.goodays.co www.google.es www.google.be *.googlesyndication.com www.google.ch *.googleadservices.com *.facebook.net *.bing.com *.eram.fr *.kameleoon.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ab48b69d-84be-485e-b94f-4ed50b3a5780.sansec.watch/; report-to report-endpoint; 4 font-src www.paypalobjects.com 'self' smartphonehoesjes.nl handyhuellen.de ploonk.fr *.smartphonehoesjes.nl *.ploonk.fr *.brandcommerce.nl *.mopinion.com fonts.gstatic.com *.cm.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://www.paypal.com https://www.sandbox.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.de *.smartphonehoesjes.nl *.ploonk.fr *.coquedetelephone.fr *.handyhuellen.de *.brandcommerce.nl *.doubleclick.net *.facebook.com *.tradedoubler.com *.sovendus-connect.com *.colorlab.io *.printlane.com metrics.smartphonehoesjes.nl metrics.handyhuellen.de metrics.ploonk.fr js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://portal.payconiq.com https://static.buckaroo.nl https://www.buckaroo.nl https://www.paypalobjects.com cdn.acc-smartphonehoesjes.nl cdn.acc-brandcommerce.nl cdn.acc-ploonk.fr cdn.acc-handyhuellen.de cdn.smartphonehoesjes.nl cdn.brandcommerce.nl cdn.ploonk.fr cdn.handyhuellen.de *.smartphonehoesjes.nl *.etrusted.com *.google.com *.google.nl *.googlesyndication.com *.facebook.com squeezely.tech *.squeezely.tech *.bing.com *.bing.net *.pointspay.com *.trustedshops.com *.roeyecdn.com *.roeye.com *.doubleclick.net *.zenaps.com *.awin1.com *.facebook.net *.cm.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.buckaroo.nl https://www.paypal.com https://www.sandbox.paypal.com https://applepay.cdn-apple.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.localhost *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.nl smartphonehoesjes.nl *.smartphonehoesjes.nl *.ploonk.fr *.handyhuellen.de *.brandcommerce.nl *.analytics.google.com *.googlesyndication.com www.clarity.ms *.google.com *.google.nl *.facebook.net *.tiktok.com *.doubleclick.net *.bing.com *.etrusted.com *.elitechnology.com *.beslist.nl squeezely.tech *.squeezely.tech *.trustedshops.com *.mopinion.com *.dwin1.com *.aiden.cx *.kickbite.io *.colorlab.io *.printlane.com *.hotjar.com *.sovendus.com *.wurflcloud.com fonts.gstatic.com *.cloudfront.net *.roeyecdn.com *.disqus.com *.avada.io *.shopify.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.localhost *.googleapis.com *.etrusted.com *.mopinion.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://www.sandbox.paypal.com smartphonehoesjes.nl *.smartphonehoesjes.nl *.handyhuellen.de *.ploonk.fr *.brandcommerce.nl wss://*.azurewebsites.net *.wurflcloud.com *.clarity.ms https://get.geojs.io *.amazon.com *.etrusted.com *.demdex.net *.sc.omtrdc.net *.cardinalcommerce.com *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.nl google.com *.google.com google.nl *.google.nl *.googlesyndication.com *.tiktok.com *.hotjar.com *.doubleclick.net *.aiden.cx *.sovendus.com *.trustedshops.com *.youtube.com *.plyr.io noembed.com *.amazonaws.com *.mopinion.com *.beslist.nl *.kickbite.io *.bing.com *.bing.net *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 default-src * data: mediastream: blob: filesystem: about: ws: wss: 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline' 4 default-src 'self' *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; style-src 'self' 'unsafe-inline' wasm-eval: fonts.googleapis.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; script-src-elem 'self' 'unsafe-inline' blob: *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; font-src 'self' data: fonts.gstatic.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; connect-src 'self' data: maps.googleapis.com cdnml.global-cache.online *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; frame-src 'self' data: *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; frame-ancestors 'none'; img-src 'self' data: *.ytimg.com img.youtube.com maps.gstatic.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net; 4 default-src 'self' fonts.gstatic.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;script-src 'self' 'unsafe-inline' *.trustpilot.com *.googletagmanager.com mc.yandex.ru *.google-analytics.com *.youtube.com mc.yandex.com mc.yandex.ru *.google.com *.gstatic.com *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com;img-src * data:;font-src 'self' fonts.gstatic.com;connect-src 'self' *.customer.io *.gist.build *.youtube.com mc.yandex.ru *.clariti.ws *.analytics.google.com *.google-analytics.com doubleclick.net *.googletagmanager.com mc.yandex.com mc.yandex.ru mc.yandex.md yandexmetrica.com *.mightytips.com https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com https://analytics.google.com;frame-src 'self' *.trustpilot.com *.youtube.com *.instagram.com *.twitter.com *.yandex.com *.google.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;script-src-elem 'self' 'unsafe-inline' *.trustpilot.com *.customer.io *.gist.build *.instagram.com *.googletagmanager.com *.yandex.ru *.google-analytics.com *.twitter.com *.youtube.com mc.yandex.com *.google.com *.gstatic.com mc.yandex.ru *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com track.trackingtraffo.com https://www.hcaptcha.com/1/api.js;frame-ancestors 'self';report-uri /cspreport.php 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://apretailer.com.br 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.us1.gigya.com *.openpay.mx *.openpay.co *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.opencontrol.mx *.kaptcha.com *.openpay.pe *.paynet.com.mx *.pagaleve.io *.pagaleve.com.br www.google-analytics.com unpkg.com googleads.g.doubleclick.net commerce.adobedtm.com magento-recs-sdk.adobe.net www.googleadservices.com www.gstatic.com *.google.com.br *.criteo.com *.doubleclick.net *.cloudfront.net *.nr-data.net *.enviou.com.br *.newrelic.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.us1.gigya.com 'self' data: 'unsafe-inline' data: *.postimg.cc magefan.com cm.magefan.com *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.openpay.mx *.pagaleve.com.br unpkg.com commerce.adobedtm.com magento-recs-sdk.adobe.net www.gstatic.com *.google.com *.google.com.br *.panini.canto.global https://panini.canto.global *.cloudfront.net *.doubleclick.net *.g.doubleclick.net *.ivitrack.com *.bidswitch.net *.criteo.com *.nr-data.net *.enviou.com.br *.newrelic.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://www.gravatar.com *.googleusercontent.com https://apretailer.com.br https://cdn.aplazo.mx *.adobedtm.com *.clarity.ms https://smartbmc.com.br https://ib.adnxs.com https://r.casalemedia.com https://ads.stickyadstv.com https://ad.360yield.com https://i.liadm.com https://contextual.media.net https://exchange.mediavine.com *.bing.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://trends.revcontent.com https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://ade.clmbtech.com https://eb2.3lift.com https://sync.1rx.io https://gum.criteo.com https://public-prod-dspcookiematching.dmxleo.com https://www.mercadopago.cl *.agkn.com *.targeting.unrulymedia.com *.dnzdns.com *.adgrx.com *.bidr.io *.yahoo.com *.emkt.dinamize.com *.dinamize.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.us1.gigya.com *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.s3.amazonaws.com *.openpay.co *.openpay.pe *.google-analytics.com *.google.com/recaptcha/ *.gstatic.com/recaptcha/ *.pagaleve.com.br analytics.tiktok.com *.clarity.ms unpkg.com www.gstatic.com *.google.com.br *.vendavalida.com.br *.zdassets.com *.criteo.com *.enviou.com.br *.cloudfront.net aprtn.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br *.metricool.com *.hotjar.com *.bing.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app downloads.mailchimp.com 'unsafe-inline' data: *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://apretailer.com.br assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.openpay.mx *.openpay.co *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.openpay.pe unpkg.com googleads.g.doubleclick.net commerce.adobedtm.com magento-recs-sdk.adobe.net www.gstatic.com *.google.com.br *.criteo.com *.vendavalida.com.br *.zendesk.com *.doubleclick.net *.us1.gigya.com *.cloudfront.net *.enviou.com.br http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br *.paniniadrenalyn.com pagead2.googlesyndication.com analytics.tiktok.com *.clarity.ms *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net googleads.g.doubleclick.net csm.us5.us.criteo.net commerce.adobedc.net https://apretailer.com.br *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 base-uri 'self' 'unsafe-inline'; report-uri https://8a41912f-2069-471c-8cfc-be803d04015d.sansec.watch/; report-to report-endpoint; 4 default-src 'self' 'unsafe-inline' 'unsafe-eval'; font-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-src 'self' https://cdn.cohesionapps.com/ https://www.googletagmanager.com/; connect-src 'self' https://cdn.cookielaw.org/ https://www.google-analytics.com/ https://yg3l958nut-dsn.algolia.net https://www.google.com/ https://geolocation.onetrust.com/ https://bam.nr-data.net https://content.cmn.com https://api.mobius.highereducation.com https://www.googletagmanager.com/ https://cdn.cohesionapps.com/ https://www.edx.org/; img-src 'self' https://res.cloudinary.com https://navi.cohesionapps.com https://cms.psychology.org/ https://simple-storage-server.highereducation.com/ https://content.cmn.com data:; script-src-elem 'self' 'unsafe-inline' https://content.cmn.com/ https://js-agent.newrelic.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://sb.scorecardresearch.com https://www.edx.org/beam.js 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.multisafepay.com https://pay.google.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com flagpedia.net *.multisafepay.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net app.youshouldask.ai interface.mailcampaigns.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com maps.googleapis.com *.multisafepay.com https://pay.google.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com ka-p.fontawesome.com app.youshouldask.ai static.cloudflareinsights.com interface.mailcampaigns.nl static.usizy.es app.aiden.cx 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu app.youshouldask.ai 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com www.gstatic.com maps.googleapis.com *.multisafepay.com *.cloudflare.com *.twitter.com *.twimg.com ka-p.fontawesome.com app.youshouldask.ai usizy.com app.aiden.cx 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' data: 'unsafe-inline' data: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 4 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com fonts.gstatic.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.googletagmanager.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.vimeocdn.com s.ytimg.com bam.eu01.nr-data.net 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com www.youtube.com maps.googleapis.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.googleapis.com *.google.com *.gstatic.com *.avada.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js-agent.newrelic.com bam.eu01.nr-data.net connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://*.ingest.sentry.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io bam.eu01.nr-data.net region1.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.net data: *.acsbapp.com *.bootstrapcdn.com *.cloudfare.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * api.bazaarvoice.com stg.api.bazaarvoice.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.pinterest.com *.hotjar.com www.google.com *.facebook.com *.facebook.net www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.facebook.com *.b0e8.com *.dynamicyield.com *.pinterest.com *.e.aa.online-metrix.net *.acsbapp.com *.cookielaw.org *.bing.com *.yahoo.com *.google.co.in google.co.in *.listrakbi.com all-clad.com *.all-clad.com emjcd.com *.emjcd.com *.dotomi.com *.espssl.com *.clarity.ms *.tagcommander.com *.adsrvr.org *.rubiconproject.com *.g.doubleclick.net magefan.com cm.magefan.com *.facebook.net *.disqus.com https://img.youtube.com www.xtento.com cdn.xtento.com 'self' data: https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.ugc.bazaarvoice.com *.listrakbi.com *.facebook.net *.b0e8.com *.bc0a.com *.cookielaw.org *.dynamicyield.com *.tagcommander.com *.cloudflare.com *.yimg.com *.pinimg.com *.hotjar.com www.google.com *.mczbf.com analytics.tiktok.com *.acsbapp.com acsbapp.com *.salesforceliveagent.com *.force.com *.curalate.com *.noibu.com *.pinterest.com *.online-metrix.net *.googleapis.com *.bing.com *.vimeo.com *.amazonaws.com *.clarity.ms click2cart.com *.adsrvr.org *.aggregated-data.com *.cloudfront.net *.amazon-adsystem.com *.tkrconnector.com acds-events.adobe.io static.kyc.red shop.pe *.shop.pe addstrap-ui.addshoppers.com returns.parcellab.com cdn.parcellab.com gstatic.com *.gstatic.com *.facebook.com *.disqus.com www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.cash.app display.ugc.bazaarvoice.com *.listrakbi.com *.ugc.bazaarvoice.com *.typekit.net *.force.com *.bootstrapcdn.com *.espssl.com *.cloudfront.net *.cloudfare.com *.addshoppers.com *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com * api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.dynamicyield.com *.cookielaw.org *.g.doubleclick.net *.listrak.com *.listrakbi.com analytics.tiktok.com *.pinterest.com *.hotjar.com *.yimg.com google.co.in *.mczbf.com *.bc0a.com *.googleapis.com facebook.com *.acsbapp.com *.click2cart.com *.clarity.ms *.aggregated-data.com *.curalate.com *.noibu.com wss://input.noibu.com *.onetrust.com *.bing.com insight.adsrvr.org *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.adsrvr.org shop.pe *.shop.pe *.facebook.com *.facebook.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com account.groupeseb.com *.salesforceliveagent.com *.salesforce.com *.force.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src * data:;img-src * data:;frame-src 'self' *.sevenrooms.com *.doubleclick.net *.smartrecruiters.com *.adyen.com *.pinterest.com *.googleadservices.com *.google.com *.googletagmanager.com *.cardinalcommerce.com sevenrooms.com *.americanexpress.com *.securesuite.co.uk secure7.arcot.com *.rsa3dsauth.co.uk mycardsecure.com www.mycardsecure.com dupe.com *.opentable.com.au;script-src 'self' *.curator.io *.google-analytics.com *.googletagmanager.com *.google.com *.licdn.com *.clarity.ms *.gstatic.com *.facebook.net *.pinimg.com *.smartrecruiters.com *.hotjar.com cdn-cookieyes.com 'unsafe-eval' 'unsafe-inline' data:;script-src-elem 'self' 'unsafe-inline' *.facebook.net *.licdn.com *.google.com *.googletagmanager.com https://www.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.smartrecruiters.com *.curator.io *.clarity.ms *.pinimg.com *.hotjar.com cdn-cookieyes.com;style-src-elem 'self' *.honey.io *.google.com *.curator.io *.smartrecruiters.com *.facebook.net *.clarity.ms 'unsafe-inline';connect-src 'self' *.facebook.com *.google.com *.google-analytics.com *.googleapis.com melprdwebsite.azurewebsites.net crownkentico-prd-as-csearch.search.windows.net *.pinterest.com *.doubleclick.net *.curator.io *.clarity.ms *.linkedin.com *.datatoolscloud.net.au *.hotjar.io *.googleadservices.com *.googletagmanager.com *.adyen.com *.cookieyes.com cdn-cookieyes.com ws://localhost:12387 wss://ws.hotjar.com https://www.google.com/ data:;report-uri /api/logs/csp-report;report-to csp-endpoint; 4 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cse.google.com https://js.hsforms.net https://platform-api.sharethis.com https://rebilly.github.io https://unpkg.com https://use.fontawesome.com https://ws.sharethis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; style-src 'self' https://cloud.typography.com https://use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 4 default-src 'self' fonts.gstatic.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;script-src 'self' 'unsafe-inline' *.googletagmanager.com mc.yandex.ru *.google-analytics.com *.youtube.com mc.yandex.com mc.yandex.ru *.google.com *.gstatic.com *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com;img-src * data:;font-src 'self' fonts.gstatic.com;connect-src 'self' *.customer.io *.youtube.com mc.yandex.ru *.clariti.ws *.analytics.google.com *.google-analytics.com doubleclick.net *.googletagmanager.com mc.yandex.com mc.yandex.ru mc.yandex.md yandexmetrica.com *.mightytips.com https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com https://analytics.google.com;frame-src 'self' *.youtube.com *.instagram.com *.twitter.com *.yandex.com *.google.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;script-src-elem 'self' 'unsafe-inline' *.instagram.com *.googletagmanager.com *.yandex.ru *.google-analytics.com *.twitter.com *.youtube.com mc.yandex.com *.google.com *.gstatic.com mc.yandex.ru *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com track.trackingtraffo.com https://www.hcaptcha.com/1/api.js;frame-ancestors 'self';report-uri /cspreport.php 4 default-src 'self' wss: *.gravatar.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.publicstuff.com *.googletagmanager.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com connect.facebook.net static.addtoany.com https://widgets.nrel.gov *.openstreetmap.org cdn-images.mailchimp.com platform.twitter.com blob:; object-src 'self' 'unsafe-inline' 'unsafe-eval' translate.googleapis.com iframe.publicstuff.com; style-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com *.ctctcdn.com cdn-images.mailchimp.com data:; img-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com www.facebook.com https://widgets.nrel.gov www.facebook.com *.openstreetmap.org cdn-images.mailchimp.com i.ytimg.com data:; media-src 'self' translate.googleapis.com iframe.publicstuff.com data:; frame-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; frame-ancestors 'self' *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com; child-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; font-src 'self' 'unsafe-inline' 'unsafe-eval' *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com user.govoutreach.com syndication.twitter.com data:; connect-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com stats.g.doubleclick.net; report-uri /report-csp-violation 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com platform.twitter.com *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://resources.paytrail.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net maps.googleapis.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io connect.facebook.net twitter.com platform.twitter.com cdn.jsdelivr.net *.gstatic.com maps.googleapis.com applepay.cdn-apple.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.fontawesome.com https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.gstatic.com applepay.cdn-apple.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com typesense.c-833.maxcluster.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * https://cdn.consentmanager.net https://delivery.consentmanager.net *.trustpilot.com *.weltpixel.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://redchamps.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com maps.googleapis.com *.amazonaws.com typesense.c-833.maxcluster.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.googletagmanager.com tagmanager.google.com *.trustpilot.com https://widgets.trustedshops.com https://integrations.etrusted.com maps.googleapis.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.fontawesome.com tagmanager.google.com fonts.google.com *.trustpilot.com https://widgets.trustedshops.com https://integrations.etrusted.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://maps.googleapis.com https://player.vimeo.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.googletagmanager.com *.trustedshops.com *.etrusted.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://667b8714-1464-4a69-9685-942a89db4a14.sansec.watch/; report-to report-endpoint; 4 default-src blob: https:; img-src data: https:; script-src 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'unsafe-inline' https:; font-src data: https:; frame-src https:; media-src data: https:; object-src 'none'; connect-src https:; frame-ancestors 'self'; 4 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.hollywoodreporter.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 3 script-src 'self' cdn.robinhood.com cdn.pdst.fm/ping.min.js www.google-analytics.com www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ tagmanager.google.com ssl.google-analytics.com connect.facebook.net sc-static.net d.impactradius-event.com www.redditstatic.com analytics.tiktok.com boards.greenhouse.io bat.bing.com www.googleadservices.com static.ads-twitter.com s.yimg.com *.usercentrics.eu snap.licdn.com collector-47804.us.tvsquared.com/tv2track.js public.flourish.studio/resources/embed.js csi.gstatic.com cdn.parsely.com *.doubleclick.net *.googlesyndication.com *.googletagservices.com platform.twitter.com/ platform.instagram.com/ www.instagram.com/embed.js www.threads.net/embed.js www.tiktok.com/embed.js lf16-tiktok-web.tiktokcdn-us.com/ www.facebook.com/ www.youtube.com/ ak.sail-horizon.com *.celtra.com *.heapanalytics.com heapanalytics.com cdn.us.heap-api.com *.doubleverify.com *.infogram.com cdn.concert.io *.adtrafficquality.google hymnal-prod.vox-cdn.com www.documentcloud.org/notes/loader.js truthsocial.com/embed.js embed.reddit.com/widgets.js embed.bsky.app/static/embed.js *.permutive.app 'unsafe-eval'; report-uri https://o62437.ingest.us.sentry.io/api/4509232895361024/security/?sentry_key=98a8908d38fbd5ecdf8e976a1cb6b404 3 default-src 'unsafe-inline' 'unsafe-eval' * data: blob: 3 default-src 'self'; report-uri https://csp.loopia.se; connect-src 'self' https://*.analytics.google.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://accesswidget-log-receiver.acsbapp.com https://adservice.google.com https://analytics.google.com https://api-eu1.hubapi.com https://api.exponea.com https://api.infinario.com https://bat.bing.com https://cdn.iubenda.com https://chat.puzzel.com https://consentcdn.cookiebot.com https://content.hotjar.io https://cta-eu1.hubspot.com https://eu-cdn.acsbapp.com https://eu.acsbapp.com https://idb.iubenda.com https://in.hotjar.com https://pagead2.googlesyndication.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://srv.motu-teamblue.services https://stats.g.doubleclick.net https://vc.hotjar.io https://www.facebook.com https://www.google.com https://www.googleadservices.com https://www.google.se; font-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com https://fonts.gstatic.com; form-action 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://bib.eway2pay.com https://payment.architrade.com https://ticket.siriusit.net https://www.facebook.com; frame-src 'self' https://*.facebook.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://5.ec1.vbus.apps.ladesk.com https://active24.ladesk.com https://consentcdn.cookiebot.com https://vars.hotjar.com https://www.google.com https://www.googletagmanager.com; img-src 'self' data: https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://bat.bing.com https://chat.puzzel.com https://googleads.g.doubleclick.net https://imgsct.cookiebot.com https://perf-eu1.hsforms.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://region1.analytics.google.com https://region1.google-analytics.com https://srv.motu-teamblue.services https://stats.g.doubleclick.net https://tbs.tradedoubler.com https://track-eu1.hubspot.com https://www.facebook.com https://www.google.com https://www.google.se https://www.googletagmanager.com https://www.gstatic.com; media-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://api.exponea.com https://api.infinario.com https://chat.puzzel.com https://g.microsoft.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://www.google.com https://www.google.se https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' https://script.hotjar.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://active24.ladesk.com https://api.exponea.com https://bat.bing.com https://cdn.iubenda.com https://chat.puzzel.com https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cs.iubenda.com https://eu.acsbapp.com https://googleads.g.doubleclick.net https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.com https://js-eu1.hs-scripts.com https://js-eu1.hsadspixel.net https://js-eu1.hubspot.com https://pagead2.googlesyndication.com https://snap.licdn.com https://srv.isy-teamblue.services https://srv.motu-teamblue.services https://static.hotjar.com https://widget.trustpilot.com https://www.google.com https://www.google.se https://www.googletagmanager.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://cdn.iubenda.com https://chat.puzzel.com https://fonts.googleapis.com 3 default-src https: data: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; report-uri /csp-violation-report-endpoint.php; report-to csp-endpoint 3 default-src 'self' *.pinduoduo.com *.pddpic.com *.yangkeduo.com *.pddugc.com *.pinduoduo.net *.v.smtcdns.net *.ourdvsss.com wss://*.pinduoduo.com wss://*.yangkeduo.com mapstyle.qpic.cn blob: data: 'unsafe-eval' 'unsafe-inline'; report-uri https://tc.pinduoduo.com/x.gif 3 script-src 'self' addtocalendar.com cdn.amcharts.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://stage-unifiedsearch.geapps.io https://unifiedsearch.geapps.io; script-src-attr 'self'; style-src 'self' addtocalendar.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://stage-unifiedsearch.geapps.io https://unifiedsearch.geapps.io maxcdn.bootstrapcdn.com; style-src-attr 'self'; frame-ancestors 'self' 3 default-src 'self' https: data: blob: gap: https://*.maersk.com; report-to reporting-endpoint; report-uri https://sescspreportcollector-prod.westeurope.prod.maersk.io/collect-data; 3 frame-ancestors 'self' https://www.rferl.org/embed https://www.rferl.org/embed/player https://www.rferl.org/embed/player/0 https://www.rferl.org/embed/player/1 https://www.rferl.org/ext https://www.rferl.org/widget; report-uri https://csp.pangeadigital.io/cspreport 3 frame-ancestors 'self'; object-src 'none'; report-uri /api/csp-reporting 3 font-src *.googleapis.com *.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: *.solodeportes.com.ar use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube-nocookie.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.retargetly.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.clarity.ms *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.powerreviews.com bat.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.newrelic.com *.powerreviews.com *.clarity.ms *.retargetly.com *.embluemail.com *.tiktokw.us *.tiktok.com *.ads-twitter.com bat.bing.com cdn.evgnet.com cdn.jsdelivr.net *.evergage.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com use.fontawesome.com *.powerreviews.com *.evergage.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.nr-data.net *.powerreviews.com *.google.com *.doubleclick.net *.tiktokw.us *.tiktok.com *.clarity.ms *.evergage.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://www.googletagmanager.com https://cdn.jsdelivr.net https://tag.aticdn.net https://www.youtube.com https://www.instagram.com https://platform.linkedin.com https://platform.twitter.com https://connect.facebook.net https://bsky.app https://js-datadome.groupe-sncf.com https://sdk.privacy-center.org https://*.ubiplace.com https://*.aws.vsct.fr https://*.cdn.vsct.fr https://*.smartvigie.fr; worker-src 'self' blob:; report-uri /api/csp-report-only; 3 default-src 'self' *.insight.com *.drift.com *.driftcdn.com *.launchdarkly.com www.googletagmanager.com play.vidyard.com *.aimtell.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.insight.com *.adroll.com *.atgsvcs.com *.custhelp.com *.webcollage.net *.driftt.com *.google.com *.marketo.com *.doubleclick.com *.doubleclick.net *.qualtrics.com assets.adobedtm.com cdn.lr-in-prod.com cdn.pricespider.com munchkin.marketo.net play.vidyard.com s.go-mpulse.net up.pixel.ad use.typekit.net ws.cs.1worldsync.com www.clarity.ms www.google-analytics.com www.googletagmanager.com www.youtube.com apps.bazaarvoice.com static.ads-twitter.com cdn-ukwest.onetrust.com cdn01.basis.net cdns.eu1.gigya.com code.jquery.com content.syndigo.com js.adsrvr.org *.cnetcontentsolutions.com mpsnare.iesnare.com unpkg.com www.googleadservices.com bat.bing.com cdn.cs.1worldsync.com cdn.tt.omtrdc.net connect.facebook.net i.simpli.fi lex.33across.com px.ads.linkedin.com s3.amazonaws.com snap.licdn.com *.hotjar.com t.sellpoints.com tracking.intentsify.io view.ceros.com w.usabilla.com ws.zoominfo.com xiecomm.paymetric.com blob:; style-src 'self' 'unsafe-inline' *.insight.com *.drift.com *.marketo.com code.jquery.com cdn.cs.1worldsync.com fonts.googleapis.com cdn.tt.omtrdc.net; img-src * data:; font-src 'self' data: *.insight.com fonts.gstatic.com use.typekit.net cdn.cs.1worldsync.com insightenterprises.qualtrics.com s.nsit.com svcs.tql.com at.alicdn.com; connect-src 'self' *.akamaihd.net *.clarity.ms *.gigya.com *.google.com *.google-analytics.com *.googlesyndication.com *.insight.com *.launchdarkly.com *.mktoresp.com *.akstat.io *.go-mpulse.net *.onetrust.com insightenterprises.tt.omtrdc.net stats.g.doubleclick.net www.google-analytics.com 366-uky-221.mktoutil.com adservice.google.com bat.bing.com cdn.aimtell.io cdn.linkedin.oribi.io cert-xiecomm.paymetric.com content.syndigo.com dpm.demdex.net et-qalogin.insight.com integration.richrelevance.com r.lr-in-prod.com rules.atgsvcs.com signals.aimtell.com sjrtp2.marketo.com smetrics.insight.com *.bazaarvoice.com ws.zoominfo.com *.adroll.com play.vidyard.com *.richrelevance.com www.facebook.com siteintercept.qualtrics.com *.googletagmanager.com; media-src player.vimeo.com www.youtube.com; object-src *.insight.com; frame-src 'self' *.adsrvr.org pixel.sitescout.com insight.demdex.net js.driftt.com app-abm.marketo.com centinelapistag.cardinalcommerce.com cert-xiecomm.paymetric.com html5-player.libsyn.com insightent.wufoo.com *.insight.com play.vidyard.com view.ceros.com www.youtube.com *.marketo.com *.doubleclick.net *.everestjs.net cbsi.demdex.net www.facebook.com beacon.aimtell.com; report-uri https://insight.report-uri.com/r/t/csp/wizard 3 default-src data: blob: about: 'self' 'unsafe-inline' 'unsafe-eval' https: wss:; report-uri /csp/report?always; 3 default-src 'self';script-src 'self' https://cdn-cookieyes.com https://www.googletagmanager.com https://www.influ2.com https://www.youtube.com https://js.hubspot.com https://js.hsforms.net https://script.hotjar.com https://www.google.com https://sc.lfeeder.com https://snap.licdn.com https://static.hotjar.com https://cdn.heapanalytics.com https://connect.facebook.net https://js.hsadspixel.net https://js.hscollectedforms.net https://www.gstatic.com https://js.hs-banner.com https://static.doubleclick.net https://googleads.g.doubleclick.net https://www.googleadservices.com https://js.hs-analytics.net https://js.hs-scripts.com https://static.hsappstatic.net https://js.storylane.io 'unsafe-inline' 'unsafe-eval';connect-src 'self' https://www.googleadservices.com https://js.hs-banner.com https://*.hotjar.com https://*.hubspot.com https://cdn.heapanalytics.com https://connect.facebook.net https://sc.lfeeder.com https://www.influ2.com https://snap.licdn.com https://t.influ2.com https://forms.hsforms.com https://log.cookieyes.com https://cdn-cookieyes.com https://www.google.com https://directory.cookieyes.com https://px.ads.linkedin.com https://api.hubapi.com https://forms.hscollectedforms.net https://region1.analytics.google.com https://surveystats.hotjar.io wss://ws.hotjar.com https://content.hotjar.io https://metrics.hotjar.io https://heapanalytics.com https://www.google.pl https://google.com https://region1.google-analytics.com https://ipapi.co https://stats.g.doubleclick.net https://dxp-au-search.funnelback.squiz.cloud https://www.facebook.com;frame-src 'self' https://www.youtube.com https://*.doubleclick.net https://www.google.com https://www.googletagmanager.com https://js.hubspot.com https://www.facebook.com https://forms.hsforms.com https://meetings.hubspot.com https://squiz.storylane.io;img-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:;font-src 'self' https:;object-src 'self' https://www.youtube.com;frame-ancestors 'self' 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://view.ceros.com https://www.googletagmanager.com https://code.jquery.com https://cdn.jsdelivr.net https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://munchkin.marketo.net https://js.driftt.com https://*.driftt.com https://players.brightcove.net https://*.brightcove.com https://*.brightcove.net https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://*.boltdns.net https://snap.licdn.com https://*.licdn.com https://px.ads.linkedin.com https://bat.bing.com https://*.bing.com https://static.oktopost.com https://*.oktopost.com https://tracking.g2crowd.com https://*.g2crowd.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://edge.api.brightcove.com https://cms.api.brightcove.com https://playback.api.brightcove.com https://analytics.api.brightcove.com https://sadmin.brightcove.com https://gallery.api.brightcove.com https://social.api.brightcove.com https://gallery-metrics.api.brightcove.com https://*.brightcovecdn.com https://manifest.prod.boltdns.net https://app.ezlynx.com https://*.ezlynx.com https://tracking-api.g2.com https://*.g2.com https://d1igp3oop3iho5.cloudfront.net https://connect.facebook.net https://js.zi-scripts.com https://*.zi-scripts.com https://ws-assets.zoominfo.com https://*.zoominfo.com https://www.google-analytics.com https://use.typekit.net https://p.typekit.net https://okt.to https://static.cloudflareinsights.com https://*.facebook.com https://*.fbcdn.net https://ajax.googleapis.com https://*.googleapis.com https://assets.ceros.com https://*.ceros.com https://cdn.rollbar.com https://cdn.intake-lr.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://www.googleadservices.com https://*.googleadservices.com https://web-sdk.smartlook.com https://www.clickcease.com https://insight.appliedsystems.com https://templates.marketo.net https://creative-services.ceros.com https://s.adroll.com https://reg.eventmobi.com https://www.gstatic.com https://dyv6f9ner1ir9.cloudfront.net https://cdnjs.cloudflare.com https://*.marchex.io https://rw1.marchex.io https://www.appliednet.com https://az416426.vo.msecnd.net https://js.monitor.azure.com https://scdn.snapapp.com https://dyv6f9ner1ir9.cloudfront.net https://platform.twitter.com https://scripts.poll-maker.com https://cdn.cookielaw.org https://resources.ezlynx.com https://web-sdk-eu.aptrinsic.com https://cdn.siteimprove.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: https://view.ceros.com https://www.googletagmanager.com https://code.jquery.com https://cdn.jsdelivr.net https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://munchkin.marketo.net https://js.driftt.com https://*.driftt.com https://players.brightcove.net https://*.brightcove.com https://*.brightcove.net https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://js.driftt.com https://*.driftt.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://*.boltdns.net https://snap.licdn.com https://*.licdn.com https://px.ads.linkedin.com https://bat.bing.com https://*.bing.com https://static.oktopost.com https://*.oktopost.com https://tracking.g2crowd.com https://*.g2crowd.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://edge.api.brightcove.com https://cms.api.brightcove.com https://playback.api.brightcove.com https://analytics.api.brightcove.com https://sadmin.brightcove.com https://gallery.api.brightcove.com https://social.api.brightcove.com https://gallery-metrics.api.brightcove.com https://*.brightcovecdn.com https://manifest.prod.boltdns.net https://app.ezlynx.com https://*.ezlynx.com https://tracking-api.g2.com https://*.g2.com https://d1igp3oop3iho5.cloudfront.net https://connect.facebook.net https://js.zi-scripts.com https://*.zi-scripts.com https://ws-assets.zoominfo.com https://*.zoominfo.com https://www.google-analytics.com https://use.typekit.net https://p.typekit.net https://okt.to https://static.cloudflareinsights.com https://*.facebook.com https://*.fbcdn.net https://ajax.googleapis.com https://*.googleapis.com https://assets.ceros.com https://*.ceros.com https://cdn.rollbar.com https://cdn.intake-lr.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://www.googleadservices.com https://*.googleadservices.com https://web-sdk.smartlook.com https://www.clickcease.com https://insight.appliedsystems.com https://templates.marketo.net https://creative-services.ceros.com https://s.adroll.com https://reg.eventmobi.com https://www.gstatic.com https://dyv6f9ner1ir9.cloudfront.net https://cdnjs.cloudflare.com https://*.marchex.io https://rw1.marchex.io https://www.appliednet.com https://az416426.vo.msecnd.net https://js.monitor.azure.com https://scdn.snapapp.com https://dyv6f9ner1ir9.cloudfront.net https://platform.twitter.com https://scripts.poll-maker.com https://cdn.cookielaw.org https://resources.ezlynx.com https://web-sdk-eu.aptrinsic.com https://cdn.siteimprove.net; style-src 'self' 'unsafe-inline' https://view.ceros.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://js.driftt.com https://*.driftt.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://*.boltdns.net https://snap.licdn.com https://*.licdn.com https://static.oktopost.com https://*.oktopost.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.brightcove.com https://*.brightcove.net https://*.brightcovecdn.com https://use.typekit.net https://p.typekit.net https://assets.ceros.com https://*.ceros.com https://d2yeu2mwujl2s5.cloudfront.net https://insight.appliedsystems.com https://templates.marketo.net https://www.appliednet.com https://resources.ezlynx.com https://web-sdk-eu.aptrinsic.com; font-src 'self' data: https://view.ceros.com https://fonts.gstatic.com https://cdn.jsdelivr.net https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://form.jotform.com https://*.jotform.com https://vwo.com https://*.vwo.com https://js.driftt.com https://*.driftt.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://static.oktopost.com https://*.oktopost.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.brightcove.com https://*.brightcove.net https://*.brightcovecdn.com https://use.typekit.net https://p.typekit.net https://media-s3-us-east-1.ceros.com https://*.appliedsystems.com https://www.appliednet.com https://resources.ezlynx.com https://dhm5hy2vn8l0l.cloudfront.net; img-src 'self' data: https: https://view.ceros.com https://www.googletagmanager.com https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://players.brightcove.net https://*.brightcove.com https://*.brightcove.net https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://js.driftt.com https://*.driftt.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://*.boltdns.net https://snap.licdn.com https://*.licdn.com https://px.ads.linkedin.com https://bat.bing.com https://*.bing.com https://static.oktopost.com https://*.oktopost.com https://tracking.g2crowd.com https://*.g2crowd.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.brightcovecdn.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://okt.to https://www.appliednet.com https://resources.ezlynx.com; frame-src 'self' https://view.ceros.com https://www.googletagmanager.com https://td.doubleclick.net https://app-abk.marketo.com https://*.marketo.com https://*.ivans.com https://players.brightcove.net https://*.brightcove.com https://*.g2.com https://*.brightcove.net https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://js.driftt.com https://*.driftt.com https://cdn-cookieyes.com https://*.cookieyes.com https://static.oktopost.com https://*.oktopost.com https://js.idio.co https://*.idio.co https://*.brightcovecdn.com https://forms2.itswebs.com https://resources.ezlynx.com; connect-src 'self' https://www.googletagmanager.com https://app-abk.marketo.com https://*.marketo.com https://*.mktoutil.com https://*.ivans.com https://www.google.com https://google.com https://analytics.google.com https://dev.visualwebsiteoptimizer.com https://stats.g.doubleclick.net https://players.brightcove.net https://*.brightcove.com https://*.brightcove.net https://form.jotform.com https://*.jotform.com https://*.buzzsprout.com https://vwo.com https://*.vwo.com https://*.visualwebsiteoptimizer.com https://js.driftt.com https://*.driftt.com https://metrics.api.drift.com https://cdn-cookieyes.com https://*.cookieyes.com https://vjs.zencdn.net https://*.zencdn.net https://*.boltdns.net http://*.boltdns.net https://snap.licdn.com https://*.licdn.com https://px.ads.linkedin.com https://bat.bing.com https://*.bing.com https://static.oktopost.com https://*.oktopost.com https://tracking.g2crowd.com https://*.g2crowd.com https://js.idio.co https://*.idio.co https://cdn.bizible.com https://*.bizible.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://web-sdk.smartlook.com https://*.smartlook.com https://*.smartlook.cloud https://manager.eu.smartlook.cloud https://edge.api.brightcove.com https://cms.api.brightcove.com https://playbook.api.brightcove.com https://analytics.api.brightcove.com https://sadmin.brightcove.com https://gallery.api.brightcove.com https://social.api.brightcove.com https://gallery-metrics.api.brightcove.com https://*.brightcovecdn.com https://manifest.prod.boltdns.net https://app.ezlynx.com https://*.ezlynx.com https://tracking-api.g2.com https://*.g2.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://okt.to https://www.facebook.com https://*.facebook.com https://js.zi-scripts.com https://*.zi-scripts.com https://ws-assets.zoominfo.com https://*.zoominfo.com https://373-dbf-030.mktoresp.com https://api.ceros.com https://media.ceros.com https://d1igp3oop3iho5.cloudfront.net https://*.marchex.io https://rw1.marchex.io https://www.appliednet.com https://www.google.ca https://*.google.ca https://resources.ezlynx.com https://esp-eu.aptrinsic.com https://my2.siteimprove.com; media-src 'self' https://*.brightcove.com https://*.brightcove.net https://*.boltdns.net http://*.boltdns.net https://*.brightcovecdn.com https://media.ceros.com https://media-s3-us-east-1.ceros.com blob: data:; worker-src 'self' blob:; object-src 'none'; upgrade-insecure-requests; frame-ancestors 'self' https://*.ezlynx.com/ https://*.appliedsystems.com/ https://*.ivans.com/ https://*.agentinsure.com/ https://*.uatezlynx.com/ https://*.vtpezlynx.com/ https://*.devezlynx.com/ https://appliedsystems--devprob.sandbox.my.site.com/ https://appliedsystems--devproa.sandbox.my.site.com/ https://appliedsystems--uat.sandbox.my.site.com/ https://appliedsystems--uat.sandbox.my.site.com/AppliedClientCommunity/s/ https://community.appliedsystems.com/; report-uri https://your-csp-report-endpoint.com/csp-violations; 3 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn-ukwest.onetrust.com/scripttemplates/ https://websdk.appsflyer.com/ https://www.google.com/recaptcha/enterprise.js https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://cdn.segment.com https://static.moonpay.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://www.moonpay.com https://api.moonpay.com https://api.coingecko.com https://cdn-ukwest.onetrust.com https://*.launchdarkly.com https://geolocation.onetrust.com https://vitals.vercel-insights.com https://*.google-analytics.com https://*.analytics.google.com https://logs.browser-intake-datadoghq.com https://cdn.segment.com https://otel-collector.moonpay.com https://otel-collector.moonpaycloud.com https://otel-collector.moonpay-staging.com; font-src 'self' https://static.moonpay.com; frame-src 'self' https://buy.moonpay.com https://sell.moonpay.com https://www.google.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; img-src 'self' https://cdn-ukwest.onetrust.com https://images.ctfassets.net https://payload-marketing.moonpay.com https://staging.moonpay-marketing-c337344.payloadcms.app https://static.moonpay.com; manifest-src 'self'; media-src 'self' https://payload-marketing.moonpay.com https://staging.moonpay-marketing-c337344.payloadcms.app; worker-src 'self'; frame-ancestors 'none'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4f9819648cf6c369f00daa5b3a3a0ea7&dd-evp-origin=content-security-policy&ddsource=csp-report 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.lytics.io *.customer.io www.googletagmanager.com www.googleoptimize.com maps.googleapis.com www.gstatic.com *.hotjar.com *.onetrust.com edge.marker.io *.swaven.com *.static-swaven.com *.mikmak.ai cdn.segment.com www.google.com *.clarity.ms js.adsrvr.org cdn.jsdelivr.net upload-widget.cloudinary.com lf16-tiktok-web.tiktokcdn-us.com www.tiktok.com connect.facebook.net *.ttwstatic.com destinilocators.com; worker-src 'self' blob:; connect-src 'self' *.mikmak.ai *.swaven.com *.ninetailed.co analytics.google.com *.clarity.ms; frame-src 'self' *.mikmak.ai *.swaven.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.fonts.net; font-src 'self' *.mikmak.ai *.swaven.com *.static-swaven.com; img-src 'self' data: *.mikmak.ai *.swaven.com *.static-swaven.com; report-uri https://o4504005838045184.ingest.sentry.io/api/4506390025338880/security/?sentry_key=ddd8b10a7a189adef47fadd8e0757eaa 3 block-all-mixed-content; report-uri https://events.ocdn.eu/v2/csp-report?_ac=events&_fv=www.onet.pl::CPROD_4_6_0 3 default-src 'none'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; form-action 'self' https://accounts-*.cyberriskalliance.com https://188-UNZ-660.mktorest.com; script-src 'self' https://lytics.cyberriskalliance.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.clarity.ms https://s.dpmsrv.com https://cdn.feathr.co https://*.g.doubleclick.net https://www.googletagservices.com https://www.googleadservices.com https://munchkin.marketo.net https://pages.cyberriskalliance.com https://connect.facebook.net https://snap.licdn.com https://player.vimeo.com https://platform.twitter.com https://cra.hum.works https://*.ml314.com https://ml314.com https://ib.adnxs.com https://js.zi-scripts.com https://a.usbrowserspeed.com https://renderer.visuel.ly; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://files.cyberriskalliance.com https://image-optimizer*.cyberriskalliance.com https://www.cyberriskalliance.com https://securepubads.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://api*.cyberriskalliance.com https://cms*.cyberriskalliance.com https://image-optimizer*.cyberriskalliance.com https://userapi*.cyberriskalliance.com https://*.hum.works https://7acfab725e3b6315db795ca16eb9966e.clients.hosted-elasticpress.io https://accounts-*.cyberriskalliance.com https://lytics.cyberriskalliance.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://www.google-analytics.com https://cdn.feathr.co https://s.dpmsrv.com https://munchkin.marketo.net https://pages.cyberriskalliance.com https://securepubads.g.doubleclick.net; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.google.com https://html5-player.libsyn.com https://securepubads.g.doubleclick.net https://*.googlesyndication.com; media-src 'self' https://html5-player.libsyn.com; manifest-src 'self'; worker-src 'self'; report-uri /_csp; report-to default; 3 frame-ancestors https://*.walmart.com;report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4ebf0f2c2b22f7e232e33c048c5f3d2b&dd-evp-origin=content-security-policy&env=prod&ddsource=csp-report&ddtags=service:marketing-web 3 frame-ancestors 'self'; 3 font-src www.paypalobjects.com https://cdn.riverty.design/ cash-f.squarecdn.com fonts.gstatic.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl https://widgets.trustedshops.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com uc8.tv * all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ uc8.tv https://documents.riverty.com/ * all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.doubleclick.net *.facebook.com *.facebook.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ * https://images.unsplash.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.imgix.net all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com maps.gstatic.com *.googleapis.com *.bing.com *.google.nl *.facebook.com *.facebook.net *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.bazaarvoice.com widgets.trustedshops.com 'self' data: data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.hotjar.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com *.googletagmanager.com tagmanager.google.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl *.googleapis.com *.bing.com *.facebook.com *.facebook.net https://player.vimeo.com/api/player.js cdn.belco.io *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.bazaarvoice.com widgets.trustedshops.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app tagmanager.google.com fonts.google.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ * https://maps.googleapis.com https://player.vimeo.com *.googletagmanager.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl *.googleapis.com *.google.com *.doubleclick.net *.googlesyndication.com cdn.belco.io wss://chat.belco.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.bazaarvoice.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src * data:; script-src * 'unsafe-eval'; script-src-elem * 'unsafe-inline'; script-src-attr *; style-src * 'unsafe-inline' blob:; style-src-elem * 'unsafe-inline'; style-src-attr * 'unsafe-inline'; img-src * 'self' data: blob:; font-src * 'self' data: blob:; connect-src * 'self' blob:; media-src * 'self' blob:; object-src * 'self' 'unsafe-inline' blob:; prefetch-src * 'self' blob:; child-src * 'self' blob:; frame-src * 'self' blob:; worker-src * 'self' blob:; frame-ancestors * 'self' blob:; form-action *; upgrade-insecure-requests; base-uri * 'self'; manifest-src * blob: sandbox allow-downloads allow-forms allow-modals allow-popups allow-same-origin allow-scripts allow-top-navigation allow-top-navigation-to-custom-protocols; 3 default-src https:; script-src https: 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://www.googletagmanager.com https://*.googlesyndication.com https://*.googleapis.com https://*.doubleclick.net; style-src https: 'unsafe-inline'; img-src data: https: 'unsafe-inline'; font-src data: https: 'unsafe-inline'; worker-src blob: https:; 3 base-uri 'self'; connect-src 'self' https://*.google.com https://boards-api.greenhouse.io https://images.prismic.io https://o43253.ingest.sentry.io https://pagead2.googlesyndication.com https://www.gstatic.com https://bat.bing.com https://*.clarity.ms; default-src 'self'; font-src 'self'; form-action 'none'; frame-ancestors 'none'; frame-src https://*.enterprise.ada.com https://boards.greenhouse.io https://insight.adsrvr.org https://td.doubleclick.net https://tpc.googlesyndication.com https://www.youtube-nocookie.com; img-src 'self' data: https://adahealth.cdn.prismic.io https://assets.ada.com https://connect.facebook.net https://googleads.g.doubleclick.net https://images.prismic.io https://prismic-io.s3.amazonaws.com https://www.facebook.com https://pagead2.googlesyndication.com https://adservice.google.com https://www.google.com https://www.googletagmanager.com https://bat.bing.com https://*.clarity.ms; manifest-src 'self'; media-src 'self' https://adahealth.cdn.prismic.io; script-src 'self' 'unsafe-inline' https://boards.greenhouse.io https://connect.facebook.net https://googleads.g.doubleclick.net https://js.adsrvr.org https://tpc.googlesyndication.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.youtube.com https://bat.bing.com https://www.clarity.ms; style-src 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.hubspot.com *.cookielaw.org *.cdntwrk.com *.wistia.com *.wistia.net *.q2.com *.sentry-cdn.com *.clarity.ms *.google.com *.googletagmanager.com *.googleapis.com *.googleadservices.com *.gstatic.com *.hsappstatic.com *.hsappstatic.net *.hubspot.net *.hs-banner.com *.hsadspixel.net *.hs-analytics.com *.hs-analytics.net *.licdn.com *.marketo.net *.marketo.com *.zoominfo.com *.bizible.com *.6sc.co *.qualified.com *.segment.com *.bugcrowd.com *.bugcrowdusercontent.com bugcrowd.com *.jsdeliver.net *.jsdelivr.net *.cloudflare.com *.doubleclick.net *.youtube.com *.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com 8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com *.crazyegg.com *.callrail.com; style-src 'self' *.q2.com 'report-sample' 'unsafe-inline' *.cdntwrk.com *.googleapis.com *.hsappstatic.net *.hubspot.net *.jsdeliver.net *.jsdelivr.net *.marketo.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net *.hubspotusercontent-na1.net *.pathfactory.com *.googletagmanager.com *.zuddl.com *.qualified.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.mktoresp.com *.hubspotusercontent-na1.net *.google.com *.hubspot.com *.hs-banner.com *.onetrust.com *.cookielaw.org *.wistia.com *.embed-cloudfront.wistia.com *.wistia.net *.6sc.co *.6sense.com *.qualified.com wss://*.qualified.com *.segment.com *.segment.io *.linkedin.com *.google-analytics.com *.clarity.ms *.hubapi.com *.doubleclick.com https://stats.g.doubleclick.net *.zoominfo.com *.adnxs.com *.litix.io *.marketo.com *.doubleclick.net *.youtube.com *.pathfactory.com *.zuddl.com api.prod.zuddl.com *.crazyegg.com *.gonorth.io *.callrail.com *.googleadservices.com; font-src 'self' data: *.gstatic.com *.cdntwrk.com *.wistia.com *.wistia.net 7044196.fs1.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com; frame-src 'self' *.q2.com *.qualified.com *.doubleclick.net *.wistia.net *.gstatic.com *.google.com *.googletagmanager.com *.bugcrowd.com bugcrowd.com *.hubspotvideo.com *.marketo.com *.youtube.com *.pathfactory.com *.uberflip.com *.zuddl.com *.on24.com *.qualified.com; img-src 'self' *.q2.com data: *.hubspotusercontent-na1.net *.hsappstatic.net *.6sc.co *.cdntwrk.com *.cookielaw.org *.wistia.com *.hsforms.com *.linkedin.com *.hubspot.com *.hubspot.net *.bizible.com *.cloudinary.com *.clarity.ms *.bing.com *.googletagmanager.com *.placeholder.com *.marketo.com googleads.g.doubleclick.net *.doubleclick.net *.google.com *.doubleclick.net *.youtube.com *.hubspotusercontent40.net *.pathfactory.com *.bizibly.com *.gstatic.com *.zuddl.com *.imgix.net *.wistia.net *.qualified.com; manifest-src 'self'; media-src 'self' *.q2.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net 7044196.fs1.hubspotusercontent-eu1.net 7044196.fs2.hubspotusercontent-eu1.net *.marketo.com blob: *.doubleclick.net *.youtube.com *.pathfactory.com; form-action 'self' *.marketo.com *.mktoweb.com *.zuddl.com *.callrail.com *.googleadservices.com *.qualified.com; frame-ancestors 'self' *.q2.com *.pathfactory.com *.lookbookhq.com; report-to https://343747560e392f7a31ae9a0247c09302.report-uri.com/r/d/csp/reportOnly 3 default-src 'self' https://*.cit.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.cit.com https://snap.licdn.com https://munchkin.marketo.net https://www.googletagmanager.com https://googleads.g.doubleclick.net https://static.ads-twitter.com https://s.yimg.com https://bat.bing.com https://connect.facebook.net https://static.hotjar.com https://script.hotjar.com https://utt.impactcdn.com https://cdn.cookielaw.org https://www.fdic.gov https://assets.adobedtm.com https://siteintercept.qualtrics.com https://siteimproveanalytics.com https://www.everestjs.net https://zn780vxspp4zyl7dr-citcx.siteintercept.qualtrics.com https://citgroup.demdex.net https://pixel.everesttech.net https://sp.analytics.yahoo.com https://g.3gl.net https://cg-7ce3a684-2bed-464c-8d1c-1a0e4cba69c6.s3.us-gov-west-1.amazonaws.com; connect-src 'self' https://*.cit.com https://graphql.contentful.com https://cms-images.cit.com https://cdn.cookielaw.org https://privacyportal.onetrust.com https://geolocation.onetrust.com https://dpm.demdex.net https://edge.adobedc.net https://bat.bing.com https://lib-us-2.brilliantcollector.com https://stats.g.doubleclick.net https://analytics.google.com https://www.google.com https://lasteventf-tm.everesttech.net https://s.yimg.com https://px.ads.linkedin.com https://siteintercept.qualtrics.com https://151-fhs-046.mktoresp.com https://894-itd-344.mktoresp.com https://284-lbb-572.mktoresp.com https://022-ygl-099151-fhs-046284-lbb-572.mktoresp.com; worker-src 'self'; style-src 'self' 'unsafe-inline' https://*.cit.com https://cdn.cookielaw.org; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.cookielaw.org; img-src 'self' https://*.cit.com https://cms-images.cit.com https://2884.global.siteimproveanalytics.io https://dpm.demdex.net https://cdn.cookielaw.org https://px.ads.linkedin.com https://www.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://bat.bing.com https://sp.analytics.yahoo.com https://cm.everesttech.net https://www.linkedin.com; frame-src 'self' https://*.cit.com https://www.googletagmanager.com https://fast.wistia.net https://citgroup.demdex.net; frame-ancestors 'self' https://customerfinancing.directcapital-sit.com https://customerfinancing.directcapital2.com https://www.customerfinancing.com https://customerfinancing.directcapital-test1.com https://customerfinancing.directcapital-test2.com https://customerfinancing.directcapital-test3.com https://customerfinancing.directcapital-test4.com onlineapps-conv.readiness.ibanking-services.com onlineapps.ibanking-services.com ibanking-services.com https://*.fisglobal.com https://*.citbank.com https://citcom-dev.ase1-dev.citnet.cit.com https://*.firstcitizens.com; media-src 'self'; font-src 'self'; 3 default-src 'self'; img-src 'self' https://listafirme.ro https://flagcdn.com https://mdbootstrap.com https://img.youtube.com https://*.googleusercontent.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://cdn.jsdelivr.net https://www.googletagmanager.com data:; frame-src https://listafirme.ro https://www.youtube.com https://static.addtoany.com https://www.google.com https://accounts.google.com https://*.firebaseapp.com; script-src 'self' https://listafirme.ro https://www.googletagmanager.com https://*.google-analytics.com https://listafirme.eu https://static.addtoany.com https://platform.listafirme.eu https://platform.listafirme.ro https://cdn.jsdelivr.net https://*.cloudflare.com 'unsafe-inline' https://*.google.com https://*.googleapis.com https://*.gstatic.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://listafirme.ro https://*.cloudflare.com https://*.google.com https://*.googleapis.com; font-src 'self' https://listafirme.ro https://*.cloudflare.com https://*.googleapis.com https://*.gstatic.com; connect-src 'self' https://listafirme.ro https://*.google-analytics.com https://static.addtoany.com https://www.google.com https://accounts.google.com https://*.googleapis.com https://cloudflareinsights.com; object-src 'none'; base-uri 'self'; form-action 'self'; 3 font-src data: *.gstatic.com *.tryggehandel.net tryggehandel.net *.googleapis.com googleapis.com *.adsrvr.org data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.collector.se *.cardinalcommerce.com *.jobylon.com *.doubleclick.net *.proffs.se *.walleydev.com *.walleypay.com doubleclick.net *.adsrvr.org *.dotdigital-pages.com *.dotdigital.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com googleadservices.com google-analytics.com *.magentocommerce.com *.s.ytimg.com *.googleadservices.com *.google-analytics.com *.googleapis.com googleapis.com *.gstatic.com *.collector.se *.adnxs.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.dk *.byggmax.com byggmax.se byggmax.no byggmax.fi byggmax.com byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.bing.com bing.com *.teads.tv teads.tv *.smartadserver.com smartadserver.com *.rubiconproject.com rubiconproject.com *.3lift.com 3lift.com *.smaato.net *.taboola.com taboola.com *.doubleclick.com *.360yield.com 360yield.com *.yahoo.com *.casalemedia.com casalemedia.com *.openx.net *.sharethrough.com sharethrough.com *.bidswitch.net *.pubmatic.com pubmatic.com *.omnitagjs.com omnitagjs.com *.yieldmo.com yieldmo.com *.ivitrack.com ivitrack.com *.advertising.com *.stickyadstv.com *.media.net media.net *.doubleclick.net *.e-planning.net *.clmbtech.com *.adform.net adform.net *.liadm.com *.postrelease.com postrelease.com *.smartclip.net *.krxd.net *.ad-stir.com *.outbrain.com outbrain.com *.tremorhub.com tremorhub.com *.demdex.net *.pingdom.net *.adscale.de *.twiago.com *.google.com *.google.se *.bluekai.com *.wisepops.com *.tapad.com *.mgid.com *.rambler.ru *.thebrighttag.com *.walleypay.com *.1rx.io 1rx.io id5-sync.com *.id5-sync.com *.mediavine.com mediavine.com *.yieldlab.net yieldlab.net *.emxdgt.com emxdgt.com *.unrulymedia.com unrulymedia.com *.tryggehandel.net tryggehandel.net adnxs.com cm.g.doubleclick.net bidswitch.net www.facebook.com *.quantserve.com quantserve.com *.adsrvr.org *.trackedlink.net https://cdn.flbx.io data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google-analytics.com *.collector.se *.assets.adobedtm.com *.authorize.net *.geostag.cardinalcommerce.com *.paypal.com *.vimeo.com *.ccdc02.com google.com *.braintreegateway.com *.ytimg.com *.signifyd.com *.adnxs.com adnxs.com adtr.io *.googletagmanager.com *.trackedlink.net *.jobylon.com *.doubleclick.net doubleclick.net *.googleapis.com googleapis.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.com *.byggmax.dk byggmax.se byggmax.no byggmax.fi byggmax.com byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.bing.com *.hotjar.com hotjar.com bing.com *.cloudflare.com *.wisepops.com *.facebook.net facebook.net *.quantserve.com quantserve.com *.quantcount.com *.cloudflareinsights.com *.pingdom.net pingdom.net *.getflowbox.net *.kuvio.io kuvio.io *.walleydev.com *.tryggehandel.net tryggehandel.net *.dynamicyield.com dynamicyield.com *.testfreaks.com testfreaks.com *.walleypay.com *.videoly.co dialogtrail.com *.dialogtrail.com wisepops.net *.wisepops.net *.adsrvr.org *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.trustpilot.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com googleapis.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.adsrvr.org *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.flbx.io flbx.io *.adsrvr.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.wisepops.com *.google-analytics.com google-analytics.com *.collector.se *.pingdom.net pingdom.net *.adnxs.com adnxs.com *.walleydev.com *.walleypay.com *.dynamicyield.com dynamicyield.com www.google.com google.com *.google.com *.doubleclick.net doubleclick.net *.dialogtrail.com dialogtrail.com *.ebbot.app ebbot.app *.adsrvr.org *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self';form-action 'self'; object-src 'self'; frame-ancestors 'self'; connect-src 'self' ely-keskus.fi *.youtube.com *.tyomarkkinatori.fi *.ahtp.fi keha-matomo-sdg-qa-qa.azurewebsites.net *.cookiebot.com wss://*.tyomarkkinatori.fi *.elisa.fi wss://*.elisa.fi tetyomarkkinatori.boost.ai lukija.aimater.com fonts.gstatic.com data:; style-src 'self' 'unsafe-inline' *.elisa.fi fonts.googleapis.com *.youtube.com gstatic.com blob:; img-src * data: blob:; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' *.tyomarkkinatori.fi *.ahtp.fi *.elisa.fi lukija.aimater.com tetyomarkkinatori.boost.ai *.cookiebot.com keha-matomo-sdg-qa-qa.azurewebsites.net youtube.com blob:; frame-src 'self' data: feed.mikle.com *.elisadesk.com *.cookiebot.com *.youtube.com; media-src 'self' data: blob:; font-src 'self' data: fonts.gstatic.com; report-uri https://csp-report-fa-prod.azurewebsites.net/api/csp-report; 3 frame-ancestors 'self' ; object-src 'none' ; report-uri https://cspreports.realpage.com/api/reports/save/report-only; 3 default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; 3 policy 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * self *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://www.silhouettedesignstore.com https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.instagram.com js.stripe.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://www.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cdninstagram.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com cdn.examplecdn.com s.pinimg.com in-automate.brevo.com cdn.by.wonderpush.com https://www.google.com https://cdn-int.safecharge.com https://cdn.safecharge.com https://secure.safecharge.com/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.instagram.com js.stripe.com js.klevu.com *.ksearchnet.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://cdn.webpushr.com https://cdn.brevo.com https://player.vimeo.com https://intljs.rmtag.com https://ut.rd.linksynergy.com https://js.klevu.com unpkg.com sibautomation.com cdn.by.wonderpush.com s.pinimg.com ct.pinterest.com in-automate.brevo.com https://magento.com https://cdn.safecharge.com https://cdn-int.safecharge.com https://play.google.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://cdn.brevo.com https://magneto-staging.s3.us-west-2.amazonaws.com https://maxcdn.bootstrapcdn.com https://cdn.safecharge.com https://fonts.googleapis.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klevu.com *.ksearchnet.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://bot.webpushr.com api.exampleconnect.com ct.pinterest.com in-automate.brevo.com cdn.by.wonderpush.com https://sdkmon.safecharge.com https://ppp-test.safecharge.com https://ppp-test.nuvei.com https://secure.safecharge.com https://play.google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src https: data:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; form-action 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self' 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com js.mollie.com www.xtento.com *.zuora.com *.worldpay.com theteachingcompanysalesllc.demdex.net *.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com theteachingcompany.d1.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://images.unsplash.com https://www.mollie.com www.xtento.com cdn.xtento.com *.teach12.com *.thegreatcoursesplus.com prd.jwpltx.com *.pinterest.com bat.bing.com *.amazon-adsystem.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://maps.googleapis.com *.avada.io js.mollie.com www.xtento.com cdn.xtento.com cdnjs.cloudflare.com *.fontawesome.com acsbap.com acsbapp.com *.acsbap.com *.acsbapp.com *.teach12.com *.tiqcdn.com cltgtstor001.blob.core.windows.net *.gstatic.com *.zuora.com *.worldpay.com *.jwpcdn.com analytics.tiktok.com *.bitmovin.com *.visioncritical.com bat.bing.com www.dwin1.com *.amazon-adsystem.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com display.ugc.bazaarvoice.com *.fontawesome.com cdnjs.cloudflare.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.teach12.com *.bitmovin.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io theteachingcompany.d1.sc.omtrdc.net *.fontawesome.com *.acsbap.com *.acsbapp.com *.bitmovin.com *.slgnt.us *.tgcmag.com *.thegreatcourses.com *.theplatform.com teachco-mp4.akamaized.net *.cloudfunctions.net *.pinterest.com analytics.tiktok.com *.tealiumiq.com *.amazon-adsystem.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za map.pargo.co.za 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.oppwa.com oppwa.com *.peachpayments.com worldtimeapi.org *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; img-src 'self' https: data:; script-src 'self' https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; connect-src 'self' https:; media-src 'self' https: data:; object-src 'self'; base-uri 'self'; report-to go1-csp; 3 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.authorize.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com www.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com mageside.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.kaptcha.com *.disqus.com *.authorize.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://scripts.ltv.ai 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 base-uri 'none' ; connect-src 'self' https://mc.yandex.ru/ ; default-src 'self' ; font-src 'self' data: ; frame-ancestors 'none' ; img-src 'self' data: https://top-fwz1.mail.ru/ ; report-to vkpay-csp-endpoint ; report-uri https://cspreport.mail.ru/vkpay?disposition=report ; script-src 'self' 'unsafe-inline' https://top-fwz1.mail.ru/ https://mc.yandex.ru/metrika/tag.js ; style-src 'self' 'unsafe-inline' 'unsafe-hashes' 3 font-src *.typekit.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.novaturas.lt dev-lt-novaturas.readymage.com * 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.novaturas.lt https://track.adform.net https://www.googletagmanager.com https://www.google.com https://master.d28zlv4dg2b2g7.amplifyapp.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com 'self' https://localhost https://novaturas-gwe-1661146907.readymage.com https://novaturas-gwe-1661146907.readymage-media.com https://prod-lt-novaturas.readymage.com https://www.google.com https://hatscripts.github.io https://www.google-analytics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com 'unsafe-inline' 'unsafe-eval' https://static.hotjar.com https://googleads.g.doubleclick.net https://connect.facebook.net https://www.google.com https://s2.adform.net https://track.adform.net https://cdn.mxapis.com/service-worker.js https://www.googletagmanager.com https://www.google-analytics.com https://svht.tradedoubler.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com 'unsafe-inline' 'unsafe-eval' *.typekit.net unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ 'self' https://bam.eu01.nr-data.net https://staging.nov.indvp.com https://pim.novatours.eu https://development.nov.indvp.com https://analytics.google.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://www.google-analytics.com ws: api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' https://dev-lt-novaturas.readymage.com https://stage-lt-novaturas.readymage.com https://staging.nov.indvp.com https://pim.novatours.eu https://development.nov.indvp.com https://novaturas-gwe-1661146907.readymage-media.com https://use.typekit.net https://www.googletagmanager.com https://localhost 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 base-uri 'self'; default-src 'self' https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://stats.g.doubleclick.com stats.g.doubleclick.com https://*.googleapis.com *.googleapis.com https://*.cookielaw.com *.cookielaw.com https://*.cookielaw.org *.cookielaw.org https://*.cloudapi.de *.cloudapi.de https://*.onetrust.com *.onetrust.com 'unsafe-inline' 'unsafe-eval'; child-src; connect-src 'self' https://cdn.cookielaw.org cdn.cookielaw.org https://privacyportal-eu.onetrust.com privacyportal-eu.onetrust.com https://api.userway.org api.userway.org https://pagead2.googlesyndication.com pagead2.googlesyndication.com https://*.google.com *.google.com https://cdn.userway.org cdn.userway.org https://*.api.userway.org *.api.userway.org https://sessions.bugsnag.com sessions.bugsnag.com https://px.ads.linkedin.com px.ads.linkedin.com https://*.facebook.com *.facebook.com https://region1.google-analytics.com region1.google-analytics.com https://geolocation.onetrust.com geolocation.onetrust.com; font-src 'self' https://privacyportal-eu-cdn.onetrust.com privacyportal-eu-cdn.onetrust.com https://cdn.userway.org cdn.userway.org data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://sidebar.bugherd.com sidebar.bugherd.com https://*.googletagmanager.com *.googletagmanager.com https://challenges.cloudflare.com challenges.cloudflare.com https://cdn.userway.org cdn.userway.org; img-src 'self' https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://*.googletagmanager.com *.googletagmanager.com https://googleads.g.doubleclick.net googleads.g.doubleclick.net https://stats.g.doubleclick.com stats.g.doubleclick.com https://stats.g.doubleclick.net stats.g.doubleclick.net https://*.google.com *.google.com https://*.google.co.uk *.google.co.uk https://*.cookielaw.org *.cookielaw.org https://px.ads.linkedin.com px.ads.linkedin.com https://*.linkedin.com *.linkedin.com https://*.facebook.com *.facebook.com https://cdn.userway.org cdn.userway.org https://d2iiunr5ws5ch1.cloudfront.net d2iiunr5ws5ch1.cloudfront.net blob: data:; media-src https://youtube.com youtube.com https://ddo8pjvnj55tt.cloudfront.net ddo8pjvnj55tt.cloudfront.net; object-src 'none'; manifest-src 'self'; script-src 'self' https://*.licdn.com *.licdn.com https://*.googleapis.com *.googleapis.com https://*.google.com *.google.com https://*.googletagmanager.com *.googletagmanager.com https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://pagead2.googlesyndication.com pagead2.googlesyndication.com https://*.cookielaw.com *.cookielaw.com https://*.cookielaw.org *.cookielaw.org https://*.onetrust.com *.onetrust.com https://connect.facebook.net connect.facebook.net https://sidebar.bugherd.com sidebar.bugherd.com https://cdn.userway.org cdn.userway.org https://*.bugherd.com *.bugherd.com https://static.cloudflareinsights.com static.cloudflareinsights.com https://challenges.cloudflare.com challenges.cloudflare.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://cdn.userway.org cdn.userway.org 'unsafe-inline'; upgrade-insecure-requests 3 script-src-elem payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com data: 'self'; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com static.runconverge.com *.facebook.net *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cloudflare.com *.trustedshops.com *.googleapis.com *.klaviyo.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.twitter.com services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.doubleclick.net *.facebook.com *.runconverge.com *.facebook.net *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.freshchat.com *.twitter.com *.pinterest.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src 'self' data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com static.runconverge.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cloudfront.net/ *.criteo.net *.stamped.io *.freshchat.com/ *.cloudflare.com *.ytimg.com *.bing.com/ *.clarity.ms/ *.google.al/ *.google.am/ *.google.at/ *.google.az/ *.google.ba/ *.google.be/ *.google.bg/ *.google.by/ *.google.ch/ *.google.cz/ *.google.de/ *.google.dk/ *.google.ee/ *.google.es/ *.google.fi/ *.google.fr/ *.google.ge/ *.google.gr/ *.google.hr/ *.google.hu/ *.google.ie/ *.google.is/ *.google.it/ *.google.kz/ *.google.li/ *.google.lt/ *.google.lu/ *.google.lv/ *.google.md/ *.google.me/ *.google.mk/ *.google.mt/ *.google.nl/ *.google.no/ *.google.pl/ *.google.pt/ *.google.ro/ *.google.rs/ *.google.ru/ *.google.se/ *.google.si/ *.google.sk/ *.google.sm/ *.google.tr/ *.google.ua/ *.google.uk/ *.google.com.ua/ *.google.com.tr/ *.google.com.gr/ *.google.com.pt/ *.google.com.pl/ cdn2.hubspot.net resources.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://img.youtube.com *.unifaun.com/ openstreetmap.org *.openstreetmap.org cdn1.stamped.io stamped.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com polyfill.io *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.runconverge.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.kk-resources.com/ *.shopalike.fi/ *.chatbotize.com/ qanuk-stage.vercel.app *.tradedoubler.com *.criteo.com *.cookiefirst.com *.omappapi.com *.googleoptimize.com *.klaviyo.com reviewsonmywebsite.com 'self' data: *.fontawesome.com *.videoly.co/ *.freshchat.com cdnjs.cloudflare.com/ *.googleapis.com/ *.noibu.com/ *.pinimg.com/ *.bing.com/ *.tiktok.com/ *.pinterest.com/ *.intercom.io/ *.intercomcdn.com/ *.clarity.ms/ polyfill-fastly.io/ services.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ unpkg.com/ cdn1.stamped.io stamped.io *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com s7.addthis.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com static.runconverge.com *.facebook.net *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cookiefirst.com *.omappapi.com reviewsonmywebsite.com *.typekit.net *.freshchat.com/ *.cloudflare.com/ *.klaviyo.com/ https://static.klaviyo.com maxcdn.bootstrapcdn.com unpkg.com/ cdn1.stamped.io stamped.io *.trustpilot.com assets.braintreegateway.com https://cdn.jsdelivr.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://maps.googleapis.com https://player.vimeo.com *.algolia.net *.algolia.com/ *.algolianet.com *.facebook.com *.facebook.net *.google.com/ payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.runconverge.com *.googletagmanager.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.criteo.com *.kelkoogroup.net/ *.chatbotize.com *.doubleclick.net *.qanuk.app *.cookiefirst.com *.omappapi.com *.googlesyndication.com reviewsonmywebsite.com *.cloudflare.com *.pinterest.com *.tiktok.com/ *.clarity.ms/ *.noibu.com/ wss://input.noibu.com/ wss://nexus-websocket-a.intercom.io/ *.intercom.io/ *.bing.com/ *.algolia.io/ *.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io *.trustpilot.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com ekr.zdassets.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 block-all-mixed-content;default-src https:;script-src * 'self' https: 'unsafe-eval' 'unsafe-inline';style-src * 'self' https: 'unsafe-inline';connect-src * https: https://*.paynearme.com;manifest-src 'self';font-src * 'self' https:;form-action 'self' https://www.facebook.com https://accounts.google.com https://twitter.com https://login.microsoftonline.com;img-src * 'self' https: data:;media-src *;object-src 'none';frame-ancestors *;frame-src * https://*.paynearme.com;worker-src 'self';base-uri 'self';report-uri /csp-report 3 default-src 'self' https:; script-src 'self' https: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data:; frame-src https:; frame-ancestors 'self'; font-src 'self' https: data:; report-uri /report-csp-violation 3 font-src fonts.gstatic.com use.typekit.net https://cdn.riverty.design/ *.cloudfront.net https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com uc8.tv *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com uc8.tv https://documents.riverty.com/ *.dotdigital-pages.com *.dotdigital.com *.facebook.com *.facebook.net *.doubleclick.net *.paypal.com *.vimeo.com *.google.com *.googletagmanager.com https://documents.riverty.com https://documents.myafterpay.com https://tag.heylink.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ imgsct.cookiebot.com https://info.dibs.se *.trackedlink.net magefan.com cm.magefan.com *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://bat.bing.com https://cdn.myafterpay.com https://instore.prisjakt.no https://pricerunner.dk https://pricerunner.se *.googleadservices.com *.google-analytics.com *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ consent.cookiebot.com https://*.dibspayment.eu *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://cdn.cookie-script.com https://bat.bing.com *.clarity.ms *.doubleclick.net https://r1-t.trackedlink.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.paypal.com https://tag.heylink.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://*.dibspayment.eu *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com https://bat.bing.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ https://*.dibspayment.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://bat.bing.com *.clarity.ms *.doubleclick.net https://fraktguide.bring.no *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com *.mercadolibre.com https://www.googletagmanager.com/ *.magerocket.com *.gocuotas.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.magerocket.com *.gocuotas.com storage.googleapis.com *.google.com *.google.com.ar imgmp.mlstatic.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://device.clearsale.com.br https://live.decidir.com *.mlstatic.com *.mercadopago.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.magerocket.com *.gocuotas.com *.googleapis.com *.google.com *.gstatic.com *.avada.io polyfill.io go.botmaker.com storage.googleapis.com https://assets-cdn.woowup.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com fonts.googleapis.com *.googleapis.com *.google.com *.gstatic.com storage.googleapis.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ storage.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://events.woowup.com https://developers.decidir.com/ https://developers-ventasonline.payway.com.ar/ *.mercadopago.com *.mercadolibre.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.magerocket.com *.gocuotas.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io go.botmaker.com stats.g.doubleclick.net maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com *.paypal.com *.paypalobjects.com *.typekit.net *.gstatic.com applepay.cdn-apple.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.chatbot.com ct.pinterest.com *.criteo.com *.criteo.net www.facebook.com shop4runners.cr.rlvs.co.uk www.awin1.com d.c.cdnsrv.de mea.shop4runners.com mea.shop4runners.eu mea.shop4runners.at mea.shop4runners.ch mea.shop4runners.fr mea.runnershub.de mea.runnershub.bg mea.runnershub.eu *.attrxs.de *.getblue.io *.sovendus.com *.sovendus-connect.com bid.g.doubleclick.net td.doubleclick.net www.googletagmanager.com *.ad-srv.net *.paypal.com *.sandbox.paypal.com *.google.com js.mollie.com google.com https://c.paypal.com *.loadbee.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com https: www.googleadservices.com *.g.doubleclick.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.gstatic.com *.google.com *.google.de *.google.at *.google.ch *.google.eu *.google.fr https://images.unsplash.com *.paypal.com *.sandbox.paypal.com img.metaffiliation.com action.metaffiliation.com https://www.mollie.com https://api.mapbox.com https://c.paypal.com https://b.stats.paypal.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.chatarmin.com *.onefid.com maps.googleapis.com api.recova.ai assets.revlifter.io bat.bing.com cdn.chatbot.com *.consentmanager.net connect.facebook.net ct.pinterest.com s.pinimg.com *.criteo.com www.awin1.com www.dwin1.com the.sciencebehindecommerce.com www.ladenzeile.de tracking.s24.com d.c.cdnsrv.de smct.co s.uicdn.com *.attrxs.de *.gsitrix.com *.corporate-benefits.eu *.getblue.io *.wewomedia.com googleads.g.doubleclick.net www.google.com www.googleadservices.com www.google-analytics.com analytics.google.com *.googletagmanager.com tagmanager.google.com *.ad-srv.net *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.google.com *.cdn-apple.com action.metaffiliation.com img.metaffiliation.com s7.addthis.com js.mollie.com google.com https://c.paypal.com *.loadbee.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com fonts.googleapis.com *.googletagmanager.com tagmanager.google.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://api.batteryincluded.io *.chatarmin.com api.paypal.com maps.googleapis.com api.recova.ai devt.revlifter.com bat.bing.com bat.bing.net cdn.chatbot.com *.consentmanager.net www.facebook.com connect.facebook.net ct.pinterest.com www.pinterest.com *.criteo.com the.sciencebehindecommerce.com www.wepowerconnections.com tracking.s24.com mea.shop4runners.com mea.shop4runners.eu mea.shop4runners.at mea.shop4runners.ch mea.shop4runners.fr mea.runnershub.de mea.runnershub.bg mea.runnershub.eu r.nunami.ai *.gsitrix.com *.wewomedia.com *.sovendus.com *.sovendus-connect.com www.googleadservices.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.de *.google.at *.google.ch *.google.eu *.google.fr *.googlesyndication.com *.paypal.com *.sandbox.paypal.com action.metaffiliation.com img.metaffiliation.com ekr.zdassets.com/ google.com autocomplete2.postdirekt.de *.loadbee.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.cloudflare.com 'self' data: *.hotjar.com *.hotjar.io data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.paypal.com *.gstatic.com *.googleapis.com *.googlesyndication.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googleadservices.com www.facebook.com trengo.s3.eu-central-1.amazonaws.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com *.cmi.co.ma test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.googlesyndication.com *.googleadservices.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk www.facebook.com *.widget.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com connect.facebook.net graph.facebook.com business.facebook.com *.hotjar.com *.hotjar.io onesignal.com *.onesignal.com *.criteo.com *.adsmurai.com gateway.bankart.si test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.bootstrapcdn.com ecom-stage.iutecredit.mk ecom.iutecredit.mk downloads.mailchimp.com onesignal.com *.onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googlesyndication.com *.doubleclick.net www.facebook.com *.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ekr.zdassets.com/ connect.facebook.net graph.facebook.com business.facebook.com wss://ws.hotjar.com *.hotjar.io test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' https://forms.office.com/ https://*.seeburger.com https://munchkin.marketo.net https://v.qq.com https://www.youtube.com https://*.seeburger-news.com https://*.doubleclick.net; frame-ancestors 'self' https://*.seeburger.com www.googletagmanager.com; font-src 'self' data: https://*.seeburger.com https://fonts.gstatic.com; img-src 'self' data: https://*.seeburger.com https://secure.leadforensics.com https://wwwseeburgercom-160c6.kxcdn.com https://i.ytimg.com www.googletagmanager.com https://googletagmanager.com https://fonts.gstatic.com https://ssl.gstatic.com https://www.gstatic.com https://*.linkedin.com https://secure.curl7bike.com https://*.google-analytics.com https://www.google.de https://www.google.com; media-src *; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.seeburger.com https://munchkin.marketo.net https://*.seeburger-news.com https://secure.curl7bike.com https://secure.leadforensics.com https://ce.lijit.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://cdn.plyr.io https://www.youtube.com https://snap.licdn.com https://googleads.g.doubleclick.net https://www.clickcease.com https://idx.liadm.com https://bat.bing.com; connect-src 'self' wss://*.seeburger.com https://idx.liadm.com https://cdn.plyr.io https://noembed.com https://*.mktoresp.com https://*.google-analytics.com https://region1.analytics.google.com https://adservice.google.com https://analytics.google.com https://www.google.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://munchkin.marketo.net https://*.seeburger-news.com; frame-src 'self' https://www.googletagmanager.com https://www.youtube.com https://v.qq.com forms.office.com https://go.seeburger-news.com; report-uri https://sentry2.in2code.de/api/7/security/?sentry_key=ac5a04f3144e74ea1ccb11c69823ed60 3 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://translate.google.com/translate_a/element.js https://www.youtube.com/iframe_api https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.gstatic.com/_/mss/boq-chrome-webstore/_/js/k=boq-chrome-webstore.ChromeWebStoreConsumerFeUi.en_US.YdWfvkayZeo.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/;report-uri /_/ChromeWebStoreConsumerFeUi/cspreport/fine-allowlist 3 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://meet.google.com/_/scs/mss-static/_/js/ https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/hangouts_echo_detector/release/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com/video_effects/effects/ https://www.gstatic.com/meetings_p2p/ https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://meet.google.com/meetsw.js https://meet.google.com/devicesw.js https://meet.google.com/notrodsw.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://meet.google.com/_/scs/mss-static/_/js/k=boq-rtc.MeetingsUi.en_US.m6kBAEog7w8.2020.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /_/MeetingsUi/cspreport/fine-allowlist 3 font-src *.gstatic.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.transbank.cl *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.newrelic.com *.herokuapp.com *.doubleclick.net/ *.googleapis.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.weltpixel.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com.ar *.instagram.com *.cdninstagram.com *.gstatic.com *.facebook.com *.newrelic.com *.clarity.ms *.bing.com *.googleapis.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com https://*.woowup.com *.herokuapp.com *.instagram.com *.facebook.net *.newrelic.com *.nr-data.net *.clarity.ms mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.google.com/ onesignal.com *.onesignal.com *.avada.io player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.herokuapp.com *.newrelic.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google.com.ar *.doubleclick.com *.doubleclick.net *.newrelic.com *.nr-data.net *.clarity.ms mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl https://get.geojs.io *.avada.io https://*.woowup.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 object-src 'none'; script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://checkoutshopper-live.adyen.com https://checkoutshopper-test.cdn.adyen.com https://homologation-payment.cdn.payline.com https://payment.cdn.payline.com https://static.addtoany.com https://uberall.com https://unpkg.com https://www.google.com https://www.youtube.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://checkoutshopper-live.adyen.com https://checkoutshopper-test.cdn.adyen.com https://homologation-payment.cdn.payline.com https://payment.cdn.payline.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 3 report-uri https://gfcorporate.report-uri.com/r/d/csp/reportOnly ; default-src 'self' www.gfms.com gfms.com www.gfps.com gfcorporate.report-uri.com *.google.at *.google.be *.google.cz *.google.dk *.google.fi *.google.fr *.google.de *.google.it *.google.nl *.google.no *.google.pl *.google.ro *.google.ru *.google.es *.google.se *.google.ch *.google.com.tr *.google.co.uk *.google.com.ar *.google.ca *.google.com *.google.com.br *.google.com.mx *.google.com.au *.google.cn *.google.co.in *.google.co.id *.google.co.jp *.google.com.my *.google.co.nz *.google.com.sg *.google.co.kr *.google.com.tw *.google.com.vn *.google.bg *.google.hr *.google.ee *.google.gr *.google.hu *.google.lv *.google.lu *.google.mk *.google.pt *.google.rs *.google.si *.google.com.ph *.google.co.th *.google.com.eg *.google.co.il *.google.co.za *.google.ae ; connect-src 'self' *.google-analytics.com apikeys.civiccomputing.com *.googleapis.com center.lon5.atomz.com clapi.civiccomputing.com sp1004e61f.guided.lon5.atomz.com sp1004e61a.guided.lon5.atomz.com sp1004e5dd.guided.lon5.atomz.com stats.g.doubleclick.net www.facebook.com uberall.com locator.uberall.com api.moin.ai www.gfps.com www.gfpstools.com neoflow.gfpstools.com cdn.linkedin.oribi.io assets.georgfischer.com google.com analytics.google.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat cdn.cookielaw.org *.onetrust.com *.svc.dynamics.com *.clarity.ms ad.doubleclick.net adservice.google.com assets-eur.mkt.dynamics.com public-eur.mkt.dynamics.com assets.adobedtm.com c-cdn.contentfry.com catalog.contentfry.com platform.contentfry.com code.jquery.com fbo-b.flippingbook.com online.flippingbook.com live.solique.ch polyfilljs.org s7e5a.scene7.com s7mbrstream-g1.scene7.com www.googleadservices.com ; font-src 'self' fonts.gstatic.com www.gfms.com widget.moin.ai static-prod.uberall.com static.prod.uberall.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google.com *.google-analytics.com *.googletagmanager.com assets.adobedtm.com ajax.googleapis.com assets.georgfischer.com cc.cdn.civiccomputing.com connect.facebook.net cdnjs.cloudflare.com gstatic.com maps.googleapis.com siteimproveanalytics.com snap.licdn.com static-prod.uberall.com uberall.com locator.uberall.com www.youtube.com www.pagespeed-mod.com www.googleoptimize.com mktdplp102cdn.azureedge.net www.pagespeed-mod.com widget.moin.ai platform.contentfry.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal.onetrust.com geolocation.onetrust.com r1.dotdigital-pages.com r1-t.trackedlink.net r1.ddlnk.net www.googleadservices.com ; script-src-elem uberall.com www.googletagmanager.com 'self' assets.georgfischer.com blob: code.jquery.com locator.uberall.com maps.googleapis.com s7e5a.scene7.com www.clarity.ms www.google.com www.googleadservices.com www.youtube.com ; style-src 'self' 'unsafe-inline' 'unsafe-eval' fonts.googleapis.com assets.georgfischer.com errors.adobeaemcloud.com widget.moin.ai ; style-src-elem www.googletagmanager.com 'self' assets.georgfischer.com blob: s7e5a.scene7.com www.gstatic.com ; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.georgfischer.com www.linkedin.com *.global.siteimproveanalytics.io nswow-imageresizer.azurewebsites.net px.ads.linkedin.com www.facebook.com connect.facebook.net *.google.com gfms.com www.gfms.com static-prod.uberall.com static.prod.uberall.com www.linkedin.com s7e5a.scene7.com *.g.doubleclick.net *.svc.dynamics.com i.ytimg.com maps.gstatic.com fonts.gstatic.com www.gfps.com www.gfpstools.com locator.uberall.com *.amazonaws.com *.googletagmanager.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat cdn.cookielaw.org c.clarity.ms m.youtube.com *.onetrust.com ; child-src 'self' blob: analytics-eu.clickdimensions.com live.solique.ch www.youtube.com ; form-action www.facebook.com www.georgfischer.com 'self' ; frame-ancestors 'self' https://*.georgfischer.com; frame-src 'self' 'unsafe-inline' 'unsafe-eval' data: analytics-eu.clickdimensions.com google.com ir.tools.investis.com irs.tools.investis.com live.solique.ch recruitingapp-5505.de.umantis.com registration.gesevent.com six-swiss-exchange.com tools.google.com uberall.com widget.moin.ai *.svc.dynamics.com *.ep-mimecast.dynamics.com www.gfps.com bim.gfps.com ir2.flife.de www.youtube.com m.youtube.com *.ep-mimecast.youtube-nocookie.com www.youtube-nocookie.com.x.af435fba09eaa04ff30886e05784e20ddae5.d045227c.id.opendns.com r1.dotdigital-pages.com display.contentfry.com googletagmanager.com cad.georgfischer.com forms.office.com foundation-gf-dev.georgfischer.com online.flippingbook.com players.brightcove.net youtube.com ; manifest-src 'self' ; media-src 'self' assets.georgfischer.com gfms.com s7e5a.scene7.com s7mbrstream-g1.scene7.com www.gfps.com ; 3 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.gstatic.com *.typekit.net *.optimonk.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.ro google.sk google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.ro *.google.sk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk data: 'self' 'unsafe-inline'; form-action *.facebook.com *.google.com test.saferpay.com www.saferpay.com saferpay.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.weltpixel.com test.saferpay.com www.saferpay.com saferpay.com https://player.vimeo.com https://www.youtube-nocookie.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.com *.diego.itg.cloud facebook.com youtube.com pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud https://consentcdn.cookiebot.com *.googletagmanager.com *.diego.hu *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.google-analytics.com test.saferpay.com www.saferpay.com saferpay.com magefan.com cm.magefan.com https://www.magezon.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.com *.diego.itg.cloud maps.gstatic.com *.diego.hu *.taggrs.io *.bing.com *.guidebot.org guidebot.org *.taggrs.cloud google.ro google.sk google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com test.saferpay.com www.saferpay.com saferpay.com player.vimeo.com https://player.vimeo.com https://www.youtube.com *.adobedtm.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.com *.diego.itg.cloud facebook.net adobedtm.com adobe.com googleapis.com pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud *.dyn-rev.app stapecdn.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com *.typekit.net *.optimonk.com *.pinterest.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com https://www.google-analytics.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com test.saferpay.com www.saferpay.com saferpay.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.doubleclick.net *.cookiebot.com *.optimonk.com *.luigisbox.com *.diego.itg.cloud pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud maps.googleapis.com *.diego.hu gorgias-convert.com *.googlesyndication.com region1.google-analytics.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' *.roche.com *.roche.net *.gene.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.roche.com *.roche.net *.gene.com snap.licdn.com cdn.walkme.com apis.google.com tpc.googlesyndication.com api.html5media.info workdevapp.com cdn-js.net gdata.youtube.com twitter.com geolocation.onetrust.com api.flickr.com graph.facebook.com sharecdn.social9.com maps.googleapis.com use.typekit.com use.typekit.net munchkin.marketo.net img.en25.com w.likebtn.com cdn.mathjax.org sadmin.brightcove.com cdnjs.cloudflare.com releases.flowplayer.org script.crazyegg.com wi.likebtn.com pepperglobal.com analytics.twitter.com cdn.blueconic.net connect.facebook.net fullstory.com script.hotjar.com gnntch.blueconic.net rules.quantcount.com secure.quantserve.com static.hotjar.com www.youtube.com www.googletagmanager.com www.google-analytics.com google-analytics.com *.gstatic.com static.ads-twitter.com sjs.bizographics.com *.linkedin.com www.google.com w.soundcloud.com s.ytimg.com *.cloudflareaccess.com *.salesforceliveagent.com https://*.roche.com:8080 https://cdnjs.org https://service.force.com/* cdn.cookielaw.org static.cloudflareinsights.com googleads.g.doubleclick.net 7232514.collect.igodigital.com; style-src * 'self' 'unsafe-inline'; img-src * 'self' data:; font-src * 'self' data:; connect-src * 'self'; media-src * 'self' data:; object-src 'self'; child-src 'self' *.roche.com *.roche.net *.gene.com *.facebook.net qpcr.probefinder.com *.force.com *.hotjar.com www.facebook.com www.google.com www.googletagmanager.com www.youtube.com; frame-src 'self' *.roche.com *.roche.net *.gene.com www.youtube.com sites.google.com *.googleapis.com *.cloudfront.net *.facebook.net *.arcot.com live.sagepay.com player.vimeo.com tpc.googlesyndication.com players.brightcove.net qpcr.probefinder.com *.eloqua.com *.hotjar.com *.soundcloud.com *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.mendeley.com *.force.com https://cdn.walkme.com/*; worker-src 'self' *.roche.com *.roche.net *.gene.com; frame-ancestors 'self' *.roche.com *.roche.net *.gene.com datastudio.google.com sites.google.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com *.cloudflareworkers.com; form-action 'self' *.roche.com *.roche.net *.gene.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com; base-uri 'self' *.roche.com *.roche.net *.gene.com *.secure.roche.com 3 default-src 'self' data: 'unsafe-eval' 'unsafe-inline' *.shopmetrics.com *.gigspot.com *.research-cloud.com https://*.jsdelivr.net https://unpkg.com https://*.unpkg.com https://*.googleapis.com https://*.google-analytics.com https://*.gstatic.com https://*.search.windows.net https://cdnjs.cloudflare.com https://code.jquery.com *.facebook.net *.facebook.com *.doubleclick.net *.googletagmanager.com *.bootstrapcdn.com *.typekit.net https://rmvelocityfrontend.blob.core.windows.net https://rec.i-say.com https://vcdn.blob.core.windows.net/* https://cdn.vcdn.vc/*; script-src 'self' data: 'unsafe-eval' 'unsafe-inline' *.shopmetrics.com *.gigspot.com *.research-cloud.com https://*.jsdelivr.net https://unpkg.com https://*.unpkg.com https://*.googleapis.com https://*.google-analytics.com https://*.gstatic.com https://*.search.windows.net https://cdnjs.cloudflare.com https://code.jquery.com *.facebook.net *.facebook.com *.doubleclick.net *.googletagmanager.com *.bootstrapcdn.com *.typekit.net https://rmvelocityfrontend.blob.core.windows.net; frame-src 'self' blob: *.shopmetrics.com *.gigspot.com *.research-cloud.com *.velocity.online https://www.googletagmanager.com *.youtube.com *.youtu.be; base-uri 'self'; form-action 'self' *.shopmetrics.com *.gigspot.com *.velocity.online; img-src * data: about: blob: filesystem: ma-file:; object-src 'none'; font-src 'self' data: *.shopmetrics.com *.bootstrapcdn.com *.typekit.net *.gstatic.com *.jsdelivr.net *.pstatic.net *.github.com; 3 frame-src 'self' td.doubleclick.net youtube.com *.youtube.com; report-uri /infra/monitoring/csp 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.olark.com mediacdn.espssl.com *.imi.chat *.frontiercoop.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com *.zopim.io *.widen.net *.widencdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * destinilocators.com *.duosecurity.com *.olark.com *.frontiercoop.com *.yotpo.com *.weltpixel.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.zendesk.com *.widen.net *.widencdn.net *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.certcapture.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com frontiercoop.widen.net *.olark.com lux.speedcurve.com mediacdn.espssl.com brxcdn.com *.frontiercoop.com cdn-cookieyes.com *.yotpo.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.widen.net *.widencdn.net *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net destinilocators.com *.olark.com cdn.speedcurve.com acsbapp.com s.pinimg.com bat.bing.com ct.pinterest.com *.exponea.com *.imi.chat *.frontiercoop.com cdn-cookieyes.com *.yotpo.com js.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.zendesk.com *.widen.net *.widencdn.net *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com assets.braintreegateway.com *.olark.com mediacdn.espssl.com *.imi.chat *.frontiercoop.com *.yotpo.com *.klevu.com *.ksearchnet.com 'unsafe-inline' *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com *.widen.net *.widencdn.net *.tagmanager.google.com *.googletagmanager.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com *.frontiercoop.com *.zopim.com *.zopim.io *.widen.net *.widencdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com bam.nr-data.net lux.speedcurve.com *.acsbapp.com acsbapp.com ct.pinterest.com bat.bing.com *.exponea.com facebook.com *.facebook.com *.imi.chat *.frontiercoop.com cdn-cookieyes.com log.cookieyes.com *.yotpo.com *.olark.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net *.zendesk.com *.widen.net *.widencdn.net *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.olark.com *.frontiercoop.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.plugins.emarsys.net *.scarabresearch.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.magento-datasolutions.com *.magento-ds.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.scarabresearch.com *.eservice.emarsys.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hatraco-shop.de; 3 font-src *.googleapis.com *.gstatic.com data: *.bootstrapcdn.com *.cloudflare.com *.klarnacdn.net *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.twitter.com 'self' 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.facebook.com *.pinterest.com *.trustpilot.com *.twitter.com *.snapwidget.com 'self' www.googletagmanager.com 'self' 'unsafe-inline'; img-src *.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com maps.gstatic.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bing.com *.clarity.ms *.cloudflare.com craftyclicks.co.uk *.demdex.net *.facebook.com fetchify.com *.goldboutique.com *.google-analytics.com *.google.co.uk *.google.com *.googleadservices.com *.googletagmanager.com *.klarna.com *.lightemporium.com *.magentocommerce.com *.pinterest.com *.elfsightcdn.com *.qpj.de *.qpj.fr *.qpjewellers.com *.rubyandoscar.com *.scarletocean.com *.twimg.com *.twitter.com *.usercentrics.eu *.wisepops.com *.ytimg.com *.roeye.com *.roeyecdn.com *.bailandstone.com *.roxoa.com 'self' https://*.google-analytics.com https://*.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.bing.com *.clickcease.com *.cloudflare.com cc-cdn.com *.facebook.net *.fontawesome.com *.getdrip.com *.google-analytics.com *.pcapredict.com *.pinimg.com *.pinterest.com *.plerdy.com *.taboola.com *.termly.io *.tiktok.com *.trustedshops.com *.trustpilot.com *.twimg.com *.twitter.com *.usercentrics.eu *.wisepops.net *.wisepops.com https://wisepops.net https://wisepops.com *.zdassets.com *.klarnaservices.com *.klarna.com *.clarity.ms https://snapwidget.com *.elfsight.com *.elfsightcdn.com *.roeyecdn.com *.qpjewellers.com/connector/ajax/emailcapture *.rubyandoscar.com/connector/ajax/emailcapture *.goldboutique.com/connector/ajax/emailcapture *.bailandstone.com/connector/ajax/emailcapture https://*.googletagmanager.com *.dotdigital.com 'self' *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com assets.braintreegateway.com *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.klarnacdn.net *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu *.zdassets.com 'self' *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.slack.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.analytics.google.com *.bootstrapcdn.com *.bing.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.google-analytics.com https://google.com/pay *.googleadservices.com *.klarna.com *.klarnaservices.com *.klarnaevt.com *.paypalobjects.com *.pcapredict.com *.pinterest.com *.plerdy.com *.sandbox.paypal.com *.termly.io *.tiktok.com *.trustpilot.com https://invitejs.trustpilot.com *.twimg.com *.twitter.com *.vimeocdn.com *.wisepops.net *.wisepops.com https://wisepops.net https://wisepops.com *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.sentry.io *.elfsight.com 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp.threatview.app/report; report-to report-endpoint; 3 script-src 'self'; object-src 'self'; report-to csp-endpoint; 3 default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; frame-ancestors 'self'; form-action 'self'; 3 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com v2.zopim.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.twitter.com https://www.facebook.com www.googletagmanager.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com https://*.google.com *.doubleclick.net *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.twitter.com axi.maxiaxi.com *.pinterest.com *.addthis.com https://consentcdn.cookiebot.com *.fast.amc.demdex.net https://tr.snapchat.com https://www.facebook.com *.cookiebot.eu *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com https://static.buckaroo.nl validate.fishpig.co.uk https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://redchamps.com ts.tradetracker.net www.magmodules.eu *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.maxiaxi.com bat.bing.com www.google.nl www.google.de www.google.fr www.google.es *.squeezely.tech tm-tradetracker.net *.pinterest.com *.googleapis.com *.googleoptimize.com *.linkedin.com *.cookiebot.com *.etrusted.com *.adobedtm.com *.zendesk.com *.zdassets.com *.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io tm.tradetracker.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com app.aiden.cx js-agent.newrelic.com bam.nr-data.net rum-static.pingdom.net *.trustpilot.com *.zopim.com static.sooqr.com *.zdassets.com bat.bing.com static.buckaroo.nl *.squeezely.tech tm-tradetracker.net *.maxiaxi.com *.clarity.ms *.googleoptimize.com *.zendesk.com bam.eu01.nr-data.net *.pinimg.com *.addthis.com *.addthisedge.com *.moatads.com *.hotjar.com *.hotjar.io *.licdn.com *.beslist.nl *.tiktok.com *.stripe.com *.cookiebot.com *.etrusted.com *.smooch.io *.pinterest.com *.convertexperiments.com d5yoctgpv4cpx.cloudfront.net *.cookiebot.eu squeezely.tech tr.kickbite.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu static.sooqr.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zendesk.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com bam.nr-data.net *.zdassets.com widget-mediator.zopim.com stats.g.doubleclick.net squeezely.tech cognito-identity.eu-central-1.amazonaws.com rum-collector-2.pingdom.net wss://widget-mediator.zopim.com *.maxiaxi.com *.clarity.ms *.googleapis.com *.googleoptimize.com *.googletagmanager.com *.pinterest.com measurement-api.criteo.com *.zendesk.com bam.eu01.nr-data.net *.addthis.com *.hotjar.com *.beslist.nl *.tiktok.com app.aiden.cx *.hotjar.io wss://ws.hotjar.com analytics.pangle-ads.com googleads.g.doubleclick.net *.ads.linkedin.com *.cookiebot.com *.etrusted.com *.smooch.io *.convertexperiments.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.bing.com tr.kickbite.io wss://*.zendesk.com *.trustedshops.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.hotjar.com *.hotjar.io wss://*.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com *.fontawesome.com *.multisafepay.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data: blob: 'unsafe-inline'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: data: 'unsafe-inline'; font-src 'self' https: data: https:; connect-src 'self' https: wss:; frame-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'self' https: data: blob:; base-uri 'self' https:; form-action 'self' https:; frame-ancestors 'self' https:; worker-src 'self' https: data: blob:; report-uri /csp-report 3 font-src fonts.gstatic.com use.typekit.net *.abtasty.com https://static.payzen.eu/static/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.prolians.fr *.hydralians.fr *.dexis.fr https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.google.com/recaptcha/ https://www.youtube.com https://www.youtube-nocookie.com *.doubleclick.net https://caast.tv https://*.caast.tv https://*.youtube.com consentcdn.cookiebot.com *.googletagmanager.com https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net media.descours-cabaud.net *.prolians.fr *.hydralians.fr *.picsum.photos *.placehold.co doc.xhander.com doc.dexis-4mp.com doc.opsial.com *.google.fr https://*.caast.tv https://i.ytimg.com imgsct.cookiebot.com *.facebook.com *.contentsquare.net *.igodigital.com medias.descours-cabaud.com https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.zdassets.com *.zopim.com static.cloudflareinsights.com https://caast.tv https://*.caast.tv https://cdn.caast.tv consent.cookiebot.com sdk.privacy-center.org *.facebook.net *.igodigital.com *.contentsquare.net *.abtasty.com js-agent.newrelic.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ challenges.cloudflare.com https://ajax.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.payzen.eu/static/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.mux.com https://*.caast.tv *.zdassets.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net *.sentry.io https://caast.tv https://*.caast.tv wss://*.caast.tv https://*.mux.com *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com https://cache.caast.tv stats.g.doubleclick.net api.privacy-center.org *.google.com *.contentsquare.net *.abtasty.com *.nr-data.net https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ 'self' 'unsafe-inline'; child-src https://caast.tv https://*.caast.tv http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net amcglobal.sc.omtrdc.net use.typekit.net commerce.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com performance.typekit.net commerce.adobe.net *.adyen.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.facebook.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.createsend1.com *.scene7.com *.klarna.com https://www.googletagmanager.com/ *.facebook.com *.facebook.net https://plumrocket.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.googlesyndication.com *.hopewiser.com *.scene7.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.facebook.com *.facebook.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://magento.com https://developer.adobe.com *.adobedtm.com *.bradford.link *.criteo.net *.createsend1.com *.cardinalcommerce.com *.doubleclick.net *.facebook.net *.googletagmanager.com *.godaddy.com *.hotjar.com *.scene7.com *.sub2tech.com *.paypalobjects.com *.xtento.com widget.freshworks.com m2epro.freshdesk.com *.preprodservices.crif-online.ch *.services.crif-online.ch *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.facebook.com *.avada.io *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://cloud.hopewiser.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://developer.adobe.com *.googlesyndication.com https://maps.googleapis.com *.scene7.com widget.freshworks.com m2epro.freshdesk.com *.preprodservices.crif-online.ch *.services.crif-online.ch *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ccavenue.ae 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.checkout.com *.klarna.com *.ccavenue.ae checkout.tabby.ai https://c.sharethis.mgr.consensu.org https://secure.ccavenue.ae 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ccavenue.ae cdn.jsdelivr.net data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.magentocommerce.com *.cloudfront.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://l.sharethis.com https://sharethis.com https://platform-cdn.sharethis.com *.facebook.com *.alothemes.com *.magepow.com *.tamara.co data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.checkout.com *.klarnacdn.net *.ccavenue.ae *.moengage.com sc-static.net *.snapchat.com *.spotii.me apigoswirl.com cdn.jsdelivr.net checkout.tabby.ai widgets.tabby.ai cdn.segment.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.cloudflare.com *.authorize.net *.braintreegateway.com *.ytimg.com *.paypal.com *.payments-amazon.com *.croapp.net https://buttons-config.sharethis.com https://platform-api.sharethis.com s7.addthis.com *.googletagmanager.com *.facebook.net *.alothemes.com *.magepow.com cdn.tamara.co maps.googleapis.com *.tamara.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://cdn.checkout.com apigoswirl.com cdn.jsdelivr.net *.yotpo.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.alothemes.com *.magepow.com *.tamara.co 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tamara.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.checkout.com *.klarnaevt.com *.ccavenue.ae *.moengage.com sc-static.net *.snapchat.com *.spotii.me apigoswirl.com api.goswirl.live checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.cloudflare.com *.twitter.com *.twimg.com api.homesrusae.evinent.site homesrusaenew-api.evinent.site api.homesrusqa.evinent.site homesrusqanew-api.evinent.site api.momstore.evinent.site momstorenew-api.evinent.site api.carters.evinent.site https://l.sharethis.com https://sharethis.com ekr.zdassets.com/ *.google-analytics.com *.alothemes.com *.magepow.com maps.googleapis.com *.tamara.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.nosto.com *.nos.to *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com www.feedoptimise.com cdn.feedoptimise.com *.globalpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.googleapis.com data: 'self' 'unsafe-inline'; script-src unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com jquery.sellxed.com www.feedoptimise.com cdn.feedoptimise.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.trustpilot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://google.com/pay https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 report-uri /es/Error/ReportCPS; 3 default-src 'self'; script-src 'report-sample' 'self' https://js.qualified.com/qualified.js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://app.qualified.com wss://ws.qualified.com; font-src 'self'; frame-src 'self' https://app.qualified.com; img-src 'self' data: https://dms6j3xpg18d6.cloudfront.net https://d3s86tfxelgbdj.cloudfront.net https://huntscanlon.com https://images.cointelegraph.com https://mma.prnewswire.com https://s.yimg.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 3 default-src 'unsafe-eval' 'unsafe-inline' blob: data: https: ws: wss:; img-src 'unsafe-inline' blob: data: *; report-uri https://csp.test.orlo.tech/report; 3 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri https://0594ebf9e3dab534acdba65c6100b639.report-uri.com/r/d/csp/reportOnly; 3 frame-ancestors 'self' *.volusion.com;default-src 'none' 3 default-src 'self' https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https: wss:; media-src 'self' https: blob: data:; object-src https: blob:; worker-src 'self' https: blob:; frame-src 'self' https: blob:; form-action 'self' https:; block-all-mixed-content; report-uri /csp-violation-report 3 font-src fonts.gstatic.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl portal.bulkgate.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.cloudflare.com portal.bulkgate.com *.wayforpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.facebook.com *.doubleclick.net *.googletagmanager.com *.binotel.com lottie.host portal.bulkgate.com ipinfo.io *.wayforpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.clarity.ms *.google.com.ua *.facebook.com blob: *.bing.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl biotus.ua biotus.kz biotus.md biotus.ru biotus.by biotus.az biotus.uz biotus.ge biotus.lt biotus.lv biotus.ee biotus.it biotus.ro biotusnew.pl *.binotel.com *.binotel.ua *.esputnik.com portal.bulkgate.com *.gstatic.com *.googleapis.com *.rawgit.com *.jsdelivr.net https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com https://maps.googleapis.com https://player.vimeo.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.clarity.ms *.cloudflare.com *.facebook.net *.facebook.com *.google.com *.tiktok.com *.doubleclick.net *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.googletagmanager.com *.binotel.com *.esputnik.com esputnik.com portal.bulkgate.com *.gstatic.com *.googleapis.com ipinfo.io analytics.tiktok.com/ *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.esputnik.com portal.bulkgate.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src ipinfo.io 'self' 'unsafe-inline'; media-src *.adobe.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.binotel.com *.binotel.ua 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com cdn.ampproject.org https://maps.googleapis.com https://player.vimeo.com *.clarity.ms *.doubleclick.net *.google.com.ua/ads/* *.google.com/ccm/collect* adservice.google.com/pagead/* *.analytics.google.com/g/collect* *.google.com *.tiktok.com *.facebook.net *.facebook.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.binotel.com wss://*.binotel.com:9028 *.esputnik.com esputnik.com portal.bulkgate.com *.gstatic.com wss://*.bulkgate.com *.googleapis.com ipinfo.io *.tiktokw.us https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.msecnd.net connect.facebook.net tags.tiqcdn.com cdn.cookielaw.org tags.tiqcdn.com eploytealium.com munchkin.marketo.net cdn.livechatinc.com api.livechatinc.com cdn.optimizely.com googletagmanager.com *.arrivia-cdn.com googleads.g.doubleclick.net deploytealium.com maps.googleapis.com *.clarity.ms *.personyze.com *.tealiumiq.com *.blob.core.windows.net cdn.quantummetric.com www.googletagmanager.com:443 cdn.jsdelivr.net:443 ajax.googleapis.com cdnjs.cloudflare.com kit.fontawesome.com pagead2.googlesyndication.com *.personyze.com static.elfsight.com:443 universe-static.elfsightcdn.com:443 bat.bing.com:443; frame-src 'self' https: *.clarity.ms *.personyze.com *.tealiumiq.com *.blob.core.windows.net pagead2.googlesyndication.com static.elfsight.com:443 universe-static.elfsightcdn.com:443; connect-src 'self' 'unsafe-inline' 'unsafe-eval' wss: https: data: blob: *.clarity.ms *.personyze.com *.tealiumiq.com *.blob.core.windows.net https://visitor-service-us-east-1.tealiumiq.com count.personyze.com googleads.g.doubleclick.net www.clarity.ms bat.bing.com bat.bing.com:443 nebula-cdn.kampyle.com api.livechatinc.com connect.facebook.net ajax.googleapis.com cdnjs.cloudflare.com cdn.quantummetric.com www.googletagmanager.com:443 cdn.jsdelivr.net:443 static.elfsight.com:443 universe-static.elfsightcdn.com:443; frame-ancestors 'self' ... *.clarity.ms *.personyze.com pagead2.googlesyndication.com; block-all-mixed-content; upgrade-insecure-requests; report-uri https://temporarycsp.azurewebsites.net/api/CreateReport; report-to csp-endpoint; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net 'self' data: https://widgets.trustedshops.com *.livechatinc.com https://td.doubleclick.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.packeta.com secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.livechatinc.com https://consentcdn.cookiebot.com/ api.ratingcaptain.com *.cookiebot.eu 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: https://maps.googleapis.com/ https://maps.gstatic.com/ https://developers.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://www.google.pl *.seznam.cz *.pricemania.sk https://imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.disqus.com *.avada.io *.shopify.com *.packeta.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com https://maps.googleapis.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.livechatinc.com https://www.googletagmanager.com *.seznam.cz https://pixel.biano.cz https://consent.cookiebot.com *.biano.sk *.biano.cz *.biano.ro https://consentcdn.cookiebot.com https://api.ratingcaptain.com *.absulo.ro *.sgtm.absulo.ro *.cookiebot.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.tagmanager.google.com *.googletagmanager.com *.pricemania.sk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://geowidget.easypack24.net *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.packeta.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://maps.googleapis.com/ *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app http://www.google-analytics.com *.livechatinc.com *.googlesyndication.com *.biano.cz *.biano.sk *.biano.ro https://consentcdn.cookiebot.com googleads.g.doubleclick.net api.ratingcaptain.com *.cookiebot.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-to csp-endpoint 3 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://maps.googleapis.com https://maps.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://consent.cookiebot.eu https://bat.bing.com https://js-eu1.hs-scripts.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-banner.com https://js-eu1.hubspot.com https://js-eu1.hsadspixel.net https://js-eu1.hs-analytics.net https://js-eu1.usemessages.com https://extend.vimeocdn.com https://connect.facebook.net https://snap.licdn.com https://bsqd.me; connect-src 'self' https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://www.google.com/ccm https://maps.googleapis.com https://googleads.g.doubleclick.net https://bat.bing.com https://api-eu1.hubspot.com https://api-eu1.hubapi.com https://cta-eu1.hubspot.com https://track-eu1.hubspot.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://js-eu1.hs-analytics.net https://px.ads.linkedin.com https://bsqd.me wss://bsqd.me; img-src 'self' data: https://www.google.com https://www.google.nl https://maps.gstatic.com https://maps.google.com https://www.gstatic.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://bat.bing.com https://track-eu1.hubspot.com https://perf-eu1.hsforms.com https://img.sct.eu1.usercentrics.eu https://px.ads.linkedin.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://player.vimeo.com https://www.youtube.com https://connect.facebook.net; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.magezon.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com maps.googleapis.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.gstatic.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://def9d71d-669f-4322-8f25-4ef099a2d33a.sansec.watch/; report-to report-endpoint; 3 font-src https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9019ddbf-da08-455e-a3c6-d8ea66ab1180.sansec.watch/; report-to report-endpoint; 3 worker-src 'none'; 3 script-src 'self' 'unsafe-inline' https://mc.yandex.ru https://www.google.com https://www.gstatic.com https://telegram.org https://js-de.sentry-cdn.com https://browser.sentry-cdn.com https://js.hcaptcha.com; object-src 'none'; form-action 'self'; frame-ancestors 'self'; 3 worker-src https://helmonline-hyva.dev.localhost helmonline.nl; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com consentcdn.cookiebot.com td.doubleclick.net www.googletagmanager.com *.criteo.com/ www.xtento.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com *.pon.bike images.pondigital.solutions *.google.nl *.google.com *.google.fr *.mailplus.nl imgsct.cookiebot.com *.bing.net *.bing.com pagead2.googlesyndication.com www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com chimpstatic.com rum-static.pingdom.net rum-collector-2.pingdom.net consentcdn.cookiebot.com consent.cookiebot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org *.clarity.ms restapi.mailplus.nl www.googleoptimize.com googletagmanager.com *.googletagmanager.com *.bing.com *.criteo.com static.criteo.net *.mouseflow.com *.tiktok.com *.hotjar.com *.beslist.nl static.cloudflareinsights.com cdn.debugbear.com pagead2.googlesyndication.com static.widget.trengo.eu www.xtento.com cdn.xtento.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com js.mollie.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.typekit.net downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://maps.googleapis.com https://player.vimeo.com devdocs.magento.com rum-collector-2.pingdom.net widgetcontent.thuiswinkel-cdn.org www.google.com *.clarity.ms consent.cookiebot.com consentcdn.cookiebot.com doubleclick.net *.bing.com *.criteo.com *.tiktok.com *.hotjar.com *.hotjar.io *.beslist.nl data.debugbear.com pagead2.googlesyndication.com api.widget.trengo.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com flagpedia.net *.multisafepay.com assets.myparcel.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://mylivechat.com https://uk.mylivechat.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com maps.googleapis.com *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com cdn.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.multisafepay.com cdn.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://uk.mylivechat.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com www.gstatic.com maps.googleapis.com *.multisafepay.com api.myparcel.nl cdn.jsdelivr.net *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src ctiapi.com s3.amazonaws.com *.fontawesome.com fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com ctiapi.com *.hestage.com *.ecklers.com *.ecklerscorvette.com *.macsautoparts.com *.rickscamaros.com *.classicchevy.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com *.doubleclick.net *.clarity.ms *.vantivprelive.com *.google.com *.listrak.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.sharethis.com ctiapi.com s3.amazonaws.com youtube.com *.ecklers.com *.gfycat.com *.imgeng.in *.cloudfront.net *.userid.io *.bing.com *.google.com *.clarity.ms *.listrakbi.com *.riskified.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com us-autocomplete-pro.api.smartystreets.com ctiapi.com *.cloudfront.net *.cloudflare.com *.bc0a.com *.online-metrix.net *.vantivprelive.com *.listrak.com *.listrakbi.com *.listrakbi.net *.userid.io *.bing.com *.datasteam.io *.doubleclick.net *.upsellit.com *.clarity.ms *.murdoog.com *.dwin1.com *.needle.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.ytimg.com *.gstatic.com *.ctiapi.com *.riskified.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com ctiapi.com *.fontawesome.com *.cloudfront.net *.listrakbi.net *.listrakbi.com *.googleapis.com unsafe-inline *.gstatic.com 'self' 'unsafe-inline'; object-src ctiapi.com s3.amazonaws.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com us-autocomplete-pro.api.smartystreets.com ctiapi.com *.bc0a.com *.brontops.com *.ecklers.com *.doubleclick.net *.cloudfront.net *.listrak.com *.clarity.ms *.ecklerscorvette.com *.macsautoparts.com *.rickscamaros.com *.classicchevy.com *.demdex.net *.cardinalcommerce.com *.google.com *.google-analytics.com *.paypalobjects.com *.ctiapi.com *.riskified.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://humanelement.report-uri.com/r/d/csp/enforce; report-to report-endpoint; 3 style-src 'self' cdn.transcend.io transcend-cdn.com www.mozilla.org; base-uri 'none'; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.mozilla.org; frame-src 'self' accounts.firefox.com js.stripe.com www.google-analytics.com www.googletagmanager.com www.youtube.com; object-src 'none'; frame-ancestors 'none'; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org; default-src 'self' *.mozilla.org; img-src 'self' blog.mozilla.org data: images.ctfassets.net www.google-analytics.com www.googletagmanager.com www.mozilla.org; upgrade-insecure-requests; connect-src 'self' cdn.transcend.io https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org/submit/bedrock/; font-src 'self' www.mozilla.org; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io js.stripe.com s.ytimg.com tagmanager.google.com transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org www.youtube.com 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/android 2 frame-ancestors 'self' *.appsflyer.com; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub077056148e159580585c94fcee3c8801&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=marketing_appsflyer_com 2 base-uri 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://climate.stripe.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://sales-live-chat.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com https://y4pfttj91h-1.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-2.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-3.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-dsn.algolia.net/1/indexes/mkt_partners/query https://tax-connectors.stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://climate.stripe.com https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://checkout.stripe.dev https://support-conversations.stripe.com https://b.stripecdn.com https://checkout.stripe.com https://crypto-js.stripe.com https://js.stripe.com https://sales-live-chat.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com https://stripe-camo.global.ssl.fastly.net 'self'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; script-src https://b.stripecdn.com https://crypto-js.stripe.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src 'none'; report-uri https://q.stripe.com/csp-violation?q=KpZVgNiuq-kCMiSXN-Apden72Zxp14J1lrE_ZvjHrFMe8yXnocFNCiHbORUs3XE%3D 2 script-src 'self' padlet.net maps.googleapis.com apis.google.com ta-echo.padlet.com api.commandbar.com cdn.commandbar.com app.getbeamer.com challenges.cloudflare.com embed.cloudflarestream.com cdn.usefathom.com blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' padlet.net fonts.googleapis.com cdn.commandbar.com app.getbeamer.com 'unsafe-inline'; font-src 'self' padlet.net fonts.gstatic.com data:; report-uri https://padlet.com/csp-report; 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://deadline.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; font-src 'self' data:; 2 default-src 'self' *.wp.com; img-src data: https:; script-src 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'unsafe-inline' https:; font-src data: https:; media-src blob: https:; frame-src https:; object-src 'none'; connect-src https:; 2 default-src 'self';base-uri 'self';connect-src 'self' data: https: wss://keepalive.gotinder.com;script-src 'nonce-mKxLZxDla3C5UkWGe44+kQ==' 'strict-dynamic' 'unsafe-hashes' 'unsafe-eval' 'wasm-unsafe-eval' 'sha256-PLCxbpHSwAa8+W198R1KQQ9UDCexTvYy4z4YmCg21NM=' 'unsafe-inline';style-src 'self' 'unsafe-inline' blob: https://*.googleapis.com https://accounts.google.com;frame-src 'self' https://tinder-api.arkoselabs.com https://*.paypal.com https://accounts.google.com https://*.doubleclick.net https://*.adyen.com;frame-ancestors 'self';form-action 'self' https://*.tinder.com https://tinder.com https://*.adyen.com;object-src 'none';img-src 'self' data: blob: https:;media-src 'self' data: https:;report-to tinderweb-csp-reports;font-src 'self' data: https:;manifest-src 'self' https: 2 media-src blob: https:; worker-src blob: https:; font-src chrome-extension: data: https:; img-src data: blob: about: https: http://track.adform.net; default-src https: blob: data: ms-appx-web: wss: 'unsafe-inline' 'unsafe-eval'; report-uri https://handelsblatt.report-uri.com/r/d/csp/reportOnly 2 default-src 'self' cdnweb.sbermobile.ru; frame-src https://cdn.rutarget.ru/ https://api.flocktory.com https://mc.yandex.ru https://tag.rutarget.ru/ ; style-src 'unsafe-inline' 'self' fonts.googleapis.com cdnweb.sbermobile.ru; font-src 'self' cdnweb.sbermobile.ru data: fonts.gstatic.com ; connect-src 'self' https://yandexmetrica.com:*/ *.sbermarketing.ru uaas.yandex.ru ad.adriver.ru api.flocktory.com kraken.rambler.ru https://*.mc.yandex.ru/ https://stats.g.doubleclick.net/ https://suggestions.dadata.ru/ https://suggest-maps.yandex.ru/ https://ymetrica1.com/ https://www.google-analytics.com/ https://unpkg.com/ https://stats.g.doubleclick.net/ https://mc.yandex.ru/ https://*.sberbank.ru/ https://sa.online.sberbank.ru:8098/; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnweb.sbermobile.ru *.yandex.net *.trbcdn.net top-fwz1.mail.ru api.flocktory.com *.top100.ru *.adriver.ru px.adhigh.net cdn.rutarget.ru yastatic.net *.maps.yandex.net suggest-maps.yandex.ru api-maps.yandex.ru *.otm-r.com www.google-analytics.com ajax.googleapis.com fonts.googleapis.com *.mc.yandex.ru mc.yandex.ru nlb-clickstream.sberbank.ru sp.otm-r.com stats.g.doubleclick.net www.google-analytics.com www.google.ru www.googletagmanager.com ; img-src 'self' data: www.gstatic.com cdnweb.sbermobile.ru adservings.ru api.flocktory.com top-fwz1.mail.ru kraken.rambler.ru api-maps.yandex.ru *.maps.yandex.net *.mc.yandex.com *.mc.yandex.ru mc.yandex.ru *.googleusercontent.com www.googletagmanager.com www.google.ru www.google.com www.google-analytics.com *.otm-r.com yandex.ru; base-uri 'self' cdnweb.sbermobile.ru; form-action 'self'; frame-ancestors 'none' 2 default-src 'self'; script-src 'self' https://*.adobedtm.com https://*.onetrust.com https://siteimproveanalytics.com https://*.jsdelivr.net https://*.libcal.com https://*.libanswers.com https://*.google.com https://www.google.com https://www.gstatic.com https://googletagmanager.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.google-analytics.com https://www.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://*.facebook.net https://www.facebook.com https://*.youtube.com https://www.youtube.com https://*.instagram.com https://www.instagram.com https://*.contentsquare.net https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://unsw.us6.list-manage.com https://*.tiqcdn.com https://*.eventbrite.com.au https://www.eventbrite.com.au https://*.twitter.com https://*.flickr.com https://*.hlx.page https://*.licdn.com https://www.tiktok.com https://*.tiktok.com https://www.googleadservices.com https://*.googleadservices.com https://googleadservices.com https://*.fouanalytics.com https://*.adsrvr.org https://*.doubleclick.net https://*.fls.doubleclick.net https://*.linkedin.com https://*.app-us1.com https://*.demdex.net https://*.hsforms.net https://*.hsforms.com https://*.dwcdn.net https://*.hs-scripts.com https://*.hs-banner.com https://*.hs-analytics.net https://*.mapbox.com https://*.mazemap.com https://*.matterport.com https://*.perplexity.ai https://*.scite.ai https://*.intercomcdn.com https://*.intercom.io https://*.b2c.com https://*.elfsight.com https://*.service.elfsight.com https://*.utils.elfsightcdn.com https://player.vimeo.com https://*.tableau.com https://*.cloudflare.com https://*.mathjax.org https://*.mailchimp.com https://*.amazonaws.com https://*.recaptcha.net https://www.recaptcha.net https://*.padlet.com https://scribehow.com https://*.flourish.studio wss://*.hotjar.com https://*.hotjar.com https://*.hotjar.io https://playvideo.qcloud.com https://*.vod-qcloud.com https://pingjs.qq.com https://*.taboola.com https://api.disqometer.com https://apps.mypurecloud.com.au/webchat https://*.shorthand.com https://iframely.shorthand.com https://*.clickdimensions.com https://*.benchplatform.com https://*.yimg.com https://*.credly.com https://www.credly.com data: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.fontawesome.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.dwcdn.net https://*.mazemap.com https://*.perplexity.ai https://*.scite.ai https://*.intercomcdn.com https://*.mailchimp.com data: blob: 'unsafe-inline'; font-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.fontawesome.com https://*.gstatic.com https://*.dwcdn.net https://*.perplexity.ai https://*.scite.ai https://*.intercomcdn.com https://*.fontshare.com https://*.alicdn.com https://*.cloudflare.com https://*.amazonaws.com data: blob:; connect-src 'self' https://*.funnelback.squiz.cloud https://*.adobedc.net https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://unsw.us6.list-manage.com https://*.google-analytics.com https://www.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.libcal.com https://*.libanswers.com https://*.onetrust.com https://*.google.com https://www.google.com https://*.doubleclick.net https://*.fls.doubleclick.net https://*.contentsquare.net https://*.linkedin.com https://*.ads.linkedin.com https://*.fouanalytics.com https://*.hlx.page https://*.demdex.net https://*.googleapis.com https://*.gstatic.com https://*.hsforms.net https://*.hsforms.com https://*.mapbox.com https://*.dwcdn.net https://*.b2c.com https://*.tiktok.com https://*.tiktokw.us https://*.facebook.net https://www.facebook.com https://www.googleadservices.com https://*.googleadservices.com https://googleadservices.com https://*.matterport.com https://*.hs-scripts.com https://*.hs-banner.com https://*.hs-analytics.net https://*.licdn.com https://*.mazemap.com https://*.perplexity.ai https://*.scite.ai https://*.intercomcdn.com https://*.intercom-messenger.com wss://*.intercom-messenger.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.intercom.io wss://*.intercom.io https://*.elfsight.com https://*.service.elfsight.com https://*.utils.elfsightcdn.com https://polyfilljs.org https://*.scribehow.com wss://*.hotjar.com https://*.hotjar.com https://*.hotjar.io https://playvideo.qcloud.com https://*.vod-qcloud.com https://*.taboola.com https://api.disqometer.com https://apps.mypurecloud.com.au/webchat wss://apps.mypurecloud.com.au/webchat https://*.adsrvr.org https://*.shorthand.com https://iframely.shorthand.com https://*.clickdimensions.com https://*.benchplatform.com https://*.yimg.com https://*.credly.com https://www.credly.com data: blob:; img-src * data: blob:; media-src * data: blob:; frame-ancestors 'self' https://*.telt.unsw.edu.au https://*.google.com https://www.google.com https://*.au.panopto.com; frame-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.forms.unsw.edu.au https://www.fonts.unsw.edu.au https://www.hostfiles.unsw.edu.au https://www.coursearchive.unsw.edu.au https://*.linkedin.com https://www.linkedin.com https://www.wrike.com https://login.microsoftonline.com https://*.google.com https://www.google.com https://*.youtube.com https://www.youtube.com https://*.mazemap.com https://*.soundcloud.com https://*.facebook.net https://www.facebook.com https://*.twitter.com https://*.eventbrite.com.au https://www.eventbrite.com.au https://*.spotify.com https://*.doubleclick.net https://*.fls.doubleclick.net https://*.hsforms.net https://*.hsforms.com https://*.matterport.com https://joom.ag https://*.joomag.com https://www.joomag.com https://*.service.anz https://unsw.au1.qualtrics.com https://*.smartsheet.com https://player.vimeo.com https://www.figma.com https://www.googletagmanager.com https://*.cs.link https://*.syd-2.linewize.net https://*.fliphtml5.com https://*.opendns.com https://*.tableau.com https://omny.fm https://*.theconversation.com https://*.zscalerone.net https://*.uri.sh https://*.dwcdn.net https://*.nogginapp.io https://*.mwginternal.com https://*.matterportvr.cn https://*.instagram.com https://www.instagram.com https://unsw.sharepoint.com https://*.ascentone.com https://*.maps.arcgis.com https://*.data.ictinternational.com https://www.sketch.com https://*.knightlab.com https://*.cloudfront.net https://*.tikee.io https://*.regionalpropertymarkets.com https://padlet.com https://*.app.carto.com https://scribehow.com https://*.shinyapps.io https://*.powerbi.com https://*.media.tumblr.com https://www.recaptcha.net https://*.gettyimages.com https://*.brevo.com https://mailchi.mp https://www.arcgis.com https://*.github.io https://*.media.tumblr.com https://*.au.panopto.com https://unswlibrary.libanswers.com https://vemcount.app https://*.shorthand.com https://iframely.shorthand.com https://fliphtml5.com https://*.campaign-archive.com https://*.adsrvr.org https://*.credly.com https://www.credly.com data: blob:; worker-src 'self' data: blob:; object-src 'self' https://www.youtube.com data: blob:; form-action 'self' https://*.hsforms.net https://*.hsforms.com https://*.civeng.unsw.edu.au https://unsw.us6.list-manage.com https://login.microsoftonline.com https://www.facebook.com; report-uri /bin/unsw/common/csp-violation-report/endpoint 2 frame-ancestors 'self'; report-to csp-endpoint 2 default-src 'none'; script-src icq.com c.icq.com cicq.org 1l-hit.mail.ru www.google-analytics.com buddyicon.foto.mail.ru www.googletagmanager.com top-fwz1.mail.ru 'sha256-DKOsdd00IXAHc7qK64HiC18YrB2K4SfiH8Sl6A9aFyg=' 'sha256-u4WiMVZhYDdCrFwB8Zn3gLba1EI3pqIlFYWFZfXJl2I=' 'sha256-ynzJCJTMBeZF6kbmzoI2rC+vDRozRAHxsPfAruxve88=' 'sha256-j51JRkq0bwz97Hd/1wJQsIy6/aX9cz16Xyp+M8FshTA=' 'self'; style-src c.icq.com icq.com cicq.org 'self' 'unsafe-inline'; img-src data: icq.com c.icq.com cicq.org api.icq.net www.google-analytics.com buddyicon.foto.mail.ru files.icq.com files.imgsmail.ru u.icq.net u.myteam.vmailru.net ub.icq.net ub.myteam.vmailru.net swa.icq.com stats.g.doubleclick.net 'self'; media-src data: icq.com c.icq.com cicq.org api.icq.net www.google-analytics.com files.icq.com api.icq.net files.imgsmail.ru u.icq.net u.myteam.vmailru.net ub.icq.net ub.myteam.vmailru.net 'self'; font-src icq.com c.icq.com cicq.org 'self'; connect-src privacy.icq.com icq.com top-fwz1.mail.ru 'self'; report-uri /system/error 2 connect-src https:; child-src https:; default-src https:; font-src data: https:; form-action https:; frame-ancestors 'self' *.ffxblue.com.au *.ffx.io *.afr.com *.cdn.ampproject.org *.platform.ink; frame-src https:; img-src https: data:; media-src blob: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; script-src-attr https: 'unsafe-eval' 'unsafe-inline'; script-src-elem https: 'unsafe-eval' 'unsafe-inline'; style-src https:; style-src-attr 'unsafe-inline'; style-src-elem https: 'unsafe-inline'; worker-src blob:; report-uri https://csp.ffx.io/; report-to csp-endpoint 2 default-src https: data: 'unsafe-inline' 'unsafe-eval'; report-uri /nmms/csp-reporting-lo 2 img-src 'self' data: www.gravatar.com https://i.ytimg.com https://i.vimeocdn.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://googletagmanager.com https://ssl.gstatic.com https://fonts.gstatic.com https://www.google.com https://cdn.cookielaw.org https://assets.worldwildlife.org; script-src 'self' 'nonce-swGJbkguq5Ip4yNm2xFFug==' https://cdn.cookielaw.org https://*.googletagmanager.com https://www.googletagmanager.com https://tagmanager.google.com https://*.gstatic.com https://challenges.cloudflare.com 'unsafe-inline' 'unsafe-eval'; manifest-src 'self'; style-src 'self' 'unsafe-inline' https://tagmanager.google.com https://fonts.googleapis.com https://www.gstatic.com https://www.google.com https://googletagmanager.com; default-src 'none'; connect-src 'self' https://releases.wagtail.org/latest.txt www.google.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://cdn.cookielaw.org https://geolocation.onetrust.com/ https://privacyportal.onetrust.com https://challenges.cloudflare.com; frame-src 'self' https://www.youtube-nocookie.com https://player.vimeo.com https://www.googletagmanager.com https://challenges.cloudflare.com; font-src 'self' data: https://fonts.gstatic.com 2 default-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; img-src 'self' https: data: image/*; frame-ancestors 'self' *.sunrise.ch; frame-src https: mailto:; connect-src https: wss: data:; font-src https: data:; media-src 'self' https:; worker-src blob:; report-uri https://www.sunrise.ch/csp-collector 2 frame-ancestors 'self' *.pdffiller.com *.signnow.com *.airslate.com; report-uri https://www.pdffiller.com/api_v3/security_report/cspViolationsReport?appKey=rs3dwgboso31.apps.marketing_pages 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: http:; script-src data: 'unsafe-inline' 'unsafe-eval' https: http: blob:; style-src data: 'self' 'unsafe-inline' https:; img-src data: 'self' https: blob: android-webview-video-poster:; font-src 'self' https: data:; connect-src 'self' data: https: wss: blob:; media-src data: https: blob:; object-src https:; child-src https: data: blob:; form-action https:; report-uri https://prod.bhaskarapi.com/api/1.0/web-backend/csp-report; 2 frame-ancestors 'self'; report-uri https://www.theaustralian.com.au/csp-reports 2 frame-ancestors 'self' https://*.kit.edu; report-uri /global-cgi-bin/csp-report; report-to csp-report 2 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tvsquared.com *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.teads.tv https://*.taboola.com https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://www.googleoptimize.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.tvsquared.com *.taboola.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.yimg.com https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.facebook.com https://www.googleoptimize.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.ru https://google.com.ua https://google.by https://google.pl https://www.google.com.cy https://*.googleapis.com https://stackadapt.com https://*.doubleclick.net https://pagead2.googlesyndication.com https://*.clarity.ms https://collect.worldoftanks.eu https://content-wg.gcdn.co https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com https://api.worldoftanks.eu ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 2 script-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; style-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; connect-src 'self'; font-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; img-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; default-src 'self' 2 default-src 'self' https://n8n.io data: 'unsafe-inline'; script-src 'self' 'sha256-4pl9dZH8ght2nZ3AX1mV23mwuukxsklzULVnAeIEKbg=' https://cdn.jsdelivr.net/npm/@webcomponents/webcomponentsjs@2.0.0/webcomponents-loader.js https://www.unpkg.com/lit@2.0.0-rc.2/polyfill-support.js https://cdn.jsdelivr.net/npm/@n8n_io/n8n-demo-component@latest/n8n-demo.bundled.js https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://static.cloudflareinsights.com/beacon.min.js/ static.cloudflareinsights.com https://script.tapfiliate.com/tapfiliate.js https://checkout.paddle.com/api/2.0/prices/; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com https://n8niostorageaccount.blob.core.windows.net https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://gravatar.com/avatar/; media-src https://n8niostorageaccount.blob.core.windows.net; connect-src 'self' https://api.n8n.io/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net; frame-src https://jobs.ashbyhq.com https://n8n-preview-service.internal.n8n.cloud https://www.recaptcha.net https://challenges.cloudflare.com https://www.linkedin.com https://buy.paddle.com; frame-ancestors 'none'; object-src 'none' 2 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' 'unsafe-eval'; base-uri 'none'; frame-ancestors 'self' 2 default-src 'self'; script-src 'report-sample' 'self' https://7052064.fs1.hubspotusercontent-na1.net https://a.omappapi.com https://app.hubspot.com https://assets.apollo.io https://cdn.demio.com https://cdn.propensity.com https://cdnjs.cloudflare.com https://code.jquery.com https://googleads.g.doubleclick.net https://import-cdn.default.com https://js.hscollectedforms.net https://js.navattic.com https://platform.linkedin.com https://s3-us-west-2.amazonaws.com https://snap.licdn.com https://static.hsappstatic.net https://www.googleadservices.com https://www.googletagmanager.com https://www.redditstatic.com https://js.hs-analytics.net https://js.hs-scripts.com; style-src 'report-sample' 'self' https://7052064.fs1.hubspotusercontent-na1.net https://ajax.googleapis.com https://cdn.demio.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://kit-free.fontawesome.com https://static.hsappstatic.net; object-src 'none'; base-uri 'self'; connect-src 'self' https://a.omappapi.com https://analytics.google.com https://aplo-evnt.com https://app.hubspot.com https://cp.hubspot.com https://forms.default.com https://forms.hsforms.com https://geo.demio.com https://js.hs-banner.com https://nucleus.default.com https://pixel-config.reddit.com https://px.ads.linkedin.com https://www.cloudflare.com https://www.google.com https://www.redditstatic.com https://z.omappapi.com https://api.hsforms.com https://api.hubapi.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://forms.hsforms.com https://play.hubspotvideo.com https://scheduler.default.com https://td.doubleclick.net https://www.googletagmanager.com; img-src 'self' https://a.omappapi.com https://alb.reddit.com https://forms-na1.hsforms.com https://forms.hsforms.com https://forms.hubspot.com https://googleads.g.doubleclick.net https://px.ads.linkedin.com https://static.hsappstatic.net https://track.hubspot.com https://www.google.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://6823595ee2a3634bf77e7bfe.endpoint.csper.io?builder=true&v=2; 2 base-uri 'self'; default-src 'self' *.atl-paas.net; script-src 'self' 'unsafe-inline' *.atl-paas.net https://recaptcha.net https://www.recaptcha.net https://accounts.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' *.atl-paas.net; img-src 'self' *.atl-paas.net; font-src 'self' *.atl-paas.net; frame-ancestors 'none'; form-action 'self'; report-uri https://web-security-reports.services.atlassian.com/csp-report/id-frontend; report-to csp-default-endpoint; connect-src 'self' *.atl-paas.net https://*.atlassian.com https://*.ingest.sentry.io; object-src 'none' 2 default-src 'self' 'unsafe-eval' 'unsafe-inline' https: blob:;style-src 'self' 'unsafe-inline' https: data:;connect-src https: wss:;frame-src https:;script-src 'unsafe-eval' 'unsafe-inline' https: blob: data:;font-src https: data:;img-src https: data: blob:;media-src https: blob:; report-uri /csp_rep 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://acsbapp.com https://snap.licdn.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://static.ads-twitter.com https://analytics.twitter.com https://connect.facebook.net https://cdn.cookielaw.org https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://cdnsecakmi.kaltura.com https://cdnapisec.kaltura.com http://cdnapi.kaltura.com https://cfvod.kaltura.com https://www.google-analytics.com https://cdn.jsdelivr.net https://script.crazyegg.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://bam.nr-data.net https://hm.baidu.com/hm.js https://www.clarity.ms https://www.googleadservices.com blob: https://vjs.zencdn.net/5.0/video.min.js https://analytics.tiktok.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' https: data; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://fonts.googleapis.com https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://script.crazyegg.com https://static.cloudflareinsights.com https://cdnapisec.kaltura.com https://cfvod.kaltura.com https://vjs.zencdn.net/5.0/video-js.min.css https://analytics.tiktok.com; frame-ancestors 'self'; report-uri /report-csp-violation 2 default-src 'self' *.sleeknote.com https://*.kindlycdn.com *.boozt.com *.klarna.com *.booztx.com wss://ws-eu.pusher.com:443 https://*.pusher.com checkout-cdn.avarda.com wss://sage.kindly.ai static.criteo.net wss://ws-eu.pusher.com https://*.kindly.ai *.booztcdn.com; script-src 'self' data: blob: *.rewardspay.com static.cloudflareinsights.com dp64mxip2za0c.cloudfront.net www.barilliance.net cdn.avo.app *.booztcdn.com www.googleoptimize.com www.googletagmanager.com analytics.tiktok.com *.clarity.ms cookie-cdn.cookiepro.com atemda.com hst.tradedoubler.com cdn.loadbee.com the.sciencebehindecommerce.com bat.bing.com *.zenaps.com s2.adform.net tagmanager.google.com vc.hotjar.io cdn.noibu.com *.sleeknote.com widget.eu.criteo.com tr.snapchat.com yastatic.net *.adyen.com googleads.g.doubleclick.net tracking.s24.com *.contentsquare.net cm.g.doubleclick.net *.issuu.com euob.isstarsbuilding.com cdn.cookielaw.org *.flixcar.com web-assets.stylitics.com s.pinimg.com pagead2.googlesyndication.com cdn.siftscience.com www.gstatic.com bam-cell.nr-data.net *.kronor.io www.googleadservices.com www.snapengage.com avdonl0p0checkout0fe.blob.core.windows.net 7276578.collect.igodigital.com www.awin1.com *.booztx.com connect.facebook.net bugcrowd.com track.adform.net www.datadoghq-browser-agent.com cdn.depict.ai ct.pinterest.com *.freshchat.com obseu.isstarsbuilding.com *.criteo.com www.dwin1.com d38knilzwtuys1.cloudfront.net *.klarnacdn.net *.klarna.com sc-static.net sslwidget.criteo.com assets.bugcrowdusercontent.com *.google.com dev.visualwebsiteoptimizer.com cdn.evgnet.com *.google-analytics.com *.booztcdn.com *.boozt.com privacyportal.onetrust.com s3.amazonaws.com maps.googleapis.com static.criteo.net *.tradedoubler.com swrap.tradedoubler.com chat.kindlycdn.com *.trustpilot.com www.google.com *.boozt.com tag.smartly.io bam.nr-data.net *.hotjar.com sdk.privacy-center.org geolocation.onetrust.com optimize.google.com lcx-embed.bambuser.com *.liveshopper.net widget.criteo.com 'unsafe-eval' 'unsafe-inline'; font-src 'self' cdn.honey.io *.booztx.com *.boozt.com fonts.gstatic.com cdnjs.cloudflare.com fonts.googleapis.com chat.kindlycdn.com avdonl0p0checkout0fe.blob.core.windows.net *.avarda.com data: *.booztcdn.com data: ; img-src optimize.google.com data: https: data: blob: 'unsafe-inline'; connect-src 'self' data: chat.kindlycdn.com *.google.com.pr www.bing.com www.googletagmanager.com *.google.com.kh bam.nr-data.net *.google.fr *.google.co.jp checkout-cdn.avarda.com wss://input.noibu.com *.google.com.eg *.google.by boozt.com *.google.com.ni *.criteo.net *.googleapis.com *.googleapis.com dev.visualwebsiteoptimizer.com *.loadbee.com *.google.mn *.google.com.lb *.google.be *.google.co.nz *.google.ps *.googleoptimize.com *.google-analytics.com *.google.com.tw *.google.com.cu analytics.tiktok.com *.google.com.np *.stylitics.com *.google.mk *.google.co.ke *.adzerk.net *.google.sk *.google.com.mt obseu.isstarsbuilding.com *.google.com.uy *.kronor.io *.google.ro *.analytics.google.com tr.snapchat.com *.google.lv *.google.com.au *.adform.net *.google.com.et wss://proxy.depict.ai:7315 *.google.com.ec *.google.md *.google.com.co *.google.ae analytics.sleeknote.com bot.kindly.ai *.google.co.zw translate.googleapis.com *.google.com.sa *.clarity.ms *.hotjar.com partner.revieve.com spk.boozt.com cdn.cookielaw.org *.snapchat.com *.onetrust.com *.google.ie vc.hotjar.io *.google.ch *.google.tn *.google.co.id *.google.cl *.google.mw *.datadoghq-browser-agent.com *.google.ba www.snapengage.com *.google.gl *.google.com.bo *.google.es *.google.co.th input.noibu.com *.avarda.com *.google.ci *.google.gr *.google.com.hk unpkg.com *.privacy-center.org *.criteo.net *.google.co.il *.google.am *.browser-intake-datadoghq.eu *.google.com.bh *.google.com *.evergage.com *.google.com.ar *.criteo.com *.google.com.ly adservice.google.com *.google.so *.booztx.com *.boozt.com *.google.co.tz *.google.com *.google.me *.google.mv *.clarity.ms google.com *.google.co.za api.depict.ai *.klarnacdn.net *.google.com.vn kronor.io bam-cell.nr-data.net www.getpica.com *.google.com.qa *.booztcdn.com *.logs.datadoghq.eu *.hotjar.io browser-intake-datadoghq.eu *.google.ru *.google.pt *.google.co.cr app.vwo.com *.google.com.tr *.google.lu *.contentsquare.net *.hotjar.com dawa.aws.dk *.google.lt sp.boozt.com *.doubleclick.net *.google.co.bw *.google.com.gh *.google.no *.sleeknote.com *.google.com.bd *.google.com.kw *.visualwebsiteoptimizer.com *.google.ge *.google.com.pe *.google.com.sg *.google.it pagead2.googlesyndication.com www.facebook.com wss://kronor.io *.google.al *.google.com.br *.google.com.ua *.google.co.vi *.google.co.ck www.googleadservices.com *.google.mu *.google.az stats.g.doubleclick.net *.google.bi *.google.lt *.google.com.na *.klarna.com *.google.ee *.google.cz *.google.com.pk *.google.gm *.google.fi *.hotjar.io media.flixfacts.com api.avo.app *.google.com.do *.google.sc *.google.rs *.google.hu *.google.si *.google.co.uz ct.pinterest.com *.google.sr *.google.iq *.google.co.zm *.google.hr *.google.tg *.google.co.uk *.google.lk *.google.com.jm *.google.kg *.google.com.af bat.bing.net *.google.pl *.google.com.ph *.google.nl *.google.cn *.google.cv wss://ws-eu.pusher.com *.contentsquare.com *.google.com.my *.google.bg fpt.boozt.com bat.bing.com *.google.is *.google.at *.google.com.mx *.google-analytics.com *.google.bt dev.visualwebsiteoptimizer.com *.klarnaevt.com code.jquery.com *.google.ca *.google.com.cy *.google.jo *.hotjar.com *.google.co.ma *.google.de *.adyen.com *.google.ga *.google.kz *.avarda.org; child-src 'self' td.doubleclick.net js.klarna.com tr.snapchat.com track.adform.net www.googletagmanager.com *.freshchat.com *.trustpilot.com static.criteo.net fpt.boozt.com *.google-analytics.com *.criteo.com *.hotjar.com blob: ; frame-src 'self' www.instagram.com *.secure2gw.ro *.otpbanka.hr *.sbanken.no *.fuib.com *.klarnacdn.net *.ing.ro td.doubleclick.net www.securesuite.co.uk static.criteo.net *.criteo.com static.criteo.net *.adyen.com widget.eu.criteo.com *.op.fi *.issuu.com www.facebook.com *.trustpilot.com *.edb.com *.rewardspay.com *.sibs.pt sc-static.net bid.g.doubleclick.net *.cardinalcommerce.com *.komplettbank.se www.rsa3dsauth.co.uk vc.hotjar.io *.snapchat.com *.skandia.se web.facebook.com *.nordea.com *.rpc-raiffeisen.com *.redsys.es trustly.com *.trustly.com *.freshchat.com *.booztcdn.com bugcrowd.com td.doubleclick.net *.saastopankki.fi *.lcl.fr the.sciencebehindecommerce.com *.komplettbank.com *.hcaptcha.co *.arcot.com gum.criteo.com xn--nskeskyen-k8a.dk *.klarna.com *.estcard.ee *.netcetera-payment.ch *.vinea.es optimize.google.com *.bpcbt.com lcx-player.bambuser.com *.hotjar.com *.alandsbanken.fi *.kronor.io *.wirecard.com *.signicat.com *.targobank.de *.swedbank.lt *.rabobank.nl player.vimeo.com *.sparebank1.no cdn.depict.ai *.boozt.com *.sia.eu *.sparkassen-kreditkarten.de *.modirum.com www.awin1.com *.danskebank.com *.btrl.ro gum.criteo.com *.zenaps.com widget.koral.nu assets.pinterest.com www.facebook.com *.fio.cz *.nexi.it td.doubleclick.net *.3dsecure.no *.wlp-acs.com staticxx.facebook.com *.loadbee.com *.nbg.gr ct.pinterest.com *.swedbank.se *.flixcar.com *.eewosecure.com acs-safekey.americanexpress.com track.adform.net dis.eu.criteo.com www.googletagmanager.com *.citadele.lv *.booztx.com www.getpica.com *.touch.tech *.luottokunta.fi *.creditmutuel.fr *.cmbchina.com; style-src 'self' *.freshchat.com *.adyen.com cdn.cookielaw.org privacyportal.onetrust.com *.booztx.com *.booztcdn.com optimize.google.com *.boozt.com fonts.googleapis.com d38knilzwtuys1.cloudfront.net tagmanager.google.co geolocation.onetrust.com *.stylitics.com *.kronor.io chat.kindlycdn.com *.flixcar.com cdn.honey.io cookie-cdn.cookiepro.com translate.googleapis.com blob: data: blob: 'unsafe-inline'; manifest-src 'self' *.booztx.com *.boozt.com *.booztcdn.com; media-src 'self' data: *.booztcdn.com storage.googleapis.com *.booztx.com www.snapengage.com; frame-ancestors 'self' ; report-uri /csp-report/; report-to csp-reports 2 frame-ancestors gofundme.com *.gofundme.com *.hopin.com pillar.io *.pillar.io takethemameal.com *.takethemameal.com kudoboard.com *.kudoboard.com werememberdev.com *.werememberdev.com weremember.com *.weremember.com forevermissed.com *.forevermissed.com fm-stage.com *.fm-stage.com fm-qa.com *.fm-qa.com; 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://robbreport.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 frame-ancestors 'self'; report-uri https://www.dailytelegraph.com.au/csp-reports 2 base-uri 'self'; default-src 'self' data: https://*.emcd.io https://at.alicdn.com https://cdn.carrotquest.app https://cdn.fontshare.com https://cdn.megabonus.com https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.intercomcdn.com https://js.intercomcdn.com https://maxcdn.bootstrapcdn.com https://mc.yandex.com https://pouch-global-font-assets.s3.eu-central-1.amazonaws.com https://telegram.org https://use.fontawesome.com https://use.typekit.net https://www.cdn-tinkoff.ru; object-src 'none'; worker-src 'none' blob:; manifest-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://*.emcd.io https://accounts.google.com https://www.google-analytics.com https://www.google.com/recaptcha/api.js https://www.googletagmanager.com https://www.recaptcha.net https://www.gstatic.com https://www.gstatic.cn https://mc.webvisor.org https://mc.yandex.com https://mc.yandex.ru/ https://cdn.jsdelivr.net/npm/yandex-metrica-watch/tag.js https://js.intercomcdn.com https://widget.intercom.io https://telegram.org/js/pixel.js https://telegram.org/js/telegram-web-app.js https://telegram.org/js/telegram-widget.js?22 https://af.click.ru/ https://ajax.cloudflare.com https://analytics.dev.mind-dev.com https://cdn.carrotquest.app https://cdn.segment.com https://cloud.roistat.com https://connect.facebook.net https://edge.fullstory.com https://*.programmatica.com https://script.marquiz.io https://script.marquiz.ru https://snap.licdn.com/li.lms-analytics/insight.min.js https://v1.slise.xyz https://widgets.outbrain.com https://appleid.cdn-apple.com/appleauth/ https://snap.licdn.com; style-src 'self' 'unsafe-inline' 'report-sample' https://telegram.org https://fonts.googleapis.com https://accounts.google.com https://mc.yandex.ru; img-src 'self' data: https://*.emcd.io https://fonts.gstatic.com https://www.googletagmanager.com https://www.gstatic.com https://mc.webvisor.org https://mc.yandex.by https://mc.yandex.com https://mc.yandex.kz https://mc.yandex.ru https://mc.yandex.uz https://yastatic.net https://*.intercomcdn.com https://messenger-apps.intercom.io https://static.intercomassets.com https://app.getbeamer.com https://cdn4.telesco.pe https://px.ads.linkedin.com https://sync.programmatica.com https://www.facebook.com https://t.me/i/userpic; frame-src 'self' data: https://accounts.google.com https://www.google.com https://www.googletagmanager.com https://www.recaptcha.net https://mc.yandex.com https://mc.yandex.ru https://intercom-sheets.com https://www.intercom-reporting.com/ https://af.click.ru https://emet.live https://emet.news https://eu.id.group-ib.com https://oauth.telegram.org https://payments.mercuryo.io https://quiz.marquiz.io https://quiz.marquiz.ru https://www.youtube.com; connect-src 'self' data: https://*.emcd.io wss://*.emcd.io https://accounts.google.com https://play.google.com https://translate.googleapis.com https://www.google-analytics.com https://www.recaptcha.net https://mc.yandex.com https://mc.yandex.md https://mc.yandex.ru https://translate.yandex.net wss://mc.yandex.ru https://uploads.intercomcdn.com wss://nexus-websocket-a.intercom.io https://browser.sentry-cdn.com https://o1144246.ingest.sentry.io https://o1144246.ingest.us.sentry.io https://api.segment.io https://cdn.segment.com https://oauth.telegram.org https://telegram.org/pxl https://adtonus.com https://analytics.dev.mind-dev.com https://api.carrotquest.app https://code.jquery.com https://containers.programmatica.com https://endpoint.em-app.tech https://infragrid.v.network https://ipapi.co https://px.ads.linkedin.com https://rktds.net https://*.fullstory.com https://v1.slise.xyz https://www.facebook.com https://*.intercom.io/ https://www.google.com/recaptcha https://mpc-prod-1-1053047382554.us-central1.run.app; report-uri https://cspr.emcd.io/; 2 default-src * data: ; script-src * 'unsafe-inline' 'unsafe-eval' ; style-src * 'unsafe-inline' data: ; frame-ancestors 'none'; report-uri /csp-violation-report-endpoint/ 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.quechoisir.org *.qccdn.fr *.tagcommander.com *.commander1.com *.trustcommander.net *.aticdn.net *.xiti.com *.bing.com *.google.com *.youtube.com *.youtu.be www.youtube-nocookie.com *.facebook.com *.kameleoon.io *.kameleoon.eu *.xiti.com *.aticdn.net *.facebook.net flo.uri.sh public.flourish.studio wss://dl1.quechoisir.org wss://dl2.quechoisir.org wss://dl.quechoisir.org upgrade-insecure-requests; report-uri https://www.quechoisir.org/csp-violation-report-endpoint/; report-to csp-endpoint> 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.arcelik.com.tr https://www.google.com https://cdn.cookielaw.org https://www.clarity.ms https://d2ztbiegtp19vn.cloudfront.net https://cdn.evgnet.com https://configs.glov.ai https://c.la1-c2-cdg.salesforceliveagent.com https://w.usabilla.com https://www.googletagmanager.com https://scripts.clarity.ms https://cdn.jsdelivr.net https://scripts.agilone.com https://maps.googleapis.com https://ui.swogo.net https://platform.poltio.com https://googleads.g.doubleclick.net https://bat.bing.com https://d6tizftlrpuof.cloudfront.net https://s.go-mpulse.net https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com https://cdn.taboola.com https://s.pinimg.com https://sslwidget.criteo.com https://analytics.tiktok.com https://connect.facebook.net https://*.useinsider.com https://trc.taboola.com https://dynamic.criteo.com https://platform.twitter.com https://poltio.arcelik.com.tr https://d.la1-c2-fra.salesforceliveagent.com https://ct.pinterest.com https://s2.adform.net https://track.adform.net https://tags.creativecdn.com https://*.mathrics.com https://www.google-analytics.com https://go.assistbox.io https://service.force.com https://www.gstatic.com https://storage.googleapis.com https://unpkg.com https://rum-static.pingdom.net https://static.ads-twitter.com https://p.teads.tv https://cdn.enhencer.com https://arc-astra.c1m0wu3z2z-arcelikas1-p1-public.model-t.cc.commerce.ondemand.com 2 default-src 'self' https://themes.googleusercontent.com/ https://apps.geodan.nl https://acc.apps.geodan.nl https://platform.twitter.com/ https://syndication.twitter.com/ http://www.rovid.nl https://geodata.rivm.nl https://statistiek.rijksoverheid.nl https://mebi.rivm.nl https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://chemkap.rivm.nl https://app.powerbi.com/ https://api.pdok.nl/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://statistiek.rijksoverheid.nl http://platform.twitter.com/ https://cdn.syndication.twimg.com https://mebi.rivm.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://apps.rivm.nl https://chemkap.rivm.nl https://*.mopinion.com https://api.pdok.nl/; object-src https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://app.powerbi.com/ https://api.pdok.nl/; style-src 'self' 'unsafe-inline' https://platform.twitter.com/ https://ton.twimg.com/ https://mebi.rivm.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://*.mopinion.com https://data.rivm.nl/ https://api.pdok.nl/; img-src 'self' https://rivm.nl/ https://*.rivm.nl/ https://statistiek.rijksoverheid.nl/ https://geodata.nationaalgeoregister.nl/ https://syndication.twitter.com/ https://pbs.twimg.com/ https://ton.twimg.com/ https://abs.twimg.com/ https://platform.twitter.com/ http://abs.twimg.com/ data: http://www.rovid.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://service.pdok.nl/ https://data.rivm.nl/ https://*.openstreetmap.org/ https://chemkap.rivm.nl https://api.pdok.nl/; frame-src 'self' https://cibrapportage.rivm.nl https://esp-ext.rivm.nl https://login-ext.rivm.nl https://chemkap.rivm.nl https://www.infectieradar.nl https://app.powerbi.com https://api.pdok.nl/; frame-ancestors 'self' https://www.atlasleefomgeving.nl https://*.gezondeleefomgeving.nl https://*.woondossier.nl/ https://roosendaal.incijfers.nl https://*.nhnieuws.nl https://chemkap.rivm.nl https://www.infectieradar.nl https://api.pdok.nl/*; child-src https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://app.powerbi.com https://api.pdok.nl/; font-src 'self' https://rivm.nl/ https://*.rivm.nl/ https://themes.googleusercontent.com/ https://cstm.rivm.nl/ https://*.mopinion.com https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://api.pdok.nl/; connect-src 'self' https://mebi.rivm.nl/ https://statistiek.rijksoverheid.nl/ https://statistiek.rijksoverheid.nl/* https://cstm.rivm.nl/ https://cstm.rivm.nl/* https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://acc-api.rivm.nl https://api.rivm.nl/ https://api.pdok.nl/* https://*.mopinion.com; report-uri /report-csp-violation 2 default-src https: ; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; report-uri /csp/ 2 : default-src 'self'; report-uri https://mtsrs.report-uri.com/r/d/csp/reportOnly; 2 default-src 'self'; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https:; object-src 'self' https:; style-src 'self' data: 'unsafe-inline' https:; img-src 'self' data: blob: https:; media-src 'self' data: blob: https:; frame-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' data: https:; 2 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 2 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https://* data: ; frame-src https://* about: javascript: 2 font-src 'self'; frame-src 'self'; img-src 'self' data: https://img.airtel.tv https://moe-email-campaigns.s3.amazonaws.com https://image.moengage.com; style-src report-sample 'self' 'unsafe-inline'; script-src report-sample 'self' 'unsafe-inline' https://app.link/_r https://cdn.branch.io/branch-latest.min.js https://www.googletagmanager.com/gtag/js https://cdn.moengage.com/webpush/moe_webSdk.min.latest.js https://cdn.moengage.com/webpush/modules/inapp.js https://cdn.moengage.com/webpush/beta/sdk.inapp.cdnHelper.js https://cdn.moengage.com/webpush/releases/serviceworker_cdn.min.latest.js https://cdn.moengage.com/webpush/moe_webSdk_cards.min.latest.js https://cdn.moengage.com/webpush/moe_webSdk_webp.min.latest.js; 2 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-J3CK_S4dtXSViBhPy_zwpA'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-J3CK_S4dtXSViBhPy_zwpA'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: logger.scot.nhs.uk *.fontawesome.com use.typekit.net *.google.com *.google.co.uk *.googleapis.com themes.googleusercontent.com *.gstatic.com code.jquery.com yui.yahooapis.com *.bootstrapcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com www.youtube-nocookie.com player.vimeo.com i.vimeocdn.com cdn.jwplayer.com content.jwplatform.com prd.jwpltx.com *.jwpcdn.com *.jwpsrv.com *.civiccomputing.com cc.cdn.civiccomputing.com secure.gravatar.com public.tableau.com www.openstreetmap.org browser-update.org s.w.org www.geoplugin.net *.wp.com hcaptcha.com *.hcaptcha.com www.careopinion.org.uk www.patientopinion.org.uk assets.nhs.uk www.travelinescotland.com; worker-src 'self' www.google.com; frame-ancestors 'self'; base-uri 'self'; report-to csp-endpoint; report-uri https://web-reports.scot.nhs.uk/api/v1/csp-report 2 default-src 'self'; img-src *; style-src 'unsafe-inline'; script-src 'unsafe-inline' 'unsafe-eval' 2 img-src https:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; 2 report-uri https://partnerize.com?gdsih-csp-report; 2 default-src * 'unsafe-inline' 'unsafe-eval' blob:; frame-src *; img-src * data:; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval' blob:; style-src * 'report-sample' 'unsafe-inline'; base-uri *; form-action *; frame-ancestors 'self' 2 default-src 'self' disney.okta.com sso.myid.disney.com *.oktacdn.com; connect-src 'self' disney.okta.com disney-admin.okta.com sso.myid.disney.com *.oktacdn.com *.mixpanel.com *.mapbox.com disney.kerberos.okta.com disney.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' disney.okta.com sso.myid.disney.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' disney.okta.com sso.myid.disney.com *.oktacdn.com; frame-src 'self' disney.okta.com disney-admin.okta.com sso.myid.disney.com login.okta.com *.vidyard.com com-okta-authenticator: api-5a45a87b.duosecurity.com; img-src 'self' disney.okta.com sso.myid.disney.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' disney.okta.com sso.myid.disney.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://data.disneystreaming.com https://data-staging.disneystreaming.com https://data-dev.disneystreaming.com https://outlooksts.disney.com 2 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.drip.com *.hsappstatic.net *.sleeknote.com *.zdassets.com *.zendesk.com *.hubspot.com *.hubspot.net *.hs-analytics.net *.hs-banner.com *.cloudflare.com *.zi-scripts.com *.g2crowd.com unpkg.com *.tiktok.com *.quora.com *.bing.com *.redditstatic.com *.ads-twitter.com *.licdn.com *.facebook.net *.snapchat.com sc-static.net *.clearbitscripts.com *.dreamdata.cloud *.g2.com ai.g2.com; connect-src 'self' *.drip.com ai.g2.com; 2 form-action *.facebook.com; default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: *.fls.doubleclick.net *.doubleclick.net *.hotjar.com *.hotjar.io wss://*.hotjar.com *.omtrdc.net *.twitter.com covers.odilo.io *.ads-twitter.com *.facebook.com *.facebook.net cdn.cookielaw.org *.googletagmanager.com *.googleadservices.com online.bancosantander.es a.omappapi.com *.googleapis.com extend.vimeocdn.com t.co adservice.google.com *.linkedin.com *.google-analytics.com *.santanderopenacademy.com *.universia.net fonts.gstatic.com in-automate.sendinblue.com z.omappapi.com api.omappapi.com snap.licdn.com images.findawayworld.com *.tiktok.com privacyportal-de.onetrust.com sibautomation.com use.typekit.net pro-becas-images-s3.s3.eu-west-1.amazonaws.com santander-privacy.my.onetrust.com; frame-ancestors 'self' *.santanderopenacademy.com *.googletagmanager.com; connect-src 'self' cdn.equalweb.com *.universia.net pro-becas-images-s3.s3.eu-west-1.amazonaws.com www.linkedin.com script.hotjar.com img.youtube.com px4.ads.linkedin.com t.co surveystats.hotjar.io analytics.twitter.com www.google.es mboxedge37.tt.omtrdc.net santanderuniversidad.tt.omtrdc.net www.googletagservices.com www.google.ie www.facebook.com cdn.cookielaw.org googleads.g.doubleclick.net stats.g.doubleclick.net www.google.com pagead2.googlesyndication.com *.analytics.google.com vc.hotjar.io metrics.hotjar.io wss://ws.hotjar.com ws.hotjar.com content.hotjar.io *.google-analytics.com px.ads.linkedin.com analytics.tiktok.com *.pangle-ads.com *.omappapi.com *.vimeo.com *.santanderopenacademy.com *.googlesyndication.com *.onetrust.com *.tiktokw.us sc-static.net *.sc-static.net snapchat.com *.snapchat.com onetrust.com *.onetrust.com omtrdc.net *.omtrdc.net analytics.google.com *.google.com *.adoberesources.net adoberesources.net *.adobedc.net adobedc.net *.demdex.net demdex.net; font-src 'self' script.hotjar.com fonts.gstatic.com data:; frame-src 'self' www.youtube.com www.google.com *.doubleclick.net track.adform.net www.facebook.com *.universia.net universia.net *.santanderopenacademy.com *.vimeo.com doubleclick.net *.doubleclick.net; img-src 'self' data: *.santanderopenacademy.com *.santanderx.com dss.hybrid.ai su-commons-documents.s3.eu-west-1.amazonaws.com pro-becas-images-s3.s3.eu-west-1.amazonaws.com i.ytimg.com non-productive-alfred-s3.s3.eu-west-1.amazonaws.com *.universia.net img.youtube.com cdn.cookielaw.org www.facebook.com fonts.gstatic.com www.google.ie www.google.com www.google.es *.googletagmanager.com *.google-analytics.com px.ads.linkedin.com px4.ads.linkedin.com t.co analytics.twitter.com covers.odilo.io images.findawayworld.com *.doubleclick.net *.odilotk.es *.googlesyndication.com snapchat.com *.snapchat.com; manifest-src 'self'; media-src 'self' data: *.santanderopenacademy.com *.santanderx.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' emd.hybrid.ai *.hybrid.ai pixel.wp.pl www.google.com 'sha256-YSegCmpoY/9vy6z9Jp/wY5F+2CZOSO85IpkqRDamw6o=' 'sha256-8UQUF8T5SdG0xN7U0SziZK/tE7Mx20WlIEvrhPZS+5c=' 'sha256-ZC4Ihfl+1sv3E25DQh090ITQKwffxiocyA9C1vaePKU=' 'sha256-y+EdpRp7NGzuxDREjdSGXuM2ZRxY/zPRIps6hzHQOcU=' 'sha256-ZC4Ihfl+1sv3E25DQh090ITQKwffxiocyA9C1vaePKU=' 'sha256-HbtNuErO4Ji0X7sd59L8NfJYuQk3WllCWK3gVuRMpfM=' 'sha256-BBirXJiJdwXRuf4PKdCNfYQLT8mhwGu68gkk2lfCqN8=' 'sha256-9gh4m8bsTLdMvKZ358mYZY2d+f5k+bk+APY/b3jwy1o=' 'sha256-xeKH9HwGHVm84iWqrxisQix9T08PGSCZTxFIO4+ewWk=' 'sha256-DwzQ63XCPWPBU9VhenPaZeU1L0tiiqJkkaWArzaMA14=' 'sha256-5t573MY7H7LQK71Vf2b+RoOG9NlBxHctIHdMjVPJIE0=' 'sha256-ZxrnaNw21FtNs0hG3ejrGPJWMFqp2c2scn3dGBS7Xtk=' 'sha256-DaJ5+aVVCCwmIoJpsto8Q2FfkqVlML3utJdn4mDMGD0=' 'sha256-Fj/OzUbSCuycXsQO3rkxgJpOQcr0O4grKcZDUi0FIiU=' 'sha256-L89rOqVn3e1Yeav7YFzFH7bxGr1IyHtjhNxYvrcVL4E=' 'sha256-g2T0Peh4PkAjcTj+CFHeM0y83Uuh+6W/+Ay4nUyncSo=' 'sha256-BpTz1JC47PMe4NhdM7n0gmuvr+83Jo3c+LLXav8o+Wc=' 'sha256-+i46atGTJGrevoy/LaA/uxqfIvacu6J/34f4LYs4FLU=' 'sha256-NW1gvrymt4M+SBgRpB7GKpbvkiAcBF120jBugIgwTkY=' 'sha256-TCOS0LXlyOYGx+xlpfAYkRxyaOiYLTlRzHwI0YQSm3Q=' 'sha256-XdoX181xfRJT12LmChyU6l4zxvoIsaAHf4FxTHoJM+I=' 'sha256-NKT4ofJEPzU1gDi1WITFInJvz8potrsIe5i+LSnCKqo=' 'sha256-w6kdg/3YV4tBVkaDe4i2aktYPtaPLEHNIGHKOXJ7aZI=' 'sha256-7OI/iFnRHuxJU3EbXDhDFX6g3cZ0C1I8U6VTbbk7bPw=' 'sha256-VY8NVZZ8EZKkngWGPFlpnC0jlPPS4naDQeeIKqLpgUU=' 'sha256-3ThNsno0lln5H88qDcBDPljNxQaOgkPiulXpM/OsV1s=' 'sha256-8N1I80yqbb8/sRov2zmhZf1nwe9Hd8PifhnSJaDP664=' 'sha256-LG4xcV34tsaAdFNYuH8Lr84Ovn0ZnSV2GoIA+TiLP5s=' 'sha256-y36RoFUJWgc8gbl/5Pk2/0bsYv2bJ+bMa8Y4LV/Wz/k=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-3FPxyKucOIUnwkis1jUlVWeg63ttBCdsnPZ7d1/U9vQ=' 'sha256-lBxE5qVCAIfADFr1+pdyVxAP7I/YVviosUAsCf3pZtU=' 'sha256-3iXpidN34sHSaOL+oY8lqqkqIs8qgMSZmmFOyyyJq5o=' 'sha256-TZjz12EnkJLarfuyWy8NqZ9HG8RpIuFAlQySbT4/4h8=' 'sha256-Y4y/Z3pJNei7wFfh20klvIrbZiajvE/JWO1KhI668Xo=' 'sha256-LigV2Z6/JVA57qW0q8wSx849ylkhI35JZTPqGObl9ks=' 'sha256-83sIN1kEH+EziQHRTaQiSWImOUtv0wFFfa74npfXyoE=' 'sha256-BMIPp0uCJPYMdHFyQdug09fBOv1yC4c3ATQ5HIB8lnU=' 'sha256-mkZ77JgvPSMOW/FuYQr4tf+Z2qIq0e/ozaNEcVp9eyc=' cdn.jsdelivr.net cdn.equalweb.com code.jquery.com track.adform.net s2.adform.net www.googletagservices.com cdn.cookielaw.org googleads.g.doubleclick.net connect.facebook.net static.hotjar.com metrics.hotjar.io script.hotjar.com *.googletagmanager.com *.google-analytics.com snap.licdn.com static.ads-twitter.com analytics.tiktok.com *.googleapis.com pro-becas-images-s3.s3.eu-west-1.amazonaws.com *.gstatic.com *.omappapi.com *.googleadservices.com *.santanderopenacademy.com *.googlesyndication.com sc-static.net *.sc-static.net snapchat.com *.snapchat.com onetrust.com *.onetrust.com omtrdc.net *.omtrdc.net analytics.google.com *.google.com *.adoberesources.net adoberesources.net *.adobedc.net adobedc.net *.demdex.net demdex.net st.hybrid.ai; style-src 'self' 'unsafe-inline' stackpath.bootstrapcdn.com *.googletagmanager.com fonts.googleapis.com *.omappapi.com; worker-src *.universia.net 2 report-uri https://csp-report.siteminder.com/api/quokka/booking-engine/report; report-to cspendpoint; default-src 'none'; connect-src 'self' *.siteminder.com 123compareme.com *.123compareme.com *.ada-tray.com *.bookmebob.com *.flip.to *.gtsgapps.com *.hijiffy.com messenger-services.com *.sojern.com *.thehotelsnetwork.com *.triptease.io *.triptease.net *.userguest.com *.theguestbook.com connect.facebook.net *.facebook.com *.edge.sdk.awswaf.com *.paypal.com recaptcha.net *.launchdarkly.com *.newrelic.com bam.nr-data.net *.hotjar.com *.hotjar.io *.googletagmanager.com *.gstatic.com *.google-analytics.com *.google.com *.googlesyndication.com *.googleadservices.com *.g.doubleclick.net *.doubleclick.net *.imgix.net; script-src 'self' 123compareme.com *.123compareme.com *.ada-tray.com *.adatray.com *.bookmebob.com *.flip.to *.gtsgapps.com *.hijiffy.com *.sojern.com *.thehotelsnetwork.com *.triptease.io *.triptease.net *.userguest.com theguestbook.com *.theguestbook.com connect.facebook.net *.edge.sdk.awswaf.com *.paypal.com recaptcha.net *.launchdarkly.com *.newrelic.com bam.nr-data.net *.hotjar.com *.googletagmanager.com *.gstatic.com *.gstatic.cn *.google-analytics.com *.google.com *.googlesyndication.com *.googleadservices.com *.g.doubleclick.net *.doubleclick.net; frame-src 'self' recaptcha.net www.googletagmanager.com *.paypal.com *.triptease.io; img-src 'self' *.imgix.net *.siteminder.com *.paypalobjects.com *.googletagmanager.com *.openstreetmap.org *.adatray.com *.thehotelsnetwork.com data:; style-src 'self' 'unsafe-inline' *.adatray.com *.thehotelsnetwork.com *.userguest.com fonts.googleapis.com; font-src 'self' data: *.adatray.com *.thehotelsnetwork.com *.userguest.com fonts.gstatic.com 2 default-src *; font-src 'self' https: data:; img-src * blob: data:; object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-attr 'self' 'unsafe-inline'; style-src * 'unsafe-inline'; base-uri 'self'; form-action 'self' http://*.enterprisedb.com http://enterprisedb.com http://enterprisedb.okta.com; frame-ancestors 'self'; report-uri https://enterprisedb.com/log-report-uri/reportOnly 2 default-src * 'self' data: 'unsafe-inline' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.adsrvr.org *.afterpay.com *.amazon-adsystem.com *.braintreegateway.com *.confirmit.com *.g.doubleclick.net *.liveperson.net *.lpsnmedia.net *.paypal.com *.paypalobjects.com *.px-cloud.net *.quantcount.com *.quantserve.com *.quantummetric.com *.rakuten.com *.sundaysky.com *.taboola.com *.visualwebsiteoptimizer.com *.yottaa.com analytics.tiktok.com apis.google.com applepay.cdn-apple.com assets.adobedtm.com bat.bing.com blob: boards.greenhouse.io cdn-fsly.yottaa.net cdn.jsdelivr.net client.px-cdn.net colrep.sitelabweb.com connect.facebook.net ct.pinterest.com gs.nmgassets.com js.narvar.com maps.googleapis.com pixel.admedia.com s.pinimg.com s3-us-west-2.amazonaws.com sc-static.net tr.snapchat.com trc.taboola.com wasm-eval www.google.com www.googleadservices.com www.googletagmanager.com www.redditstatic.com https://*.zineone.com *.wandzcdn.com *.wandzapi.com *.niceincontact.com *.windows.net; style-src 'self' data: 'unsafe-inline' fonts.googleapis.com www.gstatic.com *.paypalobjects.com https://*.zineone.com *.niceincontact.com; connect-src 'self' *.tiktokw.us *.lpsnmedia.net www.googleadservices.com *.800svc.net *.800svctest.net www.facebook.com google.com *.1800contacts.com *.1800contactstest.com *.adsrvr.org *.afterpay.com *.amazon-adsystem.com *.analytics.google.com *.braintree-api.com *.braintreegateway.com *.confirmit.com *.demdex.net *.g.doubleclick.net *.google-analytics.com *.ispot.tv *.liveperson.net *.paypal.com *.buttercms.com *.px-cdn.net *.px-client.net *.px-cloud.net *.pxchk.net *.quantcount.com *.quantserve.com *.quantummetric.com *.quick-renew.com *.reddit.com *.snapchat.com *.sundaysky.com *.taboola.com *.visualwebsiteoptimizer.com *.yottaa.net analytics.google.com analytics.tiktok.com ara.paa-reporting-advertising.amazon assets.adobedtm.com bat.bing.net collector-a.perimeterx.net colrep.sitelabweb.com ct.pinterest.com d.agkn.com gs.nmgassets.com js.narvar.com maps.googleapis.com pips.taboola.com psb.taboola.com s.pinimg.com session.sitelabweb.com ws: www.google.com www.redditstatic.com *.applicationinsights.azure.com https://*.zineone.com wss://*.zineone.com *.wandzcdn.com *.wandzapi.com *.niceincontact.com *.windows.net; report-uri https://1800contacts.report-uri.com/r/t/csp/reportOnly 2 default-src 'self' http: https: data: blob: 'unsafe-eval' 'unsafe-inline'; frame-ancestors 'self'; 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; media-src https: http: rtsp: rtmp: data:; report-uri /csp-report 2 default-src 'self' 'unsafe-inline' data: *.squaretrade.com *.facebook.com *.outbound.io *.auth0.com *.launchdarkly.com *.pndsn.com *.googleapis.com *.google.com *.googletagmanager.com *.google-analytics.com https://api.segment.io https://api.amplitude.com https://privacyportal-eu.onetrust.com https://secure.shippingapis.com https://st-prod-enc-ship-usw-ca.s3.us-west-1.amazonaws.com https://st-prod-enc-ship-use-oh.s3.us-east-2.amazonaws.com https://st-stage-enc-cust-docs-use-oh-1.s3.us-east-2.amazonaws.com https://callback.vhtcx.com https://callback.virtualhold.com https://siteintercept.qualtrics.com https://squaretrade.my.site.com https://squaretrade--qa.sandbox.my.salesforce-scrt.com https://squaretrade--qa.sandbox.my.site.com; form-action 'self' data: *.squaretrade.com *.force.com *.salesforce.com *.auth0.com; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.squaretrade.com *.auth0.com https://cdn.segment.com *.bootstrapcdn.com *.force.com *.salesforce.com *.qualtrics.com https://platform.twitter.com; font-src 'self' data: *.squaretrade.com https://fonts.gstatic.com https://use.typekit.net; img-src 'self' data: *.squaretrade.com *.auth0.com *.facebook.com https://p.typekit.net *.google.com *.twitter.com https://st-prod-enc-ship-usw-ca.s3.us-west-1.amazonaws.com https://st-prod-enc-ship-use-oh.s3.us-east-2.amazonaws.com https://cdn.cookielaw.org https://www.googletagmanager.com https://fonts.gstatic.com https://pay.google.com https://checkoutshopper-test.cdn.adyen.com https://m.media-amazon.com https://bfasset.costcostatic.com https://maps.googleapis.com; style-src-elem 'self' 'unsafe-inline' *.squaretrade.com https://hello.myfonts.net https://service.force.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://static.smartrecruiters.com https://cdn.jsdelivr.net *.bootstrapcdn.com https://www.googletagmanager.com *.my.site.com https://www.gstatic.com; script-src-elem 'self' *.squaretrade.com 'unsafe-inline' *.salesforceliveagent.com https://cdn.segment.com https://cdn.amplitude.com https://cdn.outbound.io https://connect.facebook.net https://www.googletagmanager.com https://service.force.com https://use.typekit.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com https://code.jquery.com https://ajax.googleapis.com https://platform.twitter.com *.bootstrapcdn.com https://cdn.jsdelivr.net *.smartrecruiters.com https://player.vimeo.com https://zn8jglatqcy5dkma1-squaretrade.siteintercept.qualtrics.com https://*.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://cdn.cookielaw.org https://www.youtube.com https://uat-api.paylution.com https://api.paylution.com https://zingtree.com https://squaretrade--qa.sandbox.my.site.com https://maps.googleapis.com; frame-src 'self' *.squaretrade.com https://service.force.com https://squaretrade.az1.qualtrics.com/ https://www.google.com https://www.facebook.com https://platform.twitter.com *.doubleclick.net https://www.googletagmanager.com https://zingtree.com https://www.youtube.com https://checkoutshopper-test.adyen.com https://squaretrade--qa.sandbox.my.site.com https://squaretrade.my.salesforce-scrt.com; connect-src 'self' *.squaretrade.com *.auth0.com https://cdn.cookielaw.org https://www.google.com https://privacyportal-eu.onetrust.com https://cdn.segment.com https://cdn.segment.io https://api.segment.io https://uat-api.paylution.com https://checkoutshopper-test.adyen.com https://checkoutshopper-live.adyen.com https://checkoutanalytics-test.adyen.com https://siteintercept.qualtrics.com https://st-stage-enc-cust-docs-use-oh-1.s3.us-east-2.amazonaws.com https://www.googletagmanager.com https://geolocation.onetrust.com *.launchdarkly.com https://region1.google-analytics.com https://secure.shippingapis.com https://squaretrade.my.salesforce-scrt.com https://squaretrade--qa.sandbox.my.salesforce-scrt.com https://www.facebook.com https://svc-api-int-1.qa1.squaretrade.com:20000 https://svc-api-int-1.qa2.squaretrade.com:20000 https://svc-api-int-1.qa3.squaretrade.com:20000 https://svc-api-int-1.qa4.squaretrade.com:20000 https://svc-api-int-1.qa5.squaretrade.com:20000 https://svc-api-int-1.qa6.squaretrade.com:20000 https://svc-api-int-1.qa7.squaretrade.com:20000 https://svc-api-int-8.qa1.squaretrade.com:20000 https://svc-api-int-1.stage.squaretrade.com:20000 https://svc-api-int-1.production.squaretrade.com:20000 https://maps.googleapis.com; 2 script-src 'self' https://challenges.cloudflare.com https://hcaptcha.com https://static.cloudflareinsights.com https://*.hcaptcha.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://www.google-analytics.com/ https://www.googletagmanager.com/; base-uri 'self'; object-src 'self'; report-uri /cdn-cgi/script_monitor/report 2 report-uri https://flvs.report-uri.com/r/d/csp/wizard 'self'; default-src 'self'; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com www.googletagmanager.com www.youtube.com cdn.botframework.com cse.google.com googleads.g.doubleclick.net pi.pardot.com sc-static.net e.acuityplatform.com js.ipredictive.com www.gstatic.com code.jquery.com ep2.adtrafficquality.google cdn.jsdelivr.net www.google-analytics.com snap.licdn.com origin.acuityplatform.com tr.snapchat.com go.flvs.net player.vimeo.com *.elfsight.com flvs.net www.flvs.net 'unsafe-inline' 'unsafe-eval' cdn.pardot.com cdn.ampproject.org; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com use.typekit.net cdn.jsdelivr.net p.typekit.net 'unsafe-inline'; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com ep1.adtrafficquality.google gwmtracking.com clients1.google.com www.flvs.net www.google.com googleads.g.doubleclick.net connect.facebook.net px.ads.linkedin.com syndicatedsearch.goog pixel.tapad.com dpm.demdex.net ums.acuityplatform.com flvs1.sharepoint.com *.vimeocdn.com www.googletagmanager.com flvs.net flvsprd.service-now.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: use.typekit.net; frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com www.googletagmanager.com ad.ipredictive.com go.myflvs.net www.youtube-nocookie.com player.vimeo.com www.google.com *.doubleclick.net *.adtrafficquality.google flvs.my.site.com www.youtube.com forms.flvs.net www.myflvs.net myflvs.net syndicatedsearch.goog ciqtracking.com correlation.edgate.com go.flexpointeducation.com go.flexpointvirtualschool.com; connect-src 'self' data: accounts.google.com *.google-analytics.com *.gstatic.com https://*.googletagmanager.com www.googleadservices.com *.snapchat.com www.google.com analytics.google.com ad.doubleclick.net www.google-analytics.com px.ads.linkedin.com ep1.adtrafficquality.google vimeo.com *.vimeo.com *.doubleclick.net fa-aichatbot-prod.azurewebsites.net directline.botframework.com www.flvs.net; media-src 'self' data: blob:; child-src 'self' 2 worker-src *.litter-robot.com *.litterbox.com *.whisker.com *.osano.com blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.elev.io *.paypalobjects.com *.klarnacdn.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.osano.com *.klarna.com https://*.talkable.com 'self' 'unsafe-inline'; img-src data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io widgets.automizely.com widgets.automizely.io *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca *.certcapture.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adnxs.com *.adsrvr.org *.bidr.io *.bing.com *.facebook.com *.gotolstoy.com *.lightboxcdn.com *.localizecdn.com *.reddit.com *.twitter.com *.pinterest.com *.pbbl.co *.tiktok.com *.litter-robot.com *.litterbox.com *.whisker.com aa.agkn.com https://*.ordergroove.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.cdn.imgeng.in *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adnxs.com *.ads-twitter.com *.adsrvr.org *.attn.tv *.bing.com *.byspotify.com *.dixa.io *.dstillery.com *.elev.io *.exponea.com *.facebook.net *.gleamjs.io *.gotolstoy.com *.hotjar.com *.impactcdn.com *.iubenda.com *.lightboxcdn.com *.localizecdn.com *.noibu.com *.onescreen.ai *.pepperjam.com *.pinimg.com *.pinterest.com *.redditstatic.com *.tiktok.com getrockerbox.com *.litter-robot.com *.litterbox.com *.whisker.com *.optimizely.com s3-us-west-2.amazonaws.com *.pbbl.co d2hrivdxn8ekm8.cloudfront.net *.osano.com https://*.ordergroove.com https://elements.sika.health *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.cdn.imgeng.in *.hsforms.net *.hsforms.com https://d2jjzw81hqbuqv.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.certcapture.com assets.braintreegateway.com *.gotolstoy.com *.lightboxcdn.com *.plyr.io *.litter-robot.com *.litterbox.com *.whisker.com *.osano.com *.klarnacdn.net *.adobedtm.com *.cdn.imgeng.in *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gotolstoy.com *.litter-robot.com *.litterbox.com *.whisker.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.automizely.com api.automizely.io *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.adnxs.com *.attentivemobile.com *.attn.tv *.bing.com *.dixa.io *.elev.io *.exponea.com *.facebook.com *.gotolstoy.com *.hotjar.com *.iubenda.com *.localizecdn.com *.noibu.com *.onescreen.ai *.pinterest.com *.plyr.io *.reddit.com *.redditstatic.com *.spotify.com *.tiktok.com *.litter-robot.com *.litterbox.com *.whisker.com *.googlesyndication.com *.optimizely.com *.telemetry.vaultdcr.com *.osano.com https://*.ordergroove.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://472ad5a6-d25e-45ca-8d99-f4067de68ea9.sansec.watch/; report-to report-endpoint; 2 default-src blob: data: https: 'self'; style-src blob: https: 'self' 'unsafe-inline'; media-src blob: https: 'self'; connect-src blob: https: 'self' 'unsafe-inline' wss://*.hotjar.com; frame-ancestors 'self'; script-src blob: 'unsafe-eval' 'unsafe-inline' 'self' https://*.adform.net/ https://*.hotjar.com/ https://*.go-mpulse.net https://*.outbrain.com/ https://*.volvotrucks.com/ https://ajax.googleapis.com/ajax/libs/jquery https://assets.adobedtm.com/ https://cdn.cookielaw.org/ https://connect.facebook.net/ https://documentservices.adobe.com/ https://googleads.g.doubleclick.net/ https://s7d1.scene7.com/ https://script.e-space.se/ https://snap.licdn.com/ https://static.ads-twitter.com/ https://www.googletagmanager.com/ https://www.youtube.com/; report-to csp-endpoint; report-uri https://knxzhhty06.execute-api.eu-west-1.amazonaws.com/prod/browser-reporting/csp; 2 default-src 'self' data: blob: *.armstrong.com *.armstrongceilings.com armstrongceilings.my.salesforce-sites.com d2qrdklrsxowl2.cloudfront.net player.interactivity.brightcove.com fonts.gstatic.com www.google-analytics.com;style-src 'self' 'unsafe-inline' fast.fonts.net d2qrdklrsxowl2.cloudfront.net *.s3.amazonaws.com fonts.googleapis.com display.ugc.bazaarvoice.com player.interactivity.brightcove.com;form-action 'self' *.armstrong.com *.armstrongceilings.com armstrongceilings.tfaforms.net *.salesforceliveagent.com armstrongceilings.my.site.com; frame-ancestors 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.armstrong.com *.armstrongceilings.com www.gstatic.com js-na1.hs-scripts.com js.hs-banner.com js.hs-analytics.net js.hsforms.net *.bazaarvoice.com cdn-cookieyes.com *.outbrain.com *.salesforceliveagent.com *.ugc.bazaarvoice.com assets.adobedtm.com connect.facebook.net d2qrdklrsxowl2.cloudfront.net googleads.g.doubleclick.net lib-us-3.brilliantcollector.com players.brightcove.net siteintercept.qualtrics.com snap.licdn.com vjs.zencdn.net www.googleadservices.com www.googletagmanager.com znbmda84ti8npbglj-armstrong.siteintercept.qualtrics.com *.google.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.mountain.com 100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 *.clearbitscripts.com;frame-src 'self' armstrongceilings.tfaforms.net bid.g.doubleclick.net d2qrdklrsxowl2.cloudfront.net armstrong.demdex.net www.google.com;img-src 'self' data: *.armstrong.com *.armstrongceilings.com *.bazaarvoice.com *.brightcove.com *.outbrain.com *.qualtrics.com armstrongceilings.my.salesforce-sites.com cdn-cookieyes.com cf-images.us-east-1.prod.boltdns.net cm.everesttech.net data.coremetrics.com dpm.demdex.net p.adsymptotic.com px.ads.linkedin.com s7d2.scene7.com www.google-analytics.com www.google.com www.googletagmanager.com track.hubspot.com www.facebook.com;connect-src 'self' *.akamaihd.net *.armstrong.com *.armstrongceilings.com cdn-cookieyes.com *.cookieyes.com edge.adobedc.net forms.hsforms.com *.brightcove.com *.qualtrics.com *.hapyak.com cdn.linkedin.oribi.io house-fastly-signed-us-east-1-prod.brightcovecdn.com armstrong.tt.omtrdc.net brightcove.hs.llnwd.net dpm.demdex.net edge.api.brightcove.com lib-us-3.brilliantcollector.com manifest.prod.boltdns.net stats.g.doubleclick.net *.google-analytics.com 100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 *.clearbitscripts.com 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.liqui-moly.com liquimoly.cloudimg.io *.twofour.dev data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.twofour.dev 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.google.com/ js.mollie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.liqui-moly.com walls.io *.walls.io *.cookiebot.com *.amazon-adsystem.com insight.adsrvr.org *.facebook.com *.twofour.dev 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.magezon.com https://www.mollie.com *.cloudimg.io *.liqui-moly.com liquimoly.cloudimg.io *.google.de *.google.com *.facebook.com *.twofour.dev data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.google.com/ js.mollie.com liquimoly.cloudimg.io *.scaleflex.it *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.liqui-moly.com walls.io *.walls.io *.cookiebot.com *.google-analytics.com *.googleadservices.com maps.googleapis.com googleapis.com connect.facebook.net service.liqui-moly.de *.twofour.dev 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.liqui-moly.com walls.io *.walls.io liquimoly.cloudimg.io *.twofour.dev 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://*.ingest.sentry.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.liqui-moly.com walls.io *.walls.io *.cookiebot.com *.analytics.google.com *.twofour.dev 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' *.adsrvr.org *.google.com *.doubleclick.net *.optimizely.com *.facebook.com *.cookielaw.org *.clarity.ms apps.usw2.pure.cloud www.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net code.jquery.com embed.signalintent.com *.optimizely.com cdn.segment.com *.googleapis.com www.googletagmanager.com www.google.com www.gstatic.com *.btttag.com *.bing.com *.app-us1.com *.adsrvr.org *.doubleclick.net *.cookielaw.org www.google-analytics.com *.mypurecloud.com *.googleadservices.com *.pure.cloud *.aptrinsic.com *.bootstrapcdn.com js.monitor.azure.com *.facebook.net *.facebook.com trackcmp.net extractable-finalytics-storage.s3.us-west-2.amazonaws.com extractable-finalytics-stable.s3.us-west-2.amazonaws.com *.cloudfront.net snap.licdn.com www.redditstatic.com;style-src 'self' 'unsafe-inline' use.fontawesome.com use.typekit.net embed.signalintent.com p.typekit.net *.mypurecloud.com *.googleapis.com *.aptrinsic.com *.jsdelivr.net *.bootstrapcdn.com extractable-finalytics-storage.s3.us-west-2.amazonaws.com extractable-finalytics-stable.s3.us-west-2.amazonaws.com *.cloudfront.net;img-src 'self' data: bat.bing.com *.google.com www.google-analytics.com content-cdn.com *.gstatic.com *.googleapis.com www.googletagmanager.com *.facebook.net *.facebook.com *.adsrrvr.org *.doubleclick.net *.yahoo.com *.cookielaw.org *.googlesyndication.com *.ads.linkedin.com embed.signalintent.com insight.adsrvr.org ib.adnxs.com *.reddit.com;font-src 'self' use.fontawesome.com embed.signalintent.com use.typekit.net *.mypurecloud.com *.gstatic.com *.googleapis.com *.cloudfront.net data:;connect-src 'self' ws: wss: *.googlesyndication.com signal-intent-production-back.herokuapp.com cdn.segment.com *.optimizely.com *.cookielaw.org calc-backend-prod.herokuapp.com d.btttag.com *.googleapis.com www.google-analytics.com api.segment.io *.doubleclick.net *.alaskausa.org *.bing.com *.aptrinsic.com *.episerver.net *.visualstudio.com *.google.com *.facebook.com finalyticsdata.com devfinalyticsdata.com stgfinalyticsdata.com px.ads.linkedin.com api-cdn.usw2.pure.cloud pixel-config.reddit.com www.redditstatic.com;worker-src 'self' blob:;block-all-mixed-content 2 img-src https: data: blob:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; 2 frame-ancestors 'self'; upgrade-insecure-requests; report-uri https://5b99b19026a35ad04db5bcf778a03938.report-uri.com/r/d/csp/reportOnly 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: abtasty.com ipredictive.com typekit.net socialannex.com adnxs.com auryc.com prod.bidr.io bing.com btttag.com builder.io cdnfonts.com cloudflare.com cloudfront.net cloudinary.com cnstrc.com bf.contentsquare.net contentsquare.net hj.contentsquare.net criteo.com g.doubleclick.net doubleclick.net fls.doubleclick.net dstillery.com facebook.com facebook.net getfastr.com iesnare.com analytics.google.com google.ca google.co.cr google.co.in google.co.jp google.co.uk google.co.vi google.com google.com.co google.com.mx google.com.my google.com.ph google.com.pk google.com.tr google.de google.fr google.hr google.ie google.it google.nl google.se google.sk google.tt googlesyndication.com gstatic.com googleadservices.com googleapis.com googletagmanager.com google-analytics.com fsastore.com hsastore.com welldeservedhealth.com heapanalytics.com izooto.com jquery.com listrak.com listrakbi.com pcapredict.com bing.net clarity.ms mountain.com northbeam.io oursprivacy.com pepperjam.com pepperjamnetwork.com pinimg.com pinterest.com powerreviews.com riskified.com disstg.commercecloud.salesforce.com segment.com segment.io ingest.sentry.io mobify-storefront.com adsrvr.org acsbapp.com ivaws.com postcodeanywhere.co.uk youtube.com ytimg.com zdassets.com zendesk.com zopim.com creator-prod.zmags.com zmags.com c.us.heap-api.com cas.zma.gs analytics-api.fsastore.com; frame-ancestors capacitor://localhost; 2 default-src 'self';img-src * blob: data: px.ads.linkedin.com www.facebook.com *.doubleclick.net *.clarity.ms;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bootstrapcdn.com *.typekit.net cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com code.jquery.com js.hsforms.net www.googletagmanager.com *.mysanfordchart.org *.addthis.com *.adroll.com *.adsrvr.org *.ads-twitter.com *.clarity.ms *.cloudfront.net *.doubleclick.net *.fls.doubleclick.net formstack.com *.formstack.com *.formstack.io *.g.doubleclick.net *.google.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.invocacdn.com *.liveperson.net *.lpsnmedia.net *.mpio.io onesignal.com *.onesignal.com *.qualtrics.com *.quantcount.com *.quantserve.com *.serving-sys.com *.simpli.fi *.siteintercept.qualtrics.com *.talentegy.com *.tvsquared.com *.twitter.com *.v.liveperson.net *.vimeo.com *.vimeocdn.com aa.agkn.com ajax.aspnetcdn.com assets.sitescdn.net az416426.vo.msecnd.net bat.bing.com cdn.mouseflow.com cdn.popt.in chimpstatic.com data.adxcel-ec2.com embed.typeform.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com pixel.mathtag.com pixel.videohub.tv pnapi.invoca.net px.ads.linkedin.com s.amazon-adsystem.com s.pinimg.com s3.amazonaws.com/checkout.squadup.com/default/css/bootstrap-namespace.min.css script.crazyegg.com sc-static.net siteimproveanalytics.com snap.licdn.com static.addtoany.com static.cloud.coveo.com tags.srv.stackadapt.com tracking.logpostback.com transparency.nrchealth.com trkn.us v1.addthisedge.com www.buzzsprout.com www.groupexpro.com www.youtube.com www.ypo.education/js/jsembedcode.js z.moatads.com cdn.mxpnl.com js.hubspot.com *.snapchat.com *.instabot.io *.roobrik.com connect.facebook.net services.cattailsservices.com;style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com cloud.typography.com code.jquery.com www.googletagmanager.com *.mysanfordchart.org *.formstack.com *.formstack.io *.gstatic.com *.vimeocdn.com cdn.thinglink.me checkout.stripe.com formsprod.azureedge.net onesignal.com static.cloud.coveo.com tags.srv.stackadapt.com www.groupexpro.com www.youtube.com *.instabot.io services.cattailsservices.com;font-src 'self' data: *.fontawesome.com *.typekit.com *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com *.formstack.com *.gstatic.com *.googleusercontent.com static.cloud.coveo.com staticdev.cloud.coveo.com *.roobrik.com;frame-src 'self' cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com www.googletagmanager.com tools.sanfordhealthplan.com *.mysanfordchart.org *.addthis.com *.adsrvr.org *.c.liveperson.net *.doubleclick.net *.fls.doubleclick.net *.formstack.com *.g.doubleclick.net *.google.com *.ipcamlive.com *.lpsnmedia.net *.snapchat.com *.soundcloud.com *.stripe.com *.twitter.com *.v.liveperson.net vimeo.com *.vimeo.com *.youtube.com cdn.onesignal.com e.issuu.com fast.wistia.net forms.hsforms.com host.visualcalc.com js.hsadspixel.net js.hsforms.net pixel.mathtag.com players.brightcove.net static.addtoany.com www.buzzsprout.com www.pinterest.ca www.pinterest.co.uk www.pinterest.com www.pinterest.fr www.pinterest.it www.pinterest.ph ct.pinterest.com www.thinglink.com forms.hubspot.com *.roobrik.com *.cloudfront.net sanford.az1.qualtrics.com www.groupexpro.com;frame-ancestors 'self' *.mysanfordchart.org *.snapchat.com;connect-src 'self' cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com cloud.typography.com code.jquery.com www.googletagmanager.com *.addthis.com *.adroll.com *.clarity.ms *.doubleclick.net *.g.doubleclick.net *.gannettdigital.com *.google.com *.analytics.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.gstatic.com *.linkedin.oribi.io onesignal.com *.onesignal.com *.pinterest.com *.quantcount.com *.reachlocalservices.com *.serving-sys.com *.snapchat.com *.squadup.com *.twitter.com *.vimeocdn.com *.z1.dca0.com api.hubapi.com az416426.vo.msecnd.net bat.bing.com dc.services.visualstudio.com *.hsforms.com *.hubspot.com js.hs-scripts.com hubspot-forms-static-embed.s3.amazonaws.com js.hsadspixel.net forms.hscollectedforms.net js.hscollectedforms.net n2.mouseflow.com pnapi.invoca.net sanfordhealth.formstack.com *.formstack.io usageanalytics.coveo.com *.cloud.coveo.com px.ads.linkedin.com snap.licdn.com sc-static.net api.sanfordhealth.org api-js.mixpanel.com *.instabot.io api.fbanalytics.org connect.facebook.net assets.sitescdn.net *.cloudfront.net siteimproveanalytics.com *.roobrik.com services.cattailsservices.com;form-action 'self' *.fontawesome.com cdnjs.cloudflare.com *.sanfordhealthfoundation.org *.adroll.com *.doubleclick.net *.google.com *.google-analytics.com *.googleapis.com *.gstatic.com *.pinterest.com *.serving-sys.com *.snapchat.com *.vimeocdn.com api.hubapi.com forms.hsforms.com forms.hubspot.com hubspot-forms-static-embed.s3.amazonaws.com;media-src * data:;object-src 'none';report-uri https://csp-reporting.sanfordhealth.org/; 2 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; worker-src blob: 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.modo.com.ar fonts.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.gocuotas.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.mercadopago.com.ar mercadopago.com.ar *.getblue.io *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com *.gocuotas.com www.facebook.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.google.com.ar *.google.es *.google.com.uy *.mercadopago.com.ar *.modo.com.ar *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com flagpedia.net *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.woowup.com *.hotjar.com *.pageimprove.io pageimprove.io *.getblue.io *.adidas.com *.modo.com.ar *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com *.gstatic.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.gstatic.com www.gstatic.com *.tagmanager.google.com *.googletagmanager.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.pangle-ads.com *.modo.com.ar *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com www.gstatic.com maps.googleapis.com cdn.ampproject.org www.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 upgrade-insecure-requests; base-uri 'self'; default-src 'self'; child-src 'self' https:; connect-src 'self' https:; font-src 'self' https: data:; frame-src 'self' https:; img-src 'self' blob: https: data:; media-src 'self' ssl.gstatic.com v.adsrvr.org data:; script-src 'self' ajax.cloudflare.com cdn.ampproject.org cdn.printfriendly.com choices.trustarc.com choices.truste.com ep2.adtrafficquality.google *.kaspersky-labs.com js.chargebee.com s.adroll.com s0.2mdn.net s3.amazonaws.com www.googletagservices.com www.gstatic.com www.scrible.com *.doubleverify.com *.doubleclick.net *.google *.google.com *.googleapis.com *.googlesyndication.com *.sentry-cdn.com 'unsafe-inline'; style-src 'self' js.chargebee.com pwm-image.trendmicro.com s3.amazonaws.com use.fontawesome.com www.gstatic.com *.googleapis.com *.kaspersky-labs.com *.public.law 'unsafe-inline'; worker-src 'self' https: blob:; report-uri https://www.public.law/csp-report 2 default-src 'self'; script-src 'report-sample' 'self' https://bat.bing.com/bat.js https://cdn-4.convertexperiments.com/v1/js/10047604-10048796.js https://cdn.cookiehub.eu/c2/0d3e7b1f.js https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js https://cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js https://public.our-trace.com/scripts/trace-badge.js https://recaptcha.net/recaptcha/api.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://www.convert.com/current-convert-experiences-script/dist/bundle.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/h7qt2xUGz2zqKEhSc8DD8baZ/recaptcha__en.js; style-src 'report-sample' 'self' 'unsafe-inline' https://cookiehub.net https://www.convert.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://api.our-trace.com https://bat.bing.com https://cdn-4.convertexperiments.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.google.com; font-src 'self' data:; frame-src 'self' https://recaptcha.net https://www.googletagmanager.com; frame-ancestors 'self' https://www.google.com https://recaptcha.net; img-src 'self' data: https://bat.bing.com https://public.our-trace.com https://px.ads.linkedin.com https://tracking.g2crowd.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pike13.com https://cdnjs.cloudflare.com https://connect.facebook.net https://platform.linkedin.com https://platform.twitter.com https://snap.licdn.com https://tracking.g2crowd.com https://*.google.com https://*.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://*.doubleclick.net https://*.hotjar.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.hscollectedforms.net https://*.hsforms.net https://*.hubspot.com https://*.hubspotusercontent-na1.net https://*.hsappstatic.net https://*.hubapi.com https://*.wufoo.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://*.pike13.com https://fonts.googleapis.com https://*.hsappstatic.net https://*.hsforms.net https://*.hubspotusercontent-na1.net; font-src 'self' https://*.pike13.com https://fonts.gstatic.com https://*.hubspotusercontent-na1.net https://www.google.com; img-src 'self' https://*.pike13.com https://*.hubspot.com https://*.hubspot.net https://*.hsforms.com https://*.hubspotusercontent-na1.net https://*.hsforms.com https://*.linkedin.com https://*.hsappstatic.net https://*.facebook.com https://*.facebook.net https://*.google.com https://*.googletagmanager.com https://*.twitter.com; connect-src 'self' https://*.pike13.com https://analytics.google.com https://hubspot-forms-static-embed.s3.amazonaws.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.google.com https://*.hs-banner.com https://*.hscollectedforms.net https://*.hs-collectedforms.net https://*.hsforms.net https://*.hsforms.com https://*.hubapi.com https://*.hubspot.com https://*.doubleclick.net; frame-src 'self' https://*.pike13.com https://*.hs-sites.com https://*.googletagmanager.com https://*.google.com https://*.facebook.com https://*.twitter.com; object-src 'none'; worker-src 'none'; base-uri 'self'; manifest-src 'self'; media-src 'self'; report-uri https://pike13.report-uri.com/r/d/csp/wizard; 2 script-src 'self' https://ajax.googleapis.com https://f1000research.s3-eu-west-1.amazonaws.com https://cdnjs.cloudflare.com https://cdnjs.cloudflare.com https://js.hs-scripts.com 2 report-uri /cdn-cgi/script_monitor/report 2 default-src 'self' 'unsafe-inline' *.bazaarvoice.com; connect-src 'self' 'unsafe-inline' maps.googleapis.com www.google.com www.gstatic.com analytics.google.com *.google-analytics.com *.googletagmanager.com www.google-analytics.com bam.nr-data.net *.afterpay.com *.afterpaycdn.com *.squarecdn.com static.afterpay.com *.paypal.com *.bazaarvoice.com edge.fullstory.com rs.fullstory.com ekr.zdassets.com; font-src 'self' 'unsafe-inline' data: fonts.gstatic.com use.typekit.net *.afterpay.com *.afterpaycdn.com *.squarecdn.com; frame-src 'self' 'unsafe-inline' www.google.com www.youtube.com player.vimeo.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com assets.braintreegateway.com *.paypal.com; img-src 'self' 'unsafe-inline' data: maps.googleapis.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com fonts.gstatic.com i.vimeocdn.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com site-assets.afterpay.com www.paypalobjects.com *.bazaarvoice.com rs.fullstory.com insight.adsrvr.org theathletesfootcustomercarenz.zendesk.com accentgroupsupport.zendesk.com www.facebook.com; script-src 'self' 'unsafe-inline' blob: maps.googleapis.com www.google.com www.gstatic.com *.googletagmanager.com *.google-analytics.com tagmanager.google.com js-agent.newrelic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com tagmanager.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com; child-src blob:; media-src 'self' blob: data:; worker-src 'self' blob:; report-uri https://36eddd1e-785d-4d1e-a6e1-6809b1003cef.sansec.watch/ 2 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' https:; report-uri https://usercontent.mobileread.org/csp-report 2 worker-src 'self' blob:; object-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' rum.hlx.page *.youtube.com *.gstatic.com *.licdn.com *.podigee-cdn.net static.xingcdn.com www.googleadservices.com *.google.com *.googlesyndication.com *.onetrust.com *.alida.com wave.outbrain.com *.outbrain.com *.taboola.com *.intelliad.de *.doubleclick.net platform.twitter.com cdn.mouseflow.com *.cnd-motionmedia.de *.facebook.net www.facebook.com *.bing.com *.googletagmanager.com cdn.scarabresearch.com *.spoteffects.net cdn.trackjs.com cdnjs.cloudflare.com *.realperson.de cdn.cookielaw.org *.ergodirekt.de *.ergo.com *.ergo.de *.ergocarbon.com *.ergo-reiseversicherung.de *.dkv.com *.cloudfirst.digital assets.adobedtm.com; frame-ancestors 'self' *.ergodirekt.de:* *.ergo.com:* *.ergo:* *.ergo.de *.ergocarbon.com *.ergo-reiseversicherung.de *.dkv.com *.erg.ravespace.cloud; report-uri https://csp-reporting.ergo.com/csp-reports?tenant=dospa; report-to csp-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.yotpo.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com.ar *.google.com.uy *.hotjar.com *.doubleclick.net www.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://sparta.cl/ https://newbalance.cl/ https://head.cl/ https://spyder.cl/ https://trekbikeschile.com/ https://www.dynamicyield.org/ku/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com gen.sendtric.com *.yotpo.com *.google.com *.google.com.ar *.google.com.uy *.facebook.com *.doubleclick.net sparta.cl newbalance.cl head.cl speedo.cl spyder.cl trekbikes.cl *.sparta.cl *.newbalance.cl *.head.cl *.speedo.cl *.spyder.cl *.trekbikes.cl www.mercadolibre.com www.mercadopago.cl 'self' data: *.googleapis.com *.yandex.ru *.retailrocket.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com mcdn.retailrocket.net *.google.com.ar *.google.com.uy *.googleoptimize.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.fanplayr.com *.facebook.net *.yotpo.com *.doubleclick.net *.magentosite.cloud *.freshworks.com *.hotjar.com *.retailrocket.net *.yandex.ru *.api.useinsider.com www.mercadopago.com www.mercadopago.cl sdk.mercadopago.com www.dynamicyield.org js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com analytics.tiktok.com www.tiktok.com business.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com *.googleapis.com sparta.cl newbalance.cl head.cl speedo.cl spyder.cl trekbikes.cl *.sparta.cl *.newbalance.cl *.head.cl *.speedo.cl *.spyder.cl *.trekbikes.cl *.yotpo.com *.fonts.net *.magentosite.cloud *.freshworks.com *.retailrocket.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com mcdn.retailrocket.net *.google-analytics.com *.yotpo.com *.freshworks.com *.googleapis.com stats.g.doubleclick.net *.yandex.ru api.mercadopago.com events.mercadopago.com www.mercadolibre.com *.retailrocket.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com analytics.tiktok.com www.tiktok.com business.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://spartacl.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://snap.licdn.com https://www.redditstatic.com https://policy.app.cookieinformation.com https://googleads.g.doubleclick.net https://secure.quantserve.com https://static.ads-twitter.com https://rules.quantcount.com https://analytics.tiktok.com https://tags.srv.stackadapt.com https://www.gstatic.com https://cdn.xsolla.net https://3001.scriptcdn.net https://infird.com; style-src 'self' 'unsafe-inline' https://tags.srv.stackadapt.com https://www.gstatic.com; img-src 'self' data: blob: https: https://cms.ioi.dk https://www.facebook.com https://px.ads.linkedin.com https://region1.google-analytics.com https://alb.reddit.com; font-src 'self' data: https://fonts.gstatic.com https://ioi.dk https://use.typekit.net https://r2cdn.perplexity.ai; connect-src 'self' data: https://cms.ioi.dk https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://px.ads.linkedin.com https://alb.reddit.com https://pixel-config.reddit.com https://conversions-config.reddit.com https://www.redditstatic.com https://www.facebook.com https://policy.app.cookieinformation.com https://o4504207644033024.ingest.us.sentry.io https://vimeo.com https://prreqcroab.icu https://analytics.tiktok.com https://tags.srv.stackadapt.com https://www.googleadservices.com https://pixel.quantserve.com https://pixel.quantcount.com https://googleads.g.doubleclick.net https://analytics-ipv6.tiktokw.us https://consent.app.cookieinformation.com https://store.xsolla.com https://api.killadsapi.com https://overbridgenet.com; frame-src 'self' https://www.googletagmanager.com https://policy.app.cookieinformation.com https://www.youtube.com https://player.vimeo.com https://www.google.com https://www.facebook.com https://purchase.xsolla.com https://duertry.com https://access.workspace.google.com https://accounts.google.com; frame-ancestors 'self' https://dev-ioi-website.euwest01.umbraco.io https://stage-ioi-website.euwest01.umbraco.io https://ioi-website.euwest01.umbraco.io; media-src 'self' https://dev-ioi-website.euwest01.umbraco.io https://stage-ioi-website.euwest01.umbraco.io https://cms.ioi.dk; report-uri https://4ff80cf698c8fa08a42150e2d0fae142@o4504207644033024.ingest.us.sentry.io/4510260682948608; report-to csp-endpoint 2 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self' https://jadlog.com.br https://www.jadlog.com.b; script-src 'self' https://static.zdassets.com https://www.googletagmanager.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://static.cloudflareinsights.com https://code.jquery.com https://cdnjs.cloudflare.com https://ajax.cloudflare.com https://pod-27-sunco-ws.zendesk.com; style-src 'self' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://code.jquery.com https://cdnjs.cloudflare.com https://static.zdassets.com https://cdn.cookielaw.org; img-src 'self' data: https://*.tile.openstreetmap.org https://ssl.google-analytics.com https://www.google-analytics.com https://www.google.com; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; connect-src 'self' https://cdn.cookielaw.org https://ekr.zdassets.com https://jadloglogsticahelp.zendesk.com https://pod-27-sunco-ws.zendesk.com https://www.googletagmanager.com https://www.google.com https://cloudflareinsights.com; frame-src 'self' https://www.google.com https://jadlog.force.com https://jadloglogsticahelp.zendesk.com; report-uri https://service.jadlog.com.br/csp-report-endpoint; report-to csp-endpoint 2 default-src 'self' https://*.wistia.com https://*.wistia.net https://cdn.growthbook.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google-analytics.com https://www.youtube.com https://maps.googleapis.com https://bat.bing.com https://*.demio.com https://d3s4clg74dg0wr.cloudfront.net https://zapier.com https://www.clarity.ms https://static.homerun.co https://unpkg.com/@googlemaps/ https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net https://*.intercom.io wss://*.intercom.io https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; style-src 'self' 'unsafe-inline' https://moneybird.nl https://www.moneybird.nl https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.gstatic.com https://d3s4clg74dg0wr.cloudfront.net https://fonts.googleapis.com https://*.demio.com https://static.homerun.co https://fonts.bunny.net https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.adyen.com/ https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; img-src 'self' https://moneybird.nl https://www.moneybird.nl https://prismic-io.s3.amazonaws.com https://images.prismic.io https://moneybird.cdn.prismic.io https://dl6oytjgv033w.cloudfront.net https://www.gstatic.com https://www.google-analytics.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google.nl https://www.google.com https://i.ytimg.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com https://bat.bing.com https://zapier.com https://cdn.zapier.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net data: https://*.adyen.com/ https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; object-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https://moneybird.nl https://www.moneybird.nl https://help.moneybird.nl https://bat.bing.com https://gtm.moneybird.nl https://gtm.moneybird.com https://gtm.moneybird.be https://gtm.moneybird.de https://pagead2.googlesyndication.com https://*.google-analytics.com https://www.gstatic.com https://moneybird.com https://www.moneybird.com https://homerun.co https://stats.g.doubleclick.net https://*.demio.com https://*.clarity.ms https://embed.homerun.co https://maps.googleapis.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net https://cdn.growthbook.io https://*.intercom.io wss://*.intercom.io https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; frame-src 'self' https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://moneybird.clickwebinar.com https://w.soundcloud.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://fast.wistia.com https://fast.wistia.net https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; font-src 'self' https://moneybird.nl https://www.moneybird.nl https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.bunny.net https://*.wistia.com data: https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; report-uri https://moneybird.com/csp_report; 2 script-src-attr 'unsafe-inline'; font-src https://*.gstatic.com https://fast.fonts.net https://use.typekit.net https://x.klarnacdn.net *.yotpo.com *.googleapis.com *.gstatic.com https://static.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com payments.amazon.de https://www.shopmyexchange.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com https://ct.pinterest.com https://*.fls.doubleclick.net https://postrelease.com https://*.rfihub.com *.yotpo.com https://frame.hub-box.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://alb.reddit.com https://analytics.twitter.com https://bat.bing.com https://*.doubleclick.net https://*.facebook.com https://sync.intentiq.com https://jadserve.postrelease.com https://t.co https://*.teads.tv https://r.turn.com https://*.yahoo.com *.narvar.com *.narvar.qa *.yotpo.com https://i.lfi.media https://cdn.hub-box.com https://www.danner.com https://www.lacrossefootwear.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://assets.calendly.com *.convertexperiments.com https://ads.pubmatic.com https://static.ads-twitter.com https://bat.bing.com https://cdn.attn.tv https://cdn.ravm.tv https://cdnjs.cloudflare.com https://ct.pinterest.com https://connect.facebook.net https://fast.fonts.net https://cdn.id5-sync.com https://agent.intentiq.com https://s.ntv.io https://s.pinimg.com https://platform.twitter.com https://jadserve.postrelease.com https://c1.rfihub.net https://*.taboola.com https://*.teads.tv https://s.yimg.com https://static.zdassets.com https://js.klarna.com https://*.locally.com *.yotpo.com https://*.klaviyo.com https://cdn.segment.com https://*.cdp.danner.com https://*.cdp.lacrossefootwear.com https://cdn.hub-box.com https://*.addressy.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ https://static.klaviyo.com https://cdnjs.cloudflare.com https://fast.fonts.net https://*.typekit.net https://x.klarnacdn.net *.yotpo.com *.googleapis.com https://*.klaviyo.com https://api.addressy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://i.lfi.media 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.attn.tv https://bat.bing.com https://cdn.ravm.tv https://gum.criteo.com https://id.crwdcntrl.net https://ct.pinterest.com https://*.doubleclick.net https://id5-sync.com https://eu-1-id5-sync.com/ https://*.reddit.com https://*.redditstatic.com https://*.taboola.com https://*.teads.tv https://s.yimg.com https://*.zdassets.com https://*.zendesk.com https://tags.w55c.net https://js.klarna.com https://evt-na.klarnaservices.com https://www.locally.com *.yotpo.com https://*.klaviyo.com https://api.segment.io https://cdn.segment.com https://*.cdp.danner.com https://*.cdp.lacrossefootwear.com https://api.addressy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https:; connect-src 'self' https: wss: javascript:; font-src 'self' data: use.typekit.net fonts.gstatic.com *.cloudfront.net fonts.googleapis.com assets.parentsquare.com assets.sandbox.parentsquare.com assets.staging.parentsquare.com themes.googleusercontent.com; form-action 'self' https:; frame-ancestors 'self'; img-src 'self' blob: data: https: pbs.twimg.com; media-src 'self' data: blob: https:; object-src 'self' parentsquare-restricted-data-production.s3.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; upgrade-insecure-requests; worker-src 'self' blob:; report-uri /csp_report 2 default-src 'none'; style-src 'self' 'unsafe-inline' *.gstatic.com fonts.googleapis.com maps.googleapis.com wchat.eu.freshchat.com https://static.kameleoon.com https://static.products.kameleoon.com https://graphical-editor.kameleoon.com https://simulation.kameleoon.com *.hotjar.com bat.bing.com bat.bing.net; font-src data: 'self' fonts.gstatic.com fonts.googleapis.com *.hotjar.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' apis.google.com www.google.com pagead2.googlesyndication.com googleadservices.com www.googleadservices.com googleads.g.doubleclick.net *.gstatic.com www.google-analytics.com *.googletagmanager.com maps.googleapis.com app.aiden.cx api.eu1.exponea.com wchat.eu.freshchat.com *.kameleoon.eu *.kameleoon.com js.mollie.com browser.sentry-cdn.com js.sentry-cdn.com *.hotjar.com connect.facebook.net platform.twitter.com bat.bing.com bat.bing.net flex.msn.com www.youtube.com ct.beslist.nl; img-src 'self' data: *.google.com google.com www.google.nl *.gstatic.com pagead2.googlesyndication.com *.g.doubleclick.net googleadservices.com *.googleadservices.com www.google-analytics.com www.googletagmanager.com maps.googleapis.com https://123led.nl https://www.bugherd.com *.kameleoon.io *.kameleoon.eu *.kameleoon.com *.products.kameleoon.com *.hotjar.com checkoutshopper-live.adyen.com www.facebook.com connect.facebook.net syndication.twitter.com bat.bing.com bat.bing.net i.ytimg.com; frame-src 'self' www.google.com doubleclick.net td.doubleclick.net www.googletagmanager.com https://app.aiden.cx https://www.kiyoh.com app.aiden.cx wchat.eu.freshchat.com https://graphical-editor.kameleoon.com js.mollie.com checkoutshopper-live.adyen.com acs-live-eu.adyen.com staticxx.facebook.com www.facebook.com platform.twitter.com syndication.twitter.com bat.bing.com bat.bing.net flex.msn.com youtube.com *.youtube.com *.youtube-nocookie.com; object-src 'self'; connect-src 'self' www.googlesyndication.com www.google.com google.com www.google.nl adservice.google.com pagead2.googlesyndication.com www.googleadservices.com *.analytics.google.com google-analytics.com *.google-analytics.com stats.g.doubleclick.net www.googletagmanager.com maps.googleapis.com https://analytics.google.com app.aiden.cx api.eu1.exponea.com app.eu1.exponea.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.products.kameleoon.com *.sentry.io *.hotjar.com *.hotjar.io wss://*.hotjar.com checkoutshopper-live.adyen.com www.facebook.com bat.bing.com bat.bing.net ct.beslist.nl; manifest-src 'self'; report-uri https://123inkt.report-uri.com/r/t/csp/reportOnly; 2 default-src 'self'; script-src 'self' 'report-sample'; style-src 'self'; report-to csp-endpoint 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://static.unzer.com https://applepay.cdn-apple.com maxcdn.bootstrapcdn.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com www.facebook.com *.facebook.com *.nkd.com *.nkd.it 'self' 'unsafe-inline'; frame-ancestors *.nkd.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.googletagmanager.com/ *.facebook.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com https://plumrocket.com https://accounts.google.com ad4m.at *.criteo.com *.doubleclick.net www.facebook.com hal9000.redintelligence.net *.usercentrics.eu www.usemaxserver.de *.fls.doubleclick.net *.creativecdn.com tsdtocl.com *.sovendus-benefits.com *.sovendus-connect.com *.usemaxserver.de 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com maps.googleapis.com maps.gstatic.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' data: ad11.adfarm1.adition.com bat.bing.com *.doubleclick.net *.google.com *.google.pl imagesrv.adition.com lantern.roeye.com *.nkd.com track.adform.net usage.trackjs.com *.usercentrics.eu widgets.trustedshops.com www.facebook.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.360yield.com *.3lift.com *.addlv.smt.docomo.ne.jp *.adform.net *.admixer.net *.adnxs.com *.adscale.de *.adx.opera.com *.bing.com *.casalemedia.com *.ck-ie.com *.connectad.io *.console.adtarget.com.tr *.creativecdn.com *.dmxleo.com *.e-planning.net *.facebook.com *.facebook.net *.g.doubleclick.net *.go.sonobi.com *.gumgum.com *.inmobi.com *.leap.de *.loopme.me *.marphezis.com *.media.net *.mgid.com *.nexx360.io *.openx.net *.outbrain.com *.roeye.com *.rubiconproject.com *.sharethrough.com *.taboola.com *.teads.tv *.trackjs.com *.udmserve.net *.visx.net *.adition.com *.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.plugins.emarsys.net *.scarabresearch.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.googleoptimize.com maps.googleapis.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://accounts.google.com https://www.gstatic.com *.hsforms.net *.hsforms.com ad4m.at api.sovendus.com bat.bing.com *.taboola.com cdn.mouseflow.com core.loopingo.com *.criteo.com *.epoq.de epoq-systems.de *.facebook.net lantern.roeyecdn.com *.nkd.com tags.creativecdn.com *.usercentrics.eu webanalytics.mso.digital widgets.trustedshops.com www.dwin1.com www.usemaxserver.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.bing.com *.dwin1.com *.epoq-systems.de *.loopingo.com *.usemaxserver.de *.trustedshops.com *.googletagmanager.com *.mouseflow.com *.outbrain.com *.creativecdn.com d22q3dafggn5rg.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io https://accounts.google.com https://www.gstatic.com *.googleapis.com *.epoq.de epoq-systems.de https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.scarabresearch.com *.eservice.emarsys.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com https://accounts.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com ams.creativecdn.com api.usercentrics.eu bat.bing.com *.criteo.com *.googleapis.com *.taboola.com webanalytics.mso.digital *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.bing.com *.usercentrics.eu *.creativecdn.com *.bing.net *.loopingo.com *.kameleoon.eu *.sovendus.com *.arc.epoq.de *.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self'; report-sample; report-uri https://proxy.csidetm.com/csp; report-to csp-endpoint; 2 default-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org; connect-src 'self' ws://exercism.org https://cdn.jsdelivr.net https://sessions.bugsnag.com/; img-src 'self' data: https://*; media-src *; script-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org https://js.stripe.com https://cdn.jsdelivr.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; frame-src https://js.stripe.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; font-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org https://maxcdn.bootstrapcdn.com; style-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org 'unsafe-inline' https://maxcdn.bootstrapcdn.com; child-src 'none' 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.chartbeat.com optanon.blob.core.windows.net *.brightcove.net *.brightcove.com *.googleadservices.com *.adservice.google.com https://adservice.google.com/* adservice.google.com.br *.googletagmanager.com *.tagmanager.google.com *.chimpstatic.com chimpstatic.com *.jquery.com *.zencdn.net *.ytimg.com *.surveymonkey.com *.googleapis.com *.facebook.net *.googletagservices.com *.addthis.com *.google-analytics.com *.onetrust.com *.ampproject.org *.doubleclick.net *.google.com *.mailchimp.com *.addthisedge.com *.youtube.com *.google.co.uk *.list-manage.com *.outbrain.com *.twitter.com *.twimg.com *.googlesyndication.com *.moatads.com *.radioplayer.co.uk *.cheqzone.com *.rubiconproject.com *.cookielaw.org *.cloudflareinsights.com *.instagram.com *.apester.com *.snap.licdn.com *.doubleverify.com *.aniview.com *.vidazoo.com *.ajax.cloudflare.com *.licdn.com *.pinterest.com *.embedresponsively.com *.amazonaws.com *.apester.com/* *.forces.liveblog.pro *.forces.liveblog.pro/* *.strawpoll.com *.freewheel.tv *.lkqd.net *.beachfront.com *.smartadserver.com *.aniview.com *.admanmedia.com *.improvedigital.com *.onetag.com *.indexexchange.com *.pubmatic.com *.rhythmone.com *.video.unrulymedia.com *.gstatic.com *.newrelic.com cdn.jsdelivr.net cdn.bidder.dev c.amazon-adsystem.com quantcast.mgr.consensu.org secure.quantserve.com rules.quantcount.com static.criteo.net *.dotomi.com *.tiktok.com *.google.ie *.ibytedtos.com *.tiktokcdn.com chartbeat.com *.media.net *.sharethrough.com *.openx.com *.sonobi.com *.districtm.io *.emxdgt.com *.appnexus.com *.google.com *.rhythmone.com *.33across.com *.lemmatechnologies.com *.e-planning.net *.themediagrid.com *.sovrn.com *.lijit.com *.gumgum.com *.nr-data.net *.ttwstatic.com *.thinglink.com *.thinglink.me *.defybrick.com e.infogram.com *.clarity.ms; frame-src 'self' 'unsafe-eval' *.addthis.com *.googlesyndication.com *.facebook.com/ *.outbrain.com *.twitter.com *.surveymonkey.com embeds.audioboom.com *.rubiconproject.com *.apester.com *.openx.net *.pinterest.com *.instagram.com *.embedresponsively.com *.youtube.com *.pubmatic.com *.forces.net *.forcesnews.com *.google.com *.bfbs.com apester.com/* forces.liveblog.pro forces.liveblog.pro/* *.strawpoll.com/ timbre-player.sharp-stream.com *.tiktok.com googleads.g.doubleclick.net gum.criteo.com pre.ads.justpremium.com console.googletagservices.com giphy.com *.giphy.com e.infogram.com *.thinglink.com *.thinglink.me; child-src 'self' 'unsafe-inline' 'unsafe-eval' blob: apester.com/* forces.liveblog.pro/* *.strawpoll.com/; upgrade-insecure-requests 2 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.paypalobjects.com https://lindtusa.rlvs.co.uk https://ghirardelli.slgnt.us https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js tinyurl.com/LINDT-LAUNCHER https://optmize.google.com nytrng.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://mediacdn.espssl.com/2824/Shared/Modal/chocolate.png https://www.linkedin.com https://*.linkedin.com/ https://px.ads.linkedin.com https://mcstaging.russellstover.com https://mcstaging.lindtusa.com https://mcstaging.ghirardelli.com https://mcprod.lindtusa.com *.googleadservices.com *.yieldify.com https://www.google-anaytics.com https://www.googletagmanager.com https://optimize.google.com https://cdn.livechat-static.com *.bazaarvoice.com https://shopper.shop.pe i.liadm.com v2assets.zopim.io *.cloudfunctions.net partner.mediawallahscript.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.youtube.com https://acsbapp.com/apps/app/dist/js/app.js https://cdn.noibu.com/collect.js https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js tinyurl.com/LINDT-LAUNCHER *.yieldify.com *.fraud0.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com 'unsafe-inline' https://optimize.google.com 'unsafe-inline' https://cdn.attn.tv https://www.lindt-spruengli.com/* https://www.lindt-spruengli.com/media/target/VAPI.min.js https://www.lindt-spruengli.com/media/target/at.js shop.pe *.shop.pe d3rr3d0n31t48m.cloudfront.net addshoppers.s3.amazonaws.com .traversedlp.com .voltn.com *.addshoppers.com static.traversedlp.com static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://cloud.typography.com https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js 'unsafe-inline' https://optimize.google.com https://fonts.googleapis.com 'unsafe-inline' cookie-cdn.cookiepro.com https://cookie-cdn.cookiepro.com https://cdn.cookiepro.com/scripttemplates/*/assets 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://vc.hotjar.io https://cdn.linkedin.oribi.io https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js *.fraud0.com *.lindtusa.com *.yieldify.com https://content.hotjar.io wss://ws.hotjar.com https://metrics.hotjar.io https://lindt-us.attn.tv https://events.attentivemobile.com lindt.attn.tv cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://bat.bing.com shop.pe *.shop.pe ekr.zdassets.com lindtusa.zendesk.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com https://viewer.byondxr.com https://web-apps.byondxr.com https://app.byondxr.com https://byondxr-viewer.byondxr.com https://app.byondvr.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com *.inviewuclab.com static.zdassets.com js.stripe.com *.google.com *.gstatic.com gstatic.com connect.facebook.net *.zendesk.com blob: ; script-src-elem 'self' 'unsafe-inline' https://maps.googleapis.com *.google.com *.gstatic.com static.zdassets.com js.stripe.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com cdn.datatables.net ; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com cdn.datatables.net ; style-src-attr 'unsafe-inline' ; img-src 'self' https://maps.gstatic.com https://maps.googleapis.com data: blob: 127.0.0.1:18623 *.mapbox.com *.facebook.com *.google.com *.gstatic.com ; frame-src 'self' *.google.com *.google.ie js.stripe.com player.vimeo.com www.youtube.com; font-src 'self' https://fonts.gstatic.com data: gstatic.com *.gstatic.com *.alicdn.com ; connect-src 'self' https://google.com *.google.com https://maps.googleapis.com https://maps.gstatic.com ekr.zdassets.com *.zendesk.com wss://127.0.0.1:18623 https://127.0.0.1:18623 mlts.dynamsoft.com *.mapbox.com *.inviewuclab.com https://tiles.openfreemap.org ; worker-src 'self' blob: ; upgrade-insecure-requests ; report-uri https://9a1a6d99ab6aa4ac3290a60bae476ab7.report-uri.com/r/d/csp/enforce 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.instagram.com https://plumrocket.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.cdninstagram.com *.googleapis.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.trackedlink.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.cookielaw.org *.facebook.com *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.instagram.com *.googleapis.com *.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://genki.paulmarius.fr https://genki.paulmarius.de https://genki.paulmarius.es https://genki.paulmarius.it https://genki.paulmarius.nl https://genki.paulmarius.com https://genki.paulmarius.us https://genki.paulmarius.co.uk *.bing.com *.clarity.ms *.trustpilot.com *.cookielaw.org *.cookieless-data.com *.paulmarius.fr *.googlesyndication.com *.doubleclick.net *.apicit.net *.clickintext.net *.facebook.net *.googletagmanager.com apicit.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com * *.googleapis.com maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.cookielaw.org *.googlesyndication.com *.db-ip.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src * data: blob:; font-src 'self' https:; connect-src 'self' https:; frame-src *; 2 font-src portal.bulkgate.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.benu.hu data: *.googleapis.com *.hotjar.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com business.facebook.com data: *.google.com *.youtube.com *.publitas.com *.fliphtml5.com *.hotjar.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net *.vimeocdn.com s.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com business.facebook.com https://redchamps.com www.safemage.com *.benu.hu *.cloudfront.net *.google.com *.gstatic.com *.googleapis.com *.googletagmanager.com image.arukereso.hu *.google.hu *.hotjar.com *.arukereso.hu *.bing.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.gstatic.com business.facebook.com *.avada.io https://cdnjs.cloudflare.com maps.googleapis.com *.google.com *.googletagmanager.com https://googleads.g.doubleclick.net *.googleadservices.com *.prefixbox.com *.publitas.com *.hotjar.com *.benu.hu *.arukereso.com gravity-dev-assets.oss-eu-central-1.aliyuncs.com benuhu.engine.yusp.com https://maileon-cdn.s3.eu-central-1.amazonaws.com/met/met.js clarity.ms *.clarity.ms *.bing.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com portal.bulkgate.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.prefixbox.com *.benu.hu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.gstatic.com business.facebook.com *.benu.hu *.google-analytics.com *.prefixbox.com *.doubleclick.net *.services.visualstudio.com *.hotjar.com *.hotjar.io benuhu.engine.yusp.com *.maileon.hu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.trackedlink.net *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com mrpg.scene7.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: *.yotpo.com https://js.klevu.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://security-hub.vaimo.network/public/api/content-security-policy.php; report-to report-endpoint; 2 font-src fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com https://torus-stage-halkbankmacedonia.asseco-see.com.tr/ https://epay.halkbank.mk/fim/est3Dgate form.wspay.biz formtest.wspay.biz https://ipgtest.monri.com/ https://ipg.monri.com/ https://formtest.wspay.biz/ https://form.wspay.biz/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com www.google.com *.youtube-nocookie.com *.sharethis.com www.facebook.com www.googletagmanager.com bid.g.doubleclick.net td.doubleclick.net issuu.com e.issuu.com assets.pinterest.com *.hotjar.com https://ipgtest.monri.com/ https://ipg.monri.com/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com www.google.hr *.googletagmanager.com ssl.gstatic.com www.gstatic.com www.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com maps.gstatic.com maps.googleapis.com log.pinterest.com pinterest.com www.pinterest.com *.hotjar.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com analytics.google.com www.googletagmanager.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.sharethis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googletagmanager.com tagmanager.google.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net maps.googleapis.com *.hotjar.com connect.facebook.net *.disqus.com assets.pinterest.com *.tiktok.com analytics.google.com www.googletagmanager.com *.avada.io *.shopify.com https://ipgtest.monri.com/ https://ipg.monri.com/ *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sharethis.com downloads.mailchimp.com googletagmanager.com tagmanager.google.com fonts.googleapis.com *.hotjar.com *.fontawesome.com https://fonts.bunny.net https://ipgtest.monri.com/ https://ipg.monri.com/ *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.sharethis.com *.g.doubleclick.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.com www.google.hr maps.googleapis.com *.hotjar.com *.hotjar.io wss://*.hotjar.com/ *.tiktok.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com https://symphony.ocltraining-int.com https://symphony.ocltraining-qa.com https://symphony.ocltraining.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.googletagmanager.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri https://csp-report.envytools.com 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-attr 'self' 'unsafe-inline' 'unsafe-eval' https:; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' wss: https:; object-src 'self'; child-src blob:; frame-src 'self' https:; worker-src blob:; frame-ancestors 'none'; base-uri 'none'; report-uri https://47327c6a613c1754bda1362d946d96dd.report-uri.com/r/t/csp/reportOnly; report-to csp-endpoint 2 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' api-accent.bloomreach.co *.qantasloyalty.com api.smooch.io applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/pagead *.google.com/recaptcha/ www.gstatic.com/recaptcha/ cfjump.platypusshoes.com.au cfjump.platypusshoes.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com s.pinimg.com lantern.roeyecdn.com ct.pinterest.com js-sandbox.squarecdn.com js.squarecdn.com ; style-src 'self' 'unsafe-inline' display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com *.adobetm.com foursixty.com assets.api.useinsider.com *.adobemc.com ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.platypusshoes.co.nz *.platypusshoes.com.au googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.twilio.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com amcglobal.sc.omtrdc.net adservice.google.com lantern.roeye.com accentgroupxpdev.112.2o7.net/b/ss/accentgroup-xpdev i.vimeocdn.com/video ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' api-accent.bloomreach.co *.qantasloyalty.com analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.platypusshoes.co.nz *.fullstory.com *.klaviyo.com smetrics.platypusshoes.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com www.google.com.au/ads/ga-audiences *.nr-data.net *.paypal.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com *.roymorgan.com foursixty.com kleber.datatoolscloud.net.au sentry.io vimeo.com wss://*.twilio.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com api.myunidays.com ct.pinterest.com stats.g.doubleclick.net *.useinsider.com ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net shopping.qantas.com ; frame-src 'self' api-accent.bloomreach.co *.qlstg.qantas.com www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.demdex.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com facebook.com foursixty.com google.com www.google.com vimeo.com ct.pinterest.com ; worker-src 'self' blob: *.accentgra.com *.platypusshoes.co.nz *.platypusshoes.com.au; 2 default-src 'self' *.fontawesome.com *.visualstudio.com cdn.cookielaw.org *.azure.com *.krxd.net *.facebook.com *.googletagmanager.com *.linkedin.oribi.io *.google.com *.doubleclick.net *.liveperson.net *.google-analytics.com fintactix.com *.adsrvr.org *.lpsnmedia.net *.elfsight.com;script-src 'self' 'unsafe-inline' unpkg.com code.jquery.com stackpath.bootstrapcdn.com customer.cludo.com cdnjs.cloudflare.com *.fontawesome.com *.googletagmanager.com *.licdn.com *.convergetrack.com js.monitor.azure.com *.adroll.com *.facebook.net *.google-analytics.com *.doubleclick.net *.lpsnmedia.net *.liveperson.net *.adsrvr.org *.google.com *.elfsight.com cdn.cookielaw.org maxcdn.bootstrapcdn.com cdn.jsdelivr.net;style-src 'self' 'unsafe-inline' customer.cludo.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net;img-src 'self' data: *.adsrvr.org *.convergetrack.com *.demdex.net *.google.com *.lpsnmedia.net *.linkedin.com *.facebook.com *.krxd.com *.krxd.net *.adroll.com *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.elfsight.com;font-src 'self' fonts.gstatic.com *.fontawesome.com 2 default-src 'self' https://s0.wp.com https://fonts.googleapis.com https://fonts.gstatic.com data:; frame-src 'self' data: blob: https://www.youtube.com https://player.vimeo.com https://wp-themes.com; img-src * data:; media-src * data:; style-src 'self' https://fonts.googleapis.com data: 'unsafe-inline'; script-src https://wp-themes.com 'self' data: 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; frame-ancestors 'self' https://hub.libraesva.com; report-uri https://sentry.libraesva.com/api/16/security/?sentry_key=ec35ea3e850202bb70633fcd5d55c698 2 img-src 'self' staccwexerius.blob.core.windows.net cdn.xerius.be consentcdn.cookiebot.com *.cookiebot.com data: *.google-analytics.com www.googletagmanager.com xerius-prd-911.azureedge.net media.xerius.be media.accdesk.be media.myfamily.be media.xerius-lei.eu *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.ads.linkedin.com *.linkedin.com connect.facebook.net www.facebook.com *.doubleclick.net *.tiktok.com dev.visualwebsiteoptimizer.com *.clarity.ms *.bing.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' app.varify.io media.xerius.be media.accdesk.be media.myfamily.be media.xerius-lei.eu cxppusa1formui01cdnsa01-endpoint.azureedge.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.googleadservices.com googleads.g.doubleclick.net pagead2.googlesyndication.com *.google-analytics.com *.doubleclick.net fonts.gstatic.com www.googleoptimize.com www.googletagmanager.com *.cookiebot.com consentcdn.cookiebot.com connect.facebook.net www.facebook.com *.ads.linkedin.com *.linkedin.com cdn.xerius.be staccwexerius.blob.core.windows.net xerius-prd-911.azureedge.net www.youtube.com data: xerius.piwik.pro www.gstatic.com script.hotjar.com static.hotjar.com js.monitor.azure.com js.cdn.applicationinsights.io js.cdn.monitor.azure.com *.tiktok.com amazon-adsystem.com *.amazon-adsystem.com paa-reporting-advertising.amazon *.paa-reporting-advertising.amazon trk.adbutter.net *.adnxs.com *.clarity.ms *.bing.com snap.licdn.com *.bannernow.com; worker-src 'none'; frame-ancestors 'self' auth.xerius.be 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; media-src 'self' https:; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.wilsonart.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.wilsonart.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://sogecommerce.societegenerale.eu/static/latest/images/type-carte/ https://api-sogecommerce.societegenerale.eu/static/ https://sogecommerce.societegenerale.eu/vads-payment/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com/ *.cloudflare.com *.google.com *.twitter.com *.twimg.com *.google.co.in *.ytimg.com *.googleadservices.com *.fontawesome.com *.mastercard.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.hotjar.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ https://static-sogecommerce.societegenerale.eu/static/ *.fontawesome.com *.googleapis.com *.gstatic.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://maps.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.bing.com *.zopim.com *.zdassets.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api-sogecommerce.societegenerale.eu/static/ https://static-sogecommerce.societegenerale.eu/static/ *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io *.wilsonart.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://maps.googleapis.com www.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.g.doubleclick.net *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' https://www.google-analytics.com https://brandcenter.flex.com; upgrade-insecure-requests; 2 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample'; style-src 'self' 'report-sample'; object-src 'none'; worker-src 'none'; 2 object-src 'none'; script-src 'self' 'unsafe-eval' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://rebilly.github.io https://static.addtoany.com https://unpkg.com https://webapp.recyclecoach.com maps.googleapis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://rebilly.github.io https://static.addtoany.com https://unpkg.com https://webapp.recyclecoach.com maps.googleapis.com platform.instagram.com platform.twitter.com; style-src 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 2 base-uri 'none'; connect-src 'self' analytics-ipv6.tiktokw.us api.ldnfrpl.com api.leadinfo.com c.ba.contentsquare.net cdn.cookielaw.org collector.leadinfo.net collector4.leadinfo.net *.bing.com *.bing.net *.brightsg.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.hubapi.com *.hubspot.com *.linkedin.com *.onetrust.com *.reddit.com *.redditstatic.com *.tiktok.com sentry.io wss://ws.hotjar.com; default-src 'none'; font-src https: data:; form-action 'self' *.hsforms.com shop.ie.brightsg.com; frame-ancestors 'self'; frame-src 'self' *.cloudflare.com *.google.com *.googletagmanager.com *.hs-sites-eu1.com *.hs-sites.com *.hsforms.com *.hubspot.com *.jotform.com *.vimeo.com *.youtube.com; img-src https: data: blob:; media-src https: data:; object-src 'none'; prefetch-src 'self' https:; report-uri https://brightsg.report-uri.com/r/d/csp/wizard; script-src 'self' 'unsafe-inline' cdn.cookielaw.org cdn.ldnfrpl.com cdn.leadinfo.net *.bing.com *.bing.net *.brightsg.com *.capterra.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.gstatic.com *.hotjar.com *.hotjar.io *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hsadspixel.net *.hsforms.net *.hubapi.com *.hubspot.com *.jotform.com *.licdn.com *.linkedin.com *.tiktok.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https:; upgrade-insecure-requests; worker-src 'self' blob:; report-uri https://brightsg.report-uri.com/r/d/csp/wizard; report-to csp-endpoint; 2 default-src 'self' blob: *; img-src 'self' data: *; script-src 'self' blob: * 'unsafe-inline' 'unsafe-eval'; style-src 'self' * 'unsafe-inline'; font-src 'self' data: *; connect-src *; frame-ancestors 'self'; base-uri 'self'; form-action 'self' 2 font-src storage.googleapis.com/rtux-rtux-data-integration-rti/ *.cloudflare.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action test.saferpay.com www.saferpay.com saferpay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com *.prismic.io *.google.com *.criteo.com *.criteo.net *.doubleclick.net *.pinterest.com *.facebook.com *.livechatinc.com *.sovendus-connect.com *.googletagmanager.com *.weltpixel.com www.xtento.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.prism.app-us1.com *.prismic.io *.bing.com *.google.ch *.trackjs.com *.google.com *.twiago.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.adform.net *.omnitagjs.com *.lehner-versand.ch *.casalemedia.com *.criteo.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.demdex.net *.livechat-files.com *.dmxleo.com *.profity.ch *.googleapis.com *.1rx.io www.xtento.com cdn.xtento.com test.saferpay.com www.saferpay.com saferpay.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ bx-cdn.com/static/bav2.min.js track.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/rti.min.js track.bx-cloud.com/static/rti.min.js bx-cdn.com/static/rti.min.js storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io *.trackjs.com *.gstatic.com *.livechatinc.com *.cdn.prismic.io *.google.com *.criteo.com *.pinimg.com *.bing.com *.adt313.net htm1.ch *.pinterest.com profity.ch *.profity.ch/clients/main.js *.getback.ch *.sovendus.com *.sovendus-connect.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.wi-platform-cloud.com *.bx-cdn.com *.googletagmanager.com *.bx-cloud.com *.doubleclick.net www.xtento.com cdn.xtento.com test.saferpay.com www.saferpay.com saferpay.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.getback.ch *.cloudflare.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src storage.googleapis.com/rtux-rtux-data-integration-rti/ *.googleapis.com storage.googleapis.com/*_rtux-data* 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com track.bx-cloud.com main.bx-cloud.com track-gw1.bx-cloud.com bx-cloud.com main.wi-platform-cloud.com r-st.bx-cloud.com track.bx-cloud.com/track/v2 storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io htm1.ch *.pinterest.com *.lehner-versand.ch *.criteo.com *.google.com *.getback.ch *.doubleclick.net *.wi-platform-cloud.com *.trackjs.com *.livechatinc.com *.sovendus.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.bing.com test.saferpay.com www.saferpay.com saferpay.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 upgrade-insecure-requests; report-to https://www.codium.ai; report-uri https://www.codium.ai; 2 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com cdn.qantasloyalty.com api-accent.bloomreach.co mpsnare.iesnare.com/snare.js api.smooch.io applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cfjump.vans.com.au cfjump.vans.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com dma-cdn.staging.truefitcorp.com/fitrec/dma/js/tracker.js js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com lantern.roeyecdn.com js-sandbox.squarecdn.com player.vimeo.com js.squarecdn.com *.stg.qantasloyalty.com/appcache/wid-redemptions-button/master/ ; style-src 'self' 'unsafe-inline' *.klaviyo.com/onsite/ display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com *.adobetm.com foursixty.com *.adobemc.com static.klaviyo.com/onsite/js static-tracking.klaviyo.com/onsite/js assets.api.useinsider.com/css *.klaviyo.com/onsite/ ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.vans.co.nz *.vans.com.au googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com adservice.google.com lantern.roeye.com d3k81ch9hvuctc.cloudfront.net ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' gateway.stg.qantasloyalty.com gateway.qantasloyalty.com api-accent.bloomreach.co analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.vans.co.nz *.fullstory.com *.klaviyo.com smetrics.vans.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com *.nr-data.net *.paypal.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com foursixty.com kleber.datatoolscloud.net.au sentry.io smetrics.hypedc.com vimeo.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com api.myunidays.com o19233.ingest.sentry.io/api/1188273/store ct.pinterest.com opreq.observepoint.com *.useinsider.com stats.g.doubleclick.net/g/collect *.stg.qantasloyalty.com/redemptions/ ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net shopping.qantas.com/static/fonts ; frame-src 'self' checkout.qantas.com api-accent.bloomreach.co www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.demdex.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com facebook.com foursixty.com google.com www.google.com vimeo.com *.qlstg.qantas.com/ ; worker-src 'self' blob: *.accentgra.com *.vans.co.nz *.vans.com.au; 2 frame-ancestors 'self' account.elama.global new.elama.ru elama.global *.elama.global *.elama.zone elama.ru *.elama.ru elama.com.br *.elama.com.br elama.kz *.elama.kz mc.yandex.ru mc.webvisor.com mc.webvisor.org yastatic.net webvisor.com http://webvisor.com metrika.yandex.ru yandex.com yandex.ru *.yandex.com *.yandex.net *.yandex.ru *.dev-morda.svc.elama-team.ru; report-uri https://sn.elama.global/api/26/security/?sentry_key=cf985e6d1e254161bef105622a6e28a4; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.flavedo.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com unpkg.com *.connectif.cloud *.privacy-center.org *.visualwebsiteoptimizer.com *.shippypro.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.shippypro.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.shippypro.com *.connectif.cloud t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.link.com *.amazon.com *.citrusad.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.facebook.com *.facebook.net *.google.com *.addthis.com *.pinterest.com www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com *.facebook.net https://www.magezon.com ozow-live-cdn.s3.eu-west-1.amazonaws.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://polyfill-fastly.io https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com s7.addthis.com *.facebook.com *.facebook.net *.avada.io *.google.com/ *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com www.youtube.com player.vimeo.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com ekr.zdassets.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.cloudflare.com *.twitter.com *.bootstrapcdn.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com https://plumrocket.com https://t.pepperjamnetwork.com *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.googleapis.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.googleadservices.com *.twitter.com *.adobedtm.com https://firebasestorage.googleapis.com https://img.youtube.com https://shareasale.com/sale.cfm https://track.linksynergy.com https://www.bizrate.com https://www.awin1.com https://*.zenaps.com https://track.webgains.com https://prf.hn https://track.flexlinks.com https://scripts.affiliatefuture.com https://t.powerreviews.com https://match.sharethrough.com https://cm.g.doubleclick.net https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://jadserve.postrelease.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://ps.eyeota.net https://public-prod-dspcookiematching.dmxleo.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com apis.google.com *.gstatic.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.trustedshops.com *.fontawesome.com graph.facebook.com *.adobedtm.com https://analytics.webgains.io *.avada.io *.shopify.com s7.addthis.com https://www.dwin1.com https://intljs.rmtag.com https://cdn.avmws.com https://images.bizrate.com https://www.awin1.com https://*.zenaps.com https://swrap.tradedoubler.com https://analytics.optimalpeople.fr https://www.linkconnector.com https://d3v27wwd40f0xu.cloudfront.net https://static.criteo.net https://sslwidget.criteo.com https://*.affiliatefuture.com https://static.powerreviews.com *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.bootstrapcdn.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.twitter.com https://get.geojs.io *.avada.io api.addressy.com ekr.zdassets.com/ https://shareasale.com/sale.cfm https://analytics.optimalpeople.fr https://measurement-api.criteo.com https://api.webgains.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com oct8necdneu.azureedge.net *.trustedshops.com *.cloudflare.com https://widgets.trustedshops.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es * *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://www.salesmanago.pl https://api.clerk.io https://cdn.clerk.io *.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.vimeo.com *.oct8ne.com *.googletagmanager.com * *.cookiebot.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.trustedshops.com *.bynder.com *.visualwebsiteoptimizer.com *.amazonaws.com *.atida.com *.dosfarma.com *.facebook.com *.zenaps.com *.awin1.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co t.co *.twitter.co *.twitter.com *.cloudfront.net *.doubleclick.net *.byspotify.com *.cookiebot.com *.googlesyndication.com *.syndigo.com *.assets.efarma.com *.mifarma.co.uk *.adscale.de *.usercentrics.eu cm.g.doubleclick.net r.casalemedia.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com *.pubmatic.com pixel.rubiconproject.com *.rubiconproject.com rtb-csync.smartadserver.com *.smartadserver.com criteo-sync.teads.tv *.teads.tv criteo-partners.tremorhub.com *.tremorhub.com eb2.3lift.com *.3lift.com ad.yieldlab.net *.yieldlab.net sync.1rx.io *.1rx.io *.criteo.com *.criteo.net *.consentcdn.cookiebot.eu *.atida.fr openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://cdn.clerk.io *.ggpht *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com polyfill.io https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.trustedshops.com *.clerk.io *.cloudfront.net *.zdassets.com *.zendesk.com *.api.smooch.io *.visualwebsiteoptimizer.com *.connectif.cloud *.atida.com *.dosfarma.com *.newrelic.com *.nr-data.net *.dwin1.com *.pinimg.com *.ads-twitter.com *.tiktok.com *.kk-resources.com *.bing.com *.creativecdn.com *.facebook.net *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.pinterest.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.cookiebot.eu *.clarity.ms *.roeyecdn.com *.cdn-apple.com *.lyra.com *.skeepers.io *.criteo.com static.ads-twitter.com connect.facebook.net tags.creativecdn.com *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.static.cloudflareinsights.com static.cloudflareinsights.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://api.clerk.io https://cdn.clerk.io *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.googleapis.com *.trustedshops.com *.cloudflare.com *.googletagmanager.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.consentcdn.cookiebot.eu unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://api.clerk.io https://cdn.clerk.io *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.google.com/pay *.api.smooch.io *.zdassets.com *.zendesk.com *.connectif.cloud *.atida.com *.dosfarma.com *.algolia.io *.cookiebot.com *.nr-data.net google.com *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.spotify.com *.criteo.com *.criteo.net ct.pinterest.com *.clarity.ms ad.doubleclick.net googleads.g.doubleclick.net consent.cookiebot.eu *.cookiebot.eu *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.amazonaws.com pay.google.com *.pay.google.com *.cdn.scalapay.com cdn.scalapay.com pixels.spotify.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-ancestors 'self'; report-uri https://www.goldcoastbulletin.com.au/csp-reports 2 default-src 'self'; img-src * data: https:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'unsafe-inline' *; frame-src https:; connect-src https:; font-src 'self' https://cdn.segmentify.com; 2 default-src https://*.axa.ch https://*.axa-ch.intraxa; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.axa.ch https://www.googletagmanager.com https://cdn.cookielaw.org https://cdn.mouseflow.com https://maps.google.com https://maps.googleapis.com https://connect.facebook.net https://axa-winterthur.dimelochat.com https://pay.sandbox.datatrans.com https://pay.datatrans.com https://recaptcha.net https://www.google.com https://www.gstatic.com/recaptcha/ https://bat.bing.com https://snap.licdn.com https://www.gstatic.com https://*.teads.tv https://*.survalyzer.swiss; style-src 'self' 'unsafe-inline' https://*.axa.ch https://fonts.googleapis.com https://www.googletagmanager.com https://*.survalyzer.swiss; img-src 'self' data: blob: https://*.axa.ch https://*.google.com https://*.google.ch https://maps.gstatic.com https://cdn.cookielaw.org https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://ad.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://i.ytimg.com https://px.ads.linkedin.com https://bat.bing.com https://d5cplpsrt2s33.cloudfront.net https://bat.bing.net https://maps.googleapis.com https://region1.google-analytics.com https://*.googlesyndication.com https://connect.facebook.net https://flagcdn.com https://px.ads.linkedin.com https://www.googleadservices.com https://www.gstatic.com https://*.teads.tv https://*.survalyzer.swiss; font-src 'self' data: https://*.axa.ch https://fonts.gstatic.com https://cdn.mouseflow.com https://assets.merci-app.com; connect-src 'self' https://*.axa.ch https://gtm.axa.ch https://sgtm.axa.ch https://region1.analytics.google.com https://www.google.com https://*.tt.omtrdc.net https://europe.directline.botframework.com https://digitalassistantbot-acc.azurewebsites.net https://cdn.cookielaw.org wss://europe.directline.botframework.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://o2.mouseflow.com https://www.google.ch https://selfadvisory-acc.azurewebsites.net https://*.onetrust.com https://bat.bing.com https://bat.bing.net https://px.ads.linkedin.com https://*.service.signalr.net https://pagead2.googlesyndication.com https://*.in.applicationinsights.azure.com https://www.googleadservices.com https://www.google-analytics.com wss://*.service.signalr.net https://*.mouseflow.com https://api.trongrid.io https://digitalassistantbot.azurewebsites.net https://www.facebook.com https://*.teads.tv https://snap.licdn.com https://*.survalyzer.swiss; frame-src https://*.axa.ch https://td.doubleclick.net https://8141516.fls.doubleclick.net https://www.youtube.com https://pay.sandbox.datatrans.com https://pay.datatrans.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://recaptcha.net https://www.googletagmanager.com https://*.survalyzer.swiss; block-all-mixed-content ; report-uri https://www.acc.axa.ch/servlets/external/csp-reports.csp 2 form-action 'report-sample' 'self' 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.audioeye.com akstat.io *.akstat.io cookielaw.org cdn.cookielaw.org *.google-analytics.com *.quantummetric.com quantummetric.com *.typekit.net www.googletagmanager.com tapestry.com *.tapestry.com tapestry.support *.licdn.com *.jwplatform.com *.jwpcdn.com cdn.jwplayer.com prd.jwpltx.com *.jwpsrv.com jsdelivr.net *.jsdelivr.net *.newrelic.com *-tapestry-news.pantheonsite.io cdnjs.cloudflare.com fonts.googleapis.com secure.gravatar.com px.ads.linkedin.com cdn.linkedin.oribi.io p.adsymptotic.com tapestry.gcs-web.com opensupplyhub.org *.akamaihd.net go-mpulse.net *.go-mpulse.net geolocation.onetrust.com stats.g.doubleclick.net fonts.gstatic.com data: blob:; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://code.jquery.com https://www.google.com https://www.gstatic.com https://cdn.userecho.com https://yandex.ru/ https://*.yandex.ru https://*.maps.yandex.net https://yastatic.net; font-src 'self' https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com; img-src 'self' data: https://*.starline.ru https://*.maps.yandex.net https://*.google.com https://enterprise.api-maps.yandex.ru https://cdn.userecho.com https://*.openstreetmap.org http://yandex.st/ https://yandex.st/ https://mc.yandex.ru https://yastatic.net; connect-src 'self' ws://*.starline.ru wss://rpl.starline-online.ru https://mc.yandex.ru https://geocode.starline.ru; frame-src 'self' https://*.google.com https://mc.yandex.ru/ https://arkan.ru; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://www.gstatic.com applepay.cdn-apple.com https://fonts.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.payplug.com *.dalenys.com api-qa.payplug.com secure-qa.payplug.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com https://*.afflelou.com https://p.sharinpix.com *.googlesyndication.com https://editor-assets.abtasty.com cdn.doofinder.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://flagcdn.com https://mafranchise.afflelou.com https://cms-mafranchise.afflelou.com *.googleapis.com https://*.gstatic.com https://mcstaging.afflelou.com https://secure-magenta.dalenys.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.disqus.com https://eu1-config.doofinder.com https://*.googlesyndication.com https://halc.iadvize.com https://static.iadvize.com https://iadvize.com https://static.livechat.iadvize.com https://api.iadvize.com https://try.abtasty.com https://msr.afflelou.com cdn.doofinder.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com afflelou.containers.piwik.pro *.googleapis.com https://*.gstatic.com https://vto-advanced-integration-api.fittingbox.com/ https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com https://cdn.payplug.com https://cdn-qa.payplug.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://try.abtasty.com *.doofinder.com assets.braintreegateway.com https://secure-magenta.dalenys.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://cdn.plyr.io https://*.googlesyndication.com https://halc.iadvize.com https://api.iadvize.com https://collector.iadvize.com wss://*.iadvize.com https://*.abtasty.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com afflelou.piwik.pro afflelou.containers.piwik.pro *.googleapis.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://int-bohds.afflelou.com https://int-bohds.afflelou.be https://int-bohds.afflelou.ch https://int-bohds.afflelou.ma https://int-bohds.afflelou.pt https://int-bohds.afflelou.es https://preprod-bohds.afflelou.com https://preprod-bohds.afflelou.be https://preprod-bohds.afflelou.ch https://preprod-bohds.afflelou.ma https://preprod-bohds.afflelou.pt https://preprod-bohds.afflelou.es https://bohds.afflelou.com https://bohds.afflelou.be https://bohds.afflelou.ch https://bohds.afflelou.ma https://bohds.afflelou.pt https://bohds.afflelou.es 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https: 2 font-src maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://geowidget.easypack24.net data: https://cdn.thulium.com/ script.hotjar.com widget.fitanalytics.com/ fontawesome.com *.fontawesome.com widget.fitanalytics.com static.lancerto.com data: 'self' 'unsafe-inline'; form-action www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com pay.google.com play.google.com testpay.autopay.eu pay.autopay.eu testcards.autopay.eu cards.autopay.eu secure.payu.com merch-prod.snd.payu.com smartforms.ekomi.com *.ekomiapps.de https://geowidget-app.inpost.pl/ https://pudofinder.dpd.com.pl/ *.google.com *.fls.doubleclick.net creativecdn.com gum.criteo.com *.hotjar.com facebook.com start.paypo.pl https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu static.criteo.net 'self' fledge.eu.criteo.com td.doubleclick.net *.creativecdn.com ct.pinterest.com ms.lancerto.com js-agent.newrelic.com *.googletagmanager.com csr.onet.pl ms.prochnik.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io imgsct.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com *.tiktok.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com testimages.autopay.eu images.autopay.eu *.inpost.pl static.payu.com *.gstatic.com *.googleapis.com *.ggpht lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://lancerto.com https://geowidget.easypack24.net https://osm.inpost.pl *.revhunter.tech assets.swarmcdn.com analytics.tiktok.com https://maps.googleapis.com/ https://maps.gstatic.com/ https://developers.google.com *.g.doubleclick.net pixel.wp.pl *.google.com facebook.com *.google-analytics.com www.google.pl google.pl script.hotjar.com data: smart-widget-assets.ekomiapps.de tbl.tradedoubler.com *.stickyadstv.com *.bing.com *.adform.net *.advertising.com ade.clmbtech.com *.criteo.com *.adnxs.com sync.outbrain.com *.analytics.yahoo.com *.yahoo.com *.tribalfusion.com sw-assets.ekomiapps.de *.taboola.com *.3lift.com *.rtb-csync.smartadserver.com *.casalemedia.com *.pixel.rubiconproject.com *.simage2.pubmatic.com *.criteo-sync.teads.tv *.360yield.com *.pubmatic.com *.bidswitch.net criteo-sync.teads.tv *.adscale.de *.omnitagjs.com *.smartadserver.com *.ivitrack.com *.ad.smaato.net *.sharethrough.com *.ssp.rambler.ru *.fls.doubleclick.net *.atdmt.com *.rubiconproject.com *.yieldlab.net *.e-planning.net *.ads.linkedin.com sync-tm.everesttech.net s-cs.send.microad.jp contextual.media.net us-u.openx.net cm.mgid.com pixel.tapad.com ad.as.amanad.adtdp.com an.yandex.ru trends.revcontent.com cw.addthis.com crb.kargo.com i.liadm.com jadserve.postrelease.com sync.aralego.com ad.mail.ru sync-criteo.ads.yieldmo.com a.twiago.com idsync.rlcdn.com criteo-partners.tremorhub.com d.turn.com https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu googleads4.g.doubleclick.net *.emxdgt.com *.googletagmanager.com static.lancerto.com htlfkw.lancerto.com s.thebrighttag.com beacon.krxd.net id5-sync.com exchange.mediavine.com https://csr.onet.pl https://upload.snrcdn.net *.clarity.ms dmp.adform.net ad.doubleclick.net ekomi-srr.s3.eu-central-1.amazonaws.com *.googlesyndication.com hb.yahoo.net *.salestube.pl dot.wp.pl mapa.orlenpaczka.pl tile.openstreetmap.org lantern.roeye.com *.analytics.google.com *.google.pl region1.analytics.google.com media.prochnik.pl media.lancerto.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ consent.cookiebot.com consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com *.tiktok.com testcards.autopay.eu cards.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com *.inpost.pl *.snrbox.com secure.payu.com secure.snd.payu.com *.googleapis.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud smartforms.ekomi.com *.ekomiapps.de https://geowidget.easypack24.net https://geowidget.inpost.pl https://bat.bing.com/ https://www.clarity.ms/ assets.swarmcdn.com web.snrbox.com https://cdn.thulium.com/ analytics.tiktok.com https://maps.googleapis.com/ *.google.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de *.googleadservices.com px.leadexpert.pl static.lamoda.pl *.hotjar.com pixel.wp.pl wrap.tradedoubler.com static.criteo.net sslwidget.criteo.com widget.fitanalytics.com metrics.fitanalytics.com metrics-nl.fitanalytics.com cdn.wootric.com swrap.tradedoubler.com ocdn.eu js-agent.newrelic.com bam-cell.nr-data.net *.platform.hicloud.com snap.licdn.com www.snrcdn.net unpkg.com *.doubleclick.net googletagservices.com *.googlesyndication.com www.googletagservices.com https://tbs.tradedoubler.com *.tradedoubler.com https://imgstatic.eu *.imgstatic.eu maps.googleapis.com 'unsafe-inline' https://tagmanager.google.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://cdn.juo.io https://sgqcvfjvr.onet.pl https://artemis-cdn.ocdn.eu https://player.vimeo.com https://lib.onet.pl dc.cux.io js.go2sdk.com *.creativecdn.com s.pinimg.com ct.pinterest.com cdn.jsdelivr.net ms.lancerto.com mapa.orlenpaczka.pl stapecdn.com ms.prochnik.pl www.dwin1.com *.bam.eu01.nr-data.net bam.eu01.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com testpay.autopay.eu pay.autopay.eu testcards.autopay.eu cards.autopay.eu *.googleapis.com *.snrcdn.net maxcdn.bootstrapcdn.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://geowidget.easypack24.net https://geowidget.inpost.pl assets.swarmcdn.com sw-assets.ekomiapps.de widget.fitanalytics.com customizations.fitanalytics.com www.snrcdn.net 'self' 'unsafe-inline'; object-src 'self' 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com assets.swarmcdn.com swarmify: blob: video-node.swarmcdn.com https://cdn.thulium.com/ chat-widget.thulium.com static.lancerto.com https://static.lancerto.com media.lancerto.com media.prochnik.pl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.google-analytics.com *.snrbox.com secure.payu.com merch-prod.snd.payu.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud smartforms.ekomi.com *.ekomiapps.de https://geowidget.easypack24.net https://api-pl-points.easypack24.net https://osm.inpost.pl https://bat.bing.com/ *.clarity.ms video-node.swarmcdn.com wss://hornets.swarmcdn.com *.swarmcdn.com https://cdn.thulium.com/ analytics.tiktok.com https://maps.googleapis.com/ *.g.doubleclick.net wss://v18dxapjmd.execute-api.eu-west-1.amazonaws.com *.google.com smart-widget-assets.ekomiapps.de *.hotjar.com *.facebook.com clk.leadexpert.pl wss://ws17.hotjar.com data: eligibility.wootric.com bam-cell.nr-data.net web.snrbox.com widget.fitanalytics.com https://in.juo.io https://csr.onet.pl wss://n-541921153-0-27272500-1569843303-5d91e8674295d.track.cux.io events.ocdn.eu bat.bing.com google.com/pay *.analytics.google.com pixel.wp.pl measurement-api.criteo.com pagead2.googlesyndication.com *.creativecdn.com ct.pinterest.com ms.lancerto.com js-agent.newrelic.com ms.prochnik.pl *.google.pl *.bam.eu01.nr-data.net bam.eu01.nr-data.net 'self' 'unsafe-inline'; child-src https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu bam.eu01.nr-data.net http: https: blob: 'self' 'unsafe-inline'; default-src 'self' *.bam.eu01.nr-data.net bam.eu01.nr-data.net media.lancerto.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri bam.eu01.nr-data.net 'self' 'unsafe-inline'; 2 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com kit.fontawesome.com connect.facebook.net cdn.polyfill.io code.jquery.com www.google-analytics.com ssl.google-analytics.com www.googleoptimize.com script.crazyegg.com cdn.syndication.twimg.com speedtest.bestbroadbanddeals.co.uk cdnjs.cloudflare.com maxcdn.bootstrapcdn.com widget.trustpilot.com s3.amazonaws.com cable.us4.list-manage.com admin.bestbroadbanddeals.co.uk services.xg4ken.com unpkg.com script.hotjar.com static.hotjar.com c5.adalyser.com plausible.io consent.cookiebot.com consentcdn.cookiebot.com e.infogram.com localhost:3000; connect-src 'self' consentcdn.cookiebot.com *.fontawesome.com api.addressy.com wss://ws.hotjar.com *.hotjar.com content.hotjar.io cable.us4.list-manage.com admin.bestbroadbanddeals.co.uk stats.g.doubleclick.net plausible.io localhost:3000; img-src 'self' data: *.bestbroadbanddeals.co.uk www.google.com www.googletagmanager.com www.google.co.uk www.google-analytics.com s1.2mdn.net ad.doubleclick.net stats.g.doubleclick.net gtrk.s3.amazonaws.com pbs.twimg.com code.jquery.com 19.xg4ken.com s3-eu-west-1.amazonaws.com pcf.tdscd.com c5.adalyser.com v2.crocdn.com 540k006f.tinifycdn.com imgsct.cookiebot.com; style-src 'self' 'unsafe-inline' code.jquery.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com admin.bestbroadbanddeals.co.uk pro.fontawesome.com localhost:3000; font-src 'self' *.fontawesome.com maxcdn.bootstrapcdn.com admin.bestbroadbanddeals.co.uk data: localhost:3000; object-src 'self' api.ookla.com fpdownload.adobe.com; frame-src 'self' widget.trustpilot.com vars.hotjar.com googleads.g.doubleclick.net consentcdn.cookiebot.com e.infogram.com data:; child-src 'self' blob:; report-uri /csp-violation-report/ 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://mobbex.com *.weltpixel.com *.getblue.io *.doubleclick.net *.criteo.com *.groovinads.com www.tfaforms.com https://mercadopago.com.ar https://www.mercadopago.com.ar 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://res.sugaway.io *.visualwebsiteoptimizer.com https://*.g.doubleclick.net *.clarity.ms *.bing.com mcstaging.sommiercenter.com *.groovinads.com *.criteo.com https://facebook.com url.directo.com.ar https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://www.gstatic.com https://ssl.gstatic.com https://ad.doubleclick.net https://ade.googlesyndication.com https://www.mercadopago.com.ar https://m.facebook.com https://maps.googleapis.com https://www.afip.gob.ar https://www.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://live.decidir.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://www.google.com https://maps.googleapis.com api.wcx.cloud f.wcentrix.com https://www.googletagmanager.com tagmanager.google.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.hotjar.com *.cardinalcommerce.com *.embluemail.com *.navdmp.com *.zdassets.com *.visualwebsiteoptimizer.com *.getblue.io *.zopim.com *.clarity.ms *.groovinads.com *.criteo.net *.criteo.com *.decidir.com https://*.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https//static.zdassets.com https://v2.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.embluemail.com https://fonts.googleapis.com https://*.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com bedtime.com.ar *.bedtime.com.ar 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://developers.decidir.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://www.google-analytics.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ wss://widget-mediator.zopim.com *.braindw.com *.clarity.ms *.zdassets.com *.zendesk.com *.embluemail.com *.visualwebsiteoptimizer.com *.criteo.com *.decidir.com https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://maps.googleapis.com https://www.google.com.ar https://analytics.google.com/g/collect https://www.google.com.ar/ads https://ad.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src *.certcapture.com https://aws-staging-aeroprecisionusa.smarterspecies.com https://aws-staging-2-aeroprecisionusa.smarterspecies.com/ https://www.aeroprecisionusa.com blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; upgrade-insecure-requests ; frame-ancestors 'self' *.avantlink.com *.certcapture.com *.credova.com www.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.publicsquare.com 'self'; form-action 'self' https://enews.aeroprecisionusa.com/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/ https://cdn.listrakbi.com https://mediacdn.espssl.com *.adobe.com *.certcapture.com https://maxcdn.bootstrapcdn.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.avmws.com https://cdn.listrakbi.com https://s1.listrakbi.com https://m1.listrakbi.com https://at1.listrakbi.com https://www.google-analytics.com https://www.google.com https://maps.google.com https://maps.googleapis.com https://www.googletagmanager.com https://www.gstatic.com https://jstest.authorize.net https://*.addthis.com https://v1.addthisedge.com https://z.moatads.com https://ssl.avmws.com https://bat.bing.com/bat.js https://js.hs-scripts.com https://js-agent.newrelic.com https://bam.nr-data.net https://player.vimeo.com https://f.vimeocdn.com https://widget-prime.rafflecopter.com https://js.hs-banner.com/ https://v2.zopim.com https://js.hs-analytics.net https://static.zdassets.com https://widget-mediator.zopim.com/ https://bam-cell.nr-data.net/ https://cdn.quantummetric.com https://plugin.credova.com https://tags.clickagy.com https://tags.clickagy.com/ https://widget.gleamjs.io *.upsellit.com https://upsellit.com https://prod.upsellit.com/ https://bl.listrakbi.com https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.3.4/owl.carousel.min.js https://cdnjs.cloudflare.com/ajax/libs/jquery.inputmask/3.3.1/jquery.inputmask.bundle.js assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.certcapture.com https://static.elfsight.com *.credova.com https://js.hs-banner.com https://bat.bing.com https://ekr.zdassets.com https://plugin.credova.com/plugin.min.js https://www.youtube.com *.gettopple.com *.aggle.net cdn.mouseflow.com *.googleapis.com *.gstatic.com *.kaptcha.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://developer.adobe.com https://assets.armanet.us https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.publicsquare.com *.basistheory.com *.sitevibes.com sitevibes.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; media-src https://static.zdassets.com/ *.adobe.com 'self' 'unsafe-inline'; img-src 'self' https://stats.g.doubleclick.net https://mediacdn.espssl.com https://www.xtento.com/media/images/ https://*.listrakbi.com https://www.google.com https://www.google.com.ua https://store.paradoxlabs.com https://cdn.klarna.com https://tracking.avantlink.com https://bat.bing.com https://bam.nr-data.net https://www.googletagmanager.com https://track.hubspot.com https://v2.zopim.com data: https://maps.gstatic.com https://maps.googleapis.com https://www.google-analytics.com https://pippio.com https://d2df4e9l5rljaz.cloudfront.net https://api.delivrabl.net https://aorta.clickagy.com https://idsync.rlcdn.com https://us-u.openx.net https://cm.g.doubleclick.net https://yotpo-editor-production.s3.amazonaws.com https://aa.agkn.com https://sync.crwdcntrl.net https://pixel-sync.sitescout.com https://d.agkn.com https://region1.google-analytics.com https://v2assets.zopim.io https://js.gleam.io https://upsellit.com https://prod.upsellit.com/ *.upsellit.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.certcapture.com https://files.elfsightcdn.com https://sca1.listrakbi.com https://img.youtube.com https://via.placeholder.com *.gettopple.com *.googleapis.com *.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.publicsquare.com *.sitevibes.com sitevibes.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; frame-src 'self' https://www.full30.com https://s7.addthis.com https://player.vimeo.com https://www.google.com https://widget-prime.rafflecopter.com https://ssl.kaptcha.com https://hemsync.clickagy.com https://gleam.io https://upsellit.com https://prod.upsellit.com/ *.upsellit.com fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.credova.com * https://tst.kaptcha.com www.google.com https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.publicsquare.com *.basistheory.com *.sitevibes.com sitevibes.com www.xtento.com 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://assets.iglobalstores.com/ https://v2.zopim.com/ https://yotpo-stool.s3.amazonaws.com https://maxcdn.bootstrapcdn.com https://993ecd1fa9.nxcli.io *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.sitevibes.com sitevibes.com data: 'self' 'unsafe-inline'; connect-src 'self' https://api2.authorize.net/ https://js.authorize.net https://jstest.authorize.net https://apitest.authorize.net https://m.addthis.com https://bat.bing.com https://bam.nr-data.net/ https://bat.bing.com/ https://ekr.zdassets.com/ https://www.google-analytics.com https://stats.g.double.analytics.js https://assets.iglobalstores.com/ wss://widget-mediator.zopim.com/ https://*.listrak.com/ https://*.listrakbi.com/ https://stats.g.doubleclick.net/ https://bam-cell.nr-data.net/ https://oc.listrakbi.com/coupon https://enews.aeroprecisionusa.com/ https://aeroprecisionsupport.zendesk.com/ https://aeroprecision-app.quantummetric.com/ https://rl.quantummetric.com/ https://region1.google-analytics.com https://aorta.clickagy.com https://hemsync.clickagy.com https://maps.googleapis.com https://vimeo.com https://upsellit.com https://prod.upsellit.com/ *.upsellit.com https://cdn.listrakbi.com https://bl.listrakbi.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://core.service.elfsight.com *.credova.com https://api2.authorize.net wss://widget-mediator.zopim.com https://onsite-api.listrak.com https://product.listrakbi.com https://stats.g.doubleclick.net https://aeroprecision-app.quantummetric.com https://rl.quantummetric.com https://sandbox-lending-api.credova.com https://lending-api.credova.com *.gettopple.com oirt.aggle.net https://www.stagarms.com *.googleapis.com *.kaptcha.com https://srv.armanet.us https://assets.armanet.us https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.publicsquare.com *.basistheory.com *.launchdarkly.com *.browser-intake-datadoghq.com *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; 2 default-src 'self'; img-src *; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.acer.org https://kit.fontawesome.com https://cdnjs.cloudflare.com https://code.jquery.com https://cdn.jsdelivr.net https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com https://cdn.monsido.com https://www.gstatic.com/call-tracking/ https://www.google.com/recaptcha/ https://static.ads-twitter.com https://snap.licdn.com https://connect.facebook.net https://googleads.g.doubleclick.net https://maxcdn.bootstrapcdn.com/bootstrap/ https://stackpath.bootstrapcdn.com/bootstrap/ https://*.adroll.com https://fast.wistia.com/embed/medias/ https://fast.wistia.com/assets/external/ https://acer.tfaforms.net/ https://www.tfaforms.com/wForms/ https://platform.twitter.com/ https://widgets.sociablekit.com/ https://cdn.mouseflow.com/ https://js.createsend1.com/javascript/ https://bat.bing.com; style-src 'self' 'unsafe-inline' https://*.acer.org https://fonts.googleapis.com https://cdnjs.cloudflare.com https://www.gstatic.com https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/ https://acer.tfaforms.net/dist/ https://acer.tfaforms.net/uploads/themes/ https://www.tfaforms.com/dist/ https://widgets.sociablekit.com/ https://kit.fontawesome.com https://maxcdn.bootstrapcdn.com/font-awesome/; img-src 'self' data: blob: https://*.acer.org https://www.acer-ibt.org https://www.researchconference.com.au https://www.immchallenge.org.au https://www.stemgames.org.au https://tracking.monsido.com https://www.google.com.au/ads/ https://www.google.com.au/pagead/ https://www.google.com https://www.google-analytics.com/ https://www.googletagmanager.com https://px.ads.linkedin.com https://media.licdn.com/dms/image/ https://media.licdn.com/dms/image/ https://sociablekit.com/app/ https://images.sociablekit.com/ https://t.co/i/ https://analytics.twitter.com/i/ https://www.facebook.com/tr/ https://ping.eeharbor.com https://*.adroll.com https://bat.bing.com; font-src 'self' data: https://*.acer.org https://fonts.googleapis.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://ka-p.fontawesome.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/; media-src 'self' https://www.acer.org https://www.youtube.com https://player.vimeo.com; frame-src https://www.google.com/recaptcha/ https://www.googletagmanager.com https://platform.twitter.com/widgets/ https://www.acer.org https://www.youtube.com https://player.vimeo.com https://shorthand.com; connect-src 'self' https://*.acer.org https://ka-p.fontawesome.com https://kit.fontawesome.com https://www.google.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://www.googleadservices.com https://www.google.com.au/pagead/ https://acer.tfaforms.net/api_v2/ https://stats.g.doubleclick.net/ https://www.facebook.com/tr/ https://updates.expressionengine.com https://px.ads.linkedin.com/wa/; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-uri https://csp-testing.acer.org/reportOnly/index; 2 default-src https: data:; script-src https: data: 'unsafe-inline' 'unsafe-eval'; style-src https: data: 'unsafe-inline'; frame-ancestors 'self'; report-uri https://stoklasa.report-uri.io/r/default/csp/reportOnly 2 default-src 'self'; script-src 'self' 'unsafe-eval' https://prototype.local.next.helmholtz-munich.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://*.dzd-ev.de https://images.admiralcloud.com https://prototype.local.next.helmholtz-munich.de; base-uri 'self'; frame-src 'self' https://player.vimeo.com https://www.youtube-nocookie.com; connect-src 'self' https://*.dzd-ev.de wss://*.dzd-ev.de/ https://sentry2.in2code.de/api/62/security/ wss://prototype.local.next.helmholtz-munich.de/ https://hmwa.helmholtz-munich.de; style-src 'self' 'unsafe-inline' 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://prototype.local.next.helmholtz-munich.de 'report-sample'; script-src-elem 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de https://hmwa.helmholtz-munich.de 'report-sample'; font-src 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de; report-uri https://sentry2.in2code.de/api/62/security/?sentry_key=c8671bb1cf909cd134a5b859fc8d36e1 2 default-src 'self' 'unsafe-eval' 'unsafe-inline' essentialed.com *.essentialed.com passged.com *.passged.com d2lpurk2qe2oc.cloudfront.net d3ebkza70oew6x.cloudfront.net dpg0n9q1lsnov.cloudfront.net d37nqy2yusfq54.cloudfront.net d2pfk5on3dtp5q.cloudfront.net js-agent.newrelic.com bam.nr-data.net *.typekit.net *.google.com *.google.ca *.google.com.mx *.google.co.uk *.google.de *.googletagmanager.com *.google-analytics.com *.googleapis.com *.doubleclick.net *.googlesyndication.com *.gstatic.com *.wistia.com *.wistia.net *.litix.io *.credly.com *.hubspot.com *.hs-banner.com *.hs-analytics.net *.hs-analytics.com *.hs-scripts.com *.hsforms.com *.hsforms.net *.hscollectedforms.net *.plyr.io *.crazyegg.com *.hotjar.com *.hotjar.io analytics.tiktok.com *.bing.com hiset.org *.clarity.ms *.jquery.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.paypal.com *.paypalobjects.com js.stripe.com *.facebook.com *.facebook.net widget.trustpilot.com unpkg.com data: ws: wss: about: blob:; frame-ancestors 'self' essentialed.com *.essentialed.com passged.com *.passged.com 2 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.multisafepay.com www.magmodules.eu *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net https://cdn.polyfill.io https://browser.sentry-cdn.com *.multisafepay.com https://pay.google.com squeezely.tech www.squeezely.tech *.squeezely.tech *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com *.fontawesome.com *.multisafepay.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io *.multisafepay.com squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.klaviyo.com *.cdnfonts.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.com *.amazon-adsystem.com *.doubleclick.net *.sitescout.com *.adsrvr.org *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.googleapis.com media.sezzle.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com/mapfiles/api-3/images/* *.s3.amazonaws.com *.net/company/SPJKye/images/* *.google.co.in *.cloudfront.net *.facebook.com *.amazonaws.com https://maps.googleapis.com *.sitescout.com trkn.us *.zdassets.com *.zendesk.com *.zdusercontent.com *.nextdoor.com *.redditstatic.com *.reddit.com *.amazon-adsystem.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net *.googleapis.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudfront.net/js/grin-sdk.js *.googleapis.com/maps/* *.googleapis.com/maps-api-v3/api/js *.zdassets.com *.mouseflow.com *.jquery.com *.direct/feathersnap.js *.facebook.net/en_US/fbevents.js *.facebook.net *.facebook.com *.googletagmanager.com *.amazon-adsystem.com *.googleadservices.com *.google-analytics.com *.klaviyo.com q.stripe.com *.basis.net *.smooch.io *.adsrvr.org *.redditstatic.com *.nextdoor.com safevisit.online tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com https://static.klaviyo.com https://cdn.jsdelivr.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com fonts.cdnfonts.com *.stripe.network *.stripecdn.com *.amazon.com *.cdnfonts.com *.typekit.net *.sezzle.com *.net/ffj4apz.css *.klaviyo.com tagmanager.google.com fonts.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com/cdn-cgi/trace *.googleapis.com/maps/api/* *.grin.co/fingerprint/* *.sezzle.com *.grin.co *.g.doubleclick.net https://ipapi.co *.zendesk.com *.googleapis.com *.ipdata.co *.googletagmanager.com *.mouseflow.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.webpagefx.org *.facebook.com *.zdassets.com *.smooch.io wss://api.smooch.io *.redditstatic.com *.reddit.com *.adsrvr.org *.analytics.google.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; child-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googleadservices.com https://*.storage.googleapis.com https://*.vimeo.com https://vimeo.com https://octus.chilipiper.com https://app.pendo.io https://cookie-cdn.cookiepro.com https://*.cookiepro.com https://cdn.cookielaw.org https://ajax.googleapis.com https://widget.surveymonkey.com https://go.octus.com https://go.reorg-research.com https://*.pardot.com https://cdn.pendo.io https://*.pendo.io https://*.doubleclick.net https://js.chilipiper.com https://cdn.us.heap-api.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://rs.fullstory.com https://edge.fullstory.com https://px.ads.linkedin.com https://analytics.google.com https://snap.licdn.com https://stats.g.doubleclick.net https://dev.visualwebsiteoptimizer.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https://*.algolia.net https://*.algolia.io https://*.algolianet.com https://www.googleadservices.com https://*.doubleclick.net https://app.pendo.io https://*.pendo.io https://geolocation.onetrust.com https://*.cookiepro.com https://cdn.cookielaw.org https://go.octus.com https://c.us.heap-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://rs.fullstory.com https://edge.fullstory.com https://px.ads.linkedin.com https://analytics.google.com https://snap.licdn.com https://*.doubleclick.net https://stats.g.doubleclick.net https://dev.visualwebsiteoptimizer.com; frame-src 'self' https://app.vwo.com https://vimeo.com https://octus.chilipiper.com https://player.vimeo.com https://www.googletagmanager.com https://www.surveymonkey.com https://td.doubleclick.net https://go.octus.com https://reorg-research.chilipiper.com https://www.podbean.com https://*.podbean.com https://res.cloudinary.com https://*.cloudinary.com; worker-src 'self' blob:; report-uri https://octus.com/wp-json/csp/v1/report/; report-to csp-endpoint; 2 script-src 'unsafe-eval' 'unsafe-inline' data: 'self' blob: www.google-analytics.com www.googletagmanager.com ajax.googleapis.com www.google.com js.klevu.com www.gstatic.com *.cloudmaestro.com www.googleadservices.com googleads.g.doubleclick.net r2-t.trackedlink.net static.hotjar.com wchat.freshchat.com staticw2.yotpo.com browser-update.org script.hotjar.com dev.visualwebsiteoptimizer.com js-agent.newrelic.com bam-cell.nr-data.net *.freshchat.com maps.googleapis.com assets.adobedtm.com www.googleoptimize.com h.online-metrix.net *.cardinalcommerce.com html5.dcatalog.com unpkg.com commerce.adobedtm.com cdnjs.cloudflare.com web-sdk.aptrinsic.com commerce.adobe.net fonts.googleapis.com magento-recs-sdk.adobe.net static.trackedweb.net tags.srv.stackadapt.com snap.licdn.com tags.srv.stackadapt.com bat.bing.com e.performancehealth.com f.vimeocdn.com tags.srv.stackadapt.com bam.nr-data.net services-connector-ui.magento-ds.com r2.dotdigital-pages.com *.punchout2go.com *.tradecentric.com *.pinterest.com *.facebook.net *.facebook.com *.licdn.com *.userway.org cdn.optimizely.com optimizely.com performancehealth.freshchat.com; style-src 'self' 'unsafe-inline' wchat.freshchat.com fonts.googleapis.com js.klevu.com tags.srv.stackadapt.com staticw2.yotpo.com; report-uri /.webscale/csp-report 2 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local 'self' data: *.twitter.com *.twimg.com *.zopim.com data: 'self' 'unsafe-inline'; form-action self *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.facebook.com *.twitter.com yaby.eu 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.restorio.cz 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.facebook.com platform.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.google.com *.googletagmanager.com *.ladesk.com elibro.ladesk.com *.ec1.vbus.apps.ladesk.com *.gopay.cz *.gopay.com *.hotjar.com *.outfindo.com *.packeta.com *.pinterest.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com data: *.facebook.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu media.restorio.cz media.restorio.sk media.restorio.eu yaby.eu *.yaby.eu *.vegadesign.cz *.vegadesign.local blob: *.ceneo.pl *.bing.com *.bing.net *.clarity.ms *.doofinder.com eu1-doofinderuser.s3.amazonaws.com *.doubleclick.net *.g.doubleclick.net *.facebook.net *.google.at *.google.be *.google.bg *.google.com google.com *.google.com.au *.google.com.cr *.google.com.cy *.google.com.do *.google.com.eg *.google.com.mt *.google.com.mx *.google.com.ph *.google.com.tr *.google.com.ua *.google.co.il *.google.co.in *.google.co.jp *.google.co.ma *.google.co.nz *.google.co.th *.google.co.tw *.google.co.uk *.google.ae *.google.by *.google.ca *.google.ch *.google.cz *.google.de *.google.dk *.google.es *.google.fi *.google.fr *.google.gr *.google.hr *.google.hu *.google.ie *.google.is *.google.it *.google.lu *.google.lv *.google.md *.google.me *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.rs *.google.se *.google.sk *.google.tn *.google.tr *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.googleusercontent.com *.googlesyndication.com *.heureka.cz *.heureka.sk im9.cz *.imedia.cz *.packeta.com *.seznam.cz t.co *.tiktok.com *.twiago.com *.twitter.com *.twimg.com *.ytimg.com *.zopim.com *.ziskejte.cz *.zbozi.cz *.criteo.com *.criteo.net ad.360yield.com eb2.3lift.com *.adform.net *.adnxs.com *.adnxs.net *.bidswitch.net r.casalemedia.com *.emxdgt.com id5-sync.com matching.ivitrack.com beacon.krxd.net *.1rx.io exchange.mediavine.com contextual.media.net visitor.omnitagjs.com sync.outbrain.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com sync-t1.taboola.com/ criteo-sync.teads.tv criteo-partners.tremorhub.com sync.targeting.unrulymedia.com *.yahoo.net ad.yieldlab.net sync-criteo.ads.yieldmo.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://browser.sentry-cdn.com *.googletagmanager.com *.facebook.net cdn.jsdelivr.net connect.facebook.net twitter.com platform.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu static.restorio.cz static.restorio.sk static.restorio.eu *.vegadesign.cz *.vegadesign.local *.addthis.com *.adform.net *.bing.com *.cloudflare.com *.ceneo.pl *.clarity.ms *.cloudflareinsights.com *.cookiehub.com cookiehub.net *.cookiehub.eu *.criteo.com *.criteo.net *.daktela.com *.dognet.sk login.dognet.sk *.doofinder.com *.doubleclick.net *.facebook.com *.fontawesome.com *.googleadservices.com *.google-analytics.com *.googlesyndication.com *.google.com *.google.cz *.gopay.cz *.gopay.com *.hotjar.com im9.cz *.im9.cz *.imedia.cz *.ladesk.com *.outfindo.com *.packeta.com *.pinterest.com *.pinimg.com *.selltoro.com *.seznam.cz sc-static.net *.srovname.cz stapecdn.com *.tiktok.com *.ads-twitter.com *.twitter.com *.twimg.com *.zbozi.cz *.zdassets.com *.zopim.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.restorio.cz *.restorio.sk *.restorio.eu static.restorio.cz static.restorio.sk static.restorio.eu *.vegadesign.cz *.vegadesign.local *.cloudflare.com *.cookiehub.com *.cookiehub.eu cookiehub.net *.doofinder.com *.googleapis.com *.gstatic.com *.twitter.com *.twimg.com *.zopim.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com https://*.ingest.sentry.io *.google-analytics.com *.restorio.cz *.restorio.sk *.restorio.eu yaby.eu *.vegadesign.cz *.vegadesign.local *.bing.com *.bing.net *.clarity.ms *.cookiehub.com *.cookiehub.net cookiehub.net *.cookiehub.eu restorio.bot.coworkers.ai wss://restorio.bot.coworkers.ai *.criteo.com *.criteo.net *.doofinder.com wss://eu1-layer.doofinder.com wss://eu1-recommendations.doofinder.com *.doubleclick.net *.facebook.com *.facebook.net google.com *.google.com *.google.cz *.google.sk adservice.google.com *.googleadservices.com *.googlesyndication.com *.gopay.cz *.gopay.com *.outfindo.com *.packeta.com *.pinterest.com *.selltoro.com *.seznam.cz *.srovname.cz *.tiktok.com *.tiktokw.us *.twitter.com *.twimg.com *.yaby.eu *.zdassets.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.gopay.cz *.gopay.com *.yaby.eu yaby.eu 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sentry.vegadesign.cz/api/4/security/?sentry_key=aabf49608cca46b2bf8fb3c0ad2a8eba; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cybersource.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.cybersource.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.bird.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://img.youtube.com *.online-metrix.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://dev.visualwebsiteoptimizer.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page https://fmgaggi.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com s7.addthis.com *.cardinalcommerce.com *.online-metrix.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://dev.visualwebsiteoptimizer.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://fmgaggi.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ekr.zdassets.com/ *.cardinalcommerce.com *.online-metrix.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google.com google.com https://dev.visualwebsiteoptimizer.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://*.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com *.tradecentric.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.google.com *.doubleclick.net *.facebook.com *.affirm.com *.affirm.ca *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com *.tradecentric.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com https://*.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.affirm.com *.affirm.ca www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.affirm.com *.affirm.ca *.attn.tv events.attentivemobile.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.tradecentric.com * *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.klarnacdn.net *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.tradecentric.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.affirm.com *.affirm.ca *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com * *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self';base-uri 'self' https://d6tizftlrpuof.cloudfront.net/live/;connect-src 'self' https://api.cz.nl https://app.talkjs.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://czgroep.piwik.pro https://dev.visualwebsiteoptimizer.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com;font-src 'self' data:;frame-src 'self' https://consentcdn.cookiebot.com https://overzicht.cz.nl;frame-ancestors 'self';img-src 'self' https://6005850.global.siteimproveanalytics.io https://d6tizftlrpuof.cloudfront.net https://dev.visualwebsiteoptimizer.com https://imgsct.cookiebot.com;manifest-src 'self';media-src 'self' https://cdn.talkjs.com;object-src 'self';script-src 'self' https://cdn.talkjs.com https://cdstatic-sc.cz.nl https://consent.cookiebot.com https://consentcdn.cookiebot.com/consentconfig/ https://czgroep.containers.piwik.pro/ppms.js https://dev.visualwebsiteoptimizer.com https://inzicht.cz.nl/containers/ https://siteimproveanalytics.com/js/ https://w.usabilla.com https://www.googletagmanager.com 'unsafe-inline' 'unsafe-eval';style-src 'self' https://cdstatic-sc.cz.nl 'unsafe-inline';worker-src 'self' blob:; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.spotify.com https://geowidget.easypack24.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com apm.przelewy24.pl *.spotify.com https://aptekaradicula.pl https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com static.przelewy24.pl gstatic.com *.spotify.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com tagmanager.google.com *.disqus.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.spotify.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com *.spotify.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl *.spotify.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-ancestors 'self' https://bioland.we.network/ https://my.dlv.de/ 2 default-src https: 'unsafe-inline' 2 report-to https://r4com.report-uri.io/r/default/csp/reportOnly 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com static.klaviyo.com www.shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com tracking.avantlink.com dgjcoqnzn763b.cloudfront.net www.shopperapproved.com seal.trustguard.com tgscript.s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com acsbapp.com *.google-analytics.com js-agent.newrelic.com googletagmanager.com *.hotjar.com ssl.avmws.com d395yjvh5spyzw.cloudfront.net edge.curalate.com www.google.com *.googleapis.com config.gorgias.chat contact.gorgias.help s.pinimg.com *.pinterest.com https://cdn.searchspring.net/intellisuggest/is.min.js www.shopperapproved.com shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com analytics.tiktok.com tgscript.s3.amazonaws.com https://app.zinrelo.com app.zinrelo.com https://cdn.zinrelo.com/js/all.js snapui.searchspring.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com www.gstatic.com www.shopperapproved.com use.typekit.net p.typekit.net tgscript.s3.amazonaws.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn.acsbapp.com stats.g.doubleclick.net *.google-analytics.com googletagmanager.com *.hotjar.io *.hotjar.com wss://*.hotjar.com *.tiktokw.us *.googleapis.com config.gorgias.chat wss://us-east1-898b.gorgias.chat s.pinimg.com ct.pinterest.com *.pinterest.com https://beacon.searchspring.io/beacon shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com analytics.tiktok.com api.trustguard.com *.searchspring.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src assets.gorgias.chat 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' *.nationalgrideso.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.hotjar.com *.clarity.ms bing.com *.bing.com players.brightcove.net *.nationalgrideso.com www.googletagmanager.com assets.juicer.io js.createsend1.com www.smartsurvey.co.uk assets.smartsurvey.io snap.licdn.com unpkg.com js-agent.newrelic.com *.cookieyes.com cdn-cookieyes.com my.visme.co; style-src 'self' 'unsafe-inline' *.nationalgrideso.com assets.juicer.io unpkg.com fonts.googleapis.com; img-src 'self' data: *.nationalgrideso.com *.clarity.ms www.googletagmanager.com *.google.co.uk c.bing.com www.juicer.io assets.juicer.io www.smartsurvey.co.uk *.cartocdn.com datanationalgrideso.files.wordpress.com *.tile.openstreetmap.org *.linkedin.com *.cookieyes.com cdn-cookieyes.com; frame-src 'self' *.nationalgrideso.com *.nationalgrid.com players.brightcove.net www.youtube.com app.powerbi.com my.visme.co; font-src 'self' themes.googleusercontent.com static.juicer.io fonts.googleapis.com fonts.gstatic.com; connect-src 'self' *.clarity.ms *.hotjar.io *.hotjar.com *.google-analytics.com *.analytics.google.com storage.googleapis.com www.juicer.io *.staging.datopian.com bam.nr-data.net *.cookieyes.com cdn-cookieyes.com 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://*.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://widgets.trustedshops.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sendcloud.sc *.jsdelivr.net js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://belco-prod.s3-eu-central-1.amazonaws.com https://images.unsplash.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sooqr.com *.spotlersearch.com *.amazonaws.com https://firebasestorage.googleapis.com https://www.mollie.com www.magmodules.eu *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net https://cdn.belco.io https://maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.sendcloud.sc *.avada.io *.shopify.com js.mollie.com squeezely.tech www.squeezely.tech *.squeezely.tech 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://*.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com assets.braintreegateway.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.jsdelivr.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com wss://chat.belco.io https://cdn.belco.io https://maps.googleapis.com https://player.vimeo.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://get.geojs.io *.avada.io squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 img-src https://higherlogicdownload.s3.amazonaws.com/NACE/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NACE/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/NACE/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NACE/ https://higherlogicdownload.s3.amazonaws.com/NACE/ https://higherlogiclongterm.s3.amazonaws.com/NACE/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/NACE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NACE/ 'self' https://higherlogiclongterm.s3.amazonaws.com/NACE/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/NACE/ https://higherlogicdownload.s3.amazonaws.com/NACE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NACE/ https://higherlogicstream.s3.amazonaws.com/NACE/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/NACE/ https://higherlogicdownload.s3.amazonaws.com/NACE/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NACE/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 2 worker-src * blob:; font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.fontawesome.com *.zdassets.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.mb-app.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hcaptcha.com hcaptcha.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.googletagmanager.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.zendesk.com *.zdassets.com *.googleapis.com *.atlantic.fr *.azurewebsites.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io groupe-mb.scene7.com *.cloudflare.com *.google.com *.google.co.in www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.connect.facebook.net *.doubleclick.net *.google.fr *.trustpilot.com * *.stripe.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.hcaptcha.com hcaptcha.com maps.googleapis.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.paypal.com *.googletagmanager.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.licdn.com *.bing.com *.zendesk.com *.zdassets.com *.clarity.ms *.sparkow.net t4.my-probance.one *.contentsquare.net *.googleapis.com bam.nr-data.net bam.eu01.nr-data.net *.octipas-emerch.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.zoovu.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.hcaptcha.com hcaptcha.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.googletagmanager.com *.youtube.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.clarity.ms *.scandit.com *.zendesk.com tereva.zendesk.com mabeo.zendesk.com tereva.zendesk.com/frontendevents mabeo.zendesk.com/frontendevents *.zdassets.com *.bing.com *.sparkow.net *.contentsquare.net bam.nr-data.net bam.eu01.nr-data.net *.googleapis.com *.octipas-emerch.net *.linkedin.com px.ads.linkedin.com/wa/ *.zoovu.com *.cloudfront.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.kalogirou.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com www.facebook.com www.youtube.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.cookiebot.com www.youtube.com *.contactpigeon.com *.skroutz.gr *.netsteps.net *.trust-servers.net https://www.googletagmanager.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.youtube.com p.typekit.net validator.swagger.io *.gstatic.com *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.google.gr *.cookiebot.com *.google-analytics.com maps.gstatic.com *.kalogirou.com *.contactpigeon.com *.sharethis.com *.klarnaservices.com *.netsteps.net *.trust-servers.net https://kalogirou.com https://kalogirou.com/pub/media/ *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.googleadservices.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.skroutz.gr www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ *.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io 'self' data: *.cookiebot.com *.googleadservices.com stats.g.doubleclick.net googleads.g.doubleclick.net *.kalogirou.com *.go-mpulse.net *.sharethis.com *.contactpigeon.com *.google.gr *.taboola.com *.skroutz.gr *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.kalogirou.com www.youtube.com *.contactpigeon.com *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io maps.googleapis.com stats.g.doubleclick.net googleads.g.doubleclick.net *.cookiebot.com *.kalogirou.com www.youtube.com *.go-mpulse.net *.sharethis.com *.contactpigeon.com eu.klarnaevt.com *.taboola.com *.akstat.io *.skroutz.gr *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com *.googlesyndication.com *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://components-bnpl-pe-bbva-moprestamo-com.s3.amazonaws.com *.fontawesome.com data: fonts.googleapis.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zdassets.com www.gstatic.com script.hotjar.com static.hotjar.com googleadservices.com maps.googleapis.com/ webpay3g.transbank.cl webpay3gint.transbank.cl *.google.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com static.zdassets.com www.gstatic.com static.hotjar.com script.hotjar.com googleadservices.com maps.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.moprestamo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com cdn.dnky.co amc.demdex.net www.google.com youtube.com vars.hotjar.com *.doubleclick.net *.pinterest.com *.tryadviser.com *.webviewer.appar.io *.paperless.com.pe *.extranetrosen.cl static-content.vnforapps.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.moprestamo.com magefan.com cm.magefan.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com maps.googleapis.com accounts.google.com www.extranetrosen.cl *.hsforms.com track.hubspot.com mercadopago.cl www.mercadopago.cl *.google.com.cl static.zdassets.com www.gstatic.com static.hotjar.com script.hotjar.com *.pinterest.com *.sendtric.com *.tryadviser.com *.adnxs.com *.linkedin.com *.doubleclick.net *.rosen.cl *.rosen.com.pe *.sonataplatform.com *.googleadservices.com *.google-analytics.com cdn.ckeditor.com google.com.ar https://www.mercadopago.com.pe https://www.google.com.ar https://www.google.es data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.dpm.demdex.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.moprestamo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com www.extranetrosen.cl static.zdassets.com js.hs-scripts.com js.hs-analytics.net js.hscollectedforms.net js.hs-banner.com www.googleoptimize.com static.hotjar.com *.google.cl script.hotjar.com js.hsleadflows.net *.pinimg.com www.youtube.com *.tryadviser.com *.adnxs.com *.hsadspixel.net *.verificado.ai api.verificado.ai snap.licdn.com *.google-analytics.com *.commerce.adobe.net *.magento.com *.hscollectedforms.net *.doubleclick.net *.omtrdc.net *.googletagmanager.com *.rosen.cl *.rosen.com.pe *.sonataplatform.com *.mouseflow.com *.hubspot.com *.vnforapps.com https://www.google.com *.gstatic.com https://maps.googleapis.com cdn.ckeditor.com/ pinterest.com https://www.googletagmanager.com data.appar.io *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.moprestamo.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com cdn.dnky.co *.rosen.cl *.rosen.com.pe www.extranetrosen.cl *.tryadviser.com *.googleapis.com *.gstatic.com fonts.googleapis.com/ cdn.ckeditor.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com api.comapi.com bam.nr-data.net static.zdassets.com v2.zopim.com ekr.zdassets.com rollbar-eu.zendesk.com wa.me *.hubspot.com stats.g.doubleclick.net rosen.zendesk.com wss://widget-mediator.zopim.com *.hotjar.com vc.hotjar.io www.facebook.com public.delivery.janisqa.in public.delivery.janis.in *.google.cl *.pinterest.com wss://*.hotjar.com *.hscollectedforms.net *.hubapi.com *.amazonaws.com *.amazon.com *.zendesk.com *.linkedin.com ad.doubleclick.net *.google-analytics.com maps.googleapis.com/ *.visualwebsiteoptimizer.com http://localhost:12387 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.easypack24.net https://fonts.gstatic.com *.fontawesome.com *.alothemes.com *.magepow.com fonts.gstatic.com fonts.googleapis.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com js.stripe.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com cdn.doofinder.com magefan.com cm.magefan.com *.disqus.com *.easypack24.net *.inpost.pl *.inpost.com *.openstreetmap.org https://*.googleapis.com https://*.googleusercontent.com *.alothemes.com *.magepow.com https://www.magezon.com quickchart.io img.youtube.com https://www.mollie.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com cdn.doofinder.com widget.freshworks.com m2epro.freshdesk.com *.disqus.com *.inpost.pl *.inpost.it *.easypack24.net https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.alothemes.com *.magepow.com js.mollie.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.doofinder.com widget.freshworks.com m2epro.freshdesk.com maxcdn.bootstrapcdn.com geowidget.easypack24.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net *.fontawesome.com *.alothemes.com *.magepow.com fonts.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.doofinder.com wss://*.doofinder.com widget.freshworks.com m2epro.freshdesk.com *.inpost.pl *.inpost.it *.easypack24.net maps.googleapis.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/mapsplatform_google_com 2 font-src maxcdn.bootstrapcdn.com *.lasportivausa.com data: *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.klaviyo.com *.locally.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com https://plumrocket.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.lasportivausa.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://plumrocket.com *.weltpixel.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.lasportivausa.com *.doubleclick.net *.google.com *.googleapis.com *.vimeo.com *.addthis.com *.pinterest.com disqus.com *.bazaarvoice.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.lasportivausa.com *.google.com *.googleapis.com *.gstatic.com *.googlesyndication.com via.placeholder.com *.pinterest.com *.disqus.com *.addthis.com *.bazaarvoice.com *.curalate.com *.viglink.com *.klaviyo.com *.locally.com *.doubleclick.net *.cloudfront.net *.avantlink.com *.localizecdn.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.lasportivausa.com bam.nr-data.net cdnjs.cloudflare.com *.cookielaw.org *.doubleclick.net *.google.com *.googleapis.com *.gstatic.com js-agent.newrelic.com *.newrelic.com player.vimeo.com *.addthis.com *.addthisedge.com *.moatads.com *.avmws.com *.pinimg.com *.pinterest.com *.disqus.com *.disquscdn.com *.bazaarvoice.com *.locally.com *.curalate.com *.experticity.com *.eventscalendar.co *.localizecdn.com https://global.localizecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.lasportivausa.com *.disquscdn.com *.bazaarvoice.com *.googleapis.com *.typekit.net *.localizecdn.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.lasportivausa.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.lasportivausa.com bam.nr-data.net *.doubleclick.net *.googleapis.com *.googlesyndication.com *.pinterest.com *.disqus.com *.addthis.com *.bazaarvoice.com *.curalate.com *.locally.com *.eventscalendar.co *.mixpanel.com *.localizecdn.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.lasportivausa.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 report-uri /_/csp-reports 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.xtento.com consentcdn.cookiebot.com ct.pinterest.com google.co.uk secure.livechatinc.com www.google.com www.google.co.uk yotpo.com account.fetchify.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.xtento.com cdn.xtento.com angus.finance-calculator.co.uk connectionflooring.s3.amazonaws.com bat.bing.com c.bing.com c.clarity.ms facebook.com google.com google.co.uk images-static.trustpilot.com imgsct.cookiebot.com www.google.co.uk p.yotpo.com magefan.com cm.magefan.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com www.xtento.com cdn.xtento.com api.livechatinc.com bat.bing.com cdn.jsdelivr.net cdn.livechatinc.com cdn.roomvo.com clarity.ms connect.facebook.net consent.cookiebot.com consentcdn.cookiebot.com google.co.uk js-agent.newrelic.com s.pinimg.com directwoodflooring.co.uk load.m4.directwoodflooring.co.uk flooringsuperstore.com load.m1.flooringsuperstore.com grass-direct.co.uk load.metrics.grass-direct.co.uk dreamdecking.co.uk load.m3.dreamdecking.co.uk zentiles.co.uk load.m2.zentiles.co.uk static.cloudflareinsights.com static-eu.payments-amazon.com tag.rmp.rakuten.com unpkg.com www.clarity.ms www.google.com www.google.co.uk www.gstatic.com staticw2.yotpo.com cc-cdn.com *.disqus.com https://cdn.jsdelivr.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com angus.finance-calculator.co.uk cc-cdn.com https://cdn.jsdelivr.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com api.livechatinc.com bam.eu01.nr-data.net consentcdn.cookiebot.com ct.pinterest.com google.co.uk googleads.g.doubleclick.net *.googlesyndication.com region1.analytics.google.com load.m4.directwoodflooring.co.uk load.m1.flooringsuperstore.com load.metrics.grass-direct.co.uk load.m3.dreamdecking.co.uk load.m2.zentiles.co.uk m4.directwoodflooring.co.uk m1.flooringsuperstore.com metrics.grass-direct.co.uk m3.dreamdecking.co.uk m2.zentiles.co.uk shopify-bridge.leafgrow.io u.clarity.ms www.google.com www.google.co.uk api.yotpo.com www.roomvo.com widget.trustpilot.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net 'self' https://*.uberall.com https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com cdn.doofinder.com https://images.unsplash.com https://cdn.scarabresearch.com https://static.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com * *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cdn.doofinder.com *.plugins.emarsys.net https://cdn.scarabresearch.com https://maps.googleapis.com https://snippet.plugins.emarsys.net https://static.scarabresearch.com https://locator.uberall.com https://*.uberall.com https://instantcredit.net/ https://code.jquery.com/ * *.fontawesome.com *.googleapis.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.doofinder.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.doofinder.com wss://*.doofinder.com https://recommender.scarabresearch.com *.eservice.emarsys.net https://play-merchant-config.pepperfinance.es/ https://play-api.peppermoneytest.es/ https://maps.googleapis.com https://player.vimeo.com https://cdn.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com https://instantcredit.net/ https://test.instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://frontal-eu.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://api.itau.com.br/ https://api.itau.com.br:443/ https://sts.itau.com.br/ https://sts.itau.com.br:443/ https://secure.api.itau/ https://secure.api.itau:443/ https://apisandbox.redeecommerce.rede.com.br/ https://apiquerysandbox.redeecommerce.rede.com.br/ https://api.redeecommerce.rede.com.br/ https://apiquery.redeecommerce.rede.com.br/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https://d3tw2v68rmxuj7.cloudfront.net; connect-src 'self' https: wss://*.zopim.com; font-src data: https:; frame-src https://js.stripe.com https://m.stripe.network https://www.google.com https://www.youtube.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://platform.twitter.com https://x.adroll.com https://15347100.fls.doubleclick.net https://td.doubleclick.net; img-src https:; media-src https://static.zdassets.com/web_widget/classic/latest/fda6cd35495c75f83508d9d2e77ee33d.mp3 https://d3tw2v68rmxuj7.cloudfront.net;script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'unsafe-inline' https://d3tw2v68rmxuj7.cloudfront.net https://fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/ionicons/4.5.6/css/ionicons.min.css https://use.typekit.net https://p.typekit.net; report-uri /csp 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://maxcdn.bootstrapcdn.com https://eastprodcdn.azureedge.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://images.unsplash.com https://bat.bing.net https://eastprodcdn.azureedge.net https://forms.hsforms.com https://cdn.origene.com https://perf-na1.hsforms.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://track.hubspot.com https://www.bizgeniusapp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://maps.googleapis.com landofcoder.com https://bat.bing.com https://cdn.noibu.com https://d.adroll.com https://eastprodcdn.azureedge.net https://galleryuseastprod.blob.core.windows.net https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hscollectedforms.net https://js.hubspot.com https://s.adroll.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://unpkg.com https://www.bizgeniusapp.com https://www.clarity.ms https://cdnjs.cloudflare.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://maxcdn.bootstrapcdn.com https://eastprodcdn.azureedge.net https://galleryuseastprod.blob.core.windows.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com thm.visa.com https://maps.googleapis.com https://player.vimeo.com landofcoder.com https://api-engagement-us-east.velaro.com https://api-main-us-east.velaro.com https://api-visitor-us-east.velaro.com https://bat.bing.net https://cta-service-cms2.hubspot.com https://forms.hscollectedforms.net https://px.ads.linkedin.com https://u.clarity.ms https://www.bizgeniusapp.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' blob: data:; connect-src 'self' https://*.analytics.google.com https://graphql.landsbankinn.is https://www.google-analytics.com cdn.landsbankinn.is https://log.landsbankinn.is https://www.google.com https://landsbankinn.boost.ai/ https://googleads.g.doubleclick.net https://region1.google-analytics.com/ https://stats.g.doubleclick.net/ events.mapbox.com https://landsbankinn.cdn.prismic.io/ api.mapbox.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://connect.facebook.net/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://landsbankinn.boost.ai https://www.google.com https://www.gstatic.com cdn.landsbankinn.is https://static.cdn.prismic.io blob: data: https://td.doubleclick.net https://graphql.landsbankinn.is https://e.infogram.com/ https://prismic.io/ https://*.jotform.com; style-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.gstatic.com; img-src 'self' blob: data: images.prismic.io https://prismic-io.s3.amazonaws.com/ www.gstatic.com www.google-analytics.com/ api.mapbox.com cdn.landsbankinn.is https://landsbankinn.is/ https://www.googletagmanager.com https://www.facebook.com/tr/ https://www.facebook.com/ https://boost-files-general-eu-west-1-prod.s3-eu-west-1.amazonaws.com/files/LANDSBANKINN/ https://www.google.is/ https://www.google.com/ https://landsbankinn.cdn.prismic.io/; font-src 'self' cdn.landsbankinn.is fonts.gstatic.com https://unpkg.com blob: data:; object-src 'self' https://graphql.landsbankinn.is; base-uri 'self'; form-action 'self' https://graphql.landsbankinn.is; frame-ancestors 'self' cdn.landsbankinn.is; frame-src 'self' https://www.googletagmanager.com/ https://landsbankinn.prismic.io/ cdn.landsbankinn.is https://td.doubleclick.net/ https://landsbankinn.boost.ai https://www.google.com/ https://www.google.is/ https://e.infogram.com/ https://*.jotform.com; style-src-elem https://fonts.googleapis.com 'self' https://unpkg.com 'unsafe-eval' 'unsafe-inline'; media-src 'self' blob: https://prismic-io.s3.amazonaws.com/landsbankinn/ cdn.landsbankinn.is https://landsbankinn.cdn.prismic.io/; report-to name-of-endpoint; report-uri https://log.landsbankinn.is/api/20/security/?sentry_key=5619b3ff53a764b525920b31d3e32e4a; 2 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https:; report-uri /_csp 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; connect-src 'self' https://api.mixpanel.com https://api-js.mixpanel.com https://api-eu.mixpanel.com https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https://www.youtube.com https://tagheuer-tcs-london.vercel.app https://vimeo.com/; img-src *; media-src *; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://api.uk.exponea.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://cookie-cdn.cookiepro.com https://cdn.mxpnl.com https://cdn-dev.mxpnl.com https://mixpanel.com https://*.mixpanel.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; webrtc 'block'; worker-src 'self' blob: 2 default-src https: data: 'unsafe-inline' 'unsafe-eval'; frame-src https: data: blob:; report-uri https://temporarycsp.azurewebsites.net/api/CreateReport 2 default-src 'self'; script-src 'self' 'unsafe-inline' l.getsitecontrol.com www.googletagmanager.com region1.google-analytics.com www.google-analytics.com static.ads-twitter.com www.loom.com youtube.com *.semaphoreci.com *.semaphore.io; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src 'self' data: secure.gravatar.com s.w.org www.google-analytics.com www.googletagmanager.com static.ads-twitter.com t.co analytics.twitter.com img.youtube.com *.semaphoreci.com *.semaphore.io; font-src 'self' fonts.gstatic.com data:; frame-src youtube.com www.youtube.com www.loom.com calendar.google.com www.googletagmanager.com; media-src audio.buzzsprout.com; connect-src 'self' https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://l.getsitecontrol.com; report-uri https://sentry.io/api/4509293704970240/security/?sentry_key=de4512f268813ed97e73abec15d22aab 2 font-src www.paypalobjects.com *.relaxdays.com *.gstatic.com *.trustami.com cdn.userway.org *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.pinterest.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src *.paypal.com www.paypalobjects.com *.relaxdays.com *.youtube.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.consentmanager.net *.googlesyndication.com *.youtube-nocookie.com *.facebook.com *.pinterest.com *.pinterest.de *.sibforms.com sibautomation.com *.paypalobjects.com *.googletagmanager.com cdn.userway.org *.doubleclick.net conversations-widget.brevo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.billie.io 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.paypal.com *.paypalobjects.com *.relaxdays.com i.ytimg.com *.youtube.com *.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.consentmanager.net www.it-recht-kanzlei.de *.clarity.ms *.google.com *.pinimg.com *.pinterest.com *.doubleclick.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.googleusercontent.com *.facebook.com *.tiktok.com alb.reddit.com www.datenschutz.net *.trustami.com bat.bing.com bat.bing.net cdn.userway.org www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi www.google.com.mt www.google.com.cy 'self' data: data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com s.ytimg.com *.googleapis.com *.relaxdays.com *.youtube.com *.gstatic.com *.google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.billie.io *.consentmanager.net *.clarity.ms *.pinterest.com *.pinimg.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.facebook.net *.doubleclick.net *.googlesyndication.com bat.bing.com bat.bing.net bat.bing-int.com *.tiktok.com sibautomation.com *.sendinblue.com www.redditstatic.com *.trustami.com conversations-widget.brevo.com cdn.userway.org www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.billie.io *.relaxdays.com *.googletagmanager.com *.googleapis.com *.gstatic.com cdn.userway.org *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.relaxdays.com 'self' 'unsafe-inline'; media-src *.relaxdays.com 'self' 'unsafe-inline'; manifest-src *.relaxdays.com 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.billie.io *.relaxdays.com blob: *.consentmanager.net *.google.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net *.googlesyndication.com google.com www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi *.facebook.com *.pinterest.com bat.bing.com bat.bing.net bat.bing-int.com *.tiktok.com *.sendinblue.com in-automate.brevo.com analytics.pangle-ads.com analytics-ipv6.tiktokw.us api.userway.org cdn.userway.org cmodul.solutenetwork.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://relaxdays.com/_csp_report_; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' https://webpay3gint.transbank.cl https://webpay3g.transbank.cl https://www.facebook.com/* pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: www.google.com https://player.vimeo.com https://www.youtube.com https://www.googletagmanager.com https://tagmanager.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.youtube-nocookie.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com bat.bing.com *.bat.bing.com *.msn.com *.bing.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.google.com www.gstatic.com *.avada.io https://www.googletagmanager.com https://tagmanager.google.com https://546002994.collect.igodigital.com https://assets.adobedtm.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.googleapis.com http://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com static.zdassets.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net *.sentry.io *.paypal.com google.com *.google.com qa-api.magedevteam.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://commerce.adobedc.net https://analytics.google.com https://vimeo.com https://api.magento.com https://performance.typekit.net https://pilot-payflowlink.paypal.com https://commerce.adobe.io https://commerce.adobe.net https://google.com https://qa-api.magedevteam.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline' https://mercadopago.com.br https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src maxcdn.bootstrapcdn.com data: https://*.cloudflare.com *.typekit.net *.googleapis.com https://*.authorize.net https://*.cardinalcommerce.com https://*.trustedshops.com https://*.tawk.to https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://embed.productlead.me https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net https://www.facebook.com/ https://ct.pinterest.com/ https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro 'self' 'unsafe-inline'; frame-ancestors data: 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net js.stripe.com www.google.com https://www.youtube.com https://www.google.com https://www.google.ro https://www.google.bg https://www.facebook.com/ https://*.cardinalcommerce.com https://*.authorize.net https://*.paypal.com https://*.sandbox.paypal.com https://*.hotjar.com https://*.pinterest.com https://*.googlesyndication.com https://googleads.g.doubleclick.net https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://*.tawk.to https://s7.addthis.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.vimeocdn.com s.ytimg.com www.apptrian.com www.facebook.com ct.pinterest.com data: https://*.cloudflare.com https://cdn.klarna.com https://www.magecomp.com https://*.paypal.com www.paypalobjects.com https://*.sandbox.paypal.com https://*.g.doubleclick.net https://*.vimeocdn.com https://s.ytimg.com https://*.usercentrics.eu https://*.magentocommerce.com https://www.google.ro https://www.google.com https://*.tawk.to https://cdn.jsdelivr.net https://*.cdninstagram.com https://*.xx.fbcdn.net www.instagram.com https://instagram.fcnd1-1.fna.fbcdn.net http://seal.alphassl.com/ https://secure.trust-provider.com https://ssl.comodo.com https://feedback.trusted.ro https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://ct.pinterest.com maps.gstatic.com maps.google.com https://*.themarketer.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net https://*.google.com https://sslseal.certum.pl/ *.collect.igodigital.com flagpedia.net cdn1.themarketer.com 'self' 'unsafe-inline'; script-src https://*.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net s.ytimg.com video.google.com https://*.vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net cdn-scripts.signifyd.com www.youtube.com js.stripe.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com www.pinterest.com s.pinimg.com https://*.cloudflare.com https://*.google.com *.gstatic.com https://www.googletagmanager.com https://*.googlesyndication.com maps.googleapis.com https://*.trustedshops.com https://*.usercentrics.eu https://*.cardinalcommerce.com https://*.googleadservices.com https://googleadservices.com https://*.authorize.net https://*.paypalobjects.com https://*.ytimg.com *.braintreegateway.com *.signifyd.com https://connect.facebook.net https://embed.productlead.me https://chimpstatic.com https://*.tawk.to https://*.hotjar.com https://*.getsitecontrol.com https://*.g.doubleclick.net https://js-agent.newrelic.com/ https://bam.eu01.nr-data.net/ http://seal.alphassl.com/ https://secure.trust-provider.com https://cdn.jsdelivr.net https://s.pinimg.com https://*.pinterest.com https://*.paypal.com https://*.sandbox.paypal.com https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://*.themarketer.com https://*.tiktok.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net *.collect.igodigital.com *.avada.io cdn1.themarketer.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com maxcdn.bootstrapcdn.com https://*.cloudflare.com https://*.trustedshops.com https://*.usercentrics.eu https://maxcdn.bootstrapcdn.com https://embed.productlead.me https://*.tawk.to https://cdn.jsdelivr.net https://*.googleapis.com https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://static.xpertbeauty.ro https://*.themarketer.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net *.gstatic.com cdn1.themarketer.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com connect.facebook.net graph.facebook.com ct.pinterest.com https://*.cloudflare.com https://*.paypal.com https://*.cardinalcommerce.com www.facebook.com *.google-analytics.com https://*.tawk.to wss://*.tawk.to https://*.productlead.me wss://*.productlead.me www.instagram.com https://instagram.fcnd1-1.fna.fbcdn.net https://stats.g.doubleclick.net https://bam.eu01.nr-data.net https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://ct.pinterest.com https://s7.addthis.com https://api-public.addthis.com https://in.hotjar.com https://vc.hotjar.io maps.googleapis.com https://*.themarketer.com https://*.tiktok.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net www.gstatic.com cdn1.themarketer.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://*.xpertbeauty.ro/; report-to report-endpoint; 2 default-src 'self'; script-src 'nonce-KjlwR0pVUGk3YkR1dFRBV2ZmIUo=' 'self' 'unsafe-eval' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://cdnjs.cloudflare.com; script-src-elem 'nonce-MTo4MDY2MDoxNjE3MDQ5ODExOjE3MzQ5NTc2NzU=' 'nonce-MTo4MDY2MzoxNjQ4Nzg0NDUxOjE3MzQ5NTc4NTQ=' 'self' 'unsafe-eval' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.google.com https://connect.facebook.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.kaspersky-labs.com https://api.mailxpert.ch; script-src-attr 'self' 'unsafe-inline' https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.google.com https://*.kaspersky-labs.com https://cdnjs.cloudflare.com; object-src 'self'; base-uri 'self'; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.g.doubleclick.net https://api.friendlycaptcha.com; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com; frame-src 'self' https://ige.prospective.ch https://td.doubleclick.net https://nl.mailxpert.ch https://www.youtube-nocookie.com; img-src 'self' data: blob: https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://i.ytimg.com; manifest-src 'self'; media-src 'self' data:; worker-src blob:; report-uri /CspReportLogger.php 2 object-src 'none'; script-src 'self' 'report-sample' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com maps.google.com; style-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.electronics.org/log-report-uri/reportOnly 2 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com cdn.qantasloyalty.com api-accent.bloomreach.co api.smooch.io mpsnare.iesnare.com/snare.js mpsnare.iesnare.com/script/logo.js applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/recaptcha www.gstatic.com/recaptcha *.squarecdn.com cfjump.drmartens.com.au cfjump.drmartens.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com dma-cdn.staging.truefitcorp.com/fitrec/dma/js/tracker.js js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com *.adobemc.com ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js js-sandbox.squarecdn.com s.pinimg.com lantern.roeyecdn.com ct.pinterest.com js.squarecdn.com *.stg.qantasloyalty.com/appcache/wid-redemptions-button/master/ ; style-src 'self' 'unsafe-inline' *.klaviyo.com/onsite/ display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com assets.braintreegateway.com/web/dropin/1.16.0/css/dropin.css *.adobetm.com foursixty.com *.adobemc.com static.klaviyo.com/onsite/js static-tracking.klaviyo.com/onsite/js assets.api.useinsider.com/css ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.drmartens.co.nz *.drmartens.com.au cm.everesttech.net/cm/dd googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com adservice.google.com www.drmartens.com lantern.roeye.com ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' gateway.stg.qantasloyalty.com gateway.qantasloyalty.com api-accent.bloomreach.co analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.drmartens.co.nz *.fullstory.com *.klaviyo.com smetrics.drmartens.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com *.nr-data.net *.paypal.com *.taboola.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com *.roymorgan.com foursixty.com kleber.datatoolscloud.net.au sentry.io vimeo.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com *.useinsider.com api.myunidays.com opreq.observepoint.com ct.pinterest.com stats.g.doubleclick.net/g/collect *.stg.qantasloyalty.com/redemptions/ ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net ; frame-src 'self' checkout.qantas.com api-accent.bloomreach.co www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.criteo.net *.demdex.net *.everesttech.net *.everestjs.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com everestjs.net facebook.com foursixty.com google.com www.google.com vimeo.com ct.pinterest.com *.qlstg.qantas.com/ ; worker-src 'self' blob: *.accentgra.com *.drmartens.co.nz *.drmartens.com.au; 2 base-uri 'self'; default-src 'self'; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com; font-src 'self'; frame-src 'self' https://assets-eur.mkt https://e.issuu.com https://www.googletagmanager.com https://www.google.com; img-src 'self' https://cdn.sanity.io https://media.crystallize.com https://sr.bokbasen.io blob: data: https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://vercel.live https://clerk.cappelendamm.no; style-src 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net; upgrade-insecure-requests; 2 font-src *.cloudflare.com *.bootstrapcdn.com data: maxcdn.bootstrapcdn.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es test.saferpay.com www.saferpay.com saferpay.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com www.facebook.com platform.twitter.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es test.saferpay.com www.saferpay.com saferpay.com *.cloudflare.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com amcglobal.sc.omtrdc.net yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com *.cloudflare.com *.twitter.com *.fontawesome.com s7.addthis.com *.avada.io connect.facebook.net twitter.com platform.twitter.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es https://www.sandbox.paypal.com https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com *.cloudflare.com ekr.zdassets.com/ yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-c7c-RM5Ce_PrX0d1gVQ12w'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-c7c-RM5Ce_PrX0d1gVQ12w'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' 2 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://widgets.trustedshops.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com https://plumrocket.com *.yotpo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://plumrocket.com https://accounts.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.koongo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://vimeo.com https://player.vimeo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://accounts.google.com https://www.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://accounts.google.com https://www.gstatic.com *.yotpo.com *.klarnacdn.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://accounts.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.klarnaservices.com *.koongo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.googletagmanager.com;; connect-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://stats.g.doubleclick.net https://*.google-analytics.com https://cdn.cookielaw.org https://*.feefo.com https://*.trustpilot.com;; img-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com data: https://*.google-analytics.com https://*.google.com https://*.google.co.uk https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.siteimproveanalytics.io https://*.feefo.com https://*.trustpilot.com;; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.googletagmanager.com https://static.srcspot.com https://cdn.cookielaw.org https://*.google-analytics.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://code.jquery.com https://*.feefo.com; https://*.trustpilot.com;; style-src 'self' 'unsafe-inline' https://*.securetrustbank.com https://*.v12retailfinance.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.feefo.com https://*.trustpilot.com;; font-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.trustpilot.com;; frame-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.youtube-nocookie.com https://*.trustpilot.com;; frame-ancestors 'self' 2 default-src 'self' *.google.com google.com *.google.de google.de *.google.at google.at *.google.be google.be *.google.fi google.fi *.google.no google.no *.google.ru google.ru *.google.se google.se *.google.co.uk google.co.uk *.google.nl google.nl *.google.fr google.fr *.google.pl google.pl *.google.es google.es *.google.it google.it *.google.ch google.ch *.google.dk google.dk *.google.it google.it *.google.cz google.cz *.google-analytics.com google-analytics.com *.googletagmanager.com googletagmanager.com *.googleapis.com googleapis.com *.sharp.de sharp.de *.sharp.at sharp.at *.sharp.be sharp.be *.sharp.fi sharp.fi *.sharp.no sharp.no *.sharp.ru sharp.ru *.sharp.se sharp.se *.sharp.co.uk sharp.co.uk *.sharp.nl sharp.nl *.sharp.fr sharp.fr *.sharp.pl sharp.pl *.sharp.es sharp.es *.sharp.it sharp.it *.sharp.ch sharp.ch *.sharp.se sharp.se *.sharp.dk sharp.dk *.sharp.cz sharp.cz *.sharp.eu sharp.eu *.sharpmarketing.eu imgs.aws.sharp.eu *.actonsoftware.com *.cookielaw.org *.onetrust.com onetrust.com stats.g.doubleclick.net; script-src 'self' 'unsafe-inline' *.actonservice.com actonservice.com *.googletagmanager.com googletagmanager.com *.google-analytics.com *.google.com googleapis.com *.googleapis.com *.youtube.com youtube.com bam.nr-data.net js-agent.newrelic.com *.cookielaw.org *.onetrust.com *.sharpmarketing.eu *.gstatic.com *.hotjar.com snap.licdn.com bat.bing.com; style-src 'self' 'unsafe-inline' *.sharpmarketing.eu; img-src 'self' data: *.cookielaw.org cookielaw.org *.onetrust.com onetrust.com *.google.ca google.ca *.google.co.in google.co.in *.google.ro google.ro *.google.co.jp google.co.jp *.gogle.co.id google.co.id *.google.co.th google.co.th *.google.ae google.ae *.google.co.nz google.co.nz *.google.com google.com *.google.de google.de *.google.at google.at *.google.be google.be *.google.fi google.fi *.google.no google.no *.google.ru google.ru *.google.se google.se *.google.co.uk google.co.uk *.google.nl google.nl *.google.fr google.fr *.google.pl google.pl *.google.es google.es *.google.it google.it *.google.ch google.ch *.google.dk google.dk *.google.lt google.it *.google.cz google.cz imgs.aws.sharp.eu i.ytimg.com d35hoao4dw4qk2.cloudfront.net www.google-analytics.com *.sharpmarketing.eu *.actonsoftware.com px.ads.linkedin.com bat.bing.com px4.ads.linkedin.com www.google.co.za www.google.bg googleads.g.doubleclick.net www.google.gr; frame-src *; frame-ancestors 'self' *.sharp.de sharp.de *.sharp.at sharp.at *.sharp.be sharp.be *.sharp.fi sharp.fi *.sharp.no sharp.no *.sharp.ru sharp.ru *.sharp.sk sharp.sk *.sharp.se sharp.se *.sharp.co.uk sharp.co.uk *.sharp.nl sharp.nl *.sharp.fr sharp.fr *.sharp.pl sharp.pl *.sharp.es sharp.es *.sharp.it sharp.it *.sharp.ch sharp.ch *.sharp.se sharp.se *.sharp.dk sharp.dk *.sharp.hu sharp.hu *.sharp.it sharp.it *.sharp.co.jp sharp.co.jp *.sharp.cz sharp.cz *.sharp.eu sharp.eu; child-src *; font-src 'self' data:; connect-src 'self' *.google-analytics.com google-analytics.com cdn.linkedin.oribi.io bam.nr-data.net *.onetrust.com *.cookielaw.org stats.g.doubleclick.net privacyportal-eu.onetrust.com *.sharpmarketing.eu *.hotjar.com vc.hotjar.io bat.bing.com; report-uri https://apps.sharp.eu/sharp/apps/eu/csp-violation/report.php; upgrade-insecure-requests 2 frame-ancestors *.vee24.com 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com *.google.com *.google.ca *.omappapi.com *.hotjar.com *.freshbots.ai *.pusher.com *.freshworksapi.com *.attn.tv *.route.io *.routeapp.io *.klaviyo.com d1cwup7r903a1d.cloudfront.net *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.hotjar.com *.kaptcha.com *.tdotperformance.ca *.automotivestuff.com *.addthis.com *.nort.ca *.google.ca *.bing.com *.facebook.com *.freshbots.ai *.pusher.com *.freshworksapi.com *.attn.tv *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.bing.com *.freshbots.ai *.googletagmanager.com *.shopperapproved.com *.tdotperformance.ca *.automotivestuff.com *.nort.ca *.google.com *.google.ca *.doubleclick.net *.facebook.net *.facebook.com *.hotjar.com *.riskified.com *.clarity.ms *.cloudfront.net *.omappapi.com *.crazyegg.com *.pusher.com *.freshworksapi.com *.attn.tv *.route.io *.routeapp.io *.convertexperiments.com *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.forter.com *.cloudfront.net *.optnmstr.com *.hotjar.com *.shopperapproved.com *.bing.com *.freshbots.ai *.clarity.ms *.googleapis.com *.tdotperformance.ca *.automotivestuff.com *.addthis.com *.addthisedge.com *.moatads.com *.nort.ca *.google.ca *.omappapi.com *.facebook.net *.facebook.com *.riskified.com *.doubleclick.net *.klaviyo.com *.crazyegg.com *.pusher.com *.freshworksapi.com *.noibu.com *.attn.tv *.omniconvert.com *.route.io *.routeapp.io *.route.com unpkg.com *.convertexperiments.com *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com cdn.routeapp.io fonts.googleapis.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.omappapi.com *.freshbots.ai *.tdotperformance.ca *.automotivestuff.com *.nort.ca *.google.com *.google.ca *.shopperapproved.com *.klaviyo.com *.crazyegg.com *.pusher.com *.freshworksapi.com *.attn.tv *.route.io *.routeapp.io *.convertexperiments.com *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudfront.net *.forter.com *.omappapi.com *.hotjar.com *.doubleclick.net *.shopperapproved.com *.freshbots.ai *.googleapis.com *.tdotperformance.ca *.automotivestuff.com *.addthis.com *.nort.ca *.clarity.ms *.youtube.com *.google.ca *.facebook.net *.facebook.com *.bing.com *.riskified.com *.klaviyo.com *.crazyegg.com *.hotjar.io *.pusher.com *.freshworksapi.com wss://rts-us.freshworksapi.com wss://ws.hotjar.com *.noibu.com wss://*.noibu.com *.attn.tv events.attentivemobile.com google.com/pay *.omniconvert.com *.route.io *.routeapp.io *.route.com *.convertexperiments.com *.trycaddie.com caddie-ai-public.s3.us-east-2.amazonaws.com prod-caddie-public-custom-stylesheets.s3.us-east-2.amazonaws.com *.posthog.com api.route.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.cloudflare.com 'self' data: *.hotjar.com *.hotjar.io data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.paypal.com *.gstatic.com *.googleapis.com *.googlesyndication.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googleadservices.com www.facebook.com trengo.s3.eu-central-1.amazonaws.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com *.cmi.co.ma data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.googlesyndication.com *.googleadservices.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk www.facebook.com *.widget.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com connect.facebook.net graph.facebook.com business.facebook.com *.hotjar.com *.hotjar.io onesignal.com *.onesignal.com *.criteo.com *.adsmurai.com gateway.bankart.si 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.bootstrapcdn.com ecom-stage.iutecredit.mk ecom.iutecredit.mk downloads.mailchimp.com onesignal.com *.onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googlesyndication.com *.doubleclick.net www.facebook.com *.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ekr.zdassets.com/ connect.facebook.net graph.facebook.com business.facebook.com wss://ws.hotjar.com *.hotjar.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net * *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.braintreegateway.com *.paypal.com google.com *.google.com *.lpsnmedia.net *.liveperson.net *.hotjar.com *.bragard.ca *.dotdigital-pages.com *.dotdigital.com https://plumrocket.com www.facebook.com platform.twitter.com blob: webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com * *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.linkedin.com bat.bing.com *.powerreviews.com dev.visualwebsiteoptimizer.com seal.digicert.com https://www.google.com/pagead/1p-user-list/ https://www.google.co.jp/pagead/1p-user-list/ https://www.google.com/ads/ https://www.google.co.jp/ads/ https://*.adsymptotic.com/d/px/ *.liquifire.com *.weglot.com *.bragard.ca *.trackedlink.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adobe.io magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ * *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com seal.digicert.com dev.visualwebsiteoptimizer.com js-agent.newrelic.com bam.nr-data.net code.jquery.com *.lpsnmedia.net *.liveperson.net *.hotjar.com *.resultspage.com *.resultsdemo.com *.powerreviews.com *.g.doubleclick.net https://snap.licdn.com/li.lms-analytics/ bat.bing.com *.weglot.com *.bragard.ca *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal player.vimeo.com www.facebook.com twitter.com platform.twitter.com unpkg.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com * *.magento-datasolutions.com *.magento-ds.com use.fontawesome.com *.resultspage.com *.resultsdemo.com *.powerreviews.com *.weglot.com *.bragard.ca webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com * 'self' 'unsafe-inline'; manifest-src * 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com commerce.adobe.io * *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.powerreviews.com bam.nr-data.net *.g.doubleclick.net wss://*.hotjar.com https://*.hotjar.com *.hotjar.io bat.bing.com *.weglot.com *.bragard.ca *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com data: webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src * 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.fixando.com/ https://cdn.fixando.com/ https://pics.fixando.com/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://www.googletagservices.com/ https://www.googleadservices.com/ https://fcm.googleapis.com/ https://tpc.googlesyndication.com/ https://pagead2.googlesyndication.com/ https://adservice.google.com.pk/ https://adservice.google.com.br/ https://adservice.google.com.py/ https://adservice.google.com.do/ https://adservice.google.com/ https://adservice.google.pt/ https://adservice.google.nl/ https://adservice.google.cl/ https://adservice.google.it/ https://adservice.google.pl/ https://adservice.google.no/ https://adservice.google.fr/ https://adservice.google.bg/ https://adservice.google.es/ https://adservice.google.se/ https://adservice.google.be/ https://adservice.google.de/ https://adservice.google.ch/ https://adservice.google.hu/ https://adservice.google.ie/ https://adservice.google.lu/ https://adservice.google.ru/ https://adservice.google.be/ https://adservice.google.co.uk/ https://adservice.google.co.ao/ https://adservice.google.co.in/ https://partner.googleadservices.com/ https://maps.googleapis.com/ https://optimize.google.com/ https://www.googleoptimize.com/ https://www.gstatic.com/ https://googleads.g.doubleclick.net/ https://pubads.g.doubleclick.net/ https://static.zdassets.com/ https://widget-mediator.zopim.com/ https://www.facebook.com/ https://connect.facebook.net/ https://static.hotjar.com/ https://script.hotjar.com/ https://cdn.jsdelivr.net/ https://static.zdassets.com/ https://d2wy8f7a9ursnm.cloudfront.net/ https://apis.google.com/ https://tagmanager.google.com/ https://accounts.google.com/ https://www.paypal.com/ https://cdn.socket.io/ https://widget.trustpilot.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://bucket.cdnwebcloud.com https://bat.bing.com https://www.clarity.ms https://www.google.com https://*.outbrain.com https://www.sandbox.paypal.com 2 font-src https://*.mailcampaigns.nl https://fonts.gstatic.com *.fontawesome.com *.gstatic.com 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com www.google.com https://*.hotjar.com https://*.doubleclick.net www.googletagmanager.com sst.chromeburner.com sst.uat.chromeburner.com sst.chromeburner.nl sst.uat.chromeburner.nl *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://images.unsplash.com https://*.bing.com bat.bing.net https://*.google-analytics.com https://pagead2.googlesyndication.com https://*.google.nl https://*.google.com https://*.clarity.ms https://*.facebook.com https://*.facebook.net https://*.googletagmanager.com https://*.chromeburner.test blob: https://*.chromeburner.com https://*.chromeburner.nl https://*.hotjar.com https://*.mailcampaigns.nl https://googleads.g.doubleclick.net https://*.usercentrics.eu *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://*.bing.com https://*.google-analytics.com https://pagead2.googlesyndication.com https://*.webgains.io https://*.clarity.ms https://*.facebook.net https://*.googleadservices.com https://*.doubleclick.net https://*.chromeburner.test https://*.chromeburner.com https://*.chromeburner.nl https://*.hotjar.com https://*.mailcampaigns.nl analytics.tiktok.com https://partner-cdn.shoparize.com https://*.usercentrics.eu *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.mailcampaigns.nl *.fontawesome.com *.multisafepay.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://*.bing.com bat.bing.net https://*.doubleclick.net https://*.google.com https://*.google.nl https://pagead2.googlesyndication.com https://*.clarity.ms https://*.chromeburner.test https://*.chromeburner.com https://*.chromeburner.nl https://*.googletagmanager.com https://*.hotjar.com https://*.google-analytics.com https://*.mailcampaigns.nl analytics.tiktok.com https://*.usercentrics.eu *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://chromeburner.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://static.zdassets.com https://region1.google-analytics.com https://v2.zopim.com https://ajax.googleapis.com https://analytics.silktide.com https://analytics.tiktok.com https://api.reciteme.com/asset/js https://app.geckoform.com https://cdn.populo-services.com https://connect.facebook.net https://embed.geckochat.io https://googleads.g.doubleclick.net https://l.getsitecontrol.com https://sc-static.net/scevent.min.js https://script.hotjar.com https://static.hotjar.com https://tr.snapchat.com https://www.googletagmanager.com https://cdn.populo-services.com https://www.gstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.geckoform.com https://fonts.gstatic.com/ https://embed.geckochat.io https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://cms-stmarys.cloud.contensis.com https://surveystats.hotjar.io https://googleads.g.doubleclick.net https://capigateway.adaptworldwide.com wss://widget-mediator.zopim.com https://router-euwest2.geckochat.io https://stats.g.doubleclick.net https://www.google.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://a.eu.silktide.com https://analytics.tiktok.com https://api.geckochat.io https://ekr.zdassets.com https://l.getsitecontrol.com https://region1.analytics.google.com https://tr.snapchat.com https://tr6.snapchat.com https://www.google.co.uk https://www.google.com https://www.googleadservices.com; font-src 'self' https://script.hotjar.com https://fonts.geckoform.com https://embed.geckochat.io https://fonts.gstatic.com/; frame-src 'self' https://app.geckoform.com https://td.doubleclick.net https://tr.snapchat.com https://www.youtube.com; img-src 'self' data: https://survey-images.hotjar.com https://img.youtube.com https://www.googletagmanager.com https://widget-assets.geckochat.io https://www.facebook.com https://i.ytimg.com https://populo.populo-services.com https://www.google.co.uk https://www.google.com; manifest-src 'self'; media-src 'self' https://audio.geckochat.io; worker-src 'none'; 2 object-src 'none'; script-src 'self' 'unsafe-eval' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; style-src 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 2 font-src *.cloudflare.com *.twitter.com https://*.gstatic.com https://*.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.klarnacdn.net https://*.hotjar.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.klarna.com https://*.doubleclick.net https://www.google.com https://*.hotjar.com https://*.livechatinc.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://*.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net www.feedoptimise.com cdn.feedoptimise.com https://*.doubleclick.net https://www.google.com https://www.google.co.uk https://*.facebook.com https://*.yotpo.com services.postcodeanywhere.co.uk www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com https://www.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net www.feedoptimise.com cdn.feedoptimise.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarnaservices.com https://*.nr-data.net https://*.newrelic.net https://*.livechatinc.com https://*.facebook.net https://*.webgains.io https://*.chimpstatic.com https://*.yotpo.com api.addressy.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com https://*.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://static.klaviyo.com https://*.googleapis.com *.klarnacdn.net https://*.yotpo.com api.addressy.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://*.adnxs.com https://*.avanser.com https://*.hubapi.com https://*.algolia.com https://*.algolia.net https://*.algolianet.com https://*.readspeaker.com https://*.cloudflare.com https://*.facebook.net https://*.cdnfonts.com https://*.googleapis.com https://*.gstatic.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hsforms.net https://*.hs-scripts.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hsform.com https://*.hubspot.com https://*.google.com.au https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://*.doubleclick.net https://*.cdninstagram.com https://*.myhealthforlife.com.au https://*.myhealthforlife.org.au https://*.newrelic.com https://*.vimeo.com https://*.raisely.com https://*.siteimproveanalytics.com https://*.hotjar.com https://*.licdn.com https://*.ewaypayments.com https://*.linkedin.com https://*.google.com https://*.doubleclick.net https://*.yimg.com https://*.youtube.com; object-src 'none'; img-src * data:; script-src 'self' https://*.adnxs.com https://*.avanser.com https://*.hubapi.com https://*.algolia.com https://*.algolia.net https://*.algolianet.com https://*.readspeaker.com https://*.cloudflare.com https://*.facebook.net https://*.cdnfonts.com https://*.googleapis.com https://*.gstatic.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hsforms.net https://*.hs-scripts.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hsform.com https://*.hubspot.com https://*.google.com.au https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://*.doubleclick.net https://*.cdninstagram.com https://*.myhealthforlife.com.au https://*.myhealthforlife.org.au https://*.newrelic.com https://*.vimeo.com https://*.raisely.com https://*.siteimproveanalytics.com https://*.hotjar.com https://*.licdn.com https://*.ewaypayments.com https://*.linkedin.com https://*.google.com https://*.doubleclick.net https://*.yimg.com https://*.youtube.com; style-src 'self' * 'unsafe-inline'; font-src * data:; media-src *; frame-src *.vimeo.com *.googletagmanager.com *.doubleclick.net *.youtube.com; 2 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://connect.facebook.net https://googleads.g.doubleclick.net https://d3js.org https://www.gstatic.com https://cse.google.com https://www.googleadservices.com cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://www.lbtu.lv; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://connect.facebook.net https://googleads.g.doubleclick.net https://d3js.org https://www.gstatic.com https://cse.google.com https://www.googleadservices.com cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://www.lbtu.lv; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com https://widgets.trustedshops.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://*.dpdconnect.nl js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com blackhole.lan:9000 https://maps.googleapis.com https://maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com magefan.com cm.magefan.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.sooqr.com *.spotlersearch.com https://www.mollie.com *.multisafepay.com www.xtento.com cdn.xtento.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com/ *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com selfservice.robinhq.com robincontentdesktop.blob.core.windows.net az416426.vo.msecnd.net *.googleads.g.doubleclick.net *.googleadservices.com https://*.dpdconnect.nl https://static.dhlecommerce.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com cdn.xtento.com maps.googleapis.com maps.google.apis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.sooqr.com *.spotlersearch.com *.multisafepay.com maps.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com dc.services.visualstudio.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.sooqr.com *.spotlersearch.com *.multisafepay.com maps.googleapis.com maps.google.apis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com https://maxcdn.bootstrapcdn.com https://iwae.com https://cdn.iwae.com https://static.ecorebates.com www.searchanise.com *.searchserverapi.com *.fontawesome.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com https://phone.aircall.io/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.certcapture.com https://phone.aircall.io/ *.getbread.com *.breadpayments.com *.rbcpayplan.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com www.searchanise.com *.searchserverapi.com *.twitter.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.certcapture.com https://cdn.aircall.io/ *.getbread.com *.breadpayments.com *.rbcpayplan.com magefan.com cm.magefan.com https://seal-louisville.bbb.org https://www.google.com https://bid.g.doubleclick.net https://iwae.com https://cdn.iwae.com https://bat.bing.com https://c.bing.com https://clarity.ms https://static.zdassets.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ guarantee-cdn.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com https://www.magezon.com https://redchamps.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.certcapture.com https://cdn.rawgit.com/ https://phone.aircall.io/ https://phone.aircall.io/static/ *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com https://static.zdassets.com https://acsbapp.com https://www.mczbf.com https://widget.trustpilot.com https://maxcdn.bootstrapcdn.com https://static.klaviyo.com https://fast.a.klaviyo.com https://connect.facebook.net https://ekr.zdassets.com https://static-tracking.klaviyo.com https://telemetrics.klaviyo.com/ *.googleadservices.com *.paypal.com *.cardinalcommerce.com https://static.ecorebates.com https://iwae.com https://cdn.iwae.com searchserverapi.com *.searchserverapi.com https://ingrams.ecorebates.com https://bat.bing.com https://s.pinimg.com https://clarity.ms https://ct.pinterest.com *.leadmanagerfx.com *.marketingcloudfx.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://static-forms.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ *.cloudflare.com guarantee-cdn.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.certcapture.com https://cdn.jsdelivr.net/ widget.freshworks.com m2epro.freshdesk.com https://maxcdn.bootstrapcdn.com https://iwae.com https://cdn.iwae.com https://static.ecorebates.com assets.braintreegateway.com https://static.klaviyo.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.fontawesome.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com https://www.mczbf.com https://iwae.zendesk.com https://cdn.acsbapp.com https://ekr.zdassets.com https://iwae.com https://cdn.iwae.com *.breadgateway.net https://ct.pinterest.com https://b.clarity.ms https://bat.bing.com https://acsbapp.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.amplitude.com stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://fonts.googleapis.com/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; report-uri https://tsp.register.it/report/csp-report; report-to csp-endpoint 2 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.retailrocket.net landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com www.facebook.com assets.fintoc.com https://assets.fintoc.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com www.googletagmanager.com www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.retailrocket.net landofcoder.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.retailrocket.net *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src *.retailrocket.net landofcoder.com 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com connect.facebook.net graph.facebook.com *.retailrocket.net landofcoder.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.commerce-connector.com *.typekit.net */csp/report/uri/ *.hotjar.com *.hotjar.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.wahl.com *.userway.org *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.wahl.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com *.wahl.com; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.adsrvr.org *.hotjar.com *.hotjar.io */csp/report/uri/ *.hubspot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wahl.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app fonts.googleapis.com display.ugc.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com *.klarnacdn.net *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.powerreviews.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.bootstrapcdn.com *.wahlclipper.com *.jsdelivr.net *.postcodeanywhere.co.uk *.commerce-connector.com *.typekit.net */csp/report/uri/ unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com www.gstatic.com cdn.weglot.com *.wahl.com *.userway.org 'self' 'unsafe-inline'; object-src *.wahl.com 'self' 'unsafe-inline'; media-src *.adobe.com *.wahl.com 'self' 'unsafe-inline'; manifest-src *.wahl.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com *.amazonaws.com google.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com stats.g.doubleclick.net ct.pinterest.com *.google-analytics.com *.whatcounts.com siteanalytics.whatcounts.com https://siteanalytics.whatcounts.com *.amazonaws.com/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.powerreviews.com *.nr-data.net *.wahlclipper.com *.syndigo.com *.postcodeanywhere.co.uk wss://ws41.hotjar.com *.commerce-connector.com */csp/report/uri/ wss://*.hotjar.com *.hotjar.com *.hotjar.io *.hubspot.com *.hubapi.com *.hs-banner.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.link.com x.clarity.ms cdn.cookielaw.org forms.hscollectedforms.net geolocation.onetrust.com api.userway.org cdn77.api.userway.org cdn.userway.org api.weglot.com cdn.weglot.com https://cdn-api-weglot.com *.wahl.com *.hsforms.net *.hsforms.com *.clarity.ms *.pcapredict.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; base-uri *.wahl.com 'self' 'unsafe-inline'; script-src https://pxl.jivox.com https://secure.adnxs.com https://apps.bazaarvoice.com/ cdn.weglot.com 0409890c10.translations.weglot.io assets.adobedtm.com *.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com 'self' 'unsafe-inline' sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com static.cloudflareinsights.com cdnjs.cloudflare.com google.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com *.powerreviews.com *.newrelic.com js-agent.newrelic.com *.googletagmanager.com https://www.googletagmanager.com/gtm.js bat.bing.com *.google-analytics.com *.googleoptimize.com https://www.googleoptimize.com/optimize.js *.trustedsite.com *.cloudflare.com *.twitter.com *.fontawesome.com *.nr-data.net *.wahlclipper.com *.googleapis.com *.jsdelivr.net *.bluesnap.com *.webcollage.net *.syndigo.com *.adsrvr.org *.hotjar.com *.hotjar.io *.pcapredict.com *.postcodeanywhere.co.uk *.commerce-connector.com *.amazonaws.com/ */csp/report/uri/ *.redditstatic.com *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.usemessages.com *.hs-analytics.net *.hsadspixel.net *.hsleadflows.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com www.clarity.ms cdn.cookielaw.org js.hubspot.com cdn.userway.org svht.tradedoubler.com swrap.tradedoubler.com *.wahl.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src static.hsappstatic.net https://ad.doubleclick.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobedtm.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.google.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.essentialaccessibility.com *.wahlanimal.com s.ytimg.com *.google.com.mx *.google-analytics.com ct.pinterest.com bat.bing.com *.google.co.in *.cloudflare.com *.wahlclipper.com *.powerreviews.com *.googletagmanager.com *.cloudfront.net *.webcollage.net *.syndigo.cloud *.postcodeanywhere.co.uk */csp/report/uri/ *.reddit.com *.hsforms.com *.hubspot.com *.google.com.in *.payments-amazon.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com c.clarity.ms cdn.cookielaw.org cdn.userway.org *.wahl.com *.magecomp.com *.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; default-src https://de.wahl.com https://fr.wahl.com https://nl.wahl.com https://eu.wahl.com https://es.wahl.com https://jp.mcprod.wahl.com *.wahl.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 2 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com pay.google.com play.google.com *.autopay.eu cdn.dnky.co webchat.dotdigital.com secure.payu.com merch-prod.snd.payu.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu static.payu.com *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io secure.payu.com secure.snd.payu.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.autopay.eu *.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com; font-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com data: *.olark.com fonts.gstatic.com; script-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' 'unsafe-eval' *.turn.com static.cloudflareinsights.com ajax.cloudflare.com *.youtube.com *.ytimg.com *.datadoghq-browser-agent.com *.getclicky.com clicky.com *.twitter.com *.ads-twitter.com *.facebook.net analytics.tiktok.com www.recaptcha.net recaptcha.net www.gstatic.com www.gstatic.cn www.google.com *.olark.com *.adroll.com *.googletagmanager.com tagmanager.google.com analytics.google.com google-analytics.com *.google-analytics.com *.g.doubleclick.net *.doubleclick.net *.googleadservices.com *.google.com *.googlesyndication.com *.googletagservices.com; style-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' *.getclicky.com clicky.com *.olark.com *.googletagmanager.com tagmanager.google.com *.google.com fonts.googleapis.com; img-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' data: *.turn.com secure.gravatar.com *.ytimg.com *.youtube.com *.getclicky.com *.twitter.com t.co *.facebook.com www.gstatic.com/recaptcha *.olark.com *.adroll.com d.adroll.com *.googletagmanager.com analytics.google.com *.analytics.google.com google-analytics.com *.google-analytics.com *.gstatic.com *.google.com *.doubleclick.net *.g.doubleclick.net *.googlesyndication.com www.googleadservices.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://umfworldwide.com https://ultrapassport.com https://umfstage.com https://london.resistancemusic.com https://warsaw.resistancemusic.com https://resistanceibiza.com https://ultraeurope.com https://ultrasouthafrica.com https://ultranewzealand.com https://ultrabuenosaires.com https://ultraperu.com https://ultraaustralia.com https://ultramusicfestival.com https://resistancemiami.com https://medellin.resistancemusic.com https://santiago.resistancemusic.com https://lima.resistancemusic.com https://ultrataiwan.com https://guatemala.roadtoultra.com https://ecuador.roadtoultra.com https://ultrajapan.com https://ultrahongkong.com https://ultrakorea.com https://resistancemusic.com https://ultrabali.com https://ultrachile.com https://thailand.roadtoultra.com https://india.roadtoultra.com https://ultraabudhabi.com https://costadelsol.ultrabeach.com https://costarica.roadtoultra.com https://ultrabrasil.com https://buenosaires.resistancemusic.com https://guatemala.resistancemusic.com https://colombia.roadtoultra.com https://australia.resistancemusic.com https://mexico.resistancemusic.com https://santacruz.resistancemusic.com https://panama.resistancemusic.com https://sanjose.resistancemusic.com https://uruguay.resistancemusic.com https://ultrasingapore.com https://ultramexico.com https://quito.resistancemusic.com https://ultrabeijing.com https://ultrashanghai.com https://philippines.roadtoultra.com https://paraguay.roadtoultra.com https://roadtoultra.com https://bolivia.roadtoultra.com https://*.umfworldwide.com https://*.ultrapassport.com https://*.umfstage.com https://*.london.resistancemusic.com https://*.warsaw.resistancemusic.com https://*.resistanceibiza.com https://*.ultraeurope.com https://*.ultrasouthafrica.com https://*.ultranewzealand.com https://*.ultrabuenosaires.com https://*.ultraperu.com https://*.ultraaustralia.com https://*.ultramusicfestival.com https://*.resistancemiami.com https://*.medellin.resistancemusic.com https://*.santiago.resistancemusic.com https://*.lima.resistancemusic.com https://*.ultrataiwan.com https://*.guatemala.roadtoultra.com https://*.ecuador.roadtoultra.com https://*.ultrajapan.com https://*.ultrahongkong.com https://*.ultrakorea.com https://*.resistancemusic.com https://*.ultrabali.com https://*.ultrachile.com https://*.thailand.roadtoultra.com https://*.india.roadtoultra.com https://*.ultraabudhabi.com https://*.costadelsol.ultrabeach.com https://*.costarica.roadtoultra.com https://*.ultrabrasil.com https://*.buenosaires.resistancemusic.com https://*.guatemala.resistancemusic.com https://*.colombia.roadtoultra.com https://*.australia.resistancemusic.com https://*.mexico.resistancemusic.com https://*.santacruz.resistancemusic.com https://*.panama.resistancemusic.com https://*.sanjose.resistancemusic.com https://*.uruguay.resistancemusic.com https://*.ultrasingapore.com https://*.ultramexico.com https://*.quito.resistancemusic.com https://*.ultrabeijing.com https://*.ultrashanghai.com https://*.philippines.roadtoultra.com https://*.paraguay.roadtoultra.com https://*.roadtoultra.com https://*.bolivia.roadtoultra.com; media-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com *.olark.com; connect-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com cloudflareinsights.com *.datadoghq.com *.browser-intake-datadoghq.com *.getclicky.com *.facebook.com analytics.tiktok.com analytics.pangle-ads.com *.olark.com *.googletagmanager.com *.google-analytics.com analytics.google.com *.analytics.google.com *.g.doubleclick.net *.doubleclick.net *.google.com *.googlesyndication.com www.googletagservices.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; frame-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com *.zohopublic.com *.apple.com open.spotify.com *.soundcloud.com *.youtube.com *.youtube-nocookie.com www.facebook.com *.recaptcha.net recaptcha.net www.google.com recaptcha.google.com *.olark.com *.googletagmanager.com bid.g.doubleclick.net *.google.com *.doubleclick.net *.googlesyndication.com; child-src *.youtube.com *.youtube-nocookie.com *.googletagmanager.com; worker-src www.recaptcha.net; object-src *.googlesyndication.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub7c55919a7d54d6386d0f0b19bc82e82f&dd-evp-origin=content-security-policy&ddsource=csp-report; 2 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.gstatic.com https://s3-eu-west-1.amazonaws.com/globale-prod/Images/Help-Center/fonts/TitilliumWeb-Regular.ttf https://s3.global-e.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.snapchat.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.gomoxie.solutions *.snapchat.com *.doubleclick.net *.paypalobjects.com *.kaptcha.com *.adsrvr.org https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sprinklr.com *.global-e.com *.bglobale.com *.ietf.org *.cookielaw.org *.google.ca *.doubleclick.net d1dwsi2ysdg1so.cloudfront.net us.coca-cola.com cocacola.scene7.com ct.pinterest.com *.facebook.com *.userway.org *.agkn.com *.google.com *.snapchat.com https://firebasestorage.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com *.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://static.queue-it.net https://assets.queue-it.net https://edge.adobedc.net *.global-e.com *.bglobale.com https://analytics.tiktok.com https://queue.cokestore.com https://ct.pinterest.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net rpxnow.com *.rpxnow.com forty11115.pcapredict.com *.gomoxie.solutions js-agent.newrelic.com *.gstatic.com bam.nr-data.net *.coca-cola.com *.pricespider.com *.googletagmanager.com sc-static.net *.sc-static.net *.pinimg.com cdn.kxrd.net *.userway.org *.doubleclick.net connect.facebook.net cdn.krxd.net cdn.cookielaw.org api.addressy.com *.ccnag.com *.sprinklr.com *.adsrvr.org *.snapchat.com *.googleoptimize.com *.coke.com *.avada.io *.shopify.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com *.global-e.com *.bglobale.com https://cdn.userway.org d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net *.gomoxie.solutions p.typekit.net *.pricespider.com api.addressy.com cdn.cookielaw.org *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.sprinklr.com *.global-e.com *.bglobale.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.snplow.net commerce.adobedc.net p13n.adobe.io *.adobedc.net *.demdex.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://edge.adobedc.net *.sprinklr.com https://analytics.tiktok.com https://privacyportal.onetrust.com https://smetrics.coca-colastore.com https://gem-storefront-service-stg.bglobale.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net *.shareacoke.com *.gomoxie.solutions bam.nr-data.net *.doubleclick.net *.coca-cola.com *.coke.com *.b2clogin.com *.facebook.com ct.pinterest.com *.userway.org api.addressy.com *.ccnag.com *.paypalobjects.com *.snapchat.com *.googleapis.com *.cookielaw.org https://get.geojs.io *.avada.io maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cokestore.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 font-src https://*.gstatic.com https://fonts.gstatic.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.yotpo.com *.klevu.com *.ksearchnet.com fonts.gstatic.com use.fontawesome.com app.christies.test static.klaviyo.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://*.dpdconnect.nl *.yotpo.com *.multisafepay.com https://pay.google.com www.googletagmanager.com widget.trustpilot.com d.la1-core1.sfdc-cehfhs.salesforceliveagent.com service.force.com insight.adsrvr.org 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com https://*.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.feedoptimise.com cdn.feedoptimise.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.multisafepay.com app.christies.test cdn-ukwest.onetrust.com cdn.christiesdirect.com x.klarnacdn.net apple-resources.s3.amazonaws.com play.google.com www.facebook.com js.klevu.com bat.bing.com maps.gstatic.com bat.bing.net www.google.co.uk static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js js.stripe.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://*.dpdconnect.nl www.feedoptimise.com cdn.feedoptimise.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.multisafepay.com https://pay.google.com app.christies.test widget.trustpilot.com js.klarna.com integrations.etrusted.com www.dwin1.com connect.facebook.net lantern.roeyecdn.com cdn-ukwest.onetrust.com bat.bing.com static.hotjar.com cdn.attn.tv service.force.com js.adsrvr.org analytics.tiktok.com www.clarity.ms d.la2-c2-cdg.salesforceliveagent.com d.la1-core1.sfdc-cehfhs.salesforceliveagent.com christiesdirect-dev.my.salesforce-sites.com tag.mention-me.com static.mention-me.com maps.googleapis.com static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.yotpo.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.multisafepay.com app.christies.test use.fontawesome.com x.klarnacdn.net js.klevu.com service.force.com pay.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.multisafepay.com region1.google-analytics.com s.clarity.ms js.klarna.com app.christies.test widget.trustpilot.com cdn-ukwest.onetrust.com geolocation.onetrust.com pay.google.com play.google.com maps.googleapis.com bat.bing.net static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src app.christies.test bat.bing.com s.clarity.ms pagead2.googlesyndication.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 worker-src blob:; style-src-elem 'self' 'unsafe-inline' https://assets.bouyguestelecom.fr https://fonts.googleapis.com https://use.fontawesome.com https://maxcdn.bootstrapcdn.com *.abtasty.com *.iadvize.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.google.com https://www.google.tn https://cdn.tagcommander.com *.trustcommander.net https://tag.aticdn.net https://cdnjs.cloudflare.com https://assets.bouyguestelecom.fr *.binkies3d.com https://az589851.vo.msecnd.net https://www.googletagmanager.com https://bat.bing.com https://snap.licdn.com https://dynamic.criteo.com https://www.google-analytics.com https://sslwidget.criteo.com *.bouyguestelecom-entreprises.fr https://pi.pardot.com *.iadvize.com https://connect.facebook.net https://c.amazon-adsystem.com https://player.ausha.co https://newsharecounts.s3-us-west-2.amazonaws.com *.clarity.ms *.abtasty.com https://try.abtasty.com *.contentsquare.net https://cdn.dexem.net https://sc-static.net https://next.voicepublisher.net *.snapchat.com https://ad.doubleclick.net https://googleads.g.doubleclick.net https://www.link-page.info; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' https://assets.bouyguestelecom.fr https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com *.abtasty.com *.iadvize.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' *.bouyguestelecom-pro.fr 'self' 'unsafe-inline'; frame-ancestors 'self' 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' https://www.facebook.com https://www.youtube-nocookie.com https://8940903.fls.doubleclick.net *.criteo.com https://td.doubleclick.net https://www.googletagmanager.com *.snapchat.com *.livestorm.co 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' * blob: https://trusted.cdn.com https://assets.bouyguestelecom.fr *.bouyguestelecom-entreprises.fr *.commander1.com https://az589851.vo.msecnd.net https://px.ads.linkedin.com https://bat.bing.com https://www.google-analytics.com https://www.google.com https://www.google.tn https://www.googletagmanager.com *.abtasty.com https://ad.doubleclick.net *.bouyguestelecom-pro.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.avada.io *.shopify.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.google.com https://www.google.tn https://cdn.tagcommander.com *.trustcommander.net https://tag.aticdn.net https://cdnjs.cloudflare.com https://assets.bouyguestelecom.fr *.binkies3d.com https://az589851.vo.msecnd.net https://www.googletagmanager.com https://bat.bing.com https://snap.licdn.com https://dynamic.criteo.com https://www.google-analytics.com https://sslwidget.criteo.com *.bouyguestelecom-entreprises.fr https://pi.pardot.com *.iadvize.com https://connect.facebook.net https://c.amazon-adsystem.com https://player.ausha.co https://newsharecounts.s3-us-west-2.amazonaws.com *.clarity.ms *.abtasty.com https://try.abtasty.com *.contentsquare.net https://cdn.dexem.net https://sc-static.net https://next.voicepublisher.net *.snapchat.com https://ad.doubleclick.net https://www.link-page.info 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline' https://assets.bouyguestelecom.fr https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com *.abtasty.com *.iadvize.com 'self' 'unsafe-inline'; object-src ; media-src *.adobe.com 'self' blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://logws1361.ati-host.net *.binkies3d.com https://binkiesproductionweu.servicebus.windows.net https://az589851.vo.msecnd.net *.commander1.com https://px.ads.linkedin.com https://www.google.com https://www.google-analytics.com https://analytics.google.com https://bat.bing.com https://bat.bing.net *.clarity.ms *.abtasty.com *.contentsquare.net *.iadvize.com wss://*.iadvize.com https://assets.bouyguestelecom.fr https://ad.doubleclick.net https://stats.g.doubleclick.net *.snapchat.com *.trustcommander.net https://www.google.tn *.google.fr https://yoast.com https://connect.facebook.net *.googleadservices.com *.bouyguestelecom-entreprises.fr 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' https://assets.bouyguestelecom.fr 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' https://trusted-scripts.example.com;style-src 'self'; 2 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://acsbapp.com/ https://browser.sentry-cdn.com/ https://cdn.cookielaw.org/ https://cdn.jsdelivr.net/ https://cdn.tailwindcss.com/ https://code.jquery.com/ https://fast.wistia.com/ https://js.monitor.azure.com/ https://kit.fontawesome.com/ https://www.google.com/ https://www.googletagmanager.com/ https://www.gstatic.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://fonts.googleapis.com; img-src *; font-src * data:; frame-src 'self' https://privacyportal.onetrust.com https://www.google.com; frame-ancestors 'self' *.weatherturndown.corpweb; connect-src 'self' https://*.litix.io https://cdn.acsbapp.com https://cdn.cookielaw.org https://centralus-2.in.applicationinsights.azure.com https://dc.services.visualstudio.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fast.wistia.com https://fast.wistia.net https://geolocation.onetrust.com https://ka-p.fontawesome.com https://pipedream.wistia.com https://privacyportal.onetrust.com https://www.google-analytics.com; object-src 'none'; base-uri 'self'; manifest-src 'self'; media-src 'self' blob:; worker-src 'none'; report-uri https://68654b2b841f0014a4c0d0f7.endpoint.csper.io?v=1; 2 font-src *.punchout2go.com 'self' data: https://*.olark.com https://fonts.gstatic.com data: *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.punchout2go.com 'self' data: https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.punchout2go.com 'self' data: https://spsco.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://cw.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://surefit.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://hc.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://stagingm2.spsco.com https://stagingm2.empowersupply.com https://stagingm2.surefitlab.com https://stagingm2.spshangerstore.com https://productionm2.spsco.com https://productionm2.empowersupply.com https://productionm2.surefitlab.com https://productionm2.spshangerstore.com https://www.spsco.com/ https://www.empowersupply.com https://www.surefitlab.com https://www.spshangerstore.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.online-metrix.net *.punchout2go.com https://static.olark.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://*.spsco.com https://*.punchout2go.com testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.punchout2go.com https://log.olark.com https://www.google.com https://stats.g.doubleclick.net https://*.hellobar.com https://*.magentocommerce.com https://*.paypal.com https://*.vimeocdn.com https://*.ytimg.com https://*.linkedin.com https://*.facebook.com https://*.hsforms.com https://*.clarity.ms https://*.hubspot.com https://*.bing.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.online-metrix.net *.punchout2go.com https://h.online-metrix.net http://*.olark.com https://cdnjs.cloudflare.com https://*.hellobar.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.googleadservices.com https://www.google-analytics.com https://*.hsforms.net https://*.hsforms.com https://js-agent.newrelic.com https://bam.nr-data.net https://*.cybersource.com https://connect.punchout2go.com https://js.hs-scripts.com https://*.facebook.net https://*.facebook.com https://*.paypal.com https://*.paypalobjects.com https://*.braintreegateway.com https://*.licdn.com https://*.cardinalcommerce.com https://*.ccdc02.com https://*.authorize.net https://*.signifyd.com https://*.hs-banner.com https://*.hs-analytics.com https://*.hs-analytics.net https://*.hscollectedforms.com https://*.hscollectedforms.net https://www.vimeo.com https://*.clarity.ms testflex.cybersource.com flex.cybersource.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com https://surestepdev.wpenginepowered.com/ https://surestep.net/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://form.jotform.com/ https://cdn.jotfor.ms/ https://customfaborders.jotform.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.punchout2go.com https://static.olark.com https://fonts.googleapis.com https://connect.punchout2go.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://surestepdev.wpenginepowered.com/ https://use.typekit.net/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.olark.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.punchout2go.com https://*.olark.com https://forms.hsforms.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://bam.nr-data.net https://www.google-analyitics.com https://stats.g.doubleclick.net https://*.hubspot.com https://pro.ip-api.com https://*.cardinalcommerce.com https://*.google.com https://*.clarity.ms https://*.hscollectedforms.net https://*.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com thm.visa.com 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://*.clarity.ms https://*.google-analytics.com 'self' 'unsafe-inline'; 2 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com google.com *.braintreegateway.com *.paypal.com *.google.com *.certcapture.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net youtu.be *.nr-data.net 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.trackedlink.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.yahoo.com *.bing.com *.facebook.com mossmotors.com *.mossmotors.com services.postcodeanywhere.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.hotjar.com *.facebook.net *.bing.com *.murdoog.com *.pcapredict.com *.jsdelivr.net *.yimg.com *.maxmind.com services.postcodeanywhere.co.uk *.cloudfront.net *info.mossmotors.com form.jotform.com *.freshrelevance.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.gstatic.com dmp.info.mossmotors.com dmp.info.mossmiata.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.pcapredict.com services.postcodeanywhere.co.uk assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.yimg.com *.doubleclick.net *.adobedtm.com *.mmapiws.com *.cloudfront.net connect.facebook.net *.facebook.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app dmp.info.mossmotors.com dmp.info.mossmiata.com *.dycdn.net *.freshrelevance.com wss://am.freshrelevance.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; upgrade-insecure-requests; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.timeproducts.co.uk *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com; 2 object-src 'none'; script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com 'unsafe-inline' https://analytics.aefe.fr/; script-src-attr 'self'; script-src-elem 'self' https://analytics.aefe.fr https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 2 font-src *.typekit.net fonts.gstatic.com use.typekit.net *.gstatic.com *.googleapis.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com beacon-audiences.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com *.instagram.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.klevu.com *.ksearchnet.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com beacon-audiences.magento-ds.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.stripe.network *.stripecdn.com *.amazon.com *.googleapis.com *.trustpilot.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io beacon-audiences.magento-ds.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adobedc.net *.demdex.net *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://7dc0cf2f-7ee0-4e32-abdf-e62b11896390.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com *.almapay.com *.cloudflare.com *.trustpilot.com *.avis-verifies.com *.bing.com *.sc.omtrdc.net 'self' data: https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.nootidev.com admin.nootica.fr *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ www.google.com *.hipay-tpp.com *.hipay.com *.googleapis.com *.klarna.com *.demdex.net *.hub-side.com *.nootidev.com admin.nootica.fr *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com *.sc.omtrdc.net 'self' data: *.addthis.com *.trustpilot.com sibautomation.com *.doubleclick.net *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.hipay.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.google.com maps.googleapis.com *.google.fr *.doubleclick.net *.googletagmanager.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu *.avis-verifies.com *.bing.com *.omtrdc.net *.demdex.net *.everesttech.net flagcdn.com *.nootidev.com *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com *.facebook.com *.reddit.com *.google-analytics.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.jsdelivr.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com mpsnare.iesnare.com *.paypal.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://127.0.0.1:35729 *.cloudflare.com *.google-analytics.com *.doubleclick.net *.google.fr *.googleapis.com *.googletagmanager.com *.googleoptimize.com *.trustpilot.com *.avis-verifies.com *.usercentrics.eu *.bing.com *.iesnare.com *.hipay.com 'self' data: *.addthis.com *.addthisedge.com *.moatads.com *.freshworks.com sibautomation.com *.skeepers.io umami.nootica.fr https://cdnjs.cloudflare.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.jsdelivr.net *.hipay.com *.googleapis.com *.klarnacdn.net https://use.fontawesome.com https://fonts.googleapis.com *.cloudflare.com *.typekit.net *.trustpilot.com *.avis-verifies.com *.usercentrics.eu *.bing.com *.sc.omtrdc.net 'self' data: https://cdnjs.cloudflare.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.getalma.eu *.almapay.com *.hipay-tpp.com wss://mpsnare.iesnare.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://olegnax.com *.google-analytics.com *.googlesyndication.com *.analytics.google.com *.doubleclick.net *.cloudflare.com *.bing.com *.demdex.net *.sc.omtrdc.net *.hipay.com 'self' data: ws: *.addthis.com *.brevo.com *.skeepers.io *.nootidev.com search.nootica.com search.bandeja-shop.com umami.nootica.fr *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.podigee-cdn.net 'self' data: d3c2yqbxx52o4l.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.office365.com schoeffel-lowa.de *.podigee-cdn.net komoot.com d3c2yqbxx52o4l.cloudfront.net www.komoot.com d3ms8mre5rhtvu.cloudfront.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.usercentrics.eu *.hubspot.com *.podigee-cdn.net *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com d3c2yqbxx52o4l.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleadservices.com *.usercentrics.eu *.googleapis.com *.hs-scripts.com *.hs-banner.com *.hs-analytics.net *.podigee-cdn.net *.hsforms.net *.hsforms.com *.gstatic.com d3c2yqbxx52o4l.cloudfront.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.podigee-cdn.net *.googleapis.com *.gstatic.com d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; object-src d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.cloudfront.net d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.usercentrics.eu *.googleapis.com *.googlesyndication.com t.elasticsuite.io *.hsforms.net *.hsforms.com d3c2yqbxx52o4l.cloudfront.net www.google-analytics.com analytics.google.com paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https: http: data: wss://*.forter.com 'unsafe-inline' 'unsafe-eval'; connect-src https: http: wss://*.forter.com; frame-ancestors 'self' https: http: *.czs.org 172.21.2.30 www.chasepaymentechhostedpay.com object-src 'self'; img-src 'unsafe-eval' 'unsafe-inline' data: blob: *; font-src 'self' data: https: http: *.typekit.net; script-src 'unsafe-eval' 'unsafe-inline' blob: data: https: http: 'self' emarketing.activenetwork.com d8a4d633e88a.cdn0.forter.com d8a4d633e88a.cdn1.forter.com d8a4d633e88a.cdn2.forter.com d8a4d633e88a.cdn3.forter.com d8a4d633e88a.cdn4.forter.com d8a4d633e88a.cdn5.forter.com d8a4d633e88a.cdn6.forter.com d8a4d633e88a.cdn7.forter.com d8a4d633e88a.cdn8.forter.com d8a4d633e88a.cdn9.forter.com kpstat.forter.com:7043 www.google.com maps.google.com maps.googleapis.com ssl.google-analytics.com www.google-analytics.com www.gstatic.com embed.idonate.com use.typekit.net cdn-js.net cdnjs.cloudflare.com d35u1vg1q28b3w.cloudfront.net partners.cmptch.com static.cmptch.com scriptcdn.net auctioneer.50million.club m.addthis.com s7.addthis.com m.addthisedge.com lkysearchex3688-a.akamaihd.net analyticspage.tools apiurl.org appsource.cool countmake.cool fp166.digitaloptout.com eluxer.net mirextpro.com z.moatads.com secure.myshopcouponmac.com payperclickadz.com cdn.pmqzads.com qdatasales.com widget-prime.rafflecopter.com srvvtrk.com pwm-image.trendmicro.com gateway.zscloud.net; style-src 'unsafe-eval' 'unsafe-inline' 'self' accessibility-bookmarklets.org emarketing.activenetwork.com cdnjs.cloudflare.com use.fontawesome.com fonts.googleapis.com hello.myfonts.net pwm-image.trendmicro.com; report-uri https://bzcsp.report-uri.com/r/d/csp/reportOnly 2 default-src 'self' https://branchapp.in https://branch.co https://branch.co.ke https://branch.com.ng https://branch.co.tz https://d2c5ectx2y1vm9.cloudfront.net; script-src 'self' https://d2c5ectx2y1vm9.cloudfront.net https://code.jquery.com https://ga.jspm.io https://connect.facebook.net https://www.googletagmanager.com https://www.gstatic.com/ https://cdnjs.cloudflare.com 'unsafe-inline' blob: https://www.recaptcha.net https://sdk.cashfree.com https://public.releases.juspay.in https://*.google-analytics.com https://*.google.com; style-src 'self' https://d2c5ectx2y1vm9.cloudfront.net https://cdnjs.cloudflare.com 'unsafe-inline'; font-src 'self' https://d2c5ectx2y1vm9.cloudfront.net https://fonts.gstatic.com data:; img-src 'self' https://d2c5ectx2y1vm9.cloudfront.net https://www.facebook.com data: blob: https://branch-in-production.s3.ap-south-1.amazonaws.com https://fonts.gstatic.com https://graph.facebook.com https://branch-in-public.s3.amazonaws.com; object-src 'self' blob:; connect-src 'self' https://accounts.google.com https://browser-intake-datadoghq.com https://ga.jspm.io https://d2c5ectx2y1vm9.cloudfront.net https://branch-in-production-temp.s3.ap-south-1.amazonaws.com https://www.recaptcha.net https://*.google-analytics.com https://*.google.com; frame-src https://www.recaptcha.net https://sdk.cashfree.com https://www.googletagmanager.com https://branch-in-production.s3.ap-south-1.amazonaws.com; media-src https://d2c5ectx2y1vm9.cloudfront.net; report-uri /csp-violation-report-endpoint 2 frame-src 'self' https://consentcdn.cookiebot.com https://checkoutshopper-test.adyen.com/ https://checkoutshopper.adyen.com/ https://checkoutshopper-live.adyen.com https://pay.google.com https://td.doubleclick.net https://tr.snapchat.com https://ajax.cloudflare.com https://cdn.cxense.com https://scdn.cxense.com https://id.cxense.com https://www.googleadservices.com https://mainf.global-cache.online https://www.gstatic.com https://analytics.soulz.lt https://analytics.soulz.lv https://analytics.soulz.ee https://app.omnisend.com https://cdn.userway.org https://www.googletagmanager.com https://omnisnippet1.com https://www.google.com https://acs2.3ds.modirum.com https://acs.3ds.modirum.com https://acs1.3ds.modirum.com https://acs1.swedbank.se https://acs2.swedbank.se https://3ds2-visasecure2.acdcproc.com https://3dsec.cardcenter.ch https://googleads.g.doubleclick.net https://acs.revolut.com https://acs-challenge.apata.io https://pal-test.adyen.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://boomio-widgets.adomas.workers.dev https://connect.facebook.net https://consentcdn.cookiebot.com https://*.cookiebot.com https://assets.pinterest.com https://omnisnippet1.com https://www.googletagmanager.com https://www.redditstatic.com https://services.digitalmatter.ai http://assets.pinterest.com https://www.primeai.co.uk https://www.google-analytics.com https://scdn.cxense.com/cx.js https://static.cloudflareinsights.com https://pay.google.com https://maps.googleapis.com https://checkoutshopper-test.adyen.com https://unpkg.com https://cdn.cxense.com https://analytics.tiktok.com https://ajax.cloudflare.com https://script.hotjar.com https://static.hotjar.com https://payment.ecommerce.sebgroup.com https://googleads.g.doubleclick.net https://instagram.com https://tr.snapchat.com https://sc-static.net https://checkoutshopper-live.adyen.com https://id.cxense.com https://www.googleadservices.com https://analytics.soulz.lt https://analytics.soulz.lv https://analytics.soulz.ee https://test.soulz.lt/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.lt/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.lv/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.ee/cdn-cgi/challenge-platform/scripts/jsd/main.js https://ajax.googleapis.com https://app.omnisend.com https://www.google.com https://www.gstatic.com; report-uri /nelmio/csp/report 2 worker-src blob: *.osano.com; font-src 'self' data: *.gstatic.com; style-src 'self' data: fonts.googleapis.com *.leadoo.com 'unsafe-inline' *.osano.com; default-src 'self' 'unsafe-eval' data: media.hachettelearning.com; frame-src passport.hoddereducation.co.uk *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com pay.google.com thm.visa.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu *.trustpilot.com *.youtube.com *.vimeo.com *.osano.com td.doubleclick.net verify.monzo.com; connect-src *.algolia.net *.algolianet.com 'self' *.algolia.io *.sentry.io *.browser-intake-datadoghq.eu *.sentry.io google.com/pay *.cardinalcommerce.com *.fontawesome.com vimeo.com *.osano.com *.ads.linkedin.com analytics.tiktok.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.hotjar.io www.google.com googleads.g.doubleclick.net ws.hotjar.com adservice.google.com analytics.google.com stats.g.doubleclick.net; frame-ancestors admin.hachettelearning.com 'self' admin.hachettelearning.com; script-src cdn.eu.trustpayments.com 'self' *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu pay.google.com *.fontawesome.com *.trustpilot.com *.youtube.com *.vimeo.com *.cloudflare.com *.osano.com www.googletagmanager.com 'unsafe-inline' snap.licdn.com static.hotjar.com connect.facebook.net static.ads-twitter.com analytics.tiktok.com *.analytics.google.com script.hotjar.com googleads.g.doubleclick.net; img-src secure.checkout.visa.com *.secure.checkout.visa.com *.vims.visa.com 'self' data: resourcehub-resource-api.hodder.education analytics.twitter.com *.ads.linkedin.com www.facebook.com/tr www.facebook.com www.googletagmanager.com www.google.com t.co www.google.co.uk googleads.g.doubleclick.net media.hachettelearning.com; form-action 'self' *.cardinalcommerce.com *.securetrading.net verify.monzo.com; base-uri 'self'; report-uri https://www.hachettelearning.com/csp-report 2 default-src *; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-elem * 'unsafe-inline' https://www.googletagmanager.com blob: data:; style-src * 'unsafe-inline'; style-src-elem * 'unsafe-inline'; font-src * data: moz-extension:; img-src * data: blob:; media-src * data: blob:; connect-src * properties: data:; frame-src *; worker-src * blob:; report-uri https://sentry-new.public.mybestpro.com/api/8/security/?sentry_key=54be949d75fc07530648e0a189a26f35&sentry_environment=prod 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/youtube-marketing/artists_youtube 2 font-src fonts.gstatic.com use.typekit.net *.bglobale.com *.global-e.com *.fontawesome.com *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.vimeo.com https://*.youtube.com *.bglobale.com *.global-e.com landofcoder.com *.facebook.com *.facebook.net *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://bluesound.com https://forms-na1.hsforms.com https://mcstaging.bluesound.com https://static.zdassets.com https://static.hotjar.com https://cdn.cookielaw.org https://www.google.co.uk *.bglobale.com *.global-e.com magefan.com cm.magefan.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com https://www.milople.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://js.hsforms.net https://cdn.weglot.com unsafe-inline unsafe-eval https://static.zdassets.com https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org https://widget-mediator.zopim.com https://js.hs-scripts.com *.bglobale.com *.global-e.com landofcoder.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src http://*.adobe.com fonts.googleapis.com http://fonts.googleapis.com https://js.digitalriverws.com *.fontawesome.com http://*.alothemes.com http://*.magepow.com http://assets.braintreegateway.com http://tagmanager.google.com https://www.googletagmanager.com 'self' 'unsafe-inline' https://cdn.weglot.com *.bglobale.com *.global-e.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com https://*.adobe.com https://mcstaging.bluesound.com https://www.bluesound.com https://bluesound.com https://content-bluesound-com.s3.amazonaws.com 'self' 'unsafe-inline' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://forms.hsforms.com https://js.hsforms.net https://cdn.weglot.com 'self' https://ekr.zdassets.com https://script.hotjar.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://bluesound.zendesk.com https://psbspeakers.zendesk.com wss://widget-mediator.zopim.com https://region1.analytics.google.com landofcoder.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; media-src https: data:; object-src https: data:; img-src https: data:; font-src https: data:; report-uri /csp-report 2 frame-src 'self' *.app.baqend.com www.youtube.com www.google.com js.playground.klarna.com js.klarna.com https://checkoutshopper-test.adyen.com https://pay.google.com https://wchat.freshchat.com https://connect.getflowbox.com return.4sellers.de *.webpush.freshchat.com ct.pinterest.com vercel.live *.sovendus.com *.adyen.com gum.criteo.com fledge.eu.criteo.com *.cnstrc.com cnstrc.com graphical-editor.kameleoon.com *.vimeo.com vimeo.com www.googletagmanager.com *.chat.getzowie.com 2 script-src-elem *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.payments-amazon.com *.cdn-apple.com *.billiger.de billiger.de *.bing.com *.bing.net js.braintreegateway.com *.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.digitalbridgehq.com *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.avocet.io avocet.io *.gstatic.com *.google.com *.google.co.uk www.googleadservices.com www.google-analytics.com *.googleapis.com *.googlecommerce.com *.googlesyndication.com www.googletagmanager.com s.kk-resources.com *.klarna.com *.klarnacdn.net *.klaviyo.com *.klevu.com secure.cimg.leguide.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk trues11114.pcapredict.com s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com host *.solutenetwork.com *.trustpilot.com unpkg.com 'unsafe-inline' app.vwo.com *.visualwebsiteoptimizer.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.webgains.io *.webgains.com; font-src *.klarnacdn.net *.klevu.com *.ksearchnet.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk w.appzi.io *.equalweb.com *.googleusercontent.com *.typekit.net fonts.gstatic.com *.sirv.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://hpp.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://secure-test.worldpay.com/shopper/3ds/ddc.html https://secure.worldpay.com/shopper/3ds/ddc.html https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate 'self' 'unsafe-inline'; frame-ancestors https://pay.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.equalweb.com *.google.com *.google.co.uk *.googlecommerce.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.visualwebsiteoptimizer.com app.vwo.com https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://pay.google.com https://secure-test.worldpay.com https://hpp.worldpay.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com osm.klarnaservices.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.s3.eu-west-1.amazonaws.com *.bing.com *.bing.net *.cloudfront.net *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.google.com *.google.co.uk www.google.es www.google.it www.google.fr www.google.de www.google.nl www.google.be www.google.at www.google.ie *.googlesyndication.com *.googleusercontent.com *.gstatic.com *.clarity.ms *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.sirv.com *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.cloudflare.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com *.klarnacdn.net *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.cdn-apple.com *.billiger.de billiger.de *.bing.com *.bing.net *.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.digitalbridgehq.com *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.avocet.io avocet.io *.google.com *.google.co.uk *.googleapis.com *.googlecommerce.com *.googlesyndication.com *.gstatic.com s.kk-resources.com *.klaviyo.com *.klevu.com secure.cimg.leguide.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk trues11114.pcapredict.com s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.solutenetwork.com *.trustpilot.com unpkg.com app.vwo.com *.visualwebsiteoptimizer.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.webgains.io *.webgains.com player.vimeo.com https://www.google.com/recaptcha/api.js *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js *.sirv.com https://js.klevu.com https://service.force.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.equalweb.com fonts.googleapis.com www.googletagmanager.com *.gstatic.com *.klaviyo.com services.postcodeanywhere.co.uk *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.typekit.net *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.cloudflare.com https://fonts.googleapis.com/css *.sirv.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.bing.com *.bing.net *.equalweb.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk payments-eu.amazon.com *.s3.eu-west-1.amazonaws.com *.bing.com *.bing.net payments.braintree-api.com *.datadome.co *.digitalbridgehq.com eu.prd.impact.fixtuur.com *.doubleclick.net *.equalweb.com *.facebook.com *.google.com *.google.co.uk www.google.es www.google.it www.google.fr www.google.de www.google.nl www.google.be www.google.at www.google.ie *.googleapis.com *.googlesyndication.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com s.pinimg.com ct.pinterest.com www.pinterest.com services.postcodeanywhere.co.uk region1.google-analytics.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.samsung.com *.typekit.net *.webgains.io *.visualwebsiteoptimizer.com app.vwo.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io https://www.google.com/pay https://pay.google.com/gp/p/web_manifest.json https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/ https://google.com/pay *.worldpay.com https://hpp.worldpay.com/app/hpp/135-0/telemetry https://hpp.worldpay.com/app/hpp/135-0/payment/paypalsmartbutton/continue https://payments.worldpay.com/app/hpp/135-0/telemetry/iframe *.sirv.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.onetrust.com 'self' 'unsafe-inline'; report-uri https://f4ea971e-20d9-420f-b92f-973abc905556.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com www.googletagmanager.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.gateway.spring.citi.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.amplitude.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net yotpo-stool.s3.amazonaws.com *.wistia.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.b0e8.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.mageside.com mageside.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.googleapis.com www.google.com.cy www.google.co.id www.google.com.qa *.googletagmanager.com www.google.com.bh www.google.com.tw www.google.com.om www.google.cv www.google.tn www.google.com.sg www.google.nl www.google.co.in www.google.gg www.google.ge *.ggpht.com www.google.lk www.google.by www.google.com.lb yastatic.net *.bing.net www.google.ad www.google.at www.google.al www.google.vu www.google.ro *.postcodeanywhere.co.uk www.google.no www.google.rs www.google.ie www.google.co.ke www.google.cd www.google.hr www.google.cm www.google.mw www.google.com.pa www.google.co.ve www.google.ae *.linksynergy.com google.com www.google.pl www.google.com.fj *.onetrust.com www.google.com.tr www.google.com.kw www.google.dk www.google.com.np www.google.pt www.google.se www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu yotpo-editor-production.s3.amazonaws.com www.google.com.bn www.google.ru www.google.jo www.google.co.cr www.google.it www.google.co.zm www.google.com.et www.google.ch www.google.ee www.google.hu www.google.co.ao *.google.com www.google.sm *.attn.tv www.google.iq www.google.ca www.google.com.na www.google.li www.google.sn www.google.com.mm www.google.md www.google.co.jp *.ometria.com www.google.am www.google.de www.google.cl *.doubleclick.net www.google.im *.wistia.com *.googlesyndication.com www.google.es www.google.co.za *.pinterest.com www.google.lt www.google.is www.google.gm www.google.sc www.google.co.nz www.google.lu www.google.co.uk www.google.co.zw *.google-analytics.com www.google.com.eg www.google.co.ma www.google.la www.google.com.br www.google.cg www.google.com.jm www.google.com.bd *.googleadservices.com www.google.fi www.google.sk www.google.co.ls www.google.kz www.google.co.ug www.google.com.ph *.attentivemobile.com www.google.je www.google.co.tz www.google.com.au www.google.ga *.kaltura.com www.google.tg www.google.si www.google.mn www.google.bs www.google.lv www.google.com.mt www.google.ba *.portmeirion.co.uk www.google.co.ck www.google.mk www.google.me *.clarity.ms www.google.com.kh www.google.com.sa www.google.kg www.google.so www.google.bj www.google.cz www.google.co.th www.google.co.kr www.google.dz *.bing.com www.google.ci www.google.mv www.google.com.vn www.google.ps www.google.com.hk www.google.co.bw www.google.com.ua www.google.com.af www.google.co.mz www.google.com.gh www.google.com.sl www.google.az www.google.rw www.google.com.ly www.google.bg www.google.co.uz www.google.com.pk www.google.com.my www.google.gr www.google.com.gi www.google.fr www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://rum.hlx.page *.attn.tv events.attentivemobile.com *.b0e8.com *.bc0a.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.klevu.com *.ksearchnet.com s7.addthis.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.ometria.com *.wistia.com *.livechatinc.com *.clarity.ms d21m4dsqdd3b9h.cloudfront.net *.kaltura.com *.onetrust.com *.doubleclick.net *.google-analytics.com *.pinterest.com *.klevu.com *.bing.com *.pcapredict.com *.sentry-cdn.com *.googleapis.com *.google.com *.pinimg.com *.rakuten.com *.postcodeanywhere.co.uk *.googletagmanager.com *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://statsjs.klevu.com https://js.klevu.com *.gstatic.com *.typekit.net d21m4dsqdd3b9h.cloudfront.net *.postcodeanywhere.co.uk *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com video-s3-bucket.s3.eu-west-2.amazonaws.com *.gstatic.com *.wistia.com *.kaltura.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.attn.tv events.attentivemobile.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.hub-box.com *.klevu.com *.ksearchnet.com ekr.zdassets.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.facebook.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.ometria.com www.google.cz www.google.com.bd www.google.ee *.clarity.ms www.google.co.ao www.google.lv www.google.co.ck www.google.com.gh *.kaltura.com www.google.co.uz www.google.co.zw *.bc0a.com www.google.mw www.google.ae www.google.gr www.google.mn www.google.ro www.google.ci www.google.co.tz www.google.com.np www.google.es www.google.lu www.google.com.lb www.google.at *.wistia.com *.bing.com www.google.cv www.google.com.pk www.google.cm www.google.ge www.google.se www.google.md www.google.pl www.google.com.hk *.facebook.com www.google.ie www.google.com.vn www.google.de *.googleapis.com www.google.mu www.google.co.ve www.google.vu www.google.lk www.google.sn www.google.co.za *.portmeirion.com *.postcodeanywhere.co.uk www.google.co.kr www.google.kz www.google.fi *.portmeirion.co.uk www.google.com.ly *.bing.net www.google.im www.google.be www.google.com.bn www.google.dz www.google.co.cr www.google.co.ke *.googlesyndication.com www.google.tn *.doubleclick.net www.google.ba www.google.co.nz www.google.tg www.google.jo www.google.nl www.google.ch *.googleadservices.com www.google.az *.livechatinc.com www.google.gg www.google.bg www.google.com.gi www.google.pt www.google.rs www.google.hu *.attentivemobile.com www.google.com.ua www.google.com.kh www.google.co.il www.google.co.uk *.onetrust.com www.google.fr www.google.co.in www.google.ps www.google.co.mz www.google.am www.google.mv www.google.iq www.google.co.jp www.google.co.bw www.google.com.br www.google.no www.google.kg www.google.com.om www.google.com.tw www.google.je www.google.lt www.google.com.kw www.google.dk www.google.com.tr www.google.hr www.google.co.ug www.google.la www.google.com.au www.google.ru www.google.com.et www.google.co.zm www.google.sk *.samsung.com www.google.by www.google.com.sa www.google.gm www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.me www.google.ga www.google.it www.google.al www.google.com.af www.google.sm www.google.com.bh www.google.mg www.google.is www.google.com.mm www.google.co.th www.google.rw *.pinterest.com *.spode.com www.google.com.ng www.google.sc www.google.ad www.google.com.ph www.google.com.na www.google.co.ma www.google.com.cy www.google.com.mt www.google.com.my www.google.mk www.google.si 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://32ede476-ded8-4814-88cb-f8ecfa864227.sansec.watch/; report-to report-endpoint; 2 font-src *.fontawesome.com script.hotjar.com hyfin.app data: maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com vars.hotjar.com maps.googleapis.com stats.g.doubleclick.net *.fls.doubleclick.net cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io static.hotjar.com script.hotjar.com maps.googleapis.com stats.g.doubleclick.net cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com *.gstatic.com *.googleapis.com *.cdninstagram.com *.fbcdn.net * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com script.hotjar.com static.hotjar.com maps.googleapis.com stats.g.doubleclick.net cdn.evgnet.com *.us-6.evergage.com hyfin.app *.globalpay.com *.verygoodvault.com *.smartystreets.com *.googleapis.com *.gstatic.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com static.hotjar.com script.hotjar.com cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.hotjar.com *.hotjar.io wss://*.hotjar.com bam.nr-data.net stats.g.doubleclick.net cookie-cdn.cookiepro.com maps.googleapis.com cdn.evgnet.com *.us-6.evergage.com wss://*.hyfin.app hyfin.app *.globalpay.com *.verygoodvault.com *.smartystreets.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com data: blob: connectidfeed.did2-e1.investis.com ict.infinity-tracking.net www.gstatic.com viz.tools.investis.com www.google.com maps.googleapis.com maps.google.com www.linkedin.com ajax.googleapis.com pi.pardot.com bam.nr-data.net *.googletagmanager.com *.google-analytics.com sjs.bizographics.com connect.facebook.net *.jquery.com irs.tools.investis.com *.hotjar.com px.ads.linkedin.com d2wy8f7a9ursnm.cloudfront.net ssl.p.jwpcdn.com js-agent.newrelic.com cdn.jsdelivr.net edge.api.brightcove.com *.googleapis.com www.youtube.com youtube.com s.ytimg.com unpkg.com *.investis-live.com https://otp.tools.investis.com/assets/cas_refresh/scripts/cas-tool-helper.min.js *.investisdigital.com player.vimeo.com *.connectidfeed.did2-e1.investis.com assets.investisdigital.com cdnjs.cloudflare.com cdn.jsdelivr.net irs.tools.investis.com assets.investisdigital.com code.jquery.com api.investisdigital.com *.nr-data.net *.myidx.cloud; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com data: blob: connectidfeed.did2-e1.investis.com ict.infinity-tracking.net www.gstatic.com viz.tools.investis.com www.google.com maps.googleapis.com maps.google.com www.linkedin.com ajax.googleapis.com pi.pardot.com bam.nr-data.net *.googletagmanager.com *.google-analytics.com sjs.bizographics.com connect.facebook.net *.jquery.com irs.tools.investis.com *.hotjar.com px.ads.linkedin.com d2wy8f7a9ursnm.cloudfront.net ssl.p.jwpcdn.com js-agent.newrelic.com cdn.jsdelivr.net edge.api.brightcove.com *.googleapis.com www.youtube.com youtube.com s.ytimg.com unpkg.com *.investis-live.com https://otp.tools.investis.com/assets/cas_refresh/scripts/cas-tool-helper.min.js *.investisdigital.com player.vimeo.com *.connectidfeed.did2-e1.investis.com assets.investisdigital.com cdnjs.cloudflare.com cdn.jsdelivr.net irs.tools.investis.com assets.investisdigital.com code.jquery.com api.investisdigital.com www.recaptcha.net static.cloudflareinsights.com *.myidx.cloud; style-src 'self' 'unsafe-inline' 'unsafe-eval' viz.tools.investis.com fonts.googleapis.com fonts.gstatic.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net *.investis-live.com *.investisdigital.com *.myidx.cloud; img-src 'self' 'unsafe-inline' * data: *.myidx.cloud; media-src 'self' edge.api.brightcove.com viz.tools.investis.com data: blob: connectidfeed.did2-e1.investis.com *.media.brightcove.com *.youtube.com player.vimeo.com *.connectidfeed.did2-e1.investis.com *.brightcovecdn.com *.myidx.cloud; frame-src 'self' 'unsafe-inline' * data: blob: connectidfeed.did2-e1.investis.com *.investis.com www.google.com connectidfeed.did2-e1.investis.com ir.tools.investis.com staticxx.facebook.com www.youtube.com player.vimeo.com *.connectidfeed.did2-e1.investis.com *.myidx.cloud; font-src 'self' 'unsafe-inline' data: fonts.googleapis.com fonts.gstatic.com viz.tools.investis.com themes.googleusercontent.com maxcdn.bootstrapcdn.com *.cloudflare.com 2 default-src 'self'; connect-src 'self' dc.services.visualstudio.com ssl.google-analytics.com stats.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com partner.testseek.com intranet.microk12.com middleman.microk12.com; font-src 'self' data: fonts.gstatic.com static.stockinthechannel.com; frame-src 'self' accounts.us.stockinthechannel.com app.powerbi.com ad.doubleclick.net bid.g.doubleclick.net www.youtube.com www.google.com www.vimeo.com; frame-ancestors accounts.us.stockinthechannel.com; img-src * data:; media-src 'self' images.us.stockinthechannel.com media.stockinthechannel.com static.stockinthechannel.com; manifest-src images.us.stockinthechannel.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' accounts.us.stockinthechannel.com images.us.stockinthechannel.com static.stockinthechannel.com www.googleadservices.com ssl.google-analytics.com googleads.g.doubleclick.net https://*.googletagmanager.com www.google.com www.gstatic.com www.youtube.com; style-src 'self' 'unsafe-inline' static.stockinthechannel.com fonts.googleapis.com ajax.googleapis.com; report-uri https://stockchannel.report-uri.com/r/d/csp/reportOnly 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: https://www.googletagmanager.com *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.co.in https://widget.paazl.com https://integrations.etrusted.com https://maps.googleapis.com https://www.sbsupply.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com https://maps.googleapis.com https://static.addtoany.com/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.crwdcntrl.net *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com https://widget-acc.paazl.com https://api-acc.paazl.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://maps.googleapis.com https://api.paazl.com https://widgets.trustedshops.com http://widgets.trustedshops.com https://www.googleadservices.com/ https://bootstrap.smartsuppchat.com https://www.smartsuppchat.com https://consent.studio https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ assets.braintreegateway.com https://integrations.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com https://maps.googleapis.com https://player.vimeo.com https://stats.addtoany.com/menu maps.googleapis.com maps.gstatic.com fonts.googleapis.com http://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.crwdcntrl.net https://get.geojs.io *.avada.io *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://pagead2.googlesyndication.com https://api.paazl.com https://widgets.trustedshops.com https://bootstrap.smartsuppchat.com https://consent.studio https://widget.paazl.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; report-uri /csp-violation-report-endpoint 2 script-src 'self' 'unsafe-eval' blob: https://prod-bk-web.es.rbi.tools/en/static/js/vendor.91aa41c6.js https://prod-bk-web.es.rbi.tools/en/static/js/main.9dbbf7d7.js https://prod-bk-web.es.rbi.tools/en/static/js/runtime.60312eb2.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.es.rbi.tools/en/static/js/vendor.539f11b1.js https://prod-bk-web.es.rbi.tools/en/static/js/main.aafa29ff.js https://prod-bk-web.es.rbi.tools/en/static/js/runtime.fcee8a3c.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 2 default-src 'self'; script-src 'self' 'strict-dynamic' https: data:; object-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com; report-uri /report-csp-violation; upgrade-insecure-requests 2 object-src 'none' ; base-uri 'self' ; font-src 'self' https://fonts.gstatic.com https://www.booxi.eu; manifest-src 'self' ; media-src 'self' ; frame-ancestors 'self' ; worker-src 'none' ; connect-src 'self' https://cognito-idp.eu-west-3.amazonaws.com https://maps.googleapis.com https://api.opngo.com https://static.indigoneo.eu https://auth.opngo.com; 2 font-src fonts.gstatic.com use.typekit.net *.cloudfront.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://*.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk www.google.com https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.braintreegateway.com *.google.com *.doubleclick.net *.shophumm.com.au *.criteo.com *.hotjar.com *.adsrvr.org *.freshchat.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://img.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.cloudflare.com https://cdn.klarna.com *.paypal.com *.afterpay.com *.cloudfront.net https://*.paypal.com *.nextopia.net https://*.zipmoney.com.au *.data-dynamic.net images.latitudepayapps.com *.godfreys.com.au *.feefo.com *.google.com *.google.com.au *.googletagmanager.com.au *.googletagmanager.com *.gstatic.com *.googleapis.com *.bing.com *.criteo.com *.bluekai.com *.socdm.com *.krxd.net *.pubmatic.com *.outbrain.com *.mediavine.com *.aralego.com *.aralego.net *.smaato.net *.clmbtech.com *.yieldmo.com *.emxdgt.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv *.yahoo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.rlcdn.com *.3lift.com *.360yield.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com polyfill.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.forter.com *.cloudfront.net *.openpay.com.au https://js-agent.newrelic.com https://oc-library.playground.klarnaservices.com/lib.js *.bing.com *.criteo.com *.mytopia.com.au *.google.com *.googleoptimize.com *.cfjump.com *.freshchat.com *.zip.co js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com https://static.klaviyo.com https://js.klevu.com/klevu-css/* *.klevu.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.ecomm-nav.com https://*.zipmoney.com.au *.nextopiasoftware.com https://*.facebook.com https://*.safelinks.protection.outlook.com/ *.zdassets.com *.barilliance.com *.barilliance.net *.newrelic.com *.nr-data.net data: https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net https://p.typekit.net *.nextopia.net *.cloudfront.net *.freshchat.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudfront.net *.forter.com *.zipmoney.com.au *.zip.co *.criteo.com *.googlesyndication.com *.googleapis.com *.afterpay.com https://ipapi.co/json/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.typekit.net *.bing.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.langshop.io www.google.com *.google.com *.doubleclick.net *.facebook.com data.henkterhorst.nl js.mollie.com *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.clerk.io retail.googleapis.com henkterhorst.nl *.henkterhorst.nl henkterhorst.de *.henkterhorst.de *.henkterhorst.dk brinks-media.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.1rx.io *.yieldmo.com *.omnitagjs.com *.casalemedia.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.emxdgt.com *.adform.net *.twiago.com *.dmxleo.com *.unrulymedia.com *.eyeota.net *.agkn.com *.clarity.ms https://www.magezon.com https://www.mollie.com *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.twitter.com *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com *.cloudflare.com *.amazonaws.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com https://api.clerk.io https://cdn.clerk.io robincontentdesktop.blob.core.windows.net *.pagesense.io *.adnxs.com *.faslet.net blob: data.henkterhorst.nl *.avada.io js.mollie.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.paypal.com chimpstatic.com *.newrelic.com *.cloudflare.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.nr-data.net *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com *.sooqr.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.typekit.net *.klaviyo.com *.bing.com *.sooqr.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com henkterhorst.nl *.henkterhorst.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.faslet.net *.henkterhorst.nl *.zoho.eu *.googlesyndication.com https://get.geojs.io *.avada.io *.nr-data.net *.newrelic.com *.mailcampaigns.nl *.visualstudio.com *.pinterest.com google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.doubleclick.net *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com https://squeezely.tech *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self';font-src 'self' *.typekit.net *.gstatic.com https://widget.whisbi.com https://maxcdn.bootstrapcdn.com data:;script-src 'self' https://s.go-mpulse.net/ *.typekit.net *.google.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.google-analytics.com *.googleadservices.com *.facebook.net *.ads-twitter.com https://wurfl.io https://config1.veinteractive.com https://static.whisbi.com https://px.veinteractive.com https://api.ipify.org https://library.whisbi.com https://code.jquery.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com widget.whisbi.com https://nebula-cdn.kampyle.com https://www.irishlife.ie https://script.crazyegg.com https://secure.quantserve.com https://snap.licdn.com https://bat.bing.com https://asset.gomoxie.solutions https://screencapture.kampyle.com https://screencaptue-cdn.kampyle.com https://cdn.cookielaw.org/scripttemplates/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://rules.quantcount.com/rules-p-YVPTYyQxqBHy-.js https://analytics.twitter.com/i/ https://cdn.cookielaw.org/consent/f16f9427-5e76-4da0-81ad-7617fbf6cdf4/OtAutoBlock.js https://cdn.cookielaw.org/ https://bat.bing.com/ https://cdn.cookielaw.org/ https://cdnjs.cloudflare.com/ https://googleads.g.doubleclick.net/ https://platform.twitter.com/ https://player.vimeo.com/ https://rules.quantcount.com/ https://script.crazyegg.com/ https://secure.quantserve.com/ https://static.ads-twitter.com/ https://www.google-analytics.com/ https://www.pagespeed-mod.com/ https://www.permanenttsb.ie/ 'unsafe-inline' 'unsafe-eval';style-src 'self' *.googleapis.com *.typekit.net https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://widget.whisbi.com https://www.irishlife.ie https://script.crazyegg.com *.gomoxie.solutions https://config1.veinteractive.com/scripts/ https://cdn.honey.io/ https://md-scp.kampyle.com/ https://www.googletagmanager.com/ https://www.gstatic.com/ 'unsafe-inline';frame-src 'self' *.googletagmanager.com *.google.com *.vimeo.com *.fls.doubleclick.net https://www.irishlife.ie https://config1.veinteractive.com https://script.crazyegg.com *.fls.doubleclick.net https://nebula-cdn.kampyle.com *.gomoxie.solutions https://permanenttsb.ehosts.net https://pay.realexpayments.com/ https://block.opendns.com/ https://filter.techloq.com/ https://gateway.zscalerthree.net/ https://gateway.zscalertwo.net/ https://td.doubleclick.net/ https://www.youtube.com/ https://zscaler-blockpage.endress.com/ https://zswpmanager.wip.mmc.com/;img-src 'self' *.google.ie *.typekit.net *.google-analytics.com *.gstatic.com *.googleapis.com *.google.com *.fls.doubleclick.net https://pixel-ssn.quantserve.com/ https://www.facebook.com/ https://stats.g.doubleclick.net https://udc-neb.kampyle.com data: about: https://a.volvelle.tech https://x.bidswitch.net https://cookiee1.veinteractive.com https://www.irishlife.ie https://nebula-cdn.kampyle.com https://moxie-concierge.s3.amazonaws.com https://asset.gomoxie.solutions https://bat.bing.com/action/ https://t.co/i/ https://www.google.co.uk/pagead/ https://pixel.quantserve.com/ https://px.ads.linkedin.com/ https://www.facebook.com/tr/ https://p.adsymptotic.com/d/px/ https://www.linkedin.com/px/ https://www.google.co.uk/ads/ https://cdn.cookielaw.org/logos/ https://ad.doubleclick.net/ddm/ https://www.googletagmanager.com/ https://px4.ads.linkedin.com/ https://analytics.twitter.com/ https://ad.doubleclick.net/ https://analytics.twitter.com/ https://i.vimeocdn.com/ https://i.ytimg.com/ https://lh3.ggpht.com/ https://pixel.quantserve.com/ https://prreqcroab.icu/ https://t.co/ https://udc-neb.kampyle.com/ https://www.google.ae/ https://www.google.at/ https://www.google.be/ https://www.google.ca/ https://www.google.ch/ https://www.google.co.il/ https://www.google.co.in/ https://www.google.co.nz/ https://www.google.co.th/ https://www.google.co.uk/ https://www.google.com/ https://www.google.com.ar/ https://www.google.com.au/ https://www.google.com.br/ https://www.google.com.co/ https://www.google.com.gi/ https://www.google.com.kh/ https://www.google.com.ng/ https://www.google.com.pe/ https://www.google.com.sa/ https://www.google.cz/ https://www.google.de/ https://www.google.ee/ https://www.google.es/ https://www.google.fr/ https://www.google.gr/ https://www.google.hu/ https://www.google.im/ https://www.google.it/ https://www.google.lu/ https://www.google.nl/ https://www.google.pl/ https://www.google.pt/ https://www.google.ro/ https://www.permanenttsb.ie/ https://ad.doubleclick.net/;connect-src 'self' *.typekit.net *.google-analytics.com https://c.go-mpulse.net/ https://ad.doubleclick.net/ https://www.google.co.uk/ads/ https://www.google.com/ https://pixel.quantserve.com/ https://0217990f.akstat.io/ https://bats.bing.com https://analytics.google.com/ https://privacyportal-de.onetrust.com https://cookiee1.veinteractive.com https://api.whisbi.com https://sessionapi.veinteractive.com https://dtrc.veinteractive.com https://apps.irishlife.ie https://script.crazyegg.com https://nebula-cdn.kampyle.com https://udc-neb.kampyle.com *.gomoxie.solutions https://asset.gomoxie.solutions https://cdn.cookielaw.org/consent/ https://cdn.cookielaw.org/scripttemplates/ https://panel-settings-cdn-e1.ve.com/panelsettings/live/ https://stats.g.doubleclick.net/ https://panel-settings-cdn-e1.ve.com https://tracking.crazyegg.com/ https://pagestates-tracking.crazyegg.com/healthcheck https://assets-tracking.crazyegg.com/healthcheck https://fontawesome.com/ https://cookies-data.onetrust.io/bannersdk/ https://panel-settings-cdn-e1.veinteractive.com/da20settings/live/ https://region1.analytics.google.com/g/ https://drs2.veinteractive.com/ https://bat.bing.com/actionp/ https://adservice.google.com/ https://api.blocksly.org/ https://api.datacloudstat.com/ https://api.solarspireconsulting.com/ https://maps.googleapis.com/ https://pixel.quantcount.com/ https://stats.g.doubleclick.net/ https://translate.googleapis.com/ https://wurfl.io/ https://www.google.ie/ https://cdn.cookielaw.org/ ;worker-src 'self' blob:;object-src 'self' blob:; report-uri /api/contentSecurityPolicy/log 2 default-src 'self' https://stm.smile.eu https://js.hs-scripts.com https://js.hubspot.com https://js.hs-banner.com https://js.usemessages.com https://js.hs-analytics.net https://js.hscollectedforms.net https://www.addtoany.com https://www.googletagmanager.com https://tag.aticdn.net https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.addtoany.com https://unpkg.com js.hsforms.net unpkg.com https://bwkjgjr.pa-cd.com https://forms.hscollectedforms.net https://track.hubspot.com https://api.hubspot.com https://cta-service-cms2.hubspot.com https://forms.hsforms.com https://perf-na1.hsforms.com https://app.hubspot.com http://www.w3.org/2000/svg https://www.google.com https://www.gstatic.com data: https://forms-na1.hsforms.com https://www.youtube.com https://ariane.abtasty.com https://dcinfos-cache.abtasty.com https://b.tile.openstreetmap.org https://a.tile.openstreetmap.org https://c.tile.openstreetmap.org https://lh7-eu.googleusercontent.com https://maps.gstatic.com https://exceptions.hs-embed-reporting.com https://translate.google.com https://www.collinsdictionary.com https://www.facebook.com https://c.clarity.ms https://forms-na1.hubspot.com; connect-src 'self' https://static.hsappstatic.net https://forms.hsforms.com https://forms-na1.hsforms.com https://api.hubspot.com https://track.hubspot.com https://*.hubspot.com https://*.hs-banner.com https://*.linkedin.com https://*.pa-cd.com https://*.abtasty.com https://www.google-analytics.com https://www.googletagmanager.com https://stm.smile.eu; font-src *; img-src 'self' https://fonts.gstatic.com data: https://*.hubspot.com https://*.hsforms.com https://*.linkedin.com https://www.google-analytics.com https://www.googletagmanager.com; script-src 'self' 'unsafe-eval' https://js.hs-scripts.com https://js.hubspot.com https://js.hs-banner.com https://js.usemessages.com https://js.hs-analytics.net https://js.hscollectedforms.net https://www.addtoany.com https://www.googletagmanager.com https://tag.aticdn.net https://try.abtasty.com https://stm.smile.eu https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.addtoany.com https://unpkg.com js.hsforms.net unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://js.hs-scripts.com https://js.hubspot.com https://js.hs-banner.com https://js.usemessages.com https://js.hs-analytics.net https://js.hscollectedforms.net https://www.addtoany.com https://www.googletagmanager.com https://tag.aticdn.net https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.addtoany.com https://unpkg.com js.hsforms.net unpkg.com https://bwkjgjr.pa-cd.com https://forms.hscollectedforms.net https://track.hubspot.com https://api.hubspot.com https://cta-service-cms2.hubspot.com https://forms.hsforms.com https://perf-na1.hsforms.com https://app.hubspot.com http://www.w3.org/2000/svg https://www.google.com https://www.gstatic.com data: https://forms-na1.hsforms.com/ https://forms-na1.hsforms.com https://try.abtasty.com https://www.clarity.ms https://analytics.tiktok.com https://api.livechatinc.com https://s.yimg.jp https://www.google-analytics.com https://cdn.qgraph.io https://script.infinity-tracking.com https://loader.wisepops.com https://connect.facebook.net https://cdn.livechatinc.com https://bat.bing.com https://script.hotjar.com https://b92.yahoo.co.jp/ https://img.macromill.com https://platform.linkedin.com https://www.linkedin.com https://*.licdn.com https://stm.smile.eu https://snap.licdn.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com/pagead/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.google.com https://api.mapbox.com https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-elem * 'unsafe-inline'; report-uri https://qasmileeu.report-uri.com/r/d/csp/reportOnly 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.googleapis.com https://beacon-v2.helpscout.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://js.chargebee.com https://www.googletagmanager.com https://www.gstatic.com/firebasejs/ https://www.gstatic.com/charts/ https://www.youtube.com https://static.cloudflareinsights.com https://js.stripe.com; script-src-elem 'self' 'unsafe-inline' blob: https://cdn.jsdelivr.net/gh/ https://apis.google.com https://cdn.segment.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://js.chargebee.com https://js.stripe.com https://static.cloudflareinsights.com https://beacon-v2.helpscout.net https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; img-src 'self' data: blob: https://d33v4339jhl8k0.cloudfront.net https://support.apple.com https://www.googleadservices.com https://*.mzstatic.com https://beacon-v2.helpscout.net https://s3.amazonaws.com/helpscout.net/docs/ https://s3.amazonaws.com/helpscout.net https://cdn.worshipextreme.com https://i3.ytimg.com https://i.ytimg.com https://www.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://translate.google.com https://www.worshipextreme.com https://fonts.gstatic.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://googleads.g.doubleclick.net/pagead https://api.worship.tools https://beaconapi.helpscout.net https://d3hb14vkzrxvla.cloudfront.net https://download.worshiptools.com https://ipapi.co https://pagead2.googlesyndication.com https://www.google.com https://www.googleapis.com https://region1.google-analytics.com https://www.google-analytics.com https://firestore.googleapis.com https://securetoken.googleapis.com https://translate.googleapis.com https://www.googleadservices.com https://www.googletagmanager.com https://us-east1-worship-extreme.cloudfunctions.net; media-src 'self' data: https://ssl.gstatic.com https://cdn.worshipextreme.com https://media.worshiptools.com; object-src 'none'; frame-src 'self' https://bluecirclelab.chargebee.com https://js.chargebee.com https://www.googletagmanager.com https://www.youtube.com https://docs.google.com https://www.google.com https://js.stripe.com https://worship-extreme-datastore.firebaseapp.com; worker-src 'none'; base-uri 'self'; manifest-src 'self'; report-uri https://starpraise.report-uri.com/r/t/csp/reportOnly; 2 font-src https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://a.klaviyo.com https://www.klaviyo.com *.klaviyo.com *.cloudflare.com *.adyen.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cookiebot.com *.google.se *.utils.elfsightcdn.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.klaviyo.com *.matomo.cloud *.locally.com instant.page *.cookiebot.com *.clarity.ms *.jsdelivr.net *.elfsight.com plausible.io analytics.optimalpeople.fr *.equalweb.com *.newrelic.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.cloudflare.com https://static-tracking.klaviyo.com/ *.jsdelivr.net *.adyen.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.klaviyo.com *.locally.com *.clarity.ms *.matomo.cloud *.instagram *.instagram.com *.elfsight.com analytics.optimalpeople.fr plausible.io *.equalweb.com *.cookiebot.com *.nr-data.net *.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://security-hub.vaimo.network/api/v2/content-security-policy; report-to report-endpoint; 2 frame-ancestors 'self'; block-all-mixed-content; default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net/emojione/2.2.7/lib/js/emojione.min.js https://cdn.popt.in/pixel.js https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.0/jquery.min.js https://connect.facebook.net/en_GB/sdk.js https://embed.tawk.to/_s/v4/app/62835fee0eb/js/twk-chunk-2d0b9454.js https://js.stripe.com/v3/ https://stats.g.doubleclick.net/dc.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/js https://www.gstatic.com/recaptcha/releases/4rwLQsl5N_ccppoTAwwwMrEN/recaptcha__en.js https://www.ipqualityscore.com/api/pingperfect.com/EnAWcy60QjCbGaVhQ47aEJDsOzvE8HxDKAr6xkGX0SiALznu9wGoX7FLCXQormDbwuF21HTXtvA2MlNkkv8l9hAvCvIHZwzBMhqVZkpUKj2FRYixhYbofewy9zy8sMcZVLi2VveEv7XpV9PPssOitHFBjuCGOMbNY1DcLnrgAiVTYb1UsOHaNSO5ezYFHi5mfLH5A7qII1i2K https://embed.tawk.to https://cdn.jsdelivr.net/emojione/ https://platform.twitter.com https://analytics.twitter.com https://en.twitter.com https://cdn.syndication.twimg.com https://use.fontawesome.com https://kit.fontawesome.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://connect.facebook.net https://graph.facebook.com https://js.facebook.com https://*.doubleclick.net https://*.googleadservices.com https://*.google.com https://*.googlesyndication.com https://*.googletagservices.com https://www.google-analytics.com https://ssl.google-analytics.com https://google-analytics.com https://static.cloudflareinsights.com https://ajax.googleapis.com https://js.stripe.com https://checkout.stripe.com https://www.youtube.com https://m.youtube.com https://www.googletagmanager.com https://googletagmanager.com https://secure.gravatar.com https://cdn.jsdelivr.net https://www.recaptcha.net https://recaptcha.net https://www.gstatic.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.google.com/recaptcha/ https://www.paypal.com https://www.paypalobjects.com https://static.ads-twitter.com https://*.ep-mimecast.ads-twitter.com https://cdn.popt.in https://pingperfect.com http://pingperfect.com https://rec.smartlook.com https://www.gstatic.com https://www.pagespeed-mod.com; style-src 'self' 'report-sample' 'unsafe-inline' https://cdn.popt.in/ https://cdnjs.cloudflare.com/ https://embed.tawk.to/ https://fonts.googleapis.com/ https://maxcdn.bootstrapcdn.com/ https://platform.twitter.com/ https://use.fontawesome.com/ fonts.googleapis.com embed.tawk.to ton.twimg.com platform.twitter.com *.fontawesome.com cdnjs.cloudflare.com *.google.com ajax.googleapis.com checkout.stripe.com secure.gravatar.com cdn.jsdelivr.net display.popt.in cdn.popt.in www.gstatic.com www.tinymce.com; object-src *.googlesyndication.com; frame-src 'self' https://js.stripe.com/ https://www.google.com/ va.tawk.to *.twitter.com *.facebook.com connect.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.stripe.com *.stripe.network *.youtube.com www.youtube-nocookie.com www.googletagmanager.com *.recaptcha.net recaptcha.net https://www.google.com/recaptcha/ https://recaptcha.google.com www.paypalobjects.com *.paypal.com; child-src 'self' blob: *.facebook.com connect.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com www.youtube.com www.googletagmanager.com www.paypalobjects.com *.paypal.com; img-src 'self' data: blob: https://abs.twimg.com/ https://embed.tawk.to/ https://pbs.twimg.com/ https://stats.g.doubleclick.net/ https://syndication.twitter.com/ https://www.google.co.uk/ https://www.google.com/ fonts.gstatic.com embed.tawk.to tawk.link cdn.jsdelivr.net/emojione t.co *.twitter.com *.twimg.com cdnjs.cloudflare.com *.facebook.com *.facebook.net *.fbcdn.net www.google-analytics.com ssl.google-analytics.com www.google.com analytics.google.com *.google.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com ajax.googleapis.com *.stripe.com *.ytimg.com *.youtube.com www.googletagmanager.com *.gravatar.com cdn.jsdelivr.net www.gstatic.com/recaptcha www.paypalobjects.com analytics.twitter.com www.gstatic.com steamuserimages-a.akamaihd.net www.pingperfect.com pingperfect.com uploads.mordhau.com www.google.ps www.google.ba www.google.com.mm i.imgur.com android-webview-video-poster:; font-src 'self' data: https://cdnjs.cloudflare.com/ https://embed.tawk.to/ https://fonts.gstatic.com/ https://maxcdn.bootstrapcdn.com/ https://use.fontawesome.com/ *.tawk.to wss://*.tawk.to t.co *.twitter.com *.twimg.com *.facebook.com connect.facebook.net www.google-analytics.com stats.g.doubleclick.net ampcid.google.com analytics.google.com about: cloudflareinsights.com *.doubleclick.net *.google.com *.googlesyndication.com www.googletagservices.com ajax.googleapis.com *.stripe.com www.googletagmanager.com *.gravatar.com *.paypal.com www.paypalobjects.com display.popt.in manager.eu.smartlook.cloud web-writer.eu.smartlook.cloud web-writer.br.smartlook.cloud events-writer.smartlook.com d3lopmpcew67el.cloudfront.net https://new229.com fonts.gstatic.com fonts.googleapis.com embed.tawk.to *.fontawesome.com cdnjs.cloudflare.com cdn.jsdelivr.net github.com chrome-extension:; connect-src 'self' https://verify.cpanel.net/ https://d3lopmpcew67el.cloudfront.net/ https://display.popt.in/ https://embed.tawk.to/ https://fn.eu.ipqualityscore.com/ https://region1.google-analytics.com/ https://stats.g.doubleclick.net/ https://va.tawk.to/ https://www.google-analytics.com/; manifest-src 'self'; base-uri 'self'; form-action 'self' *.twitter.com *.facebook.com connect.facebook.net *.google.com gamepanel.pingperfect.com www.paypal.com; media-src 'self' embed.tawk.to tawk.link dai.google.com; prefetch-src 'self' *.googlesyndication.com; worker-src 'self' blob: www.google.com www.recaptcha.net; report-uri https://pingperfect.report-uri.com/r/d/csp/wizard 2 font-src *.gstatic.com *.addtoany.com *.hotjar.com *.hotjar.io *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com https://wsv3cdn.audioeye.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.addtoany.com *.hotjar.com *.hotjar.io *.hsforms.com *.google.com *.braintreegateway.com *.paypal.com *.kaptcha.com https://bid.g.doubleclick.net *.gettopple.com https://analytics.tiktok.com *.weltpixel.com business.facebook.com www.commercepartnerhub.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.paypal.com *.hubspot.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.google.com blob: https://a5.behance.net https://www.googletagmanager.com *.hsforms.com https://forms.hsforms.com https://forms-na1.hsforms.com *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com business.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.hsforms.net *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://wsmcdn.audioeye.com/aem.js *.gstatic.com https://ssl.avmws.com *.addtoany.com *.hotjar.com *.hotjar.io *.hsforms.com *.hsforms.net *.hs-scripts.com *.hsleadflows.net *.hs-analytics.net *.hs-banner.com *.google.com *.braintreegateway.com *.paypal.com amcglobal.sc.omtrdc.net https://js.hsadspixel.net https://connect.facebook.net https://googleads.g.doubleclick.net https://cdnjs.cloudflare.com *.gettopple.com https://analytics.tiktok.com player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com business.facebook.com twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.googleapis.com amcglobal.sc.omtrdc.net *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.hubspot.com *.google.com hubspot-forms-static-embed.s3.amazonaws.com *.braintreegateway.com *.braintree-api.com *.paypal.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.hs-banner.com *.facebook.net https://api.hubapi.com https://googleads.g.doubleclick.net *.doubleclick.net https://dpm.demdex.net *.hsforms.com https://forms.hsforms.com *.gettopple.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us/ipv6/enrich_ipv6 https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.google-analytics.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 worker-src blob: 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.kxcdn.com geowidget.easypack24.net v2.zopim.com cdn.thulium.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com geowidget-app.inpost.pl mapa.ecommerce.poczta-polska.pl pudofinder.dpd.com.pl js.mollie.com pay.google.com *.googletagmanager.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com www.google.com *.addthis.com secure.livechatinc.com cm.g.doubleclick.net td.doubleclick.net sync.clickonometrics.pl static.clickonometrics.pl www.googletagmanager.com vars.hotjar.com ct.pinterest.com cdn2.pollster.pl widget.spreaker.com start.assets.paypo.pl start.paypo.pl popup.paypo.pl *.sovendus-connect.com *.sovendus.com cdn.consentmanager.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.googleapis.com https://firebasestorage.googleapis.com https://www.mollie.com static.przelewy24.pl www.gstatic.com gstatic.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com *.cdninstagram.com *.kxcdn.com *.twitter.com google.com td.doubleclick.net www.google.pl ct.pinterest.com *.fbcdn.net cdn.livechatinc.com www.facebook.com img.onesignal.com v2.zopim.com cdn.stamped.io content.pollster.pl s1782711468.t.eloqua.com *.adform.net ads.avct.cloud c.clarity.ms c.bing.com ssl.ceneo.pl mrtg.emailpartners.net conversionlabs.net geowidget.easypack24.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com geowidget.inpost.pl api.inpost.pl mapa.ecommerce.poczta-polska.pl api.furgonetka.pl maps.googleapis.com *.avada.io js.mollie.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com ruch-osm.sysadvisors.pl *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com *.googleapis.com www.google.com www.google.pl cdn.ampproject.org connect.facebook.net googletagmanager.com analytics.tiktok.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com cdn.livechatinc.com api.livechatinc.com chimpstatic.com delivery.clickonometrics.pl static.clickonometrics.pl profiling.clickonometrics.pl cdn.mouseflow.com onesignal.com cdn.onesignal.com geowidget.easypack24.net v2.zopim.com static.zdassets.com widget-mediator.zopim.com chat-widget.thulium.com cdn.thulium.com s.pinimg.com static.hotjar.com script.hotjar.com smart.idmnet.pl cdn2.pollster.pl exchange.pollster.pl *.adform.net img06.en25.com utrack.buybox.click hop-js.buybox.click shop-js.buybox.click s1782711468.t.eloqua.com cdn.files.smcloud.net ssl.ceneo.pl api.bebio.pl www.clarity.ms s-eu-1.pushpushgo.com ct.pinterest.com cdn.jsdelivr.net *.sovendus.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com geowidget.inpost.pl mapa.orlenpaczka.pl *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net ruch-osm.sysadvisors.pl tagmanager.google.com fonts.google.com google.com *.kxcdn.com onesignal.com www.googletagmanager.com geowidget.easypack24.net api.bebio.pl cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com chat-widget.thulium.com cdn.thulium.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.furgonetka.pl maps.googleapis.com https://get.geojs.io *.avada.io sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com stats.g.doubleclick.net pagead2.googlesyndication.com region1.google-analytics.com region1.analytics.google.com www.facebook.com analytics.tiktok.com sandbox-api-shipx-pl.easypack24.net api-shipx-pl.easypack24.net wss://widget-mediator.zopim.com widget-mediator.zopim.com ekr.zdassets.com onesignal.com api.synerise.com ai-api.synerise.com api.bebio.pl ct.pinterest.com in.hotjar.com smart.idmnet.pl check.pollster.pl q.clarity.ms utrack.buybox.click content.pollster.pl y.clarity.ms s1782711468.t.eloqua.com ssl.ceneo.pl o2.mouseflow.com grow-apps.growpoland.pl delivery.clickonometrics.pl googleads.g.doubleclick.net cdn.thulium.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://plumrocket.com *.affirm.com *.affirm.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.hubspot.com *.hsforms.com static.hsappstatic.net bat.bing.com *.googleusercontent.com obs.withflowersea.com aorta.clickagy.com *.affirm.com *.affirm.ca *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com js.usemessages.com js.hs-banner.com *.hubspot.com js.hs-analytics.net js.hs-scripts.com js.hsadspixel.net js-agent.newrelic.com ob.withflowersea.com obs.withflowersea.com script.crazyegg.com bat.bing.com www.clarity.ms amplify.outbrain.com wave.outbrain.com bigsur.ai ws-assets.zoominfo.com js.zi-scripts.com tags.clickagy.com js.adsrvr.org js.callrail.com cdn.callrail.com *.affirm.com *.affirm.ca *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://apis.google.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.hubspot.com api.hubapi.com bam.nr-data.net tr.outbrain.com amplify.outbrain.com paid.outbrain.com obs.withflowersea.com js.callrail.com script.crazyegg.com api.prod.bigsur.ai v.clarity.ms js.zi-scripts.com ws.zoominfo.com aorta.clickagy.com hemsync.clickagy.com *.affirm.com *.affirm.ca *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 style-src-elem 'self' 'unsafe-inline' *.maestra-static.io 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com *.cookiebot.eu *.maestra.io *.maestra-static.io *.pay1.de *.klarnacdn.net maps.googleapis.com *.dwin1.com *.facebook.net *.roeyecdn.com https://browser.sentry-cdn.com 'unsafe-inline'; font-src *.fontawesome.com *.facebook.com *.braintreegateway.com *.google.com *.paypal.com *.vimeo.com *.vimeocdn.com *.payments-amazon.co.uk *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.net *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.bing.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.pinterest.com *.youtube.com *.cloudflare.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com *.gstatic.com 'self' data: *.hsappstatic.net *.popmechanic.io data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.doubleclick.net *.googletagmanager.com *.bing.com *.vimeo.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.pinterest.com *.cloudflare.com documentcloud.adobe.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.maestra-static.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.facebook.com *.braintreegateway.com *.google.com *.vimeo.com *.payments-amazon.co.uk *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.net *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.bing.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.pinterest.com *.youtube.com *.cloudflare.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.awin1.com *.googleapis.com *.mindbox.cloud *.roeye.com *.ggpht.com yastatic.net *.maestra.io *.usercentrics.eu *.gstatic.com *.googleadservices.com google.com hoegl.com *.klarnaevt.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com 'unsafe-inline' 'unsafe-eval' *.maestra-static.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.facebook.com *.braintreegateway.com *.google.com *.payments-amazon.co.uk *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.net *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.bing.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.youtube.com *.cloudflare.com documentcloud.adobe.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com *.hsforms.net *.hsforms.com *.gstatic.com maps.googleapis.com 'self' *.roeyecdn.com *.maestra.io *.googleapis.com *.cookiebot.eu *.dwin1.com *.googleadservices.com *.awin1.com *.mindbox.cloud *.pay1.de *.klarnacdn.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src 'unsafe-inline' *.maestra-static.io *.fontawesome.com unsafe-inline assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.facebook.com *.braintreegateway.com *.google.com *.paypal.com *.vimeo.com *.vimeocdn.com *.payments-amazon.co.uk *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.net *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.bing.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.pinterest.com *.youtube.com *.cloudflare.com documentcloud.adobe.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com *.googleapis.com *.gstatic.com 'self' *.maestra.io *.mindbox.cloud 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.gstatic.com hoegl.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.maestra-static.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.facebook.com *.braintreegateway.com *.vimeo.com *.vimeocdn.com *.payments-amazon.co.uk *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.net *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.bing.com *.paypalobjects.com *.sandbox.paypal.com *.pinimg.com *.pinterest.com *.youtube.com *.cloudflare.com *.cookiebot.com *.adobe.io *.googlesyndication.com *.googletagservices.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.googleadservices.com *.klarnaevt.com *.klarnacdn.net *.cookiebot.eu *.googleapis.com *.klarna.com *.maestra.io *.mindbox.cloud 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://3ef0dfbf-4946-43cf-b582-5322b3d2eb53.sansec.watch/; report-to report-endpoint; 2 frame-ancestors 'self'; report-uri https://www.klik.de/api/csp-reports; report-to csp-endpoint; 2 font-src *.fontawesome.com https://fonts.bunny.net www.searchanise.com *.searchserverapi.com *.gstatic.com 'self' data: fonts.gstatic.com *.yotpo.com *.googleapis.com *.cloudflare.com fonts.googleapis.com 'unsafe-inline' data: *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.meetanshi.com js.mollie.com www.searchanise.com *.searchserverapi.com *.twitter.com www.xtento.com *.googletagmanager.com *.yotpo.com widget.trustpilot.com lpcdn.lpsnmedia.net www.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png *.meetanshi.com https://www.mollie.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.yotpo.com *.cloudflare.com *.mdoq.io *.ibottles.co.uk *.google.com *.google.co.uk *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com widget.freshworks.com m2epro.freshdesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.meetanshi.com js.mollie.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com *.yotpo.com *.cloudflare.com *.fontawesome.com *.liveperson.net *.trustpilot.com static.zdassets.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com *.yotpo.com *.cloudflare.com *.bootstrapcdn.com fonts.googleapis.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.ideal-postcodes.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.meetanshi.com api.amplitude.com stats.g.doubleclick.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.yotpo.com *.cloudflare.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk *.zendesk.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.cookiebot.com *.google.com maps.googleapis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.co.uk *.cloudflare.com *.google.co.in maps.googleapis.com https://images.unsplash.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cookiebot.com *.bing.com *.facebook.net *.google.com *.googleapis.com static.cloudflareinsights.com www.gstatic.com https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maps.googleapis.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com maps.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.cookiebot.com googleads.g.doubleclick.net maps.googleapis.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com consentcdn.cookiebot.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.googleapis.com *.gstatic.com maps.googleapis.com imgsct.cookiebot.com www.gstatic.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.adyen.com *.googleapis.com *.gstatic.com player.vimeo.com unpkg.com consent.cookiebot.com d39mkej10j6rgd.cloudfront.net d1wc04gc1zp1rt.cloudfront.net d1ekgxxzy7ounl.cloudfront.net d26u8mjnuxived.cloudfront.net consentcdn.cookiebot.com www.google.com www.gstatic.com js-agent.newrelic.com geoip.improove.io js.klarna.com js.playground.klarna.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com www.gstatic.com x.klarnacdn.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.googleapis.com region1.google-analytics.com consentcdn.cookiebot.com bam.nr-data.net catalog-service-sandbox.adobe.io js.playground.klarna.com js.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com bam.nr-data.net commerce.adobedc.net eu.playground.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.velux.de *.paypalobjects.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.jsctool.com *.google.com *.pay1.de *.hotjar.com *.solutect.de *.awin1.com *.sovendus.com *.paypalobjects.com *.taboola.com *.googlesyndication.com zaunplaner.traumgarten.de *.criteo.com *.criteo.net *.doubleclick.net *.googletagmanager.com *.demdex.net *.sovendus-benefits.com *.sovendus-connect.com *.hipay-tpp.com *.hipay.com *.paypal.com *.mondu.ai/ *.mondu.local localhost:*/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com benz24.de benz24.at benz24.ch benz24.fr *.consentmanager.net *.pay1.de *.consensu.org *.bing.com *.bing.net *.google.com *.google.de *.google.ch *.google.at *.google.fr *.google.nl *.google.be *.google.li *.google.lu *.awin1.com *.bizrate.com *.ladenzeile.de *.googletagmanager.com *.googleadservices.com *.doubleclick.net *.trustedshops.com *.velux.de *.youtube.com *.twiago.com *.1rx.io *.adnxs.com *.smartadserver.com *.taboola.com *.360yield.com *.criteo.com *.criteo.net *.unrulymedia.com https://firebasestorage.googleapis.com https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io cdnjs.cloudflare.com *.consentmanager.net *.pay1.de *.paypal.com *.ratepay.com *.googleapis.com *.sovendus.com *.googletagmanager.com *.consensu.org *.dwin1.com *.bing.com *.hotjar.com *.cnnx.link *.ladenzeile.de *.solutect.de *.awin1.com *.sciencebehindecommerce.com *.trustedshops.com benz24.de benz24.at benz24.ch benz24.fr *.velux.de chimpstatic.com *.paqato.com *.benz24.app mtm.benz24.de *.taboola.com *.googlesyndication.com *.s24.com *.youtube.com *.nextleveldefend.com nextleveldefend.com zaunplaner.traumgarten.de *.criteo.com *.doubleclick.net *.detailsdata7.com *.upsellit.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.avada.io *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com d.ratepay.com d.payla.io dr.payla.io *.consensu.org *.velux.de *.hipay.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.ratepay.com *.doubleclick.net *.google.com google.com *.google.de *.google-analytics.com *.bing.com *.bing.net *.hotjar.com *.hotjar.io *.sovendus.com *.sciencebehindecommerce.com *.trustedshops.com *.etrusted.com *.velux.de *.benz24.app mtm.benz24.de *.taboola.com *.googlesyndication.com zaunplaner.traumgarten.de *.nextleveldefend.com nextleveldefend.com *.paypal.com *.criteo.com *.googleapis.com googleapis.com *.googletagmanager.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; script-src 'self' https://*.neuro-id.com https://*.neuroid.cloud https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://analytics.google.co.uk https://*.analytics.google.co.uk https://analytics.google.ca https://*.analytics.google.ca https://analytics.google.com.au https://*.analytics.google.com.au https://analytics.google.de https://*.analytics.google.de https://analytics.google.fr https://*.analytics.google.fr https://analytics.google.jp https://*.analytics.google.jp https://*.bing.com https://bat.bing.com https://*.bing.net https://api.intellimize.co https://app.leadsrx.com https://*.datadoghq.com https://*.datadoghq-browser-agent.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://pixels.spotify.com https://*.clarity.ms https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://sp.analytics.yahoo.com https://*.analytics.yahoo.com https://cdn.plaid.com https://*.stripe.com https://*.stripe.network https://*.doubleclick.net https://adservice.google.com https://adservice.google.co.uk https://adservice.google.ca https://adservice.google.com.au https://adservice.google.de https://adservice.google.fr https://adservice.google.jp https://*.googleadservices.com https://connect.facebook.net https://dsum-sec.casalemedia.com https://ib.adnxs.com https://*.adsrvr.org https://js.dvnfo.com https://*.roeye.com https://*.roeyecdn.com https://pixel.rubiconproject.com https://*.linkedin.com https://snap.licdn.com https://*.licdn.com https://simage2.pubmatic.com https://*.twitter.com https://static.ads-twitter.com https://t.co https://www.facebook.com https://www.trcknow.com https://x.bidswitch.net https://*.yimg.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://api.segment.io https://api.sprig.com https://api.track.aspiration.com https://api2.branch.io https://app.fintelconnect.com https://app.link https://*.zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://cdn.branch.io https://cdn.cookielaw.org https://cdn.optimizely.com https://cdn.pdst.fm https://cdn.segment.com https://cdn.speedcurve.com https://cdn.sprig.com https://data.adxcel-ec2.com https://evs.track.aspiration.com https://*.intercom.io https://*.intercomcdn.com https://*.onetrust.com https://*.telemetry.vaultdcr.com https://www.dwin1.com https://clientstream.launchdarkly.com https://*.launchdarkly.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com 'unsafe-inline'; font-src 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com data:; img-src 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com https://*.neuro-id.com https://*.neuroid.cloud https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://analytics.google.co.uk https://*.analytics.google.co.uk https://analytics.google.ca https://*.analytics.google.ca https://analytics.google.com.au https://*.analytics.google.com.au https://analytics.google.de https://*.analytics.google.de https://analytics.google.fr https://*.analytics.google.fr https://analytics.google.jp https://*.analytics.google.jp https://*.bing.com https://bat.bing.com https://*.bing.net https://api.intellimize.co https://app.leadsrx.com https://*.datadoghq.com https://*.datadoghq-browser-agent.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://pixels.spotify.com https://*.clarity.ms https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://sp.analytics.yahoo.com https://*.analytics.yahoo.com https://*.doubleclick.net https://adservice.google.com https://adservice.google.co.uk https://adservice.google.ca https://adservice.google.com.au https://adservice.google.de https://adservice.google.fr https://adservice.google.jp https://*.googleadservices.com https://connect.facebook.net https://dsum-sec.casalemedia.com https://ib.adnxs.com https://*.adsrvr.org https://js.dvnfo.com https://*.roeye.com https://*.roeyecdn.com https://pixel.rubiconproject.com https://*.linkedin.com https://snap.licdn.com https://*.licdn.com https://simage2.pubmatic.com https://*.twitter.com https://static.ads-twitter.com https://t.co https://www.facebook.com https://www.trcknow.com https://x.bidswitch.net https://*.yimg.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://api.segment.io https://api.sprig.com https://api.track.aspiration.com https://api2.branch.io https://app.fintelconnect.com https://app.link https://*.zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://cdn.branch.io https://cdn.cookielaw.org https://cdn.optimizely.com https://cdn.pdst.fm https://cdn.segment.com https://cdn.speedcurve.com https://cdn.sprig.com https://data.adxcel-ec2.com https://evs.track.aspiration.com https://*.intercom.io https://*.intercomcdn.com https://*.onetrust.com https://*.telemetry.vaultdcr.com https://www.dwin1.com https://clientstream.launchdarkly.com https://*.launchdarkly.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com data:; connect-src 'self' https://*.neuro-id.com https://*.neuroid.cloud https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://analytics.google.co.uk https://*.analytics.google.co.uk https://analytics.google.ca https://*.analytics.google.ca https://analytics.google.com.au https://*.analytics.google.com.au https://analytics.google.de https://*.analytics.google.de https://analytics.google.fr https://*.analytics.google.fr https://analytics.google.jp https://*.analytics.google.jp https://*.bing.com https://bat.bing.com https://*.bing.net https://api.intellimize.co https://app.leadsrx.com https://*.datadoghq.com https://*.datadoghq-browser-agent.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://pixels.spotify.com https://*.clarity.ms https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://sp.analytics.yahoo.com https://*.analytics.yahoo.com https://cdn.plaid.com https://*.stripe.com https://*.stripe.network https://*.doubleclick.net https://adservice.google.com https://adservice.google.co.uk https://adservice.google.ca https://adservice.google.com.au https://adservice.google.de https://adservice.google.fr https://adservice.google.jp https://*.googleadservices.com https://connect.facebook.net https://dsum-sec.casalemedia.com https://ib.adnxs.com https://*.adsrvr.org https://js.dvnfo.com https://*.roeye.com https://*.roeyecdn.com https://pixel.rubiconproject.com https://*.linkedin.com https://snap.licdn.com https://*.licdn.com https://simage2.pubmatic.com https://*.twitter.com https://static.ads-twitter.com https://t.co https://www.facebook.com https://www.trcknow.com https://x.bidswitch.net https://*.yimg.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://api.segment.io https://api.sprig.com https://api.track.aspiration.com https://api2.branch.io https://app.fintelconnect.com https://app.link https://*.zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://cdn.branch.io https://cdn.cookielaw.org https://cdn.optimizely.com https://cdn.pdst.fm https://cdn.segment.com https://cdn.speedcurve.com https://cdn.sprig.com https://data.adxcel-ec2.com https://evs.track.aspiration.com https://*.intercom.io https://*.intercomcdn.com https://*.onetrust.com https://*.telemetry.vaultdcr.com https://www.dwin1.com https://clientstream.launchdarkly.com https://*.launchdarkly.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; manifest-src 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; frame-src 'self' https://cdn.plaid.com https://*.stripe.com https://*.stripe.network https://*.doubleclick.net https://adservice.google.com https://adservice.google.co.uk https://adservice.google.ca https://adservice.google.com.au https://adservice.google.de https://adservice.google.fr https://adservice.google.jp https://*.googleadservices.com https://connect.facebook.net https://dsum-sec.casalemedia.com https://ib.adnxs.com https://*.adsrvr.org https://js.dvnfo.com https://*.roeye.com https://*.roeyecdn.com https://pixel.rubiconproject.com https://*.linkedin.com https://snap.licdn.com https://*.licdn.com https://simage2.pubmatic.com https://*.twitter.com https://static.ads-twitter.com https://t.co https://www.facebook.com https://www.trcknow.com https://x.bidswitch.net https://*.yimg.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://api.segment.io https://api.sprig.com https://api.track.aspiration.com https://api2.branch.io https://app.fintelconnect.com https://app.link https://*.zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://cdn.branch.io https://cdn.cookielaw.org https://cdn.optimizely.com https://cdn.pdst.fm https://cdn.segment.com https://cdn.speedcurve.com https://cdn.sprig.com https://data.adxcel-ec2.com https://evs.track.aspiration.com https://*.intercom.io https://*.intercomcdn.com https://*.onetrust.com https://*.telemetry.vaultdcr.com https://www.dwin1.com https://clientstream.launchdarkly.com https://*.launchdarkly.com https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; media-src 'self' https://*.googleapis.com https://*.contentful.com https://preview.contentful.com https://graphql.contentful.com https://*.ctfassets.net https://*.cloudfront.net https://*.typekit.net https://*.gstatic.com https://www.google.com https://www.google.co.uk https://www.google.ca https://www.google.com.au https://www.google.de https://www.google.fr https://www.google.jp https://*.googletagmanager.com https://widget.trustpilot.com https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://*.aspcdn.co https://*.aspiration.com https://marketing.greenfi.com https://*.gpsrv.com https://*.greenfi.com https://*.plantyourchange.com https://*.locatorsearch.net https://zscaler.nml.com wss://*.aspiration.com wss://*.greenfi.com; 2 font-src fonts.gstatic.com use.typekit.net data: *.hotjar.com github.com cdn.honey.io *.photoslurp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.redsys.es facebook.com *.adyen.com *.redsys.com *.pinterest.com sas.redsys.es *.facebook.com sas.redsys.com checkoutshopper-live.adyen.com checkoutshopper-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.google.com *.addthis.com *.kampyle.com facebook.com docs.google.com *.facebook.com *.pinterest.es *.pinterest.com service.force.com *.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com blob: *.w3.org *.bing.com c.bing.com *.hotjar.com *.paypal.com bat.bing.com *.clarity.ms *.google.fr facebook.com *.kampyle.com *.gstatic.com *.ladybird.nl *.google.com *.fbcdn.net *.cookiepro.com *.pinterest.com *.pronovias.com *.facebook.com *.google.es *.photoslurp.com *.googleapis.com *.sanpatrick.com *.nicolemilano.com *.cdninstagram.com instagram.com *.verawangbride.com *.whiteonebridal.com *.googletagmanager.com scontent.fmad7-1.fna.fbcdn.net click.s50.exacttarget.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com unpkg.com *.force.com bat.bing.com *.adyen.com *.pinimg.com *.google.com *.hotjar.com *.tiktok.com dropbox.com gstatic.com *.clarity.ms *.moatads.com *.addthis.com *.kampyle.com *.gstatic.com *.dropbox.com *.cookiepro.com *.facebook.net *.facebook.com facebook.net *.photoslurp.com *.googleapis.com *.salesforce.com *.addthisedge.com *.secure.force.com http://polyfill.io service.force.com bam.eu01.nr-data.net *.nicolemilano.com *.empathybroker.com x.empathy.co x.staging.empathy.co *.lightning.force.com analytics.tiktok.com *.googletagmanager.com googletagmanager.com *.salesforceliveagent.com static.lightning.force.com *.la3-c1cs-fra.salesforceliveagent.com d.la3-c1cs-fra.salesforceliveagent.com pronoviasgroup.my.salesforce.com *.pinterest.com player.vimeo.com *.criteo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.honey.io *.kampyle.com *.force.com *.photoslurp.com service.force.com *.nicolemilano.com gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net *.photoslurp.com player.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io wss: bat.bing.com *.force.com *.tiktok.com *.google.com *.hotjar.io *.clarity.ms *.vimeo.com d.clarity.ms h.clarity.ms *.kampyle.com *.hotjar.com google.com vc.hotjar.io ws7.hotjar.com *.instagram.com *.cookiepro.com *.pinterest.com *.amazonaws.com client.rum.us-east-1.amazonaws.com sts.eu-west-1.amazonaws.com ws16.hotjar.com ws20.hotjar.com ws22.hotjar.com ws23.hotjar.com ws33.hotjar.com ws34.hotjar.com *.facebook.com *.googleapis.com *.photoslurp.com *.secure.force.com bam.eu01.nr-data.net *.empathybroker.com x.empathy.co x.staging.empathy.co stats.g.doubleclick.net *.google-analytics.com api.empathybroker.com api.empathy.co api.staging.empathy.co *.cardinalcommerce.com api-staging.empathybroker.com pronoviasgroupcti.secure.force.com analytics.pangle-ads.com properties *.criteo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 base-uri 'self'; default-src 'self' https:; connect-src 'self' data: blob: https://ga.jspm.io *.sentry.io https://consentcdn.cookiebot.com https://consent.cookiebot.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com https://static.raspberrypi.org; font-src 'self' https: data: https://fonts.gstatic.com https://*.hotjar.com; frame-src 'self' https://challenges.cloudflare.com https://consentcdn.cookiebot.com *.google.com e.issuu.com prezi.com storify.com youtube.com www.youtube.com youtube-nocookie.com www.youtube-nocookie.com; img-src 'self' https: data: https://*.raspberrypi.org https://*.hotjar.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com; media-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' blob: https://static.raspberrypi.org/js/global-nav-web-component/ https://challenges.cloudflare.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://*.googletagmanager.com https://*.hotjar.com https://browser.sentry-cdn.com https://js.sentry-cdn.com; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com https://*.hotjar.com https://static.raspberrypi.org/styles/design-system/ https://*.cookiebot.com; worker-src blob:; report-uri https://o17504.ingest.us.sentry.io/api/4507769026707457/security/?sentry_key=53fc037dc5040a1a9fe07334577adc13&sentry_environment=production 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.youtube-nocookie.com www.google.com https://*.dpdconnect.nl youtube.com *.doubleclick.net *.multisafepay.com https://pay.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://firebasestorage.googleapis.com flagpedia.net www.jmpbonderdelen.nl www.jmpbonderdelen.be www.jmpbparts.com www.jmpbteile.de www.jmpbteile.at www.jmpbdele.dk 'self' data: *.google.nl *.multisafepay.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.dpdconnect.nl https://cdn.polyfill.io https://browser.sentry-cdn.com *.avada.io player.vimeo.com *.gstatic.com maps.googleapis.com *.multisafepay.com https://pay.google.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com *.multisafepay.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.google-analytics.com *.doubleclick.net *.google.com google.com *.googlesyndication.com *.googleadservices.com *.google.nl *.multisafepay.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://static.formstack.com https://css.zohocdn.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.google.com https://www.youtube.com https://www.bullseyelocations.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://www.truck-lite.com https://www.rigidindustries.com https://www.clariencetechnologies.com https://www.lumiteclighting.com https://www.truck-lite.eu.com https://mcstaging.truck-lite.com https://trucklite.localhost https://mcstaging.clariencetechnologies.com https://pm.geniusmonkey.com https://css.zohocdn.com https://static.ctctcdn.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://maps.googleapis.com https://maps.gstatic.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://www.gstatic.com https://www.google.com *.google.bg *.googletagmanager.com https://connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://browser-update.org https://wwwtrucklitecom.formstack.com https://static.formstack.com https://www.google.com/recaptcha/api.js https://code.jquery.com https://cdnjs.cloudflare.com https://static.ctctcdn.com https://salesiq.zoho.com https://js.zohocdn.com https://static.zohocdn.com https://js-agent.newrelic.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net https://www.truck-lite.com https://mcstaging.truck-lite.com https://cdn.jsdelivr.net landofcoder.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://js.stripe.com https://www.gstatic.com/recaptcha/releases/Trd6gj1dhC_fx0ma_AWHc1me/recaptcha__en.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://p.typekit.net https://static.ctctcdn.com https://css.zohocdn.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://www.truck-lite.com https://mcstaging.truck-lite.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://wwwtrucklitecom.formstack.com https://listgrowth.ctctcdn.com https://bam.nr-data.net https://salesiq.zohopublic.com https://www.google-analytics.com https://analytics.google.com https://www.facebook.com https://maps.googleapis.com https://www.truck-lite.com https://mcstaging.truck-lite.com landofcoder.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://cdn.velovita.com https://images.ctfassets.net https://secure.gravatar.com; connect-src 'self'; report-uri https://YOUR_ENDPOINT/csp-report 2 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure-magenta.dalenys.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com cl.avis-verifies.com bat.bing.com s.pinimg.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://unpkg.com/pwacompat 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com unpkg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-src 'self' https://*.adyen.com *.cookiebot.com https://cdn.tagcommander.com https://cdn.trustcommander.net https://privacy.trustcommander.net https://privacy.commander1.com https://apps.apple.com https://*.zebet.fr https://*.zebet.com https://*.zebet.be https://*.zebet.es https://*.zebet.nl https://*.zeturf.be https://*.zeturf.com https://*.zeturf.es https://*.zeturf.fr https://*.zeturf.nl https://*.m-itrust.com https://*.redsys.es https://*.apata.io https://*.abanca.com https://*.n26.com https://*.postfinance.ch https://*.ing.fr https://*.monext.fr https://*.ing.com https://*.vinea.es https://*.verifiedbyvisa.com https://*.cic.fr https://*.cm-cic.com https://*.creditmutuel.fr https://*.modirum.com https://*.gbp.ma https://*.cornercard.ch https://*.wlp-acs.com ; report-uri /en/webservice/api/report-csp 2 font-src fonts.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.gstatic.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.monetico-services.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ *.addthis.com *.multisafepay.com https://pay.google.com static.addtoany.com *.cookiebot.com *.pinterest.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.facebook.com *.google.pl *.google.com *.bing.com *.cookiebot.com *.clarity.ms *.doubleclick.net www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io *.alothemes.com *.magepow.com *.multisafepay.com https://pay.google.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be www.clarity.ms connect.getflowbox.com static.addtoany.com cdn-4.convertexperiments.com assets.voyado.com *.cookiebot.com *.beslist.nl *.pinimg.com *.bing.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.gstatic.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.addtoany.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.monetico-services.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.addthis.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.alothemes.com *.magepow.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be testapi.multisafepay.com *.google-analytics.com *.google.com *.googlesyndication.com *.staging.voyado.com *.clarity.ms *.doubleclick.net *.pinterest.com *.cookiebot.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com www.youtube.com js-agent.newrelic.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be static.addtoany.com pay.multisafepay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tawk.to cdnjs.cloudflare.com cdn.jsdelivr.net voidlabs.containers.piwik.pro dl.frontapp.com hcaptcha.com; connect-src 'self' wss://*.tawk.to *.tawk.to newassets.hcaptcha.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com embed.tawk.to; frame-src 'self' demo.voxmail.it www.youtube-nocookie.com newassets.hcaptcha.com; font-src 'self' cdnjs.cloudflare.com fonts.gstatic.com embed.tawk.to; media-src 'self' embed.tawk.to; report-uri https://catbzhkx.uriports.com/reports/report 2 report-uri /algemeen/report_CSP_error.php; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; 2 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' unpkg.com *.cookieinformation.com *.episerver.net *.itxuc.com *.googletagmanager.com *.imgi.no *.youtube.com siteimproveanalytics.com *.siteimproveanalytics.io *.doubleclick.net localhost:5000 *.snapchat.com *.google.com *.facebook.com js.monitor.azure.com *.facebook.net snap.licdn.com sc-static.net *.tiktok.com px.ads.linkedin.com *.cloudfront.net *.eu1.odp.optimizely.com *.bing.com *.ads.linkedin.com *.services.visualstudio.com *.googlesyndication.com *.aptrinsic.com cdn.siteimprove.net adservice.google.com *.googleapis.com *.gstatic.com elvia.my.site.com elvia.my.salesforce-scrt.com elvia--test.sandbox.my.site.com elvia--test.sandbox.my.salesforce-scrt.com cookie-cdn.cookiepro.com fonts.vev.design;report-uri https://phoenix-csp-reporting.azurewebsites.net/cspreport 2 frame-ancestors 'self' *.blackbox.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.blackbox.com www.google.com www.gstatic.com googleads.g.doubleclick.net ajax.googleapis.com www.googleadservices.com www.googletagmanager.com www.google-analytics.com widget-mediator.zopim.com dx.steelhousemedia.com px.steelhousemedia.com snap.licdn.com connect.facebook.net static.ads-twitter.com img.en25.com pi.pardot.com image.providesupport.com fast.wistia.net fast.wistia.com vm.providesupport.com messenger.providesupport.com *.amazonaws.com static.zdassets.com app.enzuzo.com; base-uri 'self'; object-src 'none'; img-src 'self' data: * *.blackbox.eu *.blackbox.nl; report-uri https://errors.cohelion.com/api/25/security/?sentry_key=fdf05d19bad74c99a5f8bdc11b41c1a1 2 font-src *.klaviyo.com res-1.cdn.office.net i.icomoon.io fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.clic2buy.com *.linkbux.com *.opendns.com *.perfsimpl.com *.zipchat.ai consentcdn.cookiebot.com consentcdn.cookiebot.eu *.multisafepay.com https://pay.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.bing.com *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googleadservices.com *.googleapis.com *.gstatic.com *.trustprofile.com *.usercentrics.eu d3k81ch9hvuctc.cloudfront.net www.google.be www.google.fr www.google.nl www.google.ro https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdn.clerk.io imgsct.cookiebot.com imgsct.cookiebot.eu https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.multisafepay.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://widget-acc.paazl.com https://api-acc.paazl.com/ *.clarity.ms *.clerk.io *.clic2buy.com *.cookiebot.eu *.facebook.net *.feedbackcompany.com *.getsitecontrol.com *.google.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.paazl.com *.tiktok.com *.zipchat.ai https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://api.clerk.io https://cdn.clerk.io https://custom.clerk.io consent.cookiebot.com consent.cookiebot.eu *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://widget-acc.paazl.com https://api-acc.paazl.com/ *.gstatic.com *.klaviyo.com *.paazl.com https://static.klaviyo.com https://api.clerk.io https://cdn.clerk.io i.icomoon.io fonts.googleapis.com *.typekit.net *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://widget-acc.paazl.com https://api-acc.paazl.com/ *.clarity.ms *.conversionsapigateway.com *.datadome.co *.doubleclick.net *.facebook.com *.feedbackcompany.com *.getsitecontrol.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.paazl.com *.sentry.io *.tiktok.com *.tiktokw.us *.zipchat.ai google.com mpc-prod-21-1053047382554.us-central1.run.app www.google.be www.google.fr www.google.nl www.google.ro https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.multisafepay.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://84966c07-9303-4ce4-a8a1-d967b6d75831.sansec.watch/; report-to report-endpoint; 2 font-src https://cdn.checkout.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com https://optimize.google.com https://play.google.com localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de js.driftt.com *.freshchat.com *.snapchat.com *.askly.me www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org https://map.plugins.itella.com magefan.com cm.magefan.com *.maksekeskus.ee *.test.maksekeskus.ee https://maps.omnivasiunta.lt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com https://www.google-analytics.com https://optimize.google.com *.googleapis.com *.gstatic.com www.google.lv localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de *.cloudfront.net *.snapchat.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.checkout.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://unpkg.com s7.addthis.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl *.google.com www.googleoptimize.com *.google-analytics.com *.googleapis.com js.driftt.com *.freshchat.com inte.searchnode.io *.clerk.io *.sitescdn.net *.fibbl.com *.hotjar.com sc-static.net *.snapchat.com *.googlesyndication.com *.translatewise.com *.bloomreach.com *.exponea.com *.sizebay.technology www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.checkout.com https://unpkg.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.google.com https://www.google-analytics.com https://fonts.googleapis.com *.typekit.net *.freshchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://geocode.arcgis.com ekr.zdassets.com/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com *.fibblar.com *.fibbl.com www.gstatic.com *.google-analytics.com *.googleapis.com *.g.doubleclick.net *.scandipwa.cloud *.readymage.com *.sportland.com *.sportland.lv *.sportland.ee *.sportland.lt *.sportland.fi *.sportland.pl *.sportland.de blob: *.hotjar.com *.googlesyndication.com *.translatewise.com https://play.google.com *.bloomreach.com *.exponea.com *.sizebay.technology 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src * blob: data: 'unsafe-inline' 'unsafe-eval'; script-src * blob: data: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob:; media-src * data: blob:; font-src * data: blob:; connect-src *; frame-src *; object-src * 2 default-src https: data: 'unsafe-inline' 'unsafe-eval'; report-uri /csp_report; 2 default-src 'self'; script-src 'self'; 2 frame-ancestors 'self' *.qualtrics.com *.my.salesforce.com *.visualforce.com *.visual.force.com *.lightning.force.com; report-uri https://sjc1.qualtrics.com/csp-report 2 font-src *.googleapis.com *.gstatic.com data: *.klaviyo.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://plugin-magento-ui.glopalservice.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com agechecked.verifico.io unity.agechecked.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self' agechecked.verifico.io unity.agechecked.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net embedsocial.com *.reviews.io *.reviews.co.uk *.klarna.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com agechecked.verifico.io unity.agechecked.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.cookiepro.com *.cloudfront.net *.cdninstagram.com *.postcodeanywhere.co.uk *.bing.com *.reviews.io *.reviews.co.uk https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ services.postcodeanywhere.co.uk *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com agechecked.verifico.io unity.agechecked.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.cookiepro.com embedsocial.com *.zdassets.com *.doubleclick.net *.pcapredict.com *.postcodeanywhere.co.uk *.googlesyndication.com *.bing.com *.reviews.io *.reviews.co.uk https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com agechecked.verifico.io unity.agechecked.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com embedsocial.com *.postcodeanywhere.co.uk *.klaviyo.com 'self' data: *.cloudfront.net *.reviews.io *.reviews.co.uk https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.klarnacdn.net https://static.klaviyo.com api.addressy.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com agechecked.verifico.io unity.agechecked.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.cookiepro.com *.onetrust.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com *.googlesyndication.com *.postcodeanywhere.co.uk *.cloudfront.net *.reviews.io *.reviews.co.uk https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.stripe.com klarna.com *.link.com *.amazon.com agechecked.verifico.io unity.agechecked.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://portal.envisagedigital.co.uk/api/website/23noff24jl/report-uri; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: https://fonts.gstatic.com *.googleapis.com *.hsappstatic.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.cookiebot.com *.doubleclick.net js.mollie.com *.weltpixel.com www.xtento.com *.googletagmanager.com *.bing.com *.facebook.com *.google.com google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.bing.com *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com 'self' data: www.google.com.ua www.xtento.com cdn.xtento.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.cookiebot.com *.doubleclick.net *.facebook.com *.facebook.net *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tn *.google.com google.com *.googlesyndication.com *.googleusercontent.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.cookiebot.com *.cloudfront.net *.bing.com *.facebook.net *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com *.doubleclick.net *.googleapis.com *.googlesyndication.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com https://fonts.googleapis.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.googletagmanager.com *.pay.nl *.bing.com *.cookiebot.com *.doubleclick.net *.facebook.com *.facebook.net *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.ca www.google.ch www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gm www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kz www.google.lk www.google.lt www.google.lu www.google.lv www.google.me www.google.mg www.google.mk www.google.mu www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tn *.google.com google.com *.googlesyndication.com *.klaviyo.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com rkkck31tec.execute-api.eu-central-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cc69216c-160f-49b7-b5a2-f80ae473753e.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com https://fonts.gstatic.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net www.mainadv.com *.doubleclick.net *.2trk.info www.instagram.com calendly.com *.sendcloud.sc *.jsdelivr.net *.weltpixel.com *.trustpilot.com *.iubenda.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.roeye.com *.50-ml.com *.google.com *.google.fr *.google.it *.google.es *.google.de *.google.eu *.google.co.uk *.googletagmanager.com bat.bing.com maps.gstatic.com maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.amazonaws.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.iubenda.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.googletagmanager.com https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.preciso.net *.50-ml.eu *.50-ml.it *.50-ml.fr *.50-ml.de *.50-ml.es *.50-ml.com *.50-ml.co.uk www.clarity.ms bat.bing.com www.instagram.com *.googleapis.com maps.gstatic.com assets.calendly.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.sendcloud.sc *.jsdelivr.net *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com *.iubenda.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com sc-static.net *.snapchat.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.calendly.com https://static.klaviyo.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com capig.stape.tech *.50-ml.com *.clarity.ms maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.iubenda.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com sc-static.net *.snapchat.com *.doubleclick.net *.run.app *.typeform.com 50-ml.zendesk.com ekr.zdassets.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https:; connect-src https: wss:; font-src https: data:; frame-src https:; img-src https: data:; media-src https:; object-src https:; script-src 'unsafe-inline' 'unsafe-eval' https: data: blob:; style-src 'unsafe-inline' https:; report-uri https://www.tarifcheck-partnerprogramm.de/csp-violation-ezmd9dpdxv7nb0ecejb9/ 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.monetico-services.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.monetico-services.com https://www.googletagmanager.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://www.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.monetico-services.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.sagepay.com *.yotpo.com *.googleapis.com *.gstatic.com www.partstown.co.uk data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.sagepay.com *.facebook.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; frame-ancestors www.partstown.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com *.weltpixel.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.paypal.com *.sagepay.com validate.fishpig.co.uk *.gstatic.com *.facebook.com *.yotpo.com www.partstown.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.yotpo.com www.partstown.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.sagepay.com tagmanager.google.com *.yotpo.com *.googleapis.com www.partstown.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.partstown.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.paypal.com *.sagepay.com *.google-analytics.com analytics.google.com *.facebook.net https://www.google-analytics.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; child-src www.partstown.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.partstown.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://assetspwa.bananarepublic.com.mx; script-src 'self' https://assetspwa.bananarepublic.com.mx; script-src 'self' https://assetspwa.bananarepublic.com.mx* 'unsafe-inline'; font-src 'self' https://assetspwa.bananarepublic.com.mx; script-src https://assetspwa.bananarepublic.com.mx; style-src 'self' https://assetspwa.bananarepublic.com.mx 2 font-src www.paypalobjects.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.innoship.ro *.addthis.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com https://oqtagonmedia-1224e.kxcdn.com https://www.google.ro/ads/ga-audiences https://region1.analytics.google.com/ https://airsoftcluj-1224e.kxcdn.com/ https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com https://www.oqtagon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com *.avada.io *.shopify.com www.xtento.com cdn.xtento.com https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com https://airsoftcluj-1224e.kxcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net https://oqtagonmedia-1224e.kxcdn.com https://airsoftcluj-1224e.kxcdn.com/ https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io https://region1.analytics.google.com/g/collect 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://static.dhlecommerce.nl https://fonts.gstatic.com https://widgets.trustedshops.com fonts.gstatic.com widgets.trustedshops.com static.klaviyo.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io gum.criteo.com fledge.criteo.com fledge.eu.criteo.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com ct.pinterest.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://maps.googleapis.com https://maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com www.acc-brandfield.com *.googlesyndication.com api.taggrs.io widgets.trustedshops.com www.facebook.com bat.bing.com sync-t1.taboola.com rtb-csync.smartadserver.com pixel.rubiconproject.com x.bidswitch.net simage2.pubmatic.com eb2.3lift.com ad.360yield.com ad.yieldlab.net id5-sync.com exchange.mediavine.com jadserve.postrelease.com criteo-sync.teads.tv r.casalemedia.com sync.targeting.unrulymedia.com criteo-partners.tremorhub.com sync.outbrain.com contextual.media.net aa.agkn.com cm.g.doubleclick.net bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com www.google.nl d3k81ch9hvuctc.cloudfront.net brandfield.work public-prod-dspcookiematching.dmxleo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://static.dhlecommerce.nl https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com static.zdassets.com integrations.etrusted.com static.klaviyo.com widgets.trustedshops.com static-tracking.klaviyo.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com cdn.cookie-script.com s.pinimg.com connect.facebook.net dynamic.criteo.com bat.bing.com analytics.tiktok.com fledge.criteo.com sslwidget.criteo.com www.clarity.ms fledge.eu.criteo.com ct.pinterest.com www.google.com www.gstatic.com static.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com fonts.googleapis.com static.klaviyo.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com ekr.zdassets.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com fast.a.klaviyo.com static-forms.klaviyo.com a.klaviyo.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com ct.pinterest.com gum.criteo.com measurement-api.criteo.com *.clarity.ms ipinfo.io www.google.com *.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com l.clarity.ms www.google.com bat.bing.net analytics.tiktok.com csm.nl3.eu.criteo.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://8f7c9b71-bcff-463a-be0a-2ff1273b3e9d.sansec.watch/; report-to report-endpoint; 2 font-src *.fontawesome.com fonts.gstatic.com www.google.com www.gstatic.com maxcdn.bootstrapcdn.com crmbots.uniongroup.holdings data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com td.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.co *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com zolotakraina.ua www.google.com.ua crmbots.uniongroup.holdings *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com https://polyfill.io polyfill.io multisearch.io connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com secure.authorize.net test.authorize.net js.braintreegateway.com *.googleapis.com *.google.com *.gstatic.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com static.hotjar.com script.hotjar.com js-agent.newrelic.com www.youtube.com crmbots.uniongroup.holdings esputnik.com *.esputnik.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com crmbots.uniongroup.holdings maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io bam.nr-data.net wss://crmbots.uniongroup.holdings crmbots.uniongroup.holdings esputnik.com *.esputnik.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sandbox.paypal.com *.paypalobjects.com paypal.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.feefo.com www.google.co.uk *.tawk.to *.sandbox.paypal.com *.paypalobjects.com paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.noibu.com fullstory.com www.fullstory.com *.hotjar.com embed.tawk.to cdn.jsdelivr.net connect.facebook.net *.feefo.com www.roomvo.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tawk.to *.feefo.com *.sandbox.paypal.com *.paypalobjects.com *.paypal.com paypal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com www.roomvo.com *.feefo.com *.tawk.to wss://*.tawk.to *.sandbox.paypal.com *.paypalobjects.com paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gls.com *.szybkapaczka.pl *.gls-poland.com/ *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' data: *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.facebook.net *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.facebook.net *.szybkapaczka.pl *.gls-poland.com/ secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com cdn.doofinder.com *.facebook.com *.facebook.net https://firebasestorage.googleapis.com https://api.mapbox.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.gls-poland.com.pl/ static.payu.com 'self' data: *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com https://*.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://*.vimeo.com www.vimeo.com *.vimeocdn.com https://*.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js cdn.doofinder.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com https://*.gstatic.com *.avada.io *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ secure.payu.com secure.snd.payu.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.gstatic.com *.tawk.to cdn.jsdelivr.net *.googletagmanager.com https://static.cloudflareinsights.com https://script.hotjar.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://*.newrelic.com https://*.nr-data.net https://www.paypal.com https://www.sandbox.paypal.com https://www.paypalobjects.com https://*.vimeocdn.com https://cdn.jsdelivr.net https://*.tawk.to https://*.stripe.com https://*.stripe.network https://*.stripecdn.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaevt.com https://www.facebook.com https://connect.facebook.net https://*.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.doofinder.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.szybkapaczka.pl *.gls-poland.com/ *.stripe.network *.stripecdn.com *.gstatic.com *.tawk.to cdn.jsdelivr.net fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.szybkapaczka.pl *.gls-poland.com/ *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com *.doofinder.com wss://*.doofinder.com *.facebook.com *.facebook.net https://get.geojs.io *.avada.io *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google-analytics.com *.tawk.to wss://*.tawk.to *.analytics.google.com *.googletagmanager.com https://static.cloudflareinsights.com https://script.hotjar.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.paypal.com https://www.sandbox.paypal.com https://*.newrelic.com https://*.nr-data.net https://*.stripe.com https://connect.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src custom.intucdn.com d.digsgogo.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; frame-ancestors 'self'; report-uri https://lleung.uriports.com/reports/report; report-to default 2 default-src 'self'; base-uri 'self'; connect-src 'self' https://*.fontawesome.com https://*.google.com https://*.googleapis.com https://*.google-analytics.com https://analytics1.wpmudev.com https://cdn.ampproject.org https://www.googletagmanager.com https://yoast.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://*.fontawesome.com https://use.typekit.net; form-action 'self'; frame-ancestors 'self'; frame-src 'self' https://*.google.com https://*.salesforce-sites.com https://issgmt.focalscope.com https://player.vimeo.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.tile.openstreetmap.org https://cdnjs.cloudflare.com https://code.jquery.com https://issgmt.focalscope.com https://secure.gravatar.com https://wpmudev.com https://www.facebook.com https://www.googletagmanager.com; manifest-src 'self'; media-src 'self' https://player.vimeo.com; object-src 'none'; report-uri /wp-json/csp/v1/report; script-src 'self' 'unsafe-inline' https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://ajax.googleapis.com https://analytics.wpmucdn.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://connect.facebook.net https://issgmt.focalscope.com https://kit.fontawesome.com https://unpkg.com https://use.typekit.net https://*.wpmucdn.com; style-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://cdn.jsdelivr.net https://code.jquery.com https://fonts.bunny.net https://*.fontawesome.com https://fonts.googleapis.com https://issgmt.focalscope.com https://unpkg.com https://www.gstatic.com; upgrade-insecure-requests; worker-src 'self' blob:; 2 default-src 'self'; object-src 'self' data:; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com data: fonts.ub-assets.com builder-assets.unbounce.com; img-src 'self' data: https://*.googlesyndication.com https://www.google.pt https://*.teads.tv https://integrations.etrusted.com https://www.google.ch https://www.google.com bat.bing.com www.googletagmanager.com https://*.clarity.ms res.cloudinary.com googleads.g.doubleclick.net https://www.facebook.com https://ad.doubleclick.net *.mcoptic.ch d9hhrg4mnvzow.cloudfront.net maps.gstatic.com i.ytimg.com maps.googleapis.com yt3.ggpht.com https://widgets-images.abtasty.com https://widgets.trustedshops.com https://cdn-cookieyes.com https://c.bing.com *.abtasty.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.mczbf.com https://analytics.optimalpeople.fr https://config1.veinteractive.com https://www.dwin1.com https://*.tradedoubler.com https://*.teads.tv script.hotjar.com maps.googleapis.com cdn.goodays.co www.youtube.com 171acc6227d04b16a51477d1e15beb3b.js.ubembed.com try.abtasty.com www.google.com www.clarity.ms builder-assets.unbounce.com bat.bing.com www.gstatic.com www.googletagmanager.com cdn.jsdelivr.net bat.bing.net dcinfos-cache.abtasty.com www.sqli.ch pagead2.googlesyndication.com app.goodays.co static.doubleclick.net 171acc6227d04b16a51477d1e15beb3b.events.ubembed.com issuu.com terms.mfgroup.ch https://*.ubembed.com js-agent.newrelic.com googleads.g.doubleclick.net cdn-cookieyes.com https://*.clarity.ms https://*.nr-data.net https://widgets.trustedshops.com https://assets.ubembed.com https://ea699c206b994dccb266a248b485ac2e.js.ubembed.com https://*.etrusted.com https://widgets.abtasty.com https://static.profity.ch https://pagead2.googlesyndication.com static.hotjar.com https://*.adform.net https://connect.facebook.net https://analytics.tiktok.com; style-src 'self' 'unsafe-inline' fonts.ub-assets.com builder-assets.unbounce.com https://*.goodays.co https://*.googleapis.com https://*.gstatic.com www.youtube.com https://integrations.etrusted.com *.abtasty.com; connect-src 'self' *.mcoptic.ch *.linsenmax.ch *.visilab.ch https://www.mczbf.com https://analytics.optimalpeople.fr bat.bing.net wss://ws.hotjar.com *.hotjar.com *.hotjar.io https://*.teads.tv *.g.doubleclick.net *.facebook.com *.hotjar.com https://analytics.tiktok.com https://ad.doubleclick.net https://bat.bing.com https://www.google.ch https://www.googleadservices.com https://*.google.com https://*.googleapis.com https://*.googlesyndication.com https://*.etrusted.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.algolia.io https://*.algolia.net https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://*.nr-data.net *.abtasty.com; frame-src 'self' https://*.adform.net https://ad.ad-srv.net https://www.google.com https://*.goodays.co https://www.googletagmanager.com https://*.doubleclick.net; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com fonts.googleapis.com https://fonts.gstatic.com https://ws.colissimo.fr *.cloudflare.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.e-transactions.fr https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com business.facebook.com *.hotjar.com *.eventbrite.com sibautomation.com https://www.youtube.com https://form.typeform.com *.youtube.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com https://plumrocket.com *.weltpixel.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.trackedlink.net business.facebook.com *.trustedshops.com *.etrusted.com *.google.fr *.bing.com *.clarity.ms *.bing.net https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr *.cloudflare.com *.ytimg.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com business.facebook.com *.trustedshops.com *.etrusted.com *.hotjar.com *.eventbrite.com sibautomation.com *.bing.com *.clarity.ms *.jquery.com *.brevo.com *.cloudflare.com *.cloudflareinsights.com *.terreexotique.fr https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.fontawesome.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.trustedshops.com *.etrusted.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.googletagmanager.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com business.facebook.com *.trustedshops.com *.etrusted.com in.hotjar.com *.hotjar.io *.brevo.com *.clarity.ms *.bing.net *.bing.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.cloudflare.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://integrations.etrusted.site payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; img-src * data:; font-src * data:; connect-src *; frame-src *; media-src *; object-src 'none'; report-uri /wp-json/csp/v1/report 2 font-src *.klarnacdn.net *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com static.klaviyo.com tvape.com torontovaporizer.ca stonersguardian.com api.payengine.de payengine.de *.olark.com cdn.tvape.fr *.cloudflare.com cdnjs.cloudflare.com cloudflare.com js.klevu.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.google.com accounts.google.com *.canadapost.ca https://sso.epost.ca *.purolator.com hubspot.com forms.hubspot.com hsforms.net forms.hsforms.com hsforms.com js.hsforms.net stonersguardian.com api.payengine.de payengine.de signin.ebay.com auth.ebay.com ebay.com www.ebay.com *.cardinalcommerce.com tvape.de *.rfihub.com *.wibmo.com *.hsforms.com *.epost.ca *.paypal.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.klarna.com www.google.com accounts.google.com *.meetanshi.com *.purolator.com secure.novalnet.de customers.barzahlen.de customers-sandbox.barzahlen.de https://hosted.paysafe.com *.sendcloud.sc *.jsdelivr.net checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.trustpilot.com customer-upskkbfxkf3xe5cz.cloudflarestream.com iframe.videodelivery.net static.olark.com online.fliphtml5.com r1.dotmailer-surveys.com pp.payengine.de hsforms.net forms.hsforms.com js.hsforms.net dpm.demdex.net demdex.net youtu.be youtube.com stonersguardian.com api.payengine.de payengine.de vimeo.com 20813811p.rfihub.com *.cardinalcommerce.com *.rfihub.com *.wibmo.com *.hsforms.com *.epost.ca *.paypal.com *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com imgsct.cookiebot.com imgsct.cookiebot.eu cdn.doofinder.com validate.fishpig.co.uk *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ accounts.google.com mageside.com *.canadapost.ca *.googleapis.com *.gstatic.com *.meetanshi.com https://redchamps.com *.amazonaws.com media.sezzle.com c.clarity.ms c.bing.com videodelivery.net 6064173.fs1.hubspotusercontent-na1.net customer-upskkbfxkf3xe5cz.cloudflarestream.com tvape.co.uk verify.bluecheck.me torontovaporizer.ca cdn.torontovaporizer.ca tvape.com stats.g.doubleclick.net maps.gstatic.com d3svog4tlx445w.cloudfront.net static.olark.com log.olark.com maps.googleapis.com js.hsforms.net hsforms.net forms.hsforms.com perf.hsforms.com forms.hubspot.com *.tvape.com demdex.net chart.googleapis.com stonersguardian.com api.payengine.de payengine.de r1-t.trackedlink.net img.onesignal.com *.cardinalcommerce.com js.klevu.com x.klarnacdn.net guarantee-cdn.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com consent.cookiebot.com consent.cookiebot.eu cdn.doofinder.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.google.com accounts.google.com *.googleapis.com *.google.com *.gstatic.com *.meetanshi.com *.purolator.com cdn.novalnet.de cdn.barzahlen.de applepay.cdn-apple.com https://hosted.paysafe.com https://api.test.paysafe.com https://api.paysafe.com https://songbirdstag.cardinalcommerce.com embed.sendcloud.sc *.jsdelivr.net checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.trustpilot.com www.youtube.com cdn.jsdelivr.net embed.cloudflarestream.com embed.videodelivery.net knrpc.olark.com static.cloudflareinsights.com maps.googleapis.com stats.g.doubleclick.net www.gstatic.com r1-t.trackedlink.net c1.rfihub.net a.rfihub.net pp.payengine.de static.olark.com assets.olark.com api.olark.com a.optnmstr.com r1.dotmailer-surveys.com g1782759016.co js.hsforms.net hsforms.net forms.hsforms.com dpm.demdex.net demdex.net stonersguardian.com ajax.cloudflare.com api.payengine.de payengine.de g594253005.co verify.bluecheck.me g1782759015.co.de g1782759015.co cdn.onesignal.com onesignal.com bam.nr-data.net *.cardinalcommerce.com script.crazyegg.com cdn.noibu.com cdn4.mxpnl.com *.mxpnl.com js.klevu.com *.mantisadnetwork.com g594253006.co *.crazyegg.com *.newrelic.com *.doofinder.com *.clarity.ms data: *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.doofinder.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com *.googleapis.com maxcdn.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com static.olark.com media.sezzle.com fonts.googleapis.com hsforms.net forms.hsforms.com dpm.demdex.net demdex.net stonersguardian.com api.payengine.de payengine.de accounts.google.com onesignal.com cdn.tvape.fr verify.bluecheck.me *.cloudflare.com cdnjs.cloudflare.com cloudflare.com js.klevu.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com tvape.co.uk torontovaporizer.ca static.olark.com cdn.torontovaporizer.ca stonersguardian.com api.payengine.de payengine.de cdn.tvape.fr *.cardinalcommerce.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.doofinder.com wss://*.doofinder.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.google.com accounts.google.com *.meetanshi.com payport.novalnet.de secure.novalnet.de https://api.test.paysafe.com https://api.paysafe.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com gateway.sezzle.com sandbox.gateway.sezzle.com region1.google-analytics.com *.crazyegg.com knrpc.olark.com api.omappapi.com geoip.sezzle.com media.sezzle.com *.googleapis.com stats.g.doubleclick.net developer.google.com hsforms.net forms.hsforms.com demdex.net stonersguardian.com api.payengine.de payengine.de bam.nr-data.net onesignal.com *.cardinalcommerce.com cdn.noibu.com script.crazyegg.com input.noibu.com *.noibu.com wss://input.noibu.com/pv_part verify.bluecheck.me *.bluecheck.me cdn4.mxpnl.com *.mxpnl.com api-js.mixpanel.com *.mixpanel.com *.ksearchnet.com *.paypal.com *.amazonaws.com *.clarity.ms *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://torontovaporizer.ca/; report-to report-endpoint; 2 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.facebook.com 'self' data: *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.facebook.com 'self' data: js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://www.facebook.com/ connect.facebook.net graph.facebook.com business.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.googletagmanager.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://connect.facebook.net/ connect.facebook.net graph.facebook.com business.facebook.com apis.google.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com *.dwin1.com *.getsitecontrol.com/ https://js-agent.newrelic.com/ https://cdn.cookielaw.org/ https://cdn.equalweb.com js.klevu.com *.ksearchnet.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://www.facebook.com/ connect.facebook.net graph.facebook.com business.facebook.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net/ *.getsitecontrol.com/ https://bam.nr-data.net/ https://cdn.equalweb.com/ https://events.getsitectrl.com/ https://cdn.cookielaw.org/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.bglobale.com *.global-e.com d19ayerf5ehaab.cloudfront.net dsb5btxtdmlo9.cloudfront.net globale-prod.s3-eu-west-1.amazonaws.com *.reviews.io d1azc1qln24ryf.cloudfront.net s3-eu-west-1.amazonaws.com *.hotjar.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.bglobale.com *.global-e.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.doofinder.com *.trackedlink.net *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.cdninstagram.com *.fbcdn.net www.xtento.com cdn.xtento.com www.google.com.ua www.google.co.mz www.google.com.sl www.google.com.gh www.google.az www.google.com.ly www.google.bg www.google.co.uz www.google.com.my www.google.com.pk www.google.com.gi www.google.gr www.google.fr s3-eu-west-1.amazonaws.com www.google.com.ng www.google.com.cy www.google.co.id www.google.com.qa www.google.com.bh www.google.com.co www.google.com.tw www.google.com.om www.google.tn dsb5btxtdmlo9.cloudfront.net www.google.tt tawk.link www.google.com.sg brippo.s3.amazonaws.com www.google.nl www.google.co.in www.google.gg www.google.ge *.ggpht.com www.google.by www.google.lk www.google.com.lb *.rainbowclub.com www.google.at www.google.al *.mccreedie.co.uk www.google.ro *.postcodeanywhere.co.uk s3.amazonaws.com *.googleusercontent.com www.google.no www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.cm www.google.co.ve www.google.ae www.google.pl www.google.com.fj www.google.com.tr www.google.dk www.google.com.uy www.google.se www.google.pt www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.ru www.google.jo www.google.co.cr www.google.it www.google.co.zm www.google.com.et www.google.ch www.google.ee www.google.hu *.ojrq.net *.rainbowclub.co.uk *.tawk.to *.pxf.io www.google.ca www.google.sn www.google.md *.reviews.io www.google.co.jp www.google.am www.google.de www.google.cl *.awin1.com www.google.im *.doubleclick.net *.usercentrics.eu *.googlesyndication.com www.google.es www.google.co.za d21m4dsqdd3b9h.cloudfront.net www.google.com.ag www.google.lt www.google.sc www.google.gm www.google.co.nz www.google.lu www.google.co.uk www.google.com.do www.google.co.zw www.google.com.eg www.google.co.ma *.trackedweb.net www.google.com.jm www.google.com.bd www.google.tm *.googleadservices.com www.google.fi www.google.sk www.google.com.ph ebizmartsextensions.s3.amazonaws.com www.google.je www.google.com.au www.google.tg www.google.si *.pinterest.com www.google.lv www.google.com.mt www.google.ba www.google.mk www.google.com.kh www.google.com.sa www.google.so *.chatham.co.uk www.google.cz www.google.co.th www.google.co.kr www.google.dz www.google.ci www.google.mv www.google.com.vn data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com *.bglobale.com *.global-e.com *.klarnaservices.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com *.instagram.com www.xtento.com cdn.xtento.com https://dsb5btxtdmlo9.cloudfront.net *.impactradius-event.com *.googletagmanager.com *.pcapredict.com *.googlesyndication.com *.wisepops.com *.tawk.to *.payments-amazon.com *.toolszen.com dsb5btxtdmlo9.cloudfront.net *.dwin1.com *.doofinder.com *.hotjar.com *.doubleclick.net *.pinterest.com *.reviews.co.uk *.cloudflare.com *.typeform.com *.awin1.com *.pinimg.com *.postcodeanywhere.co.uk *.usercentrics.eu *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.bglobale.com *.global-e.com *.klarnacdn.net *.nosto.com *.nos.to assets.braintreegateway.com tagmanager.google.com *.reviews.io *.tawk.to *.mccreedie.co.uk dsb5btxtdmlo9.cloudfront.net d19ayerf5ehaab.cloudfront.net *.reviews.co.uk *.postcodeanywhere.co.uk *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cdninstagram.com *.tawk.to d21m4dsqdd3b9h.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.klarnaservices.com *.nosto.com *.nos.to wss://*.hotjar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.instagram.com *.googleusercontent.com *.tawk.to www.google.com.do www.google.co.th *.pinterest.com www.google.com.ng www.google.sc *.rainbowclub.co.uk www.google.com.ph www.google.co.ma www.google.com.cy www.google.com.co www.google.com.mt *.usercentrics.eu www.google.com.my www.google.si www.google.mk www.google.cz *.bglobale.com www.google.com.bd www.google.ee *.global-e.com www.google.lv *.wepowerconnections.com www.google.ae www.google.gr www.google.ro www.google.ci www.google.es www.google.lu www.google.at www.google.com.pk *.hotjar.io www.google.com.ag www.google.se www.google.pl www.google.ie *.facebook.com www.google.com.vn www.google.de www.google.mu www.google.lk www.google.sn www.google.co.za *.reviews.co.uk *.pxf.io *.postcodeanywhere.co.uk www.google.co.kr www.google.fi www.google.cl www.google.be www.google.im *.reviews.io *.impct.site www.google.co.ke *.googlesyndication.com www.google.tn www.google.com.uy www.google.ba www.google.co.nz www.google.jo www.google.nl *.typeform.com www.google.ch *.googleadservices.com www.google.az www.google.bg www.google.gg *.datah04.com www.google.com.gi www.google.pt www.google.rs www.google.hu www.google.com.mx www.google.com.kh www.google.com.ua www.google.co.il www.google.co.uk www.google.fr www.google.com.sl www.google.co.in www.google.am www.google.mv www.google.co.jp www.google.no www.google.com.om www.google.com.tw www.google.je www.google.dk www.google.com.tr www.google.hr www.google.com.au www.google.ru www.google.com.et www.google.co.zm www.google.sk www.google.by www.google.com.sa www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.it dsb5btxtdmlo9.cloudfront.net www.google.al www.google.mg 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e840a2bc-3d9d-4f2a-b6af-c5aad746125f.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.klaviyo.com *.scratcher.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.xtento.com *.klarna.com *.resurs.com *.vimeo.com *.google.com *.googletagmanager.com gtm.sharkgaming.dk gtm.sharkgaming.se gtm.sharkgaming.no gtm-p7bx89s-nwviz.uc.r.appspot.com *.chatbotize.com *.cookieinformation.com *.trustpilot.com *.viabill.com *.doubleclick.net *.getzowie.com chat.karlachat.com game.scratcher.io *.getblue.io *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com www.xtento.com cdn.xtento.com *.bird.eu *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.bing.com *.magentocommerce.com *.sleeknote.com sharkgaming.dk sharkgaming.se sharkgaming.no *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.google.dk *.google.se *.google.no *.charpstar.net s7g10.scene7.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.sharethis.com www.xtento.com cdn.xtento.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.resurs.com *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.app.cookieinformation.com *.sleeknote.com *.viabill.com *.trustpilot.com *.emaerket.dk *.payever.org *.hotjar.com *.bing.com addrevenue.io *.retargeted.co *.getzowie.com *.zopim.com *.adii.se *.scratcher.io *.charpstar.net *.azureedge.net gtm-p7bx89s-nwviz.uc.r.appspot.com analytics.tiktok.com *.getblue.io analytics.bestofluck.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com app.scratcher.io game.scratcher.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.omtrdc.net data: 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.charpstar.net *.klaviyo.com *.doubleclick.net *.google.com *.app.cookieinformation.com *.getzowie.com *.zopim.com wss://widget-mediator.zopim.com *.browser-intake-datadoghq.eu *.googlesyndication.com blob: *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.payever.org *.elastic-cloud.com addrevenue.io *.chatbotize.com mboxedge37.tt.omtrdc.net gtm-p7bx89s-nwviz.uc.r.appspot.com analytics.tiktok.com *.bing.com wss://ws.hotjar.com *.hotjar.com *.hotjar.io maps.googleapis.com bat.bing.net *.sparxpres.dk sparxpres.dk 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://static.dhlecommerce.nl https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://maps.googleapis.com https://maps.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.google.nl https://imgsct.cookiebot.com *.adobedtm.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com *.disqus.com player.vimeo.com https://consentcdn.cookiebot.com https://consent.cookiebot.com https://use.fontawesome.com *.adobedtm.com https://assets.adobedtm.com https://www.googleadservices.com https://www.google-analytics.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://use.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://stats.g.doubleclick.net *.googlesyndication.com https://www.sandbox.paypal.com https://www.paypal.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://www.postcode-checkout.nl https://consent.cookiebot.com https://googleads.g.doubleclick.net https://consentcdn.cookiebot.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com *.cenpos.net *.cenpos.com https://www.magezon.com *.hubspot.com *.hsforms.com *.linkedin.com *.adsymptotic.com *.otcindustrial.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ ws.zoominfo.com secure.venture-365-inspired.com js.hubspot.com cdn.callrail.com js.usemessages.com *.cenpos.com *.cenpos.net *.google.com *.cardinalcommerce.com *.termly.io *.fullstory.com *.licdn.com *.doubleclick.net *.listenlayer.com *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com ws.zoominfo.com idx.liadm.com px.ads.linkedin.com forms.hscollectedforms.net static.listenlayer.com pagead2.googlesyndication.com googleads.g.doubleclick.net js.hs-banner.com *.fullstory.com *.termly.io *.linkedin.oribi.io *.analytics.google.com *.hubspot.com *.hubapi.com *.google-analytics.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.centerpointarchery.com *.cloudflare.com *.cloudmaestro.com *.facebook.net *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.sezzle.com *.youtube.com acsbapp.com cdn.cookielaw.org cdn.jsdelivr.net cdn.sitesearch360.com cloudflare.com code.jquery.com fontawesome.com forms.hsforms.com googleapis.com jquery.com js.hsforms.net jsdelivr.net jstest.authorize.net kit.fontawesome.com mczbf.com unpkg.com www.googlecommerce.com www.gstatic.com www.mczbf.com js.sitesearch360.com js.hs-scripts.com js.hsleadflows.net js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net googleads.g.doubleclick.net js.hsadspixel.net static.hotjar.com c1.rfihub.net script.hotjar.com *.clarity.ms bat.bing.com *.ravincrossbows.com js.usemessages.com js.authorize.net plugins.experticity.com *.googlesyndication.com *.vimeo.com stockist.co ravincrossbows.com www.ravincrossbows.com *.elfsight.com widget.tagembed.com *.helloextend.com *.sharethis.com js.smct.io smct.co cdn.ckeditor.com *.envolvetech.com *.googlecommerce.com *.tiktok.com *.iubenda.com *.stamped.io *.tailwindcss.com *.mountain.com vimeo.com *.klaviyo.com *.incontact.com home-c9.incontact.com *.redditstatic.com js.smct.co delivery.gettopple.com static.klaviyo.com static-tracking.klaviyo.com facebook.com *.cartsave.io *.gettopple.com d2hrivdxn8ekm8.cloudfront.net cdn.userway.org js-agent.newrelic.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com the.sciencebehindecommerce.com lantern.roeyecdn.com fls.doubleclick.net *.credova.com *.shop.pe; style-src 'self' 'unsafe-inline' *.centerpointarchery.com *.googleapis.com *.sezzle.com acsbapp.com cdn.cookielaw.org cdn.jsdelivr.net forms.hsforms.com js.hsforms.net jstest.authorize.net mczbf.com unpkg.com www.mczbf.com cdn.sitesearch360.com *.typekit.net js.sitesearch360.com js.hs-scripts.com js.hsleadflows.net js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net googleads.g.doubleclick.net js.hsadspixel.net static.hotjar.com c1.rfihub.net script.hotjar.com *.clarity.ms bat.bing.com *.ravincrossbows.com ravincrossbows.com www.ravincrossbows.com *.bootstrapcdn.com *.stamped.io *.smct.io *.tailwindcss.com vimeo.com *.klaviyo.com cdn.ckeditor.com fonts.cdnfonts.com cdnjs.cloudflare.com cdn.userway.org kit.fontawesome.com *.fontawesome.com ka-p.fontawesome.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com the.sciencebehindecommerce.com lantern.roeyecdn.com fls.doubleclick.net; report-uri /.webscale/csp-report 2 font-src x.klarnacdn.net static.lipscore.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com *.cloudflare.com *.klarnacdn.net *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com *.perfectview.nl *.visualwebsiteoptimizer.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ osm.klarnaservices.com *.prismic.io sst.kitchenyeah.de ct.pinterest.com googletagmanager.com td.doubleclick.net *.multisafepay.com https://pay.google.com *.ad4m.at *.awin1.com deliverimages.com *.facebook.com *.formcrafts.com *.fotocadeau.nl *.google.com *.googletagmanager.com *.klarna.com *.mediacliphub.com *.noboringsuitcases.com *.opendns.com *.pinterest.com *.sleak.chat *.sovendus-connect.com *.visualwebsiteoptimizer.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com bat.bing.com *.cdn.prismic.io www.facebook.com www.google.nl *.appspot.com images.prismic.io storage.googleapis.com raw.githubusercontent.com *.taggrs.io *.prism.app-us1.com *.prismic.io static.lipscore.com blob: img.youtube.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.awin1.com *.bing.com *.bing.net bucket-ip-website.s3.eu-central-1.amazonaws.com *.clarity.ms deliverimages.com *.doubleclick.net *.facebook.com *.facebook.net *.fotocadeau.nl *.googleadservices.com *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.cv www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gm www.google.gr www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.sr www.google.tn *.google.com google.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.hscollectedforms.net *.hubspot.com *.klarnacdn.net *.klarnaevt.com *.linkedin.com *.lipscore.com *.mediacliphub.com noboringsuitcases.com *.noboringsuitcases.com *.perfectview.nl *.pinterest.com prismic-io.s3.amazonaws.com *.roeye.com *.sleak.chat *.tiktok.com *.trustedshops.com *.visualwebsiteoptimizer.com *.webflow.com *.wepowerconnections.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.klarna.com js.klarnaservices.com bat.bing.com ct.pinterest.com d5yoctgpv4cpx.cloudfront.net connect.facebook.net magento.fcdev metrics.fotoopaluminium.nl metrics.self s.pinimg.com *.appspot.com stapecdn.com static.cdn.prismic.io static.hotjar.com static.mediacliphub.com widgets.trustedshops.com www.clarity.ms *.taggrs.io *.prism.app-us1.com *.prismic.io https://widget-acc.paazl.com https://api-acc.paazl.com/ static.lipscore.com *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.awin1.com *.bing.com *.clarity.ms *.doubleclick.net *.dwin1.com *.facebook.net *.formcrafts.com *.googleapis.com translate.google.com.hk *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hscollectedforms.net *.hs-scripts.com *.hubspot.com *.jsdelivr.net *.klarna.com *.leadinfo.net *.licdn.com *.lipscore.com *.mediacliphub.com *.pinimg.com *.pinterest.com prismic.io *.roeyecdn.com *.sleak.chat *.sovendus.com *.tiktok.com *.trustedshops.com *.visualwebsiteoptimizer.com *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com x.klarnacdn.net integrations.etrusted.com https://widget-acc.paazl.com https://api-acc.paazl.com/ static.lipscore.com maxcdn.bootstrapcdn.com *.multisafepay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.cloudflare.com *.googletagmanager.com *.klarnacdn.net *.lipscore.com *.sleak.chat *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src deliverimages.com *.fotocadeau.nl *.googleapis.com *.mediacliphub.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.adobe.com *.fotocadeau.nl *.gstatic.com noboringsuitcases.com *.noboringsuitcases.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net js.klarnaservices.com js.klarna.com na.klarnaevt.com *.clarity.ms *.appspot.com ct.pinterest.com dc.services.visualstudio.com js.monitor.azure.com region1.analytics.google.com *.sentry.io *.prism.app-us1.com *.prismic.io https://widget-acc.paazl.com https://api-acc.paazl.com/ wapi.lipscore.com users.lipscore.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.algolia.io *.algolia.net *.algolianet.com *.azure.com *.bing.com *.bing.net deliverimages.com *.doubleclick.net *.facebook.com *.facebook.net *.fotoophout.nl *.googleadservices.com *.googleapis.com google.com *.google.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.hscollectedforms.net *.hubapi.com *.klarna.com *.klarnaevt.com *.leadinfo.com *.leadinfo.net *.linkedin.com *.lipscore.com *.make.com *.mediacliphub.com *.noboringsuitcases.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.pinterest.com polyfilljs.org *.sleak.chat *.sovendus.com *.tiktok.com *.tiktokw.us *.visualwebsiteoptimizer.com *.wepowerconnections.com *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.mediacliphub.com *.appspot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.leadinfo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://0857a1ae-eb26-4f26-b573-76e7e6a78da5.sansec.watch/; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'unsafe-eval' *.osha.europa.eu www.gstatic.com www.google.com cdn.jsdelivr.net europa.eu platform.twitter.com www.youtube.com cdnjs.cloudflare.com webtools.europa.eu translate.googleapis.com translate-pa.googleapis.com static.addtoany.com; style-src 'self' 'unsafe-inline' www.gstatic.com europa.eu webtools.europa.eu fonts.googleapis.com; img-src 'self' *.osha.europa.eu abs.twimg.com pbs.twimg.com europa.eu syndication.twitter.com webtools.europa.eu *.google.com *.gstatic.com i.ytimg.com; connect-src 'self' translate.googleapis.com translate-pa.googleapis.com webtools.europa.eu europa.eu piwik.osha.europa.eu www.google.com; frame-src 'self' platform.twitter.com www.google.com syndication.twitter.com www.youtube.com www.youtube-nocookie.com euosha.gestmax.eu; worker-src 'none'; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com themes.googleusercontent.com use.typekit.net; report-uri https://stat.alberora.eu/stat/CSP.php; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com instantcredit.net test.instantcredit.net *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.paycomet.com api.paycomet.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: *.assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://images.unsplash.com *.doubleclick.net analytics.google.com *.cloudfront.net static-eu.payments-amazon.com assets.braintreegateway.com *.instantcredit.net instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.spotlersearch.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com *.doubleclick.net maps.googleapis.com *.ftcdn.net *.behance.net *.paypal.com *.gstatic.com validator.swagger.io *.cloudfront.net *.ssl-images-amazon.com *.media-amazon.com static-eu.payments-amazon.com assets.braintreegateway.com *.instantcredit.net www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com instantcredit.net test.instantcredit.net *.sooqr.com *.spotlersearch.com *.klarnacdn.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.spotlersearch.com maps.googleapis.com instantcredit.net *.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.sharethis.com *.rawgit.com *.jquery.com *.facebook.net *.usercentrics.eu *.cookiebot.eu *.cookiebot.com *.g.doubleclick.net *.fontawesome.com *.googleapis.com *.linkedin.com *.hotjar.com wasm-eval *.google-analytics.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com; script-src-elem 'self' 'unsafe-inline' *.googleapis.com *.google.com *.sharethis.com *.rawgit.com *.cloudflare.com *.jquery.com *.facebook.net *.cookiebot.com *.g.doubleclick.net *.fontawesome.com *.bootstrapcdn.com *.wisoyekivo.com *.linkedin.com *.vimeo.com *.skedify.io *.plugin.skedify.io *.hotjar.com *.google-analytics.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com *.pagespeed-mod.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' *.googleapis.com *.fontawesome.com *.sharethis.com *.gstatic.com *.pvgroup.be; style-src-elem 'self' 'unsafe-inline' *.jquery.com *.googleapis.com *.bootstrapcdn.com *.skedify.io pv.skedify.show *.fontawesome.com *.sharethis.com *.gstatic.com *.pvgroup.be; style-src-attr 'unsafe-inline'; img-src 'self' data: *.google.com *.skedify.io *.vimeocdn.com *.ytimg.com *.sharethis.com *.googleapis.com *.gstatic.com *.sharethis.com *.google-analytics.com *.hotjar.com *.gstatic.com *.sharethis.com *.google.com *.sharethis.com *.facebook.com *.google-analytics.com *.google.at *.google.be *.google.ch *.google.co.uk *.google.co.za *.google.com *.google.com.ng *.google.de *.google.es *.google.fi *.google.fr *.google.ie *.google.it *.google.lu *.google.nl *.google.pt *.google.se *.googletagmanager.com *.gstatic.com *.ondernemersbelang.nl *.pv.be *.pvgroep.coop *.pvgroup.be *.reprintsdesk.com *.researchsolutions.com *.verfvanniveau.nl *.google.co.in; font-src 'self' data: *.alicdn.com *.gstatic.com github.com *.fontawesome.com *.bootstrapcdn.com *.hotjar.com; connect-src 'self' *.doubleclick.net *.google.com *.eu1.kaskocloud.com *.skedify.io *.crwdcntrl.net *.cookiebot.com *.withgoogle.com *.stbuttons.click data: *.hotjar.com *.fontawesome.com *.sharethis.com *.google.com *.googleapis.com *.ingest.sentry.io *.googlesyndication.com properties *.google-analytics.com *.g.doubleclick.net *.hotjar.io *.facebook.com; media-src 'self'; child-src *.fls.doubleclick.net *.google.com *.esignlive.eu *.cookiebot.com *.sharethis.com *.facebook.com *.linkedin.com *.youtube-nocookie.com *.youtube.com; frame-src 'self' *.fls.doubleclick.net *.google.com *.esignlive.eu blob: *.cookiebot.com *.ebconnect.be *.zscaler.net *.zscalertwo.net *.vimeo.com *.plugin.skedify.io *.sharethis.com properties *.facebook.com *.sharethis.com *.facebook.com *.google.com *.linkedin.com *.sofiskonline.be *.youtube-nocookie.com *.youtube.com; frame-ancestors 'self'; form-action 'self' *.sips-services.com *.salesforce.com *.facebook.com; manifest-src 'self'; object-src 'none' 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com *.shopify.com *.philipkingsley.co.uk data: 'self' 'unsafe-inline'; form-action *.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com https://seo.mageplaza.com *.nosto.com *.nos.to *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com *.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ *.doubleclick.net www.facebook.com *.googlesyndication.com www.apptrian.com facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com bytedance: sslocal: *.dotdigital-pages.com *.dotdigital.com business.facebook.com *.nosto.com *.nos.to *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com *.yotpo.com email.philipkingsley.co.uk ams.creativecdn.com consentcdn.cookiebot.com *.googletagmanager.com *.freshchat.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com business.facebook.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.magezon.com *.nosto.com *.nos.to www.xtento.com cdn.xtento.com *.yotpo.com imgsct.cookiebot.com *.cloudfront.net *.google.com.ua *.google.co.uk services.postcodeanywhere.co.uk *.creativecdn.com *.philipkingsley.co.uk d21m4dsqdd3b9h.cloudfront.net cfvod.kaltura.com *.philipkingsley.com ads.stickyadstv.com sync.outbrain.com ih.adscale.de sync.taboola.com dsum-sec.casalemedia.com sync.teads.tv eb2.3lift.com *.google.rs data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.google.com/ *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net www.apptrian.com facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com widget.freshworks.com m2epro.freshdesk.com business.facebook.com js.klevu.com *.ksearchnet.com *.avada.io *.nosto.com *.nos.to *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com *.yotpo.com *.salesfire.co.uk email.philipkingsley.co.uk *.cookiebot.com *.ordergroove.com *.feefo.com analytics.webgains.io tags.creativecdn.com *.hotjar.com *.freshworks.com *.clarity.ms *.freshchat.com klear.com *.mention-me.com *.pcapredict.com services.postcodeanywhere.co.uk *.zoovu.com *.zuko.io *.googleadservices.com cdn.salesfire.co.uk *.philipkingsley.co.uk gstatic.com connect.nosto.com cdn-sitegainer.com cdnapisec.kaltura.com pro.ip-api.com r.lrkt-in.com *.omniconvert.com https://cdn.lrkt-in.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net *.nosto.com *.nos.to *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.feefo.com *.freshworks.com services.postcodeanywhere.co.uk https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com connect.facebook.net graph.facebook.com tiktok.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com widget.freshworks.com m2epro.freshdesk.com business.facebook.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io *.nosto.com *.nos.to *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.ordergroove.com *.smartmetrics.co.uk ams.creativecdn.com *.freshworks.com *.feefo.com *.cookiebot.com *.clarity.ms klear.com services.postcodeanywhere.co.uk *.salesfire.co.uk *.webgains.io *.mention-me.com *.zuko.io connect.nosto.com o970468.ingest.us.sentry.io *.freshdesk.com r.lrkt-in.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.addthis.com *.facebook.com *.twitter.com *.authorize.net www.youtube.com accounts.google.com *.iubenda.com cdn-quick-ar.threedy.ai quick-ar.threedy.ai td.doubleclick.net www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.addthisedge.com *.twitter.com *.hsforms.net *.hsforms.com 'self' data: cdn.ywxi.net seal.networksolutions.com ssl.gstatic.com syndication.twitter.com *.stats.paypal.com *.cloudmaestro.com *.twimg.com maps.gstatic.com maps.googleapis.com seal-santabarbara.bbb.org *.google.com csi.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com *.authorize.net *.hsforms.net *.hsforms.com *.gstatic.com diffuser-cdn.app-us1.com/ prism.app-us1.com trackcmp.net seal-santabarbara.bbb.org platform.twitter.com apis.google.com seal.networksolutions.com www.google.com www.gstatic.com *.iubenda.com *.paypal.com *.twimg.com maps.googleapis.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam-cell.nr-data.net cdn-quick-ar.threedy.ai acsbapp.com cdn.iubenda.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.twitter.com *.twimg.com www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.googleadservices.com www.google-analytics.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.iubenda.com *.facebook.com maps.googleapis.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam-cell.nr-data.net quick-ar.threedy.ai *.acsbapp.com *.doubleclick.net stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ab6dd833-5ccc-470b-a6cb-3bca3080bb2f.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: *.tiktok.com *.ttcdn-row.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com cdn.dnky.co amc.demdex.net www.google.com youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' data: maps.gstatic.com maps.googleapis.com accounts.google.com *.tiktok.com *.ttcdn-row.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.google.com *.gstatic.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com https://maps.googleapis.com *.tiktok.com *.ttcdn-row.com *.bytedance.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com cdn.dnky.co *.googletagmanager.com *.cookielaw.org *.tiktok.com *.ttcdn-row.com 'self' 'unsafe-inline'; object-src *.tiktok.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org analytics.tiktok.com business-api.tiktok.com *.ttcdn-row.com *.bytedance.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com maxcdn.bootstrapcdn.com *.fontawesome.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.faslet.net https://cdn.flbx.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ts.tradetracker.net www.magmodules.eu https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.faslet.net https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tm.tradetracker.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com embed.pakketdienstqls.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.faslet.net https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; connect-src 'self' www.googleadservices.com ct.pinterest.com bat.bing.net px.ads.linkedin.com region1.analytics.google.com settings.luckyorange.net bat.bing.com analytics.google.com www.google.co.uk www.facebook.com stats.g.doubleclick.net www.googletagmanager.com www.google.com api.vimeo.com fresnel.vimeocdn.com; font-src 'self' www.westdean.ac.uk assets.westdean.ac.uk/ data:; frame-ancestors 'self'; frame-src 'self' ct.pinterest.com discoveruni.gov.uk *.luckyorange.com widget.discoveruni.gov.uk my.matterport.com www.googletagmanager.com player.vimeo.com vimeo.com www.youtube.com; img-src 'self' * data:; media-src d10lpsik1i8c69.cloudfront.net player.vimeo.com download-video-ak.vimeocdn.com/v3-1/playback/ vod-adaptive-ak.vimeocdn.com skyfire.vimeocdn.com; script-src 'self' www.westdean.ac.uk assets.westdean.ac.uk/ static.cloudflareinsights.com *.doubleclick.net chimpstatic.com s.pinimg.com *.bing.com *.facebook.net d10lpsik1i8c69.cloudfront.net ct.pinterest.com snap.licdn.com cdn.tickettailor.com www.googletagmanager.com player.vimeo.com *.vimeocdn.com www.youtube.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' www.westdean.ac.uk assets.westdean.ac.uk/ d10lpsik1i8c69.cloudfront.net 'unsafe-inline'; report-uri https://o74830.ingest.us.sentry.io/api/215515/security/?sentry_key=610a8846728c479cb10b52482e41c8cc; report-to csp-endpoint 2 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.facebook.com/tr/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bebemundo.com.do *.jugueton.com.do *.zdassets.com *.hotjar.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co amc.demdex.net www.google.com www.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.facebook.com/tr/ *.youtube.com *.yotpo.com *.doubleclick.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de maps.gstatic.com maps.googleapis.com accounts.google.com www.google.com www.facebook.com https://googleads.g.doubleclick.net www.google.com.ar www.google.com.do https://www.googletagmanager.com https://www.m.casacuesta.com *.youtube.com https://connect.facebook.net https://notifications-icommkt.website *.yotpo.com *.notifications-icommkt.com *.simpleanalyticscdn.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net commerce.adobedtm.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.avada.io *.google.com *.gstatic.com https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.google-analytics.com https://stats.g.doubleclick.net http://www.google.com/recaptcha/api.js https://d12zyq17vm1xwx.cloudfront.net/v2/wpn.min.js https://static.cloudflareinsights.com/ https://www.gstatic.com/recaptcha/releases/tFhBvPrftr7Y91fo1S1ASkA6/recaptcha__es.js https://externalassets.icommarketing.com/icomMkt_tracking_jquery.min.js *.youtube.com https://static.zdassets.com ekr.zdassets.com *.yotpo.com *.simpleanalyticscdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://static.zdassets.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net *.adobe.io performance.typekit.net commerce.adobe.net qa-api.magedevteam.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.comapi.com bam.nr-data.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.google-analytics.com https://www.hotjar.com https://script.hotjar.com https://analytics.google.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ http://ccnecommerce.com/ https://notifications-icommkt.com/ https://track-icommkt.com/ wss://widget-mediator.zopim.com/ *.youtube.com https://static.zdassets.com ekr.zdassets.com jugueton.zendesk.com bebemundord.zendesk.com casacuesta.zendesk.com *.googletagmanager.com *.yotpo.com *.googleapis.com *.zdassets.com *.hotjar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https: mcdn.pybydl.com; font-src 'self' https: data:; img-src 'self' https: data: mcdn.pybydl.com; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' mcdn.pybydl.com; style-src 'self' https: 'unsafe-inline' mcdn.pybydl.com; frame-src 'self' https: http: data:; connect-src 'self' https: wss: www.luck-nine.com; report-uri /csp_reports 2 default-src 'self'; img-src * 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com * data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors https://catalogues.retif.eu 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hipay-tpp.com *.hipay.com *.googleapis.com js.mollie.com s3-eu-west-1.amazonaws.com *.back.ecard.pledg.co *.front.ecard.pledg.co front.ecard.pledg.co hooks.stripe.com *.salecycle.com *.criteo.com *.hotjar.com *.facebook.net track.effiliation.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.hipay.com *.googleapis.com https://images.unsplash.com https://www.mollie.com *.retif.eu maps.googleapis.com *.google-analytics.com *.algolia.net *.algolianet.com * *.ggpht.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com https://maps.googleapis.com js.mollie.com https://cdnjs.cloudflare.com s3-eu-west-1.amazonaws.com *.back.ecard.pledg.co *.front.ecard.pledg.co *.iadvize.com *.cookielaw.org *.bing.com *.pinimg.com *.hotjar.com *.salecycle.com *.facebook.net *.licdn.com *.criteo.com *.clarity.ms analytics.tiktok.com *.target2sell.com appstatic.quanta.io track.effiliation.com https://smex-ctp.trendmicro.com:443/wis/clicktime/v1/query 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hipay.com *.googleapis.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://smex-ctp.trendmicro.com:443/wis/clicktime/v1/query * 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com s3-eu-west-1.amazonaws.com *.back.ecard.pledg.co *.front.ecard.pledg.co *.facebook.net *.criteo.com track.effiliation.com https://catalogues.retif.eu * *.gstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net 'self' https://*.uberall.com https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com cdn.doofinder.com https://images.unsplash.com https://cdn.scarabresearch.com https://static.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com * *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cdn.doofinder.com *.plugins.emarsys.net https://cdn.scarabresearch.com https://maps.googleapis.com https://snippet.plugins.emarsys.net https://static.scarabresearch.com https://locator.uberall.com https://*.uberall.com https://instantcredit.net/ https://code.jquery.com/ * *.fontawesome.com *.googleapis.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.doofinder.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.doofinder.com wss://*.doofinder.com https://recommender.scarabresearch.com *.eservice.emarsys.net https://play-merchant-config.pepperfinance.es/ https://play-api.peppermoneytest.es/ https://maps.googleapis.com https://player.vimeo.com https://cdn.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com https://instantcredit.net/ https://test.instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://frontal-eu.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://api.itau.com.br/ https://api.itau.com.br:443/ https://sts.itau.com.br/ https://sts.itau.com.br:443/ https://secure.api.itau/ https://secure.api.itau:443/ https://apisandbox.redeecommerce.rede.com.br/ https://apiquerysandbox.redeecommerce.rede.com.br/ https://api.redeecommerce.rede.com.br/ https://apiquery.redeecommerce.rede.com.br/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.tiktok.com https://www.facebook.com/tr/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.facebook.com/ *.youtube-nocookie.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://*.hotjar.com/ js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net https://*.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://*.google.be https://*.facebook.com/ https://www.facebook.com/tr/ *.google.com *.google-analytics.com *.analytics.google.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://devdocs.magento.com https://magento.com https://*.google.be https://*.g.doubleclick.net/ http://*.googletagmanager.com/ https://www.facebook.com/ https://connect.facebook.net/ https://tawk.to *.google.com *.analytics.google.com https://maps.googleapis.com https://player.vimeo.com *.avada.io maps.googleapis.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://*.tawk.to *.cookiehub.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://devdocs.magento.com https://tawk.to https://*.g.doubleclick.net/ https://*.hotjar.com/ *.google.com *.analytics.google.com *.g.doubleclick.net https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.kameleoon.io *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.babygalerie24.de *.facebook.com *.googleapis.com *.google.de *.ovh.net www.google.at www.google.ch www.google.com.bd *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.google.com *.hub.baby *.googlesyndication.com www.google.si *.googleusercontent.com www.google.co.in www.google.kz www.google.ro *.ccm19.de *.kameleoon.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com bspic.hub.baby data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.etermin.net *.ccm19.de *.facebook.net *.google.com *.googleapis.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.googletagmanager.com *.clarity.ms *.kameleoon.io *.avada.io secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.ccm19.de *.gstatic.com *.etermin.net *.kameleoon.io *.fontawesome.com https://fonts.bunny.net d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.hub.baby *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.ovh.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.ccm19.de *.google-analytics.com *.googleapis.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.doubleclick.net *.googlesyndication.com *.facebook.com *.clarity.ms *.kameleoon.io https://get.geojs.io *.avada.io payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.ccm19.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://bec24c5a-6980-491a-b199-6ac1940dc2e1.sansec.watch/; report-to report-endpoint; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.checkout-api.avarda.com *.checkout-cdn.avarda.com checkout-cdn.avarda.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.checkout-cdn.avarda.com checkout-cdn.avarda.com card-payment-frame.production.avarda.com *.stage.avarda.com pay.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * s7.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.core.windows.net *.checkout-api.avarda.com checkout-api.avarda.com *.checkout-cdn.avarda.com checkout-cdn.avarda.com openbanking-logos.production.avarda.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.klevu.com *.ksearchnet.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com halonen.fi www.halonen.fi google.fi www.google.fi data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.core.windows.net *.checkout-cdn.avarda.com checkout-cdn.avarda.com *.stage.avarda.com pay.google.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com js.klevu.com *.ksearchnet.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com s7.addthis.com m.addthis.com v1.addthisedge.com z.moatads.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.halonen.fi api.carlson.fi *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.checkout-api.avarda.com checkout-api.avarda.com google.com www.google.com pay.google.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.klevu.com *.ksearchnet.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com s7.addthis.com m.addthis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.cloudflare.com *.trustedshops.com *.googleapis.com *.klaviyo.com cdn1.stamped.io stamped.io *.fontawesome.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.facebook.com *.nosto.com *.nos.to *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.doubleclick.net *.facebook.com *.klarna.com *.nosto.com *.nos.to *.freshchat.com *.twitter.com *.pinterest.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.yotpo.com *.ingrid.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.klarna.com *.klarnaevt.com *.nosto.com *.nos.to *.rubiconproject.com/ *.sharethrough.com/ *.teads.tv/ *.tremorhub.com/ *.3lift.com/ *.yieldlab.net/ *.ads.yieldmo.com/ *.emxdgt.com/ *.adform.net/ *.demdex.net/ *.criteo.net *.adnxs.com/ *.cloudfront.net/ *.stamped.io *.freshchat.com/ *.cloudflare.com *.ytimg.com *.bing.com/ *.clarity.ms/ *.google.al/ *.google.am/ *.google.at/ *.google.az/ *.google.ba/ *.google.be/ *.google.bg/ *.google.by/ *.google.ch/ *.google.cz/ *.google.de/ *.google.dk/ *.google.ee/ *.google.es/ *.google.fi/ *.google.fr/ *.google.ge/ *.google.gr/ *.google.hr/ *.google.hu/ *.google.ie/ *.google.is/ *.google.it/ *.google.kz/ *.google.li/ *.google.lt/ *.google.lu/ *.google.lv/ *.google.md/ *.google.me/ *.google.mk/ *.google.mt/ *.google.nl/ *.google.no/ *.google.pl/ *.google.pt/ *.google.ro/ *.google.rs/ *.google.ru/ *.google.se/ *.google.si/ *.google.sk/ *.google.sm/ *.google.tr/ *.google.ua/ *.google.uk/ *.google.com.ua/ *.google.com.tr/ *.google.com.gr/ *.google.com.pt/ *.google.com.pl/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.klarna.com/ *.nosto.com *.nos.to *.cloudfront.net/ *.cookiebot.com/ *.kuvio.io/ *.reamaze.com/ *.shopalike.fi/ *.chatbotize.com/ qanuk-stage.vercel.app *.tradedoubler.com *.criteo.com *.cookiefirst.com *.omappapi.com *.googleoptimize.com *.klaviyo.com reviewsonmywebsite.com 'self' data: *.fontawesome.com *.videoly.co/ *.freshchat.com cdnjs.cloudflare.com/ *.googleapis.com/ *.noibu.com/ *.pinimg.com/ *.bing.com/ *.tiktok.com/ *.pinterest.com/ *.intercom.io/ *.intercomcdn.com/ *.clarity.ms/ *.klarnaservices.com/ *.livechatinc.com/ *.hotjar.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com cdn1.stamped.io stamped.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.ingrid.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.nosto.com *.nos.to *.cookiefirst.com *.klarnacdn.net *.omappapi.com reviewsonmywebsite.com *.typekit.net *.freshchat.com/ *.cloudflare.com/ *.klaviyo.com/ https://static.klaviyo.com cdn1.stamped.io stamped.io *.fontawesome.com assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net *.algolia.com/ *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com/ *.klarnaevt.com *.nosto.com *.nos.to *.criteo.com *.hobbybox.fi/ *.g.doubleclick.net/ *.reamaze.com/ *.cookiebot.com/ *.kelkoogroup.net/ *.chatbotize.com *.klarnaservices.com *.doubleclick.net *.qanuk.app *.cookiefirst.com *.omappapi.com *.googlesyndication.com reviewsonmywebsite.com *.cloudflare.com *.pinterest.com *.tiktok.com/ *.clarity.ms/ *.noibu.com/ wss://input.noibu.com/ wss://nexus-websocket-a.intercom.io/ *.intercom.io/ *.bing.com/ *.algolia.io/ *.klarna.com/ wss://ws.reamaze.com/ *.reamaze.io/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src self data: *.nosto.com/ *.klaviyo.com/ *.stamped.io/ https://stamped.io/ *.gstatic.com/ *.cloudfront.net/ *.cloudflare.com/ *.klarnaservices.com/ *.klarna.com/ *.klarnaevt.com/ *.klarnacdn.net/ *.yotpo.com/ *.reamaze.io/ *.reamaze.com/ wss://ws.reamaze.com/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com 'self' data: data: surveys-static.survicate.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com www.google.com.co js.intercomcdn.com intercomassets.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://www.google.com *.gstatic.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com https://maps.googleapis.com *.snrbox.com static.hotjar.com *.clarity.ms surveys-static.survicate.com script.hotjar.com widget.intercom.io js.intercomcdn.com api-iam.intercom.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com cdn.dnky.co *.googletagmanager.com *.cookielaw.org *.snrcdn.net https://surveys-static.survicate.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.synerise.com t.elasticsuite.io *.google-analytics.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org *.snrbox.com t.clarity.ms stats.g.doubleclick.net api-iam.intercom.io wss://nexus-websocket-a.intercom.io wss://ws.hotjar.com https://content.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src cdn.rawgit.com cdn.jsdelivr.net fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.sagepay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.sagepay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com hmg-attachments.s3-eu-west-1.amazonaws.com maps.gstatic.com maps.googleapis.com ssl.google-analytics.com www.facebook.com cookie-cdn.cookiepro.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com api-js.mixpanel.com bam.nr-data.net maps.googleapis.com ssl.google-analytics.com cdn.pubble.io cookie-cdn.cookiepro.com connect.facebook.net *.elavon.com *.sagepay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.pubble.io cdn.rawgit.com cdn.jsdelivr.net fonts.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com maps.googleapis.com *.google-analytics.com stats.g.doubleclick.net www.pubble.io cookie-cdn.cookiepro.com cookiepro.blob.core.windows.net *.elavon.com *.sagepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://www.google.com https://widget.trustpilot.com https://bid.g.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com https://www.google.com https://www.google.co.in magefan.com cm.magefan.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.disqus.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com/ https://amcglobal.sc.omtrdc.net *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.certcapture.com pay.google.com *.google-analytics.com googletagmanager.com *.googletagmanager.com apis.google.com https://maps.googleapis.com *.googleapis.com *.googleadservices.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.gstatic.com/recaptcha https://www.google.com/recaptcha *.google.com/ https://maps.googleapis.com/maps/api/js https://widget.trustpilot.com http://widget.trustpilot.com https://invitejs.trustpilot.com chimpstatic.com *.paypalobjects.com c.paypal.com *.paypal.com sandbox.paypal.com *.sandbox.paypal.com downloads.mailchimp.com *.list-manage.com *.disqus.com maps.googleapis.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://maps.googleapis.com/ https://js-agent.newrelic.com https://bam.nr-data.net assets.shipperhq.com *.trustpilot.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com downloads.mailchimp.com *.fontawesome.com assets.braintreegateway.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://stats.g.doubleclick.net https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://bam.nr-data.net ovs.shipperhq.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://marysvillemarine.com/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.facebook.com *.livechatinc.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.doubleclick.net *.kaptcha.com *.livechatinc.com *.rfihub.com *.adnxs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.cloudflare.com *.facebook.com *.google.com *.google.com.mx *.googleusercontent.com *.icons8.com *.marketo.net *.amazonaws.com *.magecomp.com *.bizibly.com *.showmethepartsdb2.com *.showmethepartsdb.com 3aa074a4dd.nxcli.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.fontawesome.com *.facebook.net *.doubleclick.net *.bizible.com *.bing.com *.marketo.net *.livechatinc.com *.weglot.com *.rezync.com *.licdn.com *.stackadapt.com *.hotjar.com *.rfihub.net *.boomtrain.com *.scaleflex.it *.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.stackadapt.com *.typekit.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.cloudflare.com *.doubleclick.net *.google-analytics.com *.facebook.com *.gstatic.com *.boomtrain.com *.stackadapt.com *.livechatinc.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://www.google.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com; img-src 'self' data: https://www.google.com https://www.gstatic.com https://secure.gravatar.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net; frame-src 'self' https://www.google.com https://maps.google.com https://www.youtube.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.tisda.nl/csp-report.php; 2 font-src fonts.gstatic.com use.typekit.net 'self' data: *.gstatic.com *.doubleclick.net *.facebook.com https://fonts.gstatic.com *.klevu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.ksearchnet.com https://www.gstatic.com https://media.convergetp.co.uk/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' *.klevu.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com account.fetchify.com js-eu1.hsforms.net 'self' data: *.klevu.com 'self' *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com https://*.google.com *.doubleclick.net *.facebook.com account.fetchify.com *.freshchat.com *.crwdcntrl.net/ js-eu1.hsforms.net *.klevu.com *.punchout2go.com *.tradecentric.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com magento-cloudflare.jetrails.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net 'self' https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://maps.googleapis.com https://maps.gstatic.com *.google.co.uk *.klevu.com *.ytimg.com *.ksearchnet.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://media.convergetp.co.uk/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://maps.googleapis.com *.gatorleads.co.uk *.freshchat.com *.newrelic.com *.hotjar.com *.adnxs.com js-eu1.hsforms.net *.klevu.com *.punchout2go.com *.tradecentric.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.klevu.com *.ksearchnet.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://media.convergetp.co.uk/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cc-cdn.com https://fonts.googleapis.com *.typekit.net *.freshchat.com *.klevu.com *.punchout2go.com *.tradecentric.com *.ksearchnet.com https://hcaptcha.com https://*.hcaptcha.com https://media.convergetp.co.uk/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://maps.googleapis.com *.nr-data.net *.doubleclick.net *.hotjar.io js-eu1.hsforms.net *.klevu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.ksearchnet.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://media.convergetp.co.uk/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.bootstrapcdn.com maxcdn.bootstrapcdn.com 'self' data: d1tz4u8bvomi43.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.usercentrics.eu www.xtento.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com maps.googleapis.com *.1rx.io *.3lift.com *.360yield.com *.adform.net *.adnxs.com *.adtriba.com *.amazonaws.com *.bidswitch.net *.bing.com *.casalemedia.com *.criteo.com *.demdex.net *.doubleclick.net *.emxdgt.com *.facebook.com id5-sync.com *.ivitrack.com *.juneapp.com *.media.net *.mediavine.com *.omnitagjs.com *.outbrain.com *.postrelease.com *.pubmatic.com *.roeye.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.snapchat.com squarelovin.com *.squarelovin.com *.taboola.com *.teads.tv *.tremorhub.com *.unrulymedia.com *.usercentrics.eu *.yieldlab.net *.yieldmo.com flagpedia.net cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.trustedshops.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com d1tz4u8bvomi43.cloudfront.net *.google.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.dynamicyield.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com maps.googleapis.com *.adtriba.com dwin1.com *.bing.com clarity.ms *.cloudflareinsights.com *.cloudfront.net *.criteo.com *.doubleclick.net *.facebook.net *.pinimg.com *.pinterest.com *.roeyecdn.com *.sc-static.net *.snapchat.com squarelovin.com *.squarelovin.com *.survicate.com *.usercentrics.eu *.getzowie.com *.eyefitu.com *.gstatic.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.trustedshops.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com squarelovin.com *.squarelovin.com *.cloudfront.net *.bootstrapcdn.com *.googleapis.com *.adtriba.com maxcdn.bootstrapcdn.com *.gstatic.com d.ratepay.com d.payla.io dr.payla.io d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; object-src d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.cloudfront.net d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.dynamicyield.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com *.amazonaws.com *.cloudfront.net *.squarelovin.com *.usercentrics.eu www.gstatic.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com t.elasticsuite.io *.hsforms.net *.hsforms.com d1tz4u8bvomi43.cloudfront.net region1.analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.saferpay.com https://v2.zopim.com/widget/fonts/ 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.broadmail.de test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com * https://js.stripe.com/ https://www.googletagmanager.com/ www.google.com bat.bing.com bat.bing.net *.stape.net *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.mapbox.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com api.mapbox.com https://v2.zopim.com/widget/images/avatar_simple_visitor.png stats.g.doubleclick.net px.ads.linkedin.com https://www.google.com/pagead/ https://www.google.de/pagead/ https://www.google.com/ads/ https://www.google.de/ads/ t23.intelliad.de bat.bing.com bat.bing.net *.facebook.com *.cookiefirst.com *.udo.solutions *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com https://js.stripe.com/v3/ https://www.googletagmanager.com/gtm.js https://www.google.com/recaptcha/api.js www.gstatic.com v2.zopim.com https://static.zdassets.com/ekr/asset_composer.js js-agent.newrelic.com https://snap.licdn.com/li.lms-analytics/insight.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/927165981 bam.eu01.nr-data.net bat.bing.com bat.bing.net *.googletagmanager.com *.facebook.net *.cookiefirst.com *.udo.solutions *.intelliad.de *.usercentrics.eu *.doubleclick.net *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.cookiefirst.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com wss://widget-mediator.zopim.com/ https://ekr.zdassets.com/compose/zopim_chat/ https://bam.eu01.nr-data.net/events/ ka-f.fontawesome.com https://www.google.com/ccm/ bat.bing.com bat.bing.net stats.g.doubleclick.net *.stape.net *.cookiefirst.com *.udo.solutions autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.salesfire.co.uk *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.salesfire.co.uk maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.salesfire.co.uk *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.salesfire.co.uk *.typekit.net fonts.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://bam.nr-data.net/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.salesfire.co.uk *.smartmetrics.co.uk *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com *.klevu.com *.ksearchnet.com *.fontawesome.com fonts.gstatic.com *.yotpo.com use.fontawesome.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.googletagmanager.com/ *.google.com/ https://cdn.lightwidget.com/ yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.googleapis.com *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://www.magezon.com https://*.unifaun.com yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.yotpo.com yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.googleapis.com https://www.google-analytics.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ yotpo.com *.cookiebot.com *.google-analytics.com *.googlesyndication.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://go.mufg-investorservices.com/ https://cdn.cookielaw.org https://cdn.bizible.com/ https://www.googletagmanager.com/ https://j.6sc.co/ https://snap.licdn.com/ https://munchkin.marketo.net/ https://www.google-analytics.com/ https://px.ads.linkedin.com/ https://ipv6.6sc.co/ https://b.6sc.co/ https://www.google.com https://c.6sc.co/ https://www.gstatic.com/ https://googleads.g.doubleclick.net https://static.smartrecruiters.com/ https://www.smartrecruiters.com/ https://www.buzzsprout.com/ https://www.youtube-nocookie.com/ https://geolocation.onetrust.com/ www.youtube.com https://privacyportal-eu.onetrust.com/ https://secure.adnxs.com/ https://www.googleadservices.com/ https://td.doubleclick.net/ https://epsilon.6sense.com/ https://427-brk-404.mktoresp.com/ youtu.be; img-src * 'self' data: blob:; font-src 'self' data:; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://static.dhlecommerce.nl https://fonts.gstatic.com fonts.gstatic.com fonts.googleapis.com https://widgets.trustedshops.com *.waterfilterwinkel.com *.slant.co *.fontawesome.com *.flaticon.com *.filtre-de-hotte.fr *.allspares.fr *.userway.org *.hotjar.com *.varify.io *.hsappstatic.net *.afzuigkapfilterwinkel.nl data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.dpdconnect.nl *.newrelic.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com *.wasserfilterspezialist.de *.opendns.com server-side-tagging-hgb22rqeua-uc.a.run.app *.varify.io *.criteo.net *.bing.com google.co.th *.allspares.com *.cookiebot.com *.criteo.com *.googletagmanager.com *.robinhq.com *.userway.org *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://maps.googleapis.com https://maps.gstatic.com *.trackedlink.net https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.multisafepay.com https://api.mapbox.com moogento.com *.moogento.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.google.co.id www.google.com.qa www.google.com.bh www.google.com.co www.google.by www.google.lk www.google.gl yastatic.net www.google.hr *.hubspot.com www.google.com.np www.google.com.pe www.google.co.il www.google.jo www.google.it www.google.com.et www.google.ch id5-sync.com *.baidu.com www.google.hu www.google.com.pr www.google.li www.google.md *.criteo.com www.google.am www.google.es www.google.is www.google.com.bo www.google.lu www.google.bi *.agkn.com www.google.as www.google.co.ma www.google.dm *.afzuigkapfilterwinkel.nl www.google.mn *.kelkoogroup.net www.google.com.ec www.google.ba robincontentdesktop.blob.core.windows.net *.usercentrics.eu www.google.me www.google.com.kh *.tremorhub.com www.google.co.th *.bing.com www.google.com.vn www.google.ps www.google.com.hk www.google.rw www.google.com.cy www.google.cv www.google.tt www.google.ge www.google.com.lb *.bing.net www.google.ro www.google.no www.google.cd www.google.co.ve www.google.dk www.google.mg www.google.com.bn www.google.ru www.google.ml *.userway.org www.google.sm *.media.net *.teads.tv *.allspares.nl *.allspares.fr www.google.com.ni *.bidswitch.net *.casalemedia.com www.google.com.eg www.google.com.gt *.trackedweb.net www.google.com.br www.google.com.jm *.trustedshops.com *.dunstabzugshaube-filter.de www.google.je www.google.com.mt *.1rx.io www.google.kg www.google.so www.google.mv *.pubmatic.com www.google.co.mz www.google.com.tj *.adnxs.com www.google.com.sl www.google.com.pk www.google.gr www.google.com.tw www.google.tn www.google.com.sg www.google.co.in *.allspares.de www.google.at www.google.ad *.wasserfilterspezialist.de www.google.al www.google.rs www.google.ie *.smartadserver.com www.google.co.ke www.google.cm www.google.mw www.google.com.pa www.google.ae google.com www.google.pl www.google.com.fj www.google.com.kw www.google.pt www.google.be www.google.com.mx www.google.mu *.outbrain.com *.criteo.net www.google.co.cr www.google.ee www.google.com.py *.3lift.com www.google.iq www.google.ca www.google.gy www.google.co.jp www.google.sr www.google.de www.google.lt www.google.com.do *.cashbackxl.nl *.google.com www.google.fi www.google.sk www.google.co.ug www.google.com.ph www.google.co.tz www.google.ga www.google.tg www.google.si www.google.lv *.waterfilterwinkel.com www.google.com.sa www.google.bj www.google.dj www.google.dz www.google.ci www.google.com.ua www.google.com.ar www.google.com.gh www.google.co.uz www.google.com.my www.google.fr www.google.com.ng www.google.com.om www.google.nl *.filtre-de-hotte.fr www.google.com.sv www.google.com.tr www.google.com.uy www.google.se *.etrusted.com www.google.co.ao *.taboola.com www.google.com.na www.google.sn www.google.com.mm *.cookiebot.com www.google.cl www.google.co.za *.webflow.com www.google.sc www.google.gm *.hsappstatic.net www.google.co.nz www.google.co.uk www.google.cg www.google.com.bd www.google.ht *.visualwebsiteoptimizer.com www.google.kz *.rubiconproject.com www.google.com.au www.google.bs www.google.mk www.google.cz www.google.bf www.google.co.kr www.google.az www.google.com.gi data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.dpdconnect.nl https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.multisafepay.com https://pay.google.com l.moogento.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.varify.io *.criteo.com *.allspares.fr *.beslist.nl *.hs-banner.com *.afzuigkapfilterwinkel.nl *.filtre-de-hotte.fr *.webeyez.com *.jquery.com *.kk-resources.com *.robinhq.com *.usercentrics.eu *.hs-scripts.com robincontentdesktop.blob.core.windows.net *.waterfilterwinkel.com yastatic.net *.userway.org *.hotjar.com *.criteo.net d5yoctgpv4cpx.cloudfront.net *.hs-analytics.net *.cookiebot.com *.allspares.com *.etrusted.com *.hubspot.com *.trengo.eu az416426.vo.msecnd.net *.trustedshops.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://hcaptcha.com https://*.hcaptcha.com fonts.googleapis.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.allspares.fr *.filtre-de-hotte.fr *.trustedshops.com *.fontawesome.com *.varify.io *.afzuigkapfilterwinkel.nl *.etrusted.com *.waterfilterwinkel.com *.userway.org 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com *.multisafepay.com autocomplete2.postdirekt.de wss://ws.hotjar.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site www.google.com.bd *.hotjar.io www.google.com.gt www.google.ae www.google.com.py www.google.co.tz www.google.cv *.waterfilterwinkel.com *.webeyez.com *.allspares.nl www.google.ie *.beslist.nl www.google.co.kr *.visualwebsiteoptimizer.com www.google.cl www.google.com.bn www.google.dz *.usercentrics.eu *.visualstudio.com www.google.tg *.kelkoogroup.net www.google.com.gi www.google.com.mx www.google.co.il www.google.co.in www.google.am www.google.no www.google.com.tw *.filtre-de-hotte.fr www.google.lt www.google.com.tr www.google.hr p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.afzuigkapfilterwinkel.nl www.google.ru www.google.sk www.google.by www.google.com.sg www.google.it www.google.com.bh www.google.co.th www.google.ad www.google.mk *.hotjar.com www.google.com.pr www.google.lv www.google.com.ar www.google.gr www.google.ci www.google.com.lb www.google.lu www.google.com.pk www.google.md www.google.com.hk www.google.mu www.google.sn www.google.cg *.robinhq.com www.google.az www.google.pt *.hubspot.com www.google.co.uk www.google.cd www.google.iq www.google.co.jp www.google.com.br *.userway.org *.google.com www.google.li *.samsung.com *.trengo.eu www.google.co.id *.allspares.fr www.google.com.cy www.google.si www.google.ee *.jquery.com *.criteo.com www.google.com.ni www.google.es *.cookiebot.com www.google.ge www.google.sr www.google.se www.google.pl www.google.com.vn www.google.de www.google.co.ve www.google.co.za *.dunstabzugshaube-filter.de *.bing.net www.google.be www.google.co.ke www.google.tn www.google.com.uy www.google.co.nz www.google.nl www.google.ch www.google.bg www.google.rs www.google.com.ua www.google.fr www.google.dk www.google.ca www.google.com.qa www.google.com.eg *.varify.io www.google.me www.google.ga www.google.al www.google.com.do www.google.com.ph www.google.com.na www.google.co.ma www.google.com.my www.google.cz *.allspares.de localhost www.google.co.uz www.google.ro www.google.com.np www.google.at *.bing.com server-side-tagging-hgb22rqeua-uc.a.run.app www.google.cm *.baidu.com google.com www.google.lk www.google.fi www.google.kz www.google.com.pa www.google.ba www.google.bj www.google.hu www.google.ps www.google.com.om www.google.com.kw www.google.com.au www.google.ml www.google.com.sa www.google.bi www.google.mg www.google.is www.google.com.ng www.google.com.co www.google.com.mt 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://c6d02f62-c45e-4c56-876c-2102faf3fd5c.sansec.watch/; report-to report-endpoint; 2 upgrade-insecure-requests; frame-ancestors 'self'; frame-src 'self' *.google.com *.google.com.mx *.twitter.com *.youtube.com *.vimeo.com *.facebook.com *.instagram.com *.ampproject.org *.doubleclick.net *.googleapis.com *.retargetly.com *.googlesyndication.com *.ampproject.net *.admanmedia.com *.vidible.tv *.cxense.com *.googletagmanager.com *.adnxs.com *.rubiconproject.com *.indexww.com *.openx.net *.doubleverify.com *.tiktok.com *.pubmatic.com *.adxyield.com *.indexww.com *.facebook.net; report-uri https://cmsmedios2.report-uri.com/r/d/csp/reportOnly 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.pinterest.com *.sendcloud.sc *.jsdelivr.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.trustedshops.com cdn.cookielaw.org res.cloudinary.com www.b2c-nfinity.com t.squeezely.tech cdn-icons-png.flaticon.com docker.creative-serving.com trkr.shoppingminds.net bam.nr-data.net *.googleapis.com *.etrusted.com *.pinterest.com bat.bing.com *.adyen.com *.facebook.com img.youtube.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org cdn.doofinder.com *.google.com *.google.co.uk *.google.ca b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ts.tradetracker.net *.amazonaws.com blob: www.google.ge magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.trustedshops.com squeezely.tech bat.bing.com *.etrusted.com *.kk-resources.com *.googleoptimize.com cdn.cookielaw.org l.getsitecontrol.com script.shoppingminds.com script.shoppingminds.net js-agent.newrelic.com bam.nr-data.net static.hotjar.com script.hotjar.com s2.getsitecontrol.com *.pinterest.com s.pinimg.com analytics.topdrinks.nl analytics.topdrinks.fr analytics.topdrinks.dk analytics.topdrinks.de analytics.topdrinks.at analytics.topdrinks.be unpkg.com cdn.jsdelivr.net commerce.adobe.net *.googletagmanager.com cdn.doofinder.com analytics.tiktok.com *.google.co.uk *.google.ca s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com songbirdstag.cardinalcommerce.com tm.tradetracker.net *.trustpilot.com *.sendcloud.sc *.jsdelivr.net https://connect.facebook.net *.google.fr *.disqus.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app *.etrusted.com *.pinterest.com *.sendcloud.sc *.jsdelivr.net *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.youtube.com youtu.be www.youtube-nocookie.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.google.lk analytics.topdrinks.nl ws.hotjar.com wss://ws.hotjar.com content.hotjar.io analytics.topdrinks.fr analytics.topdrinks.dk analytics.topdrinks.de analytics.topdrinks.at analytics.topdrinks.be cdn.cookielaw.org geolocation.onetrust.com *.g.doubleclick.net l.getsitecontrol.com *.shoppingminds.net *.googleapis.com bam.nr-data.net cdn1.api.trustedshops.com pay.google.com privacyportal-de.onetrust.com vc.hotjar.io events.getsitectrl.com *.etrusted.com *.pinterest.com *.adyen.com maps.googleapis.com nominatim.openstreetmap.org *.onyourmap.com *.mapbox.com *.doofinder.com wss://*.doofinder.com analytics.tiktok.com ekr.zdassets.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.sendcloud.sc *.cdn.jsdelivr.net https://analytics.tiktok.com *.google.fr *.google.co.uk *.google.ca 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com *.cdn-apple.com *.useinsider.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com airwallex.com *.airwallex.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net https://js.checkout.com *.klarna.com *.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com *.useinsider.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.paytabs.com *.paytabs.sa * checkout.tabby.ai *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net google.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com *.google.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.afterpay.com *.clearpay.co.uk *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.useinsider.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com *.facebook.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://*.checkout.com *.klarnacdn.net *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.useinsider.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com maps.googleapis.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com seondf.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com *.afterpay.com/ *.squarecdn.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.useinsider.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.useinsider.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://js.checkout.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.useinsider.com api.amplitude.com stats.g.doubleclick.net www.google-analytics.com https://get.geojs.io *.avada.io *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-uri https://a98901cf-47c3-4caa-90c6-689597e5f0ac.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com data: https://fonts.gstatic.com https://fonts.googleapis.com https://*.sovendus.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com js.mollie.com https://vars.hotjar.com https://www.pinterest.fr https://www.pinterest.com https://www.google.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com *.bird.eu a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://cdn.flbx.io magefan.com cm.magefan.com https://www.mollie.com https://www.google-analytics.com https://www.google.com https://www.google.fr *.ggpht.com *.googleapis.com https://maps.gstatic.com https://log.pinterest.com *.mondialtissus.fr *.mondialtissus.de *.mondialtissus.es *.mondialtissus.it *.mondialtissus.nl *.mondialtissus.se data: https://*.sovendus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://www.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdn.flbx.io *.getflowbox.com http://connect.getflowbox.com js.mollie.com https://sdk.privacy-center.org https://www.google-analytics.com https://www.analytics.google.com https://www.googleadservices.com https://www.googletagmanager.com https://wwww.paypalobjects.com https://s.ytimg.com https://maps.googleapis.com https://www.gstatic.com/recaptcha https://js.mollie.com https://france.mondialtissus.fr https://cdnjs.cloudflare.com https://assets.pinterest.com https://static.zdassets.com https://ekr.zdassets.com https://apis.google.com https://mondialtissus.zendesk.com https://admin.mondialtissus.fr 'unsafe-inline' https://*.sovendus.com https://cdn.jsdelivr.net https://static-sb.com https://social-sb.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com 'unsafe-inline' https://*.sovendus.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net https://*.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com https://www.google-analytics.com *.hotjar.com https://ekr.zdassets.com https://maps.googleapis.com https://mondialtissus.zendesk.com https://a.getflowbox.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://d6tizftlrpuof.cloudfront.net 'self' 'unsafe-inline'; 2 font-src *.cloudflare.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.youtube.com *.g.doubleclick.net *.facebook.com *.facebook.net https://payment-stage.ecpay.com.tw/ https://payment.ecpay.com.tw/ 'self' 'unsafe-inline'; frame-ancestors *.tappaysdk.com google.com *.google.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.tappaysdk.com google.com *.google.com *.facebook.com *.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://live-chat-console.no8.io https://*.useinsider.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.cloudflare.com *.ytimg.com *.googletagmanager.com *.google-analytics.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.tappaysdk.com google.com *.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.zdassets.com *.facebook.net *.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://live-chat-console.no8.io https://js-agent.newrelic.com https://bam.nr-data.net https://*.useinsider.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.tappaysdk.com google.com *.google.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com https://live-chat-console.no8.io tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.tappaysdk.com google.com *.google.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.tappaysdk.com google.com *.google.com *.cloudflare.com *.google-analytics.com *.googletagmanager.com *.zendesk.com *.zopim.com *.zdassets.com *.gstatic.com *.google.com.tw *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://api-next.no8.io https://js-agent.newrelic.com https://bam.nr-data.net https://*.useinsider.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://assets.adobedtm.com https://customer.cludo.com https://ds-aksb-a.akamaihd.net https://help.cybonline.co.uk https://googleservices.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://www.google.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://fusiontables.google.com https://connect.facebook.net https://www.youtube.com https://s.ytimg.com https://cse.google.com https://www.advanced-web-analytics.com https://platform.twitter.com https://casper.tsbc.com https://healthcheck252.tsbc.com https://t.contentsquare.net https://contentsquare.com https://webapp.woosmap.com https://dispawsusva.inmoment.com https://intercept-client.inmoment.com https://*.evidon.com; style-src 'self' 'unsafe-inline' https://www.gstatic.com https://fonts.googleapis.com https://www.google.com https://platform.twitter.com https://casper.tsbc.com https://healthcheck252.tsbc.com; img-src 'self' https: data: ; font-src 'self' https: ; connect-src 'self' https://clydesdalebank.tt.omtrdc.net https://clydesdalebank.d3.sc.omtrdc.net https://dpm.demdex.net https://ds-aksb-a.akamaihd.net https://api-eu1.cludo.com https://api.cludo.com https://www.google.com https://www.facebook.com https://www.twitter.com https://www.linkedin.com https://www.youtube.com https://my.cybservices.co.uk https://adservice.google.com https://casper.tsbc.com https://*.contentsquare.net https://api.woosmap.com https://webapp-conf.woosmap.com https://cybg.egain.cloud https://dispawsusva.inmoment.com https://ad.doubleclick.net https://maps.googleapis.com https://*.evidon.com; media-src 'self'; object-src 'self'; worker-src 'self' blob:; child-src 'self' blob:; frame-src 'self' https://*.cybusinessonline.co.uk https://*.cbonline.co.uk https://*.ybonline.co.uk https://*.cybonline.co.uk https://clydesdalebankplc.demdex.net https://*.fls.doubleclick.net https://www.youtube.com https://bid.g.doubleclick.net https://www.google.com https://assets.adobedtm.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.youtube-nocookie.com https://healthcheck252.tsbc.com https://www.inmoment.com https://td.doubleclick.net; frame-ancestors 'self' https://*.cybusinessonline.co.uk https://*.cbonline.co.uk https://*.ybonline.co.uk https://*.cybonline.co.uk; report-uri https://cyburi.report-uri.com/r/t/csp/reportOnly; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://fonts.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.greenhouse.io https://*.osano.com blob: https://pages.e2open.com https://cdn-cookieyes.com https://play.vidyard.com https://snap.licdn.com https://ws.zoominfo.com https://*.clarity.ms https://cdn.bizible.com https://www.googletagmanager.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js-agent.newrelic.com https://*.6sc.co https://*.adsrvr.org https://*.abrankings.com https://*.google-analytics.com https://bat.bing.com https://*.hotjar.com https://*.crazyegg.com https://connect.facebook.net https://*.marketo.net https://*.demandbase.com https://*.ads-twitter.com; style-src 'self' 'unsafe-inline' data: https://*.greenhouse.io https://*.osano.com https://pages.e2open.com https://cdn.jsdelivr.net https://*.googleapis.com; img-src 'self' data: https://secure.gravatar.com https://www.gravatar.com https://*.bizible.com https://*.bizibly.com https://*.licdn.com https://*.clarity.ms https://*.googlesyndication.com https://*.doubleclick.net https://stats.g.doubleclick.net https://*.linkedin.com https://t.co https://analytics.twitter.com https://*.6sc.co https://*.bing.com https://*.facebook.com https://*.rlcdn.com https://*.company-target.com https://*.facebook.net https://cdn-cookieyes.com https://*.vidyard.com secure.gravatar.com www.gravatar.com; connect-src 'self' https://*.greenhouse.io https://*.osano.com https://*.linkedin.com https://*.licdn.com https://www.google.com https://*.google-analytics.com https://sheets.googleapis.com https://*.vidyard.com https://bam.nr-data.net https://*.linkedin.com https://*.licdn.com https://www.google-analytics.com https://region1.google-analytics.com https://secure.adnxs.com https://*.6sc.co https://*.6sense.com https://api.company-target.com https://script.crazyegg.com https://*.mktoresp.com https://*.clarity.ms https://*.abrankings.com https://insight.adsrvr.org https://*.demandbase.com https://*.facebook.com https://*.hotjar.io https://log.cookieyes.com https://cdn-cookieyes.com; frame-src 'self' https://*.greenhouse.io https://*.osano.com https://pages.e2open.com https://www.googletagmanager.com https://*.company-target.com https://*.adsrvr.org https://*.vidyard.com; worker-src 'self' https://*.osano.com blob:; 2 img-src 'self' data: *.commercecloud.salesforce.com *.googleapis.com *.gstatic.com *.ctfassets.net *.autoshack.com *.autoshack.ca *.demandware.net nova.collect.igodigital.com prd-cdn-talkdesk.talkdesk.com www.facebook.com *.google-analytics.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.google.com *.google.ca googleads.g.doubleclick.net www.google.com pagead2.googlesyndication.com www.googleadservices.com google.com google.ca *.equalweb.com *.usercentrics.eu www.paypal.com www.paypalobjects.com www.sandbox.paypal.com;script-src 'self' 'unsafe-eval' localhost:* *.site.com *.cybersource.com www.cybersource.com storage.googleapis.com *.autoshack.ca *.autoshack.com autoshack.ca autoshack.com *.collect.igodigital.com *.googleapis.com talkdeskchatsdk.talkdeskapp.com *.googletagmanager.com *.google-analytics.com clarity.ms www.clarity.ms www.googleadservices.com www.google.com www.googletagmanager.com pagead2.googlesyndication.com googleads.g.doubleclick.net connect.facebook.net 546006088.collect.igodigital.com *.equalweb.com *.usercentrics.eu ipapi.co script.crazyegg.com *.crazyegg.com crazyegg.com wwww.crazyegg.com runtime.commercecloud.com api.quotiient.com *.doubleclick.net spglobal.com www.paypal.com www.sandbox.paypal.com pay.google.com *.cdn-apple.com www.gstatic.com gstatic.com www.google.com google.com 'unsafe-inline';connect-src 'self' localhost:* *.salesforce-scrt.com *.cybersource.com www.cybersource.com *.googleapis.com api.cquotient.com api.talkdeskappca.com *.autoshack.com *.autoshack.ca https://api.rates.autoshack.com *.spglobal.com *.google-analytics.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.google.com *.google.ca *.clarity.ms pagead2.googlesyndication.com www.googleadservices.com www.google.com google.com *.mobify-storefront.com *.collect.igodigital.com *.equalweb.com *.usercentrics.eu ipapi.co script.crazyegg.com *.crazyegg.com crazyegg.com wwww.crazyegg.com www.facebook.com api.paypal.com api.sandbox.paypal.com www.paypal.com www.sandbox.paypal.com;media-src *.ctfassets.net *.autoshack.com *.autoshack.ca;frame-src *.site.com *.cybersource.com www.cybersource.com *.ctfassets.net youtube.com www.youtube.com vimeo.com www.vimeo.com talkdeskchatsdk.talkdeskapp.com td.doubleclick.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pay.google.com *.cdn-apple.com www.google.com google.com www.gstatic.com gstatic.com *.demandware.net demandware.net development-na01-autoshack.demandware.net staging-na01-autoshack.demandware.net production-na01-autoshack.demandware.net;frame-ancestors localhost:* 'self' *.salesforce.com *.autoshack.com *.autoshack.ca autoshack.ca autoshack.com *.commercecloud.salesforce.com runtime.commercecloud.salesforce.com autoshack.com *.demandware.net demandware.net development-na01-autoshack.demandware.net staging-na01-autoshack.demandware.net production-na01-autoshack.demandware.net;child-src www.facebook.com staticxx.facebook.com *.autoshack.ca *.autoshack.com autoshack.ca autoshack.com www.autoshack.ca www.autoshack.com *.demandware.net demandware.net development-na01-autoshack.demandware.net staging-na01-autoshack.demandware.net production-na01-autoshack.demandware.net www.paypal.com www.sandbox.paypal.com;style-src 'self' fonts.googleapis.com 'unsafe-inline';worker-src 'self' blob:;default-src 'self';base-uri 'self';block-all-mixed-content;font-src 'self' https: data:;object-src 'none';script-src-attr 'none';upgrade-insecure-requests 2 font-src fonts.gstatic.com 'self' data: embed.tawk.to data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' data: www.googletagmanager.com ct.pinterest.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com 'self' data: integrations.etrusted.com interface.mailcampaigns.nl px.ads.linkedin.com www.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' data: interface.mailcampaigns.nl connect.facebook.net s.pinimg.com embed.tawk.to snap.licdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com 'self' data: integrations.etrusted.com interface.mailcampaigns.nl embed.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src embed.tawk.to 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com 'self' data: ct.pinterest.com pagead2.googlesyndication.com *.tawk.to px.ads.linkedin.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.kleecks-cdn.com *.kleecks-stats.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.fonts.googleapis.com data: *.cloudflare.com data: *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; frame-ancestors *.kleecks-cdn.com *.kleecks-stats.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.addthis.com *.pinterest.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.kleecks-cdn.com *.kleecks-stats.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com https://*.gabel1957.com https://*.somma1867.com m.media-amazon.com static-eu.payments-amazon.com *.google.it data: *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://cdn.iubenda.com https://cs.iubenda.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.instagram.com googletagmanager.com cdn.iubenda.com unpkg.com www.google.com static-eu.payments-amazon.com www.gstatic.com *.newrelic.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://*.gabel1957.com https://*.somma1867.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; object-src https://assets.adobedtm.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://*.gabel1957.com https://*.somma1867.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net https://*.vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com https://*.facebook.com *.facebook.net https://*.google.com https://*.doubleclick.net *.googlesyndication.com *.tiktok.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.cloudflare.com https://*.paypal.com *.googleapis.com https://*.addthis.com https://*.cardinalcommerce.com https://*.graph.instagram.com https://*.google-analytics.com https://*.adobe.io https://*.adobe.net https://*.adobedc.net https://*.adobedtm.com https://akoctmvv.euh.stape.net https://*.amazon.com https://*.amazonpay.com https://*.amazonservices.com https://*.braintreegateway.com https://*.braintree-api.com https://*.demdex.net https://*.zdassets.com https://*.analytics.google.com *.googletagmanager.com *.googleadservices.com https://*.iubenda.com https://*.kleecks-cdn.com https://*.kleecks-stats.com https://*.magedevteam.com https://*.nr-data.net https://*.typekit.net https://*.paypalobjects.com https://*.sentry.io https://*.snplow.net https://ss.gabel1957.com https://ss.somma1867.com https://*.unpkg.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://assets.adobedtm.com commerce.adobedc.net payments-eu.amazon.com *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri http://akoctmvv.euh.stape.net https://akoctmvv.euh.stape.net *.kleecks-cdn.com *.kleecks-stats.com 'self' 'unsafe-inline'; 2 font-src mediacdn.espssl.com fonts.gstatic.com *.acsbapp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.meetanshi.com *.force.com *.addthisedge.com *.addthis.com *.hotjar.com *.doubleclick.net *.facebook.com *.my.salesforce-sites.com *.secure.force.com www.google.com *.cdn-btsg.com www.commercepartnerhub.com *.adsrvr.org www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com www.apptrian.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.meetanshi.com https://meetanshi.com/media/logo.png https://img.youtube.com *.listrakbi.com *.b0e8.com *.elfsightcdn.com *.bazaarvoice.com mediacdn.espssl.com *.hotjar.com *.doubleclick.net butterly.com *.butterly-images.com http://butterly.com *.google.com *.google.co.in *.facebook.net *.facebook.com facebook.com google.com google.co.in *.acsbapp.com www.xtento.com *.cdn-btsg.com *.lagostina.ca lagostina.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.apptrian.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.meetanshi.com s7.addthis.com cdn.cookielaw.org cdn.bc0a.com cdn1.b0e8.com service.force.com *.listrakbi.com butterly.com *.newrelic.com *.moatads.com *.elfsight.com *.addthisedge.com *.addthis.com *.salesforceliveagent.com bam.nr-data.net acsbap.com acsbapp.com *.acsbap.com *.acsbapp.com *.hotjar.com *.facebook.net *.facebook.com *.salesforce.com *.youtube.com *.ugc.bazaarvoice.com *.google.com *.gstatic.com *.bazaarvoice.com *.adsrvr.org *.cdn-btsg.com *.mczbf.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com display.ugc.bazaarvoice.com *.listrakbi.com service.force.com *.bazaarvoice.com mediacdn.espssl.com *.hotjar.com fonts.googleapis.com *.doubleclick.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com www.apptrian.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.meetanshi.com ekr.zdassets.com/ cdn.cookielaw.org *.bc0a.com *.elfsight.com *.addthis.com mediacdn.espssl.com *.onetrust.com bam.nr-data.net fonts.googleapis.com *.facebook.net *.facebook.com *.doubleclick.net wss://*.hotjar.com *.hotjar.com *.acsbapp.com acsbapp.com acsbap.com *.acsbap.com *.elfsightcdn.com *.hotjar.io www.xtento.com butterly.com *.cdn-btsg.com *.mczbf.com *.google.com www.google.com *.bazaarvoice.com *.fbcdn.net static.xx.fbcdn.net *.xx.fbcdn.net https://static.xx.fbcdn.net *.commercepartnerhub.com commercepartnerhub.com wss://*.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src account.groupeseb.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cookiebot.eu *.youtube.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.lutz.nl *.lutzfashion.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com *.amazonaws.com ssl.gstatic.com www.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.lutz.nl *.lutzfashion.com *.getdrip.com *.tweakwise.com *.cookiebot.eu *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr chimpstatic.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com *.sooqr.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net *.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.sooqr.com *.sendcloud.sc *.jsdelivr.net tagmanager.google.com fonts.google.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.lutz.nl *.lutzfashion.com *.tweakwise.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.mailcampaigns.nl *.visualstudio.com *.pinterest.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com https://squeezely.tech *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://cdn.checkout.com *.cdn-apple.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com fonts.gstatic.com cdn.livechat.connexease.com api.connexease.com *.g.doubleclick.net *.tamara.co *.smooch.io cdnjs.cloudflare.com *.personaclick.com *.googlesyndication.com *.googleadservices.com *.googletagservices.com *.google.com google.ae *.googletagmanager.com google.com *.uplo.io *.core.windows.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://js.checkout.com *.klarna.com *.youtube.com/ checkout.tabby.ai 'self' *.paypal.com *.tamara.co *.vimeo.com *.braintreegateway.com td.doubleclick.net *.googletagmanager.com livechat.connexease.com cdn.allinone.connexease.com cdnjs.cloudflare.com tr.snapchat.com *.personaclick.com *.googlesyndication.com *.googleadservices.com *.g.doubleclick.net www.googletagservices.com *.google.com google.com *.uplo.io server-side-tagging-kbxfdsts4q-uc.a.run.app *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.tamara.co 'self' 'unsafe-inline' *.g.doubleclick.net *.facebook.com *.snapchat.com preprod.calvinklein.ae cdn.allinone.connexease.com cdn.livechat.connexease.com api.connexease.com *.smooch.io cdnjs.cloudflare.com tr.snapchat.com *.personaclick.com cdn.connexease.com *.googlesyndication.com *.googletagservices.com *.google.com *.google.ae *.google.com.af *.google.com.bh *.google.com.eg *.google.iq *.google.com.jo *.google.com.kw *.google.com.lb *.google.com.om *.google.ps *.google.com.qa *.google.com.sa *.google.com.tr *.google.com.ye *.googletagmanager.com google.com *.uplo.io *.core.windows.net *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.checkout.com *.klarnacdn.net *.cdn-apple.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.avada.io checkout.tabby.ai widgets.tabby.ai cdn.segment.com connect.facebook.net www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.tamara.co 'self' 'unsafe-inline' 'unsafe-eval' *.paypal.com *.facebook.net *.braintreegateway.com *.adobedtm.com *.g.doubleclick.net tr.snapchat.com *.tiktok.com preprod.calvinklein.ae api.segment.io sc-static.net *.tiktokw.us livechat.connexease.com cdn.allinone.connexease.com cdn.livechat.connexease.com api.connexease.com *.smooch.io td.doubleclick.net *.googletagmanager.com cdnjs.cloudflare.com *.personaclick.com cdn.connexease.com *.googlesyndication.com *.googleadservices.com *.googletagservices.com *.google.com *.google.ae *.google.com.af *.google.com.bh *.google.com.eg *.google.iq *.google.com.jo *.google.com.kw *.google.com.lb *.google.com.om *.google.ps *.google.com.qa *.google.com.sa *.google.com.tr *.google.com.ye google.com *.uplo.io *.core.windows.net https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.checkout.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com *.tamara.co fonts.googleapis.com 'self' 'unsafe-inline' livechat.connexease.com preprod.calvinklein.ae cdn.allinone.connexease.com cdn.livechat.connexease.com api.connexease.com *.g.doubleclick.net *.smooch.io cdnjs.cloudflare.com tr.snapchat.com *.personaclick.com *.googlesyndication.com *.googleadservices.com *.googletagservices.com *.google.com *.google.ae *.google.com.eg *.google.com.lb *.googletagmanager.com google.com *.uplo.io *.core.windows.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tamara.co *.core.windows.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://js.checkout.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org https://get.geojs.io *.avada.io checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.tamara.co 'self' *.braintreegateway.com *.facebook.net tr.snapchat.com get.geojs.io tr6.snapchat.com *.tiktok.com *.tiktokw.us cdn.sift.com api.braintreegateway.com livechat.connexease.com api.connexease.com cdn.livechat.connexease.com *.g.doubleclick.net *.smooch.io cdnjs.cloudflare.com *.personaclick.com *.googlesyndication.com *.googletagservices.com *.google.com *.google.ae *.google.com.eg *.google.com.lb google.com/pay *.googletagmanager.com server-side-tagging-kbxfdsts4q-uc.a.run.app *.uplo.io google.com *.core.windows.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-src 'self' www.youtube.com www.google.com js.playground.klarna.com js.klarna.com https://checkoutshopper-test.adyen.com https://pay.google.com https://wchat.freshchat.com https://connect.getflowbox.com return.4sellers.de *.webpush.freshchat.com ct.pinterest.com vercel.live *.sovendus.com *.adyen.com gum.criteo.com fledge.eu.criteo.com *.cnstrc.com cnstrc.com graphical-editor.kameleoon.com *.vimeo.com vimeo.com www.googletagmanager.com *.chat.getzowie.com 2 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.fi https://connect.facebook.net https://support.hostaan.com https://widget.trustmary.com https://embed.trustmary.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://fonts.googleapis.com https://www.gstatic.com https://cdnjs.cloudflare.com https://support.hostaan.com 'unsafe-inline' 'unsafe-eval'; font-src 'self' https://fonts.gstatic.com https://support.hostaan.com data:; connect-src 'self' https://region1.google-analytics.com https://embed.trustmary.io https://stats.g.doubleclick.net https://www.google-analytics.com https://*.facebook.com https://www.google.com https://www.googletagmanager.com https://region1.analytics.google.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.fi https://support.hostaan.com; media-src 'self' https://support.hostaan.com; img-src 'self' blob: data: https://www.googletagmanager.com https://fonts.gstatic.com https://translate.google.com https://widget.trustmary.com/ https://d2nce6johdc51d.cloudfront.net https://lh3.googleusercontent.com https://www.google.se https://www.google.fi https://www.google.com https://stats.g.doubleclick.net https://www.google.fi https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.facebook.com https://support.hostaan.com; frame-src 'self' https://www.youtube.com https://www.facebook.com https://www.googletagmanager.com https://www.google.com https://support.hostaan.com https://td.doubleclick.net; worker-src 'self' blob:; object-src 'none'; frame-ancestors 'self' https://www.hostaan.fi; report-uri https://n8n.ppweb.fi/webhook/da8630cf-3a65-402b-b95f-6fa58e667ed6; 2 font-src *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.clover.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.clover.com *.hsforms.com *.doubleclick.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io store.paradoxlabs.com https://firebasestorage.googleapis.com *.clover.com 'self' data: *.hsforms.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.clover.com *.google.com *.gstatic.com *.hsforms.com *.hsforms.net https://www.googletagmanager.com tagmanager.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.hsforms.com *.doubleclick.net *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com hdbrows.nbg.test data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.google.com *.doubleclick.net *.facebook.com account.fetchify.com widget.trustpilot.com td.doubleclick.net https://plumrocket.com *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.bird.eu www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com hdbrows.nbg.test hdbrows.com hdbrows.ng.stg.nexusbrands.eu www.google.co.uk js.klevu.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.attn.tv events.attentivemobile.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.googleapis.com *.avada.io hdbrows.nbg.test www.google.com www.gstatic.com widget.trustpilot.com invitejs.trustpilot.com tag.rmp.rakuten.com https://crm.nouveaubeauty.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cc-cdn.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.google.com hdbrows.nbg.test js.klevu.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.attn.tv events.attentivemobile.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io hdbrows.nbg.test widget.trustpilot.com https://crm.nouveaubeauty.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src hdbrows.nbg.test 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://nouveaulashes.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 font-src *.kueskipay.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com multicobros.banorte.com supercolchones.gestionplay.com.ar *.opencontrol.mx *.kaptcha.com *.openpay.pe eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com landofcoder.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar supercolchones.gestionplay.com.ar *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com multicobros.banorte.com supercolchones.gestionplay.com.ar *.facebook.net cdn.connectif.cloud newrelic.com *.s3.amazonaws.com *.openpay.co *.openpay.pe *.google-analytics.com *.google.com/recaptcha/ *.gstatic.com/recaptcha/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com landofcoder.com *.cloudflare.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com https://static.klaviyo.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com supercolchones.gestionplay.com.ar fonts.googleapis.com unsafe-inline *.paypal.com *.sandbox.paypal.com *.paypalobjects.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com supercolchones.gestionplay.com.ar 'self' 'unsafe-inline'; manifest-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.doubleclick.net https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com multicobros.banorte.com supercolchones.gestionplay.com.ar *.openpay.mx *.openpay.co *.openpay.pe api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com landofcoder.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-ancestors 'none'; report-uri https://endpoint3.collection.us2.sumologic.com/receiver/v1/http/ZaVnC4dhaV30Tj5vtZfuZ0tYPfqb8xOSxI9TJ5CbQ_ZE4W4aGoGW8HViqViD0nttCcDqHOZNNhObvJtSbYn1XDP7uSjlITCzSLlNsuSdwZ46El5dcVC6kg== 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.googleapis.com *.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.gstatic.com www.apptrian.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.gstatic.com www.apptrian.com *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com www.apptrian.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 2 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com https://webpay3gint.transbank.cl webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: https://www.google.com http://www.google.com https://www.facebook.com https://web.facebook.com https://bid.g.doubleclick.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://www.facebook.com https://www.google.com https://www.google.cl https://maps.gstatic.com https://maps.googleapis.com https://cdn.pushcrew.com https://dev.visualwebsiteoptimizer.com https://googleads.g.doubleclick.net https://pushcrew.com *.alothemes.com *.magepow.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://www.google.cl https://cdn.pushcrew.com https://dev.visualwebsiteoptimizer.com https://fonts.googleapis.com https://maps.googleapis.com https://www.googletagmanager.com https://www.gstatic.com https://connect.facebook.net https://googleads.g.doubleclick.net http://www.google.com https://tracking.krip.cl https://js-agent.newrelic.com https://bam.nr-data.net https://cdn.fitit.ai *.googleapis.com *.google.com *.gstatic.com *.alothemes.com *.magepow.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://fonts.googleapis.com https://cdn.pushcrew.com https://dev.visualwebsiteoptimizer.com https://cdn.fitit.ai *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.alothemes.com *.magepow.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://stats.g.doubleclick.net https://www.google-analytics.com https://bam.nr-data.net https://www.facebook.com https://api.bciplus.cl https://maps.googleapis.com https://pushcrew.com https://firebase.googleapis.com https://firebaseremoteconfig.googleapis.com https://us-central1-fitit-a5bde.cloudfunctions.net https://firebaselogging-pa.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.alothemes.com *.magepow.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'none'; script-src 'self' https://*.typekit.net/ https://*.clarity.ms/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://*.googleapis.com/ https://*.gstatic.com/ https://seal.thawte.com/ https://secure.bluepay.com https://seal.digicert.com/ https://www.safewayxchange.com/ 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.clarity.ms/ https://stats.g.doubleclick.net; img-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://dev.virtualearth.net/ data: https://seal.digicert.com https://www.google.com; style-src 'self' 'unsafe-inline' https://*.typekit.net/ https://fonts.googleapis.com/ https://*.gstatic.com; font-src 'self' https://*.typekit.net/ https://fonts.gstatic.com/ https://fonts.googleapis.com/; frame-src 'self' https://secure.bluepay.com https://www.safewayxchange.com/; object-src 'self'; media-src 'self' https://www.google-analytics.com/; manifest-src 'self'; frame-ancestors 'self'; report-uri https://08bfb48ddcee7d64057e88503ec1149f.report-uri.com/r/t/csp/reportOnly 2 default-src 'self' data: *.pinimg.com *.postaffiliatepro.com partneri.affilmax.cz *.doubleclick.net *.facebook.net *.google-analytics.com *.biano.cz *.dognet.sk *.googlesyndication.com *.imedia.cz *.googletagmanager.com *.googleadservices.com ;font-src 'self' data: fonts.gstatic.com *.zbozi.cz *.biano.cz *.biano.sk *.biano.hu ;connect-src 'self' google.com *.google.com *.google.hu *.google.ae *.google.co.uk *.google.cz *.google.sk *.google.de *.google.at *.google.fr *.google.it *.google.sk *.google.pl *.google.nl *.google.ie *.google.com.ua *.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.zbozi.cz *.exchangeratesapi.io *.pingdom.net *.biano.cz *.biano.sk *.biano.hu *.bianopixel.com *.dognet.sk *.foxentry.cz *.seznam.cz *.facebook.com *.pinterest.com *.doubleclick.net https://*.clarity.ms partner-events.favi.cz partner-events.favi.sk partner-events.favi.hu t.targito.signal-nabytek.cz t.targito.sg-nabytek.cz t.targito.signal-nabytok.sk t.targito.sg-nabytok.sk t.targito.butor-signal.hu t.targito.sg-butor.hu *.clickcease.com *.targito.com *.googlesyndication.com https://saas.bianoapi.com bat.bing.com bat.bing.net live.luigisbox.com api.luigisbox.com https://*.api.rvndev.com https://*.api.raventic.ai https://*.api.raventic.dev https://api.raventic.dev https://eshops-uet-tags.ams3.cdn.digitaloceanspaces.com apps.sg-nabytek.cz apps.sg-nabytok.sk apps.sg-butor.hu ;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.google.cz *.seznam.cz *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.imedia.cz *.facebook.net *.doubleclick.net *.rival.cz *.fg.cz *.3dliving.cz *.imedia.cz *.zbozi.cz *.exchangeratesapi.io *.facebook.com *.pingdom.net *.biano.cz *.biano.sk *.biano.hu *.bianopixel.com *.dognet.sk *.foxentry.cz *.googlesyndication.com *.pinimg.com *.pinterest.com partneri.affilmax.cz *.postaffiliatepro.com www.heureka.cz im9.cz cz.img9.cz *.glami.cz *.licdn.com *.linkedin.com tracking.srovname.cz https://*.clarity.ms partner-events.favicdn.net cdn.targito.signal-nabytek.cz cdn.targito.sg-nabytek.cz cdn.targito.signal-nabytok.sk cdn.targito.sg-nabytok.sk cdn.targito.butor-signal.hu cdn.targito.sg-butor.hu *.clickcease.com cdn.targito.com https://saas.bianoapi.com bat.bing.com bat.bing.net scripts.luigisbox.com cdn.luigisbox.com https://sdk.cdn.rvndev.com https://sdk.rvndn.com apps.sg-nabytek.cz apps.sg-nabytok.sk apps.sg-butor.hu ;form-action 'self' *.facebook.com *.facebook.net *.pinterest.com ;frame-src 'self' *.youtube.com *.iplatba.cz *.facebook.com *.imedia.cz *.zbozi.cz *.essox.cz *.foxentry.cz *.doubleclick.net *.googletagmanager.com *.google.com *.heureka.cz *.pinterest.com *.googlesyndication.com login.szn.cz ;worker-src 'self' *.youtube.com *.iplatba.cz *.facebook.com *.imedia.cz *.zbozi.cz *.essox.cz *.foxentry.cz *.doubleclick.net *.googletagmanager.com *.google.com *.heureka.cz *.pinterest.com *.googlesyndication.com login.szn.cz ;frame-ancestors 'self' ;img-src 'self' data: blob: *.gstatic.com *.googleapis.com *.googlecode.com *.googletagmanager.com *.google-analytics.com *.seznam.cz *.doubleclick.net *.google.com *.google.hu *.google.ae *.google.co.uk *.google.cz *.google.sk *.google.de *.google.at *.google.fr *.google.it *.google.sk *.google.pl *.google.nl *.google.ie *.google.com.ua *.imedia.cz *.facebook.com *.facebook.net *.fg.cz *.3dliving.cz *.signal-nabytek.cz *.sg-nabytek.cz *.signal-nabytok.sk *.sg-nabytok.sk *.rival.cz *.vykupto.cz *.signal.pl *.zbozi.cz *.exchangeratesapi.io *.dognet.sk *.foxentry.cz *.pinimg.com *.pinterest.com *.biano.cz *.biano.sk *.biano.hu *.heureka.cz *.heureka.sk im9.cz *.glami.cz *.googleadservices.com https://*.clarity.ms bat.bing.com bat.bing.net *.favionline.com *.bing.com cdn.targito.com https://i.cdn.rvndev.com https://i.rvndn.com ;style-src 'self' 'unsafe-inline' fonts.googleapis.com *.seznam.cz *.google.com *.gstatic.com *.fg.cz *.3dliving.cz *.signal-nabytek.cz *.sg-nabytek.cz *.signal-nabytok.sk *.sg-nabytok.sk *.sg-butor.hu *.zbozi.cz *.exchangeratesapi.io *.foxentry.cz cdn.targito.com https://saas.bianoapi.com cdn.luigisbox.com https://sdk.cdn.rvndev.com https://sdk.rvndn.com ;object-src 'self' ; report-uri /frontendreport/report/ 2 default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; report-uri /api/csp-report 2 report-uri /nelmio/csp/report 2 script-src, object-src, base-uri, frame-src 2 * 2 object-src 'none'; form-action 'self'; frame-ancestors 'self'; 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/www_google 1 default-src 'self'; script-src 'self' hubapi.com *.hubapi.com hubspot.com *.hubspot.com app.hubspot.com hubspotusercontent-na1.net *.hubspotusercontent-na1.net hsappstatic.net *.hsappstatic.net hs-banner.com *.hs-banner.com hsforms.com *.hsforms.com forms.hsforms.com *googletagmanager.com  https://munchkin.marketo.net https://snap.licdn.com *linkedin.com; 'unsafe-inline' https://trusted-cdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' https:; connect-src 'self' forms.hscollectedforms.net *.hscollectedforms.net hubspot.com *.hubspot.com hubapi.com *.hubapi.com hsforms.com *.hsforms.com hsforms.net *.hsforms.net hsappstatic.net *.hsappstatic.net googletagmanager.com *.googletagmanager.com google-analytics.com *.google-analytics.com cdn.cookielaw.org *.cookielaw.org www.google.com analytics.google.com px.ads.linkedin.com *.linkedin.com; frame-ancestors 'none'; base-uri 'self'; object-src 'none'; upgrade-insecure-requests 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv5%3F.14t%7B1-19b29db576c-0x2603#pd 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-1QkjnaudnlsbTvHNtEaMiA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io s.ytimg.com tagmanager.google.com transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube.com; form-action 'self' https://accounts.firefox.com/ https://basket.mozilla.org; upgrade-insecure-requests; img-src 'self' data: www.firefox.com www.google-analytics.com www.googletagmanager.com www.mozilla.org; font-src 'self' www.firefox.com; base-uri 'none'; default-src 'self' www.firefox.com; style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.firefox.com; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.firefox.com www.mozilla.org; connect-src 'self' basket.mozilla.org cdn.transcend.io https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.ingest.us.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com; frame-ancestors 'none'; frame-src 'self' accounts.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com; object-src 'none' 1 default-src 'self' *.usgs.gov 'unsafe-inline' *.amazonaws.com *.arcgis.com 'unsafe-eval' *.arcgisonline.com *.hotjar.io *.google-analytics.com; script-src 'self' *.usgs.gov 'unsafe-inline' *.googletagmanager.com *.addtoany.com *.jsdelivr.net *.hotjar.com *.cfigroup.com *.cloud.gov *.gov *.youtube.com *.ytimg.com www.youtube.com s.ytimg.com *.google-analytics.com *.google-analytics.com connect.facebook.net *.youtube.com/iframe_api 'unsafe-eval' *.jquery.com *.cloudflare.com *.arcgis.com *.datatables.net *.dashjs.org *.googleapis.com; object-src noop.style; style-src 'self' *.usgs.gov 'unsafe-inline' *.fontawesome.com *.cloudflare.com *.arcgis.com *.datatables.net *.gstatic.com; img-src 'self' 'unsafe-inline' *.alaska.edu *.amazonaws.com *.arcgis.com *.arcgisonline.com *.cfigroup.com *.cloud.gov *.cloudflare.com *.fontawesome.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.gov *.gstatic.com *.nationalmap.gov *.nationsonline.org *.opengeo.org *.openstreetmap.org *.pixelcaster.com *.staticflickr.com *.ucweb.com *.usgs.gov *.ytimg.com avo.alaska.edu cdnjs.cloudflare.com data: *.openstreetmap.org ; media-src 'self' *.usgs.gov 'unsafe-inline' *.gstatic.com *.google.pn *.amazonaws.com; frame-src 'self' 'unsafe-inline' *.addtoany.com *.googletagmanager.com *.prismaaccess.com *.saasprotection.com *.trendmicro.com *.trendmicro.jp *.usgs.gov safe.menlosecurity.com *.youtube.com www.youtube.com; font-src 'self' 'unsafe-inline' *.alicdn.com *.amazonaws.com *.arcgis.com *.fontawesome.com *.gstatic.com *.jsdelivr.net *.mustcheck.com *.simplycodes.com *.slant.co *.typekit.net *.usgs.gov cdn.goin.cloud cdn.scite.ai data:; connect-src 'self' 'unsafe-inline' *.amazonaws.com *.arcgis.com *.arcgisonline.com *.cloud.gov *.cloudfront.net *.fontawesome.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gov *.gstatic.com *.hotjar.com *.hotjar.io *.jsdelivr.net *.usgs.gov cdn.jsdelivr.net wss://ws.hotjar.com 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-GdPk1gm8y8jROGm5OtitmQ=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 default-src 'self' wwwv2.tailscale.com; script-src 'self' wwwv2.tailscale.com bat.bing.com cdn.rudderlabs.com www.google-analytics.com www.googletagmanager.com www.google.com *.mutinycdn.com js.hs-scripts.com js.hs-banner.com js.hubspot.com js.hs-analytics.com *.hsforms.net unpkg.com snap.licdn.com www.redditstatic.com https://bwa.marketplace.awsstatic.com widget.kapa.ai; connect-src 'self' wwwv2.tailscale.com login.tailscale.com bat.bing.com *.mutinyhq.io *.mutinycdn.com analytics.google.com www.google-analytics.com cdn.sanity.io unpkg.com *.rudderstack.com *.hubspot.com www.redditstatic.com pixel-config.reddit.com px.ads.linkedin.com https://medley.prod.irtysh.dubai.aws.dev proxy.kapa.ai kapa-widget-proxy-la7dkmplpq-uc.a.run.app metrics.kapa.ai; img-src 'self' wwwv2.tailscale.com cdn.sanity.io lh3.googleusercontent.com www.google-analytics.com *.hsforms.com alb.reddit.com px.ads.linkedin.com bat.bing.com track.hubspot.com; frame-ancestors 'none'; form-action 'self' wwwv2.tailscale.com; base-uri 'self' wwwv2.tailscale.com; block-all-mixed-content; object-src 'self' wwwv2.tailscale.com; report-to csp-endpoint; report-uri https://login.tailscale.com/csp-report; 1 frame-ancestors 'self' https://ss.datasconsole.com; worker-src 'self' blob:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.coinmarketcap.com https://cdn.fuseplatform.net https://cdn.adx.ws https://cdn.cookielaw.org https://cdn4.buysellads.net https://btloader.com https://script.4dex.io https://www.google.com https://*.googlesyndication.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://ep2.adtrafficquality.google https://www.youtube.com https://s3.tradingview.com https://organizer.bizzabo.com https://telegram.org https://staticrecap.cgicgi.io https://unpkg.com/vconsole/dist/vconsole.min.js https://browser.sentry-cdn.com https://ajax.googleapis.com/ajax/libs/jquery/ https://www.recaptcha.net/recaptcha/; report-uri https://o230231.ingest.us.sentry.io/api/1773863/security/?sentry_key=f6a79779d88945e5bf5c2b7e74ee1ed8 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.zijieimg.com *.helo-app.com *.toutiaopage.com *.zjurl.cn *.pstatp.com *.bytecdn.cn *.isnssdk.com *.byteoversea.com *.365yg.com *.ks-cdn.com *.ipstatp.com *.amemv.com *.ibytedtos.com *.ixigua.com *.ixiguavideo.com *.hypstarcdn.com *.tiktokcdn.com *.topbuzzcdn.com *.lemocamcdn.com *.musical.ly *.muscdn.com *.ulikecam.mobi *.faceu.mobi *.wukongwenda.com *.wukongwenda.cn *.toutiao13.com *.toutiaoribao.cn *.ribaoapi.com *.dongchediapp.com *.huoshanzhibo.com *.huoshanxiaoshipin.cn *.huoshanxiaoshipin.net *.huoshanvideo.cn *.huoshanvideo.net *.ieshuodong.cn *.ieshuodong.net *.byteoversea.com *.topbuzz.com *.hypstar.com *.tiktokv.com *.byted.org *.bytedance.net *.bytedance.com *.bytedance.cn *.toutiaocloud.com *.snssdk.com *.toutiao.com *.neihanshequ.com *.wukong.com *.huoshan.com *.douyin.com *.everphoto.cn *.jinritemai.com *.tuchong.com *.stock.tuchong.com *.luckycalendar.cn *.bcy.net *.feishu.cn *.dcdapp.com *.oceanengine.com *.chengzijianzhan.com *.byteimg.com *.google-analytics.com 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.rollingstone.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 frame-ancestors 'self' https://*.webflow.com https://webflow.com https://app.intellimize.com; report-uri https://webflow.report-uri.com/r/t/csp/reportOnly 1 default-src https: 'self' data: blob:; script-src https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'self' 'unsafe-inline' blob:; report-uri https://services.fandom.com/csp-logger/csp/upstream 1 default-src 'self'; script-src 'self' https://*.posthog.com https://www.youtube.com https://fast.wistia.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://*.posthog.com https://res.cloudinary.com https://www.gravatar.com https://raw.githubusercontent.com https://obuldanrptloktxcffvn.supabase.co https://cdn.shopify.com https://i.ytimg.com https://embed-ssl.wistia.com https://fast.wistia.com https://cdn.jsdelivr.net https://user-images.githubusercontent.com https://brandbadge.clearbit.com; font-src 'self' data: https://d27nj4tzr3d5tm.cloudfront.net https://res.cloudinary.com https://fonts.gstatic.com https://r2cdn.perplexity.ai https://fast.wistia.com https://use.typekit.net; connect-src 'self' https://*.posthog.com https://api.github.com https://lottie.host https://better-animal-d658c56969.strapiapp.com https://forms.default.com https://posthog.myshopify.com https://*.algolia.net https://*.algolianet.com https://api.io.inkeep.com https://fast.wistia.net https://fast.wistia.com https://embed-cloudfront.wistia.com https://api.inkeep.com; media-src 'self' https://d1hovhsvet4m1p.cloudfront.net https://res.cloudinary.com blob:; frame-src 'self' https://www.youtube-nocookie.com https://hogwars.vercel.app https://hedgehog-mode-playground.vercel.app; worker-src 'self' blob:; child-src 'self' blob:; object-src 'none'; frame-ancestors 'none'; report-uri https://us.i.posthog.com/report/?token=sTMFPsFhdP1Ssg&sample_rate=0.1&v=1; report-to posthog 1 frame-ancestors 'self'; report-uri https://www.news.com.au/csp-reports 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-I39kIRAHyrla8e9KUBvA6Q'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-I39kIRAHyrla8e9KUBvA6Q'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' 1 script-src 'nonce-06d84cb1e006465f8a1b6962125b989f' 'strict-dynamic' 'wasm-unsafe-eval' 'unsafe-eval' *.bdxiguastatic.com *.bytescm.com *.bytetos.com *.toutiao.com *.ibytedapm.com bdxiguastatic.com *.bytegoofy.com;img-src blob: data: *.douyinstatic.com *.toutiaoimg.com *.bdxiguastatic.com *.bdxiguaimg.com *.bytexservice.com *.bytednsdoc.com *.douyinpic.com *.byteeffecttos.com *.byteacctimg.com *.byteimg.com *.bytecdn.cn http: *.ixigua.com *.itoutiaoimg.com *.toutiaostatic.com s.360.cn *.bytescm.com *.byted.org pos.baidu.com www.gstatic.com jonypractic.net wx.qlogo.cn;report-to slardar-endpoint;style-src blob: 'self' pwm-image.trendmicro.com www.gstatic.com cdn.jsdelivr.net plugin.newmorehot.com *.bytedance.net lib.baomitu.com *.bdxiguastatic.com 'unsafe-inline';manifest-src *.bytednsdoc.com;frame-src wo.laiwoshop.com pwm-image.trendmicro.com a.safen100.com c.safen110.com m.youtube.com code.woqrcode.com api.xiaoduis.com *.ixigua.com cdn.hunong.xyz cha.chaweather.com cx.chacizus.com v2.maoyinews.xyz *.summer5188.com tj.shshinfo.com www.mgtv.com vip.zhanyangsh.cn; 1 default-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-FOtf8bijWxP8KR/hsg+p2A==' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; style-src 'self' 'unsafe-inline' *.typeform.com; connect-src 'self' https://cdn.ampproject.org https://consent.bumble.com https://www.googletagmanager.com *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com/pagead *.googlesyndication.com *.typeform.com *.typeformcdn.com; child-src 'self'; font-src 'self' data:; manifest-src 'self'; base-uri 'self'; frame-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; img-src * data: blob: www.googletagmanager.com; media-src * data: blob:; report-uri /jss/csp_report.phtml?token=bumble_team_site&env=production; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' hubspot.mintlify.dev app.hubspot.com cdn-3.convertexperiments.com cdnjs.cloudflare.com connect.facebook.net cta-service-cms2.hubspot.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com platform.twitter.com play.vidyard.com run.pstmn.io script.crazyegg.com script.hotjar.com static.hotjar.com static.hsappstatic.net use.typekit.net www.googletagmanager.com www.google-analytics.com www.hubspot.com 'strict-dynamic' 'nonce-UdWGgNbUodKSxhDXpzESsQ=='; report-uri https://send.hsbrowserreports.com/csp/report 1 script-src https://accounts.google.com/gsi/client; frame-src https://accounts.google.com/gsi/; connect-src https://accounts.google.com/gsi/; 1 default-src 'self'; base-uri 'self'; font-src 'self' fonts.gstatic.com *.atlassian.com data:; worker-src blob:; media-src 'self' api.media.atlassian.com *.atlassian.com; img-src data: blob: 'self' *.badgen.net *.youtube.com atlassian.wpengine.netdna-cdn.com global.discourse-cdn.com img.shields.io *.atlassian.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat www.gstatic.com *.wp.com cdn.cookielaw.org *.clicktale.net *.doubleclick.net https://googleads.g.doubleclick.net images.ctfassets.net *.public.atl-paas.net trello.com trello-backgrounds.s3.amazonaws.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.co.in *.google.com *.atlassian.com *.gravatar.com; frame-src 'self' *.atlassian.com *.atl-paas.net *.googletagmanager.com player.vimeo.com trello.com www.youtube.com www.figma.com; connect-src 'self' *.googletagmanager.com *.algolianet.com *.algolia.net *.clicktale.net *.launchdarkly.com *.trello.com *.doubleclick.net *.qualtrics.com *.onetrust.com *.sentry.io cdn.segment.com api.segment.io www.google-analytics.com cdn.cookielaw.org *.atlassian.com *.algolia.io *.google.com; report-uri https://web-security-reports.services.atlassian.com/csp-report/dac; object-src 'none'; style-src 'self' *.trellocdn.com *.atlassian.com 'unsafe-inline'; script-src 'nonce-2EdPDbrJmA+SJqUOqG4qpCCZpYDRshL7PIAucMpFkRY=' 'self' 'sha256-Nt9ereHaxV04RZ20OLtdR3uuFr1X0/Pbt5KbGls/wXg=' https://www.googleadservices.com https://player.vimeo.com/api/player.js *.segment.com *.clicktale.net mscgen.js.org *.qualtrics.com *.trellocdn.com *.atlassian.com www.googletagmanager.com www.google-analytics.com https://cdn.cookielaw.org https://cdn.jsdelivr.net/npm/search-insights@2.2.1 https://run.pstmn.io/button.js *.atl-paas.net https://srm.bf.contentsquare.net/exist 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-Ubw4NnJXfXhnfHn36rokXA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self' data: blob: https://067-umd-991.mktoresp.com https://accounts.google.com https://analytics.google.com https://api.amplitude.com https://bi-beta.pst.tech https://bi.pst.tech https://bifrost-https-v4.gw.postman.com https://blog.postman.com https://dl.pstmn.io https://eo2kpuahxhuvgexlueall7gqzq0fihon.lambda-url.us-east-1.on.aws https://events.gw.postman.com https://events.rm-api.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://identity.getpostman-beta.com https://identity.getpostman.com https://lp.postman.com https://munchkin.marketo.net https://pages.getpostman.com https://public.slidesharecdn.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://manifest.webmanifest https://ms1frkqnsp7r.statuspage.io https://run.pstmn.io https://script.hotjar.com https://skills-assets.pstmn.io https://st-ar.cdn.postman.com https://static.cloudflareinsights.com https://static.hotjar.com https://stats.g.doubleclick.net https://td.doubleclick.net https://vc.hotjar.io https://voyager.postman.com https://web.postman.com https://www.googletagmanager.com https://www.slideshare.net https://snap.licdn.com https://www.google.com https://www.youtube.com https://youtube.com https://www.linkedin.com/px/ https://www.postman.com https://snap.licdn.com/ https://i.ytimg.com https://worldtimeapi.org https://maps.google.com https://dx.mountain.com https://px.mountain.com https://gs.mountain.com https://44.238.122.172 https://100.20.58.101 https://35.85.84.151 https://44.228.85.26 https://34.215.155.61 https://35.160.46.251 https://52.71.121.170 https://18.210.229.244 https://44.212.189.233 https://3.212.39.155 https://52.22.50.55 https://54.156.2.105 https://bam.nr-data.net https://js-agent.newrelic.com https://res.cloudinary.com https://mkt.cdn.postman.com https://api.mapbox.com https://events.mapbox.com https://api.fpjs.io https://cdn.amplitude.com https://api2.amplitude.com https://www.facebook.com https://connect.facebook.net https://bat.bing.com https://js.qualified.com wss://ws.qualified.com wss://ws2.qualified.com https://app.qualified.com https://api.company-target.com https://segments.company-target.com https://tag.demandbase.com https://tag-logger.demandbase.com https://s.company-target.com https://alb.reddit.com https://www.redditstatic.com https://pixel-config.reddit.com https://content.hotjar.io https://script.hotjar.com https://static.hotjar.com wss://ws.hotjar.com https://cdn.segment.com https://api.cdp.postman.com https://api.segment.io https://evs.cdp.postman.com https://www.influ2.com https://t.influ2.com https://a.usbrowserspeed.com https://pxl.growth-channel.net https://tags.srv.stackadapt.com https://job-boards.greenhouse.io https://transcend-cdn.com https://telemetry.us.transcend.io https://unpkg.com/launchdarkly-js-client-sdk@3.8.1 https://app.launchdarkly.com/ https://events.launchdarkly.com https://tally.so/ https://postman.outgrow.us/ https://api-n.outgrow.co https://t.co/ https://analytics.twitter.com https://static.ads-twitter.com/uwt.js https://id.rlcdn.com https://cdn.cr-relay.com https://accretivemedia.go2cloud.org https://fast.wistia.net https://fast.wistia.com https://embed-ssl.wistia.com https://distillery.wistia.com https://pipedream.wistia.com https://embed-cloudfront.wistia.com https://postman.cdn.prismic.io https://static.cdn.prismic.io https://postman.prismic.io https://browser.sentry-cdn.com 'unsafe-inline' 'unsafe-eval'; form-action 'self'; base-uri 'self'; 1 script-src 'self' https: https://www.google-analytics.com https://cdn.amplitude.com 'unsafe-eval' 'unsafe-inline' data: 'nonce-icAYyImAreSs3b1hnK5LgA=='; worker-src blob: data:; report-uri https://us.sentry.io/api/4506690010480640/security/?sentry_key=aab2498373841041d6b48d721aefbdc1&sentry_environment=production&sentry_release=65deeb3f2dabb2b4bfe610722dc106d146560985 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.billboard.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 script-src https://www.airtable.com https://airtable-marketing.herokuapp.com https://airtable.com https://static.airtable.com/ 'unsafe-eval' 'unsafe-inline' 'report-sample' https: blob:; style-src 'unsafe-inline' https:; block-all-mixed-content; object-src //pages.airtable.com; base-uri 'none'; report-uri https://airtable.com/.csp/report 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-A7ikOYpGDPe9oPjsB1QsrQ=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 script-src 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' 'strict-dynamic' 'nonce-lL4n5TNfkqqSs6VDPIK2-' *.bytescm.com *.bytednsdoc.com *.ibytedapm.com *.snssdk.com *.yhgfb-cn-static.com *.bytetos.com *.byte-gslb.com *.bytegoofy.com *.bytecdn.cn *.toutiaostatic.com;style-src 'self' 'unsafe-inline' *.toutiaoimg.com *.bdxiguaimg.com *.bytescm.com *.bytegoofy.com *.douyinstatic.com *.toutiao.com *.toutiaostatic.com *.bytedance.net cdn.bootcss.com;connect-src 'self' wss: ws: data: blob: http://localhost:* toutiao.govwza.cn *.bytedance.net *.bytedance.com *.snssdk.com *.toutiaostatic.com *.bytescm.com *.toutiao.com *.bytetcc.com *.zijieapi.com *.yhgfb-cn-static.com *.toutiaovod.com *.bytednsdoc.com *.ibytedapm.com *.bytedanceapi.com *.google-analytics.com *.douyinstatic.com *.douyinvod.com *.bytegoofy.com *.bytetos.com *.toutiaoimg.com *.huoshanstatic.com *.idouyinvod.com:* *.volcsiriusbd.com:* *.volcsirius.com:* *.tt.x.bsgslb.cn:* *.dy.zzcdnx.com:* *.qc.bsccdn.net:* *.smtcdns.com:* *.ugslb.com:* *.livehwc3.cn:* *.smtcdns.net:* *.bytefcdnrd.com:* *.ksyungslb.com:* *.ksyungslb2.com:* *.ourdvsss.com:* *.tbcache.com:* *.jomodns.com:* *.douyincdn.com:* *.ixigua.com:* *.bdxigualive.com:* *.pstatp.com:* *.douyinliving.com:* *.picovr.com:* *.huoshanlive.com:* *.ihuoshanlive.com:* *.volccdn.com:* *.bestv.com.cn:* *.bytefcdn.com:* *.qnqcdn.net:* *.jomoxc.com *.jomoxd.com *.a.bdycdn.cn *.hiecheimaetu.com:* *.ppio.cloud:* *.weilayun.com:* *.saxysec.com:* *.saxyit.com:* *.saxydc.com:* *.sjxysec.com:* *.sjxydc.com:* *.vegslb.com:*;upgrade-insecure-requests;frame-ancestors 'self' *.bytedance.net *.snssdk.com shiqu.cn *.shiqu.cn zhan.vivo.com wukong.vivo.com.cn *.feishuapp.cn *.toutiao.com *.bytescm.com *.jiyunhudong.com *.bytedance.com *.feishu.cn;report-uri https://mon.zijieapi.com/log/sentry/v2/api/slardar/main/?ev_type=csp&bid=toutiao_web_pc;report-to main-endpoint 1 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 default-src * 'unsafe-eval' 'unsafe-inline' blob: data:;frame-src 'self' sinaweibo: weibo.com *.weibo.com weibo.cn *.weibo.cn sina.com.cn *.sina.com.cn sina.cn *.sina.cn *.sinaimg.cn sinanews: sinanewslite: intent: se5bed38c567feb2a: sb5750862870e1cc2: sdc77698a60e45368: sb2623a3919ed77d3: s3d4cfbed31875e1c: sc876cbd9ae34e814: sdf08f19582289581: sc640c3792845ba3e: se8525a4dbfaa192b: sb5261983836bde16: sinablog: sinanewapmwebview: sinanewsdirect: sinafinance:; script-src 'self' 'unsafe-inline' 'unsafe-eval' weibo.com *.weibo.com weibo.cn *.weibo.cn sina.com.cn *.sina.com.cn sina.cn *.sina.cn *.sinaimg.cn *.qchannel03.cn *.qihucdn.com *.qhres.com *.sinajs.cn *.leju.com *.qq.com qzonestyle.gtimg.cn; report-uri https://logger.sina.cn/report; 1 base-uri 'self';connect-src 'self' https: https://www.recaptcha.net https://challenges.cloudflare.com wss:;default-src 'self' https: wss: blob: data:;form-action 'self' https:;img-src 'self' https: http://iea.imgix.net https://iea.imgix.net data:;media-src 'self' https: data: http://iea.imgix.net https://iea.imgix.net;object-src 'none';script-src 'self' 'unsafe-eval' https://www.google.com https://www.googletagmanager.com https://www.youtube.com https://www.google-analytics.com https://www.recaptcha.net https://challenges.cloudflare.com https://snap.licdn.com https://www.gstatic.com https://stats.g.doubleclick.net https://p.adsymptotic.com https://px.ads.linkedin.com 'sha256-l/3fcn6MZG0SSVJq6fOLe49ZKIjbWdNzhreJz7KQ/1M=' 'sha256-+MedjqNIfWWYUGuHJ53XLEjzmGDCp9Om50MVUO/C/zo=' https://ieatest.blob.core.windows.net https://iea.blob.core.windows.net 'nonce-W3K1mSZVTWShG7pW6APSrOByR1hglCVO';style-src 'self' https: 'unsafe-inline';worker-src https://ieatest.blob.core.windows.net https://iea.blob.core.windows.net;frame-ancestors 'self' 1 report-to slardar-endpoint; upgrade-insecure-requests ; frame-ancestors 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com chrome-extension://dbjibobgilijgolhjdcbdebjhejelffo chrome-extension://molcibnmfbjmmfbefjfcafdeabfniobi chrome-extension://capohkkfagimodmlpnahjoijgooocdjhd chrome-extension://mijalhmcgaaaggjfhkliffkanfhimhch chrome-extension://obkcimipmjdkghadnfcjojepocldeggd chrome-extension://epjhdbhhoeemcbbbgkimcfndcbjapdaa safari-web-extension:; script-src 'nonce-5246fb0729ab4aca62b02711d2d2091f-argus' blob: data: 'self' 'unsafe-eval' 'report-sample' 'strict-dynamic' 'unsafe-inline' https:; base-uri 'self'; object-src 'self'; frame-src 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com;report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web; 1 default-src 'self' data: https: blob:; img-src 'self' data: https: http: blob:; script-src 'self' 'nonce-BE5AD328D2E83A99EE1779411F9D0C16643595D9A2A6A8A74470F7EEC6521C34' *.enable-now.cloud.sap *.salesforceliveagent.com *.siteintercept.qualtrics.com *.walkme.com *.liveperson.net *.ssl.ak.dynamic.tiles.virtualearth.net *.concursolutions.com *.sapdas-staging.cloud.sap *.sapdas.cloud.sap code.jquery.com consent.trustarc.com dev.virtualearth.net storage.glancecdn.net www.glancecdn.net www.google-analytics.com assets.adobedtm.com bam.nr-data.net maps.googleapis.com www.google-analytics.com www.googletagmanager.com siteintercept.qualtrics.com ajax.googleapis.com static.contextall.com *.bing.com www.vfmii.com blob:; style-src 'self' 'unsafe-inline' https: blob:; connect-src wss://*.glance.net 'self' https:; report-uri https://concursolutions.report-uri.com/r/t/csp/reportOnly; report-to report-only; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv5%3F.cuai%7F-19b29e99171-0x2603#pd 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/chrome 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.stripe.com https://*.paddle.com https://www.google.com https://www.gstatic.com https://maps.gstatic.com https://maps.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'self' 'unsafe-inline' https://*.paddle.com https://fonts.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://ipapi.co https://maps.gstatic.com https://maps.googleapis.com https://*.stripe.com; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com; frame-src 'self' https://www.google.com https://*.stripe.com https://*.paddle.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://ipapi.co/ https://*.paddle.com https://*.stripe.com https://maps.googleapis.com https://www.google.com/recaptcha/; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; 1 default-src * 'self' data: blob: 'unsafe-inline' 'unsafe-eval'; report-uri /csp-report-endpoint; 1 require-trusted-types-for 'script';report-uri /us/_/ThinkWithGoogle/cspreport 1 object-src 'none'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.kolesa.kz https://kolesa.kz wss://*.kolesa.kz https://sentry-common.kolesa.team yastatic.net *.adfox.ru *.yandex.ru *.yandex.net *.yandex.kz *.yandex.com yandex.ru yandex.kz yandex.com yandexadexchange.net *.ftd.agency *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.google.kz *.google.co.uz *.googlesyndication.com *.googleadservices.com *.gstatic.com *.ampproject.org *.segmentstream.com *.facebook.net *.facebook.com *.tiktok.com *.youtube.com; report-to csp-endpoint 1 base-uri 'none'; default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://cdn.heapanalytics.com https://distillery.wistia.com/x https://matillion.ddev.site:3000/ wss://matillion.ddev.site:3000 https://fast.wistia.com https://www.googletagmanager.com https://cdn.heapanalytics.com/js/heap-1873293713.js https://cdn.iubenda.com/cs/iubenda_cs.js https://connect.facebook.net/en_US/fbevents.js https://content.cdntwrk.com/components/website-widget/v1/118604/widget.js https://fast.wistia.com/assets/external/E-v1.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/848565924/ https://in.ml314.com/ud.ashx https://js.driftt.com/include/1688577300000/vh948h8ntehg.js https://js.intercomcdn.com/vendor-modern.255c4d36.js https://lift-ai-js.marketlinc.com/www.matillion.com/deployment.js https://ml314.com/tag.aspx https://munchkin.marketo.net/munchkin.js https://okt.to/ping https://pages.matillion.com/js/forms2/js/forms2.min.js https://script.hotjar.com/modules.832d10fb416834285523.js https://snap.licdn.com/li.lms-analytics/insight.beta.min.js https://static.ads-twitter.com/uwt.js https://static.hotjar.com/c/hotjar-2386626.js https://static.oktopost.com/oktrk.js https://tag.demandbase.com/00a4b81bfa345e5b.min.js https://tracking.g2crowd.com/attribution_tracking/conversions/5351.js https://widget.intercom.io/widget/rjk6vrpn https://www.google-analytics.com/analytics.js https://www.googleadservices.com/pagead/conversion/848565924/ https://www.googletagmanager.com/gtag/js https://www.iubenda.com/cookie-solution/confs/js/48216078.js https://www.redditstatic.com/ads/pixel.js; style-src 'self' 'unsafe-inline' https://p.typekit.net https://pages.matillion.com https://use.typekit.net; img-src 'self' data: 'self' data: https://alb.reddit.com https://analytics.twitter.com https://embed-ssl.wistia.com https://fast.wistia.com https://googleads.g.doubleclick.net https://heapanalytics.com https://id.rlcdn.com https://insight.adsrvr.org https://pubads.g.doubleclick.net https://px.ads.linkedin.com https://t.co https://www.facebook.com https://www.google-analytics.com https://www.google.com; connect-src 'self' https://992-uiw-731.mktoresp.com https://analytics.google.com https://api-iam.intercom.io https://api.company-target.com https://content.hotjar.io https://distillery.wistia.com https://fast.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io https://google.com https://hits-i.iubenda.com https://in.hotjar.com https://metrics.hotjar.io https://stats.g.doubleclick.net https://tag-logger.demandbase.com https://v2.api.uberflip.com https://visitor-scoring-c.marketlinc.com https://www.google-analytics.com https://www.google.com wss://nexus-websocket-a.intercom.io wss://ws.hotjar.com; font-src 'self' 'self' data: https://fast.wistia.com https://use.typekit.net; media-src 'self' blob:; frame-src 'self' 'self' https://12420912.fls.doubleclick.net https://js.driftt.com https://pages.matillion.com https://s.company-target.com https://www.facebook.com; 1 script-src 'nonce-yaOzhfU4YCf/lM2/Dkom4g==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=dd9780d5-144c-460b-9077-d86ea9d9ad4c; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 script-src 'nonce-sVtqdPfRRxY6CB83+Alb0A==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=76cb042b-4a42-4fad-9071-0fed9c23439d; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 base-uri 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://climate.stripe.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://sales-live-chat.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com https://y4pfttj91h-1.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-2.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-3.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-dsn.algolia.net/1/indexes/mkt_partners/query https://tax-connectors.stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://climate.stripe.com https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://checkout.stripe.dev https://support-conversations.stripe.com https://b.stripecdn.com https://checkout.stripe.com https://crypto-js.stripe.com https://js.stripe.com https://sales-live-chat.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com https://stripe-camo.global.ssl.fastly.net 'self'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; script-src https://b.stripecdn.com https://crypto-js.stripe.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src 'none'; report-uri https://q.stripe.com/csp-violation?q=9VQZUMuDujHmHMFVdqbvva2VGDhq0f0vKfMLZQYfVQvhMjIqc2KXQX8KAozVYyA%3D 1 default-src 'self' *.iheartmedia.com data: blob: https:; img-src 'self' data: https:; font-src https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; frame-src 'self' data: https:; child-src https:; media-src https:; object-src 'none'; connect-src 'self' wss: https:; report-uri https://csp.qw.iheartmedia.com/api/report 1 base-uri 'self'; connect-src https: wss: blob:; default-src 'none'; font-src https: data:; frame-src https: blob:; img-src https: data: blob:; manifest-src 'self'; media-src https:; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://api.compass.com https://app-glide.compass.com https://cdn.heapanalytics.com https://heapanalytics.com https://cdn.segment.com https://connect.facebook.net https://edge.fullstory.com/s/ https://maps.googleapis.com/maps/api/js/ https://static.zdassets.com/ekr/snippet.js https://static.filestackapi.com https://web-sdk.aptrinsic.com/api/aptrinsic.js https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com/recaptcha/ https://maps.googleapis.com https://apis.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.stripe.com https://stats.pusher.com https://widget.intercom.io https://js.intercomcdn.com https://boards.greenhouse.io https://siteintercept.qualtrics.com https://zn0feyon15oqdwcu1-compass.siteintercept.qualtrics.com https://www.youtube.com https://googleads.g.doubleclick.net https://snap.licdn.com https://js.hubspot.com https://js.hs-analytics.net https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-banner.com https://fast.wistia.com https://js.userpilot.io https://deploy.userpilot.io https://t.contentsquare.net https://api.compass.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn.jsdelivr.net https://code.jquery.com; script-src-elem 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://api.compass.com https://app-glide.compass.com https://cdn.heapanalytics.com https://heapanalytics.com https://cdn.segment.com https://connect.facebook.net https://edge.fullstory.com/s/ https://maps.googleapis.com/maps/api/js/ https://static.zdassets.com/ekr/snippet.js https://static.filestackapi.com https://web-sdk.aptrinsic.com/api/aptrinsic.js https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com/recaptcha/ https://maps.googleapis.com https://apis.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.stripe.com https://stats.pusher.com https://widget.intercom.io https://js.intercomcdn.com https://boards.greenhouse.io https://siteintercept.qualtrics.com https://zn0feyon15oqdwcu1-compass.siteintercept.qualtrics.com https://www.youtube.com https://googleads.g.doubleclick.net https://snap.licdn.com https://js.hubspot.com https://js.hs-analytics.net https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-banner.com https://fast.wistia.com https://js.userpilot.io https://deploy.userpilot.io https://t.contentsquare.net https://api.compass.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn.jsdelivr.net https://code.jquery.com; style-src 'report-sample' 'self' 'unsafe-inline' https://uc-frontend-assets.compass.com https://app-glide.compass.com https://www.google-analytics.com https://www.googletagmanager.com https://fonts.googleapis.com https://static.filestackapi.com https://web-sdk.aptrinsic.com https://www.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://unpkg.com blob:; worker-src 'self' blob:; report-uri /csp-report/?key=new 1 frame-ancestors 'none'; object-src 'none'; report-to https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub5b9d250bbda65cde913b47e33482ee7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aprod%2Cservice%3Aameno%2Cversion%3Abrlm_1.55.0; 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.googleadservices.com/pagead/conversion/ https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.google.com/js/bg/ https://www.gstatic.com/external_hosted/highlightjs/highlight.pack.js https://www.gstatic.com/monaco_editor/ https://fonts.gstatic.com/s/e/notoemoji/search/wrapper.js https://www.youtube.com/iframe_api https://translate.google.com/translate_a/element.js https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://maps.googleapis.com/maps/api/js https://www.gstatic.com/_/mss/boq-bard-web/_/js/k=boq-bard-web.BardChatUi.en_US.axjNXIO864s.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://maps.googleapis.com/maps-api-v3/api/js/ https://maps.googleapis.com/maps/vt https://maps.googleapis.com/maps/api/js/ https://maps.googleapis.com/maps/api/place/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/;report-uri /_/BardChatUi/cspreport/fine-allowlist 1 object-src 'none'; script-src 'self' 'report-sample' addtocalendar.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.knightlab.com https://cdnjs.cloudflare.com https://code.jquery.com https://science-catalog.fws.gov https://touchpoints.app.cloud.gov https://unpkg.com https://www.google.com maps.google.com unpkg.com; style-src 'self' 'report-sample' addtocalendar.com cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdn.knightlab.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://science-catalog.fws.gov https://unpkg.com unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 report-uri https://bringatrailer.report-uri.com/r/t/csp/wizard; base-uri 'self'; default-src 'self'; object-src 'none'; frame-ancestors 'none'; img-src 'self' data: https:; worker-src 'self' blob:; connect-src 'self' https: wss: *.doubleclick.net *.googlesyndication.com geolocation.onetrust.com *.stripe.com *.carfax.com; font-src 'self' data: https://fonts.gstatic.com *.wp.com; frame-src 'self' *.stripe.com *.google.com *.gstatic.com *.youtube.com *.youtube-nocookie.com *.vimeo.com *.flickr.com anchor.fm *.spotify.com *.facebook.com castbox.fm *.apple.com *.runbuggy.com *.onetrust.com *.googlesyndication.com *.doubleclick.net *.google-analytics.com *.adtrafficquality.google *.googleadservices.com *.googletagservices.com *.nr-data.net *.newrelic.com *.googletagmanager.com *.facebook.net *.reddit.com *.adsrvr.org *.innovid.com *.tvsquared.com *.stackadapt.com *.carfax.com; script-src 'nonce-xTTD8WqdFJJnJruuBvrOeg==' 'self' 'strict-dynamic' https://www.googletagmanager.com https://www.google-analytics.com https://js.stripe.com https://securepubads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.com https://www.gstatic.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com *.carfax.com *.hearstapps.com; style-src 'nonce-xTTD8WqdFJJnJruuBvrOeg==' 'self' 'sha256-wG10yjQtjomBxjug4y0XNRthbI89DiUxvDkjYcwyBc8=' 'sha256-6dWhdPqTY6pr0lbgV8vfUDIIH216YiDXS7ai8drnM5A=' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-OTeu7NEHDo6qutIWo0F2TmYrDhsKWCzrUgGoxxHGJ8o=' 'sha256-yTCJFvBsJ3q3wf4Dk4paMpnG1N2ABmaPEXkImUtBFdM=' 'sha256-0I2+3P72yyXJiuT4aoTemWk6gyVi6LnLMHXZrBx3gpY=' https://fonts.googleapis.com *.hearstapps.com; style-src-attr 'unsafe-inline' 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.indiewire.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-5AOmaHykyoUQlv/ngWZZ0A=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src *; script-src 'self' 'unsafe-inline' 'unsafe-eval' report-sample https://cse.google.com https://video.ku.dk https://script.hotjar.com https://connect.facebook.net https://w.usabilla.com https://ss.studier.ku.dk https://app.certainly.io https://kumain.containers.piwik.pro https://policy.app.cookieinformation.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://tile.openstreetmap.org https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google.com https://www.google.fr https://clients1.google.com https://www.facebook.com https://ss.studies.ku.dk https://region1.analytics.google.com https://tr.snapchat.com https://adm.piwik.pro https://kumain.piwik.pro https://syndicatedsearch.goog https://*.adtrafficquality.google; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com video.ku.dk https://*.cloudfront.net https://app.certainly.io https://www.survey-xact.dk https://www.google.com https://pinecast.com https://syndicatedsearch.goog https://policy.app.cookieinformation.com https://facebook.com https://www.facebook.com https://ss.studier.ku.dk https://ss.studies.ku.dk https://tr.snapchat.com https://*.adtrafficquality.google; style-src-elem 'self' https://cdnjs.cloudflare.com https://www.google.com https://app.certainly.io/sdk/webchat.js 'unsafe-inline' 'report-sample'; script-src-elem 'self' 'unsafe-inline' https://app.certainly.io https://cdnjs.cloudflare.com https://kumain.containers.piwik.pro https://w.usabilla.com https://ss.studier.ku.dk https://ss.studies.ku.dk https://www.google.com https://cse.google.com https://policy.app.cookieinformation.com https://script.hotjar.com https://static.hotjar.com https://connect.facebook.net https://sc-static.net https://tr.snapchat.com https://script.crazyegg.com https://video.ku.dk https://*.adtrafficquality.google 'report-sample'; font-src data: 'self' https://fonts.gstatic.com; connect-src * https://app.certainly.io https://kumain.containers.piwik.pro; report-uri https://www.ku.dk/@http-reporting?csp=report&requestTime=1765896561787109&requestHash=968db75ee7092183b94ba64be48af0f40fb4cd6d 1 default-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' tanki.su *.tanki.su lesta.ru *.lesta.ru *.tvsquared.com *.soloway.ru *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.edgevideo.ru https://image.sendsay.ru https://top-fwz1.mail.ru https://privacy-cs.mail.ru https://vk.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://*.adform.net https://www.googleoptimize.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://*.yandex.ru https://*.yandex.net https://*.yandex.ua https://*.yandex.by https://*.yandex.kz https://*.yandex.com.tr http://*.yandex.ru http://*.yandex.net http://*.yandex.ua http://*.yandex.by http://*.yandex.kz http://*.yandex.com.tr https://*.yandex.st https://*.yandex.com https://*.yandex.fr https://yandex.st https://u360.d-bi.fr https://bat.bing.com https://connect.ok.ru https://*.vk.com https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.vihub.ru https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://inv-dmp.admixer.net ; style-src 'self' 'unsafe-inline' lesta.ru *.lesta.ru tanki.su *.tanki.su https://fonts.googleapis.com ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com https://privacy-cs.mail.ru https://sendsay.ru https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://lesta.ru wss://tanki.su wss://*.lstprod.net https://stats.g.doubleclick.net https://*.yandex.ru https://*.yandex.net https://*.yandex.ua https://*.yandex.by https://*.yandex.kz https://*.yandex.com.tr http://*.yandex.ru http://*.yandex.net http://*.yandex.ua http://*.yandex.by http://*.yandex.kz http://*.yandex.com.tr https://*.yandex.st https://*.yandex.com https://*.yandex.fr https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.ru https://google.com.ua https://google.by https://www.googleoptimize.com https://google.pl https://*.doubleclick.net https://*.googleapis.com ; font-src 'self' lesta.ru *.lesta.ru *.tanki.su https://fonts.gstatic.com ; media-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru ; frame-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://*.yandex.ru https://webwisor.com https://metrika.yandex.ru https://metrika.yandex.by https://metrica.yandex.com https://metrica.yandex.com.tr https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://ad3.adfarm1.adition.com https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://yastatic.net https://*.addthis.com https://gleam.io https://aax-eu.amazon-adsystem.com ; frame-ancestors 'self' https://webwisor.com https://metrika.yandex.ru https://metrika.yandex.by https://metrica.yandex.com https://metrica.yandex.com.tr ; object-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://www.youtube.com ; report-uri https://cspreport.lesta.ru/cspreport 1 script-src 'strict-dynamic' 'self' https: 'nonce-9dd256b89d34ee8fc41bb858ffc5cba4762d3a7a'; script-src-elem 'self' 'nonce-9dd256b89d34ee8fc41bb858ffc5cba4762d3a7a'; object-src 'none'; base-uri 'none'; report-to csp-report; frame-ancestors 'self' 1 default-src bam.nr-data.net cdn.growthbook.io cdn-ukwest.onetrust.com geolocation.onetrust.com pagead2.googlesyndication.com privacyportal-uk.onetrust.com prod.global-fragments-server.green.which.co.uk tpc.googlesyndication.com *.safeframe.googlesyndication.com www.googletagmanager.com ep2.adtrafficquality.google which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk;script-src a.quora.com ajax.googleapis.com bat.bing.com c.amazon-adsystem.com cdn-magiclinks.trackonomics.net cdn-ukwest.onetrust.com cdn.amplitude.com cdn.jsdelivr.net connect.facebook.net ct.pinterest.com cdn.growthbook.io googleads.g.doubleclick.net manifest.prod.boltdns.net maps.googleapis.com pagead2.googlesyndication.com platform.twitter.com player.captivate.fm players.brightcove.net prod.global-fragments-server.green.which.co.uk public.flourish.studio pym.nprapps.org region1.google-analytics.com s.pinimg.com siteintercept.qualtrics.com static-ssl.responsetap.com static.ads-twitter.com static.digidip.net t.contentsquare.net tpc.googlesyndication.com track.omguk.com which.resultspage.com www.google-analytics.com www.googleadservices.com www.googletagmanager.com www.redditstatic.com yksbw1yr.micpn.com zeta-live.getsquirrel.co znbiyguoobqgm5gwu-which.siteintercept.qualtrics.com which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk 'nonce-6fd32596d82ade4373d594a692ef691076ff36fd2b684516763fa6f2e3255cd6';style-src aaf1a18515da0e792f78-c27fdabe952dfc357fe25ebf5c8897ee.ssl.cf5.rackcdn.com cdn.jsdelivr.net flo.uri.sh fonts.googleapis.com pagead2.googlesyndication.com player.captivate.fm public.flourish.studio service.force.com zeta-live.getsquirrel.co which.resultspage.com which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk;font-src fonts-which-co-uk.s3.amazonaws.com player.captivate.fm public.flourish.studio 'unsafe-inline' 'self' https://*.which.co.uk;img-src abs-0.twimg.com ad.doubleclick.net ade.googlesyndication.com adservice.google.com alb.reddit.com analytics.twitter.com artwork.captivate.fm bat.bing.com c.contentsquare.net cdn-ukwest.onetrust.com cf-images.eu-west-1.prod.boltdns.net ct.pinterest.com googleads.g.doubleclick.net house-fastly-signed-eu-west-1-prod.brightcovecdn.com maps.gstatic.com media.which.gpp.io metrics.brightcove.com pagead2.googlesyndication.com pbs.twimg.com q.quora.com s3-eu-west-1.amazonaws.com securepubads.g.doubleclick.net siteintercept.qualtrics.com storage.googleapis.com syndication.twitter.com t.co tpc.googlesyndication.com tracking.audio.thisisdax.com trx-hub.com www.facebook.com www.google-analytics.com www.google.co.uk www.google.com yksbw1yr.micpn.com ep1.adtrafficquality.google 'unsafe-inline' 'self' https://*.which.co.uk;connect-src region1.google-analytics.com which-group.my.salesforce-scrt.com cdn.growthbook.io cdn-ukwest.onetrust.com geolocation.onetrust.com pagead2.googlesyndication.com ep1.adtrafficquality.google ep2.adtrafficquality.google 'unsafe-inline' 'self' https://*.which.co.uk;base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none' 1 font-src *.fontawesome.com fonts.googleapis.com https://www.gstatic.com https://fonts.gstatic.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com *.weltpixel.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.doubleclick.net www.xtento.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com maps.googleapis.com maps.gstatic.com guarantee-cdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com get.geojs.io *.cloudflare.com guarantee-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'nonce-uMhdhb1bkHhbPSEpb8IH+LCYX9Cy31GAHSDeJUCtTv8=' 'strict-dynamic' https:; script-src 'nonce-uMhdhb1bkHhbPSEpb8IH+LCYX9Cy31GAHSDeJUCtTv8=' 'sha512-gU7kztaQEl7SHJyraPfZLQCNnrKdaQi5ndOyt4L4UPL/FHDd/uB9Je6KDARIqwnNNE27hnqoWLBq+Kpe4iHfeQ==' 'sha512-DXYctkkhmMYJ4vYp4Dm6jprD4ZareZ7ud/d9mGCKif/Dt3FnN95SjogHvwKvxXHoMAAkZX6EO6ePwpDIR1Y8jw==' 'sha512-mz4SrGyk+dtPY9MNYOMkD81gp8ajViZ4S0VDuM/Zqg40cg9xgIBYSiL5fN79Htbz4f2+uR9lrDO6mgcjM+NAXA==' 'sha512-pnt8OPBTOklRd4/iSW7msOiCVO4uvffF17Egr3c7AaN0h3qFnSu7L6UmdZJUCednMhhruTLRq7X9WbyAWNBegw==' 'strict-dynamic' https:; font-src 'self' https://res-1.cdn.office.net/files/fabric-cdn-prod_20221201.001/assets/fonts/ https://res-1.cdn.office.net/files/fabric-cdn-prod_20221201.001/assets/icons/ 'nonce-uMhdhb1bkHhbPSEpb8IH+LCYX9Cy31GAHSDeJUCtTv8='; base-uri 'none'; form-action 'self' 'nonce-uMhdhb1bkHhbPSEpb8IH+LCYX9Cy31GAHSDeJUCtTv8='; style-src 'self' 'nonce-uMhdhb1bkHhbPSEpb8IH+LCYX9Cy31GAHSDeJUCtTv8='; report-uri ; object-src 'none'; frame-ancestors 'none'; 1 connect-src 'self' *.cdn.content.amplience.net *.staging.bigcontent.io *.algolia.net direct-collect.dy-api.eu rcom-eu.dynamicyield.com st-eu.dynamicyield.com async-px-eu.dynamicyield.com direct.dy-api.eu *.algolianet.com *.worldline-solutions.com *.ingenico.com *.ideal-postcodes.co.uk *.criteo.com www.bing.com dev.virtualearth.net t.ssl.ak.dynamic.tiles.virtualearth.net insights.algolia.io *.scoota.co *.criteo.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net apps.bazaarvoice.com display.ugc.bazaarvoice.com stg.api.bazaarvoice.com static.cloudflareinsights.com staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com https://api-eu.jdadelivers.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com wss://collection.decibelinsight.net wss://cdn.decibelinsight.net *.digital-cloud.medallia.eu bam.nr-data.net ingressteam.cloudflareaccess.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com *.analytics.google.com www.google.com google.com api2.asda.com ghs-mm.asda.com; default-src 'self'; font-src 'self' fonts.gstatic.com; frame-src 'self' *; frame-ancestors 'self' *.amplience.net; img-src 'self' *.commercecloud.salesforce.com *.media.amplience.net data: asda.a.bigcontent.io asdagroceries.scene7.com *.assets-asda.com *.dynamicyield.com *.criteo.com retailmedia-static.azureedge.net staticassets-creator-design.criteo.net t.ssl.ak.dynamic.tiles.virtualearth.net www.bing.com *.scoota.co adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com analytics.tiktok.com region1.analytics.google.com www.google.co.uk fonts.gstatic.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com adservice.google.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com www.google.com google.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net gum.criteo.com x.bidswitch.net r.casalemedia.com cm.g.doubleclick.net secure.adnxs.com simage2.pubmatic.com pixel.rubiconproject.com sync-criteo.ads.yieldmo.com hb.yahoo.net sync-t1.taboola.com; media-src 'self' asdagroceries.scene7.com s7d2.scene7.com *.scoota.co static.criteo.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' apps.rokt.com storage.googleapis.com *.algolia.net cdn-eu.dynamicyield.com st-eu.dynamicyield.com *.worldline-solutions.com *.ingenico.com assets.adobedtm.com www.bing.com r.bing.com dev.virtualearth.net *.scoota.co asdagroceries.scene7.com ui.assets-asda.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net *.criteo.com *.hlserve.com apps.bazaarvoice.com display.ugc.bazaarvoice.com stg.api.bazaarvoice.com static.cloudflareinsights.com mpsnare.iesnare.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com blob: *.digital-cloud.medallia.eu staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com js-agent.newrelic.com ingressteam.cloudflareaccess.com www.googletagmanager.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com tagmanager.google.com googletagmanager.com *.googletagmanager.com www.google.com google.com haq81g6w.micpn.com migroceries.asda.com asda-promotions.co.uk api.bazaarvoice.com *.criteo.net; style-src 'self' https: 'unsafe-inline' *.bazaarvoice.com ssl.gstatic.com www.gstatic.com tagmanager.google.com fonts.googleapis.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=4AnLeU0swRM6V.ekW14E3Qv6BxO2VH13VM6vfhWdZGE-1765933205-1.0.1.1-pMmVTIZOWIxvkrVetlxhTv7rMsmY64Prfz0hUjbk1Ux995jXSBB0vO56zuGSjNRKQxjDOt3AXhmvQSivnJ1JcR.q1fZ_dhL65VfsLhH8tXXbvzD5b94zg9I.5p1jC0hPZALbWpGnYdjFgpR1L6kt_jQGjIKSTakDKMkM1kULt_Zh5v74xG89qb0Tjo0QZOdBnAafCMdUXvTq7tGAK9X7FA; report-to cf-egymywzzndewahdo 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/about_google 1 base-uri 'self'; connect-src 'self' https://*.clarity.ms/collect https://*.google-analytics.com/g/collect https://ad.doubleclick.net https://amplify.outbrain.com https://analytics.google.com https://analytics.tiktok.com https://api.segment.io https://aplo-evnt.com https://bat.bing.com https://bat.bing.net https://browser-intake-datadoghq.eu https://cdn.segment.com https://content.hotjar.io https://conversions-config.reddit.com https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://graphql.contentful.com https://id.sage.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://pagesense-collect.zoho.in https://pixel-config.reddit.com https://pixel.quantserve.com https://pixels.spotify.com https://postcodes.io https://privacyportal.cookiepro.com https://px.ads.linkedin.com https://rum-http-intake.logs.datadoghq.eu https://stats.g.doubleclick.net https://tide.api.kustomerapp.com https://tr.outbrain.com https://widget.trustpilot.com https://www.cloudflare.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.redditstatic.com https://z.clarity.ms; default-src 'none'; font-src 'self' https://cdn.kustomerapp.com https://fonts.gstatic.com https://web-assets.tide.co; frame-ancestors 'self' https://uniclient-demo.web.app; frame-src 'self' https://14663405.fls.doubleclick.net https://forms.zohopublic.in https://widget.trustpilot.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' https://ade.googlesyndication.com https://bat.bing.net https://c.clarity.ms https://cdn.prod2.kustomerhostedcontent.com https://downloads.ctfassets.net https://heapanalytics.com https://images.ctfassets.net https://impressions.onelink.me https://px.ads.linkedin.com/collect https://q.quora.com https://web-assets.tide.co https://www.facebook.com https://www.google.co.in https://www.google.com; manifest-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; report-to csp-reporting-endpoint; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd4258020965cc5258eee35ac618e9586&dd-evp-origin=content-security-policy&ddsource=csp-report; script-src 'self' 'unsafe-inline' https://a.quora.com https://amplify.outbrain.com https://analytics.tiktok.com/ https://assets.apollo.io/ https://bat.bing.com https://cdn-in.pagesense.io https://cdn.datatables.net https://cdn.heapanalytics.com https://cdn.jsdelivr.net https://cdn.kustomerapp.com https://cdn.segment.com/ https://cdnjs.cloudflare.com/ajax/libs/ https://code.jquery.com https://connect.facebook.net/ https://cookie-cdn.cookiepro.com/ https://d38xvr37kwwhcm.cloudfront.net https://geotargetly-api-2.com https://googleads.g.doubleclick.net https://googleusercontent.com https://js.stripe.com https://kit.fontawesome.com https://pixel.byspotify.com/ https://rules.quantcount.com https://script.hotjar.com https://scripts.clarity.ms https://scripts.clarity.ms/ https://secure.quantserve.com https://snap.licdn.com https://stackpath.bootstrapcdn.com https://static.ads-twitter.com https://static.hotjar.com https://tr.outbrain.com https://wave.outbrain.com https://web-assets.tide.co/ https://widget.trustpilot.com/ https://www.clarity.ms https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googletagmanager.com/ https://www.gstatic.com https://www.redditstatic.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com/ajax/libs https://fonts.googleapis.com/css https://stackpath.bootstrapcdn.com https://use.typekit.net; worker-src 'self' 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com bing.com *.bing.com stoiximan.gr *.stoiximan.gr cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=ILA0FDlDGWT0_gtSyoQ1a.X2qngKOwNKir084T_ONyQ-1765933688-1.0.1.1-jrEH59KQydEhRHmJilh.Lo_QsWCjdB4OXbUHMnxX9VvtX68m37LoNutGaB_6nUFtr4otok1nnHQrZmyj_dW5jsQ6FPpJBJthSy7bv4OO0idjZ8HIFCGs74naWu1XmyXFkoyrvbLV_snCIgFJ4pfyy3yGHZKYTIYythSxZ8ZUSdWXJpGxis3wfykps9uNEjqe; report-to cf-epdpjvwrxraoaivx 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://client-registry.mutinycdn.com https://js.qualified.com/ https://unpkg.com/ https://analytics.ahrefs.com https://fast.wistia.com https://connect.facebook.net https://browser.sentry-cdn.com;style-src 'self' 'unsafe-inline'; img-src 'self' https://logicmonitor.com https://www.logicmonitor.com https://d21y75miwcfqoq.cloudfront.net https://fast.wistia.com https://embed-ssl.wistia.com; media-src 'self' blob:; font-src 'self' data: https://fast.wistia.com; object-src 'none'; base-uri 'self'; form-action 'none'; frame-ancestors 'self' https://*.logicmonitor.com; frame-src 'self' https://logicmonitor.com https://www.logicmonitor.com ; connect-src 'self' https://app.qualified.com wss://ws2.qualified.com https://fast.wistia.com https://pipedream.wistia.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io;upgrade-insecure-requests; report-uri /wp-json/lm/v1/csp-report; report-to csp_report; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-IXH+mZlksQYbEFO4uQqXWg=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://challenges.cloudflare.com https://static.cloudflareinsights.com https://js.recurly.com https://embed.twitch.tv https://cdn.jwplayer.com https://ssl.p.jwpcdn.com https://apis.google.com https://accounts.google.com https://www.youtube.com https://clickclickbomb.com https://cdn.kiprotect.com https://coral-test-515542435449.us-central1.run.app https://embed.bsky.app; style-src 'self' 'unsafe-inline' https://js.recurly.com https://embed.twitch.tv https://accounts.google.com https://cdn.kiprotect.com; style-src-elem 'self' 'unsafe-inline' https://coral-test-515542435449.us-central1.run.app https://js.recurly.com https://embed.twitch.tv https://accounts.google.com https://cdn.kiprotect.com; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https://challenges.cloudflare.com https://cloudflareinsights.com https://static.cloudflareinsights.com https://storage.googleapis.com https://identitytoolkit.googleapis.com https://securetoken.googleapis.com https://www.googleapis.com https://firebaseinstallations.googleapis.com https://apis.google.com https://api.recurly.com https://cdn.jwplayer.com https://ssl.p.jwpcdn.com https://content.jwplatform.com https://prd.jwpltx.com https://media.enormousexplosive.com https://clickclickbomb.com https://cdn.kiprotect.com https://pingback.giphy.com wss://cdn.jwplayer.com https://coral-test-515542435449.us-central1.run.app wss://coral-test-515542435449.us-central1.run.app https://videos-cloudfront-usp.jwpsrv.com https://o4509808588357632.ingest.us.sentry.io; frame-src https://challenges.cloudflare.com https://accounts.google.com https://embed.twitch.tv https://www.twitch.tv https://www.youtube.com https://www.youtube-nocookie.com https://clickclickbomb.com https://www.clickclickbomb.com https://coral-test-515542435449.us-central1.run.app https://embed.bsky.app; media-src 'self' https://content.jwplatform.com https://cdn.jwplayer.com https://ssl.p.jwpcdn.com https://media.enormousexplosive.com https://videos-cloudfront-usp.jwpsrv.com blob:; worker-src 'self' blob: https://coral-test-515542435449.us-central1.run.app; 1 default-src 'self'; connect-src 'self' https://*.polymarket.com https://*.polymarket.dev wss://*.polymarket.com wss://*.polymarket.dev https://*.walletconnect.com wss://*.walletconnect.com wss://*.walletconnect.org https://*.amplitude.com https://*.alchemy.com https://*.alchemyapi.io https://*.socket.tech https://api.goldsky.com https://api.goldsky.io https://assets.vercel.com https://vercel.live https://vercel.com https://cdp.customer.io https://vitals.vercel-insights.com https://auth.magic.link https://*.magic.link https://*.intercom.io wss://*.intercom.io https://polymarket-upload.s3.us-east-2.amazonaws.com https://polymarket-next-assets.s3.amazonaws.com https://*.polymarket.io https://*.coinbase.com https://*.vercel-scripts.com https://api.iconify.design https://*.google-analytics.com https://js.intercomcdn.com https://api-iam.intercom.io https://*.facebook.com https://*.facebook.net https://*.redditstatic.com https://*.reddit.com https://analytics.tiktok.com wss://*.pusher.com https://*.pusher.com https://polygon-rpc.com wss://relay.walletconnect.org https://browser-intake-datadoghq.eu https://static.ads-twitter.com https://sentry.io https://api.moonpay.com https://*.fun.xyz wss://*.fun.xyz https://*.quiknode.pro https://*.base.org https://*.eth https://*.zksync.io https://pay.daimo.com https://*.pay.daimo.com https://*.daimo.com https://s3-us-west-2.amazonaws.com data:; script-src 'self' 'unsafe-eval' https://*.intercom.io https://js.intercomcdn.com https://www.redditstatic.com https://connect.facebook.net https://widget.intercom.io https://va.vercel-scripts.com https://vercel.live https://*.magic.link https://static.moonpay.com https://s3-us-west-2.amazonaws.com; script-src-elem 'self' https://*.intercom.io https://js.intercomcdn.com https://www.redditstatic.com https://connect.facebook.net https://widget.intercom.io https://va.vercel-scripts.com https://vercel.live https://*.magic.link https://static.moonpay.com https://static.ads-twitter.com https://s3-us-west-2.amazonaws.com https://analytics.tiktok.com https://cdp.customer.io https://www.dubcdn.com https://www.googletagmanager.com https://b-code.liadm.com 'sha256-FZPlDlMTeqDORmlYE10RC9clHRS4T0hmr3qmUImTEgM=' 'sha256-LpaSOWbberseWm9imoaC+ysCWgKfj1BqQTvkK+3f49U=' 'sha256-VeMw0YWTQ3B/16lvulSWfWmvFDJ6h/Dh0ZlaDcC6Xsg=' 'sha256-v0BM73yv/5GaSIfLVBRC5helX8lhanqdp82VUN86fqY=' 'sha256-HmKQJyc9Oo37hDkYVR0w9K4eR1aaxe18l9d9v+MsRGM=' 'sha256-5mcCoB7D4UCld/T8vawEJRBqmowLOddOT7MoIsyvG1Q=' 'sha256-s23mNx29vpBL+sMthBuNE6eQyH+nT28yGSujSemXoW4=' 'sha256-cQXoeQJyWFzxs/64P04eR53fqnjvuHN85IDxz3ajsXs=' 'sha256-Qk1NsNsPdFh6yJ3r/NrwdbvPty9pxQ+4Vy/HZQsFLJ8=' 'sha256-AwKpW/rVb+QKvpxfNraZn5UIDD5I87FHdwCxl6U8IqU=' 'sha256-KmWJKVKEZLyBcE4VQaphHWdW1ApiMVRN/t/9TtZD9/g=' 'sha256-3ENvm2kYNR7adex9zHzAvBeVf6xAkV7O7lZ2SlTCByE='; frame-src 'self' https://*.youtube.com https://*.walletconnect.com https://*.walletconnect.org https://*.magic.link https://global.transak.com https://vercel.live https://*.polymarket.com https://*.polymarket.dev; frame-ancestors 'self' https://auth.magic.link https://vercel.live; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://vercel.live; img-src 'self' blob: data: https://polymarket-upload.s3.us-east-2.amazonaws.com https://assets.vercel.com https://*.walletconnect.com https://alb.reddit.com https://ib.adnxs.com https://www.facebook.com https://vercel.com https://analytics.twitter.com https://t.co https://logo.moralis.io https://sdk-cdn.fun.xyz; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://fonts.intercomcdn.com https://vercel.live https://unpkg.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' https://*.polymarket.com https://*.polymarket.dev 1 font-src *.dedeman.ro data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com maps.google.com *.recaptcha.net *.dedeman.ro applepay.cdn-apple.com *.gigya.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.dedeman.ro maps.gstatic.com *.google-analytics.com *.googletagmanager.com server.arcgisonline.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org applepay.cdn-apple.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.gigya.com 'self' data: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.nr-ext.net *.nr-assets.net *.dedeman.ro *.googleapis.com *.google-analytics.com *.google.com *.recaptcha.net *.facebook.com applepay.cdn-apple.com *.plugins.emarsys.net *.scarabresearch.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.gigya.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.dedeman.ro downloads.mailchimp.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.dedeman.ro 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.dedeman.ro maps.googleapis.com *.google-analytics.com cdns.eu1.gigya.com apple-pay-gateway.apple.com apple-pay-gateway-cert.apple.com apple.com *.scarabresearch.com *.eservice.emarsys.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.dedeman.ro maps.googleapis.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'unsafe-eval' 'unsafe-inline' 'self' http: https: data: wss: blob: chrome-extension ; report-uri /cgi-bin/csp-reports.cgi 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: *.icrc.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.icrc.org www.gstatic.com www.googletagmanager.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net *.youtube.com *.vimeo.com *.vimeocdn.com js.hs-analytics.net *.hs-scripts.com *.hs-banner.com js.hsleadflows.net *.facebook.net *.bing.com *.getblue.io *.adnxs.com js.usemessages.com js.hsadspixel.net *.googlesyndication.com *.ads-twitter.com *.cloudflare.com *.licdn.com hcaptcha.com https://hcaptcha.com api.mapbox.com unpkg.com *.hubspot.com *.usercentrics.eu *.cmp.usercentrics.eu https://*.usercentrics.eu *.hotjar.com *.facebook.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' *.icrc.org *.usercentrics.eu https://*.usercentrics.eu https://hcaptcha.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com api.mapbox.com web.cmp.usercentrics.eu app.usercentrics.eu *.usercentrics.eu https://hcaptcha.com; img-src 'self' data: icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com *.bing.com *.facebook.com *.google.com *.google.ch analytics.twitter.com *.linkedin.com *.doubleclick.net *.hubspot.com ; media-src icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com; frame-src 'self' icrc.org *.icrc.org *.youtube.com *.vimeo.com *.youku.com *.getblue.io www.googletagmanager.com *.googletagmanager.com *.hcaptcha.com td.doubleclick.net *.usercentrics.eu hcaptcha.com; frame-ancestors 'self' icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com *.googletagmanager.com; child-src 'self' blob: icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com; font-src 'self' fonts.gstatic.com fonts.gstatic.com *.usercentrics.euhcaptcha.com; connect-src 'self' icrc.org *.icrc.org *.linkedin.com *.hubspot.com *.bing.com api.hubapi.com *.google-analytics.com *.googlesyndication.com *.google.com *.google.ch google-analytics.com bat.bing.net *.adnxs.com *.hcaptcha.com hcaptcha.com *.mapbox.com *.arcgis.com *.visualstudio.com *.usercentrics.eu; upgrade-insecure-requests 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.pe *.betano.pe betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery cloudflare.com *.cloudflare.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=xJ2HQHRYKyt2s2iQVFdbjka.Y2NxxaqS2bDn_YpRSdk-1765936714-1.0.1.1-dWrqS8ljDoqrgpBG.d5IQZNw.utoAiYG4QT_I9oQ4Y8PSKAnmC_snP1auOKcTOWeGvJGBhTaf93ERALJ1M8QIXlDg8LfCxxyH2VEEIEWaqct.dcb3NqRIIJ.QVmzE.armSBLnIZ0sy1RBrZSD.hglVx76nzDg7efuGPw_4.VDHqdU2hPIo3Gr6ZB3dOf277fqzsVqyF3__yIIK8pJeSZ3w; report-to cf-arbkpzdxpdkyyicd 1 base-uri 'self';script-src-elem 'self' https://snap.licdn.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://js.hs-analytics.net/analytics/ https://www.googletagmanager.com/gtag/ https://js.hs-banner.com/ https://js.hsadspixel.net/ https://x.clearbitjs.com/ https://reveal.clearbit.com/ https://tag.clearbitscripts.com/ https://cdn.koala.live/ https://app.leandata.com/ https://www.datadoghq-browser-agent.com/ https://cdn.jsdelivr.net/ https://browser.sentry-cdn.com/ https://client.crisp.chat/ 'nonce-320244d2ffb2fe5a';report-uri /api/report_csp_violation;object-src 'self';form-action 'self'; 1 font-src fonts.gstatic.com use.typekit.net self data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://store.plumrocket.com pal-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com self *.doubleclick.net *.criteo.com *.easydmp.net *.snapchat.com https://store.plumrocket.com https://accounts.google.com checkoutshopper-test.adyen.com pal-test.adyen.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com self *.bing.com *.paypal.com *.google.fr *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.cookielaw.org *.snapchat.com checkoutshopper-test.adyen.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com self sc-static.net *.abtasty.com *.jsdelivr.net *.gstatic.com *.facebook.net *.tiktok.com *.googleapis.com *.easydmp.net *.vzbl.eu *.aticdn.net *.m1by1.com *.woosmap.com *.doubleclick.net *.cookielaw.org *.snapchat.com *.valiuz.com *.mediarithmics.com *.prediggo.services https://accounts.google.com checkoutshopper-test.adyen.com 'self' 'unsafe-eval' 'nonce-eWFnamg1ZXJzam02MzAxbTVzd2IwNm1pZW0zdGxlaXE=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com self *.gstatic.com *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.snapchat.com https://accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com self *.snapchat.com *.cookielaw.org *.abtasty.com *.googleapis.com *.vzbl.eu *.criteo.com *.easydmp.net *.xiti.com *.valiuz.com *.doubleclick.net *.mediarithmics.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.bing.com *.criteo.net *.snapchat.com *.netvigie.com *.xiti.com *.valiuz.com *.googletagmanager.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com bing.com *.bing.com stoiximan.gr *.stoiximan.gr cloudflareinsights.com *.cloudflareinsights.com betano.bet.ar *.betano.bet.ar geocomply.com *.geocomply.com kameleoon.io *.kameleoon.io ads-twitter.com *.ads-twitter.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=Q5JFtOQXfLutWwzMhK4MBhgSEupo.sDZnwMLySszQ.U-1765937790-1.0.1.1-mCoJCympbapUgcv3gelkPc9c0sjRskrz8px.F55mey3tbl.7Si0FdwGCQ81NSNfDd26vYF5pl6rpJsRmlfuzXfiVyeAlHIl.kKdbdW1ngE_AUvblzOHhf5ZsynWAprd8qYuKQZSbLWxPNxJsSSPtb2LZXlq0IQfygrIDB0wBfdL5Trot5Dso.2EeOLsKb0SisGia8nMtF0Ow80WQJXXdLA; report-to cf-enfvsdybthcojbxv 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com 'unsafe-eval' 'nonce-f896ce6a26cae55cc59c641a846aeb24' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 connect-src *.bundesregierung.de analytics.bundesregierung.de https://hls-hd.myrasec.de ; style-src *.bundesregierung.de 'unsafe-inline' ; script-src *.bundesregierung.de ; script-src-elem *.bundesregierung.de 'nonce-xbfS0uftR4kOcG8IRI8lUGipuSKRrzFUm56LSOGXcHFrFlch86FRysSr+LY07j6OX9gBTf/nKaNf27MyYfQZCxB/iQoWxx8S8YyIDTSr7GVSBzunVMDjTB1D456NUGDj4iTngX5udfA07S2aD6tOpcJp8mJNtbbet5z+zH8/8o0=' ; frame-src *.bundesregierung.de ; media-src *.bundesregierung.de http://video.bundesregierung.de https://zdf-hls-18.akamaized.net ; frame-ancestors *.bundesregierung.de ; img-src *.bundesregierung.de *.bundeskanzler.de https://*.tile.openstreetmap.de data: ; default-src *.bundesregierung.de ; font-src *.bundesregierung.de ; report-uri https://www.bundesregierung.de/service/csp-report ; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/googleorg 1 default-src https: data: https://www.uptodate.com https://www.uptodate.cn; child-src https: data: blob: edge: brave: puffin:; img-src data: https: blob: https://www.uptodate.com https://www.uptodate.cn https://*.d.aa.online-metrix.net https://cdn.cookielaw.org https://app.pendo.uptodate.com https://cdn.wolterskluwer.io; font-src https: data: https://www.uptodate.com https://www.uptodate.cn; worker-src blob: brave: edge: puffin: https://www.uptodate.com https://www.uptodate.cn; media-src data: https: https://www.uptodate.com https://www.uptodate.cn; connect-src data: https: wss: https://www.uptodate.com https://www.uptodate.cn https://geolocation.onetrust.com https://cdn.cookielaw.org https://app.pendo.uptodate.com https://privacyportal-de.onetrust.com; script-src 'unsafe-inline' 'unsafe-eval' https: https://www.uptodate.com https://www.uptodate.cn https://cdn.cookielaw.org https://cdn.pendo.uptodate.com https://www.googletagmanager.com https://tmx.uptodate.com https://rollouts.cdn.uptodate.com https://www.google-analytics.com https://code.jquery.com; style-src 'unsafe-inline' https: https://www.uptodate.com https://www.uptodate.cn https://cdn.pendo.uptodate.com; frame-src https: https://www.uptodate.com https://www.uptodate.cn baiduboxapp: ms-appx-web:; report-uri /services/app/content-security-policy-report/report/json;frame-ancestors *; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-Oan7MX2PhU/2qnpJMGsNMA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.pie.org/ https://www.google.com/recaptcha/ https://accounts.google.com/ https://www.gstatic.com/ https://adblockforyoutube.com/ https://www.adblockforyoutube.com/; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: *; object-src 'none'; font-src 'self' https://fonts.gstatic.com; media-src 'self' https://cdn.pie.org; connect-src 'self' https://*.pie.org https://cdn.segment.com https://cdn.lottielab.com https://browser-intake-us5-datadoghq.com https://www.google.com/recaptcha/ https://adblockforyoutube.com https://www.adblockforyoutube.com; frame-src 'self' https://accounts.google.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/ https://recaptcha.google.com/ https://adblockforyoutube.com/ https://www.adblockforyoutube.com/; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.sheknows.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'none' ;script-src 'unsafe-eval' 'unsafe-inline' *.starbucks.co.jp *.google.com *.google-analytics.com www.googleadservices.com/pagead/ *.googletagmanager.com *.g.doubleclick.net cdn.optimizely.com/js/ *.facebook.net b92.yahoo.co.jp *.twitter.com d.adlpo.com *.treasuredata.com hm.mieru-ca.com d2fzkgg97cd93o.cloudfront.net platform.sumally.com p.jwpcdn.com jwpsrv.com apis.google.com starbucks-faq.pbcv.sitesearch.jp starbucks-faq.sitesearch.jp rum.optimizely.com s.yimg.jp b97.yahoo.co.jp ci-mpsnare.iovation.com dqpw8dh9f7d3f.cloudfront.net d3vgbguy0yofad.cloudfront.net ajax.googleapis.com auth1.freespot.com collect.ptengine.jp d-cache.microad.jp js.ptengine.jp js.fout.jp cdnjs.cloudflare.com in.treasuredata.com ssl.p.jwpcdn.com ;style-src 'unsafe-inline' *.starbucks.co.jp fonts.googleapis.com starbucks-faq.pbcv.sitesearch.jp starbucks-faq.sitesearch.jp ;img-src data: *.starbucks.co.jp *.google.com *.google.co.jp *.google-analytics.com www.googleadservices.com/pagead/ *.googletagmanager.com *.g.doubleclick.net *.twitter.com d2fzkgg97cd93o.cloudfront.net sumally.com jwpltx.com b97.yahoo.co.jp dqpw8dh9f7d3f.cloudfront.net d3vgbguy0yofad.cloudfront.net collect.ptengine.jp d-track.send.microad.jp target.fout.jp huaban.com map.chizumaru.com s3-ap-northeast-1.amazonaws.com www.google.co.id www.google.co.kr www.google.com.hk www.google.com.sg www.google.com.tw www.google.de www.gstatic.com ;font-src *.starbucks.co.jp fonts.gstatic.com ;media-src d2fzkgg97cd93o.cloudfront.net ;object-src *.starbucks.co.jp ;frame-src *.google.com *.g.doubleclick.net *.facebook.com *.twitter.com sumally.com www.youtube.com js.fout.jp dsp.fout.jp ;connect-src *.starbucks.co.jp *.g.doubleclick.net dwjw4x8nnai5d.cloudfront.net rum.optimizely.com uc.gre d11abxzrrvbz6o.cloudfront.net track.uc.cn ws://ntjp.mieru-ca.com ;report-uri https://sbjcsp2.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self';base-uri 'none';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' https: data: https://cdn.remitly.com https://*.doubleclick.net/ https://www.facebook.com https://*.google.com https://*.google-analytics.com https://www.googletagmanager.com https://*.gstatic.com/ https://getrockerbox.com/ https://media.remitly.io https://impressions.onelink.me;object-src 'none';script-src https: 'nonce-4d93fa672f42b870921190f0f1c0b94881dc800d74c7446496576ad3c5859c19' 'strict-dynamic';script-src-attr 'none';style-src https://cdn.remitly.com https://media.remitly.io https://cdn.fonts.net 'nonce-4d93fa672f42b870921190f0f1c0b94881dc800d74c7446496576ad3c5859c19';manifest-src data:;style-src-elem https://*.gstatic.com/ https://media.remitly.io https://cdn.fonts.net https://fonts.googleapis.com 'nonce-4d93fa672f42b870921190f0f1c0b94881dc800d74c7446496576ad3c5859c19';style-src-attr 'none';connect-src 'self' https://api2.branch.io/ https://cdn.remitly.com https://remitlyweb-assets-prod.int.remitly.com/ https://*.doubleclick.net/ https://www.googletagmanager.com https://sessions.bugsnag.com https://notify.bugsnag.com https://bam.nr-data.net https://uel.remitly.io https://locations.remitly.io https://translate.googleapis.com/ https://*.clarity.ms https://www.facebook.com https://connect.facebook.net https://cdn.siftscience.com https://cdn.fonts.net https://*.google.com https://www.googleadservices.com https://*.google-analytics.com https://api.remitly.io https://parasol.remitly.io https://wa.appsflyer.com https://wa.onelink.me/v1/onelink https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://media.remitly.io https://*.snapchat.com https://sc-static.net https://bat.bing.com https://bat.bing.net https://px.ads.linkedin.com https://pixel-config.reddit.com https://www.redditstatic.com https://conversions-config.reddit.com https://websdk.appsflyer.com https://*.amazon-adsystem.com https://ara.paa-reporting-advertising.amazon https://*.taboola.com https://widget.trustpilot.com/ https://*.acuityplatform.com https://*.statsig.com https://*.statsigapi.net https://*.statsigcdn.com https://featuregates.org https://featureassets.org https://assetsconfigcdn.org https://prodregistryv2.org https://cloudflare-dns.com https://beyondwickedmapping.org;frame-src https://*.amazon-adsystem.com https://*.doubleclick.net/ https://www.recaptcha.net/recaptcha/ https://remitly-3pjs.com https://www.googletagmanager.com https://www.facebook.com https://www.youtube.com https://*.snapchat.com https://sc-static.net https://widget.trustpilot.com/;worker-src 'self';media-src 'self' https:;report-uri https://www.remitly.com/csp_report_preauth 1 frame-ancestors https://*.workable.com/; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubcbe8d2ef0966e8645a91099cfac490bb&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=%40http.headers.cfray%3A9af2f304e9c8f997 1 report-uri https://mon-ttp.lemon8-app.us/monitor_browser/collect/batch/security/?bid=tiktok_pns&c=218&ev_type=csp&r=4&v=4; report-to csp-endpoint; script-src 'report-sample' 'unsafe-eval' *.tiktokcdn-us.com connect.facebook.net ct.pinterest.com; worker-src 'self' 1 default-src 'none' 'self' connect.facebook.net cookie-cdn.cookiepro.com match.adsrvr.org ps.eyeota.net static.ads-twitter.com *.imgix.net uschamber.tfaforms.net www.gstatic.com 'unsafe-eval' 'unsafe-inline' analytics.formassembly.com data: px.ads.linkedin.com t.co www.google.com dpm.demdex.net googleads.g.doubleclick.net ib.adnxs.com p1.parsely.com stats.g.doubleclick.net www.googletagmanager.com analytics.google.com; object-src 'none'; frame-src 'none' www.google.com www.youtube.com www.googletagmanager.com uschamber.wufoo.com youtube.com; frame-ancestors 'none' 'self'; form-action 'self'; base-uri 'self'; connect-src 'self' analytics.google.com cookie-cdn.cookiepro.com o4507211308007424.ingest.us.sentry.io p1.parsely.com px.ads.linkedin.com *.google-analytics.com stats.g.doubleclick.net tags.srv.stackadapt.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com wss://127.0.0.1:* www.facebook.com user.userguiding.com vc.hotjar.io analytics.formassembly.com insights.algolia.io properties *.algolianet.com *.algolia.net *.imgix.net uschamber.tfaforms.net *.google.* content.hotjar.io metrics.hotjar.io wss://ws.hotjar.com; font-src 'self' data: fonts.gstatic.com www.uschamber.com svcs.tql.com; img-src 'self' cookie-cdn.cookiepro.com data: ib.adnxs.com idsync.rlcdn.com match.adsrvr.org p1.parsely.com ps.eyeota.net px.ads.linkedin.com s3.us-east-1.amazonaws.com t.co trc.taboola.com us-u.openx.net *.imgix.net www.facebook.com www.google.com www.googletagmanager.com www.queryly.com analytics.twitter.com cdn.datatables.net dpm.demdex.net i.ytimg.com fonts.gstatic.com connect.facebook.net data.queryly.com loadus.exelator.com ssl.gstatic.com translate.google.com *.google.* www.googleadservices.com googleads.g.doubleclick.net c.clarity.ms image.uschamber.com ml314.com; manifest-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' api.queryly.com cms.www.uschamber.com connect.facebook.net cookie-cdn.cookiepro.com googleads.g.doubleclick.net in.ml314.com js.sentry-cdn.com ml314.com snap.licdn.com static.ads-twitter.com static.hotjar.com uschamber.tfaforms.net www.googletagmanager.com www.gstatic.com www.queryly.com browser.sentry-cdn.com www.google.com cdn.parsely.com co-admin.uschamber.com tags.srv.stackadapt.com cdn.skypack.dev www.youtube.com ajax.googleapis.com blob: cdn.jsdelivr.net js.stripe.com script.hotjar.com secure.wufoo.com www.uschamber.com api.disqometer.com infird.com; script-src 'unsafe-eval' 'unsafe-inline' 'self' ml314.com cdn.parsely.com co-admin.uschamber.com connect.facebook.net js.sentry-cdn.com js.stripe.com wasm-eval www.google.com www.googletagmanager.com www.gstatic.com www.queryly.com cms.www.uschamber.com googleads.g.doubleclick.net snap.licdn.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' tags.srv.stackadapt.com uschamber.tfaforms.net fonts.googleapis.com cdn.jsdelivr.net www.queryly.com www.uschamber.com code.jquery.com; worker-src blob:; style-src 'self' 'unsafe-inline'; child-src www.googletagmanager.com blob:; media-src data:; report-uri https://uschamber.report-uri.com/r/t/csp/reportOnly; 1 default-src https: data: blob: wss: android-webview-video-poster: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-to default; report-uri https://sentry.io/api/256178/csp-report/?sentry_key=c2fb05422b2242faaec1d6d8a2a000fc&sentry_environment=&sentry_release=1.2.31 1 default-src 'self'; script-src 'self' 'nonce-VAbxhJOP7SvN7ZG6HC6bIQ==' https://mc.yandex.ru https://www.googletagmanager.com; img-src 'self' data: https://mc.yandex.ru; font-src 'self'; connect-src 'self' https://mc.yandex.ru; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-to csp-endpoint; 1 base-uri 'self'; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: chrome: https:; worker-src 'self' data: blob:; child-src 'self' blob:; frame-src 'self' *.consumeraffairs.com *.google.com *.googletagmanager.com *.googleapis.com *.facebook.com *.youtube.com *.px-cloud.net i.liadm.com; connect-src 'self' *.consumeraffairs.com wss://ws.hotjar.com https://ws.hotjar.com *.px-cloud.net api.segment.io https:; report-uri https://stderr.consumeraffairs.com/api/40/security/?sentry_key=7cf6b3564e4343f68a310b937a3d823e&sentry_environment=production&sentry_release=ms-2025.12.09.00; 1 default-src 'nonce-ef919051ea0a8e39af6611de80b7f021' 'none' *.publixcdn.com;script-src 'unsafe-eval' 'unsafe-inline' blob: *.publix.com *.publixstockholder.com *.publixcdn.com *.optimizely.com *.adobedtm.com *.googletagmanager.com *.google-analytics.com s.pinimg.com *.facebook.net unpkg.com vt.myvisualiq.net *.googleapis.com platform.liquidus.net tags.crwdcntrl.net *.foresee.com *.cookielaw.org *.youtube.com x9igtv25r3.execute-api.us-east-1.amazonaws.com *.doubleclick.net *.pinterest.com *.google.com *.gstatic.com *.google.ae *.google.at *.google.bs *.google.ch *.google.co.id *.google.co.in *.google.co.jp *.google.co.uk *.google.co.ve *.google.com.ar *.google.com.au *.google.com.br *.google.com.bz *.google.com.co *.google.com.do *.google.com.gt *.google.com.jm *.google.com.mx *.google.com.pa *.google.com.pe *.google.com.pk *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.vc *.google.com.vn *.google.de *.google.ee *.google.es *.google.fr *.google.gr *.google.is *.google.it *.google.jo *.google.lu *.google.nl *.google.no *.google.pl *.google.ps *.google.ro *.google.ru *.google.se *.google.tt *.google.com; style-src 'unsafe-inline' *.publix.com *.publixstockholder.com *.publixcdn.com *.optimizely.com *.googleapis.com d127mspptluska.cloudfront.net *.google.com *.googletagmanager.com *.gstatic.com *.google.ae *.google.at *.google.bs *.google.ch *.google.co.id *.google.co.in *.google.co.jp *.google.co.uk *.google.co.ve *.google.com.ar *.google.com.au *.google.com.br *.google.com.bz *.google.com.co *.google.com.do *.google.com.gt *.google.com.jm *.google.com.mx *.google.com.pa *.google.com.pe *.google.com.pk *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.vc *.google.com.vn *.google.de *.google.ee *.google.es *.google.fr *.google.gr *.google.is *.google.it *.google.jo *.google.lu *.google.nl *.google.no *.google.pl *.google.ps *.google.ro *.google.ru *.google.se *.google.tt *.youtube.com; img-src 'self' data: *.publix.com *.publixstockholder.com *.publixcdn.com cutdcdnepcom.azureedge.net cuttcdnwimages.azureedge.net cutscdnepcom.azureedge.net *.google.com *.google-analytics.com *.googleapis.com *.gstatic.com *.doubleclick.net *.facebook.com *.cookielaw.org *.mapbox.com *.shoplocal.com *.googletagmanager.com i.ytimg.com d19hn3jcfcdeky.cloudfront.net *.widen.net d127mspptluska.cloudfront.net *.everesttech.net *.googleadservices.com *.google.ca *.adentifi.com *.prod.bidr.io *.google.com.pr *.pinterest.com *.google.ae *.google.at *.google.bs *.google.ch *.google.co.id *.google.co.in *.google.co.jp *.google.co.uk *.google.co.ve *.google.com.ar *.google.com.au *.google.com.br *.google.com.bz *.google.com.co *.google.com.do *.google.com.gt *.google.com.jm *.google.com.mx *.google.com.pa *.google.com.pe *.google.com.pk *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.vc *.google.com.vn *.google.de *.google.ee *.google.es *.google.fr *.google.gr *.google.is *.google.it *.google.jo *.google.lu *.google.nl *.google.no *.google.pl *.google.ps *.google.ro *.google.ru *.google.se *.google.tt *.youtube.com; frame-src *.publix.com *.publixstockholder.com publix.demdex.net *.optimizely.com *.pinterest.com *.doubleclick.net servedby.flashtalking.com *.youtube.com astutebot.com platform.liquidus.net *.googletagmanager.com *.google.com *.gstatic.com *.google.ae *.google.at *.google.bs *.google.ch *.google.co.id *.google.co.in *.google.co.jp *.google.co.uk *.google.co.ve *.google.com.ar *.google.com.au *.google.com.br *.google.com.bz *.google.com.co *.google.com.do *.google.com.gt *.google.com.jm *.google.com.mx *.google.com.pa *.google.com.pe *.google.com.pk *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.vc *.google.com.vn *.google.de *.google.ee *.google.es *.google.fr *.google.gr *.google.is *.google.it *.google.jo *.google.lu *.google.nl *.google.no *.google.pl *.google.ps *.google.ro *.google.ru *.google.se *.google.tt;font-src 'self' *.publixcdn.com *.gstatic.com;connect-src 'self' *.publix.com *.publixcdn.com *.cookielaw.org geolocation.onetrust.com publix-privacy.my.onetrust.com adobedc.demdex.net dpm.demdex.net *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.doubleclick.net *.optimizely.com *.facebook.com *.pinterest.com events.mapbox.com api.mapbox.com x9igtv25r3.execute-api.us-east-1.amazonaws.com *.google.com *.google.ca *.google.com.pr *.google.ae *.google.at *.google.bs *.google.ch *.google.co.id *.google.co.in *.google.co.jp *.google.co.uk *.google.co.ve *.google.com.ar *.google.com.au *.google.com.br *.google.com.bz *.google.com.co *.google.com.do *.google.com.gt *.google.com.jm *.google.com.mx *.google.com.pa *.google.com.pe *.google.com.pk *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.vc *.google.com.vn *.google.de *.google.ee *.google.es *.google.fr *.google.gr *.google.is *.google.it *.google.jo *.google.lu *.google.nl *.google.no *.google.pl *.google.ps *.google.ro *.google.ru *.google.se *.google.tt; report-uri https://ef9b5c568858c6958222512c6f2bb1f5.report-uri.com/r/d/csp/reportOnly 1 base-uri 'self';connect-src https://*.go-mpulse.net https://*.akstat.io 'self' https: *.sentry.io *.amplitude.com *.care.com *.carezen.net *.signalfx.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net font.google.com analytics.google.com tagmanager.google.com www.google.com https://*.hotjar.com https://vc.hotjar.io https://content.hotjar.io https://events.hotjar.io https://surveystats.hotjar.io wss://*.hotjar.com https://geolocation.onetrust.com jsv3.recruitics.com;default-src 'self' wss://*.care.com *.care.com *.careapis.com *.carezen.net *.cdn-care.com care.com cdn-care.com www.gstatic.com www.google.com *.googlesyndication.com tags.tiqcdn.com tags-eu.tiqcdn.com tk.getwork.com tr.snapchat.com shareasale.com *.doubleclick.net apps.rokt.com bid.g.doubleclick.net tags.w55c.net *.linkedin.com www.pinterest.com carecom.sjv.io staging-pt.ispot.tv ct.pinterest.com;font-src 'self' data: https://www.care.com https://www.dev.carezen.net https://www.stg.carezen.net fonts.gstatic.com https://script.hotjar.com;frame-ancestors 'self';img-src data: blob: *;object-src 'none';script-src https://*.go-mpulse.net 'nonce-f935b416a1946d63b9706a5696139774' 'self' *.akamaihd.net *.care.com *.careapis.com *.carezen.net *.cdn-care.com *.cloudfront.net *.googlesyndication.com *.sift.com *.monetate.net acsbapp.com analytics.tiktok.com apps.rokt.com bat.bing.com care.com cdn-care.com cdn.pdst.fm connect.facebook.net d.impactradius-event.com googleads.g.doubleclick.net securepubads.g.doubleclick.net maps.googleapis.com s.pinimg.com ssl.google-analytics.com tags-eu.tiqcdn.com tags.tiqcdn.com wss://*.care.com www.emjcd.com www.google-analytics.com www.google.com www.googleadservices.com *.googletagmanager.com www.gstatic.com tr.outbrain.com tags.w55c.net clarity.ms staging-pt.ispot.tv tracker.mnixdata.com *.mountain.com tagmanager.google.com s.go-mpulse.net collector-12308.tvsquared.com js.adsrvr.org https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org assets.calendly.com jsv3.recruitics.com 'nonce-7f04f9196753d20b0468fe7f9ad6c089' 'strict-dynamic';frame-src 'self' alchemy.veriff.com www.google.com recaptcha.google.com bid.g.doubleclick.net 12355078.fls.doubleclick.net s.go-mpulse.net carecom.sjv.io apps.rokt.com tr.snapchat.com 3239339.fls.doubleclick.net https://vars.hotjar.com insight.adsrvr.org https://www.youtube.com/ https://ots2-qa.learningcaregroup.com/ScheduleATour/ https://ots2.learningcaregroup.com/ScheduleATour/ td.doubleclick.net https://calendly.com securepubads.g.doubleclick.net *.googlesyndication.com ep2.adtrafficquality.google;style-src 'self' 'unsafe-inline' tagmanager.google.com fonts.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org 'nonce-7f04f9196753d20b0468fe7f9ad6c089';style-src-attr 'self' 'unsafe-inline' tags.tiqcdn.com tags-eu.tiqcdn.com bat.bing.com;upgrade-insecure-requests;report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=vhp-mfe%402.182.1&sentry_environment=prod 1 script-src 'unsafe-eval' blob: 'self' https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob: 'unsafe-inline' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; default-src 'self' data: blob: https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; style-src 'self' data: blob: https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com 'unsafe-inline'; img-src * data: blob:; object-src 'none'; report-uri https://services.fandom.com/csp-logger/csp/ucp; worker-src 'self' blob: 1 script-src 'nonce-KutdkgfC1s4awgOKxeSoxQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=e46fcc52-3978-45bb-beca-76e9e45d5e24; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-4b064ec1-2403-469f-a3b7-671510a97e98' https: data: https://js.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://siteintercept.qualtrics.com https://browser.sentry-cdn.com https://*.siteintercept.qualtrics.com https://www.googletagmanager.com https://js.monitor.azure.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://cdn.jsdelivr.net https://more.suse.com; img-src 'self' https: data: https://fast.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://fast.wistia.net https://fast.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com; connect-src 'self' https: wss: https://cdn.cookielaw.org https://distillery.wistia.com https://siteintercept.qualtrics.com https://dc.services.visualstudio.com https://fast.wistia.com https://fast.wistia.net https://pipedream.wistia.com wss://ws.qualified.com https://embed-ssl.wistia.com https://apple.dxcloud.episerver.net https://cdn.jsdelivr.net https://js.monitor.azure.com wss://ws.qualified.com; font-src 'self' https: data: https://fonts.gstatic.com https://fast.wistia.net; object-src 'none' ; media-src 'self' https: blob: ; frame-src 'self' https: ; form-action 'self' https://suselinux.fra1.qualtrics.com; frame-ancestors 'self' ; base-uri 'none' ; report-uri https://www.suse.com/api/reporting/; report-to csp-endpoint; 1 default-src 'self'; script-src 'self' 'wasm-unsafe-eval' https://vercel.com https://vercel.live/; style-src 'self' 'unsafe-inline'; img-src * data: blob:; connect-src * data: blob:; worker-src 'self' blob:; frame-src 'self' *; report-to https://uniswaplabs.report-uri.com/r/t/csp/reportOnly; form-action none; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/searchplayground_google 1 script-src 'self' *.cloudflare.com https://assets.adobedtm.com *.marketo.net *.google-analytics.com *.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net adservice.google.com https://trk.techtarget.com *.onetrust.com https://connect.facebook.net https://embed.cloudflarestream.com https://customer-eq7kiuol0tk9chox.cloudflarestream.com https://videodelivery.net *.greenhouse.io cdn.bizible.com d2c7xlmseob604.cloudfront.net static.cloudflareinsights.com *.6sc.co https://munchkin.marketo.net https://*.adsrvr.org https://snap.licdn.com https://static.ads-twitter.com https://*.salesloft.com https://cdn.jsdelivr.net/npm/search-insights/ 'unsafe-eval' 'unsafe-inline' https://*.qualified.com wss://*.qualified.com https://tag.demandbase.com/1be41a80498a5b73.min.js https://bat.bing.com; img-src 'self' d.adroll.com/ipixel/* cdn.bizible.com cdn.bizibly.com www.linkedin.com *.ads.linkedin.com analytics.twitter.com t.co https://cdn.filestackcontent.com cf-assets.www.cloudflare.com *.cloudflare.com cloudflare.com https://paygo-webflow-lps.builtforthis.workers.dev/images/627166964dba1c2aa8c2d5b5_performance-cloud-speed.png di.rlcdn.com id.rlcdn.com https://id.rlcdn.com/464526.gif *.6sc.co https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://www.google.com https://d5uzuhh841kux.cloudfront.net www.google.com/ads/ga-audiences https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://www.google-analytics.com https://ad.doubleclick.net https://td.doubleclick.net https://9309168.fls.doubleclick.net https://googleads.g.doubleclick.net https://adservice.google.com https://customer-eq7kiuol0tk9chox.cloudflarestream.com https://images.contentful.com https://images.ctfassets.com *.videodelivery.net https://bat.bing.com https://bat.bing.net https://*.skai-analytics.com https://*.salesloft.com https://images.ctfassets.net https://benchmarks.cdn.compute-pipe.com data: blob: https://p29.cedexis-test.com https://cedexis-test.akamaized.net https://fastly.cedexis-test.com https://ptcfc.com https://benchmark.1e100cdn.net https://testingcf.jsdelivr.net https://fastly.jsdelivr.net https://essl-cdxs.edgekey.net https://stackpath-map3.cedexis-test.com https://cdnetworks.cedexis-test.com https://limelight-ssl.cedexis-test.com https://p17003.cedexis-test.com https://vdms-ssl.cedexis-test.com https://jsdelivr.b-cdn.net https://serverless-benchmarks-js.compute-pipe.com https://serverless-benchmarks-rust.compute-pipe.com https://exactly-huge-arachnid.edgecompute.app https://uniquely-peaceful-hagfish.edgecompute.app https://d37vlkgj6jn9t1.cloudfront.net https://serverless-benchmarks-js.flame.compute-pipe.com https://performance-radar.is-cf.help.every1dns.net; worker-src 'self' *.cloudflare.com blob:; frame-src 'self' https://*.cloudflare.com https://www.googletagmanager.com https://iframe.cloudflarestream.com https://customer-eq7kiuol0tk9chox.cloudflarestream.com https://customer-rhnwzxvb3mg4wz3v.cloudflarestream.com/ https://videodelivery.net https://iframe.videodelivery.net https://9309168.fls.doubleclick.net https://9973066.fls.doubleclick.net https://bid.g.doubleclick.net https://td.doubleclick.net https://*.qualified.com https://cloudflareinc.demdex.net; connect-src 'self' https://tr.www.cloudflare.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.googletagmanager.com https://*.doubleclick.net https://www.google.com/ccm/collect https://www.google.com/pagead/landing https://px4.ads.linkedin.com https://px.ads.linkedin.com https://www.linkedin.com https://snap.licdn.com https://alb.reddit.com https://bat.bing.com https://*.algolianet.com https://*.algolia.net https://*.algolia.io https://ibc-flow.techtarget.com https://713-xsc-918.mktoresp.com https://713-xsc-918.mktoutil.com https://p29.cedexis-test.com https://cedexis-test.akamaized.net https://fastly.cedexis-test.com https://ptcfc.com https://benchmark.1e100cdn.net https://testingcf.jsdelivr.net https://fastly.jsdelivr.net https://essl-cdxs.edgekey.net https://stackpath-map3.cedexis-test.com https://cdnetworks.cedexis-test.com https://limelight-ssl.cedexis-test.com https://p17003.cedexis-test.com https://vdms-ssl.cedexis-test.com https://jsdelivr.b-cdn.net https://serverless-benchmarks-js.compute-pipe.com https://serverless-benchmarks-rust.compute-pipe.com https://exactly-huge-arachnid.edgecompute.app https://uniquely-peaceful-hagfish.edgecompute.app https://d37vlkgj6jn9t1.cloudfront.net https://serverless-benchmarks-js.flame.compute-pipe.com https://performance-radar.is-cf.help.every1dns.net https://*.cloudflare.com https://privacyportal.onetrust.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://www.google.com https://epsilon.6sense.com https://epsilon-cloudfront.6sense.com https://ipv6.6sc.co https://secure.adnxs.com https://tag-logger.demandbase.com https://api.company-target.com https://c.6sc.co https://boards-api.greenhouse.io https://videodelivery.net https://cdn.cookielaw.org wss://ws.qualified.com/cable https://app.qualified.com https://edge.adobedc.net https://adobedc.demdex.net wss://ws6.qualified.com https://*.salesloft.com https://dpm.demdex.net https://www.googleadservices.com https://translate.googleapis.com; frame-ancestors 'self' https://www.cloudflare.com; report-uri https://cf-obs.www.cloudflare.com/report; report-to csp-endpoint 1 default-src data: https: 'unsafe-inline' 'unsafe-eval'; report-uri https://track.buyma.com/csp/report.json 1 connect-src 'self' data: *.amazonaws.com *.analytics.google.com *.google-analytics.com *.doubleclick.net *.facebook.com *.googleapis.com *.gstatic.com *.masonline.id *.nr-data.net *.stockbit.com *.stockbit.io *.tiktok.com *.youtube.com wss://*.crisp.chat wss://*.stockbit.com analytics.google.com analytics-ipv6.tiktokw.us api.trongrid.io cdnma.cdnservice.space client.crisp.chat www.google.co.id www.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.stockbit.com analytics.tiktok.com apis.google.com app.midtrans.com bam.nr-data.net client.crisp.chat connect.facebook.net d2r1yp2w7bby2u.cloudfront.net js-agent.newrelic.com midtrans.com nr-data.net sg1.wzrkt.com sg1.clevertap-prod.com www.google-analytics.com www.google.com/recaptcha/api.js www.googletagmanager.com www.gstatic.com/firebasejs/ www.gstatic.com/recaptcha/ www.youtube.com/iframe_api www.youtube.com/s/player/ ssl.google-analytics.com; worker-src blob:; style-src 'self' 'unsafe-inline' *.stockbit.com *.cloudfront.net assets-nextjs.stockbit.com client.crisp.chat translate.googleapis.com; object-src 'none'; media-src 'self' assets-nextjs.stockbit.com; report-uri https://browser-intake-us5-datadoghq.com/api/v2/logs?dd-api-key=pub521231ea4d284aa9bbf819c83a438ad4&dd-evp-origin=content-security-policy&ddsource=csp-report; 1 media-src blob: https:; worker-src blob: https:; font-src chrome-extension: data: https:; img-src data: blob: about: https: http://track.adform.net; default-src https: blob: data: ms-appx-web: wss: 'unsafe-inline' 'unsafe-eval'; report-uri https://wiwo.report-uri.com/r/d/csp/reportOnly 1 connect-src https: wss:; font-src data: https:; frame-src https:; img-src blob: data: https:; media-src blob: data: https:; object-src 'self' https://*.app-eu.wrike.com https://*.app-eu.wrike-cn.com https://*.wrike.com https://*.wrike-cn.com https://*.www.wrike.com https://*.www.wrike-cn.com https://youtube.com https://d3tvpxjako9ywy.cloudfront.net https://d1c5qktmphn2d.cloudfront.net; manifest-src 'self' https://cdn.wrike.com https://cdn.wrike-cn.com; script-src 'unsafe-eval' 'unsafe-inline' data: https://*.wrike.com https://*.wrike-cn.com https://*.www.wrike.com https://*.www.wrike-cn.com https://*.app-eu.wrike.com https://*.app-eu.wrike-cn.com https://*.google-analytics.com https://*.usercentrics.eu https://*.marketo.com https://*.marketo.net https://apis.google.com https://bat.bing.com https://cdn.ravenjs.com https://connect.facebook.net https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1056104813/ https://snap.licdn.com https://static.ads-twitter.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/962492627/ https://pagead2.googlesyndication.com/pagead/conversion/962492627/ https://s.yimg.jp/images/listing/tool/cv/ytag.js https://tag.demandbase.com/63365c817f510bbb.min.js https://api.tomi.ai/029/loader.js https://tags.srv.stackadapt.com/events.js https://s.yimg.jp/images/listing/tool/cv/conversion.js https://cdn.metadata.io https://js.partnerstack.com/v1/ https://www.clarity.ms/ https://tracking.intentsify.io/ https://b97.yahoo.co.jp/pagead/conversion_async.js https://ad.doubleclick.net/ddm/adj/N1344363.197812NSO.CODESRV/ https://*.d41.co https://d3tvpxjako9ywy.cloudfront.net https://d1c5qktmphn2d.cloudfront.net https://static.cloudflareinsights.com https://fast.wistia.com https://js.qualified.com https://static.axept.io; style-src 'unsafe-inline' data: https:; default-src 'self'; report-uri https://csp-global.wrike.com/csp-report?website; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=c1Pd2WgWSbvmJag6SVZztCX2o8An99CtqBCiDTQDErg-1765938638.6826072-1.0.1.1-yQykk5ProW49i7ZdKKVkmWWesYa8Xjq67cbc2X_zINCqUhoZ2UdWu1u6Azp9VESFI05KUSwz6fICBS6OOk.VoK.s5tuGrHbFvI8NvyFLWSGyPqJ5xcRtfPSfCNgB7A.YI0biXKAogjzTB0tfJToum9mlVmdj3stFWex7I0IRjss; report-to cf-csp-endpoint 1 base-uri 'self'; media-src 'none'; object-src 'self'; manifest-src 'self'; style-src 'self' 'unsafe-inline' https://*.content.powerapps.com https://*.static.powerapps.com https://*.cdn.office.net https://vsa.services.microsoft.com https://mfpembedcdnmsit.azureedge.net; script-src 'self' blob: https://wcpstatic.microsoft.com https://shell.cdn.office.net https://res.cdn.office.net https://r4.res.office365.com https://amcdn.msftauth.net https://js.monitor.azure.com https://vsa.services.microsoft.com https://api.flow.microsoft.com https://content.powerapps.com 'sha256-CnzmUY9XDWPjkAgzDPEHLlm4gygKztleRupzQDsr608=' 'sha256-JEwSVBrCE741EV9rbuu3EqBV+pc2dpFhRHIV6+9J0mY=' 'sha256-+2jm5SNRB4WubmMQDChnXjseeCIhj34lMFWKhVn1qBE=' 'sha256-y7y27Uq4p88K6EhwSUfbhCk9VakghnU/hORgjhopExY=' 'sha256-yt+SNVxRkIi6H6yb7ndFuZM1esMX9esg3UpRHaTsyVk=' 'sha256-5YvjqBbPixZuRD6ipzNpt6RcylB/REYB44y5CGATwBQ=' 'sha256-JEwSVBrCE741EV9rbuu3EqBV+pc2dpFhRHIV6+9J0mY=' 'sha256-bshPvqn6V1743FBtawmXN97vsJUIDnycCzTIc5BF7Vo=' 'sha256-wODu+VfY8ND+vPVOUkzkfC/1jpkO6aSN5rGEBoSdnys='; font-src 'self' data: https://*.content.powerapps.com https://*.static.powerapps.com https://static2.sharepointonline.com https://*.cdn.office.net https://appsforoffice.microsoft.com https://spoprod-a.akamaihd.net; form-action 'self'; report-uri https://csp.microsoft.com/report/PowerAutomate-MakerPortal; 1 default-src 'self' *.openjdk.java.net feedburner.google.com; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' feeds.feedburner.com *.statcounter.com statcounter.com; img-src 'self' data: *.statcounter.com *.openjdk.java.net feedburner.google.com; frame-ancestors 'none'; report-uri https://openjdk.report-uri.io/r/default/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com 'unsafe-inline' data: *.fontawesome.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.google.com https://www.youtube.com https://c.paypal.com/ *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ https://cdn.sparkfun.com track.hubspot.com perf-na1.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com assets.shipperhq.com *.googleapis.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com js.hs-scripts.com cta-service-cms2.hubspot.com api.hubspot.com js.usemessages.com js.hs-analytics.net js.hsleadflows.net js.hubspot.com js.hs-banner.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com ovs.shipperhq.com *.googleapis.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ cta-service-cms2.hubspot.com api.hubspot.com forms.hubspot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sparkfun.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 frame-ancestors https: canvas.uts.edu.au; report-uri https://www.uts.edu.au/api/reporting/; report-to csp-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/about_appsheet_com 1 default-src * data: blob: wss: 'unsafe-eval' 'unsafe-inline'; connect-src * wss:; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-elem * 'unsafe-inline'; style-src * 'unsafe-inline'; img-src * data: blob:; object-src * data:; media-src * data:; frame-src *; font-src * data:; manifest-src *; worker-src * blob:; frame-ancestors 'self' *.speechify.com speechify.com *.speechify.dev; report-uri https://speechify.com/api/csp-reports; report-to speechify 1 script-src 'self' *.edpuzzle.com *.edpuzzle.dev *.edpuzzle.net 'unsafe-inline' 'unsafe-eval' latex.codecogs.com legacy.codecogs.com https://service.mtcaptcha.com https://service2.mtcaptcha.com *.google.com *.googleapis.com *.google-analytics.com lh3.googleusercontent.com accounts.google.com/gsi/style https://*.googletagmanager.com https://*.youtube.com *.ytimg.com *.soundcloud.com *.mxpnl.com *.newrelic.com *.nr-data.net d1htrclywvryi1.cloudfront.net js.stripe.com *.twitter.com https://*.awswaf.com *.appcues.com *.appcues.net login.microsoftonline.com *.codecogs.com;script-src-elem 'self' *.edpuzzle.com *.edpuzzle.dev *.edpuzzle.net 'unsafe-inline' 'unsafe-eval' latex.codecogs.com legacy.codecogs.com https://service.mtcaptcha.com https://service2.mtcaptcha.com *.google.com *.googleapis.com *.google-analytics.com lh3.googleusercontent.com accounts.google.com/gsi/style https://*.googletagmanager.com https://*.youtube.com *.ytimg.com *.soundcloud.com *.mxpnl.com *.newrelic.com *.nr-data.net d1htrclywvryi1.cloudfront.net js.stripe.com *.twitter.com https://*.awswaf.com *.appcues.com *.appcues.net login.microsoftonline.com *.codecogs.com;script-src-attr 'self' *.edpuzzle.com *.edpuzzle.dev *.edpuzzle.net 'unsafe-inline' 'unsafe-eval' latex.codecogs.com legacy.codecogs.com https://service.mtcaptcha.com https://service2.mtcaptcha.com *.google.com *.googleapis.com *.google-analytics.com lh3.googleusercontent.com accounts.google.com/gsi/style https://*.googletagmanager.com https://*.youtube.com *.ytimg.com *.soundcloud.com *.mxpnl.com *.newrelic.com *.nr-data.net d1htrclywvryi1.cloudfront.net js.stripe.com *.twitter.com https://*.awswaf.com *.appcues.com *.appcues.net login.microsoftonline.com *.codecogs.com;connect-src 'self' *.edpuzzle.com *.edpuzzle.dev *.edpuzzle.net images.edpuzzle.com https://*.awswaf.com *.nr-data.net *.mxpnl.com *.mixpanel.com https://service.mtcaptcha.com https://service2.mtcaptcha.com *.google-analytics.com *.googleapis.com *.googleusercontent.com accounts.google.com login.microsoftonline.com wss://5uj9b5geqb.execute-api.us-east-1.amazonaws.com wss://5k3vufy1vh.execute-api.us-east-1.amazonaws.com wss://api.appcues.com wss://api.appcues.net *.appcues.com *.appcues.net audio-uploads-us-standard.s3.amazonaws.com audio-uploads-us-standard.s3.us-east-1.amazonaws.com test-audio-uploads-us-standard.s3.amazonaws.com test-audio-uploads-us-standard.s3.us-east-1.amazonaws.com uploaded-profile-images-us-standard.s3.amazonaws.com test-uploaded-profile-images.s3.amazonaws.com edpuzzle-dev-student-images-cdk.s3.amazonaws.com edpuzzle-dev-student-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-student-images-cdk.s3.amazonaws.com edpuzzle-prod-student-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-teacher-images-cdk.s3.amazonaws.com edpuzzle-dev-teacher-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-teacher-images-cdk.s3.amazonaws.com edpuzzle-prod-teacher-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-teacher-files-cdk.s3.amazonaws.com edpuzzle-dev-teacher-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-student-files-cdk.s3.amazonaws.com edpuzzle-dev-student-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-teacher-files-cdk.s3.amazonaws.com edpuzzle-prod-teacher-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-student-files-cdk.s3.amazonaws.com edpuzzle-prod-student-files-cdk.s3.us-east-1.amazonaws.com res.cdn.office.net video-uploads-us-standard.s3.amazonaws.com test-video-uploads-us-standard.s3.amazonaws.com uploaded-images-us-standard.s3.amazonaws.com test-uploaded-images-dev-us-standard.s3.amazonaws.com test-thumbnails-delivery-us-standard.s3.amazonaws.com thumbnails-delivery-us-standard.s3.amazonaws.com vimeo.com *.browser-intake-datadoghq.com browser-intake-datadoghq.com https://*.googletagmanager.com;frame-ancestors 'self';frame-src *;img-src * 'self' data: blob:;style-src * 'unsafe-inline' 'self';media-src * 'self' blob:;report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf89cdec407bbb96fdd48a9726f00e7be&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aedpuzzle-server%2Cenv%3Aproduction%2Cversion%3A7.46.22;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action * 'self';object-src 'none';worker-src 'self' blob:;upgrade-insecure-requests 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://api.github.com/ https://cdnjs.cloudflare.com/ https://cdnjs.cloudflare.com/ajax/libs/ace/1.1.3/ace.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/ https://js.intercomcdn.com https://js.intercomcdn.com/vendor-modern.7a9ca9be.js https://prod.hackster-cdn.online/ https://snap.licdn.com/li.lms-analytics/insight.min.js https://js.intercomcdn.com/ https://widget.intercom.io/widget/l4h7orei https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/; style-src 'report-sample' 'self' 'unsafe-inline' https://prod.hackster-cdn.online https://cdnjs.cloudflare.com/; object-src 'none'; base-uri 'self'; connect-src 'self' blob: https://www.hackster.io/ https://hacksterio.s3.amazonaws.com/ https://7yqjt9bhux-dsn.algolia.net https://analytics.google.com https://api-iam.intercom.io https://api.hackster.io https://o4506440451424256.ingest.sentry.io https://ohm-dot-hackster-io.appspot.com https://prod.hackster-cdn.online https://px.ads.linkedin.com https://px4.ads.linkedin.com https://stats.g.doubleclick.net https://www.google-analytics.com wss://nexus-websocket-a.intercom.io; font-src 'self' data: application/font-woff https://prod.hackster-cdn.online; frame-src 'self' https://lookerstudio.google.com/ https://datastudio.google.com https://www.facebook.com/ https://www.google.com https://www.youtube.com; img-src 'self' data: blob: https://lh6.googleusercontent.com https://lh5.googleusercontent.com https://content.arduino.cc https://avatars.githubusercontent.com https://avatars2.githubusercontent.com/ https://platform-lookaside.fbsbx.com https://www.hackster.io/ https://graph.facebook.com https://gravatar.com https://hackster.imgix.net https://i.ytimg.com https://lh3.googleusercontent.com https://prod.hackster-cdn.online https://px.ads.linkedin.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.newark.com https://px4.ads.linkedin.com; manifest-src 'self' https://prod.hackster-cdn.online; media-src 'self' https://hackster.imgix.net; report-uri https://6620045c077c1adc81b63f22.endpoint.csper.io/?v=2; worker-src blob:; 1 default-src 'self'; connect-src https:; font-src 'self' data: cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; img-src blob: data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; style-src 'self' 'unsafe-inline' cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; worker-src 'self' blob:; 1 default-src 'self'; script-src 'self' 'nonce-nonce-4a6049217ae9a80f99eddebe5eadb866'; img-src 'self' data: https:; font-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; block-all-mixed-content 1 default-src 'none';script-src 'nonce-964e6c12-b909-41e6-a6bd-f49101224ad7' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.com/eum-collector/report/csp-report; 1 default-src 'none';script-src 'nonce-45343249-dec3-4b03-bb7b-e4f2b5d1915c' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.32red.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.32red.com/eum-collector/report/csp-report; 1 default-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.addthis.com *.akamai.net *.convertexperiments.com *.flickr.com *.hotjar.com *.google.com *.sierraclub.org *.twitter.com cdn.ampproject.org cdn.hypemarks.com cdn.jsdelivr.net cdn.optimizely.com connect.facebook.net google-analytics.com google.com googletagmanager.com instagram.com js.maxmind.com maps.googleapis.com partner.googleadservices.com pixel.sitescout.com public.tableau.com reddit.com scribd.com snap.licdn.com unpkg.com v1.addthisedge.com widgets.pinterest.com z.moatads.com; object-src 'self'; style-src 'self' 'unsafe-inline' https: *.sierraclub.org cdn.honey.io cdn.jsdelivr.net cdn.knightlab.com cdnjs.cloudflare.com cloud.typography.com *.hotjar.com fonts.googleapis.com google.com pro.fontawesome.com; img-src * 'unsafe-inline' blob: data: https:; media-src 'self' data:; frame-src 'self' https: *.addthis.com *.doubleclick.net *.fls.doubleclick.net *.ggusd.us *.google.com *.hotjar.com *.optimizely.com *.s3.amazonaws.com *.sierraclub.org *.stpsb.org *.twitter.com block.opendns.com blocked.goguardian.com calendar.google.com cdn.bannersnack.com ckreport.lisd.net clubvolunteer.org facebook.com funnyordie.com gateway.zscalertwo.net global.acs.prismaaccess.com googletagmanager.com instagram.com m.facebook.com maphub.net meetup.com mozbar.moz.com player.vimeo.com public.tableau.com quorum.us rcm-na.amazon-adsystem.com s7.addthis.com spur.maps.arcgis.com static.contextall.com trustpoint-lax.northcentraltrust.com vpn.myips.org web.facebook.com youtube-nocookie.com youtube.com driveelectricweek.org; frame-ancestors 'self' https: blob: sierraclub.org driveelectricweek.org; child-src 'self' https: blob: sierraclub.org driveelectricweek.org; font-src 'self' data: https: *.sierraclub.org at.alicdn.com cdn.honey.io cdn.jsdelivr.net *.hotjar.com fonts.gstatic.com pro.fontawesome.com slant.co; connect-src 'self' https: *.doubleclick.net *.google-analytics.com *.google.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.optimizely.com *.sierraclub.org cdn.linkedin.oribi.io csp.withgoogle.com facebook.com geoip-js.com google-analytics.com googletagmanager.com logx.optimizely.com maps.googleapis.com sharethis.com secure.geonames.org stats.g.doubleclick.net *.osano.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 object-src https://players.brightcove.net https://www.realpage.com https://s.realpage.com https://vjs.zencdn.net;img-src * blob: data:; font-src https://acsbapp.com https://www.realpage.com https://s.realpage.com https://use.typekit.net https://fonts.gstatic.com https://vjs.zencdn.net https://www.slant.co data:; style-src *.typekit.net https://www.realpage.com https://s.realpage.com https://fonts.googleapis.com https://www.gstatic.com https://cdn.jsdelivr.net 'unsafe-inline'; frame-ancestors 'self' *.realpage.com *.seismic.com www.realpagelearning.com *.yieldstar.com *.mpfyieldstar.com; report-to csp-report-only; report-uri https://cspreports.realpage.com/api/reports/save/report-only; 1 frame-ancestors 'self'; report-uri https://www.heraldsun.com.au/csp-reports 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com data:; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://a.usbrowserspeed.com https://pg.feroot.com https://static.hsappstatic.net https://js.hs-scripts.com https://js.hubspot.com https://js-na1.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.usemessages.com https://unpkg.com https://cdn.cookielaw.org https://js.hsforms.net https://tag.trovo-tag.com https://www.clarity.ms https://cdn.cookielaw.org https://www.googletagmanager.com https://www.statcounter.com https://s3-us-west-2.amazonaws.com https://r2.leadsy.ai https://api.hubspot.com; img-src 'self' 'unsafe-inline' data: https://www.googletagmanager.com https://c.clarity.ms https://track.hubspot.com https://cdn.cookielaw.org https://perf-na1.hsforms.com https://forms-na1.hsforms.com; connect-src 'self' https://pro.ip-api.com https://geolocation.onetrust.com https://pageguard.feroot.com https://api.hubspot.com https://cta-service-cms2.hubspot.com wss://statcounter.io https://s.clarity.ms https://n.clarity.ms https://cdn.cookielaw.org https://forms.hsforms.com https://c.statcounter.com https://www.google-analytics.com https://stats.g.doubleclick.net; worker-src blob:; frame-src https://meetings.hubspot.com https://app.hubspot.com https://www.facebook.com; report-uri https://csp.ferootstage.com/18b81144-3bd3-4865-a794-a12c61fe5488/277c4f84-de2d-44c9-9079-40f8187028cb/collect; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.artnews.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 connect-src 'self' https: 'unsafe-eval' https://*.zoom.us wss://zpns.zoom.us wss://widget-mediator.zopim.com; default-src 'self' https:; font-src 'self' https: data: data: source.zoom.us; img-src 'self' https: data: blob: *.zoom.us https://v2assets.zopim.io https://static.zdassets.com; media-src 'self' https: *.zoom.us; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob: http://zoom.us *.zoom.us; style-src 'self' https: 'unsafe-inline'; worker-src 'self' https: blob:; report-uri /csp-report 1 default-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; frame-ancestors 'self' https://teams.microsoft.com https://retailservices.teams.microsoft.com https://retailservices-ppe.teams.microsoft.com https://tasks.teams.microsoft.com https://local.teams.office.com https://devspaces.skype.com https://ssauth.skype.com https://teams.microsoft.com.mcas.ms https://teams.microsoft.com.us3.cas.ms https://local.teams.office.com:8080 https://teams.live.com https://outlook-sdf.office.com https://outlook.office.com/ https://assignments.onenote.com https://assignments.edu.cloud.microsoft https://browser-sandbox.meshxp.net/ https://spoolclientsdk.skype.com https://acsinternal-cte-beta.azurewebsites.net https://acssample-beta.azurewebsites.net https://acssample-stable.azurewebsites.net https://loop.microsoft.com https://*.loop.microsoft.com https://loop.cloud.microsoft https://loop.cloud-dev.microsoft https://app.int.whiteboard.microsoft.com https://whiteboard.cloud-dev.microsoft https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft https://*.whiteboard.microsoft.com https://whiteboard.microsoft.com https://whiteboard.office.com https://teams.cloud.microsoft https://outlook.cloud.microsoft https://m365.cloud.microsoft https://res-sdf.cdn.office.net https://res.cdn.office.net https://mesh.public.onecdn.static.microsoft https://mesh.df.onecdn.static.microsoft https://m365.cloud.microsoft https://sbrprodprv.www.office.com https://scuprodprv.www.office.com https://fa000000174.resources.office.net https://outlook.office.com https://planner.cloud.microsoft; base-uri 'none'; manifest-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; script-src 'self' 'wasm-unsafe-eval' 'report-sample' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft http://amcdn.msftauth.net https://amcdn.msftauth.net https://*.office365.com https://shell.cdn.office.net https://cdn.fluidpreview.office.net https://js.monitor.azure.com https://res-1.cdn.office.net https://res.cdn.office.net https://ch5.fluidpreview.office.net https://cdn.dev.fluidpreview.office.net https://dev.loop.microsoft.com https://res-sdf.cdn.office.net 'sha256-VCkGe6AeV2B4vV7flXt9Dkkp04wMc8zq7faHdRwhOx0=' 'sha256-Wmg7miLkEVn5v393z4Ch7lbKnpNnLZhnVOk/iJN1miE='; style-src 'self' 'unsafe-inline' 'report-sample' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft https://*.office.net https://res.cdn.office.net https://cdn.fluidpreview.office.net https://ch5.fluidpreview.office.net https://cdn.dev.fluidpreview.office.net https://dev.loop.microsoft.com https://res-sdf.cdn.office.net; font-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft data: https://*.office.net https://spoprod-a.akamaihd.net https://static2.sharepointonline.com fs.microsoft.com; img-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft blob: data: https://*.office.com https://*.office365.com https://outlook.live.com https://*.teams.microsoft.com https://*.officeapps.live.com https://web.vortex.data.microsoft.com https://shell.cdn.office.net https://urlp.asm.skype.com https://urlp.sfbassets.com https://login.live.com https://storage.live.com; connect-src 'self' blob: https://* wss://whiteboard.microsoft.com/sync wss://whiteboard.svc.cloud.microsoft/sync wss://whiteboard.svc.cloud.dev.microsoft/sync wss://*.whiteboard.microsoft.com wss://whiteboard.microsoft.com wss://*.svc.ms wss://dogfood.augloop.svc.cloud.microsoft wss://*.dogfood.augloop.svc.cloud.microsoft wss://*.augloop-dogfood.officeppe.com wss://augloop-dogfood.officeppe.com wss://augloop.svc.cloud.microsoft wss://*.augloop.svc.cloud.microsoft wss://*.augloop.office.com wss://augloop.office.com wss://augloop-gcc.office.com wss://*.augloop-gcc.office.com; worker-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; frame-src 'self' https://* https://webshell.suite.office.com; media-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; object-src 'none'; form-action 'self' https://*; report-uri https://csp.microsoft.com/report/WhiteboardWebClient-WhiteboardApp-PROD; report-to csp-endpoint; 1 default-src 'self' *.booztlet.com; script-src 'self' data: blob: bat.bing.com t.contentsquare.net geolocation.onetrust.com *.datadoghq.eu *.g.doubleclick.net cdn.taggstar.com cdn.cookielaw.org www.googletagmanager.com chat.kindlycdn.com *.sleeknote.com www.google.com *.hotjar.com www.snapengage.com 7276579.collect.igodigital.com *.trustpilot.com static.cloudflareinsights.com *.liveshopper.net sleeknotestaticcontent.sleeknote.com cdn.avo.app *.criteo.com track.adform.net *.klarnacdn.net *.criteo.net connect.facebook.net maps.googleapis.com *.hotjar.io cdn.noibu.com www.googleoptimize.com *.datadog.eu *.booztcdn.com *.kronor.io www.datadoghq-browser-agent.com *.google-analytics.com www.googleadservices.com s2.adform.net dev.visualwebsiteoptimizer.com svht.tradedoubler.com sdk.privacy-center.org analytics.tiktok.com sleeknotecustomerscripts.sleeknote.com 'unsafe-eval' 'unsafe-inline'; font-src 'self' *.booztcdn.com fonts.gstatic.com *.booztlet.com *.booztx.com chat.kindlycdn.com fonts.googleapis.com data: ; img-src optimize.google.com https: data: blob: 'unsafe-inline'; connect-src 'self' data: *.visualwebsiteoptimizer.com *.datadoghq.eu *.kronor.io wss://*.kronor.io *.google-analytics.com www.googleadservices.com www.googleoptimize.com api.mkmediaworks.com www.googletagmanager.com api.taggstar.com bat.bing.com *.contentsquare.net kronor.io api.liveshopper.net analytics.tiktok.com cdn.avo.app wss://kronor.io input.noibu.com *.hotjar.com www.google.com www.googleadservices.com stats.g.doubleclick.net www.facebook.com geolocation.onetrust.com *.datadog.eu cdn.cookielaw.org *.hotjar.io *.hotjar.com browser-intake-datadoghq.eu wss://input.noibu.com pagead2.googlesyndication.com *.booztlet.com *.sleeknote.com *.klarnacdn.net *.trustpilot.com *.g.doubleclick.net www.snapengage.com ws.hotjar.com chat.kindlycdn.com *.booztcdn.com www.datadoghq-browser-agent.com *.booztlet.com *.browser-intake-datadoghq.eu dev.visualwebsiteoptimizer.com; child-src 'self' www.googletagmanager.com *.freshchat.com fpt.booztlet.com *.google-analytics.com *.criteo.net www.booztlet.com www.facebook.com *.trustpilot.com blob: ; frame-src 'self' *.kronor.io *.criteo.com *.criteo.com *.sleeknote.com www.googletagmanager.com www.facebook.com *.trustpilot.com *.klarnacdn.net *.hotjar.com connect.facebook.net; style-src 'self' *.sleeknote.com *.booztlet.com cdn.taggstar.com *.booztcdn.com *.kronor.io chat.kindlycdn.com data: blob: 'unsafe-inline'; manifest-src 'self' *.booztlet.com; media-src 'self' data: *.booztcdn.com *.booztlet.com storage.googleapis.com; frame-ancestors 'self' ; report-uri /csp-report/; report-to csp-reports 1 default-src https: data: 'unsafe-eval' 'unsafe-inline'; report-uri /csp_reports 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; 1 default-src 'self' https:; object-src 'none'; img-src 'self' https: blob: data:; font-src 'self' https: data:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https: wss:; report-uri https://buildkite.uriports.com/reports/report 1 script-src 'self' 'unsafe-eval' 'sha256-Tzu6+wuu1SjTdVaXJEV6PivtY9mRqZb0xhhm2BLRAOA=' 'sha256-7IyttL+tUqfo+WQfAWL3v6YMknUKo9ajmbpNtuTjMN0=' 'sha256-3hfUlZv/u0yM7A3uB3JvxOvBYAe8qn24uA4O2An1VRY=' 'sha256-MV1RuepqvbyT5NhbRPeSj1juoiQBimzZ/wO2CMs3kus=' 'sha256-ABZr65Zok8xacqLFUeZR+42Msgxys7C+6WB+vtacJb8=' 'sha256-bHVKPlpu6EceFvLitpQwu5mjjCOghOO0EQqqS41Qn6Q=' 'sha256-wxehmTJycT+YLBVHLN3bWj/zTcxemiqmfRQzTQW8ir4=' 'sha256-xCJKn7hMM9SELWl17uBsfarS81wpzMEJEmq9eKBxtzs=' 'sha256-+2rXXU3laxTDtQNsImGyQ1X64rn4ISQLNShnWzx821g=' 'sha256-/J1Ywi0oxHQHCpzRvtKWWe4P+hIt7HcIaSwR9c4c5Rs=' 'sha256-39X4GDwTjoEuiHC/2kJYF7mNFjiDloAgzPDJAZFmXUA=' 'sha256-4H8OjgRPgGcbXIWnunILQFptlaDulDAprEkdWAmd5rs=' 'sha256-6ncdpKw08Cc1EFsSeeLsVjAIaYvgm1rBcI4cNp12+Qw=' 'sha256-7PIxQkJpqFtF3ibD6pIWa3xB9NioZz/ynQRYzL0/GQk=' 'sha256-7gtkfRfWNDeobU0B/hfsPp2BIWvoaQl9Qnyy5LiRnxs=' 'sha256-FCJSELYJJqB55vIG3t/ph5fM8YdnNvdK1wyBgKoLBv8=' 'sha256-FTGWq2sxofS5L8Yq87ilEpDqn9l5NkLK0cc3sd7OvnM=' 'sha256-IHOzCHp//Jl1lFsowvMxAPGD+T7zlnWM2mFk53CcUCQ=' 'sha256-Lbd7CfEvDCWYMyHY0+sXbfaSIJoSyADQN1msRc5GDNI=' 'sha256-UIJOLWy/Osv+QGQ4imdRlRujM6eUI1MSyU7o0yUPUZY=' 'sha256-ZdDTEfl8xrGn7iZ/2mMDizDIe6JRmep2vz9STHJi4Zs=' 'sha256-av+IGVQJsQwpqceEC0sQFA8e9C8QabH8uLcfyhwM7SQ=' 'sha256-eVK40NIq3UGWc8qEju5kUvLu1HgsUzj88BW49m/q4j0=' 'sha256-ggRYfkK/3LVUNlNZMQmNN9BFxap4CrJfPbtZ6v2xbjo=' 'sha256-grcTsfRWbkeUhSuDjdKCkH5D8wGl/7m/mQ40fxHu0mw=' 'sha256-jFtAwO73SFINACr8TD6icHqaE8VW008cFmXWwD0f9fM=' 'sha256-r217nY7GmxmFONoUAdkKv3HkplOIco6U4dEWu4mrSIs=' 'sha256-u24cgm8XlTjNvJyJKe51ekUDI8IYMtxoJZ/6Obf/+y0=' 'sha256-xGfPUma/ZEUO/hLpxJqIvAXja0IQ6z6bdVSim0NgRs0=' 'report-sample' https://*.doubleclick.net https://*.cdn4.forter.com https://*.google.com https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagservices.com https://*.nr-data.net https://*.yahoo.com https://api.bounceexchange.com https://assets.bounceexchange.com https://at1.listrakbi.com https://bat.bing.com https://bam.nr-data.net https://cdn.attn.tv https://cdn.browsiprod.com https://connect.facebook.net https://code.jquery.com https://cdn.jsdelivr.net https://content.linkedin.com https://cdn.listrakbi.com https://connect.nosto.com https://cdn.roirevolution.com https://f.clarity.ms https://googleads.g.doubleclick.net https://graph.facebook.com https://geoipwebservice.com https://google-analytics.com https://googletagmanager.com https://guarantee-cdn.com https://js.facebook.com https://js-agent.newrelic.com https://platform.linkedin.com https://query.yahooapis.com https://r.bing.com https://r.webeyez.com https://static.cloudflareinsights.com https://ssl.google-analytics.com https://snap.licdn.com https://static-exp1.licdn.com https://services.listrak.com https://s1.listrakbi.com https://s.pinimg.com https://sec.webeyez.com https://s.yimg.com https://tag.bounceexchange.com https://tagmanager.google.com https://www.clarity.ms https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://sdk.helloextend.com/extend-sdk-client/v1/extend-sdk-client.min.js https://cdn1.affirm.com/js/v2/affirm.js https://*.clarity.ms/s/0.6.34/clarity.js;frame-ancestors 'self' *.yahoo.com s.yimg.com;frame-src https://www.affirm.com/ https://creatives.attn.tv/ https://r.webeyez.com/ https://assets.bounceexchange.com/;block-all-mixed-content;style-src 'self' 'report-sample' 'unsafe-inline' *.licdn.com *.google.com *.bing.com code.jquery.com cdn.jsdelivr.net cdn.listrakbi.com www.googletagmanager.com;object-src *.googlesyndication.com;child-src 'self' blob: *.googlesyndication.com *.google.com *.facebook.com *.doubleclick.net connect.facebook.net www.googletagmanager.com;base-uri 'self' *.yahoo.com;form-action 'self' *.google.com *.facebook.com connect.facebook.net;worker-src 'self' blob: www.google.com; report-to default 1 default-src 'self'; connect-src 'self' https://*.analytics.google.com https://*.dacast.com/ https://*.google-analytics.com https://*.googletagmanager.com https://dacastmmd.mmdlive.lldns.net/ https://*.akamaized.net/ https://kinesis.us-east-1.amazonaws.com/ https://license.theoplayer.com/ https://www.cloudflare.com/; font-src 'self' data: https://cdnjs.cloudflare.com/ https://fonts.gstatic.com; frame-src 'self' https://*.icc-cpi.int/ https://*.dacast.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://widgets.ebscohost.com/ https://www.google.com/recaptcha/ https://signup.es-mail.co.uk/; img-src 'self' data: https://*.dacast.com/ https://*.google-analytics.com https://*.googletagmanager.com https://license.theoplayer.com/ https://*.ytimg.com; media-src 'self' blob: data: https://dacastmmd.mmdlive.lldns.net/ https://*.akamaized.net/; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.dacast.com/ https://*.google-analytics.com https://*.googletagmanager.com https://cdn.jsdelivr.net/ https://cdnjs.cloudflare.com/ https://static.cloudflareinsights.com/ https://unpkg.com/ https://www.gstatic.com/ https://cdn.jsdelivr.net https://code.jquery.com https://player.dacast.com https://unpkg.com https://www.google.com platform.twitter.com; style-src 'self' 'unsafe-inline' https://prod-nplayer.dacast.com/ https://*.dacast.com/ https://cdnjs.cloudflare.com/ https://unpkg.com/ https://cdnjs.cloudflare.com; frame-ancestors 'self'; report-uri https://www.icc-cpi.int/report-uri/reportOnly 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=gSTFCIUgcn2xt8M_DZvJYe2oifGSvCrMRbV3Jsdsj8o-1765937209-1.0.1.1-688kOfyFst6Nra1aFgu7XouVKAwTUWpUbyP8s4NZ9qI3sIwWHVn9seJakcT.IgMQWVrPyQf2UA1.Y_XcdLWawPA93mu49UcHvBCIi6p9Zl5ay9u1uqdvnDAbhNFTXkh9CT7hplYS9n6ogmURF3m9Kx.fnb2X941EeI.TbWpRfXfkNl6Vrn1hS3TsTz6ULLKi; report-to cf-csp-endpoint 1 default-src https: data: 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com fonts.gstatic.com *.fontawesome.com *.aspnetcdn.com *.jsdelivr.net *.googletagmanager.com; img-src * data: *.wistia.com; frame-ancestors 'self'; object-src 'none'; form-action 'self' *.hsforms.com *.agencybloc.com *.spinutech.com https://www.facebook.com/tr/; base-uri 'self'; media-src s3.amazonaws.com blob: *.wistia.com *.wistia.net; report-uri /csp/; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com chat.bncenlinea.com:8000 ajax.googleapis.com 341d26ed8226.bncenlinea.com ajax.aspnetcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com d3i9pllfrk5tet.cloudfront.net d3q4nr72nuserl.cloudfront.net maxcdn.bootstrapcdn.com s3.amazonaws.com www.googletagmanager.com s3.amazonaws.com;style-src 'self' 'unsafe-inline' maxcdn.bootstrapcdn.com fonts.googleapis.com d3i9pllfrk5tet.cloudfront.net d3q4nr72nuserl.cloudfront.net;font-src 'self' d3i9pllfrk5tet.cloudfront.net fonts.gstatic.com fonts.googleapis.com; img-src 'self' data: s3.amazonaws.com d3i9pllfrk5tet.cloudfront.net d3q4nr72nuserl.cloudfront.net;connect-src 'self' ajax.aspnetcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com cloudfront.net 341d26ed8226.bncenlinea.com www.google-analytics.com; 1 default-src 'self'; script-src 'nonce-UjFhQtVR0InVoYmgPL7r3A==' 'strict-dynamic' https: 'unsafe-inline'; style-src 'self' 'unsafe-inline' blob: https://app.getbeamer.com https://assets.openlearning.com https://*.ssl.cf4.rackcdn.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.openlearning.com https://oluploadslive.blob.core.windows.net https://front-us-rest.ably.io https://api.amplitude.com https://api.hubapi.com https://api.hubspot.com https://api.ipify.org https://backend.getbeamer.com https://chat.frontapp.com https://www.facebook.com https://find.userpilot.io https://forms.hubspot.com https://iframe.ly https://in.hotjar.com https://learningtime.servicebus.windows.net https://pythonutilityfunctions.azurewebsites.net https://python-util-funcs-c2dzg6bdbrdbd0g6.australiaeast-01.azurewebsites.net https://sentry.io https://stats.g.doubleclick.net https://us-west-1-chat-server.frontapp.com https://vc.hotjar.io https://www.google-analytics.com https://pagead2.googlesyndication.com https://static.userguiding.com https://metrics.userguiding.com wss://analytex.userpilot.io wss://front-us-realtime.ably.io wss://*.openlearning.com; font-src 'self' data: https://*.ssl.cf4.rackcdn.com https://assets.openlearning.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; frame-src 'self' https:; img-src 'self' data: blob: https:; manifest-src 'self' https://*.ssl.cf4.rackcdn.com; media-src 'self' https://dev-uploads.openlearning.com https://uploads.openlearning.com https://qencode.blob.core.windows.net; worker-src 'none'; child-src blob:; 1 default-src 'self' https://*.sugarondemand.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.avery.com https://*.osano.com https://analytics.tiktok.com https://www.google-analytics.com https://s.pinimg.com https://*.bazaarvoice.com https://*.dynamicyield.com https://js.squarecdn.com https://*.usablenet.com https://www.googletagmanager.com https://*.livechatinc.com https://unpkg.com/web-vitals/dist/web-vitals.iife.js https://*.google.com https://*.debugbear.com https://cdnjs.cloudflare.com/ajax/libs/picturefill/3.0.3/picturefill.min.js https://cdn.jsdelivr.net/npm/jquery@3.5.1/dist/jquery.slim.min.js https://cdn.jsdelivr.net/npm/bootstrap@4.1.3/dist/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/tether/1.4.0/js/tether.min.js https://*.salesloft.com https://*.bc0a.com https://*.attn.tv https://*.lrkt-in.com https://connect.facebook.net https://www.gstatic.com https://ct.pinterest.com https://*.curalate.com https://www.redditstatic.com https://*.doubleclick.net https://*.bing.com https://cdn.dashhudson.com/web/js/board-carousel-embed.js https://cdn.jsdelivr.net/npm/swiper@11/ https://*.cloudinary.com https://ajax.googleapis.com/ajax/libs/jquery/3.2.1/jquery.min.js https://cdn.jsdelivr.net/npm/popper.js@1.16.1/dist/umd/popper.min.js https://cdnjs.cloudflare.com/ajax/libs/lightbox2/2.11.5/js/lightbox-plus-jquery.min.js 'wasm-unsafe-eval' https://*.glance.net https://*.glancecdn.net https://*.amazon-adsystem.com https://container.pepperjam.com https://cdn.lgrckt-in.com/logger-1.min.js *.udev1a.net *.usablenet.com https://cdn.jsdelivr.net/npm/beerslider@1.0.3/dist/BeerSlider.js; style-src 'self' 'unsafe-inline' https://*.avery.com https://fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css https://*.typekit.net https://cdn.jsdelivr.net/npm/swiper@11/swiper-bundle.min.css https://cdnjs.cloudflare.com/ajax/libs/lightbox2/2.11.5/css/lightbox.min.css https://*.glance.net https://*.glancecdn.net https://avery-static-tailwind.s3.us-east-1.amazonaws.com/ *.udev1a.net *.usablenet.com https://cdn.jsdelivr.net/npm/beerslider@1.0.3/dist/BeerSlider.css; img-src 'self' data: https://*.avery.com https://www.google-analytics.com https://www.googletagmanager.com https://*.afterpay.com https://*.bazaarvoice.com https://*.doubleclick.net https://*.usablenet.com https://www.facebook.com https://*.dynamicyield.com https://*.livechatinc.com https://s3.amazonaws.com https://*.gstatic.com https://*.sugarondemand.com https://i.ytimg.com https://*.reddit.com https://*.bing.com https://*.cloudfront.net https://likeshop.me https://images.dashsocial.com https://images.dashhudson.com https://*.google.com https://*.glance.net https://*.glancecdn.net https://tvspix.com https://arttrk.com; font-src 'self' data: https://*.avery.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://*.squarecdn.com https://*.bazaarvoice.com https://*.typekit.net https://likeshop.me https://*.glance.net https://*.glancecdn.net; connect-src 'self' https://*.avery.com https://*.dynamicyield.com https://*.doubleclick.net https://dy-api.com https://www.google-analytics.com https://*.osano.com https://ct.pinterest.com https://analytics.tiktok.com https://*.bazaarvoice.com https://*.salesloft.com https://*.lrkt-in.com https://*.bc0a.com https://events.attentivemobile.com https://*.attn.tv https://*.afterpay.com https://server-side-tagging-ykzfrilmoq-uc.a.run.app https://*.amplitude.com https://*.google.com https://*.salsify.com https://salsify-ecdn.com https://*.curalate.com https://ls.chatid.com/events https://*.reddit.com https://www.redditstatic.com https://*.debugbear.com https://*.bing.com https://www.googleadservices.com https://api.likeshop.me/gallery-more https://www.facebook.com *.livechatinc.com wss://*.glance.net https://*.glance.net https://*.glancecdn.net https://direct-collect.dy-api.com https://*.amazon-adsystem.com https://ara.paa-reporting-advertising.amazon https://analytics-ipv6.tiktokw.us https://google.com https://r.lgrckt-in.com/i https://*.braintreegateway.com https://*.braintree-api.com; frame-src 'self' https://*.avery.com https://ct.pinterest.com https://*.google.com https://*.doubleclick.net https://*.livechatinc.com https://*.afterpay.com https://*.attn.tv https://www.facebook.com https://salsify-ecdn.com https://www.youtube.com https://server-side-tagging-ykzfrilmoq-uc.a.run.app https://www.googletagmanager.com https://*.amazon-adsystem.com https://*.cloudinary.com https://*.sugarondemand.com https://*.glance.net https://*.braintreegateway.com; frame-ancestors 'self' https://*.avery.com https://*.google.com; worker-src 'self' blob:; object-src 'none'; report-uri /_api/csp-report; report-to csp-endpoint; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-M4SJRekpjypf8V5DESeW0w==' 1 default-src 'none'; child-src 'self'; connect-src 'self' data: 173-yrh-728.mktoresp.com/ 173-yrh-728.mktoweb.com/ https://*.marketo.com https://*.marketo.net https://*.mktoutil.com https://*.mktoweb.com https://173-yrh-728.mktoresp.com https://analytics.google.com https://analytics.google.com/ https://analytics.tiktok.com https://api.software-downloading.com https://apm-volcano.zuoyebang.com https://app.reprintsdesk.com https://baidustatics.net https://c.ba.contentsquare.net https://cdn-ukwest.onetrust.com https://cdn-ukwest.onetrust.com/ https://cdn.shopimgs.com https://cdnml.global-cache.online https://cdnmmh.global-cache.online https://code.jquery.com https://connect.facebook.net/ https://dc.services.visualstudio.com/v2/track https://esp-eu.aptrinsic.com https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://l.clarity.ms https://pagead2.googlesyndication.com/ccm/ https://player.podigee-cdn.net https://privacyportal-uk.onetrust.com https://px.ads.linkedin.com/ https://region1.analytics.google.com https://region1.google-analytics.com/g/ https://res-1.cdn.office.net https://stats.g.doubleclick.net https://vc.hotjar.io/ https://www.facebook.com/ https://www.google.co.uk https://www.google.com https://www.google.ie/ https://www.googletagmanager.com https://y.clarity.ms www.google-analytics.com/g/ www.google.com/ccm/; font-src 'self' data: https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/ https://fonts.gstatic.com/ https://player.podigee-cdn.net; form-action 'self' https://www.facebook.com/; frame-src 'self' 173-yrh-728.mktoresp.com/ 173-yrh-728.mktoweb.com/ https://flo.uri.sh/ https://player.podigee-cdn.net https://td.doubleclick.net https://www.googletagmanager.com/ https://www.youtube-nocookie.com; img-src 'self' data: https://*.google.co.in https://*.linkedin.com https://a.emea01.idio.episerver.net/ https://c.clarity.ms https://cdn-ukwest.onetrust.com/ https://player.podigee-cdn.net https://public.flourish.studio/resources/bosh.svg https://px.ads.linkedin.com https://px.ads.linkedin.com/ https://px4.ads.linkedin.com/ https://www.facebook.com/ https://www.google.ca https://www.google.co.uk https://www.google.ie/ https://www.googletagmanager.com https://www.googletagmanager.com/td www.facebook.com/privacy_sandbox/ www.google.com/pagead/; media-src 'self'; script-src-elem 'self' 'unsafe-inline' 173-yrh-728.mktoresp.com/ 173-yrh-728.mktoweb.com/ https://*.marketo.com https://acsbapp.com/apps/app/dist/js/app.js https://analytics.tiktok.com https://cdn-ukwest.onetrust.com/scripttemplates/ https://connect.facebook.net/ https://googleads.g.doubleclick.net https://js.monitor.azure.com/scripts/b/ai.2.gbl.min.js https://lonrtp1.marketo.com https://munchkin.marketo.net/ https://player.podigee-cdn.net https://public.flourish.studio/resources/embed.js https://s.emea01.idio.episerver.net/ia.js https://script.hotjar.com/ https://scripts.clarity.ms https://snap.licdn.com/li.lms-analytics/ https://static.hotjar.com/c/ https://www.clarity.ms https://www.googletagmanager.com/ https://www.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://connect.facebook.net/ https://player.podigee-cdn.net https://public.flourish.studio/resources/embed.js; style-src-elem 'self' 'unsafe-inline' 173-yrh-728.mktoresp.com/ 173-yrh-728.mktoweb.com/ https://cdn.jsdelivr.net/npm/gsap@3.12.5/dist/gsap.min.js https://rtp-static.marketo.com; style-src 'self' 'unsafe-inline'; script-src-attr https://public.flourish.studio/resources/embed.js; report-to stott-security-endpoint;report-uri https://www.arup.com/stott.security.optimizely/api/cspreporting/reporturiviolation/; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.stripe.com *.klarna.com *.klarnaevt.com *.klarnacdn.net klarna.com https://fonts.gstatic.com https://static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.facebook.com * 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com *.google.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.weltpixel.com *.stripe.com * consentcdn.cookiebot.com consentcdn.cookiebot.eu c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com challenges.cloudflare.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.awin1.com *.zenaps.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.magezon.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com * imgsct.cookiebot.com imgsct.cookiebot.eu www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pushalert.co www.xtento.com cdn.xtento.com lookaside.fbsbx.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com s7.addthis.com *.avada.io *.google.com/ *.facebook.com https://connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com https://maps.googleapis.com https://static.hotjar.com * https://www.googletagmanager.com tagmanager.google.com consent.cookiebot.com consent.cookiebot.eu js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com challenges.cloudflare.com *.pushalert.co www.xtento.com cdn.xtento.com *.loudcrowd.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com cc-cdn.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.stripe.com *.klarna.com *.klarnaevt.com *.klarnacdn.net assets.braintreegateway.com tagmanager.google.com https://fonts.googleapis.com *.loudcrowd.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com lookaside.fbsbx.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://the.sciencebehindecommerce.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com https://developer.adobe.com https://maps.googleapis.com * https://www.google-analytics.com consentcdn.cookiebot.com consentcdn.cookiebot.eu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.pushalert.co *.loudcrowd.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.de/api/csp-report; report-to csp-endpoint 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://cloud.google.com https://*.kameleoon.io http://*.kameleoon.io https://www.googletagmanager.com http://www.googletagmanager.com https://pagead2.googlesyndication.com https://connect.facebook.net/ https://analytics.tiktok.com https://securepubads.g.doubleclick.net https://sc-static.net https://via.batch.com https://ep2.adtrafficquality.google/sodar/sodar2.js https://halc.iadvize.com http://halc.iadvize.com https://static.iadvize.com https://tr.snapchat.com https://dynamic.criteo.com https://sslwidget.criteo.com https://www.clarity.ms https://scripts.clarity.ms https://tpc.googlesyndication.com https://imasdk.googleapis.com http://imasdk.googleapis.com https://googleads.g.doubleclick.net https://cdn.goodays.co https://cdn.mappedin.com https://img.metaffiliation.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com http://fonts.googleapis.com https://cdn.cookielaw.org https://halc.iadvize.com https://static.iadvize.com https://imasdk.googleapis.com http://imasdk.googleapis.com https://cdn.goodays.co https://cdn.mappedin.com; img-src 'self' data: blob: https://res.cloudinary.com https://images.ctfassets.net https://www.google-analytics.com https://www.googletagmanager.com https://tpc.googlesyndication.com https://pagead2.googlesyndication.com https://ep1.adtrafficquality.google https://cdn.cookielaw.org https://ad.doubleclick.net https://googleads.g.doubleclick.net https://pubads.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://tr.snapchat.com https://www.google.com http://www.google.com https://www.google.co.ma https://c.clarity.ms https://c.bing.com https://resize-worker.mappedin.com https://cdn.mappedin.com https://*.westfield.com; font-src 'self' data: https://fonts.gstatic.com https://static.iadvize.com https://*.cloudfront.net; connect-src 'self' https://api.prod.westfield.digital.cloud.urw.com https://api.qa.westfield.digital.cloud.urw.com https://api.dev.westfield.digital.cloud.urw.com https://api.dev-sqli.westfield.digital.cloud.urw.com https://api.stag.westfield.digital.cloud.urw.com https://api.westfield.com https://ad.doubleclick.net https://securepubads.g.doubleclick.net https://graphql.eu.contentful.com https://prod.sgtm.westfield.com https://via.batch.com https://ws.batch.com https://pagead2.googlesyndication.com https://eu-data.kameleoon.io https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com https://cdn.cookielaw.org https://cdn.acsbapp.com https://analytics-api-s.cloudinary.com https://res.cloudinary.com https://video-analytics-api.cloudinary.com https://geolocation.onetrust.com https://unibail-privacy.my.onetrust.com https://ep1.adtrafficquality.google https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://halc.iadvize.com http://halc.iadvize.com https://api.iadvize.com https://tr.snapchat.com https://tr6.snapchat.com https://mapserver.visioglobe.com https://s.visioglobe.com https://measurement-api.criteo.com https://*.clarity.ms https://www.facebook.com https://csi.gstatic.com https://redirector.gvt1.com https://*.gvt1.com https://web.prod.westfield.digital.cloud.urw.com https://web.qa.westfield.digital.cloud.urw.com https://web.dev.westfield.digital.cloud.urw.com https://web.stag.westfield.digital.cloud.urw.com http://web.prod.westfield.digital.cloud.urw.com http://web.qa.westfield.digital.cloud.urw.com http://web.dev.westfield.digital.cloud.urw.com http://web.stag.westfield.digital.cloud.urw.com https://www.westfield.com https://api-gateway.mappedin.com https://cdn.mappedin.com https://auth.mappedin.com https://tiles-cdn.mappedin.com; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://www.googleadservices.com https://*.fls.doubleclick.net https://prod.sgtm.westfield.com https://securepubads.g.doubleclick.net https://*.safeframe.googlesyndication.com https://tr.snapchat.com https://cm.g.doubleclick.net/ https://ep2.adtrafficquality.google https://gum.criteo.com https://www.facebook.com https://app.goodays.co https://centers.cenomi.com; worker-src 'self' blob: https://via.batch.com https://ws.batch.com; media-src 'self' data: blob: https://www.snuffleupagus.click; object-src 'none'; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'self' https://id.westfield.com https://qa.id.westfield.com https://dev.id.westfield.com https://*.westfield.com https://*.urw.com https://web.prod.westfield.digital.cloud.urw.com https://web.qa.westfield.digital.cloud.urw.com https://web.dev.westfield.digital.cloud.urw.com https://web.stag.westfield.digital.cloud.urw.com https://www.google.com; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://wwd.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'self'; connect-src 'self' https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://pagesense-collect.zoho.com https://stats.g.doubleclick.net https://translate.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://connect.facebook.net https://m.facebook.com https://maps.google.com https://maps.googleapis.com https://mobile.facebook.com https://platform.twitter.com https://static.addtoany.com https://web.facebook.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: blob: https://*.google-analytics.com https://*.analytics.google.com https://fonts.gstatic.com https://pagesense-collect.zoho.com https://*.fbcdn.net https://stats.g.doubleclick.net https://translate.google.com https://translate.googleapis.com https://www.gcis.gov.za https://www.google.com https://www.google.co.za https://www.googletagmanager.com https://www.gov.za https://www.gstatic.com https://www.publicsectormanager.gov.za https://www.sanews.gov.za https://www.vukuzenzele.gov.za https://*.openstreetmap.org https://*.ytimg.com https://www.google-analytics.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://cdn.pagesense.io https://connect.facebook.net https://maps.googleapis.com https://platform.twitter.com https://static.addtoany.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com https://platform.twitter.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.gov.za/system/reporting/default; report-to default 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com http2.mlstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.mercadolibre.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com mldp.mercadopago.com www.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net imgmp.mlstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.mercadopago.com.ar www.mercadopago.cl *.google.com *.online-metrix.net *.groovinads.com *.g.doubleclick.net *.clarity.ms *.bing.com *.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.braindw.com *.mlstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br http2.mlstatic.com secure.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.googleapis.com *.google.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com h.online-metrix.net https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ i.k-analytix.com rum-static.pingdom.net live.decidir.com *.newrelic.com bam-cell.nr-data.net https://api.wcx.cloud https://static-s.braindw.com https://f.wcentrix.com https://ads01.groovinads.com https://static.hotjar.com https://script.hotjar.com https://connect.facebook.net https://googleads.g.doubleclick.net *.groovinads.com *.online-metrix.net *.bing.com *.clarity.ms *.cloudfront.net *.force.com *.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.varify.io *.collect.igodigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ http2.mlstatic.com *.force.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.braindw.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://developers.decidir.com/ https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.google-analytics.com i.konduto.com rum-collector-2.pingdom.net *.mercadolibre.com.ar *.decidir.com bam-cell.nr-data.net https://stats.g.doubleclick.net https://s.braindw.com https://a.braindw.com https://api.wcx.cloud https://f.wcentrix.com *.g.doubleclick.net *.nr-data.net *.clarity.ms *.online-metrix.net *.varify.io *.bing.com *.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src maxcdn.bootstrapcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self' https:; base-uri https://www.elysee.fr; block-all-mixed-content; child-src *; font-src 'self' data: https://fonts.gstatic.com https://www.elysee.fr https://admin.elysee.fr https://www.elysee.fr; form-action 'self'; frame-ancestors 'none'; img-src https://stats.g.doubleclick.net data: https://www.elysee.fr https://admin.elysee.fr https://www.elysee.fr https://captcha.liveidentity.com; plugin-types video/*; script-src 'unsafe-inline' https://www.elysee.fr https://isho.elysee.fr https://admin.elysee.fr https://www.elysee.fr https://captcha.liveidentity.com https://platform.twitter.com https://www.instagram.com; style-src https://fonts.googleapis.com 'unsafe-inline' https://www.elysee.fr https://admin.elysee.fr https://www.elysee.fr 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.sportico.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 object-src 'none';base-uri 'self';script-src 'nonce-r+3dT7kH3ALR+xywX2iF' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.galvia.ai https://helper.portsmouth.galvia.ai www-embed-player.js *.cookiebot.com *.cookiefirst.com *.google-analytics.com www.instagram.com *.facebook.net *.tiktok.com *.ads-twitter.com *.twitter.com lf16-tiktok-web.ttwstatic.com cdn.unibuddy.co *.googletagmanager.com bat.bing.com w.soundcloud.com s.yimg.com sc-static.net snap.licdn.com www.googleadservices.com *.doubleclick.net siteimproveanalytics.com www.youtube.com *.hotjar.com *.linkedin.com service.force.com *.salesforceliveagent.com universityofportsmouth.my.salesforce.com *.formstack.com *.googleapis.com cdn.jsdelivr.net www.google.ie sfapi.formstack.io az416426.vo.msecnd.net discoveruni.gov.uk *.discoveruni.gov.uk *.matterport.com webteamuop.github.io *.port.ac.uk *.secure.force.com portsmouthuni.h5p.com *.go-mpulse.net js-agent.newrelic.com *.algolia.net *.jquery.com bot.ivy.ai bam.nr-data.net *.force.com *.clarity.ms dev.visualwebsiteoptimizer.com artsthread.com tr.snapchat.com tags.srv.stackadapt.com https://rv-vepple-embed.web.app https://builder.lift.acquia.com universityofportsmouth.my.salesforce-sites.com vimeo.com https://player.vimeo.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com universityofportsmouth--chatbotdv2.sandbox.lightning.force.com universityofportsmouth.tfaforms.net universityofportsmouth--qa.sandbox.my.site.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://helper.portsmouth.galvia.ai modernizr.min.js *.googleapis.com platform.twitter.com lf16-tiktok-web.ttwstatic.com *.force.com static.formstack.com formsprod.azureedge.net sfapi.formstack.io port.formstack.com *.cookiefirst.com webteamuop.github.io *.port.ac.uk *.googletagmanager.com artsthread.com tags.srv.stackadapt.com *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com s3.amazonaws.com universityofportsmouth.my.salesforce-sites.com embed.tawk.to *.tawk.to cdn.jsdelivr.net builder.lift.acquia.com *.formstack.io universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com universityofportsmouth.my.salesforce.com; img-src 'self' data: *.google-analytics.com i.vimeocdn.com i.ytimg.com *.googletagmanager.com jadserve.postrelease.com bat.bing.com sp.analytics.yahoo.com *.siteimproveanalytics.io *.facebook.com *.facebook.net *.twitter.com t.co *.doubleclick.net googleads.g.doubleclick.net *.linkedin.com uks-prd-xp2-cd.azurewebsites.net ormsprod.azureedge.net port.formstack.com maps.gstatic.com *.googleapis.com lh3.ggpht.com www.google.ie *.cookiefirst.com formsprod.azureedge.net discoveruni.gov.uk *.force.com *.universityofportsmouth.my.salesforce.com *.salesforce.com *.port.ac.uk bot.ivy.ai *.clarity.ms *.bing.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com cdn.pushcrew.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google eat2mpk5ajg.exactdn.com *.eat2mpk5ajg.exactdn.com blob: https://egopbtuk8gz.exactdn.com *.egopbtuk8gz.exactdn.com *.frontdoorcdn.formstack.io https://frontdoorcdn.formstack.io images.artsthread.com *.google.co.uk https://cdn.galvia.ai/portsmouth/nellie-helper.js https://helper.portsmouth.galvia.ai ; media-src 'self'; frame-src 'self' https://www.googletagmanager.com https://helper.portsmouth.galvia.ai player.vimeo.com www.youtube.com *.linkedin.com portsmouthuni.h5p.com w.soundcloud.com viewer.joomag.com *.cookiebot.com www.instagram.com *.facebook.com *.tiktok.com *.twitter.com embed.acast.com unibuddy.co popcard.unibuddy.co tr.snapchat.com *.doubleclick.net view.genial.ly service.force.com *.hotjar.com *.matterport.com webteamuop.github.io universityofportsmouth.force.com *.port.ac.uk *.secure.force.com open.spotify.com *.google.com port.cloud.panopto.eu bot.ivy.ai app.nearpod.com *.visualwebsiteoptimizer.com universityofportsmouth.my.salesforce-sites.com *.tawk.to https://cdn.galvia.ai/portsmouth/nellie-helper.js universityofportsmouth.my.salesforce.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com; frame-ancestors 'self' portsmouthuni.h5p.com; child-src 'self' blob:; font-src 'self' data: fonts.gstatic.com use.typekit.net *.modernizr.min.js static.formstack.com fonts.googleapis.com bot.ivy.ai cdn.scite.ai embed.tawk.to *.tawk.to res-1.cdn.office.net; connect-src 'self' *.google-analytics.com www.googletagmanager.com marketing.port.ac.uk sentry10.bynder.cloud www.ucas.com *.tiktok.com tr.snapchat.com *.doubleclick.net s.yimg.com *.linkedin.com *.secure.force.com sfapi.formstack.io *.googleapis.com *.algolia.net *.cookiefirst.com ohpuem12fk-3.algolianet.com *.facebook.com vc.hotjar.io dc.services.visualstudio.com prod-discoveruni.azure-api.net cdn.linkedin.oribi.io webteamuop.github.io *.algolianet.com *.go-mpulse.net bam.nr-data.net *.akstat.io *.akamaihd.net *.hotjar.com plugin.ucads.ucweb.com *.clarity.ms tags.srv.stackadapt.com *.visualwebsiteoptimizer.com app.vwo.com *.port.ac.uk vimeo.com universityofportsmouth.my.salesforce-sites.com artsthread.com eu.perz-api.cloudservices.acquia.io *.google.com va.tawk.to embed.tawk.to *.tawk.to wss://*.tawk.to insights.algolia.io virtual.port.ac.uk *.virtual.port.ac.uk *.analytics.pangle-ads.com https://api.portsmouth.rvhosted.com eat2mpk5ajg.exactdn.com *.eat2mpk5ajg.exactdn.com https://google.com blob: https://analytics.pangle-ads.com https://egopbtuk8gz.exactdn.com *.egopbtuk8gz.exactdn.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com 1 report-to cf-csp-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: wss://*.dathost.net https://*.dathost.net https://www.googletagmanager.com https://*.cookieyes.com https://cdn-cookieyes.com https://analytics.ahrefs.com https://widget.trustpilot.com https://*.clarity.ms https://c.bing.com/ https://beacon-v2.helpscout.net https://beaconapi.helpscout.net https://d3hb14vkzrxvla.cloudfront.net https://d33v4339jhl8k0.cloudfront.net https://cdnjs.cloudflare.com https://*.js.stripe.com https://js.stripe.com https://api.stripe.com https://hooks.stripe.com https://maps.googleapis.com https://*.gravatar.com https://s3.dathost.net https://www.paypalobjects.com https://i0.wp.com https://i2.wp.com https://fonts.gstatic.com https://media.forgecdn.net https://avatars.steamstatic.com https://accounts.google.com https://challenges.cloudflare.com https://i.gyazo.com https://i.imgur.com https://i.ytimg.com https://*.youtube.com https://fonts.googleapis.com https://use.typekit.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.ae https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bg https://www.google.by https://www.google.ca https://www.google.ch https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.kr https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.ve https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.at https://www.google.com.au https://www.google.com.bg https://www.google.com.bh https://www.google.com.br https://www.google.com.co https://www.google.com.cy https://www.google.com.hk https://www.google.com.kh https://www.google.com.lb https://www.google.com.mm https://www.google.com.mx https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.qa https://www.google.com.sg https://www.google.com.tj https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.vn https://www.google.cz https://www.google.de https://www.google.dk https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.it https://www.google.kz https://www.google.lt https://www.google.lv https://www.google.md https://www.google.mk https://www.google.mn https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.ru https://www.google.rs https://www.google.se https://www.google.sk https://www.googleadservices.com; report-uri /internal-api/csp-report 1 script-src 'unsafe-eval' 'unsafe-inline' https: 'nonce-bd637c4c61745cb86a1e699b77b146ac' 'strict-dynamic'; report-uri /api/fb/cspLogs; script-src-attr 'sha256-bwK6T5wZVTANitXbrTsel7kl/PyCjCd/Dq5Qoz3imjM=' 'unsafe-hashes'; 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; worker-src blob:; report-uri https://search.ch/api/mixedcontent.json 1 script-src 'nonce-H6GAYE7yod1Jc7/pq3Inwg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=9d29eae4-6306-42fe-916f-3a4617f30bfb; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'none'; script-src 'self' 'unsafe-eval' 'strict-dynamic'; script-src-elem 'self' https://gmgn.ai https://*.gmgn.ai https://*.gmgn.cc https://static.cloudflareinsights.com https://www.googletagmanager.com https://challenges.cloudflare.com https://www.recaptcha.net https://performance.radar.cloudflare.com https://gcaptcha4.geetest.com https://static.geetest.com https://www.gstatic.com https://www.google-analytics.com 'sha256-HFZNL/mR8uHdwzdRF0KuC+AZwCVUEW4VUWL+li+2xGk=' 'sha256-UsWyQRLpYVWm5qrf+4vzBAksnkbPWegTVcIEP5ffo8Q=' 'sha256-dxRWb87NCxmjmBNw5xAnCdyGF1BT+/Rwfz5Q3IPVN2w=' 'sha256-Imv8rgvxn2GP4QJH/s+T5I8tEtsRwclyX3+LH36ke+U=' 'sha256-pDwM8EWjctpZgxxhIK4A0230b/xbz86xLQfbX0HBbMk='; frame-src 'self' https://gmgn.ai https://*.gmgn.ai https://app.insightx.network https://pro.chaininsight.vip https://faster100x.com https://www.recaptcha.net https://challenges.cloudflare.com https://player.twitch.tv https://verify.walletconnect.org https://www.youtube.com https://www.instagram.com https://www.tiktok.com blob:; object-src 'none'; base-uri 'self'; worker-src 'self' blob:; connect-src 'self' https://gmgn.ai https://*.gmgn.ai wss://*.gmgn.ai wss://gmgn.ai https://www.google-analytics.com https://o4505147559706624.ingest.us.sentry.io https://pulse.walletconnect.org https://api.web3modal.org wss://relay.walletconnect.org https://eth.merkle.io https://region1.google-analytics.com https://mainnet.base.org https://infragrid.v.network https://56.rpc.thirdweb.com https://www.googletagmanager.com https://gmgn-upload-video.s3.us-west-2.amazonaws.com https://pbs.twimg.com https://www.recaptcha.net https://abs.twimg.com wss://*.metamask.io https://*.metamask.io https://static.four.meme blob:; img-src 'self' https://gmgn.ai https://*.gmgn.ai https://static.four.meme https://*.twimg.com https: data: blob:; media-src 'self' https://*.twimg.com https://*.truthsocial.com data:; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://static.geetest.com blob:; font-src 'self' https://fonts.gstatic.com https://at.alicdn.com data:; form-action 'self' https://gmgn.ai https://*.gmgn.ai; frame-ancestors 'self'; manifest-src 'self'; report-uri https://gmgn.ai/csp-report/csp-report?m=gAAAAAAAAAAAV5wKLSUJobSjThhsJ8mEO2QK3jhpCdcqAVOe1mQ7cfpfHAn3iPw5pZF9oOjeP6V2VRisRNPikqojUPnntFoxbptR4WoB3RpRHqy5ZQc4c_XtJWRoCE-ZhlCMkRWgD_jss2mHDlI3Ykiy-vnXvZnn3g==; report-to gmgn-csp-endpoint 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.vibe.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src https: 'self' data: blob:; script-src https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'self' 'unsafe-inline' blob:; report-uri https://services.fandom.com/csp-logger/csp/f2 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.drmartens.com *.adyen.com *.google.com *.onetrust.com *.monetate.net js-agent.newrelic.com *.cloudflare.com static.cloudflareinsights.com *.paypal.com *.klaviyo.com js.afterpay.com cdn.attraqt.io *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net d2w2nqfk3z9hdt.cloudfront.net *.global-e.com www.googletagmanager.com www.google-analytics.com x.klarnacdn.net js.klarna.com assets.ntcacdn.net cdn-widgetsrepository.yotpo.com staticw2.yotpo.com www.recaptcha.net maps.googleapis.com www.googleadservices.com googleads.g.doubleclick.net pagead2.googlesyndication.com ad.doubleclick.net www.gstatic.com connect.facebook.net connect.facebook.net static.srcspot.com analytics.tiktok.com cdn.userway.org bat.bing.com *.attn.tv c.amazon-adsystem.com photorankstatics-a.akamaihd.net widgets.olapic-cdn.com s.pinimg.com ct.pinterest.com *.contentsquare.net tr.snapchat.com sc-static.net *.upsellit.com tag.rmp.rakuten.com www.redditstatic.com api.myunidays.com cdn.unidays.world rum-static.pingdom.net *.storystream.ai ucarecdn.com; worker-src 'self'; report-uri /cdn-cgi/script_monitor/report?m=kSZyymubAgEb_gNDsyPq2ISUCfwNv0K8bTdQXjuhKyY-1765939159.800045-1.0.1.1-O.fZYUtLUYMzQYvAsCBKTAPS1limX94tJcth6roJVRP8mT2M6iYmL0uCleeldfeJm1F2NOf4uwDrT1fyxH_95.eW5MipBhVb8Z1FQqRiA_Mlyp5VwdFE2Vp4Hi15jKm2F7MqyJDvwQxz6cSp00xbmlBLNqGwbltTU5wlDIpIUxHoTAQc4MinpLx6G9Hs2uU25PPqGntKD2ac558azxc89A; report-to cf-wcqsiskcdcnishmc 1 report-uri /report-violation; form-action 'self' https://*.formlabs.com https://*.marketo.com https://www.facebook.com/tr/; base-uri 'self'; object-src https://formlabs.com https://*.formlabs.com http://localhost:3001; frame-ancestors https://partneruniversity-formlabs.talentlms.com https://university-formlabs.talentlms.com https://internal-formlabs.talentlms.com https://formlabs.com https://*.formlabs.com https://dental.formlabs.com https://careers.formlabs.com http://localhost:3000; upgrade-insecure-requests 1 require-trusted-types-for 'script';report-uri /us/_/BgcMiscSites/cspreport 1 default-src 'self' https://smartcaptcha.yandexcloud.net; script-src 'self' 'unsafe-eval' 'nonce-9KafQzYxjt2wnqjCYmkFTw==' https://mc.yandex.ru https://yastatic.net https://mod.calltouch.ru https://smartcaptcha.yandexcloud.net https://vk.com https://ab-ct.ru https://abt.s3.yandex.net https://st.top100.ru https://api-maps.yandex.ru https://core-renderer-tiles.maps.yandex.net https://unpkg.com; style-src 'self' 'nonce-9KafQzYxjt2wnqjCYmkFTw==' data: https://unpkg.com; img-src 'self' data: blob: https://mc.yandex.ru https://ad.adriver.ru https://sravni.go2cloud.org https://tracking.banki.ru https://mc.yandex.md https://core-renderer-tiles.maps.yandex.net https://yastatic.net https://yandex.ru; font-src 'self' data:; connect-src 'self' https://mc.yandex.ru https://mod.calltouch.ru https://ab-ct.ru https://yastatic.net https://kraken.rambler.ru https://mc.yandex.md https://smartcaptcha.yandexcloud.net https://api-maps.yandex.ru https://core-renderer-tiles.maps.yandex.net; frame-src 'self' https://vk.com https://smartcaptcha.yandexcloud.net https://mc.yandex.ru https://adv.vbr.ru https://sravni.go2cloud.org https://money.yandex.ru; object-src 'self'; frame-ancestors 'self';report-uri /csp-report.php; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.blogher.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 report-uri https://csp.withgoogle.com/csp/youtube_kids/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-MeAfwvDqQ53X1JVm3dfqCw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src *.force.com https://content.instrumentation.getconga.com https://optimize.google.com 'self' https://stats.g.doubleclick.net https://opengraph.io https://xcelnew--xeteam3.sandbox.my.site.com https://www.gstatic.com http://api.ipstack.com https://www.google.ca https://composer.congamerge.com https://idsync.rlcdn.com https://assets.adobedtm.com https://www.google.com *.medallia.com https://www.googleoptimize.com https://analytics.google.com https://fonts.gstatic.com/ https://events.api.boomtrain.com http://adobedtm.com blob: https://accounts.google.com https://20844768p.rfihub.com https://insight.adsrvr.org https://region1.analytics.google.com https://20844767p.rfihub.com https://20844766p.rfihub.com *.kargo.com https://20844765p.rfihub.com https://data.instrumentation.getconga.com https://ssl.gstatic.com http://doubleclick.net https://xcelnew--c.vf.force.com https://xcelnew.my.salesforce-scrt.com https://pdx-col.eum-appdynamics.com https://people.api.boomtrain.com https://fonts.gstatic.com https://cdn.appdynamics.com *.kampyle.com https://twin-iq.kickfire.com http://kickfire.com https://fonts.googleapis.com https://ad.doubleclick.net https://beacon.lynx.cognitivlabs.com https://tagmanager.google.com https://tags.tiqcdn.com https://a.rfihub.com https://td.doubleclick.net https://www.google.co.in https://www.google.com.ph https://www.googletagmanager.com storage.cloud.kargo.com https://www.google-analytics.com *.salesforce.com data: https://*.my.site.com; report-to sfdc-csp-ep; report-uri https://xcelnew.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D1U0000011ttV&networkId=0DM2R000000CbkT&type=communities 1 font-src *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com *.seeedstudio.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com googleads.g.doubleclick.net *.seeedstudio.com stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com *.taboola.com seeedstudio.us11.list-manage.com static-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com *.sandbox.braintree-api.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com googleads.g.doubleclick.net *.seeedstudio.com stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com *.taboola.com https://bid.g.doubleclick.net seeedstudio.us11.list-manage.com *.sandbox.braintree-api.com *.paypal.com *.certcapture.com; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com *.google.com maps.googleapis.com *.facebook.com disqus.com *.disqus.com https://bid.g.doubleclick.net googleads.g.doubleclick.net stats.g.doubleclick.net *.taboola.com seeedstudio.us11.list-manage.com *.seeedstudio.com static-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com *.sandbox.braintree-api.com *.weltpixel.com *.certcapture.com *.oscato.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.seeedstudio.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com maps.googleapis.com *.google.com.tw bat.bing.com *.facebook.com *.linkedin.com disqus.com *.disqus.com *.amazonaws.com *.taboola.com *.scorecardresearch.com *.viglink.com p.adsymptotic.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com static.cloudflareinsights.com *.gstatic.com *.certcapture.com https://hnd.stats.paypal.com *.oscato.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io *.google.com/ *.meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com maps.googleapis.com bazaar-upgrade.seeed.local bat.bing.com connect.facebook.net snap.licdn.com stats.g.doubleclick.net disqus.com *.disqus.com *.disquscdn.com seeedsite.disqus.com *.taboola.com *.scorecardresearch.com *.seeedstudio.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com retcode.alicdn.com *.sandbox.braintree-api.com static.cloudflareinsights.com https://www.googletagmanager.com tagmanager.google.com *.certcapture.com https://assets.optile.net *.oscato.com utt.impactcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline *.seeedstudio.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com nwzimg.wezhan.net *.sandbox.braintree-api.com *.paypal.com tagmanager.google.com *.certcapture.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.seeedstudio.com *.twitter.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com googleads.g.doubleclick.net stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com https://bid.g.doubleclick.net *.taboola.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com retcode.alicdn.com arms-retcode.aliyuncs.com/ *.sandbox.braintree-api.com static.cloudflareinsights.com mc.yandex.ru https://www.google-analytics.com *.certcapture.com *.oscato.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce0%3F%3Ccjvehu%60t~sigsejtjt%60d4.21043%3E1ec0*w%60ut12%2Bar%7F01-19b2a029470-0x2603#pd 1 script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' *.bytescm.com *.bytetos.com *.ibytedapm.com *.zijieapi.com *.snssdk.com *.bytedance.com *.bytedance.net *.pstatp.com *.bytednsdoc.com *.bytegoofy.com *.byted-static.com *.yhgfb-cn-static.com data: blob: 'report-sample' 'nonce-9f0d69d0830a7653ba9869ce04d6485a-argus' 'strict-dynamic'; connect-src 'self' *.idouyinvod.com:* *.volcsiriusbd.com:* *.volcsirius.com:* *.tt.x.bsgslb.cn:* *.dy.zzcdnx.com:* *.qc.bsccdn.net:* *.smtcdns.com:* *.ugslb.com:* *.livehwc3.cn:* *.smtcdns.net:* *.bytefcdnrd.com:* *.ksyungslb.com:* *.ksyungslb2.com:* *.ourdvsss.com:* *.tbcache.com:* *.jomodns.com:* *.douyincdn.com:* *.ixigua.com:* *.bdxigualive.com:* *.pstatp.com:* *.douyinliving.com:* *.picovr.com:* *.huoshanlive.com:* *.ihuoshanlive.com:* *.volccdn.com:* *.bestv.com.cn:* *.bytefcdn.com:* *.douyinvod.com:* *.qnqcdn.net:* *.weilayun.com:* *.saxysec.com:* *.saxyit.com:* *.saxydc.com:* *.sjxysec.com:* *.sjxydc.com:* *.hiecheimaetu.com:* *.ppio.cloud:* *.vegslb.com:* *.xsj.wasu.tv:* *.zebracdn.com:* *.volctranscdn.com:* *.hizhecheng.com:* *.sealaly.net:* *.souajki.net:* *.souajki.com:* *.souajki.cn:* *.siomxity.cn:* *.siomxity.com:* *.siomxity.net:* *.uochly.cn:* *.smogfly.cloud:* *.smogfly.club:* *.iquaveizeeru.com:* *.ietheivaicai.com:* *.bytescm.com *.bytetos.com *.ibytedapm.com *.zijieapi.com *.snssdk.com *.bytedance.com *.bytedance.net *.pstatp.com *.bytednsdoc.com *.bytegoofy.com *.byted-static.com *.yhgfb-cn-static.com; frame-ancestors 'self'; upgrade-insecure-requests ; 1 default-src 'self'; script-src 'self' addevent.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io static.addtoany.com; style-src 'self' addtocalendar.com cdn.jsdelivr.net fonts.googleapis.com https://cdnjs.cloudflare.com 1 frame-ancestors 'self'; report-uri https://www.adelaidenow.com.au/csp-reports 1 script-src 'self' *.adyen.com *.allsaints.com *.bing.com *.cquotient.com *.forter.com *.g.doubleclick.net *.global-e.com *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.gstatic.com *.klarnaservices.com *.parcellab.com *.pcapredict.com *.scarabresearch.com *.squarecdn.com *.tribalfusion.com *.yotpo.com access.myunidays.com ajax.cloudflare.com allsaints.api.highstreetapp.com analytics.tiktok.com api.soreto.com appleid.cdn-apple.com assets.ntcacdn.net cdn-ukwest.onetrust.com cdn.jsdelivr.net cdn.optimizely.com cdnapisec.kaltura.com challenges.cloudflare.com chat.digitalgenius.com code.jquery.com connect.facebook.net ct.pinterest.com d.ratepay.com dnn0yrbagrg.cloudfront.net duvgq8bw.cloudfront.net edge.eu.fullstory.com js-agent.newrelic.com js.klarna.com lottingem.com platform.communicatorcorp.com player.vimeo.com rgneujpc.micpn-eu.com s.pinimg.com sc-static.net secured-pixel.com services.postcodeanywhere.co.uk static.cloudflareinsights.com statse.webtrendslive.com t.contentsquare.net tag.rmp.rakuten.com tags.creativecdn.com tr.snapchat.com tracker.marinsm.com unpkg.com widgets.trustedshops.com www.googletagmanager.com www.paypal.com www.recaptcha.net www.redditstatic.com x.klarnacdn.net; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=BUxLLrrC76yXAlYxtV2p0Tt9xDHkekp2BCvVKQDtPEI-1765939048-1.0.1.1-hbxznhxq2sykdTEKBp7ucy38IiSshtOvmnd5R.BrdaCcgePZh.Vsu4XPh9g3ImzhqKAOETWNpcsTNIxDQ9z9qiEdcgYScgNKFU_t4CVP5ppsE2Z2X_pL.GQMeN578dU3qlevx90ElGwZHsz68iqhS5vPii5X2wkg2LnkAQT_uQ28iLrQNvSIcJWAHjrVViJDcbAwWCMghAh4D_bn5UWREg; report-to cf-pykacrpfilsjoxup 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; font-src 'self' *.gstatic.com; img-src 'self' *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com data: *.onetrust.com cm.everesttech.net *.googleapis.com; connect-src 'self' *.go-mpulse.net cdn-ukwest.onetrust.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com; script-src 'self'; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src 'self'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com; script-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-to https://costa.report-uri.com/r/t/csp/reportOnly 1 object-src 'none'; script-src 'self' 'unsafe-inline' connect.facebook.net platform.linkedin.com platform.twitter.com cdn.matomo.cloud cdn.gtranslate.net translate.google.com translate.googleapis.com https://static.hotjar.com https://script.hotjar.com cdn.rawgit.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com; script-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline' 'unsafe-eval'; style-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline'; report-uri /1/batch/2/OE/mid=AF2M0KC94RCEA:sid=146-5910085-0479706:rid=EF52988753YJXACZE3YE:sn=www.acx.com 1 default-src 'self'; connect-src *; img-src * data:; script-src 'self' cdn.bizible.com kit.fontawesome.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/; font-src 'self' kit.fontawesome.com ka-p.fontawesome.com https://fast.wistia.net/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob:; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://match.adsrvr.org/ https://404-tpa-276.mktoweb.com/; frame-ancestors demo.affinipay.com; upgrade-insecure-requests; block-all-mixed-content 1 default-src 'self'; frame-src 'self' https://replicate-search-prototype-production.replicate.workers.dev https://www.googletagmanager.com https://jobs.ashbyhq.com/replicate/; worker-src https://static.replicateassets.com; connect-src 'self' https://api.replicate.com https://stream.replicate.com https://replicate.delivery https://*.replicate.delivery https://api.us.svix.com https://*.sentry.io https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d3vl36l12sfx26.cloudfront.net https://og.replicateassets.com https://static.replicateassets.com https://*.pusher.com https://www.googletagmanager.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.replicatestatus.com https://replicate-search-prototype-production.replicate.workers.dev; font-src 'self' data: https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://fonts.replicateassets.com https://*.pusher.com https://fonts.gstatic.com https://replicate-search-prototype-production.replicate.workers.dev; img-src 'self' blob: data: https://replicate.delivery https://*.replicate.delivery https://og.replicateassets.com https://static.replicateassets.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://*.githubusercontent.com https://github.com https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://replicate-search-prototype-production.replicate.workers.dev; media-src 'self' https://replicate.delivery https://*.replicate.delivery https://static.replicateassets.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://*.sentry.io https://replicate-search-prototype-production.replicate.workers.dev; script-src 'report-sample' 'self' 'nonce-MzJlZjVhM2EtMThiOC00MDc1LWEwNWQtMTNkNGM5N2ZhM2Fk' https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://static.replicateassets.com https://*.pusher.com https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://replicate-search-prototype-production.replicate.workers.dev https://jobs.ashbyhq.com/replicate/embed; style-src 'self' https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://static.replicateassets.com https://*.pusher.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://replicate-search-prototype-production.replicate.workers.dev; frame-ancestors 'self'; report-to csp-endpoint; 1 default-src 'self' cedars.okta.com myportal.cshs.org *.oktacdn.com; connect-src 'self' cedars.okta.com cedars-admin.okta.com myportal.cshs.org *.oktacdn.com *.mixpanel.com *.mapbox.com cedars.kerberos.okta.com cedars.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' cedars.okta.com myportal.cshs.org *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' cedars.okta.com myportal.cshs.org *.oktacdn.com; frame-src 'self' cedars.okta.com cedars-admin.okta.com myportal.cshs.org login.okta.com *.vidyard.com com-okta-authenticator: api-98a8a037.duosecurity.com; img-src 'self' cedars.okta.com myportal.cshs.org *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' cedars.okta.com myportal.cshs.org data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://*.csmc.edu https://*.cloud.infor.com https://*.rhythm360.io 1 default-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.clarity.ms; script-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.googletagmanager.com https://*.securiti.ai/ https://*.google.com.br/ads/ https://*.clarity.ms; script-src-elem 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://www.googletagmanager.com https://*.securiti.ai/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.google.com.br/ads/ https://analytics.google.com https://*.google-analytics.com/ https://connect.facebook.net/ https://s.pinimg.com/ https://ct.pinterest.com/ https://*.clarity.ms https://www.splash-screen.net/ https://www.youtube.com/iframe_api; img-src 'self' data: https://*.banrisul.com.br/ https://*.google.com.br/ads/ https://*.facebook.com https://ct.pinterest.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br https://*.clarity.ms; font-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://fonts.gstatic.com/ https://*.clarity.ms; style-src-elem 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.securiti.ai/ https://*.clarity.ms; connect-src 'self' https://api.banrisul.com.br https://*.securiti.ai/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br https://ct.pinterest.com https://*.clarity.ms; frame-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://www.youtube.com/ https://finansite-a.ae.com.br/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://assets.pinterest.com https://ct.pinterest.com https://*.clarity.ms https://td.doubleclick.net/; frame-ancestors 'self' https://*.corp.banrisul.com.br/; 1 default-src 'self' https://*.firstcitizens.com; script-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://assets.adobedtm.com https://acrobatservices.adobe.com https://cds-sdkcfg.onlineaccess1.com https://www.googletagmanager.com https://s.go-mpulse.net https://connect.facebook.net https://bat.bing.com https://snap.licdn.com https://js-cdn.dynatrace.com https://googleads.g.doubleclick.net https://td.doubleclick.net https://www.googleadservices.com https://px.ads.linkedin.com https://edge.adobedc.net https://www.facebook.com https://px4.ads.linkedin.com https://siteimproveanalytics.com https://www.clarity.ms https://www.google.com https://google.com https://2884.global.siteimproveanalytics.io https://c.go-mpulse.net https://zndhwk2nlgcbvdel3-firstcitizensbank.siteintercept.qualtrics.com https://t.contentsquare.net https://munchkin.marketo.net https://siteintercept.qualtrics.com https://296-cpx-295.mktoresp.com https://894-itd-344.mktoresp.com https://284-lbb-572.mktoresp.com https://151-fhs-046.mktoresp.com https://412-tmw-562.mktoresp.com https://u.clarity.ms https://c.contentsquare.net https://173bf10e.akstat.io https://k-aus1.contentsquare.net https://trial-eum-clientnsv4-s.akamaihd.net https://eyaqbbekafz5ajqacqnryaaabbtmzouy-p2jke9-59ac193c4-clienttons-s.akamaihd.net https://daaisiixzsmj6zwmxkma-p2jke9-1aa48d9c7-clientnsv4-s.akamaihd.net https://assets.sitescdn.net https://answers.yext-pixel.com https://analytics.google.com https://embed-ssl.wistia.com https://pipedream.wistia.com https://js.sentry-cdn.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://srm.bf.contentsquare.net https://www.gstatic.com https://app.fintelconnect.com https://browser.sentry-cdn.com https://*.cit.com https://answers-embed.firstcitizens.com.pagescdn.com https://info.onewestbank.com https://rum.hlx.page https://script.crazyegg.com https://js.adsrvr.org https://bat.bing.com https://scripts.clarity.ms; connect-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://analytics.google.com https://answers.yext-pixel.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://adobedc.demdex.net https://viewlicense.adobe.io https://www.google.com https://www.google-analytics.com https://dpm.demdex.net https://edge.adobedc.net https://px.ads.linkedin.com https://siteintercept.qualtrics.com https://cds-sdkcfg.onlineaccess1.com https://prod-cdn.us.yextapis.com https://ipapi.co https://api.openweathermap.org https://296-cpx-295.mktoutil.com https://script.crazyegg.com https://tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://assets-tracking.crazyegg.com https://insight.adsrvr.org https://dayintegrationintern.tt.omtrdc.net https://www.googleadservices.com https://business.linkedin.com https://openknowledge.worldbank.org https://acrobatservices.adobe.com https://assets.sitescdn.net https://bat.bing.com https://scripts.clarity.ms https://smetrics.firstcitizens.com https://browser.sentry-cdn.com https://mpc-prod-2-1053047382554.us-central1.run.app https://demo-1.conversionsapigateway.com https://graph.facebook.com; worker-src 'self'; style-src 'self' https://*.firstcitizens.com https://fonts.googleapis.com https://assets.sitescdn.net; style-src-elem 'self' https://*.firstcitizens.com https://assets.sitescdn.net https://*.cit.com https://info.onewestbank.com https://fonts.googleapis.com https://www.googletagmanager.com; img-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://2884.global.siteimproveanalytics.io px.ads.linkedin.com https://px4.ads.linkedin.com https://cm.everesttech.net https://dpm.demdex.net https://www.linkedin.com https://www.googletagmanager.com https://www.facebook.com https://googleads.g.doubleclick.net https://*.cit.com https://www.google.com https://google.com https://info.onewestbank.com https://siteintercept.qualtrics.com https://fonts.gstatic.com https://ad.doubleclick.net https://insight.adsrvr.org https://ib.adnxs.com https://cm.g.doubleclick.net https://match.adsrvr.org https://pixel.rubiconproject.com https://www.googleadservices.com; frame-src 'self' https://*.firstcitizens.com https://acrobatservices.adobe.com https://td.doubleclick.net https://firstcitizens.demdex.net https://www.google.com https://www.citrail.com https://answers-embed.firstcitizens.com.pagescdn.com https://*.cit.com https://info.onewestbank.com https://www.googletagmanager.com https://insight.adsrvr.org https://privacyportaluat.onetrust.com https://privacyportal.onetrust.com https://match.adsrvr.org https://fintactix.com https://14741597.fls.doubleclick.net https://fast.wistia.net https://15758689.fls.doubleclick.net; frame-ancestors 'self' https://www.google.com https://9808-sbx.btbanking.com https://*.firstcitizens.com https://*.fcbint.net; media-src 'self'; font-src 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://cdn.prod.website-files.com https://www.googletagmanager.com https://widget.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com https://global.localizecdn.com https://js.intercomcdn.com https://js.refiner.io https://embed.lu.ma https://app.posthog.com https://static.cloudflareinsights.com https://smartpass.instatus.com; style-src 'self' https://cdn.prod.website-files.com https://embed.lu.ma https://fonts.googleapis.com https://rsms.me/inter/ 'unsafe-inline'; font-src 'self' https://rsms.me/inter/font-files/ https://fonts.gstatic.com; img-src 'self' data: https://smartpass.app https://*.smartpass.app https://cdn.prod.website-files.com https://storage.googleapis.com/sp-img-cdn/ https://global.localizecdn.com https://www.googletagmanager.com https://widget.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com; connect-src 'self' https://smartpass.app wss://smartpass.app https://global.localizecdn.com https://firebaseinstallations.googleapis.com https://fcmregistrations.googleapis.com https://*.ingest.sentry.io https://cdn.prod.website-files.com https://www.googletagmanager.com https://*.intercom.io wss://*.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com https://*.refiner.io https://api.instatus.com; frame-src 'self' https://js.refiner.io 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-QTwFVjoLWul5nteSEw6MLw==' 1 report-uri https://mon-sg.capcutapi.com/monitor_browser/collect/batch/security/?bid=cc_web_compliance&c=680&ev_type=csp&r=2&v=2; report-to csp-endpoint; default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: bytedance: data: wss://*.capcut.com *.adtrafficquality.google *.bing.com *.bing.net *.bytecdn.com *.byteeffecttos-g.com *.byteoversea.com *.bytevcloudapi.com *.capcut-app.com *.capcut.com *.capcutapi.com *.capcutcdn-us.com *.capcutstatic.com *.capcutvod.com *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.faceueditorv.com *.faceulv.com *.giphy.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.googleusercontent.com *.gstatic.com *.ibytedtos.com *.ibyteimg.com *.pippit.ai *.sgsnssdk.com *.tiktok.com *.tiktokapis.com *.tiktokcdn.com *.tiktokv.com *.ttwstatic.com *.vodupload.com *.yhgfb-static.com *.zijieapi.com appleid.cdn-apple.com ep2.adtrafficquality.google facebook.com google.com; connect-src 'self' blob: bytedance: data: http://localhost:* https://localhost:* wss://*.capcut.com *.adtrafficquality.google *.bing.com *.bing.net *.bytecdn.com *.byteeffecttos-g.com *.byteoversea.com *.bytevcloudapi.com *.capcut-app.com *.capcut.com *.capcutapi.com *.capcutstatic.com *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.faceueditorv.com *.faceulv.com *.giphy.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.googleusercontent.com *.gstatic.com *.ibytedtos.com *.ibyteimg.com *.pipopay.com *.pipopayment.com *.pippit.ai *.run.app *.sgsnssdk.com *.tiktok.com *.tiktokapis.com *.tiktokcdn.com *.tiktokv.com *.ttwstatic.com *.twitter.com *.vodupload.com *.yhgfb-static.com *.zijieapi.com; frame-src 'self' bytedance: *.capcut.com *.google.com *.googletagmanager.com capcut-yt.onelink.me ep2.adtrafficquality.google googleads.g.doubleclick.net kefu-im-i18n.byteintl.com sg-gcp-media.evercloud.capcut.com td.doubleclick.net www.tiktok.com; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-eval' 'wasm-unsafe-eval' *.bing.com *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.googlesyndication.com *.googletagmanager.com appleid.cdn-apple.com ep2.adtrafficquality.google googleads.g.doubleclick.net scripts.clarity.ms sf16-web-login-neutral.capcutstatic.com sf16-web-login-neutral.pippitstatic.com sf16-website-login.neutral.ttwstatic.com www.clarity.ms www.gstatic.com; worker-src 'self'; base-uri 'none'; frame-ancestors 'self' bytedance: *.capcut.com 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline' blob:; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; connect-src 'self' ws: https://suggestions.dadata.ru https://www.google.com; worker-src blob:; report-uri /csp-report 1 report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubff54dddb981c8cd140e740408494c84d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction 1 form-action 'self'; manifest-src 'self'; report-uri https://csp-flkt.domdog.io/report-uri/flipkart.com/3/2-1 1 report-uri /upload/csp/csp.php; report-to csp-endpoints 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://stats.g.doubleclick.net https://connect.facebook.net https://*.mczbf.com https://*.kdukvh.com https://*.emjcd.com https://*.jdoqocy.com https://*.dotomi.com https://*.cj.com https://*.sjwoe.com https://*.clarity.ms https://onelinksmartscript.appsflyer.com https://*.apple-mapkit.com https://embed.reddit.com https://static.zdassets.com https://platform.twitter.com https://www.instagram.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googleoptimize.com https://*.googletagmanager.com https://www.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://stats.g.doubleclick.net https://storage.googleapis.com https://fonts.gstatic.com https://purecatamphetamine.github.io http://purecatamphetamine.github.io https://www.facebook.com https://connect.facebook.net https://*.clarity.ms https://googleads.g.doubleclick.net https://*.googleusercontent.com https://storage.googleapis.com https://secure.gravatar.com https://*.apple-mapkit.com https://syndication.twitter.com https://s0.wp.com https://*.bing.com; font-src 'self' data: https://cdn.jsdelivr.net https://fonts.gstatic.com https://s0.wp.com https://applepay.cdn-apple.com; worker-src 'self'; frame-src 'self' https://www.youtube.com https://*.googletagmanager.com https://embed.reddit.com https://platform.twitter.com https://www.instagram.com; connect-src 'self' https://cdn.jsdelivr.net https://*.cloudflare.com https://lown4qvbisme2qafgzvjetqzzy0tbyyr.lambda-url.us-west-2.on.aws https://analytics.google.com https://*.analytics.google.com https://www.google.com https://stats.g.doubleclick.net https://www.google-analytics.com https://*.mczbf.com https://*.kdukvh.com https://*.emjcd.com https://*.jdoqocy.com https://*.dotomi.com https://*.cj.com https://*.sjwoe.com https://www.facebook.com https://*.clarity.ms https://*.apple-mapkit.com https://*.mydnsip.com https://www.googleadservices.com https://engagements.appsflyer.com https://meta.veepn.com https://ekr.zdassets.com; media-src 'self'; frame-ancestors 'self'; object-src 'none'; report-to csp-endpoint; 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-lYlUDoBAXSKCMSccvHDOOQ'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-lYlUDoBAXSKCMSccvHDOOQ'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self'; report-uri https://uk3hg0f8.uriports.com/reports/report 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; script-src 'nonce-b7567cfcc6c04faaa98cdffa502471f8' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; style-src 'self' 'nonce-b7567cfcc6c04faaa98cdffa502471f8' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=134-8052064-6414944:rid=E68BC86B378C4C23B3D2:sn=www.amazongamestudios.com 1 default-src 'self' *.fabfitfun.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.fabfitfun.com *.recurly.com *.amazonaws.com *.ada.support www.dwin1.com *.google-analytics.com *.doubleclick.net www.googleadservices.com www.googletagmanager.com *.hcaptcha.com hcaptcha.com *.exitintel.com *.facebook.net *.facebook.com *.tiktok.com *.cookielaw.org *.segment.com *.tvsquared.com *.onetrust.com *.adsrvr.org sc-static.net *.zdassets.com *.crrnt.app *.pixlee.com *.roeyecdn.com *.amplitude.com *.bing.com *.googleapis.com *.exitintel.com *.jsdelivr.net *.datadoghq-browser-agent.com *.gladly.com *.braintreegateway.com *.paypal.com *.cloudflare.com *.hotjar.com *.clarity.ms accessibilityserver.org *.userway.org *.tryamped.com *.pinimg.com *.ads-twitter.com *.amped.io *.visualwebsiteoptimizer.com *.amazon-adsystem.com blob:; style-src * 'unsafe-inline' data: blob:; connect-src *; frame-src *; img-src * 'unsafe-inline' data: blob:; font-src * 'unsafe-inline' data: blob:; media-src * blob:; object-src 'none'; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.artforum.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 img-src https: data:; connect-src https:; report-uri https://csp-reports.yesware.com/new 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com *.amplitude.com *.ads-twitter.com use.typekit.net *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.segment.com *.doubleclick.net sc-static.net *.google.com *.gstatic.com *.googlesyndication.com connect.facebook.net js.stripe.com cdn.seon.io www.redditstatic.com analytics.tiktok.com bat.bing.com *.checkout.com; font-src 'self' data: fonts.gstatic.com use.typekit.net frontend-assets.sorare.tech frontend-assets.sorare.com frontend-assets.sorare.dev; media-src 'self' *.ctfassets.net frontend-assets.sorare.com frontend-assets.sorare.tech frontend-assets.sorare.dev assets.sorare.com assets.sorare.tech assets.sorare.dev; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net use.typekit.net use.fontawesome.com blob:; connect-src *; img-src * data:; frame-src *; manifest-src 'self' https://sorare.cloudflareaccess.com; object-src 'none'; worker-src blob:; 1 default-src data: blob:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.vtbbo.ru; style-src data: blob: 'unsafe-inline' https://*; img-src data: blob: https://*; connect-src blob: 'self' https://*.vtbbo.ru wss://*.vtbbo.ru https://*.vtbbo.ru wss://chat7.vtb.ru https://chat7.vtb.ru; object-src blob: 'self' https://*; font-src data: blob: 'self' https://*; worker-src blob: 'self' https://*.vtbbo.ru; media-src data: blob: filesystem: 'self' https://*; manifest-src 'self' 1 default-src https://www.honeybadger.io; connect-src 'self' data: https://*.savvycal.com/ https://*.frontapp.com/ https://*.fontawesome.com/ https://*.typekit.net/ https://*.honeybadger.io https://*.convertkit.com/ https://*.convertexperiments.com/ https://*.profitwell.com https://*.usefathom.com/ https://*.wistia.com/ https://fg8vvsvnieiv3ej16jby.litix.io https://pipedream.wistia.com/mput https://embedwistia-a.akamaihd.net/ https://cdnjs.cloudflare.com; font-src 'self' data: https://use.typekit.net https://cdnjs.cloudflare.com https://*.fontawesome.com; frame-src https://savvycal.com/ https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://fast.wistia.com; img-src 'self' data: https:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.gstatic.com/ https://*.savvycal.com/ https://*.frontapp.com/ https://*.fontawesome.com/ https://*.typekit.net/ https://*.profitwell.com https://*.usefathom.com/ https://*.honeybadger.io/ https://*.convertkit.com/ https://*.convertexperiments.com/ https://gist.github.com https://*.wistia.com https://cdn.syndication.twimg.com https://platform.twitter.com https://fast.wistia.com/ https://identity.netlify.com/v1/netlify-identity-widget.js https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' blob: https://*.gstatic.com/ https://*.fontawesome.com https://*.typekit.net https://github.githubassets.com/ https://platform.twitter.com https://ton.twimg.com https://cdnjs.cloudflare.com; media-src 'self' data: https://embedwistia-a.akamaihd.net https://*.wistia.com; manifest-src https://www.honeybadger.io ; report-uri https://api.honeybadger.io/v1/browser/csp?api_key=c2f13350&report_only=true&env=production 1 default-src 'self'; script-src 'self' 'unsafe-eval' https: http: 'nonce-MGY1OWIzYWYtNDIyZi00MDZlLThhODItNWZlNjdmY2QyOTZk' 'strict-dynamic'; script-src-elem 'unsafe-inline' https://yamap.com https://www.googletagmanager.com https://js.stripe.com; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' https: blob: data:; object-src 'none'; form-action 'self'; connect-src 'self' https://*; report-uri https://zk6bsphzgvpliawi65sbwjdx6m0xhmnc.lambda-url.ap-northeast-1.on.aws/; frame-src https://docs.google.com/forms; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com; script-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline' 'unsafe-eval'; style-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline'; report-uri /1/batch/2/OE/mid=ATVPDKIKX0DER:sid=137-2509703-5971157:rid=TZYS9X11SXTN2KDY9HJQ:sn=kdp.amazon.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wellhub.com *.amplitude.com https://js.appboycdn.com/web-sdk/4.0/braze.no-amd.min.js https://widget-mediator.zopim.com https://js-na1.hs-scripts.com https://static.zdassets.com https://sdk.inbenta.io https://chatbot.backoffice.gympass-staging.com/chatbot-site-gympass-com.js https://cdn.optimizely.com https://maps.googleapis.com https://x.clearbitjs.com https://js.hscollectedforms.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.google.com cdn.cookielaw.org/ cdn.segment.com bat.bing.com/bat.js cdn.jsdelivr.net/npm/jquery-validation@1.19.5/dist/jquery.validate.min.js cdn.optimizely.com/js/ cdn.segment.com/analytics.js/ cdnjs.cloudflare.com/ajax/libs/jquery.mask/1.14.16/jquery.mask.min.js code.jquery.com/jquery-3.6.0.min.js connect.facebook.net/en_US/fbevents.js googleads.g.doubleclick.net/pagead/viewthroughconversion/ j.6sc.co/6si.min.js js.driftt.com/include/ js.hs-analytics.net/analytics/ js.hs-banner.com/ js.hs-scripts.com/ js.hsadspixel.net/fb.js js.hsforms.net/forms/v2.js js.hsleadflows.net/leadflows.js js.usemessages.com/conversations-embed.js rum-static.pingdom.net/ s.yimg.com/wi/ytc.js script.hotjar.com/ snap.licdn.com/li.lms-analytics/ static.hotjar.com/c/ static.hsappstatic.net/MeetingsEmbed/ex/MeetingsEmbedCode.js tag.clearbitscripts.com/v1/ tpc.googlesyndication.com/ unpkg.com/blip-chat-widget https://js.qualified.com/ https://*.salesloft.com/ clarity.ms/tag/uet/ *.clarity.ms/tag/uet/ x.clearbitjs.com/v2/ https://s3.amazonaws.com/raichu-beta/ https://static.play.ht/playht-pageplayer-plugin.js https://bat.bing.com/p/action/ https://connect.facebook.net/signals/config/ https://js.hubspot.com/web-interactives-embed.js https://analytics.tiktok.com/ https://www.clarity.ms/s/ https://static.xingcdn.com/xingtrk/index.js; style-src 'self' 'unsafe-inline' https://sdk.inbenta.io fonts.googleapis.com https://www.googletagmanager.com/ https://s3.amazonaws.com/raichu-beta/ https://static.play.ht/playht-pageplayer-plugin.css; object-src 'none'; base-uri 'self'; connect-src 'self' *.wellhub.com https://app.qualified.com/ wss://*.qualified.com https://unleash-edge-mep.gympass.com https://unleash-edge-mep.gympass.com/api/frontend/ https://traces.observability.prd.us.gympass.cloud/collect https://ext-otel.mep.prd.us.gympass.cloud/collect https://sdk.iad-03.braze.com/api/v3/data cdn.cookielaw.org/ *.onetrust.com inbenta.io *.inbenta.io https://api.inbenta.io wss://widget-mediator.zopim.com https://zendesk-eu.my.sentry.io *.zendesk.com zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://maps.googleapis.com https://unlogged.users.gympass-staging.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.google.com google.com googleadservices.com https://www.google.com.br/ google.com.br api.hubapi.com hubspot.com *.hubspot.com api.segment.io app.clearbit.com bat.bing.com cdn.segment.com epsilon.6sense.com *.optimizely.com optimizely.com forms.hsforms.com in.hotjar.com ipv6.6sc.co js.hs-banner.com *.clarity.ms rum-collector-2.pingdom.net s.yimg.com stats.g.doubleclick.net unlogged.users.gympass.com https://play.ht/api/v2/ https://places.geo.us-east-1.amazonaws.com https://*.cloudfront.net https://px.ads.linkedin.com https://analytics.tiktok.com/ api.reclameaqui.com.br https://browser-intake-datadoghq.com/api/v2/ https://rum.browser-intake-datadoghq.com/api/v2/ https://www.facebook.com/ https://region1.analytics.google.com/ wss://*.hotjar.com/ https://*.hotjar.io/ https://o4504963224764416.ingest.us.sentry.io/api/ https://www.xing.com/xas/api/tracking_pixel_verification; font-src 'self' data: https://cdn.inbenta.io fonts.gstatic.com https://assets-cdn.gympass.com https://assets-cdn.wellhub.com https://script.hotjar.com/ https://s3.amazonaws.com/play-plugin/build/font; frame-src 'self' https://gympass.chat.blip.ai https://app.qualified.com/ optimizely.com *.cdn.optimizely.com googleadservices.com bid.g.doubleclick.net forms.hsforms.com js.driftt.com meetings.hubspot.com tpc.googlesyndication.com vars.hotjar.com facebook.com https://www.facebook.com/ www.googletagmanager.com/ https://td.doubleclick.net; img-src 'self' data: https://s3.amazonaws.com/raichu-beta/ https://assets-cdn.gympass-staging.com https://assets-cdn.gympass.com https://assets-cdn.wellhub.com https://images.partners.gympass.com/ https://tmp-images.partners.gympass.com/ https://p.adsymptotic.com https://www.googletagmanager.com cdn.cookielaw.org/ *.inbenta.com inbenta.com https://gympass-staging-images-us.s3.amazonaws.com https://maps.googleapis.com https://maps.gstatic.com *.clarity.ms/ cloudfront.net *.cloudfront.net https://www.google.com/ads/ga-audiences https://www.google.com.br/ads/ga-audiences https://www.google.com/pagead/1p-user-list/ b.6sc.co bat.bing.com https://c.bing.com/ forms-na1.hsforms.com forms.hsforms.com googleads.g.doubleclick.net https://googleads.g.doubleclick.net/ px.ads.linkedin.com sp.analytics.yahoo.com track.hubspot.com facebook.com https://www.google-analytics.com google.com google.com.br www.google.com.br https://www.google.co.uk/ https://www.google.com.ar/ https://www.google.com.mx/ https://www.google.de/ https://www.google.es/ https://www.google.cl/ https://www.google.it/ https://www.facebook.com/ https://fonts.gstatic.com/ https://px4.ads.linkedin.com/collect https://www.linkedin.com/px/ https://ads01.groovinads.com/ https://perf-na1.hsforms.com/embed/v3/counters.gif; manifest-src 'self'; media-src 'self' https://static.zdassets.com; worker-src 'self' *.gympass-staging.com blob:; 1 default-src 'self' www.youtube.com *.stripe.com *.addthis.com; script-src 'self' assets.sutori.com *.twitter.com *.twimg.com 'unsafe-inline' *.stripe.com apis.google.com 'unsafe-eval' maps.googleapis.com *.crisp.chat *.crisp.im www.youtube.com *.ytimg.com *.addthis.com *.addthisedge.com data: z.moatads.com *.pinterest.com *.iubenda.com cdn.thinglink.me http://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js https://www.thinglink.com *.instagram.com connect.facebook.net *.imgur.com *.flickr.com blob: cdn.headwayapp.co risk.clearbit.com teams.microsoft.com https://cdnjs.cloudflare.com/ajax/libs/lamejs/1.2.0/lame.min.js; script-src-elem assets.sutori.com *.twitter.com *.twimg.com 'unsafe-inline' *.googletagmanager.com *.stripe.com https://apis.google.com/ accounts.google.com 'unsafe-eval' maps.googleapis.com *.crisp.chat *.crisp.im www.youtube.com *.ytimg.com *.addthis.com *.addthisedge.com data: z.moatads.com *.pinterest.com *.iubenda.com cdn.thinglink.me http://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js https://www.thinglink.com *.instagram.com connect.facebook.net *.imgur.com *.flickr.com blob: cdn.headwayapp.co risk.clearbit.com teams.microsoft.com play.vidyard.com challenges.cloudflare.com; worker-src blob: data:; font-src 'self' data: assets.sutori.com fonts.gstatic.com https://client.crisp.chat; connect-src 'self' https://www.googleapis.com wss://www.sutori.com assets.sutori.com s3.amazonaws.com/assets.sutori.com *.google-analytics.com *.stripe.com accounts.google.com maps.googleapis.com api.amplitude.com wss://*.crisp.chat https://*.crisp.chat *.addthis.com https://syndication.twitter.com/settings https://*.wikipedia.org geo.query.yahoo.com *.flickr.com risk.clearbit.com login.microsoftonline.com blob:; img-src 'self' data: * maps.googleapis.com https://maps.gstatic.com/mapfiles/api-3/images/ https://csi.gstatic.com/ https://i.ytimg.com *.addthis.com *.pinterest.com *.iubenda.com; style-src 'self' assets.sutori.com platform.twitter.com 'unsafe-inline' accounts.google.com *.googleapis.com https://client.crisp.chat *.iubenda.com cdn.thinglink.me https://ton.twimg.com cdn.headwayapp.co; media-src 'self' assets.sutori.com https://client.crisp.chat blob:; child-src 'self' * https://www.sutori.com *.stripe.com https://www.google.com/ https://www.youtube-nocookie.com/embed/ https://www.youtube.com/embed/ *.addthis.com *.pinterest.com blob:; manifest-src assets.sutori.com; 1 style-src 'self' 'unsafe-inline' https://*.assets.post.at https://*.azureedge.net https://bpanel.streamdiver.com https://webcast.a1.net https://*.gstatic.com; report-to default; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com bing.com *.bing.com betano.pt *.betano.pt cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery clarity.ms *.clarity.ms lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=T1HnCtJoiniXtUfgtYh8KhjMypW_tEDSRot5QHvz_Ls-1765938630-1.0.1.1-8jRNDbInZosDWyF6EzpSQNQ324Ov8z0OEfshR4NehcZtIrWx8dM4Rk2Rx7ZANqfrlJtaQqirNkf9TWAFkyo7gYzKuqWyoxhR2.IJNV9ZTVRDYMZe3AB7MPAJz_6_CcgVLI8SJZoqltXBpixTh9vX5jcUmUZLM44nj7EHeBCsmbilqQkllYG9e3KNAkig1uP71.JpWIt_c6xMnuT3zvhvUA; report-to cf-efkueidpnmrzxcqg 1 script-src 'report-sample' 'nonce-rxQxasuYZcRyz9pwt0sUOA==' https: 'self' https://*.moneylion.com https://*.moneylion.dev https://www.googletagmanager.com; 1 default-src 'none';script-src 'nonce-c1058de3-762b-4fd3-bf36-94634a2a1e4b' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.co.uk https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.co.uk/eum-collector/report/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com s3-sa-east-1.amazonaws.com *.google.com.mx *.bing.com *.collect.igodigital.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.equalweb.com *.sandbox.my.site.com/ *.sandbox.my.salesforce-scrt.com/ *.facebook.net *.tiktok.com/ *.cardinalcommerce.com *.ccdc02.com unpkg.com cdn.jsdelivr.net *.g.doubleclick.net *.adobe.io *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com *.braintreegateway.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.tiktok.com *.clarity.ms *.bing.com *.collect.igodigital.com *.amazon.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.sandbox.my.site.com/ *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com unpkg.com cdn.jsdelivr.net commerce.adobedtm.com www.googleadservices.com www.google-analytics.com *.g.doubleclick.net analytics.google.com www.googletagmanager.com use.typekit.net *.adobe.io *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com js.braintreegateway.com c.paypal.com pay.google.com *.braintreegateway.com *.equalweb.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.facebook.net *.tiktok.com *.clarity.ms 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.adobedc.net *.equalweb.com *.sandbox.my.salesforce-scrt.com/ *.sandbox.my.site.com/ *.tiktok.com/ *.adobedtm.com *.adobe.com *.ccdc02.com unpkg.com cdn.jsdelivr.net commerce.adobedtm.com *.g.doubleclick.net use.typekit.net t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com *.braintreegateway.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.facebook.net *.tiktok.com *.clarity.ms *.bing.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.goldderby.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wargaming.net *.wgprod.net *.tvsquared.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://www.googleoptimize.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://tags.srv.stackadapt.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.googleoptimize.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.stackadapt.com https://*.facebook.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.com.ua https://google.pl https://*.doubleclick.net https://*.googleapis.com https://pagead2.googlesyndication.com https://*.clarity.ms https://collect.worldoftanks.com https://content-wg.gcdn.co https://api.worldoftanks.com https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://static.hotjar.com https://snap.licdn.com https://js.monitor.azure.com https://js.qualified.com https://cdn.hockeystack.com https://*.marketo.com https://*.bizible.com https://*.vwo.com https://*.drift.com https://*.demandbase.com https://*.conductor.com https://*.seismic.com; connect-src 'self' https://*.marketo.com https://*.bizible.com https://*.google-analytics.com https://*.hotjar.com https://*.qualified.com https://*.demandbase.com https://*.vwo.com https://*.hockeystack.com https://*.drift.com https://*.conductor.com https://*.seismic.com; img-src 'self' data: https://*.googleusercontent.com https://*.gravatar.com https://*.marketo.com https://*.bizible.com https://*.qualified.com https://*.hockeystack.com https://*.conductor.com https://*.seismic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'self'; 1 default-src 'self' https://fonts.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https:// connect.facebook.net/ https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://api.sardine.ai https://static.zdassets.com/ https://ekr.zdassets https://ekr.zendesk.com https://*.zopim.com wss://demonifty.zendesk.com wss://*.zopim.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://edge.fullstory.com/s/ https://static.ads-twitter.com/uwt.js https://sc-static.net/ https://googleads.g.doubleclick.net/ https://tr.snapchat.com https://cdn.mxpnl.com; style-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://fonts.googleapis.com *.live-video.net; script-src-elem 'self' 'unsafe-inline' https://js.stripe.com https://api.dev.sardine.ai https://edge.fullstory.com https://www.googletagmanager.com/gtag/js https://connect.facebook.net https://static.ads-twitter.com/uwt.js https://sc-static.net/scevent.min.js https://www.google.com/recaptcha/ https://static.zdassets.com/ https://www.gstatic.com/recaptcha/ https://tr.snapchat.com/ https://www.google-analytics.com/ https://www.googleadservices.com https://googleads.g.doubleclick.net https://api.sardine.ai https://unpkg.com/@google/model-viewer/dist/model-viewer.min.js https://www.youtube.com https://www.googleoptimize.com https://www.clarity.ms https://cdn.mxpnl.com/libs/mixpanel-recorder.min.js *.live-video.net; img-src https: blob: data:; connect-src https://browser-intake-datadoghq.com https://www.niftygateway.com https://niftygateway.com https://analytics.google.com https://*.clarity.ms https://niftygateway.zendesk.com https://api.niftygateway.com https://odysseymarket.niftygateway.com https://api.sandbox.niftygateway.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ https://www.google-analytics.com https://api-js.mixpanel.com https://www.clarity.ms wss://widget-mediator.zopim.com https://nifty-qa100.service.aws-qa.sd.gem.link https://demonifty.zendesk.com https://ekr.zdassets.com https://encrypted-tbn0.gstatic.com/images https://lh3.googleusercontent.com https://tr.snapchat.com https://eth-goerli.alchemyapi.io https://search-api-staging.s-niftygateway-001-use1.svc.gem.link https://search-api.niftygateway.com https://search-api-dev.d-niftygateway-001-use1.svc.gem.link https://ipfs.io https://rs.fullstory.com https://session-replay.browser-intake-datadoghq.com https://eth-mainnet.alchemyapi.io https://api.cloudinary.com/v1_1/nifty_gateway/auto/upload https://api.pinata.cloud/pinning/pinFileToIPFS https://openseauserdata.com https://rum.browser-intake-datadoghq.com https://api.x.immutable.com https://i.seadn.io https://cdn.optimizely.com https://img.seadn.io https://storage.opensea.io https://api.opensea.io https://sdk.iad-03.braze.com *.live-video.net ; font-src https://fonts.gstatic.com https://use.typekit.net/ 'self'; object-src 'self'; media-src https://media.niftygateway.com https://static.zdassets.com https://openseauserdata.com https://storage.opensea.io https://res.cloudinary.com blob:; frame-src https://js.stripe.com https://www.google.com https://api.sardine.ai https://api.dev.sardine.ai https://tr.snapchat.com/ https://www.youtube.com https://webusprd01.ihsmtaxsolutions.com/Nifty/ https://td.doubleclick.net/; frame-ancestors 'self'; worker-src blob:; 1 default-src *.kuajingmaihuo.com *.cdnfe.com wss://seller.kuajingmaihuo.com *.jumio.ai blob: data: 'unsafe-eval' 'unsafe-inline'; report-uri /api/sec-csp/110000010/report 1 default-src 'self'; script-src 'self' 'nonce-5bqRJLI3VhQotj2t5rMufA==' 'unsafe-eval' cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net *.googleapis.com www.gstatic.com www.google.com cse.google.com *.facebook.net api.instagram.com cdnjs.cloudflare.com unpkg.com cdn.jsdelivr.net *.googletagmanager.com tagmanager.google.com www.google-analytics.com stats.g.doubleclick.net analytics.google.com vimeo.com *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net www.youtube.com www.paypal.com www.sandbox.paypal.com sidefx.bamboohr.com https://hcaptcha.com https://*.hcaptcha.com forms.copper.com; frame-src 'self' data: static.sidefx.com media.sidefx.com www.google.com connect.facebook.net www.facebook.net www.facebook.com docs.google.com maps.google.com www.youtube.com lists.sidefx.com *.vimeo.com *.vimeocdn.com www.sandbox.paypal.com www.paypal.com https://hcaptcha.com https://*.hcaptcha.com; style-src 'self' 'unsafe-inline' cdn.sidefx.com static.sidefx.com d2wvmrjymyrujw.cloudfront.net media.sidefx.com fonts.googleapis.com www.google.com tagmanager.google.com *.vimeocdn.com www.gstatic.com https://hcaptcha.com https://*.hcaptcha.com; font-src 'self' data: cdn.sidefx.com static.sidefx.com media.sidefx.com fonts.gstatic.com; img-src 'self' data: cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net *.cdninstagram.com *.gravatar.com www.facebook.com static.lulu.com www.gstatic.com ssl.gstatic.com www.googleapis.com i.ytimg.com *.vimeocdn.com www.paypal.com t.paypal.com www.paypalobjects.com placekitten.com http://dummyimage.com resources.bamboohr.com connect.facebook.com connect.facebook.net *.google.com www.googletagmanager.com www.google-analytics.com stats.g.doubleclick.net; connect-src 'self' *.google-analytics.com *.google.com *.googletagmanager.com stats.g.doubleclick.net www.facebook.com ig.instant-tokens.com graph.instagram.com vimeo.com www.sandbox.paypal.com www.paypal.com sidefx.bamboohr.com https://hcaptcha.com https://*.hcaptcha.com forms.copper.com; media-src www.sidefx.com cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net; report-uri /csp-report/ 1 default-src 'self' https://www.madavi.de; font-src 'self' data: https://www.madavi.de; img-src 'self' insecure.madavi.de https://www.madavi.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.ampproject.org https://www.madavi.de; style-src 'self' 'unsafe-inline' https://www.madavi.de; report-uri https://www.madavi.de/wp-json/wpcsp/v1/route/LogPolicyViolation?_wpnonce=658afa43a2 1 default-src 'self'; frame-src 'self' https://datawrapper.dwcdn.net https://js.chargebee.com https://js.stripe.com https://datawrapper-test.chargebee.com https://youtube-nocookie.com https://platform.twitter.com; worker-src blob:; connect-src 'self' data: https://ifconfig.me/ip wss://ws.datawrapper.de https://pwk.datawrapper.de https://js.chargebee.com https://*.cloudfront.net https://*.sentry.io https://*.gstatic.com https://static.dwcdn.net https://datawrapper.dwcdn.net https://comments.datawrapper.de https://fonts.googleapis.com/ https://app.datawrapper.de https://api.fontsource.org/v1/fonts/ app.datawrapper.de ; font-src 'self' data: https://static.dwcdn.net https://fonts.gstatic.com https://fonts.dwcdn.net ; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' https://appsforoffice.microsoft.com https://datawrapper.dwcdn.net https://pwk.datawrapper.de 'nonce-7lmO3MXKCdbaKQJ/agxC2w=='; script-src-elem 'self' https://pwk.datawrapper.de https://js.chargebee.com https://js.stripe.com https://appsforoffice.microsoft.com https://platform.twitter.com https://pt.dwcdn.net https://datawrapper.dwcdn.net/ https://pwk.datawrapper.de https://app.datawrapper.de https://comments.datawrapper.de 'nonce-7lmO3MXKCdbaKQJ/agxC2w=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://datawrapper.dwcdn.net https://static.dwcdn.net https://pt.dwcdn.net; style-src-elem 'self' 'unsafe-inline' https://static.dwcdn.net https://js.chargebee.com https://fonts.googleapis.com https://pt.dwcdn.net https://datawrapper.dwcdn.net https://js.chargebee.com/assets/; report-uri %%CSP_REPORT_URI%% 1 connect-src 'self' https://checkoutshopper-live.adyen.com https://www.facebook.com https://www.google.com https://googleads.g.doubleclick.net https://www.googleoptimize.com https://*.hotjar.com https://*.mparticle.com https://beacon.krxd.net https://*.tre.se https://vercel.live https://api.usabilla.com https://dc.services.visualstudio.com https://stats.g.doubleclick.net https://www.google-analytics.com https://api.customersaas.com https://vc.hotjar.io wss://ws.hotjar.com https://cdn.linkedin.oribi.io https://adservice.google.com https://fonts.gstatic.com https://content.hotjar.io https://*.optimizely.com https://region1.google-analytics.com wss://ws-us3.pusher.com; default-src 'self' https://*.tre.se; font-src 'self' data: https://static.customersaas.com https://vercel.live https://assets.vercel.com; frame-src 'self' https://checkoutshopper-live.adyen.com https://6142836.fls.doubleclick.net https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://widget.trustpilot.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://www.youtube.com https://cdn.krxd.net https://cloud.epost.tre.se https://coverage.tre.se https://tre.workbuster.com https://vars.hotjar.com https://td.doubleclick.net; img-src 'self' data: https://checkoutshopper-live.adyen.com https://6142836.fls.doubleclick.net https://www.facebook.com https://clients1.google.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.googletagmanager.com https://beacon.krxd.net https://*.tre.se https://d6tizftlrpuof.cloudfront.net https://vercel.live http://images.ctfassets.net https://images.ctfassets.net https://jslog.krxd.net/ https://t.co https://w.usabilla.com https://www.google-analytics.com/collect https://www.google.se https://www.google.dk https://i.ytimg.com https://img.youtube.com https://new-collect.albacross.com https://d35v9wsdymy32b.cloudfront.net https://px.ads.linkedin.com https://ad.doubleclick.net https://vercel.com blob:; manifest-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; report-uri https://www.tre.se/logger/csp-report; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://static.customersaas.com https://clients1.google.com https://www.googleoptimize.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.googletagmanager.com https://*.hotjar.com https://*.mparticle.com https://widget.trustpilot.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://www.youtube.com https://*.adtr.io https://*.krxd.net https://adtr.io https://analytics.twitter.com https://api.usabilla.com https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://bat.bing.com https://cdn.bannerflow.com https://cdn.tre.se https://cdnn.tre.se https://connect.facebook.net https://cse.google.com https://gtm.adt313.net/jsTag https://hi3gscriptbucket.blob.core.windows.net https://rules.quantcount.com https://s.ytimg.com https://secure.quantserve.com https://ssl.google-analytics.com https://static.ads-twitter.com https://tagmanager.google.com https://w.usabilla.com/ https://www.google-analytics.com https://www.googleadservices.com https://serve.albacross.com https://tre.workbuster.com https://region1.analytics.google.com https://cdn.amplitude.com https://treva.boost.ai; style-src 'report-sample' 'self' 'unsafe-inline' https://static.customersaas.com https://www.google.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://d1r5etm691cejh.cloudfront.net; 1 default-src 'self' *.antpedia.com v.antwebinar.com hmcdn.baidu.com hm.baidu.com m.baidu.com jspassport.ssl.qhimg.com *.google-analytics.com zz.bdstatic.com s.ssl.qhres.com sp0.baidu.com s.360.cn c.mipcdn.com wpa.qq.com res.wx.qq.com mp.weixin.qq.com msite.baidu.com ae.bdstatic.com share.baidu.com bdimg.share.baidu.com *.alicdn.com *.cn-hangzhou.log.aliyuncs.com *.dns-detect.alicdn.com browser.sentry-cdn.com push.zhanzhang.baidu.com po.srf.baidu.com toutong.baidu.com static.bshare.cn cdn.jsdelivr.net sentry.io *.googleapis.com *.cnzz.com api.map.baidu.com *.uc.cn uc.gre *.gstatic.com *.ucweb.com bshare.optimix.cn s2.pstatp.com *.googlesyndication.com *.googleadservices.com *.googletagmanager.com *.qhres2.com 'unsafe-inline' 'unsafe-eval'; img-src * data: ; frame-src https://*.qq.com https://*.antpedia.com https://*.g.doubleclick.net https://*.googlesyndication.com https://*.google.com webcompt:; report-uri https://www.antpedia.com/scp-report/index.php; 1 frame-ancestors 'self' https://stage.lovdata.no https://smia.lovdata.no/ 1 frame-ancestors 'self'; block-all-mixed-content; default-src 'self'; script-src 'self' 'sha256-5s1UCPQTqKWc18lk0CbkMG0IYokX1utP9ZMQQYiuwXk=' 'sha256-G5NvPksjkp09uU+DikUdTcBXp0UV/362J6blwWczw5I=' 'sha256-HLwLpFPvuHKI0X/UFMhOHQNt1eedIdJGTPML3b+GfWo=' 'sha256-MM3CG7szGAeVIKY58JGR+X+7xTDccDemqcIY0lQLrX8=' 'sha256-OifdWXgFw+IPMAs6Nnr1te5UDPoRIbkDLB1lXZmmRP8=' 'sha256-oh6ZTSefRfIBPlcye8dBjlQBkC0A32V1QIb2htJq7ao=' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.containers.piwik.pro https://*.wistia.com https://*.wistia.net https://maps.google.com https://maps.googleapis.com https://src.litix.io https://use.typekit.net; script-src-elem 'self' 'report-sample' https: *.containers.piwik.pro *.wistia.com *.wistia.net maps.google.com maps.googleapis.com src.litix.io use.typekit.net 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline' blob: *.typekit.net fonts.googleapis.com fast.wistia.com; object-src embedwistia-a.akamaihd.net; frame-src 'self' https: blob: *.wistia.net *.wistia.com maps.google.com maps.googleapis.com uwhealth.formstack.com; child-src 'self' blob:; img-src 'self' data: blob: *.wistia.net *.wistia.com *.typekit.net *.gstatic.com *.ggpht.com *.googleapis.com embedwistia-a.akamaihd.net images.ctfassets.net maps.google.com maps.googleapis.com res.cloudinary.com swedishamericanmychart.org i.ytimg.com; font-src 'self' data: *.wistia.net *.wistia.com fonts.googleapis.com fonts.gstatic.com res.cloudinary.com use.typekit.net; connect-src 'self' microservices.uwhealth.dev microservices.uwhealth.org *.wistia.com *.typekit.net *.litix.io *.cloud.coveo.com embedwistia-a.akamaihd.net fonts.googleapis.com fonts.gstatic.com fast.wistia.net images.ctfassets.net maps.google.com maps.googleapis.com noembed.com res.cloudinary.com uwhealth.piwik.pro pnapi.invoca.net; manifest-src 'self'; base-uri 'self'; form-action 'self'; media-src 'self' data: blob: *.wistia.net *.wistia.com embedwistia-a.akamaihd.net res.cloudinary.com; prefetch-src 'self'; worker-src 'self' blob:; report-to testing 1 default-src 'self';img-src 'self' data: https://flickr.com https://*.flickr.com https://s.gravatar.com https://s.gravatar.com/avatar https://secure.gravatar.com/avatar https://i1.wp.com/cdn.auth0.com/avatars https://cdn.auth0.com/avatars https://g.stripe.com/ https://ssl.google-analytics.com https://pagead2.googlesyndication.com https://pbs.twimg.com/profile_images/ https://farm66.static.flickr.com https://www.google-analytics.com https://tpc.googlesyndication.com https://pbs.twimg.com https://securepubads.g.doubleclick.net https://*.amazon-adsystem.com https://fundingchoicesmessages.google.com https://*.3lift.com https://ams-pageview-public.s3.amazonaws.com https://www.google.com https://syndication.twitter.com https://image8.pubmatic.com https://googleads.g.doubleclick.net https://*.googleusercontent.com;base-uri 'self';font-src 'self' https: data:;frame-ancestors 'self';frame-src https://js.stripe.com https://platform.twitter.com/ https://syndication.twitter.com/ https://tpc.googlesyndication.com/ https://*.safeframe.googlesyndication.com/ https://www.google.com/ https://googleads.g.doubleclick.net/;connect-src 'self' https: https://securepubads.g.doubleclick.net/pagead/ppub_config https://bam.nr-data.net/events/1/cb925c8058;object-src none;script-src 'self' 'unsafe-inline' report-sample https://js.stripe.com/v3/ https://code.jquery.com/jquery-1.12.4.min.js https://code.jquery.com/jquery-3.4.1.slim.min.js https://code.jquery.com/jquery-migrate-1.4.1.min.js https://cdn.jsdelivr.net/npm/popper.js@1.16.0/dist/umd/popper.min.js https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/validate.js/0.13.1/validate.min.js https://cdnjs.cloudflare.com/ajax/libs/underscore.js/1.8.3/underscore-min.js https://cdnjs.cloudflare.com/ajax/libs/list.js/1.5.0/list.min.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/ https://ssl.google-analytics.com/ga.js https://js-agent.newrelic.com/nr-spa-1184.min.js https://fundingchoicesmessages.google.com https://bam.nr-data.net https://securepubads.g.doubleclick.net https://www.googletagservices.com https://adservice.google.com https://cdnjs.cloudflare.com/ajax/libs/tether/1.4.0/js/tether.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js https://cdn.jsdelivr.net/npm/clipboard@2.0.8/dist/clipboard.min.js https://platform.twitter.com/widgets.js https://cdnjs.cloudflare.com/ajax/libs/howler/2.1.1/howler.min.js https://cdnjs.cloudflare.com/ajax/libs/validator/10.9.0/validator.min.js https://*.safeframe.googlesyndication.com/ https://*.googlesyndication.com/ https://platform.twitter.com/js/ https://cdn.ampproject.org http://www.google-analytics.com https://adservice.google.be https://adservice.google.ca https://adservice.google.co.id https://adservice.google.co.mz https://adservice.google.co.th https://adservice.google.co.uk https://adservice.google.co.za https://adservice.google.com.au https://adservice.google.com.ec https://adservice.google.com.hk https://adservice.google.com.ng https://adservice.google.com.np https://adservice.google.com.ph https://adservice.google.com.sa https://adservice.google.de https://adservice.google.es https://adservice.google.fi https://adservice.google.fr https://adservice.google.ie https://adservice.google.it https://adservice.google.lk https://adservice.google.lt https://adservice.google.nl https://adservice.google.no https://adservice.google.rs https://googleads.g.doubleclick.net;script-src-attr none;style-src 'self' https: 'unsafe-inline' report-sample;report-uri https://5f9d927665d1a16209ba908c.endpoint.csper.io 1 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: 'self' data:; font-src https: 'self' data:; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-web.zinio.com https://js-agent.newrelic.com https://*.nr-data.net https://www.googleadservices.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.paypal.com https://www.paypalobjects.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.googletagmanager.com https://www.google-analytics.com https://zinio-sjc.gravityrd-services.com https://*.zopim.com https://static.zdassets.com https://d1fc8wv8zag5ca.cloudfront.net/2.10.2/sp.js https://cdn.jsdelivr.net https://recaptcha.net https://www.gstatic.com https://connect.facebook.net https://www.facebook.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://app.vwo.com;style-src 'self' 'unsafe-inline' https://*.audiencemedia.com data: https://app.vwo.com;img-src 'self' data: blob: https://*.ziniopro.com https://*.audiencemedia.com https://googleads.g.doubleclick.net https://www.google.com https://*.paypal.com https://*.braintreegateway.com https://v2assets.zopim.io https://discover.zinio.com https://sleeknotestaticcontent.sleeknote.com https://analytics.sleeknote.com https://www.google-analytics.com https://www.facebook.com https://www.googletagmanager.com https://dev.visualwebsiteoptimizer.com;media-src 'self' https://static.zdassets.com;connect-src 'self' https://*.audiencemedia.com https://*.ziniopro.com https://*.nr-data.net https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.jsdelivr.net https://*.braintree-api.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.paypal.com https://ekr.zdassets.com https://zinio.zendesk.com wss://widget-mediator.zopim.com wss://zinio.zendesk.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://collector.datacloud.zinio.com https://www.facebook.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://images.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://sleeknotecustomerscripts.sleeknote.com https://dev.visualwebsiteoptimizer.com;font-src 'self' https://*.audiencemedia.com https://fonts.gstatic.com https://sleeknotestaticcontent.sleeknote.com;frame-src 'self' https://td.doubleclick.net https://*.paypal.com https://*.braintreegateway.com https://recaptcha.net https://www.facebook.com https://web.facebook.com https://*.sleeknote.com https://app.vwo.com;frame-ancestors none 1 script-src 'strict-dynamic' 'nonce-cIsCMxzfS2wQARU7/aZRcQ==' 1 script-src 'nonce-xY34mpCe6WODq70M7pLwGg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=d5665ae4-8748-4897-916c-b75bce1bca09; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors *.unionesarda.it s.clickiocdn.com *.ampproject.org *.google.com; report-uri /csp-report 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-Rsnp7HxFBYgkTZscwhxk3g==' 1 default-src 'self' https://*.ebizautos.com; img-src *; script-src 'self' 'unsafe-inline' *; font-src *; media-src *; frame-src *; manifest-src 'self'; style-src 'self' 'unsafe-inline' *; connect-src https://*; object-src 'none'; worker-src 'none'; base-uri 'self'; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://sourcingjournal.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net data: *.hotjar.com github.com cdn.honey.io *.photoslurp.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.redsys.es facebook.com *.adyen.com *.redsys.com *.pinterest.com sas.redsys.es *.facebook.com sas.redsys.com checkoutshopper-live.adyen.com checkoutshopper-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.google.com *.addthis.com *.kampyle.com facebook.com docs.google.com *.facebook.com *.pinterest.es *.pinterest.com service.force.com *.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com blob: *.w3.org *.bing.com c.bing.com *.hotjar.com *.paypal.com bat.bing.com *.clarity.ms *.google.fr facebook.com *.kampyle.com *.gstatic.com *.ladybird.nl *.google.com *.fbcdn.net *.cookiepro.com *.pinterest.com *.pronovias.com *.facebook.com *.google.es *.photoslurp.com *.googleapis.com *.sanpatrick.com *.nicolemilano.com *.cdninstagram.com instagram.com *.verawangbride.com *.whiteonebridal.com *.googletagmanager.com scontent.fmad7-1.fna.fbcdn.net click.s50.exacttarget.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com unpkg.com *.force.com bat.bing.com *.adyen.com *.pinimg.com *.google.com *.hotjar.com *.tiktok.com dropbox.com gstatic.com *.clarity.ms *.moatads.com *.addthis.com *.kampyle.com *.gstatic.com *.dropbox.com *.cookiepro.com *.facebook.net *.facebook.com facebook.net *.photoslurp.com *.googleapis.com *.salesforce.com *.addthisedge.com *.secure.force.com http://polyfill.io service.force.com bam.eu01.nr-data.net *.nicolemilano.com *.empathybroker.com x.empathy.co x.staging.empathy.co *.lightning.force.com analytics.tiktok.com *.googletagmanager.com googletagmanager.com *.salesforceliveagent.com static.lightning.force.com *.la3-c1cs-fra.salesforceliveagent.com d.la3-c1cs-fra.salesforceliveagent.com pronoviasgroup.my.salesforce.com *.pinterest.com player.vimeo.com *.surveymonkey.com *.criteo.com ct.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.honey.io *.kampyle.com *.force.com *.photoslurp.com service.force.com *.nicolemilano.com gstatic.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net *.photoslurp.com player.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io wss: bat.bing.com *.force.com *.tiktok.com *.google.com *.hotjar.io *.clarity.ms *.vimeo.com d.clarity.ms h.clarity.ms *.kampyle.com *.hotjar.com google.com vc.hotjar.io ws7.hotjar.com *.instagram.com *.cookiepro.com *.pinterest.com *.amazonaws.com client.rum.us-east-1.amazonaws.com sts.eu-west-1.amazonaws.com ws16.hotjar.com ws20.hotjar.com ws22.hotjar.com ws23.hotjar.com ws33.hotjar.com ws34.hotjar.com *.facebook.com *.googleapis.com *.photoslurp.com *.secure.force.com bam.eu01.nr-data.net *.empathybroker.com x.empathy.co x.staging.empathy.co stats.g.doubleclick.net *.google-analytics.com api.empathybroker.com api.empathy.co api.staging.empathy.co *.cardinalcommerce.com api-staging.empathybroker.com pronoviasgroupcti.secure.force.com analytics.pangle-ads.com properties *.criteo.com *.onetrust.com *.pangle-ads.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'; script-src 'self' https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google-analytics.com https://assets.convertflow.com https://cdn.jsdelivr.net https://snap.licdn.com https://pi.pardot.com https://stats.g.doubleclick.net https://region1.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://www.google-analytics.com .https://stats.g.doubleclick.net https://cdn.cookielaw.org https://cdn.convertflow.com https://px.ads.linkedin.com https://pi.pardot.com; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://api.convertflow.com https://app.convertflow.co https://cdn.cookielaw.org https://geolocation.onetrust.com https://snap.licdn.com https://px.ads.linkedin.com https://pi.pardot.com; frame-src 'self' https://www.googletagmanager.com https://app.convertflow.co https://pi.pardot.com; upgrade-insecure-requests; report-to csp-endpoint; report-uri reporting URL/report; 1 default-src 'self'; script-src 'self' 'strict-dynamic' 'sha256-B2ijbidY/36WiZeOQ4feQK1E4pzvkySGJgi1+p+fzS0=' 'sha256-FqS75La0kucsCzYdPk70EY2E06leY4l2dj/lGHD2UBQ=' 'sha256-wS4j3xASxiV4ccFi6gFW3nQyl8HE9x9++SauQVmC2MI=' 'sha256-oSFIklmLVCmyLR2UGe+6s9BhIe+E98h+Qla6zUXZxYo=' 'sha256-4vHUiCbq6VWyfJ9HG36ClOfUtwF3YPmnGEMFLF02GSk=' 'sha256-CqS4mELSYVqNHgOX6Z3Rz3pc5BBQNvRBUX6l5mggx5s=' 'sha256-C9cjnt95nyjzeA165CXH33Y4dGPsuv7EPq+sskBKh24=' 'sha256-oVBJC84KeqkWD8YKwRhi7YulNpfCMatZ/AtBueJiJBw=' 'sha256-snSgSI0BjjybXXT5XjMlMnfGtaSL6JDTXJrb0Qa6MgY=' 'sha256-I5pzwNlOsuYvwtJ6gNrB/+EpALSuDnWzq2Vy8SQCoig=' 'sha256-65p00hdANpBG3OjFooizMqNwdxQFSbNbk8yNEThP0cU=' 'sha256-JKLpqIvSXexbwW4WCYKjnFFiX54Sdjs0p8wzlpX5Tas=' 'sha256-Nzf2PnbPY4FS30IBC+WcjRB5FM5xr6Vcf4UkYeoiUfY=' 'sha256-YK/s6V2LXII6euS3Z4rtkEEDkW7h0ZnQ93S79n013B4=' 'sha256-DAHhL2KL4/D0N95FcV2rt4kuyJqUtUFXcQ+Rgrm8n8k=' 'sha256-BDJw56hOSYkqXW5f6kYD/BThM/Ac6Kw6PY3UiOb9Ogk=' 'sha256-GXBifbBfbyuYZEXso+B6IJsm/SkFzw+kRei2aHzKOnA=' 'sha256-VApnDE2LCHgeJMjH6jRHsqEhgc+o2MSl7W6AUB7tuzY=' 'sha256-2QxNyaIYbBzc7I4msHTwUA2iiFsKDvWj9+/BXLKtWy8=' 'sha256-KA7+joXuYqEpX5+V0Zm1SOaMNG4V4xCkHQTTvF3F9qc=' 'sha256-/uQVytL3+4KdrEyU6ZN6U8oqI0M9RTsTtPCq6bOx5SQ=' 'sha256-MP90K9Avg8++m7OkTjp60jtpNs8/lCc6FnKk3tw+X80='; connect-src 'self' stats.g.doubleclick.net analytics.google.com *.analytics.google.com www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.ca www.googletagmanager.com www.google-analytics.com api.statsig.com featuregates.org statsigapi.net events.statsigapi.net api.statsigcdn.com featureassets.org assetsconfigcdn.org prodregistryv2.org cloudflare-dns.com beyondwickedmapping.org www.googletagmanager.com *.google-analytics.com www.googleadservices.com consent.cookie-script.com join.com um.join.com *.clarity.ms device.maxmind.com *.mmapiws.com api.refiner.io cdn.join.com www.youtube.com www.tiktok.com/node/ *.ttwstatic.com *.tiktokv.com *.tiktokv.eu *.tiktokw.eu www.linkedin.com; style-src 'self' 'unsafe-inline' cdn.join.com *.neutral.ttwstatic.com; img-src 'self' data: c.bing.com c.clarity.ms www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.ca www.googletagmanager.com www.google-analytics.com cdn-public-assets.join.com cdn.join.com *.ttwstatic.com *.tiktokcdn.com *.tiktokcdn-eu.com *.tiktokcdn-us.com *.ytimg.com www.linkedin.com *.googleusercontent.com; frame-src www.googletagmanager.com js.refiner.io www.youtube.com www.youtube-nocookie.com www.tiktok.com www.linkedin.com li.protechts.net quiz.tryinteract.com *.spotify.com tenor.com; font-src 'self' data: cdn.join.com *.neutral.ttwstatic.com fonts.gstatic.com; script-src-elem 'self' js.refiner.io join.com um.join.com scripts.clarity.ms device.maxmind.com googleads.g.doubleclick.net cdn.jsdelivr.net/npm/@statsig/ widget.join.com www.clarity.ms cdn.cookie-script.com www.googletagmanager.com www.youtube.com *.neutral.ttwstatic.com *.neutral.tiktokcdn-eu.com www.tiktok.com/embed.js tenor.com *.tenor.com 'sha256-7PO9Sf8E8Z6CI+XugBIVArS8kyVNIn7bMXYo4t7CPBk=' 'sha256-WzulH+JUQNOvXkAcuOQYHBLjsZEB8IDMH1Eo767Majs=' 'sha256-g/Ot9ViYMe/nTRaPD9Zqlze0e4ougD8rfFmIupGCa78=' 'sha256-LdH1VQvG32ftmjqWaXEpHBfdfuaKErChemW6fp+mgoE=' 'sha256-qY1+jSYP/QTeB46l+FBnfHfxoeuW7gZLMeucRtWBVMM=' 'sha256-z+StzS/qtI8dbtHUSgyscJFEl73eypDMffbLNjzvp4c=' 'sha256-B2ijbidY/36WiZeOQ4feQK1E4pzvkySGJgi1+p+fzS0=' 'sha256-FqS75La0kucsCzYdPk70EY2E06leY4l2dj/lGHD2UBQ=' 'sha256-wS4j3xASxiV4ccFi6gFW3nQyl8HE9x9++SauQVmC2MI=' 'sha256-oSFIklmLVCmyLR2UGe+6s9BhIe+E98h+Qla6zUXZxYo=' 'sha256-4vHUiCbq6VWyfJ9HG36ClOfUtwF3YPmnGEMFLF02GSk=' 'sha256-CqS4mELSYVqNHgOX6Z3Rz3pc5BBQNvRBUX6l5mggx5s=' 'sha256-C9cjnt95nyjzeA165CXH33Y4dGPsuv7EPq+sskBKh24=' 'sha256-oVBJC84KeqkWD8YKwRhi7YulNpfCMatZ/AtBueJiJBw=' 'sha256-snSgSI0BjjybXXT5XjMlMnfGtaSL6JDTXJrb0Qa6MgY=' 'sha256-I5pzwNlOsuYvwtJ6gNrB/+EpALSuDnWzq2Vy8SQCoig=' 'sha256-65p00hdANpBG3OjFooizMqNwdxQFSbNbk8yNEThP0cU=' 'sha256-JKLpqIvSXexbwW4WCYKjnFFiX54Sdjs0p8wzlpX5Tas=' 'sha256-Nzf2PnbPY4FS30IBC+WcjRB5FM5xr6Vcf4UkYeoiUfY=' 'sha256-YK/s6V2LXII6euS3Z4rtkEEDkW7h0ZnQ93S79n013B4=' 'sha256-DAHhL2KL4/D0N95FcV2rt4kuyJqUtUFXcQ+Rgrm8n8k=' 'sha256-BDJw56hOSYkqXW5f6kYD/BThM/Ac6Kw6PY3UiOb9Ogk=' 'sha256-GXBifbBfbyuYZEXso+B6IJsm/SkFzw+kRei2aHzKOnA=' 'sha256-VApnDE2LCHgeJMjH6jRHsqEhgc+o2MSl7W6AUB7tuzY=' 'sha256-2QxNyaIYbBzc7I4msHTwUA2iiFsKDvWj9+/BXLKtWy8=' 'sha256-KA7+joXuYqEpX5+V0Zm1SOaMNG4V4xCkHQTTvF3F9qc=' 'sha256-/uQVytL3+4KdrEyU6ZN6U8oqI0M9RTsTtPCq6bOx5SQ=' 'sha256-MP90K9Avg8++m7OkTjp60jtpNs8/lCc6FnKk3tw+X80='; media-src 'self' cdn-public-assets.join.com *.tiktokcdn-eu.com *.tiktok.com; base-uri 'self'; form-action 'self' api.refiner.io; frame-ancestors www.google.com 1 default-src 'self' https://*.googleapis.com https://*.google.com https://*.google.co.* https://*.google.com.* https://*.google.* https://google.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://api.hubspot.com https://*.hs-scripts.com https://js-na1.hs-scripts.com https://*.hs-banner.com https://js.hs-banner.com https://*.hscollectedforms.net https://forms.hscollectedforms.net https://*.hs-analytics.net https://*.hsadspixel.net https://*.website-files.com https://cdn.prod.website-files.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://assets.calendly.com https://*.linkedin.com https://get.geojs.io https://api.hubapi.com https://api.murf.ai https://login.murf.ai https://murf.ai https://d3e54v103j8qbb.cloudfront.net https://www.googletagmanager.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-analytics.net https://js.hs-banner.com https://js.usemessages.com https://snap.licdn.com https://tracking.g2crowd.com https://tracking-api.g2.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://api.factors.ai https://app.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://www.google-analytics.com https://connect.facebook.net https://www.gstatic.com https://cdn.embedly.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.googleapis.com https://*.google.com https://*.google.co.* https://*.google.com.* https://*.google.* https://google.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://*.hs-scripts.com https://js-na1.hs-scripts.com https://*.website-files.com https://cdn.prod.website-files.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://assets.calendly.com https://*.linkedin.com https://login.murf.ai https://d3e54v103j8qbb.cloudfront.net https://www.googletagmanager.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-analytics.net https://js.hs-banner.com https://js.usemessages.com https://snap.licdn.com https://tracking.g2crowd.com https://www.googleadservices.com https://app.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://connect.facebook.net https://www.gstatic.com https://cdn.embedly.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.google.com https://accounts.google.com https://*.website-files.com https://cdn.prod.website-files.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.gstatic.com https://cdn.embedly.com; font-src 'self' data: https:; img-src 'self' data: https: blob:; media-src 'self' data: blob: https://murf.ai; connect-src 'self' blob: data: https://*.googleapis.com https://*.google.com https://*.google.co.* https://*.google.com.* https://*.google.* https://google.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://api.hubspot.com https://*.hs-scripts.com https://*.hs-banner.com https://js.hs-banner.com https://*.hscollectedforms.net https://forms.hscollectedforms.net https://*.linkedin.com https://get.geojs.io https://api.hubapi.com https://api.murf.ai https://login.murf.ai https://murf.ai https://cdn.prod.website-files.com https://tracking-api.g2.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://api.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://www.google-analytics.com https://connect.facebook.net https://cdn.embedly.com https://webflow.com; frame-src 'self' https://*.google.com https://*.google.co.* https://*.google.com.* https://*.google.* https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://*.hubspot.com https://app.hubspot.com https://assets.calendly.com https://calendly.com https://login.murf.ai https://cdn.embedly.com; report-uri https://o4504603155759104.ingest.us.sentry.io/api/4509798552305664/security/?sentry_key=05d6eb750229178df61a908e1a0ed8fd; report-to csp-endpoint 1 default-src *; script-src * 'unsafe-inline' 'unsafe-eval' blob: data:; style-src * 'unsafe-inline'; img-src * data:; font-src *; connect-src * wss:; frame-src *; object-src *; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv27.mno%3Bi-19b29dc81e5-0x2604#pd 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src * data: blob:; 1 default-src 'self' motul.com *.cdninstagram.com *.elfsightcdn.com; script-src 'self' 'unsafe-eval' *.axept.io *.elfsight.com https://*.googletagmanager.com *.hotjar.com *.facebook.net 'unsafe-inline' *.googleapis.com *.channelsight.com js.monitor.azure.com *.explorify.com *.elfsightcdn.com *.youtube.com; img-src 'self' staging-cms.motul.com axeptio.imgix.net www.google.com *.gstatic.com data: *.elfsight.com *.facebook.com *.elfsightcdn.com *.googleapis.com *.hotjar.com *.cdninstagram.com *.motul.com *.amazonaws.com *.channelsight.com cscoreproweustor.blob.core.windows.net motul.incony.de *.explorify.com https://i.ytimg.com/ https://*.googleusercontent.com/places https://*.google-analytics.com https://*.googletagmanager.com; child-src 'self' motul.com *.hotjar.com *.youtube.com https://*.googletagmanager.com *.youtube-nocookie.com;; style-src 'self' 'unsafe-inline' *.elfsight.com *.googleapis.com *.channelsight.com *.explorify.com; font-src 'self' *.gstatic.com *.hotjar.com *.channelsight.com *.explorify.com data:; report-uri /api/v2/security-headers; connect-src 'self' *.axept.io axeptio.imgix.net *.spinque.com *.elfsight.com *.facebook.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google.com *.hotjar.com *.googleapis.com *.azurewebsites.net *.motul.com *.hotjar.io wss://ws4.hotjar.com *.channelsight.com https://cms.motul.com/search/api; frame-ancestors 'self' *.motul.com 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=r2fyeH5KsHSot1oQ1.YWh_NjDbadpVZQES.IEcKEUkw-1765936486-1.0.1.1-eskeMbF1mLJpj7_pYt7jE3VgG3F21NzIDF5C.CpIk2jxpQ7s2_19UxK0ZePPsFs8n8FSn0pvR5_D.clqF8l2IdwLvO3fSGkK0kNZdZpmCHDHDpUArz1FOXqhm4VLG_qULjhPqUP5IunuQNS8dguGVhpX6XgtsQ5HMWvJBQFPe4I; report-to cf-csp-endpoint 1 default-src 'self'; style-src 'self'; script-src 'self' https://maps.googleapis.com https://googletagmanager.com https://munchkin.marketo.net https://script.crazyegg.com https://www.influ2.com https://bat.bing.com https://ws.zoominfo.com https://www.clickcease.com https://tracking.g2crowd.com https://go.qgenda.com https://cdn.bizible.com https://j.6sc.co https://googleads.g.doubleclick.net; connect-src 'self' https://maps.googleapis.com https://script.crazyegg.com https://761-yjz-981.mktoresp.com https://www.google-analytics.com https://t.influ2.com https://c.6sc.co https://ipv6.6sc.co https://stats.g.doubleclick.net https://tracking.g2crowd.com https://ws.zoominfo.com https://realtime.ramblechat.com; img-src 'self' https://www.google.com https://bat.bing.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://td.doubleclick.net; object-src 'self'; upgrade-insecure-requests; 1 default-src 'self'; connect-src 'self' *.hotjar.com *.hotjar.io c.amazon-adsystem.com *.wistia.net *.wistia.com js.monitor.azure.com snap.licdn.com www.googletagmanager.com www.google.com *.doubleclick.net analytics.google.com *.givchariot.com d.adroll.com dc.services.visualstudio.com insight.adsrvr.org *.linkedin.com s.amazon-adsystem.com doublethedonation.com js.monitor.azure.com; font-src 'self' data: cdn.givechariot.com fast.wistia.net doublethedonation.com; frame-src 'self' *.adsrvr.org *.adroll.com www.googletagmanager.com www.gstatic.com *.doubleclick.net *.wistia.net *.ceros.com wwp.mysalesforce-sites.com www.careerarc.com www.google.com www.youtube.com wwp.my.salesforce-sites.com; img-src 'self' data: *.adroll.com *.doubleclick.net *.lightboxcdn.com *.wistia.com *.wistia.net ad.ipredictive.com analytics.twitter.com bat.bing.com cdn.givechariot.com cdn.jsdelivr.net doublethedonation.com fast.wistia.net *.adsrvr.org media.sabio.us *.collect.igodigital.com p1.parsely.com px.adentifi.com *.linkedin.com t.co um.simpli.fi woundedwarriorprojectsite.secure.force.com wwp.my.salesforce-sites.com www.facebook.com *.google.com www.googleadservices.com www.googletagmanager.com x.bidswitch.net media.sabio.us aa.agkn.com ads.stickyadstv.com analytics.twitter.com attrk.com bat.bing.com bcp.crwdcntrl.net ce.lijit.com cs.admanmedia.com dsum-sec.casalemedia.com eb2.3lift.com fei.pro-market.net ib.adnxs.com idsync.rlcdn.com image2.pubmatic.com loadm.exelator.com ml314.com *.igodigital.com pippio.com pixel.locker2.com pixel.rubiconproject.com pixel.tapad.com ps.eyeota.net px.adentifi.com s.ad.smaato.net simplifi.partners.tremorhub.com sync.1rx.io sync.bfmio.com sync.intentiq.com sync.outbrain.com sync.taboola.com trkn.us ups.analytics.yahoo.com us-u.openx.net arttrk.com media.sabio.us um.simpli.fi; script-src 'self' *.hotjar.com bat.bing.com *.salesforceliveagent.com cdn.givechariot.com connect.facebook.net *.wistia.com *.wistia.net *.adroll.com tag.simpli.fi www.google.com www.googleadservices.com *.googletagmanager.com *.google-analytics.com *.lightboxcdn.com www.youtube.com *.collect.igodigital.com aa.trkn.us browser.sentry-cdn.com cdn.c212.net cdn.parsely.com doublethedonation.com *.doubleclick.net js.adsrvr.org js.monitor.azure.com script.crazyegg.com snap.licdn.com tags.wdsvc.net *.ceros.com www.gstatic.com www.youtube.com; style-src 'self' cdn.givechariot.com *.wistia.com *.wistia.net js.adsrvr.org s.adroll.com www.googletagmanager.com www.lightboxcdn.com doublethedonation.com; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: dvngeac8rg9mb.cloudfront.net js.stripe.com www.gstatic.com *.googleapis.com ws.zoominfo.com www.google.com www.googletagmanager.com compilers.widgets.sphere-engine.com kit.fontawesome.com d34s7xanp5e5sf.cloudfront.net; connect-src 'self' api.stripe.com *.googleapis.com *.fontawesome.com wss://push.piazza.com; img-src 'self' data: http: https:; object-src 'none'; font-src 'self' data: *.typekit.net *.gstatic.com *.fontawesome.com; style-src 'self' 'unsafe-inline' blob: *.typekit.net *.gstatic.com *.googleapis.com dvngeac8rg9mb.cloudfront.net; frame-src 'self' www.youtube.com www.youtube-nocookie.com www.vimeo.com player.vimeo.com www.facebook.com youtu.be gfycat.com www.google.com giphy.com docs.google.com calendar.google.com www.desmos.com www.geogebra.org js.stripe.com; report-uri /security/csp_report 1 default-src 'self' blob:; base-uri 'self'; frame-ancestors 'self'; form-action 'self' https://*.furnishedfinder.com https://*.facebook.com https://www.facebook.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https:; script-src-attr 'unsafe-inline'; connect-src 'self' blob: data: https: wss://chat.stream-io-api.com wss://chat.furnishedfinder.com wss://*.tawk.to wss://*.rp.secure.iproov.me; img-src * data: blob:; font-src 'self' data: https:; frame-src 'self' blob: https:; style-src 'self' 'unsafe-inline' blob: https:; style-src-attr 'self' 'unsafe-inline'; worker-src 'self' blob:; child-src 'self' blob:; media-src 'self' data: blob: https:; object-src 'none'; manifest-src 'self' https:; report-uri https://o4507018827071488.ingest.us.sentry.io/api/4510343205421056/security/?sentry_key=1faef7d9a5760350ce11e10419c510e3&sentry_release=v0.1.8; report-to csp-endpoint-v2 1 default-src 'self'; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.facebook.net *.livechatinc.com *.google.com *.gstatic.com *.google-analytics.com *.bing.com googleads.g.doubleclick.net *.clarity.ms; style-src 'self' data: 'unsafe-inline' *.googletagmanager.com p.typekit.net use.typekit.net fonts.googleapis.com; img-src 'self' data: *.gstatic.com *.google-analytics.com *.facebook.com *.facebook.net *.itc-web.com i.ytimg.com cdn.livechatinc.com *.google.com *.bing.com *.clarity.ms; font-src 'self' data: use.typekit.net fonts.gstatic.com cdn.livechatinc.com; connect-src 'self' *.google.com *.facebook.com *.facebook.net api.livechatinc.com *.google-analytics.com stats.g.doubleclick.net *.clarity.ms; frame-src 'self' secure.livechatinc.com youtu.be *.youtube.com *.google.com; report-uri https://sentry.hutman.net/api/3/security/?sentry_key=a04ac85d1c8f41fea1eb59f045f023e1 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.lge.co.kr *.browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.criteo.com *.creativecdn.com *.naver.net *.pstatic.net *.daangn.com *.stclab.com *.google.com *.creativecdn.com *.google-analytics.com *.simpli.fi *.sauceflex.com *.facebook.com *.google.co.kr *.widerplanet.com *.daumcdn.net *.useinsider.com *.attractt.com *.criteo.net 1 default-src 'self' https: data: blob:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https: 'unsafe-inline' data: blob:; img-src 'self' https: data: blob:; font-src 'self' https: data: blob: chrome-extension: moz-extension: ms-browser-extension: safari-extension:; connect-src 'self' https: wss:; frame-ancestors 'self'; form-action 'self'; report-uri /api_v2/csp/report 1 font-src *.googleadservices.com *.googleapis.com *.fontawesome.com *.gstatic.com *.nothingbundtcakes.com tags-prod.nothingbundtcakes.com *.toasttab.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleadservices.com *.google.com *.google.com.ca *.google.com.co *.googleapis.com *.gstatic.com *.vimeo.com *.cdn-apple.com *.cookielaw.org *.usablenet.com *.usablenet.dev *.doubleclick.net *.contentsquare.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.amazonaws.com *.cognitivlabs.com *.reddit.com *.facebook.com *.adnxs.com *.magentosite.cloud *.monetate.net *.rfihub.com *.everesttech.net *.eyeota.net *.rezync.com *.attn.tv *.yimg.com *.boomtrain.com *.linkedin.com *.yahoo.com *.demdex.net *.pubmatic.com *.openx.net *.media.net *.rtactivate.com *.casalemedia.com *.rlcdn.com *.addthis.com *.tremorhub.com *.bidswitch.net *.adsrvr.org *.prf.hn prf.hn *.taggrs.io taggrs.io *.ml314.com ml314.com *.tapad.com tapad.com tags-prod.nothingbundtcakes.com *.toasttab.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com https://www.google.com/recaptcha/ *.attn.tv events.attentivemobile.com *.googleadservices.com *.googleapis.com *.cdn-apple.com *.cookielaw.org *.usablenet.com *.usablenet.dev *.contentsquare.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.tiktok.com *.bttrack.com *.adsrvr.org *.pinterest.com *.facebook.com *.magentosite.cloud *.monetate.net *.appboycdn.com *.rfihub.com *.everesttech.net *.eyeota.net *.rezync.com *.yimg.com *.boomtrain.com *.yahoo.com *.kargo.com *.licdn.com *.inpwrd.net bttrack.com *.adnxs.com *.rfihub.net cdn.bttrack.com tags-prod.nothingbundtcakes.com *.toasttab.com *.sentry.io https://gateway.moneris.com https://gatewayt.moneris.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleadservices.com *.googleapis.com *.fontawesome.com *.usablenet.com *.usablenet.dev *.nothingbundtcakes.com tags-prod.nothingbundtcakes.com *.toasttab.com https://gateway.moneris.com https://gatewayt.moneris.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.attn.tv events.attentivemobile.com *.googleadservices.com *.googleapis.com *.vimeo.com *.cdn-apple.com *.cookielaw.org *.onetrust.com *.usablenet.com *.usablenet.dev *.contentsquare.net *.doubleclick.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.tiktok.com *.bttrack.com *.adsrvr.org *.amazonaws.com *.cognitivlabs.com *.reddit.com *.pinterest.com *.facebook.com *.adnxs.com *.gstatic.com *.rlcdn.com *.magentosite.cloud *.monetate.net *.everesttech.net *.eyeota.net *.rezync.com *.yimg.com *.boomtrain.com *.yahoo.com *.kargo.com *.linkedin.com tags-prod.nothingbundtcakes.com *.toasttab.com *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://www.bing.com https://www.google.at https://www.google.de https://*.search.yahoo.com; report-uri https://www.tudorwatch.com/csp-reports/?req_id=b1cd92e 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=pix1RKzQbGvnRhWRVBIOY78hO1ULugll2jdCCNjTCco-1765941621-1.0.1.1-CvNbBSNLhglDlXWeSukoK2NsuH8fx_Ikwq2.5gnZRyXJATU9_en1CDWXI9wNlQxxaGadUH3YHnNsgQM0ACjVYh0OT3OuDjgf45mNtRUBKIdHpymlIhvAwU2SHKrXSU7nX6T4gBcRoN7dZJRgHHUUhLvDEMBLuxv_nV_btwIIcqc6XXUDaxEIrxuzbogWpZs0; report-to cf-csp-endpoint 1 default-src 'self' https://*.wistia.net https://*.wistia.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://cdn.jsdelivr.net https://analytics.sayprimer.com https://scripts.clarity.ms https://js-de.sentry-cdn.com https://*.wistia.net https://*.wistia.com https://assets.production.linktr.ee https://www.youtube.com https://assets.calendly.com https://growth.services.beekeeper.io https://connect.facebook.net https://a.omappapi.com https://tracking.g2crowd.com https://cdn-prod.eu.securiti.ai https://www.beekeeper.io https://*.zoominfo.com https://*.zi-scripts.com https://acsbapp.com https://browser.sentry-cdn.com https://js.sentry-cdn.com https://fast.wistia.com https://js.hsforms.net https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://boards.greenhouse.io https://www.bugherd.com https://sidebar.bugherd.com https://cdn.cookielaw.org https://fast.wistia.net https://www.googletagmanager.com https://www.google-analytics.com https://snap.licdn.com https://bat.bing.com https://trk.techtarget.com https://www.influ2.com https://tags.srv.stackadapt.com https://lltrck.com https://www.clarity.ms https://googleads.g.doubleclick.net https://j.6sc.co https://d10lpsik1i8c69.cloudfront.net https://tracking.intentsify.io https://pi.pardot.com https://a.usbrowserspeed.com https://a.remarketstats.com https://i.liadm.com https://a.clickcertain.com https://static.cloudflareinsights.com https://www.google.com/recaptcha/ https://*.hotjar.com https://content.p3nd0.beekeeper.io https://www.gstatic.com https://dev.visualwebsiteoptimizer.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hscollectedforms.net https://js.hsleadflows.net https://js.usemessages.com https://*.hubspot.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://assets.calendly.com https://cdn-prod.eu.securiti.ai https://a.omappapi.com https://www.beekeeper.io https://fonts.googleapis.com https://d10lpsik1i8c69.cloudfront.net https://tags.srv.stackadapt.com; connect-src 'self' data: blob: https://pagead2.googlesyndication.com https://n.clarity.ms https://e.clarity.ms https://*.litix.io https://*.wistia.com https://web-script.api.sayprimer.com https://*.wistia.net https://*.algolia.net wss://ws.hotjar.com https://ltp.linktr.ee https://calendly.com https://fast.wistia.net https://selfservice-java.beekeeper.io http://pricing.services.beekeeper.io https://stats.g.doubleclick.net https://secure.adnxs.com https://tracking-api.g2.com https://app.securiti.ai https://api.omappapi.com https://app.eu.securiti.ai https://cdn-prod.eu.securiti.ai https://analytics.google.com https://forms.hubspot.com https://*.zoominfo.com https://*.zi-scripts.com https://acsbapp.com https://*.acsbapp.com https://notify.bugsnag.com https://sidebar.bugherd.com/binoculars wss://ws-mt1.pusher.com https://sockjs.pusher.com https://fg8vvsvnieiv3ej16jby.litix.io https://forms-na1.hubspot.com https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://*.influ2.com https://c.6sc.co https://sessions.bugsnag.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.wistia.com https://yoast.com https://www.google-analytics.com https://ipv6.6sc.co https://tags.srv.stackadapt.com https://settings.luckyorange.net https://px.ads.linkedin.com https://ibc-flow.techtarget.com https://t.clarity.ms https://static.cloudflareinsights.com https://o8540.ingest.sentry.io https://*.hotjar.io wss://ws.hotjar.com/api https://*.hubspot.com https://forms.hscollectedforms.net https://api.hubapi.com https://region1.analytics.google.com https://www.google.com; font-src 'self' data: https://*.wistia.com https://fast.wistia.com https://fonts.gstatic.com https://t.influ2.com https://www.google.com; frame-src 'self' data: blob: https://fast.wistia.com https://fast.wistia.net https://www.google.com https://calendly.com http://pricing.services.beekeeper.io https://www.youtube.com https://privacy-central.eu.securiti.ai https://forms.hsforms.com https://www.youtube-nocookie.com https://boards.greenhouse.io https://*.bugherd.com https://*.wistia.com https://*.wistia.net https://open.spotify.com https://td.doubleclick.net https://www.google.com/recaptcha https://iab-eu-tcf.securiti.ai https://job-boards.greenhouse.io https://privacy-central.eu.securiti.ai https://www.googletagmanager.com; img-src 'self' data: https://*.wistia.net https://*.wistia.com https://www.google.de https://plugin-updates.wpengine.com https://assets.calendly.com https://lh7-us.googleusercontent.com https://f.hubspotusercontent10.net https://www.linkedin.com https://www.googletagmanager.com https://www.facebook.com https://sidebar.bugherd.com https://bugherd-attachments.s3.amazonaws.com https://d2iiunr5ws5ch1.cloudfront.net https://i.ytimg.com https://fast.wistia.com https://embed-ssl.wistia.com https://forms-na1.hsforms.com https://cdn.cookielaw.org https://ps.w.org https://s.w.org https://secure.adnxs.com https://ib.adnxs.com https://t.influ2.com https://px.ads.linkedin.com https://www.google.com https://bat.bing.com https://www.google-analytics.com https://lltrck.com https://b.6sc.co https://px4.ads.linkedin.com blob: https://c.clarity.ms https://c.bing.com https://dev.visualwebsiteoptimizer.com https://track.hubspot.com https://*.hsforms.com/embed/; media-src 'self' blob: https://fast.wistia.com https://*.wistia.net https://embed-cloudfront.wistia.com; worker-src 'self' blob: https://beeke25stg.eight25.xyz; frame-ancestors 'self' https://www.google.com https://privacy-central.eu.securiti.ai https://open.spotify.com https://adgen-dev.spotify.com https://local.spotify.net https://*.spotify.net https://*.spotify.com; report-to csp-violation-report-endpoint ; 1 script-src 'strict-dynamic' 'nonce-BeuvJWuXbx2m96Mk3A2Kaw==' 'self' https://assets.torob.com; style-src 'self' https://assets.torob.com/ 'unsafe-inline'; frame-ancestors 'self'; object-src 'none'; base-uri 'none'; img-src https: data: blob:; worker-src 'self'; report-uri https://sentry.torob.ir/api/5/security/?sentry_key=f93c967608d0a62ff84a3620cd0bf0e9; report-to csp-endpoint 1 default-src 'self'; script-src 'self' 'nonce-OTFlZDY3MDUtZDc3MS00YzkzLTgxODgtYzBjYzllM2ExZWZm' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://www.googletagmanager.com https://d10lpsik1i8c69.cloudfront.net https://use.fontawesome.com 'unsafe-inline'; img-src 'self' https://storage.googleapis.com/bfile-prod-assets-img/ https://storage.googleapis.com/bfile-prod-assets-orig/ https://docserv.bstock.com https://*.bstock.com https://bstock.com https://facebook.com https://www.facebook.com https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com https://*.linkedin.com https://bat.bing.com https://d10lpsik1i8c69.cloudfront.net https://*.cookielaw.org https://data.pendo.bstock.com data:; connect-src 'self' https://account.bstock.com https://erp.bstock.com https://shipment.bstock.com https://payments-transactions.bstock.com https://bapi.bstock.com https://risk.bstock.com https://offering.bstock.com https://ingestion.bstock.com https://subscription.bstock.com https://saved-search.bstock.com https://location.bstock.com https://order-process.bstock.com https://contract.bstock.com https://auth.bstock.com https://order.bstock.com https://dispute.bstock.com https://auction.bstock.com https://bridge.bstock.com https://payments-methods.bstock.com https://search.bstock.com https://listing.bstock.com https://docserv.bstock.com https://logs.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://*.launchdarkly.com https://*.bstock.com https://use.fontawesome.com https://api.segment.io https://cdn.segment.com https://content-discoveryengine.googleapis.com https://www.google.com https://www.google.com:443 https://www.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://www.googleadservices.com https://px.ads.linkedin.com https://*.doubleclick.net https://*.doubleclick.net:443 https://bat.bing.com https://*.luckyorange.net https://*.luckyorange.com https://pubsub.googleapis.com https://*.mktoresp.com https://*.mktoutil.com ws://visitors.live ws://*.visitors.live https://sdk.iad-07.braze.com https://*.pusher.com ws://*.pusher.com https://data.pendo.bstock.com https://api.stripe.com https://maps.googleapis.com https://www.googletagmanager.com https://*.cookielaw.org https://*.onetrust.com; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com; media-src 'self' https://d10lpsik1i8c69.cloudfront.net; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://*.doubleclick.net https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com; report-uri /home-portal/api/csp-report; report-to csp 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.pushpushgo.com *.klevu.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.constructor.com *.constructor.dev 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.pushpushgo.com *.klevu.com *.constructor.com *.constructor.dev data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://browser.sentry-cdn.com *.pushpushgo.com *.klevu.com *.constructor.com *.constructor.dev 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io *.constructor.com *.constructor.dev *.cnstrc.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com fonts.googleapis.com https://fonts.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: static.curations.bazaarvoice.com maxcdn.bootstrapcdn.com cdn.dynamicyield.com *.hotjar.com x.klarnacdn.net *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com *.wahooligan.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com js.stripe.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://www.googletagmanager.com/ *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com insight.adsrvr.org match.adsrvr.org www.affirm.com sandbox.affirm.com *.attn.tv bugcrowd.com imgs.cdn-btsg.com *.cloudfront.net consentag.eu track.cordial.io gum.criteo.com bid.g.doubleclick.net *.fls.doubleclick.net td.doubleclick.net www.facebook.com script.google.com *.googleapis.com *.hotjar.com *.iterable.com *.klarnaservices.com *.online-metrix.net privacyportal-cdn.onetrust.com imgs.signifyd.com *.vimeo.com vimeo.com *.wahooligan.com record.webeyez.com d.emails.wahoofitness.com wahoofitness.yonyx.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net *.googleapis.com *.gstatic.com maps.googleapis.com maps.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.adnxs.com public.adobecc.com data.adxcel-ec2.com insight.adsrvr.org match.adsrvr.org *.amazonaws.com *.atdmt.com *.bing.com *.bazaarvoice.com imgs.cdn-btsg.com *.clarity.ms cdn.cookielaw.org dis.criteo.com gum.criteo.com *.ctnsnet.com ad.doubleclick.net cm.g.doubleclick.net stats.g.doubleclick.net cdn.dynamicyield.com www.facebook.com *.google.com *.googletagmanager.com *.hotjar.com humango.ai *.iterable.com kcc0.com www.kinomap.com *.klarnaevt.com *.klarnaservices.com *.klarnauserservices.com *.ktxlytics.io www.lightboxcdn.com simage2.pubmatic.com alb.reddit.com *.rudderstack.com imgs.signifyd.com image.simplecastcdn.com t.co tk0x1.com *.wahoofitness.com *.xg4ken.com ads.yahoo.com *.analytics.yahoo.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com *.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com www.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com js.stripe.com *.affirm.com *.affirm.ca *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://*.helloextend.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com unsafe-inline *.adnxs.com js.adsrvr.org cdn.jsdelivr.net lightboxapi.azurewebsites.net cdn.attn.tv bam-cell.nr-data.net *.bazaarvoice.com bat.bing.com bugcrowd.com assets.bugcrowdusercontent.com imgs.cdn-btsg.com *.clarity.ms static.curations.bazaarvoice.com consentag.eu cdn.cookielaw.org track.cordial.io script.crazyegg.com static.criteo.net sslwidget.criteo.com *.ctnsnet.com cdn.dynamicyield.com st.dynamicyield.com connect.facebook.net *.fontawesome.com *.getroster.com *.google.com googleads.g.doubleclick.net *.hotjar.com *.iterable.com *.ktxlytics.io www.lightboxcdn.com cdn.livesession.io i.loopme.me js-agent.newrelic.com bam.nr-data.net code.jquery.com eu-library.klarnaservices.com eu-library.playground.klarnaservices.com oc-library.klarnaservices.com oc-library.playground.klarnaservices.com x.klarnacdn.net geolocation.onetrust.com h64.online-metrix.net cdn.optimizely.com www.redditstatic.com www.refersion.com assets.reflow.tv *.rudderlabs.com *.rudderstack.com cdn.segment.com imgs.signifyd.com *.stackadapt.com static.ads-twitter.com analytics.twitter.com modelviewer.dev d.emails.wahoofitness.com forms.wahoofitness.com record.webeyez.com sec.webeyez.com *.xg4ken.com *.yotpo.com www.youtube.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com display.ugc.bazaarvoice.com https://fonts.googleapis.com *.fontawesome.com static.curations.bazaarvoice.com maxcdn.bootstrapcdn.com cdn.cookielaw.org cdn.dynamicyield.com *.hotjar.com www.lightboxcdn.com x.klarnacdn.net *.stackadapt.com forms.wahoofitness.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.bazaarvoice.com data: mpsnare.iesnare.com www.wahoofitness.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adobe.io performance.typekit.net *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://*.helloextend.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.attentivemobile.com *.attn.tv bam-cell.nr-data.net *.bing.com imgs.cdn-btsg.com *.clarity.ms cdn.cookielaw.org track.cordial.io script.crazyegg.com i.ctnsnet.com stats.g.doubleclick.net *.dynamicyield.com www.facebook.com *.getroster.com analytics.google.com *.analytics.google.com *.hotjar.com *.hotjar.io mpsnare.iesnare.com *.iterable.com wss: gdpr.loopme.com i.loopme.me *.klarnaservices.com *.klarnauserservices.com *.ktxlytics.io rs.livesession.io bam.nr-data.net *.onetrust.com insight.reflow.tv *.rollbar.com *.rudderstack.com api.segment.io cdn.segment.com imgs.signifyd.com bt.signifyd.com bt.signifyd.com:1103 bt.signifyd.com:11103 d.emails.wahoofitness.com vimeo.com record.webeyez.com send.webeyez.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.wahoofitness.com/nullreport/report/nullendpoint; report-to report-endpoint; 1 default-src 'none'; font-src 'self' fonts.gstatic.com data:; img-src * 'self' data: https: https://*.usepylon.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d3vl36l12sfx26.cloudfront.net; script-src 'self' 'unsafe-inline' *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* clickhouse.com discover.clickhouse.com statuspage.incident.io www.recaptcha.net recaptcha.net https://www.datadoghq-browser-agent.com munchkin.marketo.net www.google.com google.com *.googletagmanager.com *.licdn.com www.gstatic.com js.stripe.com *.fullstory.com vercel.live https://widget.usepylon.com; style-src 'self' 'unsafe-inline' clickhouse.com discover.clickhouse.com fonts.googleapis.com vercel.live https://*.usepylon.com; object-src 'none'; worker-src 'self' blob:; connect-src 'self' 'unsafe-inline' clickhouse.com discover.clickhouse.com wss: *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* https://browser-intake-us3-datadoghq.com statuspage.incident.io www.recaptcha.net recaptcha.net *.us-east-2.amazonaws.com *.google-analytics.com *.linkedin.oribi.io *.mktoresp.com s3.eu-west-1.amazonaws.com *.fullstory.com *.auth0.com vercel.live https://*.usepylon.com wss://*.pusher.com; frame-src *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* clickhouse.com discover.clickhouse.com www.recaptcha.net recaptcha.net https://www.google.com https://www.googletagmanager.com https://js.stripe.com https://player.vimeo.com *.auth0.com vercel.live; frame-ancestors 'none'; 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googletagmanager.com *.onetrust.com assets.adobedtm.com script.hotjar.com *.googleapis.com; script-src-elem 'self' 'unsafe-inline' *.hotjar.com assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com static.hotjar.com *.googletagmanager.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' *.googleapis.com; style-src-elem 'self' 'unsafe-inline' cdn.honey.io *.googleapis.com *.googletagmanager.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' data: mdm-assets.integration.costacoffee.com *.demdex.net *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com *.onetrust.com cm.everesttech.net *.googleapis.com; font-src 'self' *.gstatic.com; connect-src 'self' web.costa-loyalty-platform.com ws://ws27.hotjar.com *.hotjar.com *.hotjar.io *.onetrust.com *.go-mpulse.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net costalimited.tt.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com *.techlab-cdn.com login.costa.co.uk *.google-analytics.com wss://ws.hotjar.com; frame-ancestors 'self'; frame-src costalimited.demdex.net *.hotjar.com; report-uri https://costa.report-uri.com/r/t/csp/reportonly; report-to default 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.flybreeze.com https://googleads.g.doubleclick.net https://connect.facebook.net https://growthbook-production.flybreeze.com https://dx.mountain.com https://gs.mountain.com https://px.mountain.com https://www.googletagmanager.com https://cdn.gladly.com https://pixel.mathtag.com https://js.adsrvr.org https://cdn.uplift-platform.com https://tag.uplift.com https://cdn.uplift.com https://analytics.tiktok.com https://script.hotjar.com https://static.hotjar.com https://bat.bing.com https://pixel.byspotify.com https://s.pinimg.com https://ct.pinterest.com https://cdnjs.cloudflare.com https://www.gstatic.com https://ads.nextdoor.com https://www.redditstatic.com https://app.termly.io https://script.gethovr.com https://www.securitytrfx.com https://socialladder.rkiapps.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://www.gstatic.com; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com; connect-src 'self' https://*.flybreeze.com https://*.nr-data.net https://www.googletagmanager.com https://www.redditstatic.com https://cdn.gladly.com https://flybreeze.gladly.com https://socialladder.rkiapps.com; img-src 'self' https://*.flybreeze.com https://googleads.g.doubleclick.net https://connect.facebook.net https://www.gstatic.com https://cdn.gladly.com https://flybreeze.gladly.com https://www.redditstatic.com https://s.pinimg.com https://pixel.mathtag.com https://analytics.tiktok.com https://bat.bing.com https://pixel.byspotify.com https://ct.pinterest.com https://script.hotjar.com https://static.hotjar.com https://www.securitytrfx.com; object-src 'none'; media-src 'self'; frame-src 'self' https://*.flybreeze.com https://www.googletagmanager.com https://www.redditstatic.com https://www.securitytrfx.com; frame-ancestors 'self' https://go.flybreeze.dev https://crewapp-staging.flybreeze.team https://clerk.docs.flybreeze.dev https://docs.flybreeze.dev https://flight-info.flybreeze.team; manifest-src 'self'; report-uri https://csp-flybreeze.domdog.io/report-uri/flybreeze.com/1/1-4; report-to csp-endpoint; 1 report-uri https://endpoint2.collection.us2.sumologic.com/receiver/v1/http/ZaVnC4dhaV3VOE24ov0vchYgO3uoxKHdePxnKoFiICkeq1Vt2reRBEg4zYmpS2XL1UJS-0Ova9gUiV2PUH3EvuXcIOdrBPvAUgkIP-ZRbRMryNUY6YGqAQ== ; block-all-mixed-content ; default-src 'report-sample' 'self' https://*.videoask.com https://*.videoask.live ; script-src 'report-sample' 'self' 'unsafe-eval' https://*.videoask.com https://*.videoask.live 'unsafe-inline' https://js.stripe.com https://www.dropbox.com https://*.calendly.com https://*.oncehub.com https://cdn.amplitude.com https://cdn.cookielaw.org https://cdn.rollbar.com https://cdn.segment.com https://connect.facebook.net https://fast.wistia.com https://script.crazyegg.com https://snap.licdn.com https://snippet.growsumo.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com https://cdn.optimizely.com https://js.partnerstack.com https://edge.fullstory.com https://a.quora.com https://static.ads-twitter.com https://analytics.tiktok.com https://tags.srv.stackadapt.com ; base-uri 'report-sample' 'self' ; img-src 'report-sample' 'self' data: blob: android-webview-video-poster: https: ; media-src 'report-sample' 'self' blob: data: https: ; connect-src 'report-sample' 'self' blob: https://*.videoask.com https://*.videoask.live wss://*.videoask.live wss://*.videoask.com https://videoask-media-dev.s3-accelerate.amazonaws.com https://videoask-media-prod.s3-accelerate.amazonaws.com https://videoask-uploads-dev.s3-accelerate.amazonaws.com https://videoask-uploads-prod.s3-accelerate.amazonaws.com https://videoask-uploads-dev.s3.amazonaws.com https://videoask-uploads-prod.s3.amazonaws.com https://videoask.eu.auth0.com https://dev-videoask.eu.auth0.com https://*.launchdarkly.com https://*.pexels.com https://*.wistia.com https://embedwistia-a.akamaihd.net https://api.rollbar.com https://api.segment.io https://api.amplitude.com https://*.g.doubleclick.net https://www.google-analytics.com https://*.crazyegg.com https://p.adsymptotic.com https://www.facebook.com https://track.segmetrics.io https://*.google.com https://rs.fullstory.com https://cdn.segment.com https://edge.fullstory.com https://js.partnerstack.com https://grsm.io https://cdn.cookielaw.org https://*.onetrust.com https://*.contentful.com https://videoask.zendesk.com https://*.optimizely.com https://region1.google-analytics.com https://analytics.tiktok.com https://partnerlinks.io ; style-src 'report-sample' 'self' https://font.typeform.com 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://cdn.cookielaw.org https://cdn.quilljs.com ; font-src 'report-sample' 'self' data: https://font.typeform.com https://fonts.gstatic.com ; frame-src 'report-sample' 'self' https://*.videoask.com https://*.videoask.live https://calendly.com https://app.acuityscheduling.com https://*.oncehub.com https://js.stripe.com https://videoask.eu.auth0.com https://dev-videoask.eu.auth0.com https://*.wistia.com https://www.facebook.com https://*.doubleclick.net https://6g4qf7txd07m.statuspage.io https://*.optimizely.com ; frame-ancestors * ; object-src 'none' ; 1 default-src 'self'; script-src 'self' 'unsafe-eval'; connect-src 'self'; img-src 'self' data: www.pkobp.pl; style-src 'self' 'unsafe-inline'; font-src 'self'; report-uri /ikd_img/skins/ipko/grcv; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://connect.facebook.net https://*.stripe.com https://*.braintreegateway.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.youtube.com https://s.ytimg.com https://*.weeecdn.com https://*.weeecdn.net https://*.tiktok.com https://*.clarity.ms https://*.cloudfront.net https://*.awswaf.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.weeecdn.com https://*.weeecdn.net; img-src 'self' data: blob: https://*.weeecdn.com https://*.weeecdn.net https://weee.pics https://*.masgusto.net https://*.google-analytics.com https://*.doubleclick.net https://*.facebook.com https://*.stripe.com https://*.youtube.com https://*.ytimg.com https://cdn.cookielaw.org https://*.anycart.com https://*.sayweee.com https://*.sayweee.net https://static.weeecdn.com https://static.weeecdn.net; font-src 'self' data: https://fonts.gstatic.com https://*.weeecdn.com https://*.weeecdn.net; connect-src 'self' wss://*.sayweee.com https://*.sayweee.com wss://*.sayweee.net https://*.sayweee.net wss://*.masgusto.com https://*.masgusto.com wss://*.masgusto.net https://*.masgusto.net https://*.google-analytics.com https://*.google.com https://region1.google-analytics.com https://*.facebook.com https://*.stripe.com https://*.braintreegateway.com https://*.onetrust.com https://*.googleapis.com https://*.gstatic.com https://*.tiktok.com https://*.weeecdn.com https://*.weeecdn.net https://cdn.cookielaw.org https://*.cloudflare.com https://*.awswaf.com https://*.clarity.ms https://*.sayweee.com https://*.sayweee.net https://www.sayweee.com https://click.sayweee.com; media-src 'self' https://*.sayweeecdn.com https://*.youtube.com https://*.tiktok.com; object-src 'none'; frame-src https://*.stripe.com https://hooks.stripe.com https://assets.braintreegateway.com https://*.youtube.com https://*.google.com https://*.facebook.com https://*.tiktok.com https://cdn.cookielaw.org; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; worker-src 'self' blob:; manifest-src 'self'; upgrade-insecure-requests; report-uri https://api.sayweee.net/ec/bff/report/csp-violation; report-to csp-endpoint 1 font-src traxxas.com fonts.googleapis.com fonts.gstatic.com cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * traxxas.com fonts.gstatic.com zonos.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com traxxas.com assurance.sysnetgs.com i1.createsend1.com i2.createsend1.com i3.createsend1.com i4.createsend1.com i5.createsend1.com i6.createsend1.com i7.createsend1.com i8.createsend1.com i9.createsend1.com i10.createsend1.com fonts.gstatic.com hn.inspectlet.com hello.zonos.com connect.facebook.net www.facebook.com facebook.com https://maps.googleapis.com https://maps.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com traxxas.com support.traxxas.com assurance.sysnetgs.com cdn.inspectlet.com fonts.gstatic.com s7.addthis.com zonos.com cdn.jsdelivr.net route.elements.zonos.com js-agent.newrelic.com connect.facebook.net https://maps.googleapis.com https://maps.gstatic.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com traxxas.com fonts.googleapis.com fonts.gstatic.com zonos.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com thm.visa.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com traxxas.com fonts.gstatic.com hn.inspectlet.com wss://ws.inspectlet.com zonos.com hello.zonos.com cdn.jsdelivr.net route.elements.zonos.com js-agent.newrelic.com connect.facebook.net cdn.inspectlet.com assurance.sysnetgs.com https://maps.googleapis.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.bing.com *.bing.net *.abtasty.com *.alicdn.com *.bootstrapcdn.com *.cdnfonts.com *.fontawesome.com *.googleusercontent.com *.slant.co zip-co-media.s3.ap-southeast-2.amazonaws.com *.zip.co *.qantas.com unpkg.com *.cloudflare.com *.totaltools.com.au *.afterpay.com *.zipmoney.com.au *.zohocdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.googletagmanager.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com magefan.com cm.magefan.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com *.abtasty.com *.adroll.com *.adsrvr.org *.bing.com *.clarity.ms *.googleusercontent.com *.online-metrix.net *.openstreetmap.org *.quantcount.com *.quantserve.com *.signifyd.com *.unbxdapi.com *.zip.co *.afterpay.com *.tapad.com *.rubiconproject.com x.bidswitch.net pixel.tapad.com *.rlcdn.com *.openx.net *.yahoo.com *.pubmatic.com s3.amazonaws.com *.casalemedia.com *.adnxs.com *.amazon-adsystem.com *.stackadapt.com *.spotify.com *.sharethis.com *.bluekai.com *.contextweb.com *.kargo.com *.twitter.com *.addthis.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.tn www.google.to www.google.tt www.google.vu www.google.ws link.totaltools.com.au render.barcodes.systems *.bing.net www.google.ad www.google.as www.google.co.mz www.google.com.cu www.google.com.vn www.google.cv www.google.dj www.google.ga www.google.gl www.google.gm www.google.ht www.google.sh www.google.td zip.co *.microsofttranslator.com *.totaltools.com.au 127.0.0.1 www.google.cf www.google.com.af www.google.com.gi www.google.com.ng www.google.com.ni www.google.com.tj www.google.dm www.google.fm www.google.gg *.baidu.com *.crwdcntrl.net *.google-analytics.com *.googleadservices.com *.jquery.com *.linksynergy.com *.paypalobjects.com *.scorecardresearch.com *.ytimg.com google.com www.google.nu *.alicdn.com *.imgur.com www.google.bi www.google.li www.google.ne www.google.pn www.google.sm www.google.st www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.plugins.emarsys.net *.scarabresearch.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com https://platform.cloud.coveo.com https://api.cloud.coveo.com https://search.cloud.coveo.com cdn-4.convertexperiments.com *.33across.com *.abtasty.com *.addthis.com *.adroll.com *.adsrvr.org *.bing.com *.clarity.ms d21gpk1vhmjuf5.cloudfront.net d3mewz86hy02zo.cloudfront.net *.emarsys.net *.online-metrix.net *.pricespider.com *.quantcount.com *.quantserve.com *.signifyd.com *.wufoo.com *.zip.co *.zdassets.com nexuspublications.com.au *.jsdelivr.net https://unpkg.com *.cloudflare.com *.microsofttranslator.com *.totaltools.com.au 127.0.0.1 googletagmanager.com unpkg.com *.fullstory.com *.googleadservices.com *.hotjar.com *.zipmoney.com.au sc-static.net rum.hlx.page translate.google.cn nominatim.openstreetmap.org api.smooch.io *.smooch.io https://hosted.mastersoftgroup.com/harmony/rest/v2/address/find https://hosted.mastersoftgroup.com/harmony/rest/au/generateID www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.abtasty.com *.fontawesome.com *.typekit.net *.zip.co *.bing.com https://unpkg.com unpkg.com *.totaltools.com.au 127.0.0.1 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com *.zdassets.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.scarabresearch.com *.eservice.emarsys.net connect.facebook.net graph.facebook.com business.facebook.com https://platform.cloud.coveo.com https://api.cloud.coveo.com https://search.cloud.coveo.com *.abtasty.com *.addthis.com *.adroll.com *.adsrvr.org *.amplitude.com *.bing.com *.bing.net *.clarity.ms *.doubleclick.net *.emarsys.net *.gstatic.com *.pricespider.com *.quantcount.com *.quantserve.com *.samsung.com *.typekit.net *.unbxd.io *.zipmoney.com.au *.zip.co d21gpk1vhmjuf5.cloudfront.net d3mewz86hy02zo.cloudfront.net *.mastersoftgroup.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bj www.google.bs www.google.bt www.google.ca www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zm www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.mm www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.it www.google.jo www.google.kg www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.tl www.google.to www.google.tt www.google.vu *.zdassets.com nominatim.openstreetmap.org www.google.bf www.google.by www.google.cd www.google.cm www.google.co.ao www.google.co.bw www.google.co.ls www.google.co.mz www.google.co.vi www.google.co.zw www.google.com.ag www.google.com.bh www.google.com.bz www.google.com.cu www.google.com.do www.google.com.lb www.google.com.mt www.google.com.sl www.google.com.vc www.google.dj www.google.dz www.google.gm www.google.hn www.google.ki www.google.kz www.google.la www.google.sh www.google.sk www.google.sr www.google.tg www.google.ws zip.co 127.0.0.1 www.google.ad www.google.com.ng www.google.com.tj www.google.ga www.google.is www.google.ml www.google.rw www.google.sc www.google.sn www.google.so www.google.tn *.alicdn.com *.googleadservices.com *.hotjar.com *.jquery.com www.google.as www.google.co.uz www.google.com.af www.google.com.ly www.google.com.ni www.google.com.py www.google.dm www.google.ht www.google.je www.google.nu www.google.ps *.openstreetmap.org *.signifyd.com *.totaltools.com.au rum.hlx.page www.google.bi www.google.fm www.google.gg www.google.li www.google.ne www.google.sm www.google.td totaltoolsnonproduction1b9a600cn.org.coveo.com totaltoolsproduction1tptz1hbe.org.coveo.com totaltoolsnonproduction1b9a600cn.analytics.org.coveo.com totaltoolsproduction1tptz1hbe.analytics.org.coveo.com platform-au.cloud.coveo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.adroll.com *.clarity.ms *.doubleclick.net *.google.com 'self' 'unsafe-inline'; report-uri https://f4c824ea-9c0b-4131-a2e2-886e99df7154.sansec.watch/; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' tags.tiqcdn.com tags.tiqcdn.cn collect.tealiumiq.com *.criteo.com *.criteo.net *.omtrdc.net *.yimg.jp *.yahoo.co.jp prf.hn *.doubleclick.net *.line.me *.google.com *.google.it *.bing.com *.google-analytics.com *.licdn.com *.tiktok.com sc-static.net *.usehero.com *.contentsquare.net *.demdex.net *.facebook.com *.googletagmanager.com *.facebook.net *.googleadservices.com *.teads.tv zegna.d3.sc.omtrdc.net www.google.* *.zegna.com *.measmerize.com *.googlesyndication.com maps.gstatic.com *.riskified.com sandbox.gestpay.net ecomm.sella.it *.online-metrix.net amp.akamaized.net *.snapchat.com *.gstatic.com *.go-mpulse.net cm.everesttech.net *.googleapis.com *.akstat.io *.akamaihd.net *.line-scdn.net *.algolianet.com *.algolia.net *.algolia.com zegna-cloud-media.s3.amazonaws.com zegna-cloud-media.s3.eu-west-1.amazonaws.com zegna-cloud-media.s3-eu-west-1.amazonaws.com livechat.zegna.cn *.baidu.com blob: data: ; font-src 'self' data: *.googleapis.com *.gstatic.com; report-uri /cgi-bin/csp_report.cgi 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://static.hotjar.com https://script.hotjar.com https://js.adsrvr.org https://connect.facebook.net https://siteimproveanalytics.com https://static.ads-twitter.com https://cdn.taboola.com https://trc.taboola.com https://psb.taboola.com https://snap.licdn.com https://munchkin.marketo.net https://widget.tagembed.com https://cdn.tagembed.com https://cdn.theaccessplatform.com https://code.jquery.com https://platform.twitter.com https://www.youtube.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://cdn.tagembed.com https://widget.tagembed.com https://cdn.theaccessplatform.com;object-src 'none';base-uri 'self';connect-src 'self' https://delivery-cqucontenthub.stylelabs.cloud https://fb.cqu.edu.au https://www-search.cqu.edu.au https://dxp-au-search.funnelback.squiz.cloud https://www.google-analytics.com https://analytics.google.com https://www.google.com.au https://google.com https://www.googletagmanager.com https://www.google.com https://adservice.google.com https://stats.g.doubleclick.net https://px.ads.linkedin.com https://pips.taboola.com https://cds.taboola.com https://622-hhc-246.mktoresp.com https://622-hhc-246.mktoutil.com https://www.facebook.com https://trc-events.taboola.com https://s3.us-west-1.wasabisys.com wss://ws.hotjar.com https://content.hotjar.io https://vc.hotjar.io https://psb.taboola.com https://api.theaccessplatform.com https://munchkin.marketo.net https://api.intentiq.com https://cdn.taboola.com https://region1.analytics.google.com https://widget.tagembed.com https://metrics.hotjar.io https://web.tagembed.com https://analytics.cqu.edu.au https://insight.adsrvr.org https://www.googleadservices.com;font-src 'self' data https://fonts.gstatic.com https://use.typekit.net https://cdn.theaccessplatform.com https://cdn.tagembed.com;frame-src 'self' https://www.googletagmanager.com https://insight.adsrvr.org https://9389440.fls.doubleclick.net https://www.youtube.com https://td.doubleclick.net https://www.facebook.com https://platform.twitter.com https://match.adsrvr.org https://tsdtocl.com https://player.vimeo.com https://eap.ascentone.com;img-src 'self' https://staff-profiles.cqu.edu.au https://delivery-cqucontenthub.stylelabs.cloud https://www.google-analytics.com https://www.google.com.au https://www.google.com https://www.googletagmanager.com https://www.google.com.co https://www.google.com.pe https://www.google.com.bd https://www.google.co.in https://www.google.com.ng https://www.google.com.np https://www.google.lk https://www.google.co.uk https://www.google.com.sg https://googleads.g.doubleclick.net https://www.googleadservices.com https://analytics.twitter.com https://px.ads.linkedin.com https://www.facebook.com https://78858.global.siteimproveanalytics.io https://t.co https://www.linkedin.com https://i.ytimg.com https://aumejtoqen.cloudimg.io https://ui-avatars.com https://fs.theambassadorplatform.com https://sync.intentiq.com https://cdn.taboola.com https://media.tagembed.com https://au-gmtdmp.mookie1.com https://secure.adnxs.com https://analytics.google.com https://i.vimeocdn.com https://stats.g.doubleclick.net https://connect.facebook.net;manifest-src 'self';media-src 'self' https://delivery-cqucontenthub.stylelabs.cloud;worker-src 'none';report-uri https://wwwcqu.report-uri.com/r/d/csp/reportOnly; 1 default-src *.facebook.com *.fbcdn.net *.instagram.com blob:;script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-IfmfDcdY' blob: 'self' 'wasm-unsafe-eval' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com;style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self';font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com *.tenor.co *.tenor.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com cdn.fbsbx.com lookaside.fbsbx.com data: blob: https://*.giphy.com *.tenor.co *.tenor.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data:;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;upgrade-insecure-requests;report-uri https://www.facebook.com/csp/reporting/?minimize=0; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.vercel.app *.uxuy.one *.uxuy.com *.uxuy.me www.googletagmanager.com; worker-src blob: 'self' *.vercel.app *.uxuy.one *.uxuy.com; object-src 'none'; 1 default-src * 'self' data: blob: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' cactusvpn.com www.cactusvpn.com billing.cactusvpn.com; report-uri https://75943a29954faa0d1b365a52c248c905.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self'; connect-src 'self' https://*.segment.io https://*.segment.com https://k.clarity.ms https://px.ads.linkedin.com https://806-qbe-674.mktoresp.com https://consent.trustarc.com https://www.google.com https://www.google-analytics.com https://analytics.google.com https://www2.profitwell.com https://fast.wistia.com https://*.wistia.com https://pipedream.wistia.com https://services.postcodeanywhere.co.uk/Capture/Interactive/ https://taxjar.netlify.app https://yoast.com; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://consent.trustarc.com https://fast.wistia.com; frame-src 'self' https://*.taxjar.com https://www.googletagmanager.com https://clarity.microsoft.com; img-src 'self' https://*.ads.linkedin.com https://www.facebook.com https://consent.trustarc.com https://www.google.com/pagead/1p-user-list/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/975686394/ https://bat.bing.com https://embed-ssl.wistia.com/deliveries/ https://fast.wistia.com/assets/images/ https://www.googletagmanager.com https://secure.gravatar.com; script-src 'self' 'unsafe-inline' https://*.segment.com https://*.clarity.ms https://public.profitwell.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://www.googletagmanager.com https://snap.licdn.com https://munchkin.marketo.net https://go.taxjar.com https://my.hellobar.com https://static.hotjar.com https://connect.facebook.net https://script.hotjar.com https://bat.bing.com https://*.cloudfront.net/js/profitwell.js https://consent.trustarc.com https://www.google-analytics.com https://fast.wistia.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/975686394/ https://api.addressy.com/js/ https://cdnjs.cloudflare.com https://code.jquery.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://go.taxjar.com; 1 object-src * ; report-uri https://www.sunlife.ca/slfreporting/reportUri 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-web.zinio.com https://js-agent.newrelic.com https://*.nr-data.net https://www.googleadservices.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.paypal.com https://www.paypalobjects.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.googletagmanager.com https://www.google-analytics.com https://d1fc8wv8zag5ca.cloudfront.net/2.10.2/sp.js https://cdn.jsdelivr.net https://recaptcha.net https://www.gstatic.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.sleeknote.com;style-src 'self' 'unsafe-inline' https://*.audiencemedia.com data:;img-src 'self' data: blob: https://*.ziniopro.com https://*.audiencemedia.com https://googleads.g.doubleclick.net https://www.google.com https://*.paypal.com https://*.braintreegateway.com https://discover.zinio.com https://sleeknotestaticcontent.sleeknote.com https://analytics.sleeknote.com https://www.google-analytics.com https://www.googletagmanager.com;media-src 'self';connect-src 'self' https://*.audiencemedia.com https://*.ziniopro.com https://*.nr-data.net https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.jsdelivr.net https://*.braintree-api.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.paypal.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://collector.datacloud.zinio.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://images.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://sleeknotecustomerscripts.sleeknote.com;font-src 'self' https://*.audiencemedia.com https://fonts.gstatic.com https://sleeknotestaticcontent.sleeknote.com;frame-src 'self' https://td.doubleclick.net https://*.paypal.com https://*.braintreegateway.com https://recaptcha.net https://*.sleeknote.com;frame-ancestors none 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https://www.gpb.org https://ping.chartbeat.net https://tpc.googlesyndication.com https://googleads.g.doubleclick.net https://www.google.com https://ep1.adtrafficquality.google https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://*.pbs.org https://*.cdn.pbs.org https://image.isu.pub https://www.googletagmanager.com https://ads.adventive.com https://assets.adventivecdn.com https://cdn.wisepops.com data:; media-src 'self' https: http://cpa.ds.npr.org; font-src 'self' https://www.gpb.org https://fonts.gstatic.com data:; connect-src 'self' https://ping.chartbeat.net https://www.googletagmanager.com https://googleads.g.doubleclick.net https://script.crazyegg.com https://securepubads.g.doubleclick.net https://www.google.com https://*.googlesyndication.com https://wisepops.net https://*.wisepops.net https://www.google-analytics.com https://activity.wisepops.com https://ep1.adtrafficquality.google https://www.googleadservices.com https://onesignal.com https://*.crazyegg.com https://*.ingest.sentry.io https://bam.nr-data.net https://csi.gstatic.com https://tracking.wisepops.com; worker-src 'self' blob: https://script.crazyegg.com ; report-uri /report-csp-violation 1 report-to slardar-endpoint; script-src 'unsafe-eval' 'report-sample' 'nonce-bf1a45c336ed63119080f2a14e3c0769-argus' 'strict-dynamic'; 1 font-src fonts.gstatic.com use.typekit.net https://cdn.checkout.com *.bglobale.com *.global-e.com *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.bglobale.com *.global-e.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.youtube.com/ *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.afd.co.uk *.brsrvr.com *.bloomreach.cloud sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.google.com *.afd.co.uk cdn.brcdn.com https://*.checkout.com *.klarnacdn.net *.online-metrix.net testflex.cybersource.com flex.cybersource.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://cdn.checkout.com *.bglobale.com *.global-e.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afd.co.uk *.dxpapi.com https://js.checkout.com *.klarnaevt.com thm.visa.com *.klarnacdn.net *.klarna.com *.klarnaservices.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klarnauserservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org experiments-api.fabric-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' blob: https://challenges.cloudflare.com https://vod-progressive-ak.vimeocdn.com https://cdn.simplecast.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://apps.sitecore.net https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com https://code.jquery.com http://ajax.googleapis.com https://maps.googleapis.com https://geoip-js.com https://www.google-analytics.com https://cdn.siteimprove.net https://player.simplecast.com https://cdnjs.cloudflare.com https://my2.siteimprove.com https://id.siteimprove.com https://unpkg.com https://platform-api.sharethis.com https://l.sharethis.com/ https://player.vimeo.com https://extend.vimeocdn.com https://vod-progressive.akamaized.net https://download-video.akamaized.net https://cdn.yoshki.com https://download-video-ak.vimeocdn.com 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://61281927.global.siteimproveanalytics.io/ https://cdn.yoshki.com https://61281927.global.siteimproveanalytics.io/; style-src 'self' https://fonts.googleapis.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net https://unpkg.com 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com 'unsafe-inline'; block-all-mixed-content; script-src 'self' https://challenges.cloudflare.com https://cdn.cookielaw.org https://www.googletagmanager.com https://maps.googleapis.com https://js.maxmind.com https://cdnjs.cloudflare.com/polyfill/ https://siteimproveanalytics.com https://www.google-analytics.com https://platform-api.sharethis.com https://extend.vimeocdn.com https://cdn.siteimprove.net http://ajax.googleapis.com https://code.jquery.com https://cdn.jsdelivr.net https://unpkg.com https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' https://www.independentsector.org; report-uri https://233122823c47f119af0143cbea7853d6.report-uri.com/r/d/csp/reportOnly; 1 font-src *.klarnacdn.net *.fontawesome.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.braintreegateway.com *.typekit.net *.kaptcha.com *.creativecdn.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.magentocommerce.com *.facebook.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://api.clerk.io https://cdn.clerk.io *.klarnacdn.net *.klarnaservices.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.googletagmanager.com vmax.backend.verbolia.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://api.clerk.io https://cdn.clerk.io *.klarnacdn.net *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.typekit.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.slgnt.eu *.syteapi.com vmax.backend.verbolia.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' www.youtube.com vimeo.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://player.vimeo.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://cdnjs.cloudflare.com https://unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self' https://login.microsoftonline.com; frame-ancestors 'self' 1 default-src 'self' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; connect-src 'self' primericaonline.okta.com primericaonline-admin.okta.com login.primericaonline.com *.oktacdn.com *.mixpanel.com *.mapbox.com primericaonline.kerberos.okta.com primericaonline.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; style-src 'unsafe-inline' 'self' 'report-sample' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; frame-src 'self' primericaonline.okta.com primericaonline-admin.okta.com login.primericaonline.com login.okta.com *.vidyard.com com-okta-authenticator: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; img-src 'self' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io blob:; font-src 'self' primericaonline.okta.com login.primericaonline.com data: *.oktacdn.com fonts.gstatic.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; frame-ancestors 'self' https://mob.primericaonline.com https://*.primericaonline.com 1 connect-src analytics.tiktok.com *.google-analytics.com 'self' 'unsafe-inline' wss:;default-src 'self' 'unsafe-inline' wss:;form-action 'self' 'unsafe-inline' wss:;frame-src *.soundcloud.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;img-src *.siteimproveanalytics.io analytics.tiktok.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;object-src 'none';script-src *.googletagmanager.com siteimproveanalytics.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;style-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com 'self' 'unsafe-inline' wss: 1 frame-ancestors 'self'; report-uri /scapi/danskespil/security/csp/testreport; 1 default-src https: wss: 'unsafe-inline' 'unsafe-eval'; img-src https: data: blob:; worker-src blob: 'self'; font-src https: data: 'unsafe-inline' 'unsafe-eval'; media-src https: wss: blob: data: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'none' 1 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.oliverbonas.com *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com; 1 font-src *.cloudflare.com *.googleapis.com *.gstatic.com *.reviews.io *.slant.co *.solvemate.com *.klarnacdn.net *.media-amazon.com chat.digitalgenius.com data: 'self' 'unsafe-inline'; form-action * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src * 'self' 'unsafe-inline'; img-src *.holzkern.com *.accdn.dev *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.ggpht.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.kameleoon.com *.experimentation.dev *.luckyorange.com *.payments-amazon.com *.pinterest.com *.reviews.io *.solvemate.com *.tiktok.com *.twitter.com d10lpsik1i8c69.cloudfront.net t.co x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com id5-sync.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com a.twiago.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com sync.1rx.io sync.targeting.unrulymedia.com collector-45613.tvsquared.com public-prod-dspcookiematching.dmxleo.com aa.agkn.com *.reviews.co.uk *.paypalobjects.com *.media-amazon.com *.klarnacdn.net *.paypal.com safesly.com *.klarna.com *.klarnaevt.com dpm.demdex.net *.vimeocdn.com *.adyen.com www.google.ad www.google.ae www.google.al www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.so www.google.sr www.google.st www.google.td www.google.tg www.google.tm www.google.tn www.google.to www.google.tt www.google.vu www.google.ws data: 'self' 'unsafe-inline'; script-src *.holzkern.com *.accdn.dev *.addthis.com *.ads-twitter.com *.bing.com *.boxx.ai *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.cnd-motionmedia.de *.criteo.com *.doubleclick.net *.facebook.net *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.kameleoon.com *.kameleoon.eu *.experimentation.dev *.netcoresmartech.com *.payments-amazon.com *.pinimg.com *.pinterest.com *.reviews.io *.snapchat.com *.solvemate.com *.sovendus.com *.tiktok.com *.vimeo.com d10lpsik1i8c69.cloudfront.net sc-static.net js.klarna.com collector-45613.tvsquared.com *.reviews.co.uk *.newrelic.com *.nr-data.net *.paypal.com *.stripe.com *.qstatic.com *.braintreegateway.com *.klarna.com *.klarnacdn.net *.gstatic.com *.cdn-apple.com *.cardinalcommerce.com *.paypalobjects.com chat.digitalgenius.com *.dgdeepai.com *.klarnaservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.holzkern.com *.cloudflare.com *.googleapis.com *.googletagmanager.com *.kameleoon.com *.experimentation.dev *.reviews.io *.solvemate.com *.vimeocdn.com *.klarnacdn.net d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.bing.com *.google.com *.gstatic.com *.solvemate.com *.vimeocdn.com 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src * 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.solvemate.com *.vimeo.com 'self' 'unsafe-inline'; report-uri https://68687097-c7e3-4199-ac7f-b76294254f77.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' https://trusted-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://trusted-images.com; font-src 'self'; frame-src 'self' https://forms.office.com; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri https://your-reporting-endpoint.com/report-csp; 1 default-src 'self' *.acadiau.ca; img-src 'self' *.acadiau.ca *.index.digital *.sitescout.com *.gstatic.com *.bc0a.com *.fontawesome.com *.picsum.photos picsum.photos *.twimg.com *.facebook.com *.twitter.com *.google.ca *.google.com www.google-analytics.com wl-pixel.index.digital pixel.sitescout.com s3.amazonaws.com *.b0e8.com *.siteimproveanalytics.io; font-src 'self' *.fontawesome.com *.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.gstatic.com cdn.jsdelivr.net; style-src 'self' *.bootstrapcdn.com *.cloudflare.com *.jsdelivr.net *.fontawesome.com *.twimg.com *.twitter.com *.googleapis.com widget.alongside.com 'unsafe-inline'; script-src 'self' *.acadiau.ca *.google.com *.googleapis.com *.fontawesome.com acuityplatform.com *.jquery.com *.bootstrapcdn.com *.cloudflare.com *.jsdelivr.net *.facebook.net *.google-analytics.com *.technolutions.net *.twitter.com *.twimg.com widget.alongside.com *.instagram.com *.cloudflare.com e.issuu.com *.pixel.ad *.hotjar.com *.bc0a.com *.b0e8.com theta360.com *.tiktok.com *.googletagmanager.com siteimproveanalytics.com 'unsafe-inline'; connect-src 'self' *.hotjar.com *.doubleclick.net www.google-analytics.com *.doubleclick.com *.sitescout.com *.doubleclick.n ka-p.fontawesome.com; frame-src 'self' *.livestream.com *.hotjar.com *.youtube.com *.vimeo.com *.twitter.com *.issuu.com *.facebook.com *.instagram.com *.sitescout.com theta360.com; frame-ancestors 'self'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: play.google.com admin.google.com accounts.google.com www.google.com drive.google.com translate.google.com translate.googleapis.com www.edmonton.ca edmonton.ca data.edmonton.ca maps.edmonton.ca gis.edmonton.ca transforming.edmonton.ca webdocs.edmonton.ca portal-onecity.edmonton.ca coewebops.com www.youtube.com edmonton.box.com edmonton.app.box.com edmonton.box.com cdn01.boxcdn.net api.box.com public.boxcloud.com www.boxcdn.net www.boxcloud.com maps.googleapis.com fonts.googleapis.com www.googletagmanager.com cdn.ckeditor.com cdn.rawgit.com cdn.datatables.net cdn.siteimprove.net www.siteimprove.com my2.siteimprove.com identity.siteimprove.com cdnjs.cloudflare.com cdn.jsdelivr.net svc.webspellchecker.net momentjs.com connect.facebook.net www.facebook.net unpkg.com www.google-analytics.com *.youtube.com fonts.gstatic.com maps.gstatic.com www.gstatic.com maxcdn.bootstrapcdn.com www.pingdom.net siteimproveanalytics.com www.siteimproveanalytics.com script.crazyegg.com code.jquery.com pagestates-tracking.crazyegg.com tracking.crazyegg.com assets-tracking.crazyegg.com www.escribemeetings.com www.tfaforms.com api.recollect.net assets.ca.recollect.net recollect-images.global.ssl.fastly.net recollect.a.ssl.fastly.net prismjs.net prismjs.com cdn.curator.io api.curator.io curator-assets.b-cdn.net www.facebook.com www.youtube-nocookie.com www.escribemeetings.com www.ytimg.com media1.giphy.com wdi-prod.yellowdev.net www.datatables.net visionservicerequests.rehrigpacific.com cdn.honey.io player.vimeo.com walkinto.in pwm-image.trendmicro.com ajax.aspnetcdn.com calendar.google.com portal.edmonton.ca infird.com www.google.ca feedback.coewebops.com region1.google-analytics.com w.soundcloud.com stackpath.bootstrapcdn.com www.global.siteimproveanalytics.io public.tableau.com edmonton.maps.arcgis.com cdn-uicons.flaticon.com overbridgenet.com ka-p.fontawesome.com use.fontawesome.com kit.fontawesome.com 550744.global.siteimproveanalytics.io ajax.googleapis.com sheets.googleapis.com curatorio.s3.amazonaws.com assets.us.recollect.net pub-edmonton.escribemeetings.com sc-static.net i.ytimg.com api.privacy-protector-adblocker.com dl.boxcloud.com *.global.siteimproveanalytics.io cdn.toolszen.com 3001.scriptcdn.net www.slant.co cdn.megabonus.com api.mapbox.com; report-uri /report-csp-violation 1 upgrade-insecure-requests; frame-ancestors 'self' https://*.sensibull.com https://kite.zerodha.com; report-uri https://7eae552da389ebb083bedadbd9428ed2.report-uri.com/r/d/csp/reportOnly 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.rab.equipment magento2.docker *.intervieweb.it *.algolia.com *.cloudflare.com *.twitter.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.rentle.io *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com magento2.docker *.intervieweb.it *.rentle.io *.twitter.com *.google.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com *.hub-box.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * www.youtube.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.gstatic.com https://images.unsplash.com magento2.docker *.clarity.ms *.rab.equipment *.intervieweb.it *.rentle.io *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.com *.iesnare.com *.locally.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.google.co.uk *.paypal.com *.twitter.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cc-cdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua *.adobedtm.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://*.avln.me/t.js https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ magento2.docker *.rab.equipment *.rentle.io *.intervieweb.it *.klarnaservices.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.algolia.com *.algolia.io *.locally.com *.outtra.com *.cookiefirst.com *.iesnare.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googlesyndication.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com apis.google.com feather.rab.equipment gtm.rab.equipment gtm.mcstaging.rab.equipment *.polyfill-fastly.io polyfill-fastly.io *.clarity.ms *.wisepops.net wisepops.net *.wisepops.com wisepops.com *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cc-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.youtube.com player.vimeo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.rab.equipment magento2.docker *.intervieweb.it *.rentle.io *.algolia.com *.outtra.com *.locally.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.cookiefirst.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.storyblok.com cc-cdn.com unsafe-inline assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.intervieweb.it magento2.docker *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.com *.iesnare.com *.locally.com 'self' data: *.rab.equipment *.rentle.io *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.amazonaws.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://www.google-analytics.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ magento2.docker *.intervieweb.it *.rentle.io *.klarnaevt.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.io *.locally.com *.outtra.com wss://mpsnare.iesnare.com *.iesnare.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googlesyndication.com *.doubleclick.net *.cookiefirst.com *.clarity.ms *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.hub-box.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com cdn.plyr.io noembed.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com static.hsappstatic.net cdn2.hubspot.net no-cache.hubspot.com js.hscollectedforms.net js.hscta.net api.hubapi.com js.hs-analytics.net js.hsleadflows.net js.hsadspixel.net js.hubspotfeedback.com feedback.hubapi.com js.hs-banner.com www.googletagmanager.com www.google.com app.hubspot.com www.google-analytics.com snap.licdn.com js.hs-scripts.com tribl.io j.6sc.co static.oktopost.com ssl.google-analytics.com trk.techtarget.com www.clarity.ms js.qualified.com js.zi-scripts.com okt.to googleads.g.doubleclick.net w.clarity.ms tracking.g2crowd.com js.hsforms.com js.hsforms.net www.gstatic.com 516015.fs1.hubspotusercontent-na1.net 19820949.fs1.hubspotusercontent-na1.net play.hubspotvideo.com play.vidyard.com platform.twitter.com connect.facebook.net platform.linkedin.com s3-us-west-2.amazonaws.com js.driftt.com edge.marker.io www.brighttalk.com www.recaptcha.net www.gstatic.cn embed.typeform.com www.googleadservices.com code.jquery.com js.hubspot.com scripts.clarity.ms blob: report-uri https://5ccc-110-235-228-46.ngrok-free.app/csp-report; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.googlesyndication.com *.clarity.ms *.google.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.youtube-nocookie.com www.google.com consentcdn.cookiebot.com *.google.ro *.facebook.com *.weltpixel.com https://*.sameday.ro *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.tbicp.com imgsct.cookiebot.com *.google.ro *.clarity.ms *.bing.com https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org https://www.selfawb.ro https://firebasestorage.googleapis.com flagpedia.net t.themarketer.com cdn1.themarketer.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.tbicp.com consentcdn.cookiebot.com *.cookiebot.com *.google.ro *.clarity.ms *.aqurate.ai *.themarketer.com *.avada.io t.themarketer.com cdn1.themarketer.com https://*.sameday.ro *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.google.ro *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com t.themarketer.com cdn1.themarketer.com https://*.sameday.ro *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.google.ro *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com consentcdn.cookiebot.com *.googlesyndication.com *.clarity.ms *.google.com google.com *.facebook.com *.aqurate.ai *.themarketer.com https://ecommerce.fancourier.ro https://nominatim.openstreetmap.org https://api.fancourier.ro https://get.geojs.io *.avada.io www.gstatic.com t.themarketer.com cdn1.themarketer.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://251703a9-46ab-4e4f-ab25-1de6ee452399.sansec.watch/; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' chrome-extension: https://rusmeteo.net https://pos.gosuslugi.ru https://counter.rambler.ru https://st.top100.ru https://mc.yandex.ru https://stat.sputnik.ru 'unsafe-eval' https://ymuc63gdgz.ru 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://pos.gosuslugi.ru chrome-extension: https://mc.yandex.ru https://mc.yandex.com https://mc.yandex.md 'unsafe-eval' 'unsafe-inline' 'unsafe-inline' https://acestream.tv https://emet.live https://emet.news ms-appx-web: https://dl.metabar.ru; object-src 'self'; report-uri /cspreportonly; 1 report-uri /csp-violations; default-src 'self'; font-src * data:; img-src * blob: data:; object-src 'none'; media-src * blob: data:; form-action *; script-src 'self' https://*.kit.com https://*.convertkit.com https://*.stripe.com https://*.intercom.io 'strict-dynamic' 'report-sample' 'unsafe-eval' 'nonce-PlCjTS8YmZggFPoThfy3YQ=='; style-src 'self' https: 'unsafe-inline'; connect-src *; child-src * blob:; worker-src 'self' blob: 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io assets.traveljoy.com; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' *.visualwebsiteoptimizer.com app.vwo.com editor.unlayer.com; style-src 'self' https: 'unsafe-inline' *.visualwebsiteoptimizer.com app.vwo.com fonts.googleapis.com; base-uri 'self'; worker-src 'self' blob:; connect-src 'self' *.visualwebsiteoptimizer.com app.vwo.com fonts.googleapis.com assets.traveljoy.com bam.nr-data.net sandbox-assets.tjoy.io api.us.nylas.com maps.googleapis.com placehold.co hare-media-cdn.tripadvisor.com s3-dev.traveljoy.com s3-assets.traveljoy.com api.unlayer.com 'self' wss://nexus-websocket-a.intercom.io/ https://ekr.zdassets.com/ https://global.ketchcdn.com/ https://traveljoy.zendesk.com/ https://api-js.mixpanel.com/ https://bam.nr-data.net/ https://api-iam.intercom.io/ https://www.google-analytics.com/ https://api.smooch.io wss://api.smooch.io; frame-src js.stripe.com connect-js.stripe.com *.visualwebsiteoptimizer.com app.vwo.com cdn.plaid.com checkout.stripe.com *.youtube.com *.youtu.be *.recaptcha.net editor.unlayer.com htp.tokenex.com 1 frame-ancestors 'self' nearpod.com *.nearpod.com *.nearpod.us; report-uri https://nearpod.report-uri.com/r/t/csp/reportOnly 1 frame-src 'self' https://widget.mercuryo.io https://*.sumsub.com https://gwa.pgalta.com; report-uri 'https://sentry.walletbot.me/api/38/security/?sentry_key=544a92e441a24f17aa6b08e34e728ed2&sentry_environment=production'; report-to csp-endpoint; 1 default-src 'self'; script-src 'self' *.argenta.be *.googleapis.com *.adobedtm.com *.googletagmanager.com *.doubleclick.net *.adsrvr.org *.teads.tv *.facebook.net *.hotjar.com *.tiqcdn.com *.pingdom.net *.google.ie 'unsafe-inline' 'unsafe-eval' wasm-eval; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://agentaspaarbank.tt.omtrdc.net *.googleapis.com *.simargenta.be *.argenta.be *.teads.tv *.googlesyndication.com *.pingdom.net *.google.com; font-src 'self'; frame-src 'self' *.tst-argenta.be *.adsrvr.org *.teads.tv *.doubleclick.net *.googletagmanager.com; img-src 'self' *.argenta.be *.simargenta.be *.facebook.com *.google.be *.google.com *.google.ie *.teads.tv *.gstatic.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 default-src 'none'; connect-src 'self' https://*.mediaflow.com https://mfstatic.com https://matomo.malmo.se https://edge.api.brightcove.com https://manifest.prod.boltdns.net https://house-fastly-signed-eu-west-1-prod.brightcovecdn.com; font-src 'self' data: https://mfstatic.com; frame-src 'self' https://stadsatlas.malmo.se https://*.mediaflow.com https://www.youtube.com; img-src 'self' data: https://devenemang.malmo.se https://test-devenemang.malmo.se https://assets.malmo.se https://malmo.se https://metrics.brightcove.com https://*.prod.boltdns.net https://assets.mediaflowpro.com https://*.brightcovecdn.com https://*.inviewer.se https://i.ytimg.com; media-src 'self' https://*.brightcovecdn.com https://*.mediaflow.com blob:; script-src 'self' 'nonce-22096230-daed-11f0-be12-a9f92954fc96' https://matomo.malmo.se https://players.brightcove.net 'strict-dynamic' 'unsafe-eval'; script-src-elem 'self' 'nonce-22096230-daed-11f0-be12-a9f92954fc96' https://matomo.malmo.se https://www.google.com/recaptcha https://players.brightcove.net https://mfstatic.com https://www.youtube.com; style-src 'self' https://malmo.se https://mfstatic.com 'unsafe-inline' data:; 1 default-src 'self' ; img-src 'self' data: blob: https://*.sykesassets.co.uk https://*.bing.com https://www.google-analytics.com https://*.mapbox.com/ https://www.facebook.com https://*.google.co.jp https://*.google.com https://*.google.co.uk https://*.google.es https://*.google.ca https://*.google.de https://*.google.it https://*.google.fr https://*.google.com.au https://*.google.com.tw https://*.google.nl https://*.google.com.br https://*.google.com.tr https://*.google.be https://*.google.com.gr https://*.google.co.in https://*.google.com.mx https://*.google.dk https://*.google.com.ar https://*.google.ch https://*.google.cl https://*.google.at https://*.google.co.kr https://*.google.ie https://*.google.com.co https://*.google.pl https://*.google.pt https://*.google.bs https://*.google.is https://*.google.no https://*.google.gg https://*.google.com.pk https://t.co https://*.doubleclick.net https://*.yahoo.com https://ads.stickyadstv.com https://visitor.omnitagjs.com https://s3-p-ew1-product-pascal-target.s3-eu-west-1.amazonaws.com https://connect.facebook.net https://www.sykescottages.co.uk https://*.adalyser.com https://*.fls.doubleclick.net https://*.contentsquare.net https://simage2.pubmatic.com https://us-u.openx.net https://*.userzoom.com https://*.linkedin.com https://bam-cell.nr-data.net https://bam.nr-data.net https://*.clarity.ms https://*.googletagmanager.com https://id5-sync.com https://script.hotjar.com https://www.glassdoor.co.uk https://ssp-csync.smartadserver.com https://property-floor-plans-production.s3.eu-west-1.amazonaws.com https://tau.collect.igodigital.com https://cdn.cookielaw.org https://optanon.blob.core.windows.net/logos/static/ot_persistent_cookie.png https://analytics.twitter.com https://exchange.mediavine.com/usersync; font-src 'self' 'unsafe-inline' https://script.hotjar.com https://fonts.gstatic.com https://www.sykescottages.co.uk https://fonts.googleapis.com https://cdnjs.cloudflare.com; script-src 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://www.google-analytics.com https://www.googleadservices.com https://bat.bing.com https://connect.facebook.net https://static.ads-twitter.com https://*.contentsquare.net https://googleads.g.doubleclick.net https://analytics.twitter.com https://*.googleapis.com https://*.hotjar.com https://*.mapbox.com https://unpkg.com https://widget.trustpilot.com https://snap.licdn.com https://*.sykescottages.co.uk https://assistjs.skimresources.com https://www.googletagmanager.com https://geolocation.onetrust.com https://js-agent.newrelic.com https://bam-cell.nr-data.net https://tau.collect.igodigital.com https://d3js.org https://cdn.jsdelivr.net https://tags.creativecdn.com https://*.braintreegateway.com https://*.igodigital.com https://*.google.co.jp https://*.google.com https://*.google.co.uk https://*.google.es https://*.google.ca https://*.google.de https://*.google.it https://*.google.fr https://*.google.com.au https://*.google.com.tw https://*.google.nl https://*.google.com.br https://*.google.com.tr https://*.google.be https://*.google.com.gr https://*.google.co.in https://*.google.com.mx https://*.google.dk https://*.google.com.ar https://*.google.ch https://*.google.cl https://*.google.at https://*.google.co.kr https://*.google.ie https://*.google.com.co https://*.google.pl https://*.google.pt https://*.google.bs https://*.google.is https://*.google.no https://*.google.gg https://*.google.com.pk https://*.clarity.ms https://widget.eu.criteo.com https://*.userzoom.com https://cdnjs.cloudflare.com https://www.sykescottages.co.uk https://*.postcodeanywhere.co.uk https://apis.google.com; script-src-elem 'unsafe-inline' 'unsafe-eval' https://*.braintreegateway.com https://snap.licdn.com https://assistjs.skimresources.com https://www.googletagmanager.com https://static.criteo.net https://js-agent.newrelic.com https://sslwidget.criteo.com https://bam-cell.nr-data.net https://bam.nr-data.net https://unpkg.com https://*.hotjar.com https://*.contentsquare.net https://cdn.jsdelivr.net https://maps.googleapis.com https://*.mapbox.com https://www.google-analytics.com https://connect.facebook.net https://widget.trustpilot.com https://cdn.cookielaw.org https://platform.twitter.com/widgets.js https://*.sykescottages.co.uk https://*.collect.igodigital.com https://www.dwin1.com/3317.js https://*.onetrust.com https://www.googleadservices.com https://ajax.googleapis.com https://*.doubleclick.net https://bat.bing.com https://static.ads-twitter.com https://analytics.twitter.com https://*.clarity.ms https://cdnjs.cloudflare.com https://d3js.org/d3.v3.min.js https://widget.eu.criteo.com https://*.userzoom.com https://bam.nr-data.net/1/e799bb56f3; style-src 'self' 'unsafe-inline' https://*.mapbox.com https://unpkg.com https://fonts.googleapis.com/css https://code.jquery.com; frame-src 'unsafe-inline' https://*.fls.doubleclick.net https://apis.google.com https://www.facebook.com https://*.trustpilot.com https://bid.g.doubleclick.net https://www.googletagmanager.com https://assets.braintreegateway.com https://youtube.com https://www.youtube.com https://ams.creativecdn.com https://vars.hotjar.com; worker-src blob: https://*.sykescottages.co.uk; child-src blob: https://*.sykescottages.co.uk; connect-src https://cdn.cookielaw.org https://*.sykescottages.co.uk https://stats.g.doubleclick.net https://*.sykes.cloud/initWebchat https://*.twil.io/closechat https://www.google-analytics.com https://googleads.g.doubleclick.net https://privacyportal-eu.onetrust.com https://*.contentsquare.net https://c.contentsquare.net https://*.mapbox.com https://*.addthis.com https://bam-cell.nr-data.net https://bam.nr-data.net https://bam.nr-data.net/jserrors/1/e799bb56f3 https://www.facebook.com https://bat.bing.com https://*.hotjar.com wss://*.hotjar.com wss://tsock.us1.twilio.com/v3/wsconnect https://*.clarity.ms https://maps.googleapis.com https://geolocation.onetrust.com https://client-analytics.braintreegateway.com https://api.braintreegateway.com https://region1.google-analytics.com/g/collect https://pagead2.googlesyndication.com https://ams.creativecdn.com/tags/v2 https://*.hotjar.io https://*.google.co.jp https://*.google.com https://*.google.co.uk https://*.google.es https://*.google.ca https://*.google.de https://*.google.it https://*.google.fr https://*.google.com.au https://*.google.com.tw https://*.google.nl https://*.google.com.br https://*.google.com.tr https://*.google.be https://*.google.com.gr https://*.google.co.in https://*.google.com.mx https://*.google.dk https://*.google.com.ar https://*.google.ch https://*.google.cl https://*.google.at https://*.google.co.kr https://*.google.ie https://*.google.com.co https://*.google.pl https://*.google.pt https://*.google.bs https://*.google.is https://*.google.no https://*.google.gg https://*.google.com.pk; media-src https://promo-videos.sykesassets.co.uk https://s3-eu-west-1.amazonaws.com; report-uri https://sykescottages.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; img-src https: data:; report-uri https://www.milestonesys.com/csp/report 1 font-src *.google.com *.googletagmanager.com *.googleapis.com fonts.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.shop.pe shop.pe *.juicer.io *.cloudfront.net v2.zopim.com data: *.bootstrapcdn.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://media.fbot.me *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com www.facebook.com *.amazonaws.com *.juicer.io shop.pe *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe *.criteo.com assets.bounceexchange.com vars.hotjar.com www.facebook.com imgs.signifyd.com h.online-metrix.net vendor1.leasestation.com amc.demdex.net nsg.symantec.com *.paypalobjects.com www.paypalobjects.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.pinterest.com https://nl.fatquartershop.com https://widget.fbot.me *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net store.paradoxlabs.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe *.fatquartershop.com pixel.voltn.com v2.zopim.com www.google.co.in *.pinterest.com www.facebook.com *.cdnwidget.com u.cdnwidget.com bat.bing.com nsg.symantec.com events.bouncex.net pippio.com p.brsrvr.com connect.facebook.net imgs.signifyd.com events.cdnwidget.com api.bounceexchange.com amc.demdex.net *.e.aa.online-metrix.net match.adsrvr.org yotpo-editor-production.s3.amazonaws.com *.cdninstagram.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.clarity.ms *.rqtrk.eu *.dynamicyield.com https://chat-assets.cdn.gladly.com https://chat-assets.cdn.gladly.qa maps.gstatic.com *.facebook.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://cnstrc.com/js/cust/fat-quarter-shop_Orxy5R.js www.google.com *.googletagmanager.com *.googleapis.com www.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com addshoppers.s3.amazonaws.com *.juicer.io *.traversedlp.com *.pinimg.com v2.zopim.com *.shop.pe shop.pe *.criteo.net *.criteo.com *.zdassets.com/ loader.wisepops.com *.cloudfront.net fatquartershop-com-dev.ecomm-nav.com connect.facebook.net vendor1.quickspark.com nsg.symantec.com script.crazyegg.com bat.bing.com tag.bounceexchange.com assets.bounceexchange.com cdn.brcdn.com imgs.signifyd.com cdns.brsrvr.com bam.nr-data.net js-agent.newrelic.com mc.s10.exacttarget.com *.hotjar.com bam-cell.nr-data.net *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.staticw2.yotpo.com https://nl.fatquartershop.com *.rqtrk.eu *.clarity.ms https://static.fbot.me https://campaign.fbot.me *.dynamicyield.com *.zendesk.com https://cnstrc.com https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/js/swiper.js https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://cdnjs.cloudflare.com https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa d2mjzob2nc713b.cloudfront.net fatquartershop.cdn1.safeopt.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.google.com *.googletagmanager.com fonts.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe events.bouncex.net stats.g.doubleclick.net www.google-analytics.com *.cloudfront.net *.addshoppers.com *.bootstrapcdn.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.staticw2.yotpo.com *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com tagmanager.google.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'unsafe-inline' data: 'unsafe-inline' blob: *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.dynamicyield.com *.zdassets.com/ https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com bat.bing.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe ekr.zdassets.com script.crazyegg.com *.pinterest.com stats.g.doubleclick.net wss: manager.eu.smartlook.cloud in.hotjar.com staging-core.dxpapi.com core.dxpapi.com imgs.signifyd.com bt.signifyd.com:11103 data.cdnbasket.net ids.cdnwidget.com pd.cdnwidget.com page.cdnbasket.net/ view.cdnbasket.net bam.nr-data.net vc.hotjar.io bam-cell.nr-data.net api.traversedlp.com *.paypal.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.clarity.ms https://public.fbot.me *.dynamicyield.com *.zendesk.com zendesk-eu.my.sentry.io *.cnstrc.com https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/js/swiper.js https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://api.us-1.gladly.chat wss://ws.us-1.gladly.chat https://chat-assets.cdn.gladly.com https://chat-sdk.cdn.gladly.com https://api.us-uat.gladly.chat wss://ws.us-uat.gladly.chat https://chat-assets.cdn.gladly.qa https://chat-sdk.cdn.gladly.qa webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net *.google-analytics.com *.facebook.net dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.de *.betano.de betgenius.com *.betgenius.com bing.com *.bing.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery clarity.ms *.clarity.ms lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=8PjNWSrDDU8tB.j2.RTq2ExVT6KJecjafQVgUEKc1FA-1765938067-1.0.1.1-bMeJ_RqGM1tVSenaxepSz3t4k6.4M0Huvw70XVxdrlr0af9dfXYl_92SL0nXRGgLEVupbA_tAuXMaknugyK0iCVsa7fwHMMRn3v13IVVfgNjeH_OXNuDlwIxF_sBkyX8wAz4tNtdNO8FLNIqjYP.cpkfsAwphugbWmc8OzXj8lv2wgErzyHg176FZ9OXgJjBJk6SH6BlLW_FfY9vTErVDg; report-to cf-uftfucvrasuiftxt 1 object-src 'none'; style-src * 'unsafe-inline' 'self' data:; img-src * blob: data: 'self'; upgrade-insecure-requests; frame-src * 'self'; child-src * blob:; default-src *; form-action * 'self'; script-src * data: wasm-eval: 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample'; connect-src * 'self'; font-src * data: 'self'; worker-src * blob: 'self'; report-uri https://o166208.ingest.sentry.io/api/1238795/security/?sentry_key=eebe259ebaa846d39aaae0e3404505ab&sentry_environment=production 1 frame-ancestors 'self'; report-uri https://ordermygear.report-uri.com/r/t/csp/wizard 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-bscYkSIUjhEBbvERJ4ICQkvTYWj98aRt' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/; font-src 'self' kit.fontawesome.com https://ka-p.fontawesome.com/ https://fast.wistia.com/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob:; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.casepeer.com/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 font-src *.googleapis.com *.gstatic.com 'unsafe-inline' data: https://www.googletagmanager.com maxcdn.bootstrapcdn.com apps.mypurecloud.com use.typekit.net static.klaviyo.com *.silencershop.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.credova.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.credova.com * *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://www.youtube.com https://c.paypal.com/ https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.silencershop.com *.signifyd.com *.online-metrix.net/ data.adxcel-ec2.com engine.gettopple.com trkn.us *.cloudfront.net https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.credova.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.jsdelivr.net *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.silencershop.com apps.usw2.pure.cloud *.signifyd.com delivery.gettopple.com *.online-metrix.net d14jnfavjicsbe.cloudfront.net sleeknotecustomerscripts.sleeknote.com sleeknotestaticcontent.sleeknote.com sec.webeyez.com widget.trustpilot.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com apps.mypurecloud.com use.typekit.net p.typekit.net *.silencershop.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://www.google-analytics.com *.credova.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.silencershop.com *.signifyd.com invitejs.trustpilot.com send.webeyez.com sec.webeyez.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com principiaskin.com *.principiaskin.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.pinterest.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com *.addthis.com *.mercadolibre.com *.weltpixel.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.authorize.net *.google.com *.paypal.com *.freshchat.com *.pagseguro.uol.com.br *.doubleclick.net *.pinterest.com *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com google.com *.gstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com *.instagram.com *.magentocommerce.com *.ytimg.com s.ytimg.com *.pinterest.com *.googleadservices.com *.google.com *.google.com.br *.google.it *.google-analytics.com www.paypalobjects.com *.paypalobjects.com *.paypal.com www.paypal.com t.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ftcdn.com *.behance.com *.pagseguro.com/ *.apptrian.com *.mercadolivre.com *.yotpo.com *.adobedtm.com *.demdex.net *.everesttech.net assets.braintreegateway.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com c.paypal.com checkout.paypal.com https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br https://stc.pagseguro.uol.com.br https://sandbox.stc.pagseguro.uol.com.br *.doubleclick.net *.onesignal.com *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com https://principiacosmeticos.com/mtracking.gif https://www.google.com.ar/ads/ga-audiences https://www.google.com.ar/pagead/1p-user-list/700931334/ https://principiaskincare.com.br/mtracking.gif https://t.co/1/i/adsct *.facebook.com content.app-us1.com cdn.jsdelivr.net *.cloudfront.net *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.mlstatic.com www.facebook.com graph.facebook.com business.facebook.com www.apptrian.com *.freshchat.com *.google.com *.google-analytics.com *.facebook.com *.adobedtm.com *.authorize.net *.braintreegateway.com *.cardinalcommerce.com *.paypal.com www.paypal.com *.ytimg.com *.googleadservices.com *.paypalobjects.com www.paypalobjects.com *.vimeo.com www.youtube.com *.viacep.com.br *.apptrian.com *.polyfill.io *.cloudflare.com *.pagseguro.uol.com.br *.tiktok.com *.pinimg.com *.mercadopago.com *.doubleclick.net *.ccdc02.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io pay.google.com *.yotpo.com *.onesignal.com https://onesignal.com/api/v1/sync/980b27db-f331-407d-8b91-7ea1ff79c577/web *.principiacosmeticos.com https://principiacosmeticos.com/mtc.js *.k-analytix.com principiaskin.com *.principiaskin.com *.cloudflareinsights.com https://designestylelab.com/css/ https://analytics-manager.com/an https://analytics-manager.com/an/ https://principiaskincare.com.br/mtc.js https://static.cloudflareinights.com/beacon.min.js/v52afc6f149f6479b8c77fa569edb01181681764108816 *.ads-twitter.com/uwt.js *.pinterest.com diffuser-cdn.app-us1.com prism.app-us1.com *.activehosted.com trackcmp.net cdn.jsdelivr.net *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com google.com *.kxcdn.com *.gstatic.com *.fontawesome.com *.freshchat.com fonts.googleapis.com *.mercadopago.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.onesignal.com https://onesignal.com/sdks/OneSignalSDKStyles.css *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com *.google.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.mercadopago.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.rastreio.alfatracking.com.br *.tracking.totalexpress.com.br *.rastreio.fmtransportes.com.br *.correios.com.br www.apptrian.com *.instagram.com *.pinterest.com *.apptrian.com *.polyfill.io *.cloudflare.com *.paypal.com *.pinimg.com *.tiktok.com *.google.com *.google.com.br *.google.it https://www.google.com.br/ads/ga-audiences https://www.google.it/ads/ga-audiences *.google-analytics.com *.doubleclick.net *.yotpo.com *.mercadolibre.com *.onesignal.com https://onesignal.com/api/v1/apps/980b27db-f331-407d-8b91-7ea1ff79c577/icon *.principiacosmeticos.com https://principiacosmeticos.com/mtc/event *.konduto.com principiaskin.com *.principiaskin.com *.googleapis.com *.viacep.com.br https://viacep.com.br/ws/ viacep.com.br/ws *.amcglobal.sc.omtrdc.net *.geostag.cardinalcommerce.com *.geo.cardinalcommerce.com *.1eafstag.cardinalcommerce.com *.1eaf.cardinalcommerce.com *.centinelapistag.cardinalcommerce.com *.centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.api.comapi.com *.webchat.dotdigital.com *.ekr.zdassets.com *.braintreegateway.com *.braintree-api.com https://principiaskincare.com.br/mtc/event https://pagead2.googlesyndication.com/pagead/buyside_topics/set/ analytics.pangle-ads.com https://google.com/ccm/form-data/700931334 https://google.com/pagead/form-data/700931334 analytics-ipv6.tiktokw.us http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.activehosted.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri csp-reporting/; report-to report-endpoint; 1 default-src 'self'; script-src 'unsafe-inline' 'self' 'unsafe-eval' blob: bat.bing.net *.speedcurve.com network-eu.bazaarvoice.com api.bazaarvoice.com www.googleadservices.com *.cdn.parcellab.com www.mczbf.com googleads.g.doubleclick.net t.contentsquare.net analytics-static.ugc.bazaarvoice.com x.klarnacdn.net www.paypal.com static-eu.payments-amazon.com cdn-ukwest.onetrust.com om.ordergroove.com stg.api.bazaarvoice.com display-stg.ugc.bazaarvoice.com display.ugc.bazaarvoice.com services.postcodeanywhere.co.uk c.zmags.com maps.googleapis.com pagead2.googlesyndication.com www.googleadservices.com cdn.ometria.com ct.pinterest.com api.bounceexchange.com js.smct.io d.impactradius-event.com script.hotjar.com js.adsrvr.org static.ads-twitter.com ad.doubleclick.net smct.co platform.twitter.com analytics.tiktok.com static.hotjar.com bat.bing.com s.pinimg.com assets.bounceexchange.com cdn.parcellab.com intentclientscriptslon.s3.eu-west-2.amazonaws.com unpkg.com tag.wknd.ai unpkg.com cdn.particularaudience.com intentclientscriptslon.s3.eu-west-2.amazonaws.com unpkg.com cdn.cookielaw.org cdn.jsdelivr.net www.google-analytics.com e.cquotient.com p.cquotient.com static.ordergroove.com cdn.cquotient.com www.gstatic.com hotelchocolat.whoson.com cas.zma.gs hotel11113.pcapredict.com cdn-ukwest.onetrust.com www.googletagmanager.com www.google.com try.abtasty.com js.klarna.com; font-src data: x.klarnacdn.net fonts.gstatic.com smc-fonts.s3-eu-west-1.amazonaws.com images.getfastr.com maxcdn.bootstrapcdn.com c.zmags.com; style-src 'self' 'unsafe-inline' hotelchocolat.whoson.com *.cdn.parcellab.com display.ugc.bazaarvoice.com assets.bounceexchange.com x.klarnacdn.net styledisplay.ugc.bazaarvoice.com smc-fonts.s3-eu-west-1.amazonaws.com cdn.parcellab.com icons.parcellab.com services.postcodeanywhere.co.uk c.zmags.com fonts.googleapis.com maxcdn.bootstrapcdn.com cas.zma.gs; connect-src 'self' *.speedcurve.com *.algolianet.com *.contentsquare.net ad.doubleclick.net *.algolia.net wss://*.hotjar.com *.hotjar.com bat.bing.net *.hotjar.io *.ometria.com google.com www.paypal.com region1.google-analytics.com cdn-ukwest.onetrust.com region1.analytics.google.com www.mczbf.com q-aeu1.contentsquare.net www.pinterest.com api.parcellab.com events.bouncex.net storage.googleapis.com srm.ba.contentsquare.net k-aeu1.contentsquare.net adservice.google.com cognito-identity.eu-west-1.amazonaws.com ids.cdnwidget.com pd.cdnwidget.com view.cdnbasket.net page.cdnbasket.net data.cdnbasket.net js.smct.io stats.g.doubleclick.net analytics.google.com ssgtm.hotelchocolat.com c.contentsquare.net ad.doubleclick.net dcinfos-cache.abtasty.com geolocation.onetrust.com eu.playground.klarnaevt.com www.sandbox.paypal.com payments-eu.amazon.com om.ordergroove.com restapi.ordergroove.com services.postcodeanywhere.co.uk privacyportal-uk.onetrust.com na.klarnaevt.com insights.algolia.io stfgatlncw-dsn.algolia.net c.zmags.com pagead2.googlesyndication.com maps.googleapis.com googleads4.g.doubleclick.net www.googleadservices.com insight.adsrvr.org bat.bing.com www.google.com firehose.eu-west-1.amazonaws.com ep.smct.co ct.pinterest.com analytics.tiktok.com ct.pinterest.com ct.pinterest.com ipl.smct.io main.inference.madewithintent.ai recs-us-e1a.particularaudience.com cdn.cookielaw.org googleads4.g.doubleclick.net insight.adsrvr.org eu.klarnaevt.com cdn-ukwest.onetrust.com js.klarna.com try.abtasty.com cas.zma.gs www.google-analytics.com ariane.abtasty.com; img-src 'self' *.speedcurve.com data: www.googleadservices.com icons.parcellab.com www.google.co.uk bat.bing.net cj.dotomi.com tbs.tradedoubler.com www.emjcd.com googleads.g.doubleclick.net match.adsrvr.org insight.adsrvr.org api.bounceexchange.com network-eu-stg-a.bazaarvoice.com network-eu.bazaarvoice.com hotelchocolat.whoson.com events.smct.co www.google-analytics.com assets.bounceexchange.com l.contentsquare.net www.google.com trk.ometria.com c.contentsquare.net ad.doubleclick.net network-eu-stg.bazaarvoice.com static-eu.payments-amazon.com www.hotelchocolat.com m.media-amazon.com www.paypalobjects.com om.ordergroove.com blog.hotelchocolat.com services.postcodeanywhere.co.uk images.creator-prod.zmags.com www.googletagmanager.com maps.gstatic.com maps.googleapis.com *.cdnwidget.com events.bouncex.net bat.bing.com analytics.twitter.com t.co cdn.cookielaw.org images.getfastr.com img.creator-prod.zmags.com cdn-ukwest.onetrust.com; frame-src 'self' 6933631.fls.doubleclick.net 13586967.fls.doubleclick.net https://online.flippingbook.com match.adsrvr.org ssgtm.hotelchocolat.com td.doubleclick.net cnc-api.zmags.com www.sandbox.paypal.com www.paypal.com testsecureacceptance.cybersource.com www.google.com www.youtube.com ls.smct.io d2d7do8qaecbru.cloudfront.net www.googleadservices.com assets.bounceexchange.com ct.pinterest.com insight.adsrvr.org www.googletagmanager.com www.google.co.uk 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.hotjar.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.authorize.net challenges.cloudflare.com data: *.hotjar.com *.gstatic.com *.doubleclick.net *.facebook.com *.brand-display.com *.sitescout.com *.addthis.com *.metalocator.com *.googletagmanager.com *.medallia.com *.adsrvr.org *.ipredictive.com *.spotify.com *.byspotify.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.magentocommerce.com *.facebook.com *.doubleclick.net *.google.com *.brand-display.com *.sitescout.com *.googletagmanager.com *.googleapis.com *.analytics.yahoo.com *.ktxlytics.io *.adnxs.com *.metalocator.com *.scooterscoffee.com *.kampyle.com *.ipredictive.com *.spotify.com *.byspotify.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.disqus.com *.avada.io *.shopify.com *.authorize.net challenges.cloudflare.com *.bluecore.com *.facebook.net *.googleapis.com *.hotjar.com *.googletagmanager.com *.doubleclick.net *.gstatic.com *.brand-display.com *.cloudflare.com *.sitescout.com up.pixel.ad *.xg4ken.com *.usersnap.com chimpstatic.com data: *.ktxlytics.io *.app-us1.com *.amazonaws.com *.addthis.com *.addthisedge.com trackcmp.net *.moatads.com *.metalocator.com *.jsdelivr.net *.medallia.com *.snapchat.com *.trackedweb.net *.appboycdn.com sc-static.net *.adsrvr.org *.ipredictive.com *.spotify.com *.byspotify.com *.braze.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.mailchimp.com *.typekit.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com https://get.geojs.io *.avada.io *.authorize.net *.bluecore.com *.googleapis.com *.hotjar.com *.hotjar.io *.doubleclick.net *.ktxlytics.io *.medallia.com *.snapchat.com *.trackedweb.net *.appboycdn.com sc-static.net *.kampyle.com *.ipredictive.com *.spotify.com *.byspotify.com *.braze.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://scooterscoffee.com/; report-to report-endpoint; 1 default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.vaude.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.criteo.com *.klarna.com js.mollie.com td.doubleclick.net app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu *.outtra.com *.googletagmanager.com *.fls.doubleclick.net *.amazon-adsystem.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com https://img.youtube.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: www.vaude.com vaude.localhost https://vaude.localhost/ www.google.de app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu uct.service.usercentrics.eu *.equalweb.com *.weglot.com ad.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com https://dynamic.criteo.com https://sslwidget.criteo.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com *.abtasty.com ion.vaude.com id.vaude.com analytics.vaude.com js-agent.newrelic.com vaude.matomo.cloud app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu *.equalweb.com cdn.matomo.cloud cdn.scarabresearch.com static.scarabresearch.com webchannel-content.eservice.emarsys.net https://vaude.homepagerecruiter.de https://cdn.tailwindcss.com https://production.neocomapp.com *.weglot.com *.outtra.com *.amazon-adsystem.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.googleapis.com *.gstatic.com *.equalweb.com *.weglot.com *.outtra.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://measurement-api.criteo.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.abtasty.com analytics.vaude.com bam.nr-data.net pagead2.googlesyndication.com vaude.matomo.cloud app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu aggregator.service.usercentrics.eu consent-api.service.consent.usercentrics.eu *.equalweb.com cdn.matomo.cloud cdn.scarabresearch.com static.scarabresearch.com webchannel-content.eservice.emarsys.net https://prompts.api.production.neocomapp.com *.weglot.com https://cdn-api-weglot.com *.outtra.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /csp-report.php; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * api.bazaarvoice.com stg.api.bazaarvoice.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.authorize.net *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://firebasestorage.googleapis.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.avada.io *.authorize.net *.cloudflare.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.certcapture.com display.ugc.bazaarvoice.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.addressy.com https://get.geojs.io *.avada.io *.authorize.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; child-src https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; connect-src 'self' https://*.cliniko.com https://stats.g.doubleclick.net https://www.google-analytics.com https://api.honeybadger.io https://*.intercom.io wss://*.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com; default-src 'self'; font-src 'self' data: https://*.cloudfront.net https://js.intercomcdn.com; form-action 'self' https://intercom.help https://api-iam.intercom.io; frame-ancestors 'none'; img-src 'self' data: https:; manifest-src 'self'; media-src: https://js.intercomcdn.com; script-src 'self' 'report-sample' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com https://ssl.google-analytics.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://www.google.com/recaptcha/api.js https://www.gstatic.com; style-src 'self' 'report-sample' 'unsafe-inline'; report-uri https://fa4a51a09d12751e5d532cfce80751aa.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self'; script-src 'report-sample' 'self' https://cdn.hu-manity.co/hu-banner.min.js https://kit.fontawesome.com/d44fbdfc72.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/lLirU0na9roYU3wDDisGJEVT/recaptcha__en.js https://www.youtube.com/iframe_api; style-src 'report-sample' 'self' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://designer-api.hu-manity.co https://ka-p.fontawesome.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://transactional-api.hu-manity.co https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://www.google.com https://www.youtube.com; img-src 'self' data: https://i.ytimg.com https://www.google.co.uk https://www.google.com; manifest-src 'self'; media-src 'self'; report-uri https://yp41w10j.uriports.com/reports/report; report-to default; worker-src 'none'; 1 frame-src https://www.google.com/ https://optimize.google.com https://*.paddle.com https://www.recaptcha.net/; report-uri /api/v1/reports; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://docs.staticstream.org https://*.google-analytics.com https://google-analytics.com https://www.googletagmanager.com https://tagmanager.google.com https://optimize.google.com https://www.googleoptimize.com https://www.recaptcha.net https://www.gstatic.com/recaptcha/ https://*.paddle.com https://*.zopim.com https://*.zdassets.com https://browser.sentry-cdn.com https://*.ingest.sentry.io https://cdn.jsdelivr.net https://code.jquery.com,; connect-src 'self' https://docs.staticstream.org https://*.google-analytics.com https://*.paddle.com https://browsec.zendesk.com wss://*.zopim.com https://*.zopim.com https://*.zdassets.com https://*.ingest.sentry.io https://bash.ws/ https://*.bash.ws/; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.net ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.net *.spreadshirt.net ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.net ; font-src 'self' https: data: *.spreadshirt.net ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.net ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.net ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com https://fonts.gstatic.com https://ws.colissimo.fr *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com 'self' data: static.sensefuel.live data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.sips-services.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com https://www.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.truefitcorp.com *.weltpixel.com https://form.typeform.com *.sagepay.com *.opayo.eu.elavon.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com *.afd.co.uk t.powerreviews.com assets-manager.abtasty.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://www.magezon.com *.sagepay.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com *.openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afd.co.uk cdn.jsdelivr.net js-agent.newrelic.com party.spockee.io app.ekoo.co ui.powerreviews.com *.truefitcorp.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com widget.proximis.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com tag.search.sensefuel.live pdata.damart.fr try.abtasty.com 'self' 'unsafe-eval' 'nonce-aHA4dHQxdnpuNHg0cGxoMmR4OHhxdTE4NzNiNDYzejM=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net ui.powerreviews.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com tag.search.sensefuel.live 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afd.co.uk *.getalma.eu *.almapay.com api.spockee.io backoffice-api.spockee.io ui.powerreviews.com display.powerreviews.com app.ekoo.co maps.googleapis.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.sagepay.com *.opayo.eu.elavon.com *.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com c.search.sensefuel.live 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://connect.facebook.net https://googleads.g.doubleclick.net https://grow.clearbitjs.com https://js-na1.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.hsforms.net https://js.hsleadflows.net https://js.hubspot.com https://js.usemessages.com https://sc.lfeeder.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://unpkg.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://api.hubapi.com https://api.hubspot.com https://cta-service-cms2.hubspot.com https://forms.hscollectedforms.net https://forms.hsforms.com https://forms.hubspot.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://stats.g.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.google.com.br; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://app.hubspot.com https://td.doubleclick.net https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: https://20650649.fs1.hubspotusercontent-na1.net https://forms-na1.hsforms.com https://forms.hsforms.com https://googleads.g.doubleclick.net https://i.ytimg.com https://perf-na1.hsforms.com https://pulsus.mobi https://px.ads.linkedin.com https://px4.ads.linkedin.com https://tr-rc.lfeeder.com https://track.hubspot.com https://www.facebook.com https://www.google-analytics.com https://www.google.com.br; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 frame-ancestors www.gstatic.com https://devmi1.wom.co https://dev.wom.co *.paypal.com *.wom.co; font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://app.wom.co *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com https://www.facebook.com *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadolibre.com https://www.googletagmanager.com https://api.retargetly.com https://*.hotjar.com https://*.doubleclick.net https://www.facebook.com https://resources-rt.idx.lat/ *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.googleapis.com maps.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com https://*.bing.com https://www.facebook.com https://www.google.com https://www.google.com.mx https://*.clarity.ms https://www.google.com.co https://analytics.twitter.com https://app.wom.co https://dev.placetopay.com https://t.co https://checkout-co.placetopay.dev *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.gstatic.com fonts.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mlstatic.com *.mercadopago.com https://widget.manychat.com https://www.google.com https://api.retargetly.com https://*.clarity.ms https://connect.facebook.net https://bat.bing.com https://analytics.tiktok.com https://d12zyq17vm1xwx.cloudfront.net https://*.hotjar.com https://static.ads-twitter.com https://script.crazyegg.com https://resources-rt.idx.lat *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com *.fontawesome.com https://app.wom.co *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; object-src *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; manifest-src *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolibre.com https://www.google-analytics.com https://stats.g.doubleclick.net https://notifications-icommkt.com https://track-icommkt.com https://analytics.tiktok.com https://*.clarity.ms https://analytics.google.com https://script.crazyegg.com https://rt.idx.lat *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org http: https: blob: 'self' 'unsafe-inline'; default-src https://*.api.comapi.com https://wom-co.convertia.com *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.amazonaws.com *.addi.com *.yieldmo.com *.casalemedia.com *.newrelic.com *.newrelic.co *.nr-data.net *.aralego.net *.aralego.com *.mediavine.com *.stickyadstv.com *.adgrx.com *.bluekai.com *.revcontent.com *.pubmatic.com *.outbrain.com *.postrelease.com *.liadm.com *.bidswitch.net *.emxdgt.com *.crcom.gov.co *.omappapi.com *.googlesyndication.com *.getblue.io *.pangle-ads.com *.yahoo.net *.wom.co https://devmi1.wom.co *.criteo.com *.clmbtech.com *.decidata.tv *.gfl85trk.com *.pingdom.net *.tremorhub.com *.smaato.net *.sharethrough.com *.360yield.com *.omnitagjs.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.rubiconproject.com *.media.net *.adnxs.com *.paypal.com *.doubleclick.net *.192.168.232.4:7105 *.avantel.co *.openstreetmap.org 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.googletagmanager.com *.googleapis.com static.cloudflareinsights.com unpkg.com translate.googleapis.com; object-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com unpkg.com; img-src 'self' data: www.google-analytics.com www.googletagmanager.com v1.sahistory.org.za http://v1.sahistory.org.za http://www.v1.sahistory.org.za https://v1.sahistory.org.za *.tile.openstreetmap.org unpkg.com http://www.sahistory.org.za http://sahistory.org.za https://www.sahistory.org.za translate.google.com translate.googleapis.com fonts.gstatic.com; media-src 'self'; frame-src 'self' www.youtube.com youtube.com; frame-ancestors 'self'; child-src 'self'; font-src 'self' fonts.gstatic.com data:; connect-src 'self' *.google-analytics.com www.google-analytics.com www.googletagmanager.com translate.googleapis.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self' 'nonce-cf3028e2-5eea-4b39-bd7c-c18681abb2f8' *.google-analytics.com *.googletagmanager.com; style-src 'self' 'unsafe-inline' 'self' 'unsafe-inline' https://media.imi.chat; script-src 'self' 'nonce-cf3028e2-5eea-4b39-bd7c-c18681abb2f8' https://cdn-widget.us.webexengage.com https://media.imi.chat; connect-src 'self' https://media.imi.chat https://cdn-widget.us.webexengage.com; img-src 'self' https://media.imi.chat data:; frame-src 'self' https://media.imi.chat; style-src-elem 'self' 'unsafe-inline' https://media.imi.chat; font-src 'self' https://media.imi.chat https://media.imi.chat/widget; object-src 'none'; base-uri 'none' 1 default-src 'self' http: https: wss: data: blob: 'unsafe-inline'; connect-src 'self' *.mypurecloud.com.au lifeline.payments2us.com *.typeform.com stockist.co *.youtube.com *.spotify.com *.vimeo.com vimeo.com cdn.usefathom.com *.hotjar.com *.clarity.ms *.google.com *.googletagmanager.com *.googleapis.com *.google-analytics.com *.gstatic.com connect.facebook.net lifeline.serviceseeker.com.au us-central1-stockist-prod.cloudfunctions.net *.bugherd.com; report-uri /report-csp-violation 1 default-src 'self' https://*.prime.diftech.org ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri /api/v1/pl-landing/csp-report 1 connect-src 'self' https://nx.nav.com https://www.google.com https://px.ads.linkedin.com https://bat.bing.com https://*.clarity.ms https://pixel-config.reddit.com https://www.redditstatic.com https://conversions-config.reddit.com https://analytics.tiktok.com https://app.launchdarkly.com https://consentcdn.cookiebot.com https://events.launchdarkly.com https://*.intercom.io wss://*.intercom.io https://*.bugsnag.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://www.facebook.com https://pagead2.googlesyndication.com https://www.buzzsprout.com 44.238.122.172 100.20.58.101 35.85.84.151 44.228.85.26 34.215.155.61 35.160.46.251 52.71.121.170 18.210.229.244 44.212.189.233 3.212.39.155 52.22.50.55 54.156.2.105; font-src 'self' https://design-assets.nav.com https://nav-web-static.nav.com https://fonts.googleapis.com https://fonts.gstatic.com *.intercomcdn.com; frame-src 'self' *.nav.com https://www.googletagmanager.com https://td.doubleclick.net https://consentcdn.cookiebot.com https://www.youtube.com https://job-boards.greenhouse.io https://www.buzzsprout.com https://www.google.com https://flo.uri.sh; script-src-elem 'self' 'strict-dynamic' 'unsafe-eval' https://nav-web-static.nav.com https://consentcdn.cookiebot.com https://px.mountain.com https://connect.facebook.net https://*.clarity.ms https://bat.bing.com https://www.buzzsprout.com 'nonce-f12b7185f3c450f10561a7efb02de7bb'; style-src 'self' 'unsafe-inline' https://nav-web-static.nav.com https://fonts.googleapis.com; media-src 'self' https://nav-web-static.nav.com https://design-assets.nav.com https://nav-cms-assets.nav.com; base-uri 'none'; img-src * data: blob:; report-to csp-endpoint 1 default-src 'self' 'report-sample'; connect-src 'self' https://matomo.psi.ch/; font-src 'self' data: player.podigee-cdn.net assets.brevo.com; frame-src 'self' *.ddev.site *.psi.ch player.vimeo.com www.youtube-nocookie.com feeds.sirop.org maps.google.com www.jove.com player.podigee-cdn.net cdnapisec.kaltura.com www.google.com www.srf.ch www.youtube.com psi.mediaspace.cast.switch.ch; img-src 'self' data: gfa-status.web.psi.ch share.web.psi.ch webcam.switch.ch; media-src 'self' *.ethz.ch data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com https://matomo.psi.ch/; script-src-elem 'self' 'unsafe-inline' test-t6dnbai-3bjapdgtwdrsg.eu-2.platformsh.site www.gstatic.com *.psi.ch www.google.com player.podigee-cdn.net sibforms.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' www.gstatic.com player.podigee-cdn.net sibforms.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' www.google.com; frame-ancestors 'self'; report-uri https://www.psi.ch/de/log-report-uri/reportOnly 1 default-src 'self' *.devfolio.co data:; script-src 'self' *.devfolio.co 'unsafe-eval' 'unsafe-inline' https://cdn.segment.com/ https://maps.googleapis.com/ https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://cdnmd.global-cache.online/ https://static.cloudflareinsights.com/ https://www.youtube.com/ https://checkout.razorpay.com/ https://apis.google.com/ https://gstatic.com/ https://ssl.gstatic.com/ https://player.vimeo.com/ https://connect.facebook.net/ https://google.com/ https://accounts.google.com/gsi/client https://ssl.google-analytics.com/ https://translate.googleapis.com/ https://unpkg.com/ https://cdn.rudderlabs.com https://www.pagespeed-mod.com/ https://www.google-analytics.com/ https://www.gstatic.com/ http://www.google.com/ *.cloudfront.net/ https://polyfill.io/ https://sessions.bugsnag.com/ https://d2wy8f7a9ursnm.cloudfront.net/v7/bugsnag.min.js https://cdn.tokenproof.xyz/js/tokenproof-oa-widget-v1.0.js blob: ; connect-src 'self' *.devfolio.co https://sessions.bugsnag.com/ https://maps.googleapis.com/ https://api.segment.io/ https://cdn.segment.com/ https://autocomplete.clearbit.com/ wss://*.devfolio.co/ https://lh3.googleusercontent.com/ https://sentry.io/ https://vimeo.com/ wss://*.bridge.walletconnect.org/ https://mainnet.infura.io wss://mainnet.infura.io https://arbitrum-mainnet.infura.io wss://eth-mainnet.ws.alchemyapi.io/ https://eth-mainnet.alchemyapi.io/ https://arb-mainnet.g.alchemy.com/ wss://arb-mainnet.g.alchemy.com/ wss://www.walletlink.org/ https://api.wallet.coinbase.com https://dns.google.com/ https://api.giphy.com/ https://registry.walletconnect.org/ https://api.segment.io/ *.dataplane.rudderstack.com/ https://api.rudderlabs.com/ https://www.google-analytics.com/ https://api.trongrid.io/ https://sun.tronex.io/ https://devfolio-prod.s3.ap-south-1.amazonaws.com/ https://explorer-api.walletconnect.com/ wss://relay.walletconnect.com/ https://sockjs-us2.pusher.com/ https://api.rudderstack.com/ https://cloudflare-eth.com/ https://anon-aadhaar-artifacts.s3.eu-central-1.amazonaws.com/ data:; style-src 'self' https://fonts.googleapis.com/ https://translate.googleapis.com/ 'unsafe-inline' data:; img-src 'self' * *.devfolio.co/ data: blob:; frame-src https://www.loom.com/ https://www.youtube.com/ https://drive.google.com/ https://m.youtube.com/ https://www.dailymotion.com/ https://vimeo.com/ https://api.razorpay.com/ https://accounts.google.com/ https://www.google.com/ https://player.vimeo.com/ https://loom.com/ https://www.drive.google.com/ https://razorpay.com/ *.razorpay.com/ https://mozbar.moz.com/; font-src 'self' https://fonts.gstatic.com/ https://devfolio-prod.s3.ap-south-1.amazonaws.com/ https://o91302.ingest.sentry.io/ https://mozbar.moz.com https://cdn.tokenproof.xyz/fonts/ data:; frame-ancestors 'self'; media-src 'self' *.devfolio.co/ *.githubusercontent.com/ https://www.youtube.com/ https://m.youtube.com/ https://youtu.be/ https://youtube.com/ https://drive.google.com/ https://www.drive.google.com/ data: blob:; report-uri https://o91302.ingest.sentry.io/api/1193563/security/?sentry_key=66b59c332abd4ee9902ba11631dc07c6 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-sclW0P9Dm/lkGiv4YYwzEZfRr236Hd++' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/; font-src 'self' kit.fontawesome.com ka-p.fontawesome.com https://fast.wistia.com/ https://fast.wistia.net/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob:; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.lawpay.com/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 default-src 'self'; child-src 'self'; connect-src 'self' cdnjs.cloudflare.com *.algolia.net *.algolianet.com *.flickr.com *.googleapis.com *.google-analytics.com *.gstatic-cache.com *.typekit.com *.typekit.net https://www.google-analytics.com https://www.googletagmanager.com https://o15468.ingest.sentry.io/api/6068037/envelope/; font-src 'self' cdnjs.cloudflare.com *.typekit.net fonts.gstatic.com app.everviz.com/static/fonts/; frame-src 'self' maps.google.com *.typekit.net player.vimeo.com translate.googleapis.com *.twitter.com www.google.com www.googletagmanager.com *.youtube.com; img-src 'self' data: cdnjs.cloudflare.com *.staticflickr.com *.twitter.com *.typekit.net *.googletagmanager.com fonts.gstatic.com translate.google.com production-new-commonwealth-files.s3.eu-west-2.amazonaws.com staging-new-commonwealth-files.s3.eu-west-2.amazonaws.com testing-new-commonwealth-files.s3.eu-west-2.amazonaws.com https://www.google-analytics.com https://www.googletagmanager.com; media-src 'self' production-new-commonwealth-files.s3.eu-west-2.amazonaws.com staging-new-commonwealth-files.s3.eu-west-2.amazonaws.com testing-new-commonwealth-files.s3.eu-west-2.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' apis.google.com code.highcharts.com connect.facebook.net embedr.flickr.com player.vimeo.com unpkg.com www.googletagmanager.com www.gstatic.com app.everviz.com/resources/js/ app.everviz.com/inject cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com player.vimeo.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; style-src 'self' 'unsafe-inline' code.highcharts.com *.typekit.net *.googleapis.com unpkg.com www.gstatic.com app.everviz.com/static/fonts/ app.everviz.com/resources/css/ cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; frame-ancestors 'self'; report-uri https://thecommonwealth.org/log-report-uri/reportOnly 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.fontawesome.com *.oct8ne.com https://cdnjs.cloudflare.com *.gstatic.com https://sandbox.sequracdn.com/ *.reskyt.com/ https://cdn.doofinder.com/* data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com https://plumrocket.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.oct8ne.com https://plumrocket.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.trustpilot.com *.paypalobjects.com/ *.flyde.io/ *.redintelligence.net/ *.reskyt.com/ *.quantummetric.com/ *.sequrapi.com/ *.klarnacdn.net/ *.doubleclick.net/ *.google.com/ https://www.facebook.com *.amazonaws.com/* https://myadsplatform-prod.s3.eu-central-1.amazonaws.com/ https://static.criteo.net https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com https://*.gstatic.com cdn.doofinder.com magefan.com cm.magefan.com *.disqus.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.padelnuestro.com https://www.google.ie *.googleapis.com *.gstatic.com https://www.google.es/ads/ https://www.googletagmanager.com/ https://www.emjcd.com/ https://cj.dotomi.com/ *.cloudfront.net *.bing.com/ *.adform.net/ *.facebook.com/ *.reskyt.com/ *.connectif.cloud/ *.doubleclick.net/ *.google.com/ *.placeholder.com https://grwapi.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.googletagmanager.com *.adyen.com cdn.doofinder.com *.disqus.com *.oct8ne.com https://cdnjs.cloudflare.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.trustpilot.com https://sdk.privacy-center.org https://js-agent.newrelic.com https://bam.nr-data.net *.googleapis.com *.gstatic.com https://www.mczbf.com/ https://cdn.connectif.cloud/ *.cloudfront.net https://commerce.adobedtm.com/ *.bing.com/ *.adform.net/ *.jsdelivr.net/ *.flyde.io/ *.facebook.net/ *.tiktok.com/ *.klarnacdn.net/ *.reskyt.com/ *.quantummetric.com/ blob *.klarna.com/ *.sequrapi.com/ *.clarity.ms/ *.google.com/ https://grwapi.net https://unpkg.com https://eu1-config.doofinder.com/* *.doofinder.com/* https://eu1-config.doofinder.com/2.x/d0f0ef47-8a08-4c9c-9f1f-3c43a3aa757c.js *.usermaven.com/* *.creativecdn.com/* *.woopra.com/* https://static.woopra.com/ https://www.woopra.com/ https://tags.creativecdn.com/ https://ams.creativecdn.com/ https://f.creativecdn.com/ https://sync.outbrain.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.doofinder.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.trustpilot.com *.googletagmanager.com/ *.reskyt.com/ *.quantummetric.com/ *.googleapis.com https://grwapi.net *.doofinder.com/* https://cdn.doofinder.com/* https://cdn.doofinder.com/livelayer/1/css/2/common.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io qa-api.magedevteam.com *.sentry.io *.adyen.com *.doofinder.com wss://*.doofinder.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://pre.wayletlabs.com/* https://pro.waylet.es/* https://region1.google-analytics.com https://api.privacy-center.org *.doubleclick.net https://bam.nr-data.net *.googleapis.com *.gstatic.com *.google.com https://www.mczbf.com/ *.connectif.cloud/ *.flyde.io/ *.tiktok.com/ *.facebook.com/ *.reskyt.com/ *.quantummetric.com/ *.googlesyndication.com/ *.klarna.com/ *.klarnacdn.net/ *.clarity.ms https://grwapi.net https://track.adform.net https://google.com *.woopra.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.mythad.com https://*.kwai-pro.com http://*.kwai-pro.com http://*.kwai.net https://*.kwai.net *.kwai.com *.snackvideo.in *.kwai.me *.kwai.app *.kwimgs.com *.yximgs.com *.cloudfront.net *.kuaishou.com https://*.gifshow.com http://*.gifshow.com https://log-sdk.ksapisrv.com https://www.googletagmanager.com https://gifshow-static.download.ks-cdn.com https://static3.avast.com https://translate.google.com https://www.gstatic.com https://fonts.gstatic.com https://connect.facebook.net www.google-analytics.com hm.baidu.com m.snackvideo.com http://*.ap4r.com https://*.ap4r.com https://*.typekit.net http://*.typekit.net ak-sgp-pic.snackvideo.in tx-sgp-pic.snackvideo.in ws-sgp-pic.snackvideo.in g-us-kampic.golden49.net g-us-kamcdn.golden49.net m.kwai.com sentry.kuaishou.com https://cdn.jsdelivr.net https://at.alicdn.com https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://cdn.linkedin.oribi.io https://www.linkedin.com https://*.google.com https://*.google-analytics.com https://*.doubleclick.net asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;img-src http: https: asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;connect-src http: https: asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;report-uri https://csplog.kwai-pro.com/log/kwai/wwwkwai 1 object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'; report-to csp-violation-endpoint; report-uri /cgi-bin/report_csp_violation.py 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.googleapis.com *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro *.google.com www.googletagmanager.com *.googletagmanager.com facebook.com *.prefixbox.com *.tiktok.com *.jsdelivr.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.facebook.com *.instagram.com *.gigya.com *.carrefour.ro carrefour.ro facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.googletagmanager.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com *.cookiebot.com *.google.com *.gigya.com *.carrefour.ro carrefour.ro *.krxd.net *.hotjar.com *.jsdelivr.net *.btdirect.ro *.tiktok.com *.prefixbox.com facebook.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com 'self' data: *.googletagmanager.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com blob: *.3lift.com *.adnxs.com *.adsrvr.org *.bluekai.com *.casalemedia.com *.ck-ie.com *.contextweb.com *.cookielaw.org *.dotomi.com *.eyeota.net *.flavedo.io *.flix360.com *.flix360.io *.flixcar.com *.google.ro *.google-analytics.com *.googleadservices.com *.kargo.com *.lijit.com *.media.net *.mediaplex.com *.openx.net *.paypal.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com servedbyadbutler.com *.sharethrough.com *.shopogen.ro *.stickyadstv.com *.streamtheworld.com *.tremorhub.com *.yahoo.com *.gigya.com 'unsafe-inline' data: *.carrefour.ro carrefour.ro facebook.com *.krxd.net *.google.com www.googletagmanager.com *.tiktok.com *.prefixbox.com *.jsdelivr.net *.newrelic.com bam.eu01.nr-data.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.cloudflare.com *.cookiebot.com *.dotomi.com *.flix360.com *.flix360.io *.flixcar.com *.flixfacts.com *.googleapis.com *.instagram.com *.jsdelivr.net *.newrelic.com *.paypal.com *.pingdom.net servedbyadbutler.com *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro chimpstatic.com www.googletagmanager.com *.krxd.net *.prefixbox.com *.tiktok.com *.cookielaw.org *.hotjar.com facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com *.shopogen.ro *.twitter.com *.typekit.net *.gigya.com 'unsafe-inline' data: *.carrefour.ro carrefour.ro *.jsdelivr.net *.prefixbox.com *.tiktok.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.citrusad.com *.doubleclick.net *.flix360.io *.flixcar.com *.googleapis.com *.googlesyndication.com *.instagram.com *.onetrust.com *.paypal.com *.pingdom.net *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro *.cookielaw.org *.krxd.net *.hotjar.com *.jsdelivr.net *.prefixbox.com *.newrelic.com bam.eu01.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-elaXPkeryAbdv-Fu6EaVUA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=qJnnlRB0_oN.CVlaWJErYKH67raIknihYItzLnGTEtc-1765934737.0293982-1.0.1.1-Oh1S6znIFTPu0Q9HS0TkDrXjLn4TB7ANxL.ZiTb6_hzT9w5x127fvjkZUNZhi8yeNPRl7ssI6UyWTLq5BzOGevDGG7FwV5lyu4pnDhkbcrxUbf4hRwgTiMtFGgxTgJ_BVc8rb1.UgbDAymvVPfyQ8h0.bNOwfXKhBA.Qiq5YKSBeRkHxMbbzMUBVsoqXP87x; report-to cf-zdikdtgtscjzscmn 1 font-src *.vita4you.gr *.googletagmanager.com *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com *.fontawesome.com 'self' data: *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.usercentrics.eu *.bing.com *.zdassets.com *.google.com *.google.gr *.clarity.ms/ applepay.cdn-apple.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.contactpigeon.com assets.vita4you.gr *.google.gr *.skroutz.gr *.zopim.com *.moosend.com *.cloudflare.com td.doubleclick.net int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com widget-v3.boxnow.gr widget-v5.boxnow.cy *.skroutz.gr *.contactpigeon.com *.hotjar.com *.facebook.com td.doubleclick.net *.clarity.ms/ *.bing.com *.googletagmanager.com *.google.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://trustmark.gr *.tiktok.com *.contactpigeon.com assets.vita4you.gr *.vita4you.gr *.googleapis.com *.gstatic.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.skroutz.gr *.moosend.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.io td.doubleclick.net *.facebook.com *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.clarity.ms/ https://bat.bing.net rum.corewebvitals.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com flagpedia.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.octocom.ai *.octocomstorage.blob.core.windows.net 'self' data: *.tiktok.com *.googletagmanager.com *.googleapis.com *.vita4you.gr *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net *.paypal.com *.google.com *.hotjar.com *.fontawesome.com *.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.skroutz.gr skroutza.skroutz.gr *.cloudflare.com *.google.gr https://trustmark.gr/badge/dist/index.js https://static.adman.gr/adman.js https://greca.adman.gr cdn.omnicliq.com/ss.js *.clarity.ms/ *.bing.com *.debugbear.com https://apis.google.com *.corewebvitals.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io *.shopify.com maps.googleapis.com https://js.klevu.com https://assets.vita4you.gr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.octocom.ai *.octocomstorage.blob.core.windows.net *.googletagmanager.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.vita4you.gr *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net *.fontawesome.com *.trustpilot.com cdn.jsdelivr.net *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.bing.com *.hotjar.com *.clarity.ms/ *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' data: *.contactpigeon.com assets.vita4you.gr *.google.gr *.zopim.com *.skroutz.gr *.moosend.com *.cloudflare.com *.youtube.com 'self' 'unsafe-inline'; manifest-src assets.vita4you.gr 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.octocom.ai *.octocomstorage.blob.core.windows.net *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.tiktok.com *.contactpigeon.com assets.vita4you.gr *.paypal.com stats.g.doubleclick.net https://googleads.g.doubleclick.net/ *.zdassets.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.skroutz.gr *.cloudflare.com api.zevioo.com https://pagead2.googlesyndication.com ss.vita4you.gr *.bing.com *.clarity.ms/ *.debugbear.com td.doubleclick.net https://bat.bing.net int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com *.addthis.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors https://*.facebook.com https://*.youtube.com https://*.graphic.com.gh; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=frYe1es.klYoAE2qa_WUAs7gsgpdz9daS5TDMJebD0w-1765936249-1.0.1.1-9pYwuEnAFsEl660vIEt6jPOs6G6lnaYJSHaFflF40s6gO5FiF3G9Nx2ppD1NDEV3nfdhmJIW0szJY6y61rKLWkx.dHQe5I7055Pmp7odYHEwgI0C3fqQKtKMEYUcRBtmcoNaAiW5qfqg3IfbjY25h1C7CTDh7MaVD3Z4I3hcU53jBT1ZdBrFQRxwqemqkLZIChunVfXWNUAN4E_8jLp0QA; report-to cf-wfotlgphuygatcxo 1 font-src 'self' data:; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com stackpath.bootstrapcdn.com unpkg.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://live-instinet-drupal.pantheonsite.io https://unpkg.com stackpath.bootstrapcdn.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 script-src 'self' https://*.churnkey.co https://*.cello.so https://*.hotjar.com https://*.hotjar.io https://*.posthog.com https://prodregistryv2.org https://featureassets.org https://api.statsig.com https://featuregates.org https://statsigapi.net https://events.statsigapi.net https://assetsconfigcdn.org https://cloudflare-dns.com https://*.ingest.sentry.io https://challenges.cloudflare.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://plausible.io https://*.google.com https://www.google.com https://www.google-analytics.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.googletagmanager.com https://*.googleusercontent.com https://*.mermaidchart.com https://vercel.live https://*.reddit.com https://www.redditstatic.com https://bat.bing.com https://www.bing.com https://c.bing.com https://www.clarity.ms 'unsafe-eval' 'nonce-DHgegado47kXpAhSADwVrw=='; report-to sentry 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: https://*.stripe.com; object-src 'none'; script-src 'self' https: https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com 'nonce-cZluB9+8k6iSDiCjb2vFCg=='; style-src 'self' https: 'nonce-cZluB9+8k6iSDiCjb2vFCg=='; frame-src 'self' https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com; connect-src 'self' https://api.stripe.com https://maps.googleapis.com; report-uri /systems/csp_report 1 frame-ancestors 'self'; report-uri https://transilien.report-uri.com/r/d/csp/enforce; report-to https://transilien.report-uri.com/r/d/csp/enforce 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/families_google 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=DoxZwvJQZPRA0TvqA9xcmWrbdJfCX.ClPabv42920FI-1765938138.4143257-1.0.1.1-qdas8W3TljTWXZ_tjYyJ_4EZ0VIGOnk0h.wOcTPZqkcem38VCe8i0Vvl6gWx5SzxFJzX.6lN_c9zDthQeUy_mmvNe.JILuG.qJUKfnhtZJM2wcJFFZPQHBrN9yNPUU3OvAzrMNbDtYrcgAo5zZ419BVQOIZw3ubZb_cA0LhyaurqXFCAVsaSGpPdAbGhRH9C; report-to cf-csp-endpoint 1 default-src 'self' dropbox.okta.com *.oktacdn.com; connect-src 'self' dropbox.okta.com dropbox-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com dropbox.kerberos.okta.com dropbox.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-YUOHkePZrFmVUFli3_qN6w' 'unsafe-eval' 'self' 'report-sample' dropbox.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-YUOHkePZrFmVUFli3_qN6w' 'self' 'report-sample' dropbox.okta.com *.oktacdn.com; frame-src 'self' dropbox.okta.com dropbox-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: api-37ec43d7.duosecurity.com; img-src 'self' dropbox.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' dropbox.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://app.dropboxer.net 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.doubleclick.net *.facebook.com *.getfastr.com *.zmags.com *.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.klarna.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.rlcdn.com *.googleapis.com *.linksynergy.com *.getfastr.com *.zmags.com *.unityclient.com *.listrakbi.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com services.postcodeanywhere.co.uk *.disqus.com https://img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.pcapredict.com *.addressy.com *.zmags.com *.zma.gs *.googleapis.com *.unityclient.com *.listrakbi.com *.thrive.today recruitingbypaycor.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com api.addressy.com *.disqus.com cdn.ampproject.org connect.facebook.net https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.addressy.com *.zmags.com *.zma.gs *.unityclient.com *.listrakbi.com assets.braintreegateway.com *.klarnacdn.net *.klevu.com *.ksearchnet.com api.addressy.com maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.addressy.com *.zmags.workers.dev *.zmags.com *.zma.gs *.googleapis.com *.unityclient.com *.listrakbi.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com api.addressy.com cdn.ampproject.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/gfiber-static-marketing-jt-team 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://stackpath.bootstrapcdn.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://optimize.google.com https://fonts.googleapis.com; script-src 'self' https://*.smallcase.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googletagmanager.com https://app.link https://script.hotjar.com https://static.hotjar.com https://www.youtube.com https://s.ytimg.com https://apis.google.com https://connect.facebook.net https://*.razorpay.com https://*.gateway-tt.in https://cdn.segment.com https://cdn.amplitude.com https://cdn.moengage.com https://stackpath.bootstrapcdn.com https://a.quora.com https://q.quora.com 'unsafe-eval' 'unsafe-inline' https://appleid.cdn-apple.com https://optimize.google.com https://www.googleoptimize.com https://*.googlesyndication.com https://partner.googleadservices.com https://www.googletagservices.com https://adservice.google.com https://adservice.google.co.in https://*.tickertape.in https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://www.gstatic.com https://*.nexum.smallcase.com https://securepubads.g.doubleclick.net https://cms.stag.smallcase.com https://tally.so/widgets/embed.js https://www.clarity.ms https://bfin.creditcase.in; img-src 'self' data: https://*.tickertape.in http://*.tickertape.in https://*.smallcase.com https://*.cloudfront.net https://s3.ap-south-1.amazonaws.com https://s3.amazonaws.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://www.google.com https://www.google.co.in https://pocket-image-cache.com https://*.ytimg.com https://script.hotjar.com https://premium.thehindubusinessline.com https://thehindubusinessline.com https://thehindu.com https://www.thehindu.com https://www.thehindubusinessline.com https://*.reutersmedia.net https://img.youtube.com https://www.facebook.com https://cdn.razorpay.com https://d36bckgfrodyym.cloudfront.net https://moe-email-campaigns.s3.amazonaws.com https://image.moengage.com https://via.placeholder.com https://q.quora.com https://optimize.google.com https://*.tenor.com https://d3jkipq6ucdzmu.cloudfront.net https://pagead2.googlesyndication.com https://www.dspim.com https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://dummyimage.com https://*.dummyimage.com https://*.coolbootsmedia.com https://*.pubmatic.com https://*.ergadx.com https://*.criteo.com https://*.themediagrid.com https://*.Pubmatic.com https://*.openx.com https://*.rubiconproject.com https://*.colombiaonline.com https://*.teads.tv https://*.rubiconproject.com https://*.triplelift.com; connect-src https://*.tickertape.in http://*.tickertape.in wss://*.tickertape.in https://*.smallcase.com https://www.google-analytics.com https://www.googletagmanager.com https://*.hotjar.com:* https://vc.hotjar.io:* wss://*.hotjar.com https://surveystats.hotjar.io https://stats.g.doubleclick.net https://graph.facebook.com https://*.razorpay.com https://cdn.segment.com https://api.segment.io https://api.amplitude.com/ https://s3.ap-south-1.amazonaws.com https://sdk-01.moengage.com https://sdk-02.moengage.com https://sdk-03.moengage.com https://d36bckgfrodyym.cloudfront.net https://*.s3.ap-south-1.amazonaws.com https://analytics.google.com https://optimize.google.com https://*.tenor.com https://d3jkipq6ucdzmu.cloudfront.net https://pagead2.googlesyndication.com https://*.vmax.com https://*.amplitude.com:* https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://firebaseremoteconfig.googleapis.com https://firebaseinstallations.googleapis.com https://firebase.googleapis.com https://*.facebook.com https://*.nexum.smallcase.com https://securepubads.g.doubleclick.net https://cms.stag.smallcase.com https://bfin.creditcase.in; frame-src https://connect.smallcase.com https://connect.smallca.se https://gateway.smallca.se/ https://vars.hotjar.com https://www.googletagmanager.com https://accounts.google.com https://www.youtube.com https://api.razorpay.com https://*.gateway-tt.in https://cdn.moengage.com https://optimize.google.com https://tpc.googlesyndication.com https://*.googlesyndication.com/ https://*.tenor.com https://googleads.g.doubleclick.net https://smallcase.zerodha.com https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://securepubads.g.doubleclick.net https://bfin.creditcase.in; font-src 'self' data: https://script.hotjar.com https://fonts.gstatic.com https://fonts.gstatic.com; frame-ancestors 'self' https://*.smallcase.com; object-src 'none' 1 script-src 'self' 'unsafe-inline' js.datadome.co ct.captcha-delivery.com *.onetrust.com *.googletagmanager.com *.cookielaw.org *.qualtrics.com *.siteintercept.qualtrics.com *.salesforce.com *.sandbox.my.salesforce.com *.en25.com *.segment.com *.amplitude.com *.salesforceliveagent.com *.salesforceliveagent.com; connect-src 'self' api-js.datadome.co *.onetrust.com *.cookielaw.org *.rcp-api.reutersconnect.com *.cdn.reuters.com *.reutersconnect.com siteintercept.qualtrics.com wss://*.rcp-api.reutersconnect.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.segment.io *.amplitude.com *.thomsonreuters.com *.cdn.reuters.com; frame-src 'self' geo.captcha-delivery.com *.onetrust.com *.salesforce.com *.sandbox.my.salesforce.com; worker-src 'self' blob: https://*.reutersconnect.com; report-to csp-endpoint; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: oct8necdneu.azureedge.net *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.hotjar.com https://fonts.gstatic.com *.klarnacdn.net https://widgets.trustedshops.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es * *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com https://www.salesmanago.pl https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.vimeo.com *.oct8ne.com * *.cookiebot.com *.cookiebot.eu *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.klarna.com shein.m2e.cloud *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.trustedshops.com *.bynder.com analytics.tiktok.com *.clerk.io assets.atida.com connect.facebook.net *.cookiebot.eu efarma-supercraft.s3.eu-south-1.amzonaws.com dwin1.com facebook.com google.com google.it googletagmanager.com *.doubleclick.net yotpo.com *.zdassets.com gastatic.com *.yotpo.com *.analytrix-tool.it *.convalytrix.it *.efarma.dna-ai.dnafactory.it *.atida.com *.dosfarma.com *.facebook.com *.zenaps.com *.awin1.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co t.co *.twitter.co *.twitter.com *.cloudfront.net *.byspotify.com *.cookiebot.com *.googlesyndication.com *.syndigo.com *.assets.efarma.com efarma-supercraft.s3.eu-south-1.amazonaws.com *.efarma.com *.bing.net *.usercentrics.eu *.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.ggpht https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js polyfill.io *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.clerk.io *.cloudfront.net *.zdassets.com *.zendesk.com *.api.smooch.io *.connectif.cloud *.atida.com *.dosfarma.com *.newrelic.com *.nr-data.net *.dwin1.com *.pinimg.com *.ads-twitter.com *.tiktok.com *.kk-resources.com *.bing.com *.creativecdn.com *.facebook.net *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.pinterest.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cookiebot.eu stapecdn.com *.efarma.com *.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com cdn.scalapay.com b2c-cdn.scalapay.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.googletagmanager.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.hotjar.com unsafe-inline assets.braintreegateway.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com *.klarnacdn.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.google.com/pay *.analytrix-tool.it *.convalytrix.it *.clerk.io *.caast.tv *.efarma.dna-ai.dnafactory.it *.api.smooch.io *.zdassets.com *.zendesk.com *.connectif.cloud *.atida.com *.dosfarma.com *.algolia.io *.cookiebot.com *.cookiebot.eu *.nr-data.net google.com *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.bing.net *.efarma.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src *; default-src *; font-src * data:; frame-src *; img-src data: *; script-src 'unsafe-inline' 'unsafe-eval' *; script-src-elem 'unsafe-inline' *; style-src 'unsafe-inline' *; style-src-elem 'unsafe-inline' *; 1 default-src 'self'; script-src 'self' 'nonce-r2jvr8KnASxxlbwm9VjqQg==' https://www.google-analytics.com https://widget.trustpilot.com http://widget.trustpilot.com https://*.sentry.io https://*.firebase.googleapis.com https://static.zdassets.com https://www.redditstatic.com/ads/pixel.js https://snap.licdn.com/li.lms-analytics/insight.min.js ; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' https://content-api.bento.capital https://content-api.changenow.io https://content-api-spb1.btc-bnb.com https://widget.trustpilot.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://explorer-api.walletconnect.com https://alb.reddit.com/rp.gif; connect-src 'self' https://l.changenow.org https://*.zdassets.com https://www.google-analytics.com https://vip-api.bento.capital https://vip-api.changenow.io https://vip-api-spb1.btc-bnb.com https://content-api.bento.capital https://content-api.changenow.io https://content-api-spb1.btc-bnb.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://affiliate-backend.changenow.io https://api.changenow.io https://explorer-api.walletconnect.com https://verify.walletconnect.com https://changenow.zendesk.com https://px.ads.linkedin.com/collect ; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; frame-src 'self' https://widget.trustpilot.com http://widget.trustpilot.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://youtube.com https://verify.walletconnect.com https://www.youtube.com ; report-uri https://l.changenow.org/api/3/security/?sentry_key=caf1b4c4d55fac9fb827b0fc4c20f664 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-W6vcSOB7twBl76SI3DYDs99JhZ8ONzrk' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/; font-src 'self' kit.fontawesome.com https://ka-p.fontawesome.com/ https://fast.wistia.com/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob:; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.docketwise.com/ https://www.youtube.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 script-src 'strict-dynamic' 'unsafe-inline' https: 'nonce-58beb13831a029b7ea5c58f98b2457fe';object-src 'none';base-uri 'none';frame-src 'self' https://paywall.imoje.pl https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://wchat.freshchat.com https://*.webpush.freshchat.com https://www.youtube.com https://youtube.com https://youtu.be https://www.youtube-nocookie.com https://youtube-nocookie.com https://www.facebook.com https://open.spotify.com/embed/ https://podcasters.spotify.com/pod/show/ https://player.vimeo.com/video/ https://td.doubleclick.net https://platform.twitter.com/ https://www.googletagmanager.com/;report-uri https://o160244.ingest.sentry.io/api/1798165/security/?sentry_key=22e91a43970d40cdae6153ad3feb9951;report-to csp-endpoint 1 default-src 'self' https://3sspw4l2.tinifycdn.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://3sspw4l2.tinifycdn.com https://a.plerdy.com https://challenges.cloudflare.com https://connect.facebook.net https://d.plerdy.com https://googleads.g.doubleclick.net https://js.stripe.com https://maps.googleapis.com https://notifications.nic.ua https://www.googletagmanager.com https://www.paypal.com https://www.paypalobjects.com; script-src-elem 'self' 'unsafe-inline' blob: https://3sspw4l2.tinifycdn.com https://a.plerdy.com https://challenges.cloudflare.com https://connect.facebook.net https://d.plerdy.com https://js.stripe.com https://maps.googleapis.com https://notifications.nic.ua https://www.googletagmanager.com https://www.paypal.com https://www.paypalobjects.com https://googleads.g.doubleclick.net *.nicnames.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://3sspw4l2.tinifycdn.com; style-src-elem 'self' 'unsafe-inline' https://3sspw4l2.tinifycdn.com https://fonts.googleapis.com https://pt.wisernotify.com https://themes.googleusercontent.com https://www.gstatic.com; style-src-attr 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com https://3sspw4l2.tinifycdn.com https://cdn.megabonus.com *.nicnames.com https://static.hsappstatic.net; img-src * data: blob:; connect-src 'self' https://3sspw4l2.tinifycdn.com https://api.locize.app https://api.nicnames.com wss://d.plerdy.com https://d.plerdy.com https://jexi.ai https://maps.googleapis.com https://nicnames.com https://ns.wisermapp.com https://overbridgenet.com https://region1.google-analytics.com https://strapi.nicnames.com https://ts-wn-log-bmggb9bcacbsd6df.westus-01.azurewebsites.net https://www.facebook.com https://www.googleadservices.com https://www.google-analytics.com https://www.google.com https://www.paypal.com; frame-src 'self' https://assets.braintreegateway.com https://challenges.cloudflare.com https://c.paypal.com https://js.stripe.com https://td.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://www.paypal.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; report-uri https://nicnames.com/csp-reports; 1 default-src data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *.nesine.com wss://*.nesine.com *.google.com *.google.com.tr *.googletagmanager.com *.google-analytics.com *.support.google.com *.doubleclick.net *.googleadservices.com *.microsoft.com *.apple.com *.facebook.com *.facebook.net connect.facebook.net *.betsolutions.com *.ertgaming.com *.yahoo.com *.newrelic.com *.twitter.com *.instagram.com *.youtube.com *.ytimg.com *.aboutcookies.org *.mobilproses.com *.omnitagjs.com *.outbrain.com *.nr-data.net *.bidswitch.net wss://*.sportradar.com *.sportradar.com *.akamaized.net *.performfeeds.com *.betradar.com *.dge.imggaming.com tjktv.ercdn.net *.tjk.org *.broadage.com *.pubmatic.com *.mediavine.com *.demdex.net *.krxd.net *.thebrighttag.com *.tremorhub.com *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.teads.tv *.3lift.com *.emxdgt.com *.sync.com *.ivitrack.com *.yieldmo.com *.yieldlab.net *.imgarena.com *.liderform.com.tr *.googleapis.com *.googlevideo.com *.gstatic.com *.azureedge.net *.semasio.net *.7platform.net *.7platform.com *.7platform.live *.nsoft-cdn.com *.launchdigi.net *.106digital.com *.gameturboz.cloud *.turboexplorer.online *.1rx.io *.adsrvr.org aa.agkn.com *.postrelease.com *.revcontent.com *.rqtrk.eu *.bing.com *.smaato.net *.narrative.io *.socdm.com *.mediawallahscript.com *.liadm.com *.stickyadstv.com *.linkedin.com *.rlcdn.com *.dable.io *.adingo.jp *.twiago.com *.bluekai.com *.crwdcntrl.net *.hs.llnwd.net *.ucweb.com *.dengage.com *.playbetman.com *.turbolabs.online *.aleaplay.com *.turbogg4u.online *.turbodiscovery.xyz *.ofmicropod.com *.dengagecdn.com launchdigi.net *.eskimi.com *.tiktok.com *.rsc.cdn77.org *.igamemedia.com *.castr.net data.widgets.sir.sportradar.com *.inseincvirtuals.com wss://data.widgets.sir.sportradar.com wss://*.sportradar.com wss://*.akamaized.net cdn.alsgp0.fds.api.mi-img.com apm-rum-sgp.inf.miui.com infragrid.v.network metrics-dre.dt.dbankcloud.cn cdn-uicons.flaticon.com *.cloudfront.net *.mobilproses.com *.codezania.com https://106gamesgalaxsys.online https://www.millipiyangoonline.com/ www.google.de www.google.com.cy www.google.nl www.google.fr www.google.co.uk www.google.iq www.google.ca www.google.pt www.google.ch www.google.bg www.google.az www.google.it www.google.no www.google.se www.google.com.sa www.google.com.qa www.google.ru www.google.be www.google.com.kw www.google.co.tz www.google.ro www.google.hu www.google.ba www.google.at www.google.rs *.millipiyangoonline.com www.google.dk www.google.co.uz www.google.dz www.google.es www.google.pl www.google.com.ly www.googletagmanager.com digital.millipiyangoonline.com www.google.at www.google.hu www.google.ro www.google.ru www.google.be dbox1.sisalsanstech.com www.millipiyangoonline.com pagead2.googlesyndication.com https://bulten.sm.mncdn.com; img-src * data:; report-uri /csp/cspreport/ 1 default-src 'self'; script-src 'self' data: https://*.openstreetmap.org app.23degrees.io matomo.ifw-kiel.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org *.trade.ifw-kiel.de http://*.ifw-kiel.de *.ifw-kiel.de corona-datenmonitor-ifw-kiel.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.ifw-kiel.de app.23degrees.io www.tagesschau.de www.facebook.com webcast.streambuzzer.com playout.3qsdn.com g24media.de 21e87844.sibforms.com; style-src-elem 'self' 'sha256-ZHuIQHi6NyMM8SsxXGIT+7n2ngsgurzDCCcFY7LqPVA=' 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org matomo.ifw-kiel.de; report-uri https://www.kielinstitut.de/@http-reporting?csp=report&requestTime=1765939927349726&requestHash=14eaab57d178866b3863106b6484163619c61a5e 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: oct8necdneu.azureedge.net *.trustedshops.com *.cloudflare.com https://fonts.gstatic.com https://widgets.trustedshops.com *.yotpo.com https://ws.colissimo.fr https://static.lyra.com/static/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es * *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline'; frame-ancestors https://www.salesmanago.pl https://api.clerk.io https://cdn.clerk.io *.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.vimeo.com *.oct8ne.com *.googletagmanager.com * *.cookiebot.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.yotpo.com https://www.youtube.com https://form.typeform.com *.hipay-tpp.com *.hipay.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.trustedshops.com *.bynder.com *.visualwebsiteoptimizer.com *.amazonaws.com *.atida.com *.dosfarma.com *.facebook.com *.zenaps.com *.awin1.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co t.co *.twitter.co *.twitter.com *.cloudfront.net *.doubleclick.net *.byspotify.com *.cookiebot.com *.googlesyndication.com *.syndigo.com *.assets.efarma.com *.mifarma.co.uk *.adscale.de *.usercentrics.eu cm.g.doubleclick.net r.casalemedia.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com *.pubmatic.com pixel.rubiconproject.com *.rubiconproject.com rtb-csync.smartadserver.com *.smartadserver.com criteo-sync.teads.tv *.teads.tv criteo-partners.tremorhub.com *.tremorhub.com eb2.3lift.com *.3lift.com ad.yieldlab.net *.yieldlab.net sync.1rx.io *.1rx.io *.criteo.com *.criteo.net *.consentcdn.cookiebot.eu *.atida.fr openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://cdn.clerk.io *.ggpht https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com polyfill.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.trustedshops.com *.clerk.io *.cloudfront.net *.zdassets.com *.zendesk.com *.api.smooch.io *.visualwebsiteoptimizer.com *.connectif.cloud *.atida.com *.dosfarma.com *.newrelic.com *.nr-data.net *.dwin1.com *.pinimg.com *.ads-twitter.com *.tiktok.com *.kk-resources.com *.bing.com *.creativecdn.com *.facebook.net *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.pinterest.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.cookiebot.eu *.clarity.ms *.roeyecdn.com *.cdn-apple.com *.lyra.com *.skeepers.io *.criteo.com static.ads-twitter.com connect.facebook.net tags.creativecdn.com *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.static.cloudflareinsights.com static.cloudflareinsights.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com https://api.clerk.io https://cdn.clerk.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.plugins.emarsys.net *.scarabresearch.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.trustedshops.com *.cloudflare.com *.googletagmanager.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.consentcdn.cookiebot.eu unsafe-inline assets.braintreegateway.com https://api.clerk.io https://cdn.clerk.io https://fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.hipay.com https://static.lyra.com/static/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.google.com/pay *.api.smooch.io *.zdassets.com *.zendesk.com *.connectif.cloud *.atida.com *.dosfarma.com *.algolia.io *.cookiebot.com *.nr-data.net google.com *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.spotify.com *.criteo.com *.criteo.net ct.pinterest.com *.clarity.ms ad.doubleclick.net googleads.g.doubleclick.net consent.cookiebot.eu *.cookiebot.eu *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.amazonaws.com pay.google.com *.pay.google.com *.cdn.scalapay.com cdn.scalapay.com pixels.spotify.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com https://ws.colissimo.fr https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.scarabresearch.com *.eservice.emarsys.net *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com data: *.bic.com *.shopbic.com *.bazaarvoice.com *.googleusercontent.com *.slant.co *.aws.projects.clever-age.net *.fontawesome.com fonts.googleapis.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.facebook.com *.wlp-acs.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.bic.com *.shopbic.com *.adsrvr.org *.amazon-adsystem.com *.criteo.com *.doubleclick.net *.googletagmanager.com *.pinterest.com *.sitescout.com *.snapchat.com *.tradedoubler.com *.wlp-acs.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.adsrvr.org *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googlesyndication.com *.googletagmanager.com *.googleusercontent.com *.ipredictive.com *.linkedin.com *.outbrain.com *.privacy-center.org *.sitescout.com *.tiktok.com s3.amazonaws.com www.google.ca www.google.es www.google.fr www.google.it www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.abtasty.com *.adsrvr.org *.amazon-adsystem.com *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.googlesyndication.com *.googletagmanager.com *.licdn.com *.noibu.com *.outbrain.com *.pinimg.com *.pinterest.com *.pixel.ad *.privacy-center.org *.skeepers.io *.snapchat.com *.tiktok.com sc-static.net targetemsecure.blob.core.windows.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.certcapture.com display.ugc.bazaarvoice.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.bazaarvoice.com *.googletagmanager.com *.typekit.net *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bic.com *.shopbic.com *.bing.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.abtasty.com *.adsrvr.org *.amazon-adsystem.com *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.com *.doubleclick.net *.facebook.com *.google-analytics.com *.googlesyndication.com *.gstatic.com *.linkedin.com *.noibu.com *.outbrain.com *.paa-reporting-advertising.amazon *.pinterest.com *.privacy-center.org *.samsung.com *.skeepers.io *.slgnt.eu *.snapchat.com *.tiktok.com *.typekit.net www.google.ca www.google.es www.google.fr www.google.it www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.bic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b5d2d853-cb54-412f-93ec-9e1c49a8e581.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com *.plex.com web-sdk.aptrinsic.com; style-src 'report-sample' 'self' data: 'unsafe-inline' ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com *.plex.com web-sdk.aptrinsic.com; img-src 'self' data: ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com www.gstatic.com 127.0.0.1:18623 *.plex.com; font-src 'self' *.plex.com data: *.plexus-online.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.plexonline.com at.alicdn.com use.typekit.net; connect-src 'self' web-sdk.aptrinsic.com esp.aptrinsic.com *.plex.com pcn-move.plexdev.io cdnma.cdnservice.space cdnma.global-cache.online cdnmb.global-cache.online 127.0.0.1:18623 js.authorize.net tablet.sigwebtablet.com:47290; media-src 'self' *.plex.com; object-src 'self'; child-src 'self'; frame-src 'self'; worker-src 'self'; frame-ancestors 'self' www.plexonline.com www.plexus-online.com; form-action 'self' *.plexus-online.com *.plexonline.com *.plex.com; base-uri 'self'; manifest-src 'self'; script-src-elem 'self' 'unsafe-inline' web-sdk.aptrinsic.com www.gstatic.com *.plexonline.com *.plex.com js.authorize.net jstest.authorize.net *.google-analytics.com www.pagespeed-mod.com *.plexus-online.com www.gstatic.com; style-src-elem 'unsafe-inline' *.plexonline.com web-sdk.aptrinsic.com www.gstatic.com maxcdn.bootstrapcdn.com *.plex.com *.plexus-online.com; report-uri https://csp.security.plex.com/csp/reporting 1 default-src 'self' www.google-analytics.com www.youtube.com cdn.cookielaw.org *.onetrust.com *.gstatic.com *.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com cdn.jsdelivr.net cdn.cookielaw.org img03.en25.com *.youtube.com *.google.com *.gstatic.com *.google-analytics.com embed.vev.page *.vev.design *.googleapis.com discover.hdrinc.com *.cloudflare.com unpkg.com; style-src 'self' 'unsafe-inline' cloud.typography.com cdn.jsdelivr.net *.googleapis.com www.hdrinc.com unpkg.com *.cloudflare.com; img-src 'self' data: *; media-src film.vev.design cdn.vev.design; frame-src 'self' *.google.com *.youtube.com *.vimeo.com discover.hdrinc.com *.doubleclick.net player.blubrry.com e.issuu.com caupneif01 *.youtube-nocookie.com *.googletagmanager.com *.cloudflare.com; child-src 'self' *.google.com *.youtube.com; font-src 'self' data: cloud.typography.com cdn.vev.design *.gstatic.com www.hdrinc.com cdn.scite.ai use.typekit.net fonts.vev.design; connect-src 'self' *.googleapis.com *.google-analytics.com *.cookielaw.org *.onetrust.com analytics.google.com *.doubleclick.net region1.analytics.google.com *.google.com *.gstatic.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com bonialconnect.com *.oney.io assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/static/ 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de secure.ogone.com v1-sim.preprod.psp-solutions.com v2-sim.preprod.psp-solutions.com www.facebook.com/tr/ bpcepaymentservices-3ds-vdm.wlp-acs.com bnpp-3ds-vdm.wlp-acs.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ https://epaync.nc/static/ https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com secure.ogone.com ogone.test.v-psp.com widget.trustpilot.com gum.criteo.com s.salecycle.com https://10766555.fls.doubleclick.net/ static.criteo.net/ www.facebook.com/ magasins.bureau-vallee.fr magasins.bureau-vallee.be magasins.bureau-vallee.nc magasins.bureau-vallee.re magasins.bureau-vallee.gf magasins.bureau-vallee.yt magasins.bureau-vallee.gp magasins.bureau-vallee.sx t.clic2buy.com bpcepaymentservices-3ds-vdm.wlp-acs.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io td.doubleclick.net https://epaync.nc/vads-payment/ https://epaync.nc/static/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org bva-preprod-fbi-fr-media-s3.s3.amazonaws.com bva-recette-fbi-fr-media-s3.s3.amazonaws.com bv-prd-fbi-fr-media.s3.eu-west-3.amazonaws.com bv-prd-fbi-fr-media.s3.amazonaws.com d2hlj6xfalexml.cloudfront.net d3n1o8ch79p937.cloudfront.net dxbyzx5id4chj.cloudfront.net bonialconnect.com content-media.bonial.biz rum-metrics.quanta.io bat.bing.com ib.adnxs.com www.facebook.com cm.g.doubleclick.net gum.criteo.com dis.criteo.com sync-t1.taboola.com x.bidswitch.net r.casalemedia.com ad.360yield.com contextual.media.net sync.outbrain.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com criteo-sync.teads.tv eb2.3lift.com ups.analytics.yahoo.com e1.emxdgt.com cm.adform.net visitor.omnitagjs.com id5-sync.com matching.ivitrack.com exchange.mediavine.com simage2.pubmatic.com criteo-partners.tremorhub.com ad.yieldlab.net sync-criteo.ads.yieldmo.com beacon.krxd.net s.thebrighttag.com www.bureau-vallee.fr www.google.fr bvci-e2.colop.com utypia.bureau-vallee.fr *.oney.io assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io www.gstatic.com jadserve.postrelease.com ad.doubleclick.net public-prod-dspcookiematching.dmxleo.com https://epaync.nc/static/latest/images/type-carte/ https://epaync.nc/static/ https://epaync.nc/vads-payment/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://assets.fintecture.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magasins.bureau-vallee.fr widget.trustpilot.com bonialconnect.com s3.amazonaws.com maps.googleapis.com/ d16fk4ms6rqz1v.cloudfront.net bat.bing.com appstatic.quanta.io try.abtasty.com acdn.adnxs.com static.criteo.net sslwidget.criteo.com connect.facebook.net cdn.jsdelivr.net static.target2sell.com js-agent.newrelic.com/ bam.eu01.nr-data.net *.oney.io magasins.bureau-vallee.be magasins.bureau-vallee.nc magasins.bureau-vallee.re magasins.bureau-vallee.gf magasins.bureau-vallee.yt magasins.bureau-vallee.gp magasins.bureau-vallee.sx rs.clic2buy.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io pagead2.googlesyndication.com tpc.googlesyndication.com *.algolia.io https://epaync.nc/api-payment/ https://epaync.nc/static/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ assets-staging.oney.io *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/static/ *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src pay.google.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com s3.eu-west-1.amazonaws.com www.bonialserviceswidget.de maps.googleapis.com trackingapi.bonial.fr bonialconnect.com dcinfos-cache.abtasty.com ariane.abtasty.com c.salecycle.com api.ipify.org i.salecycle.com wss://ws.salecycle.com/ region1.analytics.google.com www.facebook.com serv-api.target2sell.com bat.bing.com/actionp/ rum-metrics.quanta.io reco.target2sell.com bam.eu01.nr-data.net www.google.fr *.oney.io autocomplete.geocoder.api.here.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io try.abtasty.com pagead2.googlesyndication.com measurement-api.criteo.com apigw-cf.bva-integ-web.decade.fr https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ bva-recette-impression-s3.s3.eu-west-3.amazonaws.com bva-preprod-impression-s3.s3.eu-west-3.amazonaws.com bva-prod-impression-s3.s3.eu-west-3.amazonaws.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ https://epaync.nc/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; frame-ancestors 'none'; base-uri 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.mercdn.net https://www.google.com https://*.adtrafficquality.google https://*.g.doubleclick.net https://analytics.tiktok.com https://b99.yahoo.co.jp https://bat.bing.com https://*.smartnews-ads.com https://connect.facebook.net https://ct.pinterest.com https://d.line-scdn.net https://dmp.im-apps.net https://dynamic.criteo.com https://h.accesstrade.net https://s.pinimg.com https://s.yimg.jp https://*.criteo.com https://static.ads-twitter.com https://statics.a8.net https://*.blob.core.windows.net https://trj.valuecommerce.com https://*.google-analytics.com; style-src 'self' 'unsafe-inline' https://*.mercdn.net https://fonts.googleapis.com; font-src https://fonts.gstatic.com; 1 default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://webcachex-eu.datareporter.eu; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org blob: https://youtube.com https://*.youtube.com https://liwest.at/ https://*.liwest.at/ https://*.hubspot.com https://www.facebook.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://px.ads.linkedin.com *.px.ads.linkedin.com https://*.hsforms.com https://alb.reddit.com bat.bing.com https://www.google.at https://www.google.de https://www.googletagmanager.com https://maps.wien.gv.at https://fonts.gstatic.com https://webcache-eu.datareporter.eu https://maps.googleapis.com https://www.econda-monitor.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://*.frcapi.com/ https://*.liwest.at/ https://liwest-penalty-shootout.supernice.games https://liwest-qots.web.app https://liwest-tron.web.app https://*.google.com https://liwest-spendenaktion.web.app https://www.googletagmanager.com https://liwest.speedtestcustom.com https://forms-eu1.hsforms.com; connect-src 'self' data: https://*.openstreetmap.org https://*.friendlycaptcha.eu https://*.datareporter.eu https://*.hsforms.com https://hubspot-forms-static-embed-eu1.s3.amazonaws.com https://*.econda-monitor.de https://px.ads.linkedin.com https://analytics.tiktok.com https://*.hubapi.com https://bat.bing.com https://bat.bing.net https://*.hubspot.com https://pixel-config.reddit.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://pixels.spotify.com https://*.etracker.com https://*.etracker.de https://analytics-ipv6.tiktokw.us https://www.google.com https://l.ecn-ldr.de https://www.facebook.com https://connect.facebook.net https://maps.wien.gv.at https://api.opendkm.at https://static.hsappstatic.net https://www.googletagmanager.com https://api.ipgeolocation.io https://srv.doris.at https://maps.googleapis.com; script-src-elem 'self' 'report-sample' 'unsafe-inline' inline https://youtube.com https://*.youtube.com https://*.datareporter.eu https://*.webcachex-eu.datareporter.eu https://cdnjs.cloudflare.com https://*.googletagmanager.com https://*.hsforms.net https://*.vimeo.com https://tracknet.twyn.com https://l.ecn-ldr.de https://api.ipify.org https://connect.facebook.net https://bat.bing.com https://analytics.tiktok.com https://js-eu1.hsadspixel.net https://googleads.g.doubleclick.net https://*.etracker.com https://*.etracker.de https://pixel.byspotify.com https://js-eu1.hs-scripts.com https://js-eu1.hs-banner.com https://static.hsappstatic.net https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.net https://js-eu1.hubspot.com https://snap.licdn.com https://www.redditstatic.com https://maps.googleapis.com; style-src 'self' 'report-sample' https://*.datareporter.eu; worker-src blob: 'report-sample'; font-src 'self' data: https://fonts.gstatic.com; style-src-elem 'self' 'report-sample' 'unsafe-inline' inline https://webcache.datareporter.eu https://webcache-eu.datareporter.eu https://fonts.googleapis.com https://fonts.gstatic.com https://www.googletagmanager.com; report-uri https://www.liwest.at/@http-reporting?csp=report&requestTime=1765935236858974&requestHash=aa39b76438d74afee5eebe705bba99f2c98d04b3 1 default-src 'self' https: data: streamable.com; www.youtube.com; script-src 'none' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https: www.googletagmanager.com; www.youtube.com;; style-src-elem 'self' 'unsafe-inline' https: cdn.lineicons.com; fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline' https:; img-src 'self' https: data: cmefnbespa.cloudimg.io; forms-eu1.hsforms.com;; connect-src 'self' 'none' https: data: www.google.com; forms-eu1.hsforms.com; forms-eu1.hscollectedforms.net; text/plain; media-src 'self' https: www.youtube.com; frame-src 'self' https: www.youtube.com; streamable.com; www.google.com; sandbox allow-same-origin 1 font-src fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ www.facebook.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * api.razorpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com *.googletagmanager.com *.google.co.in www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ connect.facebook.net tpc.googlesyndication.com www.google.com www.google.co.in www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com stats.g.doubleclick.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com lumberjack-cx.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' data: 'self' blob: *.cloudmaestro.com backend.yoogiscloset.com frontend.yoogiscloset.com js-agent.newrelic.com *.nr-data.net backend.yoogiscloset.com frontend.yoogiscloset.com www.yoogiscloset.com xdymhcopnh.execute-api.us-east-1.amazonaws.com knrpc.olark.com www.googletagmanager.com www.googleadservices.com ajax.googleapis.com apis.google.com connect.facebook.net static.olark.com *.google-analytics.com *.listrakbi.com *.static.olark.com *.affirm.com *.firebaseapp.com *.lightwidget.com *.adroll.com *.bing.com *.doubleclick.net *.trustpilot.com storage.googleapis.com api.olark.com *.googleapis.com *.sharethis.com *.clarity.ms www.clarity.ms *.api.olark.com www.google.com connect.facebook.com www.facebook.com *.paypal.com *.paypalobjects.com www.recaptcha.net www.gstatic.com accounts.google.com; report-uri /.webscale/csp-report 1 form-action 'self'; frame-src 'none'; frame-ancestors 'self'; report-uri https://sentry.it.uwosh.edu/api/3/security/?sentry_key=a83fa724347d841bd65fdab57f19925a; report-to csp-endpoint 1 font-src *.klevu.com *.ksearchnet.com *.gstatic.com https://fonts.gstatic.com *.fontawesome.com fonts.gstatic.com https://pos.snapscan.io *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://sandbox.payfast.co.za https://www.payfast.co.za/eng/process oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; style-src *.adobe.com *.klevu.com *.ksearchnet.com *.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src *.google-analytics.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com https://ipinfo.io *.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.paypal.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; frame-src data:text fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src *.criteo.com *.krxd.net *.chatlayer.ai assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.ksearchnet.com *.google.com *.gstatic.com https://*.googleapis.com https://*.googleusercontent.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com https://pos.snapscan.io *.cloudflare.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src *.incredible.co.za *.chatlayer.ai assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com *.klevu.com *.ksearchnet.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 script-src 'nonce-wmBzE0WmaWVhs8n685Ebwg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 base-uri 'self'; connect-src 'self' https://*.fontawesome.com/ https://*.formassembly.com/ https://*.promedica.app/ https://*.vercel-storage.com/ https://*.vercel.app/ https://analytics.google.com/ https://api.stadiamaps.com/ https://cdn.cookielaw.org/ https://cm.pmdt-jss.localhost/ https://maps.googleapis.com/ https://mc-3f4459e6-26cc-45d7-95b4-1637-cd.azurewebsites.net/ https://mc-d506a988-cc64-4e20-af8c-4606-afd.azurefd.net/ https://pagead2.googlesyndication.com/ https://pcl-staging.promedica.org/ https://pcl.promedica.org/ https://promedica.matomo.cloud/ https://siteintercept.qualtrics.com/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/; default-src 'self' https://*.promedica.app/ https://*.vercel.app/; font-src 'self' data: https://*.fontawesome.com/ https://*.promedica.app/ https://*.vercel.app/ https://fonts.gstatic.com/ https://use.typekit.net/; frame-src 'self' https://td.doubleclick.net/ https://www.google.com/ https://www.youtube.com/; img-src 'self' data: http://dummyimage.com https://*.promedica.app https://*.qualtrics.com https://*.vercel.app https://cdn.cookielaw.org https://maps.googleapis.com https://maps.gstatic.com https://mc-3f4459e6-26cc-45d7-95b4-1637-cd.azurewebsites.net https://mc-d506a988-cc64-4e20-af8c-4606-afd.azurefd.net https://pcl-staging.promedica.org https://pcl.promedica.org https://www.google-analytics.com https://www.google.com.ec https://www.google.com https://www.googletagmanager.com; manifest-src 'self'; media-src 'self' data: https://pcl.promedica.org/ https://pcl-staging.promedica.org/; object-src 'none'; report-uri https://6480f3f9bf4bdd8c5cde6f2b.endpoint.csper.io/?v=1; script-src 'unsafe-inline' 'unsafe-eval' 'report-sample' 'self' https://*.promedica.app/ https://*.vercel.app/ https://cdn.cookielaw.org/ https://cdn.matomo.cloud/ https://cdn.mouseflow.com/ https://googleads.g.doubleclick.net/ https://kit.fontawesome.com/ https://maps.googleapis.com/ https://promedica.tfaforms.net/ https://siteintercept.qualtrics.com/ https://unpkg.com/ https://www.google-analytics.com/ https://www.google.com/recaptcha/ https://www.googletagmanager.com/ https://www.gstatic.com/ https://www.youtube.com/ https://zn86cv25rplysllsr-promedica.siteintercept.qualtrics.com/SIE/; style-src 'report-sample' 'unsafe-inline' 'self' https://*.promedica.app/ https://*.vercel.app/ https://fonts.googleapis.com/ https://promedica.tfaforms.net/; worker-src 'self' blob: 1 default-src 'self' http: filesystem: https://*-c2es.pantheonsite.io/ https://c2es.ddev.site https://*.addthis.com https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: filesystem: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.addthis.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://*.addthisedge.com https://cdnjs.cloudflare.com; style-src 'unsafe-inline' http: filesystem: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com; img-src 'self' http: data: filesystem: https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com; connect-src 'self' filesystem: https://*.google-analytics.com https://*.bookingbug.com https://geolocation.onetrust.com https://*.cookielaw.org https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com *.addtoany.com; font-src 'self' data: filesystem: fonts.gstatic.com use.typekit.net use.fontawesome.com bespoke.bookingbug.com; media-src 'self' filesystem: *.youtube.com *.vimeo.com *.akamaized.net; report-uri 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'self'; frame-src 'self'; worker-src 'self'; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; upgrade-insecure-requests 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' api.42chat.com *.api.42chat.com ads.aae.org *.ads.aae.org www.actox.org *.www.actox.org adobedtm.com *.adobedtm.com adroll.com *.adroll.com ads-twitter.com *.ads-twitter.com adtrafficquality.google *.adtrafficquality.google ajax.googleapis.com *.ajax.googleapis.com chatbase.co *.chatbase.co clarity.ms *.clarity.ms doubleclick.net *.doubleclick.net cookiebot.com *.cookiebot.com eventscribe.net *.eventscribe.net facebook.net *.facebook.net feathr.co *.feathr.co google-analytics.com *.google-analytics.com google.com *.google.com googleadservices.com *.googleadservices.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com hotjar.com *.hotjar.com licdn.com *.licdn.com logwork.com *.logwork.com magnetmail.net *.magnetmail.net marketo.net *.marketo.net mycadmium.com *.mycadmium.com osano.com *.osano.com realmagnet.land *.realmagnet.land revive-adserver.net *.revive-adserver.net scriptcdn.net *.scriptcdn.net snapengage.com *.snapengage.com snoball.it *.snoball.it stackadapt.com *.stackadapt.com storage.googleapis.com *.storage.googleapis.com pages.thenationalcouncil.org *.pages.thenationalcouncil.org www.tickcounter.com *.www.tickcounter.com translate.googleapis.com *.translate.googleapis.com twitter.com *.twitter.com unpkg.com *.unpkg.com vimeo.com *.vimeo.com youtube.com *.youtube.com zdassets.com *.zdassets.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=oIiDtr7gnA10o.BFh1GgYvkxvZaNjcKzo8SzDwh0q2A-1765939463.411004-1.0.1.1-CekYawtp2U8mQWUxkW17tiB49TxFZwfsKdVbccRZaeghPr_79T0Trn8wAvbjldWJSRLidsmjT1IYjH6Zf5g1c7V3_JUV0E.aivVvlLfwP4LSy2P8XiUm1J2TMaNy_ICOkfN6jlM99T2iqs.wo0S5RR6UJ_.8LJ7zLJZcmbT2ULiMkIlXq4iuq2nTyFut.pRiguZYPKwG9en1DgXNkd34Qg; report-to cf-nitwnsrsadfshnan 1 script-src 'nonce-v0T+RxMcFaD39GcOSFjTMA==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=ec88b057-e0d3-4292-8409-e90138af6aca; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 frame-ancestors 'self' https://*.jobcloud.ch https://*.jobs.ch https://*.jobup.ch; base-uri 'self'; connect-src * data: 'self'; default-src 'self' https:; font-src 'self' https: data:; form-action 'self'; frame-src 'self' https:; img-src * data: blob: 'self'; manifest-src 'self'; media-src 'self'; object-src 'self'; script-src 'self' https: * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; require-trusted-types-for 'script'; worker-src 'self' 1 frame-ancestors 'self' https://*.mastercontrol.com mastercontrol.service-now.com; object-src 'none'; form-action 'self' https://*.mastercontrol.com *.rise.com *.service-now.com mastercontrol.influitive.com gateway.zscloud.net mastercontrol.uservoice.com https://*.facebook.com https://connect.facebook.net; base-uri 'self' https://*.mastercontrol.com https://*.clarity.ms; report-uri https://reportcsp.azurewebsites.net/api/CSPViolation 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-09ngXdy14HfGX3QbH/JtHA==' 1 default-src 'self'; style-src 'self' 'unsafe-inline' googletagmanager.com tagmanager.google.com fonts.googleapis.com; script-src 'self' www.google.com *.googletagmanager.com *.gstatic.com; img-src 'self' googletagmanager.com *.gstatic.com * data:; frame-src 'self' www.youtube.com www.google.com blob:;frame-ancestors 'none'; form-action 'self'; font-src 'self' fonts.gstatic.com data:; connect-src 'self' *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.com 1 upgrade-insecure-requests; default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://accessibilityserver.org https://amplify.outbrain.com https://bam.nr-data.net https://bat.bing.com https://c.lytics.io https://cdn.segment.com https://cdn.taboola.com https://cdn.userway.org https://connect.facebook.net https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://platform.twitter.com https://qmod.quotemedia.com https://s.yimg.com https://script.hotjar.com https://securepubads.g.doubleclick.net https://sslwidget.criteo.com https://static.ads-twitter.com https://static.criteo.net https://static.hotjar.com https://tr.outbrain.com https://trc.taboola.com https://www.dwin1.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googletagservices.com https://www.redditstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://c.lytics.io https://cdnjs.cloudflare.com https://fonts.googleapis.com https://qmod.quotemedia.com https://static.c1.quotemedia.com; img-src 'self' data: https://alb.reddit.com https://analytics.twitter.com https://bat.bing.com https://c.lytics.io https://cdn.userway.org https://data.dianomi.com https://pagead2.googlesyndication.com https://pubads.g.doubleclick.net https://q.quora.com https://secure.gravatar.com https://sp.analytics.yahoo.com https://syndication.twitter.com https://t.co https://tr.outbrain.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.quotemedia.com; connect-src 'self' https://api.segment.io https://api.userway.org https://app.quotemedia.com https://bam.nr-data.net https://ca.foolpitches.com https://cdn.segment.com https://cdn.userway.org https://cds.taboola.com https://csi.gstatic.com https://in.hotjar.com https://pips.taboola.com https://s.yimg.com https://securepubads.g.doubleclick.net https://stats.g.doubleclick.net https://to.getnitropack.com https://trc-events.taboola.com https://vc.hotjar.io https://www.google-analytics.com; font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com https://static.c1.quotemedia.com; frame-src https://gum.criteo.com https://platform.twitter.com https://syndication.twitter.com https://www.facebook.com; report-uri https://csp.feroot.com/a5814c59-63d2-4c2f-8d39-70a4fbe37b03/a068f8b4-0865-4c32-bd31-375a39409b87/collect; 1 default-src 'self' blob: *.senado.gov.br *.senado.leg.br;script-src 'self' 'unsafe-eval' 'unsafe-inline' *.senado.gov.br *.senado.leg.br *.youtube.com *.google-analytics.com www.googletagmanager.com vlibras.gov.br ajax.googleapis.com www.gstatic.com;img-src 'self' data: blob: *.senado.gov.br *.senado.leg.br *.ytimg.com *.google-analytics.com *.googletagmanager.com *.youtube.com *.gstatic.com vlibras.gov.br;connect-src 'self' *.senado.gov.br *.senado.leg.br vlibras.gov.br *.vlibras.gov.br www.google-analytics.com www.googletagmanager.com;font-src 'self' data: vlibras.gov.br cdnjs.cloudflare.com fonts.gstatic.com;style-src 'self' 'unsafe-inline' *.senado.gov.br *.senado.leg.br cdnjs.cloudflare.com fonts.googleapis.com;worker-src blob: *.senado.leg.br *.senado.gov.br;object-src 'none';frame-src 'self' *.senado.gov.br *.senado.leg.br *.youtube.com www.youtube-nocookie.com;base-uri 'self';frame-ancestors 'self' *.senado.gov.br *.senado.leg.br 1 base-uri 'self';connect-src 'self' https: wss:;default-src 'none';font-src 'self' data: https:;form-action 'self' https:;frame-ancestors https:;frame-src https: blob:;img-src 'self' blob: data: https: http:;manifest-src 'none';media-src 'self' https: blob:;object-src 'self' https://djtflbt20bdde.cloudfront.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' https:;worker-src 'self' https://zenkit.com https://*.zenkit.com;report-uri /csp-report;script-src-attr 'none';style-src 'self' https: 'unsafe-inline' 1 frame-ancestors 'self' https://www.nwcg.gov 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bing.com *.google-analytics.com *.googleadservices.com *.google.co.uk *.googletagmanager.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.feefo.com *.adobedtm.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.ometria.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com *.pbffinancecalculator.info cdn.shopify.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.bing.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.googleapis.com expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.noibu.com https://www.noibu.com https://cdn.noibu.com *.facebook.net https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://api.ometria.com *.dixa.io x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.ometria.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.bing.com *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com maps.googleapis.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.advancedcommerce.services https://cdn.noibu.com wss://input.noibu.com https://input.noibu.com *.noibu.com *.facebook.net https://cdn.jsdelivr.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://api.ometria.com *.dixa.io x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io *.staging-pbffinancecalculator.info *.pbffinancecalculator.info wss://*.staging-pbffinancecalculator.info wss://*.pbffinancecalculator.info *.paybyfinance.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' * 'unsafe-inline' 'unsafe-eval' data:; connect-src 'self' https://adservice.google.com https://adservice.google.com/pagead/regclk https://analytics.google.com https://analytics.google.com/g/collect https://analytics.pangle-ads.com https://analytics.pangle-ads.com/api/v2/pangle_pixel https://analytics.tiktok.com https://analytics.tiktok.com/api/v2/pixel https://analytics.tiktok.com/api/v2/pixel/act https://api.ipify.org https://api.ipify.org/ https://api.mercadolibre.com https://api.mercadopago.com https://api.mundipagg.com https://api.siteblindado.com https://api.voxus.tv https://api.voxus.tv/verify/ https://checkip.amazonaws.com https://checkip.amazonaws.com/ https://ct.pinterest.com https://events.mercadopago.com https://logs-01.loggly.com https://maps.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://region1.analytics.google.com https://region1.google-analytics.com https://region1.google-analytics.com/g/collect https://seal.siteblindado.com https://stats.g.doubleclick.net https://stats.g.doubleclick.net/j/collect https://stats.g.doubleclick.net/g/collect https://tagging.betocarrero.com.br https://tagging.betocarrero.com.br/fcp https://targeting.voxus.com.br https://targeting.voxus.com.br/v/ https://translate-pa.googleapis.com https://translate.google.com https://translate.googleapis.com https://translation-v3.handtalk.me https://us.creativecdn.com https://us.creativecdn.com/tags/v2 https://web.facebook.com https://www.betocarrero.com.br https://www.facebook.com https://www.facebook.com/tr https://www.google-analytics.com https://www.google-analytics.com/g/collect https://www.google-analytics.com/j/collect https://www.googletagmanager.com/a https://www.google.com https://www.mercadolibre.com https://clientstream.launchdarkly.com https://logs-01.loggly.com https://logs-01.loggly.com/inputs/27cf9a30-eb89-41a7-ba82-3280d33fb2cf/tag/https/; report-to default; 1 object-src 'none';base-uri 'self';script-src 'nonce-VccKNyTFLSTCiXQeQ6+W' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' *.buzzsprout.com *.cookielaw.org *.getblueshift.com *.onetrust.org *.typekit.net *.vercel-scripts.com bat.bing.com connect.facebook.net static.hotjar.com script.hotjar.com vercel.live *.chatbot.com *.clarity.ms crux-api-onerhino.vercel.app unpkg.com cwv.onerhino.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net;style-src 'self' 'unsafe-inline' *.typekit.net vercel.live;img-src 'self' blob: data: *.buzzsprout.com *.cookielaw.org *.ctfassets.net *.facebook.com *.internationalliving.com *.nodebb.com *.youtube.com *.ytimg.com *.vercel.com vercel.com *.bing.com *.clarity.ms https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat;connect-src wss://*.pusher.com 'self' *.cookielaw.org api.getblueshift.com *.onetrust.com *.hotjar.io vercel.live *.chatbot.com bat.bing.com *.clarity.ms crux-api.vercel.app https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat;font-src 'self' *.typekit.net vercel.live;frame-src 'self' *.buzzsprout.com *.typeform.com *.youtube-nocookie.com *.youtube.com fast.wistia.net player.vimeo.com td.doubleclick.net vimeo.com vercel.live *.chatbot.com *.googletagmanager.com;object-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'none' 1 default-src https: 'unsafe-inline' 'unsafe-eval' 1 default-src 'none';script-src 'nonce-31900192-c622-4fe3-b9fd-a93311205bb9' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.bingo.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.bingo.com/eum-collector/report/csp-report; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' https://managewp.com https://orion.managewp.com https://s42013.pcdn.co https://db0hcalplzljl.cloudfront.net/ https://*.google.com api.w.org https://*.googleapis.com ogp.me https://www.facebook.com *.google-analytics.com api.w.org *.googletagmanager.com tags.tiqcdn.com use.typekit.net s.w.org https://secure.gravatar.com https://connect.facebook.net https://p.typekit.net https://www.googleadservices.com https://fonts.gstatic.com https://www.gstatic.com https://*.g.doubleclick.net https://player.vimeo.com https://*.youtube.com https://*.youtube-nocookie.com https://*.googlevideo.com https://*.ytimg.com data:; img-src * data:; object-src 'none'; 1 font-src *.googleapis.com *.gstatic.com data: *.cloudflare.com *.typekit.net *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.superoffice.com *.addthis.com *.google.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.gstatic.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.google-analytics.com *.google.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-de3cf966-4a65-4089-9693-6b567c38c6f0' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.nl https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.nl/eum-collector/report/csp-report; 1 default-src 'self' disqo.okta.com *.oktacdn.com; connect-src 'self' disqo.okta.com disqo-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com disqo.kerberos.okta.com disqo.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-7R5e76lwFdXs6HDKYvWEaQ' 'unsafe-eval' 'self' 'report-sample' disqo.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-7R5e76lwFdXs6HDKYvWEaQ' 'self' 'report-sample' disqo.okta.com *.oktacdn.com; frame-src 'self' disqo.okta.com disqo-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' disqo.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' disqo.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://www.disqotech.com 1 default-src * data: 'unsafe-inline' 1 default-src 'self'; base-uri 'none'; object-src 'none'; form-action https:; img-src 'self' https: data: blob:; font-src 'self' https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https: data: blob:; media-src 'self' https: data:; worker-src 'self' blob:; frame-src https:; manifest-src 'self' https:; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * https://*.contentsquare.net https://*.contentsquare.com https://analytics.tiktok.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.googleapis.com https://*.gstatic.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://*.contentsquare.net https://*.contentsquare.com https://www.google.nl https://www.google.de https://bat.bing.com https://match.sharethrough.com https://cm.g.doubleclick.net https://criteo-partners.tremorhub.com https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://ad.yieldlab.net https://ps.eyeota.net https://exchange.mediavine.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://eb2.3lift.com https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://dis.criteo.com https://sync.1rx.io https://analytics.tiktok.com https://*.reskyt.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://rum.hlx.page https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.googleapis.com https://*.gstatic.com *.getflowbox.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com connect.getflowbox.com t.contentsquare.net static.hotjar.com https://*.contentsquare.net https://app.contentsquare.com https://*.cookiefirst.com https://*.noibu.com https://cdn-4.convertexperiments.com https://s.pinimg.com https://static.criteo.net https://www.dwin1.com https://bat.bing.com https://ct.pinterest.com https://cdn.watchtower.graindata.com https://script.hotjar.com https://lantern.roeyecdn.com https://sslwidget.criteo.com https://cdn.segmentify.com https://*.prenatal.nl https://analytics.tiktok.com https://*.reskyt.com https://app.aiden.cx 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://*.cookiefirst.com https://cdn.segmentify.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com https://*.google.com payments-eu.amazon.com *.googleapis.com *.getflowbox.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://*.contentsquare.net https://*.contentsquare.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.cookiefirst.com https://pipeline.prenatal.nl https://region1.google-analytics.com https://www.google.nl https://ct.pinterest.com https://measurement-api.criteo.com https://vc.hotjar.io https://gandalf-eu.segmentify.com https://*.convertexperiments.com https://*.noibu.com https://analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blob: http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://*.cru.org; connect-src https://*.cru.org https://universal-editor-service.adobe.io https://*.adobeaemcloud.com https://*.adtrafficquality.google https://cru-content-based-filtering-prod.s3.amazonaws.com https://cru-content-based-filtering-stage.s3.amazonaws.com https://lq3-production.s3.amazonaws.com https://cru.oktapreview.com https://signon.okta.com https://browser-intake-datadoghq.com https://api.rollbar.com https://bat.bing.com https://bat.bing.net https://*.clarity.ms https://d3hb14vkzrxvla.cloudfront.net https://cdn.cookielaw.org https://*.doubleclick.net https://*.facebook.com https://www.googleadservices.com https://*.google-analytics.com https://*.googlesyndication.com https://www.googletagmanager.com https://maps.googleapis.com https://*.google.com https://csi.gstatic.com https://*.kommunicate.io https://api.leadquizzes.com https://px.ads.linkedin.com https://*.onetrust.com https://*.optimizely.com https://ct.pinterest.com https://*.scene7.com https://capig.stape.biz https://t.co https://analytics.twitter.com https://api.typeform.com; font-src data: https://*.cru.org https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://use.typekit.net; frame-src https://*.cru.org https://static.addtoany.com https://*.adobeaemcloud.com https://*.adtrafficquality.google https://api.arclight.org https://bat.bing.com https://*.doubleclick.net https://*.facebook.com https://google.com https://*.google.com https://www.googletagmanager.com https://www.instagram.com https://content.leadquizzes.com https://cdn.lightwidget.com https://knowgod.com https://*.kommunicate.io https://your.nextstep.is https://*.spotify.com https://platform.twitter.com https://cru.oktapreview.com https://signon.okta.com https://*.optimizely.com https://ct.pinterest.com https://form.typeform.com https://player.vimeo.com https://my.visme.co https://www.youtube.com; img-src blob: data: *; media-src blob: data: *; object-src https://*.cru.org https://*.adobeaemcloud.com; script-src 'unsafe-eval' 'unsafe-inline' https://*.cru.org https://static.addtoany.com https://*.adtrafficquality.google https://static.ads-twitter.com/uwt.js https://universal-editor-service.adobe.io https://lq3-production.s3.amazonaws.com https://bat.bing.com https://maxcdn.bootstrapcdn.com https://*.clarity.ms https://cdnjs.cloudflare.com https://cdn.cookielaw.org https://*.doubleclick.net https://connect.facebook.com https://connect.facebook.net https://*.google.com https://www.googleadservices.com https://*.googleapis.com https://www.googletagmanager.com https://*.googlesyndication.com https://www.gstatic.com https://beacon-v2.helpscout.net https://www.instagram.com https://code.jquery.com https://cdn.jsdelivr.net https://snap.licdn.com https://cdn.lightwidget.com https://knowgod.com https://*.kommunicate.io https://global.oktacdn.com https://*.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://cdn.parsely.com https://s7d2.scene7.com https://platform.twitter.com https://embed.typeform.com https://use.typekit.net https://unpkg.com/@cruglobal/recommendations-component@1.0.7/dist/index.js https://player.vimeo.com https://static-bundles.visme.co https://www.youtube.com; style-src 'unsafe-inline' https://*.cru.org https://s3-us-west-2.amazonaws.com/lq3-production01/lead_quizzes_3.0/tracking/css/global-tracking.css https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://*.kommunicate.io https://cdn-images.mailchimp.com https://s7d2.scene7.com https://*.typekit.net https://embed.typeform.com https://unpkg.com/@cruglobal/cru-content-designs@1.1.0/cruorg/styles.css https://unpkg.com/swiper/swiper-bundle.min.css; worker-src blob:; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub78c844a77df2472307b237a306fd3ce4&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Acru-dot-org%2Cenv%3Aproduction%2Ccsp-revision%3A3; report-to csp-endpoint 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://f11bb21a156cd4e9e562bfa86fe76e9b.report-uri.com/r/d/csp/wizard 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' shop2gether.com.br *.shop2gether.com.br wake-components.fbitsstatic.net shop2gether.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gstatic.com *.fbits.store *.adyen.com *.criteo.com *.criteo.net *.g.doubleclick.net *.google.com.br *.googleadservices.com static.zdassets.com clarity.ms assets.zendesk.com *.creativecdn.com *.zdassets.com shop2gether.zendesk.com widget-mediator.zopim.com *.clarity.ms td.doubleclick.net icomm-public.s3.amazonaws.com *.pagar.me *.mundipagg.com *.getnet.com.br vm.icommgroup.com.br:3005 *.icommgroup.com.br:3005 *.icommgroup.com.br s3.sa-east-1.amazonaws.com *.sa-east-1.amazonaws.com *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.adyen.com *.pagbank.com *.infraicommgroup.com:3005 *.infraicommgroup.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br n8n.icommgroup.com.br *.azurewebsites.net *.hotjar.com *.fbits.net koin-custom-conector-gateway.fbits.net *.koin.com.br static.hotjar.com static.fbits.net payments.koin.com.br *.pinterest.com paypal-wake.s3.us-east-1.amazonaws.com *.useinsider.com *.api.useinsider.com nocodb.infraicommgroup.com:8080 nocodb.infraicommgroup.com *.cardinalcommerce.com *.secureacs.com *.crmbonus.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.varify.io *.3dsecure.io *.sizebay.technology *.wepowerconnections.com *.sciencebehindecommerce.com *.zenaps.com *.awin1.com *.dwin1.com recommendationv2.api.useinsider.com wake-commerce-scripts.omni.chat viacep.com.br nominatim.openstreetmap.org trackings.nemu.com.br openfpcdn.io api.ipify.org api.bigdatacloud.net firebase.googleapis.com cdn.jsdelivr.net appleid.cdn-apple.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.internalsizebay.com src.mastercard.com api.fpjs.io ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.shop2gether.com.br shop2gether.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 script-src https://cdn-0.d41.co/tags/dnb_coretag_v5.min.js https://paapi1216.d41.co/sync/ 'sha256-vfJmH9VV5/TIZcV1LacGamAqQVskmOlPUk2sFJhJ1kc=' 'sha256-OnbHkUv7xkXIlmKaiAuShhxmotWQ4Yp4OxfIFloom/4=' 'sha256-PWr/M9XdzJS0RewxUAUp2a/joE2J9AeGXwub45mZQV0=' https://cxppeur1rdrect01sa02cdn-endpoint.azureedge.net/webtracking/WebTracking/WebTracking.bundle.js 'sha256-dGlQuWQ9CmIqr5hI4Xz9kON7gb7axLZoc5MuRjYDaC8=' https://dntfctn.com/stm.js https://googletagmanager.com https://tagmanager.google.com https://googleads.g.doubleclick.net https://bat.bing.com https://connect.facebook.net https://snap.licdn.com https://cdn.stape.io https://www.google-analytics.com/analytics.js 'self' https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://maps.googleapis.com http://*.usercentrics.eu 'sha256-q5Vld0lrKcoaBkEcE38psSPC7zxpk57XkNVghK4RAFg=' 'wasm-unsafe-eval' https://*.dmgmori.com 'sha256-hkpdWJxIz/c3/6nIyqmzeRO9A3saSt1Xz2ex2UxcqJ4='; style-src 'self' 'unsafe-inline' https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; object-src 'none'; worker-src 'self' blob:; child-src 'self' blob: https://dmgmorib2ctest.b2clogin.com https://login.dmgmori.com https://login.microsoftonline.com https://device.login.microsoftonline.com https://login.windows.net https://bid.g.doubleclick.net https://td.doubleclick.net https://www.googletagmanager.com https://gtm.dmgmori.com https://www.facebook.com https://*.usercentrics.eu https://media.dmgmori.com https://www.youtube.com https://dmgmori.geovoile.com https://my.matterport.com https://dmgmori-library.tulipintra.net; report-uri /blueprint/servlet/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gls.com *.szybkapaczka.pl *.gls-poland.com/ https://*.easypack24.net https://fonts.bunny.net fonts.googleapis.com https://*.typekit.net https://font.static.useinsider.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ secure.payu.com merch-prod.snd.payu.com https://parcelshop.dhl.pl https://pudofinder.dpd.com.pl https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.gls-poland.com/ https://*.dpd.com.pl/ https://*.dpd.cz/ https://consentcdn.cookiebot.com https://*.livechatinc.com https://secure-fra.livechatinc.com https://creativecdn.com https://martes.api.useinsider.com https://ams.creativecdn.com https://*.doubleclick.net https://*.criteo.com https://martes.api.useinsider.com/ https://*.criteo.net https://www.facebook.com https://*.avin1.com https://*.packeta.com https://api.dpd.cz/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ static.payu.com https://*.sysadvisors.pl *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.gls-poland.com.pl/ https://*.easypack24.net https://*.inpost.pl https://trustmate.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com quickchart.io img.youtube.com https://fitanu.com https://*.paynow.pl https://*.cookiebot.com https://*.glami.pl https://*.bing.com https://google.pl https://*.useinsider.com https://*.google.pl https://log.api.useinsider.com https://*.adnxs.com https://cm.g.doubleclick.net https://*.creativecdn.com https://*.udmserve.net https://*.rubiconproject.com https://*.wp.pl https://*.teads.tv https://*.taboola.com https://*.adscale.de https://*.3lift.com https://*.outbrain.com https://*.smartadserver.com https://*.yieldmo.com https://*.openx.net https://*.360yield.com https://*.33across.com https://*.seedtag.com https://sync.go.sonobi.com https://*.nexx360.io https://*.clarity.ms https://*.casalemedia.com https://*.lijit.com https://*.omnitagjs.com https://*.media.net https://*.loopme.me https://onetag-sys.com https://*.mgid.com https://*.ad.smaato.net https://*.rmp.rakuten.com https://*.visx.net http://*.credit-agricole.pl https://*.facebook.com https://*.bidswitch.net https://*.zdusercontent.com https://*.criteo.com https://*.1rx.io https://*.emxdgt.com https://*.yieldlab.net https://*.tremorhub.com https://*.sharethrough.com https://*.pubmatic.com https://*.postrelease.com https://*.mediavine.com https://*.ivitrack.com https://id5-sync.com https://*.zendesk.com https://*.dmxleo.com https://*.facebook.net https://*.avin1.com https://*.unrulymedia.com https://sklepmartes.pl https://*.packeta.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ secure.payu.com secure.snd.payu.com https://*.sysadvisors.pl https://*.googlesyndication.com https://pagead2.googlesyndication.com https://*.mapbox.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ https://unpkg.com https://cdn.jsdelivr.net https://*.easypack24.net https://trustmate.io https://cz.im9.cz https://sk.im9.cz *.avada.io *.shopify.com *.snrbox.com https://*.paynow.pl https://*.intum.com https://*.demoup.com https://cdn.intum.com https://*.cookiebot.com https://*.clarity.ms https://*.azureedge.net https://*.livechatinc.com https://*.wp.pl https://*.dmdi.pl https://*.savecart.pl https://*.goadservices.com https://*.bing.com https://*.dwin1.com https://glamipixel.com https://trafficscanner.pl https://*.cloudflareinsights.com https://martes.api.useinsider.com https://tags.creativecdn.com https://script.ar-mtch1.com https://eitri.api.useinsider.com https://*.allekurier.pl https://*.luigisbox.com https://*.criteo.com https://*.facebook.net https://*.tiktok.com https://*.avin1.com https://*.martessport.eu https://*.packeta.com https://*.sklepmartes.pl https://cdn.thulium.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://*.sysadvisors.pl https://*.mapbox.com *.szybkapaczka.pl *.gls-poland.com/ https://cdn.jsdelivr.net https://*.easypack24.net https://trustmate.io https://fonts.bunny.net *.snrcdn.net fonts.gstatic.com https://assets.api.useinsider.com https://*.luigisbox.com https://*.sklepmartes.pl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ secure.payu.com merch-prod.snd.payu.com https://*.sysadvisors.pl https://api.mapbox.com https://events.mapbox.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ https://*.easypack24.net https://trustmate.io https://get.geojs.io *.avada.io *.snrbox.com https://*.demoup.com https://mycliplister.com https://*.google-analytics.com https://*.livechatinc.com https://googleads.g.doubleclick.net https://ams.creativecdn.com https://lt.ar-mtch1.com https://*.cookiebot.com https://*.useinsider.com https://*.clarity.ms https://*.bing.com https://*.inpost.pl https://*.luigisbox.com https://*.tiktok.com https://*.sklepmartes.pl https://*.criteo.com https://*.keys.adm-services.goog https://*.facebook.com https://*.googlesyndication.com https://*.packeta.com https://pixel.wp.pl/ https://cdn.thulium.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: wss: blob:; connect-src https: wss: blob:; script-src https: 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; style-src https: 'unsafe-inline' blob:; img-src https: data: blob:; font-src https: data: blob:; object-src https: data:; media-src https: data: blob:; frame-ancestors 'none'; report-uri /security/csp_violations 1 default-src 'self';base-uri 'none';font-src m.media-amazon.com;frame-src 'self' www.facebook.com audible.demdex.net td.doubleclick.net www.googletagmanager.com;connect-src 'self' unagi-fe.amazon.com m.media-amazon.com dpm.demdex.net audible.tt.omtrdc.net audible.sc.omtrdc.net fls-fe.amazon.com unagi.amazon.com unagi-na.amazon.com fls-na.amazon.com;frame-ancestors 'self';style-src 'self' 'unsafe-inline' images-fe.ssl-images-amazon.com images-na.ssl-images-amazon.com d2nttevkh1mtzs.cloudfront.net;media-src 'self' m.media-amazon.com;object-src 'none';script-src 'self' 'unsafe-inline' d2nttevkh1mtzs.cloudfront.net images-na.ssl-images-amazon.com d1g3myji5lplsh.cloudfront.net connect.facebook.net audible.sc.omtrdc.net;img-src 'self' m.media-amazon.com images-na.ssl-images-amazon.com images-fe.ssl-images-amazon.com fls-na.amazon.com www.facebook.com fls-fe.amazon.comwww.google.com 1 default-src 'self' 'unsafe-inline' https://*.fontawesome.com https://*.googleapis.com https://accounts.google.com https://analytics.google.com https://*.analytics.google.com https://*.sentry.io https://*.google-analytics.com https://*.gstatic.com https://google-analytics.com https://*.leadinfo.net https://*.leadinfo.com https://*.doubleclick.net https://*.hotjar.io https://*.hotjar.com https://*.googletagmanager.com https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; font-src 'self' 'unsafe-inline' https://*.fontawesome.com https://fonts.gstatic.com data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://maps.googleapis.com https://accounts.google.com/gsi/ https://*.google-analytics.com https://js.mollie.com https://cdn.leadinfo.net/ ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://maps.googleapis.com https://accounts.google.com/gsi/ https://*.google-analytics.com https://js.mollie.com https://cdn.leadinfo.net/ ; frame-src 'self' https://*.doubleclick.net/ https://accounts.google.com/ https://*.mollie.com https://*.googletagmanager.com https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; img-src 'self' https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.doubleclick.net data: https://tile.openstreetmap.org https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; report-to csp-endpoint; report-uri https://www.companyweb.be/cspviolation 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.cookiebot.com fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bird.eu *.feedaty.com *.gumlet.io *.cookiebot.com *.google.it stileo.it *.adnxs.com *.sharethrough.com *.doubleclick.net *.bidswitch.net *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.media.net *.mediavine. *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.teads.tv *.tremorhub.com *.ivitrack.com *.3lift.com *.yieldlab.net ad.360yield.com id5-sync.com sync.1rx.io sync-criteo.ads.yieldmo.com *.emxdgt.com *.servenobid.com *.unrulymedia.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.feedaty.com *.avada.io https://widget.feedaty.com https://insights.algolia.io *.cookiebot.com *.dwin1.com *.criteo.com glamipixel.com *.cookieless-data.com *.cloudfront.net *.datnova.com *.sddan.com fonts.googleapis.com consent.cookiebot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.feedaty.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widget.feedaty.com *.cloudflare.com *.cookiebot.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.algolia.net *.algolia.com *.algolianet.com insights.algolia.io *.feedaty.com https://get.geojs.io *.avada.io https://widget.feedaty.com *.cookiebot.com wss://ws.salecycle.com *.salecycle.com *.criteo.com *.doubleclick.net *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.ddlnk.net magefan.com cm.magefan.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://sdk.mercadopago.com/js/v2 *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://converse.com.mx 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://sdk.mercadopago.com/ https://api.mercadopago.com/v1/payments *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net converse.com.mx searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com google.com *.tiktok.com *.bing.com *.jsdelivr.net *.scarabresearch.com *.facebook.net *.storyblok.com *.vercel-scripts.com *.vercel.app *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.vercel.com *.vercel.live vercel.live vercel.app *.cookiefirst.com *.beslist.nl *.pinterest.com *.smarketer.de *.doubleclick.net *.intercomcdn.com *.googleapis.com *.kk-resources.com *.pinimg.com *.intercom.io *.clarity.ms googletagmanager.com *.googletagmanager.com *.google-analytics.com *.paypal.com *.adyen.com unpkg.com *.unpkg.com *.hotjar.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiefirst.com *.adyen.com *.google-analytics.com googletagmanager.com *.googletagmanager.com *.google.com google.com *.googleadservices.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.google.com google.com *.googleadservices.com *.doubleclick.net *.tiktok.com *.tiktokw.us wss://*.intercom.io *.intercom.io *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.adyen.com *.cookiefirst.com *.beslist.nl *.pinterest.com *.algolia.net *.algolia.io *.bing.net *.smarketer.de *.googleapis.com *.clarity.ms *.scarabresearch.com *.googlesyndication.com *.google.com *.google.de *.google-analytics.com *.analytics.google.com googletagmanager.com *.googletagmanager.com *.paypal.com *.bing.com *.kelkoogroup.net *.facebook.com; font-src 'self' 'unsafe-inline' data:; frame-src 'self' *; img-src 'self' data: *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.cookiefirst.com *.adyen.com *.bynder.com ggm.bynder.com *.orbitvu.co *.youtube.com *.ytimg.com *.twgdns.com *.gstatic.com *.bing.net *.facebook.com *.facebook.net *.google.com google.com *.google.de *.paypalobjects.com *.storyblok.com *.doubleclick.net googletagmanager.com *.googletagmanager.com *.intercomcdn.com *.intercomassets.com *.bing.com; manifest-src 'self'; media-src 'self'; worker-src 'self'; frame-ancestors 'self' https://app.storyblok.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.youtube.com https://form.typeform.com *.criteo.com *.hotjar.com *.facebook.com *.simply-jobs.fr https://plumrocket.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.bird.eu *.trackedlink.net *.ddlnk.net https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr magefan.com cm.magefan.com *.disqus.com *.thebrighttag.com *.avis-verifies.com *.adform.net id5-sync.com *.liadm.com *.google.com *.google.fr *.kameleoon.eu *.nr-data.net *.metaffiliation.com *.facebook.com *.d-bi.fr *.adnxs.com *.omnitagjs.com *.casalemedia.com *.dmxleo.com *.360yield.com *.criteo.com *.media.net *.mediavine.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.smaato.net *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.advertising.com *.yahoo.com *.yieldlab.net *.yieldmo.com *.rlcdn.com *.smartclip.net *.tremorhub.com *.twiago.com *.krxd.net *.bing.com *.bidswitch.net *.doubleclick.net *.googletagmanager.com *.googleapis.com *.monnaiedeparis.fr blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.disqus.com *.kameleoon.eu *.google.fr *.facebook.net *.d-bi.fr *.hotjar.com *.serving-sys.com *.criteo.com *.criteo.net *.monnaiedeparis.fr *.metaffiliation.com *.eulerian.net *.doubleclick.net *.bing.com *.soundclound.com *.soundcloud.com *.piwik.pro *.gstatic.com *.clarity.ms ipinfo.io *.addtoany.com *.googletagmanager.com *.m1by1.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.monnaiedeparis.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.fontawesome.com *.googleapis.com *.addtoany.com 'self' data: *.typekit.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com qa-api.magedevteam.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com http://dpm.demdex.net *.google-analytics.com *.g.doubleclick.net *.kameleoon.eu *.google.fr *.hotjar.com *.serving-sys.com *.criteo.com *.criteo.net *.monnaiedeparis.fr *.metaffiliation.com *.eulerian.net *.piwik.pro * payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://fonts.googleapis.com; report-to report-endpoint; 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=rcg1l1jB5GMiQcDnwHO.i6eJvNr9S0IClQbXeQAAvuo-1765938695-1.0.1.1-I0FsYp81R_oDZ4KLbLHQx6qy5nA8s7z0nC0SvqTRR5AX5IbEKUeJE9CpehalHryFTijRmWzczJYsjilDo3shi0E8cGTsOZ_QordXHJeCr4laPGwrW5jDVE3sY5H.Be.6klK79Ues9ozWZ87dknECt3Pn60Wj3cn0vfUAMotW09E; report-to cf-csp-endpoint 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://bot.leadoo.com https://www.googletagmanager.com https://www.google.com https://app.interactiveads.ai https://www.gstatic.com https://www.redditstatic.com https://connect.facebook.net https://snap.licdn.com https://js-eu1.hs-scripts.com https://www.google-analytics.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-analytics.net https://js-eu1.hsadspixel.net https://js-eu1.hs-banner.com https://snap.licdn.com https://sc.lfeeder.com https://www.google-analytics.com data:; style-src 'report-sample' 'self' 'unsafe-inline' https://bot.leadoo.com https://fonts.googleapis.com https://res.leadoo.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://res.leadoo.com https://bot.leadoo.com https://www.google.com https://region1.google-analytics.com https://region1.analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://ipapi.co https://px.ads.linkedin.com https://anl.leadoo.com https://www.redditstatic.com https://pixel-config.reddit.com https://api-eu1.hubapi.com https://forms-eu1.hscollectedforms.net https://www.facebook.com https://geoip.cookieyes.com https://www.google.pl; font-src 'self' https://res.leadoo.com https://fonts.gstatic.com data:; frame-src 'self' https://app.leadoo.com https://www.google.com https://www.googletagmanager.com https://player.vimeo.com https://www.youtube.com https://bot.leadoo.com https://app.interactiveads.ai; frame-ancestors 'self' https://www.google.com; img-src 'self' https://bot.leadoo.com https://leadoo.com https://res.leadoo.com https://www.redditstatic.com https://www.facebook.com https://px.ads.linkedin.com https://track-eu1.hubspot.com https://www.google-analytics.com https://alb.reddit.com https://tr.lfeeder.com https://www.google.ie https://www.google.pl https://test.leadoo.com https://www.googletagmanager.com https://secure.gravatar.com https://a.slack-edge.com https://forms-eu1.hsforms.com https://connect.facebook.net data:; manifest-src 'self'; media-src 'self' https://leadoo.com; worker-src 'none'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=VdunHWzIxOBnh3o_xMhPKX3YGkIB8OyBvJIlzd4A1IQ-1765939550-1.0.1.1-X08mXJ1.VDKKim.VZ5c1EnAgGBtS5KBAbD4zFCdMMuQY50yTRDXPzAvDctjGKdD2nA.a4YXqmw3ZcnyfyY.3YHODUVwOtiXssMvQttMytCTwCraoWG6abrMQezvDXUf62giL1W7CATwphEMgzY.H6_U7r7DF8BVvL4FfSoweWFt4HuekqFR.GSwnf1hriN7_; report-to cf-fvanlbpalyehjqpv 1 default-src 'self' https: 'unsafe-inline' data: 'unsafe-eval'; report-uri https://servix.idnes.cz/log/csp-report.aspx?w=emimino 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.cz *.betano.cz betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=hYprqlrdyuOKWdvpLEv.8lEInXR44Qt23_SxaXJ2.BQ-1765940010-1.0.1.1-huFcUZktdVydjFjmqLG74WGYQ3JQnDFcba7BxncGie4_8F8_ulnT8IYzU0h8.UyRn8rgrdAUZyk4XUJ42oFMAiFLbMjBjV81Cohz.iZ1tzoaQqcA3vdqQqlEbmaecOXdZJgzD0ox1g4Mof5vb0NwPFqgyvZT.ntTAv8TPACuTarcF9wDClhVz64TG8ReDy3X4NSt3colRsurl6SXz5gx0Q; report-to cf-hajswonzlswupefi 1 default-src *.bellroy.com 'self' https: data:; base-uri 'self'; connect-src *.bellroy.com https: wss: www.google.com api.tangiblee.com; font-src *.bellroy.com 'self' data: https: themes.googleusercontent.com fonts.googleapis.com fonts.gstatic.com; frame-src *.bellroy.com 'self' https: data: ms-appx-web: www.facebook.com; img-src *.bellroy.com https: data: blob: android-webview-video-poster:; media-src *.bellroy.com https: data: blob:; script-src *.bellroy.com 'self' https: 'unsafe-inline' 'unsafe-eval' data: opera: google.com *.visa.com d1fc8wv8zag5ca.cloudfront.net; style-src *.bellroy.com https: 'unsafe-inline' data:; worker-src 'self' blob:; child-src 'self' blob:; block-all-mixed-content; report-uri /csp_reports 1 default-src data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *.atyarisi.com wss://*.atyarisi.com *.google.com *.google.com.tr *.googletagmanager.com *.google-analytics.com *.support.google.com *.doubleclick.net *.googleadservices.com *.microsoft.com *.apple.com *.facebook.com *.facebook.net *.yahoo.com *.newrelic.com *.twitter.com *.instagram.com *.youtube.com tjktv.ercdn.net *.tjk.org *.broadage.com *.media.net *.liderform.com.tr *.googleapis.com *.googlevideo.com *.gstatic.com *.nsoft-cdn.com *.106digital.com *.sisalsanstech.com *.rlcdn.com *.crwdcntrl.net *.dengage.com *.nr-data.net *.taboola.com *.tiktok.com *.7platform.net *.dengagecdn.com https://www.millipiyangoonline.com/ *.rsc.cdn77.org; img-src * data:; report-uri /csp/cspreport/ 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-o7auOn3pd_3uwC5TNxoRDQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 frame-ancestors 'self'; report-uri https://www.kidspot.com.au/csp-reports 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-Lkx0XnrQ00pbFTRb9UmE3Q==' 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.fi https://www.googletagmanager.com https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.fi; frame-src 'self' https://analytics.nordnet.fi https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://t.email.nordnet.fi; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogi.nordnet.fi; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.fi https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-fa7bc75c-9988-4830-a04c-8054c4d3612e' https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi https://www.recaptcha.net; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.fi; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 worker-src blob:; font-src *.gstatic.com *.stape.io *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.weltpixel.com https://secure.pay1.de/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.com/ https://www.google.de/ https://www.trustedshops.de/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://www.magezon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com d.ratepay.com https://widgets.trustedshops.com https://products.ki-demo.ovh https://tedox.ki-test.ovh blob: https://widgets-qa.trustedshops.com https://app.usercentrics.eu/ https://legal-images.trustedshops.com/ https://maps.googleapis.com/ https://maps.gstatic.com/ https://www.trustedshops.com/ https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.gstatic.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.googleapis.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io www.jsctool.com https://products.ki-demo.ovh https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com https://www.google-analytics.com https://web.cmp.usercentrics.eu https://privacy-proxy.usercentrics.eu https://app.usercentrics.eu/ https://secure.pay1.de/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com *.google.com *.gstatic.com d.ratepay.com d.payla.io dr.payla.io https://products.ki-demo.ovh https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://payments.amazon.de/ http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com www.jsctool.com https://products.ki-demo.ovh https://produkte.ki-trade.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://privacy-proxy.usercentrics.eu https://v1.api.service.cmp.usercentrics.eu https://consent-api.service.consent.usercentrics.eu https://aggregator.service.usercentrics.eu/ https://api.usercentrics.eu/ https://graphql.usercentrics.eu/ https://maps.googleapis.com/ https://region1.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.no https://www.googletagmanager.com https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.no; frame-src 'self' https://analytics.nordnet.no https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://t.email.nordnet.no; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogg.nordnet.no; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.no https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-586ac594-05d7-404d-8c94-67335fa4d10e' https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no https://www.recaptcha.net; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.no; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: blob: https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.with.is; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://connect.facebook.net https://platform.twitter.com https://cdn.jsdelivr.net https://*.googletagmanager.com https://www.google-analytics.com https://static.ads-twitter.com https://js-agent.newrelic.com *.with.is; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https://api.stripe.com https://analytics.twitter.com https://www.facebook.com https://support.with.is https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.co.jp https://*.google.com wss://ntjp.mieru-ca.com https://bam.nr-data.net *.with.is; frame-src 'self' https://js.stripe.com https://www.facebook.com https://www.youtube.com https://cdn.d2-apps.net https://10252404.fls.doubleclick.net https://www.google.com https://with-1923.firebaseapp.com; report-uri /csp-violation-report 1 script-src 'sha256-XAIGnKEhi7V9GzJn2vDSs8esyrp0xCRxOXeiXdBEhu4=' 'self' self unsafe-eval; style-src self unsafe-eval; report-uri https://d302fc2a-dd34-416c-a079-e29edadd0fcf.sansec.watch/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.facebook.net *.twimg.com *.hotjar.com *.trustedshops.com *.googleapis.com *.magentocommerce.com *.paypal.com *.cardinalcommerce.com *.authorize.net *.fontawesome.com *.mncdn.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.zopim.com *.zopim.io *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com www.rossmann.com.tr *.snapchat.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.twitter.com *.facebook.com *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com *.snapchat.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com *.snapchat.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.twitter.com *.gstatic.com *.hotjar.com *.google.com.tr *.veinteractive.com *.demdex.net *.solocpm.com *.facebook.com *.facebook.net *.addthis.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.doubleclick.net *.bluekai.com *.useinsider.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us https://www.youtube.com http://www.sandbox.paypal.com www.paypal.com *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr rossmann.api.useinsider.com td.doubleclick.net ams.creativecdn.com *.snapchat.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.swagger.io https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.hotjar.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.doubleclick.net *.google.com *.google.com.tr *.facebook.com *.facebook.net *.demdex.net *.everesttech.net *.googleapis.com *.adis.ws *.livechatinc.com *.yandex.ru *.adyen.com *.setrowid.com *.setrow.com *.instagram.com *.useinsider.com *.googletagmanager.com *.mncdn.com *.iyzicopwi.com.tr *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.zopim.com *.zopim.io *.google.co.in *.mastercard.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr *.vimeo.com *.bidswitch.net *.adnxs.com *.casalemedia.com *.media.net *.360yield.com *.outbrain.com *.rubinproject.com *.sharethrough.com *.smartadserver.net *.taboola.com *.teads.tv *.3lift.com *.emxdgt.com *.adform.net *.omnitagjs.com *.sync.com *.ivitrack.com *.mediavine.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.yieldmo.com *.semasio.net *.krxd.net *.thebrighttag.com *.smartadserver.com *.yahoo.com https://id5-sync.com *.rubiconproject.com www.rossmann.com.tr cdn.rossmann.com.tr web-image.useinsider.com image.useinsider.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com t.co www.facebook.com *.snapchat.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.magentocommerce.com *.paypal.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.instana.io *.google.com.tr *.googletagmanager.com *.veinteractive.com *.facebook.net *.supert.ag *.setrowid.com *.mainadv.com *.doubleclick.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.jsdelivr.net *.setrow.com *.instagram.com *.criteo.com *.criteo.net *.ciritizr.com *.bkrtx.com *.cloudfront.net *.useinsider.com *.critizr.com *.behance.net *.swagger.io *.avada.io *.mncdn.com *.iyzicopwi.com.tr *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.zopim.com *.zdassets.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.rossmann.com.tr www.rossmann.com.tr rossmann.api.useinsider.com connect.facebook.net tags.creativecdn.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com embeds.ipaper.io static.hotjar.com cdn.rossmann.com.tr eitri.api.useinsider.com analytics.tiktok.com script.hotjar.com ams.creativecdn.com *.snapchat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.facebook.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.magentocommerce.com *.fontawesome.com *.paypal.com *.paypalobjects.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.setrowid.com *.setrow.com *.critizr.com *.useinsider.com *.adobedtm.com *.google-analytics.com *.googletagmanager.com *.swagger.io *.mncdn.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr *.vimeo.com www.rossmann.com.tr cdn.rossmann.com.tr maxcdn.bootstrapcdn.com assets.api.useinsider.com *.snapchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com https://stats.g.doubleclick.net *.twitter.com *.facebook.com *.facebook.net *.paypalobjects.com *.hotjar.com *.hotjar.io *.twimg.com *.magentocommerce.com *.cardinalcommerce.com *.cardinalcommerce.net *.veinteractive.com *.demdex.net *.yandex.ru *.vimeo.com *.setrowid.com *.setrow.com *.useinsider.com *.adobedtm.com *.swagger.io https://get.geojs.io *.avada.io *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr www.rossmann.com.tr cdn.rossmann.com.tr rossmann.api.useinsider.com aryuder.api.useinsider.com hit.api.useinsider.com ams.creativecdn.com recommendationv2.api.useinsider.com *.snapchat.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.ingage.tech *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com *.buysoci.al *.agkn.com *.a.run.app sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com www.rossmann.com.tr cdn.rossmann.com.tr *.clarity.ms googleads.g.doubleclick.net analytics.tiktok.com *.snapchat.com *.twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data:; frame-ancestors *.weirdfish.co.uk *.adyen.com *.amazon.com *.paypal.com *.google.com *.exponea.com *.monetate.net; connect-src * data:; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' data:; 1 font-src cdn.jsdelivr.net fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://cdnjs.cloudflare.com *.fontawesome.com *.klarna.com *.klarnacdn.net usizy-media.s3.eu-west-1.amazonaws.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.klarna.com *.klarnaservices.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com cdn.doofinder.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.jsdelivr.net magefan.com cm.magefan.com *.ekinsport.com *.klarna.com *.klarnacdn.net *.klarnaevt.com media.usizy.es static.usizy.es https://*.googleapis.com https://maps.gstatic.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com cdn.jsdelivr.net *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com cdn.doofinder.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdnjs.cloudflare.com *.jsdelivr.net https://polyfill-fastly.io https://browser.sentry-cdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com static.axept.io static.usizy.es media.usizy.es sgtm.ekinsport.com https://*.googleapis.com *.alothemes.com *.magepow.com cdn.brevo.com sibautomation.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.jsdelivr.net fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.doofinder.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.jsdelivr.net *.klarna.com *.klarnacdn.net static.usizy.es *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.getalma.eu *.google-analytics.com *.facebook.com *.facebook.net *.doofinder.com wss://*.doofinder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://*.ingest.sentry.io *.klarnaservices.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaevt.com client.axept.io api.axept.io usizy.com media.usizy.es https://*.googleapis.com *.alothemes.com *.magepow.com in-automate.brevo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src *; frame-src *; img-src https: data: blob: about: safari-extension: safari-resource: chrome-extension:; worker-src blob: https: 'unsafe-eval' 'unsafe-inline'; script-src https: 'unsafe-eval' 'unsafe-inline'; report-uri https://portfolio.ccpsx.com/api/v1/errors/csp 1 font-src *.bootstrapcdn.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.authorize.net https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.authorize.net https://plumrocket.com *.hotjar.com *.addthis.com *.libsyn.com *.locally.com *.sheerid.com *.wayin.com *.newtonsoftware.com https://recruitingbypaycor.com/ *.curalate.com *.formstack.com *.trackcmp.net *.google-analytics.com *.nr-data.net data: *.typeform.com *.pagescdn.com *.yextpages.net *.googleapis.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com store.paradoxlabs.com *.disqus.com *.google.com *.mageside.com mageside.com *.bc0a.com *.curalate.com *.s3.amazonaws.com *.amazonaws.com *.leupold.com *.googleapis.com *.gstatic.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com *.b0e8.com https://img.youtube.com maps.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://developer.adobe.com https://assets.armanet.us *.kaptcha.com *.disqus.com *.google.com *.gstatic.com *.authorize.net *.hotjar.com *.curalate.com *.app-us1.com *.avmws.com *.acsbapp.com acsbapp.com *.googleapis.com *.googletagmanager.com *.paypalobjects.com *.sheerid.com *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.cloudfront.net *.locally.com *.wayin.com *.activehosted.com *.newtonsoftware.com recruitingbypaycor.com *.leupold.com *.trackcmp.net *.google-analytics.com trackcmp.net *.vimeo.com *.apptrian.com *.facebook.com *.typeform.com *.sitescdn.net *.yextpages.net *.pagescdn.com *.b0e8.com *.bc0a.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sheerid.com *.bootstrapcdn.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com *.sitescdn.net tagmanager.google.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://srv.armanet.us https://assets.armanet.us *.kaptcha.com *.authorize.net *.bc0a.com *.hotjar.com wss://*.hotjar.com *.addthis.com *.googleapis.com *.acsbapp.com *.curalate.com *.hotjar.io *.trackcmp.net *.google-analytics.com *.g.doubleclick.net *.typeform.com *.pagescdn.com *.yext.com *.yext-pixel.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'none'; default-src 'self'; script-src 'self' 'nonce-NmYwMGFhMzctZTk5ZS00Y2RhLThhYWMtM2M4Nzc5YjAwOWU5' https://status.livepix.gg https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.intercomcdn.com https://widget.intercom.io https://www.youtube.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com; img-src 'self' https://static.livepix.gg https://cdn.livepix.gg https://www.googletagmanager.com https://downloads.intercomcdn.com https://static.intercomassets.com https://js.intercomcdn.com https://messenger-apps.intercom.io https://i.ytimg.com; frame-src 'self' https://checkout.livepix.gg https://rlgrjlrv2czy.statuspage.io https://www.googletagmanager.com https://intercom-sheets.com https://www.google.com https://www.youtube.com; connect-src 'self' https://webservice.livepix.gg https://unleash.livepix.gg https://fingerprint.livepix.gg https://fp.livepix.gg https://livia.livepix.gg https://www.google.com https://www.google-analytics.com https://api-iam.intercom.io wss://nexus-websocket-a.intercom.io https://o4508013286391808.ingest.us.sentry.io; manifest-src 'self' https://static.livepix.gg; media-src 'self' blob: https://static.livepix.gg https://js.intercomcdn.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.cloudflare.com https://*.migracion.gob.do https://cdn.userway.org https://eticket.migracion.gob.do https://personal.migracion.gob.do https://cdn.jsdelivr.net https://connect.facebook.net https://www.google-analytics.com https://challenges.cloudflare.com https://static.cloudflareinsights.com; worker-src https://migracion.gob.do blob:; style-src 'self' 'unsafe-inline' https://cdn.userway.org https://fonts.googleapis.com https://cdn.jsdelivr.net; font-src 'self' https://cdn.userway.org https://fonts.gstatic.com https://cdn.jsdelivr.net; media-src https://cdn.userway.org; img-src 'self' https://secure.gravatar.com https://s.w.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org data: https://cdn.userway.org https://*.migracion.gob.do https://cdn.jsdelivr.net https://www.google-analytics.com; connect-src 'self' https://cdn.userway.org https://api.userway.org https://*.migracion.gob.do https://www.google-analytics.com https://challenges.cloudflare.com; frame-src 'self' https://cdn.userway.org https://www.facebook.com https://www.youtube.com https://be.nortic.ogtic.gob.do https://eticket.migracion.gob.do https://challenges.cloudflare.com; object-src 'self'; base-uri 'self'; form-action 'self' https://*.migracion.gob.do; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://report-uri.migracion.gob.do/api/reports; report-to csp-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests; block-all-mixed-content 1 base-uri https://*.adnami.io; worker-src blob: data:; form-action 'none' 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.dk https://www.googletagmanager.com https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.dk; frame-src 'self' https://analytics.nordnet.dk https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://t.email.nordnet.dk; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blog.nordnet.dk; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.dk https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-ac935a44-abce-4206-8f02-a696047b97c0' https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk https://www.recaptcha.net; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.dk; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 font-src https://*.hotjar.com https://*.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com api-static.mercadopago.com *.doubleclick.net http://*.twitter.com https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://*.paypal.com *.sandbox.paypal.com https://*.paypalobjects.com https://assets.adobedtm.com https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://cm.everesttech.net https://*.adobe.com https://widgets.magentocommerce.com https://t.paypal.com https://fpdbs.paypal.com https://fpdbs.sandbox.paypal.com https://*.ftcdn.net https://*.behance.net https://*.vimeocdn.com https://i.ytimg.com https://d3sbl0c71oxeok.cloudfront.net https://dhkkzdfmpzvap.cloudfront.net https://d2bpzs5y44q6e0.cloudfront.net https://d37shgu97oizpd.cloudfront.net https://d1zlqll3enr74n.cloudfront.net https://d1jynp0fpwn93a.cloudfront.net https://d2cb3tokgpwh3v.cloudfront.net https://d1re8bfxx3pw6e.cloudfront.net https://d35u8xwkxs8vpe.cloudfront.net https://d13s9xffygp5o.cloudfront.net https://d388nbw0dwi1jm.cloudfront.net https://d11p2vtu3dppaw.cloudfront.net https://d3r89hiip86hka.cloudfront.net https://dc7snq0c8ipyk.cloudfront.net https://d5c7kvljggzso.cloudfront.net https://d2h8yg3ypfzua1.cloudfront.net https://d1b556x7apj5fb.cloudfront.net https://draz1ib3z71v2.cloudfront.net https://dr6hdp4s5yzfc.cloudfront.net https://d2bomicxw8p7ii.cloudfront.net https://d3aypcdgvjnnam.cloudfront.net https://d2a3iuf10348gy.cloudfront.net https://*.ssl-images-amazon.com https://*.ssl-images-amazon.co.uk https://*.ssl-images-amazon.co.jp https://*.ssl-images-amazon.it https://*.ssl-images-amazon.fr https://*.ssl-images-amazon.es https://*.ssl-images-amazon.de https://*.media-amazon.com https://*.media-amazon.co.uk https://*.media-amazon.co.jp https://*.media-amazon.it https://*.media-amazon.fr https://*.media-amazon.es https://*.media-amazon.de https://www.facebook.com https://connect.facebook.net https://graph.facebook.com https://business.facebook.com https://sandbox.secure.checkout.visa.com https://secure.checkout.visa.com https://sandbox-assets.secure.checkout.visa.com https://assets.secure.checkout.visa.com https://thm.visa.com https://cdn.aplazo.mx https://*.mercadopago.com https://*.mercadolivre.com https://*.mercadolibre.com https://*.mercadolibre.com.br https://*.mercadopago.com.br https://*.mlstatic.com https://*.mercadolivre.com.br https://*.mercadolibre.com.mx https://*.mercadolibre.com.ar https://*.mercadopago.com.mx https://b.stats.paypal.com https://dub.stats.paypal.com https://assets.braintreegateway.com https://c.paypal.com https://checkout.paypal.com https://*.sandbox.paypal.com https://*.yotpo.com https://*.steren.com.mx https://*.ocularsolution.com https://0.s3.envato.com https://*.hsforms.com https://*.hubspot.com/ https://bat.bing.com https://maps.googleapis.com https://maps.gstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.bootstrapcdn.com https://*.hotjar.com https://*.fontawesome.com https://*.ocularsolution.com https://diffuser-cdn.app-us1.com https://*.liveperson.net https://*.omappapi.com http://js-na1.hs-scripts.com https://prism.app-us1.com http://*.twitter.com https://*.googleapis.com https://static.cloudflareinsights.com https://analytics.tiktok.com https://googleads.g.doubleclick.net https://calidad.steren.com.mx https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net https://*.hotjar.com https://*.fontawesome.com https://use.fontawesome.com https://*.omappapi.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com thm.visa.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.ocularsolution.com https://*.googleapis.com https://*.omappapi.com https://*.hubspot.com https://*.hscollectedforms.net https://bat.bing.com https://analytics.google.com https://analytics.tiktok.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com https://fonts.gstatic.com data: https://fonts.intercomcdn.com https://*.yotpo.com https://*.typekit.net https://*.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.facebook.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca https://*.trustpilot.com http://*.trustpilot.com https://*.hotjar.com https://*.affirm.com *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.infusionsoft.app https://*.doubleclick.net/ https://*.facebook.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca https://www.google.com https://track.hubspot.com https://*.intercom.io https://static.intercomassets.com https://*.intercomcdn.com https://sp.analytics.yahoo.com https://*.facebook.com https://*.amazonaws.com https://*.infusionsoft.app https://www.googletagmanager.com https://*.akamaihd.net https://px.ads.linkedin.com https://p.adsymptotic.com https://ssl.gstatic.com https://www.gstatic.com https://*.bing.com https://*.hsforms.com https://*.clarity.ms https://*.wistia.com https://cdn.auth0.com https://p.adsymptotic.com https://www.google.co.uk https://heapanalytics.com https://*.yotpo.com https://content-faculty.blueprintprep.com https://redchamps.com www.xtento.com cdn.xtento.com maps.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.affirm.com *.affirm.ca https://www.googletagmanager.com https://*.google-analytics.com https://tagmanager.google.com https://*.google.com https://googleads.g.doubleclick.net https://*.trustpilot.com http://*.trustpilot.com https://*.newrelic.com https://*.nr-data.net https://*.intercom.io https://*.intercomcdn.com https://*.hotjar.com https://*.bing.com https://*.licdn.com https://*.yimg.com https://sp.analytics.yahoo.com https://*.impactradius-event.com http://*.hs-scripts.com https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hs-analytics.net https://js.hubspot.com https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.usemessages.com https://*.facebook.net https://app.convertful.com https://*.affirm.com https://*.pdst.fm *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.clarity.ms https://vision.duel.me/duel-analytics.js https://*.wistia.com https://*.hsforms.net https://*.hsforms.com https://*.jquery.com https://*.cloudflare.com https://*.yotpo.com https://*.heapanalytics.com https://*.greenhouse.io https://*.amplitude.com https://*.sentry-cdn.com https://unpkg.com/@lottiefiles/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com cdn.xtento.com maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com https://tagmanager.google.com https://fonts.googleapis.com https://*.yotpo.com https://*.typekit.net https://*.fontawesome.com *.stripe.network *.stripecdn.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.intercom.io https://*.intercomcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com p13n-mr.adobe.io *.adobedc.net *.demdex.net *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.affirm.com *.affirm.ca https://www.googletagmanager.com https://*.google-analytics.com https://*.yimg.com https://sp.analytics.yahoo.com https://*.hubspot.com https://*.hotjar.com https://app.convertful.com https://*.affirm.com https://*.intercom.io wss://*.intercom.io https://*.newrelic.com https://*.nr-data.net https://*.paypal.com https://us-central1-adaptive-growth.cloudfunctions.net *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.bing.com https://*.clarity.ms https://*.doubleclick.net/ https://*.hotjar.io/ https://*.hotjar.com/ https://*.wistia.com https://*.hsforms.net https://*.hsforms.com https://*.hubapi.com https://*.trustpilot.com https://*.litix.io wss://*.hotjar.com https://*.yotpo.com https://*.google.com https://*.hscollectedforms.net https://*.pfx.io https://edge.adobedc.net https://*.greenhouse.io https://smetrics.blueprintprep.com https://*.amplitude.com https://*.linkedin.com https://px.ads.linkedin.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem maps.gstatic.com maps.googleapis.com fonts.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx; font-src fonts.gstatic.com use.typekit.net *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com *.gstatic.com data: https://fonts.bunny.net https://www.google.com https://www.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com 'self' *.doubleclick.net *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.google.com *.examedi.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com *.facebook.com *.sharethis.com *.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://firebasestorage.googleapis.com *.mitec.com.mx *.bird.eu *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.avada.io *.mitec.com.mx www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.jscrambler.com *.examedi.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.bunny.net *.googleapis.com *.addtoany.com *.mitec.com.mx *.google.com https://www.chopo.com.mx 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.mitec.com.mx https://www.google.com https://www.gstatic.com *.jscrambler.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.wesupply.xyz https://wesupplylabs.com *.sandbox.paypal.com *.paypalobjects.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.swagger.io *.ftcdn.net *.behance.net *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com julio.com *.scene7.com *.doubleclick.net *.google.com *.google-analytics.com *.googleadservices.com *.braintreegateway.com mcusercontent.com www.google.com.co *.sharethis.com *.aplazo.mx *.api.useinsider.com *.sandbox.paypal.com *.paypalobjects.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.bing.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.net *.connect.facebook.net https://smetrics.julio.com *.julio.com *.cardinalcommerce.com unpkg.com cdn.jsdelivr.net *.magento-datasolutions.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com *.bolt.com *.commerce-quick-checkout.com *.online-metrix.net *.cybersource.com *.braintreegateway.com *.sharethis.com *.pingdom.net *.hotjar.com *.zdassets.com *.useinsider.com *.usizy.es usizy.com *.cloudflare.com *.sandbox.paypal.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com julio.com https://smetrics.julio.com *.demdex.net *.cardinalcommerce.com *.snplow.net *.pingdom.net *.woorank.com *.adobedc.net *.youtube.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com *.bolt.com *.magento-ds.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.zdassets.com grupojulio.zendesk.com *.usizy.es usizy.com *.hotjar.io *.api.useinsider.com *.useinsider.com *.g.doubleclick.net *.crwdcntrl.net *.sandbox.paypal.com *.paypalobjects.com www.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src julio.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.ng *.betano.ng cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.io *.kameleoon.io optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com ads-twitter.com *.ads-twitter.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=4Rg6WjB25Hjgh0Kp5.mM4KJcZqCyi0SeP5VXx3gZpWI-1765938839-1.0.1.1-isFY4m1wpodVTJGG321MoVsd.OvS_iLG.e.Zzb6EMEcyyF04LINgPUaTER0OyHj0WuxLPi3b09EQPEqkCYsCbuUQopCwNxzzPvd.8L8CU9tYta_JV4f46qvkyj3PlPTpnCNixXK_c05xNDanyIZ0o3xC5UrcgUqvrUFvu9Qga9Upw5TKDPuO.lkZPs7MxUjUOXCCEK2bR4WCVubZwPjTNA; report-to cf-claijloeyuekfpkd 1 script-src 'strict-dynamic' 'nonce-IaAc4aPiKbmrJyCvufVwig==' 1 default-src 'self' *.simyo.es *.typekit.net *.sumup.com *.opentech.com *.consorsbank.de *.bkm.com.tr *.micb.md *.capitecbank.co.za *.asseco-see.hr *.ing.com *.privatbank.ua *.n26.com *.six-group.com *.seglan.com *.monext.fr *.rsa3dsauth.com *.papara.com *.sibs.pt *.bpcbt.com *.capitalone.com *.bpcprocessing.com *.kapital24.uz *.alignet.io *.revolut.com *.wlp-acs.com *.mycardplace.com *.emlpayments.com *.abanca.com *.viseca.ch *.edb.com *.arca.am *.modirum.com *.redsys.es *.marqeta.com *.vinea.es *.cardinalcommerce.com; script-src-elem 'self' 'unsafe-inline' *.redsys.es *.cardinalcommerce.com *.googleapis.com *.pinterest.com bat.bing.com *.gstatic.com *.googletagmanager.com *.doubleclick.net *.amazon-adsystem.com *.pinimg.com *.taboola.com amplify.outbrain.com jgb8.simyo.es analytics.tiktok.com *.weborama.fr connect.facebook.net foodin.site sc-static.net *.hotjar.com *.mathtag.com *.appboycdn.com *.google-analytics.com *.useinsider.com *.criteo.com *.jsdelivr.net *.cardinalcommerce.com *.google.com www.google.com/recaptcha *.xizumubama.com *.thetto.com *.roterf.com *.snapchat.com *.appsflyer.com *.bazaarvoice.com *.bimien.com; script-src 'self' 'unsafe-inline' https: 'unsafe-eval' *.typekit.net *.redsys.es *.cardinalcommerce.com *.googletagmanager.com bat.bing.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.yandex.net yastatic.net blob:; img-src 'self' *.redsys.es *.simyo.es *.google.es *.doubleclick.net *.weborama.fr *.facebook.com *.cardinalcommerce.com bat.bing.com *.google-analytics.com analytics.tiktok.com *.typekit.net *.googletagmanager.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com *.vimeocdn.com data: *.360yield.com *.doubleclick.net *.stickyadstv.com *.yieldmo.com *.bing.com blob: bttrack.com *.shoppiday.es *.goin.cloud *.honey.io *.media.net *.camarabilbao.com *.adxcel-ec2.com *.mediavine.com *.weborama.fr *.criteo.com *.liadm.com *.adnxs.com *.rlcdn.com *.postrelease.com *.roeye.com *.ggpht.com *.sharethrough.com *.yandex.ru *.veritone-ce.com *.mediawallahscript.com *.rubiconproject.com *.casalemedia.com *.smartadserver.com *.pubmatic.com *.yahoo.com *.igstatic.com *.taboola.com *.1rx.io *.outbrain.com *.revcontent.com *.omnitagjs.com webkit-masked-url://hidden *.facebook.com *.google.ad *.google.al *.google.at *.google.be *.google.bg *.google.by *.google.ca *.google.ch *.google.cl *.google.cn *.google.co.cr *.google.co.id *.google.co.in *.google.co.jp *.google.co.kr *.google.co.ma *.google.co.th *.google.co.uk *.google.co.ve *.google.co.za *.google.com *.google.com.ar *.google.com.au *.google.com.br *.google.com.co *.google.com.do *.google.com.ec *.google.ba *.google.co.uz *.google.bf *.google.ci *.google.com.gi *.google.com.gt *.google.com.ni *.google.com.np *.google.com.eg *.google.com.hk *.google.com.mt *.google.com.mx *.google.com.my *.google.com.pe *.google.com.py *.google.com.qa *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vn *.google.com.gh *.google.cz *.google.de *.google.dk *.google.ee *.google.es *.google.co.ao *.google.co.il *.google.co.ug *.google.com.bo *.google.com.bz *.google.com.na *.google.com.sv *.google.md *.google.mw *.google.iq *.google.am *.google.fi *.google.cv *.google.dz *.google.ge *.google.hn *.google.kz *.google.lk *.google.lv *.google.rs *.google.sn *.google.fr *.google.gr *.google.hr *.google.hu *.google.ie *.google.is *.google.it *.google.lt *.google.lu *.google.ae *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.se *.google.si *.google.sk *.google.cm *.google.co.ke *.google.co.nz *.google.com.pa *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.sa *.google.me *.google.mv *.google.tn *.bidswitch.net *.groovinads.com *.clarity.ms *.ytimg.com mikkiload.com *.prfrm-ads.com *.charleskeith.co.th *.barclays.co.uk *.snapchat.com *.adentifi.com *.amazonaws.com *.discordapp.com *.yandex.com *.productfruits.com *.discordapp.net *.profileengine.com *.phncdn.com *.leanlibrary.app *.ibb.co *.facebook.net *.css-tricks.com *.ipredictive.com *.line.me *.reskyt.com *.marca.com *.baidu.com *.huffingtonpost.es *.eficads.net; frame-src *.simyo.es *.redsys.es simyospain.speedtestcustom.com *.weborama.fr buybutwhere.com hipodi.com *.awin1.com *.googleapis.com cookieaquila.com *.mycardplace.com *.cardinalcommerce.com bat.bing.com *.pinterest.com *.amazon-adsystem.com *.doubleclick.net mapacob.aptica.es *.google.com *.socialmediaserver.es *.vimeo.com *.n26.com *.abanca.com *.borica.bg *.emlpayments.com *.nexigroup.com *.sebkort.com *.vinea.es *.cardcenter.ch 3dsecure-vrp.de acestream.tv *.modirum.com *.3dsecure.no *.apata.io *.edb.com *.bpcbt.com *.revolut.com *.targobank.de *.modirum.com acs2.arca.am *.bgpb.by *.marqeta.com *.wlp-acs.com *.opendns.com bnext.areq.mpts.modirum.com:9702 *.icard.com ebanking1.ccb.com.cn emet.live emet.news gateway.zscaler.net gateway.zscalertwo.net gateway.zscloud.net *.criteo.com *.rsa3dsauth.com *.moz.com sas.mc.redsys.es:9731 *.dkb.de *.arcot.com * *.criteo.net tdschded.monext.fr visa2.acs.cmbchina.com *.facebook.com *.googletagmanager.com *.pluscard.de *.pkobp.pl *.sia.eu *.alignet.io *.bpcprocessing.com *.sibs.pt *.swedbank.se *.useinsider.com *.boc.cn *.cloudfront.net *.kaspersky-labs.com *.micb.md *.merck.com *.zscalerthree.net *.secureacs.com *.bankserv.co.za *.gpesecure.com *.adsrvr.org *.ing.de *.viseca.ch *.icbc.com.cn *.netsgroup.com *.jysanbank.kz *.ukrsibbank.com *.monzo.com *.securesuite.net *.capitalone.com *.mtbank.by:8043 *.hitrust.com:9750 *.ajgirona.org *.creditagricole.ma *.mycardsecure.com *.google.com skytraf.xyz acs.hitrust-us.com:9750 securegw1.micb.md:6444 *.groovinads.com *.danskebank.com *.seglan.com *.useinsider.com div.show *.consorsbank.de *.co.uk *.indra-netplus.com *.firstdata.de *.snapchat.com *.sparkasse.at securesuite.net *.wibmo.com *.citibank.com *.zscaler.com *.bog.ge noop.style *.3dsacs.net *.bunq.com *.cihbank.ma *.ukrgasbank.com *.acdcproc.com *.privatbank.ua *.csi-processing.com *.placetopay.com *.s-id-check-sparkassen.de *.eewosecure.com *.cm-cic.com *.gc.ge *.sinnad.com.bh *.mercurypaymentservices.it ; font-src 'self' *.simyo.es *.redsys.es *.affilitizer.com *.escribelo.ai *.cdnfonts.com *.googleusercontent.com *.bootstrapcdn.com *.cardinalcommerce.com *.fontawesome.com fonts.gstatic.com *.typekit.net *.goin.cloud *.scite.ai *.cloudflare.com *.windows.net *.migaku.com *.slant.co *.alicdn.com *.faceworks.nl *.zohocdn.com yastatic.net ray.st chrome-extension moz-extension ms-browser-extension data:; connect-src 'self' *.adblockertool.com *.adfreevision.com *.amcreativemedia.com *.bttrack.com *.blackcrow.ai *.yimg.com *.browsekeeper.com *.creativecdn.com *.mczbf.com *.highdataanalytics.com *.uniswap.org *.kaspersky-labs.com infragrid.v.network *.dbankcloud.cn *.overbridgenet.com *.googlesyndication.com *.facebook.com *.simyo.es *.redsys.es ara.paa-reporting-advertising.amazon *.cardinalcommerce.com bat.bing.com *.taboola.com analytics.tiktok.com *.amazon-adsystem.com *.google-analytics.com *.doubleclick.net *.pinterest.com *.googleapis.com *.google.com *.google.com.ar *.google.com.co *.google.com.do *.google.com.mx *.google.com.pe *.google.com.tr *.google.com.uy *.google.de *.google.es *.google.fr *.google.ie *.google.it *.google.lt *.google.pt *.google.kz *.google.ro *.google.ae *.google.at *.google.ca *.google.ch *.google.cl *.google.co.ma *.google.co.uk *.google.co.ve *.google.be *.google.cm *.google.co.jp *.google.co.nz *.google.com.br *.google.cz *.google.fi *.google.com.pk *.google.com.pr *.google.com.sg *.google.com.gi *.google.ad *.google.by *.google.ba *.google.gr *.google.hu *.google.nl *.google.no *.google.rs *.google.sk *.google.se *.google.ru *.google.sn *.google.tn *.google.co.il *.google.com.pa *.google.com.qa *.google.dk *.google.me *.google.com.au *.google.com.gt *.google.com.hk *.google.co.cr *.gstatic.com *.googleadservices.com *.mplxtms.com *.yandex.ru *.cdn77.org *.adtonus.com *.fbanalytics.org *.mkmediaworks.com *.ultimateaderaser.com *.zendesk.com *.jquery.com *.zdassets.com meetlookup.com *.amazonaws.com rbtds.net *.clarity.ms zone1-services-cdn.com *.socialsolutionapp.com *.awesomeblocker.com *.global-data-lab.com *.range-offer.com *.report-uri.com *.pangle-ads.com *.adblocking247.com *.blocksly.org *.crystal-blocker.com *.datacloudstat.com *.software-downloading.com cubox.pro *.vimeocdn.com *.typekit.net *.vimeo.com *.reskyt.com *.braze.com *.criteo.com *.snapchat.com *.yandex.net *.yandex.com *.productfruits.com *.hotjar.io *.appsflyer.com *.onelink.me *.googletagmanager.com ya.ru *.socialmediaserver.es data: blob:; style-src-elem 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.scriptcdn.net *.tiktok.com *.webgains.io *.bing.com blob: bttrack.com *.amazon-adsystem.com *.taboola.com *.trackmytarget.com *.facebook.net *.weborama.fr *.pinterest.com *.eligrop.com *.hicloud.com *.kaspersky-labs.com *.doubleclick.net infimv.com *.blackcrow.ai *.simyo.es *.roeyecdn.com *.yandex.ru *.acestream.net *.pinimg.com *.yimg.com *.mplxtms.com *.criteo.net *.creativecdn.com *.dwin1.com *.google.com *.googleadservices.com *.googletagmanager.com *.mczbf.com *.opera-mini.net *.honey.io *.gstatic.com *.groovinads.com *.cloudflare.com *.useinsider.com *.line-scdn.net *.vulapo.com *.cloudfront.net *.mediarithmics.com hublosk.com *.adsrvr.org jullyambery.net *.adguard.org mikkiload.com *.prfrm-ads.com *.zdassets.com *.charleskeith.co.th *.eficads.net *.artfut.com *.clarity.ms *.reskyt.com *.bootstrapcdn.com *.fontawesome.com lonelyfix.com data:; style-src-attr 'unsafe-inline' *.typekit.net; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.google.com *.reskyt.com *.gstatic.com *.googleadservices.com; media-src data:; worker-src blob:; 1 default-src 'self' https:; object-src 'none'; connect-src 'self' https: https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https: https://www.googletagmanager.com; img-src 'self' https: https://www.googletagmanager.com https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com data:; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https: https://fonts.gstatic.com data:; script-src 'self' https: 'unsafe-eval' 'nonce-a/Utd6n1epowHi9qCLqQTQ=='; report-uri /csp_violations 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.useinsider.com https://www.gstatic.com https://fonts.gstatic.com https://*.typekit.net https://fonts.googleapis.com *.alicdn.com *.bazaarvoice.com *.googleusercontent.com *.homehardware.com.au *.hotjar.com *.hsappstatic.net *.slant.co *.zip.co *.alipayobjects.com *.cloudflare.com *.fontawesome.com *.fonts.net *.fontshare.com *.googleapis.com *.migaku.com *.mitre10.com.au *.qantas.com *.ziplyne.com *.crisp.chat data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://app.contentful.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.useinsider.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.mitre10.com.au https://*.openstreetmap.org https://scontent.cdninstagram.com https://tracker.unbxdapi.com *.dotomi.com *.eyeota.net *.googleapis.com *.mitre10.com.au *.openx.net *.pubmatic.com www.google.bf www.google.ca www.google.ch www.google.cm www.google.co.ck www.google.co.id www.google.co.in www.google.co.kr www.google.co.nz www.google.co.ug www.google.co.uk www.google.co.za www.google.co.zm www.google.com.au www.google.com.bd www.google.com.fj www.google.com.gh www.google.com.hk www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.sa www.google.com.sg www.google.com.tw www.google.com.vn www.google.de www.google.dk www.google.es www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.nl www.google.pl www.google.rs www.google.se *.amazon-adsystem.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bt www.google.by www.google.ci www.google.cl www.google.co.bw www.google.co.cr www.google.co.il www.google.co.jp www.google.co.ke www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.th www.google.co.tz www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.co www.google.com.do www.google.com.ec www.google.com.eg www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.pr www.google.com.qa www.google.com.sb www.google.com.sl www.google.com.tr www.google.com.ua www.google.com.uy www.google.cz www.google.dz www.google.ee www.google.fi www.google.ge www.google.gg www.google.hn www.google.im www.google.iq www.google.jo www.google.ki www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mk www.google.mu www.google.mw www.google.no www.google.pt www.google.ro www.google.ru www.google.sc www.google.si www.google.sk www.google.sn www.google.tn www.google.tt www.google.vu www.google.ws zip.co *.afterpay.com *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.cursors-4u.net *.google.com *.googleusercontent.com *.pinterest.com *.qualtrics.com *.shopback.com *.snapchat.com *.zipmoney.com.au dakotaram.com s3.amazonaws.com web-cockroach.herokuapp.com www.google.ad www.google.al www.google.as www.google.az www.google.bj www.google.bs www.google.cd www.google.cg www.google.co.ao www.google.com.af www.google.com.ag www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.bz www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.mm www.google.com.ni www.google.com.om www.google.com.py www.google.com.sv www.google.com.vc www.google.cv www.google.dj www.google.fm www.google.ga www.google.gm www.google.gy www.google.ht www.google.is www.google.je www.google.kg www.google.kz www.google.me www.google.mg www.google.ml www.google.mn www.google.mv www.google.nr www.google.ps www.google.rw www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to yastatic.net *.alicdn.com *.googleadservices.com www.google.com.gi www.google.dm www.google.gl www.google.nu www.google.pn www.google.sh www.google.td *.ctfassets.net www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co *.hsforms.net *.hsforms.com https://images.ctfassets.net https://images.secure.ctfassets.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.plugins.emarsys.net *.scarabresearch.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://libraries.unbxdapi.com https://d21gpk1vhmjuf5.cloudfront.net https://s3.amazonaws.com/downloads.mailchimp.com/js/goal.min.js https://cdn.optimizely.com https://rum.optimizely.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.zip.co https://cdn.scarabresearch.com *.cloudflare.com *.dotomi.com *.googleapis.com *.newrelic.com *.unbxdapi.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.hotjar.com *.mitre10.com.au *.shophumm.com.au *.zip.co *.zipmoney.com.au d21gpk1vhmjuf5.cloudfront.net https://d3m8huu8gvuyn3.cloudfront.net/rex_template_content/unbxd_rex_template_sdk.js *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.instagram.com *.p-a.io *.particularaudience.com *.pinimg.com *.pinterest.com *.qualtrics.com *.snapchat.com *.tableau.com consentag.eu dakotaram.com googletagmanager.com nexuspublications.com.au sc-static.net *.crisp.chat *.walkme.com *.humm-au.com static.cloudflareinsights.com www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co *.hsforms.net *.hsforms.com https://cdn.jsdelivr.net/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com display.ugc.bazaarvoice.com *.useinsider.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com https://*.typekit.net https://maps.googleapis.com https://libraries.unbxdapi.com *.typekit.net *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co *.bazaarvoice.com *.fontawesome.com *.fonts.net *.mitre10.com.au 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.mitre10.com.au *.youtube.com *.globalshop.com.au https://videos.ctfassets.net https://videos.secure.ctfassets.net 'self' 'unsafe-inline'; manifest-src *.useinsider.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.sharethis.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.scarabresearch.com *.eservice.emarsys.net *.useinsider.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://search.unbxd.io https://www.instagram.com https://graph.instagram.com https://*.sandbox.afterpay.com https://api.sandbox.zipmoney.com.au https://api.zipmoney.com.au https://*.sandbox.zip.co https://*.zip.co *.googleapis.com *.nr-data.net *.typekit.net localhost www.google.co.id www.google.co.in www.google.co.nz www.google.co.za www.google.com.au www.google.com.bd www.google.com.fj www.google.com.hk www.google.com.ph www.google.com.sa www.google.com.sg www.google.de www.google.dk www.google.hu www.google.pt www.google.rs *.bazaarvoice.com *.crwdcntrl.net *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxd.io *.zip.co *.zipmoney.com.au www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bf www.google.bt www.google.by www.google.ca www.google.ch www.google.cl www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pe www.google.com.pk www.google.com.qa www.google.com.sb www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.ie www.google.it www.google.jo www.google.la www.google.lk www.google.lv www.google.mu www.google.nl www.google.no www.google.pl www.google.ro www.google.ru www.google.se www.google.sk www.google.tn www.google.tt www.google.vu www.google.ws *.alicdn.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.mitre10.com.au *.p-a.io *.particularaudience.com *.pinterest.com *.qualtrics.com *.snapchat.com *.stbuttons.click *.unbxdapi.com www.google.al www.google.az www.google.bg www.google.bs www.google.cd www.google.ci www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.il www.google.co.mz www.google.co.zm www.google.com.bh www.google.com.bn www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.kw www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.om www.google.com.pa www.google.com.pg www.google.com.pr www.google.com.sv www.google.com.uy www.google.ga www.google.gm www.google.gy www.google.ht www.google.iq www.google.je www.google.kg www.google.kz www.google.lt www.google.lu www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mv www.google.mw www.google.nr www.google.ps www.google.rw www.google.sc www.google.si www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to zip.co *.crisp.chat www.google.as www.google.bj www.google.cg www.google.cm www.google.co.ls www.google.com.af www.google.com.bo www.google.com.gi www.google.com.py www.google.com.vc www.google.dm www.google.im www.google.is www.google.ki www.google.ml www.google.nu www.google.pn *.walkme.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.useinsider.com a.tribalfusion.com aa.agkn.com ad.turn.com ads.dotomi.com ads.scorecardresearch.com ads.stickyadstv.com aorta.clickagy.com ap.lijit.com bh.contextweb.com bpi.rtactivate.com c1.adform.net capi.connatix.com ce.lijit.com cm.g.doubleclick.net cms.analytics.yahoo.com cms.quantserve.com contextual.media.net cookies.nextmillmedia.com crb.kargo.com creativecdn.com cs.admanmedia.com cs.openwebmp.com csync.loopme.me dclk-match.dotomi.com dm-us.hybrid.ai dmp.brand-display.com dp-sync.dotomi.com dpm.demdex.net dsum-sec.casalemedia.com e1.emxdgt.com eb2.3lift.com edgedl.me.gvt1.com eu-u.openx.net exchange-match.mediaplex.com gw-iad-bid.ymmobi.com i.liadm.com i.w55c.net i6.liadm.com ib.adnxs.com id.rlcdn.com idpix.media6degrees.com idsync.live.streamtheworld.com idsync.rlcdn.com image2.pubmatic.com image4.pubmatic.com image8.pubmatic.com login.dotomi.com login-ds.dotomi.com match.adsby.bidtheatre.com match.adsrvr.org match.deepintent.com match.justpremium.com match.prod.bidr.io match.sharethrough.com match.sync.ad.cpe.dotomi.com openx-ums.acuityplatform.com openx.adhaven.com openx2-match.dotomi.com oxp.mxptint.net p.rfihub.com partners.tremorhub.com pippio.com pixel-sync.sitescout.com pixel.adsafeprotected.com pixel.rubiconproject.com pixel.tapad.com pm.w55c.net pmp.mxptint.net pr-bh.ybp.yahoo.com ps.eyeota.net pubmatic-match.dotomi.com px.ads.linkedin.com px.owneriq.net rtb-csync.smartadserver.com rtb.adentifi.com rtb.openx.net s.ad.smaato.net s.amazon-adsystem.com s.tribalfusion.com server.cpmstar.com simage2.pubmatic.com ssbsync.smartadserver.com stags.bluekai.com sync-tm.everesttech.net sync.1rx.io sync.bfmio.com sync.crwdcntrl.net sync.ipredictive.com sync.mathtag.com sync.search.spotxchange.com sync.smartadserver.com sync.srv.stackadapt.com sync.targeting.unrulymedia.com t.adx.opera.com tags.bluekai.com tr.blismedia.com u.openx.net um.simpli.fi ups.analytics.yahoo.com us-east.ads.audio.thisisdax.com us-u.openx.net us.ck-ie.com vop.sundaysky.com x.bidswitch.net yahoo-match.dotomi.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://87acbafe-91fb-446b-aa4c-62851bc12cb5.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.cdnfonts.com *.cloudflare.com *.gstatic.com *.klaviyo.com *.slant.co *.yotpo.com *.zip.co sc-static.net *.zdassets.com *.zendesk.com tryme.directory *.hotjar.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.googleapis.com dhv2ziothpgrr.cloudfront.net www.sportrx.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com www.sportrx.com 'self' 'unsafe-inline'; frame-ancestors www.sportrx.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.zdassets.com *.zendesk.com *.hotjar.com *.klarna.com *.yotpo.com www.sportrx.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.adsrvr.org *.avantlink.com *.bing.com *.bing.net *.cloudflare.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.klevu.com *.linksynergy.com *.liquifire.com *.pushcrew.com *.rlcdn.com *.sharethis.com *.sportrx.com *.teamusa.org *.visualwebsiteoptimizer.com *.wileyxrx.com *.xg4ken.com *.yotpo.com *.youtube.com cdn-cookieyes.com d10lpsik1i8c69.cloudfront.net *d3k81ch9hvuctc.cloudfront.net extendcoreoffersprod-offersthemelogobucketeb21afa-1lr7le13dvgtp.s3.amazonaws.com s3.amazonaws.com *.zdassets.com *.zendesk.com *.hotjar.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com dhv2ziothpgrr.cloudfront.net www.sportrx.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.attn.tv events.attentivemobile.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.zendesk.com wss://api.smooch.io *.luckyorange.net *.luckyorange.com *.googleapis.com *.pushcrew.com *.addthis.com *.addthisedge.com *.adobedtm.com *.adsrvr.org *.bing.com *.braintreegateway.com *.cloudflare.com d10lpsik1i8c69.cloudfront.net d3k81ch9hvuctc.cloudfront.net *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googlesyndication.com *.googletagmanager.com *.invoca.net *.invocacdn.com *.klaviyo.com *.klevu.com *.linksynergy.com *.moatads.com *.noibu.com input.noibu.com wss://input.noibu.com *.sharethis.com *.tiktok.com *.visualwebsiteoptimizer.com *.xg4ken.com *.yotpo.com *.youtube.com *.zdassets.com acsbapp.com cdn.acsbapp.com *.acsbapp.com cdn-cookieyes.com google-analytics.com tryme.directory *.newrelic.com *.rakuten.com *.rlcdn.com *.hotjar.com cdn.avmws.com/1016937/ *.smooch.io *.liquifire.com *.klarnacdn.net *.klarna.com *.glasseson.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaservices.com js.klevu.com *.ksearchnet.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www.sportrx.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.klaviyo.com *.klevu.com *.pushcrew.com *.yotpo.com *.zdassets.com *.zendesk.com *.hotjar.com https://static.klaviyo.com *.klarnacdn.net *.ksearchnet.com dhv2ziothpgrr.cloudfront.net www.sportrx.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.bing.com *.googleapis.com *.gstatic.com *.zdassets.com *.zendesk.com *.hotjar.com *.glasseson.com *.cloudfront.net www.sportrx.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.attn.tv events.attentivemobile.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.zendesk.com wss://api.smooch.io *.googleapis.com *.addthis.com *.adsrvr.org *.bing.com *.bing.net *.cloudflare.com *.criteo.com *.criteo.net *.datadome.co *.doubleclick.net *.facebook.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.invoca.net *.invocacdn.com *.klaviyo.com *.linksynergy.com *.luckyorange.net *.luckyorange.com *.noibu.com input.noibu.com wss://input.noibu.com *.nr-data.net *.pushcrew.com *.rlcdn.com *.samsung.com *.sharethis.com *.teamusa.org *.tiktok.com *.visualwebsiteoptimizer.com *.youtube.com *.zdassets.com acsbapp.com cdn.acsbapp.com *.acsbapp.com cdn-cookieyes.com *.cookieyes.com google-analytics.com tryme.directory d10lpsik1i8c69.cloudfront.net d3k81ch9hvuctc.cloudfront.net *.hotjar.com *.klarnaevt.com *.glasseson.com *.mixpanel.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klevu.com *.ksearchnet.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www.sportrx.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.sportrx.com http: https: blob: wss: 'self' 'unsafe-inline'; default-src *.glasseson.com *.cloudfront.net www.sportrx.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f67b9549-76ff-40d0-b57c-93081e358fa4.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; img-src 'self' data: https://www.google-analytics.com https://nhentai.website https://t1.nhentai.jp.net https://t2.nhentai.jp.net https://t3.nhentai.jp.net https://sstatic1.histats.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://static.cloudflareinsights.com https://nhentai.website; frame-src 'self' https://nhentai-website.disqus.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; report-to csp-endpoint 1 style-src-elem preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://static.klaviyo.com https://cdn.jsdelivr.net https://*.adobe.com https://fonts.googleapis.com https://*.doubleclick.net https://*.facebook.com https://fonts.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.fontawesome.com https://maxcdn.bootstrapcdn.com https://fonts.bunny.net https://fonts.static.com https://*.nosto.com https://*.nos.to https://assets.braintreegateaway.com https://*.cloudfront.net https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net; font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com https://fonts.bunny.net fonts.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.innoship.ro *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://event.2performant.com https://ams.creativecdn.com https://www.gstatic.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org * https://www.magezon.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com quickchart.io img.youtube.com *.nosto.com *.nos.to www.google.com.ua preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://ss.otter.ro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com * *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.googleapis.com https://www.gstatic.com/ *.avada.io *.shopify.com *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com https://cdn.otter.ro https://ss.otter.ro 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.adobe.com fonts.googleapis.com *.googleapis.com https://*.doubleclick.net https://*.facebook.com *.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com *.tiktok.com https://*.fontawesome.com maxcdn.bootstrapcdn.com https://*.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://fonts.bunny.net fonts.gstatic.com https://*.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://fonts.static.com https://*.nos.to https://assets.braintreegateaway.com https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net https://www.google.com/ *.doubleclick.net *.googlesyndication.com *.tiktok.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro static.klaviyo.com cdn.jsdelivr.net https://tezyo.zendesk.com https://ekr.zdassets.com https://*.zendesk.com https://*.zdassets.com https://event.2performant.com https://tidytracking.com https://ss.otter.ro 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; style-src 'self'; img-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; font-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; frame-src 'self' *.bibliu.co *.bibliu.com; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.de https://www.myheritage.de 'unsafe-eval' 'nonce-325a6a0bcde295025eeba259c7abf0d6' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.de;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src *.lafoirfouille.fr use.typekit.net fonts.gstatic.com static.sensefuel.live data: 'self' 'unsafe-inline'; form-action *.lafoirfouille.fr sogecommerce.societegenerale.eu 'self' 'unsafe-inline'; frame-src *.lafoirfouille.fr www.google.com sogecommerce.societegenerale.eu 'self' 'unsafe-inline'; img-src *.lafoirfouille.fr www.googletagmanager.com cdn-cookieyes.com tag.beyable.com data: 'self' 'unsafe-inline'; script-src *.lafoirfouille.fr front.activation.beyable.com tag.search.sensefuel.live tag.search.sensefuel.com tag.beyable.com www.gstatic.com www.google.com www.googletagmanager.com cdn-cookieyes.com static.target2sell.com *.socloz.com beyableprodrt.blob.core.windows.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.lafoirfouille.fr fonts.googleapis.com use.typekit.net p.typekit.net tag.search.sensefuel.com *.search.sensefuel.live tag.beyable.com 'self' 'unsafe-inline'; manifest-src *.lafoirfouille.fr 'self' 'unsafe-inline'; connect-src *.lafoirfouille.fr *.snoophome.com cdn-cookieyes.com *.cookieyes.com *.target2sell.com *.search.sensefuel.live *.ingest.de.sentry.io *.google-analytics.com beyableprodrt.blob.core.windows.net www.googletagmanager.com www.google.com 'self' 'unsafe-inline'; media-src *.lafoirfouille.fr *.search.sensefuel.live 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-ancestors https://*.lafoirfouille.fr/ https://api.cqeq65dd63-ffdigital1-d1-public.model-t.cc.commerce.ondemand.com https://api.cqeq65dd63-ffdigital1-s1-public.model-t.cc.commerce.ondemand.com https://api.cqeq65dd63-ffdigital1-p1-public.model-t.cc.commerce.ondemand.com https://v.calameo.com 'self'; object-src data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-ea703dfc82104969bee8e0a206da24b2' https://www.novantmychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.novantmychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com www.promessedefleurs.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com www.promessedefleurs.com 'self' 'unsafe-inline'; frame-ancestors www.promessedefleurs.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.promessedefleurs.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure-magenta.dalenys.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie www.promessedefleurs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com cl.avis-verifies.com bat.bing.com s.pinimg.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://unpkg.com/pwacompat www.promessedefleurs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com unpkg.com www.promessedefleurs.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.promessedefleurs.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net www.promessedefleurs.com 'self' 'unsafe-inline'; child-src www.promessedefleurs.com http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com www.promessedefleurs.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' data: https://vercel.live https://assets.vercel.com https://fonts.gstatic.com https://static.octopuscdn.com https://fonts.heyflow.cloud https://widget.moin.ai; style-src 'self' 'unsafe-inline' https://vercel.live https://static.octopuscdn.com https://assets.prd.heyflow.com https://fonts.heyflow.cloud https://widget.moin.ai; connect-src 'self' blob: https: https://browser-intake-datadoghq.eu; img-src 'self' data: blob: https://assets.prd.heyflow.com https://static.octopuscdn.com https://a.storyblok.com https://vercel.live https://vercel.com https://d.delivery.consentmanager.net https://cdn.consentmanager.net https://www.facebook.com https://px.ads.linkedin.com https://www.google.de https://trck.spoteffects.net https://gbskwe.joingsg.com https://www.google.com https://bat.bing.net https://googleads.g.doubleclick.net https://www.googletagmanager.com https://ad.doubleclick.net https://media.moin.ai https://bat.bing.com https://amt.octopusenergy.de https://connect.facebook.net https://tr.outbrain.com https://paid.outbrain.com https://assets.website-files.com https://cdn.oeg-kraken.energy https://pagead2.googlesyndication.com https://analytics.tiktok.com https://paid.outbrain.com https://translate.google.com https://uploads-ssl.webflow.com https://fonts.gstatic.com https://stats.g.doubleclick.net https://px.ads.linkedin.com; media-src 'self'; object-src 'none'; worker-src 'self' blob:; child-src 'self' blob:; manifest-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors https://app.storyblok.com https://octopusenergy.de; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://octopusenergy.de https://analytics.tiktok.com https://cdn.consentmanager.net https://www.googletagmanager.com https://d.delivery.consentmanager.net https://widget.moin.ai https://googleads.g.doubleclick.net https://trck.spoteffects.net https://static.hotjar.com https://amt.octopusenergy.de https://bat.bing.com https://connect.facebook.net https://trc.taboola.com https://s.pinimg.com https://wave.outbrain.com https://amplify.outbrain.com https://cdn.taboola.com https://snap.licdn.com https://script.hotjar.com https://sc-static.net https://tr.snapchat.com https://tr.outbrain.com https://ct.pinterest.com https://www.googleadservices.com https://www.google.com https://www.google.de https://www.youtube.com https://vercel.live https://app.storyblok.com https://assets.prd.heyflow.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net https://tr.snapchat.com https://ct.pinterest.com https://14621715.fls.doubleclick.net https://www.youtube.com https://form.typeform.com https://www.aboalarm.de https://vercel.live https://gateway.zscloud.net; report-uri https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubed29085b3db18380df488558228e1f2e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aoede-consumer-site%2Cenv%3Aoede-production 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://epic.gateway.patientco.com https://epic.production.paymentfusion.com https://premier.trustcommerce.com;script-src 'nonce-4c209492a8fc4407865f392d63b32c0e' https://mychart.et0965.epichosted.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart.et0965.epichosted.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';base-uri 'self';form-action 'self' 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.es https://www.myheritage.es 'unsafe-eval' 'nonce-3ff99279a9027dda4aba5f0c851c676f' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.es;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://assets.emarsys.net https://cdn.scarabresearch.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://production-tailoy-repo-magento-statics.s3.us-east-2.amazonaws.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://www.google-analytics.com https://recommender.scarabresearch.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' oqvestir.com.br *.oqvestir.com.br wake-components.fbitsstatic.net oqvestir.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.g.doubleclick.net *.doubleclick.net oqvestir.fbitsstatic.net *.criteo.com *.clarity.ms capig.shop2gether.com.br q.clarity.ms static.criteo.net clarity.ms sslwidget.criteo.com dynamic.criteo.com googleads.g.doubleclick.net gum.criteo.com bat.bing.com google.com.br googleadservices.com tags.creativecdn.com apigate.shop2gether.com.br o.clarity.ms *.creativecdn.com *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com n8n.icommgroup.com.br wake.koin.com.br *.icommgroup.com.br *.pinterest.com paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.api.useinsider.com *.useinsider.com *.secureacs.com *.crmbonus.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.sizebay.technology *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.wepowerconnections.com recommendationv2.api.useinsider.com wake-commerce-scripts.omni.chat trackings.nemu.com.br openfpcdn.io ipinfo.io api.ipify.org api.bigdatacloud.net firebase.googleapis.com *.googleapis.com d1vrnvkozosezy.cloudfront.net *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.internalsizebay.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.oqvestir.com.br oqvestir.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' http://*.uqtr.uquebec.ca http://*.uqtr.ca data: https: blob:; base-uri 'self' http://*.uqtr.ca; form-action 'self' https: javascript: inline:; report-to csp-endpoint; report-uri https://webservice.uqtr.ca/prod/nginx/csp_api/report 1 frame-ancestors https://*.prace.cz https://my.teamio.com https://*.facebook.com https://*.jobs.cz https://*.topjobs.sk; report-uri /csp-reports/ 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.wmf.com accountuat.wmf.com ad4m.at ct.pinterest.com fledge.eu.criteo.com groupe-seb.my.salesforce-sites.com gum.criteo.com service.force.com static.criteo.com static.criteo.net td.doubleclick.net www.paypalobjects.com www.sovendus-connect.com backoffice-eu.oct8ne.com static.trbo.com collect.trbo.com track2.trbo.com charger-v2.trbo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com *.awin1.com *.zenaps.com *.wepowerconnections.com magefan.com cm.magefan.com https://images.unsplash.com *.disqus.com https://img.youtube.com * https://api.mapbox.com *.hsforms.net *.hsforms.com 'self' data: *.contentsquare.net static.trbo.com collect.trbo.com track2.trbo.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.disqus.com * https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.contentsquare.net *.contentsquare.com halc.iadvize.com static.trbo.com api-v4.trbo.com charger-v2.trbo.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com service.force.com static.trbo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://maps.googleapis.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.contentsquare.net app.contentsquare.com api.paypal.com ariane.abtasty.com bat.bing.com cdn.cookielaw.org content.hotjar.io ct.pinterest.com dcinfos-cache.abtasty.com geolocation.onetrust.com googleads.g.doubleclick.net identification-api.sovendus.com maps.googleapis.com measurement-api.criteo.com pagead2.googlesyndication.com privacyportal-eu.onetrust.com region1.analytics.google.com stats.g.doubleclick.net tag.commander1.com try.abtasty.com ws.hotjar.com www.google.com www.google.de www.pinterest.com halc.iadvize.com data.trbo.com newsletter-api.trbo.com api-v4.trbo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://testgallito.free.beeceptor.com; report-to default; 1 default-src 'self' https:; font-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com; worker-src 'self' blob:; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: www.googletagmanager.com; connect-src 'self' https: ws: wss:; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf68dfe1092b9b71f30b0f8123a55b7f0&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=project%3Ask%2Cenv%3Aproduction&service=sk 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.nl https://www.myheritage.nl 'unsafe-eval' 'nonce-3c104231fb417184932455837aeac880' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.nl;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-recaptcha/_/js/k=boq-recaptcha.RecaptchaChallengePageUi.en_US.oxL6cTZPYys.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /recaptcha/challengepage/_/RecaptchaChallengePageUi/cspreport/fine-allowlist 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.fr https://www.myheritage.fr 'unsafe-eval' 'nonce-b092b2b245fe42ae556fa2d0b1ef7cbb' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.fr;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https:; style-src 'self' https:; report-uri https://csp-collector-qt0v.onrender.com/csp-report 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://static.dhlecommerce.nl https://fonts.gstatic.com *.fontawesome.com * data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://maps.googleapis.com https://maps.gstatic.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://static.dhlecommerce.nl https://maps.googleapis.com * 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com *.fontawesome.com * 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com * 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://static.unzer.com https://applepay.cdn-apple.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net https://cdn.consentmanager.net https://delivery.consentmanager.net https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com https://plumrocket.com landofcoder.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.bw-online-shop.com lantern.roeye.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net https://static.unzer.com *.online-metrix.net https://www.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.klarna.com *.klarnaevt.com *.klarnacdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.clickcease.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com *.klarnacdn.net 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.youpilot.org *.fact-finder.de https://cdn.consentmanager.net https://delivery.consentmanager.net https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com landofcoder.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; frame-src https://www.youtube.com https://www.youtube-nocookie.com; img-src 'self' data: https://i.ytimg.com; script-src 'self' https://www.youtube.com https://www.youtube-nocookie.com; connect-src 'self' https://www.youtube.com; media-src 'self' https://www.youtube.com 1 default-src 'self' thumbtack.okta.com *.oktacdn.com; connect-src 'self' thumbtack.okta.com thumbtack-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com thumbtack.kerberos.okta.com thumbtack.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-N8G_9DpQEy64vuMf-aP2pw' 'unsafe-eval' 'self' 'report-sample' thumbtack.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-N8G_9DpQEy64vuMf-aP2pw' 'self' 'report-sample' thumbtack.okta.com *.oktacdn.com; frame-src 'self' thumbtack.okta.com thumbtack-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' thumbtack.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' thumbtack.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://idp.thumbtack.io 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.merkur-static.si cdn.jsdelivr.net cdn.cnj.si omara.cdn-cnj.si ka-p.fontawesome.com media.flixfacts.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com cdn.jsdelivr.net *.nosto.com *.merkur-static.si *.fontawesome.com img.cdn-cnj.si www.merkur-static.si thumbs.nosto.com media.flixcar.com media.flixfacts.com logo.flix360.io rt.flix360.com maps.gstatic.com *.visualwebsiteoptimizer.com *.google.si *.facebook.com *.iprom.net *.hubspot.com inpref.com 536003278.recs.igodigital.com maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://api.cartfox.io https://app.cartfox.io *.avada.io *.shopify.com *.merkur-static.si cdn.jsdelivr.net unpkg.com *.pushpushgo.com *.fontawesome.com *.nosto.com *.smind.si kit.fontawesome.com inte.searchnode.io connect.nosto.com cpx.smind.si media.flixfacts.com media.flixcar.com maps.googleapis.com *.cloudfront.net *.iprom.net *.hs-scripts.com *.hs-banner.com *.hs-analytics.net *.facebook.net *.videoly.co 536003278.recs.igodigital.com 536003278.collect.igodigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.merkur-static.si cdn.jsdelivr.net media.flixcar.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://api.cartfox.io https://app.cartfox.io https://get.geojs.io *.avada.io *.merkur-static.si unpkg.com *.pushpushgo.com *.nosto.com *.fontawesome.com region1.google-analytics.com kit.fontawesome.com ka-p.fontawesome.com connect.nosto.com media.flixcar.com maps.googleapis.com *.visualwebsiteoptimizer.com inpref.com *.doubleclick.net *.iprom.net 536003278.recs.igodigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src media.flixcar.com rt.flix360.com 536003278.recs.igodigital.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://d045c69f-01fa-46bf-a2b1-87c1c2bb7952.sansec.watch/; report-to report-endpoint; 1 connect-src 'self' https://correspondent.report-uri.com https://static.cdn-decorrespondent.nl https://useruploads.cdn-decorrespondent.nl https://decorrespondent.matomo.cloud https://o206126.ingest.sentry.io https://space-corre.video-dns.com; media-src 'self' https://static.cdn-decorrespondent.nl https://traffic.omny.fm https://*.mc.tritondigital.com https://useruploads.cdn-decorrespondent.nl blob: https://space-corre.video-dns.com; form-action 'self' https://www.mollie.com https://pay.ideal.nl https://www.paypal.com; report-uri https://correspondent.report-uri.com/r/d/csp/reportOnly; report-to csp-report-only-endpoint 1 script-src 'nonce-6OMzJ74j3F9qRbi7L6ubSw==' 'self' cdn.orsted.com *.googletagmanager.com *.app.cookieinformation.com cdn.appdynamics.com *.googletagmanager.com *.gstatic.com *.googleoptimize.com www.googleadservices.com *.googleapis.com *.bing.com *.doubleclick.net *.t.co *.pardot.com *.youtube.com *.linkedin.com *.twitter.com *.globenewswire.com *.23video.com delivery.twentythree.com orsted.containers.piwik.pro orsted.piwik.pro *.crazyegg.com unpkg.com cs.lf-discover.com *.puzzel.com *.arcgis.com code.jquery.com *.lfeeder.com orsted-global-graduate-programme.simplecast.com omny.fm cdnjs.cloudflare.com *.bootstrapcdn.com *.defgo.com *.defgo.net *.vimeo.com presscloud.com *.ritzau.dk *.simplecast.com *.elnet.danskenergi.dk *.sli.do *.audioboom.com *.licdn.com *.adsrvr.org *.soundcloud.com *.google.com *.google.com.my *.google.nl *.google.dk *.facebook.net; style-src 'nonce-6OMzJ74j3F9qRbi7L6ubSw==' 'self' cdn.orsted.com fonts.googleapis.com; style-src-attr 'unsafe-inline' cdn.orsted.com; img-src 'self' data: cdn.orsted.com *.azureedge.net *.youtube.com *.23video.com delivery.twentythree.com www.googletagmanager.com *.lfeeder.com *.linkedin.com *.doubleclick.net *.pardot.com; media-src 'self' blob: cdn.orsted.com *.youtube.com *.23video.com delivery.twentythree.com; font-src 'self' data: fonts.gstatic.com cdn.orsted.com; frame-src *.app.cookieinformation.com *.youtube.com *.23video.com delivery.twentythree.com *.google.com *.google.nl *.googletagmanager.com *.doubleclick.net *.pardot.com; connect-src *.app.cookieinformation.com *.euroland.com *.eum-appdynamics.com *.googletagmanager.com *.google.com *.doubleclick.net *.googleadservices.com *.crazyegg.com *.linkedin.com orsted.piwik.pro *.pardot.com; worker-src 'self'; 1 font-src *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.fontawesome.com https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.alothemes.com *.magepow.com app.personaclick.com cdn.personaclick.com data: 'self' 'unsafe-inline'; form-action 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.facebook.com *.mncdn.org www.google.com.tr https://cdnydm.com/ https://cdn.dsmcdn.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.taggrs.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.youtube-nocookie.com player.vimeo.com *.facebook.com connect.facebook.net *.yapaytech https://cdn.yapaytech.com/ https://scripts.clarity.ms/ https://www.clarity.ms/ https://s2.adform.net/ https://track.adform.net/ https://mc.yango.com/ https://cdn.sgmntfy.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.taggrs.io https://browser.sentry-cdn.com *.alothemes.com *.magepow.com www.facebook.com graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com *.jsdelivr.net *.fontawesome.com *.alothemes.com *.magepow.com *.personaclick.com *.segmentify.com https://cdn.bellamaison.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net https://www.google.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ https://f.clarity.ms/collect https://h.clarity.ms/collect https://z.clarity.ms/collect/ https://mc.yango.com/ https://*.ingest.sentry.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-c5z4ND3FoJqjkpXKgNbcdw=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-meOopMjl0xvW9L/PPbkakH1L' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.it/api/csp-report; report-to csp-endpoint 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://mychart.personapay.com;script-src 'nonce-5f6225e60e0c4616b512b3d098aa26be' https://mywvuchart.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mywvuchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://*.epic.com https://*.geisinger.edu https://*.geisinger.org https://*.mycarecompass.edu https://*.mycarecompass.org https://*.mygeisinger.org https://geisinger.org https://www.geisinger.org;frame-src https://* 'self' epichttp: https://*.geisinger.edu https://pay.instamed.com https://paymentsafe.experianhealth.com;script-src https://mychart.mycarecompass.org 'self' 'unsafe-eval' 'unsafe-inline' https://*.geisinger.edu https://*.geisinger.org https://*.google.com https://*.googleapis.com https://*.gyantts.com https://*.jquery.com https://*.mycarecompass.org https://*.virtualearth.net https://ajax.microsoft.com https://mycarecompass.org https://twemoji.maxcdn.com https://unpkg.com https://www.gstatic.com;img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://*.amazonaws.com https://*.gyantts.com wss://web.production.gyantts.com wss://web2.dev.gyantts.com wss://web2.production.gyantts.com;style-src https://mychart.mycarecompass.org 'self' 'unsafe-inline' https://*.geisinger.edu https://*.geisinger.org https://*.gyantts.com https://*.mycarecompass.org https://mycarecompass.org https://s3.amazonaws.com;worker-src 'self' blob:;child-src 'self' blob:;font-src 'self' https://*.gyantts.com https://s3.amazonaws.com;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src *.gstatic.com *.fontawesome.com * *.googleapis.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.paypal.com https://www.googletagmanager.com https://www.google.com https://www.vimeo.com https://f.vimeocdn.com https://adyen.com https://checkoutshopper-test.adyen.com https://checkoutshopper-live.adyen.com https://pal-test.adyen.com https://pal-live.adyen.com https://amazon.com https://www.yotpo.com https://int-ecommerce.nexi.it *.kasanova.com * https://www.googletagmanager.com/ www.google.com www.gstatic.com apis.google.com accounts.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.sharethis.com https://cdn.clerk.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.google.com *.gstatic.com https://www.vimeo.com https://f.vimeocdn.com *.googleapis.com *.ggpht https://ecommerce.nexi.it *.cloudfront.net *.kasanova.com * https://static.zdassets.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://www.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.googleapis.com https://f.vimeocdn.com *.gstatic.com https://googleads.g.doubleclick.net *.clerk.io https://int-ecommerce.nexi.it *.kasanova.com https://assets.livestory.io https://js-agent.newrelic.com *.consentcdn.cookiebot.com/ * http://www.googletagmanager.com/ https://www.googletagmanager.com/ accounts.google.com cdn.jsdelivr.net *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://accounts.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.googleapis.com * *.fontawesome.com *.google.com *.gstatic.com accounts.google.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://assets.livestory.io https://api.livestory.io https://www.google-analytics.com https://int-ecommerce.nexi.it *.kasanova.com *.googleapis.com * http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com accounts.google.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' cdn2.hubspot.net *.hubspot.com *.hubspotusercontent10.net js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hs-banner.net *.hsforms.net *.hsforms.com static.hsappstatic.net js.hubspotfeedback.com feedback.hubapi.com js.usemessages.com *.vidyard.com cdnjs.cloudflare.com cdnjs.cloudflare.com 10921146.fls.doubleclick.net plausible.io *.hotjar.com *.hotjar.io *.qualified.com bttrack.com *.googletagmanager.com *.force.com *.thycotic.com *.centrify.com *.bidr.io *.rlcdn.cm t.co *.twitter.com burly.io *.clickagy.com *.doubleclck.net *.zoominfo.com lltrck.com facebook.com *.facebook.net *.redditstatic.com *.linkedin.com *.licdn.com *.demandbase.com *.zoominfo.com 'strict-dynamic' 'nonce-HFIfPHuOiwZmKx1+6E3mxA==' 1 default-src 'self'; script-src 'self' 'unsafe-inline' https: http: https://vercel.live https://vercel.com https://*.posthog.com *.clerk.accounts.dev https://cdn.mux.com https://mux.com https://*.mux.com https://stream.mux.com https://*.gleap.io/ https://translate.google.com/ https://translate.googleapis.com/ https://www.gstatic.com/ https://*.google.com/; style-src 'self' 'unsafe-inline' https://vercel.live/ https://*.mux.com; img-src 'self' blob: data: *.thenational.academy/ thenational.academy/ https://vercel.live/ https://vercel.com *.pusher.com/ data: blob: https://*.hubspot.com/ https://*.hsforms.com/ https://track.hubspot.com/ https://res.cloudinary.com/ https://res.cloudinary.com https://oaknationalacademy-res.cloudinary.com/ https://oaknationalacademy-res.cloudinary.com https://*.cloudinary.com/ https://*.cloudinary.com https://res.cloudinary.com/oak-web-application/ https://img.clerk.com/ https://*.mux.com/ https://stream.mux.com/ https://*.gleap.io/; font-src 'self' gstatic-fonts.thenational.academy/ fonts.gstatic.com/ data: https://vercel.live/ https://assets.vercel.com; object-src 'self' *.google.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self' *.google.com/; connect-src *.thenational.academy thenational.academy https://vercel.live/ https://vercel.com *.pusher.com *.pusherapp.com *.hubspot.com *.hsforms.com *.cloudinary.com/ https://eu.i.posthog.com *.posthog.com https://api.avo.app/ *.clerk.accounts.dev clerk-telemetry.com https://mux.com https://*.mux.com https://stream.mux.com https://inferred.litix.io *.gleap.io wss://*.gleap.io *.google.com *.bugsnag.smartbear.com *.bugsnag.com; media-src 'self' blob: *.thenational.academy/ https://res.cloudinary.com/ https://oaknationalacademy-res.cloudinary.com/ https://*.cloudinary.com/ https://*.mux.com/ https://stream.mux.com/ https://*.gleap.io/ https://ssl.gstatic.com; frame-src 'self' *.thenational.academy/ https://vercel.live/ https://vercel.com https://challenges.cloudflare.com https://www.avo.app/ https://stream.mux.com https://*.mux.com https://*.gleap.io/ *.google.com/; worker-src 'self' blob: *.thenational.academy/; child-src blob:; report-uri https://ph-eu-api.thenational.academy/report/?token=phc_LCrtgEAumOz4qgXuJNqMK2xisQ4mGaApixHEPXeRRoN&sample_rate=0.05&v=1; report-to posthog 1 connect-src 'self' data: https://www.motonet.fi https://graphql.datocms.com https://*.doubleclick.net https://www.instagram.com https://*.broman.group https://*.litix.io https://vimeo.com https://*.klarna.com https://*.klarnaevt.com/v1/ https://*.adyen.com/checkoutanalytics/ https://*.adyen.com/checkoutshopper/ https://api.postmarkapp.com https://www.youtube.com https://api.videoly.co https://js.testfreaks.com https://api.testfreaks.com https://reviews.testfreaks.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://api.custobar.com/js/v1/custobar.js https://*.google-analytics.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://*.googlesyndication.com https://*.adform.net https://*.creativecdn.com https://connect.facebook.net https://browser-intake-datadoghq.eu https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.fi https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com/ https://src.freshmarketer.eu/mas; img-src 'self' data: https://www.datocms-assets.com https://i.ytimg.com https://image.mux.com https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.fi; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://js.playground.kustom.co https://osm.klarnaservices.com/ https://*.adyen.com/ https://*.vimeo.com https://app.ecoonline.com https://www.maston.fi https://websds.volvo.com https://policy.app.cookieinformation.com/ https://*.criteo.com https://*.adform.net https://*.creativecdn.com https://www.facebook.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.broman.group https://maps.googleapis.com https://js.playground.kustom.co https://js.klarna.com https://js.klarna.com/web-sdk/ https://api.videoly.co/1/quchbox/0/299/quch.js https://www.paypal.com/sdk/js https://dapi.videoly.co https://www.youtube.com https://*.vimeo.com https://policy.app.cookieinformation.com https://api.custobar.com/js/v1/custobar.js https://*.criteo.net https://*.criteo.com https://*.adform.net https://connect.facebook.net https://tags.creativecdn.com https://dev.visualwebsiteoptimizer.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; object-src data:; worker-src 'self' blob:; 1 base-uri; default-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://docs.teket.jp data:; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://s.clarity.ms https://docs.teket.jp; form-action; frame-src https://www.google.com/ https://p01.mul-pay.jp; img-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://docs.teket.jp data:; object-src; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://p01.mul-pay.jp 'unsafe-inline' 'unsafe-eval' blob:; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://www.clarity.ms https://cdnjs.cloudflare.com https://code.jquery.com https://connect.facebook.net 'unsafe-inline' blob:; style-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io 'unsafe-inline' 1 connect-src 'self' https://dcinfos-cache.abtasty.com/ https://api-data-connector.abtasty.com/ https://ofx-privacy.my.onetrust.com/ https://geolocation.onetrust.com/ https://api.ofx.com https://ariane.abtasty.com https://bat.bing.com https://cdn.cookielaw.org https://*.clarity.ms https://fonts.googleapis.com https://px.ads.linkedin.com https://ssgtm.ofx.com https://stats.g.doubleclick.net https://ad.doubleclick.net/ https://try.abtasty.com https://www.redditstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.google.com https://pixel.byspotify.com https://d34r8q7sht0t9k.cloudfront.net https://pixel-config.reddit.com https://www.google.com.au https://pixels.spotify.com https://ipv4.podscribe.com https://adservice.google.co https://adservice.google.com https://*.sleeknote.com https://adservice.google.com/pagead/regclk https://www.google.com/pagead/landing https://typebot.io https://www.google.co.id/ads/ga-audiences https://www.google.co.za/ads/ga-audiences https://www.google.com.ph/ads/ga-audiences https://www.google.co.nz/ads/ga-audiences https://www.google.com.vn/ads/ga-audiences https://www.google.com.my/ads/ga-audiences https://www.google.ca/ads/ga-audiences https://www.google.bg/ads/ga-audiences https://www.google.co.in/ads/ga-audiences https://www.google.ro/ads/ga-audiences https://www.google.co.uk/ads/ga-audiences https://www.google.com.tr/ads/ga-audiences https://www.google.com.sg/ads/ga-audiences https://www.google.com.hk/ads/ga-audiences https://www.google.co.jp/ads/ga-audiences https://www.google.com.fj/ads/ga-audiences https://www.google.fi/ads/ga-audiences https://www.google.co.ma/ads/ga-audiences https://www.google.fr/ads/ga-audiences https://www.google.com.sa/ads/ga-audiences https://www.google.com.tw/ads/ga-audiences https://www.google.at/ads/ga-audiences https://www.google.co.il/ads/ga-audiences https://www.google.gr/ads/ga-audiences https://www.google.com.pk/ads/ga-audiences https://www.google.mk/ads/ga-audiences https://www.google.de/ads/ga-audiences https://www.google.co.kr/ads/ga-audiences https://www.google.com.kw/ads/ga-audiences https://www.google.co.th/ads/ga-audiences https://www.google.be/ads/ga-audiences https://www.google.com.cy/ads/ga-audiences https://www.google.es/ads/ga-audiences https://www.google.se/ads/ga-audiences https://www.google.cz/ads/ga-audiences https://www.google.lv/ads/ga-audiences https://www.google.ae/ads/ga-audiences https://www.google.lk/ads/ga-audiences https://www.google.pl/ads/ga-audiences https://www.google.hr/ads/ga-audiences https://www.google.nl/ads/ga-audiences https://www.google.ie/ads/ga-audiences https://www.google.kz/ads/ga-audiences https://www.google.rs/ads/ga-audiences https://www.google.md/ads/ga-audiences https://www.google.ch/ads/ga-audiences https://www.google.az/ads/ga-audiences https://www.google.it/ads/ga-audiences https://www.google.mu/ads/ga-audiences https://www.google.com.bd/ads/ga-audiences https://www.google.sn/ads/ga-audiences https://www.google.com.br/ads/ga-audiences https://www.google.sk/ads/ga-audiences https://www.google.ge/ads/ga-audiences https://www.google.no/ads/ga-audiences https://www.google.dk/ads/ga-audiences https://www.google.im/ads/ga-audiences https://www.google.gg/ads/ga-audiences https://www.google.com.qa/ads/ga-audiences https://www.google.ru/ads/ga-audiences https://www.google.pt/ads/ga-audiences https://www.google.com.np/ads/ga-audiences https://www.google.je/ads/ga-audiences https://www.google.com.na/ads/ga-audiences https://www.google.com.et/ads/ga-audiences https://www.google.com.kh/ads/ga-audiences https://www.google.lt/ads/ga-audiences https://www.google.com.co/ads/ga-audiences https://www.google.com.ng/ads/ga-audiences https://www.google.com.ec/ads/ga-audiences https://www.google.ci/ads/ga-audiences https://www.google.com.gh/ads/ga-audiences https://www.google.com.ar/ads/ga-audiences https://www.google.tn/ads/ga-audiences https://www.google.com.sl/ads/ga-audiences https://www.google.com.mx/ads/ga-audiences https://www.google.co.uz/ads/ga-audiences https://www.google.com.eg/ads/ga-audiences https://www.google.si/ads/ga-audiences https://www.google.as/ads/ga-audiences https://www.google.com/ccm/collect https://*.6sc.co https://*.demandbase.com https://*.company-target.com/ https://secure.adnxs.com/ https://app.navattic.com/ https://epsilon.6sense.com/ https://www.facebook.com/privacy_sandbox/topics/registration https://pixel.quantserve.com/; font-src 'self' https://fonts.gstatic.com https://common-fonts.abtasty.com https://sleeknote.com https://sleeknotestaticcontent.sleeknote.com/; frame-src 'self' https://1852302.fls.doubleclick.net https://widget.trustpilot.com https://td.doubleclick.net https://www.googletagmanager.com/ https://*.company-target.com/ https://www.google.com/ https://www.youtube.com/ https://www.youtube-nocookie.com/ https://subscriptions.smartrecruiters.com/ https://capture.navattic.com/ https://ssgtm.ofx.com/ https://go.message.ofx.com/; img-src 'self' https://c.bing.com https://static.wondaris.com https://analytics.google.com https://alb.reddit.com https://analytics.sleeknote.com https://analytics.twitter.com https://bat.bing.com https://*.clarity.ms https://pixel.quantserve.com/ https://www.linkedin.com/ https://px.ads.linkedin.com https://t.co https://www.facebook.com https://*.google-analytics.com https://www.google.com https://*.googletagmanager.com https://pixel.byspotify.com https://d34r8q7sht0t9k.cloudfront.net https://www.google.com.au https://stats.g.doubleclick.net https://ad.doubleclick.net https://cdn.cookielaw.org https://www.google.com.sg https://verifi.podscribe.com https://collector-31846.tvsquared.com https://www.google.ca/ads/ga-audiences https://www.google.ca/pagead/1p-user-list/ https://www.google.co.uk/ads/ga-audiences https://www.google.co.pk/ads/ga-audiences https://www.google.co.nz/ads/ga-audiences https://www.google.co.in/ads/ga-audiences https://www.google.co.nz/pagead/1p-user-list/ https://www.google.com.my/ads/ga-audiences https://www.google.co.in/pagead/1p-user-list/ https://www.google.com.my/pagead/1p-user-list/ https://www.google.com.ng/ads/ga-audiences https://www.google.co.za/ads/ga-audiences https://www.google.co.za/pagead/1p-user-list/ https://www.google.lk/ads/ga-audiences https://www.google.co.id/pagead/1p-user-list/ https://www.google.co.id/ads/ga-audiences https://www.google.com.hk/ads/ga-audiences https://www.google.com.hk/pagead/1p-user-list/ https://www.google.com.vn/ads/ga-audiences https://www.google.com.vn/pagead/1p-user-list/ https://www.google.dk/ads/ga-audiences https://www.google.com.ph/ads/ga-audiences https://www.google.fr/ads/ga-audiences https://www.google.co.jp/ads/ga-audiences https://www.google.co.jp/pagead/1p-user-list/ https://www.google.com.np/pagead/1p-user-list/ https://www.google.com.np/ads/ga-audiences https://www.google.com.bd/ads/ga-audiences https://www.google.pl/ads/ga-audiences https://www.google.de/ads/ga-audiences https://www.google.com.mx/ads/ga-audiences https://www.google.com.mx/pagead/1p-user-list/ https://www.google.com.ph/pagead/1p-user-list/ https://sleeknote.com https://www.google.com.ng/pagead/1p-user-list/ https://www.google.co.zm/ads/ga-audiences https://www.google.co.uz/ads/ga-audiences https://www.google.co.uz/pagead/1p-user-list/ https://www.google.com.pk/ads/ga-audiences https://www.google.co.zm/pagead/1p-user-list/ https://adservice.google.com/pagead/regclk https://www.google.ch/ads/ga-audiences https://www.google.ch/pagead/1p-user-list/ https://www.google.hu/ads/ga-audiences https://www.google.sk/ads/ga-audiences https://www.google.ae/ads/ga-audiences https://www.google.ae/pagead/1p-user-list/ https://www.google.com.cy/ads/ga-audiences https://www.google.it/ads/ga-audiences https://www.google.com.om/ads/ga-audiences https://www.google.ro/ads/ga-audiences https://www.google.com.tw/ads/ga-audiences https://www.google.com.tw/pagead/1p-user-list/ https://www.google.co.th/ads/ga-audiences https://www.google.com.tr/ads/ga-audiences https://www.google.mu/ads/ga-audiences https://www.google.mu/pagead/1p-user-list/ https://www.google.com.kh/ads/ga-audiences https://www.google.com.et/ads/ga-audiences https://www.google.co.kr/ads/ga-audiences https://www.google.co.kr/pagead/1p-user-list/ https://www.google.co.th/pagead/1p-user-list/ https://www.google.com.tr/pagead/1p-user-list/ https://www.google.bg/ads/ga-audiences https://www.google.com.sa/ads/ga-audiences https://www.google.com.sa/pagead/1p-user-list/ https://www.google.nl/ads/ga-audiences https://www.google.co.cr/ads/ga-audiences https://www.google.com.pk/pagead/1p-user-list/ https://www.google.at/ads/ga-audiences https://www.google.ie/ads/ga-audiences https://www.google.com.sg/ads/ga-audiences https://www.google.fi/ads/ga-audiences https://www.google.com.kw/ads/ga-audiences https://www.google.com.kw/pagead/1p-user-list/ https://www.google.iq/pagead/1p-user-list/ https://www.google.cz/ads/ga-audiences https://www.google.co.il/ads/ga-audiences https://www.google.co.il/pagead/1p-user-list/ https://www.google.com.bd/pagead/1p-user-list/ https://www.google.al/ads/ga-audiences https://www.google.gr/ads/ga-audiences https://www.google.rs/ads/ga-audiences https://www.google.rs/pagead/1p-user-list/ https://www.google.no/ads/ga-audiences https://www.google.mk/ads/ga-audiences https://www.google.mk/pagead/1p-user-list/ https://www.google.se/ads/ga-audiences https://www.google.com.fj/ads/ga-audiences https://www.google.com.fj/pagead/1p-user-list/ https://www.google.co.ma/ads/ga-audiences https://www.google.co.ma/pagead/1p-user-list/ https://www.google.co.ke/ads/ga-audiences https://www.google.com.bh/ads/ga-audiences https://www.google.com.bh/pagead/1p-user-list/ https://www.google.es/ads/ga-audiences https://www.google.co.ug/ads/ga-audiences https://www.google.co.ug/pagead/1p-user-list/ https://www.google.co.ke/pagead/1p-user-list/ https://www.google.com.et/pagead/1p-user-list/ https://www.google.com.sb/ads/ga-audiences https://www.google.hr/ads/ga-audiences https://www.google.lu/ads/ga-audiences https://www.google.lk/pagead/1p-user-list/ https://www.google.com.om/pagead/1p-user-list/ https://www.google.tl/ads/ga-audiences https://www.google.tl/pagead/1p-user-list/ https://www.google.kz/ads/ga-audiences https://www.google.kz/pagead/1p-user-list/ https://www.google.gg/ads/ga-audiences https://www.google.com.mm/ads/ga-audiences https://www.google.pt/ads/ga-audiences https://www.google.ee/ads/ga-audiences https://www.google.com.eg/ads/ga-audiences https://www.google.gg/pagead/1p-user-list/ https://www.google.be/ads/ga-audiences https://www.google.mn/ads/ga-audiences https://www.google.ci/ads/ga-audiences https://www.google.com.pg/ads/ga-audiences https://www.google.com.gh/ads/ga-audiences https://www.google.com.eg/pagead/1p-user-list/ https://www.google.im/ads/ga-audiences https://www.google.im/pagead/1p-user-list/ https://www.google.com.qa/ads/ga-audiences https://www.google.com.qa/pagead/1p-user-list/ https://www.google.si/ads/ga-audiences https://www.google.tn/ads/ga-audiences https://www.google.tn/pagead/1p-user-list/ https://www.google.dz/ads/ga-audiences https://www.google.dz/pagead/1p-user-list/ https://www.google.com.gh/pagead/1p-user-list/ https://www.google.ws/ads/ga-audiences https://www.google.ge/ads/ga-audiences https://www.google.ge/pagead/1p-user-list/ https://www.google.lv/ads/ga-audiences https://www.google.cl/ads/ga-audiences https://www.google.ne/ads/ga-audiences https://www.google.ne/pagead/1p-user-list/ https://www.google.me/ads/ga-audiences https://www.google.me/pagead/1p-user-list/ https://www.google.mv/ads/ga-audiences https://www.google.com.na/ads/ga-audiences https://www.google.com.na/pagead/1p-user-list/ https://www.google.mw/ads/ga-audiences https://www.google.mw/pagead/1p-user-list/ https://www.google.com.gi/ads/ga-audiences https://www.google.com.gi/pagead/1p-user-list/ https://www.google.co.tz/ads/ga-audiences https://www.google.co.tz/pagead/1p-user-list/ https://www.google.be/pagead/1p-user-list/ https://www.google.md/ads/ga-audiences https://www.google.com.pe/ads/ga-audiences https://www.google.com.pe/pagead/1p-user-list/ https://www.google.vu/ads/ga-audiences https://www.google.com.ar/ads/ga-audiences https://www.google.com.ar/pagead/1p-user-list/ https://www.google.com.lb/ads/ga-audiences https://www.google.com.lb/pagead/1p-user-list/ https://www.google.gy/ads/ga-audiences https://www.google.vu/pagead/1p-user-list/ https://www.google.lt/ads/ga-audiences https://www.google.az/ads/ga-audiences https://www.google.az/pagead/1p-user-list/ https://www.google.com.bn/ads/ga-audiences https://www.google.com.bn/pagead/1p-user-list/ https://www.google.sn/ads/ga-audiences https://www.google.sn/pagead/1p-user-list/ https://www.google.ba/ads/ga-audiences https://www.google.sm/ads/ga-audiences https://www.google.com.br/ads/ga-audiences https://www.google.com.br/pagead/1p-user-list/ https://www.google.dk/pagead/1p-user-list/ https://www.google.co.bw/ads/ga-audiences https://www.google.co.bw/pagead/1p-user-list/ https://www.google.com.jm/ads/ga-audiences https://www.google.com.jm/pagead/1p-user-list/ https://www.google.jo/ads/ga-audiences https://www.google.jo/pagead/1p-user-list/ https://www.google.ga/ads/ga-audiences https://www.google.com.do/ads/ga-audiences https://www.google.com.do/pagead/1p-user-list/ https://www.google.sr/ads/ga-audiences https://www.google.bj/ads/ga-audiences https://www.google.bj/pagead/1p-user-list/ https://www.google.com/pagead/1p-user-list/ https://www.google.ru/ads/ga-audiences https://www.google.com.co/ads/ga-audiences https://www.google.com.co/pagead/1p-user-list/ https://www.google.je/ads/ga-audiences https://www.google.je/pagead/1p-user-list/ https://www.google.com.gt/ads/ga-audiences https://www.google.com.gt/pagead/1p-user-list/ https://www.google.com.ag/ads/ga-audiences https://www.google.com.mt/ads/ga-audiences https://www.google.ad/ads/ga-audiences https://www.google.ad/pagead/1p-user-list/ https://www.google.com.ec/ads/ga-audiences https://www.google.com.ec/pagead/1p-user-list/ https://www.google.hn/ads/ga-audiences https://www.google.hn/pagead/1p-user-list/ https://www.google.ci/pagead/1p-user-list/ https://www.google.ru/pagead/1p-user-list/ https://www.google.com.sl/ads/ga-audiences https://www.google.sr/pagead/1p-user-list/ https://www.google.bs/ads/ga-audiences https://www.google.bs/pagead/1p-user-list/ https://www.google.dj/ads/ga-audiences https://www.google.com.pa/ads/ga-audiences https://www.google.com.pa/pagead/1p-user-list/ https://www.google.al/pagead/1p-user-list/ https://www.google.cl/pagead/1p-user-list/ https://www.google.ht/ads/ga-audiences https://www.google.ws/pagead/1p-user-list/ https://www.google.com.pr/ads/ga-audiences https://www.google.com.pr/pagead/1p-user-list/ https://www.google.co.ao/ads/ga-audiences https://www.google.co.ao/pagead/1p-user-list/ https://www.google.com.sb/pagead/1p-user-list/ https://www.google.as/pagead/1p-user-list/ https://www.google.as/ads/ga-audiences https://www.google.co.cr/pagead/1p-user-list/ https://www.google.md/pagead/1p-user-list/ https://*.6sc.co https://id.rlcdn.com/ https://assets-manager.abtasty.com/ https://segments.company-target.com/; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://connect.facebook.net/ https://*.clarity.ms/ https://try.abtasty.com/ https://www.googletagmanager.com/gtag/ https://sleeknotestaticcontent.sleeknote.com/ https://bat.bing.com/ https://cdn.cookielaw.org/scripttemplates/ https://cdn.jsdelivr.net/npm/@typebot.io/js@0.2.15/dist/web.js https://cdn.mouseflow.com/projects/a65f2542-c798-4cbc-b46e-2101e508dc85.js https://cdnjs.cloudflare.com/ajax/libs/jsSHA/2.3.1/sha256.js https://connect.facebook.net/en_US/fbevents.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/766888392/ https://rules.quantcount.com/rules-p-9xPpAFMcLk8qV.js https://secure.quantserve.com/quant.js https://sleeknotecustomerscripts.sleeknote.com/21647.js https://sleeknotestaticcontent.sleeknote.com/core.js https://snap.licdn.com/li.lms-analytics/ https://static.ads-twitter.com/uwt.js https://static.wondaris.com/sdks/webhook-collector-module-webjs-latest.min.js https://utt.impactcdn.com/A3571279-5f42-4d2f-9539-72ae761405d11.js https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://*.googletagmanager.com https://www.redditstatic.com/ads/pixel.js https://code.highcharts.com/stock/highstock.js https://code.highcharts.com/highcharts-more.js https://cdn.jsdelivr.net/npm/@typebot.io/js@0.2/dist/web.js https://code.highcharts.com https://analytics.google.com https://pixel.byspotify.com/ping.min.js https://d34r8q7sht0t9k.cloudfront.net/tag.js https://collector-31846.tvsquared.com https://secure.leadforensics.com https://*.6sc.co https://pi.pardot.com https://go.message.ofx.com https://*.demandbase.com https://www.gstatic.com/recaptcha/releases/ https://www.smartrecruiters.com/job-api/public/search/widgets/OFX1/ https://subscriptions.smartrecruiters.com/widget/ https://static.smartrecruiters.com/job-widget/ https://js.navattic.com; style-src 'unsafe-inline' 'report-sample' 'self' https://static.smartrecruiters.com/job-widget/ 1 default-src 'self' *.wistia.com *.wistia.net embedwistia-a.akamaihd.net/ https://fonts.googleapis.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://edge.fullstory.com https://rs.fullstory.com https://ajax.googleapis.com/ https://first.iovation.com/ https://mpsnare.iesnare.com/ https://128-koi-090.mktoresp.com/ *.gskydev.net *.gskydev.com https://auth.prod.greensky.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://code.jquery.com https://cdn.jsdelivr.net https://pages.greenskycredit.com https://www.google.com/ https://www.gstatic.com https://cdnjs.cloudflare.com https://app-ab27.marketo.com https://munchkin.marketo.net https://abrtp1-cdn.marketo.com blob: http://static.site24x7rum.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com *.wistia.com https://rtp-static.marketo.com https://abrtp1.marketo.com https://js.driftt.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com/ https://pages.greenskycredit.com/ https://cdn.jsdelivr.net/ https://www.greensky.com/ *.gskydev.com *.gskydev.net https://use.fontawesome.com/ https://pro.fontawesome.com/ https://rtp-static.marketo.com/ https://fonts.googleapis.com/ https://fonts.googleapis.com/css/ https://app-ab27.marketo.com/ https://munchkin.marketo.net; font-src 'self' https://cdnjs.cloudflare.com https://pro.fontawesome.com/ data: https://fonts.gstatic.com https://fast.wistia.com https://use.fontawesome.com; img-src 'self' https://www.googletagmanager.com https://rs.fullstory.com *.greensky.com/ *.gskydev.com/ *.gskydev.net/ https://embed-ssl.wistia.com data: https://www.google-analytics.com https://stats.g.doubleclick.net https://fast.wistia.com https://greensky.dotcmscloud.com https://*.greensky.dotcmscloud.com embedwistia-a.akamaihd.net/ https://embed-fastly.wistia.com http://embed.wistia.com/ https://www.google.com https://www.google.de https://app-ab27.marketo.com https://pages.greenskycredit.com; media-src 'self' blob: https://js.driftt.com; frame-src 'self' https://pages.greenskycredit.com/ https://app-ab27.marketo.com/ https://www.google.com/ https://js.driftt.com; connect-src 'self' https://analytics.google.com https://edge.fullstory.com https://rs.fullstory.com *.gskydev.com/ *.gskydev.net/ https://128-koi-090.mktoresp.com/ https://abrtp1.marketo.com https://*.google-analytics.com https://stats.g.doubleclick.net *.greensky.dotcmscloud.com https://greensky.dotcmscloud.com *.greensky.com *.litix.io embedwistia-a.akamaihd.net/ *.wistia.com https://128-koi-090.mktoresp.com; object-src 'self' https://app-ab27.marketo.com/ ; base-uri 'self';manifest-src 'self'; worker-src 'none'; report-to https://www.greensky.com 1 report-uri /csp-report-endpoint.php 1 font-src *.gstatic.com fonts.gstatic.com use.typekit.net *.typekit.net *.googleapis.com data: https://www.googletagmanager.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action www.facebook.com ecommerce.raiffeisenbank.rs *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self' *.jasmin.rs *.cookiebot.com *.hotjar.com *.googletagmanager.com www.gstatic.com 'self'; frame-src www.facebook.com bid.g.doubleclick.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.jasmin.rs *.yandex.com *.yandex.md *.doubleclick.net *.cookiebot.com *.googletagmanager.com *.yango.com fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com 'self' 'unsafe-inline'; img-src *.googleapis.com *.gstatic.com stats.g.doubleclick.net www.google.com www.google.rs www.facebook.com www.googletagmanager.com storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net bid.g.doubleclick.net analytics.google.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.yandex.ru https://yandex.ru *.yandex.com *.yandex.md *.cookiebot.com *.yads.tech *.sharethis.com *.ymmobi.com *.doubleclick.net *.opera.com *.jasmin.rs jasmin.b-cdn.net kickoffcrm.com *.google.ru *.yango.com *.facebook.net *.linkedin.com data: www.googleadservices.com www.google-analytics.com p.typekit.net *.paypal.com *.typekit.net magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.googleapis.com *.gstatic.com *.googletagmanager.com www.google-analytics.com connect.facebook.net googleads.g.doubleclick.net stats.g.doubleclick.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.hotjar.com *.yandex.ru *.yandex.com *.cookiebot.com *.jasmin.rs mc.yango.com jasmin.sales-snap.com *.licdn.com *.tiktok.com assets.adobedtm.com *.adobe.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.disqus.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.jasmin.rs jasmin.sales-snap.com *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.b-cdn.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.googleapis.com *.google.com google.com www.google-analytics.com connect.facebook.net stats.g.doubleclick.net *.facebook.com dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com *.cardinalcommerce.com vimeo.com ekr.zdassets.com get.geojs.io *.avada.io *.hotjar.com *.hotjar.io wss://ws.hotjar.com storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.yandex.ru *.yandex.com yandex.com *.yandex.md *.doubleclick.net *.jasmin.rs *.googlesyndication.com *.yango.com jasmin.sales-snap.com *.linkedin.com *.cookiebot.com *.tiktok.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io *.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://get.geojs.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-60b2a1a1-0ff4-43a4-a754-6639bdf8db96' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.ro https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.ro/eum-collector/report/csp-report; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; connect-src * 'unsafe-inline' 'unsafe-eval' data: blob:; img-src * data: blob:; font-src * data:; style-src * 'unsafe-inline' data:; style-src-elem * 'unsafe-inline' data:; frame-src * data: blob:; media-src * data: blob:; object-src *; frame-ancestors 'none'; report-to csp-endpoint; 1 default-src * 'unsafe-inline' 'unsafe-eval'; script-src 'none'; report-uri https://greatergiving.report-uri.com/r/d/csp/reportOnly 1 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-attr 'self'; base-uri 'self'; frame-ancestors 'self' https: 1 connect-src 'self' *.google.com *.google.cz *.leady.com *.google-analytics.com *.facebook.net connect.facebook.net https://cdn.jsdelivr.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net; script-src 'self' 'nonce-ZjcxY2I1MDU1ZWQ1ZDVmNA==' *.google.com *.google.cz *.leady.com *.google-analytics.com *.facebook.net connect.facebook.net https://cdn.jsdelivr.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net 'sha256-Ry5VVOTX8NJGEP4t9KtV/jWVgiv7ZcNmtZxCQScUTlk=' 'sha256-8iiJTU1Hf/vwORdni3nM30l8Ko0NMb8bqvTfGeIbIA4='; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; img-src 'self' 'self' https://*.google-analytics.com https://*.googletagmanager.com https://www.facebook.com/ https://*.google.cz/ https://*.googleusercontent.com https://ct.leady.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; report-uri https://www.expats.cz/csp-report 1 object-src 'none'; script-src 'self' https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem * 'unsafe-inline'; style-src 'self' cdnjs.cloudflare.com https://api.mapbox.com https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem * 'unsafe-inline'; frame-ancestors 'self' 1 script-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com ajax.googleapis.com js.pusher.com use.fontawesome.com sdk.amazonaws.com app-rsrc.getbee.io loader.getbee.io localhost:3000 localhost:8080 127.0.0.1:3000 127.0.0.1:8080; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com; img-src 'self' secure.gravatar.com cartstack.s3.amazonaws.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com; connect-src 'self' api.cartstack.com ws-us3.pusher.com wss://ws-us3.pusher.com bee-auth.getbee.io bee-utils.getbee.io bee-stats.getbee.io bee-sentry.beefree.io bee-bumper.getbee.io localhost:3000 localhost:8080 ws://localhost:3000 ws://localhost:8080; frame-src 'self' app.getbee.io; default-src 'none'; object-src 'none'; media-src 'self'; worker-src 'self'; manifest-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri /csp-report.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * sibautomation.com *.criteo.com *.gelproximity.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.elfsight.com *.elfsightcdn.com *.trustpilot.com *.trustpilot.net *.doofinder.com *.google.com *.google.it *.bidswitch.net *.doubleclick.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv eb2.3lift.com *.yahoo.com *.adform.net *.criteo.com *.popupsmart.com *.onesignal.com upstream.heidipay.com sbx-upstream.heidipay.io *.casalemedia.com id5-sync.com *.360yield.com *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.1rx.io *.agkn.com *.unrulymedia.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.gstatic.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.elfsight.com *.doofinder.com sibautomation.com *.iubenda.com *.popupsmart.com *.criteo.com *.onesignal.com onesignal.com *.gelproximity.com *.clerk.io *.hotjar.com www.google.com www.gstatic.com beacon.riskified.com tracking.trovaprezzi.it tps.trovaprezzi.it www.trovaprezzi.it *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.doofinder.com onesignal.com *.popupsmart.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.onesignal.com onesignal.com *.popupsmart.com *.elfsight.com *.doofinder.com wss://*.doofinder.com *.brevo.com *.iubenda.com *.doubleclick.net *.criteo.com *.google-analytics.com www.google.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 media-src 'self' blob: data: https://bayer04.stream41.radiohost.de https://bayer04.do-not-publish.com http://bayer04-live.cast.addradio.de https://*.cdninstagram.com; default-src 'self' https://*.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.b04itpg.de https://*.bayer04.de https://*.usercentrics.eu https://*.facebook.net https://*.wt-safetag.com https://*.flockler.com https://*.sportradar.com; script-src-elem 'self' 'unsafe-inline' https://*.bayer04.de https://www.bayer04.de https://cdn-werkself-prod.bayer04.de https://*.usercentrics.eu https://www.gstatic.com https://*.facebook.net https://*.wt-safetag.com https://*.cdn.flockler.com https://*.flockler.com https://avplayer-cdn.sportradar.com https://*.sportradar.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://*.b04itpg.de https://*.bayer04.de https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://*.sportradar.com; font-src 'self' https://*.b04itpg.de https://*.bayer04.de data:; img-src 'self' data: https://*.b04itpg.de https://*.bayer04.de https://www.bayer04.de https://cdn-werkself-prod.bayer04.de https://*.usercentrics.eu https://*.facebook.com https://*.ytimg.com https://*.youtube.com https://*.facebook.net https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://flockler.com https://*.flocklr.com https://*.cdninstagram.com https://*.twimg.com https://*.fbcdn.net https://*.raxcdn.com; connect-src 'self' data: https://*.sentry.io wss://*.b04itpg.de https://*.b04itpg.de https://*.bayer04.de https://*.usercentrics.eu https://*.wt-safetag.com https://*.facebook.com https://*.facebook.net https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://spottvod.akamaized.net https://*.youborafds01.com https://ls.readertracking.com https://eu-api.friendlycaptcha.eu; frame-src 'self' https://my.matterport.com https://*.flockler.com https://www.google.com https://www.youtube-nocookie.com; frame-ancestors 'none'; manifest-src https://*.bayer04.de; report-uri https://o4508738008186880.ingest.de.sentry.io/api/4510279136837712/security/?sentry_key=453d974898eaf8cbcad7111d916a5b22; report-to csp-endpoint 1 font-src fonts.gstatic.com data: likeme.com.co *.likeme.com.co maxcdn.bootstrapcdn.com s3.amazonaws.com *.fontawesome.com *.gstatic.com 'self' data: https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com gum.criteo.com likeme.com.co *.likeme.com.co *.criteo.com fledge.criteo.com app.zinrelo.com www.youtube.com *.addi.com td.doubleclick.net *.mercadolibre.com *.blob.core.windows.net/* *.mercadopago.com *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://ibang-webviews.ibang.ai https://app.zinrelo.com https://vars.hotjar.com https://static.criteo.net http://static.criteo.net https://td.doubleclick.net https://fledge.us.criteo.com https://fledge.eu.criteo.com 'self' 'unsafe-inline'; img-src https://assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.likeme.com.co *.cloudfront.net www.google.cl www.google.com.uy www.google.com.ar www.google.com.co dis.criteo.com criteo-sync.teads.tv criteo-partners.tremorhub.com d1qbqkkh49kht1.cloudfront.net zinrelo-notification-images.s3.amazonaws.com *.addi.com *.clarity.ms *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: https://ibangblob.blob.core.windows.net www.mercadolivre.com http://imgmp.mlstatic.com https://cdn.stickyadstv.com https://www.google.com.ar https://www.mercadopago.com.co http://img.mlstatic.com https://pixel.rubiconproject.com https://likeme.com.co https://*.g.doubleclick.net https://*.smartadserver.com https://*.cloudfront.net https://sync.outbrain.com https://contextual.media.net https://ad.360yield.com https://r.casalemedia.com https://cm.adform.net https://x.bidswitch.net https://match.sharethrough.com https://ads.stickyadstv.com https://exchange.mediavine.com https://sync-t1.taboola.com https://sync-criteo.ads.yieldmo.com https://c.bing.com https://e1.emxdgt.com https://s.ad.smaato.net https://i.liadm.com https://ads.yahoo.com https://ups.analytics.yahoo.com https://secure.adnxs.com https://ib.adnxs.com https://sp.analytics.yahoo.com https://dis.criteo.com https://i6.liadm.com https://simage2.pubmatic.com https://eb2.3lift.com https://jadserve.postrelease.com https://www.google.com.co https://criteo-sync.teads.tv https://tg.socdm.com https://visitor.omnitagjs.com https://gum.criteo.com https://matching.ivitrack.com https://trends.revcontent.com https://ade.clmbtech.com https://idsync.rlcdn.com https://tags.bluekai.com https://s3.amazonaws.com https://criteo-partners.tremorhub.com https://hb.yahoo.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com dynamic.c static.criteo.net dynamic.criteo.com sslwidget.criteo.com fast.amc.demdex.net widget.eu.criteo.com likeme.com.co *.likeme.com.co *.cloudfront.net *.zinrelo.com cdnjs.cloudflare.com www.googleoptimize.com www.clarity.ms analytics.tiktok.com *.embluemail.com s3.amazonaws.com cdn.addi.com www.youtube.com static.doubleclick.net www.google.com ajax.googleapis.com connect.nosto.com *.taboola.com *.hotjar.com *.mlstatic.com *.mercadopago.com *.google.com https://maps.googleapis.com *.blob.core.windows.net/* www.facebook.com graph.facebook.com business.facebook.com *.gstatic.com https://www.google.com https://cdn.zinrelo.com http://cdn.zinrelo.com https://www.wheelofpopups.com https://*.cloudfront.net https://app.zinrelo.com https://www.googleoptimize.com https://cdn.embluemail.com https://widgets-static.embluemail.com https://script.hotjar.com https://static.hotjar.com https://cdnjs.cloudflare.com https://*.g.doubleclick.net https://*.mailmunch.com https://widgets-api.embluemail.com https://analytics.tiktok.com https://www.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co likeme.com.co *.likeme.com.co use.fontawesome.com *.cloudfront.net maxcdn.bootstrapcdn.com www.youtube.com *.fontawesome.com *.mercadopago.com *.mlstatic.com *.googleapis.com *.gstatic.com https://trazosvisuales.com https://trazosvisuales.info https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.comapi.com bam.nr-data.net likeme.com.co *.likeme.com.co maxcdn.bootstrapcdn.com gum.criteo.com s.clarity.ms app.zinrelo.com www.youtube.com channels-public-api.addi.com www.google.cl www.google.com.uy www.google.com.ar www.google.com.co *.google.com *.clarity.ms mug.criteo.com connect.nosto.com googleads.g.doubleclick.net jnn-pa.googleapis.com *.mercadopago.com *.mercadolibre.com *.sistecredito.com/* *.blob.core.windows.net/* *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://trazosvisuales.info https://maxcdn.bootstrapcdn.com https://trazosvisuales.com https://measurement-api.criteo.com/ https://analytics.tiktok.com/ https://v.clarity.ms https://pagead2.googlesyndication.com/ https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net s.clarity.ms *.google.com www.google-analytics.com analytics.tiktok.com likeme.com.co *.likeme.com.co *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob:; font-src * data:; media-src * blob:; worker-src * blob:; frame-src * data: blob:; connect-src *; frame-ancestors 'none'; report-uri /csp-violation-report 1 worker-src blob: 'self';font-src data: https: 'self';img-src data: https: 'self';media-src https: 'self';connect-src https://*.google.com https://cea.formstack.com https://consent.cookie-script.com/ https://cookie-script.com https://edge.api.brightcove.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://manifest.prod.boltdns.net https://metrics.brightcove.com https://pixel-config.reddit.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://www.google.com https://www.redditstatic.com 'self';script-src https://*.google.com https://cdn.clinch.co https://cea.formstack.com https://connect.facebook.net https://consent.cookie-script.com/ https://cookie-script.com https://edge.api.brightcove.com https://players.brightcove.net https://snap.licdn.com https://static.formstack.com https://www.google.com https://www.googletagmanager.com/ https://www.gstatic.com/ 'self' 'sha256-DsBFEDeAVB8NfiULTlZ50vO8T1PBE1Z23d41C/l2PuY=' 'sha256-P6r4MES3B1SQPyCLTBrmNBJPZsVpoEzrg/Dzfu8xk/w=' 'sha256-yTjADT6NV2O6PKU2MuEDM2Na3ABcSUsRuRkMDHUsvjQ=' 'unsafe-eval' 'unsafe-hashes';style-src https://fonts.googleapis.com 'self' 'unsafe-hashes' 'unsafe-inline';frame-src https://player.cohostpodcasting.com https://www.google.com 'self';base-uri 'self';default-src 'self';manifest-src 'self' 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-UEOLcuITB2NclKvJKvMDPA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 frame-ancestors 'self' *.dev-emotive.com https://setup-shop.emotiveapp.co *.myshopify.com;font-src fonts.gstatic.com;default-src 'self';style-src 'self' 'unsafe-inline' https://emotivecdn.io *.dev-emotive.com fonts.googleapis.com;frame-src ;connect-src ;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://emotivecdn.io *.dev-emotive.com https://www.googletagmanager.com;img-src 'self' data: 1 font-src fonts.gstatic.com use.typekit.net self data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://store.plumrocket.com pal-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com self *.doubleclick.net *.criteo.com *.easydmp.net *.snapchat.com https://store.plumrocket.com https://accounts.google.com checkoutshopper-test.adyen.com pal-test.adyen.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com self *.bing.com *.paypal.com *.google.fr *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.cookielaw.org *.snapchat.com checkoutshopper-test.adyen.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com self sc-static.net *.abtasty.com *.jsdelivr.net *.gstatic.com *.facebook.net *.tiktok.com *.googleapis.com *.easydmp.net *.vzbl.eu *.aticdn.net *.m1by1.com *.woosmap.com *.doubleclick.net *.cookielaw.org *.snapchat.com *.valiuz.com *.mediarithmics.com *.prediggo.services https://accounts.google.com checkoutshopper-test.adyen.com 'self' 'unsafe-eval' 'nonce-c3lhanB6b2dodWl1NDRueDh0MHN3ZGJnbXlicTFjbHI=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com self *.gstatic.com *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.snapchat.com https://accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com self *.snapchat.com *.cookielaw.org *.abtasty.com *.googleapis.com *.vzbl.eu *.criteo.com *.easydmp.net *.xiti.com *.valiuz.com *.doubleclick.net *.mediarithmics.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.bing.com *.criteo.net *.snapchat.com *.netvigie.com *.xiti.com *.valiuz.com *.googletagmanager.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' https://d1mnljovdqnw4e.cloudfront.net data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://cdn.logr-ingest.com https://bat.bing.com; style-src 'self' 'unsafe-inline'; worker-src 'self' blob:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com wss://*.campspot.com https://*.rollout.io; img-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://www.campspot.com; frame-src 'self' https://www.googletagmanager.com; 1 default-src 'self'; report-uri https://o1154186.ingest.us.sentry.io/api/4510272816218112/security/?sentry_key=b015babb3f1c83d2f45d8da510da7e2c; report-to csp-sentry; img-src 'self' https://cms.storage.dev.usesmileid.com https://www.google.co.kr https://analytics.twitter.com https://t.co https://www.google.com https://googleads.g.doubleclick.net https://px.ads.linkedin.com; connect-src 'self' https://analytics.google.com https://www.google.com https://vc.hotjar.io https://api2.amplitude.com https://forms-eu1.hscollectedforms.net https://px.ads.linkedin.com; frame-src https://www.youtube.com https://www.googletagmanager.com; script-src 'self' https://webforms.pipedrive.com https://googleads.g.doubleclick.net https://static.ads-twitter.com https://script.hotjar.com https://js-eu1.hs-banner.com https://static.hotjar.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-scripts.com; style-src 'self' 'unsafe-inline'; object-src 'none'; 1 base-uri 'self'; connect-src https://apigw.paytr.com 'self'; default-src 'none'; frame-src 'self'; img-src 'self'; object-src 'none'; script-src 'self'; style-src 'self'; upgrade-insecure-requests; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=Onnq54ZkzJxWFjtiTQY511N4gEah1Mjcp814ViwjBa8-1765939256-1.0.1.1-eSfTKMhlNDTYNcYTLbRiIkdm2TZFWInMr.5xEZoiyyA1wmSpjo8Ts3mrR_LKYVOsSpT2WqtSdVqWna4U7Cbum4vOs7LcIp7S.Z21fabE0Q6LDK3PjEx6vyouZFcrRCSyG1NGSCl0D2somA6ZWdOuLfkHbXM54eGLTjFJnSidnIstc4qlyLgrfH8hbxv08EUDZkNwCEkDI7irybcPwxmgtg; report-to cf-iktjknwkvvmsembv 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.easypack24.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.oct8ne.com https://*.channelize.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://cdn.clerk.io *.feedaty.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.easypack24.net *.inpost.pl *.inpost.com *.openstreetmap.org *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.clarity.ms https://*.bing.com https://*.awin1.com https://*.scalapay.com https://*.anticafarmaciaorlandi.it https://*.oct8ne.com https://*.google.it https://*.channelize.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.channelize.io https://api.clerk.io https://cdn.clerk.io *.feedaty.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.inpost.pl *.inpost.it *.easypack24.net *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io https://*.clerk.io https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.facebook.net https://*.feedaty.com https://*.cloudflare.com https://*.clarity.com https://*.clarity.ms https://*.outbrain.com https://*.onesignal.com https://*.dwin1.com https://*.gestpay.net https://*.scalapay.com https://*.iubenda.com https://*.oct8ne.com https://*.getblue.io https://*.channelize.io https://*.bing.com https://*.connectif.cloud https://*.cookieless-data.com https://*.sddan.com https://*.airtable.com https://*.awin1.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com www.gstatic.com beacon.riskified.com tracking.trovaprezzi.it www.trovaprezzi.it tps.trovaprezzi.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.doofinder.com downloads.mailchimp.com geowidget.easypack24.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.channelize.io *.feedaty.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.inpost.pl *.inpost.it *.easypack24.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io *.paypal.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.google.com https://google.com https://*.google-analytics.com https://*.feedaty.com https://*.cloudflare.com https://*.outbrain.com https://*.clarity.ms https://*.amplitude.com https://*.bing.com https://*.scalapay.com https://*.iubenda.com https://*.oct8ne.com https://*.channelize.io https://*.connectif.cloud https://*.wepowerconnections.com https://*.sciencebehindecommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com www.google.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com cdn.userway.org 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com api.hubapi.com *.linkedin.com *.twitter.com t.co *.reddit.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com api.hubapi.com *.linkedin.com *.company-target.com *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com api.hubapi.com *.linkedin.com dev.visualwebsiteoptimizer.com *.hubspot.com virtuosity.com.br *.virtuosity.com.br seequent.com *.seequent.com *.cookielaw.org integration-5ojmyuq-5xh6rknhsg5g2.us-5.magentosite.cloud virtuosity.integration-5ojmyuq-5xh6rknhsg5g2.us-5.magentosite.cloud seequent.integration-5ojmyuq-5xh6rknhsg5g2.us-5.magentosite.cloud *.bentley.com t.co *.twitter.com *.reddit.com id.rlcdn.com *.bing.com *.google.co.in *.company-target.com *.facebook.com *.nr-data.net perf-na1.hsforms.com *.hsforms.com cdn.userway.org *.virtuosity.com tags.srv.stackadapt.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com api.hubapi.com *.linkedin.com *.hubspot.com virtuosity.com.br *.virtuosity.com.br seequent.com *.seequent.com *.ads-twitter.com *.googletagservices.com *.googlesyndication.com *.googleadservices.com *.doubleclick.net *.google.com *.marketo.com *.twitter.com *.bing.com cdn.syndication.twimg.com cdn.mouseflow.com/projects/*.js cdn.mouseflow.com *.onetrust.com cdn.cookielaw.org *.demandbase.com google-analytics.com googletagmanager.com munchkin.marketo.net *.licdn.com t.co unpkg.com *.redditstatic.com *.google-analytics.com *.googletagmanager.com *.facebook.net js-agent.newrelic.com *.bentley.com js.hs-scripts.com js.hsforms.net js.usemessages.com js.hs-analytics.net js.hsleadflows.net js.hsadspixel.net js.hs-banner.com dev.visualwebsiteoptimizer.com cdn.userway.org *.mplat-ppcprotect.com *.cloudfront.net pixel.byspotify.com *.stackadapt.com *.amazonaws.com qvdt3feo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com api.hubapi.com *.linkedin.com virtuosity.com.br *.virtuosity.com.br seequent.com *.seequent.com *.marketo.com *.marketo.net *.google.com *.licdn.com *.bing.com *.twitter.com *.onetrust.com ton.twimg.com unpkg.com *.googletagmanager.com cdn.userway.org tags.srv.stackadapt.com *.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src api.hubapi.com *.linkedin.com *.googlesyndication.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.bolt.com *.adobedc.net *.demdex.net *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com api.addressy.com api.hubapi.com *.linkedin.com virtuosity.com.br *.virtuosity.com.br seequent.com *.seequent.com *.mktoresp.com *.onetrust.com *.cookielaw.org *.linkedin.oribi.io *.company-target.com *.doubleclick.net *.google-analytics.com *.demandbase.com *.facebook.com *.visualwebsiteoptimizer.com *.hubspot.com js.hs-banner.com *.mouseflow.com *.redditstatic.com *.mplat-ppcprotect.com *.cloudfront.net pixels.spotify.com tags.srv.stackadapt.com *.userway.org *.hsforms.com *.amazonaws.com *.reddit.com api.smartling.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src *; script-src data: http: https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' data: 'unsafe-inline' https: *.bootstrapcdn.com; img-src * 'self' data: blob:; font-src *; connect-src https:; media-src *; object-src 'none'; frame-src *; report-uri https://www.hsag.com/_csp; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.google.com.mx *.clarity.ms *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com dbschile.api.useinsider.com *.queue-it.net *.clarity.ms *.getblue.io *.gorgias.chat *.mouseflow.com www.googleoptimize.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.yango.com *.clarity.ms *.gorgias.chat *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://api.systempay.fr/static/ *.fontawesome.com https://cdnjs.cloudflare.com *.googleusercontent.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.hsforms.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ https://www.googletagmanager.com/ *.hs-sites.com *.hsforms.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://maps.googleapis.com https://maps.gstatic.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org *.axept.io *.google.com *.googletagmanager.com *.googleusercontent.com *.hsforms.com *.hubspot.com *.imgix.net *.openstreetmap.org *.hsforms.net 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://maps.googleapis.com *.axept.io *.facebook.net *.googletagmanager.com *.hotjar.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hsforms.net *.hubspot.com *.bing.com *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.systempay.fr/static/ *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googletagmanager.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://maps.googleapis.com https://nominatim.openstreetmap.org *.axept.io *.axeptio.tech *.google-analytics.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.hsforms.com *.hscollectedforms.net *.hubspot.com t.elasticsuite.io *.hsforms.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://76c33e6e-b3ed-47af-8820-21ea80415831.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; img-src 'self' *.taiko-p.jp data: https://www.googletagmanager.com/ https://www.google.co.jp/ https://cdn-au.onetrust.com/; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-69421cb3a597b' */gtm.js https://www.googletagmanager.com/ https://cdn-au.onetrust.com/; connect-src */ajax/ https://stats.g.doubleclick.net/ https://cdn-au.onetrust.com/ https://www.google-analytics.com https://geolocation.onetrust.com/ https://privacyportal-au.onetrust.com/ https://analytics.google.com/ https://www.google.co.jp/; report-uri csp_report.php; 1 frame-ancestors 'self'; report-uri https://www.themercury.com.au/csp-reports 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com www.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' *.fallcoweb.it fallcoweb.it *.portalenotarile.it portalenotarile.it 'unsafe-eval' 'nonce-Aq78VBpfphwDXN0BVi9KduEe7kBzSNNQt3svrQVTRrY=' 'strict-dynamic' 'report-sample'; script-src-attr 'unsafe-inline' 'report-sample'; img-src http: https: data: blob: ; object-src 'self' firma.fallcoweb.it firma-test.fallcoweb.it; base-uri 'self'; frame-ancestors 'self' *.fallcoweb.it fallcoweb.it *.portalenotarile.it portalenotarile.it; report-uri https://o4506184205402112.ingest.us.sentry.io/api/4509672896921600/security/?sentry_key=06528fda593958158ec55deaa5621ec1; 1 font-src www.searchanise.com *.searchserverapi.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.searchanise.com *.searchserverapi.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.searchanise.com *.searchserverapi.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.pagar.me searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.pagar.me https://viacep.com.br https://www.viacep.com.br api.amplitude.com stats.g.doubleclick.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' plenitudedistribuidora.com.br *.plenitudedistribuidora.com.br wake-components.fbitsstatic.net plenitudedistribuidora.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net *.googleadservices.com *.tawk.to k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.ebit.com.br *.cartstack.com wss://vsb31.tawk.to *.cartstack.com.br *.smarthint.co app.cartstack.com.br *.datafrete.app *.getblue.io *.targeting.voxus.com.br cdn.targeting.voxus.com.br googleads.g.doubleclick.net *.g.doubleclick.net *.voxus.tv *.voxus.com.br *.loggly.com targeting.voxus.com.br *.clearsale.com.br accounts.google.com *.facebook.net connect.facebook.net *.facebook.com facebook.com *.conectiva.io *.sunset.systems *.performa.ai *.cupom.social *.conectiva.app conectiva.app api.performa.ai valid.performa.ai cartstack.com.br api.cartstack.com.br sunset.systems api.sunset.systems cupom.social app.cupom.social cdn.performa.ai *.google.com.br *.google.com *.googletagmanager.com translate.googleapis.com google.com *.trustvox.com.br rate.trustvox.com.br *.google-analytics.com apis.google.com app.cartstack.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com conectiva.io trustvox.com.br *.goadopt.io googletagmanager.com google-analytics.com gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.tiktok.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com td.doubleclick.net *.doubleclick.net integration-hub.mailclick.me *.fbits.store *.adyen.com google.co.jp google.com.bo google.co.uk google.com.uy google.pt google.com.py google.es google.it google.fr google.al google.nl google.be *.pagar.me *.mundipagg.com *.rdstation.com.br *.getnet.com.br *.clarity.ms *.stape.co sa.stape.co clarity.ms *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.google.pt *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br *.monitfy.com cdn.monitfy.com *.fpcs-monitor.com.br web.fpcs-monitor.com.br paypal-wake.s3.us-east-1.amazonaws.com newimgebit-a.akamaihd.net youtube.com yampi-vitrine-digital-prod.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.mailbiz.one *.jsdelivr.net *.3dsecure.io *.visa.com s.pinimg.com *.pinimg.com mpc-prod-18-s6uit34pua-uc.a.run.app ct.pinterest.com *.pinterest.com *.youtube.com demo-1.conversionsapigateway.com *.conversionsapigateway.com analytics-ipv6.tiktokw.us *.tiktokw.us *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.plenitudedistribuidora.com.br plenitudedistribuidora.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src cdnjs.cloudflare.com fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com magento.buildify.shop *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com platform.twitter.com magento.buildify.shop c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.polyfill.io *.sharethis.com platform.twitter.com platform.instagram.com apis.google.com magento.buildify.shop https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://browser.sentry-cdn.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com cdnjs.cloudflare.com fonts.googleapis.com magento.buildify.shop https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' fonts.gstatic.com; img-src 'self' cdn.conservadoresdigitales.cl www.google-analytics.com www.googletagmanager.com; script-src 'self' www.googletagmanager.com www.google-analytics.com www.gstatic.com www.google.com ajax.googleapis.com analytics.google.com; style-src 'self' inline fonts.googleapis.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com maps.googleapis.com maps.gstatic.com 'self' data: gpsfarma.com www.afip.gob.ar www.google.com.ar https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.mlstatic.com *.mercadopago.com maps.googleapis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.mercadopago.com *.mercadolibre.com maps.googleapis.com stats.g.doubleclick.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; script-src 'self' https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://*.googleapis.com https://cdn.jsdelivr.net https://code.jquery.com https://maps.googleapis.com https://osfhealthcare-staging.vercel.app https://osfhealthcare-uat.vercel.app https://osfhealthcare.org https://osfhealthcare-dev.vercel.app https://osfmychart.org https://payments.blackbaud.com https://platform.twitter.com https://siteimproveanalytics.com https://stackpath.bootstrapcdn.com https://static.doubleclick.net https://web2.production.gyantts.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://*.osfhealthcare.org https://www.youtube.com; style-src 'self' https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://cdn.jsdelivr.net https://*.googleapis.com https://osfhealthcare-staging.vercel.app https://osfhealthcare-uat.vercel.app https://osfhealthcare.org https://osfhealthcare-dev.vercel.app https://p.typekit.net https://s3.amazonaws.com https://use.typekit.net https://www.gstatic.com https://www.osfhealthcare.org https://www.youtube.com https://osfmychart.org; img-src 'self' data: https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://osfmychart.org https://11568.global.siteimproveanalytics.io https://edge.sitecorecloud.io https://i.ytimg.com https://*.googleapis.com https://maps.gstatic.com https://osfmychart.org https://osf-api1.dev.imagescape.com https://osf-blog.live.imagescape.com https://osf-p-001.sitecorecontenthub.cloud https://osfhealthcare-staging.vercel.app https://osfhealthcare-uat.vercel.app https://osfhealthcare.org https://osfhealthcare-dev.vercel.app https://s3.amazonaws.com https://www.gstatic.com https://www.osfhealthcare.org https://yt3.ggpht.com; font-src 'self' data: https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://fonts.gstatic.com https://s3.amazonaws.com https://use.typekit.net; connect-src 'self' https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://osfmychart.org https://discover.sitecorecloud.io https://edge.sitecorecloud.io https://googleads.g.doubleclick.net https://*.googleapis.com https://*.googleapis.com https://osfhealthcare-staging.vercel.app https://osfhealthcare-uat.vercel.app https://osfhealthcare.org https://osfhealthcare-dev.vercel.app https://platform.twitter.com https://play.google.com https://ssproxy.osfhealthcare.org https://syndication.twitter.com https://web2.production.gyantts.com https://www.google.com https://www.googletagmanager.com https://*.osfhealthcare.org https://www.youtube.com; frame-src 'self' https://osfmychart.org; media-src 'self' https://perfalytics.com https://api.perfalytics.com https://freshpaint-cdn.com https://osfmychart.org https://11568.global.siteimproveanalytics.io https://edge.sitecorecloud.io https://i.ytimg.com https://*.googleapis.com https://maps.gstatic.com https://osf-api1.dev.imagescape.com https://osf-blog.live.imagescape.com https://osf-p-001.sitecorecontenthub.cloud https://osfhealthcare-staging.vercel.app https://osfhealthcare-uat.vercel.app https://osfhealthcare.org https://osfhealthcare-dev.vercel.app https://s3.amazonaws.com https://www.gstatic.com https://*.osfhealthcare.org https://yt3.ggpht.com; 1 default-src 'none'; connect-src 'self' https://*.icfcdn.com https://www.google.com https://cdn.plyr.io https://*.gstatic.com; script-src 'nonce-140c2029a9a8cbd31731acd92d56e722e9bf48d0889b69cb6907ecbff4b65a92' 'strict-dynamic' 'report-sample'; style-src 'self' 'nonce-140c2029a9a8cbd31731acd92d56e722e9bf48d0889b69cb6907ecbff4b65a92' 'report-sample'; style-src-elem 'unsafe-inline' 'report-sample' https://fonts.googleapis.com; style-src-attr 'unsafe-inline' 'report-sample'; font-src https://fonts.gstatic.com https://fonts.googleapis.com; img-src 'self' blob: https://*.gstatic.com https://*.nsimg.net; media-src 'self' https://cdn.plyr.io https://*.nsimg.net; frame-src https:; frame-ancestors 'self'; report-to csp-report; report-uri /reporting/cspReport?reportOnly 1 frame-src 'self' *.adyen.com *.ingrid.com *.googletagmanager.com *.google.com *.consentmanager.net *.bigcontent.io *.cloudflare.com *.klarna.com *.facebook.com *.ahlens.se *.klarnaservices.com; script-src 'self' abtasty.com *.abtasty.com bing.com *.bing.com bloomreach.com *.bloomreach.com cdn-apple.com *.cdn-apple.com cloudflare.com *.cloudflare.com consentmanager.net *.consentmanager.net doubleclick.net *.doubleclick.net facebook.net *.facebook.net getflowbox.com *.getflowbox.com google.com *.google.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com hotjar.com *.hotjar.com ingrid.com *.ingrid.com klarnacdn.net *.klarnacdn.net maps.googleapis.com *.maps.googleapis.com 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=w3I0bSNLrqtnAxBT2A.2nez07nVopcpbLaKrOQtmEWY-1765939015.65966-1.0.1.1-D6rLTcv8XqnzBpuchmg8LdxHrDn6.9TEYv7q_DGLBffHzG1w1GT2g8o.uPh_dRmqeJ7YCAyfGrZtaDtXx5w6uawueVQSHZYBFdHdUaWibd.ERJUGPBAwhS8Dk0K6OmnXmcfBjrWHpqDLys3dIrnvmfdu5iVOMhfK12MZG_t10V3caVORi2m7W_ggONGDZEcs; report-to cf-crzbmwpmkwsowsjq 1 default-src 'none'; report-uri /api/sec-csp/110000764/report 1 script-src 'nonce-2ql5AY+HahkCB2QUOXhjjA==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=b6458e0a-9e14-4d14-9ea9-511260003603; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: https://www.surviocdn.com/ *.survicate.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.googletagmanager.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com *.globalgetnet.com *.magerocket.com *.gocuotas.com *.mercadolibre.com mldp.mercadopago.com www.mercadolibre.com https://www.survio.com/ *.doubleclick.net *.pinterest.com *.getblue.io *.groovinads.com *.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.globalgetnet.com *.magerocket.com *.gocuotas.com imgmp.mlstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar 'self' data: www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com *.google.com.ar *.doubleclick.net *.mercadolivre.com www.mailing.somosrex.com *.clarity.ms *.groovinads.com *.bing.com *.online-metrix.net img.survicate.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com *.braindw.com https://live.decidir.com *.globalgetnet.com *.magerocket.com *.gocuotas.com *.mlstatic.com https://www.google.com *.gstatic.com http2.mlstatic.com secure.mlstatic.com https://maps.googleapis.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.convertexperiments.com *.wcx.cloud *.pinimg.com *.survicate.com *.clarity.ms *.mathtag.com *.tiktok.com *.getblue.io *.groovinads.com *.wcentrix.com *.cloudfront.net *.pinterest.com *.icommarketing.com *.decidir.com *.mercadopago.com *.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.survicate.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com api.comapi.com bam.nr-data.net *.braindw.com https://developers.decidir.com/ *.globalgetnet.com *.iesnare.com wss://mpsnare.iesnare.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.google-analytics.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.doubleclick.net notifications-icommkt.com track-icommkt.com *.clarity.ms *.pinterest.com *.tiktok.com *.convertexperiments.com *.decidir.com *.online-metrix.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.globalgetnet.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /csp-violations; default-src 'self'; font-src * data:; img-src * blob: data:; object-src 'none'; media-src * blob: data:; form-action *; script-src 'self' https://*.kit.com https://*.convertkit.com https://*.stripe.com https://*.intercom.io 'strict-dynamic' 'report-sample' 'unsafe-eval' 'nonce-T0w/cwJKP6MAefXZd6zjzg=='; style-src 'self' https: 'unsafe-inline'; connect-src *; child-src * blob:; worker-src 'self' blob: 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://static.contactlab.it https://ingestion.webanalytics.italia.it https://www.youtube.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://static.cineca.it; img-src 'self' data: https:; media-src 'self'; frame-src 'self'; frame-ancestors 'self'; child-src 'self'; font-src 'self' data: https://static.cineca.it; connect-src 'self' https://static.cloudflareinsights.com https://ingestion.webanalytics.italia.it https://www.youtube.com; report-uri /report-csp-violation 1 frame-ancestors 'self' ; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubadd3370b28f0adfc9d9783d03cd9ce00&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags= 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.adyen.com https://acsbapp.com https://bat.bing.com https://widget.us.criteo.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://pagead2.googlesyndication.com https://*.flos.com https://*.salesforce.com https://service.force.com https://*.cquotient.com https://*.hotjar.com https://*.vimeo.com https://*.contentful.com https://*.clarity.ms https://a.omappapi.com https://api.omappapi.com https://*.optimonk.com https://*.contentsquare.net https://*.outbrain.com https://dev.visualwebsiteoptimizer.com https://consent.cookiebot.com https://*.cookiebot.com https://d.la1-c2-fra.salesforceliveagent.com https://d.la11-core1.sfdc-3d0u2f.salesforceliveagent.com https://maps.googleapis.com https://dev.flos.com https://pay.google.com https://www.paypal.com https://d.ratepay.com https://*.collect.igodigital.com https://dynamic.criteo.com https://sslwidget.criteo.com https://s.pinimg.com https://ct.pinterest.com https://connect.facebook.net https://snap.licdn.com https://acdn.adnxs.com https://analytics.webgains.io https://googleads.g.doubleclick.net; connect-src 'self' https://*.flos.com https://cdn.acsbapp.com https://bat.bing.com https://cdn-renderer.optimonk.com https://*.paypal.com https://*.salesforce.com https://service.force.com https://api.omappapi.com https://*.google.com/pagead/ https://*.adyen.com https://*.contentful.com https://*.google-analytics.com https://*.analytics.google.com https://*.clarity.ms https://front.optimonk.com https://cdn-account.optimonk.com https://cdn-limit.optimonk.com https://jfapiprod.optimonk.com https://pagead2.googlesyndication.com https://dev.visualwebsiteoptimizer.com https://maps.googleapis.com https://mapsresources-pa.googleapis.com https://google.com/pay https://www.google.com/pay https://pay.google.com/about/redirect/ https://pay.google.com/gp/p/ https://pay.google.com/gp/p/payment_method_manifest.json https://www.sandbox.paypal.com/xoplatform/logger/api/logger https://checkoutanalytics-test.adyen.com https://www.google.com/ccm/collect https://*.googleadservices.com https://www.googleadservices.com https://amplify.outbrain.com https://tr.outbrain.com https://ib.adnxs.com https://px.ads.linkedin.com https://ct.pinterest.com https://measurement-api.criteo.com https://consentcdn.cookiebot.com; img-src 'self' data: blob: https://*.flos.com https://*.dam.flos.net https://bat.bing.com https://x.bidswitch.net https://cm.g.doubleclick.net https://simage4.pubmatic.com https://r.casalemedia.com https://gum.criteo.com https://id5-sync.com https://ad.360yield.com https://contextual.media.net https://exchange.mediavine.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://aa.agkn.com https://editor-upload-cdn.optimonk.com https://cdn-content.optimonk.com https://dam.flos.net https://*.adyen.com https://*.google-analytics.com https://*.googlesyndication.com https://*.googleadservices.com https://*.clarity.ms https://c.bing.com https://dev.visualwebsiteoptimizer.com https://www.googletagmanager.com https://maps.gstatic.com https://mapsresources-pa.googleapis.com https://www.paypalobjects.com https://www.gstatic.com https://tau.collect.igodigital.com https://px.ads.linkedin.com https://www.facebook.com https://connect.facebook.net https://ib.adnxs.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.it https://pagead2.googlesyndication.com https://www.googleadservices.com https://imgsct.cookiebot.com; frame-src 'self' https://*.adyen.com https://*.facebook.com https://*.paypal.com https://*.googletagmanager.com https://*.salesforce.com https://*.vimeo.com https://*.cookiebot.com https://*.criteo.com https://*.pinterest.com https://pay.google.com https://service.force.com https://dev.visualwebsiteoptimizer.com https://www.sandbox.paypal.com; style-src 'self' 'unsafe-inline' https://cdn-content.optimonk.com https://*.googleapis.co https://*.adyen.com https://*.salesforce.com https://a.omappapi.com https://service.force.com https://cdn-asset.optimonk.com https://*.googleapis.com https://*.adyen.com https://*.salesforce.com https://a.omappapi.com https://service.force.com https://cdn-asset.optimonk.com; font-src 'self' https://*.googleapis.com https://fonts.gstatic.com https://cdn-content.optimonk.com https://cdn-custom.optimonk.com https://*.flos.com data:; worker-src 'self' blob: https://maps.googleapis.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=7.mPJ03wZsemOV8YfNBAgrzEjGPpwVUIHyqLedUcz94-1765934268-1.0.1.1-.iYWDl69xBN0j2rtDkBl91juKZZRJ3NIeevbe9oeplOwzP.XCf3OwmHWSPcVALS6bM7OTG2K0CyP4er.UmrQ__Jk_j47AL2C2SNXvhrKX..4x0Dn9bGIZkAbnhId0DhUm_P8J_8dT8V4mRzIA2kwsbuNoRL3JCeqKXeAwwcwZIlV9Jd26NnOW5n19wnWF4P7; report-to cf-wlrencmizvuyennv 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://www.gstatic.com https://fonts.gstatic.com static.zip.co *.afterpay.com *.yotpo.com *.googleapis.com *.cloudflare.com *.font.im *.optimonk.com *.nikon.co.in *.slant.co *.alicdn.com *.loli.net *.migaku.com *.ziplyne.com *.googleusercontent.com *.nikon.com.au *.hsappstatic.net *.nikon.com.sg *.fontshare.com smc.org.in *.nikon-asia.com *.nikon-mea.com unpkg.com *.nikon.co.th *.crisp.chat *.githack.com yastatic.net *.cdn-apple.com *.jsdelivr.net *.zohocdn.com *.tiktok.com *.vixverify.com *.gstatic.cn use.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com https://secure-test.worldpay.com/shopper/3ds/ddc.html swellrewards.com *.swellrewards.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com *.googletagmanager.com https://pay.google.com https://secure-test.worldpay.com swellrewards.com *.swellrewards.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.files-text.com *.livechatinc.com *.livechat-files.com *.livechat-static.com https://*.googleapis.com https://*.googleusercontent.com https://maps.gstatic.com zip.co static.zip.co bpi.zip.co *.google.com.au *.linkedin.com *.yahoo.com *.adroll.com *.afterpay.com *.yotpo.com *.bazaarvoice.com *.nikon-mea.com *.nikon.com.hk *.solone.net vumbnail.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.tl www.google.tn www.google.to www.google.tt www.google.vu www.google.ws yastatic.net *.google.com *.mynikonlife.com.au *.nikon.co.in *.nikon.com.au www.google.ad www.google.as www.google.cf www.google.co.ck www.google.com.bz www.google.com.cu www.google.com.gi www.google.com.tj www.google.cv www.google.dj www.google.fm www.google.ga www.google.gl www.google.gy www.google.je www.google.ki www.google.ml www.google.ne www.google.sr www.google.st www.google.td www.google.tg www.google.tm *.baidu.com *.giphy.com *.ibb.co *.riskified.com *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com www.google.cn *.nikon.com.sg *.optimonk.com *.crwdcntrl.net *.ctnsnet.com *.ggpht.com *.nikon-asia.com *.nikon.co.th www.google.com.au *.tiktok.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.sm bitly.com dakotaram.com s3.amazonaws.com www.google.nu *.3lift.com *.adnxs.com *.adsrvr.org *.amazon-adsystem.com *.bidswitch.net *.bing.com *.bluekai.com *.casalemedia.com *.googleadservices.com *.openx.net *.outbrain.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com *.scorecardresearch.com *.taboola.com *.tapad.com google.com www.google.nr nikon-asia.com *.ytimg.com *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.livechatinc.com *.livechat-static.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://maps.googleapis.com snapwidget.com *.zip.co d35p4vvdul393k.cloudfront.net *.yotpo.com *.optimonk.com *.tiktok.com *.crazyegg.com *.adroll.com snap.licdn.com consentag.eu ctnsnet.com *.newrelic.com *.bazaarvoice.com *.disqus.com *.tailwindcss.com *.truecreatorstudio.com *.vimeo.com unpkg.com *.googleapis.com *.nikon.co.in *.alicdn.com *.riskified.com *.stackadapt.com *.qvdt3feo.com translate.google.com.hk *.googleadservices.com *.33across.com *.ctnsnet.com *.instagram.com *.cloudflare.com *.nikon.com.au d16i99j5zwwv51.cloudfront.net *.nikon.com.sg *.nikon-asia.com dakotaram.com *.cfjump.com *.nikon-mea.com *.ucweb.com *.nikon.co.th *.crisp.chat googletagmanager.com yastatic.net *.adobe.net *.adobedtm.com *.cdn-apple.com *.google-analytics.com *.jsdelivr.net *.licdn.com *.mynikonlife.com.au *.netcoresmartech.com localhost *.vixverify.com npmcdn.com *.gstatic.cn https://*.riskified.com https://www.google.com/recaptcha/api.js https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js swellrewards.com *.swellrewards.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com display.ugc.bazaarvoice.com *.livechatinc.com https://fonts.googleapis.com zip.co bpi.zip.co *.afterpay.com *.yotpo.com *.bazaarvoice.com *.optimonk.com *.nikon.co.in *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com *.nikon.com.au *.nikon.com.sg *.nikon-asia.com *.nikon-mea.com *.nikon.co.th *.mynikonlife.com.au *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.livechatinc.com 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com *.livechat-static.com *.vimeocdn.com *.gstatic.com nikon-asia.com *.google.com *.nikon.com.au 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.livechatinc.com *.text.com api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://maps.googleapis.com *.zipmoney.com.au *.zip.co *.afterpay.com *.optimonk.com *.crazyegg.com *.linkedin.com *.tiktok.com ctnsnet.com *.nr-data.net *.googletagmanager.com *.google.com *.googleadservices.com *.yotpo.com *.bazaarvoice.com *.crwdcntrl.net *.doubleclick.net *.truecreatorstudio.com localhost truecreatorstudio.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bs www.google.bt www.google.by www.google.ca www.google.cg www.google.ch www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.tn www.google.to www.google.vu *.nikon.co.in www.google.bj www.google.cd www.google.ci www.google.cm www.google.com.cu www.google.com.ly www.google.com.ni www.google.com.pr www.google.com.sl www.google.com.sv www.google.com.tj www.google.dj www.google.ga www.google.im www.google.je www.google.ml www.google.ne www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tt www.google.ws *.baidu.com *.riskified.com *.stackadapt.com *.qvdt3feo.com www.google.com.na www.google.com.uy www.google.gg *.ctnsnet.com www.google.com.sb www.google.bi lottie.host *.nikon.com.au www.google.ad www.google.com.do *.nikon.com.sg www.google.com.ag www.google.gl *.nikon-asia.com www.google.co.ls www.google.ki www.google.com.bz *.nikon-mea.com www.google.cf *.ucweb.com *.nikon.co.th www.google.tm www.google.st www.google.co.ck *.netcoresmartech.com *.openfpcdn.io *.samsung.com google.com kg668dbov0.execute-api.us-east-1.amazonaws.com www.google.nr www.google.cn www.google.com.gi www.google.cv www.google.gy www.google.sm *.conversionsapigateway.com mpc-prod-1-1053047382554.us-central1.run.app mpc-prod-2-1053047382554.us-central1.run.app mpc-prod-18-s6uit34pua-uc.a.run.app www.google.com.vc www.google.li *.vixverify.com *.alicdn.com mpc-prod-14-s6uit34pua-ue.a.run.app test-drive-20-1053047382554.us-central1.run.app swellrewards.com *.swellrewards.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.livechatinc.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.crazyegg.com *.optimonk.com *.facebook.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.riskified.com 'self' 'unsafe-inline'; report-uri https://c147cc3c-0a23-4d12-a977-70db96924fb4.sansec.watch/; report-to report-endpoint; 1 default-src 'none'; connect-src googleads.g.doubleclick.net our.umbraco.com stats.g.doubleclick.net www.google-analytics.com www.google.com cdn.linkedin.oribi.io region1.analytics.google.com iwfsecurity.report-uri.com consentcdn.cookiebot.com translate.googleapis.com 'self'; font-src fonts.gstatic.com use.typekit.net 'self'; manifest-src 'self'; object-src 'self'; frame-src vimeo.com donorbox.org www.buzzsprout.com player.vimeo.com www.googletagmanager.com www.youtube.com consentcdn.cookiebot.com www.google.com indd.adobe.com 'self'; frame-ancestors 'self'; img-src data: t.co analytics.twitter.com fonts.gstatic.com www.google.co.uk our.umbraco.com www.gravatar.com www.googletagmanager.com www.linkedin.com www.facebook.com px4.ads.linkedin.com www.google-analytics.com px.ads.linkedin.com gtranslate.net p.typekit.net www.gstatic.com dashboard.umbraco.com i.vimeocdn.com www.google.com translate.googleapis.com translate.google.com bat.bing.com *.cookiebot.com 'self'; media-src data: 'self' vimeo.com player.vimeo.com *.akamaized.net; script-src 'self' 'unsafe-eval' bat.bing.com static.ads-twitter.com vimeo.com www.vimeo.com ajax.aspnetcdn.com www.google.com connect.facebook.net www.googleadservices.com www.gstatic.com www.google-analytics.com snap.licdn.com translate-pa.googleapis.com consent.cookiebot.com use.typekit.net translate.google.com translate.googleapis.com consentcdn.cookiebot.com use.typekit.net dev.iwf.org.uk www.googletagmanager.com *.iwf.org.uk *.cookiebot.com *.typekit.net cdn.veritonic.com inline: 'unsafe-inline' 'unsafe-eval' 'self'; style-src translate.googleapis.com www.gstatic.com inline: 'self' 'unsafe-inline'; report-uri https://iwfsecurity.report-uri.com/r/d/csp/enforce; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-'; base-uri 'none'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'strict-dynamic' 'nonce-wL4Cl0Fb6kiwKVepgJDAsg==' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.taboola.com https://*.usercentrics.eu https://analytics.tiktok.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://chat.kindlycdn.com https://connect.facebook.net https://ct.pinterest.com https://gallery.cevoid.com https://google-analytics.com https://pay.google.com https://s.pinimg.com https://t.contentsquare.net https://tr.snapchat.com https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagservices.com; style-src 'self' 'unsafe-inline' https: data:; connect-src 'self' https://*.az.contentsquare.net https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.facebook.com https://*.google-analytics.com https://*.google.com https://*.google.se https://*.klarna.com https://*.kindly.ai https://*.kustom.co https://*.snapchat.com https://*.taboola.com https://*.tiktok.com https://*.usercentrics.eu https://*.kappahl.com https://*.newbie.com https://analytics-ipv6.tiktokw.us https://api.cevoid.com https://api.klarna.com https://api.raygun.io https://api.screen9.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://bat.bing.net https://bot.kindly.ai https://cdn.raygun.io https://chat.kindlycdn.com https://checkout-test.adyen.com https://checkout.adyen.com https://checkoutanalytics-test.adyen.com https://checkoutshopper-test.cdn.adyen.com https://checkoutshopper-test.cdn.adyen.com/ https://ct.pinterest.com https://dc.services.visualstudio.com https://gallery.cevoid.com https://google.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://pay.google.com https://qcdn.screen9.com https://qcnl.tv https://statsapi.screen9.com https://t.contentsquare.net https://t1.voyado.com https://wapi.lipscore.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.pinterest.com https://www.sandbox.paypal.com; frame-src 'self' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.usercentrics.eu https://checkout.klarna.com https://ct.pinterest.com https://pay.google.com https://*.kappahl.com https://*.newbie.com https://tr.snapchat.com https://www.googletagmanager.com https://www.sandbox.paypal.com; img-src 'self' data: https: blob:; media-src 'self' blob: data: https:;font-src 'self' https: data:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; report-uri /csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com www.searchanise.com *.searchserverapi.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://cdn.mundipagg.com https://api.pagar.me *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com commerce.adobedtm.com commerce.adobe.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://ws-sandbox.bellunopag.com.br https://api.belluno.digital https://i.k-analytix.com https://i.konduto.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.adobe.io performance.typekit.net commerce.adobedtm.com commerce.adobedc.net api.magento.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://api.mundipagg.com https://api.pagar.me https://viacep.com.br https://www.viacep.com.br *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com api.amplitude.com stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src *.force.com slack-imgs-mil-dev.com 'self' https://targetbay.file.force.com https://img.youtube.com https://payments.salesforce.com/icons/ *.inboxeagle.com https://login.salesforce.com/icons/ https://*.springcm.com inboxeagle.com https://www.gstatic.com *.slack-edge-gov.com https://www.inboxeagle.com *.my-salesforce.com https://targetbay.my.site.com https://bayrewards.io *.cloudinary.com *.app.targetbay.com bayrewards.io *.amazonaws.com blob: https://targetbay.my.salesforce.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com app.bayengage.com *.twimg.com https://*.docusign.net *.bayrewards.io https://api.mixpanel.com *.slack.com https://www.paypal.com https://app.targetbay.com *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://ind144.sfdc-ppgy19.salesforce.com/icons/ https://*.clm.docusign.mil slack-imgs-gov-dev.com *.app.bayengage.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ *.targetbay.com https://app.bayengage.com app.targetbay.com targetbay--c.vf.force.com https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://img.bayengage.com https://*.clmfed.docusign.com https://i.vimeocdn.com *.salesforce.com https://*.adyen.com slack-imgs.mil data: targetbay.com; report-to sfdc-csp-ep; report-uri https://targetbay.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D5g00000KWJDm&networkId=0DMe20000000dmA&type=communities 1 default-src 'none'; script-src 'nonce-RTypiPQ+7WkcTNIxGMhF9dhEB+xacg3m' 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://www.googletagmanager.com https://assets.adobedtm.com https://cdn.cookielaw.org https://swa.regiobank.nl https://www.google-analytics.com https://player.vimeo.com https://d6tizftlrpuof.cloudfront.net https://snsbank.demdex.net https://api.usabilla.com https://tagmanager.google.com https://w.usabilla.com https://connect.facebook.net https://cdn.tt.omtrdc.net static.regiobank.nl; connect-src 'self' https://cdn.cookielaw.org https://www.google-analytics.com https://snsbank.tt.omtrdc.net https://stats.g.doubleclick.net https://swa.regiobank.nl https://api.usabilla.com https://dpm.demdex.net https://upload.snsbank.nl https://snsbank.sc.omtrdc.net https://*.advieskeuze.nl static.regiobank.nl; font-src 'self' data: https: https://fonts.gstatic.com; frame-src 'self' https://snsbank.demdex.net https://player.vimeo.com https://d6tizftlrpuof.cloudfront.net; img-src 'self' 'report-sample' data: https: https://googleads.g.doubleclick.net https://d6tizftlrpuof.cloudfront.net https://px.ads.linkedin.com/collect/ https://www.facebook.com https://snsbank.demdex.net https://www.google-analytics.com https://swa.regiobank.nl https://w.usabilla.com https://i.vimeocdn.com https://www.google.nl https://www.google.com https://www.linkedin.com https://bat.bing.com https://cdn.cookielaw.org https://www.google.be https://ssl.gstatic.com https://www.gstatic.com https://fonts.gstatic.com https://www.google.co.uk https://www.googletagmanager.com https://www.google.de https://www.google.pl https://secure.adnxs.com https://www.google.fr https://www.google.es https://translate.google.com https://www.google.gr https://www.google.fi https://www.google.lu https://www.google.ik https://www.google.ru https://charting.vwdservices.com; manifest-src 'self'; media-src 'self' data:; style-src 'self' 'unsafe-inline' data: https: https://fonts.gstatic.com https://d6tizftlrpuof.cloudfront.net https://fonts.googleapis.com https://tagmanager.google.com https://www.googletagmanager.com; object-src 'none'; worker-src blob:; frame-ancestors 'self'; base-uri 'self' https://d6tizftlrpuof.cloudfront.net; form-action 'self' https://www.solease.nl; report-uri /web/reportreceiver; 1 default-src https://*.s4c.cymru https://s4c.cymru; img-src 'self' data: https://*.s4c.cymru https://s4c.cymru https://cdn-cookieyes.com https://i.ytimg.com https://*.google.com/cse https://clients1.google.com https://*.gstatic.com; font-src 'self' data: https://*.s4c.cymru https://s4c.cymru https://fonts.gstatic.com https://cloud.typography.com; form-action 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-cookieyes.com https://*.googletagmanager.com https://*.google.com/cse https://*.hotjar.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cloud.typography.com https://*.s4c.cymru https://s4c.cymru https://*.google.com/cse; connect-src https://*.s4c.cymru https://s4c.cymru https://cdn-cookieyes.com https://log.cookieyes.com https://*.google-analytics.com; object-src 'none'; frame-ancestors 'none'; frame-src 'self' https:; report-uri https://csp.s4c.cymru/report; report-to csp-endpoint; 1 default-src 'none'; base-uri 'self'; child-src 'self' blob:; connect-src 'self' bam.nr-data.net links.services.disqus.com cdn.cookielaw.org api.segment.io *.mapbox.com *.mux.com analytics.google.com www.google-analytics.com geolocation.onetrust.com wss: bat.bing.com *.clarity.ms wahoofitness-us.attn.tv wahoofitness.attn.tv events.attentivemobile.com stats.g.doubleclick.net region1.analytics.google.com www.google.com privacyportal.onetrust.com api.rudderstack.com vc.hotjar.io region1.google-analytics.com www.google.cz www.google.au cdn.segment.com fonts.googleapis.com cdn.wahooligan.com www.google.no *.wahooligan.com; font-src 'self' cdn.wahooligan.com fonts.gstatic.com moz-extension data:; form-action 'self' www.wahooligan.com *.wahoofitness.com wahoofitness.zendesk.com api.wahooligan.com www.facebook.com bat.bing.com n.clarity.ms analytics.google.com wahoofitness.centercode.com api.wahooligan.com/oauth/authorize api.staging.wahooligan.com/oauth/authorize *.wahooligan.com; frame-ancestors 'self' *.zendesk.com *.wahooligan.com *.wahoofitness.com; frame-src 'self' disqus.com metabase.wahooligan.com www.youtube-nocookie.com js.stripe.com www.googletagmanager.com td.doubleclick.net www.facebook.com; img-src * data: blob:; media-src blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.wahooligan.com www.google-analytics.com api.tiles.mapbox.com code.jquery.com cdn.segment.com cdnjs.cloudflare.com js.stripe.com js-agent.newrelic.com bam.nr-data.net bam.nr-data.com *.zendesk.com static.zdassets.com cdn.cookielaw.org c.disquscdn.com optanon.blob.core.windows.net www.gstatic.com www.googletagmanager.com cdn.rudderlabs.com data: *.wahooligan.com; script-src-elem 'self' 'unsafe-inline' cdn.wahooligan.com code.jquery.online code.jquery.com cdn.cookielaw.org cdn.segment.com bam.nr-data.com bam.nr-data.net www.googletagmanager.com js-agent.newrelic.com optanon.blob.core.windows.net assets.zendesk.com static.zdassets.com www.google-analytics.com api.tiles.mapbox.com cdnjs.cloudflare.com geolocation.onetrust.com www.gstatic.com js.stripe.com cdn.rudderlabs.com cdn.attn.tv *.zendesk.com www.clarity.ms script.hotjar.com static.hotjar.com resources.xg4ken.com googleads.g.doubleclick.net bat.bing.com connect.facebook.net n.clarity.ms analytics.google.com *.wahooligan.com; style-src 'self' 'unsafe-inline' fonts.gstatic.com cdn.cookielaw.org fonts.googleapis.com api.tiles.mapbox.com cdn.wahooligan.com c.disquscdn.com www.gstatic.com; style-src-elem 'self' 'unsafe-inline' cdn.wahooligan.com cdn.cookielaw.org assets.zendesk.com api.tiles.mapbox.com fonts.googleapis.com www.gstatic.com connect.facebook.net cdnjs.cloudflare.com; report-uri https://www.wahooligan.com/csp_reports 1 default-src 'self' https://*.ototoy.jp; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.ototoy.jp https://bccks.jp https://cdnjs.cloudflare.com/ajax/libs/jquery.bootstrapvalidator/ https://connect.facebook.net https://platform.instagram.com https://www.instagram.com https://code.jquery.com https://scdn.line-apps.com https://d.line-scdn.net https://embed.nicovideo.jp https://platform.twitter.com https://syndication.twitter.com https://player.vimeo.com https://platform.vine.co https://static-fe.payments-amazon.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.ggpht.com https://*.googleusercontent.com https://*.google-analytics.com https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.ototoy.jp https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://cdnjs.cloudflare.com/ajax/libs/jquery.bootstrapvalidator/ https://fonts.googleapis.com; img-src 'self' data: blob: *; font-src 'self' data: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://fonts.gstatic.com; connect-src 'self' data: blob: https://*.ototoy.jp https://payments-fe.amazon.com https://api3.veritrans.co.jp https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat; frame-src 'self' https://bandcamp.com https://m.facebook.com https://mobile.facebook.com https://web.facebook.com https://www.facebook.com https://www.instagram.com https://social-plugins.line.me https://embed.nicovideo.jp https://w.soundcloud.com https://open.spotify.com https://platform.twitter.com https://syndication.twitter.com https://player.vimeo.com https://www.youtube.com https://secure2.arcot.com https://secure4.arcot.com https://dig-acs2.cafis-paynet.jp https://dig3ds.cafis-paynet.jp https://geoissuer.cardinalcommerce.com https://acs-jcn.dnp-cdms.jp https://api.veritrans.co.jp https://*.google.com https://td.doubleclick.net; report-uri /csp-report.php?v=3 1 default-src 'none';script-src 'nonce-0f9db0dc-20c0-4ec0-b027-3aee552e6975' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.vladcazino.ro https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.vladcazino.ro/eum-collector/report/csp-report; 1 default-src 'none'; connect-src 'self' embedr.flickr.com chat-us.libanswers.com resources.bepress.com playback.bepressaws.com cascade2.libchat.com visitor2.constantcontact.com distillery.wistia.com api-iam.intercom.io wss://nexus-websocket-a.intercom.io yoast.com listgrowth.ctctcdn.com www.facebook.com stats.g.doubleclick.net *.google-analytics.com analytics.google.com *.analytics.google.com *.googleapis.com; font-src 'self' data: cdn.jsdelivr.net fonts.gstatic.com static.juicer.io fonts.bunny.net; frame-src 'self' imsa.libanswers.com accounts.google.com admin.helperhelper.com community.imsa.edu v2.libanswers.com docs.google.com calendar.google.com www.youtube.com www.google.com www.facebook.com bbox.blackbaudhosting.com assets.bepress.com *.concept3d.com; img-src 'self' connect.facebook.net *.gstatic.com live.staticflickr.com www.googletagmanager.com previews.dropbox.com www.google-analytics.com *.imsa.edu s.w.org ps.w.org theeventscalendar.com fast.wistia.com data: embedwistia-a.akamaihd.net cdnjs.cloudflare.com www.paypalobjects.com *.googleapis.com onpointplugins.com secure.gravatar.com cdn.datatables.net *.facebook.com bbox.blackbaudhosting.com cdn.weglot.com localist-images.azureedge.net *.cloudfront.net imsa.edu *.googleusercontent.com *.google.com *.ctctcdn.com *.ytimg.com *.imsa.edu blackfacts.com; script-src data: 'self' 'unsafe-inline' 'unsafe-eval' assets.bepress.com blackfacts.com imsa.libanswers.com community.imsa.edu pi.pardot.com cdn.jsdelivr.net widget.intercom.io js.intercomcdn.com fast.wistia.com ajax.googleapis.com www.google.com www.gstatic.com cdnjs.cloudflare.com static.ctctcdn.com connect.facebook.net www.facebook.com assets.juicer.io bbox.blackbaudhosting.com bbox.blackbaudhosting.com cdn.datatables.net connect.facebook.net www.google-analytics.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' www.gstatic.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googleapis.com static.ctctcdn.com assets.juicer.io bbox.blackbaudhosting.com cdn.datatables.net; script-src-elem 'self' 'unsafe-inline' imsa.libanswers.com *.googleapis.com assets.bepress.com connect.facebook.net www.gstatic.com *.google.com cdnjs.cloudflare.com static.ctctcdn.com www.google-analytics.com cdn.datatables.net www.googletagmanager.com embedr.flickr.com widgets.flickr.com imsa.enterprise.localist.com *.imsa.edu blackfacts.com; style-src-elem 'self' 'unsafe-inline' static.ctctcdn.com *.googleapis.com cdn.datatables.net www.gstatic.com *.imsa.edu fonts.bunny.net imsa.enterprise.localist.com; media-src 'self' blob: ; worker-src 'self' blob: ; report-uri https://app.imsa.edu/connect/csp/report 1 default-src 'self' 'unsafe-inline'; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src https: 'self' 'unsafe-inline'; 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-op1ELme0RDm99Kye2z0kAg'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-op1ELme0RDm99Kye2z0kAg'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' 1 font-src *.easypack24.net *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.consensu.org *.sharethis.com https://player.vimeo.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.easypack24.net *.inpost.pl *.inpost.com *.openstreetmap.org *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.cdninstagram.com *.shippypro.com https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com *.inpost.pl *.inpost.it *.easypack24.net *.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.google.com *.sharethis.com *.shippypro.com *.klarna.com *.klarnaservices.com *.avada.io https://player.vimeo.com https://www.youtube.com maps.googleapis.com https://cdn.scalapay.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com widget.freshworks.com m2epro.freshdesk.com geowidget.easypack24.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com *.inpost.pl *.inpost.it *.googleapis.com *.easypack24.net maps.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com *.shippypro.com *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://gate.rapidsec.net/g/r/csp/eca81d68-abac-4bee-ae30-6ec3924dc803/0/0/3?sct=a01a04be-309d-45a5-9fa6-6a1ffcd59f0d&dpos=report; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-s3uXEkcuIRGA-0di4D-Znw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.clarity.ms https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google-analytics.com https://players.brightcove.net/ https://www.recaptcha.net https://www.gstatic.com https://js-agent.newrelic.com https://pi.pardot.com https://www.youtube.com https://in2.taskanalytics.com https://bam.nr-data.net https://snap.licdn.com https://googleads.g.doubleclick.net https://info.weareplanet.com https://www.googleadservices.com https://static.hotjar.com https://script.hotjar.com https://tag.demandbase.com https://j.6sc.co https://tracking.g2crowd.com https://connect.facebook.net https://tpc.googlesyndication.com https://cdn.weglot.com/weglot.min.js https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self' https://exlibris.ch https://*.exlibris.ch https://*.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://exlibris.ch https://*.exlibris.ch https://googletagmanager.com https://*.googletagmanager.com https://epoq-systems.de http://epoq-systems.de https://*.epoq-systems.de http://*.epoq-systems.de https://epoq.de http://epoq.de https://*.epoq.de http://*.epoq.de https://connect.facebook.net https://google.com https://*.google.com https://googleanalytics.com https://*.googleanalytics.com https://google-analytics.com https://*.google-analytics.com https://googlesyndication.com https://*.googlesyndication.com https://gstatic.com https://*.gstatic.com https://googleapis.com https://*.googleapis.com https://googleadservices.com https://*.googleadservices.com bat.bing.com https://*.hotjar.com https://*.hotjar.io https://datatrans.com https://*.datatrans.com https://googleads.g.doubleclick.net https://cookielaw.org https://*.cookielaw.org https://*.trustpilot.com https://pay.google.com https://sandbox.secure.checkout.visa.com https://*.sentry.io analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com; worker-src 'self' blob:; connect-src 'self' https://exlibris.ch https://*.exlibris.ch exlibris.azureedge.net exlibris.blob.core.windows.net https://epoq.de https://*.epoq.de .facebook.com https://migros.ch https://www.google.at https://*.google.ba https://*.migros.ch https://*.google.de https://*.google.ch https://*.google.com https://www.google.fr https://*.google.it https://*.google.li https://*.google.tn https://*.google.co.uk https://*.google.com.sa https://www.googleadservices.com https://google-analytics.com https://*.google-analytics.com https://google-analytics.ch https://*.google-analytics.ch https://google.com https://*.google.com https://analytics.google.com https://*.analytics.google.com https://analytics.google.ch https://*.analytics.google.ch https://googleapis.com https://*.googleapis.com https://googlesyndication.com https://*.googlesyndication.com https://*.googletagmanager.com bat.bing.com https://doubleclick.net https://*.doubleclick.net https://g.doubleclick.net https://*.g.doubleclick.net https://cookielaw.org https://*.cookielaw.org https://onetrust.com https://*.onetrust.com https://onetrust.io https://*.onetrust.io https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io wss://*.hotjar.com wss://hotjar.com https://*.sentry.io analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com; style-src 'self' 'unsafe-inline' https://exlibris.ch https://*.exlibris.ch https://googleapis.com https://*.googleapis.com https://google.com https://*.google.com https://googletagmanager.com https://tagmanager.google.com fast.fonts.net https://epoq-systems.de https://*.epoq-systems.de https://epoq.de https://*.epoq.de http://epoq-systems.de http://*.epoq-systems.de http://epoq.de http://*.epoq.de; img-src 'self' dhttps data: .facebook.com https://exlibris.ch https://*.exlibris.ch exlibris.azureedge.net https://epoq-systems.de https://*.epoq-systems.de https://epoq.de https://*.epoq.de http://epoq-systems.de http://*.epoq-systems.de http://epoq.de http://*.epoq.de https://gstatic.com https://*.gstatic.com https://googleapis.com https://*.googleapis.com https://google-analytics.com https://*.google-analytics.com https://doubleclick.net https://*.doubleclick.net https://g.doubleclick.net https://*.g.doubleclick.net https://googlesyndication.com https://*.googlesyndication.com https://*.google.at https://*.google.ch https://*.google.de https://*.google.dz https://*.google.es https://*.google.fr https://*.google.hr https://*.google.it https://*.google.li https://*.google.lu https://*.google.nl https://*.google.sc https://*.google.si https://*.google.co.uk https://*.google.co.in https://*.google.com https://*.google.com.pa https://*.google.com.ph https://*.google.com.gh https://*.google.com.tr https://*.google.com.br https://*.google.com.cy https://www.googleadservices.com https://googletagmanager.com https://*.googletagmanager.com https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io bat.bing.com https://cookielaw.org https://*.cookielaw.org optanon.blob.core.windows.net exlibris.blob.core.windows.net https://migros.ch https://*.migros.ch analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com https://ytimg.com https://*.ytimg.com; media-src 'self' data https://exlibris.ch https://*.exlibris.ch exlibris.blob.core.windows.net https://*.phononet.de/ exlibris.azureedge.net; frame-src 'self' bytedance: sslocal: https://exlibris.ch https://*.exlibris.ch https://google.de https://*.google.de https://google.com https://*.google.com https://googletagmanager.com https://*.googletagmanager.com https://googlesyndication.com https://*.googlesyndication.com https://youtube.com https://*.youtube.com https://datatrans.com https://*.datatrans.com https://*.fls.doubleclick.net https://bic-media.com https://*.bic-media.com https://youtube-nocookie.com https://*.youtube-nocookie.com https://doubleclick.net https://*.doubleclick.net https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io https://tradedoubler.com https://*.tradedoubler.com https://blickinsbuch.de https://*.blickinsbuch.de https://book2look.com https://*.book2look.com https://postfinance.ch https://*.postfinance.ch https://viseca.ch/ https://*.viseca.ch/ https://bonuscard.ch/ https://*.bonuscard.ch/ https://3ds.bonuscard.ch/ https://*.3ds.bonuscard.ch/ https://arcot.com/ https://*.arcot.com/ https://*.trustpilot.com https://pay.google.com https://sandbox.secure.checkout.visa.com https://3d.datatrans.com https://3d.sandbox.datatrans.com; font-src 'self' data: https://exlibris.ch https://*.exlibris.ch https://gstatic.com https://*.gstatic.com https://google.com https://*.google.com https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io; manifest-src 'self' https://exlibris.ch https://*.exlibris.ch; frame-ancestors 'self' https://exlibris.ch https://*.exlibris.ch; report-uri /loc/csp-report 1 default-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com; connect-src 'self' sf-tbid.okta.com sf-tbid-admin.okta.com tbid.digital.salesforce.com *.oktacdn.com *.mixpanel.com *.mapbox.com sf-tbid.kerberos.okta.com sf-tbid.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'unsafe-inline' 'self' 'report-sample' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com; frame-src 'self' sf-tbid.okta.com sf-tbid-admin.okta.com tbid.digital.salesforce.com login.okta.com *.vidyard.com com-okta-authenticator: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; img-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://iis.digital.salesforce.com 1 frame-ancestors 'self'; report-uri https://send.hsbrowserreports.com/csp/report?resource=website-grader-ui/static-1.7560/html/public-en.html&cfRay=9af30acf6e9989cc-SJC 1 default-src 'self' https:; font-src 'self' https: data: https://use.typekit.net https://p.typekit.net; img-src 'self' https: data: http://www.googleadservices.com; object-src 'none'; base-uri 'self'; style-src 'self' https: 'unsafe-inline' https://use.typekit.net https://cdn.consentmanager.net; script-src 'self' https: unsafe-inline unsafe-eval strict-dynamic https://use.typekit.net http://connect.facebook.net http://b-code.liadm.com https://js.intercomcdn.com https://static.intercomcdn.com https://widget.intercom.io https://app.intercom.io 'nonce-CH26fXXQRa61yv0ygF9d0w=='; connect-src 'self' https: wss://nexus-websocket-a.intercom.io 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com cdn1.stamped.io stamped.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.twitter.com *.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdn.stamped.io static.addtoany.com *.cookiebot.com *.doubleclick.net consentcdn.cookiebot.com bat.bing.com hose.gardeningexpress.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.cloudflare.com *.klarna.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net cdn1.stamped.io stamped.io www.google.com.ua mageside.com cdn.stamped.io www.ojrq.net *.clarity.ms *.bing.com *.cookiebot.com help.gardeningexpress.co.uk/ flagpedia.net www.google.de www.google.co.uk bat.bing.com hose.gardeningexpress.co.uk fonts.gstatic.com bat.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com *.trustpilot.com cdn1.stamped.io stamped.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com cdn.stamped.io static.addtoany.com *.cookiebot.com *.clarity.ms bam.nr-data.net cdn.jsdelivr.net *.impactcdn.com *.newrelic.com maps.googleapis.com consent.cookiebot.com ajax.googleapis.com bat.bing.com pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.trustpilot.com cdn1.stamped.io stamped.io *.stripe.network *.stripecdn.com *.amazon.com *.addtoany.com www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://gardeningexpress.us12.list-manage.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com cdn1.stamped.io stamped.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com http://dpm.demdex.net cdn.stamped.io static.addtoany.com *.cookiebot.com *.clarity.ms bam.nr-data.net cdn.jsdelivr.net *.impactcdn.com pagead2.googlesyndication.com gardeningexpress.pxf.io *.doubleclick.net *.google.com www.gstatic.com maps.googleapis.com bat.bing.com hose.gardeningexpress.co.uk google.com bat.bing.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://cdn.levelaccess.net https://cdn.segment.com https://js-agent.newrelic.com https://script.hotjar.com https://static.hotjar.com https://static.khealth.com https://static.legitscript.com; style-src 'self'; object-src 'none'; base-uri 'self'; img-src 'self' data: https://static.legitscript.com; font-src 'self'; connect-src 'self' https://cdn.levelaccess.net https://api.segment.io https://bam.nr-data.net https://cdn.segment.com; frame-src 'none'; manifest-src 'self'; media-src 'self'; worker-src 'self'; report-to csp-endpoint 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' ws: *.nexiuslearning.com *.google-analytics.com *.etitan.hu *.googletagmanager.com *.googleapis.com *.gstatic.com *.google.com *.bootstrapcdn.com *.extremenet.hu stats.g.doubleclick.net www.youtube-nocookie.com; report-uri https://etitancsp.azurewebsites.net/api/eTitanCSP; 1 default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval' 1 connect-src 'self'; font-src 'self'; frame-src 'self'; img-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' https://cdnjs.cloudflare.com; webrtc 'block'; worker-src 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.turing.ac.uk/log-report-uri/reportOnly; block-all-mixed-content 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://app-sj21.marketo.com https://munchkin.marketo.net https://js.stripe.com https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://p.yotpo.com https://staticw2.yotpo.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://tags.tiqcdn.com https://collect.tealiumiq.com https://cdn.mxpnl.com https://api-js.mixpanel.com https://js.zi-scripts.com https://ws.zoominfo.com https://widget.trustpilot.com https://player.vimeo.com https://app-sj21.marketo.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://p.yotpo.com https://staticw2.yotpo.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://fonts.gstatic.com https://use.fontawesome.com; img-src 'self' data: https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://s.ushipcdn.com https://resources.awsuship.com https://d2i7mi0re7cgbq.cloudfront.net https://proof-of-delivery-prod.s3.us-east-1.amazonaws.com https://uship-legacy-resources-prod.s3.us-east-1.amazonaws.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://fonts.gstatic.com https://maps.gstatic.com https://www.gstatic.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://p.yotpo.com https://staticw2.yotpo.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://*.online-metrix.net https://cdn.sanity.io https://notify.bugsnag.com https://app.jazz.co https://t.vibe.co; font-src 'self' data: https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://p.yotpo.com https://staticw2.yotpo.com https://fonts.gstatic.com https://use.fontawesome.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://api.radar.io https://static.radar.com; connect-src 'self' https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://proof-of-delivery-prod.s3.us-east-1.amazonaws.com https://uship-legacy-resources-prod.s3.us-east-1.amazonaws.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://app-sj21.marketo.com https://munchkin.marketo.net https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://p.yotpo.com https://staticw2.yotpo.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://tags.tiqcdn.com https://collect.tealiumiq.com https://cdn.mxpnl.com https://api-js.mixpanel.com https://js.zi-scripts.com https://ws.zoominfo.com https://api.radar.io https://static.radar.com; media-src 'self' data: https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud; frame-src 'self' https://www.uship.com https://about.uship.com https://api-reviews.uship.com https://api-web.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://login.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://www.googletagmanager.com https://www.google.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://js.stripe.com https://connect.stripe.com https://bat.bing.com https://www.bing.com https://bat.bing.net https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://*.online-metrix.net https://widget.trustpilot.com https://player.vimeo.com https://app-sj21.marketo.com; worker-src 'self' blob:; child-src 'self'; manifest-src 'self' https://www.ushipcdn.cloud; object-src 'none'; frame-ancestors 'self'; block-all-mixed-content; report-uri https://uship.report-uri.com/r/t/csp/reportOnly; report-to csp 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.se https://www.googletagmanager.com https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.se; frame-src 'self' https://analytics.nordnet.se https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://t.email.nordnet.se; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogg.nordnet.se; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.se https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-1700968a-b9e6-4476-8450-879f7af3c410' https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se https://www.recaptcha.net; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.se; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com https://app.sigmastocks.com; 1 default-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai; script-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai 'unsafe-inline' 'unsafe-eval'; style-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai 'unsafe-inline'; img-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai data:; font-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai data:; frame-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai; connect-src 'self' qoder.com g.alicdn.com http://127.0.0.1:3333 https://www.googletagmanager.com https://www.google-analytics.com https://cloudauth-device.aliyuncs.com https://cn-shanghai.device.saf.aliyuncs.com https://cloudauth-device.ap-southeast-1.aliyuncs.com https://ap-southeast-1.device.saf.aliyuncs.com https://captcha-open-southeast.aliyuncs.com https://*.captcha-open.aliyuncs.com https://*.captcha-open-b.aliyuncs.com https://*.captcha-open-southeast.aliyuncs.com https://*.captcha-open-southeast-b.aliyuncs.com https://cloudauth-device-dualstack.cn-shanghai.aliyuncs.com https://ap-southeast-1-ga.device.saf.aliyuncs.com https://g.alicdn.com https://o.alicdn.com https://static-captcha.aliyuncs.com https://static-captcha-sgp.aliyuncs.com https://img.alicdn.com https://tbexpand.alicdn.com https://avatars.qoder.ai https://test-cdn.qoder.ai; object-src 'none'; frame-ancestors 'none'; report-uri /csp-reports 1 default-src 'self'; report-uri https://arcules.report-uri.com/r/t/csp/wizard 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com https://premier.trustcommerce.com;script-src 'nonce-bdadc51e9e7848e69e754add34149f6e' https://essentiamychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://essentiamychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.curator.io *.elfsight.com *.hotjar.com *.facebook.net *.cloudfront.net *.micpn.com *.searchstax.com *.wisepops.com wisepops.com *.wisepops.net wisepops.net *.sentry-cdn.com *.thehotelsnetwork.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.fonts.net *.myfonts.net *.doubleclick.net *.curator.io; img-src 'self' data: blob: *.google.co.uk *.facebook.com *.doubleclick.net *.google-analytics.com *.micpn.com *.googleapis.com *.gstatic.com *.cloudfront.net *.curator.io *.tripadvisor.com; connect-src 'self' *.bing.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.micpn.com *.facebook.com *.mapbox.com *.curator.io *.wisepops.net *.wisepops.com wisepops.net wisepops.com *.thehotelsnetwork.com; font-src 'self' data: *.fonts.net *.myfonts.net *.gstatic.com; worker-src 'self' blob:; child-src 'self' blob: *.google.com *.googleapis.com *.googletagmanager.com *.doubleclick.net; frame-src 'self' *.google.com *.doubleclick.net *.facebook.com; media-src 'self'; object-src 'none'; base-uri 'self'; report-uri https://3chillies.report-uri.com/r/d/csp/reportOnly; 1 script-src 'self' 'unsafe-eval' assets.sitescdn.net connect.cooper.edu https://cdnjs.cloudflare.com https://www.skynettechnologies.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' answers-embed.cooper.edu.pagescdn.com buttons-config.sharethis.com cdn.unibuddy.co chimpstatic.com mx.technolutions.net traffic-drivers.unibuddy.co www.google-analytics.com www.googletagmanager.com www.youvisit.com www.youtube.com cooper.us10.list-manage.com s3.amazonaws.com t.sharethis.com js-agent.newrelic.com www.skynettechnologies.com assets.sitescdn.net connect.cooper.edu https://cdnjs.cloudflare.com https://www.skynettechnologies.com; style-src 'self' fonts.googleapis.com https://assets.sitescdn.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn-images.mailchimp.com fonts.googleapis.com https://assets.sitescdn.net https://cdnjs.cloudflare.com; frame-ancestors 'self' cooper.edu; report-uri https://cooper.report-uri.com/r/d/csp/wizard 1 font-src *.gstatic.com data: *.googleapis.com cdnjs.cloudflare.com js-agent.newrelic.com api.map.baidu.com *.baidu.com *.bdimg.com *.mtcaptcha.com *.bglobale.com *.global-e.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://secure-test.worldpay.com/shopper/3ds/ddc.html 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.bglobale.com *.global-e.com maisongoyard--staging.sandbox.my.salesforce-sites.com maisongoyard.my.salesforce-sites.com *.mtcaptcha.com *.smartpixels.fr c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://pay.google.com https://secure-test.worldpay.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com *.baidu.com *.bdimg.com sdk.privacy-center.org *.mtcaptcha.com goyard-marquage-webconf.smartpixels.fr ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.bglobale.com *.global-e.com *.goyard.com *.smartpixels.fr goyard-marquage-test-we-appservice-webconf.azurewebsites.net sprint-7onpvba-jccxky3s5ebcw.us-a1.magentosite.cloud www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com cdnjs.cloudflare.com bam.nr-data.net mcstaging.goyard.com mcprod.goyard.com goyard.com js-agent.newrelic.com api.map.baidu.com *.baidu.com *.bdimg.com sdk.privacy-center.org *.mtcaptcha.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.bglobale.com *.global-e.com *.goyard.com payments.worldpay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.google.com/recaptcha/api.js *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdnjs.cloudflare.com *.googleapis.com *.baidu.com *.bdimg.com *.mtcaptcha.com downloads.mailchimp.com *.bglobale.com *.global-e.com unsafe-inline assets.braintreegateway.com *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.goyard.com *.goyard.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com api.map.baidu.com *.baidu.com *.bdimg.com api.privacy-center.org *.mtcaptcha.com *.goyard.com *.bglobale.com *.global-e.com *.nr-data.net *.smartpixels.fr api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src maisongoyard--staging.sandbox.my.salesforce-sites.com maisongoyard.my.salesforce-sites.com *.mtcaptcha.com *.goyard.com *.bglobale.com *.global-e.com *.nr-data.net *.smartpixels.fr payments.worldpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.hotjar.com *.mavenoid.com *.klevu.com *.ksearchnet.com *.narvar.com *.narvar.qa *.onetrust.com www.worx.com worx.com *.signifyd.com *.onlineada.workers.dev maxaccess-api.onlineada.workers.dev *.maxaccess.io *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com s.amazon-adsystem.com *.hotjar.com www.facebook.com *.pinterest.com www.paypalobjects.com *.amc.demdex.net *.demdex.net *.cardinalcommerce.com *.authorize.net *.vimeo.com www.google.com *.ugc.bazaarvoice.com *.bazaarvoice.com *.api.bazaarvoice.com *.amazon-adsystem.com *.weltpixel.com mcstaging.worx.com tst.kaptcha.com *.adsrvr.org www.worx.com worx.com *.dap.akadns.net *.signifyd.com *.monetate.net ssl.kaptcha.com *.online-metrix.net *.captcha-delivery.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.bing.com *.adsrvr.org x.bidswitch.net pixel.advanseads *.fg8dgt.com www.facebook.com *.tremorhub.com *.reson8.com *.mathtag.com *.bluekai.com sync.search.spotxchange.com thrtle.com sync.go.sonobi.com *.demdex.net www.livehelpnow.net *.rubiconproject.net *.g.doubleclick.net tapestry.tapad.com segments.company-target.com simage2.pubmatic.com dsum.casalemedia.com ads.altitude-arena.com i.liadm.com *.listrakbi.com *.adobedtm.com *.sc.omtrdc.net *.everesttech.net *.magentocommerce.com *.sandbox.paypal.com *.ytimg.com *.swagger.io *.cloudfront.net *.bazaarvoice.com *.ugc.bazaarvoice.co *.rlcdn.com *.bfmio.com *.klevu.com *.ksearchnet.com *.narvar.com *.narvar.qa www.sandbox.paypal.com *.stats.paypal.com *.braintreegateway.com www.google.co.in *.cookielaw.org *.dap.akadns.net *.espssl.com *.s3.us-east-2.amazonaws.com *.pinterest.com *.hotjar.com www.emjcd.com *.dotomi.com *.worx.com worx.com *.five9.com *.nextdoor.com s3.amazonaws.com *.googleapis.com *.facebook.net *.eu.worx.com pippio.com *.adsymptotic.com *.openx.net *.agkn.com *.audrte.com *.krxd.net *.videohub.tv *.adxns.com *.media6degrees.com *.ads.linkedin.com *.scorecardresearch.com *.netseer.com *.us1.dyntrk.com *.insightexpressai.com *.mediawallahscript.com *.t.domdex.com *.services.xg4ken.com trkn.us *.mmsho.com *.narrative.io *.postrelease.com *.ispot.tv *.crsspxl.com *.bnmla.com *.acxiomapac.com *.y-medialink.com *.shopping.rakuten.com *.rtbiq.com *.ib-ibi.com *.signifyd.com *.monetate.net *.srv.stackadapt.com *.spotify.com *.rd.linksynergy.com um.simpli.fi cs.media.net *.addthis.com sync.ipredictive.com lrp.mxptint.net pixel.tapad.com epiv.cardlytics.com secure.adnxs.com www.entitytag.co.uk px.owneriq.net bttrack.com ssum.casalemedia.com usersync-b3.videoamp.com *.maxaccess.io *.online-metrix.net s3-us-west-2.amazonaws.com maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pixriot.com *.storeimaging.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.sharethis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com js-agent.newrelic.com bam.nr-data.net blueacornici.atlassian.net *.monetate.net www.livehelpnow.net js.klevu.com *.listrakbi.com *.facebook.net *.steelhousemedia.com *.adacado.com *.hotjar.com *.amazon-adsystem.com *.rlcdn.com *.adsrvr.org *.bidswitch.net *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.authorize.net *.paypal.com *.ytimg.com *.bazaarvoice.com *.nexus.bazaarvoice.co *.ugc.bazaarvoice.com *.api.bazaarvoice.com *.iesnare.com *.atlassian.net polyfill.io *.fg8dgt.com *.ksearchnet.com *.sandbox.braintreegateway.com *.bing.com *.tiktok.com www.mczbf.com *.cookielaw.org *.maxaccess.io *.five9.com *.r.bidswitch.net *.dstillery.com *.media6degrees.com *.onlineada.workers.dev *.fullstory.com s.pinimg.com *.mavenoid.com *.cloudfront.net mcstaging.worx.com www.worx.com worx.com *.orderwave.com *.googleapis.com get.geojs.io *.g.doubleclick.net *.nextdoor.com code.jquery.com dap-dist.akamaized.net serviceconnection.pro *.blob.core.windows.net kalicube.pro *.jsdelivr.net *.dap.akadns.net sjwoe.com www.sjwoe.com *.narvar.com *.ads.linkedin.com www.googleoptimize.com *.signifyd.com *.datadome.co *.captcha-delivery.com *.schemaapp.com ct.pinterest.com cdnjs.cloudflare.com *.online-metrix.net kenwheeler.github.io maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com display.ugc.bazaarvoice.com *.googleapis.com *.listrakbi.com *.mavenoid.com *.five9.com *.espssl.com *.typekit.net serviceconnection.pro *.onetrust.com www.worx.com worx.com *.signifyd.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com assets.braintreegateway.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.worx.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.onetrust.com bam.nr-data.net *.listrakbi.com *.listrak.com *.hotjar.io *.g.doubleclick.net *.demdex.net *.sc.omtrdc.net *.cardinalcommerce.com *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.amazonservices.de *.bazaarvoice.com *.api.bazaarvoice.com *.klevu.com *.ksearchnet.com *.sandbox.braintreegateway.com *.tiktok.com *.cookielaw.org *.onlineada.workers.dev *.cloudfront.net *.execute-api.us-east-2.amazonaws.com *.five9.com *.fullstory.com www.mczbf.com *.pinterest.com *.ingest.sentry.io *.mavenoid.com *.googleapis.com surveystats.hotjar.io serviceconnection.pro kalicube.pro *.blob.core.windows.net www.facebook.com *.jsdelivr.net *.dap.akadns.net sjwoe.com www.sjwoe.com www.worx.com worx.com *.ads.linkedin.com www.googleoptimize.com www.livehelpnow.net *.signifyd.com *.monetate.net *.datadome.co *.cloudfunctions.net *.bing.com *.schemaapp.com *.google.co.in *.maxaccess.io s.amazon-adsystem.com ara.paa-reporting-advertising.amazon maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.pixriot.com *.storeimaging.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-948804c5204242d48158e351cd5372ac' https://www.myconnectnyc.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.myconnectnyc.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: www.googletagmanager.com www.google-analytics.com *.contentsquare.net; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob: www.googletagmanager.com www.google-analytics.com www.googleadservices.com d1stxfv94hrhia.cloudfront.net commondatastorage.googleapis.com d2wy8f7a9ursnm.cloudfront.net cdn.ckeditor.com t.contentsquare.net contentsquare.com secure.livechatinc.com; style-src 'self' https: 'unsafe-inline'; child-src blob: https://accounts.google.com https://www.google.com https://storage.googleapis.com https://www.googletagmanager.com/ https://www.paypalobjects.com https://*.paypal.com https://www.sandbox.paypal.com https://*.doubleclick.net https://www.facebook.com https://connect.facebook.com https://facebook.com https://service.force.com https://finditparts.my.site.com https://finditparts.my.salesforce.com https://secure.livechatinc.com https://app.dover.com/ https://app.dover.io/; worker-src blob:; frame-ancestors 'self' https://buttercms.com https://app.fullbay.com; connect-src 'self' https: http://localhost:3035 ws://localhost:3035 ws://localhost:3001/cable wss://www-build.finditparts.com/cable wss://www.finditparts.com/cable apis.google.com maps.googleapis.com cdn.jsdelivr.net code.jquery.com www.google-analytics.com *.attn.tv *.contentsquare.net *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com secure.livechatinc.com 1 script-src 'self' 'nonce-su6DPHJTnee2lP3qpneMcC6ZBYrIVn1+rtMXzk2SiQs=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.cloudflare.com *.trustedshops.com *.bootstrapcdn.com https://display.ugc.bazaarvoice.com 'self' data: *.vortexoptics.com https://vortexoptics.com/static https://*.userway.org/ *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com/tr/ https://mcstaging.vortexoptics.com/ https://mcstaging.vortexgolf.com/ https://vortexoptics.com/ https://vortexgolf.com/ https://*.userway.org/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com https://w.soundcloud.com https://www.google.com https://vars.hotjar.com https://amc.demdex.net/ https://www.facebook.com/ https://*.doubleclick.net/ https://*.userway.org/ *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net http://amcglobal.sc.omtrdc.net/ widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com *.meetanshi.com https://mcstaging.vortexoptics.com/ *.cloudflare.com https://cdn.klarna.com *.ytimg.com *.usercentrics.eu https://www.google.com/ https://facebook.com/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://www.facebook.com/ https://connect.facebook.net/ *.bazaarvoice.com/ https://contentorigin.bazaarvoice.com/ https://vortexoptics.widen.net/ *.gettopple.com/ https://bam.nr-data.net/ *.kaltura.com/ https://*.userway.org/ https://yotpo-media-temporary.s3.amazonaws.com/ www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/js/select2.min.js *.cloudflare.com *.trustedshops.com *.usercentrics.eu https://chimpstatic.com *.zdassets.com https://www.google.com https://www.gstatic.com https://geoip.nekudo.com https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com https://connect.facebook.net/ https://widget-mediator.zopim.com https://googleads.g.doubleclick.net/ *.gettopple.com/ https://mpsnare.iesnare.com/ *.vortexoptics.com https://vortexoptics.com/static/ https://klear.com/ https://cdnapisec.kaltura.com/ https://*.userway.org/ wss://pod-13-sunco-ws.zendesk.com *.maxmind.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.bazaarvoice.com *.bootstrapcdn.com *.vortexoptics.com https://vortexoptics.com/static https://*.userway.org/ https://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/css/select2.min.css *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com https://mpsnare.iesnare.com/ https://*.userway.org/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.meetanshi.com *.gstatic.com *.cloudflare.com https://rum.hlx.page *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com https://widget-mediator.zopim.com https://in.hotjar.com http://amcglobal.sc.omtrdc.net/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/ https://dpm.demdex.net/ https://www.facebook.com/ https://*.hotjar.com https://maps.googleapis.com *.bazaarvoice.com wss://*.hotjar.com https://*.hotjar.io wss://mpsnare.iesnare.com/star wss://pod-13-sunco-ws.zendesk.com https://*.googlesyndication.com *.vortexoptics.com https://vortexoptics.com/static https://insights.algolia.io https://klear.com/ https://*.userway.org/ *.mmapiws.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://epic.gateway.patientco.com https://pay.instamed.com;script-src 'nonce-d970068bcd0e4ed689e7acae0a09627a' https://www.mylvhn.org 'self' https://www.google.com/reCaptcha/enterprise.js;img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://www.google.com;style-src https://www.mylvhn.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com uat.pinepg.in https://uat.pinepg.in/api/PG/V2 secure.pinepg.in https://secure.pinepg.in/payment 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net *.googleapis.com maps.gstatic.com www.pinelabs.com https://www.pinelabs.com/img/logo.png *.gstatic.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com https://www.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com landofcoder.com https://storage.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com https://www.google-analytics.com https://fonts.gstatic.com *.googleapis.com https://www.gstatic.com landofcoder.com https://storage.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.googleadservices.com 'self' 'unsafe-inline'; 1 worker-src blob:; form-action *.cardinalcommerce.com *.paypal.com www.sandbox.paypal.com *.amazon.com *.facebook.com *.googlesyndication.com connect.facebook.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.googletagmanager.com *.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.braintreegateway.com google.com js.stripe.com *.amazon.com *.payments-amazon.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com connect.facebook.net www.commercepartnerhub.com assets.braintreegateway.com plumrocket.com *.authorize.net www.googleadservices.com *.artifi.net assets.pinterest.com ct.pinterest.com www.paypalobjects.com i.liadm.com 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net *.google.com *.newrelic.com *.nr-data.net *.authorize.net *.commerce-payment-services.com *.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klaviyo.com fast.a.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.shopify.com *.sandbox.braintreegateway.com celebrosnlp.com *.celebros-analytics.com maps.googleapis.com www.googletagservices.com cdn.gladly.qa cdn.gladly.com *.cloudflare.com *.artifi.net *.monetate.net cdn.popt.in *.visualwebsiteoptimizer.com *.cloudfront.net s.pinimg.com bat.bing.com tag.rmp.rakuten.com ut.rd.linksynergy.com *.pinterest.com cdn.noibu.com *.hotjar.com b-code.liadm.com secure.merchantadvantage.com static.currentcatalog.com currentc-ac.celebros.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://www.currentcatalog.com/pr-csp/report/add/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.facebook.com *.twitter.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cloudflare.com *.cloudfront.net *.baen.com *.twitter.com *.twimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.fontawesome.com *.facebook.net *.authorize.net *.simpli.fi js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.gstatic.com *.twitter.com *.twimg.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.authorize.net *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src d.digsgogo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data: 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https:; frame-src 'self' https://*.vipleiloes.com.br https://*.provedor.space https://streaming01.vplpar.com:5443; media-src 'self' https:; form-action 'self' https:; base-uri 'self'; frame-ancestors 'self' https://*.vipleiloes.com.br https://streaming01.vplpar.com:5443; object-src 'none'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' www.resellerratings.com www.paypal.com cdn.attn.tv s.yimg.com static.klaviyo.com cdn-tp4.mozu.com/27977-44902/ t.contentsquare.net ajax.googleapis.com www.googleadservices.com bat.bing.com www.google.com www.googletagmanager.com live-chat.chatbotize.com d2gh7vqn9p1ieu.cloudfront.net www.res-x.com resources.xg4ken.com polaris.truevaultcdn.com pay.google.com www.paypalobjects.com challenges.cloudflare.com googleads.g.doubleclick.net cdn.sift.com www.google-analytics.com www.mczbf.com acsbapp.com s3-us-west-2.amazonaws.com maps.googleapis.com www.clarity.ms static-tracking.klaviyo.com b-code.liadm.com sv.calendars.com edge1.certona.net services.xg4ken.com connect.facebook.net se.monetate.net cdn-tp4.mozu.com cdn.equalweb.com access.equalweb.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=G8XJ45zG_96BSRd98n6gI4LLUoBoNTsNLmkkI6nnSA4-1765934062-1.0.1.1-jtL_2pd2dZbkfbNufd3kD71OrJAzAmNNwlAlur8wmF.pVhlVCNU73EQHczAJ119dD20BLE3q58m8ni4P2sGahwK2D4r1VTq3RzGn3TwUOHNt2ipXsIE_7eIDSQvLNwpiYtzFdQtpIOzZLgUHPpSlIZ3tTn6LhwuFnVM.qiMxeUr_GP_ec4rn7FWYNzsO_OC3J59w2y_3cfcow5JtBq5pgg; report-to cf-tutovyoamuhpgsnl 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://events.framer.com/script https://framer.com https://framerusercontent.com https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://events.framer.com https://lottie.host https://region1.google-analytics.com https://website-data-beta.vercel.app https://www.google-analytics.com; font-src 'self' https://cdnjs.cloudflare.com https://framerusercontent.com; frame-src 'self' https://embeds.beehiiv.com https://framer.com; img-src 'self' data: https://framerusercontent.com https://www.googletagmanager.com https://yastatic.net; manifest-src 'self'; media-src 'self' https://framerusercontent.com; worker-src 'none'; frame-ancestors 'self'; report-uri https://68af03dee39705929f59b2eb.endpoint.csper.io?builder=true&v=9; 1 report-uri https://mon.capcutapi.us/monitor_browser/collect/batch/security/?bid=cc_web_compliance&c=32&ev_type=csp&r=12&v=3; report-to csp-endpoint; default-src 'self' 'unsafe-eval' 'unsafe-inline' blob: bytedance: data: wss://*.us.capcut.com *.bing.com *.bing.net *.capcutapi.us *.capcutcdn-us.com *.capcutw.us *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.giphy.com *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.tiktokcdn-us.com *.tiktokv.us *.tiktokw.us *.ttcdn-us.com *.us.capcut.com appleid.cdn-apple.com dreamina.capcut.com ep2.adtrafficquality.google facebook.com google.com login-row.www.capcut.com www.capcut.com www.tiktok.com; connect-src 'self' blob: bytedance: data: http://localhost:* https://localhost:* wss://*.us.capcut.com *.bing.com *.bing.net *.capcutapi.us *.capcutcdn-us.com *.capcutw.us *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.pipopay.com *.pipopayment.com *.pipopayment.us *.tiktokcdn-us.com *.tiktokv.us *.tiktokw.us *.twitter.com *.us.capcut.com dreamina.capcut.com login-row.www.capcut.com www.capcut.com www.tiktok.com; frame-src 'self' bytedance: *.capcutw.us *.google.com *.googletagmanager.com capcut-yt.onelink.me dreamina.capcut.com ep2.adtrafficquality.google googleads.g.doubleclick.net media-evercloud.capcutapi.us td.doubleclick.net www.capcut.com www.tiktok.com; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-eval' 'wasm-unsafe-eval' *.bing.com *.capcutcdn-us.com *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.googlesyndication.com *.googletagmanager.com *.tiktokcdn-us.com appleid.cdn-apple.com ep2.adtrafficquality.google googleads.g.doubleclick.net scripts.clarity.ms www.clarity.ms www.gstatic.com; worker-src 'self'; base-uri 'none'; frame-ancestors 'self' bytedance: dreamina.capcut.com www.capcut.com 1 object-src 'none'; frame-ancestors https://*.workspot.com; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://*.cloudflare.com https://pi.pardot.com https://*.cookiebot.com https://*.workspot.com https://www.google-analytics.com https://www.googletagmanager.com https://*.google.co.uk https://www.workspot.com https://*.google.com https://*.googleadservices.com https://*.googleapis.com https://*.googletagmanager.com https://*.gstatic.cn https://*.gstatic.com; font-src 'self' https://*.gstatic.com https://s0.wp.com data:; img-src 'self' https://*.cookiebot.com data: https://www.google-analytics.com https://*.google.co.uk https://*.google.com https://secure.gravatar.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com; connect-src 'self' https://*.cookiebot.com https://*.google.com https://www.google-analytics.com https://stats.g.doubleclick.net yoast.com; report-uri /; 1 object-src 'none'; script-src 'nonce-8c7-vsP68xASbctM6zPvI38f' 'strict-dynamic' http: https:; base-uri 'none'; 1 default-src https: data: 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com fonts.gstatic.com *.fontawesome.com *.aspnetcdn.com *.jsdelivr.net *.googletagmanager.com *.googleadservices.com s.adroll.com wss://*.hotjar.com/api/v2/client/ws *.jquery.com; img-src data: *; frame-ancestors 'self'; object-src 'none'; form-action 'self'; base-uri 'self'; media-src s3.amazonaws.com; report-uri /csp/; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.payneglasses.com ka-f.fontawesome.com fonts.googleapis.com *.alicdn.com cdnjs.cloudflare.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com https://static.klaviyo.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://plumrocket.com https://accounts.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * self *.payneglasses.com payneglasses.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com https://www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com https://www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.payneglasses.com static.payneglasses.com payneglasses.com bat.bing.com google.com *.google.com ct.pinterest.com *.alicdn.com *.googleusercontent.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com storage.needpix.com cdn.pixabay.com c1.peakpx.com cdn.stocksnap.io https://pagead2.googlesyndication.com https://www.googletagservices.com https://d3k81ch9hvuctc.cloudfront.net https://d2xo6khwzbhes8.cloudfront.net *.google.co.in pm.geniusmonkey.com ib.adnxs.com sync.1rx.io eb2.3lift.com ade.clmbtech.com criteo-sync.teads.tv sync-t1.taboola.com rtb-csync.smartadserver.com pixel.rubiconproject.com simage2.pubmatic.com sync.outbrain.com gum.criteo.com c.bing.com contextual.media.net idsync.rlcdn.com ad.360yield.com ads.stickyadstv.com cs.adingo.jp r.casalemedia.com tg.socdm.com cm.g.doubleclick.net x.bidswitch.net sync.targeting.unrulymedia.com *.agkn.com *.criteo.com *.v.fwmrm.net user-sync.fwmrm.net *.adsrvr.org *.yahoo.com match.prod.bidr.io public-prod-dspcookiematching.dmxleo.com *.pubmatic.com *.adform.net *.simpli.fi ad.turn.com pubmatic-match.dotomi.com www.facebook.com pixel-sync.sitescout.com sync.crwdcntrl.net sync.springserve.com sync.srv.stackadapt.com sync.ipredictive.com rtb.openx.net *.iadvize.com wss://ws.hotjar.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page tagmanager.google.com https://www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://accounts.google.com https://www.gstatic.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.payneglasses.com *.loginwithamazon.com *.ssl-images-amazon.com *.hotjar.com *.iadviz.net static.payneglasses.com payneglasses.com bat.bing.com *.pinimg.com analytics.tiktok.com kit.fontawesome.com *.iadvize.com *.alicdn.com cdnjs.cloudflare.com https://d2xo6khwzbhes8.cloudfront.net https://*.cloudfront.net *.facebook.net cdn.jsdelivr.net unpkg.com vtom.neox-lab.com www.vtlicensing.com cdn.convertcart.com pm.geniusmonkey.com static.criteo.net wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com https://accounts.google.com https://www.gstatic.com https://fonts.googleapis.com assets.braintreegateway.com *.payneglasses.com static.payneglasses.com payneglasses.com *.fastsimon.com ka-f.fontawesome.com *.typekit.net *.alicdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com accounts.google.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.payneglasses.com payneglasses.com *.alicdn.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google-analytics.com www.googleadservices.com analytics.google.com https://www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.google-analytics.com https://*.analytics.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://accounts.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.payneglasses.com payneglasses.com doubleclick.net *.doubleclick.net bat.bing.com ct.pinterest.com analytics.tiktok.com *.iadvize.com ka-f.fontawesome.com *.alicdn.com cdnjs.cloudflare.com ip-geolocation-ipwhois-io.p.rapidapi.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com https://pagead2.googlesyndication.com https://www.googletagservices.com https://a.klaviyo.com https://static-tracking.klaviyo.com *.convertcart.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.cloudfront.net https://*.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com self *.payneglasses.com payneglasses.com http: https: blob: 'self' 'unsafe-inline'; default-src https://*.iadvize.com wss://*.iadvize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' Player/flowplay.js https://ajax.googleapis.com/ajax/libs/webfont/1.6.26/webfont.js https://assets-global.website-files.com/656db9d2a0a4556c7301b80a/js/webflow.9f1d254fa.js https://cdn.heapanalytics.com/js/heap-1645308922.js https://cdn.jsdelivr.net/gh/videsigns/webflow-tools@latest/Media https://cdn.jsdelivr.net/npm/@finsweet/attributes-cmsfilter@1/cmsfilter.js https://cdn.jsdelivr.net/npm/@finsweet/attributes-cmsselect@1/cmsselect.js https://cdn.jsdelivr.net/npm/@finsweet/attributes-formsubmit@1/formsubmit.js https://cdn.jsdelivr.net/npm/@finsweet/attributes-selectcustom@1/selectcustom.js https://cdn.jsdelivr.net/npm/@finsweet/cookie-consent@1/fs-cc.js https://cdn.jsdelivr.net/npm/swiper@11/swiper-bundle.min.js https://cdn.prod.website-files.com/656db9d2a0a4556c7301b80a/js/webflow.107f32587.js https://cdnjs.cloudflare.com/ajax/libs/gsap/3.11.3/ScrollTrigger.min.js https://cdnjs.cloudflare.com/ajax/libs/gsap/3.11.3/gsap.min.js https://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.5.1/highlight.min.js https://d3e54v103j8qbb.cloudfront.net/js/jquery-3.5.1.min.dc5e7f18c8.js https://hubspotonwebflow.com/assets/js/form-124.js https://js-eu1.hs-analytics.net/analytics/1711618800000/25393921.js https://js-eu1.hs-analytics.net/analytics/1711666200000/25393921.js https://js-eu1.hs-analytics.net/analytics/1723072800000/25393921.js https://js-eu1.hs-banner.com/25393921.js https://js-eu1.hs-banner.com/v2/25393921/banner.js https://js-eu1.hs-scripts.com/25393921.js https://js-eu1.hscollectedforms.net/collectedforms.js https://js-eu1.usemessages.com/conversations-embed.js https://plausible.io/js/script.js https://unpkg.com https://unpkg.com/split-type https://unpkg.com/swiper/swiper-bundle.min.js https://ws.zoominfo.com/pixel/6318ef9b7326f94006446c6b https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self' 'unsafe-inline' https://assets-global.website-files.com https://cdn.prod.website-files.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://unpkg.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://api-eu1.hubspot.com https://assets-global.website-files.com https://cdn.prod.website-files.com https://dc8jmdyhm5-1.algolianet.com https://dc8jmdyhm5-2.algolianet.com https://dc8jmdyhm5-dsn.algolia.net https://exceptions-eu1.hs-embed-reporting.com https://forms-eu1.hscollectedforms.net https://heapanalytics.com https://hubspotonwebflow.com https://js-eu1.hs-banner.com https://plausible.io https://region1.analytics.google.com https://region1.google-analytics.com https://static.hsappstatic.net https://stats.g.doubleclick.net https://webflow.com https://ws.zoominfo.com https://www.google-analytics.com https://www.google.ca https://www.google.co.in https://www.google.com.pk https://www.google.pl https://www.google.pt; font-src 'self' data: https://fonts.gstatic.com https://static.hsappstatic.net; frame-src 'self' https://app-eu1.hubspot.com https://td.doubleclick.net https://www.googletagmanager.com https://www.youtube.com; img-src 'self' blob: data: https://analytics.google.com https://assets-global.website-files.com https://avatars.githubusercontent.com https://cdn.prod.website-files.com https://exceptions-eu1.hs-embed-reporting.com https://forms-eu1.hsforms.com https://github.com https://heapanalytics.com https://i.ytimg.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://track-eu1.hubspot.com https://www.google-analytics.com https://www.google.at https://www.google.be https://www.google.ca https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.uk https://www.google.com.au https://www.google.com.gh https://www.google.com.ph https://www.google.com.pk https://www.google.de https://www.google.es https://www.google.fr https://www.google.li https://www.google.nl https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.ru https://www.google.se https://www.googletagmanager.com; manifest-src 'self'; media-src 'self' https://assets-global.website-files.com https://cdn.prod.website-files.com https://tonikstudio.fra1.cdn.digitaloceanspaces.com; report-uri https://6602a323bc57ae1120bf88dc.endpoint.csper.io/?v=7; worker-src 'none'; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv50.f0%3F%3Bc-19b2a1e68e8-0x1702#pd 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-ci6vOIZb8MzrNnu-T-QnXg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src https:;frame-ancestors about: 'self';frame-src https://optimize.google.com *;style-src https://optimize.google.com https://fonts.googleapis.com https: data: 'unsafe-inline' *;script-src https://www.googleanalytics.com https://www.google-analytics.com https://optimize.google.com * 'unsafe-inline' 'unsafe-eval';img-src https://www.google-analytics.com https://www.googletagmanager.com https://optimize.google.com https: data: *;font-src https://fonts.gstatic.com data: *;object-src 'none';connect-src * ws: wss:; report-uri https://res.destinia.com/web/csp-violation-report-endpoint; report-to default; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.mx *.betano.mx betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=5iwox2pOEBBSnQDVbjr5miiZcLLGtuFvYmV6vHAT_iY-1765939304-1.0.1.1-x75WBMlet5R.9X5ePurT5Vi.GLMfcIhwKMU.StoLxIg9VdanfRA6HJ9CNSQGyoBjE8_5jBKm1TVRcIMtNDhueoLV9xNoMAYerr4RqjYBSrzOfvFpNqwbX6LPcZLWo_5yglIWBFb9oGEH3D3IjQETtop.qQ7TQjkzXDBWGkY0lAG3KUzqDtw01Ea7XeTEkfW4H__VgUeSDlcsVv3it2lspw; report-to cf-bydbdcrwixrhxash 1 frame-ancestors 'self'; report-uri https://www.ntnews.com.au/csp-reports 1 script-src 'nonce-e9wClkZTyjY0flckd33JNQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=e85d483f-20cb-4170-b710-2bd884f76d23; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: https://*.stripe.com; object-src 'none'; script-src 'self' https: https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com 'nonce-oH55W7zf1BFmMwTSZZKfpg=='; style-src 'self' https: 'nonce-oH55W7zf1BFmMwTSZZKfpg=='; frame-src 'self' https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com; connect-src 'self' https://api.stripe.com https://maps.googleapis.com; report-uri /systems/csp_report 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.alicdn.com *.cloudflare.com *.faceworks.nl *.font.im ncspublicasset.s3.eu-west-3.amazonaws.com *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.multisafepay.com https://pay.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.multisafepay.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com *.alicdn.com *.bing.com *.bing.net *.cookiebot.com europe-west1-maxlead-dwh-test.cloudfunctions.net *.googleadservices.com *.google-analytics.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tn www.google.tt google.com *.googlesyndication.com *.licdn.com *.linkedin.com *.magento.cloud *.mailplus.nl s3.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.multisafepay.com https://pay.google.com m17.mailplus.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com www.xtento.com cdn.xtento.com 9292.nl *.bing.com *.clarity.ms *.cloudflare.com *.cookiebot.com *.cookiebot.eu *.googleadservices.com *.googlesyndication.com *.hotjar.com *.ipify.org *.licdn.com *.mailplus.nl *.marker.io *.oribi.io *.pinimg.com *.pinterest.com *.thinglink.me *.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.multisafepay.com unsafe-inline assets.braintreegateway.com *.mailplus.nl *.typekit.net *.vimeocdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com *.vimeocdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.sharethis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.multisafepay.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io 9292.nl *.alicdn.com *.bing.com *.bing.net *.clarity.ms *.cookiebot.com *.doubleclick.net *.googleadservices.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bj www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tn www.google.tt *.googlesyndication.com *.gstatic.com *.hotjar.com *.hotjar.io *.jquery.com *.linkedin.com *.marker.io *.pinterest.com s3.ap-east-1.amazonaws.com s3.eu-west-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://95b39a76-7377-449c-a715-7f75d8431eb4.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; block-all-mixed-content; child-src 'self' blob:; default-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; report-to csp-endpoint; report-uri https://sentry.nadapada.net/api/136/security/?sentry_key=7d3cea7bc0a6a8fb9a3fc5fe14a1ee02&sentry_environment=production; worker-src 'self' blob:; connect-src 'self' blob: data: https://analytics.google.com https://analytics.talentbrew.io https://content.hotjar.io https://google-analytics.com https://maps.googleapis.com https://*.werkenbijdefensie.nl https://overbridgenet.com https://p.typekit.net https://pagead2.googlesyndication.com https://pulse.werkenbijdefensie.nl https://region1.analytics.google.com https://region1.google-analytics.com https://sentry.nadapada.net/api/136/ https://stats.g.doubleclick.net https://use.typekit.net https://www.google-analytics.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.ao https://www.google.co.bw https://www.google.co.ck https://www.google.co.cr https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.ke https://www.google.co.kr https://www.google.co.ls https://www.google.co.ma https://www.google.co.mz https://www.google.co.nz https://www.google.co.th https://www.google.co.tz https://www.google.co.ug https://www.google.co.uk https://www.google.co.uz https://www.google.co.ve https://www.google.co.vi https://www.google.co.za https://www.google.co.zm https://www.google.co.zq https://www.google.co.zw https://www.google.com https://www.google.com.af https://www.google.com.ag https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.bh https://www.google.com.bn https://www.google.com.bo https://www.google.com.br https://www.google.com.bz https://www.google.com.co https://www.google.com.cu https://www.google.com.cy https://www.google.com.do https://www.google.com.ec https://www.google.com.eg https://www.google.com.et https://www.google.com.fj https://www.google.com.gh https://www.google.com.gi https://www.google.com.gt https://www.google.com.hk https://www.google.com.jm https://www.google.com.kh https://www.google.com.kw https://www.google.com.lb https://www.google.com.ly https://www.google.com.mm https://www.google.com.mt https://www.google.com.mx https://www.google.com.my https://www.google.com.na https://www.google.com.ng https://www.google.com.ni https://www.google.com.np https://www.google.com.om https://www.google.com.pa https://www.google.com.pe https://www.google.com.pg https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.py https://www.google.com.qa https://www.google.com.sa https://www.google.com.sb https://www.google.com.sg https://www.google.com.sl https://www.google.com.sv https://www.google.com.tj https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vc https://www.google.com.vn https://www.google.cv https://www.google.cz https://www.google.de https://www.google.dj https://www.google.dk https://www.google.dm https://www.google.dz https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fm https://www.google.fr https://www.google.ga https://www.google.ge https://www.google.gg https://www.google.gh https://www.google.gr https://www.google.gy https://www.google.hn https://www.google.hr https://www.google.ht https://www.google.hu https://www.google.ie https://www.google.im https://www.google.iq https://www.google.is https://www.google.it https://www.google.je https://www.google.jo https://www.google.kg https://www.google.ki https://www.google.kz https://www.google.la https://www.google.li https://www.google.lk https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.md https://www.google.me https://www.google.mg https://www.google.mk https://www.google.ml https://www.google.mn https://www.google.mu https://www.google.mv https://www.google.mw https://www.google.ne https://www.google.nl https://www.google.no https://www.google.nr https://www.google.nu https://www.google.ph https://www.google.pl https://www.google.pn https://www.google.ps https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.rw https://www.google.sc https://www.google.se https://www.google.sh https://www.google.si https://www.google.sk https://www.google.sm https://www.google.sn https://www.google.so https://www.google.sr https://www.google.st https://www.google.td https://www.google.tg https://www.google.tl https://www.google.tm https://www.google.tn https://www.google.to https://www.google.tt https://www.google.vu https://www.google.ws https://www.googleadservices.com wss://ws.hotjar.com ; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net/af/494550/0000000000000000774b907b/30/ ; frame-src 'self' https://c1.adform.net https://links.intractive.app https://track.adform.net https://web.intractive.app https://www.google.com https://www.googletagmanager.com https://www.youtube.com https://login.werkenbijdefensie.nl ; img-src 'self' data: blob: https://analytics.talentbrew.io https://fonts.gstatic.com https://i.ytimg.com https://maps.googleapis.com https://maps.gstatic.com https://media.werkenbijdefensie.nl https://pagead2.googlesyndication.com https://server.seadform.net https://stats.g.doubleclick.net https://translate.google.com https://www.google-analytics.com https://www.google.ad/ads/ https://www.google.ae/ads/ https://www.google.al/ads/ https://www.google.am/ads/ https://www.google.as/ads/ https://www.google.at/ads/ https://www.google.az/ads/ https://www.google.ba/ads/ https://www.google.be/ads/ https://www.google.bf/ads/ https://www.google.bg/ads/ https://www.google.bi/ads/ https://www.google.bj/ads/ https://www.google.bs/ads/ https://www.google.bt/ads/ https://www.google.by/ads/ https://www.google.ca/ads/ https://www.google.cat/ads/ https://www.google.cd/ads/ https://www.google.cf/ads/ https://www.google.cg/ads/ https://www.google.ch/ads/ https://www.google.ci/ads/ https://www.google.cl/ads/ https://www.google.cm/ads/ https://www.google.cn/ads/ https://www.google.co.ao/ads/ https://www.google.co.bw/ads/ https://www.google.co.ck/ads/ https://www.google.co.cr/ads/ https://www.google.co.id/ads/ https://www.google.co.il/ads/ https://www.google.co.in/ads/ https://www.google.co.jp/ads/ https://www.google.co.ke/ads/ https://www.google.co.kr/ads/ https://www.google.co.ls/ads/ https://www.google.co.ma/ads/ https://www.google.co.mz/ads/ https://www.google.co.nz/ads/ https://www.google.co.th/ads/ https://www.google.co.tz/ads/ https://www.google.co.ug/ads/ https://www.google.co.uk/ads/ https://www.google.co.uz/ads/ https://www.google.co.ve/ads/ https://www.google.co.vi/ads/ https://www.google.co.za/ads/ https://www.google.co.zm/ads/ https://www.google.co.zw/ads/ https://www.google.com/ads/ https://www.google.com.af/ads/ https://www.google.com.ag/ads/ https://www.google.com.ar/ads/ https://www.google.com.au/ads/ https://www.google.com.bd/ads/ https://www.google.com.bh/ads/ https://www.google.com.bn/ads/ https://www.google.com.bo/ads/ https://www.google.com.br/ads/ https://www.google.com.bz/ads/ https://www.google.com.co/ads/ https://www.google.com.cu/ads/ https://www.google.com.cy/ads/ https://www.google.com.do/ads/ https://www.google.com.ec/ads/ https://www.google.com.eg/ads/ https://www.google.com.et/ads/ https://www.google.com.fj/ads/ https://www.google.com.gh/ads/ https://www.google.com.gi/ads/ https://www.google.com.gt/ads/ https://www.google.com.hk/ads/ https://www.google.com.jm/ads/ https://www.google.com.kh/ads/ https://www.google.com.kw/ads/ https://www.google.com.lb/ads/ https://www.google.com.ly/ads/ https://www.google.com.mm/ads/ https://www.google.com.mt/ads/ https://www.google.com.mx/ads/ https://www.google.com.my/ads/ https://www.google.com.na/ads/ https://www.google.com.ng/ads/ https://www.google.com.ni/ads/ https://www.google.com.np/ads/ https://www.google.com.om/ads/ https://www.google.com.pa/ads/ https://www.google.com.pe/ads/ https://www.google.com.pg/ads/ https://www.google.com.ph/ads/ https://www.google.com.pk/ads/ https://www.google.com.pr/ads/ https://www.google.com.py/ads/ https://www.google.com.qa/ads/ https://www.google.com.sa/ads/ https://www.google.com.sb/ads/ https://www.google.com.sg/ads/ https://www.google.com.sl/ads/ https://www.google.com.sv/ads/ https://www.google.com.tj/ads/ https://www.google.com.tr/ads/ https://www.google.com.tw/ads/ https://www.google.com.ua/ads/ https://www.google.com.uy/ads/ https://www.google.com.vc/ads/ https://www.google.com.vn/ads/ https://www.google.com/ads/ https://www.google.com/ccm/collect https://www.google.com/pagead/ https://www.google.cv/ads/ https://www.google.cz/ads/ https://www.google.de/ads/ https://www.google.dj/ads/ https://www.google.dk/ads/ https://www.google.dm/ads/ https://www.google.dz/ads/ https://www.google.ee/ads/ https://www.google.es/ads/ https://www.google.fi/ads/ https://www.google.fm/ads/ https://www.google.fr/ads/ https://www.google.ga/ads/ https://www.google.ge/ads/ https://www.google.gg/ads/ https://www.google.gh/ads/ https://www.google.gl/ads/ https://www.google.gm/ads/ https://www.google.gr/ads/ https://www.google.gy/ads/ https://www.google.hn/ads/ https://www.google.hr/ads/ https://www.google.ht/ads/ https://www.google.hu/ads/ https://www.google.ie/ads/ https://www.google.im/ads/ https://www.google.iq/ads/ https://www.google.is/ads/ https://www.google.it/ads/ https://www.google.je/ads/ https://www.google.jo/ads/ https://www.google.kg/ads/ https://www.google.ki/ads/ https://www.google.kz/ads/ https://www.google.la/ads/ https://www.google.li/ads/ https://www.google.lk/ads/ https://www.google.lt/ads/ https://www.google.lu/ads/ https://www.google.lv/ads/ https://www.google.md/ads/ https://www.google.me/ads/ https://www.google.mg/ads/ https://www.google.mk/ads/ https://www.google.ml/ads/ https://www.google.mn/ads/ https://www.google.mu/ads/ https://www.google.mv/ads/ https://www.google.mw/ads/ https://www.google.ne/ads/ https://www.google.nl/ads/ https://www.google.no/ads/ https://www.google.nr/ads/ https://www.google.nu/ads/ https://www.google.ph/ads/ https://www.google.pl/ads/ https://www.google.pn/ads/ https://www.google.ps/ads/ https://www.google.pt/ads/ https://www.google.ro/ads/ https://www.google.rs/ads/ https://www.google.ru/ads/ https://www.google.rw/ads/ https://www.google.sc/ads/ https://www.google.se/ads/ https://www.google.sh/ads/ https://www.google.si/ads/ https://www.google.sk/ads/ https://www.google.sm/ads/ https://www.google.sn/ads/ https://www.google.so/ads/ https://www.google.sr/ads/ https://www.google.st/ads/ https://www.google.td/ads/ https://www.google.tg/ads/ https://www.google.tl/ads/ https://www.google.tm/ads/ https://www.google.tn/ads/ https://www.google.to/ads/ https://www.google.tt/ads/ https://www.google.vu/ads/ https://www.google.ws/ads/ https://www.googleadservices.com https://www.googletagmanager.com ; media-src 'self' https://media.werkenbijdefensie.nl ; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js https://apply.talentbrew.io https://cdn.jsdelivr.net/npm/sockjs-client@1.4.0/dist/sockjs.min.js https://connect.facebook.net https://maps.googleapis.com/$rpc/ https://maps.googleapis.com/maps-api-v3/ https://maps.googleapis.com/maps/ https://s2.adform.net https://sc-static.net/webview-autofill.min.js https://sentry.nadapada.net https://track.adform.net https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://cdn.matomo.cloud ; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js https://apply.talentbrew.io https://cdn.jsdelivr.net/npm/sockjs-client@1.4.0/dist/sockjs.min.js https://connect.facebook.net https://embed.intractive.app https://maps.googleapis.com/$rpc/ https://maps.googleapis.com/maps-api-v3/ https://maps.googleapis.com/maps/ https://s2.adform.net https://sc-static.net/webview-autofill.min.js https://script.hotjar.com https://sentry.nadapada.net https://static.hotjar.com https://track.adform.net https://use.typekit.net/rmg6mik.css https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://cdn.matomo.cloud ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://p.typekit.net/p.css https://use.typekit.net/rmg6mik.css https://www.googletagmanager.com https://www.gstatic.com ; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://code.jquery.com/ui/ https://src.mastercard.com/srci/integration/components/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/css/intlTelInput.css; script-src 'self' 'unsafe-eval' 'nonce-fbedb4162ce73375e0c9217e1213c951' https://js.stripe.com/ https://g.stripe.com/ https://hosted.paysafe.com/request/ https://ajax.cloudflare.com https://cdnjs.cloudflare.com/ajax/libs/moment.js/ https://static.cloudflareinsights.com https://cdn.webrtc-experiment.com/DetectRTC.min.js https://code.jquery.com/ui/ https://maps.googleapis.com/maps/api/ https://www.google.com/recaptcha/api.js https://www.datadoghq-browser-agent.com/datadog-logs-us.js https://www.datadoghq-browser-agent.com/datadog-rum-us.js https://www.datadoghq-browser-agent.com/datadog-rum-v4.js http://stats.pusher.com/timeline/v2/jsonp/ https://cdn.onesignal.com/ https://onesignal.com/api/v1/sync/ https://hpoint-cr-binaries-prod.s3.amazonaws.com/cloud/sdk/wrappers/js/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/js/intlTelInputWithUtils.min.js https://app.brainfi.sh/api/searchWidgets.callback.codeblocks https://cdn.jsdelivr.net/npm/@brainfish-ai/web-tracker@latest/dist/tracker.js https://cdn.jsdelivr.net/npm/@brainfish-ai/nudge-widget@latest/dist/index.js https://src.mastercard.com/ https://secure.checkout.visa.com/checkout-widget/resources/js/ https://qwww.aexp-static.com/akamai/remotecommerce/scripts/ https://webapp.src.discover.com/websdk/ https://content.discovercard.com/ https://js.verygoodvault.com/vgs-collect/ https://js3.verygoodvault.com/vgs-collect/ https://www.datadoghq-browser-agent.com/datadog-logs-v4.js; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https://img.gotab.io/ https://static.gotab.io/ https://s3.amazonaws.com/gotabpublic/ https://s3.amazonaws.com/gotabpublic/ https://maps.gstatic.com/ https://maps.googleapis.com/maps/ https://i.vimeocdn.com/video/ https://src.mastercard.com/srci/integration/ https://content.discovercard.com/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/img/ https://*.untappd.com/ https://checkoutshopper-live.adyen.com/checkoutshopper/images/ https://checkoutshopper-live-us.adyen.com/ https://*.googleapis.com https://cdn.prod.website-files.com/ https://gotabpublic.s3.amazonaws.com/; media-src 'self' data: https://s3.amazonaws.com/gotabpublic/ https://gotabpublic.s3.amazonaws.com/; frame-src 'self' https://js.stripe.com/ https://metabase.gotab.io/ https://report.gotab.io/ https://www.google.com/ https://js.verygoodvault.com/vgs-collect/ https://content.discovercard.com/ https://src.mastercard.com/ https://srcdcf.americanexpress.com/ https://secure.checkout.visa.com/checkout-widget/ https://checkoutshopper-live.adyen.com/ https://checkoutshopper-live-us.adyen.com/ https://chat.gotab.io/ https://app.opsi.io/ https://agent.brainfi.sh/; connect-src 'self' https://*.gotab.io/ wss://stats.gotab.io/ https://s3.amazonaws.com/gotabpublic/ https://s3.amazonaws.com/gotabpublic/ https://hosted.paysafe.com/request/api/ https://api.paysafe.com/request/api/ https://api.paysafe.com/request/api/v1/ https://checkoutshopper-live.adyen.com/checkoutshopper/ https://checkoutshopper-live-us.adyen.com/ https://*.logs.datadoghq.com/ https://*.browser-intake-datadoghq.com/ *.verygoodvault.com *.verygoodproxy.com https://maps.googleapis.com/maps/api/ https://cloud.handpoint.io/ https://cloud.handpoint.com/ ws://ws-mt1.pusher.com/app/ https://vimeo.com/api/ https://vgs-collect-keeper.apps.verygood.systems/vgs https://*.mastercard.com/ https://*.aexp-static.com/ https://*.americanexpress.com/ https://*.visa.com/ https://*.staticv.me/ https://*.discover.com/ https://*.discovercard.com/ https://content.discovercard.com/ https://src.apis.discover.com/sdk/ https://www.google.com/maps/conversion/collect https://*.googleapis.com wss://analytic.brainfi.sh/analytics/ws/ https://app.brainfi.sh/api/searchWidgets.getConfigByKey; worker-src 'self' blob:; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4721f170b2076f8c4dce4d125ff9509d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=version%3Amaster.0a05f2c8b12128587836dcef72c3d02d7fc2430e.1%2Cservice%3Agotabnode%2Cenv%3Aproduction; report-to csp-report 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/wallet_google 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-MHr-1TkmVhiB-jhuDvfWCQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: https://static.cloudflareinsights.com https://js.hs-analytics.net/analytics https://js.hs-analytics.net https://js.hscollectedforms.net https://www.gstatic.com https://boards.eu.greenhouse.io https://cdnjs.cloudflare.com https://cdn-cookieyes.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://cdn.jsdelivr.net/npm/swiper@8.4.7/swiper-bundle.min.js https://cdnjs.cloudflare.com/ajax/libs/aos/2.3.4/aos.js https://cdnjs.cloudflare.com/ajax/libs/waypoints/3.0.0/jquery.waypoints.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/16451025998/ https://js-na1.hs-scripts.com/6849561.js https://js.hs-banner.com/v2/6849561/banner.js https://js.hs-scripts.com/6849561.js https://js.hsadspixel.net/fb.js https://js.hscollectedforms.net/collectedforms.js https://js.hsforms.net/forms/embed/v2.js https://js.qualified.com/qualified.js https://sc.lfeeder.com/lftracker_v1_p1e024BeMLX7GB6d.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.addtoany.com https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://tag.clearbitscripts.com/v1/pk_d197df6018af43b45412e833b5426444/tags.js https://unpkg.com/swiper@8/swiper-bundle.min.js https://ws.zoominfo.com/pixel/6146fbdc366fa2001cc5dec5 https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/enterprise.js https://x.clearbitjs.com/v2/pk_d197df6018af43b45412e833b5426444/destinations.min.js https://px.ads.linkedin.com https://app.markup.io https://app.qualified.com https://weatherwidget.io/w/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://www.googletagmanager.com https://eleos.health/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js https://tag.demand-genius.com/demand-genius.iife.js 'nonce-eleosscripts'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: https://js.hscollectedforms.net https://js.hs-analytics.net https://static.cloudflareinsights.com https://js.hs-analytics.net/analytics https://app.markup.io https://app.qualified.com https://boards.eu.greenhouse.io https://cdn-cookieyes.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://cdn.jsdelivr.net/npm/swiper@8.4.7/swiper-bundle.min.js https://cdnjs.cloudflare.com https://cdnjs.cloudflare.com/ajax/libs/aos/2.3.4/aos.js https://cdnjs.cloudflare.com/ajax/libs/waypoints/3.0.0/jquery.waypoints.min.js https://eleos.health/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/16451025998/ https://js-na1.hs-scripts.com/6849561.js https://js.hsadspixel.net https://js.hsadspixel.net/fb.js https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-banner.com/v2/6849561/banner.js https://js.hs-scripts.com/6849561.js https://js.hscollectedforms.net https://js.hscollectedforms.net/collectedforms.js https://js.hsforms.net/forms/embed/v2.js https://js.qualified.com https://js.qualified.com/qualified.js https://px.ads.linkedin.com https://sc.lfeeder.com/lftracker_v1_p1e024BeMLX7GB6d.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.addtoany.com https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://tag.clearbitscripts.com/v1/pk_d197df6018af43b45412e833b5426444/tags.js https://unpkg.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://unpkg.com/swiper@8/swiper-bundle.min.js https://weatherwidget.io/w/ https://ws.zoominfo.com/pixel/6146fbdc366fa2001cc5dec5 https://www.google.com/recaptcha/enterprise.js https://www.googletagmanager.com https://www.googletagmanager.com/gtag/js https://x.clearbitjs.com/v2/pk_d197df6018af43b45412e833b5426444/destinations.min.js 'nonce-eleosscripts'; style-src 'self' 'unsafe-inline' 'report-sample' data: https://fonts.googleapis.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; style-src-elem 'self' 'report-sample' data: https://fonts.googleapis.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js 'nonce-eleosstyles'; style-src-attr 'unsafe-inline'; img-src 'self' data: https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net https://s.w.org https://www.linkedin.com https://cdn-cookieyes.com https://forms-na1.hsforms.com https://forms.hsforms.com https://px.ads.linkedin.com https://s3.amazonaws.com https://s3-spotlightr-output.b-cdn.net https://secure.gravatar.com https://tr.lfeeder.com https://track.hubspot.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com.gt https://images.unsplash.com https://px4.ads.linkedin.com/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; connect-src 'self' data: https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net https://api.hubapi.com https://app.clearbit.com https://app.markup.io https://app.qualified.com https://cdn-cookieyes.com https://directory.cookieyes.com https://eleos.health https://forms.hscollectedforms.net https://forms.hsforms.com https://log.cookieyes.com https://o209747.ingest.us.sentry.io https://px.ads.linkedin.com https://ws.zoominfo.com https://www.google.com https://api.spotlightr.com wss://ws.qualified.com wss://ws5.qualified.com https://www.google-analytics.com/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://analytics.propensity.com https://analytics.propensity-abm.com https://cdn.jsdelivr.net https://unpkg.com https://static.hsappstatic.net https://x.clearbitjs.com; font-src 'self' data: https://fonts.gstatic.com; media-src 'self' data: https://videos.cdn.spotlightr.com https://s3-spotlightr-output.b-cdn.net https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; report-uri https://682f45bb819d722f2bc72340.endpoint.csper.io?builder=true&v=2; object-src 'none'; frame-src 'self' https://forms.hsforms.com https://www.youtube.com https://app.qualified.com https://job-boards.eu.greenhouse.io https://job-boards.cdn.greenhouse.io https://static.addtoany.com https://td.doubleclick.net https://videos.cdn.spotlightr.com https://www.google.com https://www.googletagmanager.com https://eleos.health https://weatherwidget.io/w/; worker-src blob:; manifest-src 'self'; base-uri 'self'; upgrade-insecure-requests 1 default-src 'self'; script-src 'report-sample' 'self' 'nonce-1fFmYGEkzS8gfe9tkc4kLDnxF6pLC2iXrgXZTEeZfg4=' 'strict-dynamic' https://ajax.googleapis.com/ajax/libs/jquery/3.7.0/jquery.min.js https://ak.sail-horizon.com/spm/spm.v1.min.js https://analytics.tiktok.com/i18n/pixel/events.js https://bat.bing.com/bat.js https://cdn-ukwest.onetrust.com/scripttemplates/202503.1.0/otBannerSdk.js https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js https://connect.facebook.net/en_US/fbevents.js https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d.la3-c1-cdg.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d16fk4ms6rqz1v.cloudfront.net/capture/mrandmrssmith.js https://dv4m25lzcyglc.cloudfront.net/3.0.0/gh7rnghq.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/726324624/ https://js.stripe.com/v2/ https://js.stripe.com/v3/ https://checkout.stripe.com/checkout.js https://js.stripe.com/basil/stripe.js https://mrandmrssmith.my.salesforce.com/embeddedservice/5.0/esw.min.js https://api.feefo.com/api/javascript/mr-mrs-smith https://register.feefo.com//feefo-widget-v2/js/feefo-widget.js https://api.feefo.com/feefo-widgets-data/loader/widgets/mr-mrs-smith https://register.feefo.com/feefo-widgets-app/feefo_widgets_loader.js https://register.feefo.com/feefo-widget-v2/js/loader/pop-up-reviews.bundle.js https://se.monetate.net/js/2/a-58d4210d/p/mrandmrssmith.com/entry.js https://service.force.com/embeddedservice/5.0/client/liveagent.esw.min.js https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://static.mention-me.com/dist/static/js/async/bootloader-init.v2.b874a4b9.js https://t.contentsquare.net/uxa/cea2376851edf.js https://tag.mention-me.com/api/v2/refereefind/mm2133a6f1 https://tag.rmp.rakuten.com/111651.ct.js https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js https://www.googletagmanager.com/gtag/destination https://d2wy8f7a9ursnm.cloudfront.net/bugsnag-2.min.js https://d2wy8f7a9ursnm.cloudfront.net/v4/bugsnag.min.js https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js https://ajax.googleapis.com/ajax/libs/jqueryui/1.8.18/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://maps.googleapis.com/maps/api/js https://assets.pinterest.com/js/pinit.js https://cdnjs.cloudflare.com/ajax/libs/svgxuse/1.2.6/svgxuse.min.js https://cdn.firebase.com/js/client/1.1.2/firebase.js https://code.jquery.com/jquery-migrate-1.2.1.js https://js.braintreegateway.com/web/3.0.1/js/client.min.js https://js.braintreegateway.com/web/3.0.1/js/apple-pay.min.js https://api.skyscanner.net/api.ashx https://translate.google.com/translate_a/element.js https://static-eu.payments-amazon.com/OffAmazonPayments/uk/lpa/js/Widgets.js https://www.googleadservices.com/pagead/conversion.js https://0.r.msn.com/scripts/microsoft_adcenterconversion.js http://e.monetate.net/js/3/a-58d4210d/d/mms-monetate.mmsmith.info/t1640009934/2cbacf4e5b15a1ac/custom.js http://f.monetate.net/trk/4/s/a-58d4210d/d/mms-monetate.mmsmith.info/ https://mrandmrssmith--chatsand.sandbox.my.salesforce.com/embeddedservice/5.0/esw.min.js https://tag-demo.mention-me.com/api/v2/referreroffer/mm2133a6f1 https://static-demo.mention-me.com/dist/static/js/async/bootloader-init.v2.b874a4b9.js https://se.monetate.net/js/3/a-58d4210d/d/mms-monetate.mmsmith.info/t1640009934/2cbacf4e5b15a1ac/custom.js https://service.force.com/embeddedservice/5.0/utils/common.min.js https://service.force.com/embeddedservice/5.0/client/invite.esw.min.js https://d.la3-c1-cdg.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://service.force.com/embeddedservice/5.0/utils/inert.min.js https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://register.feefo.com/badge-ui/feefo_adaptive_badges.js https://tag-demo.mention-me.com/api/v2/refereefind/mm2133a6f1 https://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-rtl-text/v0.2.0/mapbox-gl-rtl-text.js http://register.feefo.com//feefo-widget-v2/js/feefo-widget.js https://register.feefo.com//feefo-widget-v2/js/feefo-widget.js http://se.monetate.net/js/2/a-58d4210d/d/mms-monetate.mmsmith.info/entry.js https://se.monetate.net/js/2/a-58d4210d/d/mms-monetate.mmsmith.info/entry.js http://c.webtrends-optimize.com/acs/accounts/f0fa8f35-66f6-474c-87f7-6947403a3fd3/js/wt.js https://c.webtrends-optimize.com/acs/accounts/f0fa8f35-66f6-474c-87f7-6947403a3fd3/js/wt.js; style-src * 'unsafe-inline' 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.onetrust.com https://*.feefo.com https://*.analytics.google.com https://*.google-analytics.com https://*.mapbox.com https://*.contentsquare.net https://maps.googleapis.com https://api.sail-personalize.com https://google.com https://i.salecycle.com https://notify.bugsnag.com https://sessions.bugsnag.com https://www.google.co.uk https://www.google.com https://tag-demo.mention-me.com http://ots.webtrends-optimize.com https://ots.webtrends-optimize.com https://analytics.tiktok.com https://*.mrandmrssmith.com wss://ws.salecycle.com; font-src 'self' data: https://www.mrandmrssmith.com https://use.typekit.net https://fonts.gstatic.com https://fonts.feefo.com https://mrandmrssmith.com; frame-src 'self' https://js.stripe.com https://s.salecycle.com https://service.force.com https://widget.trustpilot.com https://www.googletagmanager.com https://demo.mention-me.com https://accounts.google.com https://form.typeform.com https://tags.rd.linksynergy.com; img-src 'self' data: https://www.mrandmrssmith.com https://*.mrandmrssmith.com https://api.feefo.com https://api.mapbox.com https://cdn-ukwest.onetrust.com https://public.feefo.com https://s3-eu-west-1.amazonaws.com https://www.google.co.uk https://www.googletagmanager.com https://mrandmrssmith-res.cloudinary.com https://f.monetate.net https://bat.bing.com https://c.contentsquare.net https://www.facebook.com https://www.google.com https://consent.linksynergy.com; manifest-src 'self'; media-src 'self'; worker-src 'self' blob: 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octane.co https://*.octane.co https://octanelending.com https://*.octanelending.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.google.com *.vwo.com *.visualwebsiteoptimizer.com *.intercom.io *.intercomcdn.com *.onetrust.com https://cdn.cookielaw.org; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octane.co https://*.octane.co https://octanelending.com https://*.octanelending.com fonts.googleapis.com www.gstatic.com app.vwo.com www.googletagmanager.com translate.googleapis.com; frame-ancestors 'self' https://polarisxchange.com https://slingshot.polarisxchange.com https://indianmotorcycle.polarisxchange.com https://www.rvs.com https://rvs.com https://buy.cycletrader.com https://www.atvrider.com https://www.cyclevolta.com https://www.cycleworld.com https://www.dirtrider.com https://www.motorcyclecruiser.com https://www.motorcyclistonline.com https://www.utvdriver.com https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octanelending.com https://*.octanelending.com https://*.dev-octanelisting.com https://*.octanelisting.com; worker-src 'self' blob:; upgrade-insecure-requests 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.uk/api/csp-report; report-to csp-endpoint 1 connect-src 'unsafe-inline' https: https://chat.tendertech.ru wss://chat.tendertech.ru:7272 https://blacklist.tendertech.ru https://storage.tendertech.ru 1 default-src https://*.rsync.net:443 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://cdn-assets-prod.s3.amazonaws.com https://*.ozmoapp.com https://*.modeaondemand.com https://*.contentsquare.net https://edge.api.flagsmith.com https://*.kaptcha.com https://*.ctfassets.net https://*.freedommobile.ca https://*.appdynamics.com https://*.contentful.com https://*.eum-appdynamics.com https://*.googleapis.com https://tags.tiqcdn.com https://*.lpsnmedia.net https://*.tealiumiq.com https://*.qualtrics.com https://*.gstatic.com https://*.cardinalcommerce.com https://*.googletagmanager.com https://*.googleadservices.com https://*.google.com https://*.google.ca https://*.facebook.net https://*.facebook.com https://*.twitter.com https://*.t.co https://*.demdex.net https://*.doubleclick.net https://*.everesttech.net https://*.adswizz.com https://*.exelator.com https://*.tapad.com https://*.spatialbuzz.com https://*.spatialbuzz.net https://*.niceincontact.com https://d31hajf7vfnsd2.cloudfront.net; frame-src 'self' https://quebecor.satmetrix.com https://www.googletagmanager.com https://cxone.niceincontact.com https://web-modules-de-ca1.niceincontact.com https://asset.gomoxie.solutions https://dnyepvvjamjdg.cloudfront.net https://www.youtube.com https://*.demdex.net https://*.doubleclick.net https://*.facebook.com https://*.google.com https://*.freedommobile.ca https://*.lpsnmedia.net https://*.kaptcha.com https://*.spatialbuzz.com https://*.spatialbuzz.net; worker-src 'self' blob:; frame-ancestors 'self' https://*.freedommobile.ca; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com data: https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com webpay3g.transbank.cl webpay3gint.transbank.cl 'self' *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com cdn.dnky.co amc.demdex.net www.google.com youtube.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com/ www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com www.google.co.in cannonhome.cl maps.gstatic.com maps.googleapis.com accounts.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com magefan.com cm.magefan.com *.disqus.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.afip.gob.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com unpkg.com wchat.freshchat.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com/ https://www.gstatic.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com wchat.freshchat.com www.gstatic.com cdn.dnky.co *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com assets.braintreegateway.com *.googletagmanager.com *.cookielaw.org 'self' 'unsafe-inline'; object-src *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com 'self' 'unsafe-inline'; media-src *.adobe.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com stats.g.doubleclick.net videelect.icu regtech.sbs api.comapi.com bam.nr-data.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cookielaw.org 'self' 'unsafe-inline'; child-src *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.retailrocket.net *.embluemail.com stackpath.bootstrapcdn.com snapwidget.com widget.freshworks.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; script-src 'unsafe-eval' 'unsafe-inline' api.store.johnnywas.com applepay.cdn-apple.com *.liadm.com bat.bing.com blob: c.paypal.com cdn.cookielaw.org *.cquotient.com cdn.shopify.com cdn.taboola.com connect.bolt.com connect.facebook.net d.impactradius-event.com dev.visualwebsiteoptimizer.com fe.sitedataprocessing.com *.global-e.com googleads.g.doubleclick.net johnnywas.sspinc.io js.braintreegateway.com maps.googleapis.com *.listrakbi.com *.techlab-cdn.com pay.google.com s.go-mpulse.net s.pinimg.com sandbox-assets.secure.checkout.visa.com scripts.clarity.ms *.payments-amazon.com *.afterpay.com track.securedvisit.com trc.taboola.com widgets.store.johnnywas.com widgets.storejohnnywas.com www.clarity.ms www.googletagmanager.com www.paypal.com www.paypalobjects.com wasm-eval 'self' ajax.googleapis.com cdnjs.cloudflare.com h.online-metrix.net js.adsrvr.org *.pinterest.com a.usbrowserspeed.com *.listrak.com pagead2.googlesyndication.com static.cloudflareinsights.com static.myshlf.us p11.techlab-cdn.com; report-uri /csp-report 1 default-src 'self'; style-src 'nonce-7bac83b3-a1c8-492d-b38c-2d6dbc57e18b' https://accounts.google.com 'unsafe-hashes' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' https://*.dealoo.ch; script-src 'nonce-7bac83b3-a1c8-492d-b38c-2d6dbc57e18b' https://challenges.cloudflare.com https://storage.googleapis.com https://*.dealoo.ch; img-src 'self' https://www.apfelkiste.ch https://cms-data.apfelkiste.ch data: blob: https://i.ytimg.com https://i.vimeocdn.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.de https://www.google.ch https://www.google.fr https://*.dealoo.ch; worker-src 'self' blob:; connect-src 'self' https://devnull.apfelkiste.ch https://www.google.com https://accounts.google.com https://apis.google.com https://api.dealoo.ch https://rumdash.io https://api.zakeke.com https://*.dealoo.ch; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://challenges.cloudflare.com https://accounts.google.com https://www.google.com https://portal.zakeke.com/; object-src 'self'; font-src 'self'; media-src 'self' https://cms-data.apfelkiste.ch; child-src 'self' blob:; frame-ancestors 'self' https://cms.apfelkiste.ch; report-uri https://devnull.apfelkiste.ch/api/8/security/?sentry_key=291d0d843488451caadd66b48b4a6ae4 1 object-src 'self' *.cined.com; report-uri /_/csp-report/ 1 connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.doubleclick.net www.google.co.uk https://analytics.google.com https://vc.hotjar.io https://in.hotjar.com https://content.hotjar.io https://csmetrics.hotjar.com metrics.hotjar.io wss://ws.hotjar.com surveystats.hotjar.io https://feeds.trac.jobs sentry.issuu.com stats.g.doubleclick.net translate.googleapis.com *.onetrust.com cdn-ukwest.onetrust.com adservice.google.com https://ask.hotjar.io www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.com.ai www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.ms www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.vg www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample' *.gosh.nhs.uk www.gosh.nhs.uk feeds.trac.jobs *.googletagmanager.com www.cqc.org.uk e.issuu.com 'nonce-bskmfQDGvTl4rTBWyinnbg=='; default-src 'self' *.gosh.nhs.uk; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample' https://www.googletagmanager.com https://www.google.co.uk https://www.google.com https://feeds.trac.jobs feeds.trac.jobs 'nonce-bskmfQDGvTl4rTBWyinnbg=='; style-src 'self' 'report-sample' 'unsafe-inline' services.postcodeanywhere.co.uk fonts.googleapis.com feeds.trac.jobs www.cqc.org.uk www.gstatic.com; base-uri 'self'; font-src 'self' https://fonts.gstatic.com script.hotjar.com https://fonts.googleapis.com data:; frame-src 'self' https://www.google.com https://www.youtube.com https://vars.hotjar.com www.googletagmanager.com e.issuu.com *.recaptcha.net td.doubleclick.net; object-src 'none'; img-src 'self' data: *.gosh.nhs.uk *.google-analytics.com *.googletagmanager.com i.ytimg.com *.cqc.org.uk *.gstatic.com *.google.com stats.g.doubleclick.net feeds.trac.jobs https://static.trac.jobs static.trac.jobs healthjobsuk.com services.postcodeanywhere.co.uk dx4nr741tfc02.cloudfront.net www.healthjobsuk.com 'sha384-YephmBv2489Q13yLaARSHqhDtSlHeIs5DEiq8I1fyh4aQcG+nRoz5Y6eWndd5cVz' *.onetrust.com cdn-ukwest.onetrust.com script.hotjar.com survey-images.hotjar.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.com.ai www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.ms www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.vg www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat; media-src 'self' gosh.shorthandstories.com cdn.plyr.io data: media.gosh.nhs.uk ssl.gstatic.com *.s3.amazonaws.com; manifest-src 'self' *.gosh.nhs.uk; report-uri https://o516378.ingest.sentry.io/api/5622733/security/?sentry_key=c5f8a650e74b48a889ccadeaa5014261&sentry_environment=production 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.authorize.net *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.authorize.net *.cloudflare.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com *.maxmind.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.authorize.net *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.mmapiws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem cdn.consentmanager.net cdn.honey.io *.hagel-shop.de tracking.paqato.com static-tracking.klaviyo.com m2stage-blog.hagel-shop.de www.gstatic.com fonts.googleapis.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: cdn.elev.io media.flixfacts.com static.klaviyo.com tracking.paqato.com account.affilitizer.com at.alicdn.com cdn-uicons.flaticon.com cdn.faceworks.nl cdn.honey.io media.flixcar.com moz-extension: r2cdn.perplexity.ai http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io d3dc1lgancj6l0.cloudfront.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com http://*.facebook.com https://*.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.hagel-shop.de 'self' www.hagel-shop.de 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://cdn.consentmanager.net https://delivery.consentmanager.net www.awin1.com cdn.consentmanager.net *.criteo.com *.criteo.net *.dixa.io *.doubleclick.net *.durchsichtig.xyz *.hagel-shop.de *.hotjar.com www.facebook.com media.flixcar.com *.klarinsights.net www.paypalobjects.com www.sovendus-benefits.com www.sovendus-campaign.com www.sovendus-connect.com www.sovendus-network.com bat.bing.com www.instagram.com return.4sellers.de 10.10.10.1:8090 bcsgsrv.com bispadisch.de caclk.com cdn.elev.io cmodul.solutenetwork.com div.show fwwh.werkhaus-bielefeld.de:8091 gateway.zscaler.net gateway.zscloud.net hipodi.com kerastase-quiz.vercel.app oponas.com ptclk.com www.explorr.net www.pricejoe.com https://www.googletagmanager.com/ connect.facebook.net graph.facebook.com business.facebook.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com/ http://*.facebook.com https://*.facebook.com js.mollie.com test.saferpay.com www.saferpay.com saferpay.com gateways.zscloud.net ifw.noel.gv.at 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://cdn.consentmanager.net https://delivery.consentmanager.net validate.fishpig.co.uk sync.1rx.io ad.360yield.com eb2.3lift.com *.adnxs.com *.agkn.com www.awin1.com *.bing.com *.bing.net *.bidswitch.net *.casalemedia.com *.cloudfront.net *.consentmanager.net *.criteo.com public-prod-dspcookiematching.dmxleo.com *.doubleclick.net e1.emxdgt.com www.facebook.com media.flixcar.com *.flix360.com *.google.com *.google.de *.googletagmanager.com fonts.gstatic.com *.hagel-shop.de id5-sync.com matching.ivitrack.com contextual.media.net exchange.mediavine.com visitor.omnitagjs.com sync.outbrain.com jadserve.postrelease.com simage2.pubmatic.com *.roeye.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com criteo-sync.teads.tv *.tiktok.com criteo-partners.tremorhub.com a.twiago.com *.taboola.com sync.targeting.unrulymedia.com t.ssl.ak.dynamic.tiles.virtualearth.net www.wepowerconnections.com ad.yieldlab.net sync-criteo.ads.yieldmo.com *.zenaps.com c.clarity.ms assets.paqato.com www.google.hu www.google.es csm.nl3.eu.criteo.net www.google.nl *.hagel-shop.at bat.bing.com blob: client-side-metrics.fr3.eu.criteo.net client-side-metrics.nl3.eu.criteo.net d3k81ch9hvuctc.cloudfront.net google.com hagel-de.ddev.site media.flixfacts.com modular.flix360.io static-eu.payments-amazon.com t0.ssl.ak.dynamic.tiles.virtualearth.net t1.ssl.ak.dynamic.tiles.virtualearth.net www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.co.il www.google.co.in www.google.co.kr www.google.co.th www.google.co.uk www.google.co.uz www.google.co.za www.google.com.au www.google.com.br www.google.com.eg www.google.com.hk www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.fi www.google.fr www.google.gr www.google.hr www.google.ie www.google.it www.google.jo www.google.li www.google.lu www.google.lv www.google.md www.google.mk www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn www.zenaps.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ connect.facebook.net graph.facebook.com business.facebook.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.linkedin.com https://*.linkedin.com http://*.facebook.com https://*.facebook.com http://www.google.com/ http://www.google.de/ https://www.google.de/ https://www.googletagmanager.com http://www.googletagmanager.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://widgets.trustedshops.com/ https://www.mollie.com test.saferpay.com www.saferpay.com saferpay.com https://widgets.trustedshops.com https://integrations.etrusted.com www.hagel-shop.at www.googleads.g.doubleckick.net www.google.com.ro data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jsd-widget.atlassian.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.hagel-shop.de *.hagel-shop.at *.ablyft.com www.awin1.com *.bing.com *.clarity.ms *.consentmanager.net *.criteo.com messenger.dixa.io www.dwin1.com cdn.elev.io connect.facebook.net prod.flixgvid.flix360.io media.flixcar.com media.flixfacts.com *.google-analytics.com *.googleoptimize.com *.hotjar.com lantern.roeyecdn.com lantern.roeye.com the.sciencebehindecommerce.com *.sovendus.com www.sovendus-benefits.com www.sovendus-campaign.com www.sovendus-connect.com www.sovendus-network.com analytics.tiktok.com *.virtualearth.net www.zeitung-direkt.de tracking.paqato.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ www.facebook.com graph.facebook.com business.facebook.com https://connect.facebook.net/ https://snap.licdn.com/li.lms-analytics/insight.min.js http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io unsafe-inline userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com http://www.google.com/recaptcha/ https://widgets.trustedshops.com/ js.mollie.com test.saferpay.com www.saferpay.com saferpay.com https://widgets.trustedshops.com https://integrations.etrusted.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.bing.com media.flixcar.com *.googletagmanager.com css/light.theme.css static-tracking.klaviyo.com tracking.paqato.com www.gstatic.com https://static.klaviyo.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net data: 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.hagel-shop.de data: mcprod.hagel-shop.de media.flixfacts.com youtube.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de jsd-widget.atlassian.com api-private.atlassian.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.ablyft.com magento-recs-sdk.adobe.net commerce.adobedtm.com *.bing.com *.bing.net *.clarity.ms *.consentmanager.net *.dixa.io *.criteo.com *.doubleclick.net *.durchsichtig.xyz *.elev.io media.flixcar.com maps.googleapis.com *.google-analytics.com *.google.de *.hagel-shop.de *.hotjar.com *.hotjar.io *.klarinsights.net the.sciencebehindecommerce.com *.sovendus.com analytics.tiktok.com unpkg.com/@adobe/ www.wepowerconnections.com tracking.paqato.com api-js.datadome.co api.killadsapi.com api.vid-adblocker.com cmodul.solutenetwork.com data: overbridgenet.com rt.flix360.com static-eu.payments-amazon.com update.adblock360.org www.facebook.com www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.co.il www.google.co.in www.google.co.kr www.google.co.th www.google.co.uk www.google.com.eg www.google.com.hk www.google.com.mx www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.vn www.google.dk www.google.es www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.it www.google.lt www.google.lu www.google.mk www.google.nl www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ connect.facebook.net graph.facebook.com business.facebook.com http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com http://salesviewer.org/ userlike-cdn-widgets.s3-eu-west-1.amazonaws.com autocomplete2.postdirekt.de test.saferpay.com www.saferpay.com saferpay.com *.trustedshops.com *.etrusted.com analytics-ipv6.tiktokw.us www.google.cz 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://app.contentful.com; worker-src blob:; default-src 'self' gap: ws: 'unsafe-inline' 'unsafe-eval' data: api.country.is vercel.live vercel.app *.vercel.live *.vercel.app safevisit.online contentful.com *.contentful.com *.googleapis.com *.youtube.com *.paypal.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.com.ph *.google.ca *.google.ie *.google.co.in *.facebook.com *.amazonaws.com *.cloudfront.net *.googletagservices.com pay.google.com *.s3.amazonaws.com google.com *.sitkagear.com js.narvar.com cdn.searchspring.net js.klarna.com manifest.webmanifest cdn.tailwindcss.com cdn.cookielaw.org api.yotpo.com cdn-widgetsrepository.yotpo.com *.yotpo.com *.searchspring.io *.bigcommerce.com *.locally.com *.ctfassets.net *.onetrust.com *.criteo.com *.avmws.com *.safevisit.online *.gtm-msr.appspot *.dynamic.criteo.com *.facebook.net *.klaviyo.com *.zdassets.com *.vercel-insights.com *.csper.io klarnaservices.com *.klarnaservices.com *.gstatic.com *.bing.com *.typekit.net *.doubleclick.ne *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.aralego.com criteo-sync.teads.tv *.3lift.com *.yahoo.net *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.outbrain.com *.pubmatic.com *.smaato.net *.clmbtech.com *.yieldmo.com *.klarnacdn.net vercel.com assets.vercel.com googleads.g.doubleclick.net *.dotomi.com he.lijit.com envoydev.co track.securedvisit.com bh.contextweb.com stats.g.doubleclick.net public-prod-dspcookiematching.dmxleo.com match.adsrvr.org *.zendesk.com *.zopim.com widget-mediator.zopim.com trends.revcontent.com match.sharethrough.com tapestry.tapad.com criteo-partners.tremorhub.com ad.tpmn.co.kr e1.emxdgt.com cm.g.doubleclick.net partner.mediawallahscript.com visitor.omnitagjs.com i.liadm.com exchange.mediavine.com 1f2e7.v.fwmrm.net tags.bluekai.com dpm.demdex.net ws-us3.pusher.co eu.klarnaevt.com sockjs-us3.pusher.com ws-us3.pusher.com aa.agkn.com jadserve.postrelease.com ad.tpmn.io match.prod.bidr.io i6.liadm.com sync.crwdcntrl.net *.sv.rkdms.com *.simpli.fi *.dlx.addthis.com ws.rqtrk.eu *.youtube-nocookie.com *.klarnaevt.com *.cloudflare.com *.datadome.co *.hotjar.com *.hotjar.io *.narvar.com aorta.clickagy.com *.abtasty.com *.narvar.qa suggest-cache.searchspring.net *.captcha-delivery.com *.usablenet.com *.usablenet.dev *.gorewear.com *.dev.stagesitkagear.com *.stagesitkagear.com www.sandbox.paypal.com cdn.sand.us.zip.co localhost:* 1 font-src https://*.gstatic.com fonts.gstatic.com https://cdn.segment.com https://api.segment.io https://*.hokodo.co www.googleservices.com *.google.com *.gstatic.com https://*.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com www.xtento.com https://*.hokodo.co https://photos.pixlee.co https://photos.pixlee.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://*.gstatic.com www.xtento.com cdn.xtento.com https://site-assets.afterpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com https://www.google.co.uk https://www.gstatic.com https://d1fd8aj8bhyfe9.cloudfront.net https://cdn-ukwest.onetrust.com *.klevu.com *.ksearchnet.com flagpedia.net https://register.feefo.com https://api.feefo.com https://s3-eu-west-1.amazonaws.com pixlee.com *.pixlee.com *.pixlee.co https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com www.xtento.com cdn.xtento.com https://js.afterpay.com https://cdn.segment.com https://*.hokodo.co https://*.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://party11141.pcapredict.com https://assets.pxlecdn.com https://region1.analytics.google.com https://register.feefo.com https://js-agent.newrelic.com https://bam.nr-data.net https://services.postcodeanywhere.co.uk https://d3dh5c7rwzliwm.cloudfront.net https://d32106rlhdcogo.cloudfront.net https://dgf0rw7orw6vf.cloudfront.net https://cdn-ukwest.onetrust.com *.klevu.com *.ksearchnet.com *.gstatic.com maps.googleapis.com https://*.feefo.com/ https://euwa.puzzel.com pixlee.com *.pixlee.com *.pixlee.co https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ fonts.googleapis.com https://*.klarnacdn.net https://static.klaviyo.com https://register.feefo.com https://services.postcodeanywhere.co.uk *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com https://cdn.segment.com https://api.segment.io https://*.hokodo.co https://*.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://party11141.pcapredict.com https://assets.pxlecdn.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://register.feefo.com https://inbound-analytics.pixlee.com https://pce.afd.co.uk https://bam.nr-data.net https://cdn-ukwest.onetrust.com https://geolocation.onetrust.com https://region1.google-analytics.com *.klevu.com *.ksearchnet.com www.gstatic.com maps.googleapis.com https://api.feefo.com https://collect.feefo.com https://api.puzzel.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.brandhub.codered.net https://*.powertrain.codered.net; media-src 'self' blob:; script-src 'self' https://mb.etrackingserver.de https://*.scene7.com https://app.usercentrics.eu 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline' https://*.scene7.com; img-src 'self' https://js.api.here.com https://*.scene7.com https://*.usercentrics.eu https://dev.day.com blob: data:; connect-src 'self' https://*.usercentrics.eu https://mb.etrackingserver.de https://*.scene7.com https://*.mercedes-benz-trucks.net https://*.hereapi.com https://*.api.here.com blob:; font-src 'self' https://js.api.here.com data:; 1 connect-src *;frame-src *;img-src https: data: blob: about: safari-extension: safari-resource: chrome-extension: http://*.rackcdn.com http://*.tumblr.com http://huaban.com;worker-src https: blob:;script-src https: 'unsafe-eval' 'unsafe-inline'; report-uri /log/csp 1 frame-ancestors 'self'; report-uri https://www.delicious.com.au/csp-reports 1 default-src * https: data: blob: 'unsafe-inline' 'unsafe-hashes'; 1 report-uri https://csp.withgoogle.com/csp/youtube_other/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-tR8LuglCnLgo_sDDoDJRpA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.gstatic.com *.cdn.userway.org; font-src 'self' fonts.gstatic.com; img-src 'self' cdn.userway.org data: sppagebuilder.com maps.googleapis.com; connect-src 'self' cdn77.api.userway.org api.userway.org maps.googleapis.com; script-src 'self' cdn.userway.org ajax.googleapis.com maxcdn.bootstrapcdn.com; frame-src 'self'; script-src-elem 'self' maps.googleapis.com cdn.userway.org 'sha256-N/4d8ewez3Wzx5WmnOwGLZfRBddPWJMlVZKikRqRiQo=' 'sha256-fjHH/hDGedQwWCxjrFtTeJTwaWHkUA4R2FtSczrt+nE=' 'sha256-QMfduvzot+N77aMq4Ad7jDgq8k/X3CPHmCK3Vhh7Abw=' 'sha256-3N2OR1PZdIZ1vFuw3e0TfFqZy9zUOfzV8wTs2Amy7K4='; media-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com assets.emailmeform.com files.emailmeform.com images.dmca.com dev.mastershoe.co.uk www.mastershoe.co.uk *.sooqr.com cdn-cookieyes.com www.google.pl meetanshi.com services.postcodeanywhere.co.uk itfa.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com player.vimeo.com assets.emailmeform.com www.emailmeform.com images.dmca.com static.sooqr.com giles11128.pcapredict.com analytics.webgains.io rum-static.pingdom.net cdn-cookieyes.com dynamic.sooqr.com services.postcodeanywhere.co.uk ajax.cloudflare.com static.cloudflareinsights.com cdn.mouseflow.com dev.mastershoe.co.uk www.mastershoe.co.uk https://www.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com static.sooqr.com assets.emailmeform.com app.emailmeform.com services.postcodeanywhere.co.uk dev.mastershoe.co.uk www.mastershoe.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com cognito-identity.eu-central-1.amazonaws.com firehose.eu-central-1.amazonaws.com cdn-cookieyes.com log.cookieyes.com rum-collector-2.pingdom.net stats.g.doubleclick.net directory.cookieyes.com region1.google-analytics.com services.postcodeanywhere.co.uk dev.mastershoe.co.uk www.mastershoe.co.uk https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=jKQgaQ1EigNHs0MbVRmcbo8tIEK_UENQnHRTUM8EJmA-1765934631.2017207-1.0.1.1-yUIRAdNn_gEe0192XnyPpgL7PJUt7xW41PHAlvdI94wEZXJMEv4Xy00.afMbZSPttHE2LWgXrpsPk_3ZBSWiwSy_YUufv2n3jQ5Yj8zGpyWWiXm7_OwfmkHDfAdu0MKd7TEBRJl7rzKhGgo63983ePsuQ91SqnKJG.88ZUMYhu2NrevqxhiUYfjHEEPI_q8DrpyFiCtjrmT4UEJduGbtFA; report-to cf-ahybrucejvzmswmn 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; script-src 'nonce-5a8ee121463e4397ae179c7134e455e3' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; style-src 'self' 'nonce-5a8ee121463e4397ae179c7134e455e3' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=132-3315174-6480700:rid=C7A440AC5D2F4107A242:sn=www.newworld.com 1 default-src 'self' 'unsafe-inline' www.googletagmanager.com www.google-analytics.com ipv4check.ec-elements.com ipv6check.ec-elements.com data: 'unsafe-eval'; report-uri /csp-violation-report-endpoint/ 1 script-src 'nonce-XPdTYaF4OaW6AnXsDDkS0A==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=08e95d3c-f297-457c-80e9-c5620affafaa; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report; 1 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wargaming.net *.wgprod.net *.tvsquared.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com s.yimg.jp https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googleoptimize.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms s.yimg.jp cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com s.yimg.jp https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.facebook.com https://www.googleoptimize.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.com.ua https://google.pl https://*.doubleclick.net https://*.googleapis.com https://pagead2.googlesyndication.com https://*.clarity.ms s.yimg.jp https://collect.worldoftanks.asia https://content-wg.gcdn.co https://api.worldoftanks.asia https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 1 default-src 'none';script-src 'nonce-4c9ef5c7-c951-4210-90ef-268d3b657eb3' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.mariacasino.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.mariacasino.com/eum-collector/report/csp-report; 1 script-src 'self' 'nonce-mJNYks7GioZZzAWLCmoaIkSDPiqDdNG8tN+Hy7Upa4Q=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cloud.taggbox.com stackpath.bootstrapcdn.com cdn.userway.org cloud.tagshop.ai cdn.tagshop.ai 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com accounts.accessibe.com mossberg.app.box.com *.taggbox.com platform.twitter.com td.doubleclick.net cdn.userway.org *.authorize.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io camo.githubusercontent.com *.googleapis.com *.gstatic.com https://firebasestorage.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com web1.acsbapp.com maps.gstatic.com *.ggpht.com resources.mossberg.com cdn.taggbox.com cdn.userway.org api.delivrabl.net aorta.clickagy.com cloud.tagshop.ai idsync.rlcdn.com c.clarity.ms c.bing.com aa.agkn.com d.agkn.com us-u.openx.net cm.g.doubleclick.net *.liadm.com track.hubspot.com forms.hsforms.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.youtube.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.avada.io *.shopify.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com acsbapp.com *.acsbapp.com cdn.userway.org cdn.userconsent.org maps.googleapis.com api.pinterest.com *.taggbox.com web.taggshop.io kit.fontawesome.com widget.tagshop.ai cloud.tagshop.ai platform.twitter.com tags.clickagy.com www.clarity.ms static.cloudflareinsights.com js.hs-scripts.com js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net *.authorize.net *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com web.taggshop.io cloud.taggbox.com cdn.userway.org widget.tagshop.ai cloud.tagshop.ai cdn.tagshop.ai *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn.tagshop.ai 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net cdn.acsbapp.com api.userway.org cdn.userway.org *.userway.org maps.googleapis.com graph.facebook.com api.taggbox.com resources.mossberg.com *.doubleclick.net api.ipdata.co web.taggshop.io widget.tagshop.ai aorta.clickagy.com hemsync.clickagy.com i.clarity.ms forms.hubspot.com *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.mossberg.com; report-to report-endpoint; 1 font-src 'self' https://cdnjs.cloudflare.com https://fonts.gstatic.com; script-src 'self' 'report-sample' 'unsafe-hashes' 'unsafe-inline' https://static.addtoany.com/menu/page.js https://www.googletagmanager.com/gtag/js https://stackpath.bootstrapcdn.com/bootstrap/4.1.1/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.3/umd/popper.min.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com https://www.gstatic.com/recaptcha/releases/jdMmXeCQEkPbnFDy9T04NbgJ/recaptcha__es_419.js https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://static.addtoany.com https://www.google.com https://mdbootstrap.com https://stackpath.bootstrapcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com mdbootstrap.com stackpath.bootstrapcdn.com; script-src-elem 'self' 'report-sample' 'unsafe-hashes' 'unsafe-inline' https://static.addtoany.com/menu/page.js https://www.googletagmanager.com/gtag/js https://stackpath.bootstrapcdn.com/bootstrap/4.1.1/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.3/umd/popper.min.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com https://www.gstatic.com/recaptcha/releases/jdMmXeCQEkPbnFDy9T04NbgJ/recaptcha__es_419.js https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://static.addtoany.com https://www.google.com https://mdbootstrap.com https://stackpath.bootstrapcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com mdbootstrap.com stackpath.bootstrapcdn.com; style-src 'self' 'report-sample' 'unsafe-hashes' https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; style-src-attr 'self' 'report-sample' 'unsafe-hashes' 'unsafe-inline'; style-src-elem 'self' 'report-sample' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; base-uri 'self'; report-uri https://parlamento.gub.uy/log-report-uri/report-only 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.2mdn.net *.3lift.com *.a47b.com *.acuityplatform.com *.ad-score.com *.adform.net *.adnxs.com *.ads.smartadserver.com *.adsafeprotected.com *.adsappier.com *.adsrvr.org *.adtrafficquality.google *.amazon-adsystem.com *.amazonaws.com *.ampproject.org *.azureedge.net *.b2c.com *.basis.net *.betrad.com *.bidr.io *.c3tag.com *.cdn.fastclick.net *.celtra.com *.cloudfront.net *.cog-tr3.com *.cog-tr4.com *.demdex.net *.dotomi.com *.doubleclick.net *.doubleverify.com *.evidon.com *.exelator.com *.eyeota.net *.flashtalking.com *.flx10.com *.fouanalytics.com *.ftstatic.com *.g.doubleclick.net *.getrockerbox.com *.googlesyndication.com *.googletagmanager.com *.googletagservices.com *.gumgum.com *.id5-sync.com *.innovid.com *.jivox.com *.js7k.com *.jwplayer.com *.l-dsp.inmobicdn.net *.microsoft.com *.mxptint.net *.ns1p.net *.onedsp.inmobi.com *.p.jwpcdn.com *.peer-39.com *.polarcdn.com *.poupdate.pulsepoint.com *.puzzmo.com *.quantcount.com *.quantserve.com *.rendering.sharethrough.com *.rfihub.com *.rqtrk.eu *.rubiconproject.com *.rudderlabs.com *.scorecardresearch.com *.script.ac *.smadex.com *.srv.stackadapt.com *.trustarc.com *.truste.com *.turn.com *.update.adsrvr.org *.update.indexww.com *.update.rubiconproject.com *.update.wo.gumgum.com *.yabidos.com *.ybp.yahoo.com *.yimg.com adrta.com cdn-cookieyes.com htlbid.com openfpcdn.io *.insiad.com *.browsiprod.com *.enzymic.co *.intentiq.com *.ntv.io *.padsquad.com lottingem.com; connect-src 'self' *.3lift.com *.ad-score.com *.adform.net *.adnxs.com *.ads.smartadserver.com *.adsrvr.org *.adtrafficquality.google *.amazon-adsystem.com *.amazonaws.com *.appiersig.com *.b2c.com *.c.appier.net *.c3tag.com *.casalemedia.com *.cheilmedia.com *.cloudfront.net *.cog-tr101.com *.contextweb.com *.cookieyes.com *.dotomi.com *.doubleclick.net *.doubleverify.com *.eu-1-id5-sync.com *.eu-3-id5-sync.com *.eu-4-id5-sync.com *.flashtalking.com *.fouanalytics.com *.ftstatic.com *.g.doubleclick.net *.google-analytics.com *.googlesyndication.com *.gumgum.com *.id5-sync.com *.ingest.sentry.io *.innovid.com *.jwplayer.com *.liadm.com *.lynx.cognitivlabs.com *.ns1p.net *.openx.net *.peer-39.com *.poupdate.pulsepoint.com *.prod.na.adsqtungsten.a9.amazon.dev *.pubmatic.com *.puzzmo.com *.quantserve.com *.rubiconproject.com *.rudderstack.com *.srv.stackadapt.com *.tahoe-analytics.publishers.advertising.a2z.com *.update.adsrvr.org *.update.indexww.com *.update.rubiconproject.com *.update.wo.gumgum.com *.us-east-1.cxm-bcn.publisher-services.amazon.dev *.ybp.yahoo.com wss://*.puzzmo.com cdn-cookieyes.com id5-sync.com o1223952.ingest.sentry.io *.gstatic.com *.insiad.com *.googletagmanager.com data: sevendata.fun; form-action 'none'; report-to default 1 default-src https: 'unsafe-inline' 'unsafe-eval'; report-uri https://www.allesedv.at/mixedContentReporting.php 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com 'self' data: cdnjs.cloudflare.com fonts.bunny.net cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ servicepoints.sendcloud.sc c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.googletagmanager.com widget.trustpilot.com www.google.com consentcdn.cookiebot.com www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com log.pinterest.com ssl.google-analytics.com maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.krale-wholesale.com *.krale.shop static.pay.nl 'self' data: www.snapengage.com lh3.ggpht.com imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.google.com www.gstatic.com t.trackedlink.net assets.pinterest.com maps.googleapis.com ssl.google-analytics.com embed.sendcloud.sc js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net servicepoints.sendcloud.sc widget.trustpilot.com storage.googleapis.com www.snapengage.com static.widget.trengo.eu consent.cookiebot.com consentcdn.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com maxcdn.bootstrapcdn.com assets.braintreegateway.com fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.snapengage.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com log.pinterest.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com bam.nr-data.net bam-cell.nr-data.net www.snapengage.com api.widget.trengo.eu ws-eu.pusher.com consentcdn.cookiebot.com *.krale.shop 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.krale-wholesale.com *.krale.shop 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri; report-uri https://cybersmart.report-uri.com/r/d/csp/wizard 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://altinea.fr https://cdn.astra.com https://static.elfsight.com https://core.service.elfsight.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com/recaptcha/api.js; style-src 'self' 'unsafe-inline' https://altinea.fr https://cdn.astra.com https://fonts.googleapis.com https://use.fontawesome.com/releases/v6.6.0/css/v4-shims.css https://use.fontawesome.com/releases/v6.6.0/css/all.css https://use.typekit.net/gme6kbk.css https://p.typekit.net/gme6kbk.css; img-src 'self' https://altinea.fr data: *.webp; font-src 'self' https://altinea.fr/wp-content/ https://fonts.gstatic.com https://use.fontawesome.com/releases/v6.6.0/fonts/ https://use.typekit.net/fonts/ data:; connect-src 'self' https://altinea.fr https://core.service.elfsight.com https://www.google.com; media-src 'self' https://altinea.fr; frame-src 'self' https://altinea.fr https://www.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-uri https://votreservice.report-uri.com/r/d/csp/reportOnly; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.fontawesome.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com www.belle-lingerie.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com www.belle-lingerie.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com www.belle-lingerie.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.facebook.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com www.belle-lingerie.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.amplitude.com stats.g.doubleclick.net www.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.belle-lingerie.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.belle-lingerie.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' assets.adobedtm.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com js.authorize.net jstest.authorize.net t.paypal.com s.ytimg.com video.google.com vimeo.com *.vimeocdn.com cdn-scripts.signifyd.com *.googleapis.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com cdn.xtento.com *.klevu.com *.ksearchnet.com *.avada.io *.trustpilot.com *.yotpo.com preferredliving.com *.preferredliving.com sportys.com *.sportys.com sportystoolshop.com *.sportystoolshop.com wright-bros.com *.wright-bros.com na-library.klarnaservices.com www.googleadservices.com bat.bing.com www.googletagmanager.com *.bc0a.com hello.zonos.com cdn.mouseflow.com secure.quantserve.com cdn.attn.tv *.datasteam.io googleads.g.doubleclick.net rules.quantcount.com aa.agkn.com *.cloudmaestro.com cdn.b0e8.com cdn.iglobalstores.com *.listrakbi.com www.google-analytics.com *.listrak.com widgets.turnto.com www.google.com www.gstatic.com widget.heymarket.com *.clarity.ms *.aviationgifts.com; report-uri /.webscale/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com 'self' data: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com www.googletagmanager.com *.adyen.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com platform.cloud-iq.com.au *.facebook.com *.doubleclick.net *.bedbathntable.com.au *.criteo.com *.pinterest.com *.dotdigital-pages.com *.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.adyen.com https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com *.googleapis.com *.gstatic.com dev.visualwebsiteoptimizer.com *.google.com *.facebook.com *.cloud-iq.com.au *.afterpay.com *.linksynergy.com *.google.com.au *.bedbathntable.com.au bbnt-m2-image-library.s3-ap-southeast-2.amazonaws.com *.cdninstagram.com *.google.lk *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.socdm.com *.criteo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.media.net *.bing.com *.yieldmo.com *.aralego.com *.3lift.com *.clmbtech.com *.teads.tv *.smaato.net *.rubiconproject.com *.pubmatic.com *.outbrain.com *.aralego.net *.1rx.io *.bluekai.com *.contextweb.com *.unrulymedia.com *.trackedlink.net *.ddlnk.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com *.google.com www.googletagmanager.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.googleapis.com applepay.cdn-apple.com dev.visualwebsiteoptimizer.com *.afterpay.com *.newrelic.com cdnjs.cloudflare.com bam-cell.nr-data.net platform.cloud-iq.com.au *.crazyegg.com *.facebook.net *.facebook.com *.rakuten.com googleads.g.doubleclick.net cdn.lr-ingest.io *.foursixty.com *.bedbathntable.com.au *.tiktok.com *.pinimg.com *.criteo.com *.pinterest.com *.freshworks.net *.freshworks.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zipmoney.com.au zip.co https://www.bedbathntable.com.au 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com unpkg.com *.foursixty.com *.bedbathntable.com.au *.cloud-iq.com.au *.use.typekit.net *.p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.crazyegg.com googleads.g.doubleclick.net bam-cell.nr-data.net *.lr-ingest.io *.foursixty.com *.google-analytics.com *.doubleclick.net *.bedbathntable.com.au *.nr-data.net foursixty.com *.pinterest.com *.pangle-ads.com *.tiktok.com *.criteo.com *.google.com *.freshworks.net *.freshworks.com *.attraqt.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://cdn.cookielaw.org https://www.bnpparibas.de https://brasil.bnpparibas; script-src 'self' 'unsafe-eval' https://fast.wistia.com https://beacon-v2 https://analyticsgroupcom.bnpparibas.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas ajax.googleapis.com www.googletagmanager.com googletagmanager.com tagmanager.google.com 'sha256-77WmSGVq6PlE+/dOVkQSZGQWCrUBl6KIyLWH507dV1o=' 'sha256-1n5k85V+yfNkk7Pd+G/nJITXsGJtMZPMLnU5q7WRQvM=' 'sha256-F+QMJISS2IIkRUd2a+c+u1owMqMSoidCaHFDAmzUgOo=' 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' 'sha256-yZHeusBmoqYSsqdm5ylf993dfqVyosFaYa5gueKZDsA=' 'sha256-rjfSUjIA2A20p4lATAefLLG7Fy7VJssnkJ+SnJ2TXNo=' 'sha256-NoWu+BuWxBsWAc9iEH0HnQQP7HC05AcUDK7axdIDjwo=' 'sha256-RWn1w3BKiDlDNbD6vM1kYLpeWCwwWPkob0LMWJ2gKJk=' 'sha256-NZgDk8jyfuEX0CLm5+w8H0krLwwBRllTI+UcciXxN4w=' 'sha256-fPXetwWx4258jL256OrNtQQyvFVR4/BotkeZKtfk54Q=' 'sha256-yElBEKucE35qwHf8qWcAvqD25zOJ7TqTptcHyzGhOxw=' 'sha256-Xr7tFjKXkiF47o9/dlJ+izWVWEtr67XyWOK085/Y43E=' 'sha256-qcT/R0HkWUs2DMxvtvcMobUms6Z5/fPtfgUe2hN67gE='; style-src 'self' 'unsafe-inline' data: https://fonts.googleapis.com https://www.gstatic.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://s.w.org https://wp-rocket.me https://c.tile.openstreetmap.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org blob: https://www.google.com/pagead/landing https://ade.googlesyndication.com https://pagead2.googlesyndication.com https://ad.doubleclick.net https://contrib.territories.bnpparibas https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas secure.gravatar.com www.gravatar.com i.ytimg.com data: www.googletagmanager.com; connect-src 'self' https://bnp-privacy.my.onetrust.com https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://yoast.com https://cdn.cookielaw.org https://o173685.ingest.sentry.io https://analyticsgroupcom.bnpparibas.com https://contrib.territories.bnpparibas https://www.google.com/pagead/landing https://pagead2.googlesyndication.com https://adservice.google.com https://sourcemap.devowl.io https://sourcemap.devowl.io/real-media-library/4.22.47/adb9a2f4ef22d5d85978840bd322bf76/index.js.map www.googletagmanager.com; font-src 'self' data: https://fonts.gstatic.com https://fast.wistia.com https://github.com/google/fonts https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.gstatic.com fonts.googleapis.com data:; media-src 'self' https://asset.mediahub.bnpparibas https://upload.wikimedia.org https://broadcast.mediahub.bnpparibas data: https://mediahub.group.echonet https://my.mediahub.bnpparibas https://my.mediahub.bnpparibas/AssetLink/1cwfu8n4ki414p6d240ff18r41ver00j.mp4 https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas; frame-src 'self' https://www.youtube.com https://wp-rocket.me https://open.spotify.com https://www.youtube-nocookie.com https://centric.bnpparibas.com https://13179764.fls.doubleclick.net https://td.doubleclick.net https://gateway.zscalertwo.net https://remove.video https://mozbar.moz.com www.youtube.com www.googletagmanager.com; child-src 'self' www.youtube.com www.googletagmanager.com; worker-src 'self' blob:; 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://js-agent.newrelic.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://unpkg.com https://ws.sharethis.com https://www.google.com mdbootstrap.com stackpath.bootstrapcdn.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com *.google-analytics.com www.2checkout.com connect.facebook.net *.google.com www.googletagmanager.com www.gstatic.com *.amazon-adsystem.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com; img-src 'self' data: librarika.com covers.librarika.com:8443 storage101.lon3.clouddrive.com *.ssl.cf3.rackcdn.com *.media-amazon.com *.ssl-images-amazon.com *.amazon-adsystem.com *.amazon.com *.gstatic.com *.google-analytics.com *.google.com; font-src 'self' data: fonts.gstatic.com; frame-src *.librarika.com www.2checkout.com *.facebook.com *.google.com *.amazon-adsystem.com *.youtube.com; connect-src 'self' *.google.com www.google-analytics.com; object-src 'none'; report-uri https://5e5aa7c5f482dc373380fd2db250ce83.report-uri.com/r/d/csp/enforce 1 frame-ancestors 'self'; report-uri https://www.gq.com.au/csp-reports 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action https://api.bazaarvoice.com https://stg.api.bazaarvoice.com 'self' 'unsafe-inline'; frame-ancestors https://app.storyblok.com 'self'; frame-src bid.g.doubleclick.net https://www.google.com/recaptcha/ https://testflex.cybersource.com https://h.online-metrix.net https://api.bazaarvoice.com https://stg.api.bazaarvoice.com https://display.ugc.bazaarvoice.com https://www.googletagmanager.com https://player.vimeo.com https://*.doubleclick.net https://insight.adsrvr.org https://*.adsrvr.org 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net https://images.unsplash.com https://h.online-metrix.net https://maps.googleapis.com https://*.gstatic.com https://ib.adnxs.com https://secure.adnxs.com https://*.bazaarvoice.com https://bat.bing.com https://www.facebook.com https://adservice.google.com https://flask.nextdoor.com https://i.vimeocdn.com https://sp.analytics.yahoo.com https://img.youtube.com https://*.doubleclick.net https://cdn.cookielaw.org https://*.monetate.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://app.storyblok.com *.tokenex.com https://testflex.cybersource.com https://maps.googleapis.com https://cdn.jsdelivr.net https://acdn.adnxs.com https://*.bazaarvoice.com https://bat.bing.com https://mpsnare.iesnare.com https://resources.digital-cloud-west.medallia.com https://ads.nextdoor.com https://container.pepperjam.com https://cdn.resonate.com https://www.upsellit.com https://vimeo.com https://player.vimeo.com https://www.vimeo.com https://connect.facebook.net https://js.adsrvr.org https://cdn.cookielaw.org https://*.fullstory.com https://*.monetate.net https://cdn.bc0a.com https://ixfd2-api.bc0a.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://*.googletagmanager.com https://cdn.jsdelivr.net https://display.ugc.bazaarvoice.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io data: https://*.readyrefresh.com https://testflex.cybersource.com https://expressentry.melissadata.net https://cert-xiecomm.worldpay.com https://h.online-metrix.net https://*.googleapis.com https://ib.adnxs.com https://*.bazaarvoice.com https://bat.bing.com https://bat.bing.net https://*.google.com https://geolocation.onetrust.com https://ds.reson8.com https://cdn.cookielaw.org https://*.fullstory.com https://*.doubleclick.net https://cdn.bc0a.com https://ixfd2-api.bc0a.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src *.noibu.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com *.paypalobjects.com *.gladly.com *.cookielaw.org www.google.com www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com *.facebook.com *.facebook.net *.yotpo.com *.listrakbi.com *.cookielaw.org *.tilebar-vis.com *.byondxr.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://plumrocket.com *.weltpixel.com *.facebook.com *.paypalobjects.com *.yotpo.com *.cardknox.com *.vimeo.com vimeo.com *.googletagmanager.com *.xtento.com *.doubleclick.net *.gladly.com *.optimizely.com *.creativecdn.com *.pinterest.com *.listrakbi.com *.cookielaw.org *.noibu.com photos.pixlee.co *.tilebar-vis.com *.byondxr.com sketchfab.com cdn.cardknox.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * speedsize.com *.speedsize.com www.xtento.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com *.googleadservices.com *.facebook.com *.yotpo.com *.cdninstagram.com *.google-analytics.com *.google.com *.google.com.vn *.google.co.il *.google.com.sg *.google.co.uk *.google.de *.magentocommerce.com *.paypalobjects.com *.ytimg.com *.web-view.net *.googleapis.com *.nagich.co.il vimeo.com *.vimeo.com *.tilebar.com *.zdassets.com *.pxlecdn.com *.cloudfront.net *.roomvo.com *.tilebar-vis.com *.byondxr.com *.searchspring.net *.gladly.com *.edgecastcdn.net *.doubleclick.net *.bing.com *.pinterest.com *.optimizely.com *.adnxs.com *.pubmatic.com *.adingo.jp *.adingo.com *.creativecdn.com *.yahoo.com *.yahoo.net *.33across.com *.mobon.net *.seedtag.com *.clarity.ms *.brcdn.com *.brsrvr.com *.listrakbi.com *.cookielaw.org wac.edgecastcdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.dxpapi.com *.fontawesome.com *.googleapis.com *.gstatic.com *.google-analytics.com apis.google.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.doubleclick.net *.analytics.com *.rawgit.com *.nagich.co.il *.luckyorange.com *.xtento.com *.paypal.com *.paypalobjects.com *.forsixty.com *.criteo.com *.searchspring.io *.searchspring.net *.roomvo.io *.roomvo.com *.cloudflareinsights.com *.optimizely.com *.turnto.com *.pixlee.com *.pxlecdn.com *.tilebar-vis.com *.byondxr.com *.cloudflare.com *.gladly.com *.smooch.io *.bing.com *.creativecdn.com *.pinimg.com *.particularaudience.com *.googletagservices.com *.googlesyndication.com cnstrc.com getrockerbox.com/ *.adnxs.com *.adingo.jp *.adingo.com *.cnstrc.com *.tilebar.com *.pinterest.com *.callrail.com *.clarity.ms *.algoliaradar.com *.brcdn.com *.listrakbi.com *.cloudfront.net *.cookielaw.org *.noibu.com cdn.cardknox.com/ifields/2.15.2405.1601/ifields.min.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com *.cloudflare.com *.turnto.com *.gladly.com *.brcdn.com *.listrakbi.com *.cookielaw.org *.google.com *.gstatic.com *.typekit.net assets.braintreegateway.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com *.dxpapi.com *.doubleclick.net *.analytics.com *.facebook.com *.google-analytics.com *.nagich.co.il player.vimeo.com *.luckyorange.com *.googleapis.com *.visitors.live *.zdassets.com *.searchspring.io *.searchspring.net *.roomvo.io *.roomvo.com cloudflareinsights.com *.cloudflareinsights.com *.optimizely.com *.turnto.com *.tilebar-vis.com *.byondxr.com unpkg.com *.unpkg.com *.gladly.com *.smooch.io *.creativecdn.com *.pinimg.com *.particularaudience.com *.googletagservices.com *.googlesyndication.com *.pinterest.com *.cnstrc.com *.cardknox.com *.clarity.ms *.pixlee.com *.algolia.io *.listrakbi.com *.betanetqa.me *.cloudflare.com *.cookielaw.org https://*.noibu.com wss://*.noibu.com www.google.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /bnews/csp/report; report-to report-endpoint; 1 script-src 'nonce-4Z/vVybY1xbW58EmwEVFew==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=e86ab95f-1449-4f37-a15e-fa3845469ae2; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src *.force.com https://omt.honda.com https://owners.honda.com https://honda.demdex.net 'self' https://www.acura.com https://stats.g.doubleclick.net *.youtube-nocookie.com https://cm.everesttech.net https://cdn.cookielaw.org http://code.jquery.com https://uat2.sendyouropinions.com https://somt.honda.com https://ahfc--webproj1.my.salesforce.com https://www.gstatic.com https://consent-api.onetrust.com https://assets.adobedtm.com https://fonts.googleapis.com https://www.google.com https://analytics.google.com https://fonts.gstatic.com/ https://geolocation.onetrust.com https://dpm.demdex.net https://td.doubleclick.net https://automobiles.honda.com https://powersports.honda.com blob: https://survey2.sendyouropinions.com *.gstatic.com https://eshopping.americanhondafinance.com *.facebook.com *.youtube.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com data:; report-to sfdc-csp-ep; report-uri https://ahfc.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Dj0000001oPqD&networkId=0DM5b000000wk5s&type=communities 1 script-src 'nonce-UxXMJpyss+yfs+Flp7ZiHw==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=f869502b-2a2e-4427-a1c3-ec89240d6270; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' puravida.com.br *.puravida.com.br wake-components.fbitsstatic.net puravida.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com static.traycheckout.com.br *.traycheckout.com.br *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.2listen.com.br *.googleadservices.com *.trackcmp.net *.soclminer.com.br static.hotjar.com *.hotjar.com cdn.convertbox.com googleadservices.com wss://ws11.hotjar.com wss://ws9.hotjar.com wss://ws3.hotjar.com wss://ws18.hotjar.com wss://ws21.hotjar.com wss://ws1.hotjar.com wss://ws13.hotjar.com wss://ws20.hotjar.com wss://ws23.hotjar.com *.hotjar.io vars.hotjar.com wss://ws4.hotjar.com wss://ws16.hotjar.com wss://ws8.hotjar.com wss://ws15.hotjar.com wss://ws5.hotjar.com wss://ws12.hotjar.com wss://ws14.hotjar.com wss://ws22.hotjar.com wss://ws10.hotjar.com wss://ws19.hotjar.com wss://ws6.hotjar.com wss://ws25.hotjar.com wss://ws17.hotjar.com wss://ws7.hotjar.com wss://ws2.hotjar.com wss://ws24.hotjar.com dzpxyxks1bfmb.cloudfront.net *.getblue.io *.criteo.com *.criteo.net *.g.doubleclick.net *.cloudfront.net *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com artfut.com *.artfut.com *.pinimg.com *.bing.com *.metaffiliation.com *.2eb4a95jq.de ws.puravida.com.br *.doubleclick.net *.rdstation.com.br googleoptimize.com smct.co browser.sentry-cdn.com *.sentry.io *.bambuser.com *.btg360.com.br *.smct.co *.smct.io *.amazonaws.com *.reclameaqui.com.br *.pinterest.com *.socialminer.com *.gstatic.com *.dsspn.com *.afftrack.pro *.clarity.ms *.cloudflare.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com samuraiexpertsstorage.blob.core.windows.net recorrencia-samurai.azurewebsites.net analytics.tiktok.com *.googleoptimize.com *.oli.live mautic.puravida.com.br signalrcore.fbits.net wss://signalrcore.fbits.net survey.solucx.com.br *.cloudfront.net service.smarthint.co *.useinsider.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.licdn.com *.appspot.com *.purplemetrics.com.br *.fbitsstatic.net *.linkedin.com *.google.com.br *.googleapis.com *.unpkg.com *.fbits.store *.puravida.com.br *.adyen.com *.jsdelivr.net cdn.jsdelivr.net *.pagar.me *.mundipagg.com pvecommercefiles.blob.core.windows.net *.blob.core.windows.net *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.datadoghq-browser-agent.com *.datadoghq.com *.browser-intake-us3-datadoghq.com browser-intake-us3-datadoghq.com *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.specialone.io unpkg.com wake.koin.com.br temp-puravidalabs-backend-pvclub-black-friday-production.azurewebsites.net paypal-wake.s3.us-east-1.amazonaws.com puravidalabs-backend-ecommerce-optin-service-p.azurewebsites.net *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.crmback.io *.crmback.dev *.crmback.com x.cbstatus.net *.3dsecure.io *.cookielaw.org *.googlesyndication.com puravidalabs-backend-ecommerce-orders-api-production.azurewebsites.net puravida-br.mais.social trackings.nemu.com.br *.openfpcdn.io *.ipinfo.io api.ipify.org api.bigdatacloud.net *.visualwebsiteoptimizer.com app.vwo.com puravidalabs-backend-ecommerce-customers-api-production.azurewebsites.net *.visa.com openfpcdn.io *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.puravida.com.br puravida.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://form.typeform.com https://www.googletagmanager.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com cdn.doofinder.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://www.magezon.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.google.com/ *.disqus.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.doofinder.com wss://*.doofinder.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-HHHrRGtrxl9hvLdMlzvlSg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com *.avada.io https://player.vimeo.com https://www.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.jsdelivr.net *.fontawesome.com cdn.ywxi.net www.google.com *.googleapis.com www.googletagmanager.com www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.amazonaws.com/mfesecure-public/host/ *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com fonts.cdnfonts.com *.zohostatic.ca css.zohocdn.com cdn.userway.org *.fontawesome.com maxcdn.bootstrapcdn.com m2.grasscity.com staticw2.yotpo.com https://d1cwup7r903a1d.cloudfront.net 'self' data: *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com https://www.googletagmanager.com/ *.addthis.com *.authorize.net pub-7be69f7c77b4c166d1c3.tracking.refersion.com https://config-cdn.ksearchnet.com *.refersion.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://images.unsplash.com *.googleapis.com *.gstatic.com *.curopayments.net cdn.userway.org *.clarity.ms c.bing.com www.google.co.in shopper.shop.pe css.zohocdn.com www.grasscity.com store.paradoxlabs.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://img.youtube.com flagpedia.net m2.grasscity.com p.yotpo.com media.sezzle.com *.hsforms.net *.hsforms.com 'self' data: *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.googletagmanager.com/gtm.js shop.pe tags.srv.stackadapt.com jscloud.net analytics.ahrefs.com *.cloudfront.net *.clarity.ms cdn.userway.org shopper.shop.pe cdn.convertcart.com dc4.convertcart.com addshoppers.s3.amazonaws.com cdn.aggle.net salesiq.zohopublic.ca *.zohostatic.ca *.zohocdn.com aggle.net r1-t.trackedlink.net static.trackedweb.net self https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io maps.googleapis.com *.authorize.net https://config-cdn.ksearchnet.com js.klevu.com m2.grasscity.com script.tapfiliate.com static.cloudflareinsights.com assets.mantisadnetwork.com unpkg.com cdn.refersion.com staticw2.yotpo.com static.klaviyo.com static-tracking.klaviyo.com *.refersion.com cdn.routeapp.io https//fonts.googleapis.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.hsforms.net *.hsforms.com *.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com cdn.convertcart.com css.zohocdn.com *.zohostatic.ca cdn.userway.org tags.srv.stackadapt.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com m2.grasscity.com staticw2.yotpo.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net fonts.cdnfonts.com *.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.google.co.in r1.trackedweb.net wss://onlinesupportmatrix.support wss://onlinechatmatrix.online manage.safeopt.com cdn.convertcart.com api2.amplitude.com api.route.com api-stage.route.com wss://vts.zohopublic.ca *.zohopublic.ca salesiq.zohocloud.ca herb.aggle.net/ shop.pe shopper.shop.pe api.userway.org *.clarity.ms cdn.userway.org analytics.ahrefs.com jscloud.net tags.srv.stackadapt.com dc4.convertcart.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.authorize.net connect-sandbox.bolt.com statsjs.klevu.com js.klevu.com staticw2.yotpo.com m2.grasscity.com tracking.refersion.com *.refersion.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src thm.visa.com m2.grasscity.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'report-sample' 'strict-dynamic' https://ajax.googleapis.com/ https://api.tiles.mapbox.com/ https://cdn.nolt.io/ https://cdn.statuspage.io/ https://cdn.tiny.cloud/ https://cdnjs.cloudflare.com/ https://code.jquery.com/ https://j1h014tryv29.statuspage.io/ https://static.zdassets.com/ https://www.googletagmanager.com/ 'nonce-YVVJUzVxNE5CalA1Ul9aMkhndWxkZ0FBQUF3'; object-src 'none'; style-src 'self' 'report-sample' 'strict-dynamic' https://api.tiles.mapbox.com https://cdnjs.cloudflare.com https://fonts.googleapis.com 'nonce-YVVJUzVxNE5CalA1Ul9aMkhndWxkZ0FBQUF3'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'none'; base-uri 'self'; img-src 'self' data: https://sp.tinymce.com https://api.tiles.mapbox.com; frame-src 'self' https://j1h014tryv29.statuspage.io; media-src 'self' https://static.zdassets.com; connect-src 'self' https://ekr.zdassets.com https://omnilert.zendesk.com wss://widget-mediator.zopim.com; report-uri https://afiwlxkn53.execute-api.us-east-1.amazonaws.com/latest/csp_reports; report-to https://afiwlxkn53.execute-api.us-east-1.amazonaws.com/latest/csp_reports; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' blob: data: https://*.youtube.com https://firebase.googleapis.com https://share.keepshare.info https://static-web.jjdsn.vip https://bitkeep.page https://*.bitkeep.fun https://*.bitget.cloud https://keepshare.xyz https://gasutopia.com https://bitkeep.com https://*.facebook.net https://api.nileex.io https://keepshare.info https://*.google.com https://share.bitkeep.shop https://infragrid.v.network https://*.bitkeep.com https://ta.bitkeep.buzz:8993 https://bitkeep.io https://*.bitkeep.io https://www.google-analytics.com https://fp-constantid.bitkeep.vip https://*.bitkeep.page https://*.bjxnyj.com https://bitkeep.org https://*.bitgetstatic.com https://share.bwb.live https://*.bitkeep.vip https://*.bitget.site https://*.bitgetpro.site https://api.shasta.trongrid.io https://s3.infcrypto.com https://*.bitkeep.me https://*.jjdsn.vip https://*.mytokenpocket.vip https://sun.tronex.io https://goldshare.me https://*.bitget.com https://firebaseinstallations.googleapis.com https://www.googletagmanager.com https://*.googleapis.com https://share.bwb.site https://stats.g.doubleclick.net https://rpc-wallet.broearn.com https://api.trongrid.io https://*.bknode.vip https://cdn.bootcdn.net https://search.imtt.qq.com https://api-web.wwmxd.info https://api-web.wwmxd.site https://www.recaptcha.net https://ordinals.com https://www.gstatic.cn https://www.gstatic.com https://log.noxiaohao.com https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://share.bwb.online https://share.bwb.global https://share.bwb.win https://share.bwb.inc https://share.bwb.space https://*.walletconnect.org wss://*.walletconnect.org https://*.walletconnect.com;connect-src 'self' 'report-sample' blob: data: https://*.youtube.com https://firebase.googleapis.com https://share.keepshare.info https://*.bitkeep.fun https://bitkeep.page https://*.bitget.cloud https://keepshare.xyz https://gasutopia.com https://bitkeep.com https://*.facebook.net https://api.nileex.io https://keepshare.info https://*.google.com https://share.bitkeep.shop https://infragrid.v.network https://*.bitkeep.com https://ta.bitkeep.buzz:8993 https://bitkeep.io https://*.bitkeep.io https://www.google-analytics.com https://fp-constantid.bitkeep.vip https://*.bitkeep.page https://*.bjxnyj.com https://bitkeep.org https://*.bitgetstatic.com https://share.bwb.live https://*.bitkeep.vip https://*.bitget.site https://*.bitgetpro.site https://api.shasta.trongrid.io https://s3.infcrypto.com https://*.bitkeep.me https://*.jjdsn.vip https://*.mytokenpocket.vip https://sun.tronex.io https://goldshare.me https://*.bitget.com https://firebaseinstallations.googleapis.com https://www.googletagmanager.com https://*.googleapis.com https://share.bwb.site https://stats.g.doubleclick.net https://rpc-wallet.broearn.com https://api.trongrid.io https://*.bknode.vip https://cdn.bootcdn.net https://search.imtt.qq.com https://api-web.wwmxd.info https://api-web.wwmxd.site https://ordinals.com https://www.gstatic.cn https://www.gstatic.com https://log.noxiaohao.com https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://share.bwb.online https://share.bwb.global https://share.bwb.win https://share.bwb.inc https://share.bwb.space https://region1.google-analytics.com https://*.walletconnect.org wss://*.walletconnect.org https://*.walletconnect.com https://cloudflare-eth.com https://eth.llamarpc.com https://api-web.bitkeep.asia https://api-web.bitkeep.biz https://api-web.bitkeep.life https://api-web.chainnear.com https://api-web.bitkeep.fun;frame-src 'self' 'report-sample' https://www.google.com https://www.recaptcha.net https://*.bitget.com https://static-web.jjdsn.vip https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://*.walletconnect.org;frame-ancestors 'self' https://bulbaswap.io https://app.bulbaswap.io https://www.bulbaswap.io https://bulba.bknode.vip https://*.bitget.com https://static-web.jjdsn.vip https://www.google.com https://www.recaptcha.net https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com;report-uri https://log.noxiaohao.com/v1/buried/log/cspSecurity; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.salesforceliveagent.com *.cloudflare.com *.force.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.com *.google.pl *.bing.net js.hubspotfeedback.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; style-src 'self' 'unsafe-inline' *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; img-src 'self' data: blob: *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; frame-src *.force.com *.adsrvr.org *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.hs-sites.com *.hsforms.net *.hubspot.com *.googletagmanager.com *.doubleclick.net gtm.prosci.com; connect-src 'self' *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; font-src 'self' data: *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; 1 img-src 'self' data: https://criticalcss.com http://jogodotigre.com https://translate.google.com https://fonts.gstatic.com https://cassinovipp.com blob: https://jogajuntobet.io https://deliveryimages.net https://via.placeholder.com https://www.googletagmanager.com https://brfffx.oss-us-west-1.aliyuncs.com https://i.ytimg.com https://s2-g1.glbimg.com https://gambling.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://infird.com https://cdn.jsdelivr.net https://cdn.datatables.net https://connect.facebook.net https://platform.twitter.com https://yoast.com https://beacon-v2.helpscout.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.googletagmanager.com data: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' blob: https://infird.com https://cdn.jsdelivr.net https://cdn.datatables.net https://connect.facebook.net https://platform.twitter.com https://yoast.com https://beacon-v2.helpscout.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.googletagmanager.com data: ; style-src 'self' 'unsafe-inline' https://cdn.datatables.net https://cdn.jsdelivr.net https://fonts.googleapis.com https://www.gstatic.com https://me.kis.v2.scr.kaspersky-labs.com ; style-src-elem 'self' 'unsafe-inline' https://cdn.datatables.net https://cdn.jsdelivr.net https://fonts.googleapis.com https://www.gstatic.com https://me.kis.v2.scr.kaspersky-labs.com ; font-src 'self' http://jogodotigre.com https://fonts.gstatic.com https://use.typekit.net data:; frame-src 'self' https://m.pgsoft-games.com https://pgsoftslotsdemo.com https://www.youtube.com blob:; connect-src 'self' https://yoast.com https://translate.googleapis.com https://maps.googleapis.com https://my.yoast.com http://jogodotigre.com wss://localhost https://metrics-dre.dt.dbankcloud.cn https://metrics-dra.dt.dbankcloud.cn https://www.google-analytics.com https://www.googletagmanager.com; media-src 'self' data:; worker-src 'self' blob:; report-uri https://jogodotigre.com/wp-json/rsssl/v1/csp?rsssl_apitoken=537255591; 1 default-src https: data: 'unsafe-inline' 'unsafe-eval' blob: wss:; report-uri https://464b711251f54c909b7a68dbb569ad3b.myssl-uri.com/api/csp-report 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: wss://ws.salecycle.com; object-src 'none'; style-src 'self' https: 'unsafe-hashes' 'unsafe-inline' https://*.aircaraibes.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' data: https:; media-src 'self'; frame-src 'self' https://*.aircaraibes.com https://aircaraibes.qualifioapp.com https://www.googletagmanager.com/ https://*.salecycle.com https://*.pinterest.com https://*.criteo.com https://*.cloudfront.net; frame-ancestors 'self' https://www.liligo.com https://www.liligo.fr https://checkin.si.amadeus.net https://*.aircaraibes.com; font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com https://*.finchatbot.com; connect-src 'self' https: wss://ws.salecycle.com; upgrade-insecure-requests 1 default-src https:; connect-src https: wss:; font-src https: data:; frame-src https:; img-src https: data:; media-src https:; object-src https:; script-src 'unsafe-inline' 'unsafe-eval' https: data: blob:; style-src 'unsafe-inline' https:; report-uri https://www.check24.net/csp-violation-ezmd9dpdxv7nb0ecejb9/ 1 default-src 'self'; child-src 'none'; connect-src 'self' https://*.bozar.be https://*.contentsquare.net https://*.facebook.com https://*.google-analytics.com https://*.onetrust.com https://*.recombee.com https://*.secutix.com https://*.visualwebsiteoptimizer.com https://*.vwo.com https://o419740.ingest.sentry.io/api/5336472/envelope/; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://*.googletagmanager.com https://*.google.com https://*.matterport.com https://*.soundcloud.com https://*.spotify.com https://*.vimeo.com https://*.youtube.com; img-src 'self' https://*.cookielaw.org https://*.facebook.com https://*.googletagmanager.com https://*.vimeocdn.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.bozar.be https://*.hotjar.com https://*.cookielaw.org https://*.contentsquare.net https://*.googletagmanager.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com; script-src-elem 'self' 'unsafe-inline' https://*.bozar.be https://*.cookielaw.org https://*.facebook.net https://*.googletagmanager.com https://*.hotjar.com https://matomojs.trackify.info https://*.visualwebsiteoptimizer.com https://*.vwo.com https://*.youtube.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'self' https://*.bozar.be https://*.secutix.com; report-uri https://o419740.ingest.sentry.io/api/5336472/security/?sentry_key=352ab04e14224ad0804d381177289653&sentry_environment=master-7rqtwti&sentry_release=295b6893ded6f01bcdcdf29545c5b26fe1683a68; block-all-mixed-content 1 worker-src blob: *.osano.com 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.cloudinary.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.narvar.com *.narvar.qa *.abtasty.com cdnjs.cloudflare.com *.yottaa.net use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com cloudinary.com *.cloudinary.com 'self' facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com forms.hsforms.com globalshopex.com api.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.krxd.net *.attn.tv 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.adyen.com cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.klarna.com facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.certcapture.com forms.hsforms.com scrubsandbeyond.ytuz.net cdn.krxd.net *.osano.com ct.pinterest.com *.studentbeans.com globalshopex.com *.attn.tv *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com cloudinary.com *.cloudinary.com blob: *.klarna.com *.klarnaevt.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.narvar.com *.narvar.qa *.ometria.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.certcapture.com *.abtasty.com aa.agkn.com *.amazonaws.com *.payments-amazon.com *.bing.com *.clarity.ms *.foregenix.com maps.gstatic.com maps.googleapis.com forms.hsforms.com track.hubspot.com nova.collect.igodigital.com logs-01.loggly.com www.ojrq.net scrubsandbeyond.ytuz.net beacon.krxd.net *.pinterest.com *.px-cloud.net track.sv.rkdms.com www.scrubsandbeyond.com track.securedvisit.com *.yottaa.net fonts.gstatic.com events.attentivemobile.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.vimeo.com unpkg.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.googleapis.com *.gstatic.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.certcapture.com *.abtasty.com bat.bing.com www.clarity.ms cnstrc.com maps.googleapis.com js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net js.hsforms.net *.hs-scripts.com *.igodigital.com utt.impactcdn.com d.impactradius-event.com *.krxd.net action.media6degrees.com js-agent.newrelic.com *.osano.com s.pinimg.com assets.pinterest.com cdn.roirevolution.com *.securedvisit.com seoab.io cdn.studentbeans.com *.yottaa.net rapid-cdn.yottaa.com *.yottaa-prod.com globalshopex.com cdn.noibu.com *.attn.tv *.yotpo.com swellrewards.com *.swellrewards.com platform.twitter.com *.ometria.com https://cdn.amplitude.com https://www.scrubsandbeyond.com https://tkzgz.scrubsandbeyond.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app cloudinary.com *.cloudinary.com *.googleapis.com unpkg.com *.klarnacdn.net *.fontawesome.com *.google.com *.gstatic.com assets.braintreegateway.com *.certcapture.com *.abtasty.com *.osano.com *.yottaa.net use.typekit.net p.typekit.net www.googletagmanager.com ometria.email *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cloudinary.com *.cloudinary.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com cloudinary.com *.cloudinary.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com google.com/pay pay.google.com *.certcapture.com *.amazonaws.com *.abtasty.com bat.bing.com *.clarity.ms stats.g.doubleclick.net accounts.google.com fonts.googleapis.com maps.googleapis.com forms.hubspot.com forms.hsforms.com scrubsandbeyond.ytuz.net api.ipify.org www.iplocate.io *.ingest.sentry.io *.osano.com ct.pinterest.com *.px-cloud.net seoab.io storage.googleapis.com event-service-jtdpxp3bfa-ew.a.run.app *.yottaa.net https://*.cnstrc.com cdn.noibu.com input.noibu.com wss://input.noibu.com https://api.scrubsandbeyond.com/api/locations *.attn.tv events.attentivemobile.com tkzgz.scrubsandbeyond.com *.yotpo.com swellrewards.com *.swellrewards.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com mcstaging.packersproshop.com www.packersproshop.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.google.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com magefan.com cm.magefan.com 'self' 'unsafe-inline' adobe.com *.affirm.com *.bing.com *.bing.net *.scorecardresearch.com *.cloudfront.net *.cookielaw.org *.google.com.au *.googlesyndication.com *.mathtag.com *.mimecast.com *.zonos.com mcstaging.packersproshop.com www.packersproshop.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.bing.com d1z2jf7jlzjs58.cloudfront.net *.c212.net *.cookielaw.org *.everestjs.net *.iglobalstores.com *.googletagmanager.com *.googlesyndication.com *.gstatic.com www.google.com *.mathtag.com *.onetrust.com *.scorecardresearch.com *.packersproshop.com *.tiktok.com *.zonos.com acds-events.adobe.io js-agent.newrelic.com mcstaging.packersproshop.com www.packersproshop.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.adobedtm.com bam.nr-data.net *.bing.com *.bing.net *.cardinalcommerce.com *.scorecardresearch.com *.cloudfront.net *.cookielaw.org *.demdex.net *.everesttech.net *.google-analytics.com *.googlesyndication.com *.gstatic.com www.google.com *.omtrdc.net *.onetrust.com *.parsely.com *.tiktok.com *.zonos.com sedge.nfl.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1a78f49d-a75b-466e-a8d0-2a6f25a8e22d.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mobilpay.ro secure.mobilpay.ro 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.innoship.ro https://www.googletagmanager.com/ www.xtento.com *.cookiebot.com *.creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.ro *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.tbicp.com *.tile.openstreetmap.org *.openstreetmap.org http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com t.themarketer.com cdn1.themarketer.com www.xtento.com cdn.xtento.com *.cookiebot.com *.sportguru.ro blob: *.creativecdn.com *.onesignal.com onesignal.com *.cloudfront.net *.zopim.io bat.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.tbicp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com t.themarketer.com cdn1.themarketer.com www.xtento.com cdn.xtento.com *.cookiebot.com *.onesignal.com *.zopim.com *.hotjar.com *.zdassets.com onesignal.com *.creativecdn.com bat.bing.com www.clarity.ms static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net t.themarketer.com cdn1.themarketer.com *.onesignal.com onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net stats.g.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com c1api.themarketer.com c2api.themarketer.com c3api.themarketer.com region1.analytics.google.com googleads.g.doubleclick.net *.cookiebot.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com *.creativecdn.com *.onesignal.com onesignal.com *.tbibank.ro tbibank.ro u.clarity.ms *.gstatic.com *.merchant-center-analytics.goog c4api.themarketer.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobe.com *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.doubleclick.net *.hubspot.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.clickagy.com *.adsrvr.org *.hs-scripts.com *.hsleadflows.net *.hs-banner.com *.hsadspixel.net *.hs-analytics.net *.usemessages.com *.hubspotfeedback.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobe.com *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.clickagy.com *.adsrvr.org *.linkedin.com *.hubspot.com *.hubapi.com *.trustpilot.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://*.analytics.google.com https://*.aptrinsic.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sentry.io https://api.ipgeolocation.io https://api.triptease.io https://bat.bing.com https://bat.bing.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://content.hotjar.io https://data.flip.to https://dc.services.visualstudio.com https://fonts.googleapis.com https://google.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://mc.yandex.com https://mc.yandex.ru https://messages.guest-experience.triptease.io https://metrics.corinthia.com https://metrics.hotjar.io https://onboard.triptease.io https://p.relay-t.io https://region1.analytics.google.com https://sa.flip.to https://scripts.affilired.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://stats.g.doubleclick.net https://sync.srv.stackadapt.com https://tags.srv.stackadapt.com https://vc.hotjar.io https://wl-suppliers.app.cvent.com https://www.dripuploads.com https://www.facebook.com https://www.google.ae https://www.google.co.uk https://www.google.com https://www.menumodo.com https://www.thehotelsnetwork.com wss://ws.hotjar.com; default-src 'self' https://*.adform.net https://*.adnxs.com https://*.sentry.io https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/; font-src 'self' data: https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/ https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.gstatic.com/s/barlow/ https://fonts.gstatic.com/s/lato/ https://fonts.gstatic.com/s/roboto/ https://static.tacdn.com https://use.typekit.net https://www.menumodo.com; frame-src 'self' https://*.adsrvr.org https://*.fls.doubleclick.net https://*.speedrfp.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://customs.affilired.com https://mc.yandex.com https://mc.yandex.ru https://onboard.triptease.io https://targeted-messages.triptease.io https://td.doubleclick.net https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.youtube-nocookie.com; img-src 'self' blob: data: *.ggpht.com *.googleapis.com *.linkedin.com https://*.adform.net https://*.adnxs.com https://*.adsrvr.org https://*.analytics.google.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ad.doubleclick.net https://bat.bing.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cm.g.doubleclick.net/pixel https://cms.analytics.yahoo.com https://d1cmxvrarpztze.cloudfront.net https://dpm.demdex.net https://googletagmanager.com https://i.ytimg.com https://imgsct.cookiebot.com https://mc.yandex.com https://mc.yandex.ru https://metrics.corinthia.com https://pubads.g.doubleclick.net https://region1.analytics.google.com https://ssl.gstatic.com https://stackadapt.com https://static.tacdn.com https://stats.g.doubleclick.net https://storage.ghadiscovery.com https://sync.srv.stackadapt.com https://tags.srv.stackadapt.com https://tags.w55c.net https://www.facebook.com https://www.google.ae https://www.google.co.uk https://www.google.com https://www.gstatic.com https://www.menumodo.com https://www.pages04.net https://www.tripadvisor.co.uk maps.gstatic.com; manifest-src 'self'; media-src 'self'; script-src-elem 'self' 'unsafe-inline' *.licdn.com https://*.adsrvr.org https://*.aptrinsic.com https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ajax.googleapis.com https://api.getdrip.com https://bat.bing.com https://browser.sentry-cdn.com https://cdn.denomatic.com https://cdn.flip.to https://cdn.jsdelivr.net https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdn.jsdelivr.net/npm/feather-icons/ https://cdn.jsdelivr.net/npm/ip-geolocation-api-jquery-sdk@1.0.6/ https://cdn.jsdelivr.net/npm/jquery@3.5.1/ https://cdn.jsdelivr.net/npm/jquery@3.6.4/ https://cdn.jsdelivr.net/npm/popper.js@1.16.1/ https://cdn.otstatic.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/ https://code.jquery.com/jquery-3.2.1.slim.min.js https://components.flip.to https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://contentz.mkt941.com https://customs.affilired.com https://d16fk4ms6rqz1v.cloudfront.net https://googleads.g.doubleclick.net https://integration.flip.to https://js.monitor.azure.com https://js.sentry-cdn.com https://maps.googleapis.com https://maps.googleapis.com/maps/api/* https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://mc.yandex.com https://mc.yandex.ru https://navigator.ink-global.com https://onboard.triptease.io https://p.relay-t.io https://script.crazyegg.com https://script.hotjar.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.s3.eu-west-1.amazonaws.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://static.hotjar.com https://static.tacdn.com https://static.x-channel.triptease.io https://tag.getdrip.com https://tag.yieldoptimizer.com https://tagmanager.google.com https://tags.srv.stackadapt.com/events.js https://targeted-messages.triptease.io https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.jscache.com https://www.menumodo.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.tripadvisor.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.adsrvr.org https://*.aptrinsic.com https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ajax.googleapis.com https://api.getdrip.com https://bat.bing.com https://browser.sentry-cdn.com https://cdn.denomatic.com https://cdn.flip.to https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdn.jsdelivr.net/npm/feather-icons@4.29.0/ https://cdn.jsdelivr.net/npm/feather-icons/ https://cdn.jsdelivr.net/npm/ip-geolocation-api-jquery-sdk@1.0.6/ https://cdn.jsdelivr.net/npm/jquery@3.5.1/ https://cdn.jsdelivr.net/npm/jquery@3.6.4/ https://cdn.jsdelivr.net/npm/popper.js@1.16.1/ https://cdn.otstatic.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/ https://code.jquery.com/jquery-3.2.1.slim.min.js https://components.flip.to https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://contentz.mkt941.com https://customs.affilired.com https://d16fk4ms6rqz1v.cloudfront.net https://googleads.g.doubleclick.net https://googletagmanager.com https://integration.flip.to https://js.monitor.azure.com https://js.sentry-cdn.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://mc.yandex.com https://mc.yandex.ru https://navigator.ink-global.com https://onboard.triptease.io https://p.relay-t.io https://script.crazyegg.com https://script.hotjar.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.s3.eu-west-1.amazonaws.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://static.hotjar.com https://static.tacdn.com https://tag.getdrip.com https://tag.yieldoptimizer.com https://tagmanager.google.com https://tags.srv.stackadapt.com https://targeted-messages.triptease.io https://wl-suppliers.app.cvent.com https://www.google.com https://www.gstatic.com/recaptcha/ https://www.jscache.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.tripadvisor.co.uk https://www.tripadvisor.com; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.css https://p.typekit.net https://tags.srv.stackadapt.com/sa.css https://use.typekit.net https://www.menumodo.com; style-src 'self' 'unsafe-inline' data: https://*.aptrinsic.com https://*.googletagmanager.com https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://fonts.googleapis.com https://googletagmanager.com https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://p.typekit.net https://static.tacdn.com https://tagmanager.google.com https://use.typekit.net https://www.menumodo.com; script-src-attr https://www.menumodo.com; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://connect.facebook.net https://connect.facebook.com https://www.facebook.com https://analys.quicknet.se; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://www.googletagmanager.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.gstatic.com https://connect.facebook.net https://connect.facebook.com https://www.facebook.com https://graph.facebook.com https://analys.quicknet.se; frame-src 'self' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://www.facebook.com http://mk.quicknet.se https://mk.quicknet.se; object-src 'none'; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'self'; report-uri https://quicknet.se/wp-json/csp/v1/report 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com https://fonts.gstatic.com/ *.typekit.net *.nosto.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com *.klarna.com https://www.googletagmanager.com/ *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * widget.trustpilot.com simplicity.trustpilot.com *.googlesyndication.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.klarna.com *.klarnaevt.com *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://s3-eu-west-1.amazonaws.com *.cdninstagram.com *.poundshop.com *.poundland.com *.poundland.co.uk *.dealz.ie *.onetrust.com s.kelkoogroup.net c.bing.com c.clarity.ms bat.bing.com *.ometria.com *.google.ac *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.ua *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.com.kh *.google.cc *.google.cd *.google.cf *.google.cat *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gf *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gp *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.iq *.google.ie *.google.co.il *.google.im *.google.co.in *.google.io *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.com.lc *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.ne *.google.com.nf *.google.com.ng *.google.com.ni *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pk *.google.com.pa *.google.com.pe *.google.com.ph *.google.pl *.google.com.pg *.google.pn *.google.co.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.rs *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.sm *.google.so *.google.st *.google.sr *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tk *.google.tl *.google.tm *.google.to *.google.tn *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.co.ug *.google.co.uk *.google.com *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.co.za *.google.co.zm *.google.co.zw data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com *.klarna.com js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.poundshop.com *.poundland.com *.poundland.co.uk *.dealz.ie s.kelkoogroup.net widget.trustpilot.com invitejs.trustpilot.com sdk.loyaltylion.net foursixty.com sdk-static.loyaltylion.net bat.bing.com *.zendesk.com static.zdassets.com *.ometria.com analytics.tiktok.com www.clarity.ms s.kk-resources.com *.googlesyndication.com *.onetrust.com *.newrelic.com *.soreto.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com sdk.loyaltylion.net foursixty.com *.onetrust.com *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://the.sciencebehindecommerce.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaevt.com *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sdk.loyaltylion.net foursixty.com platform.loyaltylion.com *.zendesk.com widget-mediator.zopim.com wss://widget-mediator.zopim.com analytics.tiktok.com *.clarity.ms s.kelkoogroup.net invitejs.trustpilot.com zendesk-eu.my.sentry.io *.ometria.com *.google-analytics.com *.onetrust.com *.newrelic.com *.nr-data.net *.googlesyndication.com *.soreto.com googleads.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://04bdc3b5-2455-47f6-9c1d-24c9c5f93a61.sansec.watch/; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; 1 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: https://media.flixcar.com/ https://media.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.facebook.com/tr/ https://content.jwplatform.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co amc.demdex.net www.google.com youtube.com *.hotjar.com https://www.facebook.com/tr/ https://static.addtoany.com/ https://static.zdassets.com/ https://script.hotjar.com *.googlesyndication.com *.googletagmanager.com *.doubleclick.net *.google 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.gstatic.com maps.googleapis.com accounts.google.com https://googleads.g.doubleclick.net https://www.google.com.ar https://www.google.com.do https://www.googletagmanager.com https://www.m.casacuesta.com https://connect.facebook.net logo.flixfacts.co.uk https://widgets.magentocommerce.com/ https://media.flixcar.com/ *.flix360.com notifications-icommkt.website *.googlesyndication.com *.zdassets.com/ekr/snippet.js *.googletagmanager.com *.simpleanalyticscdn.com *.flixcar.com *.ocularsolution.com *.amazonaws.com *.syndigo.cloud *.baidu.com *.cloudfront.net *.syndigo.com *.google data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com/ *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net commerce.adobe.net unpkg.com commerce.adobedtm.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.hotjar.com *.hotjar.io https://static.hotjar.com/c/hotjar- https://static.hotjar.com https://script.hotjar.com https://www.google-analytics.com https://www.google-analytics.com/u/analytics_debug.js https://stats.g.doubleclick.net http://www.google.com/recaptcha/api.js https://static.zdassets.com/ https://d12zyq17vm1xwx.cloudfront.net/v2/wpn.min.js https://static.cloudflareinsights.com/ https://externalassets.icommarketing.com/icomMkt_tracking_jquery.min.js intent://arvr.google.com https://static.addtoany.com/menu/page.js https://static.addtoany.com/ https://static.zdassets.com/ekr/snippet.js *.flixfacts.com/ *.flixcar.com/ https://media.flixfacts.com/js/loader.js https://media.flixcar.com/delivery/static/tracking/tracking.js https://samsungxr.s3.amazonaws.com/js/ar_casacuesta.js https://cdn.jsdelivr.net/gh/Wruczek/Bootstrap-Cookie-Alert@gh-pages/cookiealert.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/1AZgzF1o3OlP73CVr69UmL65/recaptcha__es.js *.googlesyndication.com *.googletagmanager.com *.singular.net *.icommkt.online *.syndigo.com *.flixfacts.com *.ocularsolution.com *.syndigo.cloud *.zdassets.com *.zopim.com *.flix360.io *.adobedtm.com *.google/sodar/sodar2.js *.gbqofs.com *.gbqofs.io *.doubleclick.net *.gbss.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://media.flixfacts.com/ https://media.flixcar.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.youtube.com https://static.zdassets.com/ https://media.flixcar.com/ https://media.flixfacts.com/ https://media.flixsyndication.net/ https://assets-jpcust.jwpsrv.com/ https://ssl.p.jwpcdn.com/ *.cloudfront.net/ https://d3nkfb7815bs43.cloudfront.net/ https://d2m3ikv8mpgiy8.cloudfront.net/ https://media.pointandplace.com/ https://player.pointandplace.com/ https://t.pointandplace.com/ *.pointandplace.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net vimeo.com api.magento.com commerce.adobedtm.com commerce.adobedc.net commerce.adobe.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.comapi.com bam.nr-data.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.hotjar.com *.hotjar.io https://www.google-analytics.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ http://ccnecommerce.com/ https://notifications-icommkt.com/ https://track-icommkt.com/ https://casacuesta.zendesk.com/ https://ekr.zdassets.com/ wss://widget-mediator.zopim.com/ *.youtube.com https://prod.flixgvid.flix360.io https://t.flix360.com https://syndication.flix360.com *.flix360.com *.amazonaws.com *.flixcar.com *.googlesyndication.com *.syndigo.com *.ocularsolution.com *.simpleanalitycscdn.com *.casacuesta.com *.simpleanalyticscdn.com *.singular.net *.baidu.com *.google *.gbqofs.io *.gstatic.com *.google.com.do/ads/ga-audiences wss://ws.hotjar.com/api/v2/client/ws *.doubleclick.net *.syndigo.cloud *.googleapis.com *.gbss.io *.gbqofs.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net https://fonts.gstatic.com data: *.klevu.com *.flixcar.com *.flixfacts.com https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.klarna.com *.klevu.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://briqpay.test *.briqpay.com *.klarna.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.hotjar.com *.klarnaservices.com *.ingrid.com *.klarnaevt.com *.dibspayment.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adnxs.com *.omtrdc.net *.bing.com *.cloudflare.com *.cookiebot.com *.elongroup.se *.elon.se elon.se *.facebook.com *.googleadservices.com *.google-analytics.com *.google.se *.googletagmanager.com *.googleapis.com *.imbox.io *.klevu.com *.klarnaservices.com *.vaimo.net *.ytimg.com *.pricerunner.se *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.jwpsrv.com *.jwplayer.com *.uc.se *.prisjakt.no *.googlesyndication.com *.where-to-buy.co *.clarity.ms *.doubleclick.net *.dialogtrail.com *.lemonpi.io *.facebook.net *.reddit.com *.elon.no *.wistia.com *.videoly.co https://where-to-buy.co https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://briqpay.test *.briqpay.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adnxs.com *.bing.com *.clarity.ms *.cookiebot.com *.depict.ai *.elongroup.se *.facebook.net *.googletagmanager.com *.googleapis.com *.hotjar.com *.imbox.io *.klevu.com *.myvisitors.se *.oribi.io *.pertento.ai *.pinimg.com *.pinterest.com *.testfreaks.com *.charpstar.net *.flixfacts.com *.loadbee.com *.flix360.io *.flixcar.com *.unpkg.com *.dialogtrail.com *.adform.net *.elon.se *.cloudfront.net *.videoly.co *.scaleflex.it *.redditstatic.com *.voyado.com https://unpkg.com https://bf-content.elon.se https://c.bannerflow.net *.ingrid.com *.klarnaevt.com https://www.elon.se 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com *.depict.ai *.dibspayment.eu *.googleapis.com *.gstatic.com *.klevu.com *.flixcar.com https://www.elon.se 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.flixcar.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.adnxs.com *.demdex.net *.clarity.ms *.cookiebot.com *.depict.ai *.dibspayment.eu *.google-analytics.com *.g.doubleclick.net *.hotjar.com *.hotjar.io *.klarnauserservices.com *.ksearchnet.com *.pertento.ai *.pinterest.com security-hub.vaimo.network *.apptus.cloud *.iconify.design *.dialogtrail.com *.flix360.io *.charpstar.net *.loadbee.com *.flixcar.com *.googlesyndication.com *.elon.no *.bing.com *.facebook.com *.reddit.com *.unisvg.com wss://ws.depict.ai wss://headless.dialogtrail.com https://bf-content.elon.se https://c.bannerflow.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-DpJEHqiZDBrFwlmwmWeetg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; frame-src https://www.googletagmanager.com; 1 report-to slardar-endpoint; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=wukong_home_page; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' data: blob: 'nonce-5b3c7ae981d542f6f3ea998e2836d6ad-argus' 'strict-dynamic' https:; 1 default-src 'self' https://*.zorgdomein.nl; style-src 'self' 'unsafe-inline' https://*.zorgdomein.nl https://fonts.googleapis.com https://*.wootric.com https://*.wootric.eu; script-src 'self' 'nonce-85afd073b8a61b5a1f7edeb82eb965c7' https://*.zorgdomein.nl https://*.zdassets.com https://*.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com https://*.wootric.com https://*.wootric.eu https://*.googleapis.com; img-src https://* 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data:; connect-src https://*.zorgdomein.nl wss://*.zorgdomein.nl https://*.zdassets.com https://*.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com https://*.googleapis.com *.google.com https://*.gstatic.com https://*.wootric.com https://*.wootric.eu; frame-src 'self' https://*.zorgdomein.nl https://*.quicksight.aws.amazon.com *.google.com http: https:; report-uri /api/v1/report-uri; font-src 'self' https://*.zorgdomein.nl https://fonts.gstatic.com data:; base-uri 'self'; report-to csp-endpoint 1 object-src 'none';base-uri 'self';script-src 'nonce-hjrtvBkE4XBgsyee_7NQUQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/maps-tactile 1 connect-src 'self' https://status.netservicesgroup.com https://www.google-analytics.com; default-src 'self' http://www.techadvisory.org https://maps.googleapis.com https://csi.gstatic.com https://maps.gstatic.com https://helpdesk.netservicesgroup.com:80; img-src 'self' http://www.internettrafficreport.com https://csi.gstatic.com https://maps.googleapis.com https://maps.gstatic.com http://www.techadvisory.org https://www.netservicesgroup.com http://graphs.ntppool.net http://www.pool.ntp.org https://www.google-analytics.com https://secure.trust-provider.com http://www.trustlogo.com/; frame-src https://www.google.com https://status.netservicesgroup.com; child-src https://status.netservicesgroup.com https://www.google.com https://helpdesk.netservicesgroup.com http://openspeedtest.com https://urldefense.proofpoint.com https://quickclick.com; style-src 'self' https://www.netservicesgroup.com https://status.netservicesgroup.com 'sha256-zL+zKXgt2515GaHwEfkV8QPRfZZcGr/ibUw4EJ3V13s=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-Pkt8j98M46glrPDzrqR9I9gac/h2nvberIdQkhIGySk=' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://secure.trust-provider.com 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc=' https://secure.comodo.com; script-src 'self' https://www.google.com https://www.gstatic.com https://secure.trust-provider.com http://www.trustlogo.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.netservicesgroup.com https://ajax.googleapis.com https://oss.maxcdn.com https://ssl.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://status.netservicesgroup.com https://secure.comodo.com 'sha256-3ocR7726kV2Y3awnQx4u408K1Dxd7l3X9nvrC91J15k=' 'sha256-YG4fTNWYCHAm4AVC2mnK8Tj09alaJWJTk+LJy+5kHho=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc=' 'sha256-/LNrhX3k9yooaUcjJ9wGqDoSJEFQEozZc8jtdbq+lMg=' 'sha256-ahfvWH65y6WEYvXXrsReZDD9l5f9wMFjeLjl+8hkRIg=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc='; font-src 'self' https://www.netservicesgroup.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; report-uri https://www.netservicesgroup.com/csp.php 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.googlesyndication.com https://*.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://tpc.googlesyndication.com https://www.googletagmanager.com https://www.google-analytics.com https://*.google.com https://adservice.google.com https://adservice.google.co.uk https://challenges.cloudflare.com https://www.gstatic.com https://www.recaptcha.net https://static.cloudflareinsights.com https://*.adtrafficquality.google; connect-src 'self' https:; img-src 'self' data: blob: https:; frame-src 'self' https://*.doubleclick.net https://*.googlesyndication.com https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://fundingchoicesmessages.google.com https://*.google.com https://www.gstatic.com https://www.recaptcha.net https://challenges.cloudflare.com https://*.adtrafficquality.google; style-src 'self' 'unsafe-inline' https:; font-src 'self' data: https:; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requests; 1 base-uri 'self'; default-src 'self' https: wss: ws:; script-src 'self' 'unsafe-eval' https://cdn.jsdelivr.net/npm/cross-storage@1.0.0/dist/hub.min.js https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://*.services.atlassian.com https://code.jquery.com/jquery-3.6.0.min.js https://remote-app-switcher.stg-east.frontend.public.atl-paas.net https://translate.googleapis.com/_/translate_http/_/js/ https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js https://js.intercomcdn.com https://widget.intercom.io/widget/ https://www.gstatic.com/recaptcha/releases/ https://www.google.com/recaptcha/ https://js.stripe.com https://meet.jit.si https://bam.nr-data.net 'sha256-u8Qc9T1x0D5Z/CHTQ498yO/+i2ySExBMOwf4RL2t4WI=' 'sha256-FV4wGfcn2NrqSJwtGQUWZ2Ie5XrIVKqtnc6g2gmRRco=' 'sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw=' 'sha256-N6H1UNp6u4dhUx+FZUQMMcXz17KIEWQw+ZVCPp4d3Zo=' 'sha256-qyYeb40S0YW7zrzwvSX5SEThkjXxwfWSwDp+FlCY0ic=' 'sha256-XHhqFY/vlAF49XCJL4Eg+ttSAnGAobln30utBWOcPhU=' 'sha256-L8u6aiCFdh23FnTLOjO9T7p6zkSJPTaOzZoZUz9OnVQ=' 'sha256-ZMCyrJrkz95Pmv4GzcpT7uihWvUib4x2CFIKGfMsuYU=' 'sha256-ffGUIypjdVM8v7ybOzYmI52fKI8S9IVsUI1OqyrUw8Q=' 'sha256-4qVpzn2Bx0qK9KtIsF/n3VVomtjXD/qPqKpKFNRrMWY=' 'sha256-eETIIu3VZ7EA7inGoTk/IDe2GZACdmowaBuJOhm6Bik=' 'nonce-c0a64ca8a9524e4abcc59b2734db936d'; style-src 'self' 'unsafe-inline' https://*.opsgeni.us https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://fonts.googleapis.com/css2 data:; img-src 'self' data: https:; font-src 'self' https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://fonts.intercomcdn.com https://fonts.gstatic.com data:; frame-ancestors 'self' https://*.app.opsgeni.us https://*.opsgeni.us https://*.atlassian.net chrome-extension://dmjofbngkpnmmiccjhikngiodkbofnpc chrome-extension://deejhllflojhohbeechaicbcofamcbkp; form-action 'self'; report-uri https://web-security-reports.services.atlassian.com/csp-report/og-frontend; report-to csp-default-endpoint; connect-src 'self' https: wss: ws:; object-src 'none'; frame-src 'self' https://*.opsgeni.us https://intercom-sheets.com https://*.atlassian.com https://*.opsgenie.com https://js.stripe.com https://reporting.opsgenie.com https://www.google.com 1 default-src 'self' *.ponycanyon.co.jp; font-src 'self' *.ponycanyon.co.jp fonts.gstatic.com data:; form-action 'self' *.ponycanyon.co.jp; worker-src 'self' blob: *.ponycanyon.co.jp cdnjs.cloudflare.com; connect-src 'self' *.ponycanyon.co.jp *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com www.google.co.jp *.clarity.ms; frame-src 'self' *.ponycanyon.co.jp www.youtube.com td.doubleclick.net www.googletagmanager.com open.spotify.com embed-cdn.spotifycdn.com; img-src *; media-src 'self' blob: *.ponycanyon.co.jp; script-src 'self' 'unsafe-inline' *.ponycanyon.co.jp ajax.aspnetcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googletagmanager.com *.google.com www.google-analytics.com ad.jp.ap.valuecommerce.com *.clarity.ms embed-cdn.spotifycdn.com; style-src 'self' 'unsafe-inline' *.ponycanyon.co.jp cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com; report-uri https://csp-log.ponycanyon.co.jp/; 1 default-src *.pharm24.gr *.skroutz.gr static.zdassets.com data:; frame-src *.pharm24.gr virtual-assistants.gr *.googletagmanager.com *.skroutz.gr *.hotjar.com *.checkout.com *.dco.gr *.disqus.com *.linkwi.se *.adsrvr.org *.google.com *.googlesyndication.com *.agkn.com *.facebook.net *.facebook.com *.youtube.com *.cookiebot.com *.aimtell.com; img-src * data: *.pharm24.gr *.youtube.com *.facebook.com trustmark.gr; script-src 'self' 'unsafe-inline' *.pharm24.gr *.skroutz.gr *.google.com *.debugbear.com virtual-assistants.gr secure.dcomodo.net *.vc-portal.com *.skroutz.gr *.gstatic.com *.checkout.com salesmanago.com *.salesmanago.com *.saleago.com bat.bing.com *.clarity.ms *.adman.gr *.hotjar.com *.googleapis.com *.google.com *.cloudflareinsights.com *.cloudflare.com *.disquscdn.com *.shareaholic.com *.shareaholic.net *.stackpathcdn.com *.cloudfront.net *.adsrvr.org *.instagram.com *.ampproject.org *.googlesyndication.com *.disqus.com *.cookiebot.com trustmark.gr *.agkn.com *.zdassets.com *.trustmark.gr *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.facebook.com connect.facebook.net *.facebook.net googleads.g.doubleclick.net *.doubleclick.net *.zopim.com *.linkwi.se s3.amazonaws.com *.amazonaws.com *.aimtell.com cdn-cfdnp.nitrocdn.com 'unsafe-inline' 'unsafe-eval' blob: data: gap:; style-src 'self' *.googleapis.com *.pharm24.gr *.vc-portal.com *.bootstrapcdn.com cdn-cfdnp.nitrocdn.com 'unsafe-inline'; worker-src 'self' *.aimtell.com blob: data: gap:; font-src 'self' *.hotjar.com *.stats.pharm24.gr *.pharm24.gr *.vc-portal.com *.gstatic.com *.bootstrapcdn.com *.stackpathcdn.com *.zopim.com cdn-cfdnp.nitrocdn.com data:; connect-src *.debugbear.com google.com *.checkout.com *.cookiebot.com *.zendesk.com *.saleago.com *.salesmanago.com *.salesmanago.pl *.getnitropack.com *.adman.gr *.hotjar.com *.googlesyndication.com *.trustmark.gr *.ampproject.org *.google.com *.google.gr *.disqus.com *.shareaholic.com *.shareaholic.net backup.pharm24.gr:* *.pharm24.gr *.doubleclick.net *.google-analytics.com *.agkn.com *.zdassets.com *.amazonaws.com *.zopim.com bat.bing.com a.clarity.ms *.facebook.com *.aimtell.com wss://widget-mediator.zopim.com wss://ws6.hotjar.com/api/v2/client/ws 1 img-src slack-imgs-mil-dev.com https://content.vistana.com https://*.2o7.net https://stats.g.doubleclick.net https://img.youtube.com https://payments.salesforce.com/icons/ https://www.vistana.com https://privacy-portal-mvwc.my.onetrust.com https://login.salesforce.com/icons/ https://tmvcaboundhotels.hts.hopper.com *.marriottvacationclub.com *.slack-edge-gov.com https://c.az.contentsquare.net https://placekitten.com https://assets.adobedtm.com https://api.securedvisit.com *.cloudinary.com https://*.contentsquare.com https://videos.marriottvacations.com https://dpm.demdex.net *.amazonaws.com *.google-analytics.com *.siteintercept.qualtrics.com *.google.com https://mvcomdev1-mvw.cs200.force.com https://*.analytics.google.com https://sso.mvwc.com https://pagead2.googlesyndication.com https://www.paypal.com https://content.securedvisit.com https://content-qa-vistana.com https://*.omtrdc.net slack-imgs-gov.com https://siteintercept.qualtrics.com *.salesforce-experience.com https://mvwvo--exppod2--c.sandbox.vf.force.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://smetrics.marriottvacationclub.com slack-mil-dev.com *.clicktale.net https://www.gstatic.com/recaptcha/ https://geolocation.onetrust.com https://*.demdex.net https://mordev.112.2o7.net https://www.google.com/recaptcha/ https://bat.bing.com *.slack-edge.mil https://www.sandbox.paypal.com https://unsplash.it https://www.googletagmanager.com https://www.google-analytics.com https://c.la1-c1-ia4.salesforceliveagent.com *.salesforce.com https://*.adyen.com data: *.force.com 'self' https://mvwvo.file.force.com siteintercept.qualtrics.com https://cdn.cookielaw.org https://www.ibm.com https://track.sv.rkdms.com https://www.gstatic.com https://mormarriottvacationsp.112.2o7.net *.my-salesforce.com https://sv.marriottvacationclubs.com https://marriottownershipres.tt.omtrdc.net https://images.securedvisit.com https://analytics.google.com https://track.securedvisit.com blob: *.facebook.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com https://*.pingone.com *.twimg.com https://*.pcdn.co https://voa-reservation.vacationclub.com *.slack.com https://mvwvo.my.salesforce.com https://cm.everesttech.net *.slack-imgs.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://s32171.pcdn.co *.kampyle.com *.doubleclick.net https://privacy-portal-mvwc-cdn.my.onetrust.com https://usa810.sfdc-8tgtt5.salesforce.com/icons/ https://players.brightcove.net https://*.adobe.com https://s20426.pcdn.co https://www.google.co.in https://i.vimeocdn.com https://cdn.tt.omtrdc.net https://*.contentsquare.net slack-imgs.mil; report-to sfdc-csp-ep; report-uri https://mvwvo.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4x000006sQxi&networkId=0DM4x000000dPWp&type=communities 1 default-src 'self'; base-uri 'self'; child-src 'self' blob: *.doubleclick.net *.facebook.com *.google.com *.googlesyndication.com *.vimeo.com connect.facebook.net vimeo.com www.googletagmanager.com; connect-src 'self' 'strict-dynamic' *.acsbapp.com *.analytics.google.com *.bsnteamsports.com *.fancloth.shop *.fontawesome.com *.google.com *.google-analytics.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.nr-data.net *.zdassets.com *.zendesk.com *.zopim.com *.zopim.io acsbapp.com ajax.googleapis.com browser-intake-datadoghq.com cdn.cookielaw.org code.jquery.com dev.visualwebsiteoptimizer.com fonts.googleapis.com fonts.gstatic.com geolocation.onetrust.com privacyportal.onetrust.com settings.luckyorange.net stats.g.doubleclick.net vimeo.com vimeocdn.com www.facebook.com www.ssgecom.com wss://*.hotjar.com wss://in.visitors.live wss://visitors.live wss://widget-mediator.zopim.co https://chat-assets.cdn.gladly.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com https://us-1.gladly.com https://api.us-1.gladly.chat wss://ws.us-1.gladly.chat https://api.smooch.io https://*.config.smooch.io wss://api.smooch.io https://gladly-production.sinter-collect.com https://js.verygoodvault.com https://js2.verygoodvault.com https://st-ea.hiw19909.jscrambler.com https://hiw19909.jscrambler.com https://jscrambler.com; font-src 'self' data: *.bsnteamsports.com *.fancloth.shop *.bootstrapcdn.com *.bsnteamsports.com *.fancloth.shop *.fontawesome.com *.gladly.com *.typekit.net *.zopim.com cdnjs.cloudflare.com fonts.googleapis.com fonts.gstatic.com script.hotjar.com static.zdassets.com; form-action 'self' *.facebook.com *.google.com connect.facebook.net; frame-src 'self' *.paymetric.combid.g.doubleclick.net *.vimeo.com xiecomm.worldpay.com cert-xiecomm.worldpay.com vars.hotjar.com www.google.com www.googletagmanager.com td.doubleclick.net https://js.verygoodvault.com https://js2.verygoodvault.com; img-src 'self' data: blob: *.bsnteamsports.com *.fancloth.shop *.bsnteamsports.com *.bsnsports.com *.google.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.nr-data.net *.zdassets.com *.zdusercontent.com *.zendesk.com *.zopim.com *.zopim.io *.vimeo.com *.vimeocdn.com ajax.googleapis.com cdn.cookielaw.org code.jquery.com dev.visualwebsiteoptimizer.com googleads.g.doubleclick.net imfarm.bsnsports.com pulse.art.bsnsports.com script.hotjar.com ssgsales.com www.facebook.com stats.g.doubleclick.net https://chat-assets.cdn.gladly.com https://media.cdn.gladly.com https://media.smooch.io; media-src *.vimeo.com static.zdassets.com vimeo.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com; object-src 'none'; script-src 'self' 'strict-dynamic' 'unsafe-eval' 'report-sample' https: 'unsafe-inline' 'nonce-eg5Z1JRBSJHvgDREtM8FEg=='; style-src 'self' 'report-sample' 'unsafe-inline' *.bsnteamsports.com *.fancloth.shop *.bootstrapcdn.com *.fontawesome.com *.google.com *.googleapis.com *.typekit.net *.zdassets.com cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com fonts.googleapis.com tagmanager.google.com unpkg.com www.googletagmanager.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com; upgrade-insecure-requests; report-uri https://62e17a85e7a4e344fdd77145.endpoint.csper.io?v=1; worker-src 'self' blob: www.google.com 1 default-src 'self' *.charteredaccountants.ie *.realexpayments.com *.payandshop.com; script-src-elem 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.doubleclick.net * *.cloudflare.com *.fontawesome.com *.jsdelivr.net *.gstatic.com *.googletagmanager.com *.facebook.net *.jquery.com *.cookiebot.com *.googleapis.com; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.digicert.com *.zendesk.com *.zopim.com *.zdassets.com *.youtube.com googleads.g.doubleclick.net *.licdn.com *.google-analytics.com *.cookiebot.com *.fontawesome.com *.jsdelivr.net *.crazyegg.com *.telerikstatic.com *.aspnetcdn.com *.facebook.net *.cloudflare.com *.googleapis.com *.googletagmanager.com *.charteredaccountants.ie *.jquery.com; style-src 'report-sample' 'unsafe-inline' *.bootstrapcdn.com *.jquery.com *.cloudflare.com *.jsdelivr.net *.googleapis.com *.fontawesome.com *.telerikstatic.com *.charteredaccountants.ie; object-src 'none'; base-uri 'self' *.charteredaccountants.ie; connect-src 'self' *.zendesk.com *.zopim.com *.zdassets.com *.google.co.uk *.google.com *.google.ie *.googleadservices.com *.google.co.in *.googletagmanager.com *.fontawesome.com *.charteredaccountants.ie *.cookiebot.com *.google-analytics.com *.crazyegg.com *.doubleclick.net *.facebook.com *.gstatic.com *.licdn.com *.linkedin.com; font-src 'self' data: *.bootstrapcdn.com *.zopim.com *.gstatic.com *.fontawesome.com; frame-src 'self' *.googletagmanager.com *.googleadservices.com *.cookiebot.com *.linkedin.com *.google.com charteredaccountantsireland.mediasite.com *.facebook.com *.youtube.com *.realexpayments.com *.payandshop.com *.charteredaccountants.ie *.doubleclick.net; img-src 'self' data: *.zopim.com *.charteredaccountants.ie *.googletagmanager.com *.googleadservices.com *.google.ie *.linkedin.com *.digicert.com *.facebook.com *.google-analytics.com *.google.co.uk *.google.com *.google.co.in *.doubleclick.net *.cookiebot.com; manifest-src 'self' *.charteredaccountants.ie; media-src 'self' *.zopim.com *.zdassets.com *.charteredaccountants.ie; frame-ancestors 'self' *.linkedin.com *.google.com *.charteredaccountants.ie *.realexpayments.com *.payandshop.com; report-uri https://csp.charteredaccountants.ie/index.php; worker-src blob:; 1 font-src fonts.gstatic.com use.typekit.net cdn.jsdelivr.net cdn.almapay.com *.googleapis.com https://www.gstatic.com data: fonts.googleapis.com https://cdnjs.cloudflare.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.getalma.eu *.almapay.com/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bird.eu *.openstreetmap.org maps.googleapis.com maps.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com cdn.jsdelivr.net *.almapay.com *.googleapis.com https://*.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://polyfill-fastly.io https://browser.sentry-cdn.com sentry.bird.eu *.google.com/ https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.almapay.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com https://*.google.com payments-eu.amazon.com *.paypal.com *.getalma.eu *.almapay.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.ingest.sentry.io sentry.bird.eu https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self';font-src 'self' data: https://fonts.gstatic.com;connect-src 'self' https://brandportal.uponor.com https://*.usercentrics.eu https://*.google.com https://*.googleapis.com https://*.linkedin.com https://*.stackadapt.com https://*.doubleclick.net https://*.teads.tv https://*.clarity.ms https://*.google-analytics.com https://*.adobe.io https://*.hotjar.io wss://*.hotjar.com https://*.bing.com https://uponorna.my.site.com https://*.lumoa.me https://*.sharethis.com https://pixel-config.reddit.com https://www.redditstatic.com https://*.google.ee https://*.google.de https://*.google.cz https://*.google.se https://salesviewer.org https://*.google.fi https://bat.bing.net https://*.facebook.com https://*.google.is https://*.google.pl https://*.google.sk; frame-src https://*.youtube.com https://*.googletagmanager.com https://*.doubleclick.net https://*.force.com https://*.google.com https://*.usercentrics.eu https://*.teads.tv https://*.adobe.com https://*.tfaforms.net https://*.facebook.com https://*.bimsmith.com https://go.eu.uponor.com https://*.transistor.fm https://go.uponor.info https://youtube.com https://locator.maplet.com/ https://uponorna.my.site.com/; script-src 'self' 'nonce-vgv4QFU8TfVxb+uYlUAYTK63HSEDbTR0QEdcM3F6nms=' 'strict-dynamic'; img-src 'self' data: https://brandportal.uponor.com https://*.usercentrics.eu https://*.facebook.com https://*.linkedin.com https://*.teads.tv https://bat.bing.com https://maps.gstatic.com https://*.google.com https://*.doubleclick.net https://d2csxpduxe849s.cloudfront.net https://*.googletagmanager.com https://*.clarity.ms https://img.youtube.com https://*.sharethis.com https://*.uponor.com https://googleapis.com https://*.krxd.net https://*.google.lt https://*.google.hu https://*.google.dk https://alb.reddit.com https://*.google.ca https://*.google.ee https://*.google.de https://*.google.cz https://*.google.se https://*.google.co.uk https://*.google.pt https://*.globenewswire.com https://*.google.pl https://*.google.nl https://*.google.es https://*.google.ba https://cdn.midas-network.com https://*.google.fr https://*.google.si https://*.google.com.uy https://*.google.fi https://*.google.sk https://*.google.co.in https://*.google.no https://*.google.ro; style-src 'self' 'unsafe-inline' https://*.force.com https://*.usercentrics.eu https://*.stackadapt.com https://*.googleapis.com; object-src 'self' https://*.usercentrics.eu;form-action 'self' https://*.uponor.com https://*.tfaforms.net https://*.facebook.com; base-uri 'self'; 1 font-src *.oney.io *.staging.oney.io *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com fonts.gstatic.com https://stackpath.bootstrapcdn.com https://fonts.gstatic.com/ https://akio-25-49.akio.cloud/ *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.fd-recette.net https://akio-25-49.akio.cloud/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.hipay-tpp.com *.hipay.com *.paypal.com *.google.com/ *.googleapis.com *.photoweb.com *.photoweb.es *.contentsquare.net *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://www.googletagmanager.com https://widget.trustpilot.com https://privacy.fnac.phoenix.digitalphoto.group https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com https://gum.criteo.com/ https://www.mainadv.com/ https://tag.perfmaker.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.hipay.com *.google.com *.oney.io *.staging.oney.io magefan.com cm.magefan.com *.facebook.com https://firebasestorage.googleapis.com * https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com photoweb.com *.photoweb.com *.magento.digitalphoto.dev blob: *.contentsquare.net https://akio-25-49.akio.cloud/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.google.com *.oney.io *.staging.oney.io *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com * maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.newrelic.com *.eu01.nr-data.net *.trustpilot.com *.contentsquare.net *.privacy-center.org *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.hipay.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com https://stackpath.bootstrapcdn.com https://fonts.googleapis.com/ https://fonts.google.com https://akio-25-49.akio.cloud/ *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.oney.io *.staging.oney.io *.google-analytics.com https://get.geojs.io *.avada.io maps.googleapis.com *.google.com https://stats.g.doubleclick.net *.eu01.nr-data.net *.contentsquare.net *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://api.privacy-center.org/v1/events https://prompts.maze.co/api/widgets https://sdk.fra-02.braze.eu/api/v3/data/ https://pagead2.googlesyndication.com/ https://jls.photoweb.fr/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://sst.photoweb.fr 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com; 1 img-src *.force.com slack-imgs-mil-dev.com 'self' https://stats.g.doubleclick.net https://gmocloudcommunity.force.com https://b99.yahoo.co.jp https://img.youtube.com https://payments.salesforce.com/icons/ https://login.salesforce.com/icons/ https://www.google.co.jp https://www.domainking.jp https://www.gstatic.com https://www.wadax.ne.jp *.slack-edge-gov.com *.my-salesforce.com https://www.youtube.com https://cache.img.gmo.jp *.cloudinary.com https://www.google.com https://seal.atlas.globalsign.com https://analytics.google.com *.amazonaws.com blob: https://news-tool.gmocloud.com https://altus.gmocloud.com slack-imgs.com https://dnsck.gmocloud.com slack-gov-dev.com *.sfdcstatic.com *.twimg.com https://faq.wadax.ne.jp https://news.gmocloud.com *.slack.com https://www.paypal.com https://translation.googleapis.com *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://icl.dns.ishioka.xyz *.salesforce-experience.com https://gmogshd-ch.file.force.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://jpn160.sfdc-p1i6qd.salesforce.com/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://support.gmocloud.com https://i.vimeocdn.com https://gmogshd-ch.my.salesforce.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://www.rapidsite.jp https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://gmogshd-ch.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D10000000Hq6P&networkId=0DM5F00000001rL&type=communities 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.googleapis.com https://static.klaviyo.com https://klaviyo.com *.fontawesome.com https://fonts.bunny.net https://d1cwup7r903a1d.cloudfront.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com https://static.klaviyo.com https://klaviyo.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * gstatic.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ https://images.unsplash.com *.googleapis.com https://*.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://klaviyo.com https://www.google.co.in https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://analytics.google.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.sezzle.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net https://maps.googleapis.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://klaviyo.com https://cdn-cookieyes.com *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com gstatic.com cdn.routeapp.io https//fonts.googleapis.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com https://static.klaviyo.com https://klaviyo.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net fonts.cdnfonts.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://klaviyo.com https://log.cookieyes.com https://cdn-cookieyes.com https://api.lab.amplitude.com https://api.amplitude.com https://region1.amplitude.com https://region2.amplitude.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com gstatic.com api.route.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' wss://*.fieldlevel.com:4000 https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com https://*.litix.io https://*.mux.com https://api.mapbox.com https://events.mapbox.com;font-src 'self' https://js.intercomcdn.com https://fonts.intercomcdn.com; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=KrJmDacbDX7_Q5Yg6xVRZvzV3ZYjZv_2vjlOP8CI-6TjxcSijqvKPu91VeZg5dzjIvg=&policy_id=71&user_id=&request_id=c2402618-f331-424e-b309-85d9d4a57d05; report-to csp-endpoint-krjmdacbdxqygxvrzvzvzyjzvvjlopcitjxcsijqvkpuvezgdzjivg; frame-ancestors 'none' 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://*.klarnacdn.net https://fonts.gstatic.com https://fonts.gstatic.com/s/lato/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.klarna.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.avis-verifies.com https://*.criteo.com https://*.facebook.com https://widgets.rr.skeepers.io sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.quirumed.com https://www.quirumed.com https://*.onetrust.com https://*.google.es https://*.facebook.com https://*.media.net https://*.outbrain.com https://*.rubiconproject.com https://*.sharethrough.com https://*.smartadserver.com https://*.taboola.com https://*.teads.tv https://*.3lift.com https://*.adform.net https://*.omnitagjs.com https://*.casalemedia.com https://*.criteo.com https://www.sync-criteo.ads.yieldmo.com https://id5-sync.com https://www.id5-sync.com https://*.ivitrack.com https://*.mediavine.com https://*.pubmatic.com https://*.tremorhub.com https://*.yieldlab.net https://*.bidswitch.net https://*.doubleclick.net https://*.adnxs.net https://*.ib.adnxs.com https://www.ib.adnxs.com https://*.secure.adnxs.com https://secure.adnxs.com https://*.360yield.com https://*.krxd.net https://*.thebrighttag.com https://*.bing.com https://*.ups.analytics.yahoo.com https://www.ups.analytics.yahoo.com https://ib.adnxs.com https://jadserve.postrelease.com https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://sync.targeting.unrulymedia.com https://c.clarity.ms https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://aa.agkn.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://*.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://*.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.klarna.com *.klarnacdn.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.doofinder.com https://*.avis-verifies.com https://*.googlesyndication.com https://*.onetrust.com https://*.criteo.net https://*.criteo.com https://*.facebook.net https://*.googleoptimize.com https://*.datadome.co https://*.bing.com https://*.newrelic.com https://*.retailrocket.net https://*.nr-data.net https://*.quirumed.com https://*.bolt.com https://*.commerce-quick-checkout.com https://*.clarity.ms https://*.google.com https://*.googleadservices.com https://*.google-analytics.com https://*.googletagmanager.com https://*.paypal.com https://*.sandbox.paypal.com https://*.paypalobjects.com https://*.t.paypal.com https://*.s.ytimg.com https://live.sequracdn.com https://assets.adobedtm.com https://geostag.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://unpkg.com https://cdn.noibu.com https://*.klarnaservices.com https://*.klarna.com https://js.klarna.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.sgmtfy.com/* https://cdn.sgmntfy.com https://*.cloudflare.com https://*.cloudflare.com/* https://cdnjs.cloudflare.com/* https://widgets.rr.skeepers.io https://client.rum.us-east-1.amazonaws.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://*.retailrocket.net https://*.klarnacdn.net https://*.cloudflare.com https://*.cloudflare.com/* https://cdnjs.cloudflare.com/* https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.sgmtfy.com/* https://cdn.sgmntfy.com https://fonts.googleapis.com/* https://fonts.googleapis.com/css https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.klarnacdn.net *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.doofinder.com https://*.avis-verifies.com https://*.googlesyndication.com https://*.onetrust.com https://*.google-analytics.com https://*.google.com https://*.doubleclick.net https://*.retailrocket.net https://*.nr-data.net https://*.datadome.co https://*.google.es https://www.google.es https://www.google.com https://*.bing.com https://*.newrelic.com https://*.cardinalcommerce.com https://*.paypal.com https://*.braintree-api.com https://*.client-analytics.sandbox.braintreegateway.com https://*.client-analytics.braintreegateway.com https://api.sandbox.braintreegateway.com https://api.braintreegateway.com https://t.clarity.ms https://input.noibu.com https://*.noibu.com https://cdn.noibu.com wss://input.noibu.com https://measurement-api.criteo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.klarnaservices.com https://evt-eu.playground.klarnaservices.com https://widgets.rr.skeepers.io https://bat.bing.com https://api-product-reviews.cxr.skeepers.io sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: cdn.privacy-mgmt.com maps.googleapis.com www.news.co.uk uk-script.dotmetrics.net *.google-analytics.com *.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com cdn.privacy-mgmt.com *.tiqcdn.com unpkg.com uk-script.dotmetrics.net *.scorecardresearch.com *.google-analytics.com *.googletagmanager.com *.brightcove.com; style-src 'self' 'unsafe-inline' data: use.fontawesome.com fonts.googleapis.com use.typekit.net maps.google.com unpkg.com; img-src 'self' data: *.googleapis.com *.gstatic.com *.google-analytics.com *.scorecardresearch.com *.news.co.uk www.news.co.uk *.dotmetrics.net newsuk.s3.amazonaws.com *.google.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com; font-src 'self' data: fonts.gstatic.com; frame-src 'self' *.youtube.com *.vimeo.com *.brightcove.com cdn.privacy-mgmt.com; 1 font-src *.typekit.net https://app.feetai.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net www.jakeshoes.co.uk data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.jakeshoes.co.uk 'self' 'unsafe-inline'; frame-ancestors www.jakeshoes.co.uk 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.jakeshoes.co.uk 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.google.co.uk *.facebook.com *.placeholder.com placehold.it *.jakeshoes.co.uk *.googleapis.com https://sizewise.cloud https://cdn.prod.website-files.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com www.jakeshoes.co.uk data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.hotjar.com *.facebook.net *.mailchimp.com https://sizewise.cloud https://app.sizewise.cloud https://unpkg.com https://cdn.jsdelivr.net https://app.feetai.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.google.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com www.jakeshoes.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com *.typekit.net https://app.sizewise.cloud widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com tagmanager.google.com www.jakeshoes.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.jakeshoes.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doubleclick.net *.hotjar.io *.googleapis.com *.mailchimp.com *.intuit.com *.amazonaws.com https://sizewise.cloud https://app.sizewise.cloud widget.freshworks.com m2epro.freshdesk.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com www.jakeshoes.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.jakeshoes.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.jakeshoes.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://portal.envisagedigital.co.uk/api/website/hpvyxowvuq/report-uri; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.addressfinder.io *.adsrvr.org *.creativecdn.com gum.criteo.com *.doubleclick.net *.ezy-way.online www.facebook.com *.flowpaper.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net lowes.api.useinsider.com *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.ddlnk.net www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.addressfinder.io *.bing.com *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online www.facebook.com *.freshchat.com *.google.com.au *.google.co.nz *.googletagmanager.com *.google.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.reddit.com *.statsigapi.net *.stripe.com *.trackedweb.net *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.addressfinder.io https://rum.hlx.page *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com https://cdn.searchspring.net/intellisuggest/is.min.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adsrvr.org *.amazonaws.com *.bing.com *.creativecdn.com *.criteo.com *.ezy-way.online www.facebook.com *.freshchat.com *.freshworksapi.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.redditstatic.com *.searchspring.io *.tiktok.com *.useinsider.com connect.facebook.net graph.facebook.com business.facebook.com https://www.lowes.com.au 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.addressfinder.io webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net assets.braintreegateway.com *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online *.facebook.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.google.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypal.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net *.useinsider.com *.vimeo.com *.youtube.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.addressfinder.io *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online *.facebook.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.google.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypal.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net *.vimeo.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.addressfinder.io *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net *.freshrelevance.com wss://*.freshrelevance.com wss://*.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com https://beacon.searchspring.io/beacon api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.aimtell.io *.creativecdn.com *.criteo.com *.doubleclick.net *.ezy-way.online www.facebook.com *.flowpaper.com *.freshchat.com *.google.com.au *.google.co.nz *.googletagmanager.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.paypalobjects.com *.pxf.io *.reddit.com *.redditstatic.com *.statsigapi.net *.stripe.com *.typekit.net *.useinsider.com *.youtube.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.bing.com *.creativecdn.com *.criteo.net *.ezy-way.online *.google.com *.google.com.au *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.nr-data.net *.searchspring.io self *.tiktok.com *.trackedweb.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' blob: data: https://cdn.dsspn.com/trk/pix.js https://*.google.com https://*.geetest.com https://*.geevisit.com https://www.googletagmanager.com https://appleid.cdn-apple.com https://vk.com https://analytics.tiktok.com https://connect.facebook.net https://*.google-analytics.com https://telegram.org https://*.ada.support https://widget-mediator.zopim.com https://*.coincatch.com https://*.coincatch.cc https://*.bgbstatic.com https://*.gdrichem.com https://gateway.test.95516.com https://*.checkout.com https://gateway.95516.com https://www.facebook.com https://*.youtube.com https://dn-staticdown.qbox.me https://megacheck.vip https://*.megacheck.vip https://*.saintpay.com https://*.skypay.space https://*.noxiaohao.com https://*.megacheck.net https://megacheck.net https://*.7b7x.com https://7b7x.com https://*.onfido.com https://cdn.builder.io https://www.fedstable.com https://applepay.cdn-apple.com https://*.apple.com https://*.gstatic.com https://*.googleapis.com https://static.zdassets.com https://bat.bing.com https://pagead2.googlesyndication.com https://tpc.googlesyndication.com https://*.hotjar.com https://partner.googleadservices.com https://*.adsrvr.org https://static.ads-twitter.com https://*.glassgs.com https://wcs.naver.net https://*.zendesk.com https://scripts.mediamathrdrt.com; connect-src 'self' 'report-sample' data: blob: https://www.googletagmanager.com https://wa.appsflyer.com https://*.google.com https://*.coincatch.com wss://*.coincatch.com https://*.coincatch.cc wss://*.coincatch.cc https://*.google-analytics.com https://analytics.tiktok.com https://www.facebook.com https://*.analytics.google.com https://*.ada.support wss://*.ada.support https://wa.onelink.me https://widget-mediator.zopim.com wss://widget-mediator.zopim.com https://*.bgbstatic.com https://*.gdrichem.com https://gateway.test.95516.com https://*.checkout.com wss://*.checkout.com https://gateway.95516.com https://telegram.org https://*.youtube.com https://www.tradingview.com https://api.tronstack.io wss://*.gdrichem.com https://megacheck.vip https://*.megacheck.vip wss://megacheck.vip wss://*.megacheck.vip https://*.megacheck.net wss://*.megacheck.net https://megacheck.net wss://megacheck.net https://*.saintpay.com wss://*.saintpay.com https://*.skypay.space wss://*.skypay.space https://*.noxiaohao.com wss://*.noxiaohao.com https://*.gdrichem.com:8443 https://*.omkbic.com:8443 https://dn-staticdown.qbox.me https://*.7b7x.com https://7b7x.com wss://*.7b7x.com wss://7b7x.com https://*.onfido.com wss://*.onfido.com https://cdn.builder.io https://www.fedstable.com wss://www.fedstable.com wss://stream.fedstable.com https://*.coincatch.com https://*.geetest.com https://*.geevisit.com https://*.zendesk.com wss://*.zendesk.com https://ekr.zdassets.com https://static.zdassets.com https://bat.bing.com https://pagead2.googlesyndication.com https://tpc.googlesyndication.com https://*.hotjar.com wss://*.hotjar.com https://connect.facebook.net https://analytics.pangle-ads.com https://partner.googleadservices.com https://*.gstatic.com https://*.gurenla.com https://*.glassgs.com wss://*.glassgs.com https://*.adsrvr.org https://wcs.naver.net https://wcs.naver.com https://static.ads-twitter.com https://scripts.mediamathrdrt.com; frame-src 'self' 'report-sample' blob: data: https://scripts.mediamathrdrt.com https://*.coincatch.com https://*.coincatch.cc https://*.google.com https://*.bgbstatic.com https://www.facebook.com https://oauth.telegram.org https://telegram.org https://*.checkout.com https://*.ada.support https://*.youtube.com https://www.googletagmanager.com https://gateway.95516.com https://widget-mediator.zopim.com https://*.gdrichem.com https://gateway.test.95516.com https://*.google-analytics.com https://megacheck.vip https://*.megacheck.vip https://*.saintpay.com https://*.skypay.space https://*.noxiaohao.com https://*.megacheck.net https://megacheck.net https://*.7b7x.com https://7b7x.com https://*.onfido.com https://tpc.googlesyndication.com https://*.glassgs.com https://*.adsrvr.org https://*.adsrvr.cn; frame-ancestors 'self'; report-uri https://65266bb9a5a15fa1ff36a6b6.endpoint.csper.io?v=8; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.authorize.net *.google.com cdnjs.cloudflare.com cdn.rawgit.com maps.googleapis.com rw1.marchex.io connect.facebook.net googleads.g.doubleclick.net *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com cdn.jsdelivr.net *.youtube.com *.vimeo.com s.ytimg.com *.googlesyndication.com *.hotjar.com unpkg.com *.googleapis.com investors.danaher.com cdn.cookielaw.org *.onetrust.com *.marketingcloudfx.com *.leadmanagerfx.com *.usefathom.com *.decibelinsight.net *.decibel.com *.medallia.com; object-src *.oembed.com *.vimeo.com *.youtube.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com *.gstatic.com *.typekit.net *.jsdelivr.net maxcdn.bootstrapcdn.com investors.danaher.com *.onetrust.com; img-src 'self' 'unsafe-inline' data: maps.googleapis.com px.marchex.io *.facebook.com *.google.com *.gstatic.com cdn.rawgit.com raw.githubusercontent.com *.g.doubleclick.net *.google-analytics.com *.googletagmanager.com zensource-salisbury.s3.amazonaws.com chat.mcsoftware.com *.timevaluecalculators.com *.ytimg.com cdn.cookielaw.org *.vimeocdn.com *.usefathom.com; media-src *.vimeo.com *.youtube.com *.spotify.com *.vimeocdn.com 'self'; frame-src 'self' 'unsafe-inline' *.doubleclick.net *.google.com players.brightcove.net *.youtube.com *.googletagmanager.com vars.hotjar.com *.spotify.com *.vimeo.com player.vimeo.com; font-src data: 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.onetrust.com; connect-src 'self' 'unsafe-inline' *.authorize.net *.facebook.com *.onetrust.com stats.addtoany.com *.google-analytics.com cdn.cookielaw.org *.hotjar.com:* *.hotjar.com:* vc.hotjar.io:* wss://*.hotjar.com stats.g.doubleclick.net *.clarity.ms privacyportal-de.onetrust.com *.marketingcloudfx.com *.leadmanagerfx.com *.decibelinsight.net *.decibel.com *.medallia.com; report-uri /report-csp-violation 1 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; upgrade-insecure-requests; block-all-mixed-content 1 font-src fonts.gstatic.com use.typekit.net apps.bazaarvoice.com script.hotjar.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.punchout2go.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.googletagmanager.com esqa.moneris.com www3.moneris.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com *.punchout2go.com e.bmr.co www.facebook.net www.facebook.com ct.pinterest.com td.doubleclick.net static.addtoany.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net https://axeptio.imgix.net apps-stg.bazaarvoice.com www.bmr.ca *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat static.hotjar.com script.hotjar.com survey.hotjar.com www.facebook.net www.facebook.com cdn.cookielaw.org maps.googleapis.com maps.gstatic.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net *.wishabi.com *.wishabi.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.googletagmanager.com esqa.moneris.com www3.moneris.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.punchout2go.com https://*.axept.io e.bmr.co js-agent.newrelic.com s.pinimg.com ct.pinterest.com static.hotjar.com script.hotjar.com connect.facebook.net connect.facebook.com plausible.io cdn.cookielaw.org maps.googleapis.com www.gstatic.com r2-t.trackedlink.net bam.nr-data.net bam-cell.nr-data.net static.addtoany.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net p.flipp.com cdn-gateflipp.flippback.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com display.ugc.bazaarvoice.com *.punchout2go.com static.hotjar.com script.hotjar.com cdn.cookielaw.org www.gstatic.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.gstatic.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.axept.io https://*.axeptio.eu https://*.axeptio.techimg-src https://axeptio.imgix.net network-a.bazaarvoice.com network-stg-a.bazaarvoice.com apps-stg.bazaarvoice.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.hotjar.com wss://*.hotjar.com *.hotjar.io www.facebook.com ct.pinterest.com plausible.io cdn.cookielaw.org maps.googleapis.com stats.g.doubleclick.net bam.nr-data.net bam-cell.nr-data.net aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net p.flipp.com cdn-gateflipp.flippback.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a4825dc4-e033-47b9-830c-751e434948c6.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-uri https://14edc0c0-b3cc-497c-8aa2-2e84efa49370.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; base-uri 'self'; font-src 'self' https: data:; img-src 'self' data: https:; object-src 'none'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; manifest-src https://s3.amazonaws.com/galore-assets/manifest.json; frame-src 'self' https://js.stripe.com https://www.recaptcha.net/ https://www.facebook.com/ https://bid.g.doubleclick.net; frame-ancestors 'self' https://www.care.com/ https://getgalore.com/; script-src 'self' https: 'unsafe-inline' http://cdn.mxpnl.com/libs/mixpanel-2.2.min.js http://connect.facebook.net/en_US/sdk.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/en_US/sdk.js; upgrade-insecure-requests; report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=galore-mfe@v18.257.0&sentry_environment=prod 1 font-src https://fonts.gstatic.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnaservices.com *.klarnacdn.net *.klarna.com *.addsauce.com *.fontawesome.com *.bootstrapcdn.com *.funky-buddha.com *.cloudfront.net fonts.googleapis.com skroutza.skroutz.gr data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.vivapayments.com skroutza.skroutz.gr *.modirum.com *.eurocommerce.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.klarna.com *.klarnacdn.net www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: connect.facebook.net graph.facebook.com business.facebook.com *.contactpigeon.com *.bestprice.gr *.googletagmanager.com *.cookiebot.com *.grxchange.gr *.criteo.com *.skroutz.gr skroutza.skroutz.gr https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io maps.googleapis.com maps.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.plenigo.com *.klarnacdn.net *.klarnaservices.com *.klarna.com *.addsauce.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com *.designer-images.net *.bestprice.gr *.visualwebsiteoptimizer.com *.cloudflarestream.com *.rubiconproject.com *.smartadserver.com *.funky-buddha.com *.sharethrough.com *.casalemedia.com *.postrelease.com *.unrulymedia.com *.servenobid.com *.cookiebot.com *.bidswitch.net *.mediavine.com *.omnitagjs.com *.tremorhub.com *.linkedin.com *.outbrain.com *.360yield.com *.pubmatic.com *.yieldlab.net *.ivitrack.com *.taboola.com *.yieldmo.com *.demdex.net *.criteo.com *.google.gr *.3lift.com *.media.net *.adnxs.com *.teads.tv *.bing.com *.glami.gr *.emxdgt.com id5-sync.com trustmark.gr *.1rx.io *.e-satisfaction.com glamipixel.com fonts.googleapis.com skroutza.skroutz.gr blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.playground.klarnaservices.com *.klarnacdn.net *.klarnaservices.com *.klarna.com *.funky-buddha.com *.addsauce.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.vivapayments.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com *.avada.io *.stat-track.com polyfill.io *.moosend.com *.bestprice.gr *.visualwebsiteoptimizer.com *.googleoptimize.com *.googleapis.com *.cookiebot.com *.socital.com *.eyefitu.com *.simpler.so *.skroutz.gr *.hotjar.com *.clarity.ms *.criteo.com *.tiktok.com *.linkwi.se *.licdn.com glamipixel.com *.adman.gr *.bing.com trustmark.gr self data: snapppt.com *.e-satisfaction.com cdn.simpler.so sdk.local.simpler.so skroutza.skroutz.gr https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.klarnacdn.net *.klarna.com *.addsauce.com *.findbar.io *.fontawesome.com *.moosend.com *.bootstrapcdn.com *.bestprice.gr *.contactpigeon.com *.funky-buddha.com *.cloudfront.net *.myfonts.net *.e-satisfaction.com skroutza.skroutz.gr https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.funky-buddha.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.findbar.io blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.playground.klarnaservices.com *.playground.klarnaevt.com *.klarnaservices.com *.addsauce.com *.klarnacdn.net *.klarna.com *.klarnaevt.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com *.googlesyndication.com *.monitor.azure.com *.visualstudio.com *.funky-buddha.com *.googleapis.com *.cookiebot.com *.linkedin.com *.bestprice.gr *.socital.com *.eyefitu.com *.simpler.so *.criteo.com *.clarity.ms *.hotjar.io *.bing.com wss: *.e-satisfaction.com button.simpler.so button.staging.simpler.so analytics.simpler.so analytics.staging.simpler.so button.local.simpler.so fonts.googleapis.com skroutza.skroutz.gr https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src *.contactpigeon.com http: https: blob: 'self' 'unsafe-inline'; default-src *.funky-buddha.com *.clarity.ms *.criteo.net *.google.com *.tiktok.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-fc01db92-765d-459c-9041-5303c727920f' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.se https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.se/eum-collector/report/csp-report; 1 default-src 'self' 'unsafe-inline' *.gardners.com; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.gardners.com *.braintreegateway.com *.cardinalcommerce.com *.gardners.com *.gardners.com/scripts/jquery-3.7.1.min.js *.google-analytics.com *.googletagmanager.com api.os.uk api.whichosmap.co.uk assets.braintreegateway.com code.jquery.com/jquery-migrate-3.5.2.min.js js.braintreegateway.com maps-api-ssl.google.com songbird.cardinalcommerce.com whichosmap.co.uk www.google.com www.gstatic.com www.gstatic.com/recaptcha/releases/p09oe8YIFfKgcnqQ9m9k4aiB/recaptcha__en.js; script-src-elem 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.gardners.com/scripts *.gardners.com/scripts/jquery-3.7.1.min.js *.googletagmanager.com *.paypal.com api.whichosmap.co.uk assets.braintreegateway.com code.jquery.com/jquery-migrate-3.5.2.min.js js.braintreegateway.com maps-api-ssl.google.com songbird.cardinalcommerce.com whichosmap.co.uk www.google-analytics.com www.google.com/recaptcha/api.js www.gstatic.com/recaptcha; style-src 'report-sample' 'self' 'unsafe-inline' *.gardners.com *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk api.whichosmap.co.uk assets.braintreegateway.com stackpath.bootstrapcdn.com whichosmap.co.uk; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk api.whichosmap.co.uk stackpath.bootstrapcdn.com whichosmap.co.uk; style-src-attr 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gardners.com *.braintree-api.com *.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com api.braintreegateway.com api2.smartrecruitonline.com client-analytics.braintreegateway.com maps.googleapis.com translate.googleapis.com; font-src 'report-sample' 'self' 'unsafe-inline' data: *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk fonts.gstatic.com stackpath.bootstrapcdn.com; frame-src 'report-sample' 'self' *.cardinalcommerce.com *.paypal.com api.whichosmap.co.uk assets.braintreegateway.com whichosmap.co.uk www.google.com www.youtube.com; img-src 'report-sample' 'self' blob: data: data: https: *.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.paypal.com *.youtube.com/ api.os.uk api.whichosmap.co.uk assets.braintreegateway.com jackets.dmmserver.com maps-api-ssl.google.com maps.gstatic.com www.googletagmanager.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://67917890e3f085153460661d.endpoint.csper.io?v=4; 1 font-src https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdnjs.cloudflare.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://nominatim.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri *.google.com *.gstatic.com 'self' 'unsafe-inline'; default-src *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; media-src *.google.com *.gstatic.com *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src *.google.com *.gstatic.com 'self' 'unsafe-inline'; child-src *.google.com *.gstatic.com http: https: blob: 'self' 'unsafe-inline'; object-src *.google.com *.gstatic.com 'self' 'unsafe-inline'; style-src *.google.com *.gstatic.com *.doofinder.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; img-src *.google.com *.gstatic.com https://alehop.smartie.io widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com cdn.doofinder.com https://images.unsplash.com *.oct8ne.com *.facebook.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; form-action *.google.com *.gstatic.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; font-src *.google.com *.oct8ne.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com *.storyblok.com 'self'; frame-src td.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.oct8ne.com *.hotjar.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; connect-src *.google.com *.googlesyndication.com analytics.tiktok.com *.analytics.google.com *.gstatic.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; script-src https://analytics.tiktok.com *.google.com *.gstatic.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com cdn.doofinder.com https://maps.googleapis.com *.oct8ne.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self'; img-src 'self' files.booktrust.org.uk; script-src 'self' 'nonce-ZnZ6ZmNodGducXNvaWJseGltcWh6bXB4enJrZHVhamlybWNu' cdn.jsdelivr.net/npm/; style-src 'self' 'unsafe-inline'; connect-src 'self' *.algolia.io *.algolia.net; frame-src 'self' 'nonce-ZnZ6ZmNodGducXNvaWJseGltcWh6bXB4enJrZHVhamlybWNu'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-dHi2M3CYb1Z0oS4jDDuWkg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: 'unsafe-inline' 'unsafe-eval' data:; report-uri https://www0mansion0review0jp.report-uri.com/r/d/csp/reportOnly; 1 font-src *.googleapis.com *.gstatic.com 'unsafe-inline' data: https://cdn.checkout.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net x.klarnacdn.net css.zohocdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.trustpilot.com *.pcapredict.com *.postcodeanywhere.co.uk testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com geostag.cardinalcommerce.com geo.cardinalcommerce.com *.sagepay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com https://js.checkout.com *.klarna.com *.clearpay.co.uk *.trustpilot.com *.pcapredict.com *.postcodeanywhere.co.uk *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com geostag.cardinalcommerce.com geo.cardinalcommerce.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com asp.alliedgoldltd.com *.sagepay.com *.awin1.com *.zenaps.com *.fls.doubleclick.net www.facebook.com www.commercepartnerhub.com www.googletagmanager.com *.weltpixel.com td.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.gstatic.com *.googleapis.com *.afterpay.com *.clearpay.co.uk *.trustpilot.com *.pcapredict.com *.postcodeanywhere.co.uk *.google.com *.google.co.uk www.gstatic.com alliedstorage.blob.core.windows.net *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com *.awin1.com *.zenaps.com www.wepowerconnections.com *.bing.com *.clarity.ms *.thejewelhut.co.uk cdn.flockr.co *.facebook.net osm.klarnaservices.com eu1-files.zohopublic.eu css.zohocdn.com *.facebook.com *.segmentify.com www.google.co.uk *.doubleclick.net data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.checkout.com *.klarnacdn.net *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.trustpilot.com *.pcapredict.com *.postcodeanywhere.co.uk *.google-analytics.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com asp.alliedgoldltd.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnaservices.com house11167.pcapredict.com *.sagepay.com *.avada.io *.shopify.com *.awin1.com www.dwin1.com *.zenaps.com the.sciencebehindecommerce.com cdn.flockr.co static.cloudflareinsights.com ajax.cloudflare.com bat.bing.com *.clarity.ms *.thejewelhut.co.uk apis.google.com js.klarna.com salesiq.zohopublic.eu *.zohocdn.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com cdn.segmentify.com cdn.sgmntfy.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://cdn.checkout.com *.afterpay.com/ *.squarecdn.com *.trustpilot.com *.postcodeanywhere.co.uk widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net cdn.flockr.co x.klarnacdn.net css.zohocdn.com tagmanager.google.com cdn.segmentify.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.bing.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.googleapis.com https://js.checkout.com *.klarnaevt.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.pcapredict.com *.postcodeanywhere.co.uk *.google-analytics.com https://stats.g.doubleclick.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com geostag.cardinalcommerce.com geo.cardinalcommerce.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.klarna.com *.klarnaservices.com services.postcodeanywhere.co.uk *.sagepay.com https://get.geojs.io *.avada.io the.sciencebehindecommerce.com api.flockr.co *.bing.com *.thejewelhut.co.uk google.com pay.google.com *.facebook.com *.clarity.ms js.klarna.com bat.bing.net x.klarnacdn.net eu.klarnaevt.com salesiq.zohopublic.eu wss://vts.zohopublic.eu *.facebook.net gandalf-eu.segmentify.com *.trustpilot.com pagead2.googlesyndication.com *.google.com *.doubleclick.net www.google.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://0ef6f58f-2fe5-4f67-b795-60e7a4c811e4.sansec.watch/; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' *.stripe.com data: *.alicdn.com *.clientgear.com *.pinterest.com *.doubleclick.net *.stripe.com *.googletagmanager.com *.bing.com *.pinimg.com *.taboola.com *.criteo.com *.criteo.net *.facebook.com omnisnippet1.com *.facebook.net *.soundestlink.com *.zdassets.com *.google-analytics.com *.pubmatic.com *.revcontent.com *.sharethrough.com *.smaato.net *.tremorhub.com *.clmbtech.com *.tpmn.co.kr *.vieldmo.com *.emxdgt.com *.bidswitch.net *.adnxs.com *.mediawallahscript.com contextual.media.net *.rubiconproject.com *.samrtadserver.com *.teads.tv *.31ift.com *.yahoo.com *.omnitagjs.com *.casalemedia.com *.stickyadstv.com *.360yield.com *.liadm.com *.tpmn.io *.mediavine.com *.postrelease.com *.outbrain.com *.tapad.com *.tapad.com *.yieldmo.com *.smartadserver.com *.demdex.net 'unsafe-eval' *.sentry.io *.imgdb.cn *.superbed.cn *.3lift.com *.rezync.com *.rfihub.com *.bluekai.com *.pippio.com *.turn.com *.zendesk.com *.google.com *.klaviyo.com *.googleadservices.com *.socdm.com *.adtdp.com *.dable.io *.adingo.jp *.rlcdn.com *.krxd.net *.yahoo.net *.recaptcha.net *.gstatic.com *.fridayparts.com *.tiktok.com *.paypal.com *.mczbf.com *.googleusercontent.com *.paypalobjects.com *.twitter.com *.ads-twitter.com *.omnisendlink.com *.impactcdn.com *.dotomi.com *.emjcd.com *.clarity.ms *.agkn.com *.adgrx.com *.aralego.com *.aralego.net *.targeting.unrulymedia.com *.1rx.io fridayparts.sjv.io *.jeeda.net *.bxtag.com *.youtube.com dev.visualwebsiteoptimizer.com 1 default-src 'self' jhnet.okta.com sso.jhnet.com *.oktacdn.com; connect-src 'self' jhnet.okta.com jhnet-admin.okta.com sso.jhnet.com *.oktacdn.com *.mixpanel.com *.mapbox.com jhnet.kerberos.okta.com jhnet.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' jhnet.okta.com sso.jhnet.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' jhnet.okta.com sso.jhnet.com *.oktacdn.com; frame-src 'self' jhnet.okta.com jhnet-admin.okta.com sso.jhnet.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' jhnet.okta.com sso.jhnet.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' jhnet.okta.com sso.jhnet.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; worker-src 'self' blob:; base-uri 'self'; form-action *; frame-ancestors 'self' 1 default-src 'report-sample' 'self' 'unsafe-inline' data: blob: *.skeb.jp *.imgix.net challenges.cloudflare.com *.pay.jp *.s3.ap-northeast-1.amazonaws.com misskey.io *.misskeyusercontent.jp www.gravatar.com *.twimg.com t.co static.ads-twitter.com analytics.twitter.com analytics.google.com *.gstatic.com *.gstatic.cn fonts.googleapis.com www.googletagmanager.com www.google-analytics.com *.doubleclick.net www.recaptcha.net *.sentry.io *.algolia.net *.algolianet.com cdn.plyr.io *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat;report-to csp-violation-report 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' 'nonce-c2594437-7be4-4590-8c3a-9ef4ffdb3117' *.aaui-879784980514.s3.us-east-2.amazonaws.com *.aauicdnva7.azureedge.net *.adform.net *.app.launchdarkly.com *.awaascicdprodva7.blob.core.windows.net *.d30ln29764hddd.cloudfront.net *.doubleclick.net *.euroland.com *.eurolandir.com *.googletagmanager.com *.jquery.com *.leaddesk.com *.linkedin.com *.omniture.com *.omtrdc.net *.services.adobe.com *.youtube.com http://maps.google.com/maps-api-v3/api/ http://maps.google.com/maps/api/ http://maps.googleapis.com/maps/api/ https://*.aptrinsic.com https://*.flockler.com https://adminconsole.adobe.com https://adobe.com https://adobe.io https://adobe.net https://adobeid-na1.services.adobe.com https://ajax.googleapis.com https://analytics-eu.clickdimensions.com https://api.emea01.idio.episerver.net https://app.powerbi.com https://assets.adobedtm.com https://assets.adobedtm.com https://assets2.adobe.com https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://cdn.cookielaw.org https://cdn.jsdelivr.net/npm/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/ https://cloudui-emea01.profilestore.episerver.net https://connect.facebook.net https://cookie-cdn.cookiepro.com https://d1igp3oop3iho5.cloudfront.net/v2/YTCU__QFgA3N4sqa5K5xQA-eu1/zaius-min.js https://d1igp3oop3iho5.cloudfront.net/v2/buA6R3hGThUwo2b3jMhdjQ-eu1/zaius-min.js https://dl.episerver.net https://fl-cdn.scdn1.secure.raxcdn.com https://geolocation.onetrust.com https://googleads.g.doubleclick.net https://js.monitor.azure.com/scripts/ https://kuula.co https://ld-webchat.s3.eu-north-1.amazonaws.com https://login.microsoftonline.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com/bootstrap/ https://research.innolink.fi https://s.emea01.idio.episerver.net/ https://snap.licdn.com https://sstats.adobe.com https://static.ads-twitter.com https://tpc.googlesyndication.com https://videolle.viewin360.co https://www.google.com https://www.google.com/recaptcha/ https://www.googleadservices.com https://www.gstatic.com/recaptcha/ https://youtube.com https://metsa-virtual-exhibition.netlify.app https://metsa-virtual-exhibition-two.netlify.app https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/ https://*.hotjar.com/ https://cxppeur1rdrect01sa02cdn.blob.core.windows.net/; report-uri https://www.metsagroup.com/api/reporting/; report-to csp-endpoint; 1 object-src 'none'; script-src 'nonce-FJdCFzAo3_STMMtkBpP7bk7q' 'strict-dynamic' http: https:; base-uri 'none'; 1 font-src *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com www.redwolfairsoft.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com airwallex.com *.airwallex.com google.com *.google.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com www.redwolfairsoft.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com www.redwolfairsoft.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com www.google.com www.googletagmanager.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://www.google.com www.redwolfairsoft.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com google.com *.google.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.redwolfairsoft.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ www.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://www.google.com https://www.gstatic.com www.redwolfairsoft.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com www.redwolfairsoft.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.redwolfairsoft.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com thm.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.redwolfairsoft.com 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com www.redwolfairsoft.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com www.redwolfairsoft.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com *.yotpo.com *.userway.org *.klarnacdn.net *.fontawesome.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net *.typeform.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.userway.org *.listrakbi.com magefan.com cm.magefan.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.abtasty.com *.alby.com *.userway.org *.yotpo.com *.cloudfront.net *.listrakbi.com *.gstatic.com *.cloudflare.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.bootstrapcdn.com *.userway.org *.yotpo.com *.listrakbi.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.abtasty.com api.experianaperture.io *.alby.com *.userway.org *.listrakbi.com bam.nr-data.net *.launchdarkly.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src 'self' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com data:;style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com assets.mxapis.com *.cloudfront.net www.gstatic.com;style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com fonts.soundestlink.com www.gstatic.com assets.mxapis.com *.cloudfront.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.hotjar.com *.cloudflare.com *.doubleclick.net static.cloudflareinsights.com *.clarity.ms *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net *.googleapis.com;script-src-elem 'self' 'unsafe-inline' cdn.datatables.net static.cloudflareinsights.com *.clarity.ms *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.cloudflare.com *.doubleclick.net www.youtube.com pagead2.googlesyndication.com *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net;connect-src 'self' https://api.e-menessaptieka.lv *.nordcode.io *.google-analytics.com *.doubleclick.net *.google.com *.cookiebot.com *.bing.com *.googlesyndication.com *.clarity.ms *.facebook.com adservice.google.com graph.facebook.com www.googleadservices.com www.google.com www.google.lt www.google.lv googleadservices.com google.com google.lt google.lv pagead2.googlesyndication.com *.nosto.com *.sentry.io *.googleapis.com *.equalweb.com *.soundestlink.com *.dot.vu ams.creativecdn.com analytics.tiktok.com *.e-menessaptieka.lv *.moonmart.lt *.mxapis.com *.tiktokw.us;frame-src 'self' *.cookiebot.com *.doubleclick.net *.youtube.com accounts.google.com *.ladesk.com live.dot.vu ams.creativecdn.com cdn.mxapis.com;img-src 'self' data: https://api.e-menessaptieka.lv https://images.e-menessaptieka.lv *.klix.app *.cookiebot.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.googletagmanager.com *.google.com *.google.lt *.google.lv *.cloudflare.com *.tawk.to tawk.link *.hotjar.com *.soundestlink.com *.googleapis.com *.gstatic.com *.facebook.com *.youtube.com *.doubleclick.net *.dmxleo.com *.hotjar.com *.bing.com *.adform.net *.criteo.com *.clarity.ms *.demdex.net x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com googleads.g.doubleclick.net omnisnippet1.com csm.fr3.eu.criteo.net id5-sync.com ade.googlesyndication.com *.nosto.com *.appspot.com serve.mxapis.com *.e-menessaptieka.lv *.moonmart.lt www.googleadservices.com *.creativecdn.com static.salidzini.lv ema.ladesk.com;default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://api.e-menessaptieka.lv https://images.e-menessaptieka.lv;report-uri https://api.e-menessaptieka.lv/csp/report 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com 'unsafe-inline' data: *.channelsight.com *.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.snapchat.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.twitter.com s.amazon-adsystem.com *.facebook.com *.doubleclick.net insight.adsrvr.org *.filestackapi.com *.addthis.com flexfaceoffsweeps.azurewebsites.net match.adsrvr.org viewinyourspace.com *.viewinyourspace.com *.myepigraph.com playcanv.as *.snapchat.com *.clinch.co *.pinterest.com https://recaptcha.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.bird.eu *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.bazaarvoice.com *.google.com *.taboola.com *.facebook.com *.facebook.net *.hubspot.com *.hsforms.com r.turn.com *.adnxs.com pixel.mediaiqdigital.com *.gravatar.com *.channelsight.com cscoreproweustor.blob.core.windows.net *.skil.com *.googleapis.com *.doubleclick.net *.seeitinyourspace.com *.pinterest.com *.nextdoor.com *.reddit.com insight.adsrvr.org *.ispot.tv egopowerplus.com *.egopowerplus.com egopowerplus.com.au *.flexpowertools.com pixel.roymorgan.com *.myepigraph.com *.intentiq.com edge.curalate.com *.linkedin.com *.trackedlink.net *.ddlnk.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com datadash.egopowerplus.com datadash.skil.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bazaarvoice.com *.filestackapi.com *.facebook.net *.crazyegg.com js.hs-scripts.com *.taboola.com js.adsrvr.org js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net *.googleapis.com geoip-js.com secure-ds.serving-sys.com *.adnxs.com bs.serving-sys.com *.addthis.com *.addthisedge.com z.moatads.com cscoreproweustor.blob.core.windows.net flexsweepstakes2022.azurewebsites.net js.monitor.azure.com edge.curalate.com ipinfo.io *.tiktok.com sc-static.net *.channelsight.com unpkg.com *.jsdelivr.net viewinyourspace.com *.viewinyourspace.com *.cookielaw.org *.addevent.com *.pinimg.com *.nextdoor.com *.crwdcntrl.com *.crwdcntrl.net mjca-yijws.global.ssl.fastly.net cdn.480app.com cdn.nmgassets.com *.clinch.co *.vimeo.com *.redditstatic.com *.snapchat.com adriano-au.avanser.com *.amazon-adsystem.com *.licdn.com *.pinterest.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://egopowerplus.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bazaarvoice.com cscoreproweustor.blob.core.windows.net *.channelsight.com cdn.jsdelivr.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com api.bazaarvoice.com *.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.twitter.com *.twimg.com *.bazaarvoice.com *.crazyegg.com forms.hubspot.com *.channelsight.com *.doubleclick.net *.taboola.com secure-ds.serving-sys.com viewinyourspace.com *.viewinyourspace.com chervon-website-api.herokuapp.com chervon-website-api-dev.herokuapp.com *.jotform.com dc.services.visualstudio.com *.addthis.com edge.curalate.com geoip-js.com *.hsforms.com *.facebook.com *.tiktok.com *.snapchat.com *.cookielaw.org *.rain-staging.com *.seeitinyourspace.com *.gstatic.com blob: *.googleapis.com *.pinterest.com cdn.nmgassets.com jdl.nmgplatform.com colrep.sitelabweb.com lm.serving-sys.com us-central1-epigraph-product-configurator.cloudfunctions.net *.intentiq.com *.flexpowertools.com *.skil.com *.egopowerplus.com *.linkedin.com s.amazon-adsystem.com ara.paa-reporting-advertising.amazon js.monitor.azure.com *.reddit.com *.redditstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-Iog1K+DJC4blkrVYsTuqoQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=41060598-aae3-4e2b-853f-a529c897d160; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'none'; img-src 'self' data: https://stats.o74.net; script-src 'self' https://stats.o74.net/piwik.js 'nonce-WQz2y/po7E0SbNcLoH0617v7FwxAkyJf' 'unsafe-inline'; style-src 'self' 'nonce-WQz2y/po7E0SbNcLoH0617v7FwxAkyJf'; font-src 'self'; base-uri 'self'; frame-ancestors 'none'; connect-src 'self' https://stats.o74.net ; form-action 'self'; report-uri https://cspreporter.o74.net/tell/man.fyi; report-to cspreporter-o74; 1 font-src fonts.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.ccavenue.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.youtube-nocookie.com services.sheerid.com *.authorize.net *.ccavenue.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com *.visualwebsiteoptimizer.com *.hsforms.com *.gstatic.com shareasale.com *.google.com.ua bat.bing.com *.facebook.com *.fs1.hubspotusercontent-na1.net track.hubspot.com t.co analytics.twitter.com/ bat.bing.net *.google.de services.sheerid.com *.cloudfront.net edge.marker.io store.paradoxlabs.com *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com maps.googleapis.com *.visualwebsiteoptimizer.com *.hsforms.net *.dwin1.com *.amplitude.com js.hs-scripts.com bat.bing.com static.ads-twitter.com *.hotjar.com cdn.jsdelivr.net cdn.jst.ai tags.srv.stackadapt.com js.hubspot.com js.hsadspixel.net js.hscollectedforms.net js.hs-banner.com js.hubspotfeedback.com js.hsleadflows.net js.hs-analytics.net my.jst.ai *.clarity.ms aly.jst.ai smct.co edge.marker.io services.sheerid.com *.forethought.ai static-tracking.klaviyo.com api.marker.io *.authorize.net *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.avada.io connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tags.srv.stackadapt.com services.sheerid.com *.klaviyo.com https://static.klaviyo.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com v.ftcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com https://maps.googleapis.com https://player.vimeo.com forms.hsforms.com *.googleapis.com *.amplitude.com *.visualwebsiteoptimizer.com bat.bing.net bat.bing.com cta-service-cms2.hubspot.com api.hubapi.com *.hotjar.com *.hotjar.io forms.hscollectedforms.net *.clarity.ms tags.srv.stackadapt.com forms.hubspot.com smct.co aly.jst.ai wss://ws.hotjar.com/api/v2/client/ws api.marker.io ipapi.co static-tracking.klaviyo.com *.authorize.net *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.google.com *.nr-data.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.pendo.io https://*.jquery.com https://*.google.com https://*.gstatic.com https://*.storage.googleapis.com https://js-agent.newrelic.com *.newrelic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com blob: *.newrelic.com; script-src-elem 'self' https://*.pendo.io *.newrelic.com *.googleapis.com; img-src 'self' https://*.pendo.io https://myhealthrecord.com:9999 https://*.myhealthrecord.com:9999 https://*.greenwayhealth.com:9999 https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com blob data:; font-src 'self' https://fonts.gstatic.com https://*.greenwayhealth.com https://*.login.greenwayhealth.com https://*.authstagingpoc.aws.greenwayhealth.com https://*.gisdev.aws.greenwayhealth.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com *.googleapis.com; style-src-elem 'self' 'unsafe-inline' https://*.storage.googleapis.com https://*.googleapis.com https://myhealthrecord.com:9999 https://*.myhealthrecord.com:9999 https://*.greenwayhealth.com:9999 https://pendo-static-4979136297566208.storage.googleapis.com *.googleapis.com https://*.pendo.io; style-src-elem 'self' *.googleapis.com https://pendo-static-4979136297566208.storage.googleapis.com https://*.pendo.io; connect-src 'self' https://*.pendo.io https://*.greenwayhealth.com:9004 https://*.myhealthrecord.com https://bam.nr-data.net https://bam-cell.nr-data.net *.nr-data.net https://phprod-patient-specific-documents.s3.amazonaws.com *.googleapis.com https://pendo-static-4979136297566208.storage.googleapis.com; frame-src 'self' https://*.instamed.com https://*.aws.greenwayhealth.com https://*.google.com https://*.pendo.io; report-uri https://api.myhealthrecord.com/PortalAPI/v1/CspReporting/LogCspReport 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com https://api.systempay.fr/static/ *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.pinterest.com/ https://wisepops.net/ https://*.wisepops.com/ https://*.trustpilot.com/ https://*.systempay.fr/ https://*.amaymag2.dnd.fr/ https://*.atelier-amaya.com/ *.weltpixel.com *.trustpilot.com *.dotdigital-pages.com *.dotdigital.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ www.xtento.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com maps.googleapis.com maps.gstatic.com https://*.cdninstagram.com/ https://*.instagram.com/ https://*.google.com/ https://*.google.fr/ https://*.zdassets.com/ https://*.pinterest.com/ https://*.facebook.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://assets.shipup.co https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ www.xtento.com cdn.xtento.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com/maps/api/mapsjs *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://cdn.shipup.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com https://cdnjs.cloudflare.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com *.gstatic.com *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com https://cdn.shipup.co https://api.systempay.fr/static/ *.fontawesome.com tagmanager.google.com https://cdnjs.cloudflare.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://*.zdassets.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com/maps/api/mapsjs https://api.shipup.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://www.google-analytics.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.be2bill.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ https://www.youtube.com https://form.typeform.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com uat-secure.pointspay.com secure.pointspay.com *.google.com *.be2bill.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://firebasestorage.googleapis.com https://secure-magenta.dalenys.com uat-secure.pointspay.com secure.pointspay.com *.google-analytics.com *.googleadservices.com *.be2bill.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.avada.io *.shopify.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com uat-secure.pointspay.com secure.pointspay.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.doubleclick.net *.be2bill.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com https://maps.googleapis.com https://player.vimeo.com https://ws.colissimo.fr https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com https://get.geojs.io *.avada.io https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ uat-secure.pointspay.com secure.pointspay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; report-uri https://dcc-cspreport.enovation.ie/csp-report-dccdrupal.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com https://plumrocket.com *.iubenda.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://accounts.google.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: track.goggles4u.info https://track.goggles4u.info www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net https://images.unsplash.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://maps.googleapis.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com https://accounts.google.com https://www.gstatic.com www.xtento.com cdn.xtento.com *.yotpo.com https://js.klevu.com sst.goggles4u.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klevu.com *.ksearchnet.com https://accounts.google.com https://www.gstatic.com *.yotpo.com *.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://maps.googleapis.com https://player.vimeo.com https://checkout.iwdagency.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://accounts.google.com *.yotpo.com sst.goggles4u.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.co *.betano.co betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kameleoon.io *.kameleoon.io optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery cloudflare.com *.cloudflare.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=PuD4PyMvyZ99zf1rkW0FFP0wdikx9Izb.aKWzE9lBeg-1765935039-1.0.1.1-BzLefvYqGyRL3NwKZDa55rtrKsf2C6Ktm1kFOmT_mi__a1GHI9GfaEu.ljWsoqAVj9YUagCzft4dLZ7sWtCTcNbSkcnoByQEcQzqFEleRa48fb03anPGyxJUggVGML.P14RZV67jtWu_cFJd3R9r.V_uGqYxmvvlX_P6LGnQaoPIY8xHxIhBlXtu2Z3V2pNkU.guFmZ4ATcfPK0wx9qdOg; report-to cf-xmddmujtfcakmjau 1 frame-ancestors 'none'; report-uri https://13fc2e96c75baedc98bc60c37c2c93be.report-uri.com/r/d/csp/wizard; script-src 'strict-dynamic' 'nonce-VNQWwY8OH6VIEwLTtcODhg==' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com translate.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.sagepay.com *.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sagepay.com *.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.gstatic.com maps.googleapis.com cdn.rawgit.com/googlemaps/ cdn.jsdelivr.net/gh/googlemaps/ https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.googleapis.com *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com widget.freshworks.com m2epro.freshdesk.com maps.googleapis.com *.sagepay.com *.elavon.com *.avada.io *.alothemes.com *.magepow.com translate.google.com *.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com www.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com widget.freshworks.com m2epro.freshdesk.com maps.googleapis.com *.sagepay.com *.elavon.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-7049666b-bf9d-473c-a733-56848aef1dc7' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.casinohuone.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.casinohuone.com/eum-collector/report/csp-report; 1 font-src *.squarecdn.com fonts.googleapis.com fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com *.cash.app *.dotdigital-pages.com *.dotdigital.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.cash.app *.trackedlink.net maps.googleapis.com maps.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.klevu.com *.ksearchnet.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ *.squarecdn.com *.cash.app fonts.googleapis.com display.ugc.bazaarvoice.com *.klevu.com *.ksearchnet.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://224c98c5-2b57-48b9-abd5-386e2aff2a6c.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.typekit.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://b.6sc.co https://j.6sc.co https://ajax.googleapis.com https://js.navattic.com https://cdn.cookielaw.org https://static.ads-twitter.com https://unpkg.com https://js.hsforms.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hubspot.com https://snap.licdn.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://boards.greenhouse.io https://fireblocks.chilipiper.com https://tracking.g2crowd.com https://cdnjs.cloudflare.com https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://d3js.org; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://use.typekit.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://b.6sc.co https://j.6sc.co https://ajax.googleapis.com https://js.navattic.com https://cdn.cookielaw.org https://static.ads-twitter.com https://unpkg.com https://js.hsforms.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hubspot.com https://snap.licdn.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://boards.greenhouse.io https://fireblocks.chilipiper.com https://tracking.g2crowd.com https://cdnjs.cloudflare.com https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://d3js.org; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://cdn.cookielaw.org https://code.jquery.com; img-src 'self' data: https: https://www.google-analytics.com; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://fast.wistia.com https://fast.wistia.net; connect-src 'self' https://www.google-analytics.com https://b.6sc.co https://c.6sc.co https://ipv6.6sc.co https://analytics.google.com https://www.google.com https://cdn.cookielaw.org https://forms.hsforms.com https://api.hubapi.com https://cta-service-cms2.hubspot.com https://px.ads.linkedin.com https://tracking-api.g2.com https://stats.g.doubleclick.net https://fast.wistia.com https://fast.wistia.net https://embed-cloudfront.wistia.com https://distillery.wistia.com https://pipedream.wistia.com https://cdn.jsdelivr.net wss:; frame-src 'self' https://www.youtube.com https://fast.wistia.net https://forms.hsforms.com https://app.hubspot.com https://www.googletagmanager.com https://td.doubleclick.net https://fireblocks.chilipiper.com https://www.google.com https://capture.navattic.com https://job-boards.greenhouse.io https://lottie.host; media-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self' https://forms.hsforms.com; upgrade-insecure-requests; 1 default-src 'self'; script-src 'report-sample' 'self' data: 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://static.olark.com https://cdn.jsdelivr.net https://8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com https://ai.ocelotbot.com https://analytics.tiktok.com https://googleads.g.doubleclick.net https://mx.technolutions.net https://s.yimg.com https://*.hotjar.com https://siteimproveanalytics.com https://slate.uwplatt.edu https://unpkg.com https://www.googletagmanager.com https://youtube.com https://ep1.adtrafficquality.google; script-src-elem 'report-sample' 'self' 'unsafe-inline' https://mx.technolutions.net https://googleads.g.doubleclick.net https://siteimproveanalytics.com https://partner.googleadservices.com https://ai.ocelotbot.com https://slate-technolutions-net.cdn.technolutions.net https://8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com https://www.googletagmanager.com/ https://www.youtube.com https://libraryh3lp.com https://unpkg.com https://static.olark.com https://cdn.jsdelivr.net https://*.google.com https://*.uwplatt.edu https://ep2.adtrafficquality.google https://slate-uwplatt-edu.cdn.technolutions.net https://fw.cdn.technolutions.net; style-src 'report-sample' 'self' 'unsafe-inline' https://www.google.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://static.olark.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' https://slate-technolutions-net.cdn.technolutions.net https://static.olark.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://*.google.com https://*.uwplatt.edu https://ep2.adtrafficquality.google https://slate-uwplatt-edu.cdn.technolutions.net https://fw.cdn.technolutions.net; object-src 'none'; base-uri 'self'; connect-src 'self' https://knrpc.olark.com https://www.googleadservices.com https://stats.g.doubleclick.net https://ai.ocelotbot.com https://libraryh3lp.com https://6349506.global.r2.siteimproveanalytics.io https://analytics.google.com https://analytics.tiktok.com https://content.hotjar.io https://mx.technolutions.net https://s.yimg.com https://*.uwplatt.edu https://www.google.com https://www.googletagmanager.com https://slate-uwplatt-edu.cdn.technolutions.net https://ep1.adtrafficquality.google; font-src 'self' data: https://fonts.gstatic.com https://static.olark.com; frame-src 'self' https://www.youtube-nocookie.com https://static.olark.com https://libraryh3lp.com https://e.issuu.com https://www.googletagmanager.com https://ep2.adtrafficquality.google https://syndicatedsearch.goog https://www.youtube.com https://*.uwplatt.edu; img-src 'self' data: https://googleads.g.doubleclick.net/ https://se-images.campuslabs.com https://id.ocelotbot.com https://image.isu.pub https://6349506.global.r2.siteimproveanalytics.io https://*.uwplatt.edu https://sp.analytics.yahoo.com https://trkn.us https://*.google.com https://log.olark.com https://www.googletagmanager.com https://syndicatedsearch.goog https://ep1.adtrafficquality.google; manifest-src 'self'; media-src 'self' https://static.olark.com; worker-src 'none'; frame-ancestors 'self' *.uwplatt.edu https://uwplatt.sharepoint.com; report-uri https://sentry.uwplatt.edu/api/4/security/?sentry_key=70d6cb927e9344631160d6d130a75ea0&sentry_environment=csp_reporting; report-to csp-endpoint; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com *.typekit.net *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net *.yotpo.com www-wp.silencercentral.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net www-wp.silencercentral.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.authorize.net *.yotpo.com www-wp.silencercentral.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com store.paradoxlabs.com maps.gstatic.com https://*.ipredictive.com https://www.googletagmanager.com *.gleamjs.io *.gleam.io *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net maps.googleapis.com https://js.ipredictive.com *.gleamjs.io *.gleam.io *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www-wp.silencercentral.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com *.typekit.net *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www-wp.silencercentral.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://www.google-analytics.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www-wp.silencercentral.com 'self' 'unsafe-inline'; child-src www-wp.silencercentral.com http: https: blob: 'self' 'unsafe-inline'; default-src www-wp.silencercentral.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' data: *.marianatek.com *.cookielaw.org *.chilipiper.com *.googletagmanager.com *.google.com *.gstatic.com *.cloudflare.com *.youtube.com *.youtube-nocookie.com *.vimeo.com *.licdn.com *.facebook.net *.clarity.ms *.google-analytics.com *.hs-scripts.com *.doubleclick.net unpkg.com *.wistia.net;upgrade-insecure-requests; 1 default-src https://*.hint.com 'self' https://static.hsappstatic.net; img-src 'self' https://*.hint.com https://www.facebook.com https://app.hubspot.com https://*.hsforms.com https://avatars.hubspot.net https://static.hsappstatic.net https://www.google.com https://www.google.com https://t.co https://www.google-analytics.com https://analytics.twitter.com https://facebook.com https://heapanalytics.com https://p.typekit.net https://px.ads.linkedin.com https://www.google.com/ads https://www.facebook.com/tr https://track.hubspot.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://www.gstatic.com https://www.google.com/recaptcha/enterprise.js https://313589.fs1.hubspotusercontent-na1.net https://platform.twitter.com https://platform.linkedin.com/in.js https://js.hsleadflows.net https://script.hotjar.com https://www.googletagmanager.com https://snap.licdn.com https://static.hotjar.com https://static.hsappstatic.net https://js.hs-scripts.com https://app.hubspot.com https://www.google-analytics.com https://static.ads-twitter.com https://cdn.heapanalytics.com https://connect.facebook.net https://my.hellobar.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hscollectedforms.net https://js.hsadspixel.net https://hsleadflows.net https://googleads.g.doubleclick.net; style-src 'self' 'unsafe-inline' https://static.hsappstatic.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://www.gstatic.com https://use.typekit.net https://cdn2.hubspot.net https://p.typekit.net https://fast.fonts.net https://px.ads.linkedin.com; object-src 'self'; font-src 'self' https://2562809.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com https://fonts.gstatic.com https://cdn2.hubspot.net https://use.typekit.net; connect-src 'self' https://forms.hscollectforms.net https://forms.hscollectforms.net https://js.hs-banner.com https://api.hubapi.com https://www.google-analytics.com https://*.hubspot.com https://stats.g.doubleclick.net https://forms.hscollectedforms.net; frame-src https://platform.twitter.com https://www.google.com 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.pinterest.com https://ghirardelli.slgnt.us 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://ghirardelli.slgnt.us https://www.paypalobjects.com https://lindtusa.rlvs.co.uk https://optmize.google.com https://www.google.com/ https://ct.pinterest.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.upsellit.com https://mediacdn.espssl.com/2824/Shared/Modal/chocolate.png https://www.linkedin.com https://*.linkedin.com/ https://px.ads.linkedin.com *.googleadservices.com *.russellstover.com https://www.google-anaytics.com https://www.googletagmanager.com https://optimize.google.com https://bam.nr-data.net *.bazaarvoice.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.youtube.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com 'unsafe-inline' https://optimize.google.com 'unsafe-inline' https://www.lindt-spruengli.com/* https://www.lindt-spruengli.com/media/target/VAPI.min.js https://www.lindt-spruengli.com/media/target/at.js https://click2cart.com https://ghirardelli.mycontactcenter.net/ https://pop1-apps.mycontactcenter.net/ https://form.jotform.com https://ghirardelli-pages.vercel.app https://form.jotform.com/jsform/250416509718156 https://form.jotform.com/250695600740152 https://api-js.datadome.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://cloud.typography.com 'unsafe-inline' https://optimize.google.com https://fonts.googleapis.com 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://cdn.linkedin.oribi.io https://vc.hotjar.io *.ghirardelli.com *.hotjar.io *.bing.com ws.hotjar.com wss://ws.hotjar.com sc-api.click2cart.com https://geolocation.onetrust.com https://bat.bing.com ghirardelli-pages.vercel.app https://ghirardelli-pages.vercel.app/api/synup https://ghirardelli-pages.vercel.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.vimeo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://bluewhaleresearch.com/ https://static.cloudflareinsights.com/ https://www.google.com/ https://www.gstatic.com/ https://snap.licdn.com/ https://googleads.g.doubleclick.net/ https://visitor.reactful.com/ https://scout-cdn.salesloft.com/ https://ml314.com/ https://js.zi-scripts.com/ https://cdn.metadata.io/ https://static.hotjar.com/ https://js.driftt.com/ https://script.hotjar.com https://bluewhaleresearch.com/46b119dd-5482-4cb3-bee3-fa3465598d50 https://kit.fontawesome.com/ https://bluewhaleresearch.com/wp-content/plugins/formidable-signature/js/frm.signature.min.js https://www.googleadservices.com/ https://tags.srv.stackadapt.com/ https://bluewhaleresearch.com/8726e6ea-dedb-4a95-8fac-e459e1ac38d5 *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: https://tags.srv.stackadapt.com/ *.vimeocdn.com fonts.googleapis.com 'unsafe-inline' maps.googleapis.com maps.google.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://px.ads.linkedin.com/ https://www.google.co.in/ https://dpm.demdex.net/ https://match.adsrvr.org/ https://sync.crwdcntrl.net/ https://ps.eyeota.net/ https://ml314.com/ https://i.vimeocdn.com/ https://trc.taboola.com/ https://tags.bluekai.com/ https://ib.adnxs.com/ https://loadus.exelator.com/ https://googleads.g.doubleclick.net/ https://sync-tm.everesttech.net/ https://cms.analytics.yahoo.com/ https://ups.analytics.yahoo.com/ https://sync.srv.stackadapt.com/ https://idsync.rlcdn.com/ https://p.rfihub.com/ https://i.liadm.com/ https://pixel.tapad.com/ https://aax-eu.amazon-adsystem.com/ https://token.rubiconproject.com/ https://cm.mgid.com/ https://crb.kargo.com/ https://i.w55c.net/ https://api.retargetly.com/ https://qvdt3feo.com/ https://px4.ads.linkedin.com/ https://tags.srv.stackadapt.com/ secure.gravatar.com www.gravatar.com data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com i.ytimg.com www.googletagmanager.com; connect-src 'self' https://scout.salesloft.com/ https://api-gw.metadata.io/ https://visitor.reactful.com/ https://js.zi-scripts.com/ https://a.usbrowserspeed.com/ https://vc.hotjar.io/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://ws.zoominfo.com/ https://tracking.reactful.com/ https://metrics.hotjar.io/ https://px.ads.linkedin.com/ https://ka-f.fontawesome.com/ https://bluewhaleresearch.com/ https://www.google.com/ https://tags.srv.stackadapt.com/ https://googleads.g.doubleclick.net/ https://pagead2.googlesyndication.com/ https://yoast.com/ *.vimeo.com www.google-analytics.com stats.g.doubleclick.net ampcid.google.com analytics.google.com about: maps.googleapis.com maps.google.com www.googletagmanager.com; font-src 'self' data: https://bluewhaleresearch.com/ https://ka-f.fontawesome.com/ https://s0.wp.com/ data: fonts.gstatic.com fonts.googleapis.com; object-src 'self' https://bluewhaleresearch.com/; media-src 'self' https://bluewhaleresearch.com/; frame-src 'self' https://www.google.com/ https://www.gstatic.com/ https://td.doubleclick.net/ https://js.driftt.com/ https://i.liadm.com/ *.vimeo.com *.vimeocdn.com maps.googleapis.com maps.google.com www.youtube.com www.googletagmanager.com; child-src 'self' *.vimeo.com *.vimeocdn.com www.youtube.com www.googletagmanager.com; report-uri https://bluewhaleresearch.com?gdsih-csp-report; 1 child-src 'self' https://www.googletagmanager.com https://*.liveperson.net https://cdn.appdynamics.com https://*.lpsnmedia.net https://www.facebook.com https://connect.facebook.net https://*.google.com https://widget.trustpilot.com https://*.doubleclick.net https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://d2d7do8qaecbru.cloudfront.net https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://www.youtube.com https://www.zenaps.com https://*.akamaihd.net https://*.translate.naver.net https://recaptcha.net https://tr.snapchat.com https://*.abtasty.com; connect-src 'self' https://*.thcdn.com https://*.ingest.sentry.io https://*.pingdom.net https://*.doubleclick.net https://*.google-analytics.com https://capture.trackjs.com https://fp.zenaps.com https://www.facebook.com https://*.google.com https://*.thehut.net https://privacyportal-eu.onetrust.com https://geolocation.onetrust.com https://cdn.cookielaw.org wss://*.liveperson.net https://*.liveperson.net https://*.lpsnmedia.net https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://cognito-identity.eu-west-1.amazonaws.com https://firehose.eu-west-1.amazonaws.com https://*.ringcentral.com wss://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://services.postcodeanywhere.co.uk https://*.sciencebehindecommerce.com https://*.akamaihd.net https://*.googleapis.com https://*.trustpilot.com https://*.pinterest.com https://*.doubleclick.net https://*.bing.com https://connect.facebook.net https://*.parcellab.com https://storyboard.storystream.ai https://content.storystream.ai https://*.abtasty.com https://d3g5d7323c2i6m.cloudfront.net https://d29qb9vav0xwuc.cloudfront.net https://d7c4jjeuqag9w.cloudfront.net https://apps.storystream.ai https://upload.uploadcare.com https://598nyfqkt7.execute-api.eu-west-1.amazonaws.com https://sgtm.www.berghaus.com https://*.ometria.com https://www.berghaus.com/e2/ds/relay https://horizon-api.www.berghaus.com/graphql https://*.ingest.sentry.io https://s1.thcdn.com; font-src 'self' data: https://*.thcdn.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://fonts.smct.co https://fonts.smct.io https://*.ringcentral.com blob: data: https://*.abtasty.com https://*.gstatic.com https://*.googleapis.com https://d7c4jjeuqag9w.cloudfront.net; form-action 'self' https://www.facebook.com https://m.berghaus.com https://checkout.berghaus.com https://www.berghaus.com https://connect.facebook.net https://tr.snapchat.com; img-src 'self' data: https://*.thcdn.com https://col.eum-appdynamics.com https://usage.trackjs.com https://*.lpsnmedia.net https://*.doubleclick.net https://www.google-analytics.com https://*.google.com https://cx.atdmt.com https://www.zenaps.com https://*.ringcentral.com https: blob:; media-src 'self' https://*.thcdn.com https://*.lpsnmedia.net blob: https://player.vimeo.com https://vod-progressive.akamaized.net https://download-video.akamaized.net https://d7c4jjeuqag9w.cloudfront.net https://media.storystream.ai; report-uri https://csp.thehut.net/cspReport.txt; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.thcdn.com https://*.thehut.net https://rum-static.pingdom.net https://*.liveperson.net https://*.lpsnmedia.net https://*.doubleclick.net https://static.cdn-apple.com https://*.liveperson.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://cdn.parcellab.com https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com https://cdnjs.cloudflare.com https://fp.zenaps.com https://www.youtube.com https://www.google-analytics.com https://*.google.com https://connect.facebook.net https://bat.bing.com https://widget.trustpilot.com https://s.ytimg.com https://www.googletagservices.com https://*.googleapis.com https://www.facebook.com https://www.googleadservices.com https://*.gstatic.com https://*.gstatic.cn https://www.dwin1.com https://cdn.trackjs.com https://recaptcha.net https://*.sciencebehindecommerce.com https://*.akamaihd.net https://*.microsofttranslator.com https://google.com https://*.trustpilot.com https://*.translate.naver.net https://*.doubleclick.net https://*.google-analytics.com https://sc-static.net https://*.google.co.uk https://google.co.uk https://static.ads-twitter.com https://*.twitter.com https://apps.storystream.ai blob: https://*.abtasty.com https://*.googleapis.com https://ucarecdn.com https://sgtm.www.berghaus.com https://*.upsellit.com https://*.ometria.com https://s1.thcdn.com; style-src 'self' 'unsafe-inline' https://*.thcdn.com https://*.google.com https://*.googleapis.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.lpsnmedia.net https://*.liveperson.net https://fonts.googleapis.com https://fonts.smct.co https://fonts.smct.io https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://*.googleapis.com https://*.translate.naver.net https://*.microsofttranslator.com https://cdn.parcellab.com https://*.abtasty.com https://*.gstatic.com https://*.googleapis.com https://d7c4jjeuqag9w.cloudfront.net https://*.ometria.com https://s1.thcdn.com; report-to report-endpoint; 1 base-uri 'self'; default-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-src 'self' https://td.doubleclick.net; connect-src 'self' https://swile-privacy.my.onetrust.com https://cdn.cookielaw.org https://swile.containers.piwik.pro https://swile.piwik.pro/ https://adservice.google.com https://googleads.g.doubleclick.net https://www.google.com; img-src 'self' blob: data: https://cdn.cookielaw.org https://www.google.fr https://www.googletagmanager.com https://fonts.gstatic.com; manifest-src 'self'; object-src 'none'; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub1f7041eb55ec9a12eea50b161be3d8c0&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to csp; script-src 'nonce-NGVhYTM2NDUtMTJjZi00MDZkLTgxYjItODIyMTBlNTdiNDk4' 'strict-dynamic'; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://fonts.googleapis.com 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com https://www.nominette.com https://demo.nominette.nl data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.gstatic.com https://www.nominette.com https://demo.nominette.nl 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com www.google.com *.hotjar.com *.hotjar.io *.weltpixel.com https://www.nominette.com https://demo.nominette.nl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com maps.gstatic.com maps.googleapis.com *.google.com *.google.be *.googleapis.com *.gstatic.com *.google-analytics.com *.magentocommerce.com *.trustprofile.io bat.bing.com *.facebook.com https://www.nominette.com https://demo.nominette.nl maps.google.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com maps.googleapis.com *.google.com www.gstatic.com *.googleapis.com *.newrelic.com *.nr-data.net *.hotjar.com *.hotjar.io *.voyado.com https://www.nominette.com bat.bing.com *.clarity.ms *.realytics.io *.realytics.net connect.facebook.net https://demo.nominette.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com *.googleapis.com https://www.nominette.com https://demo.nominette.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.google.be *.google-analytics.com *.googleapis.com *.nr-data.net *.g.doubleclick.net *.hotjar.com *.hotjar.io *.voyado.com *.exatom.io bat.bing.com *.clarity.ms *.realytics.io *.stape.cc 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'nonce-TODU99hjmiKN2uApmmJ7ohPY' 'strict-dynamic' http: https:; base-uri 'none'; 1 default-src 'self' http: https://*-chcf-wp.pantheonsite.io/ https://chcf-wp.ddev.site https://*.addthis.com https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.addthis.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://*.addthisedge.com https://cdnjs.cloudflare.com; style-src 'unsafe-inline' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com; img-src 'self' http: data: https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.bookingbug.com https://geolocation.onetrust.com https://*.cookielaw.org https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com *.addtoany.com; font-src 'self' data: fonts.gstatic.com use.typekit.net use.fontawesome.com bespoke.bookingbug.com; media-src 'self' *.youtube.com *.vimeo.com *.akamaized.net; report-uri 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'self'; frame-src 'self' blob: *.youtube.com *.youtube-nocookie.com *.doubleclick.net *.soundcloud.com *.facebook.com *.vimeo.com *.addtoany.com *.infogram.com *.simplecast.com; worker-src 'self'; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; upgrade-insecure-requests 1 default-src ws: wss: http: https: data: 'unsafe-inline' 'unsafe-eval'; report-uri https://app.cyberimpact.com/csp-violation-report/ 1 default-src 'self' http: https://*.gates-pre-prod.byf1.dev https://*.gates-production.byf1.dev https://*.gatesfoundation.org https://*.addthis.com https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.addthis.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://*.addthisedge.com https://cdnjs.cloudflare.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://privacyportal.onetrust.com https://geolocation.onetrust.com; style-src 'unsafe-inline' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://privacyportal.onetrust.com https://geolocation.onetrust.com; img-src 'self' http: data: https://*.gatesfoundation.org https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.bookingbug.com https://geolocation.onetrust.com https://*.cookielaw.org https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com; font-src 'self' data: fonts.gstatic.com use.typekit.net use.fontawesome.com bespoke.bookingbug.com; media-src 'self' *.youtube.com *.vimeo.com *.akamaized.net; report-uri 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'self'; frame-src 'self' *.youtube.com *.youtube-nocookie.com go.communications.gatesfoundation.org *.doubleclick.net *.soundcloud.com *.facebook.com *.vimeo.com challenges.cloudflare.com; worker-src 'self'; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; upgrade-insecure-requests 1 default-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.cookiebot.com:* *.fanplayr.com:* *.doubleclick.net:* *.media:* *.googletagmanager.com:* *.sc-static.net:* *.tiktok.com:* *.force.com:* *.jsdelivr.net:* *.amazon-adsystem.com:* *.amazon-adsystem.com:* *.fastclick.net:* *.crwdcntrl.net:* *.id5-sync.com:* *.cloudflare.com:* *.salesforceliveagent.com:* *.snapchat.com:* *.googleapis.com:* *.sc-static.net:* sc-static.net:* *.smilewanted.com:* *.reciteme.com:* https://c.ltmsphrcl.net https://www.googletagservices.com https://cdn.js7k.com https://ep2.adtrafficquality.google https://cadmus.script.ac https://bat.bing.com https://s2.adform.net https://snap.licdn.com https://secure.adnxs.com https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* https://track.adform.net:* *.byspotify.com:* *.geoedge.be:*; object-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.jsdelivr.net:* *.force.com:* *.googleapis.com:* *.reciteme.com:* *.cloudflare.com:* https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* ; img-src 'self' *.northernrailway.co.uk:* *.netlify.app:* *.snapchat.com:* *.cookiebot.com:* *.googleapis.com:* *.googletagmanager.com:* *.fanplayr.com:* data: *.reciteme.com:* https://ep1.adtrafficquality.google https://dt.adsafeprotected.com https://www.facebook.com *.googlesyndication.com https://id5-sync.com *.googleusercontent.com:*; media-src 'self'; frame-src 'self' *.cookiebot.com:* *.snapchat.com:* *.force.com:* *.northernrailway.co.uk:* *.smilewanted.com:* *.yahoo.com:* *.adnxs.com:* *.ck-ie.com:* *.33across.com:* *.smaato.net:* *.onetag-sys.com:* *.360yield.com:* onetag-sys.com:* *.smartadserver.com:* ssp-sync.criteo.com:* *.ssp-sync.criteo.com:* *.eskimi.com:* *.rubiconproject.com:* *.pubmatic.com:* *.openx.net:* dis.criteo.com:* *.sharethrough.com:* *.lijit.com:* *.doubleclick.net *.googlesyndication.com https://www.google.com https://track.adform.net:*; frame-ancestors 'self' https://game.northernrailway.co.uk:*; child-src 'self'; font-src 'self' *.gstatic.com:* *.reciteme.com:* data:; connect-src 'self' *.amazon-adsystem.com:* *.northern-trains.ddev.site *.tiktok.com:* *.snapchat.com:* *.amazon.dev:* *.criteo.com:* *.crwdcntrl.net:* *.fanplayr.com:* *.googlesyndication.com:* *.a2z.com:* *.eu-1-id5-sync.com:* id5-sync.com:* *.33across.com:* *.cookiebot.com:* *.google-analytics.com:* *.reciteme.com:* *.smilewanted.com *.doubleverify.com https://px.ads.linkedin.com https://c.ltmsphrcl.net *.doubleclick.net https://region1.analytics.google.com https://pixels.spotify.com https://web.hb.ad.cpe.dotomi.com *.4dex.io https://onetag-sys.com https://esp.rtbhouse.com https://prg.smartadserver.com https://data.ad-score.com https://fastlane.rubiconproject.com https://ad.360yield.com https://tlx.3lift.com https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* *.tiktokw.us:*; report-uri /report-csp-violation 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/tv_google 1 default-src 'none'; connect-src 'self' https: policy.app.cookieinformation.com; font-src https:; frame-src https:; img-src 'self' data: https:; manifest-src 'self' https:; media-src 'self' https:; script-src 'unsafe-inline' https: maps.google.com; style-src 'unsafe-inline' https:; worker-src https:; base-uri https:; form-action https:; frame-ancestors 'self' https:; report-uri https://ing.dk/log-report-uri/reportOnly 1 default-src https://odin.study https://*.odin.study; connect-src https://odin.study https://*.odin.study wss://odin.study https://storage.yandexcloud.net *.s3.yandexcloud.net https://mc.yandex.ru/watch/ https://analytics.google.com/ *.analytics.google.com https://mc.yandex.ru/ https://mc.yandex.md/ https://mc.yandex.com/ https://mc.yandex.by/ https://mc.yandex.kz/ https://www.google.ru/ads/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://cdn.plyr.io/ https://sentry.smile-tech.study wss://janus3333.odin.study https://fcmregistrations.googleapis.com/ https://firebaseinstallations.googleapis.com/; script-src https://odin.study https://*.odin.study 'unsafe-inline' 'unsafe-eval' https://mc.yandex.ru/metrika/ https://mc.yandex.com/watch/ https://mc.yandex.ru/clmap/ https://yastatic.net/s3/ https://api-maps.yandex.ru/ https://www.googletagmanager.com/ https://www.google-analytics.com/analytics.js https://captcha-api.yandex.ru/ https://core-renderer-tiles.maps.yandex.net/; img-src https://odin.study https://*.odin.study https://storage.yandexcloud.net *.s3.yandexcloud.net data: https://mc.yandex.ru/metrika/ https://mc.yandex.ru/clamp/ https://pic.rutube.ru/ https://www.google.ru/ads/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://unpkg.com/emoji-datasource-google@15.0.1/ https://unpkg.com/emoji-datasource-google@14.0.0/ https://yandex.ru/clck/ https://mc.yandex.ru/ https://mc.yandex.md/ https://mc.yandex.com/ https://mc.yandex.by/ https://api-maps.yandex.ru https://vkvideo.ru/ https://files.gitbook.com/ https://informa.gitbook.io/; style-src https://odin.study https://*.odin.study 'unsafe-inline' https://fonts.googleapis.com/; frame-src https://odin.study https://*.odin.study https://mc.yandex.ru https://view.officeapps.live.com https://r.office.microsoft.com https://storage.yandexcloud.net *.s3.yandexcloud.net https://captcha-api.yandex.ru https://vk.ru https://vkvideo.ru https://www.youtube.com https://td.doubleclick.net; media-src https://odin.study https://*.odin.study https://storage.yandexcloud.net *.s3.yandexcloud.net blob: https://cdn.plyr.io/static/ https://drive.google.com; font-src https://odin.study https://*.odin.study data:; report-uri https://odin.study/api/reports/csp; report-to odin-csp-endpoint 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-ba953958-c75e-4e7b-b7b5-c0143d8c1630' https: data: https://js.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://siteintercept.qualtrics.com https://browser.sentry-cdn.com https://*.siteintercept.qualtrics.com https://www.googletagmanager.com https://js.monitor.azure.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://cdn.jsdelivr.net https://more.suse.com; img-src 'self' https: data: https://fast.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://fast.wistia.net https://fast.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com; connect-src 'self' https: wss: https://cdn.cookielaw.org https://distillery.wistia.com https://siteintercept.qualtrics.com https://dc.services.visualstudio.com https://fast.wistia.com https://fast.wistia.net https://pipedream.wistia.com wss://ws.qualified.com https://embed-ssl.wistia.com https://apple.dxcloud.episerver.net https://cdn.jsdelivr.net https://js.monitor.azure.com wss://ws.qualified.com; font-src 'self' https: data: https://fonts.gstatic.com https://fast.wistia.net; object-src 'none' ; media-src 'self' https: blob: ; frame-src 'self' https: ; form-action 'self' https://suselinux.fra1.qualtrics.com; frame-ancestors 'self' ; base-uri 'none' ; report-uri https://www.suse.com/api/reporting/; report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com static.harveynorman.si static.mage.harvey.optiweb.serv.si media.flixfacts.com media.flixcar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com *.harveynorman.si *.harvey.optiweb.serv.si *.cookiebot.com *.doubleclick.net *.criteo.com *.criteo.net www.google.si *.creativecdn.com blob: *.facebook.com *.reddit.com static.youreko.com *.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.flixcar.com media.flixfacts.com rt.flix360.com logo.flix360.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com s7.addthis.com *.avada.io *.segmentify.com cdn.sgmntfy.com api.squalomail.com *.criteo.com *.criteo.net *.googleapis.com cdnjs.cloudflare.com *.hotjar.com *.cookiebot.com *.harveynorman.si *.livechatinc.com *.creativecdn.com www.gstatic.com static.harveynorman.si static.mage.harvey.optiweb.serv.si https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com maps.googleapis.com static.youreko.com api.youreko.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.loadbee.com media.flixcar.com media.flixfacts.com prod.flixgvid.flix360.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.segmentify.com cdnjs.cloudflare.com www.googletagmanager.com static.harveynorman.si static.mage.harvey.optiweb.serv.si tagmanager.google.com static.youreko.com assets.braintreegateway.com media.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.segmentify.com *.criteo.com *.cookiebot.com pagead2.googlesyndication.com *.hotjar.io *.doubleclick.net *.creativecdn.com *.harveynorman.si capig.stape.host static.mage.harvey.optiweb.serv.si *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app maps.googleapis.com api.youreko.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com media.flixcar.com pk.takoleasy.si *.loadbee.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com cdn.livechatinc.com stats.g.doubleclick.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.livechatinc.com *.dotit.com *.ncco.com dotit.wufoo.com stats.g.doubleclick.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.livechatinc.com stats.g.doubleclick.net dotit.wufoo.com www.wrike.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.livechatinc.com *.disqus.com *.dotit.com *.ncco.com stats.g.doubleclick.net cp-ywz-382.chili-publish.online cp-ywz-382.chili-publish-sandbox.online https://img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.livechatinc.com *.disqus.com stats.g.doubleclick.net chimpstatic.com *.wufoo.com www.youtube.com apis.google.com *.google.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com stats.g.doubleclick.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.livechatinc.com stats.g.doubleclick.net *.analytics.google.com *.google-analytics.com dotit.wufoo.com *.smartystreets.com apis.google.com *.google.pl 'self' 'unsafe-inline'; child-src stats.g.doubleclick.net http: https: blob: 'self' 'unsafe-inline'; default-src stats.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri stats.g.doubleclick.net 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' hubspot.mintlify.dev app.hubspot.com cdn-3.convertexperiments.com cdnjs.cloudflare.com connect.facebook.net cta-service-cms2.hubspot.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com platform.twitter.com play.vidyard.com run.pstmn.io script.crazyegg.com script.hotjar.com static.hotjar.com static.hsappstatic.net use.typekit.net www.googletagmanager.com www.google-analytics.com www.hubspot.com 'strict-dynamic' 'nonce-ioDVoKaZGVQtgyKicCDtOA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://fonts.bunny.net *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.googletagmanager.com *.doubleclick.net www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com magefan.com cm.magefan.com maps.googleapis.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.cdninstagram.com *.fbcdn.net *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com ajax.googleapis.com maps.googleapis.com *.disqus.com *.avada.io *.shopify.com *.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.instagram.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cash.app *.certcapture.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'none'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.instagram.com *.googleusercontent.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://north40outfitters.report-uri.com/r/t/csp/reportOnly; report-to report-endpoint; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-v8LPLAai4rtuybc0nMKc0g=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 script-src 'strict-dynamic' 'sha256-Nqnn8clbgv+5l0PgxcTOldg8mkMKrFn4TvPL+rYUUGg=' 'sha256-weogirlFgf2zfcYnMLiYLPFr1r8OlrcBmVkaXQ8/gr0=' 'sha256-hS1/d+uUuGe2Mab9hgGLbBcUpyHsASPtZlMP4ltEqdw=' 'sha256-ag96uDBR0oaIFczIQpabSozMTX7FZqwDo49K145MLFM=' 'sha256-ioYOEdGxe3k+hlzlsPm7DH8J2ihJoqGHOZ3NVrP0+KI=' 'sha256-OhHDlbnyDzZxZZU4kC8yaxqyRy4W9QoCDZOlHZDARgw=' 'sha256-xeobZ+06OCHR4HV3IGWhxWQ1pCyS5/9lhVEntjRCVAo=' 'nonce-OWIyZGMyNmQ0ZWIxYjIzYzA2ZDBiN2U5NzhjMmE3ZWRlNjI1MWQ5NDYzODMwNzdmMTFlYWRkNDM4ZTkzZDMyZmRlNzk5OTk3MTAyMTEyZmUwZWMwMjBjMWQxYmNiNzdkOGJlMjE3MmI2YWQ5NDM0N2NhNjdhODY5NWM1YzJmMTk=' self https://www.googletagmanager.com; default-src self; style-src 'sha256-xfi4cYsS7hWgjngpxpAvZTzj0DgRlUyoK77Bd+K2cuU=' 'sha256-ACHhjgOUuuyZySynlo+/Daurh4OiGc72PUDKH/XpFig=' 'sha256-w5Gyf/un8AQq3qFRt3Po1vM8lQcZpMY4OyTLKs7psfs=' 'sha256-jhO7MO7YAg0TLGTsluDJxzUM1Prn0dVd2mCuXK4Iugw=' 'sha256-71QAxCwq8RiThmnhSaiRBHeIt1ZeSKEmaoxieaZoYQc=' 'sha256-KBn0GSvWilHx7S+9fBz2bvN4kTXtWgzsefl3t16obJ4=' 'sha256-VvGbc5uc0VF+mSJCrqOZzX2tZY9gtbQDhs25w0MZMSs=' 'sha256-Ao6jE25UXUIRTfYn+cZ7FyEhN8Oqp93b7rDOxc7rx7o=' 'sha256-JJ3nwoTh8hUvTxwhTGEBGb1U1UbZuzjLzrqWZ8eP/pE=' 'sha256-0exl01RrkLKiyGSJEXwuUd47SZq8ZgrB03RNMJ3mEGA=' 'sha256-igtFAPFL5WVIIkl0KHcbdsk+saJpmz+AZYJBAG4FDBg=' 'sha256-6KigPIoBL0TmJWS4G5SUFk7bIGyl5FRn/1la0iTMMqU=' 'sha256-VFSNO+uz5RUBijCMEpM3I6Fc7orcCJPSXhq9xfLuQX4=' 'sha256-X11QMsuRjV/87y7Qxon5uoKI0swiIRW8IcITsMrGILE=' 'sha256-TP9uPznGcYkOScVXXihEQuKezOeUhN1OYBNa3h6piuQ=' 'sha256-x/fY75judYUbWYvafhMZVdK4MNLjlbF1953L82LgMr0=' 'sha256-Q+5na10OvLjb+FlkcxA6XrZNx5N96Wpl7HWy6LolM44=' 'sha256-nCC+XAHWtfbgggChp6PqZ3Ln0iVCBi1iMjVS6ZvYhAI=' 'nonce-OWIyZGMyNmQ0ZWIxYjIzYzA2ZDBiN2U5NzhjMmE3ZWRlNjI1MWQ5NDYzODMwNzdmMTFlYWRkNDM4ZTkzZDMyZmRlNzk5OTk3MTAyMTEyZmUwZWMwMjBjMWQxYmNiNzdkOGJlMjE3MmI2YWQ5NDM0N2NhNjdhODY5NWM1YzJmMTk=' self https://www.googletagmanager.com; connect-src self; frame-src self; img-src self; frame-ancestors none 1 report-uri /csp-violations; default-src 'self'; font-src * data:; img-src * blob: data:; object-src 'none'; media-src * blob: data:; form-action *; script-src 'self' https://*.kit.com https://*.convertkit.com https://*.stripe.com https://*.intercom.io 'strict-dynamic' 'report-sample' 'unsafe-eval' 'nonce-LjT00rI3RxwHV2gijtpmrA=='; style-src 'self' https: 'unsafe-inline'; connect-src *; child-src * blob:; worker-src 'self' blob: 1 script-src 'self' 'unsafe-eval' chrome-extension: 'unsafe-inline' 'unsafe-inline' https://botadmin.yakutia.click https://admin.verbox.ru https://mc.yandex.ru https://api-maps.yandex.ru https://widget.me-talk.ru https://yastatic.net https://core-renderer-tiles.maps.yandex.net https://static.site-chat.me https://265061847.mc.yandex.ru https://1093744743.mc.yandex.ru https://1546922566.mc.yandex.ru blob: https://777313552.mc.yandex.ru https://static.me-talk.ru https://mc.yandex.kz https://320332180.mc.yandex.ru https://connect.facebook.net https://mc.yandex.com https://ucads-cdn.ucweb.com https://he70.82omyo.com 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://mc.yandex.ru chrome-extension: https://mc.yandex.md cpnp-js-call https://metrika.yandex.ru 'unsafe-eval' 'unsafe-inline' 'unsafe-inline' https://mc.yandex.com https://ucads-cdn.ucweb.com https://pro.culture.ru https://connect.albank.ru https://dl.metabar.ru https://widget.me-talk.ru https://www.ciuvo.com https://m.youtube.com https://www.youtube.com https://div.show https://acestream.tv https://emet.live https://emet.news https://cashbacksurf.ru https://192.168.10.1 https://loader.media https://utp.ucweb.com https://doramaclub.site https://lordfilms.pub https://lordfilms.vin https://lordfilm-crew.net https://surfe.be https://lenta.ru https://yammyanime.club https://aniboom.one https://skysound7.com; object-src 'self'; report-uri /cspreportonly; 1 font-src data: *.gstatic.com oct8necdneu.azureedge.net *.oct8ne.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.vimeo.com *.oct8ne.com *.marvimundo.es *.marvimundo.com *.asesorcoloracion.es *.asesordecuidado.es *.diadermine.es *.ekomi.es *.jebbit.com *.reskyt.com *.cookiebot.com *.facebook.com *.doubleclick.net *.sequrapi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com www.xtento.com js.monei.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.oct8ne.com *.cookiebot.com *.google.com.ua *.facebook.com *.bing.com *.ggpht *.marvimundo.com *.ekomiapps.de cdn.doofinder.com *.clarity.ms *.rawgit.com *.jsdelivr.net *.doubleclick.net *.connectif.cloud *.google.sm *.google.sk *.google.si *.google.se *.google.rs *.google.ro *.google.pt *.google.pl *.google.no *.google.me *.google.lv *.google.lu *.google.lt *.google.li *.google.it *.google.is *.google.ie *.google.hu *.google.hr *.google.gr *.google.fr *.google.fi *.google.ee *.google.de *.google.cz *.google.com.mt *.google.com.gi *.google.co.uk *.google.ch *.google.bg *.google.be *.google.at *.google.ad www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.adyen.com *.webeyez.com *.nr-data.net *.facebook.net *.bing.com *.googlesyndication.com *.marvimundo.com *.ekomiapps.de *.cloudflare.com *.cloudflareinsights.com *.newrelic.com *.facebook.com *.clarity.ms *.doofinder.com *.connectif.cloud *.doubleclick.net *.google.sm *.google.sk *.google.si *.google.se *.google.rs *.google.ro *.google.pt *.google.pl *.google.no *.google.me *.google.lv *.google.lu *.google.lt *.google.li *.google.it *.google.is *.google.ie *.google.hu *.google.hr *.google.gr *.google.fr *.google.fi *.google.ee *.google.de *.google.cz *.google.com.ua *.google.com.mt *.google.com.gi *.google.co.uk *.google.ch *.google.bg *.google.be *.google.at *.google.ad *.sequrapi.com *.hotjar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com maps.googleapis.com www.xtento.com cdn.xtento.com js.monei.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.ekomiapps.de *.doofinder.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.adyen.com *.googleapis.com *.webeyez.com cognito-identity.eu-west-1.amazonaws.com firehose.eu-west-1.amazonaws.com *.trackingplan.com *.nr-data.net *.cookiebot.com *.googlesyndication.com *.bing.com *.marvimundo.com *.ekomiapps.de *.cloudflare.com *.cloudflareinsights.com *.newrelic.com *.doofinder.com wss://*.doofinder.com *.clarity.ms *.connectif.cloud *.facebook.com *.doubleclick.net *.google.sm *.google.sk *.google.si *.google.se *.google.rs *.google.ro *.google.pt *.google.pl *.google.no *.google.me *.google.lv *.google.lu *.google.lt *.google.li *.google.it *.google.is *.google.ie *.google.hu *.google.hr *.google.gr *.google.fr *.google.fi *.google.ee *.google.de *.google.cz *.google.com.ua *.google.com.mt *.google.com.gi *.google.co.uk *.google.ch *.google.bg *.google.be *.google.at *.google.ad *.sequrapi.com eu1-search.doofinder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com api.monei.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' *.gstatic.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.pipedrive.com data:; img-src 'self' *.ch-aviation.com *.servedbyadbutler.com servedbyadbutler.com *.pipedrive.com *.secureprivacy.ai images.prismic.io *.googletagmanager.com googletagmanager.com *.googleapis.com *.google.com *.gstatic.com data:; script-src 'self' *.servedbyadbutler.com servedbyadbutler.com *.googleapis.com *.googletagmanager.com *.google.com *.pipedrive.com *.highcharts.com *.secureprivacy.ai wasm-unsafe-eval data:; script-src-elem 'self' *.secureprivacy.ai *.servedbyadbutler.com servedbyadbutler.com *.gstatic.com *.googleapis.com *.googletagmanager.com *.googletagservices.com *.google.com *.pipedrive.com *.pipedriveassets.com *.doubleclick.net *.highcharts.com *.secureprivacy.ai data: 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; connect-src 'self' *.google.com *.gstatic.com *.servedbyadbutler.com servedbyadbutler.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.pipedrive.com *.doubleclick.net *.secureprivacy.ai *.sentry.io *.talentlyft.com data: 'unsafe-inline'; frame-src 'self' *.pipedrive.com *.doubleclick.net *.google.com; style-src 'self' *.fontawesome.com *.secureprivacy.ai *.googleapis.com 'unsafe-inline'; media-src 'self' data:; report-uri https://www.ch-aviation.com/csp-report-to 1 script-src 'nonce-815b55ace53276d00787ba7f226c7c37d4aa17b359fd0ebeaa845f339e8a5879' 'strict-dynamic';object-src 'none';base-uri 'none';frame-ancestors 'none'; 1 script-src 'nonce-78AD3ExHy6U0+4jgkMx2rQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=d006e7c4-d618-4be5-aef2-0978d3451dec; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 ; default-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com *.paypalobjects.com *.licdn.com *.clarity.ms https://ttz41d7zd1.execute-api.eu-west-1.amazonaws.com/Prod/js storage.googleapis.com cdn.mxpnl.com *.finance-calculator.co.uk angus.finance-calculator.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com *.dotdigital-pages.com script.hotjar.com player.vimeo.com www.googleoptimize.com *.bookingbug.com *.paypal.com static.trackedweb.net *.trackedlink.net *.gstatic.com static.zdassets.com *.trustpilot.com optimize.google.com tagmanager.google.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.facebook.net *.cquotient.com services.postcodeanywhere.co.uk cdn.cquotient.com www.googletagmanager.com googleads.g.doubleclick.net https://iploc.tryzens-analytics.com:12443 *.pcapredict.com maps.googleapis.com services.postcodeanywhere.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com *.sub2tech.com www.google-analytics.com p.cquotient.com static.hotjar.com www.googleadservices.com *.adyen.com geolocation.onetrust.com cdn.cookielaw.org *.googletagmanager.com extend.vimeocdn.com *.christopherward.com *.appointedd.com *.ratepay.com unpkg.com *.tryzens-analytics.com tally.so *.tally.so ; style-src 'self' 'unsafe-inline' *.klaviyo.com angus.finance-calculator.co.uk storage.googleapis.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.paypalobjects.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com *.adyen.com optimize.google.com tagmanager.google.com foursixty.com cdn.jsdelivr.net fonts.googleapis.com services.postcodeanywhere.co.uk cdn.cookielaw.org *.christopherward.com ; frame-src 'self' *.doubleclick.net storage.googleapis.com *.surveymonkey.com *.finance-calculator.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.dotdigital-pages.com *.bookingbug.com vars.hotjar.com *.paypal.com *.paypalobjects.com *.google.com widget.trustpilot.com *.youtube.com *.vimeo.com optimize.google.com www.facebook.com *.klarnaservices.com *.adyen.com extend.vimeocdn.com *.appointedd.com tally.so *.tally.so ; child-src 'none' ; img-src 'self' data: *.doubleclick.net *.vimeocdn.com *.clarity.ms px.ads.linkedin.com c.bing.com storage.googleapis.com angus.finance-calculator.co.uk *.paypalobjects.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com www.jrni.com *.bookingbug.com *.paypal.com stats.g.doubleclick.net *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com edge.disstg.commercecloud.salesforce.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com cdn.sub2tech.com *.sub2tech.com www.google-analytics.com *.paypalobjects.com static.secure-afterpay.com.au um.simpli.fi www.instagram.com www.googletagmanager.com services.postcodeanywhere.co.uk pixel.mathtag.com aa.agkn.com cx.atdmt.com www.facebook.com *.pbbl.co *.optimove.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.gstatic.com *.googleapis.com *.google.com *.adyen.com t1.stormiq.com cdn.cookielaw.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.christopherward.com *.cloudflare.com ; font-src 'self' data: www.christopherward.com fonts.gstatic.com res.cloudinary.com *.paypalobjects.com googleads.g.doubleclick.net ; connect-src 'self' *.onetrust.com *.mixpanel.com *.klaviyo.com *.collector-11207.tvsquared.com g.clarity.ms clarity.ms collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com angus.finance-calculator.co.uk dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com wss://*.hotjar.com *.hotjar.com *.hotjar.io *.paypal.com *.adyen.com widget.trustpilot.com wss://widget-mediator.zopim.com christopherward.zendesk.com *.trackedweb.net ekr.zdassets.com https://ttz41d7zd1.execute-api.eu-west-1.amazonaws.com/Prod/js* *.klarnaevt.com stats.g.doubleclick.net www.facebook.com https://www.tryzens-analytics.com:12280 *.pinterest.com *.klarnauserservices.com *.optimove.events www.google-analytics.com *.hotjar.com *.optimove.net *.hotjar.io https://uat.tryzens-analytics.com:12280 api.cquotient.com services.postcodeanywhere.co.uk cdn.cookielaw.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat google.com/pay extend.vimeocdn.com unpkg.com *.tryzens-analytics.com player.vimeo.com download-video-ak.vimeocdn.com ; form-action 'self' http://portal.afterpay.com http://portal-sandbox.afterpay.com *.playground.klarna.com *.klarna.com *.afterpay.com www.facebook.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.paypal.com *.adyen.com ; media-src 'self' static.zdassets.com res.cloudinary.com *.akamaized.net download-video-ak.vimeocdn.com player.vimeo.com ;; report-uri https://chw-csp.tryzens-analytics.com; 1 default-src 'self'; base-uri 'self'; script-src 'self' 'unsafe-eval' https: http: 'nonce-ab56dfec-bc8a-49f7-9297-6d3acff9390f' 'strict-dynamic'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.googletagmanager.com try.abtasty.com *.abtasty.com https://*.new-immo-group.app https://*.new-immo-group.dev https://*.safeti-immobilien.de https://*.safti.es https://*.safti.fr https://*.safti.fr; connect-src 'self' http://demo.safti.local:12081 https://googleads.g.doubleclick.net https://*.abtasty.com https://*.clarity.ms https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.new-immo-group.app https://*.new-immo-group.dev https://*.safeti-immobilien.de https://*.safti.es https://*.safti.fr https://*.safti.fr https://abtasty.com http://dcinfos-cache.abtasty.com https://api.privacy-center.org https://ariane.abtasty.com/ https://bo.safeti-immobilien.de/api https://bo.safti.es https://bo.safti.es/api/highlightblock https://bo.safti.es/api/saftiblock https://bo.safti.fr https://bo.safti.fr/api/highlightblock https://bo.safti.fr/api/saftiblock https://clarity.ms https://dcinfos-cache.abtasty.com https://google-analytics.com https://google.com https://googletagmanager.com https://maps.googleapis.com https://new-immo-group.app https://new-immo-group.dev https://safeti-immobilien.de https://safti.es https://safti.fr https://stats.g.doubleclick.net; font-src 'self' *.abtasty.com https://abtasty.com https://fonts.gstatic.com https://*.new-immo-group.app https://*.new-immo-group.dev https://*.safeti-immobilien.de https://*.safti.es https://*.safti.fr https://*.safti.fr; img-src 'self' data: *.new-immo-group.app *.new-immo-group.dev http://demo.safti.local:9873 https://*.clarity.ms https://*.leadsmonitor.io https://*.safeti-immobilien.de https://*.safti.es https://*.safti.fr https://*.safti.fr https://c.bing.com https://clarity.ms https://leadsmonitor.io https://maps.googleapis.com https://maps.gstatic.com https://nig-aws-preprod-bien-photo.s3.eu-west-3.amazonaws.com https://nig-aws-prod-bien-photo.s3.eu-west-3.amazonaws.com https://photo.safeti-immobilien.de https://purecatamphetamine.github.io https://safeti-immobilien.de https://safti.es https://safti.fr https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.google.de https://www.google.es https://www.google.fr https://www.googletagmanager.com https://sdk.privacy-center.org https://*.new-immo-group.dev; worker-src 'self' blob:; frame-src 'self' https://*.alainbossard.fr https://*.bien-estimer-safti.fr https://*.cloudpano.com https://*.dailymotion.com https://*.facebook.com https://*.floorfy.com https://*.google.com https://*.istaging.com https://*.klapty.com https://*.matterport.com https://*.nodalview.com https://*.previsite.com https://*.previsite.net https://*.provirtualvisit.com https://*.rhinov.pro https://*.ricohtours.com https://*.youtu.be https://*.youtube.com https://alainbossard.fr https://bien-estimer-preprod.new-immo-group.app/ https://bien-estimer-safti.fr https://cloudpano.com https://dailymotion.com https://facebook.com https://floorfy.com https://google.com https://istaging.com https://klapty.com https://login.microsoftonline.com/ https://matterport.com https://nodalview.com https://oauth2-proxy.new-immo-group.app/ https://*.new-immo-group.dev https://*.new-immo-group.app https://omega-de.new-immo-group.dev https://omega-es.new-immo-group.dev https://omega-fr.new-immo-group.dev https://omega-preprod-safti-de.new-immo-group.app https://omega-pt.new-immo-group.dev https://omega.safti.de https://omega.safti.es https://omega.safti.fr https://omega.safti.pt https://player.vimeo.com https://previsite.com https://previsite.net https://provirtualvisit.com https://rhinov.pro https://ricohtours.com https://td.doubleclick.net https://tour.giraffe360.com https://youtu.be https://youtube.com https://qa-assistant.abtasty.com/ https://play.danim.com/ http://localhost:*; frame-ancestors 'self' http://*.safti-fr.localhost http://safti-fr.localhost https://*.safeti-immobilien.de https://*.safti.es https://*.safti.fr https://*.safti.fr https://omega-de.new-immo-group.dev https://omega-es.new-immo-group.dev https://omega-fr.new-immo-group.dev https://omega-pt.new-immo-group.dev https://omega.safti.de https://omega.safti.es https://omega.safti.fr https://omega.safti.pt https://safeti-immobilien.de https://safti.es https://safti.fr; media-src 'self' https://*.safti.es https://*.safti.fr https://*.safti.fr https://*.safeti-immobilien.de https://safti.es https://safti.fr https://safeti-immobilien.de; object-src 'self' https://*.safti.es https://*.safti.fr https://*.safti.fr https://*.safeti-immobilien.de https://safti.es https://safti.fr https://safeti-immobilien.de; manifest-src 'self' *.new-immo-group.app https://*.safeti-immobilien.de/ https://*.safti.es https://*.safti.fr https://*.safti.fr https://safeti-immobilien.de https://safti.es https://safti.fr 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-cookieyes.com https://js.intercomcdn.com https://js.stripe.com https://m.stripe.network https://static.doubleclick.net https://widget.intercom.io https://widget.trustpilot.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.kr https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.br https://www.google.com.co https://www.google.com.eg https://www.google.com.hk https://www.google.com.mm https://www.google.com.mx https://www.google.com.my https://www.google.com.ng https://www.google.com.np https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vn https://www.google.cz https://www.google.de https://www.google.dk https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.is https://www.google.it https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.se https://www.google.si https://www.google.sk https://static.hotjar.com https://challenges.cloudflare.com https://*.b-cdn.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn-cookieyes.com https://www.youtube.com https://*.b-cdn.net ; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com; img-src 'self' data: https://cdn-cookieyes.com https://challenges.cloudflare.com https://www.youtube.com https://downloads.intercomcdn.com https://js.intercomcdn.com https://i.ytimg.com https://www.google.de https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.kr https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.br https://www.google.com.co https://www.google.com.eg https://www.google.com.hk https://www.google.com.mm https://www.google.com.mx https://www.google.com.my https://www.google.com.ng https://www.google.com.np https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vn https://www.google.cz https://www.google.de https://www.google.dk https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.is https://www.google.it https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.se https://www.google.si https://www.google.sk https://*.b-cdn.net; media-src 'self' https://*.b-cdn.net ; connect-src 'self' https://api-iam.intercom.io https://cdn-cookieyes.com https://challenges.cloudflare.com https://googleads.g.doubleclick.net https://m.stripe.com https://widget.trustpilot.com https://www.youtube.com wss://nexus-websocket-a.intercom.io ; frame-src 'self' https://www.youtube.com https://challenges.cloudflare.com https://js.stripe.com https://widget.trustpilot.com ; object-src 'none'; form-action 'self'; base-uri 'self'; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.slant.co *.userway.org eadn-wc05-14712294.nxedge.io *.fontawesome.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ *.instagram.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://td.doubleclick.net widget.usersnap.com *.googletagmanager.com *.doubleclick.net https://plumrocket.com landofcoder.com *.google.com/ *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com maps.googleapis.com maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.agkn.com *.doubleclick.net *.facebook.com *.google.com *.nexcesscdn.net *.pricespider.com *.sitescout.com *.userway.org *.pixel.ad eadn-wc05-14712294.nxedge.io *.reddit.com *.google-analytics.com *.googletagmanager.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ *.instagram.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.addthis.com *.crazyegg.com *.doubleclick.net *.elfsight.com *.facebook.net *.google-analytics.com *.googletagmanager.com *.klevu.com *.mapbox.com *.noibu.com *.pricespider.com *.userway.org d31qbv1cthcecs.cloudfront.net *.krxd.net *.pixel.ad *.sitescout.com *.owneriq.net eadn-wc05-14712294.nxedge.io widget.usersnap.com resources.usersnap.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com https://ajax.cloudflare.com *.kaptcha.com landofcoder.com *.avada.io *.google.com/ *.cloudflare.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com assets.braintreegateway.com *.mapbox.com *.pricespider.com *.userway.org eadn-wc05-14712294.nxedge.io *.tagmanager.google.com *.googletagmanager.com *.fontawesome.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net https://js.klevu.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.addthis.com *.crazyegg.com *.doubleclick.net *.facebook.com *.google-analytics.com *.googleapis.com *.mapbox.com *.noibu.com wss://input.noibu.com *.pricespider.com *.userway.org *.pixel.ad *.agkn.com *.sitescout.com *.owneriq.net *.elfsight.com eadn-wc05-14712294.nxedge.io widget.usersnap.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com *.kaptcha.com landofcoder.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://86c8b4f9-cefc-4184-9926-360586b833fe.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net use.typekit.net static.zip.co *.typekit.net *.australianplantsonline.com.au *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.omappapi.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.com bat.bing.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com pos.baidu.com *.baidu.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com use.typekit.net *.typekit.net *.australianplantsonline.com.au cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net use.typekit.net *.typekit.net *.adobedtm.com *.australianplantsonline.com.au *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in *.google.co.in *.sc.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com *.paypalobjects.com *.paypal.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ytimg.com static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.app bat.bing.com *.adobe.net *.site.com dev-54ta5gq-6zoeclprllyye.ap-3.magentosite.cloud 'self' *.google.bg *.facebook.net *.doubleclick.net *.googlesyndication.com *.instant.one *.choosewine.com.au rec.smartlook.com t.cfjump.com img.youtube.com maps.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net t.zip.co cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com magefan.com cm.magefan.com *.disqus.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com https://tags.srv.stackadapt.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com *.ytimg.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://api.addressfinder.io *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com use.typekit.net typekit.net australianplantsonline.com.au *.australianplantsonline.com.au adobedtm.com adobe.com z.clarity.ms clarity.ms rec.smartlook.com smartlook.com t.cfjump.com cfjump.com zip.co static.zipmoney.com.au zipmoney.com.au tagmanager.google.com google.com www.google.co.in adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com bidswitch.net doubleclick.net casalemedia.com openx.net taboola.com outbrain.com pubmatic.com google-analytics.com 3lift.com rubiconproject.com google.co.in sc.omtrdc.net demdex.net dpm.demdex.net cm.everesttech.net everesttech.net magentocommerce.com widgets.magentocommerce.com googleadservices.com paypalobjects.com t.paypal.com paypal.com ftcdn.net behance.net p.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io gstatic.com sandbox.paypal.com swagger.io afterpay.com facebook.com glopal.com glopalservice.com braintreegateway.com d.adroll.com c.bing.com bing.com googletagmanager.com ib.adnxs.com adnxs.com s3-us-west-2.amazonaws.com amazonaws.com js-agent.newrelic.com newrelic.com sandbox.my.site.com hello.zonos.com zonos.com front.optimonk.co optimonk.co qa.clevertar.app *.clevertar.com bat.bing.com cardinalcommerce.com optimonk.com a.omappapi.com googleapis.com unpkg.com magento-datasolutions.com omtrdc.net vimeocdn.com youtube.com magento-ds.com google.bg facebook.net googlesyndication.com trackedlink.net trackedweb.net ddlnk.net dotdigital-pages.com dhv2ziothpgrr.cloudfront.net yotpo.com yahoo.com instant.one addthis.com dnky.co dotdigital.internal pages.com adobe.net ccdc02.com downloads.mailchimp.com www.gstatic.com/recaptcha/ www.google.com/recaptcha/ *.magento-datasolutions.com portal.sandbox.clearpay.co.uk portal.clearpay.co.uk portal.sandbox.afterpay.com portal.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com s7.addthis.com *.instant.one *.choosewine.com.au *.winedirect.com.au *.adobedtm.com *.z.clarity.ms *.clarity.ms *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co *.zipmoney.com.au *.adroll.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.googleadservices.com *.paypalobjects.com *.paypal.com *.ftcdn.net *.behance.net *.typekit.net *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io *.bing.com *.adnxs.com *.amazonaws.com *.newrelic.com *.sandbox.my.site.com *.zonos.com *.optimonk.co *.clevertar.app *.cardinalcommerce.com *.optimonk.com *.googleapis.com *.unpkg.com *.omtrdc.net *.dhv2ziothpgrr.cloudfront.net *.yotpo.com *.yahoo.com *.addthis.com *.dnky.co *.dotdigital.internal *.pages.com *.vimeo.com *.adobe.net *.ccdc02.com js.braintreegateway.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com pos.baidu.com *.baidu.com *.disqus.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.cloudflare.com https://static.hotjar.com https://*.hotjar.com https://cdn.oribi.io https://*.srv.stackadapt.com https://*.tiktok.com https://qvdt3feo.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.addressfinder.io cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com static.zip.co *.australianplantsonline.com.au *.a.omappapi.com *.clevertar.app *.choosewine.com.au *.cardinalcommerce.com *.googleapis.com *.googlesyndication.com *.dnky.co *.instant.one a.omappapi.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.winedirect.com.au *.yotpo.com unsafe-inline assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com https://*.srv.stackadapt.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src pos.baidu.com *.baidu.com use.typekit.net *.typekit.net *.australianplantsonline.com.au *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://api.addressfinder.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com dpe0djwch8671.cloudfront.net a.omappapi.com js.monitor.azure.com *.js.monitor.azure.com jfapiprod.optimonk.com cdn-limit.optimonk.com use.typekit.net *.typekit.net bam.nr-data.net mcstaging.australianplantsonline.com.au because it violates the following Content Security Policy directive: "connect-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.telemetry-dev.adobe.io search-admin-ui.magento-ds.com telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io *.magento-datasolutions.com *.magento-ds.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com ekr.zdassets.com/ *.instant.one *.choosewine.com.au *.winedirect.com.au *.z.clarity.ms *.clarity.ms stats.g.doubleclick.net *.g.doubleclick.net manager.eu.smartlook.cloud *.smartlook.com www.google.co.in *.adobedtm.com *.adobe.com rec.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.co.in *.sc.omtrdc.net *.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com *.googleadservices.com *.analytics.yahoo.com *.paypalobjects.com t.paypal.com *.paypal.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io site-assets.afterpay.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com cdn1.stamped.io checkout.paypal.com stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.app bat.bing.com api.omappapi.com front.optimonk.com australiaeast-1.in.applicationinsights.azure.com cdn-account.optimonk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.aptrinsic.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com api.amplitude.com https://*.tiktok.com https://*.srv.stackadapt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.cumulusmedia.com 'report-sample'; base-uri 'self'; script-src 'strict-dynamic' 'self' 'inline-speculation-rules' *.cumulusmedia.com 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' *.googletagmanager.com 'sha256-GyUsdBtdHKlqtQSzGDSvNCHPdK8s1GO2S2y9jj4oYog=' *.google-analytics.com stats.wp.com 'sha256-+zMjo4vywISTRiN+RDp+W665czd5i8MOxiovBqr69F0=' 'sha256-X7SYke/fTbXP5LTn1g56zfcWCiSzQpGhzSLHvvNm0jo=' form.jotform.com cdn.jotfor.ms *.cookielaw.org 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' *.onetrust.com connect.facebook.net s3.tradingview.com https://www.google.com/recaptcha/ https://challenges.cloudflare.com/turnstile/ 'sha256-riitXBKGtl5y5ccA7GF6ccqJuwEVP5tm8j0ff/fbw9U=' 'sha256-k8zlbQ8Yw3tO1mzGrtP0m5BxCIEa+iH8LXA4dctSEMI=' 'sha256-wBhUGm/Lzl4TA4tJsiguA/vnV9LaNE6plmk4Xn/6/Mw=' 'sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw=' 'sha256-5oZoxPs07HkLGv2K/yyNWiLlCvxwJuQdhXLKg2AXhT0=' 'nonce-genr+U+q7ifdXUDH9fz+ouHI' 'report-sample'; style-src 'self' 'unsafe-inline' *.cumulusmedia.com fonts.googleapis.com cdn.jotfor.ms 'report-sample'; img-src 'self' data: *.cumulusmedia.com *.wp.com *.googletagmanager.com *.google-analytics.com *.cookielaw.org *.jotform.com; font-src 'self' data: *.cumulusmedia.com fonts.gstatic.com https://www.google.com/recaptcha/; connect-src 'self' *.cumulusmedia.com *.google-analytics.com *.doubleclick.net submit.jotform.com *.cookielaw.org *.onetrust.com; object-src 'none'; frame-src 'self' *.cumulusmedia.com *.jotform.com *.youtube.com s.tradingview.com www.tradingview-widget.com challenges.cloudflare.com; report-uri https://www.cumulusmedia.com/wp-admin/admin-ajax.php?action=wpshr 1 default-src *; img-src https:; frame-src 'none' 1 default-src 'self'; base-uri 'self'; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; media-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ista.piwik.pro https://*.usercentrics.eu https://www.youtube.com https://maps.googleapis.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://*.googleapis.com https://tracking.ista.com https://www.googletagmanager.com https://www.clickcease.com https://www.googleoptimize.com https://*.hotjar.com https://siteintercept.qualtrics.com https://*.siteintercept.qualtrics.com https://www.facebook.com https://connect.facebook.net https://*.twitter.com 'report-sample'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https: blob: 'report-sample'; style-src 'self' 'unsafe-inline' https://*.usercentrics.eu https://fonts.googleapis.com 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://fonts.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com/debug/badge.css 'report-sample'; worker-src 'self' 'unsafe-inline' 'unsafe-eval' blob: 'report-sample'; object-src 'none'; connect-src 'self' https://tracking.ista.com https://ista.piwik.pro https://*.usercentrics.eu https://fonts.googleapis.com *.google.com https://*.googleapis.com https://*.gstatic.com blob: data: https://*.google.com https://*.google.de https://*.g.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://siteintercept.qualtrics.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; frame-src 'self' https://*.usercentrics.eu *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.googlesyndication.com https://tracking.ista.com https://www.googletagmanager.com https://www.facebook.com https://*.twitter.com; frame-ancestors 'self'; report-uri https://www.ista.com/corporate/@http-reporting?csp=report&requestTime=1765900039979168&requestHash=91853f9fb895be31b19c274c48e17833082abc09 1 font-src fonts.gstatic.com *.kueskipay.com *.gstatic.com *.zotabox.com https://*.tawk.to *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.kueskipay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com https://hotjar.com https://fast.amc.demdex.net https://secure.authorize.net https://static.addtoany.com https://www.googletagmanager.com https://td.doubleclick.net https://*.creativecdn.com https://*.mercadopago.com https://*.mercadopago.com.mx *.mercadolibre.com *.google.com/ *.sandbox.paypal.com *.paypalobjects.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.google.com *.google.com.mx *.facebook.com *.zotabox.com *.mercadolibre.com *.mercadolivre.com *.swagger.io *.akamai.net *.dico.com.mx https://bat.bing.com https://*.tawk.to https://www.googletagmanager.com https://*.mercadopago.com.mx *.mlstatic.com *.mercadopago.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.sandbox.paypal.com *.paypalobjects.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://chimpstatic.com downloads.mailchimp.com *.list-manage.com *.facebook.com https://connect.facebook.net graph.facebook.com https://business.facebook.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.addtoany.com https://*.hotjar.com https://*.zotabox.com *.facebook.net *.tawk.to *.mailchimp.com *.pinterest.com *.tumblr.com *.tumblr.cb1 *.doubleclick.net https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://pilot-payflowlink.paypal.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://*.paypal.com https://graph.facebook.com https://*.kueskipay.com https://*.doubleclick.net https://*.tawk.to https://*.hotjar.io https://*.mercadolibre.com https://*.google-analytics.com https://*.hsforms.com https://*.dico.com.mx *.google.com https://*.mercadopago.com https://*.sandbox.paypal.com *.paypalobjects.com https://t.elasticsuite.io https://*.hsforms.net https://*.creativecdn.com https://bat.bing.com https://analytics.tiktok.com https://www.googleoptimize.com *.mlstatic.com *.mercadopago.com *.sandbox.paypal.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline downloads.mailchimp.com https://static.klaviyo.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.tawk.to *.fontawesome.com *.addtoany.com maxcdn.bootstrapcdn.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net https://amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com www.facebook.com https://connect.facebook.net graph.facebook.com https://business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.doubleclick.net https://dpm.demdex.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://pilot-payflowlink.paypal.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://*.paypal.com https://graph.facebook.com https://*.kueskipay.com https://*.doubleclick.net https://*.tawk.to https://*.hotjar.com https://*.hotjar.io https://*.zotabox.com https://*.mercadolibre.com *.google-analytics.com https://*.hsforms.com https://*.dico.com.mx https://*.google.com https://*.mercadopago.com https://*.sandbox.paypal.com *.paypalobjects.com t.elasticsuite.io https://*.hsforms.net wss://*.tawk.to https://*.creativecdn.com https://analytics.tiktok.com https://google.com *.mercadopago.com *.mercadolibre.com http://dpm.demdex.net *.sandbox.paypal.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-7HLxg0ZTvofV3xsvXJKevA==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=7641aabe-fe42-44fd-8930-561dd874303f; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self'; script-src 'self' *.artfut.com *.bootstrapcdn.com *.clarity.ms *.cloudfront.net *.criteo.com *.facebook.com *.fullstory.com *.gstatic.com *.google-analytics.com *.google.com *.googleapis.com *.jsdelivr.net *.livechatinc.com *.moengage.com *.onetrust.com *.razorpay.com *.tatadigital.com *.trackier.com *.unbxdapi.com c.amazon-adsystem.com connect.facebook.net googleads.g.doubleclick.net sc-static.net tr.snapchat.com www.googleadservices.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.googleapis.com *.jsdelivr.net *.onetrust.com www.gstatic.com; img-src 'self' data: https:; connect-src 'self' aax-eu.amazon-adsystem.com ad.doubleclick.net analytics.google.com api.fastrackeyewear.com apac-recommendations.unbxd.io ara.paa-reporting-advertising.amazon connect.facebook.net d3995ea24pmi7m.cloudfront.net google.com *.amazon.in *.clarity.ms *.criteo.com *.facebook.com *.fullstory.com *.google.com *.googleapis.com *.livechatinc.com *.moengage.com *.onetrust.com *.paytm.in *.phonepe.com *.razorpay.com *.tatadigital.com *.titaneyeplus.com *.unbxdapi.com s.amazon-adsystem.com search.unbxd.io secure.paytmpayments.com stats.g.doubleclick.net tr.snapchat.com tr6.snapchat.com www.google-analytics.com www.google.co.in www.google.com www.googleadservices.com; font-src 'self' *.amazon-adsystem.com *.gstatic.com *.google.co.in *.onetrust.com *.unbxd.io ad.doubleclick.net ara.paa-reporting-advertising.amazon google.com stats.g.doubleclick.net www.google-analytics.com www.googleadservices.com; frame-src 'self' *; report-uri https://admin.titaneyeplus.com/csp.php; 1 script-src 'self' 'nonce-fE2y1moMfEUf5xGkLZ77XaRDHpCH8mMDnKJQ9UKo7vw=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://api.w3-edge.com https://www.googletagmanager.com https://www.googletagservices.com https://cdn.privacy-mgmt.com https://cdnjs.cloudflare.com https://secure.hook6vein.com https://a.usbrowserspeed.com https://www.details-enterprise-7.com https://pi.pardot.com https://www.google.com https://www.google-analytics.com https://go.skymedia.co.uk https://js-agent.newrelic.com https://bam.nr-data.net https://yoast.com https://ajax.googleapis.com https://assets.adobedtm.com https://www.gstatic.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://cdn.cflight.co.uk https://gdpr-tcfv2.sp-prod.net https://fluid.4strokemedia.com https://cdnb.4strokemedia.com https://z.moatads.com https://imasdk.googleapis.com https://pagead2.googlesyndication.com https://s0.2mdn.net;connect-src 'self' https://bam.nr-data.net https://cdn.privacy-mgmt.com https://my.yoast.com https://www.skymedia.co.uk https://cdn.skymedia.co.uk https://cdn.skymedia.ie https://cmp.skymedia.de https://edge.adobedc.net https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://fluid.4strokemedia.com https://feed.4strokemedia.com https://api.condatis.sky https://playback.brightcovecdn.com https://videos.skysports.com https://manifest.prod.boltdns.net https://securepubads.g.doubleclick.net https://videos.skynews.com https://csi.gstatic.com https://idx.liadm.com; img-src 'self' data: https: https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie; font-src 'self' data: https://fonts.gstatic.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://fonts.bunny.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://fonts.bunny.net;media-src 'self' https: blob: https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://playback.brightcovecdn.com https://videos.skysports.com https://videos.skynews.com;frame-src 'self' https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://players.brightcove.net https://www.youtube.com https://securepubads.g.doubleclick.net https://tpc.googlesyndication.com https://cdn.privacy-mgmt.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie; 1 base-uri 'self'; form-action 'self'; default-src 'self'; connect-src 'self' data: https://stats.nederhost.nl/ https://zammad.nederhost.nl/ wss://zammad.nederhost.nl/; frame-ancestors 'none'; frame-src 'self'; img-src 'self' data:; report-to csp-endpoint; report-uri /_/report_csp_violation; script-src 'self' 'nonce-poIv0wUAcssI2ImN' 'unsafe-eval' https://stats.nederhost.nl/ https://cdn.matomo.cloud/stats.nederhost.nl/ https://zammad.nederhost.nl/; style-src 'self' data: 'nonce-poIv0wUAcssI2ImN' https://zammad.nederhost.nl/; style-src-attr 'unsafe-inline'; 1 font-src www.paypalobjects.com https://fonts.gstatic.com *.cloudflare.com *.googleapis.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://0merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://assets.braintreegateway.com https://c.paypal.com https://tst.kaptcha.com https://geostag.cardinalcommerce.com https://0merchantacsstag.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://checkout.paypal.com https://www.google.com https://player.vimeo.com static.addtoany.com *.addthis.com *.cookiebot.com *.criteo.com *.fls.doubleclick.net *.awin1.com *.zenaps.com *.wesupply.xyz https://wesupplylabs.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.it https://b.stats.paypal.com https://c.paypal.com https://dub.stats.paypal.com blob: https://maps.google.com https://maps.gstatic.com *.facebook.com *.google.it *.bidswitch.net *.doubleclick.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.ups.analytics.yahoo.com *.adform.net *.omnitagjs.com *.casalemedia.com id5-sync.com *.360yield.com *.ivitrack.com *.mediavine.com/ *.outbrain.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.krxd.net *.thebrighttag.com *.cookiebot.com *.roeye.com *.emxdgt.com *.yieldmo.com *.postrelease.com *.criteo.com *.1rx.com *.dmxleo.com *.unrulymedia.com *.googleapis.com *.gstatic.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bird.eu https://cdn.clerk.io *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.google.com https://www.gstatic.com https://c.paypal.com https://songbirdstag.cardinalcommerce.com https://maps.google.com https://maps.googleapis.com static.addtoany.com connect.facebook.net *.addthis.com *.moatads.com *.addthisedge.com *.cookiebot.com *.criteo.com *.gestpay.net *.dwin1.com *.hotjar.com *.sella.it *.roeyecdn.com *.preciso.net *.2trk.info *.googleapis.com *.gstatic.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://api.clerk.io https://cdn.clerk.io *.google.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.hsforms.net *.hsforms.com *.cloudflare.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://www.gstatic.com *.cloudflare.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.addtoany.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://payments.sandbox.braintree-api.com https://api.sandbox.braintreegateway.com https://origin-analytics-sand.sandbox.braintree-api.com https://centinelapistag.cardinalcommerce.com https://kg668dbov0.execute-api.us-east-1.amazonaws.com https://writer.cardinalcommerce.com https://www.sandbox.paypal.com https://vimeo.com https://maps.googleapis.com *.addthis.com *.googleapis.com *.doubleclick.net *.cookiebot.com *.google.com *.criteo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com t.elasticsuite.io *.hsforms.net *.hsforms.com analytics.google.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://d1aosrekaw7sk8.cloudfront.net/reports; upgrade-insecure-requests; default-src 'self' 'unsafe-eval' 'unsafe-inline' ws: blob: data: tagging.dupixent.com ad.doubleclick.net iron-wsa01 ironport 8188202.fls.doubleclick.net ad.doubleclick.net adservice.google.com aim-tag.hcn.health ajax.googleapis.com analytics.google.com analytics.tiktok.com ap.lijit.com apis.google.com apps.healthgrades.com bat.bing.com bcbolt446c5271-a.akamaihd.net bcp.crwdcntrl.net bh.contextweb.com c.clarity.ms cdn.cookielaw.org cdn.di-capt.com cdn.jsdelivr.net cdnjs.cloudflare.com clientstream.launchdarkly.com cm.g.doubleclick.net code.jquery.com connect.facebook.net content.hotjar.io contextual.media.net d1lkfzu2puirk6.cloudfront.net di.rlcdn.com dpm.demdex.net eb2.3lift.com edge.api.brightcove.com fast.fonts.net feedback-pa.clients6.google.com fonts.cdnfonts.com fonts.googleapis.com fonts.googleapis.com fonts.gstatic.com form.typeform.com geolocation.onetrust.com googleads.g.doubleclick.net gum.criteo.com i.liadm.com i6.liadm.com ib.adnxs.com insight.adsrvr.org insights.algolia.io integrations.eu-de.assistant.watson.appdomain.cloud js.adsrvr.org manzanasjuegosco-a.akamaihd.net maps.googleapis.com maps.gstatic.com match.adsrvr.org match.deepintent.com match.sharethrough.com metrics.brightcove.com metrics.hotjar.io ms-cookie-sync.presage.io pixel.rubiconproject.com player.vimeo.com players.brightcove.net players.brightcove.net privacyportal-eu.onetrust.com px.ads.linkedin.com px4.ads.linkedin.com region1.analytics.google.com region1.google-analytics.com rialto-gms.s3.amazonaws.com rtb-csync.smartadserver.com rtb.gumgum.com sc-static.net script.hotjar.com security-eu.mimecast.com snap.licdn.com spoppe-b.azureedge.net ssum-sec.casalemedia.com staging-apps.healthgrades.com static.hotjar.com stats.g.doubleclick.net sync.1rx.io sync.crwdcntrl.net tags.bluekai.com td.doubleclick.net td.doubleclick.net thrtle.com token.rubiconproject.com translate-pa.googleapis.com translate.googleapis.com trc.lhmos.com trotjidayo-1.algolianet.com trotjidayo-2.algolianet.com trotjidayo-3.algolianet.com trotjidayo-dsn.algolia.net uipglob.semasio.net unpkg.com use.fontawesome.com vc.hotjar.io vjs.zencdn.net web-chat.global.assistant.watson.appdomain.cloud www.clarity.ms www.dupixent.com www.facebook.com www.google-analytics.com www.google-analytics.com www.google.com www.google.com.au www.googletagmanager.com fresnel-events.vimeocdn.com vod-adaptive-ak.vimeocdn.com player-telemetry.vimeo.com fresnel.vimeocdn.com www.medtargetsystem.com z.clarity.ms ws.hotjar.com secure.adnxs.com www.gstatic.com www.eventmgmtportal.com sanofi-privacy.my.onetrust.com trotjidayo-1.algolianet.com trotjidayo-3.algolianet.com trotjidayo-2.algolianet.com trotjidayo-dsn.algolia.net lpopeventportal-2-0-2.sanofigenzyme.intouch-preview.com som.healthgrades.com sanofi-japan-dev.eval.janraincapture.com sanofi-japan-staging.eval.janraincapture.com sanofi-japan.us.janraincapture.com sanofi-dev.us-dev.janraincapture.com sanofi-staging.us-dev.janraincapture.com sanofi.us.janraincapture.com sanofi-dev.eu-dev.janraincapture.com sanofi-staging.eu-dev.janraincapture.com sanofi.eu.janraincapture.com vod-adaptive-ak.vimeocdn.com player-telemetry.vimeo.com fresnel.vimeocdn.com fresnel-events.vimeocdn.com photos.healthgrades.com use.typekit.net p.typekit.net; 1 base-uri 'none'; font-src 'self' data: https://sumdog.com https://*.sumdog.com netdna.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com script.hotjar.com; img-src 'self' blob: data: visualisations0.sumdog.com https://sumdog.com https://*.sumdog.com imgsct.cookiebot.com s3.eu-west-1.amazonaws.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' https://sumdog.com https://*.sumdog.com https://students.sumdog.com/WebGL/Core/Build/ *.cookiebot.com www.googletagmanager.com/gtag www.google.com/recaptcha/api.js www.gstatic.com/recaptcha/* www.googleoptimize.com *.paypal.com www.paypalobjects.com *.cardinalcommerce.com *.hotjar.com 'unsafe-hashes' 'sha256-gPjlli1HEdLlR0AZTY971/wQVOdSkl9mEinLnxrPpJw=' 'nonce-949eec08b8909b5f3a85e877124d74b9'; style-src 'self' 'unsafe-inline' https://sumdog.com https://*.sumdog.com *.cookiebot.com assets0.sumdog.com fonts.googleapis.com accounts.google.com assets.braintreegateway.com; report-uri /csp-violation-report; connect-src * blob: data:; media-src 'self' blob: https://sumdog.com https://*.sumdog.com questions-assets0.sumdog.com; frame-src * 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.stape.io static.klaviyo.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io js.mollie.com https://plumrocket.com https://accounts.google.com *.consentmanager.net ridersdeal.mycleverpush.com www.sovendus-benefits.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://www.mollie.com *.consentmanager.net cookie-cdn.cookiepro.com www.googletagmanager.com pagead2.googlesyndication.com www.facebook.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io js.mollie.com https://accounts.google.com https://www.gstatic.com *.kameleoon.io *.kameleoon.com *.kameleoon.eu *.kameleoon.net *.consentmanager.net maps.googleapis.com 'self' *.sovendus.com chimpstatic.com *.googlesyndication.com *.cookiepro.com connect.facebook.net *.hotjar.com static.cleverpush.com *.zdassets.com apis.google.com www.google.com www.gstatic.com cdn.jsdelivr.net magento-recs-sdk.adobe.net static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.googleapis.com *.googletagmanager.com *.stape.io https://accounts.google.com https://www.gstatic.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://accounts.google.com api.cleverpush.com *.cookiepro.com data.ridersdeal.com *.zdassets.com ridersdeal.zendesk.com maps.googleapis.com *.sovendus.com www.chatbase.co bam.nr-data.net ridersdeal-web.talk.insaight.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action 'self'; report-to csp-report; 1 style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; connect-src 'self' https://region1.analytics.google.com https://rl.quantummetric.com https://ingesteu.quantummetric.com https://maps.googleapis.com https://widget.staging.meetingdoctors.com https://pagead2.googlesyndication.com https://region1.google-analytics.com https://www.googleadservices.com https://adservice.google.com https://www.google.com https://google.com https://www.google-analytics.com https://analytics.google.com https://www.google.es https://www.google.de https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://insight.adsrvr.org https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://cdn.cookielaw.org https://ursae.asisa.es https://www.asisa.es https://asisa.es https://www.youtube.com https://vltkthtp1c.execute-api.eu-west-1.amazonaws.com https://asisa-es.my.salesforce-scrt.com https://privacyportal-de.onetrust.com https://asisa-es.my.site.com; child-src 'self' https://widget.staging.meetingdoctors.com https://vltkthtp1c.execute-api.eu-west-1.amazonaws.com https://www.googletagmanager.com https://www.youtube.com; script-src 'self' 'unsafe-eval' https://www.youtube.com https://widget.staging.meetingdoctors.com https://maps.googleapis.com https://www.gstatic.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org; script-src-elem 'self' 'unsafe-inline' https://googleads.g.doubleclick.net https://maps.googleapis.com https://cdn.cookielaw.org https://www.googletagmanager.com https://www.gstatic.com https://js.adsrvr.org https://cdn.quantummetric.com https://analytics.tiktok.com https://www.youtube.com https://widget.staging.meetingdoctors.com https://asisa-es.my.site.com https://pagead2.googlesyndication.com https://widget.meetingdoctors.com https://connect.facebook.net https://www.googleadservices.com; frame-src 'self' https://widget.staging.meetingdoctors.com https://vltkthtp1c.execute-api.eu-west-1.amazonaws.com https://www.googletagmanager.com https://www.youtube.com https://patient-test.vital-hub.com https://insight.adsrvr.org https://match.adsrvr.org https://asisa-es.my.site.com https://cloud.info.asisa.es; media-src 'self' https://cms.meetingdoctors.com; img-src 'self' data: https://lh7-rt.googleusercontent.com https://cms.meetingdoctors.com https://www.googletagmanager.com https://cdn-icons-png.flaticon.com https://maps.googleapis.com https://maps.gstatic.com https://cdn.cookielaw.org https://www.google.com https://www.google.es https://pagead2.googlesyndication.com https://www.facebook.com https://streetviewpixels-pa.googleapis.com; default-src 'self'; font-src 'self' data: https://fonts.gstatic.com; style-src-attr 'self' 'unsafe-inline' https://asisa-es.my.site.com; report-uri /bin/wasisa/csp-report; 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com https://script.hotjar.com https://fonts.gstatic.com https://embed.tawk.to https://i5.walmartimages.com https://use.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.canadapost.ca https://sso.epost.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.dotdigital-pages.com *.dotdigital.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com webchat.dotdigital.com webchat.staging.dotdigital.com www.xtento.com https://vars.hotjar.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://testflex.cybersource.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com mageside.com *.canadapost.ca *.googleapis.com *.gstatic.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.gstatic.com *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://maps.gstatic.com https://www.google.com https://www.google.ca https://stats.g.doubleclick.net https://tools.applemediaservices.com https://aq.flippenterprise.net https://f.wishabi.net https://cdn.flippenterprise.net https://apple-resources.s3.amazonaws.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com maps.googleapis.com developers.google.com *.googleapis.com *.google.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://maps.googleapis.com https://maps.gstatic.com https://connect.facebook.net https://static.hotjar.com https://kent-esengage.live.exchangesolutions.com https://cdn.jsdelivr.net https://embed.tawk.to https://a.omappapi.com https://aq.flippenterprise.net *.disqus.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.hsforms.net *.hsforms.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com display.ugc.bazaarvoice.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://a.omappapi.com https://embed.tawk.to https://aq.flippenterprise.net https://use.typekit.net https://p.typekit.net *.gstatic.com https://js.klevu.com https://kent.ca 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://api.omappapi.com https://maps.googleapis.com https://va.tawk.to https://embed.tawk.to https://aq.flippenterprise.net https://dam.flippenterprise.net https://app.launchdarkly.com https://region1.analytics.google.com https://cdn-gateflipp.flippback.com https://p.flipp.com https://events.launchdarkly.com https://google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: code.ionicframework.com maxcdn.bootstrapcdn.com media.flixfacts.com media.flixcar.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com media.flixcar.com *.zdassets.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com gateway.apaylater.com gateway.atome.sg media.flixcar.com *.flix360.com *.flix360.io 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ gateway.apaylater.com gateway.atome.sg static.hotjar.com cdnjs.cloudflare.com js-agent.newrelic.com bam-cell.nr-data.net www.google.com www.gstatic.com media.flixcar.com media.flixfacts.com *.zendesk.com *.zdassets.com *.outbrain.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com gateway.apaylater.com gateway.atome.sg code.ionicframework.com *.freshchat.com maxcdn.bootstrapcdn.com media.flixcar.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleapis.com bam-cell.nr-data.net *.google-analytics.com media.flixcar.com *.zendesk.com *.zdassets.com *.outbrain.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-lRxLGvmww7P1P006UxQcFUd4mqVSXfca'; base-uri 'none' 1 script-src 'nonce-vvOO1NvK3LdE7ksJJloUQExunTRsrBPr' 'strict-dynamic' 'self' https: http:; report-uri /.netlify/functions/__csp-violations 1 default-src 'none'; base-uri 'self'; block-all-mixed-content; connect-src 'self' support.webkeeper.ch wss://support.webkeeper.ch www.google-analytics.com my.webkeeper.ch stats.g.doubleclick.net; font-src * data:; form-action 'self' www.webkeeper.ch; frame-ancestors 'none'; frame-src support.webkeeper.ch; img-src * data:; manifest-src 'self'; media-src support.webkeeper.ch; script-src 'self' 'unsafe-inline' 'unsafe-eval' support.webkeeper.ch www.google-analytics.com maps.googleapis.com developers.google.com treellionaire.com data:; style-src 'self' 'unsafe-inline' support.webkeeper.ch fonts.googleapis.com data:; report-uri /csp-report.php 1 default-src 'self' https: data: wss: http: umbraco.tv packages.umbraco.org our.umbraco.org; block-all-mixed-content; form-action https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' ajax.cloudflare.com static.cloudflareinsights.com umbraco.tv packages.umbraco.org our.umbraco.org code.jquery.com fonts.googleapis.com use.typekit.net unpkg.com cdn.jsdelivr.net ajax.aspnetcdn.com kit.fontawesome.com www.googletagmanager.com www.recaptcha.net www.google.com www.google-analytics.com www.gstatic.com js.authorize.net jstest.authorize.net;font-src 'self' https: data: fonts.gstatic.com use.typekit.net kit-pro.fontawesome.com;img-src 'self' https: data: umbraco.tv packages.umbraco.org our.umbraco.org p.typekit.net www.goole-analytics.com www.gstatic.com www.googletagmanager.com;media-src https: data: umbraco.tv packages.umbraco.org our.umbraco.org p.typekit.net;style-src 'self' 'unsafe-inline' https: data: use.typekit.net p.typekit.net fonts.googleapis.com kit-pro.fontawesome.com unpkg.com cdn.jsdelivr.net; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.stape.io *.fontawesome.com https://fonts.bunny.net *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://widgets.trustedshops.com world.nerogiardini.it data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * world.nerogiardini.it 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com world.nerogiardini.it 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * world.nerogiardini.it 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io https://firebasestorage.googleapis.com intpaye.netsgroup.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com world.nerogiardini.it data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com world.nerogiardini.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.feedaty.com https://static.klaviyo.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com world.nerogiardini.it 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com world.nerogiardini.it 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.stape.io https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site world.nerogiardini.it 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com world.nerogiardini.it http: https: blob: 'self' 'unsafe-inline'; default-src world.nerogiardini.it 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://nerogiardini.it/scommercereporturi/report/storefront; report-to report-endpoint; 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=eNPXJD_DxeFUk8VQypFCh2KoG_A2ylxGnEzc_498vjI-1765936789-1.0.1.1-LrxkGQnVyN8dBNolotux0Dp0fTpIYgw1.9Hqnch0TqjRWkvgjuCozLqAGvr0SebQye6UQx9VJ9Cr3.NrFOuExY6BfZmfqC1F6camuoL5qS9eZxXuHlmrgmILdvvjECB3l2IWsuvhA7Upc_OmpPfaGxddf_NOJBSNAieM_AGYW7N7bEjSZV7CTKmKH7RhEkDX; report-to cf-csp-endpoint 1 default-src 'self'; script-src 'self' https:; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https:; report-uri /api/csp-report; 1 font-src fonts.googleapis.com fonts.gstatic.com celebrosnlp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.xtento.com ws.sharethis.com c.sharethis.mgr.consensu.org www.facebook.com t.sharethis.com *.weltpixel.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com https://a.klaviyo.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com celebrosnlp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com connect.facebook.net googletagmanager.com ws.sharethis.com maps.googleapis.com foursixty.com jscdn.appier.net click.accesstra.de goofleads.g.doubleclick.net t.sharethis.com https://static.klaviyo.com https://fast.a.klaviyo.com s7.addthis.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com ajax.googleapis.com *.instagram.com celebrosnlp.com ai.celebros-analytics.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com gateway.apaylater.com gateway.atome.sg fonts.googleapis.com cdn.curator.io ws.sharethis.com unsafe-inline assets.braintreegateway.com tagmanager.google.com celebrosnlp.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com anylist.c.appier.net l.sharethis.com https://static.klaviyo.com https://fast.a.klaviyo.com ekr.zdassets.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.celebros.com *.celebros.com:446 *.celebros-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.smartschool.be widgets.wp.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' maps.googleapis.com *.wp.com https://ssl.p.jwpcdn.com *.wp.com use.typekit.net p.jwpcdn.com; script-src-attr 'none'; style-src 'self' *.smartschool.be 'unsafe-inline' *.wp.com; font-src 'self' *.smartschool.be *.typekit.net wordpress.com c0.wp.com s0.wp.com data:; img-src 'self' http://www.smartschool.be pixel.wp.com *.typekit.net data:; connect-src maps.googleapis.com 'self' performance.typekit.net stats.g.doubleclick.net *.google-analytics.com; frame-src player.vimeo.com 'self'; report-uri /csp-violation.php 1 frame-ancestors 'self' https://app.contentful.com; worker-src blob:; default-src 'self' gap: ws: 'unsafe-inline' 'unsafe-eval' data: api.country.is vercel.live vercel.app *.vercel.live *.vercel.app safevisit.online contentful.com *.contentful.com *.googleapis.com *.youtube.com *.youtube-nocookie.com *.paypal.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.com.ph *.google.ca *.google.ie *.google.co.in *.facebook.com *.amazonaws.com *.cloudfront.net *.googletagservices.com pay.google.com *.s3.amazonaws.com google.com *.sitkagear.com js.narvar.com cdn.searchspring.net js.klarna.com manifest.webmanifest cdn.tailwindcss.com cdn.cookielaw.org api.yotpo.com cdn-widgetsrepository.yotpo.com *.yotpo.com *.searchspring.io *.bigcommerce.com *.locally.com *.ctfassets.net *.onetrust.com *.criteo.com *.avmws.com *.safevisit.online *.gtm-msr.appspot *.dynamic.criteo.com *.facebook.net *.klaviyo.com *.zdassets.com *.browser-intake-datadoghq *.vercel-insights.com *.csper.io klarnaservices.com *.klarnaservices.com datadoghq-browser-agent.com *.datadoghq-browser-agent.com browser-intake-datadoghq.com *.browser-intake-datadoghq.com *.gstatic.com *.bing.com *.typekit.net *.doubleclick.net *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.aralego.com criteo-sync.teads.tv *.3lift.com *.yahoo.net *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.outbrain.com *.pubmatic.com *.smaato.net *.clmbtech.com *.yieldmo.com *.klarnacdn.net vercel.com assets.vercel.com *.experticity.com 10974823.collect.igodigital.com *.collect.igodigital.com *.bazaarvoice.com gore-rebrand-fonts.surge.sh viev-fonts.surge.sh googleads.g.doubleclick.net envoydev.co track.securedvisit.com bh.contextweb.com stats.g.doubleclick.net public-prod-dspcookiematching.dmxleo.com match.adsrvr.org trends.revcontent.com match.sharethrough.com tapestry.tapad.com criteo-partners.tremorhub.com ad.tpmn.co.kr e1.emxdgt.com cm.g.doubleclick.net partner.mediawallahscript.com visitor.omnitagjs.com i.liadm.com exchange.mediavine.com 1f2e7.v.fwmrm.net tags.bluekai.com dpm.demdex.net ws-us3.pusher.co eu.klarnaevt.com sockjs-us3.pusher.com ws-us3.pusher.com aa.agkn.com track.sv.rkdms.com sync.crwdcntrl.net *.hotjar.com widget-mediator.zopim.com aorta.clickagy.com *.searchspring.net *.googlesyndication.com *.liadm.com *.abtasty.com appclip.loopid.com noembed.com *.klarnaevt.com *.usablenet.com *.usablenet.dev *.gorewear.com *.rebrand.gorewear.com rebrand.gorewear.com www.sandbox.paypal.com cdn.sand.us.zip.co localhost:* *.origin.gorewear.com origin.gorewear.com 1 object-src 'none'; connect-src 'self' *.puretaboo.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.puretaboo.com join.gammasecure.com; script-src 'self' *.puretaboo.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.puretaboo.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' *.gstatic.com; img-src 'self' * data:; frame-src 'self' *.retargetly.com *.doubleclick.net; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com; connect-src 'self' *.hypera.com.br http://cdn.evgnet.com/beacon/hyperapharma/hypera/scripts/evergage.min.js https://hyperapharma.us-4.evergage.com https://banner-geolocalizacao.hypera-pharma-s-account.workers.dev https://mapa-gripe.hypera-pharma-s-account.workers.dev *.viacep.com.br *.google-analytics.com *.google.com *.clarity.ms *.hypera.com.br *.retargetly.com *.doubleclick.net; script-src 'self' 'nonce-a9f8efbf1bcb58eaca003c7ff01f8a54' 'nonce-b0d5fee76a0621e54ddbf831efa5a9ba8a4cf33d' *.googletagmanager.com *.viacep.com.br *.google.com *.gtm.js https://www.googletagmanager.com *.google-analytics.com *.retargetly.com *.navdmp.com *.gstatic.com *.facebook.net *.clarity.ms *.cloudfront.net cdn.jsdelivr.net *.hypera.com.br api.hypera.com.br hypera.com.br http://cdn.evgnet.com/beacon/hyperapharma/hypera/scripts/evergage.min.js https://hyperapharma.us-4.evergage.com; style-src 'self' 'unsafe-inline' fonts.gstatic.com fonts.googleapis.com *.hypera.com.br 1 script-src *.hsadspixel.net *.hs-analytics.net js.hscta.net *.hubspot.com static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com *.googletagmanager.com *.hotjar.com 'unsafe-inline' *.mouseflow.com; img-src js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net *.hsforms.net *.hsforms.com *.google-analytics.com *.googletagmanager.com *.hotjar.com *.mouseflow.com; connect-src *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.mouseflow.com; frame-src *.hubspot.com play.hubspotvideo.com *.hubspot.net *.hsforms.net *.mouseflow.com; style-src cdn2.hubspot.net *.harmonicinc.com; child-src *.hsforms.com *.mouseflow.com; font-src *.hotjar.com *.hotjar.io *.mouseflow.com; 1 font-src *.googleapis.com https://www.gstatic.com *.fontawesome.com https://live.icecat.biz data: https://googletagmanager.com https://tagmanager.google.com https://fonts.gstatic.com locator.uberall.com script.hotjar.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com dashboard.trustprofile.com td.doubleclick.net https://s3-eu-west-1.amazonaws.com/ https://td.doubleclick.net https://google-analytics.com https://objects.icecat.biz/ *.trustpilot.com https://www.google.com www.xtento.com trafic-career.talent-soft.com view.publitas.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com funtrafic.imgix.net bat.bing.com www.google.be lqip-funtrafic.imgix.net https://funtrafic-large.imgix.net/media/ https://funtrafic-thumb.imgix.net/media/ https://pdpthumb-funtrafic.imgix.net https://pdplarge-funtrafic.imgix.net https://pdpfull-funtrafic.imgix.net https://content.fun.be https://adservice.google.com https://region1.analytics.google.com https://googletagmanager.com https://tagmanager.google.com https://bat.bing.com https://pagead2.googlesyndication.com https://td.doubleclick.net https://google-analytics.com www.xtento.com cdn.xtento.com bat.bing.net catalogmedia.trafic.com funtrafic-thumb.imgix.net joko-mobile-app-media.s3.eu-west-1.amazonaws.com locator.uberall.com magentoadmin.trafic.com www.google.de www.google.fr www.google.lt www.google.lu *.google.com www.trafic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://www.gstatic.com cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com static.hotjar.com eu1-config.doofinder.com widget.trustpilot.com invitejs.trustpilot.com script.hotjar.com bat.bing.com js-agent.newrelic.com https://live.icecat.biz https://bat.bing.com https://js-agent.newrelic.com https://googletagmanager.com https://tagmanager.google.com https://td.doubleclick.net https://google-analytics.com *.trustpilot.com www.xtento.com cdn.xtento.com api.mapbox.com locator.uberall.com view.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.fontawesome.com cdn.doofinder.com https://live.icecat.biz blob: https://googletagmanager.com https://tagmanager.google.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com region1.analytics.google.com eu1-api.doofinder.com bam.eu01.nr-data.net https://invitejs.trustpilot.com https://live.icecat.biz https://magentoadmin.trafic.docker https://adservice.google.com https://region1.analytics.google.com https://www.google.com https://www.google.be https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://td.doubleclick.net https://google-analytics.com https://pagead2.googlesyndication.com api.mapbox.com bat.bing.com bat.bing.net content.hotjar.io events.mapbox.com locator.uberall.com surveystats.hotjar.io vc.hotjar.io *.hotjar.com wss: wss://ws.hotjar.com www.google.lu *.google.com *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com bam.eu01.nr-data.net googleads.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://gvb-apim-service-prod2.azure-api.net https://gvb-app.matomo.cloud consentcdn.cookiebot.com https://dc.services.visualstudio.com/v2/track https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.dynamics.com https://*.azureedge.net https://cdn.jsdelivr.net/npm/@lottiefiles/dotlottie-web@0.41.0/dist/dotlottie-player.wasm ; script-src 'strict-dynamic' 'nonce-LUFWq7hn2+NEqy/6/HAqgWqnXJMCX/0NQp01gTt2awk=' 'sha256-X9GtzORyUShRgrb5vBVwF3p8WtKom3jBuMyocEhfL3Q=' 'self' https://cdn.matomo.cloud https://gvb-app.matomo.cloud consent.cookiebot.com consentcdn.cookiebot.com https://*.dynamics.com https://*.azureedge.net; frame-src 'self' consentcdn.cookiebot.com https://*.tiqets.com; base-uri 'self'; block-all-mixed-content; font-src 'self' https: data:; img-src * 'self' data: https; object-src 'none'; script-src-attr 'none'; style-src 'self' https://gvb-apim-service-prod2.azure-api.net 'unsafe-inline'; 1 default-src 'self' data: blob: https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com; connect-src 'self' data: properties: https://cmfglifeinsurance.us-6.evergage.com https://*.google-analytics.com https://*.google.com https://*.linkedin.com https://*.niceincontact.com https://clientstream.launchdarkly.com/ https://fonts.gstatic.com https://*.optimizely.com https://*.cunamutual.com https://www.nextinsure.com https://geolocation.onetrust.com https://privacyportal.onetrust.com https://*.googlesyndication.com https://*.trustage.com https://us-central1-adaptive-growth.cloudfunctions.net https://cdn.linkedin.oribi.io https://s.yimg.com https://*.doubleclick.net https://*.trustagedem.com https://*.trustagedemo.com https://*.oktacdn.com https://*.bing.com https://*.googleapis.com https://cunamutual.okta.com https://cdn.cookielaw.org https://cunamutual.oktapreview.com/ https://*.googleadservices.com/ https://*.qualtrics.com/ https://dc.services.visualstudio.com/ https://*.levelaccess.net https://www.googletagmanager.com https://facebook.com/ https://*.segment.io https://*.segment.com https://*.permutive.com https://calc-backend-prod.herokuapp.com https://www.facebook.com https://eastus2-0.in.applicationinsights.azure.com; frame-ancestors 'self' https://trustage.com https://*.optimizely.com https://*.trustagedem.com https://*.trustagedemo.com; frame-src 'self' https://trustage.com https://*.googlesyndication.com https://cunamutual.widen.net https://login.microsoftonline.com https://*.widencdn.net https://*.opendns.com https://*.optimizely.com https://www.youtube.com https://chase.hostedpaymentservice.net https://chase-var.hostedpaymentservice.net https://*.doubleclick.net https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com https://*.oktacdn.com https://www.googletagmanager.com https://*.trustpilot.com/ https://*.flashtalking.com https://*.google.com https://*.qualtrics.com https://*.affec.tv https://*.opendns.com https://www.facebook.com https://*.ceros.com https://home-c27.incontact.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://cmfglifeinsurance.us-6.evergage.com https://*.googlesyndication.com https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com https://static-demo.trustage.cloud https://*.trustage.com https://*.googleadservices.com https://*.trustagedem.com https://*.trustagedemo.com https://cdn.cookielaw.org https://*.signalintent.com https://*.google.com https://chase-var.hostedpaymentservice.net https://chase.hostedpaymentservice.net https://cdn.pdst.fm https://snap.licdn.com https://insurance.mediaalpha.com https://us-central1-adaptive-growth.cloudfunctions.net https://s.yimg.com https://*.facebook.net https://geolocation.onetrust.com https://cdn.linkedin.oribi.io https://privacyportal.onetrust.com https://*.google.com https://sp.analytics.yahoo.com https://*.linkedin.com https://www.pagespeed-mod.com https://*.google-analytics.com https://*.salesforceliveagent.com/ https://*.oktacdn.com/ https://*.trustpilot.com/ https://*.gstatic.com/ https://*.googletagmanager.com/ https://az416426.vo.msecnd.net/ https://*.levelaccess.net/ https://*.qualtrics.com/ https://www.googleoptimize.com https://bat.bing.com https://solutions.invocacdn.com https://pnapi.invoca.net https://*.affec.tv/ https://*.evgnet.com/ https://*.ceros.com https://home-c27.incontact.com https://secure.adnxs.com https://cdn.permutive.com https://trkn.us https://www.facebook.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.trustage.com https://cmfglifeinsurance.us-6.evergage.com https://www.gstatic.com https://*.optimizely.com https://*.affec.tv/ https://chase.hostedpaymentservice.net https://*.bing.com https://*.google.com https://*.doubleclick.net https://*.googleadservices.com https://*.google-analytics.com https://www.googletagmanager.com https://*.googleadservices.com https://*.googlesyndication.com https://cdn.pdst.fm https://cdn.cookielaw.org https://snap.licdn.com https://*.qualtrics.com https://s.yimg.com https://*.salesforceliveagent.com https://*.facebook.com https://connect.facebook.net https://www.youtube.com https://bat.bing.com https://*.evgnet.com/ https://*.levelaccess.net https://chase-var.hostedpaymentservice.net https://*.oktacdn.com https://www.googleoptimize.com https://*.trustpilot.com/ https://az416426.vo.msecnd.net/ https://solutions.invocacdn.com https://secure.adnxs.com https://cdn.permutive.com https://*.signalintent.coms https://*.segment.com https://*.ceros.coms; style-src 'self' 'unsafe-inline' https://cmfglifeinsurance.us-6.evergage.com https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com https://*.signalintent.com https://rsms.me https://*.googleapis.com https://*.google.com https://*.googlesyndication.com https://google.ca https://www.googleoptimize.com https://*.google-analytics.com https://*.trustpilot.com/ https://www.youtube.com https://web-modules-de-na1.niceincontact.com https://pwm-image.trendmicro.com https://cdn.honey.io; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: https:; font-src 'self' data: https://cmfglifeinsurance.us-6.evergage.com https://fonts.gstatic.com https://rsms.me https://maxcdn.bootstrapcdn.com https://fonts.cdnfonts.com https://use.fontawesome.com https://static2.sharepointonline.com https://static.zip.co https://embed.signalintent.com https://appservice.azureedge.net/; report-uri /api/csp/report; 1 default-src 'none'; script-src 'self' *.twitter.com *.google.com *.recaptcha.net *.googletagmanager.com *.google-analytics.com; img-src *; 1 font-src *.googleapis.com *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com *.fontawesome.com * *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.trackedlink.net maps.googleapis.com maps.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gateway.apaylater.com gateway.atome.sg ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.facebook.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.gstatic.com fonts.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gateway.apaylater.com gateway.atome.sg cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googletagmanager.com *.facebook.net *.avada.io https://*.googletagmanager.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com gateway.apaylater.com gateway.atome.sg cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com https://get.geojs.io *.avada.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; connect-src 'self' aipoweredmarketer.okta.com aipoweredmarketer-admin.okta.com login.goacoustic.com *.oktacdn.com *.mixpanel.com *.mapbox.com aipoweredmarketer.kerberos.okta.com aipoweredmarketer.mtls.okta.com https://oinmanager.okta.com data: www.acoustic.com app.goacoustic.com consent.trustarc.com *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; style-src 'unsafe-inline' 'self' 'report-sample' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; frame-src 'self' aipoweredmarketer.okta.com aipoweredmarketer-admin.okta.com login.goacoustic.com login.okta.com *.vidyard.com www.acoustic.com app.goacoustic.com consent.trustarc.com; img-src 'self' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: www.acoustic.com app.goacoustic.com consent.trustarc.com blob:; font-src 'self' aipoweredmarketer.okta.com login.goacoustic.com data: *.oktacdn.com fonts.gstatic.com www.acoustic.com app.goacoustic.com consent.trustarc.com; frame-ancestors 'self' 1 default-src https: wss://ws.tsarvar.com wss://wst.tsarvar.com wss://wst2.tsarvar.com; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data: 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' code.jquery.com cdn.appdynamics.com col.eum-appdynamics.com fonts.gstatic.com ajax.googleapis.com www.googleapis.com fonts.googleapis.com use.fontawesome.com www.w3schools.com home.textkernel.nl staging.textkernel.nl www.dropbox.com apis.google.com www.google.com html5shim.googlecode.com media.readspeaker.com s7.addthis.com d2sl310zdnr3q6.cloudfront.net www.google-analytics.com https://apps.knollenstein.com https://appsdev.knollenstein.com font.visma.com *.easycruit.com m.addthis.com api-public.addthis.com flowanalytic.site networkanalytics.xyz knowledge-and-support-center.visma.net m.addthisedge.com apply.indeed.com content.googleapis.com commondatastorage.googleapis.com themes.googleusercontent.com www.googletagmanager.com fast.fonts.net db.onlinewebfonts.com hello.myfonts.net cdnjs.cloudflare.com d1fc8wv8zag5ca.cloudfront.net connect.facebook.net emea3.recruitmentplatform.com tag.goldenbees.fr s.ytimg.com www.findizer.fr webfonts.zohostatic.com platform.linkedin.com zgao.nl cdn.ontame.io *.ziggeo.com *.amazonaws.com api-eu-west-1.ziggeo.com embed-cdn-eu-west-1.ziggeo.com embed-eu-west-1.ziggeo.com assets.ziggeo.com hc-cdn.visma.net cdn.wootric.com production.wootric.com eligibility.wootric.com *.onetrust.com cdn.cookielaw.org https://storage.googleapis.com/snowplow-cto-office-tracker-bucket/3.1.1/sp.js https://snowplow.visma.com/com.snowplowanalytics.snowplow/tp2 *.sharethis.com www.gstatic.com easycruit.com; img-src 'self' data: * 'unsafe-inline' 'unsafe-eval'; report-uri https://easycruit.com/api/logging/v1/csp-report 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.se https://www.myheritage.se 'unsafe-eval' 'nonce-d43b0877d4519b33136546e5666af776' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.se;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src https: 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; img-src https: data: 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://cdn.livechatinc.com https://secure.livechatinc.com https://fonts.google.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure.livechatinc.com https://widget.trustpilot.com https://consentcdn.cookiebot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://app-wallee.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com *.amazonaws.com maps.gstatic.com https://cdn.livechatinc.com https://secure.livechatinc.com https://cdn.livechat-static.com https://cdn.livechat-files.com/ https://bat.bing.com https://www.google.co.uk https://s.ytimg.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://app-wallee.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com maps.googleapis.com https://api.livechatinc.com https://cdn.livechatinc.com https://secure.livechatinc.com https://cdn.livechat-static.com https://widget.trustpilot.com https://bat.bing.com https://script.thisisbeacon.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://js-agent.newrelic.com https://bam.nr-data.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://app-wallee.com https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://app-wallee.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.livechatinc.com https://secure.livechatinc.com https://cdn.livechat-static.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ws.postcoder.com https://api.livechatinc.com https://cdn.livechatinc.com https://secure.livechatinc.com https://youtube.com https://google.com https://fonts.google.com https://v5api.thisisbeacon.com https://consentcdn.cookiebot.com https://bam.nr-data.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://app-wallee.com https://assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src https://api.livechatinc.com https://cdn.livechatinc.com https://secure.livechatinc.com https://youtube.com https://google.com https://fonts.google.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.fls.doubleclick.net *.google-analytics.com *.overdrive.com bam.nr-data.net connect.facebook.net hello.myfonts.net stats.g.doubleclick.net tracking.crazyegg.com/clock; connect-src 'self' *.google-analytics.com analytics.google.com bam.nr-data.net hello.myfonts.net manager.us.smartlook.cloud script.crazyegg.com/pages/data-scripts/0023/8294.json stats.g.doubleclick.net tracking.crazyegg.com/clock www.facebook.com/tr/ api.digioh.com jsapi.azurewebsites.net analytics.digioh.com; script-src 'self' apis.google.com/js/platform.js bam.nr-data.net connect.facebook.com connect.facebook.net js-agent.newrelic.com script.crazyegg.com servedbyadbutler.com/adserve/ servedbyadbutler.com/app.js web-sdk.smartlook.com www.google-analytics.com/analytics.js www.googletagmanager.com cdn.digioh.com scripts.digioh.com lightboxcdn.digioh.com 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' apis.google.com/ apis.google.com/_/scs/apps-static/_/js/ apis.google.com/js/platform.js bam.nr-data.net connect.facebook.net js-agent.newrelic.com/ script.crazyegg.com/pages/scripts/0023/8294.js script.crazyegg.com/pages/versioned/common-scripts/ servedbyadbutler.com/adserve/ servedbyadbutler.com/app.js web-sdk.smartlook.com www.google-analytics.com/analytics.js www.google-analytics.com/plugins/ua/ec.js www.google.com/recaptcha www.googletagmanager.com 'unsafe-inline'; style-src 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'nonce-4L9OHGtBWeDIhWVaKLA6dFx5evI='; img-src 'self' data: images.contentreserve.com/ img1.od-cdn.com servedbyadbutler.com/getad.img/ t.co/i/ www.facebook.com/tr/ www.google-analytics.com/collect www.google.com/ads/ www.googletagmanager.com/a www.googletagmanager.com/td cdn.digioh.com *.google-analytics.com *.doubleclick.net; frame-src 'self' 9250847.fls.doubleclick.net accounts.google.com/ classroom.google.com www.facebook.com/ www.gstatic.com/; worker-src blob:; object-src 'none'; report-uri https://itsentry.overdrive.com/api/13/security/?sentry_key=86a98bc6ee19c71aed01755910f50c3c 1 font-src fonts.googleapis.com fonts.gstatic.com celebrosnlp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.xtento.com ws.sharethis.com c.sharethis.mgr.consensu.org www.facebook.com t.sharethis.com *.weltpixel.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ve01-lnx003-psr-cms.wt-id.dev stage-api-psr.wt-id.dev *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com celebrosnlp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com connect.facebook.net googletagmanager.com ws.sharethis.com maps.googleapis.com foursixty.com jscdn.appier.net click.accesstra.de goofleads.g.doubleclick.net t.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.zdassets.com s7.addthis.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com celebrosnlp.com ai2.celebros-analytics.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com gateway.apaylater.com gateway.atome.sg fonts.googleapis.com cdn.curator.io ws.sharethis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com tagmanager.google.com celebrosnlp.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com anylist.c.appier.net l.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.zendesk.com ekr.zdassets.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com ve01-lnx003-psr-cms.wt-id.dev stage-api-psr.wt-id.dev landofcoder.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.celebros.com *.celebros.com:446 *.celebros-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none' ; img-src 'self' data: https://blob.userflow.com https://cdn.userflow.com https://js.userflow.com https://storage.googleapis.com/studio1-prod-blob/ * ; connect-src 'self' https://browser-intake-datadoghq.eu https://rum.browser-intake-datadoghq.eu https://logs.browser-intake-datadoghq.eu https://session-replay.browser-intake-datadoghq.eu https://api.analytics.pigment.app https://cdn.analytics.pigment.app https://auth.pigment.app https://staging-login.pigment.app wss://pigment.app wss://e.userflow.com https://cdn.userflow.com https://e.userflow.com https://js.userflow.com https://rs.fullstory.com wss://rs.fullstory.com https://edge.fullstory.com https://global.oktacdn.com https://api.segment.io https://cdn.segment.com https://api.maptiler.com https://api.vitally-eu.io https://app.vitally-eu.io https://use.typekit.net https://fonts.googleapis.com https://fonts.gstatic.com cdn.vitally-eu.io ; script-src 'self' cdn.analytics.pigment.app edge.fullstory.com rs.fullstory.com js.userflow.com cdn.userflow.com cdn.announcekit.app cdn.segment.com cdn.vitally-eu.io ; frame-src announcekit.co auth.pigment.app staging-login.pigment.app https://fast.wistia.net pigmentforms.typeform.com ; style-src 'self' 'unsafe-inline' js.userflow.com cdn.userflow.com fonts.googleapis.com cdn.announcekit.co https://use.typekit.net https://p.typekit.net ; worker-src blob: ; font-src 'self' https://use.typekit.net fonts.gstatic.com data: ; manifest-src 'self' ; object-src 'none' ; media-src https://blob.userflow.com https://cdn.userflow.com https://storage.googleapis.com/studio1-prod-blob/ ; frame-ancestors https://pigment7-dev-ed.develop.lightning.force.com/ https://pigment7-dev-ed--c.develop.vf.force.com/ https://wiki.klarna.net/ ; base-uri 'self' ; form-action https://announcekit.co ; report-uri https://pigment.uriports.com/reports/report ; report-to report ; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=437&v=v1.0&payload=rJeyhteK1R4ehvX19W96lNbaCGhFOwYEfK03vVIAbGSAqTMkAdvym88TbB6ZcVIk3BKtzXIrOm_KBfeoBaCjF0XFfegHdnslKbyvyJexsPFSMjFKbJDiIhCRyAFJ7zhMrLkXQZhPqzOvV5xVSDi6NtAfsc9rXSBW_kA58IBRC0aRenQ2MnT5ellPCBc3xg0R0qZ29PkZAuKgEeDKDC5IEg==; 1 script-src 'strict-dynamic' 'nonce-mnBvwN6bAvhuqBjgmyJseA==' 1 font-src *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ account.fetchify.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.com *.facebook.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.facebook.com *.facebook.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.clerk.io https://cdn.clerk.io chimpstatic.com downloads.mailchimp.com *.list-manage.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com cc-cdn.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.com *.facebook.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';connect-src 'self' https://analytics.majestic.com https://analytics.majesticseo.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.analytics.google.com https://*.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.majesticseo.com https://analytics.majestic.com https://info.majestic.com https://*.googletagmanager.com www.google-analytics.com https://www.googleadservices.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://platform.twitter.com/;style-src 'self' 'unsafe-inline';img-src 'self' data: https:;font-src 'none';object-src 'none';media-src 'none';frame-src www.openstreetmap.org www.youtube.com https://www.youtube-nocookie.com/ https://player.vimeo.com/ https://www.google.com/recaptcha/ https://platform.twitter.com/ https://player.captivate.fm/ https://syndication.twitter.com/;child-src www.openstreetmap.org www.youtube.com https://www.google.com/recaptcha/ https://platform.twitter.com/ https://syndication.twitter.com/;frame-ancestors https://docs.google.com https://*.googleusercontent.com;report-uri /csp/report;report-to report-endpoint 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-CAVFx7IWr8W4gb0E-wefiw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 script-src-elem 'self' *.googletagmanager.com https://*.mopinion.com https://integration.occ7.mtel.eu https://connect.facebook.net https://snap.licdn.com https://www.clarity.ms https://c.clarity.ms/ https://www.youtube.com https://static.doubleclick.net https://api.evolveip.eu/ChatWebAzure/EipChat.js 'nonce-lBgdjm3hQxoQJUWfM5C0Zm55/cb/iNSBZ4Dy23q6p9Y='; script-src 'self' 'unsafe-eval' *.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net 'sha256-TqjM/ocl9Ih4hsJxBuYJi9DiPkAJnBID1b5nkiBEnYI=' 'sha256-vemytl4W5Qmww8+4p7ijbNPmvDbs6GPIf7CXCwtOWgc=' 'nonce-lBgdjm3hQxoQJUWfM5C0Zm55/cb/iNSBZ4Dy23q6p9Y='; report-uri /umbraco/api/csp/report; default-src 'none'; font-src 'self' data: https://fonts.gstatic.com https://cdn.faceworks.nl https://*.mopinion.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.mopinion.com https://edge.cookieconsent.io; img-src 'self' mijn.s-bb.nl *.googletagmanager.com px.ads.linkedin.com https://www.facebook.com https://edge.cookieconsent.io https://www.toegankelijkheidsverklaring.nl; form-action 'self'; base-uri 'self'; frame-ancestors 'self'; frame-src 'self' youtube.com www.youtube.com; manifest-src 'self'; connect-src 'self' https://*.google-analytics.com https://*.mopinion.com https://*.clarity.ms https://api.cookieconsent.io https://px.ads.linkedin.com https://connect.facebook.net https://api.evolveip.eu https://ukaz-web01f.ccaas.enghouse.cloud/scripts/ChatExtension.dll 1 script-src 'self' 'nonce-vT80Dc3uic0HFSyVWG9+LQHPP0A=' 'strict-dynamic' 'unsafe-eval'; object-src 'none'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: https://static.okx.com https://*.alicdn.com https://*.aliyuncs.com https://*.coinall.ltd https://*.geetest.com https://*.geevisit.com https://*.qbox.me https://*.facebook.net https://*.google-analytics.com https://*.google.com https://googletagmanager.com https://*.googletagmanager.com https://*.gstatic.cn https://*.gstatic.com https://*.intercom.io https://*.intercomcdn.com https://*.jingyunyilian.com https://*.okcoin.com https://*.okx.com https://*.recaptcha.net https://telegram.org https://*.twitter.com https://*.yandex.ru https://*.online-metrix.net;frame-src 'self' blob: https://static.okx.com https://*.google.com https://*.google.com https://*.okcoin.com https://*.onelink.me https://*.recaptcha.net https://*.twitter.com https://*.walletconnect.com https://*.walletconnect.org https://*.yandex.com https://*.yandex.ru https://*.online-metrix.net;object-src 'self' https://static.okx.com;connect-src 'self' https://static.okx.com blob: data: https://*.agora.io https://*.aliyuncs.com https://*.amazonaws.com https://*.solana-frontend.blockrazor.io https://*.coinall.ltd https://*.edge.sd-rtn.com:* https://*.google.com.sa https://*.googleapis.com https://stats.g.doubleclick.net https://dkapi-ga.geetest.com https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.intercom.io https://*.jingyunyilian.com https://*.okcoin.com https://*.okex.org https://*.okx.com https://*.okx.cab https://*.okx.ac https://*.onetrust.com https://*.recaptcha.net https://*.walletconnect.com https://*.yandex.com https://*.yandex.ru wss://*.edge.agora.io:* wss://*.amazonaws.com wss://*.coinall.ltd:* wss://*.helius-rpc.com wss://*.ilivedata.com:* wss://*.intercom.io:* wss://*.okx.ac:* wss://*.okx.com:* wss://*.ouchyi.org:* wss://*.edge.sd-rtn.com:* wss://*.walletconnect.com wss://*.walletconnect.org https://vv-0.0.3.okx.com;form-action 'self';frame-ancestors 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' c.amazon-adsystem.com *.prod.mplat-ppcprotect.com res4.applovin.com c.albss.com s.axon.ai cdn.attn.tv the.sciencebehindecommerce.com lantern.roeyecdn.com www.dwin1.com *.bing.com bat.bing.net t.contentsquare.net *.scarabresearch.com connect.facebook.net www.facebook.com uktc.fospha.com www.googletagmanager.com maps.googleapis.com pagead2.googlesyndication.com googleads.g.doubleclick.net www.google-analytics.com *.google.com www.gstatic.com *.google-analytics.com heapanalytics.com cdn.heapanalytics.com cdn.huel.io global.localizecdn.com services.postcodeanywhere.co.uk pub.loudcrowd.com survey-cdn.lumoa.me *.mention-me.com *.clarity.ms *.onetrust.com *.optimizely.com paperplaneslive.com www.paypal.com cdn.pdst.fm d34r8q7sht0t9k.cloudfront.net www.redditstatic.com *.shopify.com cdn.shopify.com sc-static.net tr.snapchat.com pixel.byspotify.com js.stripe.com cdn.studentbeans.com connect.studentbeans.com d2hrivdxn8ekm8.cloudfront.net acdn.adnxs.com action.dstillery.com *.tiktok.com analytics-ipv6.tiktokw.us sf16-website-login.neutral.ttwstatic.com widget.trustpilot.com va.vercel-scripts.com vercel.live b99.yahoo.co.jp s.yimg.jp *.zdassets.com *.zendesk.com *.zopim.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com www.gstatic.com fonts.gstatic.com cdn.huel.io services.postcodeanywhere.co.uk *.onetrust.com cdn.studentbeans.com sf16-website-login.neutral.ttwstatic.com vercel.live *.zdassets.com *.zendesk.com *.zopim.com; img-src blob: data: 'self' trkn.us match.adsrvr.org ce.lijit.com huel-us.attn.tv events.attentivemobile.com www.awin1.com www.wepowerconnections.com lantern.roeye.com *.bing.com bat.bing.net *.ctfassets.net www.facebook.com connect.facebook.com connect.facebook.net lookaside.fbsbx.com uktc.fospha.com www.googletagmanager.com *.gstatic.com maps.google.com googleads.g.doubleclick.net region1.analytics.google.com stats.g.doubleclick.net *.google-analytics.com pagead2.googlesyndication.com google.com translate.google.com www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat heapanalytics.com cdn.heapanalytics.com cdn.huel.io cdn.shopify.com huel.io us-s2s.huel.com uk-s2s.huel.com huel-assets.s3.eu-west-2.amazonaws.com s3.eu-west-2.amazonaws.com huel.imgix.net huel-crm.imgix.net global.localizecdn.com media.loudcrowd.com mention-me.com *.clarity.ms *.onetrust.com paperplaneslive.com t.paypal.com *.podscribe.com alb.reddit.com tr.snapchat.com segment.prod.bidr.io *.media6degree.com ib.adnxs.com analytics.tiktok.com analytics-ipv6.tiktokw.us vercel.com b99.yahoo.co.jp www.zenaps.com v2assets.zopim.io static.zdassets.com; font-src 'self' data: *.onetrust.com vercel.live; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' www.facebook.com; media-src data: blob: 'self' lookaside.fbsbx.com cdn.huel.io media.loudcrowd.com cdn.shopify.com *.ctfassets.net; frame-src 'self' huelus.aftership.com aax-eu.amazon-adsystem.com www.awin1.com www.facebook.com www.googletagmanager.com www.google.com www.gstatic.com *.huel.com huel.com mention-me.com huel.mention-me.com huel-privacy.my.onetrust.com *.optimizely.com tr.snapchat.com js.stripe.com *.studentbeans.com www.tiktok.com vercel.live *.youtube.com cdn.smooch.io *.zdassets.com *.zendesk.com *.zopim.com; connect-src 'self' aax-eu.amazon-adsystem.com ara.paa-reporting-advertising.amazon ara.paa-reporting-advertising.amazon.com c.amazon-adsystem.com *.prod.mplat-ppcprotect.com *.applovin.com ttip-ipv4-prod.telemetry.vaultdcr.com ttip-ipv6-prod.telemetry.vaultdcr.com tte-prod.telemetry.vaultdcr.com *.attn.tv events.attentivemobile.com the.sciencebehindecommerce.com www.wepowerconnections.com *.bing.com bat.bing.net cognito-idp.eu-west-2.amazonaws.com *.ctfassets.net webchannel-content.eservice.emarsys.net *.scarabresearch.com www.facebook.com lookaside.fbsbx.com fbcapig.huel.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.cloudfunctions.net google.com analytics.google.com region1.analytics.google.com stats.g.doubleclick.net googleads.g.doubleclick.net www.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat heapanalytics.com cdn.heapanalytics.com huel.io *.huel.io *.huel-staging.io huel.com *.huel.com hibble.myshopify.com huelczech.myshopify.com huelpoland.myshopify.com hueleurope.myshopify.com hueldenmark.myshopify.com huelgermany.myshopify.com huelamerica.myshopify.com hueljapan.myshopify.com huelsweden.myshopify.com huel.imgix.net huel-crm.imgix.net global.localizecdn.com api.addressy.com *.loudcrowd.com websurvey.lumoa.me *.mention-me.com *.clarity.ms *.onetrust.com *.optimizely.com paperplaneslive.com *.podscribe.com *.pusher.com *.reddit.com www.redditstatic.com *.shopify.com monorail-edge.shopifysvc.com *.snapchat.com pixels.spotify.com *.studentbeans.com ib.adnxs.com *.tiktok.com analytics-ipv6.tiktokw.us vercel.live *.zdassets.com *.zendesk.com *.zopim.com zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com; frame-ancestors 'self' app.contentful.com; upgrade-insecure-requests; report-to sentry; report-uri https://o4506552359124992.ingest.us.sentry.io/api/4509920468533248/security/?sentry_key=01841fdb68b60d9143ac67a06a18c18f; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://tagmanager.google.com https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://bildermangel.de https://www.google-analytics.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://*.vvs.de https://vvsjobs.softgarden.io https://www.paperturn-view.com http://paperturn-view.com https://*.paperturn-view.com https://www.unserebroschuere.de https://dig-aboprod.noncd.db.de https://www.googletagmanager.com https://*.consentmanager.net; font-src 'self' https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; worker-src 'self' https://www.googletagmanager.com https://tagmanager.google.com https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de https://*.vvs.de; connect-src 'self' https://apistaging.vvs.de https://*.vvs.de https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.google.com https://www.googletagmanager.com https://region1.google-analytics.com https://abo.bahn.de https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; object-src 'none'; style-src 'self' https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de 'unsafe-inline' 'report-sample'; form-action 'self' https://dig-aboprod.noncd.db.de https://abo.bahn.de; script-src-attr 'none' 'report-sample'; report-uri https://www.vvs.de/@http-reporting?csp=report&requestTime=1758610862619452&requestHash=37a59644ef9051c8efc5aa5fa70c9054b934deef 1 default-src 'self'; script-src 'self' 'nonce-Y7spR5Wfty3vphi95OSx6GRbutDg3VtuS_Xt_1XltMoyVJnMqXnVQQ' data: https://api-web.educagri.fr *.google-analytics.com https://www.googletagmanager.com https://analytics-sc.institut-agro.fr https://player.vimeo.com 'report-sample' https://ajax.googleapis.com/ https://analytics-sc.institut-agro.fr/; style-src-attr 'unsafe-inline' 'self' 'report-sample' data: https://api-web.educagri.fr https://use.fontawesome.com *.ckeditor.com; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://api-web.educagri.fr https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube-nocookie.com/ https://www.youtube.com/; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.data.sigea.educagri.fr *.dailymotion.com *.genially.com *.view.genial.ly https://view.genial.ly *.arteradio.com *.calameo.com *.facebook.com https://www.google.com https://fermewikisagro.fr *.francetv.fr; font-src 'self' data: https://fonts.gstatic.com https://use.fontawesome.com https://api-web.educagri.fr; connect-src 'self' data: https://api-web.educagri.fr *.google-analytics.com https://analytics-sc.institut-agro.fr https://analytics-sc.institut-agro.fr/; style-src 'self' 'report-sample' data: https://api-web.educagri.fr https://fonts.googleapis.com https://use.fontawesome.com; script-src-elem 'self' 'nonce-Y7spR5Wfty3vphi95OSx6GRbutDg3VtuS_Xt_1XltMoyVJnMqXnVQQ' data: https://api-web.educagri.fr *.google-analytics.com https://www.googletagmanager.com https://analytics-sc.institut-agro.fr https://player.vimeo.com 'report-sample'; report-uri https://cem.educagri.fr/api/csp/0/FE 1 script-src 'nonce-0InLrmgs2lQ9Jc-L6I7JpQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://plumrocket.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com *.avada.io https://cdnjs.cloudflare.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com *.fontawesome.com https://cdnjs.cloudflare.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://nominatim.openstreetmap.org https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://cdn.checkout.com instantcredit.net test.instantcredit.net fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; style-src https://cdn.checkout.com *.doofinder.com instantcredit.net test.instantcredit.net *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; img-src https://www.googletagmanager.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com https://images.unsplash.com instantcredit.net test.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; frame-src https://www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://js.checkout.com *.klarna.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; script-src https://analytics.tiktok.com/ https://ui.swogo.net/ https://www.googletagmanager.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.checkout.com *.klarnacdn.net cdn.doofinder.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com https://sandbox.sequracdn.com https://live.sequracdn.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src https://analytics.tiktok.com/ https://tracking.swogo.net/ https://api.swogo.net/ https://api.trustedshops.com/ https://www.googletagmanager.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com *.doofinder.com wss://*.doofinder.com instantcredit.net *.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; 1 report-to *.usercentrics.eu; font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.adobedtm.com *.adobe.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.cardinalcommerce.com *.paypal.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.youtube.com *.braintreegateway.com *.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io *.cookiebot.eu wss://widget-mediator.zopim.com/ maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://widgets.trustedshops.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.adobedtm.com *.adobe.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.youtube.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ *.easypack24.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.adobedtm.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.braintreegateway.com *.googleapis.com *.gstatic.com secure.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ *.cookiebot.eu *.easypack24.net merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com https://images.unsplash.com *.googleapis.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.cardinalcommerce.com *.ytimg.com *.vimeo.com *.braintreegateway.com *.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ wss://ws.hotjar.com *.hotjar.com *.hotjar.io connect.facebook.net *.cookiebot.eu *.easypack24.net static.payu.com https://geowidget.easypack24.net *.inpost.pl *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.googleapis.com *.gstatic.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.cardinalcommerce.com *.ytimg.com *.braintreegateway.com secure.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ wss://ws.hotjar.com *.hotjar.com *.hotjar.io cdn.jsdelivr.net *.trustedshops.com connect.facebook.net *.cookiebot.eu *.easypack24.net ai-data secure.snd.payu.com https://geowidget.easypack24.net *.inpost.pl *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.adobedtm.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.cardinalcommerce.com *.paypal.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.youtube.com *.braintreegateway.com *.gstatic.com *.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io *.cookiebot.eu wss://widget-mediator.zopim.com/ *.easypack24.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.adobedtm.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.zdassets.com https://static.zdassets.com *.zendesk.com *.zopim.com *.google.com *.google.pl *.newrelic.com *.cardinalcommerce.com *.paypal.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.youtube.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ *.cookiebot.eu *.easypack24.net https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com *.adobedtm.com *.adobe.com *.doubleclick.net *.ccdc02.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.zdassets.com *.zendesk.com *.zopim.com *.google.pl *.newrelic.com bam.eu01.nr-data.net *.ytimg.com *.vimeocdn.com *.youtube.com *.braintreegateway.com *.gstatic.com secure.payu.com *.avada.io *.usercentrics.eu https://get.geojs.io wss://widget-mediator.zopim.com/ wss://ws.hotjar.com *.hotjar.com *.hotjar.io geoip.maxmind.com connect.facebook.net *.cookiebot.eu *.easypack24.net merch-prod.snd.payu.com *.inpost.pl *.openstreetmap.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; img-src 'self' data:; font-src 'self' https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://stackpath.bootstrapcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://stackpath.bootstrapcdn.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://apis.google.com https://static.site24x7rum.com https://cdn.jsdelivr.net https://maxcdn.bootstrapcdn.com https://stackpath.bootstrapcdn.com; connect-src 'self' https://www.google-analytics.com https://col.site24x7rum.com; require-trusted-types-for 'script'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.doubleclick.net *.facebook.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * customer-jo4fg3675hw5zuyf.cloudflarestream.com gum.criteo.com fledge.eu.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedaty.com cdn.flbx.io *.cloudfront.net *.iubenda.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com customer-jo4fg3675hw5zuyf.cloudflarestream.com www.gstatic.com a.omappapi.com matching.ivitrack.com x.bidswitch.net sync-t1.taboola.com sync.outbrain.com zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it sync.1rx.io ib.adnxs.com rtb.csync.smartserver.com r.casalemedia.com gum.criteo.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com *.dmxleo.com *.smartadserver.com *.omnitagjs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedaty.com *.getflowbox.com *.iubenda.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com static.zdassets.com cdn.clerk.io customer-jo4fg3675hw5zuyf.cloudflarestream.com cdn.iubenda.com api.clerk.io cs.iubenda.com js-agent.newrelic.com embed.cloudflarestream.com www.google.com www.gstatic.com dynamic.criteo.com a.omappapi.com static.hotjar.com sslwidget.criteo.com script.hotjar.com ecomm.sella.it sandbox.gestpay.net pod-29.zendesk.com sgtm.jeannebaret.com sgtm.cmpsport.com mn.cmpsport.com mn.melby.it connect.facebook.net https://static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.feedaty.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com www.gstatic.com a.omappapi.com cdnjs.cloudflare.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.feedaty.com *.getflowbox.com *.iubenda.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com region1.google-analytics.com ekr.zdassets.com customer-jo4fg3675hw5zuyf.cloudflarestream.com api.openweathermap.org cmp.zendesk.com bam.nr-data.net idb.iubenda.com region1.analytics.google.com api.omappapi.com gum.criteo.com measurement-api.criteo.com wss://pod-29.zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it connect.facebook.net *.doubleclick.net mn.cmpsport.com mn.melby.it 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.nr-data.net *.criteo.net *.cloudflarestream.com *.cloudflare.com *.clerk.io *.cmpsport.com *.melby.it *.zdassets.com *.chimpstatic.com *.iubenda.com *.zendesk.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com dk5s5cje1o3yr.cloudfront.net *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.freshmarketer.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.hotjar.com www.facebook.com *.pinterest.com *.g.doubleclick.net *.zinrelo.com *.google.com *.google.co.in *.freshchat.com *.freshmarketer.com *.adroll.com panorama.2020.net *.ampproject.org *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.lilyanncabinets.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.visualwebsiteoptimizer.com bat.bing.com *.bing.com www.google.co.in *.facebook.com *.facebook.net *.pinterest.com cdn.pushcrew.com *.magecomp.com *.googletagmanager.com *.shopperapproved.com *.clarity.ms *.lilyanncabinets.com *.cloudfront.net *.amazonaws.com *.adroll.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com pixel.rubiconproject.com pixel.advertising.com sync.outbrain.com sync.taboola.com eb2.3lift.com dsum-sec.casalemedia.com image2.pubmatic.com ups.analytics.yahoo.com dk5s5cje1o3yr.cloudfront.net *.ytimg.com *.pinimg.com *.heatmap.it *.gstatic.com maps.googleapis.com *.hotjar.io *.hotjar.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com polyfill.io *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com bat.bing.com *.woopra.com chimpstatic.com dev.visualwebsiteoptimizer.com cdn.pushcrew.com connect.facebook.net s.pinimg.com apis.google.com *.freshchat.com *.freshmarketer.com www.gstatic.com *.googletagmanager.com *.clarity.ms *.smartlook.com *.cardinalcommerce.com *.shopperapproved.com *.googlecommerce.com *.zinrelo.com *.cloudfront.net webmoder.space *.adroll.com *.hotjar.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.pinterest.com dk5s5cje1o3yr.cloudfront.net downloads.mailchimp.com mc.us2.list-manage.com ajax.googleapis.com *.heatmap.it *.fw-cdn.com *.klaviyo.com maps.googleapis.com https://analytics.tiktok.com *.fwusercontent.com *.ampproject.org *.answerbase.com cdn.skypack.dev *.static.klaviyo.com *.static-tracking.klaviyo.com *.cdnjs.cloudflare.com *.ttwstatic.com fw-cdn.com https://s.pinimg.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.list-manage.com *.googleapis.com *.google.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com cdn.pushcrew.com *.freshchat.com *.freshmarketer.com fonts.googleapis.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.adroll.com *.pinterest.com dk5s5cje1o3yr.cloudfront.net downloads.mailchimp.com mc.us2.list-manage.com *.hotjar.io *.hotjar.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.ttwstatic.com *.shopperapproved.com *.fontawesome.com *.gstatic.com https://static.klaviyo.com *.googleapis.com *.google.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://lilyanncabinets.com *.cdninstagram.com *.amazonaws.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.lilyanncabinets.com dk5s5cje1o3yr.cloudfront.net *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.klaviyo.com *.visualwebsiteoptimizer.com *.clarity.ms ct.pinterest.com *.doubleclick.net *.cardinalcommerce.com *.google-analytics.com *.smartlook.cloud *.smartlook.com *.demdex.net *.chimpstatic.com *.facebook.com *.woopra.com *.hotjar.com *.hotjar.io ws34.hotjar.com *.adroll.com *.pinterest.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.lilyanncabinets.com dk5s5cje1o3yr.cloudfront.net *.freshmarketer.com maps.googleapis.com ws23.hotjar.com *.tiktok.com *.fw-cdn.com *.fwusercontent.com *.ampproject.org *.answerbase.com *.google.co.in *.googleadservices.com prod-init.100ms.live wss://*.100ms.live wss://rts-us-fcht.freshworksapi.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.app.zinrelo.com wss://*.hotjar.com www.google.com https://google.com bat.bing.com *.bing.com *.breadgateway.net *.sentry.io *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.getbread.com *.chimpstatic.com *.cloudfront.net *.adroll.com *.pinterest.com *.klaviyo.com *.hotjar.io *.hotjar.com ws23.hotjar.com *.fw-cdn.com *.ampproject.org *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://climate.stripe.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://sales-live-chat.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com https://y4pfttj91h-1.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-2.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-3.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-dsn.algolia.net/1/indexes/mkt_partners/query https://tax-connectors.stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://climate.stripe.com https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://checkout.stripe.dev https://support-conversations.stripe.com https://b.stripecdn.com https://checkout.stripe.com https://crypto-js.stripe.com https://js.stripe.com https://sales-live-chat.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com https://stripe-camo.global.ssl.fastly.net 'self'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; script-src https://b.stripecdn.com https://crypto-js.stripe.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src 'none'; report-uri https://q.stripe.com/csp-violation?q=zXWQ7RygtzLhJxvhHQdVXQvCEp3y1Q8UwD3oPEkm8SZuKK8UejRa4NRAqkmKRYU%3D 1 default-src 'self'; connect-src 'self' https://t.segger.com/; font-src 'self' 'unsafe-inline' data: ; style-src 'self' 'unsafe-inline' data: ; img-src 'self' data: blob: https://t.segger.com/ https://i.ytimg.com; script-src 'self' 'unsafe-inline' https://t.segger.com/; script-src-elem 'self' 'unsafe-inline' https://t.segger.com/ https://www.youtube.com/iframe_api; frame-src https://www.youtube-nocookie.com 'self'; object-src 'self' data: blob:; media-src 'self'; report-uri https://sentry.marketing-factory.de/api/23/security/?sentry_key=c95fa11bd7c34b6757a4f34eca12437f 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-OOdE_od03_oEZczUhU5-gQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 worker-src blob:; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com fonts.gstatic.com *.kxcdn.com https://fonts.cdnfonts.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://secure.asxgw.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.fbcdn.net blob: ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://verify.etrustmark.rs https://rs.beosport.com maps.gstatic.com *.ggpht https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://asxgw.com https://asxgw.paymentsandbox.cloud https://secure.asxgw.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.googleapis.com *.google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://s-eu-1.pushpushgo.com form.beosport.rs/static_files/js/form.widget.js https://maps.googleapis.com https://cdnjs.cloudflare.com *.avada.io s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-eval' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8=' 'sha256-OIkmMoDWrMET+9yYXfy4kYiZBSGdTuH3/LGJwXz4dbQ=' 'sha256-sA4VQiCGZ0SoC9lRUhrksOsX2gyXQEuHg4kSBIW0NEE=' 'sha256-c0lCqfyjzjX/z/E3XbnFt91p2H29aTfAgw8EjWp/fZI=' 'sha256-vEvkWASy62ASaFxwu/PJbHplao3U4RHMscHIG0WJ/Bk=' 'sha256-kcLwbkMxoYXD1+pfTCjKcZiKwrSg1OvWbfrbGCEKCJk=' 'sha256-jFhMjIj2mk11gJ73zMfIxd2bY7KD+ytCtZ/D9ManRc8=' 'sha256-6ixR+oMcnzgWfqUMhTzL7wXbLD5XOuFMHNcTSt5qov0=' 'sha256-LDIYwFJ02I7TUBglvosPtK0tPqIZkCRZMbWutdyCCAQ=' 'sha256-nf8KOhKoAdxPSwpv2RidJS8ZZzJhFY7WlN7FC+qdWc8=' 'sha256-3WKFMY9tUFN5N13PAP/JYO8r7IKSLJh0/tgh/V9MkRQ=' 'sha256-T3EuRb1GGbNmQ0vw9RUrW9VEstcYOrsXAoxvhYdOvIk=' 'sha256-coL0pEv1rb+grF9AzX+5ontRniER4BFzra+DqTYSAis=' 'sha256-5C79GT8eq2lLXsap6ckT7RIW2BBB6xceZxo8HZDjwyE=' 'sha256-Kj8xM4xKFKZOhkroQhn0wDm7HLvSMJ5jjXf4wDD9kLQ=' 'sha256-kDNtJT2efDxEQCDHPhzf12/6ZKrOJgpR7ze4tIpOkzg=' 'sha256-Y0D3AiTZ5scvOayGpk638SU9EGZdZCxmdS81i5h7sR0=' 'sha256-bpKe9LdxDRMgKSQ0H1JxXAYFf/zUg/V89o4nC7fFLIM='; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.google.com *.kxcdn.com downloads.mailchimp.com https://fonts.cdnfonts.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://asxgw.com https://asxgw.paymentsandbox.cloud https://www.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com https://get.geojs.io *.avada.io ekr.zdassets.com/ *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' data: wss://fulltextsearch.org/flare ka-f.fontawesome.com yoast.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://www.google.pl translate.googleapis.com www.gdpsystem.eu connect.facebook.net; default-src 'self'; font-src 'self' data: https://fonts.gstatic.com fonts.googleapis.com cdn.jsdelivr.net *.fontawesome.com/releases/v5.15.4/; frame-src 'self' data: uwr.edu.pl *.uwr.edu.pl maps.google.com *.youtube.com youtube.com player.vimeo.com www.google.com; img-src 'self' data: blob: graph.facebook.com *.xx.fbcdn.net s.w.org *.ytimg.com uwr.edu.pl *.uwr.edu.pl *.fna.fbcdn.net secure.gravatar.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com www.google.pl https://ssl.gstatic.com https://www.gstatic.com *.vimeocdn.com; object-src 'self'; script-src 'self' cdn.jsdelivr.net https://*.googletagmanager.com www.youtube.com use.fontawesome.com kit.fontawesome.com ajax.googleapis.com cdn-eu.readspeaker.com polyfill.io code.jquery.com https://tagmanager.google.com www.googletagmanager.com https://www.google-analytics.com www.gdpsystem.eu 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' uwr.edu.pl data: code.jquery.com kit.fontawesome.com polyfill.io cdn-eu.readspeaker.com cdn-eu.readspeaker.com ajax.googleapis.com cdn.jsdelivr.net www.youtube.com/iframe_api *.www-widgetapi.js www.youtube.com cdnjs.cloudflare.com cdn.datatables.net secure.polldaddy.com connect.facebook.net www.googletagmanager.com www.gdpsystem.eu 'unsafe-inline'; style-src 'self' cdn.jsdelivr.net cdn-eu.readspeaker.com https://tagmanager.google.com https://fonts.googleapis.com www.gdpsystem.eu 'unsafe-inline'; style-src-elem 'self' uwr.edu.pl cdn.jsdelivr.net www.youtube.com fonts.googleapis.com cdn-eu.readspeaker.com www.gdpsystem.eu 'unsafe-inline'; worker-src 'self' uwr.edu.pl blob: 1 default-src 'self' https: data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-scripts.com https://*.hscollectedforms.net https://*.hs-banner.com https://*.hubspotusercontent.com https://*.hubspotusercontent-eu1.net https://js.hs-analytics.net https://js.hsforms.net https://api.hsforms.com https://api.hubapi.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hs-web-analytics.net https://static.hsappstatic.net https://cdn2.hubspot.net https://cdn.hubspot.com https://*.cloudfront.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://stats.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org https://www.youtube.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https: data:; connect-src 'self' https: wss: https://www.tayyarijeetki.in; media-src 'self' https: data: blob:; worker-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self' https://*.hubspot.com; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.instagram.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com https://applepay.cdn-apple.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com cdn.doofinder.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net *.instagram.com cdn.doofinder.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com *.doofinder.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com *.doofinder.com wss://*.doofinder.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com https://fonts.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mobilpay.ro *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.googletagmanager.com/ *.innoship.ro js.mollie.com www.xtento.com *.googletagmanager.com *.livechatinc.com *.facebook.com *.criteo.com doubleclick.net *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.tile.openstreetmap.org *.openstreetmap.org https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com *.facebook.com *.google.ro *.cloudfront.net nailsup.ro *.nailsup.ro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ cdnjs.cloudflare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.mollie.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com *.tiktok.com *.facebook.net *.livechatinc.com attr-2p.com nailsup.ro *.hotjar.com *.criteo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.tiktok.com *.livechatinc.com *.doubleclick.net *.googlesyndication.com *.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-633e7ec5-174d-4ec7-b660-dea7667fdf28' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.ottokasino.com https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.ottokasino.com/eum-collector/report/csp-report; 1 default-src 'self'; connect-src *; font-src data: *; frame-src *; img-src data: *; media-src *; object-src *; script-src 'self' 'unsafe-eval' 'unsafe-inline' *; style-src 'self' 'unsafe-inline'; report-uri https://csp-reports.firmseek.com/hodgsonruss; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.adobe.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com api.razorpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.adtrafficquality.google *.clarity.ms *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com cdn.razorpay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com http://sp-kf-collector.dev.gokwik.io https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.lightwidget.com *.artfut.com *.adtrafficquality.google *.googlesyndication.com s3-ap-southeast-1.amazonaws.com *.cloudflare.com *.clarity.ms *.vimeo.com *.mxpnl.com *.bing.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com cdn.jsdelivr.net checkout.razorpay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com http://sp-kf-collector.dev.gokwik.io https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.onedirect.in *.adtrafficquality.google *.clarity.ms *.mixpanel.com *.adobe.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com wss://sockets.wizzy.ai *.wizsearch.in wss://sockets.wizsearch.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com https://ws.colissimo.fr https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com https://cdnjs.cloudflare.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.youtube.com https://form.typeform.com https://www.google.com https://www.gstatic.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.disqus.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr integrations.etrusted.com res-1.cloudinary.com t4.my-probance.one https://sogecommerce.societegenerale.eu/static/latest/images/type-carte/ https://api-sogecommerce.societegenerale.eu/static/ https://sogecommerce.societegenerale.eu/vads-payment/ https://img.youtube.com https://firebasestorage.googleapis.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com app.zipchat.ai app.trygr.io cdn.trygr.io s.pinimg.com cdn.caast.tv ct.pinterest.com static.hotjar.com script.hotjar.com fast-static.smarketer.de widgets.trustedshops.com t4.my-probance.one https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.avada.io *.shopify.com player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com assets.braintreegateway.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com integrations.etrusted.com https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com app.zipchat.ai app.trygr.io cache.caast.tv ct.pinterest.com content.hotjar.io wss://ws.hotjar.com fast.smarketer.de https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://get.geojs.io *.avada.io maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com stoiximan.com.cy *.stoiximan.com.cy cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=6Vixawzgbi8RcO9mMkjOFsIlAd7gn5E3nGL6j_2HZck-1765936837-1.0.1.1-sOwBomz4_Nw6REimOnZZ5tPnazNyfl9cx9N5zlmdTg2IirIBrjSlp7xysM1JejkNqNxdNIOwAxCdMxUkRAfcSPsAZ.BmvQ2Pq0OllCnfrfFooBMLrpjOpUdVEg2VA40mHPGfO1XoXpNpZnhUqRqzvBlTTvjJrT3BFfLTw5VU33zu91n7l6dX4Wj0cCjomGC5srNd3Irxw9_nBY6lUmx9bg; report-to cf-yexsaqxzlnxukxgr 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com * use.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com community.blackovis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com https://plumrocket.com * *.yotpo.com swellrewards.com *.swellrewards.com community.blackovis.com 'self' 'unsafe-inline'; frame-ancestors community.blackovis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://plumrocket.com * *.yotpo.com swellrewards.com *.swellrewards.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com community.blackovis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nextopia.net store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com * *.yotpo.com swellrewards.com *.swellrewards.com maps.gstatic.com *.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net community.blackovis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.nextopia.net *.ecomm-nav.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com * *.yotpo.com swellrewards.com *.swellrewards.com maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com community.blackovis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com maxcdn.bootstrapcdn.com cdn.nextopia.net unsafe-inline * *.yotpo.com swellrewards.com *.swellrewards.com tagmanager.google.com *.googleapis.com community.blackovis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com community.blackovis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nextopia.net *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com * *.yotpo.com swellrewards.com *.swellrewards.com *.google-analytics.com https://imgs.signifyd.com community.blackovis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com community.blackovis.com http: https: blob: 'self' 'unsafe-inline'; default-src community.blackovis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.audioeye.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.brightcove.net *.brightcove.com *.weltpixel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.brightcove.net *.brightcove.com *.boltdns.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.facebook.com *.reddit.com *.adtrafficquality.google *.cookielaw.org *.lightboxcdn.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.brightcove.net *.brightcove.com *.attn.tv events.attentivemobile.com *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ordergroove.com maps.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.adtrafficquality.google *.audioeye.com *.clarity.ms *.cookielaw.org *.gstatic.com *.lightboxcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com *.typekit.net *.googlesyndication.com tagmanager.google.com *.audioeye.com *.lightboxcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.brightcove.net *.brightcove.com *.boltdns.net *.brightcovecdn.com maps.googleapis.com *.attn.tv events.attentivemobile.com *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ordergroove.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.adtrafficquality.google *.audioeye.com *.clarity.ms *.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.brightcovecdn.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://assets.adobedtm.com https://static.cloud.coveo.com https://www.gstatic.com https://www.google.com https://maps.googleapis.com https://dpm.demdex.net; https://analytics.cloud.coveo.com https://marketplace.api.healthcare.gov https://viewlicense.adobe.io https://smetrics.bcbsnd.com https://px.ads.linkedin.com https://geo.fcc.gov; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://assets.adobedtm.com https://static.cloud.coveo.com https://acrobatservices.adobe.com https://www.gstatic.com https://www.google.com https://maps.googleapis.com https://www.youtube.com https://player.vimeo.com https://connect.facebook.net https://api.dmcdn.net https://googleads.g.doubleclick.net https://snap.licdn.com https://www.googletagmanager.com https://ipapi.co; connect-src 'self' https://dpm.demdex.net https://analytics.cloud.coveo.com https://platform.cloud.coveo.com https://marketplace.api.healthcare.gov https://viewlicense.adobe.io https://smetrics.bcbsnd.com https://px.ads.linkedin.com https://maps.googleapis.com https://www.google.com https://api.bcbsnd.com https://geo.fcc.gov; img-src 'self' data: https://cm.everesttech.net https://maps.gstatic.com https://smetrics.bcbsnd.com https://www.google.co.in https://www.facebook.com https://www.google.com; media-src 'self' https://dai.ly https://dl6.webmfiles.org https://fb.watch https://vimeo.com https://youtube.com https://youtu.be; frame-src 'self' https://bcbsnd.demdex.net https://acrobatservices.adobe.com https://www.googletagmanager.com https://www.google.com https://player.vimeo.com https://www.youtube.com; report-to csp-endpoint; report-uri /services/bcbsnd/cspViolation 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com 'unsafe-inline' data: *.gstatic.com 'self' data: www.designsbyjuju.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.designsbyjuju.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net www.designsbyjuju.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com https://www.googletagmanager.com/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.youtube.com https://c.paypal.com/ *.weltpixel.com www.designsbyjuju.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com store.paradoxlabs.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ 'self' data: blog.designsbyjuju.com www.designsbyjuju.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com *.attn.tv events.attentivemobile.com *.certcapture.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com *.google.com *.gstatic.com embedsocial.com sec.webeyez.com https://www.googletagmanager.com tagmanager.google.com www.designsbyjuju.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com embedsocial.com tagmanager.google.com www.designsbyjuju.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.designsbyjuju.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.attn.tv events.attentivemobile.com *.certcapture.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ send.webeyez.com sec.webeyez.com cognito-identity.eu-west-1.amazonaws.com firehose.eu-west-1.amazonaws.com https://www.google-analytics.com www.designsbyjuju.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com www.designsbyjuju.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.designsbyjuju.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.mx/api/csp-report; report-to csp-endpoint 1 default-src 'self'; script-src 'self' https://agrilife.org; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://agrilife.org; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.stevens.com.pa https://www.googletagmanager.com/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com tracker.metricool.com www.facebook.com www.google.cl *.stevens.com.pa stevens.com.pa *.clau.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com www.google.com rum-static.pingdom.net connect.facebook.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com bam.nr-data.net rum-collector-2.pingdom.net www.google.com.ar test-drive-11-s6uit34pua-uc.a.run.app http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net www.google.com *.stevens.com.pa stevens.com.pa 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.thechronicle.com.au/csp-reports 1 default-src 'self'; script-src 'self' 'nonce-MmFkYTk0NDYtODEzMy00OWRiLWI0YzgtMWM3YjdkZDJjOTAy' 'strict-dynamic' ; style-src 'self' 'unsafe-inline' 'nonce-MmFkYTk0NDYtODEzMy00OWRiLWI0YzgtMWM3YjdkZDJjOTAy' https://fonts.googleapis.com https://myhealthatvanderbilt.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' blob: data: https://*.files.vanderbilthealth.com https://api.krames.com; font-src 'self' https://fonts.gstatic.com; object-src 'self' https://*.files.vanderbilthealth.com; connect-src 'self' https://edge.adobedc.net http://*.mktoresp.com http://*.swiftypecdn.com; frame-src https://myhealthatvanderbilt.com https://play.vidyard.com https://www.youtube-nocookie.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; block-all-mixed-content; upgrade-insecure-requests; report-uri /api/v1/csp-report; report-to csp-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.acuityplatform.com challenges.cloudflare.com *.cloudfunctions.net *.configcat.com storage.googleapis.com cloudflare.hcaptcha.com cf-assets.hcaptcha.com *.kooth.com global.localizecdn.com *.segment.com *.segment.io *.sentry.io *.usefathom.com *.xenzonegroup.com wss://*.xenzonegroup.com wss://*.twilio.com *.snapchat.com media.twiliocdn.com flex-api.twilio.com; script-src-elem 'self' 'unsafe-inline' data: *.acuityplatform.com challenges.cloudflare.com storage.googleapis.com *.kooth.com global.localizecdn.com *.segment.com *.usefathom.com *.xenzonegroup.com www.googletagmanager.com *.doubleclick.net connect.facebook.net sc-static.net *.snapchat.com media.twiliocdn.com flex-api.twilio.com; connect-src 'self' *.cloudfunctions.net *.configcat.com *.kooth.com global.localizecdn.com *.localizejs.com *.segment.com *.segment.io *.sentry.io *.usefathom.com *.xenzonegroup.com wss://*.xenzonegroup.com wss://*.twilio.com *.analytics.google.com *.google-analytics.com *.snapchat.com media.twiliocdn.com flex-api.twilio.com; img-src * data:; media-src * data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src * data: chrome-extension: moz-extension: safari-web-extension:; frame-src 'self' vimeo.com *.vimeo.com challenges.cloudflare.com www.googletagmanager.com *.doubleclick.net *.snapchat.com; object-src 'none'; report-uri https://o367623.ingest.sentry.io/api/5691169/security/?sentry_key=d228aa23f64c4234b0ed98ff46a429d3?sentry_environment=csp_header_in_test_environments_or_csp-report-only_header_in_live 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.angusrobertson.com.au; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.secure-afterpay.com.au bam.nr-data.net *.hotjar.com googleads.g.doubleclick.net *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.bing.com *.google.com *.gstatic.com *.forter.com *.visualwebsiteoptimizer.com *.cloudfront.net static.scarabresearch.com cdn.scarabresearch.com apis.google.com *.criteo.com static.criteo.net *.newrelic.com connect.facebook.net platform.twitter.com d.impactradius-event.com *.afterpay.com; connect-src 'self' blob: *.cloudfront.net *.google-analytics.com *.hotjar.io *.nr-data.net stats.g.doubleclick.net *.emarsys.net *.scarabresearch.com *.hotjar.com *.salecycle.com *.forter.com opentag-stats.qubit.com *.visualwebsiteoptimizer.com recommender.scarabresearch.com angusrobertson.4tqiav.net; img-src 'self' data: *.criteo.net *.google-analytics.com *.google.com *.bing.com *.google.com.au *.pinterest.com *.cloudfront.net *.visualwebsiteoptimizer.com *.facebook.com syndication.twitter.com *.secure-afterpay.com.au *.angusrobertson.com.au *.loggly.com; frame-src 'self' *.cloudfront.net *.angusrobertson.com.au *.google.com platform.twitter.com www.facebook.com staticxx.facebook.com www.youtube.com *.criteo.com *.criteo.net *.hotjar.com *.salecycle.com bid.g.doubleclick.net 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.fr/api/csp-report; report-to csp-endpoint 1 script-src 'strict-dynamic' 'self' 'nonce-nJGFQ540vWKnNnscq3FRww==' 'report-sample'; report-uri /gdhvb2c.onmicrosoft.com/B2C_1_signup_signin/client/cspreport?p=B2C_1_signup_signin 1 default-src 'self' https://quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com *.qqcw.us; connect-src 'self' https://*.ads.linkedin.com https://www.googleadservices.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://js.stripe.com https://api.stripe.com https://*.googleapis.com https://cdn.sanity.io https://*.google.com https://*.gstatic.com https://unpkg.com https://*.mouseflow.com https://api.segment.io/v1/m https://connect.facebook.net/en_US/fbevents.js https://*.facebook.net https://*.facebook.com https://qqcw.report-uri.com/r/t/csp/reportOnly https://www.googletagmanager.com https://tagmanager.google.com https://*.fbot.me https://cdn.feathery.io https://api.feathery.io https://cdn.jsdelivr.net https://www.google-analytics.com https://google.com https://*.doubleclick.net data: blob:; font-src 'self' https://use.fontawesome.com https://fonts.gstatic.com https://js.stripe.com https://*.fbot.me; img-src 'self' https://d3st4nmzrq9nfk.cloudfront.net https://*.ads.linkedin.com https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://*.googleapis.com https://*.gstatic.com https://cdn.sanity.io *.google.com *.facebook.net www.facebook.com *.googleusercontent.com https://www.google-analytics.com https://*.googleadservices.com https://*.doubleclick.net https://www.googletagmanager.com https://*.fbot.me data: blob:; media-src 'self' https://quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://*.fbot.me; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ads.linkedin.com https://snap.licdn.com https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://js.stripe.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://unpkg.com https://cdn.mouseflow.com *.googleusercontent.com https://connect.facebook.net/en_US/fbevents.js *.facebook.net https://www.googletagmanager.com https://tagmanager.google.com/ https://*.fbot.me https://*.feathery.io https://cdn.jsdelivr.net https://www.google-analytics.com https://*.doubleclick.net https://googleadservices.com https://www.youtube.com blob:; style-src 'self' 'unsafe-inline' https://dontdrivedirty.com https://*.dontdrivedirty.com https://use.fontawesome.com https://fonts.googleapis.com https://tagmanager.google.com/ https://fonts.googleapis.com/ https://*.fbot.me data: blob:; frame-src 'self' https://www.facebook.com https://js.stripe.com *.google.com https://www.googletagmanager.com https://tagmanager.google.com/ https://*.fbot.me https://cdn.feathery.io https://cdn.jsdelivr.net https://*.doubleclick.net https://www.youtube-nocookie.com/ https://keycloak.dev.qqcw.us https://auth.dontdrivedirty.com; report-uri https://qqcw.report-uri.com/r/t/csp/reportOnly?ngsw-bypass=true; 1 report-to kmstools.com; font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: *.postescanada-canadapost.ca https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.shift4.com *.shift4test.com *.i4go.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ data: *.google.com *.gstatic.com *.facebook.com *.postescanada-canadapost.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.shift4.com *.shift4test.com *.i4go.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com *.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.gstatic.com *.googleapis.com *.signifyd.com *.online-metrix.net *.google.com *.paypal.com *.googletagmanager.com *.analytics.yahoo.com s.ytimg.com *.postescanada-canadapost.ca kmstools.com *.kmstools.com *.cloudfront.net *.bing.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://firebasestorage.googleapis.com *.shift4.com *.shift4test.com *.i4go.com *.facebook.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.eigendev.com *.googleapis.com *.gstatic.com *.facebook.net *.googleapis.net *.googletagmanager.com *.google.com data: *.postescanada-canadapost.ca *.newrelic.com *.nr-data.net *.searchspring.net *.trustpilot.com *.3cx.com *.my3cx.ca:5001 *.tctm.co *.bing.com *.clickcease.com snapui.searchspring.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.avada.io *.shopify.com *.shift4.com *.shift4test.com *.i4go.com https://www.googletagmanager.com tagmanager.google.com unpkg.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.gstatic.com *.googleapis.com *.postescanada-canadapost.ca *.searchspring.net unsafe-inline assets.braintreegateway.com https://fonts.bunny.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com *.googleapis.com *.google-analytics.com *.nr-data.net *.doubleclick.net *.signifyd.com *.searchspring.io *.postescanada-canadapost.ca *.3cx.com *.my3cx.ca:5001 api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://get.geojs.io *.avada.io *.shift4.com *.shift4test.com *.i4go.com *.facebook.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; script-src-elem 'none'; script-src-attr 'none'; report-uri https://csp-report.apptrana.com/csp/report/11447 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.cloudflare.com *.bing.com *.rfihub.net *.boomtrain.com *.cookielaw.org *.facebook.net *.doubleclick.net *.derbysoftsec.com *.rezync.com *.cdn.digitaloceanspaces.com *.azds.com *.sojern.com *.quantcount.com *.crazyegg.com *.quantserve.com *.cloudflareinsights.com *.stackadapt.com *.google-analytics.com *.googletagmanager.com *.tiqcdn.com *.stripe.com *.googleapis.com *.gstatic.com *.google.com *.callrail.com *.googleadservices.com *.yimg.com *.simpli.fi *.matomo.cloud plausible.io *.umami.is *.posthog.com *.threatspike.com *.qvdt3feo.com *.montage.com; script-src-elem 'self' 'unsafe-inline' *.cloudflare.com *.bing.com *.rfihub.net *.boomtrain.com *.cookielaw.org *.facebook.net *.doubleclick.net *.derbysoftsec.com *.rezync.com *.cdn.digitaloceanspaces.com *.azds.com *.sojern.com *.quantcount.com *.crazyegg.com *.quantserve.com *.cloudflareinsights.com *.stackadapt.com *.google-analytics.com *.googletagmanager.com *.tiqcdn.com *.stripe.com *.googleapis.com *.gstatic.com *.google.com *.callrail.com *.googleadservices.com *.yimg.com *.simpli.fi *.montage.com *.storage.googleapis.com plausible.io *.matomo.cloud *.sc-static.net *.posthog.com *.threatspike.com *.umami.is *.infird.com *.hotjar.com *.upsellit.com *.redditstatic.com blob:; connect-src 'self' *.azds.com *.boomtrain.com *.callrail.com *.cookielaw.org *.crazyegg.com *.doubleclick.net *.facebook.com *.g.doubleclick.net *.google-analytics.com google.com *.google.com.mx *.google.com *.google.de *.googleadservices.com *.googletagmanager.com *.googleapis.com *.google.co.uk *.onetrust.com *.sojern.com *.stackadapt.com *.tiqcdn.com *.myhotelshop.de *.awsapprunner.com *.run.app *.letsway.com *.bing.com *.bing.net *.googlesyndication.com *.matomo.cloud *.umami.dev *.yimg.com plausible.io *.pendry.com *.posthog.com *.yoast.com *.launchdarkly.com *.geoedge.com *.adsrvr.org *.yoast.com *.cloudfront.net *.adform.net *.adnxs.com *.tiktokw.us *.tiktok.com *.browsekeeper.com *.redditstatic.com *.reddit.com *.overbridgenet.com *.montage.com data:; frame-src 'self' *.doubleclick.net *.facebook.com *.googletagmanager.com *.google.com *.pcibooking.net *.rfihub.net *.rfihub.com *.sojern.com *.stripe.com *.azds.com *.zscalerthree.net *.truetour.app truetour.app visitingmedia.com *.vimeo.com *.formcrafts.com *.ibotta.com *.contextall.com *.canyonsdistrict.org *.ggusd.us *.menlosecurity.com *.zscaler.net *.snapchat.com *.montage.com blob:; style-src * 'unsafe-inline'; img-src * data: blob:; font-src * data:; media-src * 'self' data:; manifest-src * 'self'; worker-src 'self' blob:; child-src 'self' blob:; report-uri https://cfe87652b26de6b69f71ed43bef9cf37.report-uri.com/r/d/csp/reportOnly; 1 upgrade-insecure-requests; default-src 'self' https: data: wss: 'unsafe-inline' 'unsafe-eval'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.klevu.com *.ksearchnet.com pro.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com *.google.com/ js.mollie.com https://www.googletagmanager.com *.yotpo.com *.stripe.com klarna.com *.link.com ct.pinterest.com insight.adsrvr.org 10716119.fls.doubleclick.net td.doubleclick.net app.hubspot.com www.facebook.com swellrewards.com *.swellrewards.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.certcapture.com https://images.unsplash.com https://www.magezon.com *.klevu.com *.ksearchnet.com https://www.mollie.com *.monrovia.com js.hubspot.com js.hs-analytics.net js.hsleadflows.net js.hsadspixel.net js.hs-banner.com js.adsrvr.org mnc-img-01.sfo2.cdn.digitaloceanspaces.com forms-na1.hsforms.com ad.doubleclick.net *.yotpo.com dhv2ziothpgrr.cloudfront.net www.facebook.com track.hubspot.com perf-na1.hsforms.com images.unsplash.com https://mnc-img-01.sfo2.cdn.digitaloceanspaces.com https://*.klevu.com pagead2.googlesyndication.com swellrewards.com *.swellrewards.com ade.googlesyndication.com *.global.siteimproveanalytics.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.certcapture.com https://maps.googleapis.com *.google.com/ *.klevu.com *.ksearchnet.com js.mollie.com www.gstatic.com https://js.klevu.com js.hsforms.net web-sdk.smartlook.com player.vimeo.com f.vimeocdn.com config-cdn.ksearchnet.com s.pinimg.com ct.pinterest.com *.yotpo.com *.swellrewards.com swellrewards.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net js.hs-scripts.com siteimproveanalytics.com cdn.noibu.com rec.smartlook.com connect.facebook.net js.adsrvr.org js.hubspotfeedback.com js.hubspot.com js.hs-analytics.net js.hsleadflows.net js.hsadspixel.net js.hs-banner.com https://rapid-cdn.yottaa.com *.monrovia.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.klevu.com *.ksearchnet.com use.typekit.net p.typekit.net *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.certcapture.com https://maps.googleapis.com https://player.vimeo.com *.klevu.com *.ksearchnet.com *.monrovia.com *.stripe.com *.swellrewards.com klarna.com *.klarnacdn.net *.link.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com dhv2ziothpgrr.cloudfront.net forms.hsforms.com forms-na1.hubspot.com manager.eu.smartlook.cloud ct.pinterest.com insight.adsrvr.org api.hubapi.com cta-service-cms2.hubspot.com forms.hubspot.com web-writer.us.smartlook.cloud assets-proxy.smartlook.cloud static.hsappstatic.net pagead2.googlesyndication.com *.yotpo.com swellrewards.com *.klarna.com *.klarnaevt.com *.amazon.com *.smsbump.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self';connect-src https://*.go-mpulse.net https://*.akstat.io 'self' https: *.sentry.io *.amplitude.com *.care.com *.carezen.net *.signalfx.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net font.google.com analytics.google.com tagmanager.google.com www.google.com https://*.hotjar.com https://vc.hotjar.io https://content.hotjar.io https://events.hotjar.io https://surveystats.hotjar.io wss://*.hotjar.com https://geolocation.onetrust.com;default-src 'self' wss://*.care.com *.care.com *.careapis.com *.carezen.net *.cdn-care.com care.com cdn-care.com www.gstatic.com www.google.com *.googlesyndication.com tags.tiqcdn.com tags-eu.tiqcdn.com tk.getwork.com tr.snapchat.com shareasale.com *.doubleclick.net apps.rokt.com bid.g.doubleclick.net tags.w55c.net *.linkedin.com www.pinterest.com carecom.sjv.io staging-pt.ispot.tv ct.pinterest.com;font-src 'self' data: https://www.care.com https://www.dev.carezen.net https://www.stg.carezen.net fonts.gstatic.com https://script.hotjar.com;frame-ancestors 'self';img-src data: blob: *;object-src 'none';script-src https://*.go-mpulse.net 'nonce-f122e3153c857aac8979cf1b12e090a4' 'self' *.akamaihd.net *.care.com *.careapis.com *.carezen.net *.cdn-care.com *.cloudfront.net *.googlesyndication.com *.sift.com *.monetate.net acsbapp.com analytics.tiktok.com apps.rokt.com bat.bing.com care.com cdn-care.com cdn.pdst.fm connect.facebook.net d.impactradius-event.com googleads.g.doubleclick.net maps.googleapis.com s.pinimg.com ssl.google-analytics.com tags-eu.tiqcdn.com tags.tiqcdn.com wss://*.care.com www.emjcd.com www.google-analytics.com www.google.com www.googleadservices.com *.googletagmanager.com www.gstatic.com tr.outbrain.com tags.w55c.net clarity.ms staging-pt.ispot.tv tracker.mnixdata.com *.mountain.com tagmanager.google.com s.go-mpulse.net collector-12308.tvsquared.com js.adsrvr.org https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org https://dev.visualwebsiteoptimizer.com 'nonce-7e9e67d9caeef0f5b6091d6ceac1500f' 'strict-dynamic';frame-src 'self' alchemy.veriff.com www.google.com recaptcha.google.com bid.g.doubleclick.net 12355078.fls.doubleclick.net s.go-mpulse.net carecom.sjv.io apps.rokt.com tr.snapchat.com 3239339.fls.doubleclick.net https://vars.hotjar.com insight.adsrvr.org https://www.youtube.com/ https://ots2-qa.learningcaregroup.com/ScheduleATour/ https://ots2.learningcaregroup.com/ScheduleATour/ td.doubleclick.net;style-src 'self' 'unsafe-inline' tagmanager.google.com fonts.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org 'nonce-7e9e67d9caeef0f5b6091d6ceac1500f';style-src-attr 'self' 'unsafe-inline' tags.tiqcdn.com tags-eu.tiqcdn.com bat.bing.com;upgrade-insecure-requests;report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=hp-vhp-mfe%401.342.3&sentry_environment=prod 1 manifest-src https:; media-src https:; upgrade-insecure-requests; style-src 'self' https: 'unsafe-inline'; object-src 'none'; connect-src 'self' https:; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.searchanise.com *.searchserverapi.com v2.zopim.com embed.tawk.to *.commerce-connector.com *.flixcar.com fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sameday.ro c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.weltpixel.com *.2performant.com *.doubleclick.net *.pinterest.com *.force.com *.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com cdn.kfea.ro shopmania.ro *.openstreetmap.org t.themarketer.com cdn1.themarketer.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com v2assets.zopim.io *.google.ro *.facebook.com *.widgetwhats.com tawk.link compari.ro ct.pinterest.com *.flix360.com *.flixcar.com *.flix360.io *.bing.com bat.bing.com cdn-cookieyes.com cdn1.mktr2.com c.clarity.ms data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.sameday.ro unpkg.com/map-fanbox-points@0.0.5/umd/map-fanbox-points.js *.themarketer.com cdn1.themarketer.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com https://www.googletagmanager.com tagmanager.google.com *.zdassets.com v2.zopim.com *.facebook.net *.facebook.com attr-2p.com *.widgetwhats.com chimpstatic.com embed.tawk.to *.jsdelivr.net *.hotjar.com *.arukereso.com *.gstatic.com *.clarity.ms *.pinimg.com *.pinterest.com *.enzuzo.com cdn-cookieyes.com *.googlesyndication.com *.commerce-connector.com *.force.com *.salesforceliveagent.com aqurate.ai *.flixcar.com *.flix360.io *.flixfacts.com popupsmart.com *.sharethis.com *.tiktok.com *.omniconvert.com *.2performant.com *.bing.com bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sameday.ro t.themarketer.com cdn1.themarketer.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com tagmanager.google.com *.googleapis.com *.widgetwhats.com embed.tawk.to *.googletagmanager.com tpc.googlesyndication.com *.cloudfront.net *.commerce-connector.com *.force.com *.popupsmart.com popupsmart.com *.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com cdn1.mktr2.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.fancourier.ro *.themarketer.com cdn1.themarketer.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.amplitude.com stats.g.doubleclick.net https://www.google-analytics.com ekr.zdassets.com wss://widget-mediator.zopim.com pagead2.googlesyndication.com *.google.ro googleads.g.doubleclick.net region1.analytics.google.com *.2performant.com *.widgetwhats.com zdata-ro-bellabike.s3.eu-west-1.amazonaws.com *.tawk.to kfea.zendesk.com api.edrone.me *.pinterest.com *.clarity.ms *.commerce-connector.com *.facebook.com *.hotjar.com *.hotjar.io *.google-analytics.com *.sharethis.com *.enzuzo.com *.flixcar.com *.tiktok.com *.omniconvert.com region1.google-analytics.com *.cookieyes.com log.cookieyes.com cdn-cookieyes.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src widget-mediator.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.fontawesome.com *.oct8ne.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com https://www.googletagmanager.com/ *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.gstatic.com *.feedaty.com *.erickson.it http://risorseonline.erickson.it *.salesmanago.com cdn.doofinder.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com *.feedaty.com *.iubenda.com *.acsbapp.com *.salesmanago.com *.erickson.it *.zdassets.com cdn.doofinder.com https://code.gelproximity.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.feedaty.com *.doofinder.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.feedaty.com *.doubleclick.net *.scalapay.com *.erickson.it *.acsbapp.com *.zdassets.com *.iubenda.com *.doofinder.com wss://*.doofinder.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://gmm9n9.pixum.de https://bn3mcl4n8l.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://gmm9n9.pixum.de https://bn3mcl4n8l.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 script-src 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' 'unsafe-eval' 'nonce-GQaEMgfDu2D+TZUZAmomBCiyUj82gu9CwqLKKMNPJEU='; base-uri 'none'; connect-src 'self' https://*.fontawesome.com https://*.googleapis.com https://*.googlesyndication.com https://consentcdn.cookiebot.com https://analytics.tiktok.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net; img-src data: 'self' https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://cdn.startpeople.be https://img.youtube.com https://i.ytimg.com https://imgsct.cookiebot.com https://vumbnail.com/ https://i.vimeocdn.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.css https://cdnjs.cloudflare.com/ajax/libs/bootstrap-datepicker/1.9.0/css/bootstrap-datepicker3.min.css https://cdn.jsdelivr.net/npm/bootstrap@5.3.0-alpha3/dist/css/bootstrap.min.css https://cdn.jsdelivr.net/npm/select2@4.0.13/dist/css/select2.min.css https://cdn.jsdelivr.net/npm/select2-bootstrap-5-theme@1.3.0/dist/select2-bootstrap-5-theme.min.css https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.3/font/bootstrap-icons.css https://fonts.googleapis.com; frame-src 'strict-dynamic' 'self' https://consentcdn.cookiebot.com https://www.google.com/recaptcha/ https://www.youtube-nocookie.com/ https://player.vimeo.com/; report-to csp-endpoint; report-uri https://csp-dxp.rgfstaffing.be/csp 1 script-src 'strict-dynamic' 'nonce-e51bcf3809563afcbf1f5c9fa87745d9' 'unsafe-inline' 'unsafe-eval' https: ; frame-ancestors 'self' ; base-uri 'self'; object-src 'none'; report-uri https://csp.phenompeople.com/violations; 1 object-src 'none'; connect-src 'self' *.21sextury.com *.21members.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.21sextury.com *.21members.com join.gammasecure.com; script-src 'self' *.21sextury.com *.21members.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.21sextury.com *.21members.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com https://*.gstatic.com data: https://*.typekit.net *.klarnacdn.net *.klevu.com *.ksearchnet.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.clearpay.co.uk *.iubenda.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.afterpay.com *.clearpay.co.uk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reviews.io *.reviews.co.uk *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.squarecdn.com downloads.mailchimp.com https://static.klaviyo.com https://*.googleapis.com https://*.typekit.net *.klarnacdn.net *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-JX5gBqt9LocPzOz7Rxi7Lw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' litium.revolutionrace.de fbcdn.revolutionrace.de wss://fbcdn.revolutionrace.de *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.de *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.musette.ro data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.facebook.com/ *.googlesyndication.com *.tiktok.com *.innoship.ro landofcoder.com https://www.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org https://firebasestorage.googleapis.com *.musette.ro *.google.com/ads/ *.google.ro *.google.ro/ads/ *.trusted.ro/ trusted.ro/ *.profitshare.ro *.omtrdc.net musette.ro maps.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com landofcoder.com www.termsfeed.com *.avada.io *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jivosite.com *.profitshare.ro profitshare.ro *.7w.ro *.aptrinsic.com *.musette.ro maps.googleapis.com chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.aptrinsic.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.jivosite.com *.musette.ro *.salofarm.ro *.stormers.ro 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.jivosite.com *.musette.ro 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com landofcoder.com https://get.geojs.io *.avada.io https://stats.g.doubleclick.net/ *.jivosite.com *.7w.ro *.aptrinsic.com maps.googleapis.com socialplugin.facebook.net region1.analytics.google.com wss://chat-eu1-4.jivosite.com *.musette.ro 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.beautysuccess.fr fonts.googleapis.com googleapis.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.weltpixel.com *.hipay-tpp.com *.hipay.com *.googleapis.com https://www.youtube.com https://form.typeform.com libs.hipay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.hipay.com *.googleapis.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.beautysuccess.fr maps.googleapis.com googleapis.com maps.gstatic.com *.openstreetmap.org api.maptiler.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com https://www.googletagmanager.com tagmanager.google.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.gstatic.com *.beautysuccess.fr *.googletagmanager.com maps.googleapis.com googleapis.com api.socloz.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.hipay.com *.googleapis.com tagmanager.google.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.gstatic.com *.beautysuccess.fr googleapis.com libs.hipay.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com https://www.google-analytics.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.beautysuccess.fr api.maptiler.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; connect-src 'self' bam.nr-data.net sentry.io *.freshworksapi.com wss://*.freshworksapi.com www.google-analytics.com heapanalytics.com www.in-freshbots.ai *.pusher.com; font-src 'self' d2r0bfj5oxwi8g.cloudfront.net d3t6wcud4kij68.cloudfront.net d28y7gk8dndm8e.cloudfront.net data: fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com heapanalytics.com; frame-src 'self' *.webpush.freshchat.com *.freshreports.com wchat.freshchat.com *.freshid.io *.freshworks360.io *.chargebee.com *.myfreshworks.dev *.freshworksweb.com freshdesk.com *.freshworks.com *.int.myfreshworks.dev; img-src https: data: blob: heapanalytics.com; manifest-src 'self'; media-src 'self' https:; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-eval' accounts.freshworks.com bam.nr-data.net d2r0bfj5oxwi8g.cloudfront.net d3t6wcud4kij68.cloudfront.net d28y7gk8dndm8e.cloudfront.net js-agent.newrelic.com polyfill.io wchat.freshchat.com sentry.io js.chargebee.com www.google-analytics.com *.freshworksapi.com heapanalytics.com *.heapanalytics.com fonts.googleapis.com cdn.in-freshbots.ai stats.pusher.com cdn.inlinemanual.com fe-perf-assets.freshworks.com 'unsafe-inline'; style-src 'report-sample' 'self' 'unsafe-inline' accounts.freshworks.com d2r0bfj5oxwi8g.cloudfront.net d3t6wcud4kij68.cloudfront.net d28y7gk8dndm8e.cloudfront.net wchat.freshchat.com fonts.googleapis.com cdn.in-freshbots.ai heapanalytics.com; worker-src 'self'; report-uri https://vfm4r1o44m.execute-api.us-east-1.amazonaws.com/default/FreshreleaseCSPReport 1 script-src https://www.charly.com/ 'nonce-cWhreDcyN214cWhyZGJzejNtN3VzZ25rODR3NXFlMzNvY3p3dW1nMWZ1emgx' 'self' 'unsafe-eval' *.adobe.com *.adobe.io *.adobedtm.com *.braintreegateway.com *.magento-datasolutions.com *.magento-ds.com *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com *.sentry-cdn.com *.sentry.io *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net cdn.jsdelivr.net/npm/@adobe/ commerce.adobe.net developers.google.com https://h64.online-metrix.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ js.magento-datasolutions.com magento-recs-sdk.adobe.net maps.googleapis.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ use.typekit.net vimeo.com www.vimeo.com byspotify.com tiktok.com global-cache.online infird.com gstatic.com paypalobjects.com googleapis.com facebook.net facebook.com connect.facebook.net *.googletagmanager.com *.google-analytics.com *.google.com pinimg.com pinterest.com; style-src 'self' blob: 'unsafe-inline' https://www.charly.com/ 'unsafe-hashes' *.fonts.googleapis.com https://fonts.googleapis.com; img-src data: 'self' https://www.charly.com/ *.google.ie *.paypal.com *.paypalobjects.com *.facebook.com *.facebook.net connect.facebook.net google.com gstatic.com paypal.com flagcdn.com *.googletagmanager.com wolfcharly.com mcstaging.wolfcharly.com googleapis.com google.cctld com.mxmedia *.paypalobjects.com *.maps.gstatic.com *.maps.googleapis.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com; object-src 'none'; base-uri 'none'; child-src 'self'; font-src 'self' fonts.gstatic.com use.typekit.net *fonts.googleapis.com https://fonts.gstatic.com cdnfonts.com; frame-src assets.braintreegateway.com *.google.com *.youtube.com *.youtu.be *.vimeo.com *.adobe.com *.braintreegateway.com *.demdex.net fast.amc.demdex.net *.paypal.com *.paypalobjects.com *.youtube-nocookie.com schools-blocked.s3-website-us-east-1.amazonaws.com opendns.com paypal.com doubleclick.net pinterest.com *.googletagmanager.com *.google-analytics.com; report_uri https://82b58f34-a752-41e9-b0d2-7837f734aca7.sansec.watch/; report-to report-endpoint; frame-ancestors 'self' https://www.charly.com/; manifest-src 'self' 'unsafe-inline' https://www.charly.com/; connect-src 'self' https://www.charly.com/ *.adobe.io *.analytics.google.com *.braintreegateway.com 'unsafe-inline' *.magento-datasolutions.com *.magento-ds.com *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com *.sentry-cdn.com *.sentry.io *.snplow.net *.telemetry-dev.adobe.io *.telemetry.adobe.io amcglobal.sc.omtrdc.net api.magento.com commerce.adobedc.net dpm.demdex.net maps.googleapis.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com search-admin-ui-qa.magento-datasolutions.com search-admin-ui.magento-ds.com www.facebook.com; worker-src 'self'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.hsadspixel.net https://js.hs-banner.com https://*.hs-analytics.net https://js.hscta.net https://*.hubspot.com https://static.hsappstatic.net https://*.usemessages.com https://*.hubspot.net https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hsforms.net https://*.hsforms.com https://*.hs-scripts.com https://*.hubspotfeedback.com https://feedback.hubapi.com https://website-assets.atlan.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleoptimize.com https://*.googletagmanager.com https://*.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://cdn.jsdelivr.net https://ajax.googleapis.com https://unpkg.com https://embedsocial.com https://platform.twitter.com http://*.ads-twitter.com https://cdn.syndication.twimg.com https://static.ads-twitter.com https://*.clarity.ms https://bat.bing.com https://ipgeolocation.abstractapi.com https://platform.linkedin.com https://snap.licdn.com https://*.quora.com https://*.zi-scripts.com https://*.zoominfo.com https://player.vimeo.com https://f.vimeocdn.com https://*.vimeocdn.com https://*.salesloft.com https://*.demandbase.com https://*.company-target.com https://cdn.dreamdata.cloud https://www.redditstatic.com https://cdn.seersco.com https://*.sibforms.com https://*.ashbyhq.com https://plausible.io https://*.plausible.io https://darkvisitors.com https://*.darkvisitors.com https://connect.facebook.net https://*.facebook.com https://www.youtube.com https://s.ytimg.com https://js.blazeverify.com https://js.emailable.com/v1 https://www.gartner.com https://gartner.com *.crazyegg.com https://builder.io https://*.calendly.com https://cdnjs.cloudflare.com https://cloudflare.com https://static.cloudflareinsights.com https://cdn.rollbar.com https://*.rollbar.com https://*.chatbase.co https://*.emailable.com https://cdn-cookieyes.com https://*.cookieyes.com https://*.default.com https://*.lindy.ai https://*.g2.com https://groas.ai https://*.groas.ai https://tofuhq.com https://*.tofuhq.com;object-src 'none';worker-src blob:;report-uri https://o4507661801488384.ingest.sentry.io/api/4507683673866240/security/?sentry_key=b5327dda5a6527e6c04e9aa0de05fe22; report-to csp-endpoint 1 font-src *.gstatic.com 'self' data: *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.paypal.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com magefan.com cm.magefan.com *.disqus.com *.hsforms.net *.hsforms.com 'self' data: *.cloudfront.net https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com *.hsforms.net *.hsforms.com www.google.com *.gstatic.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.gstatic.com *.cloudflare.com getfirebug.com *.yotpo.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.cloudflare.com *.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com https://geowidget.easypack24.net *.spotify.com *.cepd.tech *.drogerienatura.pl *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://geowidget-app.inpost.pl/ secure.payu.com merch-prod.snd.payu.com *.spotify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org static.payu.com https://img.youtube.com *.spotify.com *.cepd.tech *.drogerienatura.pl *.syndigo.cloud trustmate.io cdn.cookiesaur.com google.pl *.google.pl visitor.omnitagjs.com sync.addlv.smt.docomo.ne.jp hbx.media.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com tagmanager.google.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org secure.payu.com secure.snd.payu.com pay.google.com applepay.cdn-apple.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com s7.addthis.com *.spotify.com *.cookiesaur.com *.jsdelivr.net *.cloudflare.com *.syndigo.com *.cepd.tech *.drogerienatura.pl *.newrelic.com *.nr-data.net trustmate.io static.hotjar.com tags.creativecdn.com connect.facebook.net s2.adform.net script.hotjar.com track.adform.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.spotify.com *.cloudflare.com *.cepd.tech *.drogerienatura.pl trustmate.io unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.easypack24.net *.inpost.pl *.openstreetmap.org secure.payu.com merch-prod.snd.payu.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com ekr.zdassets.com/ *.spotify.com *.cookiesaur.com *.syndigo.com trustmate.io *.newrelic.com *.nr-data.net *.cepd.tech *.drogerienatura.pl ams.creativecdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' api-accent.bloomreach.co api.smooch.io applepay.cdn-apple.com *.googleadservices.com *.braintreegateway.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cfjump.skechers.com.au cfjump.skechers.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com dma-cdn.staging.truefitcorp.com/fitrec/dma/js/tracker.js js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com s.pinimg.com/ct lantern.roeyecdn.com/lantern_global_cf42725.min.js *.adobemc.com js-sandbox.squarecdn.com api.myunidays.com player.vimeo.com ct.pinterest.com js.squarecdn.com *.stg.qantasloyalty.com/appcache/wid-redemptions-button/master/ *.stg.qantasloyalty.com/ ; style-src 'self' 'unsafe-inline' display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com *.adobetm.com foursixty.com *.adobemc.com static.klaviyo.com/onsite/js ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.skechers.co.nz *.skechers.com.au cm.everesttech.net/cm/dd googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com blob amcglobal.sc.omtrdc.net adservice.google.com lantern.roeye.com i.vimeocdn.com/video ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' api-accent.bloomreach.co analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.skechers.co.nz *.fullstory.com *.klaviyo.com smetrics.skechers.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com *.nr-data.net *.paypal.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com *.roymorgan.com foursixty.com kleber.datatoolscloud.net.au sentry.io vimeo.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com api.myunidays.com ct.pinterest.com/stats ct.pinterest.com/static ct.pinterest.com/v3 ct.pinterest.com/user lantern.roeye.com *.useinsider.com www.googletagmanager.com/td ad.doubleclick.net *.stg.qantasloyalty.com/ ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net ; frame-src 'self' api-accent.bloomreach.co www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.demdex.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com facebook.com foursixty.com google.com www.google.com vimeo.com *.pinterest.com *.qlstg.qantas.com/ ; worker-src 'self' blob: *.accentgra.com *.skechers.co.nz *.skechers.com.au; 1 default-src 'self' https:; connect-src 'self' https: wss:; script-src 'unsafe-inline' 'self' https:; worker-src blob:; style-src 'unsafe-inline' 'self' https:; object-src 'none'; img-src 'self' data: https:; frame-ancestors 'self' 1 frame-ancestors 'none'; report-uri /csp_logger/; 1 font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.cdn-apple.com *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com *.playground.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.facebook.com *.bing.com *.coccinelle.com stileo.it *.cookiebot.com *.google.it *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com *.klarna.com *.klarnaevt.com *.worldline-solutions.com *.secured-by-ingenico.com https://firebasestorage.googleapis.com *.webtrekk.net *.wt-eu02.net https://fbc.wcfbc.net https://*.flx1.com/ https://dmp.adform.net/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de kit.fontawesome.com *.cookiebot.com *.jsdelivr.net *.facebook.net *.clarity.ms *.bing.com glamipixel.com *.coccinelle.com *.rakuten.com *.rmtag.com *.criteo.com *.adobedtm.com *.cardinalcommerce.com *.doubleclick.net *.google.com *.r-data.net *.accelasearch.io *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com *.klarna.com x.klarnacdn.net *.cdn-apple.com *.avada.io https://responder.wt-safetag.com https://*.flx1.com/ https://www.googletagmanager.com https://*.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.gstatic.com *.fontawesome.com *.googleapis.com *.google.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.cookiebot.com *.googlesyndication.com *.google-analytics.com *.doubleclick.net *.coccinelle.com *.criteo.com *.klarnaevt.com *.playground.klarnaevt.com *.klarnaservices.com *.playground.klarnaservices.com *.klarnacdn.net x.klarnacdn.net *.klarna.com *.worldline-solutions.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io https://*.flx1.com/ https://*.gstatic.com https://jamie.g.shortest-route.com https://*.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; https://cdnjs.cloudflare.com https://connect.facebook.net https://cse.google.com https://dx.mountain.com https://googleads.g.doubleclick.net \ https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://analytics.google.com https://www.googletagmanager.com https://52.71.121.170 https://px.mountain.com script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://js.hs-analytics.net https://cdnjs.cloudflare.com https://connect.facebook.net https://cse.google.com https://dx.mountain.com https://googleads.g.doubleclick.net \ https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://analytics.google.com https://www.googletagmanager.com https://52.71.121.170 https://js.hubspot.com https://maps.googleapis.com https://px.mountain.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://ws.zoominfo.com https://www.google.com/cse/static/element/197b0e284b1b1f14/cse_element__en.js https://www.googletagmanager.com/gtm.js https://www.youtube.com/iframe_api; https://52.71.121.170 https://54.156.2.105 https://api.hubapi.com https://cta-service-cms2.hubspot.com https://forms.hscollectedforms.net https://maps.googleapis.com https://ws.zoominfo.com https://www.google.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.google.com; object-src 'none'; base-uri 'self'; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://share.hsforms.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' https://clients1.google.com https://forms.hsforms.com https://googleads.g.doubleclick.net https://maps.gstatic.com https://perf-na1.hsforms.com https://px.ads.linkedin.com https://track.hubspot.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com; manifest-src 'self'; media-src 'self' https://www.youtube.com https://youtu.be; report-uri https://nccer.us/csp?s=www.nccer.org; frame-ancestors 'self'; worker-src 'none'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://kelseyseyboldepiciframe-pp-prtl.spectrumretailnet.com;script-src 'nonce-4a99f968866b42fbb5d08586983d0bb3' https://mykelseyonline.com 'self' 'unsafe-eval' https://play.vidyard.com/ repo-stg.rakanto.com repo.rakanto.com;img-src https://* 'self' blob: data:;connect-src 'self' cse.rakanto.com epichttp: https://stage-cse.rakanto.com www.google.com;style-src https://mykelseyonline.com 'self' 'unsafe-inline' www.gstatic.com;worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:;report-uri /MkoApi/api/CspReport; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com www.searchanise.com *.searchserverapi.com staticw2.yotpo.com https://*.hotjar.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.hub-box.com www.searchanise.com *.searchserverapi.com *.twitter.com secure.livechatinc.com widget.trustpilot.com frame.hubbox.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.twitter.com *.twimg.com www.google.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com services.postcodeanywhere.co.uk *.google-analytics.com *.analytics.google.com https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io magento-recs-sdk.adobe.net www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com *.adyen.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net searchanise-ef84.kxcdn.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com cdn.cookie-script.com cdn.livechatinc.com api.livechatinc.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net widget.trustpilot.com searchserverapi.com cpage11112.pcapredict.com services.postcodeanywhere.co.uk analytics.ahrefs.com www.googleoptimize.com *.clarity.ms https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com *.twitter.com services.postcodeanywhere.co.uk maxcdn.bootstrapcdn.com https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.hub-box.com api.amplitude.com stats.g.doubleclick.net bam.nr-data.net bam-cell.nr-data.net services.postcodeanywhere.co.uk api.livechatinc.com *.google-analytics.com *.analytics.google.com mcprod.vapeuk.co.uk *.clarity.ms analytics.ahrefs.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'report-sample' https://static.mycasavi.com 'sha256-HqcrltV/add35ktFKnghPtUZD86xFk2tNSOVuSxlxZI=' 'sha256-nP0EI9B9ad8IoFUti2q7EQBabcE5MS5v0nkvRfUbYnM=' https://cdn.eu.pendo.io https://pendo-eu-static.storage.googleapis.com https://pendo-eu-static-5744612903485440.storage.googleapis.com https://app.intercom.io https://widget.intercom.io/ https://js.intercomcdn.com https://browser.sentry-cdn.com https://widget.moin.ai https://cdn.crowdin.com https://crowdin.com https://cdn-a.cumul.io https://static.hotjar.com https://script.hotjar.com https://maps.googleapis.com https://cdn.jsdelivr.net https://agent.b4u-cloud.de 'nonce-AgOlLU+LhVlkWTMRo50n2A==';worker-src 'self' blob: https://static.mycasavi.com;report-uri /csp-report;base-uri 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com cdn.livechatinc.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.punchout2go.com *.tradecentric.com https://connect.punchout2go.com 'self' 'unsafe-inline'; frame-ancestors https://cdn.livechatinc.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.punchout2go.com *.tradecentric.com https://cdn.chatbot.com https://*.doubleclick.net https://*.livechatinc.com https://vars.hotjar.com https://*.paymetric.com https://stementorstg.wpengine.com https://calendar.time.ly https://*.worldpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://p.adsymptotic.com https://hm.baidu.com/hm.gif https://bat.bing.com https://c.bing.com https://c.clarity.ms https://*.doubleclick.net/ https://d3cgm8py10hi0z.cloudfront.net/is.gif https://www.facebook.com/privacy_sandbox/ https://www.facebook.com/tr/ https://maps.googleapis.com/maps/ https://maps.gstatic.com/mapfiles/ https://www.google.ca/pagead/ https://www.google.com/pagead/ https://www.google.ca/ads/ https://www.google.com/ads/ https://www.googletagmanager.com/ https://static.kameleoon.com https://px.ads.linkedin.com/ https://cdn.files-text.com/api/accounts/avatars/ https://connect.punchout2go.com https://*.stemcell.com https://t.co https://analytics.twitter.com https://sp.analytics.yahoo.com https://www.linkedin.com/ https://id.rlcdn.com https://aorta.clickagy.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.googletagmanager.com *.punchout2go.com *.tradecentric.com https://cdn.recapture.io https://rum.hlx.page/ https://maps.googleapis.com/ https://hm.baidu.com/hm.js https://bat.bing.com https://*.clarity.ms/ https://cdn.chatbot.com https://tags.clickagy.com https://www.clickcease.com/ https://img.en25.com https://*.doubleclick.net https://connect.facebook.net https://ajax.googleapis.com/ajax/libs/ https://seal.geotrust.com/getgeotrustsslseal geoip-js.com https://*.hotjar.com https://*.livechatinc.com https://snap.licdn.com https://js-agent.newrelic.com https://bam.nr-data.net https://cmp.osano.com https://connect.punchout2go.com/jslib/ https://*.recapture.io/beacon/ https://cdn.recapture.io/sdk/ https://cdn.searchspring.net/intellisuggest/is.min.js https://*.stemcell.com/media/ https://*.twitter.com https://static.ads-twitter.com https://calendar.time.ly https://unpkg.com/tabulator-tables@6.2.1/dist/js/tabulator.min.js https://*.xisecurenet.com https://s.yimg.com/wi/ytc.js https://ws.zoominfo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.punchout2go.com *.tradecentric.com https://connect.punchout2go.com/jslib/ https://www.googletagmanager.com/debug/badge.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com https://app.recapture.io https://bat.bing.com/ https://cdn.chatbot.com https://*.clarity.ms/ https://*.doubleclick.net/ https://geoip-js.com https://www.googleadservices.com https://analytics.google.com/ *.google-analytics.com/ https://fonts.googleapis.com https://www.google.com/pagead/ https://maps.googleapis.com/ https://*.googlesyndication.com/ https://*.hotjar.com https://*.hotjar.io/ https://api.kameleoon.com https://na-data.kameleoon.io https://na-data.kameleoon.eu https://px.ads.linkedin.com/ https://cdn.linkedin.oribi.io https://*.livechatinc.com https://bam.nr-data.net https://*.api.osano.com/ https://connect.punchout2go.com https://d3peztlk7w3332.cloudfront.net *.searchspring.io *.searchspring.net https://s.yimg.com https://geo-ip.js wss://*.hotjar.com https://aorta.clickagy.com https://vc.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net cdnjs.cloudflare.com www.googletagmanager.com www.google-analytics.com pagead2.googlesyndication.com www.googleadservices.com www.gstatic.com securepubads.g.doubleclick.net use.typekit.net www.youtube.com s.ytimg.com js.hsforms.net www.googletagservices.com www.google.com ep2.adtrafficquality.google tpc.googlesyndication.com; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com use.typekit.net p.typekit.net; font-src 'self' data: fonts.gstatic.com cdn.jsdelivr.net cdnjs.cloudflare.com use.typekit.net; img-src 'self' data: *; media-src 'self' https://video.aapg.org blob: data:; connect-src 'self' * https://video.aapg.org; frame-src *; object-src 'none'; base-uri 'self'; form-action *; frame-ancestors *; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com 'self' 'self' data: https://*.tawk.to data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' https://*.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://www.googletagmanager.com/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' https://consentcdn.cookiebot.com 'self' 'unsafe-inline'; img-src cdn.zitmaxx.nl https://pim.zitmaxx.nl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com 'self' data: https: http: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://cdn.ablyft.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://www.google.com https://www.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.googletagmanager.com https://www.googleoptimize.com https://*.tawk.to https://secure.adnxs.com https://*.expivi.net d5yoctgpv4cpx.cloudfront.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://sst.zitmaxx.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' https://*.tawk.to https://*.expivi.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src https://pim.zitmaxx.nl dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' https://*.google-analytics.com wss://*.tawk.to rkkck31tec.execute-api.eu-central-1.amazonaws.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src *.spiraxsarco.com *.onetrust.com *.onetrust.io *.google-analytics.com *.hotjar.com *.hotjar.io *.clarity.ms wss://*.hotjar.com 'self' px.ads.linkedin.com google.com analytics.google.com region1.analytics.google.com www.google-analytics.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com ad.doubleclick.net stats.g.doubleclick.net 680-ryi-639.mktoresp.com forms.hubspot.com forms.hsforms.com cdn.linkedin.oribi.io hummingbirdwebsocket-nld2.cloud.adobe.io adservice.google.com translate.googleapis.com googleads.g.doubleclick.net www.google.com www.google.co.uk www.google.ae www.google.by www.google.com.gh www.google.com.mm www.google.ga www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bs www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.hu www.google.co.id www.google.co.il www.google.co.im www.google.co.in www.google.co.je www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.nf www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.uz www.google.com.vc www.google.com.vn www.google.cn www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.gg www.google.gl www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mn www.google.ms www.google.mu www.google.mw www.google.net www.google.nl www.google.no www.google.nr www.google.nu www.google.pl www.google.pn www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sm www.google.sn www.google.tm www.google.tn www.google.to www.google.tp www.google.tt www.google.tv www.google.uz www.google.vg www.google.vu www.google.ws www.google.co.zw www.google.dz/ads/ga-audiences www.google.al/ads/ga-audiences www.google.bf/ads/ga-audiences ttps://www.google.by/ads/ga-audiences www.google.cm/ads/ga-audiences www.google.co.ao/ads/ga-audiences ttps://www.google.co.mz/ads/ga-audiences www.google.co.tz/ads/ga-audiences www.google.com.bn/ads/ga-audiences ttps://www.google.com.gh/ads/ga-audiences www.google.com.kh/ads/ga-audiences www.google.com.lb/ads/ga-audiences ttps://www.google.com.mm/ads/ga-audiences www.google.com.ng/ads/ga-audiences www.google.com.pg/ads/ga-audiences ttps://www.google.dz/ads/ga-audiences www.google.ge/ads/ga-audiences www.google.iq/ads/ga-audiences www.google.sr/ads/ga-audiences 680-ryi-639.mktoutil.com wss://lo.msg.liveperson.net bat.bing.com js.calltrk.com mc.yandex.ru yandexmetrica.com:30103 ymetrica1.com; font-src *.onetrust.com 'self' fonts.gstatic.com use.typekit.net script.hotjar.com data:; img-src optimize.google.com www.google-analytics.com www.googletagmanager.com 'self' data: *; manifest-src 'self'; script-src *.onetrust.com *.scr.kaspersky-labs.com www.googleanalytics.com www.googleoptimize.com optimize.google.com static.ads-twitter.com 'self' 'nonce-ZTMzMTlmNTItZjdhMi00MjVmLTlmN2YtNzczYTg5OGVkNTIw' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'sha256-NiPpcuG5iPK1KPR3YIEEEz98KT0W7243V6u7FeP7hdE=' 'sha256-gRuNVLzs+xy+3p6+I1CnZb8pDmnXUWSlO9ejbnSR/lQ=' 'sha256-ibqfaR/CmFL3wQZAxIuZ0V4RMm9txqHSln46Z5WyeVA=' 'sha256-30EB3olZggJZ3OT2ahL22VzuYSIEPTzmMb+L3StxKgI=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-qbWCytLP5JMsZSG1DsvruBVK5O5otEfzrwtrYklbihw=' 'sha256-bkXrlHTrWu78qnQooXw+JqlG1rZijbuVZIkNBzTfagM=' 'sha256-vbs/XR7vkC12NXdDH8FEaUASiJdg/16cqF/0T3ze1ks=' 'sha256-4nxBwvGtrokGNkqD2OxOt8Y07P7caJHk00sGwjNYF5I=' 'sha256-/Fu0G2rh4wmpTYIDt4lb/x5WJp6zusqpavun8dZ8Yns=' 'sha256-yqVa7ver8F3o3KAsmdt2r10wQlIPCHuaBhkxEMbFQKE=' 'sha256-pZ/qdkaCfUhJbPDW6dxGk6IT/oRRR/mlpXeonIs9iew=' 'sha256-t2dxu6v8zWLBnuT0wS9gbS8+6dWSZKwyh8Oc1O+KFKM=' 'sha256-nOEqrdYQbjOqHNv8REn7NbgmgfgpHFGAMJeDad9+6Cc=' 'sha256-i9Hqrp5R5xqtEYAfxGINmtDPcds/LnLceINVGS0StZg=' 'sha256-5E/6sj96qbSHixz46qooKeWA+LIjK6XzdMgxXJYGMCo=' 'sha256-ZjDDDO/TrMCju3UiIns3DMC7cnl6jp0zh9NKm11JAyY=' 'sha256-pJrmX8BIQNU7+D+cF3F3p3Z/mHxe83gyTZAzRGq+YBE=' solutions.spiraxsarco.com ssl.google-analytics.com connect.facebook.net www.facebook.net www.google-analytics.com www.googletagmanager.com www.gstatic.com www.youtube.com platform.twitter.com cdn.syndication.twimg.com www.google.com accdn.lpsnmedia.net googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsforms.net js.hsleadflows.net lo.v.liveperson.net lpcdn.lpsnmedia.net lptag.liveperson.net munchkin.marketo.net script.hotjar.com snap.licdn.com static.hotjar.com www.googleadservices.com www3.spiraxsarco.com cdn.calltrk.com pi.pardot.com bat.bing.com js.calltrk.com; style-src-elem *.onetrust.com 'self' solutions.spiraxsarco.com fonts.googleapis.com p.typekit.net use.typekit.net platform.twitter.com ton.twimg.com assets.calendly.com optimize.google.com www.googletagmanager.com 'unsafe-inline'; frame-src *.spiraxsarco.com *.doubleclick.net optimize.google.com vars.hotjar.com *.liveperson.net lpcdn.lpsnmedia.net www.traceparts.com traceparts-cache.s3.eu-west-1.amazonaws.com www.googletagmanager.com www.facebook.com www.google.com www.youtube.com m.youtube.com share.hsforms.com platform.twitter.com syndication.twitter.com player.vimeo.com calendly.com spiraxsarco.octadesk.com www.buzzsprout.com go.pardot.com www.linkedin.com; media-src 'self' *.spiraxsarco.com lpcdn.lpsnmedia.net; form-action 'self' resources.spiraxsarco.com; style-src-attr 'unsafe-inline'; object-src 'none'; base-uri 'self'; report-uri https://steam.report-uri.com/r/d/csp/enforce 1 default-src 'self' *.nscc.ca; img-src 'self' *.nscc.ca *.gstatic.com *.fontawesome.com *.google.ca *.google.com www.google-analytics.com app.careerbeacon.com s3.amazonaws.com syndication.twitter.com www.facebook.com *.monsido.com data: www.googletagmanager.com maps.googleapis.com https://ad.doubleclick.net https://px.ads.linkedin.com/ https://www.linkedin.com/px/ https://i.ytimg.com/vi_webp/ https://syndicatedsearch.goog https://ep1.adtrafficquality.google; font-src 'self' *.nscc.ca *.fontawesome.com *.googleapis.com *.gstatic.com cdn.kendostatic.com data:; style-src 'self' *.nscc.ca *.fontawesome.com *.googleapis.com *.google.com app.simplycast.ca widget.alongside.com cdn.kendostatic.com kendo.cdn.telerik.com tags.srv.stackadapt.com www.googletagmanager.com static-assets-ca.libanswers.com https://kendo.cdn.telerik.com 'unsafe-inline'; script-src 'self' *.nscc.ca *.google.com *.googleapis.com *.gstatic.com https://googleads.g.doubleclick.net *.fontawesome.com *.google-analytics.com *.googletagmanager.com app.simplycast.ca *.youtube.com widget.alongside.com platform.twitter.com lgapi-ca.libapps.com https://ep2.adtrafficquality.google islpronto.islonline.net ca.libraryh3lp.com api3-ca.libcal.com cdn.kendostatic.com *.monsido.com *.crazyegg.com connect.facebook.net tags.srv.stackadapt.com js.adsrvr.org blob: static-assets-ca.libanswers.com https://jsonip.com https://server402.islonline.net/live/islpronto https://code.jquery.com https://unpkg.com https://cdn.kendostatic.com/2023.3.1010/js/* https://kendo.cdn.telerik.com https://qvdt3feo.com/events.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://analytics.tiktok.com/i18n/pixel/events.js https://analytics.tiktok.com/i18n/pixel/static/ 'unsafe-inline'; connect-src 'self' *.nscc.ca www.google-analytics.com https://www.google.com https://ad.doubleclick.net csp.withgoogle.com ka-p.fontawesome.com kit.fontawesome.com api3-ca.libcal.com *.crazyegg.com tags.srv.stackadapt.com *.monsido.com analytics.google.com stats.g.doubleclick.net maps.googleapis.com https://px.ads.linkedin.com/ https://px.ads.linkedin.com/wa/ https://analytics.tiktok.com/api/v2/pixel https://analytics.tiktok.com/api/v2/pixel/act https://ep1.adtrafficquality.google; frame-src 'self' *.youtube.com *.google.com https://www.googletagmanager.com syndication.twitter.com platform.twitter.com ca.libraryh3lp.com *.fls.doubleclick.net insight.adsrvr.org cckc.airtime.pro www.facebook.com https://player.vimeo.com https://td.doubleclick.net https://app.simplycast.ca https://match.adsrvr.org/track/upb/* https://ep2.adtrafficquality.google; frame-ancestors 'self' *.nscc.ca:*; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://geowidget.easypack24.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://fonts.gstatic.com https://cdn.thulium.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://geowidget-app.inpost.pl/ https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com data.imoje.pl *.disqus.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://cmp.uniconsent.com https://www.google.pl https://www.facebook.com/ https://data.imoje.pl https://imgsct.cookiebot.com https://www.google.nl https://maps.gstatic.com/ *.clarity.ms *.clarity.com https://maps.googleapis.com https://c.bing.com blob: https://cdn.thulium.com https://e24files.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js paywall.imoje.pl sandbox.paywall.imoje.pl *.disqus.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrbox.com https://connect.facebook.net https://cmp.uniconsent.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://analytics.tiktok.com *.clarity.ms *.clarity.com https://unpkg.com https://cdn.thulium.com https://browser.sentry-cdn.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io cdn.jsdelivr.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.easypack24.net *.inpost.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrcdn.net https://fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net https://cdn.thulium.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://region1.analytics.google.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com/ https://player.vimeo.com *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrbox.com https://www.sentry.macopedia-dev.pl https://cmp.uniconsent.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://www.google.pl https://www.google.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://pagead2.googlesyndication.com https://js-agent.newrelic.com https://googleads.g.doubleclick.net https://analytics.tiktok.com *.clarity.ms *.clarity.com https://cdn.thulium.com wss://chat-proxy-service.thulium.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' litium.revolutionrace.com fbcdn.revolutionrace.com wss://fbcdn.revolutionrace.com *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.com *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com platform.twitter.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com googlesyndication.com *.googlesyndication.com google.com *.google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com *.newrelic.com nr-data.net *.nr-data.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com googlesyndication.com *.googlesyndication.com google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com *.newrelic.com nr-data.net *.nr-data.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net twitter.com platform.twitter.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.maxmind.com www.xtento.com cdn.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googlesyndication.com *.googlesyndication.com google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com nr-data.net stripe.com *.stripe.com *.wetanz.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.mmapiws.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com *.googletagmanager.com googlesyndication.com *.googlesyndication.com google.com *.google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.userway.org *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.userway.org *.automann.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.pixriot.com *.storeimaging.com data: 'self' 'unsafe-inline'; style-src *.adobe.com fonts.googleapis.com *.userway.org *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src *.clarity.ms dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.userway.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://get.geojs.io *.avada.io webservices.purolator.com devwebservices.purolator.com *.pixriot.com *.storeimaging.com 'self' 'unsafe-inline'; frame-src automann-scanner.global.ssl.fastly.net fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com *.livechatinc.com *.userway.org www.googletagmanager.com webservices.purolator.com devwebservices.purolator.com 'self' 'unsafe-inline'; script-src *.clarity.ms *.cloudfront.net assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net/ https://maps.googleapis.com browser-update.org *.userway.org *.livechatinc.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.truefitcorp.com *.fontawesome.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.googletagmanager.com js.stripe.com tralut.iclothing.com m.stripe.network b.stripecdn.com pay.google.com newassets.hcaptcha.com https://plumrocket.com *.truefitcorp.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.feedoptimise.com cdn.feedoptimise.com www.google.ie fonts.gstatic.com *.truefitcorp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://shareasale.com/sale.cfm cdn1.stamped.io stamped.io maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.channelize.io www.feedoptimise.com cdn.feedoptimise.com newassets.hcaptcha.com cdn.jsdelivr.net cdn.segmentify.com cdn1.stamped.io cdn.sgmntfy.com js.stripe.com cdnjs.cloudflare.com gtm.trlution.com analytics.tiktok.com https://cdn.segmentify.com/ https://cdn.truefit.com/ *.truefitcorp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.dwin1.com stamped.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com cdn.segmentify.com cdn1.stamped.io cdnjs.cloudflare.com www.googletagmanager.com *.truefitcorp.com https://static.klaviyo.com *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com assets.braintreegateway.com stamped.io *.stripe.network *.stripecdn.com *.amazon.com use.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.channelize.io www.google.com region1.analytics.google.com gandalf-eu.segmentify.com tralut.iclothing.com js.stripe.com api.stripe.com merchant-ui-api.stripe.com r.stripe.com m.stripe.com pay.google.com api.hcaptcha.com *.truefitcorp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com cdn1.stamped.io stamped.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src www.google.ie www.google.com analytics.tiktok.com www.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' *.helsana.ch fonts.googleapis.com translate.googleapis.com;style-src-elem 'self' 'unsafe-inline' *.helsana.ch fonts.googleapis.com translate.googleapis.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net interaktiv.contilla.de use.fontawesome.com;img-src 'self' data: *.helsana.ch *.pinterest.com s0.2mdn.net bat.bing.com www.facebook.com connect.facebook.net cm.everesttech.net dpm.demdex.net apple-resources.s3.amazonaws.com *.applemediaservices.com *.googlesyndication.com *.gstatic.com maps.googleapis.com www.googleadservices.com www.googletagmanager.com www.google-analytics.com *.doubleclick.net t.co *.linkedin.com *.google.com *.google.ch *.google.de *.google.fr *.google.li *.google.it *.google.ad *.google.ae *.google.al *.google.at *.google.ba *.google.be *.google.bf *.google.bg *.google.bj *.google.ca *.google.cd *.google.cg *.google.ci *.google.cl *.google.cm *.google.cn *.google.cz *.google.dk *.google.dz *.google.ee *.google.es *.google.fi *.google.ga *.google.gr *.google.ht *.google.hr *.google.hu *.google.ie *.google.iq *.google.jo *.google.lk *.google.lt *.google.lu *.google.lv *.google.me *.google.mg *.google.ml *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.si *.google.sk *.google.sn *.google.tg *.google.tn *.google.tt *.google.vg *.google.co.ao *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ma *.google.co.th *.google.co.uk *.google.co.za *.google.com.af *.google.com.ar *.google.com.au *.google.com.bh *.google.com.bo *.google.com.br *.google.com.co *.google.com.cy *.google.com.ec *.google.com.eg *.google.com.gh *.google.com.hk *.google.com.kh *.google.com.lb *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ni *.google.com.pe *.google.com.pk *.google.com.py *.google.com.sa *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.vn userlike-cdn-operators.s3-eu-west-1.amazonaws.com d3upe020n1uosc.cloudfront.net www.userlike.com userlike-store-media-files.s3.amazonaws.com i.ytimg.com interaktiv.contilla.de;font-src 'self' data: *.gstatic.com d3dc1lgancj6l0.cloudfront.net use.fontawesome.com *.helsana.ch;media-src 'self' data: blob: *.helsana.ch d3dc1lgancj6l0.cloudfront.net userlike-store-media-files.s3.amazonaws.com www.userlike.com;object-src 'none';worker-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.helsana.ch cdn.cookielaw.org static.ads-twitter.com analytics.twitter.com *.pinterest.com s.pinimg.com *.gstatic.com api.microsofttranslator.com bat.bing.com www.google.ch www.google.com www.google.de www.google.fr *.googlesyndication.com *.doubleclick.net www.googletagservices.com consentcdn.cookiebot.com analytics.twitter.com snap.licdn.com www.googleadservices.com www.google-analytics.com connect.facebook.net consent.cookiebot.com cdn.tt.omtrdc.net maps.googleapis.com www.googletagmanager.com assets.adobedtm.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net;script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: *.helsana.ch cdn.cookielaw.org static.ads-twitter.com snap.licdn.com analytics.twitter.com *.pinterest.com s.pinimg.com *.gstatic.com api.microsofttranslator.com bat.bing.com www.google.ch www.google.com www.google.de www.google.fr *.googlesyndication.com *.doubleclick.net www.googletagservices.com consentcdn.cookiebot.com www.googleadservices.com www.google-analytics.com connect.facebook.net consent.cookiebot.com cdn.tt.omtrdc.net maps.googleapis.com www.googletagmanager.com cdnjs.cloudflare.com assets.adobedtm.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net interaktiv.contilla.de analytics.tiktok.com;connect-src 'self' wss://*.helsana.ch *.helsana.ch maps.googleapis.com privacyportal-eu.onetrust.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com *.cookielaw.org api.sitesearch360.com *.ads-twitter.com *.linkedin.com *.pinterest.com api.openweathermap.org www.facebook.com www.bing.com bat.bing.com *.googlesyndication.com *.google.com *.doubleclick.net www.google-analytics.com tt.omtrdc.net dpm.demdex.net wss://umd.userlike.com umd.userlike.com api.userlike.com d3upe020n1uosc.cloudfront.net www.userlike.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu interaktiv.contilla.de;frame-src 'self' *.helsana.ch *.pinterest.ch *.pinterest.com *.google.com *.googlesyndication.com bid.g.doubleclick.net consentcdn.cookiebot.com www.youtube.com fls.doubleclick.net assets.adobedtm.com www.facebook.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net www.youtube.com player.vimeo.com *.undpartner.digital;frame-ancestors 'self' *.helsana.ch;report-uri https://helsana.report-uri.com/r/d/csp/wizard;report-to wizard; 1 script-src 'self' https://cdn.suitableshop.net https://bat.bing.com https://d5yoctgpv4cpx.cloudfront.net https://tggng.suitableshop.com 'unsafe-inline' ; 1 default-src https://d13qcyivyon4xf.cloudfront.net https://*.recollect.net https://www2.elpasotexas.gov https://*.piktochart.com https://elpasotx.citysourced.com https://alive5.com https://*.pure.cloud https://td.doubleclick.net https://*.userway.org https://*.powerbigov.us 'self' data:; script-src https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com 'sha256-EFV8pmp/wh+U6PZamj4KQ0q8X4ZQK18tF7skjashMC0=' 'sha256-d470bixwKmL9bRvqX+/YcGn63ywAfKoybYPkM5Uytpg=' 'sha256-CWheM/qrotfHL9rkBHCUQoQJ26R59qBT9Y6zmdWMo4I=' https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net 'sha256-GZcyqV0YX2St+S/OQczTu1wNNg/O+RTwzw2JTTta3P0=' https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com 'sha256-EhQpu6NNucte8YbnJ4xqNQ3ZEr6lZr9OylXRM08U23w=' 'sha256-6LGMzcnzg+kSHN9kCfnGBfyFkTD5ralHy4kgX9bEKac=' https://*.userway.org https://alive5.com 'sha256-Ktbr5+uWaq/tdIzd+uSnzMynWRb8C1GgwNmidruZnl4=' https://*.elpasotexas.gov 'sha256-N/ojzpn0NH2iToAWgtz7/qj3VTBrzGc5Kq/wcHmeC9g=' 'sha256-32mhgs7qr26DY71TSkr2GH6b4cN1O1vqJZeD8VqK09E=' 'sha256-ogBzyJChbukfa3Sy3FmuFfBT4HErpPzLDY1mDXuD08I=' https://*.clarity.ms 'sha256-1Mtgu0LP1N914Q7hPqP5oj1G7I5kj4eUK9emzGHCGU0=' https://*.youtube.com 'sha256-ISZqhiP5lsW/o4tzWAjiLcmBSgn4ci50MHTdBAJeJzo=' https://*.googleadservices.com 'unsafe-eval' https://*.facebook.net https://*.adtrafficquality.google https://*.cloudflareinsights.com 'self' 'report-sample' 'nonce-7f436dee0898b6c8'; style-src https://*.googleapis.com https://*.fontawesome.com https://*.google.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://alive5.com https://*.userway.org https://*.gstatic.com 'self' 'unsafe-inline' 'report-sample'; connect-src https://*.fontawesome.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com https://googletagmanager.com https://*.acsbapp.com https://webmessaging.usw2.pure.cloud https://*.pure.cloud https://*.userway.org https://*.alive5.com https://alive5.com https://*.clarity.ms https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.googleapis.com 'self' data:; font-src https://*.gstatic.com https://*.fontawesome.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://acsbapp.com https://*.userway.org 'self' data:; img-src https://*.google.com https://*.googleapis.com https://*.google-analytics.com https://*.jsdelivr.net https://*.fastly.net https://*.recollect.net https://*.piktochart.com https://*.userway.org https://*.alive5.com https://*.clarity.ms https://*.gstatic.com https://*.googletagmanager.com https://*.bing.com https://tip411.com https://*.tip411.com https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.google.com.mx 'self' data:; Strict-Transport-Security max-age=31536000; frame-src https://syndicatedsearch.goog https://www2.elpasotexas.gov https://alive5.com https://*.youtube.com https://*.powerbigov.us https://*.google.com https://*.adtrafficquality.google https://*.userway.org https://googletagmanager.com https://coepgis.map.arcgis.com https://*.googletagmanager.com https://tip411.com https://*.tip411.com 'self'; media-src https://*.gstatic.com 'self'; script-src-elem https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com 'sha256-EFV8pmp/wh+U6PZamj4KQ0q8X4ZQK18tF7skjashMC0=' 'sha256-d470bixwKmL9bRvqX+/YcGn63ywAfKoybYPkM5Uytpg=' 'sha256-CWheM/qrotfHL9rkBHCUQoQJ26R59qBT9Y6zmdWMo4I=' https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net 'sha256-GZcyqV0YX2St+S/OQczTu1wNNg/O+RTwzw2JTTta3P0=' https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com 'sha256-EhQpu6NNucte8YbnJ4xqNQ3ZEr6lZr9OylXRM08U23w=' 'sha256-6LGMzcnzg+kSHN9kCfnGBfyFkTD5ralHy4kgX9bEKac=' https://*.userway.org https://alive5.com 'sha256-Ktbr5+uWaq/tdIzd+uSnzMynWRb8C1GgwNmidruZnl4=' https://*.elpasotexas.gov 'sha256-N/ojzpn0NH2iToAWgtz7/qj3VTBrzGc5Kq/wcHmeC9g=' 'sha256-32mhgs7qr26DY71TSkr2GH6b4cN1O1vqJZeD8VqK09E=' 'sha256-ogBzyJChbukfa3Sy3FmuFfBT4HErpPzLDY1mDXuD08I=' https://*.clarity.ms 'sha256-1Mtgu0LP1N914Q7hPqP5oj1G7I5kj4eUK9emzGHCGU0=' https://*.youtube.com 'sha256-ISZqhiP5lsW/o4tzWAjiLcmBSgn4ci50MHTdBAJeJzo=' https://*.googleadservices.com 'unsafe-eval' https://*.facebook.net https://*.adtrafficquality.google 'sha256-RlhVC6WGhVrcsY0hAmbU/YhaSUz2iA2q1f16/7A6jLU=' 'self' 'report-sample' 'nonce-7f436dee0898b6c8'; frame-ancestors 'self'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.pl/api/csp-report; report-to csp-endpoint 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.xtento.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.xtento.com cdn.xtento.com *.trackedlink.net *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com maps.gstatic.com *.feefo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net www.xtento.com cdn.xtento.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com assets.shipperhq.com *.trustpilot.com *.feefo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com assets.shipperhq.com *.trustpilot.com *.feefo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com rms.shipperhq.com https://rms.shipperhq.com wss://rms.shipperhq.com ovs.shipperhq.com *.feefo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com www.google.com.ua ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com gzuvq.sanitairkamer.nl https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site gzuvq.sanitairkamer.nl https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 font-src *.squarecdn.com *.googleapis.com https://www.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.bootstrapcdn.com *.stamped.io foursixty.com *.zipmoney.com.au font.static.useinsider.com *.pinterest.com *.cloudfront.net *.livechatinc.com *.zip.co https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com dhv2ziothpgrr.cloudfront.net https://cdn.livechatinc.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com https://plumrocket.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com *.cash.app https://www.google.com *.doubleclick.net www.facebook.com *.affirm.com *.affirm.ca https://plumrocket.com *.livechatinc.com *.paypal.com *.kaptcha.com beaconlighting.api.useinsider.com *.addthis.com *.addthisedge.com *.pinterest.com *.cloudfront.net *.scarabresearch.com www.xtento.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * photos.pixlee.co https://accounts.google.com *.yotpo.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com https://www.affirm.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.cash.app *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.affirm.com *.affirm.ca *.beaconlighting.com.au *.trackjs.com *.cdninstagram.com *.zipmoney.com.au *.magentosite.cloud *.stamped.io *.scarabresearch.com *.paypal.com *.api.useinsider.com *.pinterest.com *.cloudfront.net *.livechatinc.com blob: *.zip.co www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pixlee.com *.yotpo.com dhv2ziothpgrr.cloudfront.net t.zip.co static.zipmoney.com.au static.zip.co https://web1.acsbapp.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app polyfill.io *.googleapis.com https://www.gstatic.com https://www.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.affirm.com *.affirm.ca s7.addthis.com iguana2.com *.stamped.io *.zipmoney.com.au foursixty.com *.trackjs.com *.bootstrapcdn.com *.livechatinc.com beaconlighting.api.useinsider.com *.addthis.com *.addthisedge.com z.moatads.com *.api.useinsider.com *.pinterest.com *.cloudfront.net *.scarabresearch.com *.zip.co www.xtento.com cdn.xtento.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.plugins.emarsys.net connect.facebook.net graph.facebook.com business.facebook.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pxlecdn.com *.pixlee.com https://accounts.google.com https://cdn.searchspring.net/intellisuggest/is.min.js *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net static.zipmoney.com.au static.zip.co zip.co https://cdn1.affirm.com/js/v2/affirm.js https://acsbapp.com/ https://trx-cdn.zip.co/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ *.squarecdn.com *.cash.app fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com *.bootstrapcdn.com *.stamped.io foursixty.com *.api.useinsider.com *.pinterest.com *.cloudfront.net *.livechatinc.com *.scarabresearch.com *.zip.co downloads.mailchimp.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://accounts.google.com https://www.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.affirm.com *.affirm.ca ekr.zdassets.com/ *.bootstrapcdn.com *.zipmoney.com.au foursixty.com *.foursixty.com *.labs.au.edge.zip.co *.trackjs.com stamped.io *.livechatinc.com *.api.useinsider.com carrier.useinsider.com *.doubleclick.net *.pinterest.com *.cloudfront.net *.scarabresearch.com *.zip.co *.eservice.emarsys.net connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com https://inbound-analytics.pixlee.com https://accounts.google.com https://beacon.searchspring.io/beacon *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://cdn.acsbapp.com/ https://trx.zip.co/z/t https://www.affirm.com/ https://tracker.affirm.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.affirm.com/ 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.posthog.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://cdn.segment.com; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://*.posthog.com https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://video-messages.intercomcdn.com https://messenger-apps.intercom.io https://messenger-apps.eu.intercom.io https://messenger-apps.au.intercom.io https://*.intercom-attachments.com https://static.intercomassets.eu https://static.au.intercomassets.com https://www.google-analytics.com https://www.googletagmanager.com https://*.google.com https://*.doubleclick.net https://www.google.com.tr; font-src 'self' https://js.intercomcdn.com https://fonts.intercomcdn.com; connect-src 'self' https://*.posthog.com https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://cdn.segment.com https://api.segment.io https://vitals.vercel-insights.com https://*.doubleclick.net https://analytics.google.com https://stats.g.doubleclick.net; object-src 'none'; base-uri 'self'; form-action 'self' https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io; frame-src https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://*.doubleclick.net; worker-src 'self' https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; media-src https://js.intercomcdn.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com; frame-ancestors 'none'; manifest-src 'self' https://upstash.com; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net api.mundipagg.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page api.mundipagg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.mundipagg.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.wicked.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.wicked.com join.gammasecure.com; script-src 'self' *.wicked.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.wicked.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 object-src 'none'; script-src-attr 'self'; script-src-elem 'self' https://analytics.clickdimensions.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 1 default-src 'self' wss: *.gravatar.com *.seeclickfix.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdn.embedly.com/widgets/platform.js cdnjs.cloudflare.com static.cloudflareinsights.com *.fontawesome.com *.countyofsb.org * 'self'; style-src * 'self' 'unsafe-inline'; img-src * 'self' data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.googletagmanager.com *.seeclickfix.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdn.embedly.com/widgets/platform.js cdnjs.cloudflare.com static.cloudflareinsights.com *.fontawesome.com * 'self' about: 'unsafe-inline' 'unsafe-eval' data:; worker-src * 'self' data: blob: 'unsafe-eval' 'unsafe-inline'; frame-src * 'self'; media-src 'self' blob: *; font-src * 'self' data: *.fontawesome.com * 'self' data:; upgrade-insecure-requests; form-action 'self'; frame-ancestors 'self';report-uri /contentsecuritypolicy/report 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-22536317cfd046198494169740cdd9bf' https://www.viewmychart.com 'self';img-src https://* 'self' blob: data:;style-src https://www.viewmychart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 frame-ancestors 'none'; default-src https://www.czater.pl 'self'; script-src https://www.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://googleads.g.doubleclick.net https://*.czater.pl 'self' 'unsafe-inline'; img-src https://static.sprintdatacenter.pl https://rapiddc.pl https://www.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://*.google.com https://*.google.pl https://googleads.g.doubleclick.net https://www.googleadservices.com data: 'self'; style-src https://www.czater.pl 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com; form-action 'self'; connect-src https://*.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://*.google.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com wss://s2.czater.pl 1 default-src 'self'; script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.google.com *.googleadservices.com *.googletagmanager.com *.jquery.com *.facebook.net *.cookiebot.com *.doubleclick.net *.privacymanager.io *.disqus.com *.twitter.com *.trustpilot.com *.clarity.ms *.gstatic.com *.youtube.com youtube.com; style-src 'self' data: 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://a.disquscdn.com https://c.clarity.ms https://c.disquscdn.com https://clm.nektony.com https://googleads.g.doubleclick.net https://imgsct.cookiebot.com https://nektony.com https://ps.w.org https://referrer.disqus.com https://secure.gravatar.com https://ssl.gstatic.com https://syndication.twitter.com https://www.google.com https://www.google.com.ua https://www.googletagmanager.com *.facebook.com *.bing.com; font-src 'self' data: https://fonts.gstatic.com https://nektony.com; connect-src *; media-src 'self'; frame-src 'self' https://consentcdn.cookiebot.com https://disqus.com https://store.payproglobal.com https://td.doubleclick.net https://widget.trustpilot.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.youtube-nocookie.com https://www.youtube.com; worker-src 'self'; upgrade-insecure-requests; report-uri https://nektony.com/csp-report-mode1.php; manifest-src 'self'; 1 default-src 'self' http: https: data: blob: 'unsafe-inline' 'unsafe-eval' 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://*.silkandsnow.com https://analytics.tiktok.com https://www.dwin1.com https://www.googletagmanager.com https://connect.facebook.net https://bat.bing.com https://static.hotjar.com https://utt.impactcdn.com https://c5.adalyser.com https://js.adsrvr.org https://googleads.g.doubleclick.net https://script.hotjar.com https://lantern.roeyecdn.com https://fast.ssqt.io https://s.pinimg.com https://diffuser-cdn.app-us1.com https://widget.wickedreports.com https://prism.app-us1.com https://*.chat.getzowie.com https://trackcmp.net https://www.redditstatic.com https://script.hotjar.com https://utt.impactcdn.com https://*.signifyd.com https://*.affirm.com https://maps.googleapis.com https://static.kyc.red https://www.gstatic.com https://c.amazon-adsystem.com https://www.paypal.com https://h64.online-metrix.net https://trustspot.io https://s3.amazonaws.com https://app.ravecapture.com https://ct.pinterest.com https://www.paypalobjects.com https://www.google.com https://www.gstatic.com https://maps.google.com; style-src 'self' 'unsafe-inline' https://trustspot.io https://app.ravecapture.com https://s3.amazonaws.com https://www.google.com https://cdn.honey.io https://app.ravecapture.com https://fonts.googleapis.com ; report-to csp-endpoint; report-uri https://www.silkandsnow.com/csp_report.php; 1 default-src 'none'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requests; block-all-mixed-content; script-src 'self' 'unsafe-inline' https://*.seniorly.com https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://*.googleapis.com https://cdn.segment.com https://cdn.builder.io https://cdn.accessibly.app https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://*.seniorly.com https://*.facebook.com https://*.linkedin.com https://*.gstatic.com https://*.googleapis.com https://www.google-analytics.com https://*.doubleclick.net https://i.ytimg.com https://d1qiigpe5txw4q.cloudfront.net https://cdn.builder.io; font-src 'self' data: https://*.seniorly.com https://fonts.gstatic.com; connect-src 'self' https://*.seniorly.com https://api.segment.io https://cdn-settings.segment.com https://www.google-analytics.com https://region1.google-analytics.com https://*.doubleclick.net https://*.googleapis.com https://dash.accessibly.app https://alt-tags.accessibly.app; frame-src 'self' https://www.youtube.com https://player.vimeo.com my.matterport.com https://dash.accessibly.app; media-src 'self' https://*.seniorly.com; form-action 'self' https://*.seniorly.com; worker-src 'self' blob:; manifest-src 'self'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.tr/api/csp-report; report-to csp-endpoint 1 default-src 'self' *.itrustcapital.com; script-src *.itrustcapital.com https://www.googletagmanager.com 'unsafe-inline' 'self' ; style-src 'self' *.itrustcapital.com use.fontawesome.com 'unsafe-inline' https://www.google-analytics.com; font-src 'self' *.itrustcapital.com use.fontawesome.com 'unsafe-inline'; connect-src sdk.iad-05.braze.com api.amplitude.com dataschemasprodstorage.blob.core.windows.net *.alloy.co https://rum.browser-intake-us3-datadoghq.com https://www.googletagmanager.com 'self' *.itrustcapital.com https://www.google-analytics.com www.google-analytics.com https://stats.g.doubleclick.net wss:; img-src 'self' *.itrustcapital.com https://www.google-analytics.com www.google-analytics.com https://stats.g.doubleclick.net blob:; object-src 'none'; frame-src https://www.googletagmanager.com; report-uri https://csp-report.browser-intake-us3-datadoghq.com/api/v2/logs?dd-api-key=pubb464f8903d11bb4c37d5cbb555ed196a&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=csp-report; report-to default 1 script-src ‘self’; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'nonce-RandomString123456' https://metaswitch.com https://*.metaswitch.com 'strict-dynamic' 'nonce-ArB7fOTPI1ES7hvEjULsSg=='; style-src 'self' 'nonce-RandomString123456' https://metaswitch.com https://*.metaswitch.com; img-src 'self' data: https://metaswitch.com https://*.metaswitch.com; font-src 'self' https://metaswitch.com https://*.metaswitch.com; connect-src 'self' https://metaswitch.com https://*.metaswitch.com; frame-src 'self' https://metaswitch.com https://*.metaswitch.com; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri https://770a769bea45352cd46f7e284097b330.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.tiktok.com tiktok.com maxcdn.bootstrapcdn.com *.userway.org *.minnetonkamoccasin.com *.espssl.com *.slant.co sc-static.net *.afterpay.com *.migaku.com *.qantas.com *.rakuten.com *.fontshare.com *.cloudflare.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: https://plumrocket.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com landofcoder.com *.tiktok.com https://*.online-metrix.net https://imgs.signifyd.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.tiktok.com flagpedia.net https://imgs.signifyd.com https://*.online-metrix.net *.cluepixel.com www.google.co.id www.google.com.qa *.googletagmanager.com www.google.com.co www.google.com.bh www.google.com.tw *.espssl.com www.google.tn *.online-metrix.net www.google.com.sg *.facebook.com *.listrakbi.com www.google.co.in *.yotpo.com *.cookielaw.org www.google.gg *.ggpht.com www.google.by www.google.lk www.google.gl www.google.at www.google.ad www.google.vu www.google.al www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.cm www.google.mw www.google.com.pa www.google.ae www.google.com.pg google.com www.google.pl www.google.com.fj www.google.com.kw www.google.bt www.google.com.np www.google.pt www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu *.afterpay.com www.google.jo *.bing.com *.criteo.net www.google.co.cr www.google.it www.google.co.zm www.google.ch www.google.com.et www.google.ee www.google.com.py *.facebook.net www.google.hu *.google.com www.google.com.pr www.google.iq www.google.ca www.google.li www.google.gy www.google.md www.google.co.jp www.google.sr *.criteo.com www.google.am www.google.de www.google.im www.google.es *.pinterest.com www.google.lt www.google.is www.google.com.bo www.google.lu www.google.bi www.google.as www.google.com.do www.google.co.zw *.google-analytics.com www.google.co.ma www.google.fi www.google.sk www.google.dm www.google.co.ls *.6g2d4pn2yqc42.ent.platform.sh www.google.co.ug www.google.com.ph www.google.co.tz www.google.ga www.google.si www.google.tg www.google.mn www.google.lv *.adsrvr.org *.doubleclick.net www.google.com.ec www.google.ba *.rlcdn.com www.google.me www.google.com.kh *.curalate.com www.google.com.sa www.google.bj www.google.dj www.google.co.th www.google.dz www.google.ci www.google.com.vn www.google.ps www.google.com.hk www.google.fm www.google.co.vi www.google.com.ua www.google.com.ar www.google.com.gh www.google.rw www.google.co.uz www.google.com.my www.google.fr www.google.com.ng *.typekit.net www.google.com.cy www.google.com.om www.google.cv www.google.tt www.google.nl www.google.ge www.google.com.lb *.snapchat.com www.google.ro www.google.no www.google.com.sv www.google.cd www.google.co.ve www.google.com.tr www.google.dk www.google.com.uy www.google.se www.google.mg www.google.hn www.google.ru www.google.com.bn www.google.ne www.google.tl www.google.ml www.google.co.ao *.userway.org www.google.com.cu www.google.com.na www.google.sn www.google.com.mm www.google.cl www.google.com.vc www.google.com.ni *.googlesyndication.com www.google.co.za www.google.com.ag *.adnxs.com www.google.sc www.google.gm www.google.co.nz www.google.com.bz www.google.co.uk www.google.com.eg www.google.com.gt www.google.la www.google.com.br www.google.com.jm www.google.cg www.google.com.bd www.google.tm www.google.ht *.minnetonkamoccasin.com www.google.kz *.rubiconproject.com www.google.je www.google.com.au www.google.bs www.google.com.mt www.google.co.ck www.google.mk www.google.kg www.google.so www.google.cz www.google.bf www.google.co.kr www.google.cn www.google.mv www.google.co.bw www.google.com.af www.google.co.mz www.google.com.tj www.google.com.sl www.google.az www.google.com.ly www.google.bg www.google.com.pk www.google.com.gi www.google.gr data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.sharethis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.klevu.com *.ksearchnet.com landofcoder.com *.tiktok.com maps.googleapis.com *.googletagmanager.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://js.klevu.com *.cluepixel.com *.listrakbi.com *.nimblecapture.com *.criteo.com *.snapchat.com *.yotpo.com *.cookielaw.org *.listrak.com *.google.com *.cloudflare.com *.mczbf.com *.criteo.net *.userway.org *.online-metrix.net *.minnetonkamoccasin.com sc-static.net *.pinterest.com *.jsdelivr.net *.facebook.net *.afterpay.com *.pinimg.com *.googlesyndication.com *.doubleclick.net *.google-analytics.com localhost *.adobedtm.com *.bing.com *.curalate.com d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com *.cash.app *.sharethis.com unsafe-inline assets.braintreegateway.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.tiktok.com tiktok.com maxcdn.bootstrapcdn.com *.gstatic.com https://statsjs.klevu.com https://js.klevu.com *.yotpo.com *.listrakbi.com *.userway.org *.cloudflare.com *.afterpay.com *.typekit.net *.minnetonkamoccasin.com *.googletagmanager.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.curalate.com *.bing.com *.googleapis.com *.userway.org *.gstatic.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src *.tiktok.com tiktok.com *.minnetonkamoccasin.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.sharethis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com landofcoder.com *.tiktok.com www.gstatic.com maps.googleapis.com https://imgs.signifyd.com *.cluepixel.com *.userway.org *.criteo.com *.onetrust.com *.listrakbi.com www.google.com.vn www.google.de *.google-analytics.com www.google.co.kr *.pinimg.com *.curalate.com *.googlesyndication.com *.doubleclick.net *.nimblecapture.com *.cookielaw.org *.bing.com *.criteo.net www.google.ca *.espssl.com *.pinterest.com *.snapchat.com localhost www.google.com.pk *.rlcdn.com *.facebook.com sc-static.net *.luckyorange.net www.google.co.jp *.listrak.com *.adsrvr.org *.mczbf.com *.samsung.com *.minnetonkamoccasin.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.afterpay.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; base-uri *.criteo.com *.doubleclick.net *.onetrust.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://2d02ba86-f55d-42ab-9b05-087fb2c163a0.sansec.watch/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com landofcoder.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net st.softgamings.com cdn.livechatinc.com www.google.com api.livechatinc.com www.gstatic.com snap.licdn.com bat.bing.com connect.facebook.net mc.yandex.ru www.clarity.ms scripts.clarity.ms consent.cookiebot.com *.softgamings.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com st.softgamings.com *.softgamings.com; font-src 'self' fonts.gstatic.com st.softgamings.com data: *.softgamings.com; img-src 'self' data: https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.com https://googleads.g.doubleclick.net st.softgamings.com www.facebook.com www.google.ru px.ads.linkedin.com cdn.files-text.com secure.gravatar.com agstatic.com bat.bing.com www.googletagmanager.com *.softgamings.com images.dmca.com; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://www.google.com https://px.ads.linkedin.com wss://mc.yandex.ru https://z.clarity.ms https://v.clarity.ms https://mc.yandex.ru *.softgamings.com https://hooks.slack.com https://bat.bing.com https://stats.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googletagmanager.com https://googleads.g.doubleclick.net; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://cdn.livechatinc.com https://secure.livechatinc.com https://mc.yandex.ru https://www.clarity.ms *.softgamings.com https://www.youtube.com/ https://consentcdn.cookiebot.com https://bid.g.doubleclick.net; media-src 'self' https://video.softgamings.com *.softgamings.com 1 base-uri 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' assets.talentio.com cdn.ravenjs.com widget.intercom.io js.intercomcdn.com www.google-analytics.com analytics.google.com translate.googleapis.com www.googletagmanager.com ; img-src 'self' data: blob: https: http:; child-src 'self' blob:; form-action 'self' www.facebook.com id.talentio.com api-iam.intercom.io ; font-src 'self' data: assets.talentio.com fonts.gstatic.com use.fontawesome.com use.typekit.net fonts.intercomcdn.com ; frame-ancestors 'self'; frame-src 'self' blob: youtube.com *.youtube.com speakerdeck.com *.speakerdeck.com slideshare.net *.slideshare.net twitter.com *.twitter.com note.com *.note.com google.com *.google.com google.co.jp *.google.co.jp facebook.com *.facebook.com backcheck.jp *.backcheck.jp s3.ap-northeast-1.amazonaws.com intercom-sheets.com; manifest-src 'none'; object-src 'self' blob: s3.ap-northeast-1.amazonaws.com; style-src 'self' 'unsafe-inline' assets.talentio.com fonts.googleapis.com use.typekit.net p.typekit.net use.fontawesome.com translate.googleapis.com ; media-src 'none'; worker-src 'self' blob:; connect-src 'self' assets.talentio.com *.sentry.io sentry.io api-iam.intercom.io uploads.intercomcdn.com wss://nexus-websocket-a.intercom.io www.google-analytics.com analytics.google.com s3.ap-northeast-1.amazonaws.com translate.googleapis.com 1 default-src 'self' https://*.alltuu.live https://alltuu-frontend-log-tracking.cn-hangzhou.log.aliyuncs.com https://www.gstatic.com https://alltuu-help-video.oss-cn-shanghai.aliyuncs.com https://open.work.weixin.qq.com https://cdn.jsdelivr.net https://cdnjs.cloundflare.com https://gw.alipayobjects.com https://lf1-cdn-tos.bytegoofy.com https://alltuu.cc https://s9.cnzz.com https://zz.bdstatic.com https://v1.cnzz.com https://g.alicdn.com https://mp.weixin.qq.com https://res.wx.qq.com https://open.weixin.qq.com https://turing.captcha.qcloud.com https://sp0.baidu.com/ https://turing.captcha.gtimg.com https://at.alicdn.com data: blob: https://*.alltuu.ren https://*.alltuu.com 'unsafe-eval' 'unsafe-inline'; report-uri https://csp-page.alltuu.com;connect-src 'self' https://*.alltuu.live https://mcs.snssdk.com https://alltuu-storage.oss-accelerate.aliyuncs.com https://alltuu-prsoon-private.oss-cn-hangzhou.aliyuncs.com https://aegis.qq.com https://mp.weixin.qq.com/ https://alltuu-msg.cn-hangzhou.log.aliyuncs.com/ https://alltuu-flashapp.cn-hangzhou.log.aliyuncs.com https://ai-platform-data-analysis.cn-hangzhou.log.aliyuncs.com https://ai-data-analysis.cn-hangzhou.log.aliyuncs.com https://*.alltuu.com wss://*.alltuu.com https://alltuu-frontend-log.cn-hangzhou.log.aliyuncs.com https://videocloud.cn-hangzhou.log.aliyuncs.com https://alltuu-storage.oss-cn-hangzhou.aliyuncs.com https://alltuu-frontend-log-tracking.cn-hangzhou.log.aliyuncs.com data: blob:;frame-src 'self' https://* blob: data: ; 1 default-src *; script-src *; object-src *; style-src *; img-src *; media-src *; frame-src *; font-src *; connect-src * 1 default-src 'self' https://assets.step.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.sentry-cdn.com https://*.sentry.io https://www.google-analytics.com https://www.googletagmanager.com https://consent.cookiebot.com https://*.cookiebot.com https://connect.facebook.net https://*.iesnare.com https://js.stripe.com https://maps.googleapis.com https://cdn.plaid.com https://assets.step.com https://*.clarity.ms https://c.bing.com https://cdn.mgln.ai https://cdn.segment.com https://googleads.g.doubleclick.net https://websdk.appsflyer.com https://boards.greenhouse.io https://www.recaptcha.net https://www.gstatic.com https://pagead2.googlesyndication.com https://sc-static.net https://*.snapchat.com https://*.tiktok.com; script-src-elem 'self' 'unsafe-inline' https://js.sentry-cdn.com https://*.sentry.io https://www.google-analytics.com https://www.googletagmanager.com https://consent.cookiebot.com https://*.cookiebot.com https://connect.facebook.net https://*.iesnare.com https://js.stripe.com https://maps.googleapis.com https://cdn.plaid.com https://assets.step.com https://*.clarity.ms https://c.bing.com https://cdn.mgln.ai https://cdn.segment.com https://googleads.g.doubleclick.net https://websdk.appsflyer.com https://boards.greenhouse.io https://www.recaptcha.net https://www.gstatic.com https://pagead2.googlesyndication.com https://sc-static.net https://*.snapchat.com https://*.tiktok.com https://static.userback.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://assets.step.com https://www.googletagmanager.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://assets.step.com https://www.googletagmanager.com; img-src 'self' data: https://images.ctfassets.net https://assets.step.com https://step.com https://pps.step.com https://logos.step.com https://www.google-analytics.com https://www.facebook.com https://connect.facebook.net https://*.cookiebot.com https://maps.gstatic.com https://googleads.g.doubleclick.net https://www.google.com https://www.googleadservices.com https://mgln.ai https://us.mgln.ai https://pixel.tapad.com https://*.clarity.ms https://c.bing.com https://www.googletagmanager.com https://fonts.gstatic.com https://images.contentful.com https://*.onelink.me https://impressions.onelink.me https://pagead2.googlesyndication.com https://*.snapchat.com https://*.tiktok.com https://*.tiktokw.us; font-src 'self' data: https://fonts.gstatic.com https://assets.step.com https://*.cdn.office.net https://use.typekit.net; media-src 'self' https://videos.ctfassets.net; connect-src 'self' https://*.sentry.io https://www.google-analytics.com https://*.step.com https://*.dev.step.com https://*.iesnare.com wss://*.iesnare.com https://*.cookiebot.com https://*.braze.com https://*.mixpanel.com https://assets.step.com https://cdn.segment.com https://graphql.contentful.com https://www.google.com https://mgln.ai https://api.segment.io https://www.googleadservices.com https://analytics.google.com https://*.clarity.ms https://c.bing.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.facebook.com https://*.conversionsapigateway.com https://*.appsflyer.com https://*.onelink.me https://www.gstatic.com https://region1.analytics.google.com https://www.googletagmanager.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://*.run.app https://*.snapchat.com https://*.tiktok.com https://*.tiktokw.us; worker-src 'self' blob:; frame-src 'self' https://*.cookiebot.com https://js.stripe.com https://hooks.stripe.com https://cdn.plaid.com https://www.youtube-nocookie.com https://*.withpersona.com https://www.googletagmanager.com https://job-boards.greenhouse.io https://www.recaptcha.net https://*.snapchat.com https://*.53.com https://*.typeform.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://assets.step.com *.step.com https://app.contentful.com; upgrade-insecure-requests; report-uri /api/csp-report; report-to csp-endpoint; 1 default-src 'none';script-src 'nonce-cbbf5adb-7f46-4b87-9811-e9282b204cdc' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.be https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.be/eum-collector/report/csp-report; 1 connect-src https://api.segment.io https://cdn.segment.com https://stats.g.doubleclick.net https://www.google-analytics.com https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com 'self' https://api.ipstack.com https://geoip-js.com https://*.launchdarkly.com https://*.aptrinsic.com https://sentry.pub.jamf.build https://api.services.jamfnow.com https://services-api.services.jamfnow.com https://jamfsw.okta.com/.well-known/openid-configuration https://jamfsw.okta.com/oauth2/v1/token; img-src https://*.google-analytics.com https://ssl.google-analytics.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.ao https://www.google.co.bw https://www.google.co.ck https://www.google.co.cr https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.ke https://www.google.co.kr https://www.google.co.ls https://www.google.co.ma https://www.google.co.mz https://www.google.co.nz https://www.google.co.th https://www.google.co.tz https://www.google.co.ug https://www.google.co.uk https://www.google.co.uz https://www.google.co.ve https://www.google.co.vi https://www.google.co.za https://www.google.co.zm https://www.google.co.zw https://www.google.com https://www.google.com.af https://www.google.com.ag https://www.google.com.ai https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.bh https://www.google.com.bn https://www.google.com.bo https://www.google.com.br https://www.google.com.bz https://www.google.com.co https://www.google.com.cu https://www.google.com.cy https://www.google.com.do https://www.google.com.ec https://www.google.com.eg https://www.google.com.et https://www.google.com.fj https://www.google.com.gh https://www.google.com.gi https://www.google.com.gt https://www.google.com.hk https://www.google.com.hz https://www.google.com.jm https://www.google.com.kh https://www.google.com.kw https://www.google.com.lb https://www.google.com.ly https://www.google.com.mm https://www.google.com.mt https://www.google.com.mx https://www.google.com.my https://www.google.com.na https://www.google.com.ng https://www.google.com.ni https://www.google.com.np https://www.google.com.om https://www.google.com.pa https://www.google.com.pe https://www.google.com.pg https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.py https://www.google.com.qa https://www.google.com.sa https://www.google.com.sb https://www.google.com.sg https://www.google.com.sl https://www.google.com.sv https://www.google.com.tj https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vc https://www.google.com.vn https://www.google.cv https://www.google.cz https://www.google.de https://www.google.dj https://www.google.dk https://www.google.dm https://www.google.dz https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fm https://www.google.fr https://www.google.ga https://www.google.ge https://www.google.gg https://www.google.gl https://www.google.gm https://www.google.gr https://www.google.gy https://www.google.hn https://www.google.hr https://www.google.ht https://www.google.hu https://www.google.ie https://www.google.im https://www.google.iq https://www.google.is https://www.google.it https://www.google.je https://www.google.jo https://www.google.kg https://www.google.ki https://www.google.kz https://www.google.la https://www.google.li https://www.google.lk https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.md https://www.google.me https://www.google.mg https://www.google.mk https://www.google.ml https://www.google.mn https://www.google.ms https://www.google.mu https://www.google.mv https://www.google.mw https://www.google.ne https://www.google.nl https://www.google.no https://www.google.nr https://www.google.nu https://www.google.pk https://www.google.pl https://www.google.pn https://www.google.ps https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.rw https://www.google.sc https://www.google.se https://www.google.sh https://www.google.si https://www.google.sk https://www.google.sm https://www.google.sn https://www.google.so https://www.google.sr https://www.google.st https://www.google.td https://www.google.tg https://www.google.tl https://www.google.tm https://www.google.tn https://www.google.to https://www.google.tt https://www.google.vg https://www.google.vu https://www.google.ws blob: data: https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://video-messages.intercomcdn.com https://messenger-apps.intercom.io https://messenger-apps.eu.intercom.io https://messenger-apps.au.intercom.io https://*.intercom-attachments-1.com https://*.intercom-attachments.eu https://*.au.intercom-attachments.com https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://static.intercomassets.eu https://static.au.intercomassets.com https://appinstallers-packages.services.jamfcloud.com 'self' https://*.aptrinsic.com https://*.jamfnow.com https://*.services.jamfnow.com https://jamfnow-customapps.s3.amazonaws.com; script-src https://cdn.segment.com https://www.google-analytics.com https://www.googletagmanager.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com 'self' https://geoip-js.com/js/apis/geoip2/v2.1/geoip2.js https://*.salesforceliveagent.com https://*.aptrinsic.com https://www.youtube.com; child-src https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; font-src https://js.intercomcdn.com https://fonts.intercomcdn.com 'self' https://fonts.gstatic.com; form-action https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io; media-src https://js.intercomcdn.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com; style-src 'unsafe-inline' 'self' https://*.aptrinsic.com https://fonts.googleapis.com; base-uri 'self'; default-src 'self' https:; report-uri https://sentry.pub.jamf.build/api/266/security/?sentry_key=69c661b6de484d0285748b2206db8711&sentry_environment=production; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cakebox.com fonts.googleapis.com cdn.jsdelivr.net *.klaviyo.com cdnjs.cloudflare.com *.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * consentcdn.cookiebot.com consentcdn.cookiebot.eu *.trustpilot.com *.weltpixel.com *.adobedtm.com *.vimeo.com widget.trustpilot.com vars.hotjar.com *.doubleclick.net app.involve.me ssl.kaptcha.com *.onetrust.com js.ryft.com embedded.ryftpay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.cookiebot.com imgsct.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.adobedtm.com s.ytimg.com services.postcodeanywhere.co.uk bat.bing.com *.facebook.com *.google.co.in lantern.roeye.com static-tracking.klaviyo.com *.cloudfront.net *.cakebox.com *.cookiepro.com *.googletagmanager.com *.wepowerconnections.com *.zenaps.com ad.doubleclick.net cm.g.doubleclick.net *.google.com *.google.com.vn *.google.co.uk *.onetrust.com *.adroll.com x.bidswitch.net ml314.com pixel.tapad.com dsum-sec.casalemedia.com dsync.rlcdn.com pixel.rubiconproject.com *.openx.net sync.outbrain.com idsync.rlcdn.com *.pubmatic.com sync.taboola.com ib.adnxs.com eb2.3lift.com match.adsrvr.org *.stickyadstv.com *.sitescout.com *.springserve.com *.ipredictive.com *.turn.com *.mdhv.io dsp.360yield.com www.eggfreecake.co.uk *.usercentrics.eu https://www.ryft.com embedded.ryftpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.cookiebot.com consent.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.disqus.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com *.adobedtm.com *.cardinalcommerce.com unpkg.com cdn.jsdelivr.net *.cloudflare.com *.braintreegateway.com *.livechatinc.com *.pcapredict.com storage.googleapis.com maps.google.com services.postcodeanywhere.co.uk bat.bing.com *.hotjar.com s.pinimg.com c3.adalyser.com connect.facebook.net rum-static.pingdom.net ct.pinterest.com lantern.roeyecdn.com *.soakandsleep.com cdn.bronto.com dynamic.criteo.com *.apptrian.com *.dwin1.com paperplaneslive.com *.cloudfront.net *.cookiepro.com *.googletagmanager.com stats.g.doubleclick.net *.amplitude.com *.sovendus.com *.zenaps.com www.google.com *.involve.me *.onetrust.com *.adroll.com www.subconvertize.com js-agent.newrelic.com *.googlesyndication.com *.config-security.com *.triplewhale.com *.cookiebot.eu *.ryftpay.com https://embedded.ryftpay.com/v2/ryft.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.trustpilot.com tagmanager.google.com static-tracking.klaviyo.com *.soakandsleep.com services.postcodeanywhere.co.uk www.google.com cdnjs.cloudflare.com *.typekit.net *.cdn-apple.com *.googleapis.com *.gstatic.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.google-analytics.com *.adobedtm.com *.adobe.com *.braintreegateway.com *.gstatic.com *.telemetry-dev.adobe.io services.postcodeanywhere.co.uk ct.pinterest.com rum-collector-2.pingdom.net api.livechatinc.com paperplaneslive.com *.cloudfront.net *.trustpilot.com api2.amplitude.com *.googletagmanager.com *.onetrust.com invitejs.trustpilot.com *.sovendus.com *.cookiepro.com *.bing.com www.google.com stats.g.doubleclick.net *.involve.me *.adroll.com bam.nr-data.net *.hotjar.* wss://ws.hotjar.com content.hotjar.io *.config-security.com *.ryftpay.com https://embedded.ryftpay.com/v2/ryft.min.js.map embedded.ryftpay.com smp-paymentservices.apple.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com *.fontawesome.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.akamaihd.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com *.facebook.com *.google.com *.list-manage.com *.americanexpress.com *.cartasi.it *.nexi.it 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com *.sharethis.com *.iubenda.com *.livechatinc.com *.online-metrix.net *.tracead.com tracead.com *.signifyd.com img.signifyd.com *.addthis.com *.jrs5.com pubxtag1.com amc.demdex.net *.facebook.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.hotjar.com *.cartasi.it *.nexi.it 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com *.googleapis.com *.feedaty.com *.payments-amazon.com *.linksynergy.com *.nxtck.com *.mediaforge.com *.jrs5.com *.dc-storm.com *.rd.linksynergy.com *.ra.linksynergy.com *.facebook.com *.google.it *.google.com *.signifyd.com *.e.aa.online-metrix.net smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.demdex.net *.ytimg.com *.facebook.net *.akamaihd.net *.photorank.me *.zoorate.com *.nomination.com *.bing.com *.livehelp.it *.doubleclick.net *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.sharethis.com *.googleapis.com *.gstatic.com *.feedaty.com *.iubenda.com *.googletagmanager.com *.chimpstatic.com chimpstatic.com *.doofinder.com *.signifyd.com *.livechatinc.com *.facebook.net *.rmtag.com *.tracead.com tracead.com *.addthis.com *.amazon.com *.amazonaws.com *.googleadservices.com *.google-analytics.com *.jsdelivr.net *.moatads.com *.addthisedge.com *.pinterest.com smct.co *.smct.co smct.io *.smct.io *.akamaihd.net *.zoorate.com *.cloudflare.com *.bing.com *.hotjar.com *.doubleclick.net *.livehelp.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com *.feedaty.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.jsdelivr.net *.gstatic.com *.zoorate.com *.akamaihd.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com *.sharethis.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.feedaty.com *.iubenda.com *.doofinder.com *.g.doubleclick.net *.doubleclick.net *.signifyd.com *.signifyd.com:11103 *.signifyd.com:11103/onload https://bt.signifyd.com:11103 https://bt.signifyd.com:11103/onload bt.signifyd.com *.facebook.com *.livechatinc.com *.addthis.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.akamaihd.net *.hotjar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.dk *.betano.dk betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=L5Px9Aq1APhvjV8EoZ2ZmYPOriiz4Jjg4OqbSp5fisE-1765936643-1.0.1.1-yNkxcExpjo26R_JkVUX5dmkWHk6YBf2gpM0bmEr4Pe6yByo15WVmVRoSj6d.Bi89fqbj.uOYlaCF3TmfiJQOjaO5H8KbbXP51f6lKmX9Tuv0Wg9IuGWy2lVv40CWblKTJjE7lK7D8S45HgxZd0339zi9CoTbB.X2s9vwTcLEO6p0QbNiflVpWQi2pgOlQoct5gv.ZLAcQ__K6UcjOYhafg; report-to cf-cukwpaxgkmirkusy 1 default-src 'self' bcbolt-uktv.akamaized.net uktv.brightcovecdn.com *.brightcove.net; script-src 'self' 'nonce-MmUwNzE3YmUtN2QwNS00ODEwLWE0YzUtNjgxNzViNDEwNDVl' 'sha256-PGOSsZtvDKqZ+myXb5DE395jRSa3aOFSIEbmfmin1yc=' 'sha256-f1m9UGZ2ljCQQQ1wMdfXdMrRTWacFIRtepSeAClkohI=' *.2cnt.net *.adalyser.com *.boltdns.net uktv.brightcovecdn.com *.brightcove.com *.brightcove.net cdn-ukwest.onetrust.com client.rum.us-east-1.amazonaws.com *.doubleclick.net *.fwmrm.net connect.facebook.net js.appboycdn.com *.googletagmanager.com mp.simplestream.com tag.aticdn.net tags.tiqcdn.com uktvltd.hb.omtrdc.net vjs.zencdn.net; style-src 'self' 'unsafe-inline' use.fontawesome.com; img-src 'self' data: https: *.2cnt.net *.adalyser.com *.ati-host.net *.brightcove.com uktv.brightcovecdn.com *.fwmrm.net *.doubleclick.net appboy-images.com braze-images.com c4-ads-creative-prod.s3.eu-west-1.amazonaws.com cdn-ukwest.onetrust.com cdn.braze.eu https://uktv-res.cloudinary.com uktv-static.s3.eu-west-1.amazonaws.com; font-src 'self' data: https: https://use.typekit.net appboy-images.com braze-images.com cdn.braze.eu use.fontawesome.com; connect-src 'self' *.2cnt.net *.ati-host.net bcbolt-uktv.akamaized.net uktv.brightcovecdn.com *.boltdns.net *.brightcove.com *.brightcove.net dataplane.rum.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com sts.eu-west-1.amazonaws.com *.doubleclick.net *.google.com www.googleadservices.com *.fwmrm.net *.litix.io *.mppglobal.com *.onetrust.com sdk.fra-02.braze.eu *.sentry.io *.uktvapi.co.uk *.uktv.co.uk; frame-src 'self' *.doubleclick.net; worker-src 'self' blob: https:; media-src 'self' blob: https: *.boltdns.net uktv.brightcovecdn.com; report-uri https://o59029.ingest.us.sentry.io/api/4510029393428480/security/?sentry_key=8a2537262166e290fbc1a00cd2a20fa3; report-to csp-reporting-endpoint; 1 default-src 'self'; base-uri 'none'; connect-src https: wss:; font-src https: data:; form-action 'self' *.bauhaus.cz *.facebook.com *.mail-komplet.cz; frame-ancestors 'self'; frame-src https:; img-src https: data:; object-src 'none'; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; report-uri https://kosik.bauhaus.cz/csp_report; report-to bauhaus-csp; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com https://js.playground.klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.script.crazyegg.com *.empathy.co *.cdn.aplazame.com api.aplazame.com *.maps.googleapis.com *.cdn.jsdelivr.net https://www.google-analytics.com https://cdnjs.cloudflare.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; script-src-elem 'unsafe-inline' *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.aplazame.com *.empathy.co cdn.jsdelivr.net script.crazyegg.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; style-src 'self' 'unsafe-inline' *.klarnacdn.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; img-src 'self' data: https://www.joseluisjoyerias.com https://www.google-analytics.com *.clarity.ms c.bing.com *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com *.klarnacdn.net; font-src 'self' *.klarna.com *.klarnacdn.net *.klarnaevt.com https://fonts.gstatic.com cdn.aplazame.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; connect-src 'self' *.hotjar.com *.hotjar.io *.empathy.co *.klarna.com *.klarnacdn.net *.klarnaevt.com https://js.playground.klarna.com https://www.google-analytics.com google.com script.crazyegg.com maps.googleapis.com api.aplazame.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com capig.stape.pro; frame-src 'self' *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com *.klarna.com; child-src 'self'; form-action 'self'; base-uri 'self'; report-uri /csp-report-endpoint 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://www.clarity.ms/ https://scripts.clarity.ms/ *.wp.com https://fast.wistia.com/ https://analytics.wpmucdn.com/ https://cdn.jotfor.ms/ https://cdnjs.cloudflare.com/ https://sidebar.bugherd.com/ https://maps.googleapis.com/ https://www.google.com/ https://www.gstatic.com/ https://payfacto.bamboohr.com/ https://www.bugherd.com/ https://cdn-cookieyes.com/ https://hb.wpmucdn.com/maitredpos.com/ https://www.googletagmanager.com/ https://stats.wpmucdn.com/ https://cdn.callrail.com/ https://js.callrail.com/ https://j.6sc.co/ https://www.gstatic.com/ https://static.hotjar.com/ https://script.hotjar.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://use.fontawesome.com/ https://ams.wpml.org/ https://fonts.bunny.net/ https://hb.wpmucdn.com/maitredpos.com/ https://fonts.googleapis.com/; object-src 'none'; base-uri 'self'; connect-src 'self' https://y.clarity.ms/collect https://analytics3.wpmudev.com/ https://sessions.bugsnag.com/ wss://ws-mt1.pusher.com/ https://sockjs.pusher.com/ https://epsilon.6sense.com/ https://cdn.ampproject.org/ https://ams.wpml.org/ https://maps.google.com/ https://maps.googleapis.com/ https://app.callrail.com/ https://www.google-analytics.com/ https://metrics.hotjar.io/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://distillery.wistia.com/ https://payfacto.bamboohr.com/ https://stats.g.doubleclick.net/ https://c.6sc.co/ https://analytics.google.com/ https://ipv6.6sc.co/ https://js.callrail.com/ https://cdn-cookieyes.com/ https://log.cookieyes.com/ https://stats1.wpmudev.com/; font-src 'self' data: https://use.fontawesome.com/ https://fonts.bunny.net/ https://fonts.gstatic.com/; frame-src 'self' about: blob: data: https://form.jotform.com/ https://maps.google.com/ https://www.google.com/ https://sidebar.bugherd.com/ https://www.google.com/ https://forms.zohopublic.com; img-src 'self' data: https://www.googletagmanager.com/ https://c.clarity.ms/c.gif https://c.bing.com/ *.smushcdn.com *.wp.com https://d2iiunr5ws5ch1.cloudfront.net/ https://ps.w.org/ https://secure.gravatar.com/ https://wpmudev.com/ https://i0.wp.com/ https://www.google.ca/ https://resources.bamboohr.com/ https://b.6sc.co/ https://cdn-cookieyes.com/ https://b3550802.smushcdn.com/; manifest-src 'self'; media-src 'self'; worker-src blob:; frame-ancestors 'self' https://google.com/; 1 script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdn.cupio.ro https://ss.cupio.ro https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://*.googleapis.com https://www.googleoptimize.com https://www.googleadservices.com https://www.google.ro https://www.google.com https://connect.facebook.net https://*.facebook.com https://*.pinterest.com https://ct.pinterest.com https://s.pinimg.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.snapchat.com https://sc-static.net https://bat.bing.com https://bat.bing.net https://event.2performant.com https://attr-2p.com https://*.klarna.com https://*.klarnacdn.net https://*.revolut.com https://aqurate.ai https://cdn.channelize.io https://trusted.ro https://js.stripe.com cupio.ro https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.gstatic.com https://*.clarity.ms https://*.tiktok.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com https://*.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.googleapis.com *.zopim.com *.zopim.io *.klarnacdn.net https://fonts.bunny.net 'self' data: https://cdn.cupio.ro https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://fonts.cdnfonts.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.twitter.com *.cupio.ro https://www.facebook.com https://payflowlink.paypal.com https://sandbox.payu.ro/ https://secure.payu.ro/ https://cdn.channelize.io https://*.revolut.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.gstatic.com https://*.clarity.ms https://*.tiktok.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.facebook.com https://connect.facebook.net graph.facebook.com business.facebook.com *.innoship.ro https://plumrocket.com https://*.revolut.com *.cdn-apple.com *.google.com/ pay.google.com https://*.gstatic.com https://accounts.google.com *.weltpixel.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com https://*.klarna.com 'self' *.cupio.ro https://ss.cupio.ro https://*.pinterest.com https://s.pinimg.com *.vimeo.com https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://event.2performant.com https://js.stripe.com https://hooks.stripe.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org https://www.magezon.com *.revolut.com *.google.com *.cdn-apple.com https://*.google.com pay.google.com https://*.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com https://www.google-analytics.com *.twitter.com *.twimg.com https://*.vimeocdn.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.co.in *.mastercard.com https://*.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com 'self' *.cupio.ro https://cdn.cupio.ro https://www.googleadservices.com https://trusted.ro https://*.ytimg.com https://*.pinterest.com https://s.pinimg.com https://*.klarnacdn.net https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://bat.bing.net https://event.2performant.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://www.google.com https://www.google.ro https://redchamps.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://connect.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.channelize.io https://*.revolut.com *.google.com/ pay.google.com https://*.gstatic.com https://accounts.google.com https://www.gstatic.com *.cloudflare.com *.twitter.com https://www.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://bat.bing.com *.zopim.com *.zdassets.com https://*.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdn.cupio.ro https://ss.cupio.ro https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.googleapis.com https://www.googleoptimize.com https://www.googleadservices.com https://www.google.ro https://*.facebook.com https://*.pinterest.com https://ct.pinterest.com https://s.pinimg.com https://*.cookieyes.com https://*.snapchat.com https://sc-static.net https://bat.bing.net https://event.2performant.com https://attr-2p.com https://*.klarnacdn.net https://aqurate.ai https://cdn.channelize.io https://trusted.ro cupio.ro https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://www.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://accounts.google.com https://www.gstatic.com *.cloudflare.com https://fonts.googleapis.com *.twitter.com *.twimg.com https://*.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.klarnacdn.net https://fonts.bunny.net 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.cupio.ro https://*.klarnacdn.net https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.channelize.io https://*.revolut.com *.cdn-apple.com pay.google.com https://*.gstatic.com https://accounts.google.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://www.google-analytics.com https://stats.g.doubleclick.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://*.klarna.com https://get.geojs.io *.avada.io 'self' *.cupio.ro https://ss.cupio.ro https://*.googleapis.com https://www.googletagmanager.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://bat.bing.net https://event.2performant.com https://attr-2p.com https://directory.cookieyes.com https://*.klarnacdn.net https://*.klarnaservices.com https://tracker.aqurate.ai https://analytics-ipv6.tiktokw.us https://cdn.channelize.io https://api.stripe.com https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://ct.pinterest.com *.stripe.com klarna.com *.klarna.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojavirus.com.br *.lojavirus.com.br wake-components.fbitsstatic.net lojavirus.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com googleadservices.com yapay.com.br googlesyndication.com cloudflare.com cnt.my clearsale.com.br zdassets.com ebit.com.br traycheckout.com.br doubleclick.net ecommercemail.com.br online-metrix.net hertzen.com k-analytix.com zendesk.com citydsp.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.yapay.com.br *.googleadservices.com *.cloudflare.com *.googlesyndication.com *.cnt.my *.ebit.com.br *.traycheckout.com.br *.clearsale.com.br *.zdassets.com *.k-analytix.com *.hertzen.com *.doubleclick.net *.ecommercemail.com.br *.online-metrix.net *.zendesk.com *.citydsp.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.btg360.com.br dzpxyxks1bfmb.cloudfront.net *.zopim.com *.gstatic.com *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.yourviews.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net *.ucarecdn.com *.uploadcare.com *.yviews.com.br *.lojaconfiavel.com *.lightwidget.com bt-wake-connector.com.br lojavirus.fbitsstatic.net *.fbitsstatic.net *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io gstatic.com *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojavirus.com.br lojavirus.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.versapay.com *.paynup.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.twitter.com *.paynup.com *.versapay.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.certcapture.com *.amazonaws.com *.google.co.in t.co.in t.co *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.versapay.com *.paynup.com *.trackedlink.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com *.ads-twitter.com *.pinimg.com *.qualtrics.com *.hotjar.com *.pinterest.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com *.datadoghq.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com webchat.dotdigital.com webchat.staging.dotdigital.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.pinterest.com *.googleapis.com *.qualtrics.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net wss://ws.hotjar.com *.google.co.in *.cloudflare.com *.twitter.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/magento_os/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.klarnacdn.net *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.klarna.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://cdn.ingrid.com/ https://js.klarna.com/ https://js.playground.kustom.co/ https://js.live.kustom.co/ https://td.doubleclick.net/ https://widget.imbox.io/ https://widget-launcher.imbox.io/ *.trustpilot.com *.yotpo.com *.ingrid.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.klarna.com/ https://js.playground.kustom.co/ https://js.live.kustom.co/ bat.bing.com bat.bing.net cdn-cookieyes.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com bat.bing.com bat.bing.net cdn-cookieyes.com *.trustpilot.com *.yotpo.com *.ingrid.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.klarnacdn.net *.trustpilot.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.klarna.com/ https://js.playground.kustom.co/ https://js.live.kustom.co/ region1.google-analytics.com region1.analytics.google.com pagead2.googlesyndication.com www.google.com/ccm/collect log.cookieyes.com cdn-cookieyes.com bat.bing.com bat.bing.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://26dd9fdb-d1ae-4de1-a1b1-9eeb5fbcd903.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com *.gstatic.com https://script.hotjar.com *.landbot.io cash-f.squarecdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es api.paycomet.com *.ogone.com *.v-psp.com https://www.facebook.com *.redsys.es * 'self' 'unsafe-inline'; frame-ancestors *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.adobe.com https://bid.g.doubleclick.net https://www.linkbux.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.dotdigital-pages.com *.dotdigital.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com api.paycomet.com *.doubleclick.net pay.google.com service.force.com hal9000.redintelligence.net https://pikolinrecommend.botslovers.com https://*.soreto.com https://ams.creativecdn.com/ https://www.facebook.com/ https://www.awin1.com/ *.redsys.es https://www.googletagmanager.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com *.trackedlink.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.gstatic.com *.adotmob.com *.facebook.com *.facebook.net *.google.com *.google.es *.googleapis.com *.omtrdc.net https://*.g.doubleclick.net/ *.doubleclick.net https://*.googletagmanager.com *.google-analytics.com *.analytics.google.com *.media-amazon.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://ade.googlesyndication.com https://lantern.roeyecdn.com https://lantern.roeye.com https://pikolinrecommend.botslovers.com https://*.tagmanager.google.com https://pikolin.botslovers.com https://cdn.botslovers.com https://t.teads.tv/ https://c.clarity.ms/ https://*.bing.com/ https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com https://rt.udmserve.net/ https://pixel.rubiconproject.com https://www.awin1.com/ https://eb2.3lift.com/ https://secure.adnxs.com/ https://ih.adscale.de/ https://sync.outbrain.com/ https://ssp-csync.smartadserver.com/ https://ads.stickyadstv.com https://ads.yieldmo.com/ https://api.soreto.com/ https://cdn.doofinder.com/ https://ib.adnxs.com/ eu1-doofinderuser.s3.amazonaws.com https://*.collect.igodigital.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com https://maps.googleapis.com *.gstatic.com *.zdassets.com js-agent.newrelic.com *.serving-sys.com *.facebook.net *.doubleclick.net *.zopim.com *.cstatic.weborama.fr https://cdn.cookielaw.org https://pikolin.botslovers.com.co https://pikolin.botslovers.com https://pikolinrecommend.botslovers.com https://cdn.landbot.io *.payments-amazon.com pay.google.com https://service.force.com https://cdn.doofinder.com *.clarity.ms *.hotjar.com https://www.dwin1.com https://www.wepowerconnections.com https://lantern.roeyecdn.com https://espadesa.my.salesforce.com/ https://*.googletagmanager.com https://*.tagmanager.google.com https://*.google-analytics.com https://www.googleadservices.com https://p.teads.tv/ https://*.soreto.com https://cdn.frizbit.com/ https://js.cookieless-data.com/ https://*.adform.net/ https://js.sddan.com/ https://tags.creativecdn.com/ https://*.bing.com https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://*.datnova.com/ https://static.lightning.force.com https://espadesa.secure.force.com https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/ https://d.la2-c1-cdg.salesforceliveagent.com/ *.redsys.es https://sslwidget.criteo.com/ https://dynamic.criteo.com/ https://*.collect.igodigital.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com https://assets.adobedtm.com https://510004498.collect.igodigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com/ *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com service.force.com *.clarity.ms https://cdn.doofinder.com https://*.googletagmanager.com https://*.tagmanager.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.frizbit.com/ https://espadesa.secure.force.com/ *.cash.app *.trustpilot.com 'self' 'unsafe-inline'; object-src *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.pikolin.com/es *.pikolin.com/pt pikolin.tt.omtrdc.net *.magentosite.cloud *.beds.es *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.serving-sys.com *.google-analytics.com *.analytics.analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.demdex.net *.paypal.com *.doubleclick.net https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://maps.googleapis.com https://google.com https://www.google.es https://www.google.com https://pagead2.googlesyndication.com pay.google.com https://payments-eu.amazon.com *.amazon.com eu1-layer.doofinder.com wss://eu1-layer.doofinder.com/ *.clarity.ms https://*.hotjar.io https://*.hotjar.com wss://*.hotjar.com https://pikolinrecommend.botslovers.com *.tt.omtrdc.net https://pikolin.botslovers.com https://cdn.botslovers.com/ https://www.facebook.com/ https://cm.teads.tv/ https://t.teads.tv/ https://www.wepowerconnections.com https://*.soreto.com https://*.frizbit.com/ https://ams.creativecdn.com/ https://the.sciencebehindecommerce.com/ https://geolocation.onetrust.com https://privacyportal.onetrust.com https://privacyportal-eu.onetrust.com https://*.bing.com/ https://espadesa.secure.force.com/ *.googleapis.com *.landbot.io * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com https://*.trustpilot.com/ 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es https://*.soreto.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; report-uri https://pikolin.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com maxcdn.bootstrapcdn.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com *.slant.co *.smassets.net *.cloudflare.com *.gstatic.com *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bugherd.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn account.fetchify.com *.mention-me.com vimeo.com *.termly.io *.evri.com *.facebook.com *.google.com *.trustpilot.com *.googletagmanager.com *.surveymonkey.com google.com *.vimeo.com *.doubleclick.net *.gnatta.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sweetanalytics.com *.brooktaverner.us *.ometria.com *.visualwebsiteoptimizer.com *.bing.com *.clarity.ms *.google.co.uk *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.gstatic.com *.googleapis.com *.convertexperiments.com www.google.com.cy www.google.co.id www.google.com.qa www.google.com.bh www.google.com.co *.googletagmanager.com www.google.com.tw *.brooktaverner.co.uk www.google.cv www.google.tn www.google.tt www.google.com.sg *.facebook.com brippo.s3.amazonaws.com www.google.nl www.google.co.in *.adroll.com d3k81ch9hvuctc.cloudfront.net www.google.gg www.google.ge www.google.by www.google.lk www.google.com.lb *.bing.net *.twitter.com t.co www.google.ad www.google.at www.google.vu www.google.al www.google.ro www.google.no www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.cd www.google.cm www.google.mw www.google.com.pa www.google.co.ve www.google.ae www.google.pl google.com *.vimeo.com www.google.com.tr www.google.com.kw www.google.dk www.google.com.uy www.google.com.np www.google.se www.google.pt www.google.mg www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn www.google.com.bn www.google.ru www.google.jo www.google.co.cr gnattawatchtower.blob.core.windows.net www.google.it www.google.co.zm www.google.com.et www.google.ch www.google.ee *.facebook.net www.google.hu www.google.co.ao *.omguk.com www.google.com.pr *.gstatic.com www.google.iq www.google.ca www.google.com.na www.google.li www.google.gy www.google.sn www.google.md www.google.com.mm www.google.co.jp www.google.am www.google.de www.google.cl www.google.im *.doubleclick.net www.google.es *.googlesyndication.com www.google.co.za www.google.com.ag www.google.lt www.google.is www.google.sc www.google.com.bo www.google.co.nz www.google.lu www.google.com.bz www.google.bi www.google.co.uk www.google.com.do www.google.co.zw www.google.com.eg www.google.com.gt www.google.co.ma www.google.com.br www.google.cg www.google.com.jm www.google.com.bd *.googleadservices.com www.google.fi *.smassets.net www.google.sk www.google.co.ug www.google.kz www.google.com.ph ebizmartsextensions.s3.amazonaws.com www.google.je www.google.co.tz www.google.com.au www.google.ga www.google.si www.google.tg www.google.mn www.google.bs www.google.lv www.google.com.mt www.google.com.ec www.google.ba www.google.mk www.google.me www.google.com.kh www.google.com.sa *.cloudflare.com *.adalyser.com www.google.so www.google.cz www.google.dj www.google.co.th www.google.co.kr www.google.dz www.google.mv www.google.com.vn www.google.com.hk www.google.sh www.google.co.bw www.google.com.ua www.google.co.mz www.google.com.ar www.google.com.gh www.google.com.sl mageside.com www.google.az www.google.com.ly www.google.bg www.google.co.uz www.google.com.my www.google.com.pk www.google.gr www.google.com.gi www.google.fr www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trustpilot.com *.glopal.com *.sweetanalytics.com *.ometria.com *.ads-twitter.com *.twitter.com *.googletagmanager.com *.visualwebsiteoptimizer.com *.zdassets.com *.bing.com *.clarity.ms *.adroll.com *.bugherd.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://maps.googleapis.com *.mention-me.com *.convert.com *.googleapis.com *.gstatic.com *.33across.com *.termly.io *.klaviyo.com *.getelevar.com *.webgains.io *.adalyser.com *.doubleclick.net *.omguk.com *.cloudflare.com *.brooktaverner.co.uk *.gnatta.com *.convertexperiments.com *.cloudflareinsights.com *.surveymonkey.com *.paypal.com *.evri.com brooktaverner.us *.facebook.net *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.glopal.com *.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.brooktaverner.co.uk *.typekit.net *.gnatta.com *.klaviyo.com *.gstatic.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.ometria.com *.sweetanalytics.com *.zopim.com *.clarity.ms *.google-analytics.com brooktaverner.zendesk.com *.zdassets.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com *.mention-me.com www.google.cz *.webgains.io www.google.com.bd www.google.ee vimeo.com www.google.co.ao www.google.lv www.google.tt www.google.com.gh www.google.com.ar www.google.co.uz www.google.co.zw www.google.mw www.google.ae www.google.gr www.google.ro www.google.co.tz www.google.com.np www.google.es www.google.lu www.google.com.lb www.google.at www.google.com.jm *.bing.com www.google.cv www.google.com.pk *.datadome.co www.google.bs www.google.cm google.com www.google.ge *.brooktaverner.co.uk www.google.sh www.google.se www.google.md www.google.pl www.google.so www.google.com.hk *.facebook.com www.google.ie *.getelevar.com www.google.com.vn www.google.de www.google.mu www.google.co.ve www.google.vu www.google.lk www.google.sn www.google.co.za www.google.co.kr *.visualwebsiteoptimizer.com www.google.kz www.google.fi *.convertexperiments.com www.google.com.ly www.google.cg www.google.cl *.bing.net www.google.com.pa www.google.im www.google.be www.google.com.bn www.google.com.ec www.google.dz www.google.co.cr www.google.co.ke *.klaviyo.com *.googlesyndication.com www.google.tn www.google.com.uy www.google.ba *.doubleclick.net www.google.co.nz www.google.dj www.google.jo www.google.nl www.google.ch *.googleadservices.com www.google.az *.sentry.io www.google.bg www.google.gg *.gnatta.com www.google.com.gi www.google.pt www.google.rs www.google.hu www.google.com.mx www.google.com.kh www.google.com.ua www.google.co.il www.google.co.uk www.google.fr www.google.co.in www.google.gy www.google.co.mz www.google.cd www.google.am www.google.iq www.google.co.jp www.google.com.br www.google.no *.google.com www.google.com.tw www.google.je www.google.lt www.google.com.kw www.google.dk www.google.com.tr www.google.hr www.google.co.ug www.google.com.au www.google.ru www.google.com.et www.google.co.zm www.google.li *.termly.io www.google.sk www.google.com.sa www.google.by www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.me www.google.it www.google.al www.google.com.bh www.google.is www.google.com.mm www.google.com.do www.google.co.th www.google.com.ng www.google.sc www.google.ad www.google.com.ph www.google.com.na www.google.co.ma www.google.com.cy www.google.com.co www.google.com.mt *.googletagmanager.com www.google.com.my www.google.si 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://c07a795d-56fb-4453-8188-078c928ca0fb.sansec.watch/; report-to report-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/sre_google 1 child-src 'self' bid.g.doubleclick.net *.bitexen.com www.google.com; connect-src 'self' *.bitexen.com firebase.googleapis.com firebaseinstallations.googleapis.com salesiq.zoho.com salesiq.zohopublic.com sdkapi.netmera.com stats.g.doubleclick.net www.google-analytics.com api.intotheblock.com desk.zoho.com vts.zohopublic.com www.tradingview.com app.adjust.com app.adjust.net.in app.adjust.world fonts.gstatic.com koinbulteni.com region1.google-analytics.com wasm.regulaforensics.com; font-src 'self' css.zohocdn.com fonts.gstatic.com css.zohocdn.com css.zohostatic.com; form-action 'self' *.bitexen.com; frame-ancestors 'self'; frame-src 'self' bid.g.doubleclick.net pixel.sitescout.com s.tradingview.com *.hcaptcha.com *.geetest.com *.bitexen.com www.google.com; img-src 'self' data: *.bitexen.com pixel.sitescout.com salesiq.zohopublic.com sdkapi.netmera.com www.facebook.com www.google.com www.google.com.tr accounts.zoho.com googleads.g.doubleclick.net koinbulteni.com s3.eu-west-1.amazonaws.com ssl.google-analytics.com web.facebook.com www.google-analytics.com region1.google-analytics.com static.geetest.com static.geevisit.com www.gstatic.com *.hcaptcha.com www.googletagmanager.com; manifest-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdn.netmera-web.com connect.facebook.net firebasestorage.googleapis.com googleads.g.doubleclick.net js.zohocdn.com salesiq.zoho.com secure.adnxs.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com app.intotheblock.com code.jquery.com js-agent.newrelic.com js.zohostatic.com ntm.netmera-web.com s3.tradingview.com ssl.google-analytics.com d17nz991552y2g.cloudfront.net *.geetest.com *.geevisit.com; script-src 'self' 'unsafe-eval' cdn.netmera-web.com js-agent.newrelic.com g792337344.co connect.facebook.net *.hcaptcha.com app.intotheblock.com firebasestorage.googleapis.com googleads.g.doubleclick.net js.zohocdn.com js.zohostatic.com ntm.netmera-web.com s3.tradingview.com salesiq.zoho.com secure.adnxs.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com *.geetest.com *.hcaptcha.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' data: cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com css.zohocdn.com fonts.googleapis.com use.fontawesome.com css.zohostatic.com *.geetest.com *.hcaptcha.com; style-src 'unsafe-eval' data: cdnjs.cloudflare.com css.zohocdn.com css.zohostatic.com fonts.googleapis.com *.hcaptcha.com *.geetest.com *.bitexen.com; worker-src *.bitexen.com; object-src 'none'; report-uri https://reporturi.bitexen.com/r/d/csp/wizard 1 object-src 'none'; script-src 'nonce-iSg4zo3mvotobaTekUrhjg==' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:; base-uri 'none'; report-uri https://o463592.ingest.sentry.io/api/5471479/security/?sentry_key=ab531d6dca0d488898493ccc9706f202&sentry_environment=prod 1 script-src https://www.aah.co.uk/ https://www.googletagmanager.com/gtm.js 'unsafe-inline' https://*.evergage.com 'self' https://payments.salesforce.com/ https://stats.g.doubleclick.net https://cdn-ukwest.onetrust.com/scripttemplates/202306.2.0/otBannerSdk.js https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://cdn.cookielaw.org https://cdn-ukwest.onetrust.com/consent/ae1f04fa-00ba-4719-b25f-f9edcd356795/OtAutoBlock.js https://consent.trustarc.com http://aahtools.co.uk https://www.gstatic.com https://checkoutshopper-live.adyen.com/ https://cdn-ukwest.onetrust.com/scripttemplates/202308.1.0/otBannerSdk.js https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://cdn.evgnet.com https://pay.google.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://geolocation.onetrust.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ blob: https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://*.abtasty.com https://cdn-ukwest.onetrust.com/scripttemplates/202308.2.0/otBannerSdk.js https://www.googletagmanager.com import: https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js https://www.google-analytics.com https://ssl.gstatic.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval' https://cdn-ukwest.onetrust.com/scripttemplates/202306.2.0/otSDKStub.js; report-to sfdc-csp-ep; report-uri https://celesio.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D24000000aWJn&networkId=0DM4H000000TnMn&type=communities 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.dotdigital-pages.com *.dotdigital.com https://www.facebook.com https://tpc.googlesyndication.com https://consentcdn.cookiebot.com https://assets.braintreegateway.com https://*.paypal.com https://interfaces.zapier.com https://*.zapier.app https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.trackedlink.net *.ddlnk.net https://www.google.fi https://maps.gstatic.com https://maps.googleapis.com https://log.pinterest.com https://eckerolinechatbottest.blob.core.windows.net https://fonts.gstatic.com https://assets.braintreegateway.com https://*.paypal.com https://imgsct.cookiebot.com https://px.ads.linkedin.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://ajax.cloudflare.com https://js-agent.newrelic.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://assets.pinterest.com https://maps.googleapis.com https://eckerolinechatbottest.blob.core.windows.net https://api.videoly.co https://www.google.fi https://www.googleadservices.com https://tpc.googlesyndication.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js.braintreegateway.com https://assets.braintreegateway.com https://www.paypalobjects.com https://*.paypal.com https://snap.licdn.com https://interfaces.zapier.com https://dapi.videoly.co https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.eckeroline.fi 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://fast.fonts.net https://eckerolinechatbottest.blob.core.windows.net https://use.typekit.net https://p.typekit.net https://assets.braintreegateway.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://maps.googleapis.com https://fonts.gstatic.com https://vimeo.com https://consentcdn.cookiebot.com https://api.sandbox.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://api.braintreegateway.com https://client-analytics.braintreegateway.com https://*.paypal.com https://px.ads.linkedin.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src https://assets.braintreegateway.com https://*.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.analytics.google.com *.clarity.ms *.google-analytics.com *.googletagmanager.com affil.eshop-rychle.cz consent.cookie-script.com exponea-api.eshop-rychle.cz googleads.g.doubleclick.net pagead2.googlesyndication.com stats.g.doubleclick.net www.google.com www.youtube.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; font-src 'self' *.hotjar.com fonts.gstatic.com; img-src 'self' *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.hotjar.com bat.bing.com c.seznam.cz googleads.g.doubleclick.net www.facebook.com www.google.com www.google.cz www.seznam.cz; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.googletagmanager.com *.hotjar.com affil.eshop-rychle.cz bat.bing.com c.imedia.cz c.seznam.cz cdn.cookie-script.com connect.facebook.net exponea-api.eshop-rychle.cz googleads.g.doubleclick.net static.hotjar.com script.hotjar.com www.clarity.ms www.google.com www.googleadservices.com www.gstatic.com www.seznam.cz; style-src 'self' 'unsafe-inline' *.hotjar.com fonts.googleapis.com 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com https://mcstaging.booktrump.com https://mcstaging.trumphotels.com https://integration-5ojmyuq-r7ma66w2vxzgu.us-5.magentosite.cloud https://integration2-hohc4oi-r7ma66w2vxzgu.us-5.magentosite.cloud 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://mcstagingdoral.booktrump.com https://mcstagingireland.booktrump.com https://mcstaging.booktrump.com https://mcstaging.trumphotels.com https://integration-5ojmyuq-r7ma66w2vxzgu.us-5.magentosite.cloud https://integration2-hohc4oi-r7ma66w2vxzgu.us-5.magentosite.cloud 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://bat.bing.com https://*.bing.com https://*.synxis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.facebook.net www.termsfeed.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com *.sharethis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://backend.alia-cloudflare.com https://capture.celopay.com https://api.cartstack.com https://*.cartstack.com https://script.hotjar.com https://www.thehotelsnetwork.com https://*.thehotelsnetwork.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com use.typekit.net p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com https://get.geojs.io *.avada.io *.sharethis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://capture.celopay.com https://api.cartstack.com https://*.cartstack.com https://bat.bing.com https://*.bing.com https://www.thehotelsnetwork.com https://*.thehotelsnetwork.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.weeklytimesnow.com.au/csp-reports 1 connect-src 'self' https://*.greenbone.net https://www.cloud.ccm19.de https://pagead2.googlesyndication.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.pt https://www.googleadservices.com https://bat.bing.com; default-src 'none'; font-src 'self' data:; frame-src 'self' https://www.googletagmanager.com https://www.cloud.ccm19.de https://bid.g.doubleclick.net; img-src 'self' data: blob: https://mautic.greenbone.net https://www.cloud.ccm19.de https://*.googletagmanager.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.google.com https://*.google.pt https://bat.bing.com; script-src 'self' 'unsafe-inline' https://www.cloud.ccm19.de https://matomo.greenbone.net https://*.googletagmanager.com https://www.googleadservices.com https://*.g.doubleclick.net https://www.google.com https://bat.bing.com; style-src 'self' 'unsafe-inline' https://www.cloud.ccm19.de; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.br/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: use.fontawesome.com *.antartica.cl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * tracking.bciplus.cl www.google.com wchat.freshchat.com *.antartica.cl www.mercadopago.cl www.mercadolibre.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: www.facebook.com www.google.cl *.antartica.cl www.gstatic.com www.mercadolibre.com www.mercadopago.cl *.google.com.ar antartica.cl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fw-cdn.com/ *.freshchat.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.mercadopago.cl *.googletagmanager.com *.facebook.net *.hotjar.com unpkg.com tracking.krip.cl r2-t.trackedlink.net www.clarity.ms static.trackedweb.net js-agent.newrelic.com wchat.freshchat.com static.zdassets.com *.antartica.cl sdk.mercadopago.com http2.mlstatic.com https://fw-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.freshchat.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com use.fontawesome.com *.antartica.cl www.mercadopago.cl www.gstatic.com *.googletagmanager.com *.cookielaw.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com api.bciplus.cl ekr.zdassets.com libreriaantartica.zendesk.com wchat.freshchat.com bam.nr-data.net *.antartica.cl api.mercadopago.com www.mercadolibre.com events.mercadopago.com *.hotjar.com *.hotjar.io *.clarity.ms *.doubleclick.net *.cookielaw.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.google.com bam.nr-data.net r2.trackedweb.net commerce.adobedc.net *.antartica.cl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-4cfa9671e10f439aab71026223047afe' https://mychart.et0316.epichosted.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart.et0316.epichosted.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.gstatic.com *.googleapis.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://secure-test.worldpay.com/shopper/3ds/ddc.html *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.clearpay.co.uk https://pay.google.com https://secure-test.worldpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com 5900250.fls.doubleclick.net *.payments-amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com *.clearpay.co.uk *.cloudflare.com *.gstatic.com *.google-analytics.com *.hsforms.net *.hsforms.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.klarna.com *.googleadservices.com *.google.com *.google.co.uk *.run4it.com *.fbcdn.net d23yuld0pofhhw.cloudfront.net ut.ra.linksynergy.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://www.google.com/recaptcha/api.js *.gstatic.com *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.google-analytics.com https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js *.hsforms.net *.hsforms.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.feefo.com *.run4it.com *.klevu.com *.payments-amazon.com connect.facebook.net tag.rmp.rakuten.com *.typekit.net *.google.com theed11117.pcapredict.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com *.cloudflare.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.klevu.com *.run4it.com *.postcodeanywhere.co.uk unpkg.cm 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com t.elasticsuite.io *.hsforms.net *.hsforms.com api.addressy.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.feefo.com *.instagram.com *.amazon.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.googletagmanager.com *.google.com *.fontawesome.com https://fonts.bunny.net https://www.google.com https://www.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.google.com *.googletagmanager.com *.googleapis.com *.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors self www.google.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.googletagmanager.com *.facebook.com *.squarecdn.com www.google.com www.gstatic.com apis.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com maps.gstatic.com *.google.com *.google.co.in *.redditstatic.com *.reddit.com https://firebasestorage.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com https://meetanshi.com/media/logo.png www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com maps.googleapis.com *.authorize.net *.paypal.com *.mouseflow.com localmenu.katzsdelicatessen.com *.addthis.com *.noibu.com *.redditstatic.com *.reddit.com *.tiktok.com *.tiktokw.us *.facebook.com *.vibe.co *.avada.io *.shopify.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.gstatic.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.fontawesome.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.google.com *.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://static.klaviyo.com *.gstatic.com assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com maps.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleapis.com *.doubleclick.net *.klaviyo.com *.report-uri.com *.noibu.com wss://*.noibu.com *.redditstatic.com *.reddit.com *.facebook.com *.tiktok.com *.tiktokw.us *.vibe.co https://get.geojs.io *.avada.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.report-uri.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://katzsdelicatessen.report-uri.com/r/d/csp/enforce; report-to report-endpoint; 1 report-uri /core/api/Monitoring/SaveCSPReport 1 script-src 'nonce-V1J3pNL7TiY-ReYm7CU7Hw' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 connect-src 'unsafe-inline' 'unsafe-eval' adsrvr.org *.adsrvr.org attentivemobile.com *.attentivemobile.com attn.tv *.attn.tv adnxs.com *.adnxs.com cdn-api-weglot.com cloudflare.com *.cloudflare.com cloudflareinsights.com *.cloudflareinsights.com contentsquare.net *.contentsquare.net doubleclick.net *.doubleclick.net f1lasvegasgp.com *.f1lasvegasgp.com facebook.com *.facebook.com facebook.net *.facebook.net fonts.googleapis.com google-analytics.com *.google-analytics.com google.ae *.google.ae google.at *.google.at google.be *.google.be google.ca *.google.ca google.cl *.google.cl google.co.id *.google.co.id google.co.il *.google.co.il google.co.in *.google.co.in google.co.jp *.google.co.jp google.co.kr *.google.co.kr google.co.ma *.google.co.ma google.co.nz *.google.co.nz google.co.uk *.google.co.uk google.co.ve *.google.co.ve google.co.za *.google.co.za google.com *.google.com google.de *.google.de google.dk *.google.dk google.es *.google.es google.fi *.google.fi google.fr *.google.fr google.gr *.google.gr google.it *.google.it google.nl *.google.nl google.pl *.google.pl google.ro *.google.ro google.rs *.google.rs google.se *.google.se google.si *.google.si googleadservices.com *.googleadservices.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com gstatic.com *.gstatic.com jsdelivr.net *.jsdelivr.net hotjar.com *.hotjar.com licdn.com *.licdn.com linkedin.com *.linkedin.com perplexity.ai *.perplexity.ai privacy-mgmt.com *.privacy-mgmt.com salesforce-scrt.com *.salesforce-scrt.com site.com *.site.com sojern.com *.sojern.com tiktok.com *.tiktok.com tiktokw.us *.tiktokw.us vimeo.com *.vimeo.com weglot.com *.weglot.com zi-scripts.com *.zi-scripts.com zoominfo.com *.zoominfo.com google.pt *.google.pt; frame-src 'unsafe-inline' 'unsafe-eval' site.com *.site.com privacy-mgmt.com *.privacy-mgmt.com doubleclick.net *.doubleclick.net vimeo.com *.vimeo.com; img-src 'unsafe-inline' 'unsafe-eval' adnxs.com *.adnxs.com adsrvr.org *.adsrvr.org attentivemobile.com *.attentivemobile.com attn.tv *.attn.tv cdn-api-weglot.com cloudflare.com *.cloudflare.com cloudflareinsights.com *.cloudflareinsights.com contentsquare.net *.contentsquare.net doubleclick.net *.doubleclick.net f1lasvegasgp.com *.f1lasvegasgp.com facebook.com *.facebook.com facebook.net *.facebook.net fonts.googleapis.com google-analytics.com *.google-analytics.com google.ae *.google.ae google.at *.google.at google.be *.google.be google.ca *.google.ca google.cl *.google.cl google.co.id *.google.co.id google.co.il *.google.co.il google.co.in *.google.co.in google.co.jp *.google.co.jp google.co.kr *.google.co.kr google.co.ma *.google.co.ma google.co.nz *.google.co.nz google.co.uk *.google.co.uk google.co.ve *.google.co.ve google.co.za *.google.co.za google.com *.google.com google.de *.google.de google.dk *.google.dk google.es *.google.es google.fi *.google.fi google.fr *.google.fr google.gr *.google.gr google.it *.google.it google.nl *.google.nl google.pl *.google.pl google.pt *.google.pt google.rs *.google.rs google.ro *.google.ro google.se *.google.se google.si *.google.si googleadservices.com *.googleadservices.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com gstatic.com *.gstatic.com hotjar.com *.hotjar.com jsdelivr.net *.jsdelivr.net licdn.com *.licdn.com linkedin.com *.linkedin.com perplexity.ai *.perplexity.ai privacy-mgmt.com *.privacy-mgmt.com salesforce-scrt.com *.salesforce-scrt.com site.com *.site.com sojern.com *.sojern.com tiktok.com *.tiktok.com tiktokw.us *.tiktokw.us vimeo.com *.vimeo.com weglot.com *.weglot.com zi-scripts.com *.zi-scripts.com zoominfo.com *.zoominfo.com www.google.com.au www.google.com www.google.com.mx googleads.g.doubleclick.net www.google.com.co www.google.com.ar www.google.com.qa www.google.com.tw www.google.com.py www.google.com.br www.google.com.my www.google.com.sv google.co.bw *.google.co.bw google.co.ke *.google.co.ke google.cz *.google.cz; style-src site.com *.site.com 'unsafe-inline' 'unsafe-eval' fonts.googleapis.com f1lasvegasgp.com *.f1lasvegasgp.com weglot.com *.weglot.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=IWt4KjI1CwoxtEvLHApSlGUkeruqLU6bVtOOjB6iB18-1765934833.0313578-1.0.1.1-YzHsTmsnw4fyIKXiRMKStsQ6GMLmEXEg0.cqwMM_nYAgVCQerOneoujLlyRfe3UlsT49P7lWWMOz5AOUjDEA7jfC4z6cU9WFjG0FzutCXmfbLKG1y6eHTxaGxycIE8QydJdpw96_.jXV.WAfVDNu.Y019WTZmly6tBx5y7o8SLGZFDfzQRgzLo2kJNxN7YS4v8F_ZqQKb1JwkRh8pkUllA; report-to cf-sqzthlhytfaykmsj 1 object-src 'none'; script-src 'self' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.recaptcha.net unpkg.com; style-src 'self' cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 frame-ancestors 'self'; base-uri 'self'; object-src 'self'; script-src 'self' 'strict-dynamic' 'nonce-rand1765937721' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' http: https:; 1 default-src 'self' 'unsafe-inline'; img-src data: https:; script-src-elem 'self' https: 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; connect-src https:; frame-src https:; object-src 'self' 'unsafe-inline' https:; style-src-elem 'self' 'unsafe-inline' https:; report-uri /csp-violation-report-endpoint/ 1 frame-ancestors 'self'; report-uri https://www.geelongadvertiser.com.au/csp-reports 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action *.cognitoforms.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.paygate.co.za/payweb3/process.trans oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-src *.cognitoforms.com *.peachpayments.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; 1 img-src 'self' data: dev.visualwebsiteoptimizer.com cdn.cookielaw.org www.googletagmanager.com *.siteimproveanalytics.io *.intoxalock.com *.facebook.com *.lpsnmedia.net *.gstatic.com *.googleapis.com i.ytimg.com 'self' data: dev.visualwebsiteoptimizer.com cdn.cookielaw.org www.googletagmanager.com *.siteimproveanalytics.io *.intoxalock.com *.facebook.com *.lpsnmedia.net *.gstatic.com *.googleapis.com i.ytimg.com px.ads.linkedin.com; script-src m555.bluemod.us cdn.cookielaw.org www.googletagmanager.com js.monitor.azure.com *.liveperson.net *.liveperson.com *.lpsnmedia.net unpkg.com getrockerbox.com siteimproveanalytics.com *.infinity-tracking.com *.facebook.com *.intoxalock.com *.facebook.net *.ubembed.com *.googleapis.com https://www.google.com/recaptcha/api.js *.gstatic.com m555.bluemod.us *.googletagmanager.com *.gstatic.com mindrco.blueconic.net dev.visualwebsiteoptimizer.com snap.licdn.com www.youtube.com 'self' 'unsafe-inline' 'nonce-ub68ybLFElE1SHse9MeayFBC9RyGI2NFgnvmCu6m5hA='; font-src 'self' data: *.gstatic.com; connect-src dev.visualwebsiteoptimizer.com *.applicationinsights.azure.com cdn.cookielaw.org *.google.com *.infinity-tracking.com *.googleapis.com *.onetrust.com dev.visualwebsiteoptimizer.com *.onetrust.com t081.intoxalock.com r5.visualwebsiteoptimizer.com px.ads.linkedin.com ad.doubleclick.net www.google-analytics.com 'self'; frame-src 'self' *.trustpilot.com www.googletagmanager.com td.doubleclick.net lpcdn.lpsnmedia.net *.liveperson.net *.youtube.com https://www.google.com https://locations.intoxalock.com.yext-cdn.com https://www.zeemaps.com/ 'self' *.trustpilot.com www.googletagmanager.com td.doubleclick.net lpcdn.lpsnmedia.net *.liveperson.net *.youtube.com https://www.google.com https://locations.intoxalock.com.yext-cdn.com https://www.zeemaps.com https://13396136.fls.doubleclick.net https://www.facebook.com; style-src *.googleapis.com 'self' 'unsafe-inline'; worker-src 'self' blob:; default-src 'self'; 1 default-src 'self' *.localphone.com *.localphone.co.uk; img-src * data:; child-src *; frame-src *; script-src 'self' 'unsafe-inline' *.localphone.com https://js.stripe.com https://*.google.com https://ajax.googleapis.com http://www.google-analytics.com https://*.gstatic.com https://*.g.doubleclick.net https://www.googleadservices.com https://www.facebook.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' *.localphone.com https://*.googleapis.com https://cdn.jsdelivr.net; font-src 'self' data: fonts.gstatic.com https://sxt.cdn.skype.com; connect-src 'self' *.localphone.com; 1 frame-ancestors 'self' *.preview.devprod.cloudflare.dev;frame-src 'self' www.youtube.com player.vimeo.com www.recaptcha.net www.google.com www.googletagmanager.com sgtm-cr.vistra.com *.hsforms.com td.doubleclick.net consentcdn.cookiebot.com s.company-target.com cdn.yoshki.com cdn.userway.org platform.twitter.com; report-uri https://vistragroup.com/csp-report 1 default-src 'self' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; connect-src 'self' solutionreach.okta.com solutionreach-admin.okta.com login.solutionreach.com *.oktacdn.com *.mixpanel.com *.mapbox.com solutionreach.kerberos.okta.com solutionreach.mtls.okta.com https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; frame-src 'self' solutionreach.okta.com solutionreach-admin.okta.com login.solutionreach.com login.okta.com; img-src 'self' solutionreach.okta.com login.solutionreach.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com data: blob:; font-src 'self' solutionreach.okta.com login.solutionreach.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net a.omappapi.com *.fontawesome.com *.alothemes.com *.magepow.com *.google.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://seo.mageplaza.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com event.getblue.io static.omni.chat *.criteo.com static.criteo.net td.doubleclick.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.mollie.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.oceandrop.com.br c.clarity.ms *.bing.com www.google.com.br cm.g.doubleclick.net collect.vendavalida.com.br *.criteo.com *.omappapi.com a.mgid.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.mollie.com cdn.mundipagg.com api.pagar.me *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com event.getblue.io widget.getblue.io static.omni.chat a.omappapi.com oceandrop-br.mais.social js-agent.newrelic.com www.clarity.ms *.hotjar.com bat.bing.com www.googleoptimize.com collect.vendavalida.com.br *.criteo.com secure.afilio.com.br a.mgid.com *.ubembed.com widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.mollie.com 3ds2.pagar.me 3ds2-sdx.pagar.me *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com oceandrop-br.mais.social a.omappapi.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://maps.googleapis.com https://player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oceandrop-br.mais.social omnichat-web-chat.omni.chat webchat-adapter.omni.chat *.omappapi.com *.clarity.ms bam.nr-data.net ws.hotjar.com *.hotjar.io *.criteo.com stats.g.doubleclick.net collect.vendavalida.com.br bat.bing.com widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br *.google.com google.com pay.sandbox.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' cdnjs.cloudflare.com kit.fontawesome.com apps.elfsight.com static.elfsight.com cdn.usebootstrap.com *.cloudmaestro.com www.gstatic.com www.google-analytics.com www.google.com googletagmanager.com *.googletagmanager.com *.optimizely.com stockist.co *.stockist.co *.klaviyo.com static.cloudflareinsights.com tags.clickagy.com cdn.jsdelivr.net cdn.userway.org stackpath.bootstrapcdn.com *.bootstrapcdn.com; report-uri /.webscale/csp-report 1 default-src 'self'; script-src 'self' 'strict-dynamic' 'nonce-9CsDtiKYwfUs9ACCMtcm1O' 'unsafe-inline' 'sha256-sJOaoOnYrCB4s7vHlk8eB3Sf1DXMMxJDcUkymhc4cwE=' 'sha256-AKHJ5+iyvFAj8YbbeERhdT4N11jVAknE5SmSHpm2rEc=' *.danlon.dk *.bing.com *.wp.com cdn.jsdelivr.net cdn.raffle.ai widget.trustpilot.com *.wistia.net secure.gaug.es *.cookieinformation.com *.hotjar.com *.sleeknote.com yoast.com *.facebook.com *.facebook.net *.clarity.ms snap.licdn.com *.google.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.g.doubleclick.net td.doubleclick.net *.googlesyndication.com; style-src 'self' blob: 'unsafe-inline' *.danlon.dk *.wp.com cdn.jsdelivr.net; font-src 'self' data: *.wp.com cdn.jsdelivr.net *.gstatic.com; img-src 'self' data: blob: *.danlon.dk *.bing.com *.wp.com *.wordpress.com ps.w.org cdn.jsdelivr.net widget.trustpilot.com secure.gaug.es *.linkedin.com *.facebook.com *.facebook.net *.clarity.ms https://delivery.twentythree.com https://report.23video.com secure.gravatar.com *.google.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.g.doubleclick.net td.doubleclick.net *.googlesyndication.com *.google.com *.google.co.uk *.google.de *.google.fr *.google.it *.google.es *.google.nl *.google.be *.google.se *.google.dk *.google.no *.google.fi *.google.pl *.google.cz *.google.hu *.google.sk *.google.gr *.google.pt *.google.at *.google.ie *.google.ch *.google.bg *.google.hr *.google.ro *.google.si *.google.lv *.google.lt *.google.ee *.google.rs *.google.md; frame-src blob: *.wp.com wordpress.com *.wordpress.com *.raffle.ai widget.trustpilot.com *.wistia.net *.cookieinformation.com *.facebook.com *.facebook.net *.google.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.g.doubleclick.net td.doubleclick.net *.googlesyndication.com; connect-src 'self' data: *.danlon.dk *.bing.com *.wp.com cdn.jsdelivr.net *.raffle.ai widget.trustpilot.com *.wistia.com *.wistia.net *.cookieinformation.com *.hotjar.io *.hotjar.com wss://ws.hotjar.com *.sleeknote.com *.linkedin.com yoast.com *.facebook.com *.facebook.net *.clarity.ms https://api.nelioabtesting.com prod-141.westeurope.logic.azure.com *.datah04.com *.google.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.g.doubleclick.net td.doubleclick.net *.googlesyndication.com sentry.abtion.com; object-src 'none'; base-uri 'self'; form-action 'self' *.danlon.dk; frame-ancestors 'self' app.danlon.dk; report-uri https://sentry.abtion.com/api/7/security/?sentry_key=97033f75405e88044ce3cd946c89f5d3&sentry_environment=production; report-to sentry; 1 font-src *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.dotdigital-pages.com *.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.googleapis.com *.gstatic.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.adyen.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tracking.trovaprezzi.it www.trovaprezzi.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com *.nosto.com *.nos.to maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src *.force.com slack-imgs-mil-dev.com 'self' *.slack.com https://www.paypal.com https://img.youtube.com https://images-na.ssl-images-amazon.com https://payments.salesforce.com/icons/ https://www.abebooks.com https://login.salesforce.com/icons/ *.slack-imgs.com slack-imgs-gov.com https://usa856.sfdc-yfeipo.salesforce.com/icons/ https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://indiecommunity.file.force.com https://www.gstatic.com *.slack-edge-gov.com *.my-salesforce.com slack-imgs-gov-dev.com *.slack-edge.com *.cloudinary.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://www.kdpcommunity.com *.amazonaws.com blob: https://indiecommunity.my.salesforce.com https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://kdpcommunity.com https://assets.prod.abebookscdn.com https://i.vimeocdn.com https://completion.amazon.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.salesforce.com *.twimg.com https://*.adyen.com slack-imgs.mil https://testdata.coremetrics.com data:; report-to sfdc-csp-ep; report-uri https://indiecommunity.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Df4000001cwvQ&networkId=0DMf4000000gttr&type=communities 1 default-src 'self'; script-src 'report-sample' 'self' https://cdnjs.cloudflare.com/ajax/libs/lottie-web/5.8.1/lottie.min.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://player.vimeo.com/api/player.js 'sha256-FSevH+aW1elUrWYqKfiu3xdrYlsrq1pzbI5VpKisyLM='; style-src 'report-sample' 'self' https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://www.google-analytics.com https://o969560.ingest.sentry.io https://stats.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://player.vimeo.com; img-src https: data:; manifest-src 'self'; media-src 'self' https://assts.stories.sc https://player.vimeo.com https://*.vimeocdn.com; report-uri https://o969560.ingest.sentry.io/api/5920728/security/?sentry_key=e6ced77cc723478fad969f5f3ba00b06 worker-src 'none'; 1 default-src 'self'; child-src 'self'; font-src 'none'; frame-ancestors 'self'; frame-src 'self'; manifest-src 'self'; media-src 'none'; object-src 'self'; worker-src 'self' blob: 0.0.0.0:3000; connect-src 'self' *.openhistoricalmap.org openhistoricalmap.github.io *.amazonaws.com http://127.0.0.1:8111 https://vector.openstreetmap.org https://api.maptiler.com https://tile.thunderforest.com https://render.openstreetmap.org https://nominatim.openhistoricalmap.org/ https://overpass-api.openhistoricalmap.org/api/interpreter https://routing.openstreetmap.de/ https://graphhopper.com/api/1/route https://valhalla1.openstreetmap.de/route https://www.wikidata.org/w/api.php; form-action 'self' render.openstreetmap.org tile.thunderforest.com; img-src 'self' data: www.gravatar.com *.wp.com tile.openstreetmap.org gps.tile.openstreetmap.org *.tile.thunderforest.com tile.tracestrack.com *.openstreetmap.fr https://commons.wikimedia.org/wiki/ upload.wikimedia.org; script-src 'self' openhistoricalmap.github.io 'wasm-unsafe-eval' 'nonce-24RmDdAJRHnuWyG6k6AcJyhHcY5Qnked'; style-src 'self' openhistoricalmap.github.io 'unsafe-inline' 'nonce-24RmDdAJRHnuWyG6k6AcJyhHcY5Qnked' 1 default-src 'self';style-src 'self' 'unsafe-inline';style-src-elem 'unsafe-inline' 'self' https://*.intercomcdn.com/ https://fonts.googleapis.com/css2;script-src 'unsafe-eval' https://*.intercom.io;script-src-elem 'self' 'unsafe-inline' https://*.intercom.io/ https://*.intercomcdn.com/ https://www.googletagmanager.com/gtag/ https://fonts.googleapis.com/css2;img-src 'self' data: blob: https://images.stealthex.io https://stealthex.io/blog/wp-content/ https://*.intercomassets.com https://*.intercomcdn.com https://fc-use1-00-pics-bkt-00.s3.amazonaws.com/;media-src https://*.intercom.io;frame-src https://*.intercom.io https://intercom-sheets.com;worker-src 'self' blob: https://*.intercom.io/;font-src 'self' data: https://fonts.gstatic.com/ https://*.intercomcdn.com/;connect-src 'self' https://stealthex.io/api/ https://www.google-analytics.com/g/collect https://*.ingest.sentry.io/api/ wss://*.intercom.io/ https://*.intercom.io/;report-uri https://stealthex.report-uri.com/r/d/csp/reportOnly 1 default-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://elegant-harmony-f8a4c00980.media.strapiapp.com https://cms.sandbox-london-b.fetch-ai.com; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com; frame-ancestors 'none'; base-uri 'self'; 1 default-src 'self' https: 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com d17anp2eo56k6j.cloudfront.net d9h1vtbtgkgvf.cloudfront.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.reevoo.com/ *.feefo.com *.speedex.gr data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com unpkg.com *.unpkg.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.facebook.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.snappibank.com.gr unpkg.com *.unpkg.com cdnjs.cloudflare.com *.addthis.com data 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.findbar.io https://images.unsplash.com unpkg.com *.unpkg.com *.disqus.com *.hsforms.net *.hsforms.com *.mydesigndrops.com mddhyva.magedeploy.com media.mydesigndrops.com *.cdninstagram.com sp.analytics.yahoo.com *.cookiebot.com *.google.gr *.sharethrough.com *.outbrain.com *.bidswitch.net *.dnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.adnxs.com *.id5-sync.com *.pubmatic.com *.postrelease.com *.rubiconproject.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.emxdgt.com *.yieldmo.com *.unrulymedia.com *.1rx.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.findbar.io unpkg.com *.unpkg.com cdnjs.cloudflare.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io cdn.simpler.so sdk.local.simpler.so *.hsforms.net *.hsforms.com *.mydesigndrops.com *.feefo.com *.clarity.ms skroutza.skroutz.gr *.skroutz.gr dynamic.criteo.com sslwidget.criteo.com widgets.reevoo.com go.linkwi.se s.yimg.com measurement-api.criteo.com metrics.find.gr plausible.io *.cookiebot.com *.hotjar.com *.pinimg.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.findbar.io unpkg.com *.unpkg.com https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com *.reevoo.com/ *.feefo.com *.speedex.gr 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.findbar.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.snappibank.com.gr *.findbar.io unpkg.com *.unpkg.com https://get.geojs.io *.avada.io button.simpler.so button.staging.simpler.so analytics.simpler.so analytics.staging.simpler.so button.local.simpler.so t.elasticsuite.io *.hsforms.net *.hsforms.com *.feefo.com *.hotjar.com wss://ws.hotjar.com *.hotjar.io widgets.reevoo.com skynet.reevoo.com measurement-api.criteo.com s.yimg.com metrics.find.gr plausible.io *.doubleclick.net *.pinterest.com *.clarity.ms *.cookiebot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' *.usercentrics.eu *.youtube.com tracker.muellergroup.com data: connect.facebook.net *.googletagmanager.com analytics.tiktok.com *.amazon-adsystem.com; frame-src *.youtube.com *.youtube-nocookie.com *.frcapi.com *.facebook.com; img-src 'self' data: *.ytimg.com *.usercentrics.eu *.facebook.com *.googlesyndication.com ad.doubleclick.net analytics.tiktok.com; connect-src 'self' noembed.com *.plyr.io *.usercentrics.eu tracker.muellergroup.com analytics.tiktok.com analytics-ipv6.tiktokw.us *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.googlesyndication.com *.facebook.com; report-uri https://allesmuelleroderwas.de/@http-reporting?csp=report&requestTime=1765935811911606&requestHash=ace1187d4d3f274888d56894c8b7933198e36e94 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * vr-pay-ecommerce.de test.vr-pay-ecommerce.de apple-pay-gateway.apple.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * vr-pay-ecommerce.de test.vr-pay-ecommerce.de eu-prod.ppipe.net/ test.ppipe.net/ oppwa.com/ test.oppwa.com/ apple-pay-gateway.apple.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com vr-pay-ecommerce.de test.vr-pay-ecommerce.de www.gstatic.com/ apple-pay-gateway.apple.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.klarna.com vr-pay-ecommerce.de test.vr-pay-ecommerce.de apple-pay-gateway.apple.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com vr-pay-ecommerce.de test.vr-pay-ecommerce.de apple-pay-gateway.apple.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com vr-pay-ecommerce.de test.vr-pay-ecommerce.de pay.google.com www.google.com/pay apple-pay-gateway.apple.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.klevu.com *.ksearchnet.com fonts.gstatic.com blog.vintageking.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.syfpos.com *.facebook.com blog.vintageking.com 'self' 'unsafe-inline'; frame-ancestors blog.vintageking.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * syf.demdex.net *.syfpos.com *.syf.com *.weltpixel.com www.xtento.com https://www.googletagmanager.com/ *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net https://*.online-metrix.net https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.affirm.com *.affirm.ca https://helloextend-static-assets.s3.amazonaws.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net www.xtento.com cdn.xtento.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klevu.com *.ksearchnet.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://imgs.signifyd.com https://*.online-metrix.net blog.vintageking.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com https://*.leadmanagerfx.com https://*.marketingcloudfx.com www.xtento.com cdn.xtento.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.klevu.com *.ksearchnet.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.syfpos.com *.klevu.com *.ksearchnet.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com blog.vintageking.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ blog.vintageking.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net https://*.leadmanagerfx.com https://*.marketingcloudfx.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klevu.com *.ksearchnet.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blog.vintageking.com http: https: blob: 'self' 'unsafe-inline'; default-src blog.vintageking.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://stats.g.doubleclick.net; connect-src 'self' https: wss: data: https://www.facebook.com https://graph.facebook.com https://*.nr-data.net https://bam.nr-data.net https://bam.eu01.nr-data.net https://js-agent.newrelic.com https://*.google-analytics.com https://pro.ip-api.com/json https://stats.g.doubleclick.net https://ad.doubleclick.net https://td.doubleclick.net https://*.doubleclick.net https://*.onetrust.com https://pagead2.googlesyndication.com https://bat.bing.com https://u.clarity.ms https://*.clarity.ms https://px.ads.linkedin.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://tagmanager.google.com https://www.googletagmanager.com https://*.googletagmanager.com https://secure.leadforensics.com https://*.agile-company-365.com https://*.igodigital.com https://connect.facebook.net https://snap.licdn.com https://www.google-analytics.com https://cdn.mouseflow.com https://*.mouseflow.com wss://*.mouseflow.com; font-src 'self' data: https://fonts.gstatic.com https://*.cdn.office.net https://use.typekit.net https://use.typekit.com; frame-src 'self' data: https://www.youtube-nocookie.com https://www.youtube.com https://*.fls.doubleclick.net https://td.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://*.doubleclick.net; img-src 'self' https: data: https://*.cloudfunctions.net https://www.google-analytics.com https://www.facebook.com https://www.google.com/ads/ga-audiences https://www.google.co.uk/ads/ga-audiences https://*.onetrust.com https://www.googleadservices.com https://www.googletagmanager.com https://ade.googlesyndication.com https://c.clarity.ms https://px.ads.linkedin.com https://ad.doubleclick.net https://*.doubleclick.net https://bat.bing.com https://c.bing.com https://pixel.byspotify.com https://*.igodigital.com https://www.datocms-assets.com https://*.mouseflow.com; media-src 'self' https: data: blob:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: * https://js-agent.newrelic.com https://bam.nr-data.net https://bam.eu01.nr-data.net https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://www.googleoptimize.com https://connect.facebook.net https://*.onetrust.com https://bat.bing.com https://snap.licdn.com https://secure.agile-company-365.com https://*.agile-company-365.com https://px.ads.linkedin.com https://www.clarity.ms https://*.clarity.ms https://www.clarity.com https://ts.clarity.com https://v.clarity.com https://ad.doubleclick.net https://*.doubleclick.net https://adservice.google.com https://secure.leadforensics.com https://pixel.byspotify.com https://*.igodigital.com https://*.infinity-tracking.com https://cdn.mouseflow.com; style-src 'self' 'unsafe-inline' blob: data: * https://fonts.googleapis.com; upgrade-insecure-requests; report-uri https://o4508693778268160.ingest.de.sentry.io/api/4509629814800465/security/?sentry_key=7af8eb49226dd30e4cc31a2e2f6ea5cc; 1 img-src *.force.com slack-imgs-mil-dev.com https://mzmoment-test.app https://www.vevromerike.no 'self' https://stats.g.doubleclick.net https://vevromerike.no https://img.youtube.com https://vev.my.site.com https://payments.salesforce.com/icons/ https://e360-tracking-service-cdp1.sfdc-yzvdd4.svc.sfdcfc.net https://login.salesforce.com/icons/ https://vev.my.salesforce.com optimize.google.com lightning.force.com *.googlesyndication.com https://www.gstatic.com https://assets.mapquestapi.com *.slack-edge-gov.com *.my-salesforce.com https://www.youtube-nocookie.com *.cloudinary.com *.vevromerike.no www.google.no https://www.google.com https://www.googleoptimize.com https://romerikebb.sharepoint.com *.amazonaws.com https://region1.google-analytics.com blob: https://vev.lightning.force.com https://fra80.sfdc-urlt2q.salesforce.com/icons/ https://monitoringpublic.solaredge.com *.facebook.com https://d.la1-core1.sfdc-urlt2q.salesforceliveagent.com https://www.telia.no slack-imgs.com https://c.tiles.mapbox.com slack-gov-dev.com *.sfdcstatic.com https://tileproxy.cloud.mapquest.com https://mzmoment.app *.twimg.com https://vev.my.salesforce-scrt.com https://vev--c.visualforce.com *.slack.com https://www.paypal.com *.google.no https://a.tiles.mapbox.com *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://d.la11-core1.sfdc-urlt2q.salesforceliveagent.com *.doubleclick.net https://app.oneflow.com https://www.mapquestapi.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://commonapi-gw.get.no https://d.tiles.mapbox.com https://artikler.get.no https://mapconfig.mqcdn.com https://www.google.com/recaptcha/ https://m83tkyrsgfqwkylcgqzgkzlbgy.c360a.salesforce.com *.slack-edge.mil https://www.sandbox.paypal.com *.vev.lightning.force.com https://www.arrowcommunications.co.uk https://i.vimeocdn.com https://vev.file.force.com https://www.googletagmanager.com https://d.la3-c2-fra.salesforceliveagent.com https://www.google-analytics.com https://b.tiles.mapbox.com *.salesforce.com https://vev--c.vf.force.com https://*.adyen.com slack-imgs.mil https://service.force.com https://vev.live-preview.salesforce-experience.com data:; report-to sfdc-csp-ep; report-uri https://vev.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D24000000Zs0w&networkId=0DM08000000sXzv&type=communities 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://www.facebook.com/tr/ 'self' 'unsafe-inline'; frame-ancestors *.bebemundo.com.do *.jugueton.com.do *.zdassets.com *.hotjar.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co amc.demdex.net www.google.com youtube.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.facebook.com/tr/ *.doubleclick.net *.googlesyndication.com *.adtrafficquality.google 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.gstatic.com maps.googleapis.com accounts.google.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.google.com.pa www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com https://googleads.g.doubleclick.net www.google.com.ar www.google.com.do https://www.googletagmanager.com https://www.m.casacuesta.com https://connect.facebook.net https://notifications-icommkt.website *.google.com.do/ads/ga-audiences *.simpleanalyticscdn.com *.googlesyndication.com *.doubleclick.net *.mcprod.supermercadosnacional.com *.googletagmanager.com *.googleapis.com *.google.com.do *.zdassets.com/ekr/snippet.js *.google.com.ar/pagead/1p-conversion *.baidu.com *.cloudfront.net *.adtrafficquality.google data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com *.googleapis.com *.gstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net *.klaviyo.com *.xtento.com *.tiktok.com *.pangle-ads.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://www.google.com https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.google-analytics.com https://stats.g.doubleclick.net http://www.google.com/recaptcha/api.js https://d12zyq17vm1xwx.cloudfront.net/v2/wpn.min.js https://static.cloudflareinsights.com/ https://www.gstatic.com/recaptcha/releases/tFhBvPrftr7Y91fo1S1ASkA6/recaptcha__es.js https://externalassets.icommarketing.com/icomMkt_tracking_jquery.min.js https://static.zdassets.com ekr.zdassets.com https://maps.googleapis.com *.googlesyndication.com *.cloudflareinsights.com *.cloudfront.net *.woopra.com *.simpleanalyticscdn.com *.icommarketing.com *.singular.net *.adtrafficquality.google *.gbqofs.com *.icommkt.online xandar-lsw-v3.instaleap.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.zdassets.com *.youtube.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.comapi.com bam.nr-data.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net *.klaviyo.com *.xtento.com *.tiktok.com *.pangle-ads.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://www.hotjar.com https://script.hotjar.com https://analytics.google.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ http://ccnecommerce.com/ https://notifications-icommkt.com/ https://track-icommkt.com/ wss://widget-mediator.zopim.com/ *.youtube.com https://static.zdassets.com ekr.zdassets.com jugueton.zendesk.com bebemundord.zendesk.com casacuesta.zendesk.com *.googletagmanager.com *.google.com.ar *.doubleclick.net *.icommkt.com wss://widget-mediator.zopim.com *.simpleanalyticscdn.com *.woopra.com *.googlesyndication.com *.icommkt.com/push-register/get-webhook-data *.gstatic.com *.googleapis.com *.zopim.com *.com.do/ads/ga-audiences *.singular.net *.gbqofs.io *.adtrafficquality.google xandar-lsw-v3.instaleap.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.zohocdn.com https://static.zohocdn.com.cn https://*.zohostatic.com https://*.zohowebstatic.com https://*.zoho.com https://salesiq.zoho.com https://cdn.pagesense.io; report-uri https://logsapi.zoho.com/csplog?service=creator; 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com https://*.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.gstatic.com applepay.cdn-apple.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.securetrading.net *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * *.rvvuptech.com *.rvvup.com *.afterpay.com *.clearpay.co.uk *.sandbox.paypal.com cdn.eu.trustpayments.com *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com thm.visa.com *.mastercard.com *.salesfire.co.uk *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net *.typeform.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com www.gstatic.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk https://*.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.afterpay.com assets.dev.rvvuptech.com assets.rvvup.com *.sandbox.paypal.com *.stats.paypal.com *.gstatic.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com widgets.dividebuy.co.uk widgets.dividebuysandbox.co.uk *.salesfire.co.uk *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.sharethis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.plugins.emarsys.net *.scarabresearch.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.afterpay.com *.sandbox.paypal.com checkout.dev.rvvuptech.com checkout.rvvup.com cdn.eu.trustpayments.com *.securetrading.net *.secure.checkout.visa.com *.cardinalcommerce.com *.mastercard.com applepay.cdn-apple.com widgets.dividebuysandbox.co.uk widgets.dividebuy.co.uk *.salesfire.co.uk *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com https://*.googleapis.com https://*.typekit.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com unsafe-inline assets.braintreegateway.com checkout.dev.rvvuptech.com checkout.rvvup.com widgets.dividebuy.co.uk widgets.dividebuysandbox.co.uk *.salesfire.co.uk *.typekit.net *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sharethis.com *.scarabresearch.com *.eservice.emarsys.net https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.afterpay.com *.sandbox.paypal.com *.dev.rvvuptech.com *.rvvup.com www.apple.com apple.com browser-intake-datadoghq.com browser-intake-datadoghq.eu api.dividebuysandbox.co.uk api.dividebuy.co.uk *.salesfire.co.uk *.smartmetrics.co.uk *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' *.hubspot.com *.hs-analytics.net *.hs-scripts.com; connect-src 'self' *.hubspot.com *.hubapi.com; img-src 'self' *.hs-analytics.net *.hubspotusercontent##.net; frame-src 'self' *.hubspotvideo.com *.hscollectedforms.net; style-src 'self' *.hubspotusercontent##.net; 1 font-src fonts.gstatic.com use.typekit.net use.fontawesome.com wsv3cdn.audioeye.com *.klevu.com *.ksearchnet.com *.gstatic.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com https://plumrocket.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://www.google.com googleads.g.doubleclick.net home-c36.nice-incontact.com td.doubleclick.net wsv3cdn.audioeye.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw www.xtento.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.paymetric.com *.punchout2go.com *.tradecentric.com *.trustpilot.com gum.criteo.com static.criteo.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com www.bosspetedge.com cdn.jsdelivr.net fonts.gstatic.com aa.agkn.com c.clarity.ms www.zenaps.com cm.adgrx.com *.google.com bat.bing.com *.lightboxcdn.com imgsct.cookiebot.com trk.ometria.com api.soreto.com criteo-partners.tremorhub.com x.bidswitch.net visitor.omnitagjs.com r.casalemedia.com *.sync.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com sync.targeting.unrulymedia.com mention-me.com *.soreto.com id5-sync.com c1.adform.net dis.criteo.com cm.adform.net ade.clmbtech.com ade.googlesyndication.com *.ometria.com c.bing.com sync.aralego.com sync.outbrain.com tags.bluekai.com widget.eu.criteo.com cdn.aralego.net s.ad.smaato.net ads.stickyadstv.com idsync.rlcdn.com cs.adingo.jp adx.dable.io gum.criteo.com tg.socdm.com *.googletagmanager.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw www.xtento.com cdn.xtento.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paymetric.com *.klevu.com *.ksearchnet.com bat.bing.net cm.g.doubleclick.net ib.adnxs.com ad.360yield.com rtb-csync.smartadserver.com sync-t1.taboola.com sync.1rx.io dpm.demdex.net public-prod-dspcookiematching.dmxleo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.sharethis.com *.google-analytics.com *.googletagmanager.com s7.addthis.com home-c36.nice-incontact.com wsmcdn.audioeye.com wsv3cdn.audioeye.com bam.nr-data.net www.xtento.com cdn.xtento.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paymetric.com js.klevu.com *.ksearchnet.com https://apis.google.com *.punchout2go.com *.tradecentric.com *.trustpilot.com kit.fontawesome.com js-agent.newrelic.com static.hotjar.com rum-static.pingdom.net bat.bing.com cdn.attn.tv static.criteo.net sslwidget.criteo.com widget.us.criteo.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sharethis.com *.googleapis.com www.googletagmanager.com use.typekit.net p.typekit.net use.fontawesome.com wsv3cdn.audioeye.com cdn.taggstar.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.paymetric.com *.klevu.com *.ksearchnet.com *.punchout2go.com *.tradecentric.com *.trustpilot.com cdnjs.cloudflare.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.sharethis.com www.google.com google.com report-prod.audioeye.com analytics.audioeye.com wsv3cdn.audioeye.com invitejs.trustpilot.com stats.g.doubleclick.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paymetric.com *.klevu.com *.ksearchnet.com bam.nr-data.net region1.google-analytics.com rum-collector-2.pingdom.net bat.bing.net petedge.attn.tv events.attentivemobile.com https://region1.analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.kueskipay.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sandbox.paypal.com *.paypalobjects.com landofcoder.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar gnc.com.mx *.gnc.com.mx *.mercadopago.com.mx *.google.com.mx *.bing.com *.clarity.ms https://cdn.aplazo.mx/ assets.instantsearchplus.com *.akamaized.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sandbox.paypal.com *.paypalobjects.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net cdnjs.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.gstatic.com *.fontawesome.com player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.getblue.io *.scarabresearch.com *.facebook.net *.appspot.com *.convertexperiments.com *.clarity.ms *.hotjar.com *.zdassets.com *.survicate.com *.recapture.io *.bing.com *.tiktok.com *.zendesk.com wss://widget-mediator.zopim.com/ https://api.aplazo.net https://posbifrost.aplazo.net https://api.aplazo.mx https://posbifrost.aplazo.mx js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com https://cdn.recapture.io landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.google.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.cdnfonts.com *.fastsimon.com assets.braintreegateway.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.doubleclick.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fastsimon.com *.scarabresearch.com *.zdassets.com *.zendesk.com *.zopim.com *.clarity.ms *.tiktok.com wss://widget-mediator.zopim.com/ *.hotjar.com *.googleapis.com https://api.aplazo.net https://posbifrost.aplazo.net https://api.aplazo.mx https://posbifrost.aplazo.mx api.instantsearchplus.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com https://app.recapture.io landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: google.com https://affiliates.baptistchart.com pay.instamed.com;script-src 'nonce-fd31d0045dd14da0bf942ff9ab8f92ae' https://my.baptistchart.com 'self';img-src https://* 'self' blob: data: google.com https://affiliates.baptistchart.com;connect-src 'self' epichttp: google.com https://affiliates.baptistchart.com https://www.google.com;style-src https://my.baptistchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self' google.com https://affiliates.baptistchart.com;media-src https://* 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.katapult.com *.klevu.com *.ksearchnet.com *.fontawesome.com data: v2.zopim.com js.klevu.com static.klaviyo.com *.wistia.com maxcdn.bootstrapcdn.com fonts.yieldify-production.com acsbapp.com *.hotjar.com *.nudgify.com fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.rainforestpay.com *.cardinalcommerce.com *.authorize.net *.splitit.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.katapult.com d.agkn.com *.vibe.co *.paytomorrow.com vimeo.com *.doubleclick.net *.trustpilot.com *.paypalobjects.com *.wistia.net *.sharethis.com *.zendesk.com *.zdassets.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.adroll.com *.attn.tv *.yieldify.com *.kaptcha.com *.sirv.com *.nudgify.com *.gstatic.com *.stripe.com *.rainforestpay.com *.cardinalcommerce.com *.authorize.net *.splitit.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.katapult.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://* vimeo.com bat.bing.com js.klevu.com *.klaviyo.com v2.zopim.com maps.googleapis.com *.doubleclick.net *.wistia.com *.attn.tv *.nudgify.com *.paytomorrow.com *.splitit.com *.amazonaws.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://static.addtoany.com/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.katapult.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.kaptcha.com *.disqus.com *.visualwebsiteoptimizer.com *.mida.so *.omniconvert.com *.convertexperiments.com *.metrics.convertexperiments.com *.vibe.co *.cometlytrack.com *.alhena.ai *.cookiehub.eu *.redditstatic.com *.wisernotify.com *.liadm.com *.getgobot.com v2.zopim.com static.zdassets.com ekr.zdassets.com widget-mediator.zopim.com *.trustpilot.com bat.bing.com *.klaviyo.com *.doubleclick.net acsbapp.com *.wistia.com *.wistia.net *.steelhousemedia.com *.mouseflow.com *.sharethis.com js-agent.newrelic.com *.zendesk.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.adroll.com www.googleoptimize.com *.yieldify.com *.noibu.com *.lordoftheentertainingostriches.com *.sirv.com *.howuku.com *.usbrowserspeed.com *.clarity.ms *.nudgify.com *.gstatic.com api.wisernotify.com *.userway.org *.dotomi.com *.lab.amplitude.com *.googleapis.com *.parados.ai *.criteo.com rum.hlx.page cdn.routeapp.io https//fonts.googleapis.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com elements.sika.health *.stripe.com *.rainforestpay.com *.authorize.net *.paytomorrow.com *.splitit.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.katapult.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.mida.so *.omniconvert.com *.convertexperiments.com *.metrics.convertexperiments.com *.cookiehub.eu *.wisernotify.com js.klevu.com *.klaviyo.com *.sharethis.com maxcdn.bootstrapcdn.com wss://*.hotjar.com *.nudgify.com *.gstatic.com *.userway.org *.lab.amplitude.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net *.trustpilot.com *.paytomorrow.com *.splitit.com https://statsjs.klevu.com https://js.klevu.com https://medmartonline.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.alhena.ai blob: embedwistia-a.akamaihd.net *.zendesk.com *.zdassets.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://stats.addtoany.com/menu *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.kaptcha.com *.mida.so *.omniconvert.com *.convertexperiments.com *.metrics.convertexperiments.com *.vibe.co *.cometlytrack.com *.alhena.ai *.bugsnag.com *.cookiehub.net *.cookiehub.eu *.redditstatic.com *.reddit.com *.azurewebsites.net *.wisermapp.com *.ip-api.com *.liadm.com *.getgobot.com *.googlesyndication.com *.attentivemobile.com *.klarnacdn.net *.yieldify.com *.dc.yieldify.com *.yieldify-production.com *.zopim.com wss://widget-mediator.zopim.com static.zdassets.com ekr.zdassets.com *.acsbapp.com *.doubleclick.net *.klaviyo.com https://bt.signifyd.com:11103/ *.signifyd.com:11103 *.paypalobjects.com *.wistia.com *.litix.io *.akamaihd.net bat.bing.com *.trustpilot.com *.sharethis.com *.mouseflow.com maps.googleapis.com *.zendesk.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.adroll.com *.lordoftheentertainingostriches.com *.noibu.com wss://*.noibu.com fonts.googleapis.com *.breadgateway.net *.howuku.com *.clarity.ms *.nudgify.com *.gstatic.com api.wisernotify.com dp70uvwpivouv.cloudfront.net *.userway.org *.api.userway.org *.paytomorrow.com *.lab.amplitude.com *.parados.ai *.route.com *.amplitude.com *.criteo.com api.route.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com *.sikahealth.com *.stripe.com *.rainforestpay.com *.authorize.net *.splitit.com *.amazonaws.com logs.browser-intake-datadoghq.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src vimeo.com *.vimeocdn.com *.getbread.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src * 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https:; font-src 'self' https: data:; frame-src 'self' https:; img-src 'self' https: data:; manifest-src 'self' https:; media-src 'self'; worker-src 'self'; frame-ancestors 'self'; 1 font-src *.cloudfront.net *.reviews.io *.reviews.co.uk *.finance-calculator.co.uk *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.sirv.com *.boldr.dev *.typekit.net fonts.gstatic.com d1azc1qln24ryf.cloudfront.net/40686/revsglobal-pr-mod/ d19ayerf5ehaab.cloudfront.net/css/product-widget/fonts/ media.flixcar.com/delivery/ media.flixfacts.com/ data: *.fontshare.com/ *.icomoon.io/ static.klaviyo.com www.smarthomesounds.co.uk data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com/tr/ connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.reviews.io *.reviews.co.uk syndication.twitter.com/ platform.twitter.com/ www.smarthomesounds.co.uk 'self' 'unsafe-inline'; frame-ancestors www.smarthomesounds.co.uk 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.youtube.com/embed/ *.youtube-nocookie.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.googletagmanager.com/ platform.twitter.com *.reviews.io *.reviews.co.uk *.finance-calculator.co.uk *.deko.finance *.dekopay.com *.dekopay.org js.mollie.com www.paypalobjects.com www.google.com/recaptcha/ platform.twitter.com/ syndication.twitter.com/ media.flixcar.com/ td.doubleclick.net player.gotolstoy.com www.smarthomesounds.co.uk 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com i.ytimg.com/ https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ pinterest.com assets.pinterest.com syndication.twitter.com *.cloudfront.net assets.reviews.io/img/ *.reviews.co.uk *.finance-calculator.co.uk *.dekopay.com 'self' data: https://www.mollie.com *.sirv.com *.youtube.com https://dashboard.feedbucket.app stats.g.doubleclick.net www.google.com/ads/ga-audiences www.google.co.uk/ads/ga-audiences www.google.co.uk/pagead/ www.google.nl/ads/ga-audiences www.google.nl/pagead/ s.ytimg.com data: *.smarthomesounds.co.uk data: *.sozowebdesign.com www.gravatar.com/ media.reviews.co.uk/ files.jivosite.com/ d23yuld0pofhhw.cloudfront.net/default/uk/ d23yuld0pofhhw.cloudfront.net/uk/live/en_gb/ platform.twitter.com/ syndication.twitter.com/ abs.twimg.com/ pbs.twimg.com/ ton.twimg.com/ c.bing.com bat.bing.com smarthomesounds.co.uk api.ecologi.com/badges/ d3np41mctoibfu.cloudfront.net/p/images/ https://rt.flix360.com/ media.flixcar.com/ assets-jpcust.jwpsrv.com/ media.flixfacts.com/ *.clarity.ms via.placeholder.com/ logo.flix360.io/ static.elfsight.com phosphor.utils.elfsightcdn.com cdn.jwplayer.com/ bat.bing.net cdn-cookieyes.com www.smarthomesounds.co.uk data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com/ https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ twitter.com platform.twitter.com *.reviews.io widget.reviews.co.uk/ *.finance-calculator.co.uk *.dekopay.com *.avada.io js.mollie.com https://cdnjs.cloudflare.com *.sirv.com player.vimeo.com cdn.feedbucket.app chatapi.helpscout.net *.klaviyo.com js.datadome.co *.google-analytics.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ googleads.g.doubleclick.net/pagead/viewthroughconversion/ google.com/pagead/ *.usersnap.com chimpstatic.com downloads.mailchimp.com mc.us7.list-manage.com code.jivosite.com/ smart11249.pcapredict.com/js/sensor.js services.postcodeanywhere.co.uk platform.twitter.com/ cdn.syndication.twimg.com bat.bing.com qeryz.com/survey/ script.crazyegg.com js-agent.newrelic.com bam.nr-data.net beacon-v2.helpscout.net media.flixcar.com media.flixfacts.com/js/ prod.flixgvid.flix360.io/ media.flixfacts.com/ *.clarity.ms analytics.webgains.io api.webgains.io cdn.jsdelivr.net/npm/@alpinejs/ widget.gotolstoy.com/script.js widget.wickedreports.com static.elfsight.com cdn-cookieyes.com log.cookieyes.com directory.cookieyes.com bat.bing.net bat.bing-int.com www.smarthomesounds.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://static.klaviyo.com *.cloudfront.net *.reviews.io widget.reviews.co.uk/ *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.sirv.com https://cdn.feedbucket.app *.klaviyo.com *.typekit.net fonts.googleapis.com d19ayerf5ehaab.cloudfront.net/css/product-widget/ d1azc1qln24ryf.cloudfront.net/40686/revsglobal-pr-mod/ code.jivosite.com/ data: widget.reviews.co.uk/ services.postcodeanywhere.co.uk platform.twitter.com/ ton.twimg.com/ cdn-images.mailchimp.com/embedcode/ k3v2w4q6.stackpathcdn.com/survey/ media.flixcar.com/ media.flixfacts.com/ *.fontshare.com/ *.icomoon.io/ angus.finance-calculator.co.uk/ www.smarthomesounds.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.sirv.com blob: code.jivosite.com/ beacon-v2.helpscout.net/ media.flixcar.com/ www.smarthomesounds.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk *.finance-calculator.co.uk *.dekopay.com https://get.geojs.io *.avada.io *.sirv.com *.youtube.com blob: dashboard.feedbucket.app cdn.feedbucket.app chatapi.helpscout.net *.klaviyo.com api-js.datadome.co *.google-analytics.com *.analytics.google.com stats.g.doubleclick.net *.googlesyndication.com https://www.google.com/ccm/ google.com/pagead/ bat.bing.com/actionp/ widget.reviews.co.uk/ api-cache.reviews.co.uk/ api.reviews.co.uk/ *.jivosite.com/ services.postcodeanywhere.co.uk qeryz.com/survey/ script.crazyegg.com/ tracking.crazyegg.com/ d3hb14vkzrxvla.cloudfront.net/v1/ beaconapi.helpscout.net/v1/ bam.nr-data.net/events/ *.clarity.ms endpoint1.collection.us2.sumologic.com api.webgains.io media.flixcar.com/ track.wickedreports.com storage.elfsight.com core.service.elfsight.com cdn-cookieyes.com log.cookieyes.com directory.cookieyes.com bat.bing.net bat.bing.com bat.bing-int.com www.smarthomesounds.co.uk 'self' 'unsafe-inline'; child-src www.smarthomesounds.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.smarthomesounds.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.stape.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.staging.flexint.net *.dynamicyield.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.staging.flexint.net *.dynamicyield.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.flexshopper.com *.dynamicyield.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com *.stape.io mcstaging.flex.store *.flexshopper.xyz images.flexshopper.xyz http://images.flexshopper.xyz *.adxcel-ec2.com *.bing.com *.360yield.com *.liadm.com *.media.net *.mediavine.com *.postrelease.com *.criteo.com *.outbrain.com *.pubmatic.com *.revcontent.com *.rubiconproject.com *.sharethrough.com *.smaato.net *.tapad.com *.teads.tv *.tremorhub.com *.clmbtech.com *.tpmn.co.kr *.3lift.com *.yieldmo.com *.emxdgt.com *.1rx.io *.bidswitch.net *.adnxs.com *.mediawallahscript.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.agkn.com *.unrulymedia.com *.crwdcntrl.net *.adsrvr.org *.stickyadstv.com *.imrworldwide.com *.lijit.com *.mathtag.com *.bidr.io *.facebook.net *.facebook.com *.dmxleo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.exponea.com *.osano.com acsbapp.com *.livevox.com *.staging.flexint.net *.flexshopper.com *.flexshopper.xyz *.dynamicyield.com *.bloomreach.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io edge.fullstory.com cdn.segment.com api.segment.io *.steelhousemedia.com *.criteo.com *.listrakbi.com *.ipredictive.com *.liadm.com *.bing.com *.facebook.net *.taboola.com *.impactradius-event.com *.pinimg.com *.googleapis.com *.pinterest.com *.maxmind.com device.maxmind.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.flexshopper.com *.listrakbi.com *.dynamicyield.com maxcdn.bootstrapcdn.com *.googleapis.com *.googletagmanager.com *.stape.io assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.exponea.com *.osano.com *.acsbapp.com *.livevox.com *.flexshopper.com *.flexshopper.xyz *.dynamicyield.com *.bloomreach.com/ *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.stape.io *.fullstory.com cdn.segment.com api.segment.io *.taboola.com *.pinterest.com *.listrakbi.com *.mmapiws.com d-ipv6.mmapiws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com upstream.heidipay.com sbx-upstream.heidipay.io *.klarnacdn.net *.fontawesome.com applepay.cdn-apple.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.vieffetrade.com *.livechatinc.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com storage.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.vieffetrade.com *.livechatinc.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com upstream.heidipay.com sbx-upstream.heidipay.io *.klarna.com *.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.vieffetrade.com 'unsafe-inline' data: widget.trustpilot.com cdn.iubenda.com cs.iubenda.com cdn.jsdelivr.net *.livechatinc.com *.payplug.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.network *.stripecdn.com *.amazon.com *.vieffetrade.com *.livechatinc.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com upstream.heidipay.com sbx-upstream.heidipay.io *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.stripe.com klarna.com *.link.com *.amazon.com *.vieffetrade.com idb.iubenda.com widget.trustpilot.com *.livechatinc.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.it https://www.myheritage.it 'unsafe-eval' 'nonce-7427a332a7ea013ddae6ee3d6baf55be' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.it;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.braintreegateway.com https://*.google.com https://*.cdn-apple.com https://*.reviews.io https://*.reviews.co.uk https://grwapi.net https://*.cloudflare.com https://*.jquery.com https://*.jsdelivr.net https://*.termly.io https://*.gstatic.com https://*.facebook.net https://*.googletagmanager.com https://*.google-analytics.com https://*.gumlet.com https://*.cardinalcommerce.com https://*.doubleclick.net https://*.googleadservices.com https://*.paypal.com https://*.paypalobjects.com https://*.pcapredict.com https://*.postcodeanywhere.co.uk https://where-to-buy.co https://*.where-to-buy.co https://*.pricespider.com; style-src 'self' 'unsafe-inline' data: https://grwapi.net https://*.reviews.io https://*.braintreegateway.com https://*.cloudflare.com https://*.jsdelivr.net https://*.googleapis.com https://*.google.com https://*.gstatic.com https://*.tooled-up.com https://*.postcodeanywhere.co.uk; img-src 'self' data: blob: https://grwapi.net https://*.tooled-up.com https://*.gumlet.com https://*.paypal.com https://*.paypalobjects.com https://*.facebook.com https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://*.google.co.uk https://*.googlesyndication.com https://*.doubleclick.net https://*.googleadservices.com https://*.reviews.io https://*.gstatic.com https://*.postcodeanywhere.co.uk https://*.ytimg.com https://*.where-to-buy.co https://where-to-buy.co; frame-src 'self' https://*.reviews.io https://*.youtube.com https://*.braintreegateway.com https://*.googletagmanager.com https://*.google.co.uk https://*.google.com https://*.termly.io https://*.doubleclick.net https://*.facebook.com https://*.cardinalcommerce.com https://*.paypal.com https://*.reviews.co.uk https://*.youtube-nocookie.com https://*.americanexpress.com https://*.rsa3dsauth.co.uk https://*.pricespider.com; connect-src 'self' https: wss:; font-src 'self' data: https://*.reviews.io https://*.cloudflare.com https://*.jsdelivr.net https://*.gstatic.com; report-uri https://www.tooled-up.com/api/csp-report; report-to csp-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apexmagnets.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apexmagnets.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com www.apexmagnets.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apexmagnets.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com validate.fishpig.co.uk flagpedia.net www.apexmagnets.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apexmagnets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com www.apexmagnets.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apexmagnets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apexmagnets.com 'self' 'unsafe-inline'; child-src www.apexmagnets.com http: https: blob: 'self' 'unsafe-inline'; default-src custom.intucdn.com www.apexmagnets.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.facebook.net https://connect.facebook.net https://app.termly.io https://tracking.recommend.pro https://js.klevu.com https://foursixty.com https://loader.wisepops.com https://wisepops.net https://wisepops.com https://*.wisepops.com https://*.hotjar.com https://*.trackedweb.net https://*.trackedlink.net https://*.googlesyndication.com https://pay.google.com https://static.zdassets.com https://track.sweetanalytics.com https://www.dwin1.com https://lantern.roeyecdn.com https://*.pcapredict.com https://services.postcodeanywhere.co.uk https://www.paypal.com https://www.paypalobjects.com https://googleads.g.doubleclick.net https://static.cloudflareinsights.com https://*.dotdigital-pages.com https://*.awin1.com https://www.awinblackfriday.com https://the.sciencebehindecommerce.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://js.klevu.com https://foursixty.com https://cdn.jsdelivr.net https://services.postcodeanywhere.co.uk https://www.gstatic.com; img-src 'self' data: blob: https://www.paypalobjects.com https://www.facebook.com https://*.google.com https://*.google.co.uk https://*.google.fr https://*.google.ca https://*.google.com.au https://*.doubleclick.net https://googleads.g.doubleclick.net https://www.googletagmanager.com https://www.googleadservices.com https://*.penelopechilvers.co.uk https://js.klevu.com https://cdn.jsdelivr.net https://*.gstatic.com https://fonts.gstatic.com https://penelopechilvers.com https://track.sweetanalytics.com https://lantern.roeye.com https://t.paypal.com https://services.postcodeanywhere.co.uk https://*.adyen.com https://www.zenaps.com https://scontent.cdninstagram.com https://foursixty.com https://*.facebook.net https://*.wisepops.com https://*.trackedlink.net https://tracking.recommend.pro https://pagead2.googlesyndication.com https://track.linksynergy.com https://*.awin1.com https://www.awinblackfriday.com https://www.youtube.com; connect-src 'self' https://*.google.com https://google.com https://*.googleapis.com https://*.googleadservices.com https://*.googlesyndication.com https://*.doubleclick.net https://googleads.g.doubleclick.net https://app.termly.io https://tracking.recommend.pro https://foursixty.com https://metrics.foursixty.com https://wisepops.net https://wisepops.com https://*.wisepops.com https://capig.stape.de https://*.trackedweb.net https://*.trackedlink.net https://www.facebook.com https://ekr.zdassets.com https://penelopechilvershelp.zendesk.com https://track.sweetanalytics.com wss://widget-mediator.zopim.com wss://ws.hotjar.com https://*.ksearchnet.com https://*.sentry.io https://*.adyen.com https://services.postcodeanywhere.co.uk https://*.google-analytics.com https://*.consent.api.termly.io https://*.hotjar.io https://www.wepowerconnections.com https://the.sciencebehindecommerce.com https://www.awinblackfriday.com https://www.paypal.com; font-src 'self' https://fonts.gstatic.com https://js.klevu.com https://penelopechilvers.com data:; object-src 'none'; media-src 'self' https://static.zdassets.com blob:; frame-src 'self' https://www.googletagmanager.com https://*.cloudflarestream.com https://pay.google.com https://www.facebook.com https://*.adyen.com https://*.dotdigital-pages.com https://*.awin1.com https://www.youtube.com https://www.youtube-nocookie.com; worker-src 'self' blob:; report-uri /csp-violations; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com static.klaviyo.com fonts.gstatic.com *.newrelic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.newrelic.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com bat.bing.com *.newrelic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com apis.google.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com js.klevu.com *.ksearchnet.com *.kaptcha.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com fonts.googleapis.com bat.bing.com *.newrelic.com *.google.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.certcapture.com https://static.klaviyo.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.newrelic.com *.google.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.kaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.doubleclick.net *.nr-data.net *.newrelic.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com *.newrelic.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com api.payplug.com secure.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cdn.jsdelivr.net https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.getalma.eu https://nominatim.openstreetmap.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'nonce-xqFUsTX7V+BzBuT9Dmp4gVNP' 'unsafe-eval' https://cdn.cookielaw.org https://*.googletagmanager.com http://jsi-cdn.steelcentral.net;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.googletagmanager.com;img-src 'self' http://tsys.d2.sc.omtrdc.net http://beacons.apm.my.aternity.com https://*.google-analytics.com https://*.googletagmanager.com blob: data:;font-src 'self' https://fonts.gstatic.com data:;connect-src 'self' https://cdn.cookielaw.org https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com;report-uri /Centre/Public/CspReporter/Report 1 default-src 'self'; child-src 'none'; object-src 'none'; script-src http: https: 'strict-dynamic' 'nonce-CkaqS+opCES4FZ2Ufs4xF1w/Iv7MJ3LnZBa/5k0wXLw='; connect-src 'self' https://vitruv.uni-tuebingen.de https://services.dnb.de; worker-src blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: http://*.tile.osm.org https://*.tile.osm.org https://services.dnb.de; font-src 'self'; base-uri 'self'; frame-src 'self'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.no https://www.myheritage.no 'unsafe-eval' 'nonce-ad67b4093fa42f75af7611bf90f3f94b' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.no;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 script-src 'unsafe-inline' 'unsafe-eval' https:; style-src * 'unsafe-inline' 'unsafe-eval'; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; frame-ancestors 'self'; report-to br.loccitaneaubresil.com; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self'; media-src 'self'; object-src 'none'; frame-src 'self'; frame-ancestors 'self'; form-action 'self'; base-uri 'self' 1 default-src 'self'; script-src 'self' 'unsafe-eval' https://www.youtube.com https://*.wistia.com https://*.wistia.net https://*.org.coveo.com https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://mychart.chw.org https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; script-src-elem 'self' 'unsafe-inline' https://www.youtube.com https://*.wistia.com https://*.wistia.net https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://browser.sentry-cdn.com https://mychart-np.et0815.epichosted.com https://mychart.chw.org https://www.google.com https://www.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://*.addtoany.com https://my-symptom.appcatalyst.com https://*.contentsquare.net https://*.heap-api.com https://*.calltrk.com https://elearning.childrenswi.org https://fonts.googleapis.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; style-src 'self' 'unsafe-inline' https://*.sitecorecloud.io https://mychart.chw.org https://cdn.jsdelivr.net https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://elearning.childrenswi.org https://fonts.googleapis.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://www.youtube.com https://*.sitecorecloud.io https://*.wistia.com https://*.wistia.net https://*.org.coveo.com https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://cw-sp-collector.modea.com https://mychart.chw.org https://cdn.jsdelivr.net https://ipapi.co https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://*.litix.io https://*.contentsquare.net https://*.heap-api.com https://js.calltrk.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; frame-src 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://www.youtube.com https://mychart.chw.org https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://mychart.chw.org; frame-ancestors 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://*.sitecorecloud.io http://localhost:3000 https://mychart.chw.org https://*.xealth.io; media-src 'self' https: data: blob:; object-src 'none'; base-uri 'self'; form-action 'self'; worker-src 'self' blob:; manifest-src 'self'; report-to csp-endpoint; report-uri https://childrenswi.org/api/csp-report/xt2c9f8er8 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' abcdaconstrucao.com.br *.abcdaconstrucao.com.br wake-components.fbitsstatic.net abcdaconstrucao.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.ebit.com.br *.moz.com *.googleadservices.com *.btg360.com.br *.clearsale.com.br *.targeting.voxus.com.br cdn.targeting.voxus.com.br api.ipify.org api.voxus.tv *.loggly.com *.voxus.com.br targeting.voxus.tv *.google.com.br google-analytics.com *.google-analytics.com *.googleapis.com storage.googleapis.com *.googletagmanager.com *.g.doubleclick.net *.criteo.net *.criteo.com *.plataformasocial.com.br *.lomadee.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.*hotjar.com *.hotjar wss://ws4.hotjar.com wss://ws1.hotjar.com wss://ws2.hotjar.com wss://ws3.hotjar.com wss://ws5.hotjar.com wss://ws6.hotjar.com wss://ws7.hotjar.com wss://ws8.hotjar.com wss://ws9.hotjar.com wss://ws10.hotjar.com wss://ws11.hotjar.com wss://ws12.hotjar.com wss://ws13.hotjar.com wss://ws14.hotjar.com wss://ws15.hotjar.com wss://ws16.hotjar.com wss://ws17.hotjar.com wss://ws18.hotjar.com wss://ws19.hotjar.com connect.facebook.net static.fbits.net *.segment.com *.securiti.ai *.pingdom.net *.clarity.ms *.1rocket.io *.dito.com.br *.segment.io *.abcdaconstrucao.com.br produtos.abcdaconstrucao.com.br produtos.devabc.com.br *.marketingautomation.services *.getblue.io dzpxyxks1bfmb.cloudfront.net *.digitalabc.com.br *.gstatic.com gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net maps.googleapis.com samuraiexpertsstorage.blob.core.windows.net ameprod.azurewebsites.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com checkout.abcdaconstrucao.com.br *.tiktok.com *checkout.abcdaconstrucao.com.br *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.abcevoce.com.br *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io leadwake.br-s1.cloudhub.io cdn.jsdelivr.net *.3dsecure.io viacep.com.br *.visa.com *.hkdk.events *.wake.tech hkdk.events *.goadopt.io axeptio-api.goadopt.io *.unpkg.com *.amazonaws.com *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.abcdaconstrucao.com.br abcdaconstrucao.com.br; report-uri https://pub-csp.fbits.net/cbdf2c53-455c-4353-aa2e-973fcc2a5f0e; report-to https://pub-csp.fbits.net/cbdf2c53-455c-4353-aa2e-973fcc2a5f0e; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.facebook.net *.twimg.com *.hotjar.com *.trustedshops.com *.googleapis.com *.magentocommerce.com *.paypal.com *.cardinalcommerce.com *.authorize.net *.fontawesome.com https://fonts.bunny.net *.mncdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.twitter.com *.gstatic.com *.hotjar.com *.google.com.tr *.veinteractive.com *.demdex.net *.solocpm.com *.facebook.com *.facebook.net *.addthis.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.doubleclick.net *.bluekai.com *.useinsider.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.hotjar.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.doubleclick.net *.google.com *.google.com.tr *.facebook.com *.facebook.net *.demdex.net *.everesttech.net *.googleapis.com *.adis.ws *.livechatinc.com *.yandex.ru *.adyen.com *.setrowid.com *.setrow.com *.instagram.com *.useinsider.com *.googletagmanager.com https://firebasestorage.googleapis.com *.mncdn.com *.mobilexpress.com.tr *.google.nl *.google.be *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.magentocommerce.com *.paypal.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.instana.io *.google.com.tr *.googletagmanager.com *.veinteractive.com *.facebook.net *.supert.ag *.setrowid.com *.mainadv.com *.doubleclick.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.jsdelivr.net *.setrow.com *.instagram.com *.criteo.com *.criteo.net *.ciritizr.com *.bkrtx.com *.cloudfront.net *.useinsider.com *.critizr.com *.behance.net *.swagger.io *.avada.io *.shopify.com *.mncdn.com *.mobilexpress.com.tr *.segmentify.com *.sgmntfy.com *.cookiespool.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.jquery.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com *.adform.net s2.adform.net track.adform.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.facebook.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.magentocommerce.com *.fontawesome.com *.paypal.com *.paypalobjects.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.setrowid.com *.setrow.com *.critizr.com *.useinsider.com *.adobedtm.com *.google-analytics.com *.googletagmanager.com *.swagger.io https://fonts.bunny.net *.mncdn.com *.google.com *.jsdelivr.net *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com *.yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.google.com *.jsdelivr.net *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com *.yandex.ru yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com vicco-videos.lg.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com *.google-analytics.com *.doubleclick.net *.twitter.com *.facebook.com *.facebook.net *.paypalobjects.com *.hotjar.com *.hotjar.io *.twimg.com *.magentocommerce.com *.cardinalcommerce.com *.cardinalcommerce.net *.veinteractive.com *.demdex.net *.yandex.ru *.vimeo.com *.setrowid.com *.setrow.com *.useinsider.com *.adobedtm.com *.swagger.io https://get.geojs.io *.avada.io *.segmentify.com *.sgmntfy.com *.googleapis.com *.cookiespool.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.gelproximity.com *.hipay-tpp.com *.hipay.com *.paypal.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.openstreetmap.org *.salesmanago.pl *.salesmanago.es *.salesmanago.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com unpkg.com commerce.adobedtm.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.gelproximity.com *.hipay.com *.hipay-tpp.com https://mpsnare.iesnare.com *.zdassets.com *.newrelic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com mpsnare.iesnare.com *.paypal.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com widget.freshworks.com m2epro.freshdesk.com *.hipay.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.zdassets.com data: mpsnare.iesnare.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com commerce.adobedtm.com commerce.adobedc.net *.snplow.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.zendesk.com *.zdassets.com *.zopim.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; media-src 'self' https://stream.klgd.ru rtmp://stream.klgd.ru https://wowza.klgd.ru https://cctv.klgd.ru 1 default-src 'self' https: data: blob:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: blob: https:; font-src 'self' data: https:; frame-src 'self' https:; connect-src 'self' data: blob: https: wss:; media-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self'; report-uri https://napi.jumbomail.me/api/reports/csp-report; 1 report-uri /api/csp 1 default-src 'self' sunpower.okta.com login.mysunpower.com *.oktacdn.com; connect-src 'self' sunpower.okta.com sunpower-admin.okta.com login.mysunpower.com *.oktacdn.com *.mixpanel.com *.mapbox.com sunpower.kerberos.okta.com sunpower.mtls.okta.com https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' sunpower.okta.com login.mysunpower.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' sunpower.okta.com login.mysunpower.com *.oktacdn.com; frame-src 'self' sunpower.okta.com sunpower-admin.okta.com login.mysunpower.com login.okta.com *.vidyard.com; img-src 'self' sunpower.okta.com login.mysunpower.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' sunpower.okta.com login.mysunpower.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://sds.mysunpower.com https://eddie.mysunpower.com 1 font-src *.googleapis.com *.gstatic.com data: use.typekit.net www.google.com www.google.by unpkg.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.merchante-solutions.com https://hostedpayments.merchante.com https://merchantacsstag.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.ca-dev.co *.chargeafter.com www.google.com https://elements.sandbox.fortis.tech https://elements.fortis.tech https://merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://cdn-sandbox.ca-dev.co https://cdn.chargeafter.com *.gstatic.com *.googleapis.com *.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.files-text.com www.google.by www.facebook.com *.godaddy.com *.bing.net *.omappapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn-sandbox.ca-dev.co https://cdn.chargeafter.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com https://developer.adobe.com https://magento.com https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.omappapi.com a.opmnstr.com api.chargeafter.com seal.godaddy.com connect.facebook.net *.callrail.com *.livechatinc.com wss://*.livechatinc.com client.prod.mplat-ppcprotect.com *.searchspring.net snapui.searchspring.io app.termly.io www.clarity.ms *.prod.equally.ai 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.typekit.net a.omappapi.com unpkg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.ca-dev.co *.chargeafter.com *.googleapis.com https://developer.adobe.com https://elements.sandbox.fortis.tech https://elements.fortis.tech https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com https://writer.cardinalcommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com logging-proxy-ca-production-170512-af60esna.uc.gateway.dev *.omappapi.com *.gateway.dev js.callrail.com click.prod.mplat-ppcprotect.com app.termly.io 9vbqsm.a.searchspring.io d.clarity.ms app.callrail.com wss://*.livechatinc.com *.bing.net *.livechatinc.com *.doubleclick.net *.googlesyndication.com *.prod.equally.ai *.consent.api.termly.io xoksmy.a.searchspring.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src fanatics.live *.fanatics.live stream-io-api.com *.stream-io-api.com 'self' wss: https://os.fanatics.live https://*.fanatics.live *.live-video.net https://websdk.appsflyer.com https://sdk.split.io https://streaming.split.io https://auth.split.io https://events.split.io https://sdk.iad-05.braze.com https://cdn.segment.com https://api.segment.io https://www.googletagmanager.com https://connect.facebook.net https://*.google-analytics.com https://td.doubleclick.net/ https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://us1.browser-intake-datadoghq.com https://us3.browser-intake-datadoghq.com https://us5.browser-intake-datadoghq.com https://datadoghq.com https://*.datadoghq.com https://*.livekit.cloud https://*.cloudfront.net https://*.amazonaws.com/web-prod-assets-0l9t/ https://*.amazonaws.com/web-staging-assets-0l9t/ https://*.amazonaws.com/fl-application-assets/ https://*.amazonaws.com/fl-application-asset/ https://d2wpy28tlhnoxg.cloudfront.net/media_convert https://google.com https://www.google.com/ccm/collect https://*.appsflyer.com https://fanatics.live/api/auth/session https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://ekr.zdassets.com https://fanaticslive.zendesk.com https://unpkg.com https://cdn.jsdelivr.net https://cdn.cookielaw.org/ https://*.onetrust.com https://*.rive.app fonts.googleapis.com *.fonts.googleapis.com marker.io *.marker.io sentry.io *.sentry.io fullstory.com *.fullstory.com stripe.com *.stripe.com tiktok.com *.tiktok.com https://chat-insights.getstream.io; default-src fanatics.live *.fanatics.live fonts.googleapis.com *.fonts.googleapis.com fullstory.com *.fullstory.com google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com zdassets.com *.zdassets.com stripe.com *.stripe.com stream-io-api.com *.stream-io-api.com sentry.io *.sentry.io marker.io *.marker.io live-video.net *.live-video.net 'self' https://cdn.jsdelivr.net 'unsafe-inline'; font-src https://fonts.gstatic.com/* https://fonts.gstatic.com fanatics.live *.fanatics.live jsdelivr.net *.jsdelivr.net https://cdn.jsdelivr.net; frame-src 'self' https://js.stripe.com/ https://td.doubleclick.net https://www.google.com/ https://odyssey.dev.fanatics.live/ https://odyssey.staging.fanatics.live/ https://odyssey.fanatics.live/ https://www.googletagmanager.com https://use.fontawesome.com https://fonts.googleapis.com https://cdn.appsflyer.com/; frame-ancestors https://docs.fanatics.live https://topps.com https://*.topps.com/ https://*.vercel.app/ https://*.dacwdev.com/ https://*.dacardworld.com/ https://*.wweshop.com/ https://*.wweshop.com https://shop.wwe.com https://*.wwe.com https://ufcstore.com https://*.ufcstore.com https://ufc.com https://*.ufc.com; img-src * blob: 'self' data:; media-src * blob:; script-src 'self' 'sha256-6EL/zz29Q8UFwqahdj1cGAxqbH5Xd+he4QVXaoQno44=' https://cdn.segment.com https://js.stripe.com https://js.appboycdn.com https://sdk.iad-05.braze.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com/recaptcha/ https://*.datadoghq-browser-agent.com https://static.zdassets.com https://pod-29.zendesk.com https://*.fullstory.com https://cdn.cookielaw.org/ https://*.onetrust.com https://analytics.tiktok.com 'unsafe-eval' marker.io *.marker.io live-video.net *.live-video.net fanatics.live *.fanatics.live 'unsafe-inline'; worker-src 'self' blob: https://*.datadoghq.com https://*.datadoghq-browser-agent.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=IzMWqKFxReWEOrZxThPVLH3gujQo6tnJawDyuiFbVgI-1765940053-1.0.1.1-V2RXWJc1IEgLtY2sGr3y1gT6vcCKWcoEKB6zOsnQdbIwIbNvjAv3CUWvBeir8FD0ahpPQC8Ap5JQY5TNrWlRY9B9UrBhFWKTIkRleDZuw5i1DjwXlv0iWE66mAlB0lQqNLUKoh2Lcdv4vDPaGmiMRALYtH8nWpFPntV6Wgx9HvYqQM1ty5WnkcCKbP2wzYeq_ZbehKGw9nmtOijzK1sn_w; report-to cf-peqjtndobwglwczu 1 default-src 'self'; script-src 'self' 'nonce-5n52EUSQF99ISok0kUmNzg==' 'strict-dynamic' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://use.typekit.net https://fast.wistia.net; img-src 'self' data: blob: *.simmons-simmons.com https://images.contentstack.io https://assets.contentstack.io *.google-analytics.com *.googletagmanager.com https://c.bing.com https://c.clarity.ms *.clarity.ms *.wistia.com *.wistia.net https://cdn.heapanalytics.com https://heapanalytics.com https://px.ads.linkedin.com *.typekit.net *.buzzsprout.com; font-src 'self' https://fast.wistia.com https://fonts.gstatic.com https://use.typekit.net data:; connect-src 'self' *.simmons-simmons.com *.litix.io https://px.ads.linkedin.com https://images.contentstack.io https://assets.contentstack.io *.contentstack.io *.contentstack.com *.google-analytics.com *.googletagmanager.com *.clarity.ms *.sentry.io https://sentry.io *.sentry-cdn.com https://heapanalytics.com https://cdn.heapanalytics.com *.licdn.com *.wistia.com *.woopra.com *.mixpanel.com wss://*.clarity.ms https://www.google.com; frame-src 'self' https://www.google.com *.simmons-simmons.com https://sites-simmons-simmons.vuturevx.com https://cdn.yoshki.com *.wistia.com https://fast.wistia.com *.lightwidget.com *.buzzsprout.com *.youtube.com *.vimeo.com; media-src 'self' blob: https://assets.contentstack.io; frame-ancestors 'none'; base-uri 'self'; object-src 'none'; form-action 'self' *.simmons-simmons.com; upgrade-insecure-requests; report-uri https://api.simmons-simmons.com/health/csp-report 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com https://cdn.checkout.com images.getfastr.com https://fonts.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://js.checkout.com *.klarna.com consentcdn.cookiebot.com consentcdn.cookiebot.eu https://*.cylindo.com/ ls.smct.io td.doubleclick.net d2d7do8qaecbru.cloudfront.net ct.pinterest.com edigitalsurvey.com sst.heals.com https://*.fixtuur.io/ https://*.digitalbridgehq.com blob: intent: https://www.googletagmanager.com/ https://www.google.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com imgsct.cookiebot.com imgsct.cookiebot.eu https://*.cylindo.com/ links.imagerelay.com images.getfastr.com gis.goinstore.com bat.bing.com c.az.contentsquare.net www.google.com.ua ad.doubleclick.net adservice.google.com sp.analytics.yahoo.com insight.adsrvr.org assets.reviews.io heals.content.fixtuur.io services.postcodeanywhere.co.uk js.checkout.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com https://www.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.checkout.com *.klarnacdn.net consent.cookiebot.com consent.cookiebot.eu https://*.cylindo.com/ heals-1.store-uk1.advancedcommerce.services cas.zma.gs static.klaviyo.com static-tracking.klaviyo.com gis.goinstore.com sdk.fixtuur.io cdn.shipup.co cdn.usehero.com consentcdn.cookiebot.com s.pinimg.com smct.co t.contentsquare.net bat.bing.com analytics.webgains.io cdn.sub2tech.com assets.gocertify.me js.smct.io js-agent.newrelic.com ct.pinterest.com uk005.sub2tech.com s.yimg.com sm001.sub2tech.com viewer.cylindo.com scripts.sirv.com uk002.sub2tech.com www.google.com static-na.payments-amazon.com www.gstatic.com services.postcodeanywhere.co.uk cdn.checkout.com https://*.fixtuur.io/ https://*.digitalbridgehq.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com https://*.cylindo.com/ cdn.shipup.co widget.reviews.io assets.reviews.io gis.goinstore.com viewer.cylindo.com scripts.sirv.com js.checkout.com https://static.klaviyo.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://js.checkout.com *.klarnaevt.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu https://*.cylindo.com/ analytics.google.com sst.heals.com cas.zma.gs fast.a.klaviyo.com static-forms.klaviyo.com eu.prd.impact.fixtuur.com ct.pinterest.com ep.smct.co k-eu1.az.contentsquare.net api.usehero.com c.az.contentsquare.net srm.aa.contentsquare.net bam.nr-data.net s.yimg.com adservice.google.com api.reviews.io heals.content.fixtuur.io stats.sirv.com www.google-analytics.com services.postcodeanywhere.co.uk js.checkout.com fpjs.checkout.com risk.checkout.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com k-eu1.az.contentsquare.net c.az.contentsquare.net bam.nr-data.net www.google.com google.com stats.sirv.com heals-1.tracking-uk1.advancedcommerce.services www.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://349fdf52-472e-46ad-8c8c-5e785e5026a3.sansec.watch/; report-to report-endpoint; 1 script-src-elem data: 'self' 'unsafe-inline' 'report-sample' 'unsafe-eval' https://web-sdk.aptrinsic.com https://s7.addthis.com https://static.hotjar.com https://script.hotjar.com https://host.hotjar.com https://www.google.com https://assets.adobedtm.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://analytics.google.com https://www.googletagmanager.com https://www.googleapis.com https://*.newrelic.com https://*.nr-data.net https://geostag.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://geoapi.cardinalcommerce.com https://1eafapi.cardinalcommerce.com https://songbird.cardinalcommerce.com https://www.paypal.com https://www.sandbox.paypal.com https://www.paypalobjects.com https://t.paypal.com https://vimeo.com https://www.vimeo.com https://*.vimeocdn.com https://*.youtube.com https://use.typekit.net https://*.typekit.net https://*.magento-ds.com https://*.cloudflare.com https://*.gstatic.com https://js.braintreegateway.com https://assets.braintreegateway.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://checkout.razorpay.com https://*.facebook.net https://*.avada.io; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.cloudflare.com maxcdn.bootstrapcdn.com https://maxcdn.bootstrapcdn.com/ https://maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com 'self' data: play.google.com api.razorpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net https://cm.everesttech.net https://*.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://*.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' https://www.magecomp.com https://assets.adobedtm.com https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://widgets.magentocommerce.com https://www.googleadservices.com https://www.google.co.in https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://bid.g.doubleclick.net https://analytics.google.com https://www.googletagmanager.com https://*.ftcdn.net https://*.behance.net https://www.paypal.com https://www.paypalobjects.com https://fpdbs.paypal.com https://fpdbs.sandbox.paypal.com https://*.vimeocdn.com https://p.typekit.net https://*.gstatic.com https://validator.swagger.io https://cdn.razorpay.com https://*.facebook.com https://firebasestorage.googleapis.com https://assets.braintreegateway.com https://checkout.paypal.com cdn.razorpay.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ 'self' data: 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.cloudflare.com https://static.hotjar.com https://script.hotjar.com https://assets.adobedtm.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com tagmanager.google.com https://*.facebook.net https://js.braintreegateway.com https://checkout.razorpay.com checkout.razorpay.com *.googletagmanager.com *.facebook.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' data: 'report-sample' *.cloudflare.com https://maxcdn.bootstrapcdn.com https://www.bunnycart.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com 'self' data: *.hotjar.io wss://ws.hotjar.com https://*.hotjar.io https://*.facebook.com https://www.facebook.com https://www.facebook.com/*/ https://lumberjack-cx.razorpay.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; connect-src 'self' https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'none'; frame-src https://www.google.com; img-src 'self' https://www.google-analytics.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'report-sample' 'self' https://s.go-mpulse.net https://www.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'report-sample' 'self' https://fonts.googleapis.com; worker-src 'none' 1 font-src data: fonts.gstatic.com *.fontawesome.com https://fonts.gstatic.com *.gstatic.com 'self' data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.doubleclick.net td.doubleclick.net https://*.moneris.com/ www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com track.hubspot.com servedbyadbutler.com img.youtube.com www.facebook.com www.google.co.in twin-iq.kickfire.com ad.doubleclick.net c.clarity.ms c.bing.com maps.googleapis.com store.paradoxlabs.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.pixriot.com *.storeimaging.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.hotjar.com js.hs-banner.com js.hs-scripts.com js.hs-analytics.net servedbyadbutler.com js.hscollectedforms.net js.hubspot.com js.hsadspixel.net tracker.gaconnector.com www.clarity.ms tag.simpli.fi twin-iq.kickfire.com js.usemessages.com https://*.moneris.com/ *.avada.io *.hsforms.net *.hsforms.com *.google.com *.gstatic.com maps.googleapis.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.moneris.com/ *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com stats.g.doubleclick.net maps.googleapis.com www.google.com *.hotjar.com cta-service-cms2.hubspot.com forms.hscollectedforms.net api.hubapi.com api.hubspot.com wss://ws.hotjar.com *.hotjar.io *.clarity.ms www.facebook.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com www.googleapis.com *.pixriot.com *.storeimaging.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-NQzCK2LSk4szhicRboQKwm00SoE=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; script-src 'self' ajax.cloudflare.com; 1 frame-ancestors 'self'; report-uri https://www.townsvillebulletin.com.au/csp-reports 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ccavenue.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.ccavenue.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.ccavenue.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.ccavenue.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.ccavenue.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com fonts.googleapis.com *.gstatic.com 'self' data: https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.klaviyo.com https://cdn.icomoon.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.reviews.io *.reviews.co.uk *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.reviews.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ magento-cloudflare.jetrails.com *.reviews.io *.reviews.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://app-wallee.com *.criteo.com *.facebook.com ct.pinterest.com int.post.ch www.post.ch/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ytimg.com *.cloudfront.net *.reviews.io *.reviews.co.uk magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://app-wallee.com *.hsforms.net *.hsforms.com 'self' data: *.360yield.com *.3lift.com *.adform.net *.adnxs.com *.angela-bruderer.ch *.bidswitch.net *.casalemedia.com *.criteo.com *.doubleclick.net *.facebook.com *.google.de *.id5-sync.com id5-sync.com *.ivitrack.com *.krxd.net *.media.net *.mediavine.com *.omnitagjs.com *.outbrain.com *.praktikus.ch *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.smartclip.net *.taboola.com *.tdintern.de *.teads.tv *.thebrighttag.com *.tremorhub.com *.twiago.com *.yahoo.com *.yieldlab.net *.yieldmo.com *.usercentrics.eu *.cloudflareaccess.com *.emxdgt.com *.1rx.io *.unrulymedia.com wheelioapp.azureedge.net *.wheelio-app.com dealioappstorage.blob.core.windows.net bat.bing.com ct.pinterest.com *.google.ch d3k81ch9hvuctc.cloudfront.net https://trck.spoteffects.net https://dev.visualwebsiteoptimizer.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.luware.cloud *.reviews.io *.reviews.co.uk *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://app-wallee.com https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.cloudflareinsights.com *.criteo.com *.datareporter.eu *.getback.ch *.getsitecontrol.com *.usersnap.com analytics.maileon.com *.usercentrics.eu *.visualwebsiteoptimizer.com wheelioapp.azureedge.net *.wheelio-app.com wheeliofuncstats.azurewebsites.net *.cloudflare.com *.profity.ch *.neocomapp.com *.plugins.emarsys.net *.scarabresearch.com connect.facebook.net *.usernap.com s.pinimg.com bat.bing.com static.profity.ch/ static.klaviyo.com https://static-tracking.klaviyo.com https://analytics.maileon.com angela-bruderer-ag.onlyfy.jobs gtm.adt313.net https://trck.spoteffects.net https://ajax.cloudflare.com https://apis.google.com/js/api.js https://production.neocomapp.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.luware.cloud *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com unsafe-inline assets.braintreegateway.com https://app-wallee.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline' data: *.datareporter.eu wheelioapp.azureedge.net *.wheelio-app.com *.klaviyo.com static.getback.ch static-tracking.klaviyo.com https://cdn.icomoon.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.cloudflareaccess.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.luware.cloud *.service.signalr.net *.cloudfront.net *.reviews.io *.reviews.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://app-wallee.com https://assets.secure.checkout.visa.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.criteo.com *.datareporter.eu *.doubleclick.net *.getsitecontrol.com *.google.de *.bing.com *.getback.ch analytics.maileon.com *.googlesyndication.com *.usercentrics.eu *.visualwebsiteoptimizer.com *.neocomapp.com *.klaviyo.com *.scarabresearch.com *.eservice.emarsys.net region1.analytics.google.com ct.pinterest.com events.getsitectrl.com https://fast.a.klaviyo.com https://static-forms.klaviyo.com https://a.klaviyo.com https://insights.algolia.io *.facebook.com https://dev.visualwebsiteoptimizer.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.luware.cloud *.googleapis.com *.adobe.com *.angela-bruderer.ch *.cloudflareaccess.com *.cloudflareinsights.com *.datareporter.eu *.facebook.com *.mediavine.com *.newrelic.com *.nr-data.net *.omnitagjs.com *.praktikus.ch *.tdintern.de *.tremorhub.com *.yieldlab.net *.getback.ch 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-scripts.com https://*.hscollectedforms.net https://*.hs-banner.com https://*.hubspotusercontent.com https://*.hubspotusercontent-eu1.net https://js.hs-analytics.net https://js.hsforms.net https://api.hsforms.com https://api.hubapi.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hs-web-analytics.net https://static.hsappstatic.net https://cdn2.hubspot.net https://cdn.hubspot.com https://*.cloudfront.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://stats.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org https://www.youtube.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https: data:; connect-src 'self' https: wss: https://www.cadburydessertscorner.com; media-src 'self' https: data: blob:; worker-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self' https://*.hubspot.com; 1 frame-ancestors 'self'; report-uri https://csp.core.anybotics.com/csp-report 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.fi https://www.myheritage.fi 'unsafe-eval' 'nonce-2a23a69a01070246fe3667f450be314d' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.fi;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 base-uri 'none'; default-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://*.youtube.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net cdn.prod.website-files.com assets.website-files.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net cdn.prod.website-files.com assets.website-files.com; img-src 'self' data: *.webflow.io cdn.prod.website-files.com assets.website-files.com d3e54v103j8qbb.cloudfront.net; font-src 'self' fonts.gstatic.com data: cdn.prod.website-files.com assets.website-files.com; connect-src 'self' *.webflow.io analytics.google.com *.analytics.google.com *.google-analytics.com stats.g.doubleclick.net; form-action https:; frame-ancestors 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' blob: *.webflow.io assets.website-files.com *.googletagmanager.com *.google-analytics.com cdn.jsdelivr.net d3e54v103j8qbb.cloudfront.net cdn.prod.website-files.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com https://script.hotjar.com *.algolia.com *.googleapis.com *.bootstrapcdn.com https://*.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.kohlerbycochez.com network-a.bazaarvoice.com maps.gstatic.com *.algolia.com media.flixcar.com rt.flix360.com *.google.com *.google-analytics.com *.googleadservices.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com https://*.bazaarvoice.com https://*.google.com.pa data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://apps.bazaarvoice.com *.kohlerbycochez.com apps.bazaarvoice.com static.hotjar.com script.hotjar.com h.online-metrix.net js-agent.newrelic.com www.google.com www.gstatic.com maps.googleapis.com *.algolia.com media.flixfacts.com media.flixcar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://cdn.jsdelivr.net https://scripts.publitas.com https://view.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com *.algolia.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com videos.pexels.com *.algolia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kohlerbycochez.com bam.nr-data.net maps.googleapis.com https://surveystats.hotjar.io media.flixcar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://*.bazaarvoice.com https://*.hotjar.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net *.kohlerbycochez.com ws.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-cc81e86d3e0e496cad791d7f1ed86da8' https://az-mychart.franciscanalliance.org 'self';img-src https://* 'self' blob: data:;style-src https://az-mychart.franciscanalliance.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com use.typekit.net *.adbr.io *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.cookiebot.com *.adbr.io *.googletagmanager.com *.cookiebot.eu *.criteo.com *.lightwidget.com *.addthis.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.clerk.io *.google.it *.zopim.io *.adbr.io *.adabra.com *.bing.com img.sct.eu1.usercentrics.eu *.clarity.ms *.bidswitch.net *.criteo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.addthisedge.com *.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io *.cookiebot.com *.cookiebot.eu fullstory.com assets.zendesk.com static.zdassets.com cdn.jsdelivr.net *.adbr.io *.cloudflare.com *.reaktion.com *.clerk.io *.bing.com *.criteo.com *.clarity.ms *.lightwidget.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.addthis.com *.moatads.com *.addthisedge.com *.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://cdn.scalapay.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io *.bootstrapcdn.com cdn.jsdelivr.net fonts.gstatic.com fonts.googleapis.com *.typekit.net *.adbr.io https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.cookiebot.com *.g.doubleclick.net *.googlesyndication.com *.zendesk.com *.zopim.com *.zdassets.com wss://widget-mediator.zopim.com *.adbr.io *.reaktion.com *.bing.com *.criteo.com *.clarity.ms *.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.googleapis.com https://www.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com *.yotpo.com *.gstatic.com *.fonts.googleapis.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.authorize.net *.google.com *.yotpo.com *.addthis.com *.pinterest.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.googleapis.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com store.paradoxlabs.com *.yotpo.com *.cloudflare.com https://cdn.klarna.com *.vimeocdn.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com cdn.ampproject.org raw.githubusercontent.com *.googleapis.com https://www.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.authorize.net https://www.google.com *.yotpo.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org *.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.authorize.net *.yotpo.com *.cloudflare.com *.paypal.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' pdfconvertertools.com *.pdfconvertertools.com *.google.com *.youtube.com *.facebook.com *.amazon.com sentry-cdn.com *.ingest.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: pdfconvertertools.com *.pdfconvertertools.com *.google.com *.youtube.com *.facebook.com *.amazon.com cdnjs.cloudflare.com js.sentry-cdn.com *.sentry-cdn.com chrome-extension: *.googletagmanager.com *.doubleclick.net *.googleadservices.com; style-src 'self' 'unsafe-inline' pdfconvertertools.com fonts.googleapis.com cdnjs.cloudflare.com; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com cdnjs.cloudflare.com; media-src 'self' data: blob:; img-src 'self' data: https: chrome-extension: pdfconvertertools.com *.pdfconvertertools.com *.google.com *.youtube.com *.facebook.com *.amazon.com storage.googleapis.com *.googletagmanager.com *.doubleclick.net *.googleadservices.com; frame-src 'self' pdfconvertertools.com *.pdfconvertertools.com *.google.com *.youtube.com *.facebook.com *.amazon.com *.googletagmanager.com *.doubleclick.net; report-uri /csp-report 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://*.typekit.net https://fonts.googleapis.com https://cdn.jsdelivr.net https://*.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com https://*.loginwithamazon.com https://*.doubleclick.net https://cdn-cookieyes.com https://js.hs-scripts.com https://js.hs-banner.com https://js.usemessages.com https://js.hsadspixel.net https://js.hs-analytics.net https://snap.licdn.com https://*.zdassets.com https://*.facebook.net https://*.c-ctrip.com https://*.quantummetric.com https://*.scriptcdn.net https://*.alipayobjects.com https://*.navahididi.com https://cdn.brightwrite.com https://cdn.brightwrite-staging.com https://*.fullstory.com https://fullstory.com https://*.xcover.com; connect-src 'self' https://*.sentry.io https://sentry.io https://*.amazonaws.com https://*.amazon.com https://*.google.com https://google.com https://*.google.com.au https://*.google.com.br https://*.google.com.co https://*.google.com.mt https://*.google.com.mx https://*.google.com.sg https://*.google.com.sv https://*.google.com.ph https://*.googleapis.com https://*.google-analytics.com https://*.google.ae https://*.google.at https://*.google.be https://*.google.ch https://*.google.cz https://*.google.de https://*.google.es https://*.google.fr https://*.google.hu https://*.google.ie https://*.google.it https://*.google.nl https://*.google.no https://*.google.pl https://*.google.pt https://*.google.co.id https://*.google.co.jp https://*.google.co.kr https://*.google.com.my https://*.google.com.tr https://*.google.com.tw https://*.google.co.uk https://*.google.co.za https://*.doubleclick.net https://*.linkedin.com https://*.hubapi.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.brightwrite.com https://brightwrite-data.com https://*.fullstory.com https://*.hubspot.com https://*.adyen.com https://*.zdassets.com https://*.xcover.com https://*.covergenius.biz https://*.zendesk.com https://*.hsforms.com blob: https://browser-intake-datadoghq.eu; img-src 'self' https: data:; font-src 'self' https: data:; frame-src 'self' https://*.google.com https://*.googletagmanager.com https://*.amazon.com https://*.doubleclick.net https://*.adyen.com https://*.web.app https://*.xcover.com; upgrade-insecure-requests; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pube2daa5996f2fad21d085fd09ecccdd5d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Axcover-website%2Ccluster-group%3Axcover%2Cenv%3Aproduction 1 default-src 'self' guatemaladigital.com:* ; form-action 'none' ; frame-src 'self' googleads.g.doubleclick.net tpc.googlesyndication.com www.google.com/recaptcha/ recaptcha.google.com/recaptcha/ td.doubleclick.net; frame-ancestors 'none' ; style-src 'self' 'unsafe-inline' ; script-src 'self' 'unsafe-inline' www.statcounter.com www.google-analytics.com ssl.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com pagead2.googlesyndication.com partner.googleadservices.com tpc.googlesyndication.com www.googletagservices.com adservice.google.com adservice.google.com.gt adservice.google.com.sv adservice.google.co.cr static.hotjar.com tools.luckyorange.com websdk.smartlook.com script.hotjar.com settings.luckyorange.com ssl.mousestats.com www.clarity.ms a.plerdy.com ; img-src 'self' data: d3w3rr05w2dn4u.cloudfront.net *.amazonaws.com images-na.ssl-images-amazon.com/images/ m.media-amazon.com/images/ i.ebayimg.com/images/ www.googletagmanager.com pagead2.googlesyndication.com www.google-analytics.com www.google.com.gt ; connect-src 'self' data: guatemaladigital.com:* pagead2.googlesyndication.com c.statcounter.com www.google-analytics.com settings.luckyorange.com vc.hotjar.io ws.hotjar.com content.hotjar.io wss://ws.hotjar.com analytics.google.com i.clarity.ms ; media-src 'self' gd-archivos.s3.amazonaws.com ; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.fontawesome.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.youtube.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com https://squeezely.tech 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sooqr.com *.spotlersearch.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com *.run2day.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.avada.io *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr chimpstatic.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com https://squeezely.tech *.googleoptimize.com *.ecookie.nl https://ecookie.nl *.livechatinc.com *.shoppingminds.com *.omappapi.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.sooqr.com *.spotlersearch.com unsafe-inline assets.braintreegateway.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.omappapi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org https://get.geojs.io *.avada.io *.sooqr.com *.spotlersearch.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com *.mailcampaigns.nl *.visualstudio.com *.pinterest.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.doubleclick.net *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com https://squeezely.tech https://cognito-identity.eu-central-1.amazonaws.com *.omappapi.com *.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://dgap.org https://createsend.com https://api.friendlycaptcha.com https://internationalepolitik.de https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com https://matomo.dgap.org/; font-src 'self' data: dgap.org https://player.podigee-cdn.net https://fonts.gstatic.com; frame-src 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://www.youtube-nocookie.com/embed/ https://e.issuu.com https://www.google.com https://player.podigee-cdn.net https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://matomo.dgap.org https://www.openstreetmap.org https://cloud.dgap.org https://audio.podigee-cdn.net https://sign.dgap.dev https://www.helpmundo.de https://www.helpdirect.org https://tube.dgap.org; img-src 'self' https://www.gstatic.com https://*.met.vgwort.de https://www.googletagmanager.com https://www.google-analytics.com data: dgap.org https://matomo.dgap.org https://images.podigee-cdn.net https://region1.google-analytics.com; manifest-src 'self'; media-src 'self' https://audio.podigee-cdn.net; prefetch-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' https://dgap.org https://matomo.dgap.org https://www.google-analytics.com https://www.googletagmanager.com https://internationalepolitik.de https://ip-quarterly.com https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com https://matomo.dgap.org/; script-src-attr 'self' 'report-sample'; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://dgap.org https://www.googletagmanager.com https://www.google-analytics.com https://matomo.dgap.org https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com; style-src 'self' 'report-sample' 'unsafe-inline' https://js.createsend1.com https://www.gstatic.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'report-sample' 'unsafe-inline'; style-src-elem 'self' 'report-sample' 'unsafe-inline' https://www.google.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net https://cdnjs.cloudflare.com; worker-src 'self' blob:; form-action 'self' https://www.createsend.com https://dgap.org; frame-ancestors 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://sign.dgap.dev; report-uri https://dgap.org/en/system/reporting/default; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ https://test.oppwa.com/ https://oppwa.com/ https://www.datafast.com.ec/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://test.oppwa.com/ https://oppwa.com/ https://www.datafast.com.ec/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net *.bolt.com qa-api.magedevteam.com *.sentry.io https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';connect-src 'self' marketing.cockroachlabs.cloud https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://autocomplete.clearbit.com https://status.cockroachlabs.cloud https://marketing.cockroachlabs.cloud https://marketing.management-staging.crdb.io 350-qin-827.mktoresp.com https://eligibility.wootric.com https://wootric-eligibility.herokuapp.com https://r3f773swz03t.statuspage.io https://checkout.stripe.com https://api.stripe.com https://fast.appcues.com https://cookie-cdn.cookiepro.com https://privacyportal.cookiepro.com https://geolocation.onetrust.com wss://api.appcues.net https://api.segment.io https://cdn.segment.com https://session-replay.browser-intake-datadoghq.com https://rum.browser-intake-datadoghq.com https://logs.browser-intake-datadoghq.com https://session-replay.browser-intake-us5-datadoghq.com https://rum.browser-intake-us5-datadoghq.com https://logs.browser-intake-us5-datadoghq.com https://browser-intake-us5-datadoghq.com https://kapa-widget-proxy-la7dkmplpq-uc.a.run.app ;script-src 'self' 'unsafe-inline' 'unsafe-eval' marketing.cockroachlabs.cloud https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.google-analytics.com https://*.googletagmanager.com https://r3f773swz03t.statuspage.io cdn.wootric.com https://cookie-cdn.cookiepro.com https://cdn.jsdelivr.net munchkin.marketo.net https://checkout.stripe.com https://js.stripe.com cdn.segment.com https://cdn.madkudu.com fast.appcues.com https://widget.kapa.ai ;child-src 'self' marketing.cockroachlabs.cloud blob: https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://www.cockroachlabs.com https://td.doubleclick.net https://checkout.stripe.com https://js.stripe.com https://r3f773swz03t.statuspage.io;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fast.appcues.com;font-src 'self' https://fonts.gstatic.com data:;img-src 'self' data: https://logo.clearbit.com https://*.stripe.com https://cookie-cdn.cookiepro.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat;report-uri /csp-reports 1 script-src https: blob: mediastream: data: 'unsafe-inline' 'unsafe-eval' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: *; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: techport.ru *.techport.ru https://*.yandex.net https://techport.api.useinsider.com https://vk.com https://*.vk.com https://www.odnoklassniki.ru https://odnoklassniki.ru https://ok.ru https://connect.ok.ru https://yandex.ru https://*.yandex.ru https://ya.ru https://yandex.st https://yastatic.net https://*.yadro.ru https://webvisor.com https://mc.webwisor.org https://google.com https://*.google.com https://google.ru https://*.google.ru https://translate.google.cn https://*.googleapis.com https://*.googleadservices.com https://googletagservices.com https://*.googletagservices.com https://google-analytics.com https://*.google-analytics.com https://gstatic.com https://*.gstatic.com https://*.googlesyndication.com https://*.mail.ru https://top-fwz1.mail.ru https://youtube.ru https://*.youtube.ru https://youtube.com https://*.youtube.com https://s.ytimg.com https://9khj7ltnoi.a.trbcdn.net https://techpont.ru https://*.flixfacts.com https://*.flixcar.com https://*.flix360.com https://*.flix360.io https://logo.flixfacts.co.uk https://media.flixsyndication.net https://*.doubleclick.net https://www.alexa.com https://*.alexa.com https://ssp.rambler.ru https://profile.ssp.rambler.ru https://*.paymentgate.ru https://*.robokassa.ru https://*.sandbox.paypal.com https://*.paypal.com https://paypal.com https://www.paypal.com https://*.mkb.ru https://*.rbsuat.com https://*.begun.ru https://newrelic.com https://*.newrelic.com https://bam.nr-data.net https://techport.api.sociaplus.com https://flv.isitetv.com https://rum.ngenix.net https://*.cdnvideo.ru https://app.clicker.one https://*.24ttl.stream https://goodmod.ru https://p95bxv.ru https://x.cnt.my/ https://dmrtx.com/ https://*.searchbooster.io https://*.searchbooster.net https://cdn.diginetica.net https://getrcmx.com https://ga.segmel.com https://api.b2pos.ru/shop/v2/connect.js https://dpartaptm.com/ https://widget.yourgood.app https://cdn1.imshop.io https://do.price-port.ru; report-uri //www.techport.ru/csp; report-to //www.techport.ru/csp; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://cdn-cookieyes.com https://sdk.woosmap.com https://unpkg.com https://checkoutshopper-test.cdn.adyen.com https://checkoutshopper-live.cdn.adyen.com https://f.vimeocdn.com https://www.youtube.com https://www.google.com https://static.doubleclick.net; style-src 'self' 'unsafe-inline' https://cdn-cookieyes.com https://checkoutshopper-test.cdn.adyen.com https://checkoutshopper-live.cdn.adyen.com https://f.vimeocdn.com https://www.youtube.com; img-src 'self' data: blob: https://cdn-cookieyes.com https://www.google.com https://www.google.es https://www.googletagmanager.com https://i.vimeocdn.com https://www.youtube.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://api.woosmap.com https://cdn-cookieyes.com https://region1.google-analytics.com https://region1.analytics.google.com https://pagead2.googlesyndication.com https://www.google.com https://stats.g.doubleclick.net https://log.cookieyes.com https://www.googletagmanager.com https://vimeo.com https://arclight.vimeo.com https://lensflare.vimeo.com https://i.vimeocdn.com https://f.vimeocdn.com https://vod-adaptive-ak.vimeocdn.com https://www.youtube.com https://googleads.g.doubleclick.net https://jnn-pa.googleapis.com; frame-src 'self' https://*.cdn.adyen.com https://player.vimeo.com https://vimeo.com https://www.googletagmanager.com https://www.youtube.com; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; 1 default-src 'self'; script-src 'self' 'nonce-2d78fd30-5d44-4186-9311-7c2749f44fd2' 'strict-dynamic' https: http:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://accounts.google.com https://googletagmanager.com https://tagmanager.google.com https://www.googletagmanager.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com data: https://fonts.googleapis.com; frame-src 'self' 'nonce-2d78fd30-5d44-4186-9311-7c2749f44fd2' https://js.driftt.com https://www.google.com https://www.googletagmanager.com https://c.sandbox.paypal.com https://c.paypal.com https://accounts.google.com https://td.doubleclick.net https://api.recurly.com https://www.youtube.com https://www.youtube-nocookie.com; connect-src 'self' 'nonce-2d78fd30-5d44-4186-9311-7c2749f44fd2' https://*.analytics.google.com https://bat.bing.com https://api.rollbar.com https://px.ads.linkedin.com https://api.recurly.com https://*.google-analytics.com http://rum-collector-2.pingdom.net https://www-data.neat.com https://www.googleadservices.com https://stats.g.doubleclick.net https://www.facebook.com https://accounts.google.com https://m1.openfpcdn.io https://docs.google.com https://*.googletagmanager.com https://pagead2.googlesyndication.com https://google.com https://analytics.google.com https://bat.bing.net https://cx.neat.com https://edge.fullstory.com https://rs.fullstory.com https://manager.eu.smartlook.cloud https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat; img-src 'self' 'nonce-2d78fd30-5d44-4186-9311-7c2749f44fd2' https://*.google-analytics.com https://www.facebook.com https://bat.bing.com https://px.ads.linkedin.com https://seal-dc-easternpa.bbb.org https://*.googletagmanager.com data: https://www-data.neat.com https://ct.capterra.com https://googleads.g.doubleclick.net https://i.ytimg.com https://neat-cms-staging.s3.amazonaws.com https://neat-cms-prod.s3.amazonaws.com https://connect.facebook.net https://www.linkedin.com https://ssl.gstatic.com https://www.gstatic.com https://pagead2.googlesyndication.com https://www.googleadservices.com https://google.com https://fonts.gstatic.com https://googletagmanager.com https://bat.bing.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://*.paypal.com https://stats.g.doubleclick.net; object-src 'none'; base-uri 'self'; media-src 'self' data:; report-uri https://www.neat.com/api/csp/report; report-to csp-report-endpoint 1 default-src 'self'; script-src 'self' 'unsafe-hashes' 'sha256-u7q4c5i0dFA4WdZcdX0lItFS7Plw7BvMpWADeKlLVUs=' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' https://www.googletagmanager.com https://www.google-analytics.com https://accounts.google.com https://cdn-4.convertexperiments.com https://static.hotjar.com https://script.hotjar.com https://bat.bing.com https://tags.creativecdn.com https://connect.facebook.net https://analytics.tiktok.com https://googleads.g.doubleclick.net https://cdn.onesignal.com https://chimpstatic.com https://maps.googleapis.com https://maps.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://accounts.google.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.google.cl https://www.googleadservices.com https://accounts.google.com https://static-cdn-prod.cocha.cloud https://gcp-production-cdn.cocha.cloud https://bat.bing.com https://connect.facebook.net https://analytics.tiktok.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://maps.gstatic.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://accounts.google.com https://static-cdn-prod.cocha.cloud https://gcp-production-cdn.cocha.cloud https://apis-prod.cocha.cloud https://region1.google-analytics.com https://bat.bing.com https://analytics.tiktok.com https://onesignal.com https://cdn.onesignal.com https://api.hotjar.com https://content.hotjar.io wss://ws.hotjar.com https://cdn-4.convertexperiments.com https://us.creativecdn.com https://metrics.hotjar.io https://maps.googleapis.com https://maps.gstatic.com; media-src 'self' https://static-cdn-prod.cocha.cloud; frame-src 'self' https://www.googletagmanager.com https://accounts.google.com https://bid.g.doubleclick.net; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.gstatic.com *.typekit.net *.trustedshops.com *.trustpilot.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.dotdigital-pages.com *.dotdigital.com *.nosto.com *.nos.to *.sharethis.com *.addthis.com *.moatads.com *.mastercard.com *.paypal.com *.livechatinc.com *.vimeo.com *.pinterest.com/ *.doubleclick.net *.adsrvr.org *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.disqus.com https://img.youtube.com *.nosto.com *.nos.to *.zipmoney.com.au *.gstatic.com *.googleapis.com beaumont-tiles.com.au *.beaumont-tiles.com.au *.google.com *.adnxs.com *.pinterest.com *.ggpht.com *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io polyfill.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.disqus.com *.nosto.com *.nos.to *.sharethis.com *.addthis.com *.moatads.com *.addthisedge.com *.googleapis.com *.newrelic.com *.nr-data.net *.mastercard.com *.zipmoney.com.au *.livechatinc.com *.roomvo.com *.pinimg.com *.serving-sys.com *.adsrvr.org *.adnxs.com *.zip.co *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.bootstrapcdn.com *.cloudflare.com *.typekit.net *.googleapis.com *.trustpilot.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.nosto.com *.nos.to *.demdex.net *.sharethis.com *.addthis.com *.nr-data.net *.zipmoney.com.au *.zip.co *.paypal.com *.livechatinc.com *.google-analytics.com *.serving-sys.com *.pinterest.com maps.googleapis.com *.doubleclick.net *.roomvo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.fontawesome.com *.klarnacdn.net *.homescapesonline.com *.paypalobjects.com *.googleapis.com *.homescapes.de *.homescapes.fr maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.facebook.com *.pinterest.com *.arcot.com *.cardinalcommerce.com *.homescapes.de *.homescapes.fr *.homescapesonline.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.trustpilot.com *.facebook.com bid.g.doubleclick.net/ *.kaptcha.com *.paypalobjects.com *.googletagmanager.com *.pinterest.com *.googleapis.com *.arcot.com *.cardinalcommerce.com *.homescapes.de *.homescapes.fr *.homescapesonline.com *.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * *.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudflare.com *.facebook.com *.pinterest.com *.bing.com *.google.com *.google.co.in *.clarity.ms *.homescapesonline.com *.klarnacdn.net https://b.stats.paypal.com https://dub.stats.paypal.com *.googletagmanager.com *.klarnaevt.com *.braintreegateway.com *.paypalobjects.com *.googleapis.com *.awin1.com *.linksynergy.com *.homescapes.de *.homescapes.fr *.ytimg.com *.adobedtm.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com *.tiktok.com *.pinimg.com *.trustpilot.com *.googletagmanager.com *.klarna.com *.noibu.com *.clarity.ms *.googleadservices.com *.google-analytics.com *.facebook.net *.klarnaservices.com *.bing.com tag.rmp.rakuten.com apis.google.com *.googlecommerce.com *.homescapesonline.com *.abrankings.com *.klarnacdn.net *.paypal.com *.klarnaevt.com *.braintreegateway.com *.paypalobjects.com *.googleapis.com *.cardinalcommerce.com *.homescapes.de *.homescapes.fr *.klaviyo.com *.pinterest.com *.dwin1.com *.adobedtm.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com x.klarnacdn.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.klarnacdn.net *.homescapesonline.com *.paypalobjects.com *.googleapis.com *.homescapes.de *.homescapes.fr https://static.klaviyo.com assets.braintreegateway.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.cloudflare.com *.pinterest.com *.google-analytics.com https://stats.g.doubleclick.net *.tiktok.com *.klarnaservices.com *.clarity.ms *.homescapesonline.com https://payments.braintree-api.com https://static-forms.klaviyo.com https://cdn.abrankings.com *.klarnacdn.net *.googletagmanager.com *.klarnaevt.com *.braintreegateway.com *.paypalobjects.com *.bing.com *.google.co.in *.facebook.com *.googleapis.com *.trustpilot.com *.amazonaws.com/ *.cardinalcommerce.com *.homescapes.de *.homescapes.fr *.googlesyndication.com 'self' data: https://www.wepowerconnections.com https://static.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com x.klarnacdn.net *.klarna.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://UMHEALTHCAREEPICIFRAME-PP-PRTLTST.SPECTRUMRETAILNET.COM https://umhealthcareepiciframe-pp-prtl.spectrumretailnet.com;script-src 'nonce-8cfa186adab348188c012d37444a0098' https://myuhealthchart.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://myuhealthchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com https://www.gstatic.com https://webforms.pipedrive.com https://cdn.cmh-1.pipedriveassets.com https://cdn.was-1.pipedriveassets.com https://client.crisp.chat https://static.hotjar.com https://script.hotjar.com https://use.typekit.net https://cdn-cookieyes.com; connect-src 'self' https://*.googletagmanager.com https://www.google.com https://www.gstatic.com https://client.crisp.chat wss://client.relay.crisp.chat https://api.weglot.com https://cdn-cookieyes.com https://log.cookieyes.com https://vc.hotjar.io https://stats.g.doubleclick.net; frame-src 'self' https://www.google.com https://webforms.pipedrive.com https://*.googletagmanager.com https://www.youtube.com https://www.youtube-nocookie.com https://datastudio.google.com https://lookerstudio.google.com; img-src 'self' data: https: https://image.crisp.chat https://img.youtube.com; style-src 'self' 'unsafe-inline' https://client.crisp.chat https://use.typekit.net https://p.typekit.net; font-src 'self' data: https: https://use.typekit.net; object-src 'none'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com maxcdn.bootstrapcdn.com *.fontawesome.com data: *.googleapis.com *.acsbapp.com acsbapp.com *.laderach.com laderach.com https://fonts.bunny.net https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com www.facebook.com *.adyen.com laderach.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.googletagmanager.com https://plumrocket.com consentcdn.cookiebot.com *.addthis.com *.avada.io *.paypalobjects.com www.facebook.com tpc.googlesyndication.com vars.hotjar.com *.laderach.com *.demdex.net *.vimeo.com *.doubleclick.net laderach.com policy.app.cookieinformation.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com maps.gstatic.com *.ytimg.com *.vimeocdn.com *.facebook.net *.acsbapp.com *.googleusercontent.com *.googleapis.com *.clarity.ms *.bing.com *.google.de *.google.es *.doubleclick.net *.paypalobjects.com services.postcodeanywhere.co.uk laderach.isa-test.de www.facebook.com bat.bing.com googletagmanager.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.laderach.com laderach.com *.disqus.com https://firebasestorage.googleapis.com data: https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com consent.cookiebot.com *.addthisedge.com *.addthis.com *.moatads.com acsbapp.com *.acsbapp.com *.doubleclick.net *.gstatic.com *.paypalobjects.com static.addtoany.com lader11112.pcapredict.com services.postcodeanywhere.co.uk checkoutshopper-live.adyen.com g3367433695.co g3565518030.co g6140614385.co g15252493795.co g15450578130.co g15648662465.co *.cloudflare.com tpc.googlesyndication.com static.hotjar.com script.hotjar.com bat.bing.com *.clarity.ms *.laderach.com laderach.com *.disqus.com *.avada.io *.shopify.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net policy.app.cookieinformation.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.gstatic.com services.postcodeanywhere.co.uk *.laderach.com laderach.com https://fonts.bunny.net https://fonts.googleapis.com https://cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube-nocookie.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net googletagmanager.com *.addthis.com *.facebook.com facebook.com *.acsbapp.com *.doubleclick.net wss://ws30.hotjar.com *.hotjar.io *.hotjar.com metrics.laderach.com *.clarity.ms services.postcodeanywhere.co.uk bat.bing.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.laderach.com laderach.com https://get.geojs.io *.avada.io maps.googleapis.com policy.app.cookieinformation.com consent.app.cookieinformation.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klevu.com *.ksearchnet.com powertoolworld.co.uk *.powertoolworld.co.uk *.cloudflare.com *.google.co.uk *.google.com *.googleapis.com *.googleusercontent.com *.facebook.net data: *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.bugherd.com *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * powertoolworld.co.uk *.powertoolworld.co.uk *.google.co.uk *.google.com *.gstatic.com *.googleapis.com *.googleusercontent.com *.doubleclick.net *.facebook.net *.geoplugin.net *.braintreegateway.com data: *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.clearpay.co.uk js.mollie.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * powertoolworld.co.uk *.powertoolworld.co.uk *.cloudflare.com *.google.co.uk *.gstatic.com *.googleapis.com *.googleusercontent.com *.facebook.net data: *.reviews.io *.braintreegateway.com *.kaptcha.com *.braintree-api.com *.geoplugin.net *.sharethis.com *.sharethis.mgr.consensu.org *.hotjar.com *.tagserve.com *.clic2buy.com *.clic2drive.com *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.afterpay.com *.clearpay.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://img.youtube.com https://www.mollie.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com powertoolworld.co.uk *.powertoolworld.co.uk *.cloudflare.com *.google.co.uk *.googleapis.com *.googleusercontent.com *.ytimg.com *.paypalobjects.com *.cloudfront.net *.payments-amazon.com *.cardinalcommerce.com *.reviews.io *.geoplugin.net *.postcodeanywhere.co.uk *.sharethis.com *.trackjs.com *.hotjar.com *.tagserve.com *.bing.com *.wisepops.com wisepops.net *.wisepops.net *.clarity.ms *.clic2buy.com *.clic2drive.com *.reviews.co.uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com s7.addthis.com js.mollie.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com powertoolworld.co.uk *.powertoolworld.co.uk chimpstatic.com *.chimpstatic.com *.cloudflare.com *.cloudflareinsights.com *.trackedlink.net *.google.co.uk *.googleapis.com *.googleusercontent.com *.klevu.com data: *.reviews.io *.cardinalcommerce.com *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.trackedweb.net *.dotdigital-pages.com *.comapi.com *.dotdigital.com *.authorize.net *.cloudfront.net *.dynamicyield.com *.geoplugin.net *.postcodeanywhere.co.uk *.pcapredict.com *.sharethis.com *.trackjs.com cdn.jsdelivr.net *.hotjar.com *.tagserve.com *.zendesk.com *.zdassets.com static.zdassets.com *.zopim.com *.bing.com widget-mediator.zopim.com *.wisepops.com wisepops.net *.wisepops.net *.clarity.ms *.clic2buy.com *.clic2drive.com *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.afterpay.com/ *.squarecdn.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com powertoolworld.co.uk *.powertoolworld.co.uk *.cloudflare.com *.google.co.uk *.google.com *.googleusercontent.com *.facebook.net data: *.cardinalcommerce.com *.paypal.com *.cloudfront.net *.reviews.io *.geoplugin.net *.postcodeanywhere.co.uk *.sharethis.com *.hotjar.com *.tagserve.com *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com powertoolworld.co.uk *.powertoolworld.co.uk *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com widget.freshworks.com m2epro.freshdesk.com api.addressy.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com ekr.zdassets.com/ *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com powertoolworld.co.uk *.powertoolworld.co.uk *.cloudflare.com *.google.co.uk *.gstatic.com *.googleapis.com *.googleusercontent.com *.reviews.co.uk data: *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.comapi.com *.dotdigital.com *.braintreegateway.com *.bugsnag.com *.pusherapp.com ws.pusherapp.com *.bugherd.com *.geoplugin.net *.postcodeanywhere.co.uk *.sharethis.com *.trackjs.com *.hotjar.com *.hotjar.io *.tagserve.com *.zendesk.com *.zdassets.com static.zdassets.com *.zopim.com widget-mediator.zopim.com wss://widget-mediator.zopim.com *.wisepops.com wisepops.net *.wisepops.net *.clarity.ms *.clic2buy.com *.clic2drive.com *.cloudfront.net *.reviews.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' blob: https: data:;script-src 'report-sample' 'self' https: 'unsafe-inline';style-src 'self' https: 'unsafe-inline';connect-src https: wss:;object-src 'none';child-src 'self' blob:;base-uri 'none';frame-ancestors 'self';report-uri https://dot.fordeal.com/api/csp-reports?who=client_customer&app=fordeal;report-to csp-endpoint 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.mercadolibre.com https://www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com www.facebook.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar connect.facebook.net graph.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.mlstatic.com *.google.com https://www.gstatic.com *.avada.io business.facebook.com www.sandbox.paypal.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.googleapis.com *.gstatic.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.mercadopago.com www.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com one.elavonpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://*.ravecapture.com https://trustspot-app-assets.s3.amazonaws.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.googletagmanager.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net https://www.circularhub.com https://flyers.canex.ca https://td.doubleclick.net https://www.facebook.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com maps.googleapis.com https://services.postcodeanywhere.co.uk https://ws1.postescanada-canadapost.ca https://www.google.ca https://www.facebook.com https://*.ravecapture.com https://ravecapture-app-assets.s3.amazonaws.com https://*.canex.ca https://*.flippenterprise.net https://*.wishabi.net https://*.wishabi.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com imgs.signifyd.com *.hsforms.net *.hsforms.com 'self' data: https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.googletagmanager.com maps.googleapis.com developers.google.com https://s7.addthis.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net https://trustspot.io https://*.ravecapture.com https://www.circularhub.com https://acsbap.com https://acsbapp.com https://cdn.acsbapp.com https://ws1.postescanada-canadapost.ca https://cdn.jsdelivr.net https://commerce.adobedtm.com https://unpkg.com https://connect.facebook.net https://*.hotjar.com https://h64.online-metrix.net https://*.flippenterprise.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com cdn-scripts.signifyd.com imgs.signifyd.com *.hsforms.net *.hsforms.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://trustspot.io https://ws1.postescanada-canadapost.ca https://*.flippenterprise.net https://*.ravecapture.com downloads.mailchimp.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.gstatic.com *.google.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net https://acsbap.com https://cdn.acsbapp.com https://ws1.postescanada-canadapost.ca https://stats.g.doubleclick.net https://*.hotjar.io https://connect.facebook.net https://*.facebook.com https://*.flippenterprise.net https://*.flippback.com https://*.flipp.com https://*.ravecapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://db82ede2-bcf0-414d-936f-71c652e4bd68.sansec.watch; report-to report-endpoint; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.cz https://www.myheritage.cz 'unsafe-eval' 'nonce-15f2967a5a8252ec999719fe6bb1e1fb' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.cz;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.googletagmanager.com *.grudado.com.br *.doubleclick.net *.paypal.com *.mercadolibre.com *.pinterest.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.addthis.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googletagmanager.com *.grudado.com.br *.facebook.com *.google.com *.google.com.br *.mercadolibre.com *.mercadolivre.com *.mercadolivre.com.br *.doubleclick.net *.bing.com *.pinimg.com *.pinterest.com *.mercadopago.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://images.unsplash.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: www.google.com.ua *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.mixpnl.com https://analytics.tiktok.com *.clarity.ms *.logr-ingest.com *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.paypal.com *.vimeo.com *.video.google.com *.facebook.net *.doubleclick.net *.mlstatic.com *.mercadopago.com *.bing.com *.pinimg.com *.sgtm.grudado.com.br ct.pinterest.com *.mercadolibre.com.br *.mercadopago.com.br *.mercadolivre.com.br google.com *.facebook.com 'unsafe-inline' *.mercadolivre.com *.mercadolibre.com https://mercadopago.com.br https://maps.googleapis.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io *.shopify.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com unpkg.com www.xtento.com cdn.xtento.com load.sgtm.grudado.com.br https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.mixpanel.com https://cdn.growthbook.io https://analytics.tiktok.com https://*.clarity.ms https://*.grudado.com.br https://viacep.com.br *.doubleclick.net *.google.com *.mercadopago.com *.mercadolibre.com *.pinterest.com *.pinpiaa.com *.bing.com *.mercadolibre.com.br *.mercadopago.com.br *.mercadolivre.com.br google.com *.facebook.com *.mercadolivre.com https://mercadopago.com.br *.mlstatic.com https://maps.googleapis.com https://player.vimeo.com ekr.zdassets.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net load.sgtm.grudado.com.br https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://*.customily.com https://*.amazonaws.com 'self' data: maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://*.google.com https://*.google.co.uk https://*.gstatic.com https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.personalisedgiftsshop.co.uk https://*.personalisedweddinggifts.co.uk https://*.yookiki.com https://*.google.com 'self' 'unsafe-inline'; frame-ancestors https://*.personalisedgiftsshop.co.uk https://*.personalisedweddinggifts.co.uk https://*.yookiki.com https://*.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://*.personalisedgiftsshop.co.uk https://*.personalisedweddinggifts.co.uk https://*.yookiki.com https://*.google.com sandbox-buy.paddle.com buy.paddle.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.customily.com https://*.amazonaws.com 'self' data: *.trackedlink.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net https://www.mollie.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://*.feefo.com https://*.gstatic.com https://*.elfsightcdn.com https://*.elfsight.com https://*.ggpht.com https://*.dycdn.net https://cdn-cookieyes.com https://bat.bing.com https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.customily.com https://*.amazonaws.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ cdn.jsdelivr.net *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com maps.googleapis.com js.mollie.com * https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com https://*.google.com https://*.google.co.uk https://*.elfsight.com https://cdn-cookieyes.com https://bat.bing.com https://cdn.paddle.com/paddle/v2/paddle.js https://public.profitwell.com buy.paddle.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com https://*.google.com https://*.google.co.uk https://*.googleapis.com https://*.feefo.com https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com https://cdn-cookieyes.com https://bat.bing.com sandbox-cdn.paddle.com cdn.paddle.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com https://*.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.customily.com https://*.amazonaws.com 'self' data: *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com * https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com https://cdn-cookieyes.com https://bat.bing.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://*.google.com https://personalisedgiftsshop.co.uk https://*.personalisedgiftsshop.co.uk https://personalisedweddinggifts.co.uk https://*.personalisedweddinggifts.co.uk https://yookiki.com https://*.yookiki.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /rest/V1/csp/storefront/report; report-to report-endpoint; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:; script-src 'self' https://*.googletagmanager.com 'nonce-13bf39abe81ac8b8db9415b51be6e696' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; style-src 'self' 'nonce-13bf39abe81ac8b8db9415b51be6e696' https://fonts.googleapis.com; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; frame-ancestors 'self'; 1 default-src https://kiwirail.co.nz/* https://www.googletagmanager.com/ www.kiwirail.co.nz/* http://www.w3.org/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://www.facebook.com https://www.youtube.com/ https://connect.facebook.net/ 'self' 'unsafe-inline'; img-src http://www.w3.org/ https://www.facebook.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline' data:;report-uri https://www.kiwirail.co.nz/csp/v1/report;report-to csp-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.artifi.net *.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.fontawesome.com *.hotjar.com *.sfdcstatic.com *.shopify.com *.trustedshops.com *.twimg.com *.twitter.com *.checkout.vficloud.net *.vficloud.net *.amazonaws.com *.checkout.verifone.cloud *.verifone.cloud *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.swellrewards.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.artifi.net *.boyslife.org *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.doubleclick.net *.facebook.com *.force.com *.hotjar.com *.kaptcha.com *.scouting.org *.swellrewards.com *.twitter.com *.weltpixel.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.artifi.net *.cookiebot.com *.amazonaws.com *.bing.com *.clarity.ms *.cloudflare.com *.cloudfront.net *.facebook.com *.facebook.net *.google.com *.google.co.in *.google.lv *.googleadservices.com *.googletagmanager.com *.hotjar.com *.klarna.com *.lightemporium.com *.magentocommerce.com *.scoutshop.org *.scoutstuff.org *.shopify.com *.siteimproveanalytics.io *.smsbump.com *.swellrewards.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.reddit.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.artifi.net *.cookiebot.com *.verifone.cloud *.clarity.ms *.cloudflare.com *.crazyegg.com *.doubleclick.net *.ecomm-nav.com *.facebook.net *.fontawesome.com *.force.com *.google-analytics.com *.googleoptimize.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.jquery.com *.klaviyo.com *.nextopia.net *.nextopiasoftware.com *.paypal.com *.salesforceliveagent.com siteimproveanalytics.com *.stape.io *.swellrewards.com *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu *.vficloud.net *.chasepaymentechhostedpay-var.com *.chasepaymentechhostedpay.com *.my.salesforce-sites.com *.lightning.force.com *.secure.force.com *.checkout.vficloud.net *.checkout.verifone.cloud widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.googletagmanager.com tagmanager.google.com *.redditstatic.com *.reddit.com unpkg.com *.kaptcha.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.artifi.net *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.force.com *.google.com *.googleapis.com *.gstatic.com *.klaviyo.com *.nextopia.net *.swellrewards.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu *.secure.force.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com tagmanager.google.com assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.scoutshop.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.artifi.net *.cookiebot.com *.clarity.ms *.cloudflare.com *.crazyegg.com *.doubleclick.net *.facebook.com *.google.lv *.hotjar.com *.hotjar.io *.klaviyo.com *.scoutshop.org *.socialannex.com *.swellrewards.com *.twimg.com *.twitter.com wss: *.secure.force.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.kaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f0e6bfef-e270-42d2-8f01-c8e72656172d.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com cdn.cookielaw.org *.onetrust.com *.globalpay.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.cookielaw.org *.onetrust.com *.trustpilot.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.gstatic.com https://images.unsplash.com blob: *.cloudfront.net cdn.cookielaw.org *.onetrust.com *.googlesyndication.com *.facebook.com bat.bing.com *.doubleclick.net *.contentsquare.net *.google.co.uk *.impactcdn.com *.globalpay.com bat.bing.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com cdn.cookielaw.org *.onetrust.com *.trustpilot.com cdn-ukwest.onetrust.com unpkg.com bat.bing.com t.contentsquare.net connect.facebook.net analytics.tiktok.com *.impactcdn.com *.pxf.io *.sjv.io *.impct.site *.adobedc.net *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com widget.trustpilot.com *.adalyser.com bat.bing.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com cdn.cookielaw.org *.onetrust.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n.adobe.io *.adobedc.net *.demdex.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://www.google-analytics.com https://maps.googleapis.com https://player.vimeo.com cdn.cookielaw.org *.onetrust.com *.trustpilot.com *.googlesyndication.com analytics.tiktok.com *.google-analytics.com *.contentsquare.net *.doubleclick.net *.impactcdn.com *.pxf.io *.sjv.io *.impct.site api.addressy.com https://google.com/pay widget.trustpilot.com bat.bing.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com static.addtoany.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com mcstaging.trainworld.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.certcapture.com static.addtoany.com connect.facebook.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://cdn.jsdelivr.net www.facebook.com graph.facebook.com business.facebook.com *.authorize.net maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.addtoany.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com *.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com http://dpm.demdex.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.elecrow.com *.chromestatus.com *.bootcss.com maxcdn.bootstrapcdn.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://store.plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.addthis.com *.pinterest.com *.amazonaws.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://store.plumrocket.com cashier1.uat.useepay.com cashier.useepay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.elecrow.com *.shopify.com github.com *.githubusercontent.com *.wp.com *.imgur.com bitronics.store www.longan-labs.cc www.facebook.com elecrow.s3.us-west-1.amazonaws.com *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: blob: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google-analytics.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.facebook.net *.pinterest.com *.instagram.com *.dwin1.com *.livechatinc.com *.elecrow.com *.bootcdn.net *.googletagmanager.com *.doubleclick.net t.contentsquare.net s7.addthis.com *.fontawesome.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cashier.useepay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.bootcss.com maxcdn.bootstrapcdn.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com *.elecrow.com *.googletagmanager.com *.doubleclick.net *.amazonaws.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.youtube.com *.ytimg.com *.wistia.com *.wistia.net *.qq.com *.gtimg.cn *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com snap.licdn.com *.facebook.com *.facebook.net connect.facebook.net *.dynamics.com *.microsoftonline.com *.friendlycaptcha.com friendlycaptcha.com *.heraeus-web.com *.cookiefirst.com; script-src-elem 'self' 'unsafe-inline' *.youtube.com *.wistia.com *.wistia.net *.qq.com *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.friendlycaptcha.com *.sociablekit.com localtesting.com *.azureedge.net *.maptiler.com *.licdn.com *.heraeus-web.com; style-src 'self' 'unsafe-inline' *.wistia.com *.wistia.net *.friendlycaptcha.com *.sociablekit.com *.cookiefirst.com *.heraeus-web.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com *.heraeus-web.com *.cookiefirst.com *.sociablekit.com; img-src 'self' data: blob: *.youtube.com *.ytimg.com *.googlevideo.com *.wistia.com *.wistia.net *.qq.com *.gtimg.cn *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.friendlycaptcha.com *.sociablekit.com *.licdn.com *.azureedge.net *.heraeus.com *.heraeus-web.com; font-src 'self' data: *.wistia.com *.wistia.net *.heraeus-web.com; connect-src 'self' *.youtube.com *.wistia.com *.wistia.net *.qq.com *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.microsoftonline.com *.friendlycaptcha.com friendlycaptcha.com *.heraeus-web.com *.accentapi.com *.heraeus.com *.azurewebsites.net *.azureedge.net *.sociablekit.com *.maptiler.com sgtm.argor-heraeus.com sgtm.heraeus-medical.com sgtm.heraeus-medevio.com sgtm.heraeus-group.com sgtm.heraeus-electronics.com sgtm.heraeus-precious-metals.com sgtm.heraeus-printed-electronics.com sgtm.heraeus-remloy.com sgtm.heraeus-electro-nite.com sgtm.heraeus-epurio.com sgtm.heraeus-amloy.com sgtm.heraeus.com; frame-src 'self' *.youtube.com *.youtube-nocookie.com *.wistia.com *.wistia.net *.qq.com *.linkedin.com *.facebook.com *.dynamics.com *.friendlycaptcha.com friendlycaptcha.com *.powerapps.com *.heraeus-web.com *.heraeus.com heraeus.sharepoint.com login.microsoftonline.com sgtm.argor-heraeus.com sgtm.heraeus-medical.com sgtm.heraeus-medevio.com sgtm.heraeus-group.com sgtm.heraeus-electronics.com sgtm.heraeus-precious-metals.com sgtm.heraeus-printed-electronics.com sgtm.heraeus-remloy.com sgtm.heraeus-electro-nite.com sgtm.heraeus-epurio.com sgtm.heraeus-amloy.com sgtm.heraeus.com; frame-ancestors 'self' *.heraeus-web.com *.heraeus.com; media-src 'self' data: blob: *.wistia.com *.wistia.net *.heraeus-web.com *.heraeus.com; child-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' *.dynamics.com; report-uri /api/csp-report 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.lndo.site *.weprovide.shop script.hotjar.com unpkg.com use.typekit.net *.triggerbee.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io landofcoder.com maps.googleapis.com chart.googleapis.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.lndo.site *.weprovide.shop dtm.cando.eu vars.hotjar.com ct.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com 'self' data: www.google.nl *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com cdn.flbx.io *.cloudfront.net 'self' blob: data http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.lndo.site *.weprovide.shop maps.google.com maps.googleapis.com mailing.deli-home.nl *.clarity.ms *.omappapi.com ct.pinterest.com cdn.cookielaw.org *.cando.eu skantrae.com *.weekampdeuren.nl dev.visualwebsiteoptimizer.com *.triggerbee.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.getflowbox.com landofcoder.com maps.googleapis.com chart.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.lndo.site *.weprovide.shop cdnjs.cloudflare.com code.jquery.com optanon.blob.core.windows.net geolocation.onetrust.com *.omappapi.com bam.nr-data.net cdn.cookielaw.org js-agent.newrelic.com s.pinimg.com *.hotjar.com *.clarity.ms cdn.leadinfo.net ct.pinterest.com dev.visualwebsiteoptimizer.com *.triggerbee.com *.myvisitors.se *.jotform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.trustpilot.com *.lndo.site *.weprovide.shop optanon.blob.core.windows.net a.omappapi.com cdn.cookielaw.org p.typekit.net skantrae.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.getflowbox.com *.googleapis.com landofcoder.com maps.googleapis.com chart.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.lndo.site *.weprovide.shop *.cando.eu bam.nr-data.net *.clarity.ms *.omappapi.com ct.pinterest.com sp.spheremall.com *.hotjar.com *.hotjar.io wss://*.hotjar.com cdn.cookielaw.org geolocation.onetrust.com dev.visualwebsiteoptimizer.com *.triggerbee.com gethatch.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; img-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://img.youtube.com https://*.clarity.ms https://c.bing.com https://i.bojoko.com https://bojoko.com/assets; media-src 'self' https://i.bojoko.com; script-src 'report-sample' 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://static.cloudflareinsights.com https://cdn-4.convertexperiments.com https://*.clarity.ms 'sha256-ZUDX9Z+y1rWudy0ln+zV0AsrZoVsm3aQhzUY359l8FM=' 'sha256-Zu9ZHvBSKzZyXjZrz4AX9EWoBfFbXk/x/UxqJDROcHc=' https://bojoko.com/assets 'sha256-DTbEkHFgvUtFQTfjMrYQg7Y5+V+TkrorUrIwyvfty7w='; style-src 'report-sample' 'self' 'unsafe-inline' https://bojoko.com/assets; object-src 'none'; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://region1.google-analytics.com https://region1.analytics.google.com https://plausible.bojoko.com https://cdn-4.convertexperiments.com https://*.clarity.ms; frame-src 'self' https://www.youtube-nocookie.com/embed/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; frame-ancestors 'none'; worker-src 'none'; report-uri https://bojoko.endpoint.csper.io; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://www.facebook.com https://www.tiktok.com https://analytics.tiktok.com https://bat.bing.com https://secure.ewaypayments.com https://*.ewaypayments.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://hcaptcha.com https://*.hcaptcha.com https://*.honeybot.ai; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com https://maps.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://www.google-analytics.com https://www.facebook.com https://connect.facebook.net https://analytics.tiktok.com https://www.tiktok.com https://bat.bing.com https://*.ewaypayments.com https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com https://*.hcaptcha.com https://*.honeybot.ai; media-src 'self' https://www.youtube.com https://*.ytimg.com; frame-src 'self' https://www.youtube.com https://www.facebook.com https://www.tiktok.com https://*.ewaypayments.com https://www.google.com https://www.gstatic.com https://hcaptcha.com https://*.hcaptcha.com https://*.honeybot.ai; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://analytics.tiktok.com https://www.tiktok.com https://bat.bing.com https://*.ewaypayments.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://hcaptcha.com https://*.hcaptcha.com https://*.honeybot.ai; object-src 'none'; base-uri 'self'; form-action 'self' https://*.ewaypayments.com; frame-ancestors 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.cloudflare.com *.klaviyo.com *.hotjar.com *.hotjar.io *.networkmerchants.com *.echeckpoint.com *.cdnfonts.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cybersource.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.cybersource.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.online-metrix.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.sezzle.com https://maps.gstatic.com https://maps.googleapis.com https://maps.google.com http://maps.google.com *.jotfor.ms *.jotform.com *.c3vault1.com *.storepoint.co https://res.cloudinary.com https://icons.storepoint-icons.com *.elfsight.com *.elfsightcdn.com *.commoninja.com *.cloudfront.net *.hotjar.com *.hotjar.io *.networkmerchants.com *.echeckpoint.com *.signifyd.com *.sezzle.com *.googleapis.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com *.cardinalcommerce.com *.online-metrix.net *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com https://static.cloudflareinsights.com *.cloudflare.com *.lr-ingest.com *.ingest-lr.com *.jotform.com *.jotfor.ms *.storepoint.co *.elfsight.com *.commoninja.com *.cloudfront.net *.hotjar.com *.hotjar.io *.networkmerchants.com *.echeckpoint.com *.signifyd.com *.sezzle.com *.googleapis.com www.gstatic.com maps.googleapis.com cdn.ampproject.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com fonts.cdnfonts.com https://fonts.googleapis.com *.jotfor.ms *.storepoint.co *.fontawesome.com *.cloudflare.com *.elfsight.com *.commoninja.com *.klaviyo.com *.hotjar.com *.hotjar.io *.networkmerchants.com *.echeckpoint.com *.typekit.net *.sezzle.com *.cdnfonts.com *.googleapis.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cardinalcommerce.com *.online-metrix.net *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com https://maps.googleapis.com *.doubleclick.net https://bcp.crwdcntrl.net *.lr-ingest.com *.ingest-lr.com *.jotform.com https://api.jotform.com *.storepoint.co *.elfsight.com *.commoninja.com *.klaviyo.com *.hotjar.com *.hotjar.io *.networkmerchants.com *.echeckpoint.com *.sezzle.com *.automaticffl.com *.googleapis.com places.googleapis.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com *.weltpixel.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com https://www.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://bat.bing.com/ http://bat.bing.com/ www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.attn.tv events.attentivemobile.com https://www.dwin1.com https://widget.usersnap.com https://s.pinimg.com https://ct.pinterest.com https://connect.facebook.net https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://bat.bing.com/ http://bat.bing.com/ www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.attn.tv events.attentivemobile.com https://www.facebook.com https://ct.pinterest.com https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://bat.bing.com/ http://bat.bing.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.google.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.youtube.com/ *.google.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://www.googletagmanager.com/ *.meetanshi.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: https://static.afterpay.com https://site-assets.afterpay.com/ d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://platform-api.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com https://clauem2.arrowtheme.com https://scontent.cdninstagram.com/ https://buttons-config.sharethis.com https://l.sharethis.com https://platform-cdn.sharethis.com https://scontent-ams4-1.cdninstagram.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.meetanshi.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.maps.googleapis.com *.trackedlink.net *.google.com *.maps.gstatic.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com https://connect.facebook.net https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com *.avada.io *.meetanshi.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com unsafe-inline assets.braintreegateway.com *.fontawesome.com https://static.klaviyo.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.clearpay.co.uk *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.meetanshi.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://geowidget.easypack24.net *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dhl.pl https://geowidget-app.inpost.pl/ https://mapa.ecommerce.poczta-polska.pl secure.payu.com merch-prod.snd.payu.com *.twitter.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.googleapis.com *.lizardlabs.pl *.trustedshops.com ruch-osm.sysadvisors.pl static.payu.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net tile.openstreetmap.org mapa.orlenpaczka.pl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.instagram.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://mapa.ecommerce.poczta-polska.pl *.cloudfront.net ruch-osm.sysadvisors.pl secure.payu.com secure.snd.payu.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com mapa.orlenpaczka.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.cloudfront.net ruch-osm.sysadvisors.pl *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.googleapis.com ruch-osm.sysadvisors.pl secure.payu.com merch-prod.snd.payu.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com nominatim.openstreetmap.org 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src *.cerifi.com 'unsafe-inline' 'self' *.bootstrapcdn.com cdnjs.cloudflare.com *.jquery.com; media-src *.cerifi.com 'unsafe-inline' 'self' *.kaltura.com blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: code.jquery.com snap.licdn.com js.zi-scripts.com *.bootstrapcdn.com *.googleadservices.com cloud.scorm.com *.cloud.scorm.com *.googleapis.com *.kaltura.com use.fontawesome.com *.cerifi.com www.google.com r.bing.com *.clarity.ms connect.facebook.net www.facebook.com *.doubleclick.net cdnjs.cloudflare.com *.callrail.com bat.bing.com www.googletagmanager.com www.google-analytics.com js.stripe.com serverapi.arcgisonline.com cdn.tiny.cloud cdn.jsdelivr.net www.gstatic.com cdn.cookielaw.org *.vidyard.com; connect-src 'self' *.cerifi.io *.doubleclick.net *.kaltura.com js.zi-scripts.com *.callrail.com cloud.scorm.com *.cloud.scorm.com *.clarity.ms www.google-analytics.com *.bootstrapcdn.com cdn.tiny.cloud geolocation.onetrust.com autosuggest.cerificpedge.com cdn.cookielaw.org bat.bing.com www.googletagmanager.com *.cerifi.com snap.licdn.com code.jquery.com *.googleadservices.com analytics.google.com *.googleapis.com use.fontawesome.com serverapi.arcgisonline.com www.google.com r.bing.com connect.facebook.net px.ads.linkedin.com www.facebook.com cdn.linkedin.oribi.io cdn.jsdelivr.net; frame-src 'self' *.kaltura.com *.doubleclick.net cloud.scorm.com *.cloud.scorm.com *.clarity.ms www.googletagmanager.com *.cerifi.com js.stripe.com www.google.com cdn.tiny.cloud *.vidyard.com www.facebook.com; frame-ancestors 'self' *.cerificpedge.com *.cerifi.io *.cerifi.com; img-src * data: blob:; style-src 'unsafe-inline' 'self' cdn.jsdelivr.net *.bootstrapcdn.com cdn.tiny.cloud ajax.googleapis.com code.jquery.com; report-uri https://CeriFiCPEdge.com/ContentSecurityPolicy/CSPreports 1 style-src 'self' 'unsafe-inline' https://engine.styla.com https://fast.fonts.net https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://delivery-assets.squarelovin.com https://fonts.googleapis.com https://cdn.parcellab.com https://www.gstatic.com; connect-src 'self' https://*.joop.com https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.kameleoon.io https://*.kameleoon.eu https://blackbit-styla.s3.eu-central-1.amazonaws.com https://*.styla.com https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://tracking-api.squarelovin.com https://www.paypal.com https://*.adyen.com https://*.clarity.ms https://ad.doubleclick.net https://*.bing.com https://*.bing.net https://ct.pinterest.com https://px.ads.linkedin.com https://ib.adnxs.com/pixie/up https://www.facebook.com https://connect.facebook.net https://*.hotjar.io wss://ws.hotjar.com https://analytics.tiktok.com https://google.com https://*.google.com https://*.analytics.google.com https://*.googleapis.com https://api.parcellab.com https://bt.fraud0.com https://recommender.scarabresearch.com https://in.hotjar.com https://sizekick-products.b-cdn.net https://*.sizekick.io https://api-js.mixpanel.com https://sizekick-real-shapes.b-cdn.net wss://sizekick-sizing.europe-west1.firebasedatabase.app https://size-recommendation-54boaeyuqq-ey.a.run.app https://o4505249677770752.ingest.sentry.io; base-uri 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; object-src https://sizekick.io https://*.sizekick.io; worker-src 'self' https://joop.com https://*.joop.com blob:; frame-src 'self' https://joop.com https://*.joop.com https://app.usercentrics.eu https://web.cmp.usercentrics.eu https://player.vimeo.com https://www.google.com https://td.doubleclick.net https://*.fls.doubleclick.net https://pay.google.com https://www.paypal.com https://*.adyen.com https://*.global-e.com https://www.facebook.com https://bat.bing.com https://widget.sizekick.io https://my.sizekick.io https://my-sizekick.firebaseapp.com https://my-dev.sizekick.io https://widget-dev.sizekick.io; media-src 'self' https://joop.com https://*.joop.com data: https://styla-prod-us.imgix.net https://cdn.kameleoon.com https://cdn-vid.squarelovin.com https://my.sizekick.io; frame-ancestors 'self' https://joop.com https://*.joop.com; img-src 'self' https://joop.com https://*.joop.com blob: data: https://www.googletagmanager.com https://*.analytics.google.com https://*.google.com https://www.google.ch https://www.google.de https://www.google.fr https://www.google.at https://www.google.pt https://www.google.hu https://www.google.it https://www.google.ee https://www.google.pl https://www.google.lt https://www.google.hr https://www.google.co.uk https://www.google.nl https://www.google.be https://stats.g.doubleclick.net https://www.googleadservices.com https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.api.service.cmp.usercentrics.eu https://styla-prod-us.imgix.net https://s3.global-e.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://cdn.squarelovin.com https://cdn-vid.squarelovin.com https://*.adyen.com https://*.cdn.adyen.com https://*.clarity.ms https://*.hotjar.com https://www.paypalobjects.com https://icons.parcellab.com https://www.gstatic.com https://fast.fonts.net https://*.bing.com https://*.bing.net https://ad.doubleclick.net https://googleads.g.doubleclick.net https://*.google-analytics.com https://*.vimeocdn.com https://www.facebook.com https://ib.adnxs.com https://px.ads.linkedin.com https://secure.adnxs.com https://lantern.roeye.com https://static.kameleoon.com https://icons.parcellab.com https://bt.fraud0.com https://analytics.tiktok.com https://widget.sizekick.io https://my.sizekick.io; default-src 'self' https://joop.com https://*.joop.com; font-src 'self' data: https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://fast.fonts.net https://fonts.gstatic.com https://s3.global-e.com https://script.hotjar.com; report-uri https://joop.com/csp/report; report-to csp-endpoint; 1 font-src *.fontawesome.com *.googleapis.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.typekit.net *.twimg.com *.trustedshops.com *.bootstrapcdn.com https://*.hotjar.com https://static.klaviyo.com https://surveys-static.survicate.com *.cookie-script.com cookie-script.com *.paybyrd.com 'self' data: *.stripecdn.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com *.paybyrd.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com *.stripe.com stripe.com *.paybyrd.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ google.com https://static.addtoany.com/ https://www.googletagmanager.com/ www.google.com www.gstatic.com apis.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.revolut.com *.google.com *.cdn-apple.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com secure.authorize.net test.authorize.net js.stripe.com m.stripe.com x.klarnacdn.net *.weltpixel.com vars.hotjar.com *.doubleclick.net *.paybyrd.com *.link.com *.amazon.com *.trustpilot.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com https://cosmetis.com *.mcusercontent.com *.cloudflare.com *.google.pt *.google.es *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com *.tradetracker.net *.pampanetwork.com *.mailchimp.com *.cloudfront.net https://*.clarity.ms https://*.hotjar.com https://c.bing.com https://googleads.g.doubleclick.net https://cosmetis.boost.propelbon.com https://static.zdassets.com *.doofinder.com *.criteo.com *.cookie-script.com cookie-script.com *.paybyrd.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com https://static.addtoany.com/ apis.google.com cdn.doofinder.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com *.gstatic.com *.avada.io *.shopify.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.revolut.com *.cdn-apple.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.google.pt *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com tagmanager.google.com https://*.hotjar.com 'unsafe-inline' *.zdassets.com *.zendesk.com *.mailchimp.com mc.us6.list-manage.com *.newrelic.com *.nr-data.net *.doubleclick.net *.activehosted.com *.cloudfront.net wss://*.zopim.com wss://*.wizzy.ai *.app-us1.com trackcmp.net https://*.clarity.ms https://surveys-static.survicate.com https://api6.ipify.org *.cookie-script.com cookie-script.com https://iic.cosmetis.com *.doofinder.com *.criteo.com api6.ipify.org *.survicate.com api64.ipify.org *.paybyrd.com *.hsforms.net *.hsforms.com *.stripe.network *.stripecdn.com *.amazon.com *.link.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com *.bootstrapcdn.com *.zendesk.com *.mailchimp.com *.googletagmanager.com https://*.hotjar.com 'unsafe-inline' https://surveys-static.survicate.com *.cookie-script.com cookie-script.com *.paybyrd.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.zdassets.com *.paybyrd.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.doofinder.com wss://*.doofinder.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com ws://127.0.0.1:35729/livereload *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.google-analytics.com stats.g.doubleclick.net *.facebook.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.zdassets.com *.zendesk.com *.zopim.com wss://*.zopim.com *.nr-data.net wss://*.wizzy.ai https://*.wizzy.ai https://*.clarity.ms https://www.google.pt https://care4ict.nl/health_check.php wss://pod-18.zendesk.com https://gtm.cosmetis.com https://survey.survicate.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://iic.cosmetis.com wss://*.doofinder.com/ *.criteo.com https://*.criteo.com/ *.cookie-script.com cookie-script.com *.sentry.io *.paybyrd.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://84a5a812-f528-4463-ba29-abdbc1fc7d38.sansec.watch/; report-to report-endpoint; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://tag.heylink.com https://www.beautycos.dk https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cybersource.com *.facebook.com *.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.cybersource.com https://www.google.com https://www.facebook.com *.doubleclick.net *.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.online-metrix.net *.google.com *.google.co.in *.doubleclick.net *.hsforms.com *.hubspot.com *.googletagmanager.com *.nr-data.net https://trains.walthers.com/hubfs/Ma_yJuhneJoly2o2l-flyer_CONs-1.jpg https://cdnjs.cloudflare.com/ajax/libs/tinymce/4.9.6/skins/lightgray/img/trans.gif data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.gstatic.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.googletagmanager.com *.google.com *.google.co.in *.hs-analytics.net *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.hsleadflows.net *.hsadspixel.net *.doubleclick.net *.loyaltylion.net *.klevu.com https://cdn.equalweb.com http://assets.adobedtm.com https://h64.online-metrix.net *.hsforms.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.loyaltylion.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.walthers.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.google.com *.google-analytics.com *.doubleclick.net *.hubspot.com *.hubapi.com *.hs-banner.com *.walthers.com *.googleapis.com https://cdn.equalweb.com *.loyaltylion.net *.loyaltylion.com https://forms.hscollectedforms.net https://kg668dbov0.execute-api.us-east-1.amazonaws.com *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://cdn.privacytools.com.br https://fonts.googleapis.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com js.stripe.com https://cdn.privacytools.com.br https://api.pre.globalgetnet.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d2r1yp2w7bby2u.cloudfront.net us1.clevertap-prod.com us1.clevertap.com wzrkt.com https://firebasestorage.googleapis.com https://cdn.privacytools.com.br *.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com in1.api.clevertap.com sg1.api.clevertap.com us1.api.clevertap.com aps3.api.clevertap.com mec1.api.clevertap.com api.clevertap.com us1.clevertap-prod.com d2r1yp2w7bby2u.cloudfront.net s3-eu-west-1.amazonaws.com wzrkt.com *.avada.io *.shopify.com https://cdn.privacytools.com.br https://privacyportal-br-cdn.onetrust.com *.googletagmanager.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdn.privacytools.com.br https://fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com in1.api.clevertap.com sg1.api.clevertap.com us1.api.clevertap.com aps3.api.clevertap.com mec1.api.clevertap.com api.clevertap.com us1.clevertap-prod.com us1.clevertap.com wzrkt.com https://get.geojs.io *.avada.io https://cdn.privacytools.com.br *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com data: cdn.jsdelivr.net bonialconnect.com *.obi.si 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.googleapis.com *.bing.com *.doubleclick.net *.facebook.com *.google.si cdn.jsdelivr.net *.obi.si www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com *.doubleclick.net *.facebook.net *.googletagmanager.com *.hotjar.com cdn.jsdelivr.net *.obi.si unpkg.com bonialconnect.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app cdn.jsdelivr.net *.obi.si assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.googleapis.com *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://47738902-d1d8-4336-9c96-59f55199dfd3.sansec.watch/; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' http://*.mogucdn.com https://*.mogucdn.com http://*.juangua.com https://*.juangua.com http://*.meilishuo.com https://*.meilishuo.com http://*.meilishuo.net https://*.meilishuo.net http://*.mogujie.com https://*.mogujie.com http://*.qq.com https://*.qq.com http://*.mogujie.org https://*.mogujie.org http://*.meili-inc.com https://*.meili-inc.com http://*.mogu.com https://*.mogu.com http://*.mogu-inc.com https://*.mogu-inc.com; report-uri http://sd.mogujie.com/index.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com assets.bounceexchange.com *.bounceexchange.com *.bsscommerce.com fonts.googleapis.com *.googleapis.com *.arkswimwear.com *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com https://plugin-magento-ui.glopalservice.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com widgets.sandbox.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.bounceexchange.com dash.bounceexchange.com dash-staging.bounceexchange.com *.bounceexchange.com *.arkswimwear.com *.bsscommerce.com web-writer.sg.smartlook.cloud *.sg.smartlook.cloud c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com assets.bounceexchange.com events.bouncex.net *.bounceexchange.com *.bouncex.net *.bsscommerce.com bam.nr-data.net *.nr-data.net *.adobedtm.com *.arkswimwear.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com www.paypalobjects.com *.paypalobjects.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com pos.baidu.com *.baidu.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud ml314.com pixel.tapad.com *.tapad.com match.adsrvr.org *.adsrvr.org https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io t.zip.co static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.attn.tv events.attentivemobile.com *.googleapis.com *.bsscommerce.com *.arkswimwear.com *.adobedtm.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com www.google.co.in a.adroll.com *.adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.google-analytics.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com www.paypalobjects.com *.paypalobjects.com *.paypal.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com bam.nr-data.net idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud tag.wknd.ai tag.bounceexchange.com assets.bounceexchange.com api.bounceexchange.com dev.bounceexchange.com dash.bounceexchange.com dash-staging.bounceexchange.com *.wknd.ai *.bounceexchange.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com cdn1.stamped.io stamped.io static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.arkswimwear.com *.bsscommerce.com *.bounceexchange.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bsscommerce.com bam.nr-data.net *.nr-data.net *.arkswimwear.com *.adobedtm.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in a.adroll.com *.adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.google-analytics.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com www.paypalobjects.com *.paypalobjects.com t.paypal.com *.paypal.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src *.bsscommerce.com *.arkswimwear.com *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.typekit.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com web-writer.sg.smartlook.cloud *.sg.smartlook.cloud 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com www.facebook.com *.facebook.com graph.facebook.com business.facebook.com *.attn.tv events.attentivemobile.com *.googleapis.com events.bouncex.net coupons.bounceexchange.com *.cdnwidget.com *.cdnbasket.net *.bsscommerce.com bam.nr-data.net *.arkswimwear.com *.z.clarity.ms *.clarity.ms stats.g.doubleclick.net *.g.doubleclick.net manager.eu.smartlook.cloud *.smartlook.com www.google.co.in *.adobedtm.com *.adobe.com *.assets.adobedtm.com rec.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com www.paypalobjects.com *.paypalobjects.com t.paypal.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src blob: data: *; font-src 'self' data:; default-src 'none'; object-src 'none'; worker-src 'none'; connect-src 'self' *.algolia.net *.algolianet.com *.algolia.io; base-uri 'none'; style-src 'unsafe-inline' *; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-EM4yomIH2HxuAilZCHMxbg=='; media-src * 1 default-src 'self'; img-src 'self' data: https://tile.openstreetmap.org; object-src 'none'; script-src 'self' 'nonce-OVdKUGtyNmZJWDVBWjRxTjFlUUUwYw=='; style-src 'self' 'unsafe-inline'; report-to csp; report-uri /csp-report?parent_request_id=002h4eqv1mps2vuherj0&parent_request_id_hmac=0d3ddce0831fdcb54d9daa24ec811a6c294a11c4 1 default-src 'none'; connect-src 'self' www.google.com https://cdncache-a.akamaihd.net wss wss://generatorhostels.com ws1.hotjar.com ws2.hotjar.com ws3.hotjar.com ws4.hotjar.com ws5.hotjar.com graylog.hotjar.com cdnjs.cloudflare.com ajax.googleapis.com www.google-analytics.com stats.g.doubleclick.net wss://ws2.hotjar.com wss://ws3.hotjar.com wss://ws4.hotjar.com insights.hotjar.com generatorweb.sihot.com; font-src data null generatorweb.sihot.com maxcdn.bootstrapcdn.com fonts.gstatic.com 'self'; manifest-src 'self' generatorhostels.com; object-src 'self' generatorhostels.com; frame-src 'self' service.securesrv12.com secure.liveshoppersmac.com 3dsecure.klikbca.com geschuetzteinkaufen.commerzbank.de acs.sia.eu vcas1.visa.com www.securesuite.net acs1.edb.com secure5.arcot.com aacsw.3ds.verifiedbyvisa.com tpc.googlesyndication.com sas.redsys.es cdncache-a.akamaihd.net mastercardsecurecode.secureacs.com acs1.swedbank.se analytics-google.net https://acs2-3dsecure.cic.fr https://braip.com.br www.securesuite.co.uk secure.edb.com tsys.arcot.com secure7.arcot.com www.googletagmanager.com mozbar.moz.com www.facebook.com acs.airplus.com connect.facebook.net saferpay.com www.saferpay.com generatorweb.sihot.com generatorhostels.com bid.g.doubleclick.net staticxx.facebook.com vars.hotjar.com www.google.com www.instagram.com www.youtube.com w.soundcloud.com; img-src googleads.g.doubleclick.net butstrap.space https://spedcheck.space www.gstatic.com www.google.ge www.google.pl www.google.ru www.google.cm www.google.com.eg www.google.co.kr www.google.com.np www.google.co.th www.google.dz www.google.no www.google.com.hk www.google.com.mm www.google.co.il www.google.az www.google.sk www.google.ie www.google.com.pe lh3.ggpht.com www.google.de www.google.cz www.google.co.za www.google.se www.google.dk www.google.gr www.google.lv www.google.com.tw https://gateway.zscalertwo.net www.google.com.ph www.google.com.uy www.google.fi www.google.com.ua www.google.com.cy www.google.com.jm www.google.im www.google.co.ve www.google.com.sg www.google.ca www.google.es www.google.kg www.google.be www.google.at www.google.pt www.google.fr www.google.it www.google.com.br www.google.com.ar https://gallery.mailchimp.com www.google.ch www.google.me www.google.com.ec www.google.ro www.google.kg www.google.nl www.google.com.mx https://canvaspl-a.akamaihd.net https://cdnstats-a.akamaihd.net www.google.com.lb www.google.com.co www.google.com.tr www.google.cl www.google.dk www.google.co.in www.google.hr www.gstatic.com generatorweb.sihot.com generatorstorage.blob.core.windows.net generatorhostels.com cbks0.googleapis.com csi.gstatic.com data: geo0.ggpht.com geo1.ggpht.com geo2.ggpht.com geo3.ggpht.com img.youtube.com khms0.googleapis.com khms1.googleapis.com maps.googleapis.com maps.gstatic.com 'self' generator.azureedge.net ssl.google-analytics.com stats.g.doubleclick.net web.facebook.com www.facebook.com www.google.co.uk www.google.com www.google-analytics.com ajax.googleapis.com; media-src 'self' data:; script-src 'self' data blob about asset tpc.googlesyndication.com cdnjs.cloudflare.com cdn.jsdelivr.net www.thehotelsnetwork.com cdn.scarabresearch.com fdz.octapi.net data1.iti-maps.fr data1.itineraire.info asset about spedcheck.space rules.similardeals.net tags.clickintext.net lb.apicit.net butstrap.space https://cdncache-a.akamaihd.net secure.liveshoppersmac.com generatorweb.sihot.com maxcdn.bootstrapcdn.com ajax.googleapis.com api.instagram.com connect.facebook.net eval: googleads.g.doubleclick.net inline: maps.googleapis.com platform.instagram.com s.ytimg.com script.hotjar.com 'self' ssl.google-analytics.com static.hotjar.com 'unsafe-eval' 'unsafe-inline' www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.instagram.com www.youtube.com; style-src ajax.googleapis.com fonts.googleapis.com inline: 'self' 'unsafe-inline' maxcdn.bootstrapcdn.com generatorweb.sihot.com; report-uri https://crafted.report-uri.com/r/d/csp/reportOnly 1 worker-src blob:; form-action *.cardinalcommerce.com *.paypal.com www.sandbox.paypal.com *.amazon.com *.facebook.com *.googlesyndication.com connect.facebook.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.googletagmanager.com *.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.braintreegateway.com google.com js.stripe.com *.amazon.com *.payments-amazon.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com connect.facebook.net www.commercepartnerhub.com assets.braintreegateway.com plumrocket.com *.authorize.net www.googleadservices.com *.artifi.net assets.pinterest.com ct.pinterest.com www.paypalobjects.com i.liadm.com 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net *.google.com *.newrelic.com *.nr-data.net *.authorize.net *.commerce-payment-services.com *.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klaviyo.com fast.a.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.shopify.com *.sandbox.braintreegateway.com celebrosnlp.com *.celebros-analytics.com maps.googleapis.com www.googletagservices.com cdn.gladly.qa cdn.gladly.com *.cloudflare.com *.artifi.net *.monetate.net cdn.popt.in *.visualwebsiteoptimizer.com *.cloudfront.net s.pinimg.com bat.bing.com tag.rmp.rakuten.com ut.rd.linksynergy.com *.pinterest.com cdn.noibu.com *.hotjar.com b-code.liadm.com secure.merchantadvantage.com static.lillianvernon.com lillianv-ac.celebros.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://www.lillianvernon.com/pr-csp/report/add/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com *.hotjar.com fonts.googleapis.com cdn.cookiehub.eu https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.networkmerchants.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com googleads.g.doubleclick.net secure.livechatinc.com *.weltpixel.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.amazonaws.com bat.bing.com cdn.ywxi.net blob *.instantsearchplus.com *.bbb.org cdn.livechat-files.com *.facebook.com *.hotjar.com *.clarity.ms *.bing.com *.google.com.ar www.doubleclick.net cdn.cookiehub.eu p.brsrvr.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.networkmerchants.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.certcapture.com *.fontawesome.com *.livechatinc.com bat.bing.com *.clarity.ms 199001.tctm.co *.facebook.net *.facebook.com *.cokertirecompany.com *.hotjar.com e.zip-corvette.com www.googletagservices.com www.doubleclick.net cdn.cookiehub.eu cdn.brcdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.networkmerchants.com *.certcapture.com *.bootstrapcdn.com static-autocomplete.fastsimon.com ping.fastsimon.com settings.fastsimon.com static-grid.fastsimon.com *.typekit.net cdn.cookiehub.eu cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://cokertire.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.clarity.ms api.livechatinc.com bat.bing.com api.fastsimon.com suggest.instantsearchplus.com suggest.fastsimon.com static-autocomplete.fastsimon.com static-grid.fastsimon.com ping.fastsimon.com settings.fastsimon.com stats.g.doubleclick.net bam.nr-data.net 199001.tctm.co *.facebook.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com googleads.g.doubleclick.net cdn.cookiehub.eu c.ba.contentsquare.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' chrome-extension: https://mc.yandex.ru 'unsafe-inline' 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://mc.yandex.ru chrome-extension: https://mc.yandex.com; object-src 'self'; report-uri /cspreportonly; 1 frame-ancestors 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://3dsgate.borica.bg/ secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-src td.doubleclick.net player.flipsnack.com/ fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com/ https://plumrocket.com *.weltpixel.com 'self' 'unsafe-inline'; font-src maxcdn.bootstrapcdn.com fonts.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; connect-src app.avada.io www.google-analytics.com stats.g.doubleclick.net/j/ region1.analytics.google.com maps.googleapis.com/maps/api/mapsjs/gen_204?csp_test=true maps.googleapis.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.ingest.sentry.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io https://www.google-analytics.com *.google-analytics.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; script-src 'self' app.avada.io connect.facebook.com connect.facebook.net facebook.com googleads.g.doubleclick.net www.google-analytics.com www.google.com/pagead/ www.google.bg/pagead/ www.facebook.com/tr/ maps.googleapis.com i.adwise.bg static.hotjar.com https://script.hotjar.com/ https://www.google.com/ https://www.gstatic.com/recaptcha/releases/u-xcq3POCWFlCr3x8_IPxgPu/recaptcha__en.js assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com www.apptrian.com www.facebook.com graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.google.com/ https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src data: www.google.com www.google.bg maps.googleapis.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.gstatic.com *.facebook.com *.reddit.com 'self' 'unsafe-inline'; style-src fonts.googleapis.com temax.bg getfirebug.com downloads.mailchimp.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https:// https://1hbotx6kw4.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://www.pixum.de https://1hbotx6kw4.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 font-src https://fonts.gstatic.com userlike-cdn-umm.b-cdn.net *.gstatic.com data: *.cloudfront.net *.mey.com app.usercentrics.eu 'self' data: 'self' 'unsafe-inline';form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com 'self' 'unsafe-inline';frame-ancestors https://*.etracker.com www.gstatic.com 'self';frame-src *.google.com vimeo.com player.vimeo.com charger-v2.trbo.com static.trbo.com track2.trbo.com collect.trbo.com https://www.googletagmanager.com https://td.doubleclick.net player.vimeo.com *.youtube-nocookie.com *.youtube.com https://collect.mey.com https://*.criteo.com userlike-cdn-umm.b-cdn.net userlike-cdn-widgets.s3-eu-west-1.amazonaws.com api.userlike.com https://static.criteo.net *.zenaps.com *.awin1.com bid.g.doubleclick.net td.doubleclick.net ct.pinterest.com www.awin1.com fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de ad.ad-srv.net *.adsrvr.org *.fls.doubleclick.net www.facebook.com opt.kuponacdn.de gum.criteo.com pixel.mathtag.comm pp.payengine.de pptest.payengine.de checkoutshopper-test.adyen.com/ checkoutshopper.adyen.com/ 'self' 'unsafe-inline';img-src *.googleusercontent.com https://*.gstatic.com https://*.googleapis.com *.cdninstagram.com static.trbo.com track2.trbo.com collect.trbo.com https://*.google.nl https://*.google.be https://*.google.at https://*.google.ch https://*.google.it https://*.google.es https://*.google.fr https://*.google.dk https://*.google.lu https://*.google.ca https://*.google.ie https://*.google.pt https://*.google.si https://*.google.co.uk https://*.google.pl https://*.google.com.hk https://*.google.gr https://*.google.com.sg https://*.google.se https://*.google.no https://*.google.ad https://*.google.ru https://*.google.fi https://*.google.co.in https://*.google.com.ua https://*.google.hr https://*.google.hu https://*.google.com https://*.google.com.tr https://*.google.co.jp https://*.google.com.sa https://*.google.md https://*.google.com.br https://*.google.rs https://*.google.com.tw https://*.google.ee https://*.google.co.th https://*.google.jo https://*.google.com.qa https://*.google.kz https://*.google.com.ar https://*.google.tn https://*.google.li https://*.google.sk https://*.google.com.vn https://*.google.ae https://*.google.lv https://*.google.co.kr https://*.google.bf https://*.google.ro https://*.google.co.il https://google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.google.com https://googleads.g.doubleclick.net https://www.googletagmanager.com *.vimeocdn.com https://*.outbrain.com https://*.roeye.com https://www.wepowerconnections.com userlike-store-media-files.s3.amazonaws.com www.userlike.com userlike-cdn-web.b-cdn.net userlike-cdn-operators.s3-eu-west-1.amazonaws.com userlike-cdn-operators.userlike.com ct.pinterest.com bat.bing.com *.zenaps.com *.awin1.com googleads.g.doubleclick.net www.etracker.de id5-sync.com s.thebrighttag.com beacon.krxd.net *.google.de *.google.com ads.creative-serving.com *.uimserv.net *.adnxs.com ups.analytics.yahoo.com visitor.omnitagjs.com *.ad.smaato.net matching.ivitrack.com exchange.mediavine.com *.taboola.com *.stickyadstv.com criteo-sync.teads.tv cm.adform.net sync-criteo.ads.yieldmo.com ad.sxp.smartclip.net *.emxdgt.com criteo-partners.tremorhub.com sync.outbrain.com *.3lift.com *.smartadserver.com ads.yahoo.com *.casalemedia.com *.bidswitch.net *.twiago.com contextual.media.net match.sharethrough.com *.pubmatic.com cdn.stickyadstv.com *.adscale.de ad.360yield.com sp.analytics.yahoo.com ad.yieldlab.net cotads.adscale.de *.criteo.com *.liadm.com pixel.rubiconproject.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.awin1.com *.bing.com *.cloudfront.net stats.g.doubleclick.net *.doubleclick.net *.g.doubleclick.net www.facebook.com www.google.com www.google.de www.googletagmanager.com *.usercentrics.eu *.adfarm1.adition.com *.adition.com *.pinterest.com pixel.mathtag.com *.adnxs.com checkoutshopper-test.adyen.com/ checkoutshopper.adyen.com/ *.mey.com *.clarity.ms app.usercentrics.eu api.usercentrics.eu aggregator.service.usercentrics.eu 'self' data: 'self' 'unsafe-inline';script-src *.googleusercontent.com https://*.ggpht.com https://*.gstatic.com https://*.googleapis.com www.instagram.com platform.instagram.com player.vimeo.com charger-v2.trbo.com static.trbo.com api-v4.trbo.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net *.vimeocdn.com www.vimeo.com vimeo.com https://*.roeyecdn.com https://tagmanager.google.com https://googletagmanager.com https://www.googletagmanager.com https://*.outbrain.com ct.pinterest.com https://*.criteo.com *.zenaps.com *.awin1.com collect.mey.com userlike-cdn-umm.b-cdn.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com cdn.polyfill.io www.googleoptimize.com browser.sentry-cdn.com *.etracker.de *.etracker.com *.google.de *.google.com assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.googletagmanager.com *.adyen.com *.googleapis.com www.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jquery.sellxed.com *.adform.net *.amazon.com js.adsrvr.org www.awin1.com bat.bing.com *.dt51.net *.cloudfront.net googleads.g.doubleclick.net www.dwin1.com connect.facebook.net www.google.com *.google-analytics.com www.gstatic.com mastertag.kpcustomer.de opt.kuponacdn.de bam.nr-data.net bam.eu01.nr-data.net js-agent.newrelic.com static.shopgate.com the.sciencebehindecommerce.com tagmanager.google.com *.usercentrics.eu *.kuponacdn.de app.theadx.com browser-update.org pixel.mathtag.com pptest.payengine.de *.adnxs.com static.criteo.net s.pinimg.com sslwidget.criteo.com *.clarity.ms *.mey.com *.google.com *.gstatic.com app.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval';style-src https://fonts.googleapis.com static.trbo.com https://tagmanager.google.com https://googletagmanager.com https://www.googletagmanager.com *.adobe.com fonts.googleapis.com *.usercentrics.eu *.cloudfront.net *.mey.com *.googleapis.com *.gstatic.com app.usercentrics.eu 'self' 'unsafe-inline';object-src 'self' 'unsafe-inline';media-src *.cdninstagram.com www.userlike.com userlike-store-media-files.s3.amazonaws.com userlike-cdn-umm.b-cdn.net *.adobe.com blob: 'self' 'unsafe-inline';manifest-src 'self' 'unsafe-inline';connect-src https://*.gstatic.com https://*.googleapis.com www.instagram.com platform.instagram.com *.cdninstagram.com vimeo.com player.vimeo.com data.trbo.com newsletter-api.trbo.com api-v4.trbo.com *.snplow.net commerce.adobedc.net *.adobe.io https://www.google.com https://google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://player.vimeo.com vimeo.com http://bat.bing.net https://*.outbrain.com www.userlike.com userlike-cdn-web.b-cdn.net umd.userlike.com wss://umd.userlike.com ct.pinterest.com https://*.etracker.de https://*.criteo.com https://*.wepowerconnections.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://collect.mey.com https://*.googletagmanager.com *.addressy.com maps.googleapis.com userlike-cdn-umm.b-cdn.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com sentry.mey.netz98.org eu-api.friendlycaptcha.eu www.etracker.de www.facebook.com www.clarity.ms dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de stats.g.doubleclick.net mey.dvinci-hr.com bam.eu01.nr-data.net the.sciencebehindecommerce.com *.usercentrics.eu aggregator.service.usercentrics.eu bat.bing.com *.pinterest.com *.google-analytics.com *.maps.googleapis.com *.mey.com *.cloudfront.net *.clarity.ms www.googletagmanager.com app.usercentrics.eu api.usercentrics.eu aggregator.service.usercentrics.eu blob: 'self' 'unsafe-inline';child-src userlike-cdn-umm.b-cdn.net userlike-cdn-widgets.s3-eu-west-1.amazonaws.com api.userlike.com http: https: blob: 'self' 'unsafe-inline';default-src https://*.outbrain.com https://*.clarity.ms https://c.bing.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval';base-uri 'self' 'unsafe-inline';report-uri https://sentry.mey.netz98.org/api/2/security/?sentry_key=81ac2c0efc304bedbb370dc8e745b346&sentry_environment=stage3;report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.bootstrapcdn.com *.gstatic.com *.typekit.net *.hotjar.com *.audioeye.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://www.gstatic.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.authorize.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com *.doubleclick.net *.leasestation.com *.kaptcha.com *.google.com *.google.co.in *.networkmerchants.com *.paypalobjects.com *.cdn-btsg.com *.audioeye.com *.milwaukeetool.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net *.ohiopowertool.com https://seal-centralohio.bbb.org *.google.com *.google.co.in *.bing.com *.clarity.ms *.amazonaws.com *.shareasale.com *.nexmart.com *.noibu.com *.cdn-btsg.com *.quickspark.com *.bazaarvoice.com https://arttrk.com/ *.hotjar.com *.userway.org *.ojrq.net *.linkedin.com https://cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.sandbox.paypal.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com www.apptrian.com *.affirm.com *.affirm.ca apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com utt.impactcdn.com *.authorize.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox-assets.secure.checkout.visa.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://www.dwin1.com https://seal-centralohio.bbb.org *.bing.com *.quickspark.com *.doubleclick.net *.clarity.ms *.nr-data.net *.newrelic.com *.google.com *.networkmerchants.com *.milwaukeetool.com *.noibu.com *.cdn-btsg.com *.pricespider.com *.hotjar.com *.audioeye.com *.impactcdn.com *.online-metrix.net *.userway.org *.gstatic.com *.licdn.com https://cdn.cookielaw.org *.roeyecdn.com *.epigraph.cloud https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com display.ugc.bazaarvoice.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com *.mailchimp.com *.bootstrapcdn.com *.quickspark.com *.networkmerchants.com *.gstatic.com *.googleapis.com *.userway.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com *.affirm.com *.affirm.ca api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://imgs.signifyd.com *.doubleclick.net *.clarity.ms *.nr-data.net *.networkmerchants.com *.bing.com *.noibu.com wss://*.noibu.com *.cdn-btsg.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.audioeye.com *.sjv.io *.userway.org *.linkedin.com https://cdn.cookielaw.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com strict-dynamic http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com https://script.hotjar.com *.algolia.com *.googleapis.com *.bootstrapcdn.com https://*.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.kohlerbycochez.com network-a.bazaarvoice.com maps.gstatic.com *.algolia.com media.flixcar.com rt.flix360.com *.google.com *.google-analytics.com *.googleadservices.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com https://*.bazaarvoice.com https://*.google.com.pa data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://apps.bazaarvoice.com *.kohlerbycochez.com apps.bazaarvoice.com static.hotjar.com script.hotjar.com h.online-metrix.net js-agent.newrelic.com www.google.com www.gstatic.com maps.googleapis.com *.algolia.com media.flixfacts.com media.flixcar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://cdn.jsdelivr.net https://view.publitas.com https://scripts.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com *.algolia.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com videos.pexels.com *.algolia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kohlerbycochez.com bam.nr-data.net maps.googleapis.com https://surveystats.hotjar.io media.flixcar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://*.bazaarvoice.com https://*.hotjar.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net *.kohlerbycochez.com ws.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.bunny.net cdn.jsdelivr.net cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com www.facebook.com interface.mailcampaigns.nl *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.addthis.com js.mollie.com *.multisafepay.com https://pay.google.com https://plumrocket.com www.googletagmanager.com *.doubleclick.net tagging.proforto.nl www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.disqus.com https://img.youtube.com https://www.mollie.com *.multisafepay.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com px.ads.linkedin.com bat.bing.com www.google.nl t.squeezely.tech www.facebook.com region1.analytics.google.com www.google.fr *.faslet.net trengo.s3.eu-central-1.amazonaws.com *.mailcampaigns.nl *.doubleclick.net cdn.proforto.nl tagging.proforto.nl images.prismic.io proforto-cdn.imgix.net https://maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; style-src *.adobe.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.multisafepay.com tagmanager.google.com fonts.google.com fonts.bunny.net *.faslet.net *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.trengo.eu player.vimeo.com *.vimeocdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src https://tagging.proforto.nl dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com www.google.com b.billypx.com px.ads.linkedin.com analytics.tiktok.com *.doubleclick.net rkkck31tec.execute-api.eu-central-1.amazonaws.com api.faslet.net cdn.api.prod.faslet.net bat.bing.com bat.bing.net p2iqhncxyh.execute-api.eu-central-1.amazonaws.com pagead2.googlesyndication.com metrics.hotjar.io *.trengo.eu *.convertexperiments.com tagging.proforto.nl *.tiktokw.us wss://*.hotjar.com interface.mailcampaigns.nl *.yotpo.com https: 'self' 'unsafe-inline'; script-src https://tagging.proforto.nl assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net js.mollie.com *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com cdn-4.convertexperiments.com connect.facebook.net static.hotjar.com script.hotjar.com analytics.tiktok.com bat.bing.com squeezely.tech snap.licdn.com bgmin.cdn.billygrace.com d5yoctgpv4cpx.cloudfront.net widget.prod.faslet.net player.vimeo.com *.trengo.eu localhost:5174 *.proforto.nl *.yotpo.com https: 'self' 'unsafe-inline' 'unsafe-eval'; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-tmfQjDSWovn9dY11Gzy6SQ==' 1 default-src 'self'; script-src 'report-sample' 'self' https://app-script.monsido.com/v2/monsido-script.js https://apps.usw2.pure.cloud/genesys-bootstrap/genesys.min.js https://connect.facebook.net/en_US/fbevents.js https://js.adsrvr.org/up_loader.1.1.0.js https://s.swiftypecdn.com/install/v2/st.js https://sc-static.net/scevent.min.js https://ssl.google-analytics.com/ga.js https://static.ads-twitter.com/uwt.js https://tr.snapchat.com/config/com/f46d0350-ae7f-4886-b620-b497a4d93c9f.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://capidashboard.ialottery.com https://tr.snapchat.com https://tr6.snapchat.com https://www.google-analytics.com; font-src 'self'; frame-src 'self' https://10921257.fls.doubleclick.net https://apps.usw2.pure.cloud https://insight.adsrvr.org https://pixel-sync.sitescout.com https://tr.snapchat.com https://www.youtube.com; img-src 'self' https://analytics.twitter.com https://ssl.google-analytics.com https://t.co https://tracking.monsido.com https://www.facebook.com https://www.google.com; manifest-src 'self'; media-src 'self'; report-uri https://668597ef014602b312931fd2.endpoint.csper.io/?v=0; worker-src 'none'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://matomo.eah-jena.de/matomo.js https://*.openstreetmap.org 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://www.studycheck.de https://*.typo3.org https://https//www.studycheck.de/%2A https://matomo.eah-jena.de/matomo.php; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://www2.hochschulsport.eah-jena.de; connect-src 'self' data: https://*.openstreetmap.org https://www.eah-jena.de https://matomo.eah-jena.de; font-src 'self' data:; style-src blob: data: 'self' 'unsafe-inline' 'report-sample'; worker-src blob: 'report-sample'; report-uri https://www.eah-jena.de/@http-reporting?csp=report&requestTime=1765942610417420&requestHash=8ecb56acd6336e91dc8fd29a38d235ca35154c3c 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.g.doubleclick.net https://tpc.googlesyndication.com/sodar/sodar2/225/runner.html *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.google.com *.google.com.ar *.googlesyndication.com *.googleapis.com *.googletagmanager.com *.facebook.com blob: https://www.magezon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://desa.infonet.com.py:8035 https://*.bancard.com.py 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.g.doubleclick.net *.googlesyndication.com *.google.com.ar *.googleadservices.com *.googleapis.com *.nr-data.net *.facebook.net *.newrelic.com tracker.metricool.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com https://vpos.infonet.com.py:8888 https://vpos.infonet.com.py 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googlesyndication.com *.g.doubleclick.net *.googleapis.com *.nr-data.net *.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.playpilot.com *.playpilot.tech *.userback.io *.fonts.googleapis.com *.gstatic.com *.google-analytics.com; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data:; frame-src *; connect-src *; media-src *; worker-src * 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google.com https://*.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://www.jablonet.net https://connect.facebook.net https://requestor.bezpecnostnicentrum.cz https://logbook.jablonet.net https://logbook-dev.jablonet.net https://logbook-stg.jablonet.net https://logbook-val.jablonet.net; report-uri https://files.jablonet.net/security-policy/csp.php; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri https://www.miteksystems.com/report-uri/reportOnly 1 object-src 'none';base-uri 'self';script-src 'nonce-LcSSHLLqx0H8xq/R6nJW' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 report-uri https://o7202.ingest.us.sentry.io/api/278133/security/?sentry_key=3fa89efb7ac645f5820f641a4e80c50f&sentry_environment=production; report-to csp-endpoint; default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; connect-src * data: blob:; img-src * data: blob:; style-src * 'unsafe-inline' data: blob:; media-src * data: blob:; font-src * data: blob:; object-src * data: blob:; frame-src * data: blob:; worker-src * data: blob:; manifest-src * data: blob:; frame-ancestors *; 1 font-src https://fonts.gstatic.com/ maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.portmone.com.ua https://td.doubleclick.net/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.googleapis.com https://maps.gstatic.com https://maps.googleapis.com https://www.googleadservices.com https://www.google-analytics.com https://www.google.ca/pagead https://www.google.ca/pagead/1p-user-list/ https://www.google.ca/ads/ga-audiences magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googleapis.com https://maps.gstatic.com https://maps.googleapis.com https://www.googleadservices.com https://www.google-analytics.com www.gstatic.com *.googletagmanager.com *.google-analytics.com www.portmone.com.ua https://connect.facebook.net https://www.google.ca/pagead/1p-user-list/ https://www.google.ca/ads/ga-audiences https://tools.luckyorange.com https://cdn.polyfill.io https://browser.sentry-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://www.openlayers.org/api/OpenLayers.js http://openlayers.org/api/OpenLayers.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com *.googletagmanager.com *.google-analytics.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.googleapis.com https://maps.gstatic.com https://maps.googleapis.com https://www.google-analytics.com https://www.googleadservices.com *.googletagmanager.com *.google-analytics.com *.stats.g.doubleclick.net gate.portmone.com.ua https://pagead2.googlesyndication.com/pagead/buyside_topics/set/ https://stats.g.doubleclick.net https://tools.luckyorange.com https://settings.luckyorange.com https://*.ingest.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://cdn.omise.co *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.youtube.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.gstatic.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gateway.apaylater.com gateway.atome.sg ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.facebook.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.googleapis.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://cdn.omise.co gateway.apaylater.com gateway.atome.sg *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.googletagmanager.com *.facebook.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com unsafe-inline gateway.apaylater.com gateway.atome.sg cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://cdn.omise.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.nr-data.net *.newrelic.com *.ampproject.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 img-src https://indigitall-cdn.com *.force.com slack-imgs-mil-dev.com https://www.google.cl 'self' https://lapolartarjeta.my.salesforce.com https://lapolartarjeta.file.force.com https://stats.g.doubleclick.net https://img.youtube.com https://lapolartarjeta--qa--c.documentforce.com https://www.lapolar.cl https://www.google.com.br https://payments.salesforce.com/icons/ https://www.facebook.com https://login.salesforce.com/icons/ https://eu2.device-api.indigitall.com soluciones.devetel.net https://srvsw.lapolar.cl:9051 *.documentforce.com https://lapolartarjeta--botonpago--c.visualforce.com https://www.gstatic.com *.slack-edge-gov.com http://placehold.it *.my-salesforce.com https://lapolar.qservus.com *.cloudinary.com https://www.google.com https://api.ipify.org https://certif.upago.cl https://dev.db5bbba2911wg.amplifyapp.com *.amazonaws.com blob: http://via.placeholder.com *.redcalidad.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com https://staging.d1jacr2a8kiddz.amplifyapp.com https://ssl.gstatic.com *.twimg.com abcpass.tarjetaabc.cl https://cdn.wallpaperhub.app https://5cap.dec.cl https://usa342.sfdc-yfeipo.salesforce.com/icons/ https://qa-lapolartarjeta.cs123.force.com *.slack.com https://www.paypal.com https://lapolartarjeta.builder.salesforce-communities.com *.slack-imgs.com slack-imgs-gov.com https://inbox-api.indigitall.com https://cdn-qservus.redcalidad.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://fingerprint.api.vusecurity.com http://source.unsplash.com https://webfly-p4.abcd.envs.veritran.com https://micuenta.tarjetalapolar.cl https://source.unsplash.com https://tarjetalapolar.force.com https://lapolartarjeta--dev.livepreview.salesforce-communities.com slack-imgs-gov-dev.com *.slack-edge.com abcpass-qa.tarjetaabc.cl https://indigitall.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://fonts.googleapis.com https://inapp-api.indigitall.com slack-mil-dev.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://lapolartarjeta--c.visualforce.com https://qs28.qservus.com *.qservus.com validacionidentidad.tarjetaabc.cl https://www.google.com/recaptcha/ https://dev-lapolartarjeta.cs2.force.com https://webfly-p4.abcq.veritran.com *.slack-edge.mil https://www.sandbox.paypal.com https://www.abc.cl https://device-api.indigitall.com https://qa-lapolartarjeta.cs197.force.com https://i.vimeocdn.com *.tarjetalapolar.cl https://www.googletagmanager.com https://eu2.indigitall-cdn.com https://use.fontawesome.com *.salesforce.com https://www.google-analytics.com https://*.adyen.com slack-imgs.mil https://www.tarjetalapolar.cl data:; report-to sfdc-csp-ep; report-uri https://lapolartarjeta.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D3k000000tOhd&networkId=0DM3k000000kdPK&type=communities 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: cdnjs.cloudflare.com 'self' data: https://static.klaviyo.com/ *.livehelpnow.net *.clearbags.com *.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.certcapture.com *.trustpilot.com js.driftt.com vars.hotjar.com photos.pixlee.co c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * clearbags.sjv.io https://static.klaviyo.com https://www.klaviyo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.certcapture.com *.cloudfront.net *.edgecastcdn.net wac.edgecastcdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://staging.clearbags.cloud/ *.brandlock.io *.bing.com *.trkn.us trkn.us *.adsrvr.org *.linkedin.com *.rlcdn.com *.clearbags.com *.facebook.com *.google.pl *.livehelpnow.net *.bizrate.com *.xg4ken.com *.pixlee.com *.simpleanalyticscdn.com *.sansec.io *.itstarsbuilding.com *.google.com *.visualwebsiteoptimizer.com *.ojrq.net clearbags.sjv.io *.logs-01.loggly.com editor-upload-cdn.optimonk.com https://www.klaviyo.com https://trk.klaviyo.com https://www.google-analytics.com https://static.klaviyo.com https://*.klaviyo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.attn.tv events.attentivemobile.com *.certcapture.com *.trustpilot.com *.hotjar.com chimpstatic.com *.mailchimp.com *.list-manage.com js.driftt.com cdn.searchspring.net *.turnto.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.googletagmanager.com tagmanager.google.com *.pinimg.com *.amazonawx.com *.pixlee.com *.cnnx.link *.licdn.com *.bing.com *.cloudfront.net *.taboola.com *.facebook.com *.livehelpnow.net *.amazonaws.com *.facebook.net *.noibu.com *.xg4ken.com *.linksynergy.com *.liadm.com *.pxlecdn.com *.clearbags.com *.pinterest.com *.itstarsbuilding.com *.thoughtmetric.io *.impactcdn.com clearbags.sjv.io front.optimonk.com gs-cdn.optimonk.com cdn-asset.optimonk.com 'unsafe-inline' 'unsafe-eval' *static.klaviyo.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com cdnjs.cloudflare.com cdn.searchspring.net *.turnto.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com https://static-tracking.klaviyo.com/ https://static.klaviyo.com 'unsafe-inline' *.noibu.com *.livehelpnow.net *.clearbags.com cdn-asset.optimonk.com front.optimonk.com 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.attn.tv events.attentivemobile.com *.certcapture.com in.hotjar.com *.hotjar.io *.turnto.com *.searchspring.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.livehelpnow.net *.noibu.com *.demdex.net *.pinterest.com *.linkedin.com *.facebook.com *.taboola.com wss://input.noibu.com *.liadm.com wss://app.livehelpnow.net *.doubleclick.net *.pixlee.com *.userway.org *.brandlock.io bat.bing.com *.thoughtmetric.io *.visualwebsiteoptimizer.com *.itstarsbuilding.com *.amazonaws.com clearbags.sjv.io https://a.klaviyo.com https://b.klaviyo.com https://trk.klaviyo.com https://analytics.klaviyo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.clearbags.com/csp/csp/report; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://recaptcha.net/ https://gstatic.com/ https://www.recaptcha.net/ https://www.gstatic.com/ https://assets.adobedtm.com/; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net/ https://recaptcha.net/ https://gstatic.com/; font-src 'self' https://cdn.jsdelivr.net/; img-src 'self' https: data: blob:; connect-src https:; frame-src 'self' https://recaptcha.net/ https://gstatic.com/ https://www.recaptcha.net/ https://www.gstatic.com/ https://clydesdalebankplc.demdex.net/; frame-ancestors 'none'; 1 default-src 'self' 'unsafe-inline' blob: data: https:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' http://*.quantserve.com https: https://*.doubleclick.net https://*.teads.tv; worker-src 'self' blob:; connect-src 'self' https: wss:; img-src 'self' https:; frame-src 'self' http://*.trendmicro.com https:; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.careem-pay.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: www.searchanise.com *.searchserverapi.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://checkout.payfort.com www.searchanise.com *.searchserverapi.com *.twitter.com searchserverapi1.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com mindmup.github.io *.b-cdn.net *.tap.company *.careem-pay.com https://player.vimeo.com https://www.youtube-nocookie.com www.searchanise.com *.searchserverapi.com *.twitter.com searchserverapi1.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.visa.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.b-cdn.net flagpedia.net blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com searchserverapi1.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.visa.com *.mastercard.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.b-cdn.net *.careem-pay.com *.cloudflare.com *.avada.io *.gstatic.com maps.googleapis.com https://player.vimeo.com https://www.youtube.com 'unsafe-inline' searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com searchserverapi1.com searchserverapi.com cdn.amplitude.com https://ipinfo.io https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.b-cdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com https://fonts.googleapis.com http://fonts.googleapis.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com searchserverapi1.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.dev.tap.company *.tap.company https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.amplitude.com stats.g.doubleclick.net searchserverapi1.com api2.amplitude.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors https://*.fls.doubleclick.net https://ben-campagnes.ben.nl https://ben-campagnes.nl https://beninruil.valyuu.com https://dekkingskaart.odido.nl https://web.cmp.usercentrics.eu https://*.ben.nl https://www.youtube.com; report-uri /report-csp-violation 1 script-src-elem 'self' 'unsafe-inline' https://script.hotjar.com/modules.e4b2dc39f985f11fb1e4.js https://static.hotjar.com/c/hotjar-4972391.js https://euassets.gulfoilltd.com/ https://www.youtube.com/ https://platform.twitter.com/ https://www.gstatic.com/ https://secure.data-insight365.com/js/265784.js https://www.google-analytics.com/analytics.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.hotjar.com/c/hotjar-3470892.js https://snap.licdn.com/li.lms-analytics/insight.old.min.js https://script.hotjar.com/modules.2de3322c0609a6da3702.js https://connect.facebook.net/signals/config/214369947959115 https://secure.data-insight365.com/Track/Capture.aspx https://connect.facebook.net/signals/config/515690463347689 https://script.hotjar.com/modules.cf637fb03b42388e3bf3.js https://script.hotjar.com/browser-perf.33dcc26815d7481e62e8.js https://script.hotjar.com/modules.12bb18a8ada54a042e86.js cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://connect.facebook.net/en_US/fbevents.js https://script.hotjar.com/browser-perf.8417c6bba72228fa2e29.js https://script.hotjar.com/modules.4bbac2bdc7f1b66d3009.js https://www.googletagmanager.com/ https://pbs.twimg.com https://script.hotjar.com/modules.60031afbf51fb3e88a5b.js https://script.hotjar.com/modules.3128f1ee3ce5b65c4961.js https://a.usbrowserspeed.com https://secure.data-insight365.com https://script.hotjar.com/modules.a3cb6dcf71aec7e1a87f.js https://script.hotjar.com/sentry.58c81e3e25532810f6fd.js https://script.hotjar.com/ https://static.addtoany.com https://www.gstatic.com; style-src 'self' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com netdna.bootstrapcdn.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://euassets.gulfoilltd.com/ https://script.hotjar.com/modules.0ef46a83101151841364.js https://cdn.fonts.net/t/1.css cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com netdna.bootstrapcdn.com; frame-ancestors 'self' 1 default-src 'self' data: wss: *.episerver.net *.readspeaker.com *.arcgisonline.nl *.arcgisonline.com *.arcgis.com *.google.com *.googleapis.com *.hotjar.com *.hotjar.io *.prorail.nl *.spoordata.nl *.werkenbijprorail.nl *.youtube-nocookie.com www.google.nl www.googletagmanager.com px.ads.linkedin.com www.google-analytics.com https://www.gstatic.com/recaptcha/ https://www.recaptcha.net https://prorail.projectatlas.app *.cookiebot.com connect.facebook.net www.facebook.com snap.licdn.com *.bing.com *.clarity.ms *.clarity.ml *.indeed.com *.talent.com *.doubleclick.net bs.serving-sys.com connect.facebook.com pagead2.googlesyndication.com s2.adform.net sc-static.net secure.adnxs.com secure-ds.serving-sys.com secure-ds-serving-sys.com static.jobrapido.com *.snapchat.com track.adform.net www.googleadservices.com *.joboti.com joboti-widget.azurewebsites.net res.cloudinary.com http://res.cloudinary.com netdna.bootstrapcdn.com www.geluidregister.nl cdn.starred.com cdn.jsdelivr.net www.redditstatic.com *.reddit.com *.billypx.com *.cdn.billygrace.com onesignal.com cdn.onesignal.com api.onesignal.com 'unsafe-inline' 'unsafe-eval'; 1 script-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://www.googletagmanager.com https://geolocation.onetrust.com https://maps.googleapis.com/ https://js.monitor.azure.com azure.com https://www.google-analytics.com https://www.google.com https://amrest.containers.piwik.pro https://amrest.piwik.pro/ppms.js https://cdnjs.cloudflare.com https://unpkg.com https://www.gstatic.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://maps.googleapis.com/ https://js.monitor.azure.com azure.com https://www.google.com https://amrest.containers.piwik.pro https://amrest.piwik.pro/ppms.js https://cdnjs.cloudflare.com https://unpkg.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com blob: https://www.gstatic.com https://www.google.com https://cdnjs.cloudflare.com https://unpkg.com; base-uri 'self'; frame-ancestors 'self'; report-uri https://www.amrest.eu/en/report-uri/reportOnly 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com static.zdassets.com *.instant.one *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com www.google.com *.limepay.com.au www.xtento.com *.instant.one c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.sharethis.com https://widgets.dev.optty.com https://widgets.optty.com www.xtento.com cdn.xtento.com *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com *.facebook.com *.facebook.net *.cardinalcommerce.com includestest.ccdc02.com *.authorize.net *.braintreegateway.com s.ytimg.com assets.adobedtm.com *.magento-ds.com *.plugins.emarsys.net *.scarabresearch.com *.limepay.com.au *.zdassets.com *.instant.one *.paypal.com *.google.com *.cloudflare.com *.yotpo.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.zipmoney.com.au *.zip.co *.hotjar.com *.hotjar.io *.googletagservices.com *.pinimg.com *.pinterest.com *.clarity.ms *.zendesk.com *.google.co.in *.zopim.com *.doubleclick.net *.criteo.com theblockshop.api.useinsider.com *.sli-spark.com *.newrelic.com *.amazonaws.com bam.nr-data.net wss://widget-mediator.zopim.com pagead2.googlesyndication.com public-prod-dspcookiematching.dmxleo.com static.secure-afterpay.com.au *.afterpay.com *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com *.reddit.com *.google-analytics.com *.googletagmanager.com dhv2ziothpgrr.cloudfront.net t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://api.addressfinder.io *.sharethis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.plugins.emarsys.net *.scarabresearch.com *.limepay.com.au https://widgets.dev.optty.com https://widgets.optty.com www.xtento.com cdn.xtento.com *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.authorize.net *.braintreegateway.com *.zdassets.com *.instant.one *.paypal.com *.google.com *.cloudflare.com *.yotpo.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.zipmoney.com.au *.zip.co *.hotjar.com *.hotjar.io *.googletagservices.com *.pinimg.com *.pinterest.com *.clarity.ms *.zendesk.com *.google.co.in *.zopim.com *.doubleclick.net *.criteo.com theblockshop.api.useinsider.com *.sli-spark.com *.newrelic.com *.amazonaws.com bam.nr-data.net wss://widget-mediator.zopim.com pagead2.googlesyndication.com public-prod-dspcookiematching.dmxleo.com static.secure-afterpay.com.au *.afterpay.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com dhv2ziothpgrr.cloudfront.net static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://api.addressfinder.io *.sharethis.com https://cdnjs.cloudflare.com *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com *.facebook.com *.facebook.net *.cardinalcommerce.com includestest.ccdc02.com *.authorize.net *.braintreegateway.com s.ytimg.com *.vimeocdn.com assets.adobedtm.com *.magento-ds.com *.plugins.emarsys.net *.scarabresearch.com *.limepay.com.au cdn.xtento.com *.zdassets.com *.instant.one *.paypal.com *.google.com *.cloudflare.com *.yotpo.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.zipmoney.com.au *.zip.co *.hotjar.com *.hotjar.io *.googletagservices.com *.pinimg.com *.pinterest.com *.clarity.ms *.zendesk.com *.google.co.in *.zopim.com *.doubleclick.net *.criteo.com theblockshop.api.useinsider.com *.sli-spark.com *.newrelic.com *.amazonaws.com bam.nr-data.net wss://widget-mediator.zopim.com pagead2.googlesyndication.com public-prod-dspcookiematching.dmxleo.com static.secure-afterpay.com.au *.afterpay.com *.gstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://api.addressfinder.io *.sharethis.com *.scarabresearch.com *.eservice.emarsys.net https://api.dev.optty.com https://api.optty.com *.theblockshop.com.au theblockshop.resultspage.com assets.resultspage.com *.resultspage.com *.facebook.com *.facebook.net *.cardinalcommerce.com includestest.ccdc02.com *.authorize.net *.braintreegateway.com s.ytimg.com *.vimeocdn.com assets.adobedtm.com *.magento-ds.com *.plugins.emarsys.net *.limepay.com.au cdn.xtento.com *.zdassets.com *.instant.one *.paypal.com *.google.com *.cloudflare.com *.yotpo.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.zipmoney.com.au *.zip.co *.hotjar.com *.hotjar.io *.googletagservices.com *.pinimg.com *.pinterest.com *.clarity.ms *.zendesk.com *.google.co.in *.zopim.com *.doubleclick.net *.criteo.com theblockshop.api.useinsider.com *.sli-spark.com *.newrelic.com *.amazonaws.com bam.nr-data.net wss://widget-mediator.zopim.com pagead2.googlesyndication.com public-prod-dspcookiematching.dmxleo.com static.secure-afterpay.com.au *.afterpay.com *.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com google.com *.google-analytics.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.run.app dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.instant.one 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-4F+WVEFxkuU7tlBa1ZwpSBFK' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-yCIuCSoSHUxS1DqePxUwsw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 frame-ancestors 'self'; report-uri https://www.bestrecipes.com.au/csp-reports 1 default-src 'self' https://*.clarity.ms; form-action 'self'; frame-ancestors 'none'; frame-src *.youtube.com secure.luton.gov.uk assets.nhs.uk https://*.one.network https://www.googletagmanager.com *.hotjar.com *.hotjar.io; font-src 'self' data: fonts.gstatic.com *.hotjar.com *.hotjar.io www.googletagmanager.com emea3.recruitmentplatform.com; img-src 'self' data: www.luton.gov.uk secure.luton.gov.uk www.googletagmanager.com www.cqc.org.uk www.google-analytics.com *.gstatic.com *.hotjar.com *.hotjar.io https://*.clarity.ms https://c.bing.com https://translate.google.com emea3.recruitmentplatform.com https://static.lumessetalentlink.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' cc.cdn.civiccomputing.com code.jquery.com portal.v7.roadworks.org www.googletagmanager.com www.google-analytics.com www.cqc.org.uk *.hotjar.com *.hotjar.io https://*.clarity.ms https://c.bing.com https://connect.facebook.net emea3.recruitmentplatform.com; style-src 'unsafe-inline' 'self' fonts.googleapis.com www.cqc.org.uk emea3.recruitmentplatform.com; connect-src 'self' apikeys.civiccomputing.com *.google-analytics.com *.hotjar.com *.hotjar.io wss://*.hotjar.com https://*.clarity.ms emea3.recruitmentplatform.com *.tb.lumesse.com; object-src 'none'; report-uri https://349104827b8b658b4e1be80ecb2de25d.report-uri.com/r/d/csp/reportOnly 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-c0c95ebb8b35f6abf5e7da6f355c5677' 'strict-dynamic' https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/tag/js/gpt.js https://static.hotjar.com/ https://cdn.cookielaw.org/ https://imasdk.googleapis.com/ https://*.hotjar.io/ https://connect.facebook.net/ https://*.facebook.com/ https://*.facebook.net/ https://analytics.tiktok.com/ https://galt.hit.gemius.pl/ ; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org/ https://fonts.googleapis.com/ https://www.biathlonworld.com/embedded-player.css https://www.atletiek.nl/build/css/css-ebu.build.css; img-src 'self' data: https://imageservice.evsports.opentv.com/images/v1/image/Sport/ https://cabi.evsports.sports.opentv.com/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://static.hotjar.com/ https://cdn.cookielaw.org/logos/ https://www.google.com/ https://www.google.co.uk/ https://www.facebook.com/ https://*.g.doubleclick.net/ https://ep1.adtrafficquality.google/pagead/ https://*.googlesyndication.com/ https://www.ebu.ch/files/live/sites/ebu/files/images/ https://*.cloudfront.net/EBU/; font-src 'self' data: https://fonts.gstatic.com/; connect-src 'self' https://cdn.cookielaw.org/ https://api.evsports.opentv.com/metadata/delivery/ https://www.google.com/pagead/form-data/ https://www.google.com/ccm/form-data/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://*.googlesyndication.com/ https://ep1.adtrafficquality.google/getconfig/sodar https://securepubads.g.doubleclick.net/pagead/ https://securepubads.g.doubleclick.net/gampad/ https://analytics.tiktok.com/ https://www.facebook.com/ https://*.tiktokw.us/ https://*.hotjar.com/ https://galt.hit.gemius.pl/ https://firebase.googleapis.com/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://*.facebook.com/ https://*.fbcdn.net/ https://*.facebook.net/ https://*.google-analytics.com/ https://*.onetrust.com/ https://*.hotjar.io/ wss://ws.hotjar.com/ https://*.akamaized.net/ https://*.anycast.nagra.com/ https://evs-dtvsports-vod-secure2.akamaized.net/ https://*.ampproject.org/ https://api.evsports.opentv.com/ https://api.evsports.opentv.com/useractivityvault/v1/useractivity/; frame-src https://files.eurovisionsport.com/ https://www.google.com/ https://ep2.adtrafficquality.google/ https://www.googletagmanager.com/ https://*.g.doubleclick.net/ https://*.safeframe.googlesyndication.com/ http://imasdk.googleapis.com/ http://console.googletagservices.com/ https://www.ebu.ch/ https://eurovisionsport.com/; media-src 'self' blob: https://*.akamaized.net/ https://*.anycast.nagra.com/ https://*.sports.opentv.com/; script-src-elem 'self' 'nonce-c0c95ebb8b35f6abf5e7da6f355c5677' https://cdn.ampproject.org/ https://*.hotjar.com/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://cdn.cookielaw.org/ https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/ https://imasdk.googleapis.com/js/sdkloader/ima3.js https://*.hotjar.io/; object-src 'none'; base-uri 'self'; form-action 'self'; 1 default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; form-action 'self' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: p.typekit.net static.klaviyo.com libs.intiaro.com likeshop.me data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.certcapture.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.googleapis.com cdn.metalocator.com cdn.brandfolder.io log.pinterest.com cdn.cookielaw.org https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net code.metalocator.com assets.pinterest.com libs.intiaro.com cdn.dashhudson.com cdn.cookielaw.org sec.webeyez.com js.hellomedian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js-agent.newrelic.com https://cdn.visenze.com https://home-c61.nice-incontact.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com use.typekit.net p.typekit.net libs.intiaro.com https://static.klaviyo.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.gstatic.com *.googleapis.com bam.nr-data.net bam-cell.nr-data.net analytics.data.visenze.com api.likeshop.me search.visenze.com kravet.prinpay.com wss://wss.public-api.intiaro.com cdn.cookielaw.org hlg.tokbox.com wss://socket.hellomedian.com app.hellomedian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /_csp/report; report-to report-endpoint; 1 default-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com; frame-ancestors https://cloud.orioncontactcenter.com.ar:65232 1 child-src 'self' blob: *.adairs.com.au; connect-src 'self' *.aptrinsic.com *.braintreegateway.com *.braze.com *.clarity.ms *.creativecdn.com *.google-analytics.com *.google.com *.googleapis.com *.hotjar.com *.hotjar.io *.inside-graph.com *.paypal.com *.pinterest.com *.spotify.com *.unbxd.io *.unbxdapi.com *.yieldify-production.com *.yieldify.com cdn.jsdelivr.net cdnjs.cloudflare.com dc.services.visualstudio.com google.com js.monitor.azure.com payments.braintree-api.com wss://stellar-live.inside-graph.com wss://ws.hotjar.com www.facebook.com/tr/; font-src 'self' *.gstatic.com *.typekit.net/ *.yieldify-production.com *.yieldify.com https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/; frame-src 'self' *.braintreegateway.com *.creativecdn.com *.criteo.com *.criteo.net *.googletagmanager.com *.paypal.com *.pinterest.com pay.google.com; img-src 'self' data: *.adairs.co.nz *.adairs.com.au *.afterpay.com *.bing.com *.creativecdn.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.idio.episerver.net *.inside-graph.com *.paypal.com *.yieldify.com c.clarity.ms ib.adnxs.com r.turn.com www.facebook.com www.google.com.au www.paypalobjects.com; media-src 'self' *.inside-graph.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.afterpay.com *.aptrinsic.com *.bing.com *.braze.com *.cfjump.com *.clarity.ms *.creativecdn.com *.criteo.com *.criteo.net *.google-analytics.com *.googleapis.com *.googletagmanager.com *.hotjar.com *.idio.episerver.net *.inside-graph.com *.paypal.com *.pdst.fm *.pinimg.com *.pinterest.com *.rakuten.com *.unbxd.io *.unbxdapi.com *.wisepops.com *.yieldify.com applepay.cdn-apple.com cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com connect.facebook.net https://static.cloudflareinsights.com/ js.monitor.azure.com pay.google.com r.turn.com static.zip.co static.zipmoney.com.au unpkg.com wisepops.net; style-src 'self' 'unsafe-inline' *.afterpay.com *.aptrinsic.com *.googleapis.com *.inside-graph.com *.typekit.net/ *.unbxd.io *.unbxdapi.com applepay.cdn-apple.com cdn.datatables.net cdn.jsdelivr.net; default-src 'none'; report-to stott-security-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.gstatic.com https://www.shopperapproved.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com/ https://js.stripe.com https://apis.google.com https://assets.mailerlite.com https://client.crisp.chat https://bat.bing.com https://s.yimg.com https://googleads.g.doubleclick.net https://cdn.taboola.com https://js.cnnx.link https://trc.taboola.com https://web.squarecdn.com https://*.awswaf.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://t.sharethis.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.shopperapproved.com https://client.crisp.chat https://assets.mailerlite.com https://web.squarecdn.com; font-src 'self' https://fonts.gstatic.com https://client.crisp.chat https://square-fonts-production-f.squarecdn.com https://d1g145x70srn7h.cloudfront.net; img-src 'self' data: https:; connect-src 'self' https://apis.google.com https://api.stripe.com https://www.google-analytics.com https://www.google.com https://bat.bing.com https://*.sentry.io https://s.yimg.com https://analytics.google.com https://psb.taboola.com https://pips.taboola.com https://trc.taboola.com https://cds.taboola.com https://client.crisp.chat wss://client.relay.crisp.chat https://pci-connect.squareup.com https://trc-events.taboola.com https://l.sharethis.com; frame-src 'self' https://t.sharethis.com https://www.facebook.com https://www.youtube.com https://js.stripe.com https://www.google.com https://assets.mailerlite.com https://bat.bing.com https://s.yimg.com https://shopperapproved.com https://apis.google.com https://*.taboola.com https://*.googletagmanager.com https://*.doubleclick.net https://web.squarecdn.com 1 default-src 'self'; connect-src 'self' *.nixonpeabody.com *.nixonpeabody.localhost stats.g.doubleclick.net analytics.google.com region1.analytics.google.com *.typekit.net *.vercel.app *.linkedin.com *.clarity.ms *.bing.com *.onetrust.com *.google.com *.doubleclick.net apps.sitecore.net cdn.cookielaw.org googletagmanager.com www.google-analytics.com www.googleadservices.com snap.licdn.com cdn.pdst.fm pixels.spotify.com youtube.com www.youtube.com player.vimeo.com open.spotify.com vercel.com vercel.live vitals.vercel-insights.com wss://ws-us3.pusher.com www.googletagmanager.com *.google.com *.google.ca *.google.co.uk *.google.com.au *.google.co.in *.google.de *.google.fr *.google.it *.google.es *.google.jp *.google.com.br *.google.co.kr *.google.co.za *.google.com.mx *.google.nl *.google.se *.google.dk *.google.no *.google.ch *.google.be *.google.ie *.google.pl *.google.ro *.google.ru *.google.com.hk *.google.sg *.google.com.tw *.google.co.nz *.google.fi *.google.pt; script-src 'self' 'unsafe-inline' *.searchstax.com *.clarity.ms cdn.cookielaw.org www.googletagmanager.com tagmanager.google.com snap.licdn.com vercel.live cdn.pdst.fm player.vimeo.com static.searchstax.com *.doubleclick.net; script-src-elem 'self' 'unsafe-inline' *.searchstax.com *.clarity.ms cdn.cookielaw.org www.googletagmanager.com tagmanager.google.com snap.licdn.com vercel.live cdn.pdst.fm player.vimeo.com static.searchstax.com *.doubleclick.net googleads.g.doubleclick.net; img-src * data: blob:; style-src 'self' 'unsafe-inline' *.typekit.net use.typekit.net vercel.live *.googletagmanager.com tagmanager.google.com fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' *.typekit.net use.typekit.net vercel.live *.googletagmanager.com tagmanager.google.com fonts.googleapis.com; object-src 'self' data: blob:; base-uri 'self'; form-action 'self'; font-src 'self' data: *.typekit.net use.typekit.net vercel.live assets.vercel.com fonts.gstatic.com; frame-src 'self' vercel.live *.doubleclick.net player.vimeo.com youtube.com www.youtube.com cdn.yoshki.com open.spotify.com www.googletagmanager.com; frame-ancestors 'none'; upgrade-insecure-requests; report-to csp-report; 1 default-src 'none'; script-src 'report-sample' 'self'; style-src 'report-sample' 'self' https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='; font-src 'self' https://fonts.gstatic.com; report-uri https://web-api.attempt.signicat.io/security/csp/report; frame-ancestors 'none'; form-action 'none'; base-uri 'none'; require-trusted-types-for 'script'; connect-src 'self' https://pink-panther.prod-eu.identity.signicat.global wss://pink-panther.prod-eu.identity.signicat.global; style-src 'self' https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-fNw4bil3JBKS+MQcMzAmRVRc4aHCgdPeiScEGmny6ec='; img-src 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oscato.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io embed.tawk.to www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com https://hnd.stats.paypal.com *.oscato.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.facebook.com embed.tawk.to connect.facebook.net graph.facebook.com business.facebook.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com https://assets.optile.net *.oscato.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com embed.tawk.to 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.tawk.to va.tawk.to www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.oscato.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; upgrade-insecure-requests; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' mfstatic.com static.mediaflowpro.com dl.episerver.net; style-src-attr 'self' 'unsafe-inline'; font-src 'self' mfstatic.com dl.episerver.net static.mediaflowpro.com; form-action 'self' information.his.se; frame-src 'self' *.imbox.io *.kaltura.nordu.net www.youtube.com play.mediaflowpro.com web103.reachmee.com; frame-ancestors 'self'; img-src 'self' data: *.mediaflowpro.com *.mediaflow.com *.his.se i.ytimg.com dl.episerver.net *.inviewer.se mfstatic.com *.mfstatic.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.matomo.cloud *.imbox.io mfstatic.com www.youtube.com cdn.siteimprove.net web103.reachmee.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' *.matomo.cloud *.imbox.io mfstatic.com www.youtube.com cdn.siteimprove.net web103.reachmee.com static.mediaflowpro.com *.inviewer.se dl.episerver.net; worker-src 'self' blob:; connect-src 'self' *.matomo.cloud noembed.com *.mediaflow.com mfstatic.com stats.mediaflowpro.com *.siteimprove.com; media-src 'self' blob: *.mediaflow.com *.mediaflowpro.com; report-uri /csp-report; 1 default-src 'self' *.tillamook.com tillamook.com stackpath.bootstrapcdn.com; img-src 'self' data: *.ctfassets.net ctfassets.net *.cookielaw.org cookielaw.org www.google.com/ads/ www.google-analytics.com/ www.facebook.com/ c.lytics.io/c/b5c7317d218cb2a0ef160219694b5a9e www.googletagmanager.com; media-src 'self' *.ctfassets.net ctfassets.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: destinilocators.com https://connect.facebook.net/ *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.cookielaw.org cookielaw.org www.google-analytics.com/ www.googletagmanager.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.clarity.ms givebutter.com/ destinilocators.com/ www.googleoptimize.com/ cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js cdnjs.cloudflare.com/ajax/libs/iframe-resizer/2.8.10/iframeResizer.min.js cdnjs.cloudflare.com/ajax/libs/easyXDM/2.4.20/easyXDM.min.js va.vercel-scripts.com/v1/speed-insights/script.debug.js widget.intercom.io js.intercomcdn.com www.recaptcha.net analytics.tiktok.com/i18n/pixel/events.js; style-src 'self' 'unsafe-inline' *.typekit.net typekit.net api.tiles.mapbox.com www.exploretock.com stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css fonts.googleapis.com/css; style-src-elem 'self' 'unsafe-inline' *.typekit.net stackpath.bootstrapcdn.com fonts.googleapis.com; font-src 'self' *.tillamook.com tillamook.com *.typekit.net typekit.net www.exploretock.com stackpath.bootstrapcdn.com fonts.gstatic.com; connect-src 'self' wss: *.tillamook.com tillamook.com *.tillamaps.com tillamaps.com *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.doubleclick.net doubleclick.net *.ingest.sentry.io *.ingest.us.sentry.io *.ctfassets.net ctfassets.net *.mapbox.com mapbox.com *.algolianet.com *.algolia.net *.onetrust.com onetrust.com *.cookielaw.org cookielaw.org analytics.google.com api.addresszen.com *.clarity.ms/collect www.recaptcha.net preview.contentful.com/ www.google-analytics.com/ vitals.vercel-insights.com/ cdn.contentful.com/ analytics.google.com/ d2k6913brarspg.cloudfront.net/ www.facebook.com/tr/ analytics.tiktok.com/api/v2/pixel qcjajnmiprtqkimhahis.supabase.co; frame-src 'self' https://vars.hotjar.com https://www.facebook.com/ https://www.google.com/ https://www.youtube.com https://www.youtube-nocookie.com https://destinilocators.com/ https://td.doubleclick.net/; frame-ancestors https://app.contentful.com; worker-src 'self' blob:; child-src 'self' blob:; report-uri https://16x3230g.uriports.com/reports/report; report-to default 1 img-src 'self' data: https://*.siteimproveanalytics.io; script-src 'self' https://siteimproveanalytics.com cdn.jsdelivr.net https://cdn.jsdelivr.net; script-src-attr 'self'; script-src-elem 'self' https://js-agent.newrelic.com https://bam.nr-data.net https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/V6_85qpc2Xf2sbe3xTnRte7m/recaptcha__en.js cdn.jsdelivr.net https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 frame-src *.force.com https://player.vimeo.com https://www.vimeo.com 'self' https://stats.g.doubleclick.net https://script.hotjar.com *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://usa274.sfdc-lywfpd.salesforce.com https://pal-test.adyen.com *.cybersource.com *.youtube.es https://static.hj.contentsquare.net *.adis.ws https://cpaacademy.my.salesforce.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video https://www.interamark.com https://www.cpaacademy.org *.youtube.fr https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws https://*.hotjar.com *.forceusercontent.com https://cpaacademy--c.na100.visual.force.com *.youtube.com *.brightcove.net *.youtube.nl https://service.force.com/embeddedservice/ https://fast.wistia.net https://cpaacademy.s3.us-west-2.amazonaws.com *.quip.com *.arkoselabs.com https://api.mixpanel.com *.youtube-nocookie.com https://www.paypal.com https://cpaacademy.na100.my.salesforce.com https://appiniummastertrial.secure.force.com https://play.vidyard.com *.youtube.com.br *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://cpaacademy.file.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net https://cpaacademy.org *.youtube.ca https://location.force.com *.vidyard.com https://cpaacademy.s3.amazonaws.com https://cpaacademy.s3-us-west-2.amazonaws.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://beta.cpaacademy.org https://cdn.embedly.com https://cpaacademy--livepreview.na100.force.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com http://click.edu.cpaacademy.org https://staging.cpaacademy.org https://vimeo.com https://*.a.forceusercontent.com/lightningmaps/ https://t.contentsquare.net https://www.googletagmanager.com https://cpaacademy.my.site.com *.wistia.net https://www.google-analytics.com *.salesforce.com https://*.contentsquare.net *.youtube.pl; report-to sfdc-csp-ep; report-uri https://cpaacademy.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00DC0000000PiAN&networkId=0DMQh0000000DQI&type=communities 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.alliai.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://*.alliai.com wss://*.alliai.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src localhost:* *.texasfile.com app.pendo.io data.pendo.io pendo-static-5685311968116736.storage.googleapis.com *.google-analytics.com; worker-src blob:; frame-ancestors *.texasfile.com app.pendo.io; script-src 'self' *.texasfile.com cdn.ravenjs.com *.google-analytics.com https://recaptcha.net www.google.com/recaptcha/api.js www.gstatic.com https://www.googletagmanager.com https://cdn.pydata.org/bokeh/release/bokeh-2.4.3.min.js https://cdn.pydata.org/bokeh/release/bokeh-widgets-2.4.3.min.js https://cdn.pydata.org/bokeh/release/bokeh-tables-2.4.3.min.js app.pendo.io pendo-io-static.storage.googleapis.com cdn.pendo.io pendo-static-5685311968116736.storage.googleapis.com data.pendo.io data: 'unsafe-eval' 'unsafe-inline'; img-src 'self' media.texasfile.com www.texasfile.com https://ssl.google-analytics.com staging.texasfile.com qa.texasfile.com lb2.texasfile.com assets.texasfile.com staging-assets.texasfile.com https://stats.g.doubleclick.net https://www.google.com/ads https://i.ytimg.com cdn.pendo.io app.pendo.io pendo-static-5685311968116736.storage.googleapis.com data.pendo.io data: blob:; default-src 'self' *.texasfile.com 'nonce-uLw53E5Plj9yv+7a5sL7bA=='; frame-src *.texasfile.com https://www.google.com https://www.youtube.com; font-src 'self' *.texasfile.com fonts.googleapis.com fonts.gstatic.com; style-src 'self' *.texasfile.com fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/bokeh/1.0.4/bokeh.min.css https://cdnjs.cloudflare.com/ajax/libs/bokeh/1.0.4/bokeh-widgets.min.css https://cdnjs.cloudflare.com/ajax/libs/bokeh/1.0.4/bokeh-tables.css app.pendo.io cdn.pendo.io pendo-static-5685311968116736.storage.googleapis.com 'unsafe-inline' 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://static.klaviyo.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.hotjar.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com bat.bing.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.google.com *.google.bg *.googletagmanager.com connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net *.pcapredict.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com services.postcodeanywhere.co.uk *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.facebook.com *.facebook.net *.google.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googlesyndication.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.livechatinc.com https://*.haiku.ai https://api.hubspot.com https://api.mixpanel.com https://cdn.freshmarketer.com https://cdn.mxpnl.com https://cdnjs.cloudflare.com https://code.jquery.com https://connect.facebook.net https://forms.hsforms.com https://googleads.g.doubleclick.net https://info.proctoru.com https://ip.freshmarketer.com https://js.hs-analytics.net https://js.hs-scripts.com https://js.hsadspixel.net https://js.hsforms.net https://js.usemessages.com https://maxcdn.bootstrapcdn.com https://pi.pardot.com https://px.ads.linkedin.com https://snap.licdn.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://www.linkedin.com https://www.youtube.com https://js.hscta.net https://cta-service-cms2.hubspot.com https://hire.withgoogle.com https://*.adroll.com https://*.consensu.org https://*.twitter.com/ https://cdn.syndication.twimg.com/ https://*.fullstory.com/ https://js.hs-banner.com https://api.hubapi.com https://sc.lfeeder.com https://tagmanager.google.com https://yas.bamboohr.com https://*.cincopa.com https://www.meazurelearning.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.typekit.net https://maxcdn.bootstrapcdn.com https://platform.twitter.com/ https://tagmanager.google.com https://*.bamboohr.com https://*.meazurelearning.com https://cdn.jsdelivr.net; img-src https: data:; connect-src https://www.google-analytics.com https://*.haiku.ai https://api.mixpanel.com https://api.hubspot.com https://api.hubapi.com https://*.fullstory.com/ https://*.bamboohr.com https://stats.g.doubleclick.net; font-src 'self' data: https://use.typekit.net https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; media-src https://*.livechatinc.com; frame-ancestors 'none'; object-src 'none'; frame-src https://secure.livechatinc.com https://bid.g.doubleclick.net https://forms.hsforms.com https://www.facebook.com https://www.youtube.com https://hire.withgoogle.com https://www.proctoru.com https://player.vimeo.com https://platform.twitter.com/ https://syndication.twitter.com/ https://twitter.com/; upgrade-insecure-requests 1 font-src *.typekit.net fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.fontawesome.com *.bootstrapcdn.com self data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * self 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google-analytics.com *.googleadservices.com *.paypal.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com self *.super99.com *.scene7.com *.facebook.com cm.everesttech.net *.doubleclick.net *.swagger.io *.braintreegateway.com *.clarity.ms https://analytics.tiktok.com https://c.bing.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com beacon-audiences.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com self unsafe-inline *.facebook.com *.facebook.net *.connect.facebook.net https://smetrics.super99.com *.super99.com *.cardinalcommerce.com unpkg.com cdn.jsdelivr.net *.googleadservices.com *.google-analytics.com *.google.com *.googletagmanager.com *.paypalobjects.com *.vimeo.com *.bolt.com *.commerce-quick-checkout.com *.cybersource.com *.braintreegateway.com *.clarity.ms https://analytics.tiktok.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com beacon-audiences.magento-ds.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com unsafe-inline assets.braintreegateway.com self 'self' 'unsafe-inline'; object-src none 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com self 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n.adobe.io beacon-audiences.magento-ds.com *.adobedc.net *.demdex.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com self *.super99.com https://smetrics.super99.com *.facebook.com *.pingdom.net *.woorank.com *.youtube.com *.vimeo.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com *.bolt.com *.braintreegateway.com *.clarity.ms https://analytics.tiktok.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com unicons.iconscout.com static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.cookiebot.com *.cookiebot.eu *.googletagmanager.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.cookiebot.com *.cookiebot.eu *.googlesyndication.com d3k81ch9hvuctc.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.cookiebot.com *.cookiebot.eu *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com unicons.iconscout.com static-tracking.klaviyo.com https://static.klaviyo.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com *.facebook.net *.cookiebot.com *.cookiebot.eu *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://cdn-4.convertexperiments.com https://logs.convertexperiments.com https://static.hsappstatic.net *.metrics.convertexperiments.com *.wse-abtesting-components.pages.dev https://mktmedia.wallstreetenglish.com https://mktmediadev.wallstreetenglish.com https://no-cdn.convertexperiments.com https://www.googleanalytics.com *.cookiebot.com *.hotjar.io *.reviews.io data: *.amazonaws.com *.cloudflare.com *.googleapis.com *.gstatic.com *.google.com *.google-analytics.com *.typekit.net *.hsforms.com *.hs-sites.com *.wsemktapp.com *.reviews.co.uk *.cloudfront.net *.hs-banner.com *.doubleclick.net *.hubspot.com *.hotjar.com *.hubapi.com *.facebook.com *.linkedin.com *.adsymptotic.com *.crwdcntrl.net *.bing.com *.clarity.ms *.cpmktg.com *.mathtag.com *.youtube.com *.slideshare.net *.googletagmanager.com *.fna.fbcdn.net *.cdninstagram.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://js.usemessages.com https://cdn-4.convertexperiments.com https://logs.convertexperiments.com *.metrics.convertexperiments.com *.wse-abtesting-components.pages.dev https://no-cdn.convertexperiments.com https://www.googleanalytics.com *.cookiebot.com *.hubspot.com *.googletagmanager.com *.googleapis.com *.hsforms.net *.reviews.io *.hsforms.com js.hscta.com *.wsemktapp.com *.google-analytics.com *.gstatic.com *.cloudfront.net *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hscollectedforms.net *.hsleadflows.net f.hubspotusercontent20.net *.hotjar.com *.facebook.net www.googleadservices.com snap.licdn.com *.doubleclick.net *.bing.com *.cpmktg.com *.aimage.it:3000 *.clarity.ms *.crwdcntrl.net *.youtube.com *.google.com https://js.storylane.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com *.googletagmanager.com *.cookiebot.com *.typekit.net *.googleapis.com *.reviews.io data: *.wsemktapp.com *.cloudfront.net *.fna.fbcdn.net *.hubspot.com *.cdninstagram.com; object-src 'none'; frame-src 'self' https://app.storylane.io https://js.hsforms.net *.hsforms.com *.hs-sites.com https://consentcdn.cookiebot.com https://widget.reviews.io https://www.googletagmanager.com https://www.google.com; 1 font-src *.googleapis.com *.gstatic.com data: *.cloudinary.com https://staticw2.yotpo.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com cloudinary.com *.cloudinary.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.hotjar.com *.google.com *.vimeo.com *.livechatinc.com https://cloudinary.com shell.davidsonsinc.com https://www.youtube.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com cloudinary.com *.cloudinary.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.cloudflare.com https://p.yotpo.com https://cdn-yotpo-images-production.yotpo.com *.facebook.com *.pinterest.com *.google.com https://bat.bing.com https://cdn.livechat-files.com https://online.flippingbook.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.vimeo.com unpkg.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com https://assets.pinterest.com https://ct.pinterest.com https://staticw2.yotpo.com https://static.hotjar.com https://connect.facebook.net https://static-tracking.klaviyo.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam-cell.nr-data.net https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://s.pinimg.com https://bat.bing.com https://r2-t.trackedlink.net https://script.hotjar.com https://cdn.livechatinc.com https://api.livechatinc.com https://davcc.disqus.com https://vc.hotjar.io/ https://in.hotjar.com https://online.flippingbook.com https://d33i2vgywgme2s.cloudfront.net *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cloudinary.com *.cloudinary.com *.googleapis.com unpkg.com unsafe-inline assets.braintreegateway.com https://staticw2.yotpo.com https://static.klaviyo.com https://fonts.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cloudinary.com *.cloudinary.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com cloudinary.com *.cloudinary.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://staticw2.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://telemetrics.klaviyo.com https://bam.nr-data.net https://bam-cell.nr-data.net https://stats.g.doubleclick.net https://ct.pinterest.com https://api.livechatinc.com *.hotjar.com *.hotjar.io *.google-analytics.com https://fbo-b.flippingbook.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.davidsonsinc.com; report-to report-endpoint; 1 script-src-elem *.bing.com *.clarity.ms *.googleadservices.com *.youtube.com *.global-e.com *.bglobale.com *.redditstatic.com *.bing-int.com www.googletagmanager.com static-tracking.klaviyo.com static.klaviyo.com *.herroom.com unpkg.com *.googleapis.com www.paypal.com js.braintreegateway.com pay.google.com c.paypal.com cdn.kustomerapp.com connect.facebook.net gepi.global-e.com web.global-e.com webservices.global-e.com www.google.com www.gstatic.com *.pinimg.com cdn.noibu.com *.cloudfront.net utt.impactcdn.com googleads.g.doubleclick.net *.pinterest.com se.monetate.net www.paypalobjects.com *.sitejabber.com *.slick.min.js *.msn.com *.r.msn.com *.listrakbi.com cdn.jsdelivr.net *.listrak.com *.aftership.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem *.googleapis.com *.bglobale.com *.herroom.com p.typekit.net use.typekit.net gepi.global-e.com static.klaviyo.com static-tracking.klaviyo.com *.sitejabber.com *.listrakbi.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.global-e.com *.bglobale.com s3-eu-west-1.amazonaws.com cdn.kustomerapp.com globale-prod.s3-eu-west-1.amazonaws.com *.sitejabber.com *.espssl.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.cloudfront.net *.pinterest.com *.global-e.com *.youtube.com *.listrakbi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com www.googletagmanager.com *.weltpixel.com *.bglobale.com *.global-e.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.braintreegateway.com *.google.com *.cloudfront.net *.pinterest.com *.listrakbi.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.global-e.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.gstatic.com *.facebook.com *.reddit.com *.bglobale.com assets.herroom.net media.herroom.com *.bing.com *.clarity.ms maps.googleapis.com *.herroom.com *.google.ch bat.bing.net widgets.automizely.com widgets.automizely.io herroom.scene7.com www.googletagmanager.com s3-eu-west-1.amazonaws.com cdn.kustomerhostedcontent.com *.google.com *.brandlock.io media.hisroom.com www.ojrq.net logs-01.loggly.com *.cloudfront.net connect.facebook.net *.sitejabber.com *.doubleclick.net *.g.doubleclick.net *.listrakbi.com *.espssl.com data: 'self' 'unsafe-inline'; script-src *.adobe.com www.googleadservices.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.magento-ds.com *.global-e.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.maxmind.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net t.paypal.com www.googleapis.com vimeo.com www.vimeo.com www.google.com www.googletagmanager.com www.google-analytics.com *.bglobale.com unpkg.com *.clarity.ms *.cloudfront.net *.listrakbi.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.pinimg.com *.listrak.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.global-e.com assets.braintreegateway.com *.bglobale.com *.typekit.net widgets.automizely.com widgets.automizely.io use.typekit.net *.sitejabber.com *.listrakbi.com 'self' 'unsafe-inline'; object-src *.listrakbi.com 'self' 'unsafe-inline'; media-src *.adobe.com assets.herroom.net *.espssl.com *.listrakbi.com 'self' 'unsafe-inline'; manifest-src *.listrakbi.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.mmapiws.com *.bing.com *.clarity.ms *.brandlock.io *.cloudfront.net *.clartity.ms *.google.ch bat.bing.net *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.automizely.com api.automizely.io *.global-e.com *.bing-int.com maps.googleapis.com a.klaviyo.com andragroup.api.kustomerapp.com www.facebook.com input.noibu.com cdn.noibu.com wss://input.noibu.com herroom.pxf.io hisroom.sjv.io *.pinterest.com herroom.scene7.com *.pndsn.com resource-proxy.noibu.com *.sitejabber.com *.listrakbi.com *.listrak.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src self *.herroom.com *.hisroom.com mcprod.herroom.com *.hisrroom.com *.listrakbi.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri self *.herroom.com *.hisroom.com *.listrakbi.com 'self' 'unsafe-inline'; 1 frame-src 'self'; report-uri http://events.convio.com/site/XFrameViolation 1 default-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.%2A.civiccomputing.com *.civiccomputing.com *.clarity.ms *.cloudflare.com *.googletagmanager.com *.jsdelivr.net *.library.wales; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws *.library.wales *.llgc.org.uk *.staticflickr.com *.ticketsource.co.uk fonts.gstatic.com play.google.com syndication.twitter.com translate.google.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.doubleclick.net *.googletagmanager.com *.libanswers.com *.library.wales *.llyfrgell.cymru *.lyfrgell.cymru *.twitter.com div.show hwb.gov.wales sketchfab.com www.canva.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.clarity.ms *.fontawesome.com *.libanswers.com *.library.wales connect.facebook.net fonts.googleapis.com; script-src-elem 'self' 'nonce-jisHoREzis5dW3p6J8AKU47VA14ZYd6rPhPXhMNxwSgXeIcY1j5Y7A' https: 'unsafe-eval' blob: *.%2A.civiccomputing.com *.%2A.v2.scr.kaspersky-labs.com *.civiccomputing.com *.flickr.com *.googletagmanager.com *.libanswers.com adblockers.opera-mini.net connect.facebook.net s3.amazonaws.com wusote.hirizasune.com 'report-sample'; connect-src 'self' https: data: blob: wss: *.google.com https://*.googleapis.com https://*.gstatic.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; font-src 'self' https: data: blob: wss: https://fonts.gstatic.com; worker-src 'self' 'nonce-jisHoREzis5dW3p6J8AKU47VA14ZYd6rPhPXhMNxwSgXeIcY1j5Y7A' blob:; style-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline' 'inline' 'report-sample'; report-uri https://www.library.wales/@http-reporting?csp=report&requestTime=1765937750702151&requestHash=2a2af42f66f24b91756337293b5257a856d5c6c2 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.sulisfineart.com www.sulisfineart.com/static/* https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com td.doubleclick.net www.google.com checkout.paypal.com c.paypal.com www.paypalobjects.com https://widget.trustpilot.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com https://firebasestorage.googleapis.com flagpedia.net x.klarnacdn.net *.google.com c.paypal.com www.sulisfineart.com dashboard.edesk.com c6.paypal.com lhr.stats.paypal.com https://www.google-analytics.com https://www.googletagmanager.com https://widget.trustpilot.com https://static.cloudflareinsights.com https://*.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.instagram.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.shopify.com *.gstatic.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.app.easyship.com http://cdnjs.cloudflare.com *.newrelic.com *.sdk.loyaltylion.net *.sdk-static.loyaltylion.net *.paypal.com *.google-analytics.com *.googletagmanager.com sulisfineart.local.com www.sulisfineart.com sdk.loyaltylion.net widgets.xsellco.com sdk-static.loyaltylion.net www.google.com www.gstatic.com www.sulisfineart.com/static/* js.braintreegateway.com c.paypal.com *.posthog.com https://www.googletagmanager.com https://www.google-analytics.com https://widget.trustpilot.com https://js-agent.newrelic.com https://sdk.loyaltylion.net https://static.cloudflareinsights.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com sdk.loyaltylion.net www.sulisfineart.com https://cdnjs.cloudflare.com sdk-static.loyaltylion.net widgets.xsellco.com www.sulisfineart.com/static/* *.trustpilot.com 'self' 'unsafe-inline'; object-src www.sulisfineart.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.app.easyship.com *.nr-data.net *.google-analytics.com *.eu.klarnaevt.com *.gstatic.com www.sulisfineart.com widgets.xsellco.com platform.loyaltylion.com www.sulisfineart.com/static/* https://cdnjs.cloudflare.com payments.braintree-api.com client-analytics.braintreegateway.com c.paypal.com *.posthog.com https://www.google-analytics.com https://widget.trustpilot.com https://sdk.loyaltylion.net https://eu.i.posthog.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.sulisfineart.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.sulisfineart.com/; report-to report-endpoint; 1 font-src www.paypalobjects.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com maps.googleapis.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.fontawesome.com mdbootstrap.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://unpkg.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn2.hubspot.net resources.paytrail.com https://log.pinterest.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com https://assets.pinterest.com bnSQZ2z9YDOGs4NgOKjSdQtzYlkZxVoLxk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.paytrail.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action 'self' geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *; frame-ancestors 'self'; frame-src 'self' *.cookiebot.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *; img-src 'self' *.cookiebot.com *.openstreetmap.org *.google.pl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com static.payu.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://integrations.etrusted.com; script-src 'self' *.cookiebot.com 'unsafe-eval' 'unsafe-inline' *.openstreetmap.org *.makalu.com.pl *.paynow.pl assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com secure.payu.com secure.snd.payu.com *.snrbox.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://integrations.etrusted.com 'nonce-dzZ6OGlwZGNpczQ5OHVxamM3dmd4dzB5MDBwOXN0N3M=' 'nonce-NGIzYnllZnNvYzRtdWwyMWd3bmN0NHk1MnI3YmtqamM=' 'nonce-NmJkb3hiNDh6NGpmdW9qYTMwYjFjdThtOW50aDZycWI=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src 'self' 'unsafe-eval' 'unsafe-inline' *.makalu.com.pl *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.snrcdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com https://widgets.trustedshops.com https://integrations.etrusted.com; object-src 'self' 'unsafe-eval'; media-src 'self' *.adobe.com; manifest-src 'self' 'unsafe-inline'; connect-src 'self' *.cookiebot.com 'unsafe-inline' *.openstreetmap.org *.makalu.com.pl *.google.pl dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com *.snrbox.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.trustedshops.com *.etrusted.com; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' *.googleapis.com; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://s.brightspace.com https://*.ally.ac https://leaplti.desire2learn.com/ https://leaplti-fr.brightspace.com/ https://tryleap.brightspace.com/ https://leaplti-es.desire2learn.com/ https://leaplti-ptbr.desire2learn.com/ https://leaplti-us.brightspace.com/ https://leaplti-apac.brightspace.com/ https://leaplti-emea.brightspace.com/ https://leapqa.net https://leaplti-ap.brightspace.com https://login.microsoftonline.com/ https://login.live.com/ https://cdn.lcs.brightspace.com/ https://leaplti-in.brightspace.com; report-uri https://logger.ca-central-1.logging.brightspace.com/log/csp/YF4LGVc_tlrbtSgaOjIcLQAAAZsp2Shv 1 base-uri 'self';connect-src 'self' adservice.google.com identitytoolkit.googleapis.com securetoken.googleapis.com https://stats.g.doubleclick.net wss://orbx-orbs.firebaseio.com wss://*.firebaseio.com www.facebook.com www.google-analytics.com www.google.com consentcdn.cookiebot.com;default-src 'self';form-action 'self' www.facebook.com;img-src 'self' data: *.orbxdirect.com https://orbxdirect.com doubleclick.net i.ytimg.com *.stripe.com *.orbxsystems.com web.goog.cdn.orbxdirect.com www.facebook.com www.google-analytics.com www.gravatar.com imgsct.cookiebot.com;media-src 'self';object-src 'none';script-src 'self' cdnjs.cloudflare.com connect.facebook.net wasm-eval www.google-analytics.com www.googletagmanager.com challenges.cloudflare.com 'nonce-NeQgeEpn1KhYmfVQqr0nwugsHnmpy27i';script-src-elem 'self' apis.google.com cdnjs.cloudflare.com checkout.stripe.com connect.facebook.net doubleclick.net *.firebaseio.com www.google-analytics.com www.googleadservices.com www.googletagmanager.com consent.cookiebot.com consentcdn.cookiebot.com 'nonce-NeQgeEpn1KhYmfVQqr0nwugsHnmpy27i';style-src 'self' fonts.googleapis.com p.typekit.net use.typekit.net;style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com p.typekit.net use.typekit.net;style-src-attr 'self' 'unsafe-inline';font-src 'self' fonts.gstatic.com use.typekit.net;frame-src checkout.stripe.com orbx-orbs.firebaseapp.com *.firebaseio.com doubleclick.net www.facebook.com facebook.com youtube.com challenges.cloudflare.com consentcdn.cookiebot.com;frame-ancestors 'none';script-src-attr 'nonce-NeQgeEpn1KhYmfVQqr0nwugsHnmpy27i' 1 font-src *.paypalobjects.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.cookiebot.com *.doubleclick.net *.pinterest.com *.pinterest.co.uk *.bat.bing.com *.paypalobjects.com *.reviews.io *.reviews.co.uk *.pinterdev.com commerce-app.pintergration.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com *.clearpay.co.uk *.trackedlink.net www.feedoptimise.com cdn.feedoptimise.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bing.com *.doubleclick.net *.ometria.com *.pinterest.com *.pinterest.co.uk *.bat.bing.com *.connect.facebook.net *.clarity.ms *.google.com *.google.co.uk *.googletagmanager.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.feedoptimise.com cdn.feedoptimise.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.bing.com *.cookiebot.com *.dwin1.com *.googleoptimize.com *.ometria.com *.pinimg.com *.trustpilot.com *.connect.facebook.net *.bat.bing.com *.d.impactradius-event.com *.zdassets.com *.clarity.ms *.pinterest.com *.pinterest.co.uk *.impactcdn.com *.grahamandgreen.pxf.io grahamandgreen.pxf.io cdn.jsdelivr.net *.reviews.io *.reviews.co.uk *.pinterdev.com commerce-app.pintergration.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cookiebot.com *.doubleclick.net *.ometria.com *.pinterest.com *.pinterest.co.uk *.trustpilot.com *.clarity.ms *.grahamandgreen.pxf.io grahamandgreen.pxf.io *.bing.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.pinterdev.com commerce-app.pintergration.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 block-all-mixed-content; default-src 'none'; base-uri 'self'; child-src mc.yandex.ru mc.yandex.com blob:; connect-src 'self' tomesto.ru api.tomesto.ru wss://api.tomesto.ru https://scdn.tomesto.ru https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ru *.bugsnag.com mc.yandex.ru mc.yandex.by mc.yandex.com mc.yandex.md mc.yandex.kz suggestions.dadata.ru *.nr-data.net https://*.tiles.mapbox.com https://api.mapbox.com https://events.mapbox.com; font-src 'self' fonts.gstatic.com data:; form-action 'self'; img-src 'self' https: data: blob:; manifest-src 'self'; media-src 'self' tomesto.ru *.tomesto.ru; object-src 'none'; script-src 'self' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' tomesto.ru *.tomesto.ru https://*.googletagmanager.com d2wy8f7a9ursnm.cloudfront.net mc.yandex.ru mc.yandex.com https://js-agent.newrelic.com *.nr-data.net 'nonce-VmiMYuIR5wjch79A0OCZqA=='; style-src 'self' 'unsafe-inline' tomesto.ru *.tomesto.ru fonts.googleapis.com; worker-src blob:; report-uri https://api.tomesto.ru/csp_report 1 worker-src 'none'; font-src fonts.gstatic.com use.typekit.net kit.fontawesome.com *.fontawesome.com *.googleapis.com maxcdn.bootstrapcdn.com https://d3b4nwfy34ee2t.cloudfront.net https://d2nh8svgavbdh6.cloudfront.net css.zohocdn.com 'self' data: https://d2f594itnhlick.cloudfront.net fontawesome.com assets.adobedtm.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ api.razorpay.com 'self' www.googletagmanager.com https://td.doubleclick.net https://securestage.paytmpayments.com https://9618151.fls.doubleclick.net *.facebook.com *.doubleclick.net *.facebook.com/tr/ *.td.doubleclick.net https://*.td.doubleclick.net https://www.paypal.com https://www.sandbox.paypal.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.facebook.com https://meetanshi.com/media/logo.png cdn.razorpay.com 'self' b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com checkout.paypal.com www.facebook.com www.sandbox.paypal.com www.google.co.in c.clarity.ms *.bing.com/* https://d2nh8svgavbdh6.cloudfront.net https://d2f594itnhlick.cloudfront.net *.google.co.in *.adroll.com *.bidswitch.net tennishub.in ups.analytics.yahoo.com analytics.twitter.com google-analytics.com t.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googletagmanager.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://salesiq.zohopublic.in/widget cdn.jsdelivr.net https://www.clarity.ms/tag/jj2l9znc71 https://www.clarity.ms/s/0.7.69/clarity.js https://www.clarity.ms/tag/k45caocwix https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/471564928839789 https://js.zohocdn.com/salesiq/js/floatbutton1_jpInXe9VDveFPJJRfAolK73kxWVZ9fnhF9uuhrdGNpVho-1tsqriT3evhYJkgBKU_.js www.clarity.ms connect.facebook.net js.zohocdn.com salesiq.zohopublic.in https://d29rw3zaldax51.cloudfront.net *.cloudflare.com https://securestage.paytmpayments.com https://static-staging.paytmpayments.com https://staticpg.paytmpayments.com https://accounts-staging.paytm.in https://d3b4nwfy34ee2t.cloudfront.net https://beta.tennishub.in https://d2nh8svgavbdh6.cloudfront.net https://d2f594itnhlick.cloudfront.net script.crazyegg.com d1w4iaoithra2p.cloudfront.net static.ads-twitter.com tpc.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com d29rw3zaldax51.cloudfront.net https://d2nh8svgavbdh6.cloudfront.net d3b4nwfy34ee2t.cloudfront.net css.zohocdn.com 'self' 'unsafe-inline' 'report-sample' https://static-staging.paytmpayments.com https://d2f594itnhlick.cloudfront.net tennishub.in d1w4iaoithra2p.cloudfront.net prod.tennishub.in 'self' 'unsafe-inline'; object-src none 'self' 'unsafe-inline'; media-src *.adobe.com d3b4nwfy34ee2t.cloudfront.net 'self' d29rw3zaldax51.cloudfront.net d2f594itnhlick.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com https://get.geojs.io *.avada.io lumberjack.razorpay.com lumberjack-metrics.razorpay.com google.com 'self' https://d3b4nwfy34ee2t.cloudfront.net https://d2nh8svgavbdh6.cloudfront.net *.cardinalcommerce.com *.clarity.ms wss://vts.zohopublic.in/watchws https://www.google.co.in https://d.clarity.ms/collect https://api.razorpay.com *.paypal.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'unsafe-inline' salesiq.zohopublic.in stats.g.doubleclick.net https://securestage.paytmpayments.com https://d2f594itnhlick.cloudfront.net https://securegw.paytm.in https://securegw-stage.paytm.in googleadservices.com googletagmanager.com sandbox.paypal.com paypalobjects.com paypal.com get.geojs.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' z.clarity.ms www.google.com vts.zohopublic.in 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://cdnjs.cloudflare.com applepay.cdn-apple.com *.survicate.com https://github.com https://use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.monetico-services.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net www.facebook.com *.monetico-services.com connect.facebook.net graph.facebook.com business.facebook.com api.payplug.com secure.payplug.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ survey.survicate.com sdk.privacy-center.org cdn.mouseflow.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.survicate.com *.typekit.net *.klaviyo.com *.clarity.ms 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.monetico-services.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://o2.mouseflow.com *.clarity.ms 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob; script-src 'self' https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'self'; frame-src https:; object-src 'none'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report.php 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com chart.googleapis.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ 'self' https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicstream.s3.amazonaws.com/UNIFORMLAWS/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.ca *.betano.ca betano.com *.betano.com betgenius.com *.betgenius.com bing.com *.bing.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com geocomply.com *.geocomply.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kameleoon.eu *.kameleoon.eu kaizengaming.com *.kaizengaming.com optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery clarity.ms *.clarity.ms lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=8cQ2d2zj_6oiH7XcAEACoa7L1MWFct5vKlid7wg2IHA-1765940841-1.0.1.1-egyAvTTiqFWh_jUz7v649rbX6lDWkF6U0U2LCvqfiVmCrgTjvyAzfmqVj4zn4pV4d.4OdJ5BClrYMzpd8L4hE5wPYiJNyV0mU2xtSU_T_gTqEd2uaJjsH3yew70rwKSnRvsSWcbTf7dPXURVXvpUb64VpO03hBY0SGL_vpOFkFpwGNWlU7.jBXyW5sKGKTMO8OcEORvuRcfJMl8H7k6ATg; report-to cf-jacwihvfjdsufxdo 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.shopperapproved.com *.vertexsmb.com www.googletagmanager.com www.sageexchange.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.certcapture.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com *.vertexsmb.com seal.godaddy.com static.hotjar.com www.sageexchange.com *.formstack.com *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.shopperapproved.com seal-boston.bbb.org *.googleapis.com maps.gstatic.com *.meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://www.shopperapproved.com https://direct.shopperapproved.com *.vertexsmb.com seal.godaddy.com static.hotjar.com www.sageexchange.com *.formstack.com stats.g.doubleclick.net bat.bing.com *.ywxi.net *.amazonaws.com *.sagepayments.net maps.googleapis.com *.meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com downloads.mailchimp.com unsafe-inline *.googleapis.com seal.godaddy.com stats.g.doubleclick.net bat.bing.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com *.vertexsmb.com seal.godaddy.com static.hotjar.com *.googleapis.com *.formstack.com stats.g.doubleclick.net www.sageexchange.com *.ywxi.net *.amazonaws.com *.sagepayments.com *.meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://salucro5.salucro.com;script-src 'nonce-a700e6e43d884f31944485c5a1ce2b57' https://www.mybassetthealthconnection.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.mybassetthealthconnection.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com *.cash.app display.ugc.bazaarvoice.com unsafe-inline assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self' ; connect-src https://*.ampproject.org https://*.appsflyer.com https://bat.bing.com https://*.clarity.ms https://*.cloudfront.net https://*.compare.com https://*.criteo.com https://*.criteo.net https://stats.g.doubleclick.net https://www.facebook.com https://app.five9.com https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://www.googletagmanager.com https://*.insurify.com https://insurify.com https://insurifycdn.com https://*.klaviyo.com https://*.makestories.io https://*.mixpanel.com https://*.mxpnl.com https://*.pinterest.com wss://ws.pusherapp.com https://insurify.sjv.io https://*.snapchat.com https://lux.speedcurve.com https://analytics.tiktok.com https://widget.trustpilot.com https://*.usersnap.com https://ifrm.insurify.com https://browser-intake-datadoghq.com 'self' ; default-src 'self' ; font-src https://*.insurify.com https://fonts.gstatic.com https://*.bootstrapcdn.com https://insurifycdn.com https://widget.trustpilot.com https://ifrm.insurify.com 'self' data: ; form-action https://www.facebook.com https://tr.snapchat.com https://widget.trustpilot.com https://ifrm.insurify.com 'self' ; frame-ancestors 'self' ; frame-src https://insight.adsrvr.org https://match.adsrvr.org https://cj.dotomi.com https://*.doubleclick.net https://www.emjcd.com https://www.facebook.com https://*.pinterest.com https://www.quotelab.com https://tr.snapchat.com https://www.googletagmanager.com https://widget.trustpilot.com https://app.usecanopy.com https://ifrm.insurify.com 'self' ; img-src https://*.google.com https://*.googleapis.com https://www.google.bg https://www.google.com.pk https://www.googletagmanager.com https://maps.gstatic.com https://ib.adnxs.com https://*.appsflyer.com https://segment.prod.bidr.io https://*.bing.com https://*.clarity.ms https://*.cloudfront.net https://*.compare.com https://*.doubleclick.net https://www.facebook.com https://*.google-analytics.com https://www.gstatic.com https://insurifycdn.com *.makestories.io https://*.mediaalpha.com https://*.nextinsure.com https://*.pinterest.com https://www.shopperapproved.com https://*.snapchat.com https://lux.speedcurve.com https://*.storyblok.com https://cdn.transparent.ly https://widget.trustpilot.com https://*.usersnap.com 'self' data: ; media-src *.googlevideo.com 'self' ; script-src https://*.google.com https://*.googleapis.com https://www.google.bg https://www.google.com.pk https://maps.gstatic.com https://acdn.adnxs.com https://js.adsrvr.org *.ampproject.org https://*.appsflyer.com https://bat.bing.com https://*.bootstrapcdn.com https://*.clarity.ms https://*.cloudflare.com https://*.cloudfront.net https://*.compare.com https://*.criteo.com https://*.criteo.net https://googleads.g.doubleclick.net https://connect.facebook.net https://app.five9.com https://*.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://d.impactradius-event.com https://*.insurify.com https://insurifycdn.com https://*.jquery.com https://*.klaviyo.com https://insurance.mediaalpha.com https://*.mixpanel.com https://*.mxpnl.com https://s.pinimg.com https://*.pinterest.com https://sc-static.net https://www.shopperapproved.com https://cdn.speedcurve.com https://analytics.tiktok.com https://widget.trustpilot.com https://unpkg.com https://*.usersnap.com https://ifrm.insurify.com 'self' 'unsafe-inline' 'unsafe-eval' ; style-src https://fonts.googleapis.com https://*.bootstrapcdn.com https://*.googleapis.com https://*.ampproject.org https://widget.trustpilot.com https://ifrm.insurify.com 'self' 'unsafe-inline' ; worker-src 'self' blob: ; report-uri https://report-uri.insurify.com/json; 1 block-all-mixed-content; default-src 'self'; img-src 'self' blob: data: https:; script-src 'self' 'strict-dynamic' 'unsafe-inline' cdnjs.cloudflare.com js.intercomcdn.com k0r92gxvnwz6.statuspage.io https:; style-src 'self' 'unsafe-inline' fonts.googleapis.com tagmanager.google.com https://www.googletagmanager.com cdnjs.cloudflare.com cdn.jsdelivr.net embed.lpcontent.net; font-src 'self' data: https:; connect-src 'self' https: wss://*.intercom.io wss://*.pusher.com wss://*.ably.io wss://*.sessionstack.com; frame-src 'self' https:; media-src 'self' blob: data: https:; object-src 'self' *.amazonaws.com;; base-uri 'self'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubce2055812be5901b8d66c0f68cdc5bce&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=environment%3Aprod%2Cservice%3Asftptogo; 1 font-src maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.clearpay.co.uk *.mondu.ai/ *.mondu.local localhost:*/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.afterpay.com *.clearpay.co.uk *.adalyser.com *.tvsquared.com *.imgix.net magefan.com cm.magefan.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.klevu.com *.ksearchnet.com https://img.youtube.com flagpedia.net *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js *.cloudflareinsights.com *.gorgias.chat *.tvsquared.com *.adalyser.com *.addtoany.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net js.klevu.com *.ksearchnet.com *.gstatic.com maps.googleapis.com *.hsforms.net *.hsforms.com *.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com downloads.mailchimp.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.addtoany.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.gorgias.chat api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://dpm.demdex.net www.gstatic.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' cdn.360-value.com/ *.melissadata.net *.360-value.com; script-src 'nonce-RrfpfUJL3vzSKv+oGOgHow==' 'strict-dynamic' 'self' 'unsafe-inline' 'unsafe-eval' cdn.360-value.com/ *.melissadata.net *.360-value.com *.google.com *.googleapis.com *.bing.com *.virtualearth.net *.kampyle.com; frame-src cdn.360-value.com/ *.melissadata.net *.360-value.com *.kampyle.com; style-src 'self' 'unsafe-inline' cdn.360-value.com/ *.melissadata.net *.360-value.com *.google.com *.googleapis.com *.bing.com *.medallia.com *.kampyle.com; img-src 'self' cdn.360-value.com/ *.melissadata.net *.360-value.com *.google.com *.googleapis.com *.gstatic.com *.ggpht.com *.propmix.io *.bing.com *.virtualearth.net *.iso.com *.airmapserver.com:8080 *.kampyle.com data:; font-src 'self' cdn.360-value.com/ *.melissadata.net *.360-value.com *.google.com *.googleapis.com *.gstatic.com data:; connect-src 'self' cdn.360-value.com/ *.melissadata.net *.360-value.com *.googleapis.com *.gstatic.com *.bing.com *.virtualearth.net *.kampyle.com *.cybersource.com *.medallia.com; report-uri https://360-value.com/apps/iv/rest/cspReport; frame-ancestors * http: https: ; base-uri 'self'; 1 default-src 'self' data: https://cdn.eye-able.com https://www.eye-able-cdn.com; script-src 'self' 'nonce-RJkQtX_EqYGswlAqo_T1yX-QgpJCEOy7cOtkYcjDYXNhB9uYL5fXjw' data: https://*.openstreetmap.org https://piwik.westfaelische-hochschule.org https://*.b-ite.com https://www.eye-able-cdn.com 'sha256-kpp7jp1G7DKU2k6CPD6k/asyeO7+E2xEijdXf6SIVBo=' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://cdn.eye-able.com https://www.eye-able-cdn.com https://*.b-ite.com https://fonts.gstatic.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com; style-src-elem 'self' 'nonce-RJkQtX_EqYGswlAqo_T1yX-QgpJCEOy7cOtkYcjDYXNhB9uYL5fXjw' https://cdn.eye-able.com https://www.eye-able-cdn.com https://*.b-ite.com https://www.gstatic.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-ON+MdrZ2dq2tx2UE4WU1JvzaQayLhnhp+UdCmcBUXVA=' 'sha256-evlXprP8aYZfWtGuNDGteVp2szOTXZRCzJSjAs6HoQU=' 'sha256-WMm2rxgrdLbPiNOT3khywmfmX3KBQRnomQ+oL369Sik=' 'sha256-ZVjd2zfSTfAVh1y7eCcNk0SPGUQOP/H8vzrFJIVgg90=' 'sha256-cLU5/oMMUHS/N9urTg6WSPUWPuAZ02hayXsYjoUkva4=' 'sha256-iYqob1vCcitIN4aN8bIKm+LqktmCbhq/FJKYOIMyJI4=' 'sha256-p08VBe6m5i8+qtXWjnH/AN3klt1l4uoOLsjNn8BjdQo=' 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org https://piwik.westfaelische-hochschule.org https://*.b-ite.com; font-src 'self' data: https://cdn.eye-able.com https://www.eye-able-cdn.com https://fonts.gstatic.com https://cdn.scite.ai; style-src 'self' data: https://cdn.eye-able.com https://www.eye-able-cdn.com https://*.b-ite.com 'report-sample'; script-src-elem 'self' 'nonce-RJkQtX_EqYGswlAqo_T1yX-QgpJCEOy7cOtkYcjDYXNhB9uYL5fXjw' data: https://*.openstreetmap.org https://piwik.westfaelische-hochschule.org https://*.b-ite.com https://www.eye-able-cdn.com 'sha256-kpp7jp1G7DKU2k6CPD6k/asyeO7+E2xEijdXf6SIVBo=' https://cdn.eye-able.com https://connect.facebook.net 'sha256-Qv/VPCnMI30bPS9FCon86d6xCsmIBEeK7FUH2g3DSLA=' 'sha256-DHn6qIXxJ7Goiu9HCn2oUxRIiD5CncdiPGVck5LCmSw=' 'sha256-NNTZOCItJc2lwjmx5YPNr6GxN4IApSMqiyET2r1se98=' 'sha256-L1KTRnCkar390nbS9IVhytBi3LCcvlipxKCUQ5Pwh34=' 'sha256-xalV6Dk0W9vOogZ92sSSJKhCykaV2LYzK6On9AJ322o=' 'sha256-p25tvfrhwmHHQYBjAzut79Nba5GtD0Ddk31vVGWslfs=' 'sha256-rtaVU57dLbRdkXCugTr49x7HJRqjTwe5YoVCy2M4dDE=' 'sha256-ZgQOjhfNErc+jFOCITznCiFox3pQHBhC74pqacwXZ3Q=' 'sha256-ZgQOjhfNErc+jFOCITznCiFox3pQHBhC74pqacwXZ3Q=' 'sha256-+6LzFOOApZCAm6cux/qCcYofBOE+g5eXU6nFCrc0eyA=' 'sha256-ZIbFciq4U8SN2z6C2F3IsHx9XU+6EjoyS1Va9yDsHP4=' 'report-sample'; script-src-attr 'self' data: 'unsafe-inline' 'report-sample'; object-src 'none'; report-uri https://www.w-hs.de/@http-reporting?csp=report&requestTime=1765940749661721&requestHash=d5abe41466c3341321c9f2b9b729c1c12f5aca8d 1 style-src 'unsafe-inline' *; media-src *; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-avJfKua/G6ssvhBlf3DNQA=='; default-src 'none'; object-src 'none'; img-src blob: data: *; connect-src 'self' *.algolia.net *.algolianet.com *.algolia.io; base-uri 'none'; font-src 'self' data:; frame-ancestors 'none'; worker-src 'none' 1 child-src 'self' *.youtube.com; default-src * 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com data:; frame-src 'self' https://challenges.cloudflare.com *.plaid.com js.stripe.com *.youtube.com https://www.googletagmanager.com https://*.doubleclick.net https://www.facebook.com/ https://tpc.googlesyndication.com https://intercom-sheets.com/ https://calendly.com https://*.calendly.com https://capture.navattic.com https://guideline.navattic.com https://insight.adsrvr.org https://iframe.cloudflarestream.com/ https://customer-x5mykgv2c1zv0440.cloudflarestream.com/ https://match.adsrvr.org; img-src 'self' *.guideline.io https://cms-assets.guideline.com https://imagedelivery.net https://*.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.google.com https://*.google-analytics.com https://pagead2.googlesyndication.com https://www.facebook.com ads-twitter.com *.bing.com *.microsoft.com https://*.adsymptotic.com https://t.co https://*.linkedin.com https://analytics.twitter.com https://cdn.cookielaw.org https://trkn.us https://www.gravatar.com https://*.googleadservices.com https://alb.reddit.com https://*.intercomcdn.com https://*.intercomassets.com https://*.intercomusercontent.com data:; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' https://challenges.cloudflare.com https://cdn-assets-prod.s3.amazonaws.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://tracking-api.g2.com https://cdn.prod.uidapi.com https://*.googletagmanager.com https://tagmanager.google.com 'unsafe-eval' 'nonce-12816aceff1089d7ae9e22fb612f77c9' 'strict-dynamic'; worker-src 'self' *.youtube.com; base-uri 'self'; frame-ancestors 'self' https://*.squareup.com https://squareup.com https://*.squareupstaging.com https://squareupstaging.com https://*.checkhq.com https://*.eddy.com https://eddy.com https://app.belfrysoftware.com https://*.joinwarp.com https://*.monograph.com https://*.enkempass.com https://*.central.inc https://*.keka.com https://*.lumberfi.com https://*.workstream.us https://pro.housecallpro.com https://*.tryplayground.com https://*.7shifts.com https://app.getthera.com https://dashboard.miter.com https://*.zenoti.com https://*.prod.aioapp.com https://app.gosteelhead.com https://*.encompassfi.com https://*.joinhomebase.com; report-uri https://sentry2.guideline.com/api/6/security/?sentry_key=f678b7ad3eade55e6da26393e869e420; 1 font-src *.gstatic.com 'self' data: *.zopim.com *.loyaltylion.com *.loyaltylion.net *.bootstrapcdn.com *.googleapis.com *.hotjar.com wss://ws.hotjar.com *.typekit.net *.fontawesome.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.loyaltylion.com *.loyaltylion.net *.bootstrapcdn.com *.googleapis.com *.zopim.com wss://*.zopim.com *.demdex.net *.klarnaservices.com *.studentbeans.com *.beans.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.reviews.co.uk *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com *.addthis.com *.demdex.net *.criteo.com *.doubleclick.net *.vimeo.com *.google-analytics.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.loyaltylion.com *.loyaltylion.net *.bootstrapcdn.com *.googleapis.com *.zopim.com wss://*.zopim.com https://rcgmal4n.klarnaservices.com *.klarnaservices.com *.dotmailer-surveys.com *.google.com *.freshchat.com *.reviews.co.uk *.hotjar.com wss://ws.hotjar.com *.zenaps.com *.braintreegateway.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.feefo.com *.nosto.com *.bing.com *.facebook.com *.facebook.net *.google.com *.google.co.uk *.google.co.in *.googletagmanager.com *.postcodeanywhere.co.uk *.klevu.com *.demdex.net *.omtrdc.net *.doubleclick.net *.google-analytics.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.loyaltylion.com *.loyaltylion.net *.googleapis.com https://www.facebook.com https://www.google-analytics.com *.zopim.com wss://*.zopim.com *.dotmailer-surveys.com blob: *.klarnaservices.com *.pinterest.com *.bootstrapcdn.com https://yznrgxhu.klarnaservices.com *.klarnacdn.net *.icons8.com *.linkedin.com ids-couk.m2.s.ayko.com *.gstatic.com *.awin1.com *.zenaps.com *.dancedirect.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com chimpstatic.com *.nosto.com *.trackedweb.net trackedweb.net *.zopim.com *.dotmailer-surveys.com *.pcapredict.com *.loyaltylion.com *.klevu.com *.facebook.net *.bing.com *.rakuten.com *.zdassets.com *.jquery.com *.windows.net *.criteo.net *.criteo.com *.doubleclick.net *.addthis.com *.addthisedge.com *.moatads.com *.postcodeanywhere.co.uk *.google.com *.google.co.in *.gstatic.com *.cloudflare.com *.google-analytics.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.loyaltylion.net *.bootstrapcdn.com *.googleapis.com https://eu-library.klarnaservices.com/ *.pinterest.com *.klarnaservices.com *.klarnacdn.net *.adyen.com *.fontawesome.com *.freshchat.com *.hotjar.com wss://ws.hotjar.com *.pingdom.com *.dwin1.com *.pingdom.net *.scenttrail.co.uk scenttrail.co.uk *.licdn.com *.instagram.com *.adt313.net *.zenaps.com *.sciencebehindecommerce.com *.studentbeans.com *.beans.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.amazon.com *.link.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.loyaltylion.com *.klevu.com *.windows.net *.postcodeanywhere.co.uk *.google-analytics.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.loyaltylion.net *.bootstrapcdn.com fonts.googleapis.com *.zopim.com wss://*.zopim.com http://fonts.googleapis.com https://fonts.googleapis.com *.freshchat.com *.typekit.net data: downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedweb.net *.zdassets.com *.zopim.com wss://*.zopim.com *.google-analytics.com *.doubleclick.net *.loyaltylion.com *.demdex.net *.postcodeanywhere.co.uk *.addthis.com *.bing.com *.facebook.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.loyaltylion.net *.wpengine.com *.bootstrapcdn.com *.googleapis.com https://babea371.klarnauserservices.com *.feefo.com *.omtrdc.net *.klarnaservices.com *.klarnauserservices.com *.klarnaevt.com *.google.co.in *.hotjar.com *.hotjar.io wss://ws.hotjar.com wss://ws.hotjar.io *.pingdom.net *.dancedirect.com *.linkedin.com *.google.co.uk *.sciencebehindecommerce.com *.adt690.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klarna.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://aaalifetest.report-uri.com/r/t/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.bglobale.com *.global-e.com maxcdn.bootstrapcdn.com *.cloudflare.com *.typekit.net *.trustedshops.com 'self' data: *.crisp.chat *.hotjar.com *.hotjar.io *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.ometria.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bglobale.com *.global-e.com *.iubenda.com secure.authorize.net *.facebook.com *.facebook.net *.pinterest.com *.pinterest.co.uk *.hotjar.com *.hotjar.io *.clarity.ms *.rakuten.com *.vimeo.com *.linksynergy.com *.bounceexchange.com *.bouncex.net *.google.com/ *.stripe.com *.doubleclick.net *.paypalobjects.com *.gorgias.chat3- *.gorgias.chat4- *.gorgias.chat5- *.gorgias.io4- *.gorgias.work klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bglobale.com *.global-e.com *.iubenda.com www.google.com.ua www.google.com.uk www.google.com.fr www.google.com.de www.google.com.es *.cloudflare.com *.cloudfront.net https://cdn.klarna.com *.cdnwidget.com *.paypal.com https://s.ytimg.com *.usercentrics.eu *.ometria.com *.cdn-ometria-com.s3-eu-west-1.amazonaws.com *.postcodeanywhere.co.uk *.bing.com *.pinterest.com *.pinterest.co.uk *.pinimg.com *.facebook.com *.facebook.net *.clarity.ms *.hotjar.com *.hotjar.io *.google.com *.google.co.uk *.vimeo.com *.linksynergy.com *.bounceexchange.com *.bouncex.net *.googletagmanager.com *.gstatic.com *.astleyclarke.com *.emjcd.com cj.dotomi.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bglobale.com *.global-e.com *.iubenda.com www.google.com *.cloudflare.com *.trustedshops.com *.usercentrics.eu *.cloudfront.net client.crisp.chat *.pcapredict.com *.postcodeanywhere.co.uk *.ometria.com *.pinterest.com *.pinterest.co.uk *.pinimg.com *.facebook.com *.facebook.net *.clarity.ms *.hotjar.com *.hotjar.io *.bing.com *.googleoptimize.com *.googleapis.com *.google.co.uk *.rakuten.com *.linksynergy.com *.bounceexchange.com *.bouncex.net *.wknd.ai *.stripe.com *.mczbf.com *.gorgias.chat2- *.gorgias.chat3- *.gorgias.chat4- *.gorgias.chat5- *.gorgias.io4- *.gorgias.work config.gorgias.chat cdn.ometria.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.bglobale.com *.global-e.com maxcdn.bootstrapcdn.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu client.crisp.chat *.postcodeanywhere.co.uk *.bounceexchange.com *.gorgias.chat2- *.gorgias.chat3- *.gorgias.chat4- *.gorgias.chat5- *.gorgias.io4- *.gorgias.work *.googletagmanager.com *.stripe.network *.stripecdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.iubenda.com data: *.cloudflare.com *.paypal.com *.ometria.com *.cdn-ometria-com.s3-eu-west-1.amazonaws.com *.crisp.chat wss://client.relay.crisp.chat *.postcodeanywhere.co.uk *.doubleclick.net *.pinterest.com *.bing.com *.pinimg.com *.facebook.com *.facebook.net *.clarity.ms *.hotjar.com *.hotjar.io wss://*.hotjar.com *.rakuten.com *.linksynergy.com *.bounceexchange.com *.bouncex.net *.google-analytics.com *.analytics.google.com *.googleapis.com *.cdnbasket.net *.mczbf.com *.google.com/ *.google.co.uk/ google.com *.astleyclarke.com *.trustpilot.com *.gorgias.chat3- *.gorgias.chat4- *.gorgias.chat5- *.gorgias.io4- *.gorgias.work config.gorgias.chat api.ometria.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cae44243-9d5b-441e-a28a-9392df894e78.sansec.watch/; report-to report-endpoint; 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.curtmfg.com googleads.g.doubleclick.net www.googletagmanager.com secure.quantserve.com www.google-analytics.com www.google.com connect.facebook.net static.hotjar.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com www.googleadservices.com rules.quantcount.com *.hotjar.com js-agent.newrelic.com bam-cell.nr-data.net; report-uri /.webscale/csp-report 1 frame-src https://www.facebook.com https://go.nexon.com.au *.google.com; 1 default-src 'self'; frame-src td.doubleclick.net www.youtube.com youtube.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.typekit.net; font-src 'self' data: fonts.gstatic.com use.typekit.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com *.clarity.ms www.youtube.com; connect-src 'self' *.google.com www.google-analytics.com stats.g.doubleclick.net *.clarity.ms; img-src 'self' data: secure.gravatar.com *.clarity.ms www.googletagmanager.com i.ytimg.com; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=24831&v=v1.0&payload=ymp00hZ1EycWvkX3IquhUieuZ-WwiM7wmeLf82fnMT6pUZ5yKevVikT-ngB7BfWK8foLZ2v_8uZQ1XcRDBaDNPRGMUoh5jcpuRXdHGWPoBwWgQAmfAVrJNyqa9yxlOZYDyv8MXjVqbzsm8YgaPLGiwf6N38CEQXSy1j6jltgEsQwIe67PVhvel_bIEWTtC-J-tBUqjlepY70O5G45iUfKw==; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; script-src 'self' 'sha256-zn3op8od+cOgUB9F16FfC5YXIaE1ejBzRagBPmmqAdk=' https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net; connect-src 'self' https://*.google-analytics.com https://*.google.com https://*.facebook.com; img-src 'self' data: https://www.google-analytics.com https://i.ytimg.com https://www.facebook.com https://www.google.com https://www.google.co.jp; style-src 'self' https://fonts.googleapis.com https://cdnjs.cloudflare.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; frame-src https://www.youtube.com https://www.youtube-nocookie.com https://form.run https://www.googletagmanager.com; upgrade-insecure-requests 1 font-src https://client.crisp.chat https://fonts.gstatic.com *.fontawesome.com cdnjs.cloudflare.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com static.addtoany.com/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://image.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s3.antoineonline.com *.doubleclick.net *.paypal.com *.ytimg.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.googleadservices.com *.amazonaws.com antoine-images.com *.olx.com.lb *.ibb.co cdn-cookieyes.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://client.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s3.antoineonline.com *.cardinalcommerce.com *.doubleclick.net *.paypal.com *.ytimg.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.mastercard.com *.gateway.mastercard.com pay.google.com static.addtoany.com cdn-cookieyes.com *.newrelic.com *.nr-data.net *.livechatinc.com 'self' data: eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://client.crisp.chat https://static.klaviyo.com *.googleapis.com *.addtoany.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s3.antoineonline.com *.cardinalcommerce.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.cookieyes.com cdn-cookieyes.com *.nr-data.net *.livechatinc.com 'self' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.escape.com.au/csp-reports 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.monetico-services.com js.mollie.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.weltpixel.com www.xtento.com www.googletagmanager.com js.stripe.com m.stripe.network www.facebook.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.bird.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com www.burdastyle.fr www.facebook.com bat.bing.com *.burdastyle.fr *.burdastyle.com *.abo-online.fr *.burdastyle.es *.burdastyle.pt *.burdastyle.uk *.burdastyle.nl *.burdastyle.dk *.burdastyle.se *.burdastyle.pl *.faitmain-magazine.fr maps.googleapis.com www.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com static.klaviyo.com connect.facebook.net *.googletagmanager.com bat.bing.com js.stripe.com m.stripe.network analytics.tiktok.com static.cloudflareinsights.com static-tracking.klaviyo.com www.google.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.monetico-services.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google-analytics.com *.facebook.net *.a.klaviyo.com static-forms.klaviyo.com bat.bing.com m.stripe.com www.google.com www.google.fr region1.analytics.google.co 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' cdnjs.cloudflare.com cdn.jsdelivr.net *.zdassets.com cdn.brcdn.com *.googleapis.com *.google-analytics.com *.google.com *.newrelic.com bam.nr-data.net *.amazonaws.com *.jquery.com fonts.fontawesome.com fonts.gstatic.com use.fontawesome.com sarnova-dev.s3.amazonaws.com *.akstat.io *.klaviyo.com *.nice-incontact.com *.boundtree.com *.brsrvr.com *.stackadapt.com *.hotjar.io *.hotjar.com *.go-mpulse.net *.googletagmanager.com *.doubleclick.net player.vimeo.com www.youtube.com; script-src 'self' *.klaviyo.com cdn.brcdn.com sarnova.s3.amazonaws.com *.nice-incontact.com *.google-analytics.com *.newrelic.com *.hotjar.com *.go-mpulse.net *.stackadapt.com *.googleadservices.com cdn.acsbapp.com www.youtube.com 'unsafe-inline' *.googletagmanager.com *.acsbapp.com acsbapp.com 'unsafe-eval'; connect-src 'self' cdn.acsbapp.com *.acsbapp.com acsbapp.com tags.srv.stackadapt.com *.klaviyo.com www.google-analytics.com www.google.com www.googleadservices.com *.hotjar.com bam.nr-data.net api-js.datadome.co c.go-mpulse.net analytics.google.com; worker-src 'self' blob: 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' js.hscta.net js-eu1.hscta.net js.hs-analytics.net static.hsappstatic.net track.hubspot.com no-cache.hubspot.com *.hubspot.com *.hs-sites.com *.hs-scripts.com forms.hsforms.com forms.hsforms.net cdn2.hubspot.net www.googletagmanager.com www.google-analytics.com stats.g.doubleclick.net connect.facebook.net snap.licdn.com bat.bing.com 'strict-dynamic' 'nonce-OrLHd6bAXXyau8fIgBgX9g==' 1 report-uri https://www.yelp.com/csp_report_only?id=4a314a96abb6093b&page=csp_report_frame_directives%2Cfull_site_ssl_csp_report_directives&policy_hash=41d0c45536d2a082f11d1cd0e00fde7f&site=www×tamp=1765941302; frame-ancestors 'self' https://*.yelp.com; default-src https:; img-src https: data: blob:; script-src https: data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'unsafe-inline' data:; font-src data: https:; child-src https: yelp-webview://* yelp://* data:; object-src 'none'; worker-src blob: https:; base-uri 'self'; form-action https: 1 default-src 'self';script-src 'self' 'unsafe-inline' https://pay.google.com https://applepay.cdn-apple.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;img-src 'self' data:;connect-src 'self';font-src 'self' 'unsafe-inline' https://fonts.googleapis.com;media-src 'self';frame-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests 1 default-src 'self' https://d1g5x7b3jtu99v.cloudfront.net;script-src 'self' 'unsafe-inline' js.stripe.com widget.intercom.io js.intercomcdn.com cdn.segment.com cdn.lr-in-prod.com https://*.google-analytics.com api.figma.com https://d1g5x7b3jtu99v.cloudfront.net data: connect.facebook.net https://googleads.g.doubleclick.net https://*.googletagmanager.com cdn.jsdelivr.net js.hs-scripts.com js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net js.hsforms.net static.hsappstatic.net https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://cdn.vector.co/pixel.js https://*.clarity.ms https://api.app.bullseye.so cdn.getkoala.com js.hsadspixel.net cdn.cr-relay.com a.usbrowserspeed.com d-code.liadm.com https://web.cmp.usercentrics.eu https://assets.revenuehero.io snap.licdn.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com https://d1g5x7b3jtu99v.cloudfront.net;img-src *;font-src 'self' fonts.gstatic.com https://fonts.intercomcdn.com https://d1g5x7b3jtu99v.cloudfront.net;media-src 'self' https://js.intercomcdn.com https://d1g5x7b3jtu99v.cloudfront.net;connect-src 'self' https://*.chromatic.com https://index.chromatic.com snapshots.chromatic.com api-iam.intercom.io nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://cdn.segment.com https://*.google-analytics.com https://analytics.google.com https://api.segment.io https://stats.g.doubleclick.net https://api-us-east-1.graphcms.com https://r.lr-in-prod.com webmention.io hichroma.us15.list-manage.com https://*.ingest.sentry.io api.figma.com https://pagead2.googlesyndication.com https://forms.hscollectedforms.net https://api.hsforms.com forms.hsforms.com https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://google.com api.vector.co https://*.clarity.ms https://api.app.bullseye.so https://pro.ip-api.com api.cr-relay.com https://www.facebook.com api.getkoala.com https://api.hubapi.com https://*.usercentrics.eu https://app.revenuehero.io px.ads.linkedin.com;child-src 'self' blob:;frame-src 'self' https://www.chromatic.com https://index.chromatic.com snapshots.chromatic.com js.stripe.com https://www.youtube.com https://chromatic-interactive-demo.netlify.app https://*.chromatic.com https://td.doubleclick.net https://*.googletagmanager.com https://meetings.hubspot.com https://forms.hsforms.com https://popup.schedulehero.io;frame-ancestors 'self' https://*.chromatic.com 1 default-src https:; connect-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline' blob:; script-src-elem https: 'unsafe-eval' 'unsafe-inline' blob:; img-src https: data: blob:; media-src https: data: blob:; frame-src https: data: blob:; form-action 'self' https://www.facebook.com; font-src https: data:; style-src 'unsafe-inline' https:; worker-src https: blob:;report-to csp-report-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.googleapis.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com www.gstatic.com *.trackedlink.net *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src self; connect-src self; default-src self; font-src self; img-src self; manifest-src self; media-src self; prefetch-src self; object-src self; script-src 'strict-dynamic' 'sha256-SR8bN339OMynNJtiOzokEXzJnun61AQRM3sZP6Vm+M4=' 'sha256-q3zEDUi6jsrAJ7yXcvfYY8d0Of1fXCLY/i1LV+xLmM8=' 'nonce-NGQ5Mzg2NjZlMzIzZWE1ODQwYmM1OTM3YTEzMzY0ODk4ZTkxZWUzNTM3OTcyNTM2MjA1ZDA1ZTNhNDU3MzdlODI1OWIyMDZjOWFjMWI3NDc2ZGQ4NGRkZTlmY2RjYTg1Zjg4MmQ2OWI4ZmVjNTkzYTIzNGY3ODNjYzJhNmM4MmU=' self; style-src 'nonce-NGQ5Mzg2NjZlMzIzZWE1ODQwYmM1OTM3YTEzMzY0ODk4ZTkxZWUzNTM3OTcyNTM2MjA1ZDA1ZTNhNDU3MzdlODI1OWIyMDZjOWFjMWI3NDc2ZGQ4NGRkZTlmY2RjYTg1Zjg4MmQ2OWI4ZmVjNTkzYTIzNGY3ODNjYzJhNmM4MmU=' self; worker-src self; frame-ancestors 'self' 1 default-src 'self' data: gap: *.klarna.com *.freshchat.com *.vimeo.com *.youtube.com *.whittard.co.uk *.whittard.com mention-me.com *.zenaps.com *.sub2tech.com *.gstatic.com *.facebook.com *.bglobale.com *.global-e.com *.onetrust.com *.windows.net *.whittardofchelsea.freshdesk.com *.tvsquared.com; img-src data: blob: *.demandware.net *.commercecloud.salesforce.com *.ads.linkedin.com *.demdex.net *.amazonaws.com *.ometria.com *.googletagmanager.com *.facebook.net *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.gstatic.com *.doubleclick.net *.googleapis.com *.google-analytics.com *.googleadservices.com *.google.com *.whittard.co.uk *.whittard.com *.postcodeanywhere.co.uk *.pcapredict.com *.yotpo.com *.tokywoky.com img.tokywoky.com *.klarnaservices.com *.klarnacdn.net *.mention-me.com *.awin1.com *.dwin1.com bda.bookatable.com i.ytimg.com *.contentsquare.net *.contentsquare.com *.sub2tech.com *.cloudfront.net *.youtube.com *.vimeo.com bat.bing.com *.zenaps.com *.msgfocus.com *.fbsbx.com *.fbcdn.net graph.facebook.com *.zscloud.net *.googleusercontent.com *.klarnaevt.com i.vimeocdn.com *.surveymonkey.com *.kaltura.com *.gocertify.me *.bglobale.com *.global-e.com *.bc0a.com *.b0e8.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.googleanalytics.com *.google-analytics.com *.googleoptimize.com *.tvsquared.com analytics.whittard.com analytics.whittard.co.uk ade.googlesyndication.com *.abtasty.com *.roeyecdn.com *.roeye.com *.linkedin.com; child-src 'self' blob: *.abtasty.com *.studentbeans.com *.google.com *.doubleclick.net *.facebook.com *.tokywoky.com *.freshchat.com mention-me.com *.mention-me.com *.klarna.com *.klarnaservices.com bda.bookatable.com *.sub2tech.com *.youtube.com *.vimeo.com *.zenaps.com *.googlesyndication.com *.online-metrix.net *.pagetiger.com *.googletagmanager.com connect.studentbeans.com *.googleapis.com *.surveymonkey.com *.paperform.co paperform.co *.ordergroove.com *.worldpay.com *.cardinalcommerce.com *.gocertify.me *.bglobale.com *.global-e.com whittardofchelsea.freshdesk.com *.pinterest.com *.whittard.co.uk *.whittard.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.postcodeanywhere.co.uk *.pcapredict.com *.bootstrapcdn.com *.myfonts.net cdnjs.cloudflare.com *.yotpo.com *.freshchat.com *.mention-me.com *.sub2tech.com bda.bookatable.com *.klarnacdn.net *.whittard.co.uk *.whittard.com *.ordergroove.com *.particularaudience.com *.p-a.io *.google.com *.amazonaws.com *.abtasty.com *.gstatic.com; font-src 'self' data: *.gstatic.com *.g.doubleclick.net *.bootstrapcdn.com *.yotpo.com *.bookatable.com *.alicdn.com *.klarnacdn.net *.whittard.co.uk *.whittard.com *.ordergroove.com *.fontawesome.com *.bglobale.com *.global-e.com *.abtasty.com *.googleapis.com use.typekit.net; media-src 'self' data: *.facebook.com *.youtube.com *.vimeo.com *.paypal.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' snap.licdn.com code.jquery.com *.pinimg.com *.cquotient.com *.ometria.com *.tryzens-analytics.com:12443 *.tvsquared.com *.facebook.net cdnjs.cloudflare.com cdn.cquotient.com *.googletagmanager.com www.googletagmanager.com *.g.doubleclick.net *.googleapis.com *.google-analytics.com *.googleadservices.com *.google.com *.gstatic.com *.dwin1.com *.postcodeanywhere.co.uk *.pcapredict.com *.z-analytics.net *.yotpo.com *.tokywoky.com *.msecnd.net *.freshchat.com *.klarnaservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mention-me.com *.worldpay.com *.cardinalcommerce.com bda.bookatable.com bat.bing.com *.contentsquare.net *.contentsquare.com *.sub2tech.com *.yottaa.com *.cloudfront.net *.freshworksapi.com *.zenaps.com *.paypal.com *.paypalobjects.com *.awin1.com *.dwin1.com *.sessioncam.com *.whittard.co.uk *.whittard.com *.bootstrapcdn.com *.googlesyndication.com www.google.com *.studentbeans.com onlineerp.solution.quebec widget.surveymonkey.com *.paperform.co paperform.co *.ordergroove.com cdnapisec.kaltura.com *.gocertify.me *.bglobale.com *.global-e.com *.b0e8.com *.vimeo.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.googleanalytics.com *.googleoptimize.com analytics.whittard.com analytics.whittard.co.uk *.amazonaws.com *.abtasty.com *.roeyecdn.com *.roeye.com *.pinterest.com *.zi-scripts.com *.roeye.com *.payments-amazon.com *.tryzens-analytics.com unpkg.com cdn.cookielaw.org; connect-src 'self' *.ads.linkedin.com snap.licdn.com *.rapid.yottaa-network.net pagead2.googlesyndication.com *.google-analytics.com *.googleadservices.com *.g.doubleclick.net *.tryzens-analytics.com:12280 *.ometria.com *.postcodeanywhere.co.uk *.pcapredict.com *.yotpo.com *.tokywoky.com *.klarnauserservices.com *.klarnaservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mention-me.com mention-me.com bda.bookatable.com *.z-analytics.net *.contentsquare.net *.contentsquare.com *.sub2tech.com *.cloudfront.net *.awin1.com *.dwin1.com *.yottaa.net *.sessioncam.com bat.bing.com *.facebook.com *.google.com *.facebook.net *.googleapis.com widget.surveymonkey.com *.s3.amazonaws.com *.ordergroove.com *.worldpay.com *.cardinalcommerce.com *.gocertify.me *.bglobale.com *.global-e.com *.vimeo.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.gstatic.com *.abtasty.com analytics.whittard.com analytics.whittard.co.uk ade.googlesyndication.com *.whittard.com *.whittard.co.uk *.amazonaws.com *.pinterest.com *.zi-scripts.com *.zoominfo.com *.tryzens-analytics.com unpkg.com cdn.cookielaw.org *.google.co.uk *.bing.net payments-eu.amazon.com; manifest-src 'self'; ; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/whittard-cspdata; 1 script-src-attr https://cdn.evgnet.com https://*.googleapis.com https://tag.rmp.rakuten.com/ https://js.squarecdn.com/ https://unpkg.com/ https://livesearch-metrics.magento-ds.com/ https://*.addressfinder.io https://cdn.jsdelivr.net/ https://*.newrelic.com https://*.freshchat.com https://commerce.adobedtm.com/ https://*.braintreegateway.com https://*.stripe.com https://www.google.com/ https://www.googletagmanager.com/ https://*.trackedlink.net https://*.trackedweb.net https://t.cfjump.com/ https://s.pinimg.com/ https://tags.creativecdn.com/ https://analytics.tiktok.com/ https://www.clarity.ms/ https://connect.facebook.net/ https://www.gstatic.com/ https://pt.wisernotify.com/ https://ct.pinterest.com/ https://*.paypal.com https://*.google.com 'self' 'unsafe-inline'; script-src-elem https://cdn.evgnet.com https://*.googleapis.com https://tag.rmp.rakuten.com/ https://js.squarecdn.com/ https://unpkg.com/ https://livesearch-metrics.magento-ds.com/ https://*.addressfinder.io https://cdn.jsdelivr.net/ https://*.newrelic.com https://*.freshchat.com https://commerce.adobedtm.com/ https://*.braintreegateway.com https://*.stripe.com https://www.google.com/ https://www.googletagmanager.com/ https://*.trackedlink.net https://*.trackedweb.net https://t.cfjump.com/ https://s.pinimg.com/ https://tags.creativecdn.com/ https://analytics.tiktok.com/ https://www.clarity.ms/ https://connect.facebook.net/ https://www.gstatic.com/ https://pt.wisernotify.com/ https://ct.pinterest.com/ https://*.paypal.com https://*.google.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://stackpath.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app www.google.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.googleapis.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.tagalys.com https://sdk.giftflick.com.au/ https://cdn.giftflick.com.au/ https://gf-cdn.s3-ap-southeast-2.amazonaws.com/ *.clarity.ms *.google.com https://c.bing.com/ *.facebook.com https://www.google.com.au/ https://ad.doubleclick.net/ https://*.rubiconproject.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://api.addressfinder.io https://rum.hlx.page https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.convertexperiments.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://cdnjs.cloudflare.com https://d3htxdwqp62ai4.cloudfront.net http://d2r9py2hfy5mgp.cloudfront.net http://d3fzz8zsf83ont.cloudfront.net https://storage.googleapis.com https://player.vimeo.com/ https://www.giftflick.com.au/ https://sdk.giftflick.com.au/ *.creativecdn.com https://s.pinimg.com/ *.pinterest.com *.clarity.ms https://dusk-455267821617990643-help.freshchat.com/ https://analytics.tiktok.com/ https://connect.facebook.net/ *.wisernotify.com t.cfjump.com *.dusk.com.au *.attn.tv https://cdn.jsdelivr.net/npm/@growthbook/ https://tag.rmp.rakuten.com/ https://cdn.evgnet.com https://*.googleapis.com https://js.squarecdn.com/ https://unpkg.com/ https://livesearch-metrics.magento-ds.com/ https://*.addressfinder.io https://cdn.jsdelivr.net/ https://*.newrelic.com https://*.freshchat.com https://commerce.adobedtm.com/ https://*.braintreegateway.com https://*.stripe.com https://www.google.com/ https://www.googletagmanager.com/ https://*.trackedlink.net https://*.trackedweb.net https://t.cfjump.com/ https://tags.creativecdn.com/ https://www.clarity.ms/ https://www.gstatic.com/ https://pt.wisernotify.com/ https://ct.pinterest.com/ https://*.paypal.com https://*.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io static.afterpay.com/ *.squarecdn.com *.cash.app assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com https://cdnjs.cloudflare.com https://tagalys-assets.s3-ap-southeast-1.amazonaws.com https://d3htxdwqp62ai4.cloudfront.net https://stackpath.bootstrapcdn.com https://sdk.giftflick.com.au/ https://dusk-455267821617990643-help.freshchat.com/ *.wisernotify.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://player.vimeo.com/ https://cdn.giftflick.com.au/ https://videos-demo.giftflick.com.au/ https://download-video.akamaized.net/ https://*.vimeocdn.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.convertexperiments.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://api-r1.tagalys.com https://api-r2.tagalys.com https://api-r3.tagalys.com https://api-r4.tagalys.com https://staging-api-r2.tagalys.com http://tagalys-api.docker:3000 https://www.giftflick.com.au/ https://api-demo.giftflick.com.au/ https://api.giftflick.com.au/ *.creativecdn.com *.pinterest.com *.clarity.ms https://analytics.tiktok.com/ *.wisermapp.com *.azurewebsites.net *.doubleclick.net *.attn.tv https://cdn.growthbook.io/ https://*.evergage.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.fontawesome.com *.googleapis.com *.cloudflare.com *.vimeo.com *.youtube.com *.googletagmanager.com *.ckeditor.com *.google-analytics.com *.newrelic.com *.nr-data.net; object-src *; img-src * data: blob:; frame-src *; font-src * data: blob:; report-uri /report-csp-violation 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com data: *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.trustedshops.com *.googleapis.com *.eichholtz.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com www.google.com *.appspot.com *.cookiebot.com *.eichholtz.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.elfsight.com *.cloudflare.com *.googleadservices.com *.paypal.com *.twitter.com *.pingdom.net *.appspot.com *.cookiebot.com *.facebook.com *.eichholtz.com *.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googletagmanager.com tagmanager.google.com *.sharethis.com *.elfsight.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.gstatic.com *.fontawesome.com *.chimpstatic.com chimpstatic.com *.pingdom.net *.appspot.com *.cookiebot.com *.eichholtz.com *.hotjar.com *.clarity.ms *.mxpnl.com *.mixpanel.com *.facebook.net *.cookieconsent.io *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com *.typekit.net *.elfsight.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.eichholtz.com *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.sharethis.com *.elfsight.com *.cloudflare.com *.twitter.com *.appspot.com *.cookiebot.com *.pingdom.net *.eichholtz.com *.hotjar.com *.hotjar.io *.clarity.ms *.mixpanel.com *.cookieconsent.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: *.cloudflare.com *.twitter.com *.googleapis.com *.bootstrapcdn.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.cleverreach.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.twitter.com *.addthis.com *.uptain.de *.hotjar.com *.cleverreach.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudfront.net magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com maps.gstatic.com x.klarnacdn.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.google.de *.maxcluster.net *.magecomp.com *.ssl-amazon.com *.wimo.com *.google.com *.google.com.ua *.trbo.com *.clarity.ms *.usercentrics.eu *.bing.com blob: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.googleapis.com *.gstatic.com *.disqus.com https://cdn.jsdelivr.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com maps.googleapis.com x.klarnacdn.net/ https://www.googletagmanager.com tagmanager.google.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com widgets.pinterest.com app.uptain.de *.hotjar.com *.facebook.net *.cloudflareinsights.com *.cleverreach.com *.cleverreach.de *.googleoptimize.com *.trbo.com *.clarity.ms *.usercentrics.eu *.cardinalcommerce.com cdn.jsdelivr.net *.googletagmanager.com data: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com *.cloudflare.com *.twitter.com *.typekit.net *.bootstrapcdn.com data: *.trbo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline';, connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com maps.googleapis.com https://www.google-analytics.com *.cloudflare.com *.twitter.com *.uptain.de *.hotjar.com wss://ws15.hotjar.com *.hotjar.io *.google.de *.doubleclick.net ekr.zdassets.com/ *.clarity.ms *.usercentrics.eu 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.usercentrics.eu assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net *.google.com analytics.google.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com *.cardinalcommerce.com cdn.jsdelivr.net *.googletagmanager.com *.hotjar.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.de *.payments-amazon.es *.cloudflareinsights.com *.facebook.net *.facebook.com data: *.trbo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com *.google-analytics.com *.google.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.facebook.net *.klaviyo.com *.hotjar.com *.authorize.net sec.webeyez.com www.gstatic.com www.google.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.cardinalcommerce.com includestest.ccdc02.com *.paypal.com pilot-payflowlink.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.cardinalcommerce.com includestest.ccdc02.com *.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com google.com *.google.com pay.google.com *.affirm.com *.affirm.ca *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.doubleclick.net www.google.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.paypal.com www.paypalobjects.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.typekit.net *.gstatic.com validator.swagger.io assets.braintreegateway.com *.googleapis.com *.affirm.com *.affirm.ca *.klaviyo.com *.adobedtm.com *.facebook.com *.facebook.net magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com https://firebasestorage.googleapis.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com *.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com pay.google.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.klaviyo.com *.hotjar.com *.webeyez.com *.adobedtm.com *.googleadservices.com *.addthis.com *.facebook.net sec.webeyez.com www.gstatic.com www.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.klaviyo.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.cardinalcommerce.com includestest.ccdc02.com *.paypal.com www.paypalobjects.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.affirm.com *.affirm.ca *.klaviyo.com capig.stape.biz *.webeyez.com *.adobedtm.com *.hotjar.io *.hotjar.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.mmapiws.com 'self' 'unsafe-inline'; child-src *.braintreegateway.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com static.baufragen.de data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadolibre.com *.multisafepay.com https://pay.google.com *.cookiebot.com cloud.web.oracdecor.com/newsletter pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com cdn.flbx.io *.cloudfront.net *.disqus.com https://img.youtube.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.multisafepay.com *.cookiebot.com static.przelewy24.pl www.gstatic.com gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.googleapis.com *.gstatic.com *.getflowbox.com *.disqus.com https://z.moatads.com https://cdn.jsdelivr.net *.mlstatic.com *.mercadopago.com *.multisafepay.com https://pay.google.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com svs.oracdecor.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.multisafepay.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.getflowbox.com *.mercadopago.com *.mercadolibre.com *.multisafepay.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com svs.oracdecor.com https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob: ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' 'nonce-758030eb-9338-4168-b3dd-bb2c9c8fb697' http: https: https://bpoint.com.au https://bpoint.uat.linkly.com.au; style-src 'self' 'unsafe-inline' https://*.arcgis.com https://bpoint.com.au https://bpoint.uat.linkly.com.au; connect-src 'self' http: https: data: mediastream: blob: filesystem: ws: wss: analytics.google.com https://*.arcgis.com https://*.arcgisonline.com https://dc.services.visualstudio.com https://*.doubleclick.net wss://ws.hotjar.com https://*.hotjar.io https://content.hotjar.io https://vc.hotjar.io https://surveystats.hotjar.io https://bpoint.com.au https://bpoint.uat.linkly.com.au; font-src 'self' https://*.arcgis.com https://script.hotjar.com data:; object-src 'none' ; frame-src 'self' https://*.google.com https://*.youtube.com *.westernpower.com.au https://*.microsoftcrmportals.com/ https://*.doubleclick.net https://*.apac01.idio.episerver.net/ https://online.flippingbook.com/ https://*.googletagmanager.com/; base-uri 'self' ; report-uri https://www.westernpower.com.au/api/csp; report-to csp-endpoint; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com *.dinhvan.com https://fonts.gstatic.com https://ws.colissimo.fr data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu https://www.youtube.com https://form.typeform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.dinhvan.com *.doubleclick.net *.google.fr *.googlesyndication.com *.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net *.dinhvan.com *.tiktok.com *.axept.io chimpstatic.com s.pinimg.com ct.pinterest.com *.facebook.net downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com *.dinhvan.com downloads.mailchimp.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.dinhvan.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.axept.io *.google.fr *.dinhvan.com analytics.tiktok.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com ct.pinterest.com s.pinimg.com *.vimeocdn.com vimeo.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'nonce-Sdy8TWwdneRwHeyuNUr9ukWYUMBb8R7bXgzKQmBkNm4=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 font-src fonts.gstatic.com use.typekit.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com *.typekit.net *.trustedshops.com *.similarinc.com *.zipmoney.com.au *.zendesk.com *.bootstrapcdn.com p-a.io *.particularaudience.com *.digidirect.com.au images.latitudepayapps.com imageapi.magebinary.co.nz *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.zipmoney.com.au *.digidirect.com.au *.images.latitudepayapps.com *.imageapi.magebinary.co.nz *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app * *.zipmoney.com.au *.digidirect.com.au *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://plumrocket.com *.weltpixel.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com cdn.klarna.com *.paypal.com s.ytimg.com *.google.com *.facebook.com *.adsrvr.org *.google.com.ph *.similarinc.com *.cloudfront.net digidirect.zendesk.com *.pinterest.com *.analytics.yahoo.com *.zendesk.com *.gstatic.com *.klarnacdn.net *.facebook.net *.doubleclick.net *.kayweb.com.au p-a.io *.particularaudience.com *.services.qantasloyalty.com *.adobedtm.com *.latitudepayapps.com zip.co bpi.zip.co *.latitudefinancial.com *.google.lk *.digidirect.com.au https://www.magezon.com marketplacer.imgix.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com maps.googleapis.com *.cloudfront.net *.testfreaks.com *.cfjump.com *.facebook.net *.benchplatform.com *.livechatinc.com *.g.doubleclick.net googletagmanager.com *.adsrvr.org *.studio19.com.au *.particularaudience.com *.srv.stackadapt.com cfjump.digidirect.com.au *.gstatic.com t.cfjump.com settings.luckyorange.net *.similarinc.com *.api.similarinc.com *.zipmoney.com.au *.zip.co *.zdassets.com assets.pinterest.com r3.dotdigital-pages.com api.smooch.io *.klarna.com *.klarnacdn.net *.google.com *.cardinalcommerce.com *.braintreegateway.com *.braintree-api.com *.paypal.com *.visitors.live *.eventbrite.com *.eventbriteapi.com *.wibmo.com *.paypal.cn *.paypalobjects.com *.googleadservices.com *.soreto.com *.kayweb.com.au p-a.io api-recs.particularaudience.com d10lpsik1i8c69.cloudfront.net gtm.js *.connect.studentbeans.com *.studentbeans.com *.instagram.com *.jquery.com *.adobedtm.com *.adobed.com *.latitudefinancial.com *.static.afterpay.com *.latitudepayapps.com *.clarity.ms *.zendesk.com *.digidirect.com utt.impactcdn.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu tags.srv.stackadapt.com *.similarinc.com *.zipmoney.com.au *.gstatic.com *.google.com *.kayweb.com.au *.bootstrapcdn.com p-a.io *.particularaudience.com *.cloudfront.net *.zip.co *.digidirect.com images.latitudepayapps.com/ imageapi.magebinary.co.nz/ *.fontawesome.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.zendesk.com *.kayweb.com.au p-a.io *.particularaudience.com *.services.qantasloyalty.com *.zip.co *.zipmoney.com.au *.digidirect.com.au 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.zendesk.com *.cloudflare.com *.paypal.com t.cfjump.com settings.luckyorange.net *.particularaudience.com stats.g.doubleclick.net *.google-analytics.com tags.srv.stackadapt.com secure.studio19.com.au secure.polygongroup.com.au bam-cell.nr-data.net *.similarinc.com *.api.similarinc.com *.zipmoney.com.au *.visitors.live *.googleapis.com *.zdassets.com digidirect.zendesk.com *.zip.co api.smooch.io *.gstatic.com *.google.com *.klarnacdn.net *.cardinalcommerce.com *.demdex.net *.braintree-api.com *.braintreegateway.com *.wibmo.com *.paypal.cn *.paypalobjects.com *.kayweb.com.au p-a.io *.qantasloyalty.com *.services.qantasloyalty.com api-recs.particularaudience.com d10lpsik1i8c69.cloudfront.net *.static.afterpay.com *.doubleclick.net *.clarity.ms wss://in.visitors.live visitors.live insight.adsrvr.org api-preview.luckyorange.com *.digidirect.com digidirect.pxf.io d.impct.site api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com google.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.images.latitudepayapps.com *.imageapi.magebinary.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://hosting.gl; script-src 'self' 'unsafe-inline' https://hosting.gl https://hosting.gl/templates/lagom2/assets/js/ https://statistics.hosting.gl https://www.googletagmanager.com https://connect.facebook.net https://widget.trustpilot.com https://cdn.datatables.net https://customerwidget.joinflow.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; connect-src 'self' https://region1.google-analytics.com https://statistics.hosting.gl https://www.facebook.com https://api.telavox.se https://payment.quickpay.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' https://www.facebook.com data:; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://widget.trustpilot.com; form-action 'self'; frame-ancestors 'self'; report-uri https://hostinggl.report-uri.com/r/d/csp/wizard 1 connect-src 'self' https://api.stripe.com https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://*.thedonkeysanctuary.org.uk https://*.googlesyndication.com https://ds.cookiehub.net https://consent.cookiehub.net https://region-eu.cookiehub.net https://consent-eu.cookiehub.net https://cookiehub.net https://cdn.cookiehub.eu https://api.edq.com https://*.google-analytics.com/ sentry.io https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com https://www.googletagmanager.com https://live.streamdays.com https://*.google.com; img-src 'self' https://*.webtrends-optimize.com https://planyo-ch.s3.eu-central-2.amazonaws.com https://www.planyo.com data: https://*.googlesyndication.com https://i.ytimg.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.js.stripe.com https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://cookiehub.net https://cdn.cookiehub.eu cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://js.stripe.com https://www.gstatic.com https://www.planyo.com; script-src-elem 'self' 'unsafe-inline' https://*.webtrends-optimize.com https://maxcdn.bootstrapcdn.com https://www.googletagmanager.com https://cdn.cookiehub.eu https://live.streamdays.com https://ajax.googleapis.com https://*.googlesyndication.com https://www.google.com/recaptcha/ cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://js.stripe.com https://www.gstatic.com https://www.planyo.com; style-src 'self' 'report-sample' 'unsafe-inline' https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://cookiehub.net https://cdn.cookiehub.eu https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.planyo.com https://assets.planyoexperts.com https://cdn.cookiehub.eu https://cookiehub.net https://cdnjs.cloudflare.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com maxcdn.bootstrapcdn.com *.myfeelback.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com bpcepaymentservices-3ds-vdm.wlp-acs.com *.modirum.com *.cic.fr *.cafis-paynet.jp *.creditmutuel.fr *.lcl.fr *.americanexpress.com *.dnp-cdms.jp *.sg.fr *.viseca.ch *.redsys.es *.monext.fr *.rpc-raiffeisen.com *.sparda.de *.citibank.com sicher-bezahlen.sparkasse.at 3ds-challenge.n26.com esecure.sia.eu *.uobgroup.com *.revolut.com *.fssnet.co.in *.e-i.com *.neuflizeobc.net *.cm-cic.com *.apata.io *.nexigroup.com *.cardcenter.ch *.gps.com.bh *.bkm.com.tr *.airplus.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.lamaisonduchocolat.com *.avis-verifies.com *.reetags.com *.prismic.io vimeo.com *.googletagmanager.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypalobjects.com bpcepaymentservices-3ds-vdm.wlp-acs.com *.modirum.com *.wlp-acs.com *.cic.fr *.cafis-paynet.jp *.creditmutuel.fr www.googletagmanager.com *.lcl.fr *.americanexpress.com *.dnp-cdms.jp *.sg.fr *.viseca.ch *.redsys.es *.monext.fr *.rpc-raiffeisen.com *.sparda.de *.citibank.com sicher-bezahlen.sparkasse.at *.arcot.com 3ds-challenge.n26.com esecure.sia.eu *.uobgroup.com *.revolut.com *.fssnet.co.in *.e-i.com *.neuflizeobc.net *.cm-cic.com *.apata.io *.nexigroup.com *.cardcenter.ch *.gps.com.bh *.bkm.com.tr *.monzo.com *.airplus.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com * *.googleapis.com *.lamaisonduchocolat.com https://bat.bing.com https://sdk.privacy-center.org https://cm.g.doubleclick.net https://www.facebook.com https://www.google.com https://www.google.fr *.linkedin.com https://rum-metrics.quanta.io *.reetags.com https://sync-t1.taboola.com https://ad.360yield.com https://ad.yieldlab.net https://contextual.media.net https://e1.emxdgt.com https://eb2.3lift.com https://exchange.mediavine.com https://ib.adnxs.com https://id5-sync.com https://jadserve.postrelease.com https://matching.ivitrack.com https://match.sharethrough.com https://pixel.rubiconproject.com https://r.casalemedia.com https://rtb-csync.smartadserver.com https://secure.adnxs.com https://simage2.pubmatic.com https://sync.1rx.io https://sync.outbrain.com https://visitor.omnitagjs.com https://x.bidswitch.net *.prismic.io https://images.unsplash.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com lamaisonduchocolat.com *.clarity.ms *.google.com *.bing.com *.google.co.jp *.google.com.hk *.doubleclick.net *.google.ro *.google.com.sg *.google.at *.a8.net *.google.com.tw www.americanexpress.com *.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com *.gstatic.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.lamaisonduchocolat.com https://bat.bing.com https://sdk.privacy-center.org https://googleads.g.doubleclick.net https://connect.facebook.net https://snap.licdn.com https://www.clarity.ms https://appstatic.quanta.io *.reetags.com https://*.taboola.com https://analytics.tiktok.com https://acdn.adnxs.com https://ad.avtm.fr https://analytics.optimalpeople.fr https://trk.adbutter.net prismic.io https://maps.googleapis.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.zdassets.com *.vimeo.com *.a8.net *.tradedoubler.com *.algolia.net *.algolianet.com *.prismic.io *.myfeelback.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.lamaisonduchocolat.com *.reetags.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com tagmanager.google.com *.myfeelback.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.lamaisonduchocolat.com *.prismic.io *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.lamaisonduchocolat.com *.privacy-center.org https://googleads.g.doubleclick.net https://www.facebook.com https://www.google.com *.linkedin.com *.reetags.com https://*.taboola.com https://analytics.tiktok.com https://analytics.optimalpeople.fr https://ib.adnxs.com https://maps.googleapis.com https://player.vimeo.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com yubinbango.github.io *.clarity.ms rum-metrics.quanta.io *.zdassets.com *.zendesk.com *.bing.com *.bing.net *.googlesyndication.com *.vimeo.com *.trackingplan.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src 'self' https://werbung.transgourmet.de https://www.youtube.com https://www.google.com www.recaptcha.net *.b2clogin.com *.loadbee.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com js-agent.newrelic.com www.youtube.com www.google-analytics.com bam.nr-data.net static.dvinci-easy.com maps.googleapis.com bat.bing.com www.gstatic.com connect.facebook.net widget.msgp.pl googleads.g.doubleclick.net blob: cdnjs.cloudflare.com https://cdn.kiprotect.com https://cdnjs.cloudflare.com unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' www.googletagmanager.com static.dvinci-easy.com unpkg.com js-agent.newrelic.com www.google-analytics.com maps.googleapis.com bam.nr-data.net connect.facebook.net bat.bing.com www.gstatic.com www.youtube.com widget.msgp.pl https://www.xing-events.com/resources/js/amiandoExport.js www.google.com content.syndigo.com www.recaptcha.net js.monitor.azure.com googleads.g.doubleclick.net job.transgourmet.de *.dvinci-easy.com *.clarity.ms *.loadbee.com cdnjs.cloudflare.com https://cdn.kiprotect.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' static.dvinci-easy.com fonts.googleapis.com cdnjs.cloudflare.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; base-uri 'self'; frame-ancestors 'self' https://werbung.transgourmet.de 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-ikIPF4i3ZDIi5naiy1INcQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.insightsc3m.com *.googleapis.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.omtrdc.net *.adobedtm.com *.certcapture.com *.azurewebsites.net *.insightsc3m.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com smetrics.onnicotine.com target.onnicotine.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com *.datadome.co *.azurewebsites.net *.insightsc3m.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.azurewebsites.net *.insightsc3m.com *.fontawesome.com *.googleapis.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.omtrdc.net *.adobedtm.com *.certcapture.com *.datadome.co *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com smetrics.onnicotine.com target.onnicotine.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fonts.net *.annefontaine.com mediacdn.espssl.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.annefontaine.com * *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hotjar.com *.vimeo.com vimeo.com secure.livechatinc.com *.pinterest.com *.criteo.com *.annefontaine.com *.weltpixel.com * *.sendcloud.sc *.jsdelivr.net *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.certcapture.com *.meetanshi.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.pinterest.com *.annefontaine.com *.listrakbi.com bat.bing.net *.zonos.com *.ubiconproject.com *.doubleclick.net *.gorgias.chat *.gorgias.io cdn.cookielaw.org cdn.files-text.com cdn.livechat-static.com id5-sync.com x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com gum.criteo.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com sync.1rx.io pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv sync.targeting.unrulymedia.com dis.criteo.com aa.agkn.com * *.bing.com *.bing.net *.bird.eu *.amazonaws.com guarantee-cdn.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.certcapture.com *.meetanshi.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com maps.gstatic.com *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com f.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://na-library.klarnaservices.com *.fonts.net *.listrakbi.com *.listrak.com g792337341.co *.hotjar.com *.facebook.com js-agent.newrelic.com bam.nr-data.net https://cdn.cookielaw.org *.appspot.com *.zonos.com vimeo.com *.bing.com https://bat.bing.com *.pinimg.com *.gorgias.chat *.criteo.com *.clarity.ms https://www.clarity.ms *.akamaized.net *.adscale.de *.casalemedia.com https://static.criteo.net https://dynamic.criteo.com https://sslwidget.criteo.com/ https://acsbapp.com *.annefontaine.com cdn.weglot.com cdn.livechatinc.com api.livechatinc.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page *.sendcloud.sc *.jsdelivr.net *.cloudflare.com guarantee-cdn.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.tiktok.com *.certcapture.com *.meetanshi.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com maps.googleapis.com ajax.googleapis.com *.instagram.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fonts.net *.listrakbi.com cdn.listrakbi.com *.annefontaine.com *.cash.app *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.certcapture.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.listrakbi.com *.pinterest.com bam.nr-data.net *.doubleclick.net stats.g.doubleclick.net *.zonos.com *.acsbapp.com acsbapp.com *.clarity.ms https://fonts.googleapis.com https://cdn.cookielaw.org *.criteo.com *.annefontaine.com cdn.weglot.com https://na-library.klarnaservices.com eu.klarnaevt.com *.gorgias.chat wss://us-east1-898b.gorgias.chat api.livechatinc.com cdn.livechatinc.com bat.bing.net *.onetrust.com * *.bing.com *.bing.net *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.facebook.com *.facebook.net *.googlesyndication.com *.tiktok.com *.certcapture.com *.meetanshi.com *.pinterdev.com commerce-app.pintergration.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.gorgias.chat *.annefontaine.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' 'nonce-YbmKh1fnQSiBxFWd6D83rw==' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' strict-dynamic www.google-analytics.com maps.googleapis.com maps.gstatic.com consent.cookiebot.eu consentcdn.cookiebot.eu bat.bing.com cdn.mouseflow.com genesys-chatbot-dev.wbs-web.de genesys-chatbot-stage.wbs-web.de chatbot.wbs-web.de connect.facebook.net tr.wbstraining.de wbstraining.omq.de *.youtube.com youtube.com *.azureedge.net *.convertexperiments.com t.webmetic.de www.redditstatic.com redditstatic.com rns.matelso.de snap.licdn.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com www.google-analytics.com *.analytics.google.com img.sct.eu1.usercentrics.eu userlike-cdn-operators.userlike.com maps.googleapis.com maps.gstatic.com tr.wbstraining.de wbstraining.omq.de googleads.g.doubleclick.net www.googleadservices.com px.ads.linkedin.com alb.reddit.com bat.bing.com t.webmetic.de connect.facebook.net facebook.com *.facebook.com linkedin.com *.linkedin.com fonts.gstatic.com px4.ads.linkedin.com translate.google.com googletagmanager.com *.googletagmanager.com *.google.com google.com *.google.de google.de *.google.nl google.nl *.google.at google.at stats.g.doubleclick.net; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com consent.cookiebot.eu consentcdn.cookiebot.eu www.etermin.net tr.wbstraining.de genesys-chatbot-stage.wbs-web.de genesys-chatbot-dev.wbs-web.de chatbot.wbs-web.de; style-src 'self' 'unsafe-inline' fonts.googleapis.com 'report-sample'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com wbstraining.omq.de *.googletagmanager.com googletagmanager.com *.gstatic.com gstatic.com 'report-sample'; script-src-elem 'self' 'unsafe-inline' strict-dynamic tr.wbstraining.de maps.googleapis.com maps.gstatic.com consent.cookiebot.eu consentcdn.cookiebot.eu userlike-cdn-umm.a-cdn.net userlike-cdn-umm.b-cdn.net wbstraining.omq.de bat.bing.com snap.licdn.com t.webmetic.de *.convertexperiments.com cdn.mouseflow.com connect.facebook.net rns.matelso.de www.redditstatic.com redditstatic.com genesys-chatbot-dev.wbs-web.de genesys-chatbot-stage.wbs-web.de chatbot.wbs-web.de googletagmanager.com *.googletagmanager.com youtube.com *.youtube.com *.gstatic.com gstatic.com *.azureedge.net 'report-sample'; connect-src 'self' sentry.wbs-web.de consent.cookiebot.eu consentcdn.cookiebot.eu api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com maps.googleapis.com maps.gstatic.com tr.wbstraining.de wbstraining.omq.de bat.bing.com px.ads.linkedin.com hub.webmetic.de t.webmetic.de *.rec.mouseflow.com pixel-config.reddit.com rns.matelso.de facebook.com *.facebook.com www.redditstatic.com wss://umd.userlike.com/umd/%2A *.convertexperiments.com conversions-config.reddit.com googletagmanager.com *.googletagmanager.com sentry.io translate.googleapis.com translate-pa.googleapis.com umd.userlike.com *.googleadservices.com googleadservices.com *.google.com google.com *.google.de google.de *.azureedge.net public-eur.mkt.dynamics.com googleads.g.doubleclick.net; font-src 'self' userlike-cdn-umm.a-cdn.net userlike-cdn-umm.b-cdn.net fonts.gstatic.com wbstraining.omq.de cdn.mouseflow.com chrome-extension r2cdn.perplexity.ai; report-uri https://www.wbstraining.de/csp-report-endpoint/ 1 frame-ancestors 'self' *.liantis.be; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com *.klarna.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net cdn.doofinder.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net https://www.magezon.com cdn-cookieyes.com www.facebook.com www.google.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.google.com/ s7.addthis.com cdn-cookieyes.com connect.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com *.klarnacdn.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.cookieyes.com cdn-cookieyes.com g.doubleclick.net server-side-tagging-47bwte2uaa-uc.a.run.app *.googlesyndication.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors *.hana.ondemand.com 'self'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src googleapis.com *.zdassets.com 'self' 'unsafe-inline'; font-src googleapis.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; style-src googleapis.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; connect-src static-forms.klaviyo.com googleapis.com facebook.com facebook.net klaviyo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; form-action googleapis.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-src googleapis.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za map.pargo.co.za 'self' 'unsafe-inline'; img-src googleapis.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src googleapis.com klaviyo.com facebook.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com www.gstatic.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net tawk.link data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.tawk.to cdn.jsdelivr.net *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.tawk.to wss://*.tawk.to *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' https://googleads.g.doubleclick.net/pagead/viewthroughconversion/823935011/ https://js.monitor.azure.com/scripts/b/ai.2.min.js https://player.vimeo.com/api/player.js https://www.clarity.ms https://www.googletagmanager.com/gtm.js; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js https://player.vimeo.com/api/player.js https://f.vimeocdn.com https://googleads.g.doubleclick.net https://snap.licdn.com https://www.clarity.ms https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/recaptcha/releases/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://eastus-0.in.applicationinsights.azure.com https://*.clarity.ms https://www.google-analytics.com https://www.google.com https://px.ads.linkedin.com https://www.googleadservice.com/pagead; font-src 'self'; frame-src 'self' https://td.doubleclick.net https://www.googletagmanager.com https://ai.appraisalinstitute.org/ https://embed.podcasts.apple.com/ https://player.vimeo.com/ https://www.google.com/ https://www.youtube.com/; img-src 'self' data: https://*.appraisalinstitute.org https://dummyimage.com https://placedog.net https://via.placeholder.com https://*.clarity.ms https://www.google.com https://www.googletagmanager.com https://appraisalinstitute-org-authoring-2023.azurewebsites.net https://px.ads.linkedin.com https://*.bing.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; frame-ancestors 'self' https://appraisal-org-local-2023.bluemod.me/ https://appraisal-cms-local-2023.bluemod.me/ https://appraisal-org-dev-2023.bluemod.us/ https://appraisal-cms-dev-2023.bluemod.us/ https://appraisal-org-test-2023.bluemod.us/ https://appraisal-cms-test-2023.bluemod.us/ https://appraisalinstitute-org-authoring-2023.azurewebsites.net/ https://appraisalinstitute-cms-authoring-2023.azurewebsites.net/ https://www.appraisalinstitute.org/ https://appraisalinstitute-cms-prod-2023.azurewebsites.net/; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: code.jquery.com *.google-analytics.com stats.g.doubleclick.net www.googletagmanager.com *.google.com www.google.cz unpkg.com api.mapy.cz api.mapy.com; block-all-mixed-content; report-uri https://www.mudrc.net/report.php?csp 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src self https://www.google.com https://www.gstatic.com; style-src 'self';frame-src self https://www.google.com https://www.gstatic.com;frame-ancestors 'self' 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com https://*.tidiochat.com https://*.tidio.co https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com https://www.google.com *.doubleclick.net *.facebook.com *.youtube-nocookie.com https://*.hulla-cdn.com live.hullabalook.com https://*.pinterest.com https://online-mi.flexiti.fi https://online.flexiti.fi https://plumrocket.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.s3.amazonaws.com cdnjs.cloudflare.com unpkg.com https://*.google.ca https://onlineapi-mi.flexiti.fi https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com https://*.hotjar.com https://*.omappapi.com https://*.privacy-center.org *.googleapis.com https://*.hulla-cdn.com https://*.hullabalook.com https://*.tidio.co https://*.tidiochat.com https://*.clarity.ms https://*.pinterest.com https://*.klaviyo.com https://*.pinimg.com https://hosted.paysafe.com https://www.gstatic.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com maxcdn.bootstrapcdn.com https://*.hullabalook.com https://*.hulla-cdn.com https://*.omappapi.com https://*.klaviyo.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://*.tidiochat.com https://*.tidio.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ vimeo.com maps.googleapis.com https://*.privacy-center.org wss://*.hotjar.com/ https://*.hotjar.com https://*.hotjar.io https://*.omappapi.com wss://*.tidio.co/ https://*.tidio.co https://*.hulla-cdn.com https://*.hullabalook.com https://*.pinterest.com/ https://*.googlesyndication.com https://*.g.doubleclick.net/ https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://*.privacy-center.org https://*.hullabalook.com https://*.hulla-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' plausible.io *.bing.com *.boomtrain.com *.callrail.com *.cdn.digitaloceanspaces.com *.cloudflare.com *.cloudflareinsights.com *.cookielaw.org *.crazyegg.com *.derbysoftsec.com *.doubleclick.net *.facebook.net *.gstatic.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.quantcount.com *.quantserve.com *.rezync.com *.rfihub.net *.sojern.com *.stackadapt.com *.stripe.com *.tiqcdn.com *.azds.com *.qvdt3feo.com *.pendry.com; script-src-elem 'self' 'unsafe-inline' plausible.io *.bing.com *.boomtrain.com *.callrail.com *.cdn.digitaloceanspaces.com *.cloudflare.com *.cloudflareinsights.com *.cookielaw.org *.crazyegg.com *.derbysoftsec.com *.doubleclick.net *.facebook.net *.gstatic.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.quantcount.com *.quantserve.com *.rezync.com *.rfihub.net *.sojern.com *.stackadapt.com *.stripe.com *.storage.googleapis.com *.tiqcdn.com *.azds.com *.acumbamail.com *.threatspike.com *.acumbamail.com *.tms-plugins.com *.sc-static.net *.googlesyndication.com *.infird.com *.pendry.com blob:; connect-src 'self' *.azds.com *.boomtrain.com *.callrail.com *.cookielaw.org *.crazyegg.com *.doubleclick.net *.facebook.com *.g.doubleclick.net *.google-analytics.com google.com *.google.com *.googleadservices.com *.googletagmanager.com *.googleapis.com *.google.com.mx *.google.pl *.google.ca *.onetrust.com *.sojern.com *.stackadapt.com *.tiqcdn.com *.myhotelshop.de *.awsapprunner.com *.run.app *.letsway.com *.bing.com *.bing.net *.googlesyndication.com *.quantcount.com *.quantserve.com plausible.io *.emlsend.com *.yoast.com *.cloudfront.net *.launchdarkly.com *.overbridgenet.com *.geoedge.com *.dreamsadnetwork.com *.pendry.com; frame-src 'self' *.doubleclick.net *.facebook.com *.googletagmanager.com *.google.com *.pcibooking.net *.rfihub.net *.rfihub.com *.sojern.com *.stripe.com *.azds.com *.techloq.com *.ibosscloud.com *.wikimedia.org *.zscalerthree.net *.zscaler.net visitingmedia.com *.vimeo.com *.formcrafts.com *.menlosecurity.com *.dadco.com *..dpisd.org *.linewize.net *.pendry.com blob:; img-src * data: blob:; font-src * data:; media-src * 'self' data:; manifest-src * 'self'; style-src * 'unsafe-inline' data:; worker-src 'self' blob:; report-uri https://cfe87652b26de6b69f71ed43bef9cf37.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self' blob: data: https://*.dzengi.com https://dzengi.com https://ekr.zdassets.com https://currencysupport1713960465.zendesk.com https://id.zopim.com https://img.youtube.com https://i.ytimg.com https://syndication.twitter.com https://connect.facebook.net https://www.facebook.com https://dzengi.bamboohr.com https://www.google.com https://www.gstatic.com https://fonts.gstatic.com https://*.analytics.google.com https://*.google-analytics.com https://analytics.google.com https://accounts.google.com https://apis.google.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://translate-pa.googleapis.com https://translate.google.com https://translate.googleapis.com https://translate.googleapis.com https://www.google.ae https://www.google.am https://www.google.az https://www.google.bg https://www.google.by https://www.google.ca https://www.google.cz https://www.google.de https://www.google.dk https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fr https://www.google.ge https://www.google.ie https://www.google.it https://www.google.kg https://www.google.kz https://www.google.lt https://www.google.lv https://www.google.md https://www.google.nl https://www.google.no https://www.google.pl https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.sk https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.th https://www.google.co.uk https://www.google.co.uz https://www.google.co.za https://www.google.com.ar https://www.google.com.cy https://www.google.com.ng https://www.google.com.np https://www.google.com.tr https://www.google.com.ua https://test-website-files.idzengi.xyz https://test-website-static.idzengi.xyz https://*.backend-capital.com wss://*.backend-capital.com wss://*.dzengi.com wss://widget-mediator.zopim.com https://mc.yandex.az https://mc.yandex.by https://mc.yandex.com https://mc.yandex.com.am https://mc.yandex.com.ge https://mc.yandex.kz https://mc.yandex.lt https://mc.yandex.lv https://mc.yandex.md https://mc.yandex.ru https://mc.yandex.tj https://mc.yandex.tm https://mc.yandex.uz https://yandex.ru https://yastatic.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://test-website-static.idzengi.xyz https://prod-static.dzengi.com https://www.googletagmanager.com https://www.gstatic.com https://www.google.com https://accounts.google.com https://apis.google.com https://*.google-analytics.com https://*.analytics.google.com https://connect.facebook.net https://appleid.cdn-apple.com https://platform.twitter.com https://static.zdassets.com https://translate-pa.googleapis.com https://translate.google.com https://translate.googleapis.com https://mc.yandex.ru https://mc.yandex.by https://mc.yandex.lt https://mc.yandex.lv https://mc.yandex.tj https://mc.yandex.tm https://mc.yandex.uz https://mc.yandex.com.am https://mc.yandex.az https://mc.yandex.md https://yandex.ru https://yastatic.net https://mc.yandex.kz https://mc.yandex.com https://mc.yandex.com.ge; style-src 'self' 'unsafe-inline' https://test-website-static.idzengi.xyz https://prod-static.dzengi.com https://www.googletagmanager.com https://www.gstatic.com https://accounts.google.com https://fonts.googleapis.com; media-src 'self' data: blob: https://static.zdassets.com; font-src 'self' data: https://test-website-static.idzengi.xyz https://prod-static.dzengi.com https://fonts.gstatic.com; frame-src 'self' https://www.youtube.com https://www.google.com https://www.googletagmanager.com https://accounts.google.com https://support.google.com https://td.doubleclick.net https://platform.twitter.com https://mc.yandex.ru https://mc.yandex.by https://mc.yandex.lt https://mc.yandex.lv https://mc.yandex.tj https://mc.yandex.tm https://mc.yandex.uz https://mc.yandex.com.am https://mc.yandex.az https://mc.yandex.md https://yandex.ru https://yastatic.net https://mc.yandex.kz https://mc.yandex.com https://mc.yandex.com.ge; report-uri https://test-api.dzengi.com/csp 1 default-src 'none';script-src 'nonce-4ab5d0db-58f1-4fd4-846c-439d37d9bf23' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.dk https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.dk/eum-collector/report/csp-report; 1 font-src 'self' 'unsafe-inline' https://fonts.gstatic.com https://d1fxy698ilbz6u.cloudfront.net https://d3e26335nux8ic.cloudfront.net; media-src 'self' https://landia-audio-assets.s3.us-west-2.amazonaws.com; frame-src 'self' https://td.doubleclick.net https://www.googletagmanager.com https://js.stripe.com/; default-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.googletagmanager.com https://d1fxy698ilbz6u.cloudfront.net https://d3e26335nux8ic.cloudfront.net https://uptime.betterstack.com; connect-src 'self' https://google.com https://www.google.com https://storage.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://region1.analytics.google.com https://pagead2.googlesyndication.com https://analytics.google.com https://stats.g.doubleclick.net https://d1fxy698ilbz6u.cloudfront.net https://d3e26335nux8ic.cloudfront.net https://region1.google-analytics.com https://region2.google-analytics.com https://region3.google-analytics.com https://www.facebook.com https://api.amplitude.com https://www.myreviews.ai https://uptime.betterstack.com https://landia-audio-assets.s3.us-west-2.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.amplitude.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://widget.trustpilot.com https://d1fxy698ilbz6u.cloudfront.net https://d3e26335nux8ic.cloudfront.net https://uptime.betterstack.com https://js.stripe.com; img-src 'self' data: https://landia-logos.s3.amazonaws.com https://landia-misc.s3-us-west-2.amazonaws.com https://www.google-analytics.com https://www.facebook.com https://www.google.com https://www.google.cz https://d1fxy698ilbz6u.cloudfront.net https://d3e26335nux8ic.cloudfront.net https://cdn.jsdelivr.net https://googleads.g.doubleclick.net 1 img-src https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/ACCA/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogiclongterm.s3.amazonaws.com/ACCA/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ 'self' https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://higherlogicstream.s3.amazonaws.com/ACCA/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://10176109.fls.doubleclick.net/ https://www.googletagmanager.com/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src 'self' *.gs.com; script-src 'unsafe-inline' 'unsafe-eval' *.gs.com:* https://assets.adobedtm.com https://gsgir.122.2o7.net https://*.tt.omtrdc.net https://view.ceros.com ir-vh.akamaihd.net https://amp.akamaized.net https://cdn.appdynamics.com; connect-src 'self' wss://*.gs.com:* *.gs.com:* https://assets.adobedtm.com https://gsgir.122.2o7.net https://*.tt.omtrdc.net https://view.ceros.com ir-vh.akamaihd.net https://amp.akamaized.net https://col.eum-appdynamics.com https://girprod.akamaized.net https://irqa.akamaized.net https://video.goldmansachs.com *.datadoghq.com; img-src *.gs.com:* https://gsgir.122.2o7.net data: blob: https://col.eum-appdynamics.com; style-src 'unsafe-inline' *.gs.com:* https://fast.fonts.net; media-src 'self' *.gs.com ir-vh.akamaihd.net blob: https://girprod.akamaized.net https://irqa.akamaized.net https://video.goldmansachs.com; frame-ancestors 'self' https://goldmansachs.experiencecloud.adobe.com:*; worker-src blob: *.gs.com:* *.gs.com:*; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.nic.audi/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com https://pos.snapscan.io https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk secure.nmi.com secure.networkmerchants.com collectcheckout.com merchantx.transactiongateway.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://plumrocket.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk secure.nmi.com secure.networkmerchants.com collectcheckout.com merchantx.transactiongateway.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.googletagmanager.com https://pos.snapscan.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.bablic.com https://s3-us-west-2.amazonaws.com/jsstore/a/* *.fraudlabspro.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.googletagmanager.com secure.nmi.com secure.networkmerchants.com collectcheckout.com merchantx.transactiongateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com https://static.klaviyo.com https://fonts.bunny.net *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.typekit.net secure.nmi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.snplow.net commerce.adobedc.net commerce.adobe.io https://c.bablic.com https://e2.bablic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk ws: secure.nmi.com secure.networkmerchants.com collectcheckout.com merchantx.transactiongateway.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data:; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://images.ctfassets.net; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com; frame-ancestors 'self' 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com data: *.googleapis.com https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io *.oct8ne.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.weltpixel.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.hotjar.com *.pinterest.com *.pinterest.es *.criteo.com *.cookiebot.com *.doubleclick.net *.googletagmanager.com *.oct8ne.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de cdn.doofinder.com https://maps.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.facebook.com *.pinterest.com *.google.es *.clarity.ms *.quantserve.com *.lladro.com *.yahoo.com *.3lift.com *.360yield.com *.pubmatic.com *.outbrain.com *.rubiconproject.com *.adnxs.com *.casalemedia.com *.tapad.com *.smartadserver.com *.taboola.com *.addthis.com *.dable.com *.criteo.com *.media.net *.bidswitch.net *.revcontent.com *.teads.tv *.sharethrough.com *.liadm.com *.dable.io *.yieldmo.com *.advertising.com *.clmbtech.com *.smaato.net *.dmxleo.com *.cookiebot.com visitor.omnitagis.com id5-sync.com matching.ivitrack.com exchange.mediavine.com jadserve.postrelease.com criteo-partners.tremorhub.com ad.yieldlab.net *.emxdgt.com sync.1rx.io sync.targeting.unrulymedia.com *.line.me www.googletagmanager.com visitor.omnitagjs.com *.oct8ne.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.gstatic.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr *.cloudflare.com *.cloudfront.net *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com *.googletagmanager.com *.facebook.net *.pinimg.com *.hotjar.com *.tiktok.com *.quantserve.com *.doubleclick.net *.quantcount.com *.doofinder.com *.oct8ne.com *.clarity.ms *.criteo.com *.criteo.net *.cookiebot.com www.mczbf.com *.line-scdn.net *.pinterest.com cdn.jsdelivr.net *.useberry.com js.mollie.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr https://fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com www.google.com payments-eu.amazon.com *.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.doofinder.com wss://*.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr *.analytics.google.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com *.doubleclick.net *.luckyorange.net *.pinterest.com *.tiktok.com *.clarity.ms *.oct8ne.com *.criteo.com www.mczbf.com *.cookiebot.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://seoulwebdev.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com https://mcstaging.booktrump.com https://mcstaging.trumphotels.com https://integration-5ojmyuq-r7ma66w2vxzgu.us-5.magentosite.cloud https://integration2-hohc4oi-r7ma66w2vxzgu.us-5.magentosite.cloud 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://mcstagingdoral.booktrump.com https://mcstagingireland.booktrump.com https://mcstaging.booktrump.com https://mcstaging.trumphotels.com https://integration-5ojmyuq-r7ma66w2vxzgu.us-5.magentosite.cloud https://integration2-hohc4oi-r7ma66w2vxzgu.us-5.magentosite.cloud 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://bat.bing.com https://*.bing.com https://*.synxis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.facebook.net www.termsfeed.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com *.sharethis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://backend.alia-cloudflare.com https://capture.celopay.com https://api.cartstack.com https://*.cartstack.com https://script.hotjar.com https://www.thehotelsnetwork.com https://*.thehotelsnetwork.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com https://use.typekit.net https://p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://player.vimeo.com https://download-video.akamaized.net 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com https://get.geojs.io *.avada.io *.sharethis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://capture.celopay.com https://api.cartstack.com https://*.cartstack.com https://bat.bing.com https://*.bing.com https://www.thehotelsnetwork.com https://*.thehotelsnetwork.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' 'self' blob: data: https:; style-src 'self' 'unsafe-inline' blob: data: https:; default-src 'self' https:; img-src https: blob: data: android-webview-video-poster:; frame-src blob: data: https:; worker-src blob: data: https:; child-src blob: data: https:; object-src 'self'; font-src 'self' https: blob: data: safari-extension://*; media-src 'self' blob: data: https:; connect-src wss: blob: data: https:; report-uri /csp_ep 1 font-src fonts.googleapis.com fonts.gstatic.com data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com vars.hotjar.com consentcdn.cookiebot.com js.mollie.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com www.google.it www.google.de px.ads.linkedin.com *.omappapi.com *.gstatic.com *.cookiebot.com https://www.mollie.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com unpkg.com *.doofinder.com *.hotjar.com consent.cookiebot.com *.omappapi.com static.zdassets.com snap.licdn.com consentcdn.cookiebot.com js-agent.newrelic.com bam.nr-data.net *.clarity.ms *.adiacent.space *.activehosted.com js.mollie.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com unpkg.com *.omappapi.com *.doofinder.com *.multisafepay.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com *.doofinder.com www.google.com googleads.g.doubleclick.net *.google-analytics.com ekr.zdassets.com *.omappapi.com erreahelp.zendesk.com wss://widget-mediator.zopim.com consentcdn.cookiebot.com bam.nr-data.net *.googlesyndication.com *.clarity.ms *.linkedin.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: blob: https://www.google.co.uk https://www.google.ro https://www.google.jo https://www.googletagmanager.com https://www.google.co.ke https://www.google.gr https://i.ytimg.com https://www.google.com.my https://www.google.hu https://www.google.ie https://stats.g.doubleclick.net https://www.google.de https://www.google.co.th https://www.google.es https://www.google.ca https://www.google.co.kr https://www.google.com.ph https://www.google.fr https://www.dailymaverick.co.za https://www.google.com.ec https://www.google.se https://www.google.com.mm https://www.google.com.hk https://www.google.com.au https://www.google.co.in https://www.google.no https://www.google.co.jp https://www.google.com.sa https://www.google.rs https://www.google.ru https://www.google.co.nz https://www.google.com.eg https://www.google.co.za https://www.google.hn https://www.google.com.tr https://www.google.com.br https://www.google.com.mx https://www.google.mu https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://tag.getdrip.com https://api.getdrip.com https://a.omappapi.com https://sleeknotestaticcontent.sleeknote.com https://d14jnfavjicsbe.cloudfront.net https://sleeknotecustomerscripts.sleeknote.com https://www.scribd.com https://connect.facebook.net https://3001.scriptcdn.net https://www.google-analytics.com https://platform.twitter.com https://js.stripe.com https://cdn.jsdelivr.net https://proxy.beyondwords.io 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://tag.getdrip.com https://api.getdrip.com https://a.omappapi.com https://sleeknotestaticcontent.sleeknote.com https://d14jnfavjicsbe.cloudfront.net https://www.google-analytics.com https://sleeknotecustomerscripts.sleeknote.com https://www.scribd.com https://connect.facebook.net https://3001.scriptcdn.net https://platform.twitter.com https://js.stripe.com https://cdn.jsdelivr.net https://proxy.beyondwords.io ; style-src 'self' 'unsafe-inline' https://a.omappapi.com data: https://fonts.googleapis.com https://ajax.googleapis.com ; style-src-elem 'self' 'unsafe-inline' https://a.omappapi.com data: https://fonts.googleapis.com https://ajax.googleapis.com ; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://td.doubleclick.net https://www.scribd.com https://www.google.com https://datawrapper.dwcdn.net https://onsite-subscribe.getdrip.com https://www.youtube.com https://js.stripe.com https://www.paypal.com https://secure.declassifieduk.org blob:; connect-src 'self' https://analytics.google.com https://sleeknotestaticcontent.sleeknote.com https://fonts.googleapis.com https://stats.g.doubleclick.net https://api.omappapi.com https://region1.analytics.google.com https://region1.google-analytics.com https://www.google-analytics.com https://z.omappapi.com https://www.google.co.uk https://a.omappapi.com https://www.google.co.ke https://www.google.ca https://www.google.com.au https://api.beyondwords.io blob: https://metrics.beyondwords.io; media-src 'self' blob:; worker-src 'self' blob:; report-uri https://www.declassifieduk.org/wp-json/rsssl/v1/csp?rsssl_apitoken=676120949; 1 font-src *.gstatic.com data: *.cloudfront.net *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com fonts.googleapis.com js.klarna.com *.fontawesome.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com googleads.g.doubleclick.net ct.pinterest.com *.bing.com *.hotjar.com *.hotjar.io *.doubleclick.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com google.com js.klarna.com ggmmoebel.com www.ggmmoebel.com *.facebook.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com googleads.g.doubleclick.net ct.pinterest.com *.bing.com *.hotjar.com *.hotjar.io *.doubleclick.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com www.google.com media.ggmmoebel.com cdn.ggmmoebel.com mediacdn.ggmmoebel.com *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com google.com js.klarna.com *.googletagmanager.com backend.ggmmoebel.com ggmmoebel.com www.ggmmoebel.com *.cloudflarestream.com *.mondu.ai/ *.mondu.local localhost:*/ *.facebook.com *.pinterest.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com googleads.g.doubleclick.net ct.pinterest.com *.bing.com *.hotjar.com *.hotjar.io *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com *.gstatic.com *.googleapis.com media.ggmmoebel.com cdn.ggmmoebel.com mediacdn.ggmmoebel.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com google.com js.klarna.com *.googletagmanager.com backend.ggmmoebel.com ggmmoebel.com www.ggmmoebel.com website.ggm-m.com *.cdninstagram.com *.content.instagram.com *.google.ba *.bing.com *.smarketer.de *.pinimg.com *.facebook.com *.pinterest.com *.facebook.net *.google.de *.hotjar.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com ct.pinterest.com *.clarity.ms *.hotjar.io *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.adyen.com polyfill.io *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ media.ggmmoebel.com cdn.ggmmoebel.com mediacdn.ggmmoebel.com *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com google.com js.klarna.com widget.freshworks.com m2epro.freshdesk.com *.googletagmanager.com backend.ggmmoebel.com ggmmoebel.com www.ggmmoebel.com analytics.tiktok.com analytics-ipv6.tiktokw.us cdn.dashjs.org *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js cdn.jsdelivr.net *.avada.io www.youtube.com *.bing.com *.smarketer.de *.pinimg.com *.facebook.com *.facebook.net *.hotjar.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com *.cookiefirst.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com ct.pinterest.com *.clarity.ms *.hotjar.io *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com fonts.googleapis.com js.klarna.com widget.freshworks.com m2epro.freshdesk.com *.googletagmanager.com backend.ggmmoebel.com ggmmoebel.com www.ggmmoebel.com cdn.jsdelivr.net *.fontawesome.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com *.cookiefirst.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com googleads.g.doubleclick.net ct.pinterest.com *.bing.com *.hotjar.com *.hotjar.io *.doubleclick.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com *.content.instagram.com *.cloudflarestream.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.cloudfront.net *.reviews.io *.reviews.co.uk *.paypalobjects.com *.klarnaservices.com *.klarnacdn.net *.google.com google.com js.klarna.com widget.freshworks.com m2epro.freshdesk.com ggmmoebel.com www.ggmmoebel.com analytics.tiktok.com analytics-ipv6.tiktokw.us insights.algolia.io https://get.geojs.io *.avada.io stats.g.doubleclick.net *.google-analytics.com *.pinterest.com *.smarketer.de *.facebook.com *.hotjar.com *.googlesyndication.com service.force.com *.salesforceliveagent.com *.my.salesforce-sites.com *.cookiefirst.com api.paypal.com static.cloudflareinsights.com a.omappapi.com api.omappapi.com googleads.g.doubleclick.net ct.pinterest.com *.clarity.ms *.bing.com *.hotjar.io *.doubleclick.net 'self' 'unsafe-inline'; child-src media.ggmmoebel.com cdn.ggmmoebel.com mediacdn.ggmmoebel.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.thulium.com 'self' *.ekomiapps.de *.payu.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com https://plumrocket.com 'self' 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com secure.payu.com merch-prod.snd.payu.com https://plumrocket.com *.ceneo.pl *.paypo.pl *.payu.com *.onet.pl *.googletagmanager.com youtube.com *.askspot.io paypo.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.hsforms.net *.hsforms.com static.payu.com *.google.pl *.skalnik.pl 'self' *.openstreetmap.org *.pagesense.io *.ekomiapps.de *.google.de *.amazonaws.com *.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com secure.payu.com secure.snd.payu.com *.quartic.pl *.skalnik.pl *.ceneo.pl *.uptimiarium.eu *.luigisbox.com *.getresponse.com *.savecart.pl recostream.com *.thulium.com *.gr-wcon.com *.gr-cdn.com 'self' 'unsafe-eval' *.uptimiarum.eu 'nonce-test' 'unsafe-inline' *.tiktok.com *.clickonometrics.pl *.hotjar.com *.onet.pl *.gr-cdn-e.eu *.cloudflareinsights.com *.pagesense.io *.clarity.ms *.ekomiapps.de *.ekomi.com *.bing.com *.payu.com *.askspot.io *.tmtarget.com https://static.payu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com *.thulium.com *.luigisbox.com 'self' 'unsafe-inline' *.ekomiapps.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.thulium.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com t.elasticsuite.io *.hsforms.net *.hsforms.com secure.payu.com merch-prod.snd.payu.com *.luigisbox.com *.recostream.com *.savecart.pl *.getresponse.com *.thulium.com *.uptimiarium.eu 'self' *.uptimiarum.eu *.payu.com *.openstreetmap.org *.ocdn.eu *.onet.pl wss: ws.hojtar.com *.hotjar.io *.tiktok.com *.eu01.nr-data.net *.clickonometrics.pl *.skalnik.pl *.clarity.ms *.ekomiapps.de *.ekomi.com *.bing.net *.tiktokw.us bat.bing.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; default-src 'none'; child-src; connect-src 'self' https://myaccount.sure.com http://myaccount.sure.com myaccount.sure.com https://myaccounttest.sure.com:2087 http://myaccounttest.sure.com:2087 myaccounttest.sure.com:2087 https://rec.smartlook.com http://rec.smartlook.com rec.smartlook.com https://ekr.zdassets.com http://ekr.zdassets.com ekr.zdassets.com https://*.zopim.com http://*.zopim.com *.zopim.com wss://widget-mediator.zopim.com https://*.searchiq.co http://*.searchiq.co *.searchiq.co https://*.cookiepro.com http://*.cookiepro.com *.cookiepro.com https://*.google.com http://*.google.com *.google.com https://*.podscribe.com http://*.podscribe.com *.podscribe.com https://www.google-analytics.com http://www.google-analytics.com www.google-analytics.com https://pixel-config.reddit.com http://pixel-config.reddit.com pixel-config.reddit.com https://www.redditstatic.com http://www.redditstatic.com www.redditstatic.com https://www.facebook.com http://www.facebook.com www.facebook.com https://sessions.bugsnag.com http://sessions.bugsnag.com sessions.bugsnag.com wss://ws-mt1.pusher.com https://*.postcodeanywhere.co.uk http://*.postcodeanywhere.co.uk *.postcodeanywhere.co.uk https://*.zendesk.com http://*.zendesk.com *.zendesk.com https://*.googlesyndication.com http://*.googlesyndication.com *.googlesyndication.com; font-src 'self' https://fonts.gstatic.com http://fonts.gstatic.com fonts.gstatic.com https://use.typekit.net http://use.typekit.net use.typekit.net https://*.zopim.com http://*.zopim.com *.zopim.com https://*.searchiq.co http://*.searchiq.co *.searchiq.co https://*.youtube.com http://*.youtube.com *.youtube.com data:; form-action 'self' https://*.twitter.com http://*.twitter.com *.twitter.com https://*.facebook.com http://*.facebook.com *.facebook.com; frame-ancestors 'none'; frame-src https://youtube.com http://youtube.com youtube.com https://*.twitter.com http://*.twitter.com *.twitter.com https://*.doubleclick.net http://*.doubleclick.net *.doubleclick.net https://*.bugherd.com http://*.bugherd.com *.bugherd.com https://www.googletagmanager.com http://www.googletagmanager.com www.googletagmanager.com https://www.facebook.com http://www.facebook.com www.facebook.com; img-src 'self' https://www.google-analytics.com http://www.google-analytics.com www.google-analytics.com https://www.google.com http://www.google.com www.google.com https://www.google.co.uk http://www.google.co.uk www.google.co.uk https://t.co http://t.co t.co https://www.facebook.com http://www.facebook.com www.facebook.com https://v2.zopim.com http://v2.zopim.com v2.zopim.com https://*.doubleclick.net http://*.doubleclick.net *.doubleclick.net https://*.twitter.com http://*.twitter.com *.twitter.com https://*.twimg.com http://*.twimg.com *.twimg.com https://*.searchiq.co http://*.searchiq.co *.searchiq.co https://alb.reddit.com http://alb.reddit.com alb.reddit.com https://bat.bing.com http://bat.bing.com bat.bing.com https://*.cookiepro.com http://*.cookiepro.com *.cookiepro.com https://verifi.podscribe.com http://verifi.podscribe.com verifi.podscribe.com https://d2iiunr5ws5ch1.cloudfront.net http://d2iiunr5ws5ch1.cloudfront.net d2iiunr5ws5ch1.cloudfront.net https://*.postcodeanywhere.co.uk http://*.postcodeanywhere.co.uk *.postcodeanywhere.co.uk https://placehold.co http://placehold.co placehold.co https://*.googlesyndication.com http://*.googlesyndication.com *.googlesyndication.com blob: data:; media-src https://youtube.com http://youtube.com youtube.com https://static.zdassets.com http://static.zdassets.com static.zdassets.com; object-src 'none'; manifest-src 'self'; script-src 'self' https://myaccount.sure.com http://myaccount.sure.com myaccount.sure.com https://myaccounttest.sure.com:2087 http://myaccounttest.sure.com:2087 myaccounttest.sure.com:2087 https://www.googletagmanager.com http://www.googletagmanager.com www.googletagmanager.com https://www.google-analytics.com http://www.google-analytics.com www.google-analytics.com https://www.googleadservices.com http://www.googleadservices.com www.googleadservices.com https://*.googleapis.com http://*.googleapis.com *.googleapis.com https://*.doubleclick.net http://*.doubleclick.net *.doubleclick.net https://v2.zopim.com http://v2.zopim.com v2.zopim.com https://static.zdassets.com http://static.zdassets.com static.zdassets.com https://*.twitter.com http://*.twitter.com *.twitter.com https://static.ads-twitter.com http://static.ads-twitter.com static.ads-twitter.com https://*.facebook.net http://*.facebook.net *.facebook.net https://rec.smartlook.com http://rec.smartlook.com rec.smartlook.com https://*.twimg.com http://*.twimg.com *.twimg.com https://*.searchiq.co http://*.searchiq.co *.searchiq.co https://cdn.co-buying.com http://cdn.co-buying.com cdn.co-buying.com https://*.bugherd.com http://*.bugherd.com *.bugherd.com https://*.postcodeanywhere.co.uk http://*.postcodeanywhere.co.uk *.postcodeanywhere.co.uk https://*.pcapredict.com http://*.pcapredict.com *.pcapredict.com https://*.cookiepro.com http://*.cookiepro.com *.cookiepro.com https://*.cloudfront.net http://*.cloudfront.net *.cloudfront.net https://*.bing.com http://*.bing.com *.bing.com https://*.redditstatic.com http://*.redditstatic.com *.redditstatic.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.typekit.net http://*.typekit.net *.typekit.net https://*.googleapis.com http://*.googleapis.com *.googleapis.com https://*.twitter.com http://*.twitter.com *.twitter.com https://*.twimg.com http://*.twimg.com *.twimg.com https://*.searchiq.co http://*.searchiq.co *.searchiq.co https://*.postcodeanywhere.co.uk http://*.postcodeanywhere.co.uk *.postcodeanywhere.co.uk 'unsafe-inline' 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net https://widgets.trustedshops.com integrations.etrusted.com *.cloudflare.com *.twitter.com *.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' data: *.yotpo.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://seo.mageplaza.com www.facebook.com *.copernica.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com https://www.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://*.dpdconnect.nl *.dpdconnect.nl service2.loyaltyinabox.com *.pinterest.com www.facebook.com www.youtube.com view.publitas.com www.google.com www.google.nl www.google.de *.google.com maps.google.com chat.babypark.nl *.doubleclick.net td.doubleclick.net googleads.g.doubleclick.net widget.trustpilot.com *.cookiebot.com *.cookiebot.eu chatwidget-prod.web.app www.googletagmanager.com sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl folders.baby-dump.nl *.twitter.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.klevu.com *.ksearchnet.com www.babypark.nl www.babypark.de www.babydeals.be dehoevebuitenleven.nl m2.babypark.mavendev.com m2.babypark-de.mavendev.com www.ikenik.nl m2.ikenik.mavendev.com m2.babydump.mavendev.com m2.babydump-de.mavendev.com www.google.com www.google.nl www.google.de www.google.com.ua www.facebook.com ct.pinterest.com www.googletagmanager.com www.zenaps.com www.awin1.com static.zdassets.com *.bing.com *.bing.net www.thuiswinkel.org i.ytimg.com img.youtube.com blob: lantern.roeye.com *.clarity.ms *.cookiebot.com *.cookiebot.eu integrations.etrusted.com stats.g.doubleclick.net sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://*.dpdconnect.nl js.klevu.com *.ksearchnet.com *.avada.io www.googletagmanager.com checkout.buckaroo.nl *.clarity.ms lantern.roeyecdn.com widgets.trustedshops.com web-sdk.smartlook.com www.dwin1.com s.pinimg.com connect.facebook.net static.buckaroo.nl view.publitas.com api.360productviewer.com googleads.g.doubleclick.net bat.bing.com bat.bing.net static.zdassets.com js-agent.newrelic.com *.livechatinc.com bam.eu01.nr-data.net chat.babypark.nl widget.trustpilot.com *.pinterest.com *.hotjar.com *.hotjar.io *.cookiebot.com *.cookiebot.eu integrations.etrusted.com chatwidget-prod.web.app *.cloudflare.com *.google.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com https://widgets.trustedshops.com *.yotpo.com sst.babypark.nl https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net checkout.buckaroo.nl integrations.etrusted.com chatwidget-css.web.app *.cloudflare.com *.googleapis.com *.google.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu maxcdn.bootstrapcdn.com unsafe-inline https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com integrations.etrusted.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io *.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.clarity.ms *.pinterest.com *.doubleclick.net stats.g.doubleclick.net googleads.g.doubleclick.net manager.eu.smartlook.cloud ekr.zdassets.com wss://widget-mediator.zopim.com api.360productviewer.com www.facebook.com livechat.fabulor.eu bam.eu01.nr-data.net region1.analytics.google.com *.google.com *.hotjar.com *.hotjar.io analytics.google.com bat.bing.com bat.bing.net *.cookiebot.com *.cookiebot.eu *.copernica.com integrations.etrusted.com api.ipify.org *.cloudflare.com *.twitter.com *.twimg.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.yotpo.com sst.babypark.nl https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ apply.ciis.edu https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ apply.ciis.edu https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' 'unsafe-inline' https://use.typekit.net/ https://p.typekit.net/ https://www.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.typekit.net; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.splitit.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.instagram.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.splitit.com *.trustpilot.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.typekit.net *.commoninja.com *.coreprint.net *.livechatinc.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.cdninstagram.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.splitit.com *.amazonaws.com *.facebook.com *.reddit.com *.cloudfront.net *.authorize.net *.cardinalcommerce.com *.adobedtm.com *.livechatinc.com *.onetrust.com *.pcapredict.com cdn-ukwest.onetrust.com cdn.livechatinc.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.instagram.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://api.goaffpro.com https://static.goaffpro.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.splitit.com *.trustpilot.com *.cloudflare.com *.facebook.net https://www.googletagmanager.com tagmanager.google.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.commoninja.com *.authorize.net *.cardinalcommerce.com *.adobedtm.com *.livechatinc.com *.onetrust.com *.pcapredict.com cdn-ukwest.onetrust.com cdn.livechatinc.com p.typekit.net *.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.splitit.com *.trustpilot.com *.facebook.net tagmanager.google.com *.typekit.net *.cardinalcommerce.com *.adobedtm.com *.livechatinc.com *.onetrust.com *.pcapredict.com p.typekit.net cdn-ukwest.onetrust.com cdn.livechatinc.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://api.goaffpro.com https://static.goaffpro.com *.ideal-postcodes.co.uk *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.splitit.com *.amazonaws.com logs.browser-intake-datadoghq.com *.facebook.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.typekit.net *.commoninja.com *.authorize.net *.adobe.com *.adobedtm.com *.livechatinc.com *.onetrust.com *.pcapredict.com cdn-ukwest.onetrust.com cdn.livechatinc.com p.typekit.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://online.flippingbook.com/; report-to report-endpoint; 1 default-src https: wss:; script-src https: wss: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 default-src 'self'; base-uri 'self'; child-src 'self' *.youtube-nocookie.com *.twitter.com *.gstatic.com *.googleapis.com *.googletagmanager.com 3f5l8ze0o4j2m.cloudfront.net *.youtube.com *.youtube-no-cookie.com *.ytimg.com *.google.com www.google.com https://player.vimeo.com https://www.facebook.com https://staticxx.facebook.com; connect-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com *.google-analytics.com https://www.facebook.com/tr http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com https://heatmaps.monsido.com https://stats.g.doubleclick.net/ https://analytics.tiktok.com/ https://px.ads.linkedin.com https://region1.analytics.google.com https://www.google.com https://analytics.google.com a.eu.silktide.com a.us.silktide.com https://js-ap1.hscollectedforms.net https://forms-ap1.hscollectedforms.net; frame-src 'self' https://staticcdn.co.nz https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io *.youtube-nocookie.com *.twitter.com *.gstatic.com *.googleapis.com *.googletagmanager.com 3f5l8ze0o4j2m.cloudfront.net *.youtube.com *.youtube-no-cookie.com *.ytimg.com *.google.com www.google.com https://player.vimeo.com https://www.facebook.com https://staticxx.facebook.com https://optimize.google.com https://tr.snapchat.com https://bid.g.doubleclick.net/ https://td.doubleclick.net; frame-ancestors 'self'; font-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com fonts.gstatic.com fonts.googleapis.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://use.typekit.net data: 'self'; form-action 'self' *.twitter.com https://www.facebook.com/tr/ https://connect.facebook.com https://tr.snapchat.com/; img-src 'self' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googletagmanager.com d3f5l8ze0o4j2m.cloudfront.net *.ytimg.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://staticcdn.co.nz/embed/close.png https://optimize.google.com https://p.typekit.net https://px.ads.linkedin.com https://bat.bing.com/ https://p.adsymptotic.com/ https://www.google.com/ https://www.google.co.nz/ https://www.google.co.uk/ https://tracking.monsido.com/ https://cdn.monsido.com/ https://www.linkedin.com/ https://dc.ads.linkedin.com/ data: https://www.facebook.com https://collect-ap-southeast-2.tealiumiq.com https://www.xn--tepkenga-szb.ac.nz https://px4.ads.linkedin.com https://i.vimeocdn.com https://forms-ap1.hsforms.com https://track-ap1.hubspot.com https://www.google.com.au/; manifest-src 'self'; media-src 'self'; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.jquery.com *.staticcdn.co.nz https://use.typekit.net https://cdnjs.cloudflare.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://static.hotjar.com/* d3f5l8ze0o4j2m.cloudfront.net https://connect.facebook.net https://staticcdn.co.nz https://www.googletagmanager.com https://www.google-analytics.com https://www.google-analytics.com/analytics.js https://stats.g.doubleclick.net https://optimize.google.com https://snap.licdn.com/li.lms-analytics/insight.min.js https://bat.bing.com https://46e2fa37ca504ebc8217a70ea9c22c81.js.ubembed.com/ https://sc-static.net/ https://www.nmit.ac.nz/ https://app-script.monsido.com/ https://assets.ubembed.com/ https://vxml4.plavxml.com/ https://heatmaps.monsido.com/ https://cdn.monsido.com/ https://analytics.tiktok.com/ https://googleads.g.doubleclick.net/ https://www.googleadservices.com/ https://tags.tiqcdn.com https://analytics.silktide.com https://snap.licdn.com https://js-ap1.hs-scripts.com https://js-ap1.hscollectedforms.net https://js-ap1.hs-banner.com https://js-ap1.hs-analytics.net; style-src 'self' 'unsafe-inline' *.twimg.com *.twitter.com *.gstatic.com *.googleapis.com fonts.googleapis.com https://optimize.google.com/optimize/editor/css/css.css https://optimize.google.com https://www.nmit.ac.nz/themes/nmit/css/cookieconsent.min.css; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com consentcdn.cookiebot.com service.force.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com img.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net s.ytimg.com * *.bird.eu 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adobedtm.com dev.visualwebsiteoptimizer.com *.exacttarget.com *.google.it/pagead/1p-user-list serverside.stiga.com *.cookiebot.com via.placeholder.com maps.googleapis.com *.teads.tv www.xtento.com *.trustpilot.com imgsct.cookiebot.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.youtube.com video.google.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.klarna.com consent.cookiebot.com *.collect.igodigital.com serverside.stiga.com cdnjs.cloudflare.com service.force.com *.salesforceliveagent.com dev.visualwebsiteoptimizer.com *.clarity.ms *.imedia.cz consentcdn.cookiebot.com *.teads.tv *.seznam.cz *.xtento.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com getfirebug.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com service.force.com *.klarnacdn.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.google-analytics.com *.facebook.com *.facebook.net api.addressy.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com consentcdn.cookiebot.com *.googlesyndication.com dev.visualwebsiteoptimizer.com serverside.stiga.com *.klarna.com *.klarnaevt.com trustpilot.com googleads.g.doubleclick.net *.teads.tv *.clarity.ms noembed.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://wog.ch/ https://www.wog.ch/ https://fonts.gstatic.com/s/roboto/v30/KFOlCnqEu92Fr1MmEU9fBBc4AMP6lQ.woff2; base-uri 'self' https://wog.ch/ https://www.wog.ch/; style-src-elem 'self' https://wog.ch/ https://www.wog.ch/ 'unsafe-inline' https://fonts.googleapis.com/; style-src 'self' 'unsafe-inline' https://wog.ch/ https://www.wog.ch/ https://fonts.googleapis.com/; media-src 'self' data: https://wog.ch/ https://wwww.wog.ch/; img-src 'self' https://wog.ch/ https://www.wog.ch/ https://www.games.ch/ https://i.ytimg.com/ data: https://www.paypalobjects.com/ https://t.paypal.com/ https://developer.android.com/ https://files.newsletter2go.com/ https://www.google.com/ https://www.googleadservices.com/ https://adservice.google.com/ https://google.com/ https://www.google.ch https://*.google-analytics.com https://*.googletagmanager.com https://googleads.g.doubleclick.net https://www.econda-monitor.de; script-src-elem 'self' 'unsafe-inline' https://apis.google.com https://wog.ch/ https://www.wog.ch/ https://s.ytimg.com/ https://www.google.com/ https://www.gstatic.com/ https://www.paypal.com/ https://www.paypalobjects.com/ https://checkout.postfinance.ch/ https://static.newsletter2go.com/ https://appjs.blickinsbuch.de/ https://www.blickinsbuch.de/ https://*.googletagmanager.com https://www.googleadservices.com/ https://www.google-analytics.com/ https://googleads.g.doubleclick.net/ https://www.econda-monitor.de/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://wog.ch/ https://www.wog.ch/ https://www.paypal.com/ https://www.paypalobjects.com/ https://checkout.postfinance.ch/ https://s.ytimg.com/ https://www.google.com/ https://www.googletagmanager.com/ https://www.googleadservices.com/ https://www.gstatic.com/ https://googleads.g.doubleclick.net https://appjs.blickinsbuch.de/ https://www.blickinsbuch.de/gateway/check.php; font-src 'self' https://wog.ch/ https://www.wog.ch/ data: https://fonts.gstatic.com; frame-src 'self' https://accounts.google.com https://wog.ch/ https://www.wog.ch/ https://www.youtube.com/ https://www.google.com/ https://www.googletagmanager.com/ https://myaccount.google.com/ https://maps.google.com/ https://bid.g.doubleclick.net https://td.doubleclick.net https://www.sandbox.paypal.com/ https://www.paypal.com/ https://www.paypalobjects.com/ https://wog.games.ch/ https://www.games.ch/ https://www.blickinsbuch.de/ https://www.blickinsbuch.net/ https://checkout.postfinance.ch/; connect-src 'self' data: https://wog.ch/ https://www.wog.ch/ https://code.jquery.com https://checkout.postfinance.ch/ https://www.sandbox.paypal.com/ https://www.paypal.com/ https://api.newsletter2go.com/ https://www.econda-monitor.de/ https://adservice.google.com/ https://www.googleadservices.com/ https://ad.doubleclick.net/ https://www.google.com/ https://region1.google-analytics.com/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; report-uri https://worldofgames.report-uri.com/r/d/csp/reportOnly; report-to default 1 default-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; 1 default-src 'none'; script-src 'self' https://palmbeachschools.us001-rapididentity.com https://mysdpbc.org/; style-src 'self' https://palmbeachschools.us001-rapididentity.com https://mysdpbc.org/; img-src 'self' https://palmbeachschools.us001-rapididentity.com https://mysdpbc.org/; form-action 'none'; frame-ancestors 'none'; 1 manifest-src 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.seamly-app.com https://*.cookiebot.com https://*.umbrella.com https://*.srcspot.com https://*.infomedics.nl https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://service.mtcaptcha.com https://static.srcspot.com https://unpkg.com https://matomo.infomedics.nl/; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.seamly-app.com https://*.cookiebot.com https://*.umbrella.com https://*.srcspot.com https://*.infomedics.nl https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://service.mtcaptcha.com https://static.srcspot.com https://unpkg.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com themes; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'none'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://static.cloudflareinsights.com https://www.googletagmanager.com https://www.google-analytics.com https://login.microsoftonline.com https://secure.aadcdn.microsoftonline-p.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self' https://planetaryscienceinstitute.kindful.com; frame-ancestors 'self'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://acsbapp.com https://browser.sentry-cdn.com https://cdn.cookielaw.org https://code.jquery.com https://cdn.jsdelivr.net https://fast.wistia.com https://js.monitor.azure.com https://kit.fontawesome.com https://www.google.com https://www.google.com/recaptcha https://www.googletagmanager.com https://www.gstatic.com https://connect.facebook.net https://polyfill.io https://ajax.googleapis.com https://developers.google.com https://maps.googleapis.com https://maps.gstatic.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://acsbapp.com https://browser.sentry-cdn.com https://cdn.cookielaw.org https://code.jquery.com https://cdn.jsdelivr.net https://fast.wistia.com https://js.monitor.azure.com https://kit.fontawesome.com https://www.google.com https://www.google.com/recaptcha https://www.googletagmanager.com https://www.gstatic.com https://connect.facebook.net https://polyfill.io https://ajax.googleapis.com https://developers.google.com https://maps.googleapis.com https://maps.gstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://code.jquery.com https://fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://code.jquery.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://cdn.acsbapp.com https://cdn.cookielaw.org https://dc.services.visualstudio.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fast.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io https://geolocation.onetrust.com https://ka-p.fontawesome.com https://pipedream.wistia.com https://privacyportal.onetrust.com https://www.google-analytics.com https://analytics.google.com https://connect.facebook.net https://maps.googleapis.com https://maps.gstatic.com https://stats.g.doubleclick.net; font-src 'self' https://cdnjs.cloudflare.com https://fast.wistia.com https://ka-p.fontawesome.com https://fonts.gstatic.com data:; frame-src 'self' https://www.google.com https://www.facebook.com https://static.xx.fbcdn.net; img-src 'self' data: https://cdn.cookielaw.org https://fast.wistia.com https://embed-ssl.wistia.com https://www.globalmedicalresponse.com https://app-gmr-corpweb-amr.azurewebsites.net https://www.googletagmanager.com https://maps.gstatic.com https://maps.googleapis.com https://www.facebook.com https://facebook.com https://m.facebook.com; manifest-src 'self'; media-src 'self' blob:; worker-src 'none'; report-uri https://68654f9f841f0014a4c0d103.endpoint.csper.io?v=0; 1 default-src 'unsafe-inline' *.tulotero.es *.es.tulotero.net tulotero.es es.tulotero.net tulotero.net *.redsys.es api.fpjs.io static.tulotero.net tulotero-prod-es-public-files.s3.eu-west-3.amazonaws.com wa.appsflyer.com websdk.appsflyer.com wa.onelink.me wa.appsflyer.com websdk.appsflyer.com wa.onelink.me *.hotjar.com *.hotjar.io *.googleusercontent.com *.google.es *.google.com *.google-analytics.com *.googleapis.com www.googletagmanager.com www.googleadservices.com tpc.googlesyndication.com *.g.doubleclick.net td.doubleclick.net *.gstatic.com *.twitter.com t.co static.ads-twitter.com platform.twitter.com *.facebook.com connect.facebook.net fpnpmcdn.net graph.facebook.com bat.bing.com *.tiktok.com t.resfu.com data: blob: 'self'; frame-src 'self' sis.redsys.es td.doubleclick.net data: blob: ; frame-ancestors *.tulotero.es *.es.tulotero.net tulotero.es es.tulotero.net tulotero.net *.redsys.es api.fpjs.io static.tulotero.net tulotero-prod-es-public-files.s3.eu-west-3.amazonaws.com wa.appsflyer.com websdk.appsflyer.com wa.onelink.me wa.appsflyer.com websdk.appsflyer.com wa.onelink.me *.hotjar.com *.hotjar.io 'self'; report-uri https://csp-reports.es.tulotero.net/report/v13; block-all-mixed-content;manifest-src 'self'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com *.finance-calculator.co.uk *.s3.eu-west-2.amazonaws.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.myfonts.net *.bootstrapcdn.com *.electromarket.co.uk *.tawk.to *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.reviews.io *.reviews.co.uk *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.salesfire.co.uk *.finance-calculator.co.uk *.deko.finance *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com *.google-analytics.com *.gstatic.com *.google.com *.trustpilot.com *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com s3.eu-west-1.amazonaws.com *.blackhorseflexpay.co.uk https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.google.com *.google.co.uk *.paypal.com *.doubleclick.net *.electromarket.co.uk destiny-files.com *.bronto.com *.tawk.to *.jsdelivr.net *.postcodeanywhere.co.uk *.reviews.io *.reviews.co.uk *.klarna.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.salesfire.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com dekowallet-feature-assets.s3.eu-west-2.amazonaws.com *.blackhorseflexpay.co.uk/ *.postcodeanywhere.co.uk https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.cloudflare.com *.google-analytics.com *.googletagmanager.com *.google.com *.fontawesome.com *.divido.com *.electromarket.co.uk *.tawk.to *.pcapredict.com *.doubleclick.net *.trustpilot.com *.bronto.com *.jsdelivr.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.salesfire.co.uk *.typekit.net *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.gstatic.com *.myfonts.net *.electromarket.co.uk *.bootstrapcdn.com *.jsdelivr.net *.postcodeanywhere.co.uk *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.smartmetrics.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.electromarket.co.uk *.tawk.to wss://*.tawk.to *.google.com *.google-analytics.com *.doubleclick.net *.postcodeanywhere.co.uk *.brontops.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.link.com *.amazon.com *.twitter.com *.twimg.com *.facebook.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.keva.fi https://disqus.com https://*.disquscdn.com https://static.aim.front.ai https://905keva.boost.ai; style-src 'self' 'unsafe-inline' *.tinymce.com *.tiny.cloud https://*.googleapis.com https://*.episerver.net https://*.disquscdn.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://ton.twimg.com https://platform.twitter.com https://hello.myfonts.net https://fonts.googleapis.com https://cdn.reactandshare.com https://static.aim.front.ai; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tinymce.com *.tiny.cloud https://*.reactandshare.com https://*.keva.fi https://disqus.com https://keva-fi.disqus.com https://*.disquscdn.com https://cdn.syndication.twimg.com https://api.twitter.com https://platform.twitter.com https://*.snoobi.com https://insight.fonecta.fi https://netdna.bootstrapcdn.com https://*.episerver.net https://code.jquery.com https://ajax.aspnetcdn.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://*.vo.msecnd.net https://connect.facebook.net https://*.krxd.net https://survey.taloustutkimus.fi https://www.googleadservices.com https://snap.licdn.com https://unpkg.com https://js.monitor.azure.com https://static.aim.front.ai/ https://905keva.boost.ai; img-src 'self' data: blob: kevadevstorage.blob.core.windows.net *.tinymce.com *.tiny.cloud https://*.reactandshare.com https://*.adsymptotic.com/ https://*.gstatic.com https://*.keva.fi https://*.episerver.net https://*.twitter.com https://*.twimg.com https://insight.fonecta.fi https://cdn.shopify.com https://nuget.episerver.com https://raw.githubusercontent.com https://www.facebook.com https://referrer.disqus.com https://*.disquscdn.com https://beacon.krxd.net https://*.snoobi.com https://www.linkedin.com https://*.ads.linkedin.com https://static.aim.front.ai https://boost-files-general-eu-west-1-prod.s3-eu-west-1.amazonaws.com; connect-src wss: https: ws: https://dc.services.visualstudio.com https://static.aim.front.ai https://905keva.boost.ai; font-src 'self' *.tinymce.com *.tiny.cloud https://*.cloudflare.com https://*.keva.fi https://netdna.bootstrapcdn.com https://fonts.gstatic.com https://cdn.reactandshare.com https://static.aim.front.ai https://*.cloudfront.net; frame-src 'self' *.tinymce.com *.tiny.cloud https://*.keva.fi https://*.twitter.com https://www.youtube.com https://disqus.com https://staticxx.facebook.com https://cdn.krxd.net https://survey.taloustutkimus.fi https://player.vimeo.com https://www.riddle.com https://*.soundcloud.com https://app.powerbi.com https://dashboard.find.episerver.net/; object-src 'self'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com https://www.gstatic.com https://fonts.gstatic.com *.hotjar.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com *.worldpay.com *.nosto.com *.nos.to https://secure-test.worldpay.com/shopper/3ds/ddc.html *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ lpcdn.lpsnmedia.net www.facebook.com cdn.knightlab.com *.worldpay.com *.nosto.com *.nos.to https://pay.google.com https://secure-test.worldpay.com *.dotdigital-pages.com *.dotdigital.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com https://www.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.afd.co.uk *.bing.com www.facebook.com www.google.co.in www.google.com *.clarity.ms cdn-ukwest.onetrust.com www.googletagmanager.com *.nosto.com *.nos.to *.cloudflare.com *.gstatic.com *.trackedlink.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com d21m4dsqdd3b9h.cloudfront.net *.doubleclick.net *.facebook.com *.facebook.net www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.cl www.google.cm www.google.co.bw www.google.co.id www.google.co.il www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.tn www.google.tt www.google.vu *.google.com *.hotjar.com *.onetrust.com s3.amazonaws.com *.trackedweb.net *.trustpilot.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://www.google.com *.afd.co.uk *.lpsnmedia.net bat.bing.com cdn-ukwest.onetrust.com *.googleapis.com *.liveperson.net survey.g.doubleclick.net *.google.co.in *.google.com *.clarity.ms analytics.webgains.io connect.facebook.net *.newrelic.com *.nr-data.net *.worldpay.com *.varify.io *.nosto.com *.nos.to https://www.google.com/recaptcha/api.js https://www.gstatic.com *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js tagmanager.google.com https://www.googletagmanager.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.klevu.com *.ksearchnet.com landofcoder.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.bing.com *.facebook.com *.facebook.net *.hotjar.com *.klevu.com *.onetrust.com *.webgains.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.nosto.com *.nos.to *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.trustpilot.com *.onetrust.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.onetrust.com stats.g.doubleclick.net *.clarity.ms widget.trustpilot.com *.nr-data.net *.afd.co.uk *.nosto.com *.nos.to https://www.google-analytics.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klevu.com *.ksearchnet.com landofcoder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.bing.com *.contentsquare.net *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.googleapis.com www.google.ae www.google.am www.google.at www.google.az www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.bw www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.gg www.google.gl www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.lk www.google.lt www.google.lv www.google.mg www.google.mk www.google.mn www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.sh www.google.si www.google.sk www.google.tn www.google.tt *.hotjar.com *.hotjar.io *.trustpilot.com *.webgains.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://708f9030-f3a8-4d71-9a62-c459d3d729dd.sansec.watch/; report-to report-endpoint; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline' blob:; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' company.modyo.cloud cdn-cookieyes.com js.intercomcdn.com static.cloudflareinsights.com platform.twitter.com www.googletagmanager.com sc.lfeeder.com googleads.g.doubleclick.net snap.licdn.com ajax.cloudflare.com script.crazyeggs.com cdn.jsdelivr.net cdn.outfunnel.com cdn.dynamicframework.dev www.google.com www.gstatic.com www.youtube.com; style-src 'self' 'unsafe-inline' company.modyo.cloud fonts.googleapis.com cdn.dynamicframework.dev www.googletagmanager.com cdn.jsdelivr.net; img-src 'self' data: blob: company.modyo.cloud cdn.modyo.cloud downloads.intercomcdn.com px.ads.linkedin.com px4.ads.linkedin.com i.ytimg.com yt3.ggpht.com www.googleadservices.com static.intercomassets.com lh4.googleusercontent.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat tr.lfeeder.com www.googletagmanager.com cdn-cookieyes.com tr-rc.lfeeder.com wt.outfunnel.com; report-uri https://modyo-reports.uriports.com/reports/report, report-to default 1 default-src 'self' data: 'unsafe-inline' d.bongo4u.com; script-src 'self' data: 'unsafe-inline' d.bongo4u.com blob: 'unsafe-eval' bongo4u.com *.bongo4u.com *.emerge2.com *.google.com *.gstatic.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com *.yahooapis.com *.mailchimp.com *.list-manage.com chimpstatic.com *.ipify.org jsonip.com *.amazonaws.com/downloads.mailchimp.com/ *.jquery.com *.hotjar.com acsbapp.com *.bootstrapcdn.com googleads.g.doubleclick.net *.elfsight.com *.createsend1.com *.roomvo.com; connect-src 'self' data: 'unsafe-inline' d.bongo4u.com comments.emerge2.com util.emerge2.com bongo4u.com *.emerge2.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.ca *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.doubleclick.net *.facebook.com *.hotjar.io *.hotjar.com acsbapp.com *.acsbapp.com *.elfsight.com createsend.com *.ipify.org *.mailchimp.com *.catalog-display.com *.roomvo.com *.opencagedata.com *.googleusercontent.com; frame-src 'self' data: 'unsafe-inline' d.bongo4u.com bongo4u.com *.google.com *.google.ca *.googleapis.com *.googletagmanager.com *.youtube.com *.youtu.be *.facebook.com *.twitter.com *.twimg.com *.instagram.com *.yahoo.com *.catalog-display.com *.shortstack.com *.pgtb.me *.formstack.com *.list-manage.com *.doubleclick.net *.orgill.com *.orgill.ca *.adobe.com *.hotjar.com *.storefrontcloud.io *.roomvo.com *.loom.com; object-src 'self' data: 'unsafe-inline' d.bongo4u.com blob: *.apple.com *.macromedia.com; img-src 'self' https: data: blob: d.bongo4u.com *.bongo4u.com *.ytimg.com *.orgill.com android-webview-video-poster; media-src 'self' https: data: d.bongo4u.com; style-src 'self' data: 'unsafe-inline' d.bongo4u.com bongo4u.com *.bongo4u.com *.googletagmanager.com *.google.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.bootstrapcdn.com *.twitter.com *.twimg.com *.mailchimp.com *.cloudflare.com/ajax/libs/; font-src 'self' data: 'unsafe-inline' d.bongo4u.com *.googleapis.com fonts.gstatic.com *.bootstrapcdn.com fonts.cdnfonts.com *.googleusercontent.com *.cloudflare.com/ajax/libs/ *.hotjar.com *.acsbapp.com; report-uri https://util.emerge2.com/csp_violations_tracker.php; 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com *.cloudfront.net *.zopim.com *.sfdcstatic.com https://c1.sfdcstatic.com/etc/clientlibs/sfdc-aem-master/clientlibs_base/fonts/SalesforceSans-Regular.ttf use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com speedsize.com *.speedsize.com www.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net widgets.automizely.com widgets.automizely.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.scosche.com *.google.co.in *.sharethis.com *.adnxs.com *.adsrvr.org *.b1img.com *.amazon.com/* http://b1img.com *.force.com *.cloudfront.net speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com landofcoder.com s7.addthis.com *.googletagmanager.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cardinalcommerce.com g.doubleclick.net *.google.com *.zdassets.com *.nmgassets.com *.expertrec.com *.tiktok.com *.trackedweb.net *.shop.pe *.google.co.in *.sharethis.com *.zopim.com *.adnxs.com *.b1js.com *.cloudfront.net *.hotjar.com *.b1img.com http://shop.pe *.amazonaws.com http://b1img.com *.jsdelivr.net *.zendesk.com *.newrelic.com *.force.com https://service.force.com/embeddedservice/5.0/esw.min.js *.shopbox.ai https://shopbox-widgets-storybook.pages.dev/sbmain.min.js https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com https://d41000002lgrjea2.my.salesforce-sites.com *.my.salesforce-sites.com https://d41000002lgrjea2.my.salesforce.com/lightning/lightning.out.js https://d41000002lgrjea2.my.salesforce.com/lightning/lightning.out.delegate.js https://cdnjs.cloudflare.com/ajax/libs/dompurify/1.0.10/purify.js https://cmp.osano.com/AzqbnpTQhAyVm3E99/8df62698-cfde-462e-8a72-94fe3192c7c1/osano.js https://s.pinimg.com/ct/core.js https://s.pinimg.com/ct/lib/main.15f60036.js https://d41000002lgrjea2.my.salesforce-sites.com/liveAgentSetupFlow/embeddedService/sidebarApp.app *.iesnare.com *.pinimg.com *.pinterest.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com widgets.automizely.com widgets.automizely.io *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.addshoppers.com *.force.com https://d41000002lgrjea2.my.salesforce-sites.com https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com *.my.salesforce-sites.com https://static-tracking.klaviyo.com/onsite/js/532.fa051703115da6a50763.css *.klaviyo.com speedsize.com *.speedsize.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.iesnare.com *.zdassets.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io api.automizely.com api.automizely.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com landofcoder.com ekr.zdassets.com/ *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sharethis.com *.trackedweb.net *.klaviyo.com *.zopim.com *.zendesk.com *.hotjar.io *.shop.pe wss://widget-mediator.zopim.com wss://pod-27.zendesk.com *.nr-data.net https://bam.nr-data.net *.jsdelivr.net *.my.sentry.io *.hotjar.com/* wss://ws.hotjar.com *.safeopt.com *.scosche.com *.force.com *.run.app *.a.run.app https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com https://d41000002lgrjea2.my.salesforce-sites.com *.my.salesforce-sites.com *.tiktok.com *.pinterest.com *.googleapis.com *.iesnare.com *.osano.com *.api.osano.com wss://mpsnare.iesnare.com/star speedsize.com *.speedsize.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com www.amac.nl *.amac.nl a-mac.nl www.amac-pro.nl *.aidencloud.eu *.youweagency.dev *.youweplatform.com apps-amac.bookerz.nl script.hotjar.com *.klarnacdn.net *.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.paypal.com *.sandbox.paypal.com *.pilot-payflowlink.paypal.com *.adyen.com *.pay.google.com *.payments.amazon.com *.payments-eu.amazon.com *.rsa3d.com 'self' 'unsafe-inline'; frame-ancestors app.contenzi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * app.aiden.cx *.aiden.cx *.adyen.com *.adyenpayments.com abc.amac.nl apps-amac.bookerz.nl contact.robinhq.com tr.snapchat.com td.doubleclick.net 6615279.fls.doubleclick.net www.facebook.com *.rsa3d.com *.securesuite.co.uk *.klarna.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com * https://static.buckaroo.nl *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com www.amac.nl *.amac.nl a-mac.nl www.amac-pro.nl *.aidencloud.eu *.youweagency.dev *.youweplatform.com dev.visualwebsiteoptimizer.com px.ads.linkedin.com tr.snapchat.com t.squeezely.tech www.facebook.com ad.doubleclick.net adservice.google.com www.google.nl abc.amac.nl region1.analytics.google.com robincontentdesktop.blob.core.windows.net ade.googlesyndication.com www.linkedin.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.disqus.com https://img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com commerce.adobedtm.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com app.aiden.cx *.aiden.cx https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl *.googletagmanager.com tagmanager.google.com www.amac.nl *.amac.nl *.aidencloud.eu *.youweagency.dev *.youweplatform.com code.jquery.com static.cloudflareinsights.com apps-amac.bookerz.nl widget.trustpilot.com invitejs.trustpilot.com www.dwin1.com snap.licdn.com sc-static.net static.hotjar.com squeezely.tech script.hotjar.com dev.visualwebsiteoptimizer.com tr.snapchat.com robincontentdesktop.blob.core.windows.net connect.facebook.net az416426.vo.msecnd.net analytics.tiktok.com ajax.cloudflare.com cdnjs.cloudflare.com selfservice.robinhq.com www.googleoptimize.com bat.bing.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.trustpilot.com a11328.ctz-content.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl tagmanager.google.com fonts.google.com www.amac.nl *.amac.nl *.aidencloud.eu *.youweagency.dev *.youweplatform.com apps-amac.bookerz.nl code.jquery.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amac.nl *.aidencloud.eu a-mac.nl www.amac-pro.nl *.youweagency.dev *.youweplatform.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net api.magento.com commerce.adobe.io www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com commerce.adobedtm.com commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * app.aiden.cx *.aiden.cx https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.google-analytics.com *.analytics.google.com *.googletagmanager.com dev.visualwebsiteoptimizer.com www.amac.nl px.ads.linkedin.com abc.amac.nl googleads.g.doubleclick.net dc.services.visualstudio.com tr6.snapchat.com tr.snapchat.com analytics.tiktok.com www.facebook.com pagead2.googlesyndication.com bat.bing.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com a11328.ctz-content.com 'self' 'unsafe-inline'; child-src app.aiden.cx *.aiden.cx http: https: blob: 'self' 'unsafe-inline'; default-src www.amac.nl *.amac.nl *.aidencloud.eu *.youweagency.dev *.youweplatform.com tr6.snapchat.com tr.snapchat.com commerce.adobedc.net googleads.g.doubleclick.net analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://404d70f5-70c9-40a8-824b-f381e27a4eeb.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com *.gstatic.com *.hotjar.com *.cloudfront.net static.klaviyo.com *.reviews.io *.reviews.co.uk *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.reviews.io *.reviews.co.uk *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.google.com/ *.hotjar.com *.livechatinc.com *.reviews.co.uk widget.reviews.co.uk *.reviews.io *.pingdom.com *.heritagepartscentre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net data: * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.google.com *.google.co.uk *.cloudfront.net *.facebook.com *.yotpo.com *.heritagepartscenter.com www.google.co.in *.google-analytics.com bat.bing.com imgsct.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.reviews.io *.reviews.co.uk *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page polyfill.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com *.pcapredict.com/js/sensor.js *.google.com/ *.gstatic.com *.hotjar.com *.doubleclick.net *.newrelic.net *.livechatinc.com *.facebook.net *.webgains.io *.chimpstatic.com *.yotpo.com *.reviews.co.uk *.trackedlink.net *.googleapis.com gtm.heritagepartscentre.com consent.cookiebot.com bat.bing.com www.clarity.ms consentcdn.cookiebot.com scripts.clarity.ms static.zdassets.com static.zdassets.com/web_widget static.onsitesupport.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.reviews.io *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.yotpo.com *.cloudfront.net *.reviews.co.uk static.onsitesupport.io https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.reviews.io *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.livechatinc.com *.heritagepartscenter.com *.onsitesupport.io static.onsitesupport.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com *.hotjar.com *.adobedc.net *.reviews.co.uk bat.bing.com l.clarity.ms consentcdn.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.cloudflare.com *.twitter.com *.twimg.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://d3f6h8s0w402y5.cloudfront.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com seal.digicert.com widget.trustpilot.com cdn.what3words.com cdn.evgnet.com walls.io l.getsitecontrol.com guidedrec.preferabli.com www.google.com www.gstatic.com services.postcodeanywhere.co.uk c1.rfihub.net d3f6h8s0w402y5.cloudfront.net www.tag4arm.com snap.licdn.com static.ads-twitter.com cdn.taboola.com s.pinimg.com connect.facebook.net smct.co s.yimg.com static.chartbeat.com assets.apollo.io client.prod.mplat-ppcprotect.com cdn.datalabsgroup.com cdnjs.cloudflare.com www.googleadservices.com googleads.g.doubleclick.net 6261229.collect.igodigital.com trc.taboola.com bat.bing.com s2.getsitecontrol.com ct.pinterest.com apis.google.com accounts.google.com a.img-statics.com service.force.com d.la11-core1.sfdc-cehfhs.salesforceliveagent.com d.la1-c1-cdg.salesforceliveagent.com static.lightning.force.com virginwines.my.salesforce-sites.com www.fastuktrack.com apps.rokt.com virginwines.my.salesforce.com s.kk-resources.com blob: netfree.link secured-pixel.com data1.klastaf.com js.braintreegateway.com assets.braintreegateway.com songbird.cardinalcommerce.com c.paypal.com www.paypal.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net *.contentsquare.net app.contentsquare.com *.tradedoubler.com a.imgstatics.com apis.google.com accounts.google.com *.googleapis.com xzdeav5g.micpn-eu.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com guidedrec.preferabli.com services.postcodeanywhere.co.uk d3f6h8s0w402y5.cloudfront.net service.force.com virginwines.my.salesforce-sites.com virginwines.my.salesforce.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev; frame-src 'self' *; connect-src 'self' l.getsitecontrol.com region1.google-analytics.com api-js.mixpanel.com services.postcodeanywhere.co.uk api.preferabli.com guidedrec.preferabli.com px.ads.linkedin.com region1.analytics.google.com bat.bing.com c.contentsquare.net 6261229.collect.igodigital.com www.tag4arm.com stats.g.doubleclick.net psb.taboola.com click.prod.mplat-ppcprotect.com aplo-evnt.com api.ipify.org ct.pinterest.com events.getsitectrl.com srm.ba.contentsquare.net s.yimg.com trc-events.taboola.com k-aeu1.contentsquare.net pclick.prod.mplat-ppcprotect.com zu7k3v809b.execute-api.eu-west-1.amazonaws.com www.facebook.com s.kelkoogroup.net virginwines.my.salesforce-sites.com trc.taboola.com apis.google.com analytics.google.com www.google.co.uk www.google-analytics.com ad.doubleclick.net a.imgstatics.com bat.bing.net api.privacy-protector-adblocker.com pagead2.googlesyndication.com api.braintreegateway.com client-analytics.braintreegateway.com *.braintree-api.com www.paypal.com *.cloudfront.net *.cardinalcommerce.com *.contentsquare.net *.contentsquare.com fonts.googleapis.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net apis.google.com accounts.google.com *.googleapis.com https://www.google.com google.com 6abynomjpa.execute-api.eu-west-1.amazonaws.com www.googleadservices.com *.google.com *.pinterest.com kg668dbov0.execute-api.us-east-1.amazonaws.com api.what3words.com https://www.facebook.com *.doubleclick.net *.conviva.com; font-src 'self' https: data:; img-src 'self' https: data: analytics.twitter.com t.co ad.doubleclick.net px.ads.linkedin.com *.webtrends-optimize.com *.contentsquare.net; report-to csp-collector; 1 default-src 'self'; script-src 'self' 'unsafe-inline' ; style-src 'self' 'unsafe-inline' ; img-src 'self' *.gaertner.de; frame-src 'self' https://www.openstreetmap.org ; font-src 'self' ; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com data: *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com scontent.* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ display.ugc.bazaarvoice.com *.fontawesome.com assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://3bb61dc1-a559-4e04-a5cd-44834bae6c9a.sansec.watch/; report-to report-endpoint; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 script-src 'sha256-1sunfECq9zYCHg9tw4VdpU7EbDetPWv9PeUCxfuvQF4=' 'self' self unsafe-eval *.criteo.com; style-src self unsafe-eval; report-uri https://0771da0b-b592-4245-a1e0-f93423ca942b.sansec.watch/ 1 style-src-elem 'unsafe-inline' cdn.listrakbi.com *.googleapis.com *.livehelpnow.net *.shipperhq.com tcc.test cary.test *.userway.org thecarycompany.com *.thecarycompany.com; font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com data: *.hawksearch.com *.hawksearch.net *.userway.org *.livehelpnow.net *.shipperhq.com *.gstatic.com *.googleapis.com tcc.test cary.test *.thecarycompany.com thecarycompany.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.certcapture.com data: *.avis-verifies.com *.livechatinc.com *.shipperhq.com *.userway.org *.trustpilot.com guarantee-cdn.com *.pinterest.com *.google.com services.listrak.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.googleapis.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.certcapture.com tcc.test cary.test *.thecarycompany.com www.thecarycompany.com *.adobedtm.com *.wistia.com *.wistia.net *.akamaihd.net seal-chicago.bbb.org *.listrakbi.com maps.gstatic.com *.bing.com *.linkedin.com *.google.com nsg.symantec.com tcs-analytics-tracker.now.sh tcs-analytics-tracker.vercel.app guarantee-cdn.com www.facebook.com hn.inspectlet.com thecarycompany.com *.livehelpnow.net googleadservices.com *.cookielaw.org *.userway.org http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com 'unsafe-inline' data: *.wistia.com *.wistia.net seal-chicago.bbb.org *.listrakbi.com nsg.symantec.com *.online-metrix.net *.shipperhq.com *.authorize.net secure.authorize.net test.authorize.net *.licdn.com *.chatservice.co *.inspectlet.com www.facebook.com *.msecnd.net *.bing.com *.doubleclick.net *.google.com *.googleadservices.com *.google-analytics.com *.googlecommerce.com *.googletagmanager.com *.googleapis.com *.gstatic.com guarantee-cdn.com *.cardinalcommerce.com.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trustpilot.com *.cookielaw.org *.userway.org *.livehelpnow.net *.sentry-cdn.com *.thomasnet.com ip.convirza.com tcc.test cary.test thecarycompany.com *.thecarycompany.com cdn.jsdelivr.net *.pinimg.com *.fontawesome.com *.pinterest.com services.listrak.com testflex.cybersource.com flex.cybersource.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ x.klarnacdn.net connect.facebook.net graph.facebook.com business.facebook.com assets.shipperhq.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com data: *.listrakbi.com *.shipperhq.com *.userway.org *.livehelpnow.net tcc.test cary.test *.googleapis.com *.thecarycompany.com thecarycompany.com assets.shipperhq.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: *.wistia.com *.wistia.net *.akamaihd.net *.userway.org tcc.test cary.test *.thecarycompany.com thecarycompany.com *.livehelpnow.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com data: *.wistia.com *.litix.io *.shipperhq.com wss://rms.shipperhq.com *.doubleclick.net *.chatservice.co *.inspectlet.com ws.inspectlet.com tcs-analytics-tracker.now.sh tcs-analytics-tracker.vercel.app *.google.com *.googleapis.com *.bing.com *.trustpilot.com *.cookielaw.org developer.livehelpnow.net *.userway.org *.livehelpnow.net wss://app.livehelpnow.net ip.convirza.com dni.logmycalls.com tcc.test cary.test *.thecarycompany.com thecarycompany.com geolocation.onetrust.com *.linkedin.com *.pinterest.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com rms.shipperhq.com https://rms.shipperhq.com ovs.shipperhq.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5502b8453f99696234832a80aaf978ec.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' *.googleapis.com; base-uri 'self'; frame-ancestors 'self' www.gstatic.com; form-action 'self' *.paypal.com pilot-payflowlink.paypal.com *.twitter.com; frame-src 'self' youtube.com *.youtube.com *.youtube-nocookie.com *.paypal.com *.checkout.com www.google.com *.doubleclick.net *.googletagmanager.com *.cookiebot.com cdn.smooch.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.luigisbox.com scripts.luigisbox.com assets.adobedtm.com *.adobe.com *.cloudflare.com cdnjs.cloudflare.com https://cdnjs.cloudflare.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.google.com *.gstatic.com *.googleapis.com *.fontawesome.com *.zopim.com *.zdassets.com *.checkout.com *.cookiebot.com *.cookiefirst.com consent.cookiefirst.com *.bing.com *.clarity.ms s.ytimg.com www.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.checkout.com https://*.ggpht.com https://*.googleusercontent.com *.pcapredict.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.googleapis.com *.fontawesome.com *.cloudflare.com *.checkout.com *.cookiefirst.com cdn.luigisbox.com; font-src 'self' data: fonts.gstatic.com *.gstatic.com *.cloudflare.com *.twitter.com *.trustedshops.com *.googleapis.com cdn.checkout.com https://www.gstatic.com *.twimg.com; img-src 'self' data: *.luigisbox.com *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com www.google.co.uk *.google.co.uk *.google-analytics.com analytics.google.com *.googletagmanager.com *.paypal.com t.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.youtube.com *.gstatic.com *.cloudflare.com *.lsengineers.co.uk *.twitter.com *.twimg.com *.doubleclick.net *.bing.com *.bing.net bat.bing.net *.zdassets.com *.googleapis.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com consent.cookiefirst.com *.cookiefirst.com; connect-src 'self' wss: *.luigisbox.com *.google-analytics.com analytics.google.com *.doubleclick.net *.googletagmanager.com *.newrelic.com *.nr-data.net *.adobe.io *.paypal.com *.checkout.com *.clarity.ms *.cookiefirst.com *.bing.com *.bing.net *.googleapis.com *.googlesyndication.com https://js.checkout.com https://*.google.com https://*.gstatic.com https://*.googleapis.com *.zendesk.com *.zdassets.com ekr.zdassets.com lsengineers.zendesk.com; object-src 'self'; media-src 'self' *.adobe.com *.zdassets.com; manifest-src 'self'; child-src 'self' https: http: 1 default-src 'self' https://*.liadm.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.google.com https://www.gstatic.com https://*.hsforms.net https://*.marker.io https://www.youtube.com/s/player/010fbc8d/www-widgetapi.vflset/www-widgetapi.js https://www.youtube.com/iframe_api https://*.hsadspixel.net https://*.hs-analytics.net https://*.hscollectedforms.net https://*.hubspot.com https://*.hsleadflows.net https://*.hs-banner.com https://*.usemessages.com https://*.clarity.ms https://*.jsdelivr.net https://js.zi-scripts.com https://googleads.g.doubleclick.net https://*.pixel.ad https://*.hs-scripts.com https://unpkg.com https://code.jquery.com https://*.spinutech.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://analytics.tiktok.com https://bat.bing.com https://cdn.mxpnl.com https://snap.licdn.com https://px.ads.linkedin.com https://cdn.taboola.com https://ddwl4m2hdecbv.cloudfront.net/b/ https://*.liadm.com https://b2bjsstore.s3.us-west-2.amazonaws.com; connect-src 'self' https://www.googleadservices.com https://www.googletagmanager.com https://*.zoominfo.com https://*.hsforms.com https://*.marker.io https://*.linkedin.com https://*.bing.com https://*.bing.net https://*.stape.biz https://*.facebook.net https://*.facebook.com https://*.clarity.ms https://*.hscollectedforms.net https://*.hubspot.com https://*.hubapi.com https://js.zi-scripts.com https://*.spinutech.com https://google.com https://www.google.com https://*.google.com https://*.g.doubleclick.net https://www.google-analytics.com https://analytics.tiktok.com https://px.ads.linkedin.com https://cdn.mxpnl.com https://pro.ip-api.com https://alocdn.com/c/vn3d8u2u/a/xtarget/p.json https://*.liadm.com https://9xgnrndqve.execute-api.us-west-2.amazonaws.com https://a.usbrowserspeed.com; img-src * 'self' data: android-webview-video-poster; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.typekit.net https://cdn.jsdelivr.net; font-src 'self' data: https://fonts.gstatic.com https://*.typekit.net; manifest-src 'self' https://www.spinutech.com; frame-src 'self' https://*.hsforms.com https://www.google.com https://www.youtube.com https://*.sitescout.com https://www.googletagmanager.com https://mozbar.moz.com https://block.opendns.com https://*.doubleclick.net https://*.spinutech.com; worker-src 'self' blob:; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self' https://*.hsforms.com; report-uri https://services.spinudev.com/csp/cspreport; 1 object-src 'none'; connect-src 'self' *.dogfartnetwork.com *.dfxtra.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.dogfartnetwork.com *.dfxtra.com join.gammasecure.com; script-src 'self' *.dogfartnetwork.com *.dfxtra.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.dogfartnetwork.com *.dfxtra.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.vimeo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: *.vimeocdn.com fonts.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: secure.gravatar.com www.gravatar.com data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com www.googletagmanager.com; connect-src 'self' *.vimeo.com www.google-analytics.com stats.g.doubleclick.net ampcid.google.com analytics.google.com about: www.googletagmanager.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; frame-src 'self' *.vimeo.com *.vimeocdn.com www.googletagmanager.com; child-src 'self' *.vimeo.com *.vimeocdn.com www.googletagmanager.com; 1 object-src 'none'; worker-src 'self' blob:; base-uri 'self'; frame-ancestors 'self' 1 connect-src *.bundesregierung.de analytics.bundesregierung.de 'self' https://hls-hd.myrasec.de ; style-src *.bundesregierung.de 'self' 'unsafe-inline' ; script-src *.bundesregierung.de 'self' ; script-src-elem 'self' *.bundesregierung.de 'nonce-AGkhtAuIlp5ktRu+IzHkPfmK2Nj7bg/Q40W6hPhJ47jShQDUvefxCdMpXUef/Z1p/JcPJxRxLOypIJIRU/KoxQmPiBTemoPQ7NAtgZjgYbc3ylylTk8hTd39wUdC6LjdswulN/h6Ss+CFT6+cyUL0HvfI2UVNjkNcNECeqSBRLU=' ; frame-src *.bundesregierung.de 'self' ; media-src *.bundesregierung.de 'self' http://video.bundesregierung.de https://zdf-hls-18.akamaized.net ; frame-ancestors *.bundesregierung.de 'self' ; img-src 'self' *.bundesregierung.de https://*.tile.openstreetmap.de data: ; default-src *.bundesregierung.de 'self' ; font-src *.bundesregierung.de 'self' ; report-uri https://www.bundeskanzler.de/service/csp-report ; 1 child-src blob: data: https:; connect-src https: wss:; default-src blob: data: https: 'report-sample' 'unsafe-eval' 'unsafe-inline'; font-src data: https:; form-action https:; frame-src data: https:; img-src blob: data: https:; media-src blob: data: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; script-src-elem https: 'nonce-6JocLQNgR0EduErXbSGAFA=='; style-src https: 'unsafe-inline'; report-uri https://csp.ffx.io/; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.woodpeck.com cdn.materialdesignicons.com mediacdn.espssl.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.networkmerchants.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * vars.hotjar.com www.paypalobjects.com *.g.doubleclick.net *.vimeo.com www.youtube-nocookie.com *.listrak.com secure.windriverfinancialgateway.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.networkmerchants.com *.googleapis.com *.certcapture.com magefan.com cm.magefan.com *.facebook.com https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com maps.gstatic.com *.woodpeck.com *.bm23.com *.g.doubleclick.net www.google.ae www.google.am www.google.com.ar www.google.at www.google.com.au www.google.az www.google.be www.google.com.bh www.google.com.br www.google.com.bs www.google.by www.google.ca www.google.ch www.google.cl www.google.com.co www.google.co.cr www.google.com.cy www.google.cz www.google.de www.google.dk www.google.com.do www.google.ee www.google.es www.google.fi www.google.fr www.google.gy www.google.com.hk www.google.hr www.google.hu www.google.gr www.google.co.id www.google.ie www.google.co.il www.google.co.in www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.com.lb www.google.lk www.google.lu www.google.lv www.google.co.kr www.google.com.kw www.google.kz www.google.mk www.google.mn www.google.mw www.google.com.mx www.google.com.my www.google.com.ng www.google.nl www.google.no www.google.co.nz www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.pl www.google.com.pr www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.com.sa www.google.se www.google.com.sg www.google.si www.google.sk www.google.com.sv www.google.co.th www.google.com.tr www.google.com.tw www.google.com.ua www.google.co.uk www.google.com.uy www.google.co.za translate.google.com www.facebook.com mediacdn.espssl.com *.listrakbi.com code.jquery.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.networkmerchants.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io *.shopify.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.woodpeck.com *.hotjar.com *.g.doubleclick.net browser-update.org www.google.com *.algolia.net *.algolianet.com connect.facebook.net *.listrak.com *.listrakbi.com code.jquery.com secure.windriverfinancialgateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.networkmerchants.com *.certcapture.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.woodpeck.com *.googleapis.com translate.google.com cdn.materialdesignicons.com secure.windriverfinancialgateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.networkmerchants.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.certcapture.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.woodpeck.com *.hotjar.com *.hotjar.io secure.windriverfinancialgateway.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com *.flaticon.com *.baomitu.com *.googleusercontent.com *.faircado.com *.faceworks.nl *.jsdelivr.net *.typekit.net *.cloudflare.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.yotpo.com *.3dsecure.no *.wlp-acs.com *.marqeta.com *.cardcomplete.com *.securesuite.net *.eewosecure.com *.apata.io *.google.com *.easybank.at *.americanexpress.com *.securesuite.co.uk *.rsa3dsauth.com *.n26.com *.monext.fr *.ing.de *.sparkassen-kreditkarten.de *.firstdata.de *.arcot.com *.psa.at 3dsecure-vrp.de *.rabobank.nl *.salesforce.com *.sparkasse.at 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.sendcloud.sc *.weltpixel.com *.yotpo.com *.opendns.com *.rabobank.nl *.wlp-acs.com *.psa.at *.bing.com *.arcot.com *.google.com *.firstdata.de google.com 3dsecure-vrp.de *.vimeo.com *.zscaler.net *.easybank.at *.americanexpress.com *.microsoftonline.com *.sbk-vs.de *.marqeta.com *.ing.de *.doubleclick.net *.rsa3dsauth.com *.facebook.com *.googletagmanager.com *.zscloud.net *.apata.io *.sparkassen-kreditkarten.de *.eewosecure.com *.agu.com *.convert.com *.3dsecure.no *.securesuite.net *.monext.fr *.securesuite.co.uk *.tradetracker.net *.sparkasse.at bing.com *.saasprotection.com vimeo.com *.n26.com *.cloudflare.com caclk.com *.zscalertwo.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://www.google.nl *.trackedlink.net magefan.com cm.magefan.com *.gstatic.com *.facebook.com *.yotpo.com *.facebook.net *.google.com *.agu.com *.trustedshops.com *.tradetracker.net *.googleusercontent.com *.tiktok.com *.bing.net *.bing.com *.google-analytics.com *.vimeo.com *.h-ams.net *.doubleclick.net *.convertexperiments.com ipavatarbucket.s3.eu-central-1.amazonaws.com *.googleadservices.com yastatic.net *.googletagmanager.com *.linkedin.com agu.com *.googleapis.com bucket-ip-website.s3.eu-central-1.amazonaws.com *.trackedweb.net google.com *.flaticon.com *.clarity.ms data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.sendcloud.sc https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.yotpo.com *.convertexperiments.com *.doubleclick.net *.bing.com d5yoctgpv4cpx.cloudfront.net *.kk-resources.com *.google.com *.vimeo.com *.googletagmanager.com *.convert.com *.eyefitu.com *.clarity.ms *.googleapis.com *.cookie-script.com secured-pixel.com *.trustedshops.com *.tiktok.com *.agu.com *.googleadservices.com *.tradetracker.net *.varify.io *.licdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com tagmanager.google.com *.yotpo.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bing.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.facebook.net *.yotpo.com *.visualstudio.com *.clarity.ms *.googleapis.com *.agu.com *.gstatic.com *.trustedshops.com *.convertexperiments.com *.doubleclick.net *.facebook.com *.linkedin.com *.bing.net *.hotjar.io agu.com *.eyefitu.com *.cookie-script.com *.npass.app *.tiktok.com *.varify.io p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.azure.com *.googleadservices.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://d3a47fe8-35b6-4db2-9ced-33cd80c05948.sansec.watch/; report-to report-endpoint; 1 font-src *.force.com https://api.ipify.org https://fonts.gstatic.com/ 'self' https://stats.g.doubleclick.net blob: https://qrcargo.my.site.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://maps.a.forceusercontent.com https://qrcargo.my.salesforce-scrt.com https://www.youtube.com data:; report-to sfdc-csp-ep; report-uri https://qrcargo.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4K000000Cwhy&networkId=0DM4K000000gVJm&type=communities 1 base-uri 'self'; child-src 'self'; connect-src 'self' ws: https://*.psychologytools.com https://a.optinmonster.com https://a.omappapi.com https://api.omappapi.com https://checkout.stripe.com https://api.stripe.com https://maps.googleapis.com https://plausible.io; default-src 'self'; font-src 'self' https://fonts.gstatic.com https://*.psychologytools.com https://fonts.bunny.net data:; form-action 'self' https://*.psychologytools.com; frame-src 'self' https://*.psychologytools.com https://checkout.stripe.com https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com https://www.youtube.com; img-src 'self' data: https://*.psychologytools.com https://psychologytools-com-local.s3.eu-west-1.amazonaws.com https://psychology-tools-dev-files.s3.eu-west-1.amazonaws.com https://media-engine-local-public.s3.eu-west-2.amazonaws.com https://media-engine-local-private.s3.eu-west-2.amazonaws.com https://media-engine-dev-public.s3.eu-west-2.amazonaws.com https://media-engine-staging-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://*.stripe.com https://gravatar.com https://*.cloudfront.net; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'nonce-CHlvyaQDIRMCORqAeD5dgOySiISsqb7V' 'self' 'unsafe-eval' https://*.psychologytools.com https://cdn.jsdelivr.net/npm/sweetalert2@11 https://checkout.stripe.com https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com; script-src-attr 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net/npm/sweetalert2@11 https://psychologytools-com-local.s3.eu-west-1.amazonaws.com https://media-engine-local-public.s3.eu-west-2.amazonaws.com https://media-engine-local-private.s3.eu-west-2.amazonaws.com https://media-engine-dev-public.s3.eu-west-2.amazonaws.com https://media-engine-staging-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com; script-src-elem 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net/npm/sweetalert2@11 https://a.omappapi.com https://cdn.jsdelivr.net/npm/choices.js@9.0.1/public/assets/scripts/choices.min.js https://plausible.io; style-src 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net/npm/sweetalert2@11; style-src-attr 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net/npm/sweetalert2@11; style-src-elem 'self' 'unsafe-inline' https://*.psychologytools.com https://fonts.googleapis.com https://cdn.jsdelivr.net/npm/sweetalert2@11 https://a.omappapi.com https://cdn.jsdelivr.net/npm/choices.js@9.0.1/public/assets/styles/choices.min.css https://fonts.bunny.net; 1 default-src 'self'; script-src 'self' 'nonce-MySd23INaboECeDwjfInAQ' 'strict-dynamic'; style-src 'self' 'unsafe-inline'; img-src *; connect-src *; frame-src *; object-src 'none'; form-action 'self'; base-uri 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com portal.bulkgate.com *.boxnow.gr *.everypay.gr *.fontawesome.com https://fonts.bunny.net v2.zopim.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com portal.bulkgate.com *.boxnow.gr *.everypay.gr www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com portal.bulkgate.com *.boxnow.gr *.everypay.gr www.google.com analytics.skroutz.gr skroutza.skroutz.gr www.facebook.com go.linkwi.se www.pinterest.com gr.pinterest.com tpc.googlesyndication.com *.facebook.com *.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io portal.bulkgate.com *.boxnow.gr *.everypay.gr ping.contactpigeon.com https://firebasestorage.googleapis.com www.facebook.com www.google.gr v2.zopim.com connect.facebook.net linkedin.com google-analytics.com analytics.skroutz.gr skroutza.skroutz.gr ct.pinterest.com *.glamipixel.com glamipixel.com *.glami.gr www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com maps.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com portal.bulkgate.com *.gstatic.com *.boxnow.gr *.everypay.gr ping.contactpigeon.com *.avada.io *.shopify.com go.linkwi.se analytics.skroutz.gr *.skroutz.gr connect.facebook.net v2.zopim.com www.gstatic.com static.zdassets.com www.google.com https://js.everypay.gr 'self' data: *.zopim.com s.pinimg.com analytics.tiktok.com tpc.googlesyndication.com www.contactpigeon.com *.glamipixel.com glamipixel.com *.glami.gr js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com portal.bulkgate.com *.gstatic.com *.boxnow.gr ping.contactpigeon.com *.fontawesome.com https://fonts.bunny.net www.googletagmanager.com www.contactpigeon.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com portal.bulkgate.com *.gstatic.com *.boxnow.gr *.everypay.gr ping.contactpigeon.com https://get.geojs.io *.avada.io 'unsafe-inline' data: 'unsafe-inline' wss: stats.g.doubleclick.net 'unsafe-inline' ekr.zdassets.com 'unsafe-inline' maps.googleapis.com gtmss.izyshoes.gr www.facebook.com ct.pinterest.com analytics.tiktok.com 'unsafe-inline' ekr.zendesk.com region1.analytics.google.com socialplugin.facebook.net *.facebook.com web.facebook.com *.contactpigeon.com *.googlesyndication.com www.google.com googleads.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.contactpigeon.com 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.cloudflare.com *.gstatic.com *.iconscout.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net pay.ozow.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.facebook.com *.facebook.net https://www.google.com/ secure.authorize.net test.authorize.net www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es cdn.dnky.co webchat.dotdigital.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com https://vars.hotjar.com/ www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com *.facebook.net https://www.magezon.com ozow-live-cdn.s3.eu-west-1.amazonaws.com *.cloudflare.com https://stats.g.doubleclick.net/ *.cloudfront.net s.ytimg.com *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.yotpo.com *.linkedin.com t.co *.google.com *.google.co.za *.adsymptotic.com *.adroll.com *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com *.facebook.com *.facebook.net *.googleapis.com *.google.com *.gstatic.com *.avada.io *.google.com/ *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.twitter.com secure.authorize.net test.authorize.net js.braintreegateway.com *.cardinalcommerce.com video.google.com *.payments-amazon.com *.payments-amazon.de *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.yotpo.com https://www.gstatic.com/ *.paypal.com www.youtube.com sibforms.com *.addtoany.com *.googleoptimize.com static.zdassets.com *.hotjar.com *.roomvo.com *.trustpilot.com connect.facebook.net snap.licdn.com static.ads-twitter.com *.adroll.com d.adroll.mgr.consensu.org player.vimeo.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.addtoany.com *.cloudflare.com *.iconscout.com *.bootstrapcdn.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com sibforms.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com *.facebook.com *.facebook.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.cloudflare.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.yotpo.com *.zdassets.com *.zendesk.com roomvo.com wss://widget-mediator.zopim.com/ *.google-analytics.com stats.g.doubleclick.net cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com data: *.facebook.com *.onetrust.com *.cookielaw.org *.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ data: *.google.com *.addthis.com *.tagembed.com *.flipsnack.com *.facebook.com bt.signifyd.com:11103 *.walls.io *.onetrust.com *.cookielaw.org *.equalada-api.herokuapp.com *.herokuapp.com *.doubleclick.net maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.cardinalcommerce.com *.facebook.com *.google.com www.google.co.in mcusercontent.com *.onetrust.com *.cookielaw.org *.clarity.ms *.googletagmanager.com *.google-analytics.com c.bing.com magefan.com cm.magefan.com https://img.youtube.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com data: *.cardinalcommerce.com *.facebook.net *.zassets.com static.zdassets.com *.google.com walls.io *.g.doubleclick.net *.moatads.com *.addthisedge.com *.addthis.com *.tagembed.com *.ccdc02.com chimpstatic.com *.authorize.net mc.us5.list-manage.com *.mailchimp.com *.zopim.com *.onetrust.com *.cookielaw.org *.hotjar.com *.smartlook.com *.clarity.ms *.googletagmanager.com maps.googleapis.com chart.googleapis.com s7.addthis.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com data: *.mailchimp.com *.onetrust.com *.cookielaw.org *.fontawesome.com maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com data: *.zdassets.com *.onetrust.com *.cookielaw.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com data: wss: *.zendesk.com *.zopim.com widget-mediator.zopim.com stats.g.doubleclick.net bam-cell.nr-data.net *.authorize.net bt.signifyd.com:11103 *.onetrust.com *.cookielaw.org bam.nr-data.net vc.hotjar.io *.clarity.ms *.demdex.net *.cardinalcommerce.com *.google.com manager.eu.smartlook.cloud maps.googleapis.com chart.googleapis.com ekr.zdassets.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://dev.visualwebsiteoptimizer.com https://global.oktacdn.com https://px.ads.linkedin.com https://static.hsappstatic.net https://api.hubapi.com https://i.clarity.ms https://surveystats.hotjar.io https://pagead2.googlesyndication.com https://bat.bing.com https://previewtac.oktapreview.com https://tac.okta.com https://www.facebook.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.google.com https://analytics.google.com https://bam.nr-data.net wss://ws.hotjar.com https://content.hotjar.io https://api.global.chalet.8x8.com https://hubspot-forms-static-embed.s3.amazonaws.com https://forms.hsforms.com https://youtube.com https://www.google-analytics.com https://www.clarity.ms https://events.hotjar.io https://www.youtube.com https://region1.google-analytics.com https://api.hsforms.com https://www.googletagmanager.com; font-src 'self' https://consentcdn.cookiebot.com https://www.googletagmanager.com https://youtube.com https://www.youtube.com; frame-src 'self' https://consentcdn.cookiebot.com https://www.googletagmanager.com https://youtube.com; object-src 'self' blob:; script-src 'self' 'report-sample' 'unsafe-inline' blob: https://www.googletagmanager.com https://dev.visualwebsiteoptimizer.com https://code.jquery.com https://consent.cookiebot.com https://static.hotjar.com https://js.hs-scripts.com https://snap.licdn.com https://bat.bing.com https://connect.facebook.net https://www.google-analytics.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hs-banner.com https://www.clarity.ms https://script.hotjar.com https://scripts.clarity.ms https://previewtac.oktapreview.com https://tac.okta.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://bam.nr-data.net https://js.hsforms.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://global.oktacdn.com https://unpkg.com mdbootstrap.com; style-src 'self' 'report-sample' 'unsafe-inline' blob: data: cdnjs.cloudflare.com fonts.googleapis.com https://unpkg.com mdbootstrap.com use.fontawesome.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self'; upgrade-insecure-requests; block-all-mixed-content; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://ajax.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://challenges.cloudflare.com https://c.sproutvideo.com https://cdn.heyzine.com https://d1ajyp3swh7ygp.cloudfront.net https://dvtuw1sdeyetv.cloudfront.net https://fundraising.mentalhealth-uk.org https://heyzine.com https://hzstats.com https://maps.googleapis.com https://mentalhealth-uk.org https://mentalhealthuk.tfaforms.net https://pagead2.googlesyndication.com https://platform.twitter.com https://player.vimeo.com https://s3.amazonaws.com https://static.doubleclick.net https://static.hotjar.com https://td.doubleclick.net https://donorbox.org https://js.stripe.com https://checkout.stripe.com https://script.hotjar.com https://*.googletagmanager.com https://*.googleadservices.com https://*.doubleclick.net https://*.tfaforms.net https://www.tfaforms.com https://connect.facebook.net https://www.google.com https://www.gstatic.com https://unpkg.com https://videos.sproutvideo.com https://www.youtube-nocookie.com https://www.youtube.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' data: https://ajax.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://challenges.cloudflare.com https://c.sproutvideo.com https://cdn.heyzine.com https://d1ajyp3swh7ygp.cloudfront.net https://dvtuw1sdeyetv.cloudfront.net https://fundraising.mentalhealth-uk.org https://heyzine.com https://hzstats.com https://maps.googleapis.com https://mentalhealth-uk.org https://mentalhealthuk.tfaforms.net https://pagead2.googlesyndication.com https://platform.twitter.com https://player.vimeo.com https://s3.amazonaws.com https://static.doubleclick.net https://static.hotjar.com https://td.doubleclick.net https://donorbox.org https://js.stripe.com https://checkout.stripe.com https://script.hotjar.com https://*.googletagmanager.com https://*.googleadservices.com https://*.doubleclick.net https://*.tfaforms.net https://www.tfaforms.com https://connect.facebook.net https://www.google.com https://www.gstatic.com https://unpkg.com https://videos.sproutvideo.com https://www.youtube-nocookie.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://c.sproutvideo.com https://cdnc.heyzine.com https://d1ajyp3swh7ygp.cloudfront.net https://dvtuw1sdeyetv.cloudfront.net https://fonts.googleapis.com https://fundraising.mentalhealth-uk.org https://labs.os.uk https://maxcdn.bootstrapcdn.com https://mentalhealth-uk.org https://mentalhealthuk.tfaforms.net https://unpkg.com https://www.tfaforms.com https://www.youtube-nocookie.com https://www.youtube.com; img-src 'self' data: https://*.exactdn.com https://euc7zxtct58.exactdn.com https://s3-eu-west-2.amazonaws.com https://s3.amazonaws.com https://imgsct.cookiebot.com https://api.os.uk https://cdn-thumbnails.sproutvideo.com https://cdnc.heyzine.com https://challenges.cloudflare.com https://d1ezvg7* 1 default-src 'self' ; script-src 'self' 'unsafe-eval' https://analitica.dacoruna.gal 'nonce-aUIKeq4wLYP7Hw1uBOwxhQAAAME'; img-src 'self' data: blob: ; frame-src 'self' ; style-src 'self' 'unsafe-inline'; font-src 'self' ; connect-src 'self' https://analitica.dacoruna.gal ; object-src 'self' ; frame-ancestors 'self' ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.snapchat.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.demdex.net/ www.facebook.com platform.twitter.com tst.kaptcha.com c.sandbox.paypal.com *.tieks.com *.snapchat.com *.doubleclick.net *.pinterest.com ssl.kaptcha.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://*.taboola.com https://*.linkedin.com https://*.licdn.com https://*.reddit.com https://*.redditstatic.com https://*.attentivemobile.com https://*.attn.tv https://metrics.tieks.com https://*.clarity.ms https://*.quora.com https://*.bing.net widget.freshworks.com m2epro.freshdesk.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com z.moatads.com platform.twitter.com static.zdassets.com *.zopim.com *.facebook.net *.pinimg.com *.yimg.com sc-static.net *.ads-twitter.com *.doubleclick.net *.newrelic.com *.nr-data.net *.adobedtm.com *.queue-it.net *.bing.com *.tiktok.com *.snapchat.com *.pinterest.com unpkg.com *.equalweb.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com unsafe-inline assets.braintreegateway.com unpkg.com access.equalweb.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com tieks.com *.tieks.com static.zdassets.com *.rackcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://*.taboola.com https://*.linkedin.com https://*.licdn.com https://*.reddit.com https://*.redditstatic.com https://*.attentivemobile.com https://*.attn.tv https://metrics.tieks.com https://*.clarity.ms https://*.quora.com https://*.bing.net widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com wss://widget-mediator.zopim.com/ *.zendesk.com *.zdassets.com *.tieks.com maps.googleapis.com *.yimg.com *.pinterest.com *.snapchat.com *.doubleclick.net *.nr-data.net www.facebook.com bat.bing.com *.tiktok.com pagead2.googlesyndication.com *.google-analytics.com analytics.pangle-ads.com *.equalweb.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-6fead1d2-ba44-469d-af4d-835376d5a1da' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.ottocasino.se https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.ottocasino.se/eum-collector/report/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * test.saferpay.com www.saferpay.com saferpay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * test.saferpay.com www.saferpay.com saferpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io github.blog *.bird.eu https://firebasestorage.googleapis.com https://cdn.cookielaw.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com test.saferpay.com www.saferpay.com saferpay.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com jquery.sellxed.com *.avada.io https://cdn.cookielaw.org js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://hello.myfonts.net assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io https://cdn.cookielaw.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com *.google-analytics.com *.facebook.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; report-uri https://nz14bhs2.uriports.com/reports/report; report-to default 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://analytics.ahrefs.com https://static.reo.dev https://static.hsappstatic.net https://snap.licdn.com https://vercel.live https://www.googletagmanager.com https://*.google.com https://*.doubleclick.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' https://last9.ghost.io https://last9.github.io https://prod-files-secure.s3.us-west-2.amazonaws.com https://cdn.simpleicons.org https://www.gravatar.com https://i.ytimg.com https://images.unsplash.com data: https://px.ads.linkedin.com https://www.google.es https://www.google.it https://www.google.ru https://www.google.fi https://www.google.de https://www.google.no https://www.google.fr https://www.google.pl https://www.google.lk https://www.google.dk https://www.google.ro https://*.google.com https://*.google.co.in https://*.doubleclick.net; connect-src 'self' https://analytics.ahrefs.com https://api.reo.dev https://px.ads.linkedin.com https://analytics.google.com https://www.google-analytics.com https://pagead2.googlesyndication.com https://region1.google-analytics.com https://www.google.pl https://*.google.com https://*.google.co.in; frame-src 'self' https://meetings.hubspot.com https://www.youtube.com https://www.loom.com https://vercel.live https://www.googletagmanager.com https://td.doubleclick.net; font-src 'self' https://fonts.gstatic.com data:; report-to csp-endpoint; report-uri https://last9.io/api/csp-report/ 1 font-src *.force.com https://content.vistana.com 'self' https://stats.g.doubleclick.net https://www.vistana.com siteintercept.qualtrics.com https://cdn.cookielaw.org https://privacy-portal-mvwc.my.onetrust.com https://www.ibm.com https://tmvcaboundhotels.hts.hopper.com *.marriottvacationclub.com https://c.az.contentsquare.net https://mormarriottvacationsp.112.2o7.net https://placekitten.com https://sv.marriottvacationclubs.com https://marriottownershipres.tt.omtrdc.net https://assets.adobedtm.com https://*.contentsquare.com https://videos.marriottvacations.com https://analytics.google.com https://fonts.gstatic.com/ https://dpm.demdex.net blob: https://*.pingone.com *.siteintercept.qualtrics.com https://*.pcdn.co https://mvcomdev1-mvw.cs200.force.com https://*.analytics.google.com https://pagead2.googlesyndication.com https://voa-reservation.vacationclub.com https://content.securedvisit.com https://content-qa-vistana.com https://cm.everesttech.net https://*.omtrdc.net https://siteintercept.qualtrics.com https://mvwvo--exppod2--c.sandbox.vf.force.com https://s32171.pcdn.co *.kampyle.com *.doubleclick.net https://privacy-portal-mvwc-cdn.my.onetrust.com https://smetrics.marriottvacationclub.com *.clicktale.net https://geolocation.onetrust.com https://*.demdex.net https://players.brightcove.net https://mordev.112.2o7.net https://*.adobe.com https://s20426.pcdn.co https://www.google.co.in https://bat.bing.com https://unsplash.it https://cdn.tt.omtrdc.net https://www.googletagmanager.com https://www.google-analytics.com https://c.la1-c1-ia4.salesforceliveagent.com *.salesforce.com data:; report-to sfdc-csp-ep; report-uri https://mvwvo.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4x000006sQxi&networkId=0DM4x000000dPWp&type=communities 1 font-src *.googleapis.com *.gstatic.com data: *.bglobale.com *.global-e.com https://az693360.vo.msecnd.net *.typekit.net *.typenetwork.com https://plugin-magento-ui.glopalservice.com *.klarnacdn.net *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.bglobale.com *.global-e.com *.abtasty.com *.abstasty.net csxd.izipizi.com *.cloudfront.net *.criteo.com *.criteo.net *.facebook.com *.facebook.net *.salecycle.com *.salecycle.net *.tiktok.com *.tiktok.net *.hipay-tpp.com *.hipay.com *.paypal.com *.klarna.com www.youtube.com https://www.googletagmanager.com/ www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * uat-secure.pointspay.com secure.pointspay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.bglobale.com *.global-e.com *.3lift.com *.360yield.com *.adform.com *.adnxs.com *.assets.sc-trc.com *.nr-data.net *.bing.com *.bidswitch.net *.casalemedia.com *.clarity.ms *.contentsquare.net *.criteo.com *.doubleclick.com *.doubleclick.net *.facebook.com *.facebook.net *.ivitrack.com *.izipizi.com *.krxd.net *.media.net *.mediavine.com *.omnitagjs.com *.outbrain.com *.pubmatic.com *.salecycle.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.com *.teads.tv *.thebrighttag.com *.tiktok.com *.tiktok.net *.tremorhub.com *.vo.msecnd.net.com *.yahoo.com *.yieldlab.net *.yieldmo.com *.rubiconproject.com *.adform.net *.sync.com *.emxdgt.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.adobedtm.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com uat-secure.pointspay.com secure.pointspay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bglobale.com *.global-e.com *.abtasty.com *.abstasty.net acsbapp.com *.beyable.com https://az693360.vo.msecnd.net https://tag.beyable.com *.bing.com *.clarity.ms *.criteo.com *.criteo.net *.contentsquare.com *.privacy-center.org *.doubleclick.net *.elitrack.com *.facebook.com *.facebook.net *.fittingbox.com *.fittingbox.net *.hotjar.com *.jquery.com *.msecnd.net *.salecycle.com *.salecycle.net *.rr.skeepers.io t.contentsquare.net *.tiktok.com *.vimeo.com *.tiktok.net *.windows.net *.zdasets.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com https://maps.googleapis.com/maps/api/mapsjs *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.cdn-apple.com izipizi.my.join-stories.com *.klarna.com *.klarnacdn.net x.klarnacdn.net www.youtube.com player.vimeo.com *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com uat-secure.pointspay.com secure.pointspay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bglobale.com *.global-e.com *.typekit.net *.zdassets.com *.typenetwork.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.hipay.com *.klarnacdn.net *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com data: mpsnare.iesnare.com *.amazonaws.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.abtasty.com *.abstasty.net *.acsbapp.com bat.bing.com https://az693360.vo.msecnd.net *.bing.com *.clarity.ms *.contentsquare.net *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.google.fr *.google-analytics.com *.googlesyndication.com *.hotjar.io *.izipizi.com *.privacy-center.org *.salecycle.com wss://ws.salecycle.com *.sentry.io *.rr.skeepers.io *.tiktok.com *.tiktok.net *.vimeo.com *.windows.net *.zdassets.com *.zendesk.com *.zopim.com https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com https://maps.googleapis.com/maps/api/mapsjs *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net cdn.plyr.io noembed.com *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://nominatim.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com uat-secure.pointspay.com secure.pointspay.com maps.googleapis.com 'self' 'unsafe-inline'; child-src blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.fontawesome.com *.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.facebook.com *.securetrading.net * 1merchantacsstag.cardinalcommerce.com payments.securetrading.net *.cardinalcommerce.com *.trustpayments.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.google.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.vimeo.com *.trustpilot.com *.hotjar.com *.facebook.com *.google.com *.livechatinc.com *.pinterest.co.uk *.trustpayments.com *.googletagmanager.com *.dropbox.com account.fetchify.com *.klarna.com * *.securetrading.net brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com *.secure.checkout.visa.com *.cardinalcommerce.com pay.google.com thm.visa.com *.mastercard.com *.weltpixel.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.google.com *.google.co.uk *.doubleclick.net *.facebook.com *.livechatinc.com cladcodecking.co.uk *.cladcodecking.co.uk *.clarity.ms *.bing.com *.googletagmanager.com *.visualwebsiteoptimizer.com *.bing.net *.cladco.co.uk *.files-text.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://cc-cdn.com *.disqus.com *.klarna.com *.klarnaevt.com *.klarnacdn.net gstatic.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.klaviyo.com *.google-analytics.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.googletagmanager.com *.chimpstatic.com *.trustpilot.com *.hotjar.com *.facebook.net *.bing.com *.livechatinc.com *.google.com *.google-analytics.com *.clarity.ms *.klarnaservices.com *.elfsight.com *.zoominfo.com *.pinterest.com *.tiktok.com googletagmanager.com universe-static.elfsightcdn.com *.cookie-script.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.dropbox.com cc-cdn.com https://cc-cdn.com *.disqus.com https://cdn.jsdelivr.net *.klarna.com *.klarnacdn.net x.klarnacdn.net webservices.securetrading.net cdn.eu.trustpayments.com songbirdstag.cardinalcommerce.com *.trustpayments.com *.securetrading.net pay.google.com *.secure.checkout.visa.com *.cardinalcommerce.com *.mastercard.com *.googleadservices.com *.redditstatic.com *.reddit.com *.ads-twitter.com *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.bootstrapcdn.com *.gstatic.com *.googleapis.com *.klarnacdn.net https://static.klaviyo.com cc-cdn.com https://cdn.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.fontawesome.com *.hotjar.io *.hotjar.com *.craftyclicks.co.uk *.bing.com *.google-analytics.com *.doubleclick.net *.googleadservices.com *.clarity.ms *.google.co.uk *.klarna.com *.google.com *.visualwebsiteoptimizer.com *.elfsight.com *.facebook.com *.tiktokw.us *.bing.net *.googlesyndication.com *.livechatinc.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com o402164.ingest.sentry.io *.sentry.io *.cardinalcommerce.com google.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.klaviyo.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://portal.envisagedigital.co.uk/api/website/brtj8tbu2q/report-uri; report-to report-endpoint; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-f7dda3f75a804fff8071d9b51522266b' https://myuthealthhouston.org 'self' https://hcaptcha.uth.edu https://hcaptchatest.uth.edu;img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://myuthealthhouston.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 base-uri 'self'; default-src 'none'; child-src 'self'; connect-src 'self' https://*.google-analytics.com https://sentry.io https://stats.g.doubleclick.net https://www.facebook.com; font-src 'self' https://fonts.gstatic.com https://hello.myfonts.net data:; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com blob: data:; media-src 'none'; object-src 'self' blob:; manifest-src 'self'; script-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://browser.sentry-cdn.com https://www.youtube.com https://s.ytimg.com https://connect.facebook.net 'unsafe-inline'; style-src 'self' https://fonts.googleapis.com https://hello.myfonts.net 'unsafe-inline'; report-uri https://o115950.ingest.sentry.io/api/5442953/security/?sentry_key=2d010088d19e4231bfaafcd8c84034a0&sentry_release=&sentry_environment=live; upgrade-insecure-requests 1 script-src 'strict-dynamic' 'nonce-6v95z2knzzPx1ZMF0eGxYw==' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://static.klaviyo.com https://embed.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com t.themarketer.com cdn1.themarketer.com *.klaviyo.com https://cdn-cookieyes.com https://embed.tawk.to https://www.google.ro https://www.googleadservices.com https://analytics.tiktok.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io t.themarketer.com cdn1.themarketer.com https://static.cloudflareinsights.com https://web-sdk.smartlook.com https://web-sdk.smartlook.com/es6 https://web-sdk.smartlook.com/recorder.js https://*.smartlook.com https://*.smartlook.cloud https://cdn.aqurate.ai https://www.google-analytics.com https://www.googleadservices.com https://region1.google-analytics.com *.klaviyo.com player.vimeo.com *.braintreegateway.com fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdn-cookieyes.com https://cdn.cookie-script.com www.google.ro *.clarity.ms https://cdn.roomvo.com https://analytics.tiktok.com https://analytics.tiktok.com/i18n/pixel/ https://analytics.tiktok.com/i18n/pixel/static/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net t.themarketer.com cdn1.themarketer.com https://static.klaviyo.com https://embed.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com ekr.zdassets.com/ https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com https://region1.google-analytics.com https://www.googleadservices.com https://www.gstatic.com https://www.googletagmanager.com https://cdn.aqurate.ai www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klaviyo.com *.braintreegateway.com *.tawk.to *.cookieyes.com https://web-sdk.smartlook.com https://*.smartlook.com https://*.smartlook.cloud *.clarity.ms https://analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; report-uri https://www.nt-ware.com/contentsecuritypolicyreport/index.php; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.cloudflare.com *.trustedshops.com *.joemerino.com *.google.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com speedsize.com *.speedsize.com *.cookiebot.com *.easysize.me *.pinterest.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://www.mollie.com https://redchamps.com speedsize.com *.speedsize.com *.cloudflare.com *.klarna.com *.ytimg.com *.usercentrics.eu *.bing.com *.joemerino.com *.google.com *.google.co.in *.clarity.ms *.googletagmanager.com *.pinterest.com *.d1pna5l3xsntoj.cloudfront.net *.trustedshops.com *.popupsmart.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.pinimg.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.gstatic.com js.mollie.com speedsize.com *.speedsize.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.adyen.com *.cookiebot.com *.helloretail.com *.cloudfront.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.com *.pinterest.com *.mollie.com *.sendcloud.sc *.avada.io *.yotpo.com *.etrusted.com *.etrusted.site *.googletagmanager.com *.braintreegateway.com *.glinkseclin.com glinkseclin.com *.windows.net *.robinhq.com *.msecnd.net *.easysize.me *.g1980843351.co g1980843351.co *.googleadservices.com *.cloudfront.net *.hotjar.com *.clarity.ms *.bing.com *.pingdom.net geotargetly-api-2.com *.popupsmart.com *.doubleclick.net *.pinimg.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com sst.joemerino.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.klaviyo.com sc-static.net *.snapchat.com unpkg.com *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com speedsize.com *.speedsize.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.cdn.popupsmart.com *.d1pna5l3xsntoj.cloudfront.net *.adobe.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com speedsize.com *.speedsize.com *.cloudflare.com *.glinkseclin.com wss://glinkseclin.com *.visualstudio.com *.doubleclick.net *.clarity.ms *.pingdom.net *.cookiebot.com *.eu01.nr-data.net *.pinterest.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinimg.com sc-static.net *.snapchat.com *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.joemerino.com/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com securepayments.sandbox.paypal.com securepayments.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.googleapis.com https://*.gstatic.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com https://*.gstatic.com *.google.com/ https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' bam.nr-data.net js-agent.newrelic.com tags.srv.stackadapt.com snap.licdn.com connect.facebook.net www.google-analytics.com www.googletagmanager.com googleads.g.doubleclick.net translate.googleapis.com prod.ally.ac a.omappapi.com a.opmnstr.com yoda.unifyed.com www.googleadservices.com js.adsrvr.org translate.google.com cdn01.basis.net translate-pa.googleapis.com cdn.gtranslate.net tags.srv.stackadapt.com *.google.com; style-src 'self' 'unsafe-inline' cloud.typography.com tags.srv.stackadapt.com a.omappapi.com prod.ally.ac translate.googleapis.com fonts.gstatic.com fonts.googleapis.com www.gstatic.com; img-src 'self' my.unifyed.com px.ads.linkedin.com www.gstatic.com www.facebook.com www.google.com pixel.sitescout.com www.google-analytics.com i.ytimg.com i.vimeocdn.com translate.google.com translate.googleapis.com fonts.gstatic.com ad.doubleclick.net manageimages-prod.s3.amazonaws.com data:; frame-src 'self' insight.adsrvr.org *.doubleclick.net www.youtube.com www.youtube-nocookie.com pixel.sitescout.com player.vimeo.com www.facebook.com; frame-ancestors 'self' insight.adsrvr.org *.doubleclick.net www.youtube.com www.youtube-nocookie.com pixel.sitescout.com player.vimeo.com www.facebook.com; child-src 'self' insight.adsrvr.org *.doubleclick.net www.youtube.com www.youtube-nocookie.com pixel.sitescout.com player.vimeo.com www.facebook.com; font-src 'self' themes.googleusercontent.com fonts.gstatic.com; connect-src 'self' cloud.typography.com tags.srv.stackadapt.com api.omappapi.com prod.ally.ac translate.googleapis.com yoda.unifyed.com www.google-analytics.com stats.g.doubleclick.net bam.nr-data.net play.google.com www.facebook.com https://px.ads.linkedin.com/wa/; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://cwi.shell.451.io/ https://cwi2.shell.451.io/ https://embed-forms.451.io/ https://js.hubspot.com/ https://maps.googleapis.com/ https://25livepub.collegenet.com/ https://ai.ocelotbot.com/ https://ajax.googleapis.com/ajax/libs/ https://analytics.tiktok.com/ https://analytics.tiktok.com/i18n/pixel/events.js https://api3.libcal.com/ https://cdn.jsdelivr.net/npm/ https://cdn.jsdelivr.net/gh/snowplow/ https://cdnjs.cloudflare.com/ajax/libs/ https://collector-16905.us.tvsquared.com/tv2track.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/ https://cwi.edu/ https://cwidaho.libanswers.com/ https://embed.financialaidtv.com/ https://embed.ocelotbot.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027274136/ https://googleads.g.doubleclick.net/pagead/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027274136/ https://h5p.org/ https://imageserver.ebscohost.com/ https://js-agent.newrelic.com/ https://js.hs-analytics.net/analytics/1692888000000/21023521.js https://js.hs-analytics.net/analytics/ https://js.hs-banner.com/ https://js.hs-scripts.com/21023521.js https://js.hsadspixel.net/fb.js https://js.hscollectedforms.net/ https://js.hsforms.net/ https://js.hscta.net/cta/ https://cta-service-cms2.hubspot.com/ https://lgapi.libapps.com/ https://live.cwid7.lndo.site/ https://us2.siteimprove.com/ https://*.clarity.ms/ https://wufoo.com/scripts/embed/form.js https://www.google-analytics.com/ https://www.google.com/jsapi/ https://www.google.com/recaptcha/ https://www.google.com/pagead/ https://translate.google.com/ https://translate.googleapis.com/ https://dev.visualwebsiteoptimizer.com/ https://www.googletagmanager.com/ https://www.gstatic.com/ https://www.googleadservices.com/ https://unpkg.com/ https://*.googlesyndication.com/ https://app.vwo.com/ https://static.kuula.io/ https://use.typekit.net/ https://js.stripe.com/ https://snap.licdn.com/ https://c.lytics.io/ https://static.ads-twitter.com/ https://secure.qgiv.com/ https://bat.bing.com/ https://search.cwi.edu/ https://browsersync.cwidaho.ddev.site/ https://translate-pa.googleapis.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://cwi.edu https://ai.ocelotbot.com https://fonts.googleapis.com https://p.typekit.net https://stackpath.bootstrapcdn.com https://use.typekit.net https://www.gstatic.com https://app.vwo.com https://c.lytics.io https://search.cwi.edu/ https://api.lytics.io/; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.google-analytics.com https://analytics.google.com https://*.451.io/ https://*.hsforms.com https://api.hubapi.com/ https://cta-service-cms2.hubspot.com/ https://25livepub.collegenet.com https://ai.ocelotbot.com https://analytics.tiktok.com https://api3.libcal.com https://bam.nr-data.net https://*.siteimprove.com https://forms.hscollectedforms.net https://hubspot-forms-static-embed.s3.amazonaws.com https://live.cwid7.lndo.site https://*.clarity.ms https://*.doubleclick.net https://use.typekit.net https://pubsub.googleapis.com https://translate.googleapis.com/ https://www.facebook.com https://www.googletagmanager.com https://adservice.google.com https://www.google.com https://*.googlesyndication.com https://maps.googleapis.com https://*.visualwebsiteoptimizer.com/ https://px.ads.linkedin.com/ https://search.cwi.edu/ https://bat.bing.com/; font-src 'self' data: https://fonts.gstatic.com https://stackpath.bootstrapcdn.com https://use.typekit.net; frame-src 'self' https://cwi.messenger.451.io https://cwi.discoveredu.ai https://cwi2.messenger.451.io https://ctl.h5p.com https://*.hsforms.com https://embed-forms.451.io https://cwi.maps.arcgis.com https://cwi.wufoo.com https://cwilibrary.wufoo.com https://cwidaho.libanswers.com https://docs.google.com https://e.issuu.com https://embed.ocelotbot.com https://maps.google.com https://player.vimeo.com https://www.facebook.com https://www.google.com https://www.youtube.com https://yoshki.com https://*.doubleclick.net https://25livepub.collegenet.com https://*.googlesyndication.com https://www.googletagmanager.com https://creatorapp.zohopublic.com https://creator.zohopublic.com https://app.vwo.com https://kuula.co/ https://cwidaho.viewin360.co/ https://js.stripe.com/ https://cwi.bolt-discovery.451.io/ https://cwi2.bolt-discovery.451.io/ https://c.lytics.io/ https://secure.qgiv.com/; img-src https: data:; manifest-src 'self'; media-src 'self' data:; report-uri https://64dcbe2ca068cd9821c1af0b.endpoint.csper.io?v=41; worker-src 'self' blob:; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://static.addtoany.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://fonts.bunny.net; img-src 'self' https://wpassets.ncwit.org https://www.google-analytics.com https://secure.gravatar.com data:; font-src 'self' https://fonts.gstatic.com https://use.typekit.net https://fonts.bunny.net data:; connect-src 'self' https://analytics.google.com; frame-src 'self' https://www.youtube.com https://static.addtoany.com https://www.google.com https://academic-alliance-memberships.softr.app https://ncwit-workforce-members.softr.app; object-src 'none'; 1 default-src 'self'; base-uri 'self'; font-src 'self' https://use.typekit.net fonts.gstatic.com; form-action 'self' https://accounts.google.com/ https://crm.zoho.com/crm/WebToLeadForm https://courses.projectstem.org https://clever.com; frame-src 'self' https://www.google.com https://www.recaptcha.net/recaptcha/api2/ https://player.vimeo.com https://scratch.mit.edu https://videos.projectstem.org https://www.sociablekit.com http://lsrelay-config-production.s3.amazonaws.com http://schools-blocked.s3-website-us-east-1.amazonaws.com https://form.jotform.com https://submit.jotform.com; img-src 'self' data: https://i.vimeocdn.com/video/ https://p.typekit.net https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://googleads.g.doubleclick.net https://code.org; manifest-src 'self'; media-src https://files.projectstem.org https://videos.projectstem.org https://videos.stg.projectstem.site https://player.vimeo.com https://vod-progressive.akamaized.net https://download-video.akamaized.net; object-src 'none'; script-src 'self' 'strict-dynamic' 'unsafe-inline' https://www.google.com/recaptcha/api.js https://player.vimeo.com https://use.typekit.net https://www.googleadservices.com/pagead/conversion.js https://www.googletagmanager.com/gtag/js https://www.gstatic.com/recaptcha/releases/ https://www.recaptcha.net https://projectstem.org 'nonce-0zjNOXQVCgKe7Hr/6WqwhA=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/css2; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net/j/collect https://files.projectstem.org https://docs.projectstem.org https://projectstem.org; worker-src 'self' 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; frame-ancestors 'self'; report-uri https://syonmedia.uriports.com/reports/report; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com data: *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com scontent.* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ display.ugc.bazaarvoice.com *.fontawesome.com assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://852e3dc5-adca-44c7-a08d-70d745bf3d90.sansec.watch/; report-to report-endpoint; 1 font-src *.bootstrapcdn.com *.gstatic.com *.googleapis.com *.paypal.com *.juicer.io/fonts/ *.fontawesome.com https://fonts.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com *.google.com https://plumrocket.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.certcapture.com *.bootstrapcdn.com *.googleapis.com *.paypal.com *.gstatic.com *.paypalobjects.com *.omtrdc.net magefan.com cm.magefan.com *.google.com *.mageside.com mageside.com *.disqus.com *.juicer.io https://img.youtube.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.bootstrapcdn.com *.googleapis.com www.google.com *.paypal.com *.gstatic.com chimpstatic.com freegeoip.net *.ipstack.com *.google.com *.disqus.com *.juicer.io/embed.js cdn.jsdelivr.net services.sheerid.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.bootstrapcdn.com *.googleapis.com *.paypal.com *.gstatic.com *.juicer.io/embed.css cdn.jsdelivr.net *.fontawesome.com https://fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.juicer.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://assets.adoberesources.net https://i.vimeocdn.com https://i.ytimg.com blob: https://pd.w.org https://img.rawpixel.com https://aorta.clickagy.com https://cdn.bizible.com https://www.googletagmanager.com https://cdn.bizibly.com https://www.google.ca https://www.google.com.mx https://www.google.com.br https://www.google.co.in https://www.google.es https://www.google.com.ph https://www.google.com.co https://www.google.com.pr https://www.google.co.uk https://www.google.com.ua https://www.googleadservices.com https://www.google.com.sg https://www.google.cl https://www.google.com.pk https://www.google.com.gh https://www.google.de https://www.google.com.au https://www.google.com.ar https://stats.g.doubleclick.net https://www.google.com.my https://www.google.co.id https://www.google.co.jp https://www.google.com.hk https://www.google.pl https://www.google.sn https://www.google.ru https://www.google.com.kh https://www.google.ie https://www.google.be https://www.google.fr https://www.google.pt https://www.google.co.il https://www.mcg.com https://www.google.com.vn https://www.google.nl https://www.google.ae https://www.google.com.eg https://www.google.am https://www.google.com.et https://cdn.honey.io https://www.google.com.ni https://www.google.com.pe https://www.google.co.nz https://www.google.co.ke https://www.google.com.ng https://www.google.co.za https://www.google.is https://www.google.bg https://www.google.com.tr https://www.google.ch https://www.google.se https://www.google.co.kr https://www.google.com.np https://www.google.sk https://www.google.com.ec https://www.google.hu https://www.google.co.cr https://www.google.al https://www.google.kg https://www.google.com.bd https://www.google.gr https://www.google.com.sa https://www.google.com.qa https://www.google.no https://www.google.kz https://translate.google.com https://www.google.com.sv https://www.google.it https://www.google.com.om https://www.google.iq https://www.google.ee https://www.google.co.th https://www.google.co.ma https://dpm.demdex.net https://www.google.com.na https://www.google.com.kw https://www.google.com.bh https://www.google.com.jm https://www.google.by https://www.google.la https://www.google.com.tj https://www.google.com.tw https://fonts.gstatic.com https://www.google.com.bn https://www.google.com.uy https://www.google.si https://www.google.at https://www.google.bs https://www.google.lk https://www.google.hr https://www.google.com.pg https://www.google.com.pa https://www.google.ge https://googleads.g.doubleclick.net https://www.facebook.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://munchkin.marketo.net https://static.addtoany.com https://assets.adoberesources.net https://www.google.com https://www.gstatic.com https://cdn.jsdelivr.net https://hosting.simplemaps.com https://connect.arlocdn.net https://maxcdn.bootstrapcdn.com https://packages.arlocdn.net https://code.jquery.com https://cdnjs.cloudflare.com https://images.uc.cn https://connect.facebook.net https://www.googletagmanager.com https://tags.clickagy.com https://cdn.bizible.com blob: https://googleads.g.doubleclick.net https://js.zi-scripts.com https://web-sdk.smartlook.com https://www.mcg.com https://api.wire.threatspike.com http://munchkin.marketo.net https://me.kis.v2.scr.kaspersky-labs.com https://secured-pixel.com https://snap.licdn.com https://s.yimg.jp https://cdn.cookielaw.org https://www.google-analytics.com https://sb.scorecardresearch.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://munchkin.marketo.net https://static.addtoany.com https://assets.adoberesources.net https://www.google.com https://www.gstatic.com https://cdn.jsdelivr.net https://hosting.simplemaps.com https://connect.arlocdn.net https://maxcdn.bootstrapcdn.com https://packages.arlocdn.net https://code.jquery.com https://cdnjs.cloudflare.com https://images.uc.cn https://connect.facebook.net https://www.googletagmanager.com https://tags.clickagy.com https://cdn.bizible.com blob: https://googleads.g.doubleclick.net https://js.zi-scripts.com https://web-sdk.smartlook.com https://www.mcg.com https://api.wire.threatspike.com http://munchkin.marketo.net https://me.kis.v2.scr.kaspersky-labs.com https://secured-pixel.com https://snap.licdn.com https://s.yimg.jp https://cdn.cookielaw.org https://www.google-analytics.com https://sb.scorecardresearch.com ; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://p.typekit.net https://use.typekit.net https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://cdn.honey.io https://www.mcg.com https://fonts.googleapis.com https://www.gstatic.com data: ; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://p.typekit.net https://use.typekit.net https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://cdn.honey.io https://www.mcg.com https://fonts.googleapis.com https://www.gstatic.com data: ; font-src 'self' https://use.typekit.net https://cdnjs.cloudflare.com https://fonts.gstatic.com https://www.mcg.com https://r2cdn.perplexity.ai https://cdn.scite.ai https://www.slant.co https://static.shopback.com https://static.hsappstatic.net data:; frame-src 'self' https://static.addtoany.com https://player.vimeo.com https://job-boards.greenhouse.io https://www.youtube.com https://www.google.com https://redirector.menlosecurity.com https://safe.menlosecurity.com https://www.googletagmanager.com https://hemsync.clickagy.com https://gateway.zscaler.net https://vimeo.com blob:; connect-src 'self' https://658-wjs-398.mktoresp.com https://project-hummingbird-hummingbird-websocket-nodejs-de-112831.cloud.adobe.io https://658-wjs-398.mktoutil.com https://yoast.com https://info.mcg.com https://mcghealth.arlo.co https://localhost about https://use.typekit.net https://insights-collector.newrelic.com data: https://www.googletagmanager.com https://analytics.google.com https://ws.zoominfo.com https://js.zi-scripts.com https://aorta.clickagy.com https://data.hockeystack.com https://stats.g.doubleclick.net https://hemsync.clickagy.com https://www.google-analytics.com https://www.googleadservices.com https://region1.analytics.google.com https://www.google.com.ph https://www.google.com.mx https://www.google.cl https://www.google.com.au https://www.google.co.in https://www.google.com.my https://telemetry.adobe.io https://www.google.by https://www.google.com.br https://www.google.ca https://www.google.be https://www.google.fr https://www.google.pt https://www.google.co.uk https://cdn.jsdelivr.net https://www.google.com.co https://www.google.com.hk https://www.google.am https://www.google.com.et https://www.google.de https://www.google.co.za https://www.google.com.eg https://www.google.co.jp https://stats.addtoany.com https://www.google.pl https://www.google.ie https://www.google.com.bd http://658-wjs-398.mktoresp.com https://www.google.com.pr https://www.google.com.pk https://www.google.ae https://www.google.no https://www.google.gr https://www.google.com.sa blob: https://www.mcg.com https://www.google.com.tw https://www.google.com.gh https://www.google.com.ng https://www.google.com.sg https://www.google.ch https://www.google.co.nz https://www.google.hr https://www.google.com.pe https://www.google.nl https://www.google.com.ua https://translate.googleapis.com https://www.google.es https://capig.stape.gl https://www.facebook.com https://clientstream.launchdarkly.com; media-src 'self' https://www.mcg.com https://upload.wikimedia.org; worker-src 'self' blob:; report-uri https://www.mcg.com/wp-json/really-simple-security/v1/csp?rsssl_apitoken=895454071; 1 default-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ ; script-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ 'unsafe-inline' 'unsafe-eval' https://unpkg.com/tailwindcss@%5E1.0/ https://unpkg.com/tailwindcss@^1.0/ https://unpkg.com/trix@1.2.3/ https://cdn.jsdelivr.net/jquery/ https://cdn.jsdelivr.net/momentjs/ https://cdn.jsdelivr.net/npm/daterangepicker/ https://cdn.jsdelivr.net/npm/ace-builds@1.43.1/ https://cdn.jsdelivr.net/npm/ace-builds@1.43.3/ https://a.slack-edge.com https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ https://cmp.osano.com https://snippet.maze.co https://challenges.cloudflare.com https://ajax.cloudflare.com/cdn-cgi/scripts/ https://ajax.aspnetcdn.com https://appsforoffice.microsoft.com https://cdn.amplitude.com https://js.stripe.com ; style-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ 'unsafe-inline' https://unpkg.com/tailwindcss@%5E1.0/ https://unpkg.com/tailwindcss@^1.0/ https://unpkg.com/trix@1.2.3/ https://cdn.jsdelivr.net/npm/daterangepicker/ https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com/bootstrap/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://use.fontawesome.com https://static.licdn.com https://a.slack-edge.com https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ https://assets-cdn.maze.co ; img-src * data: blob: ; font-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://use.fontawesome.com https://a.slack-edge.com https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ https://assets-cdn.maze.co https://i.s-microsoft.com/fonts/ ; media-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ data: https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ https://cdn.mycurricula.com ; connect-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ data: blob: https://cdn.plyr.io https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ https://tattle.api.osano.com https://prompts.maze.co https://graph.microsoft.com https://browser-intake-datadoghq.com https://cdn.jsdelivr.net/codemirror.spell-checker/ wss://sat-ws.mycurricula.com https://sr-client-cfg.amplitude.com https://api-sr.amplitude.com https://api2.amplitude.com/2/httpapi https://api.eu.amplitude.com/2/httpapi ; worker-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ blob: ; frame-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ https://breach-notice.com https://businessnotice.org https://databoxonline.com https://electronic-hr.com https://emailtransaction.com https://employee-services.org https://feedback-collect.com https://filesharingnow.com https://fraud-assistance.com https://governmentnotice.org https://invite-meeting.com https://mailbox-quota.com https://news-article.com https://notificationservices.org https://passwordsnotification.com https://payment-process.com https://securelinkedin.com https://security-updater.com https://securitynotifications.org https://mycurricula.com https://alerts.mycurricula.com https://phish.mycurricula.com https://t.maze.co https://challenges.cloudflare.com https://js.stripe.com https://www.youtube.com https://player.vimeo.com ; manifest-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ https://s3.amazonaws.com/media.mycurricula.com/ https://media.mycurricula.com.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.mycurricula.com/ https://s3.amazonaws.com/media.aws-cdn/ https://media.aws-cdn.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/media.aws-cdn/ https://s3.amazonaws.com/aware-production/ https://aware-production.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/aware-production/ https://s3.amazonaws.com/curricula-phishing/ https://curricula-phishing.s3.amazonaws.com https://s3.us-east-1.amazonaws.com/curricula-phishing/ ; child-src 'self' https://d2v8pn2kg220hg.cloudfront.net/5cc8e592-eb44-44d2-b205-f4aff43a1162/ blob: ; report-uri https://mycurricula.com/_/csp/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.googleapis.com *.klevu.com *.ksearchnet.com *.narvar.com *.narvar.qa *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.payfabric.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app *.certcapture.com *.payfabric.com *.weltpixel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.googleapis.com *.certcapture.com *.payfabric.com https://assets.mudpie.com maps.gstatic.com maps.googleapis.com cdnjs.cloudflare.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.narvar.com *.narvar.qa www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.googleapis.com *.gstatic.com *.certcapture.com *.payfabric.com maps.googleapis.com *.zdassets.com https://foursixty.com *.i95dev.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://js.klevu.com https://www.mudpie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.cash.app *.certcapture.com maps.gstatic.com maps.googleapis.com https://foursixty.com *.i95dev.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://www.mudpie.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.googleapis.com *.certcapture.com *.payfabric.com maps.googleapis.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com/ https://foursixty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.doubleclick.net https://www.google-analytics.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' blob: https://prod-bk-web.de.rbi.tools/en/static/js/vendor.d1b062fe.js https://prod-bk-web.de.rbi.tools/en/static/js/main.442372fd.js https://prod-bk-web.de.rbi.tools/en/static/js/runtime.b7ebc6aa.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.de.rbi.tools/en/static/js/vendor.5edd5354.js https://prod-bk-web.de.rbi.tools/en/static/js/main.a739f22b.js https://prod-bk-web.de.rbi.tools/en/static/js/runtime.10de8980.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: ubuy.syf.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com use.fontawesome.com *.googleapis.com https://*.hotjar.com https://*.hotjar.io https://apps.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.syfpos.com www.facebook.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * syf.demdex.net *.syfpos.com *.syf.com ubuy.syf.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com e.issuu.com www.youtube.com youtube.com woobox.com www.woobox.com facebook.com www.facebook.com instagram.com www.instagram.com s7.addthis.com assets.pinterest.com ecwportal.vertexsmb.com *.hotjar.com *.hotjar.io *.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com www.addthis.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com log.pinterest.com www.facebook.com *.googleadservices.com www.google.pl *.familyfarmandhome.com https://*.hotjar.com https://*.hotjar.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com https://chimpstatic.com ubuy.syf.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com js-agent.newrelic.com bam.nr-data.net woobox.com www.woobox.com s7.addthis.com m.addthis.com v1.addthisedge.com assets.pinterest.com ecwportal.vertexsmb.com connect.facebook.net freegeoip.app api.ipbase.com *.google-analytics.com *.hotjar.com *.hotjar.io widgets.syfpayments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com downloads.mailchimp.com assets.braintreegateway.com *.syfpos.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com ubuy.syf.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com use.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com ubuy.syf.com buy.syf.com svcs.syf.com usvcs.syf.com www.b2bcreditservices.com iwww.b2bcreditservices.com js-agent.newrelic.com bam.nr-data.net s7.addthis.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com wss://*.hotjar.io https://*.doubleclick.net *.connect.facebook.net *.facebook.com www.google.pl www.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://stats.codepoints.net:443; img-src 'self' data: https://stats.codepoints.net:443; style-src 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://stats.codepoints.net:443; font-src 'self'; 1 report-uri https://fathom.report-uri.com/r/t/csp/wizard; default-src 'none'; form-action 'none'; object-src 'none'; frame-ancestors 'none'; block-all-mixed-content; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action https://testsecurepay.eway2pay.com/fim/est3Dgate https://bib.eway2pay.com/fim/est3Dgate *.facebook.com *.gc.sales-snap.com https://rs.raiffeisenbank.rs pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src *.googletagmanager.com *.doubleclick.net/ *.yandex.com *.facebook.com *.gc.sales-snap.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ www.facebook.com platform.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src *.etrustmark.rs *.facebook.com *.google.com https://yandex.ru *.clarity.ms *.bing.com *.google.rs *.yandex.ru *.yango.com https://core.yads.tech *.doubleclick.net *.yandex.com *.gamecentar.rs https://gamecentar.rs/static/ https://gamecentar.rs/media/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com https://www.magezon.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com data: 'self' 'unsafe-inline'; script-src *.sales-snap.com *.facebook.net *.yandex.ru *.clarity.ms *.google-analytics.com *.googletagmanager.com mc.yango.com mc.yandex.ru mc.yandex.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io *.google.com/ connect.facebook.net twitter.com platform.twitter.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sales-snap.com *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google.com mc.yango.com *.yandex.com *.sales-snap.com *.clarity.ms dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://get.geojs.io *.avada.io *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action 'self' www.paypal.com securepayments.paypal.com www.facebook.com www.cbz.at www.fontis-shop.ch; report-uri https://www.scm-shop.de/csp-report; report-to csp-endpoint 1 default-src 'self' https: data: blob:; img-src 'self' https: data: blob:; style-src 'self' 'unsafe-inline' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; font-src 'self' https: data:; connect-src 'self' https:; frame-src 'self' https://tpc.googlesyndication.com https://googleads.g.doubleclick.net https://www.youtube.com https://open.spotify.com 1 style-src *.searchspring.net *.klaviyo.com platform-api.sharethis.com *.adobe.com fonts.googleapis.com https://fonts.googleapis.com assets.braintreegateway.com *.yotpo.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; media-src *.kaltura.com *.zdassets.com *.elfsightcdn.com *.d3k81ch9hvuctc.cloudfront.net ccspersistenceprod-contentstaticassets04b201d4-1apqb8dyegznm.s3.us-east-1.amazonaws.com *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; img-src *.elfsightcdn.com *.googlesyndication.com *.clarity.ms *.adtrafficquality.google *.kaltura.com *.bing.com *.zonos.com d3k81ch9hvuctc.cloudfront.net *.searchspring.io *.ccspersistenceprod-contentstaticassets04b201d4-1apqb8dyegznm.s3.us-east-1.amazonaws.com *.sharethis.com *.wisepops.com *.zendesk.com *.google.com.py *.zdusercontent.com *.google.es *.bing.net *.google.ca *.google.com.ar *.google.rs *.google.com.br *.google.cz *.google.com.pe *.google.pl *.google.hr *.google.com.ph *.google.de *.google.co.jp *.google.co.in *.google.co.uk *.google.fr *.google.ch *.google.co.za *.google.ie ccspersistenceprod-contentstaticassets04b201d4-1apqb8dyegznm.s3.us-east-1.amazonaws.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bird.eu *.getbread.com *.breadpayments.com *.rbcpayplan.com maps.gstatic.com https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com https://extendcoreoffersprod-offersthemelogobucketeb21afa-1lr7le13dvgtp.s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; connect-src *.wisepops.net *.elfsight.com *.wisepops.com *.clarity.ms *.adtrafficquality.google *.acsbapp.com *.bing.com *.breadgateway.net *.zdassets.com *.zonos.com *.gstatic.com *.searchspring.io *.googlesyndication.com *.zendesk.com *.zopim.com *.sharethis.com *.bing.net *.datadome.co *.google.com.ar *.google.rs *.elfsightcdn.com *.google.com.ph *.google.fr *.google.ch platform-api.sharethis.com wisepops.net wss://widget-mediator.zopim.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.googleapis.com https://*.helloextend.com https://*.ingest.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.route.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.refersion.com https://imgs.signifyd.com 'self' 'unsafe-inline'; script-src *.elfsight.com *.googlesyndication.com *.polyfill-fastly.io *.cloudflareinsights.com *.wisepops.net *.hotjar.com *.clarity.ms *.acsbapp.com *.adtrafficquality.google *.bing.com *.searchspring.net *.zdassets.com *.zopim.com *.zonos.com *.sharethis.com *.wisepops.com *.scriptcdn.net *.elfsightcdn.com *.highpointscientific.com *.googletagmanager.com platform-api.sharethis.com elfsightcdn.com wisepops.net assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.googleapis.com https://*.helloextend.com https://browser.sentry-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com polyfill-fastly.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.routeapp.io fonts.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com *.avada.io *.refersion.com www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; font-src *.klaviyo.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.yotpo.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.yotpo.com https://www.googletagmanager.com/ *.refersion.com www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' noembed.com *.plyr.io *.usercentrics.eu tracker.muellergroup.com translate.googleapis.com; img-src 'self' data: *.ytimg.com *.usercentrics.eu translate.google.com fonts.gstatic.com; default-src 'self' 'unsafe-inline' *.usercentrics.eu *.youtube.com tracker.muellergroup.com data: connect.facebook.net; frame-src *.youtube.com *.youtube-nocookie.com; report-uri https://www.muellergroup.com/@http-reporting?csp=report&requestTime=1765934621150869&requestHash=07ae921dcf7f9a58cdc21eb01aa990425552d8a5 1 default-src * data: 'unsafe-eval' 'unsafe-inline' blob: 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.getalma.eu *.google.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ api.payplug.com secure.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net * https://*.gstatic.com *.adyen.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.bird.eu a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cdn.jsdelivr.net *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ cdn.jsdelivr.net *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * *.adyen.com *.getalma.eu *.google-analytics.com www.facebook.com *.facebook.net *.google.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 block-all-mixed-content;child-src blob:;connect-src 'self' d2xg8ju40huerl.cloudfront.net cdnmain.guidefitter.com guidefitterconfidential.s3.amazonaws.com s3.amazonaws.com/upload.guidefitter.com/ game.guidefitter.com osc-collector.xyz.guidefitter.com https://*.facebook.com https://*.zendesk.com https://*.zdassets.com wss://widget-mediator.zopim.com https://*.zopim.com https://*.authorize.net https://*.bing.com https://vimeo.com https://*.vimeo.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.g.doubleclick.net https://us-street.api.smartystreets.com https://*.klaviyo.com https://*.clarity.ms https://analytics.tiktok.com *.dca0.com https://*.mapbox.com https://lending-api.credova.com https://api.ipify.org https://*.armanet.us guidefitterconfidential.s3.us-east-1.amazonaws.com s3.us-east-1.amazonaws.com/upload.guidefitter.com/;default-src 'self' d2xg8ju40huerl.cloudfront.net cdnmain.guidefitter.com cdnmedia.guidefitter.com;font-src 'self' *.typekit.net fonts.gstatic.com data:;frame-src 'self' https://www.facebook.com https://connect.facebook.net fbrpc://call player.vimeo.com https://www.googletagmanager.com https://www.google-analytics.com https://bid.g.doubleclick.net https://td.doubleclick.net https://www.youtube.com https://widget-prime.rafflecopter.com;img-src * blob: data:;media-src 'self' *.zdassets.com shop.guidefitter.com google.com;script-src 'self' d2xg8ju40huerl.cloudfront.net cdnmain.guidefitter.com game.guidefitter.com https://*.zdassets.com https://*.zopim.com https://*.authorize.net https://bat.bing.com https://*.cdn-apple.com https://connect.facebook.net player.vimeo.com https://www.google.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://www.googleadservices.com https://*.klaviyo.com https://analytics.tiktok.com 'unsafe-inline' 'unsafe-eval' blob: data: https://*.mapbox.com https://*.adroll.com https://*.adroll.mgr.consensu.org https://*.dca0.com https://widget-prime.rafflecopter.com https://snap.licdn.com https://*.armanet.us;style-src 'self' *.typekit.net d2xg8ju40huerl.cloudfront.net cdnmain.guidefitter.com 'unsafe-inline';report-to default;report-uri https://guidefitter.report-uri.com/r/d/csp/reportOnly 1 font-src *.googleapis.com *.gstatic.com 'self' data: oct8necdneu.azureedge.net *.oct8ne.com *.fontawesome.com *.punchout2go.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com 'self' data: *.twitter.com *.facebook.com vendedoreswurth.aclonline.es *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com *.tradecentric.com 'self' 'unsafe-inline'; frame-ancestors *.punchout2go.com 'self' data: 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.vimeo.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com *.twitter.com *.google.com *.addtoany.com *.facebook.com *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.oct8ne.com *.cookiebot.com *.google.com.ua *.facebook.com *.bing.com https://images.unsplash.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.punchout2go.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.doubleclick.net *.cookielaw.org *.magentocommerce.com *.wuerth.com vendedoreswurth.aclonline.es wurth.aclonline.es cdn.connectif.cloud *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com media.witglobal.net *.media.wuerth.com http://media.wuerth.com https://*.clarity.ms https://*.bing.com *.wurth.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com polyfill.io *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.adyen.com *.webeyez.com *.nr-data.net *.facebook.net *.bing.com *.googlesyndication.com https://maps.googleapis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.connectif.cloud *.addtoany.com *.cookielaw.org *.doubleclick.net *.jsdelivr.net *.jquery.com *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com https://*.clarity.ms *.newrelic.com *.onetrust.com bat.bing.com bat.bing.net analytics.tiktok.com *.paypalobjects.com *.sandbox.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.fontawesome.com *.addtoany.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.jsdelivr.net *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.adyen.com *.webeyez.com cognito-identity.eu-west-1.amazonaws.com firehose.eu-west-1.amazonaws.com *.trackingplan.com *.nr-data.net *.cookiebot.com *.googlesyndication.com *.bing.com https://maps.googleapis.com https://player.vimeo.com http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.punchout2go.com *.cloudflare.com *.twitter.com *.twimg.com *.cookielaw.org *.doubleclick.net *.analytics.google.com *.connectif.cloud *.facebook.com compliance.wurth.es *.reskyt.com https://*.launchdarkly.com https://*.mixpanel.com https://*.mxpnl.com https://*.twilio.com wss://*.twilio.com *.wuerth.com https://*.clarity.ms *.newrelic.com *.onetrust.com bat.bing.com bat.bing.net analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com 'unsafe-inline' data: *.cloudflare.com mishimoto.nyc3.cdn.digitaloceanspaces.com *.mishimoto.com *.parastorage.com https://client.crisp.chat maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mishimoto.com *.mishimoto.com/checkout *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com www.google.com *.certcapture.com *.sandbox.paypal.com creatives.attn.tv *.paypalobjects.com api.sandbox.braintreegateway.com *.google.com/ platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.klarna.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://images.unsplash.com *.certcapture.com *.google.com *.google.co.uk *.mishimoto.com *.bing.com *.clarity.ms *.cookielaw.org *.nyc3.cdn.digitaloceanspaces.com *.cloudimg.io https://image.crisp.chat *.disqus.com https://www.magezon.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://img.youtube.com https://www.mollie.com *.reddit.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.certcapture.com *.google-analytics.com *.googleadservices.com bam.nr-data.net *.sandbox.paypal.com *.bing.com *.mishimoto.com *.getbread.com *.breadpayments.com cdn.attn.tv *.attentivemobile.com *.clarity.ms *.cookielaw.org *.arkane.com *.nyc3.cdn.digitaloceanspaces.com *.hotjar.com cdnjs.cloudflare.com cdn.optimizely.com *.jquery.com https://client.crisp.chat *.disqus.com https://z.moatads.com https://cdn.jsdelivr.net *.google.com/ *.googletagmanager.com twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.mollie.com assets.shipperhq.com wmvvz.mishimoto.eu cdn.bc0a.com *.logr-ingest.com *.lrkt-in.com *.redditstatic.com *.tapfiliate.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.mishimoto.com mishimoto.nyc3.cdn.digitaloceanspaces.com *.parastorage.com https://client.crisp.chat https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.klarnacdn.net *.fontawesome.com assets.shipperhq.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.certcapture.com *.google-analytics.com *.googlesyndication.com stats.g.doubleclick.net *.sandbox.paypal.com bam.nr-data.net *.mishimoto.com/checkout *.attn.tv *.clarity.ms events.attentivemobile.com *.cookielaw.org *.arkane.com *.optimizely.com *.jquery.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.analytics.google.com *.googletagmanager.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com rms.shipperhq.com wss://rms.shipperhq.com/ www.googleapis.com *.mishimoto.com *.bc0a.com *.logr-ingest.com *.lrkt-in.com *.redditstatic.com *.reddit.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cookielaw.org 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https://*.obvsg.at 'unsafe-inline' 1 default-src 'self'; connect-src 'self' https://*.usercentrics.eu https://analytics.algolia.com https://*.algolia.net https://insights.algolia.io https://*.scarabresearch.com https://*.abtasty.com https://api-js.mixpanel.com https://maps.googleapis.com https://maps.gstatic.com https://www.google.com https://www.google.de https://ams.creativecdn.com https://bat.bing.net https://bat.bing.com https://*.pinterest.com https://www.googleadservices.com https://locator.uberall.com https://*.mapbox.com https://google.com/ https://api.friendlycaptcha.com https://*.adyen.com https://*.zenloop.com https://*.sovendus.com https://api.userlike.com https://userlike-cdn-umm.b-cdn.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://www.facebook.com https://webchannel-content.eservice.emarsys.net https://www.paypal.com https://www.sandbox.paypal.com https://apple-pay-gateway.apple.com https://apple-pay-gateway-cert.apple.com https://sgtm.blume2000.de https://sgtm.blume2000.at https://sgtm.blume2000.ch https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://eu-api.friendlycaptcha.eu wss://umd.userlike.com umd.userlike.com https://userlike-cdn-web.b-cdn.net https://www.userlike.com blob: https://y.clarity.ms https://s.clarity.ms; script-src 'self' https://*.usercentrics.eu https://*.scarabresearch.com https://try.abtasty.com https://maps.googleapis.com https://www.googletagmanager.com https://va.vercel-scripts.com https://sgtm.blume2000.de https://sgtm.blume2000.at https://sgtm.blume2000.ch https://connect.facebook.net https://s.pinimg.com https://ct.pinterest.com https://tags.creativecdn.com https://bat.bing.com https://www.dwin1.com https://*.hotjar.com https://lantern.roeyecdn.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://cdn.jsdelivr.net/gh/paulirish/lite-youtube-embed@master/src/lite-yt-embed.js https://locator.uberall.com https://*.mapbox.com https://zenloop-website-overlay-production.s3.amazonaws.com https://*.zenloop.com https://userlike-cdn-umm.b-cdn.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.sovendus.com https://vercel.live https://www.paypal.com https://apple-pay-gateway.apple.com https://apple-pay-gateway-cert.apple.com https://applepay.cdn-apple.com https://*.abtasty.com https://www.clarity.ms https://scripts.clarity.ms 'unsafe-inline' 'unsafe-eval' https://api.userlike.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://*.abtasty.com; img-src 'self' data: blob: https://suite16.emarsys.net https://link.mailing.blume2000.de https://link.mailing.blume2000.at https://link.mailing.blume2000.ch https://*.abtasty.com https://res.cloudinary.com https://maps.gstatic.com https://maps.googleapis.com https://app.usercentrics.eu https://lantern.roeye.com https://bat.bing.net https://bat.bing.com https://www.google.com https://www.google.de https://www.googleadservices.com https://www.facebook.com https://i.ytimg.com/ https://www.googletagmanager.com https://locator.uberall.com https://connect.facebook.net https://*.cdn.adyen.com https://*.doubleclick.net https://uct.service.usercentrics.eu https://www.paypalobjects.com https://*.google-analytics.com https://storage.googleapis.com https://api.mapbox.com https://ib.adnxs.com https://rt.udmserve.net https://cm.adform.net https://ih.adscale.de https://cm.g.doubleclick.net https://visitor.omnitagjs.com https://pixel.advertising.com https://ice.360yield.com https://dsum-sec.casalemedia.com https://pixel.rubiconproject.com https://hbx.media.net https://cs.mobfox.com/ https://cm.mgid.com https://onetag-sys.com https://us-u.openx.net https://sync.outbrain.com https://simage2.pubmatic.com https://bh.contextweb.com https://s.seedtag.com/ https://match.sharethrough.com https://s.ad.smaato.net https://us.ck-ie.com https://ce.lijit.com https://sync.taboola.com https://eb2.3lift.com https://s-cs.rmp.rakuten.com https://dot.wp.pl https://ad.yieldlab.net https://ads.yieldmo.com https://t.visx.net https://ssc-cms.33across.com/ https://inv-nets.admixer.net https://sync.e-planning.net https://csync.loopme.me https://adn.caprofitx.com https://sync.addlv.smt.docomo.ne.jp https://sync.teads.tv https://sync.console.adtarget.com.tr https://dot.wp.pl https://sync.1rx.io https://ssp-csync.smartadserver.com https://rtb.gumgum.com https://sync.connectad.io https://csync.smilewanted.com https://sync.go.sonobi.com https://fast.nexx360.io https://hb.yahoo.net https://sync-service.net https://sync.cootlogix.com https://cs.adingo.jp https://sync.inmobi.com https://stickyadstv.com https://yellowblue.io https://dmxleo.com https://ms-cookie-sync.presage.io https://adtech.ink https://cm-exchange.toast.com https://ad.as.amanad.adtdp.com https://sync.bidence.net https://cs.gssprt.jp https://sp.gmossp-sp.jp/ https://analytics.ad.daum.net https://s-cs.send.microad.jp https://mixer.mobon.net https://tg.socdm.com https://sync.ad-stir.com https://t.adx.opera.com https://ad.tpmn.co.kr https://userlike-cdn-operators.userlike.com https://userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://userlike-cdn-web.b-cdn.net https://www.userlike.com https://userlike-store-media-files.s3.amazonaws.com https://i.ytimg.com; font-src 'self' https://res.cloudinary.com https://locator.uberall.com https://assets.zenloop.com https://userlike-cdn-umm.b-cdn.net https://*.abtasty.com https://applepay.cdn-apple.com https://fonts.gstatic.com; worker-src 'self' blob:; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://www.googletagmanager.com https://ct.pinterest.com https://www.facebook.com https://*.adyen.com https://www.sovendus-connect.com https://www.sovendus-benefits.com https://vercel.live/ https://www.paypal.com https://www.sandbox.paypal.com https://apple-pay-gateway.apple.com https://apple-pay-gateway-cert.apple.com https://sgtm.blume2000.de https://sgtm.blume2000.at https://sgtm.blume2000.ch https://ams.creativecdn.com https://*.edb.com https://*.abtasty.com https://applepay.cdn-apple.com https://api.userlike.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net https://www.youtube.com https://player.vimeo.com; frame-ancestors 'self' https://app.storyblok.com https://blume2000.io https://*.blume2000.io https://blume2000.de https://*.blume2000.de https://blume2000.at https://*.blume2000.at https://blume2000.ch https://*.blume2000.ch http://localhost:3000 http://localhost:3001; media-src 'self' https://userlike-cdn-umm.b-cdn.net https://userlike-store-media-files.s3.amazonaws.com https://www.userlike.com blob:; child-src 'self' https://api.userlike.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net blob:; object-src 'none' 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com 'self' data: *.fontawesome.com *.bootstrapcdn.com *.punchout2go.com *.tradecentric.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.salesforce.com *.punchout2go.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.schoolhealth.com mcstaging2.schoolhealth.com/ portal.punchout2go.com qa-portal.punchout2go.com dev-portal.punchout2go.com sapportal.ocps.net sapportalqap.ocps.net shop.equallevel.com *.punchout2go.com *.tradecentric.com *.ariba.com *.nps.k12.nj.us 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.sharethis.com https://static.addtoany.com/ *.certcapture.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com js.mollie.com *.schoolhealth.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: blob: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.gstatic.com *.googleapis.com *.certcapture.com *.b0e8.com *.cenpos.net *.cenpos.com https://images.unsplash.com https://www.mollie.com https://*.asknice.ly *.schoolhealth.com *.chartbeat.com *.chartbeat.net *.pages03.net *.unbxdapi.com *.punchout2go.com *.tradecentric.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.sharethis.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com *.certcapture.com *.b0e8.com *.bc0a.com *.cenpos.com *.cenpos.net *.google.com *.cardinalcommerce.com https://maps.googleapis.com js.mollie.com https://static.asknice.ly ssl.google-analytics.com *.cloudfront.net *.cloudflare.com *.pages03.net *.addtoany.com *.chartbeat.com *.punchout2go.com *.tradecentric.com *.unbxdapi.com *.unbxd.com *.unbxd.io data: *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.certcapture.com *.fontawesome.com https://static.asknice.ly *.bootstrapcdn.com *.punchout2go.com *.tradecentric.com *.googleapis.com *.unbxdapi.com *.unbxd.com *.unbxd.io tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io vimeo.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.sharethis.com https://stats.addtoany.com/menu *.googleapis.com *.certcapture.com https://maps.googleapis.com https://player.vimeo.com https://*.asknice.ly *.doubleclick.net *.demdex.net *.punchout2go.com *.tradecentric.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.ctfassets.net;img-src data: blob: *;style-src 'self' 'unsafe-inline' *.gstatic.com;font-src 'self' fonts.gstatic.com;media-src 'self' *.ctfassets.net *.gstatic.com;frame-src 'self' *.ctfassets.net *.youtube.com *.ungpd.com;connect-src 'self' *.ctfassets.net *.contentful.com *.swish.nu;object-src 'none';script-src 'self'; report-uri https://eo7f9vdutam5kd9.m.pipedream.net; report-to csp-report; 1 img-src https://higherlogicdownload.s3.amazonaws.com/NSBA/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NSBA/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/NSBA/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NSBA/ https://higherlogicdownload.s3.amazonaws.com/NSBA/ https://higherlogiclongterm.s3.amazonaws.com/NSBA/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/NSBA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NSBA/ 'self' https://higherlogiclongterm.s3.amazonaws.com/NSBA/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/NSBA/ https://higherlogicdownload.s3.amazonaws.com/NSBA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NSBA/ https://higherlogicstream.s3.amazonaws.com/NSBA/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/NSBA/ https://higherlogicdownload.s3.amazonaws.com/NSBA/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NSBA/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.usablenet.com *.udev1a.net *.narvar.com *.narvar.qa *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn https://logistics-stage.ecpay.com.tw/Express/map https://logistics.ecpay.com.tw/Express/map https://logistics-stage.ecpay.com.tw/helper/printTradeDocument https://logistics.ecpay.com.tw/helper/printTradeDocument *.twitter.com *.usablenet.com *.udev1a.net https://plumrocket.com *.authorize.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn landofcoder.com maps.googleapis.com chart.googleapis.com *.twitter.com *.usablenet.com *.udev1a.net https://plumrocket.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://accounts.google.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com magefan.com cm.magefan.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.usablenet.com *.udev1a.net *.clarity.ms *.bing.com *.nofraud.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com *.narvar.com *.narvar.qa hexagon-analytics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com landofcoder.com maps.googleapis.com chart.googleapis.com 'self' *.paypal.com *.sandbox.paypal.com *.googletagmanager.com *.plumrocket.com *.tawk.to *.bam-cell.nr-data.net *.gstatic.com *.usablenet.com *.udev1a.net *.nofraud.com *.clarity.ms *.mmapiws.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com cdn.sift.com api3.veritrans.co.jp *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://accounts.google.com https://www.gstatic.com cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com self *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.usablenet.com *.udev1a.net assets.braintreegateway.com https://accounts.google.com https://www.gstatic.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com landofcoder.com maps.googleapis.com chart.googleapis.com self *.cloudflare.com *.twitter.com *.twimg.com *.usablenet.com *.udev1a.net *.nofraud.com *.clarity.ms *.mmapiws.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com api3.veritrans.co.jp *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://accounts.google.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://mcstaging.mikimoto.com/; report-to report-endpoint; 1 default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.googleapis.com https://www.google-analytics.com https://www.googleanalytics.com https://www.googleoptimize.com https://optimize.google.com *.google.com https://*.google.com https://*.googleusercontent.com https://*.ggpht.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://*.gstatic.com https://*.googleadservices.com http://s3.amazonaws.com https://snap.licdn.com https://connect.facebook.net https://www.facebook.com https://static.hotjar.com https://script.hotjar.com http://*.tiqcdn.com https://pageimprove.io https://*.linkedin.com https://partenamut.activehosted.com https://*.tealiumiq.com https://*.youtube.com https://*.decibelinsight.net https://wurfl.io https://bat.bing.com https://*.googlesyndication.com https://*.teads.tv https://*.clarity.ms/ https://dev.visualwebsiteoptimizer.com https://tags.partenamut.be/partenamut-site/prod/utag.sync.js https://tags.partenamut.be/partenamut-site/prod/utag.js https://tags.partenamut.be https://analytics.tiktok.com https://analytics.tiktok.com/i18n/pixel/events.js https://collect.partenamut.be; style-src 'unsafe-inline' 'self' https://*.googleapis.com https://fonts.googleapis.com https://optimize.google.com https://unpkg.com https://script.hotjar.com https://static.hotjar.com https://*.gstatic.com https://fonts.bunny.net; img-src 'self' https://*.googleapis.com https://*.gstatic.com https://*.google.com *.googleusercontent.com https://*.google.be https://*.google-analytics.com https://googleads.g.doubleclick.net https://*.linkedin.com https://*.partenamut.be https://*.facebook.com https://dummyimage.com https://placehold.co https://www.googletagmanager.com http://www.w3.org/2000/svg https://*.tealiumiq.com https://s535jira.mutworld.be https://flagcdn.com https://script.hotjar.com https://static.hotjar.com https://bat.bing.com https://ad.doubleclick.net https://*.teads.tv https://dev.visualwebsiteoptimizer.com https://tags.partenamut.be/partenamut-site/prod/utag.js https://*.clarity.ms https://c.bing.com https://www.google.com/pagead/form-data https://survey-images.hotjar.com data:; frame-src 'self' https://*.google.com https://optimize.google.com https://vars.hotjar.com/ https://*.youtube.com https://*.partenamut.be https://cloud.cavai.com/ www.facebook.com https://idp.iamfas.belgium.be/ https://td.doubleclick.net/ https://*.teads.tv/ https://td.doubleclick.net.x.ccf80dde0e0820444b0b8f9038e392127391.d045232a.id.opendns.com https://10649093.fls.doubleclick.net https://maternity-leave---partena.bubbleapps.io; font-src 'self' https://fonts.gstatic.com https://script.hotjar.com https://fonts.bunny.net; object-src 'self' data: 'unsafe-eval'; media-src 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; base-uri 'self'; navigate-to *; connect-src 'self' https://*.cloud.es.io https://*.googleapis.com *.google.com https://*.google.com https://*.google.com https://*.gstatic.com https://*.google-analytics.com https://*.facebook.com https://*.linkedin.oribi.io https://*.hotjar.io https://*.hotjar.com https://pageimprove.io https://*.tealiumiq.com https://*.decibelinsight.net wss://*.hotjar.com https://*.cloud.es.io https://bat.bing.com https://*.linkedin.com https://*.googlesyndication.com wss://*.decibelinsight.net https://wurfl.io https://*.g.doubleclick.net https://*.teads.tv https://*.clarity.ms/ https://dev.visualwebsiteoptimizer.com https://adservice.google.com https://www.google.com/pagead/form-data https://google.com/ccm/form-data/1035243604 https://google.com:433/ccm/form-data/1035243604 https://*.adservice.google.com https://adservice.google.com https://analytics.tiktok.com https://*.partenamut.be data: blob:; worker-src 'self' blob:;;report-uri https://mutualit.uriports.com/reports; report-to default 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-UPMzMMw4cKu0cp28EwFp6A' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 script-src 'strict-dynamic' 'nonce-rAnd0m123' 'unsafe-inline' http: https:; object-src 'none'; base-uri 'none'; require-trusted-types-for 'script'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com https://fast.amc.demdex.net https://vimeo.com *.player.vimeo.com http://consent-pref.trustarc.com https://consent-pref.trustarc.com https://player.vimeo.com https://www.youtube-nocookie.com https://plumrocket.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src *.assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.certcapture.com https://cdn1.1800flowers.com *.googletagmanager.com *.amcglobal.sc.omtrdc.net *.portotheme.com https://images.contentstack.io https://px.ads.linkedin.com https://p.adsymptotic.com http://consent.trustarc.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.storyblok.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://maps.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com https://optimize.google.com https://www.googleoptimize.com/optimize.js http://tags.tiqcdn.com https://js-agent.newrelic.com https://cdn.auth0.com https://bam.nr-data.net *.jquery.com https://assets.adobedtm.com *.auth0.com data: https://snap.licdn.com/li.lms-analytics/insight.min.js https://px.ads.linkedin.com https://www.googleoptimize.com https://edge.fullstory.com/s/fs.js *.rs.fullstory.com https://rs.fullstory.com/rec/integrations https://snap.licdn.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.storyblok.com https://player.vimeo.com https://www.youtube.com *.googletagmanager.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com unpkg.com *.instagram.com maps.googleapis.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.certcapture.com https://fonts.googleapis.com https://static.klaviyo.com *.storyblok.com http://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.storyblok.com blob: *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.certcapture.com *.google-analytics.com https://stats.g.doubleclick.net https://bam.nr-data.net *.dpm.demdex.net *.rs.fullstory.com https://rs.fullstory.com/rec/page https://rs.fullstory.com/rec/bundle *.assets.adobedtm.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io analytics.google.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; connect-src 'self' bwia.okta.com bwia-admin.okta.com bwlogin.iaproducers.com *.oktacdn.com *.mixpanel.com *.mapbox.com bwia.kerberos.okta.com bwia.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; frame-src 'self' bwia.okta.com bwia-admin.okta.com bwlogin.iaproducers.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' bwia.okta.com bwlogin.iaproducers.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://www.iaproducers.com 1 default-src 'self' *.doubleclick.net get.geojs.io sgtm.adagio-city.com; child-src 'self' blob:; connect-src 'self' cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com ad.avtm.fr *.google.com.ua *.cardinalcommerce.com *.online-metrix.net *.fastlylb.net *.facebook.com *.execute-api.us-east-1.amazonaws.com *.google.nl *.metaffiliation.com *.wonderpush.com *.analytics.google.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com sgtm.adagio-city.com *.pinterest.com s.pinimg.com get.geojs.io analytics.tiktok.com *.nr-data.net *.us-east-1.amazonaws.com *.kontorolabs.com *.alphalyr.com *.sojern.com bat.bing.net bat.bing.com https://www.google-analytics.com https://www.googletagmanager.com; font-src *; frame-src 'self' *.cedexis-test.com *.doubleclick.net static.addtoany.com *.google.com *.youtube.com my.matterport.com *.citrix-itm-test.com *.facebook.com *.fbcdn.net *.citm-test.com *.cardinalcommerce.com *.online-metrix.net cedexis-test.gcorelabs.com *.contentsquare.net csxd.all.accor.com csxd.mag-adagio.com ct.pinterest.com s.pinimg.com *.adagio-city.com *.googletagmanager.com sgtm.adagio-city.com *.itm.cloud.com *.by.wonderpush.com; img-src * data:; media-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' adagio.nonce cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com ssl.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com ad.avtm.fr *.google.com.ua *.google.de *.cardinalcommerce.com *.elitrack.com *.metaffiliation.com *.wonderpush.com ct.pinterest.com s.pinimg.com tck.alphalyr.com *.sojern.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://static.addtoany.com https://try.abtasty.com https://www.google.com staticaws.fbwebprogram.com; script-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com ad.avtm.fr *.google.com.ua *.cardinalcommerce.com *.online-metrix.net *.elitrack.com *.metaffiliation.com *.wonderpush.com s.pinimg.com cdn.jsdelivr.net *.adagio-city.com analytics.tiktok.com ct.pinterest.com bat.bing.com tck.alphalyr.com *.sojern.com surveys-static-prd.survicate-cdn.com survey.survicate.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://static.addtoany.com https://try.abtasty.com https://www.google.com staticaws.fbwebprogram.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; style-src-elem * 'unsafe-inline'; frame-ancestors 'self' 1 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.vivapayments.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.cardlink.gr *.alphaecommerce.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: https://www.google.gr https://www.google-analytics.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.designer-images.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com https://v2.zopim.com https://go.linkwi.se https://skroutza.skroutz.gr *.skroutz.gr https://static.zdassets.com *.addthis.com *.google-analytics.com https://*.octocom.ai cdn.stat-track.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.vivapayments.com *.disqus.com *.avada.io *.stat-track.com polyfill.io *.moosend.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.octocom.ai fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.moosend.com *.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://*.zdassets.com https://ianos-chat.zendesk.com https://www.merchant-center-analytics.goog *.zopim.com widget-mediator.zopim.com https://region1.google-analytics.com/ wss://*.zopim.com wss://widget-mediator.zopim.com *.googlesyndication.com *.doubleclick.net https://*.octocom.ai www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://static.zdassets.com https://ekr.zdassets.com https://ekr.zendesk.com wss://*.zopim.com wss://widget-mediator.zopim.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://www.scor.com/en/system/reporting/csp_report; report-to csp_report 1 font-src fonts.gstatic.com *.googleapis.com https://origin.xtlo.net https://mediacdn.espssl.com *.fontawesome.com *.richpanel.com *.gstatic.com https://fonts.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.credova.com *.authorize.net 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.networkmerchants.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.credova.com * *.trysera.com https://td.doubleclick.net www.xtento.com *.authorize.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.networkmerchants.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ammunitiondepot.com *.facebook.com *.symantec.com *.exitintel.com *.cloudfront.net credova.com *.credova.com *.clickagy.com *.adxcel-ec2.com *.googe.com *.provenpixel.com *.rlcdn.com *.google.com *.espssl.com *.google.co.in *.ytimg.com *.listrakbi.com https://guarantee-cdn.com *.amped.io https://origin.xtlo.net https://tracking.avantlink.com https://www.googletagmanager.com https://lh3.googleusercontent.com *.amazonaws.com *.richpanel.com www.xtento.com cdn.xtento.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com maps.gstatic.com *.gstatic.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.networkmerchants.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.credova.com *.hiconversion.com *.ammunitiondepot.com *.facebook.com *.facebook.net *.symantec.com *.exitintel.com *.gorgias.io *.listrakbi.com *.crazyegg.com *.qualaroo.com *.cloudfront.net *.listrak.com *.clickagy.com *.provenpixel.com *.gstatic.com *.nofraud.com https://guarantee-cdn.com *.sumo.com *.amped.io https://a.ads.rmbl.ws https://h64.online-metrix.net https://ammunition-depot.extole.io https://origin-4.xtlo.net https://ssl.avmws.com *.cloudflareinsights.com https://classic.avantlink.com/ *.richpanel.com www.xtento.com cdn.xtento.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.avada.io *.shopify.com *.authorize.net maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.networkmerchants.com *.googleapis.com *.listrakbi.com https://mediacdn.espssl.com *.richpanel.com *.fontawesome.com https://fonts.googleapis.com https://fonts.bunny.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.amazonaws.com *.richpanel.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com https://maps.googleapis.com https://player.vimeo.com *.networkmerchants.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.credova.com *.doubleclick.net *.listrak.com *.listrakbi.com *.signifyd.com *.signifyd.com:* bt.signifyd.com *.cloudfront.net *.crazyegg.com *.clickagy.com *.google.com *.mmapiws.com https://bl.listrakbi.com *.sumo.com *.amped.io *.tryamped.com https://sumo.com https://services.nofraud.com https://ipapi.co https://ammunition-depot.extole.io https://referral.ammunitiondepot.com *.richpanel.com https://t.lt02.net wss://*.richpanel.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://ipinfo.io/json https://get.geojs.io *.avada.io *.authorize.net maps.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.fr ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.fr *.spreadshirt.fr ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.fr ; font-src 'self' https: data: *.spreadshirt.fr ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.fr ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.fr ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 font-src fonts.gstatic.com use.typekit.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app maxcdn.bootstrapcdn.com *.zip.co data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * api.bazaarvoice.com stg.api.bazaarvoice.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com magefan.com cm.magefan.com *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://img.youtube.com t.zip.co static.zipmoney.com.au static.zip.co https://imgs.signifyd.com https://*.online-metrix.net back3nd-zc8erm2098.camerahouse.com.au camerahouse.staging.overdose.digital *.camerahouse.com.au https://www.google.com.vn/ https://www.google.com.au/ x.bidswitch.net cm.g.doubleclick.net ib.adnxs.com tg.socdm.com r.casalemedia.com cs.adingo.jp ads.stickyadstv.com ad.360yield.com idsync.rlcdn.com contextual.media.net c.bing.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com s.ad.smaato.net rtb-csync.smartadserver.com sync-t1.taboola.com criteo-sync.teads.tv ade.clmbtech.com eb2.3lift.com sync-criteo.ads.yieldmo.com sync.1rx.io dis.criteo.com sync.targeting.unrulymedia.com image8.pubmatic.com ups.analytics.yahoo.com image4.pubmatic.com ad.doubleclick.net sync.aralego.com rtb.openx.net cdn.aralego.net um.simpli.fi public-prod-dspcookiematching.dmxleo.com vc.hotjar.io cdn.livechat-files.com bpi.zip.co zip.co maps.gstatic.com maps.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com s7.addthis.com https://cdn.searchspring.net/intellisuggest/is.min.js static.zipmoney.com.au static.zip.co zip.co https://cdn-scripts.signifyd.com https://imgs.signifyd.com *.jst.ai *.livechatinc.com *.studio19.com *.crazyegg.com *.hotjar.com *.criteo.com *.google.com *.criteo.net *.studio19.com.au *.zip.co h64.online-metrix.net *.pcapredict.com *.searchspring.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app unsafe-inline assets.braintreegateway.com display.ugc.bazaarvoice.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com maxcdn.bootstrapcdn.com *.zip.co 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ekr.zdassets.com/ https://beacon.searchspring.io/beacon https://imgs.signifyd.com *.googleapis.com *.jst.ai *.doubleclick.net *.criteo.com *.crazyegg.com *.studio19.com.au *.zipmoney.com.au *.zip.co *.searchspring.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'unsafe-eval' 'unsafe-inline' blob blob: data: https: wss:; block-all-mixed-content; report-uri /csp.php?h=f743080d&v=4 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com *.klevu.com *.yotpo.com *.livechatinc.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.elev.io *.zdassets.com *.cartfulsolutions.com *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com data: *.greatlakesskipper.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cybersource.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.criteo.net *.criteo.com *.livechatinc.com *.wufoo.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net getshogun.com *.klaviyo.com *.facebook.com *.cybersource.com insight.adsrvr.com insight.adsrvr.org *.frstre.com *.cloudfront.net *.g.doubleclick.net *.twitter.com *.cloudmaestro.com *.elev.io *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com *.addthis.com *.recaptcha.net *.freshdesk.com airtable.com *.paypalobjects.com *.kaptcha.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: landofcoder.com *.yotpo.com *.vimeo.com *.pixlee.com *.pixlee.co *.pxlecdn.co *.jst.ai *.jsdelivr.net *.pxlecdn.com *.klaviyo.com *.facebook.com *.facebook.net *.google.com *.bing.com *.choozle.com s3.amazon.com s3.amazonaws.com *.g.doubleclick.net *.adsrvr.org *.twitter.com *.swagger.io *.cloudfront.net *.godaddy.com *.cartfulsolutions.com *.cloudmaestro.com *.trustwave.com/ *.taboola.com *.media.net *.3lift.com *.rubiconproject.com *.adnxs.com *.outbrain.com *.adform.net *.360yield.com *.yieldmo.com *.bidswitch.net *.yahoo.com *.smartadserver.com *.advertising.com *.stickyadstv.com *.fwmrm.net *.adscale.de *.teads.tv *.postrelease.com *.sharethrough.com *.ivitrack.com *.casalemedia.com *.smaato.net *.pubmatic.com *.omnitagjs.com *.criteo.com *.mediawallahscript.com *.mgid.com *.addthis.com *.revcontent.com *.liadm.com *.rlcdn.com *.turn.com *.krxd.net *.google.com.ar *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com *.bazaarvoice.com *.klevu.com *.greatlakesskipper.com *.clmbtech.com *.tapad.com *.openx.net *.dmxleo.com *.tremorhub.com *.kargo.com *.tpmn.co.kr *.agkn.com *.amanad.adtdp.com *.bluekai.com *.mathtag.com *.zemanta.com *.bnmla.com *.stackadapt.com *.simpli.fi *.admanmedia.com *.loopme.me *.digitaleast.mobi *.yieldlab.net *.lemmatechnologies.com *.avct.cloud *.deepintent.com *.dotomi.com *.creative-serving.com *.twiago.com *.amazon-adsystem.com *.mediavine.com *.socdm.com *.octillion.tv *.bidr.io.tv *.everesttech.net *.w55c.net *.emxdgt.com *.adgrx.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.reddit.com *.googletagmanager.com *.doubleclick.net *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com quickchart.io img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ www.google.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.klevu.com *.cloudflare.com *.klaviyo.com acsbapp.com *.acsbap.com acsbap.com *.online-metrix.net *.criteo.net *.criteo.com *.trustwave.com *.livechatinc.com *.wufoo.com *.fontawesome.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.gstatic.com *.jsdelivr.net *.justuno.com *.getshogun.com *.zdassets.com *.elev.io *.facebook.net *.zopim.com *.govx.com govxconnect.com *.pinimg.com *.bing.com *.tapfiliate.com *.cloudfront.net *.pepperjam.net *.pepperjam.com *.g.doubleclick.net *.ensighten.com *.bestworlds.com *.cartsave.io *.twitter.com *.swagger.io *.payments-amazon.com *.amazon.com *.godaddy.com *.cartfulsolutions.com *.cybersource.com *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com polyfill.io *.oribi.io *.paypal.com *.cloudflareinsights.com *.braintree-api.com *.greatlakesskipper.com *.trackedweb.net *.emxdgt.com *.uptrendsdata.com *.noibu.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.googleapis.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.trackedlink.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com *.disqus.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.klevu.com *.fontawesome.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.bestworlds.com *.cartsave.io *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.paypal.com *.braintree-api.com apps.bazaarvoice.com *.greatlakesskipper.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.tagmanager.google.com *.googletagmanager.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.zdassets.com *.cloudmaestro.com agentcore.s3.amazonaws.com *.freshchat.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.klaviyo.com *.jst.ai *.acsbapp.com acsbapp.com *.jsdelivr.net *.zdassets.com *.zendesk.com *.facebook.com *.elev.io *.zopim.com wss://*.zopim.com *.google-analytics.com *.g.doubleclick.net *.pinterest.com *.bestworlds.com *.cartsave.io *.bing.com *.amazon.com *.cartfulsolutions.com *.cloudmaestro.com adapter.aivo.co *.agentbot.net *.oribi.io *.hotjar.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.ksearchnet.com *.trackedweb.net *.googleadservices.com *.google.com.ar *.uptrendsdata.com *.noibu.com *.twitter.com *.twimg.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.trackedlink.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com *.cloudmaestro.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com *.greatlakesskipper.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.lampdirect.nl data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.lampdirect.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.lampdirect.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b428c232-f415-4fb2-b456-fef23ba335ec.sansec.watch/; report-to report-endpoint; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-70al4EW7Vnt3bkL369N9R1EPa' 'strict-dynamic'; frame-ancestors 'self'; manifest-src 'self' 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://platform.twitter.com https://cdn.syndication.twimg.com https://www.google-analytics.com https://www.googletagmanager.com https://siteimproveanalytics.com https://w.usabilla.com https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://platform.twitter.com https://cdn.syndication.twimg.com https://ton.twimg.com https://www.google-analytics.com https://www.googletagmanager.com https://siteimproveanalytics.com https://w.usabilla.com https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' 'unsafe-inline' https://platform.twitter.com https://ton.twimg.com https://w.usabilla.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-uri https://www.provincie-utrecht.nl/system/reporting/csp_reportonly; report-to csp_reportonly 1 font-src www.paypalobjects.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.psigate.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.trustpilot.com *.meetanshi.com meetanshi.com api.razorpay.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.meetanshi.com meetanshi.com cdn.razorpay.com https://cdnjs.cloudflare.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.trustpilot.com *.cloudflareinsights.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com player.vimeo.com *.meetanshi.com meetanshi.com checkout.razorpay.com http://cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com https://cdnjs.cloudflare.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.meetanshi.com meetanshi.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com tfhub.dev storage.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.jp/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com googletagmanager.com isst.dewitschijndel.nl tpc.googlesyndication.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.multisafepay.com pagead2.googlesyndication.com ad.doubleclick.net c.clarity.ms bat.bing.com www.google.rs www.google.ie www.google.it www.google.be www.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com 'self' data: robincontentdesktop.blob.core.windows.net az416426.vo.msecnd.net selfservice.robinhq.com tpc.googlesyndication.com dewitschijndel.nl connect.facebook.net bat.bing.com scripts.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.multisafepay.com profiles-staging.2factors.nl dewitschijndel.nl maps.googleapis.com bat.bing.com www.google.it www.google.be www.google.rs www.google.nl ad.doubleclick.net dc.services.visualstudio.com az416426.vo.msecnd.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 script-src 'self' 'report-sample' https://frontend.leon.aero https://ajax.googleapis.com/ajax/libs/webfont/1/webfont.js https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://cdn.tiny.cloud blob:; img-src 'self' 'report-sample' https://leon-downloads.s3.eu-west-1.amazonaws.com https://leon-downloads.s3-eu-west-1.amazonaws.com https://api.maptiler.com https://frontend.leon.aero https://lsotest2.s3.eu-west-1.amazonaws.com https://leonfiles.s3.eu-west-1.amazonaws.com https://leon-passporteye-production.s3.eu-west-1.amazonaws.com https://leon-passporteye-dev.s3.eu-west-1.amazonaws.com https://leon-marketplace-prod.s3.eu-west-1.amazonaws.com https://charts.leon.aero data: blob:; style-src 'self' 'unsafe-inline' https://leon-downloads.s3.eu-west-1.amazonaws.com https://leon-downloads.s3-eu-west-1.amazonaws.com 'report-sample' https://frontend.leon.aero https://fonts.googleapis.com https://cdn.tiny.cloud https://lsotest2.s3.eu-west-1.amazonaws.com https://leonfiles.s3.eu-west-1.amazonaws.com; font-src * data: blob: 'unsafe-inline'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://leon-passporteye-production.s3.eu-west-1.amazonaws.com https://leon-passporteye-dev.s3.eu-west-1.amazonaws.com blob: https://secure.payu.com https://merch-prod.snd.payu.com https://www.youtube.com/; object-src 'none'; report-uri https://europe-1.leon.aero/webservices/NewrelicLogger/new_relic_logger.php 1 connect-src 'self' *.cdn.content.amplience.net *.staging.bigcontent.io *.algolia.net direct-collect.dy-api.eu rcom-eu.dynamicyield.com st-eu.dynamicyield.com async-px-eu.dynamicyield.com direct.dy-api.eu *.algolianet.com *.worldline-solutions.com *.ingenico.com *.ideal-postcodes.co.uk *.criteo.com www.bing.com dev.virtualearth.net t.ssl.ak.dynamic.tiles.virtualearth.net insights.algolia.io *.scoota.co *.criteo.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net apps.bazaarvoice.com display.ugc.bazaarvoice.com stg.api.bazaarvoice.com static.cloudflareinsights.com staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com https://api-eu.jdadelivers.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com wss://collection.decibelinsight.net wss://cdn.decibelinsight.net *.digital-cloud.medallia.eu bam.nr-data.net ingressteam.cloudflareaccess.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com *.analytics.google.com www.google.com google.com api2.asda.com ghs-mm.asda.com; default-src 'self'; font-src 'self' fonts.gstatic.com; frame-src 'self' *; frame-ancestors 'self' *.amplience.net; img-src 'self' *.commercecloud.salesforce.com *.media.amplience.net data: asda.a.bigcontent.io asdagroceries.scene7.com *.assets-asda.com *.dynamicyield.com *.criteo.com retailmedia-static.azureedge.net staticassets-creator-design.criteo.net t.ssl.ak.dynamic.tiles.virtualearth.net www.bing.com *.scoota.co adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com analytics.tiktok.com region1.analytics.google.com www.google.co.uk fonts.gstatic.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com adservice.google.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com www.google.com google.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net gum.criteo.com x.bidswitch.net r.casalemedia.com cm.g.doubleclick.net secure.adnxs.com simage2.pubmatic.com pixel.rubiconproject.com sync-criteo.ads.yieldmo.com hb.yahoo.net sync-t1.taboola.com; media-src 'self' asdagroceries.scene7.com s7d2.scene7.com *.scoota.co static.criteo.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' apps.rokt.com storage.googleapis.com *.algolia.net cdn-eu.dynamicyield.com st-eu.dynamicyield.com *.worldline-solutions.com *.ingenico.com assets.adobedtm.com www.bing.com r.bing.com dev.virtualearth.net *.scoota.co asdagroceries.scene7.com ui.assets-asda.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net *.criteo.com *.hlserve.com apps.bazaarvoice.com display.ugc.bazaarvoice.com stg.api.bazaarvoice.com static.cloudflareinsights.com mpsnare.iesnare.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com blob: *.digital-cloud.medallia.eu staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com js-agent.newrelic.com ingressteam.cloudflareaccess.com www.googletagmanager.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com tagmanager.google.com googletagmanager.com *.googletagmanager.com www.google.com google.com haq81g6w.micpn.com migroceries.asda.com asda-promotions.co.uk api.bazaarvoice.com *.criteo.net; style-src 'self' https: 'unsafe-inline' *.bazaarvoice.com ssl.gstatic.com www.gstatic.com tagmanager.google.com fonts.googleapis.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=Ou_kZ0eAac1cnDnKxUDlE1cpA0pC_S8ipMHmqOnWmrY-1765939811-1.0.1.1-M7wusUCSpuKRxVNoEHdlT51fC93x8OR9bqDn9vFgEIaVhQQkp7isjqI.xfQPI6PF_QLaG9CUhGOEFY8KOqG4JFnfPg8.da3vUQfehOHsEMowxiDvnhjvT6vYZGwnW3ERR9KSEbtdmGzOyJ.sq8q_uBrtLUiVQq3GRKfIlhyKYc8T.NGTmFVOBbu6iYk7AjtdoCwiciwuXDUBo6M8CuM0zg; report-to cf-jsauoervvpvxaoih 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com cash-f.squarecdn.com cdn.jsdelivr.net cdn.almapay.com https://fonts.gstatic.com https://ws.colissimo.fr *.cloudflare.com sdkm.gwbq.fr static.sensefuel.live *.fontawesome.com *.bootstrapcdn.com d3gbdgnfs9ulge.cloudfront.net https://www.google.com https://www.gstatic.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * d3gbdgnfs9ulge.cloudfront.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com * *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ https://form.typeform.com *.pinterest.com *.addthis.com media.lepetitsouk.fr static.lepetitsouk.fr d3gbdgnfs9ulge.cloudfront.net *.snapwidget.com static.addtoany.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://maps.googleapis.com * a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr *.cloudflare.com sdkm.gwbq.fr *.googleadservices.com *.google-analytics.com *.googleapis.com *.google.com *.google.fr *.instagram.com *.facebook.com *.facebook.net d3gbdgnfs9ulge.cloudfront.net axeptio.imgix.net https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cdn.jsdelivr.net cdn.ampproject.org raw.githubusercontent.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.cloudflare.com sdkm.gwbq.fr *.google-analytics.com *.googletagmanager.com *.google.fr *.gstatic.com *.trustedshops.com *.fontawesome.com static.addtoany.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com *.googleapis.com *.facebook.com *.facebook.net graph.instagram.com widgets.pinterest.com d3gbdgnfs9ulge.cloudfront.net *.axept.io * *.moatads.com *.pinterest.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app cdn.jsdelivr.net downloads.mailchimp.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.cloudflare.com sdkm.gwbq.fr *.googleapis.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com tag.search.sensefuel.live d3gbdgnfs9ulge.cloudfront.net *.addtoany.com *.google.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com *.openstreetmap.org https://maps.googleapis.com * *.getalma.eu *.almapay.com cdn.ampproject.org https://ws.colissimo.fr https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.cloudflare.com sdkm.gwbq.fr *.gstatic.com *.pinterest.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.google.fr *.instagram.com *.doubleclick.net media.lepetitsouk.fr static.lepetitsouk.fr d3gbdgnfs9ulge.cloudfront.net c.search.sensefuel.live *.axept.io static.addtoany.com *.facebook.com l.search.sensefuel.live *.facebook.net http://dpm.demdex.net *.addthis.com https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-37VmFbhqrWUVLmLTjqUBGg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 worker-src sdiapi.com sdiapi.net; font-src *.googleapis.com fonts.gstatic.com data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com js.klevu.com www.notcutts.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com www.notcutts.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com sdiapi.com sdiapi.net *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.notcutts.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com sdiapi.com sdiapi.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * web.notcutts.co.uk consentcdn.cookiebot.com js.stripe.com m.stripe.network *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com www.notcutts.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.dycdn.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com js.klevu.com imgsct.cookiebot.com www.facebook.com 'self' data: *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net www.xtento.com cdn.xtento.com www.notcutts.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com sdiapi.com sdiapi.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net am.freshrelevance.com *.klarnaservices.com js.klevu.com *.ksearchnet.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.stripe.com ls.dycdn.net consent.cookiebot.com analytics-eu.clickdimensions.com consentcdn.cookiebot.com web.notcutts.co.uk cdn-eu.clickdimensions.com www.google.com www.gstatic.com static.hotjar.com connect.facebook.net script.hotjar.com m.stripe.network *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com www.notcutts.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com cdn.jsdelivr.net js.klevu.com www.gstatic.com *.tagmanager.google.com *.googletagmanager.com www.notcutts.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com www.notcutts.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline';, connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com thm.visa.com sdiapi.com sdiapi.net api.addressy.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.dycdn.net am.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.klarnaservices.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com c12.dycdn.net consentcdn.cookiebot.com content.hotjar.io m.stripe.com region1.google-analytics.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app www.notcutts.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.notcutts.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src am.freshrelevance.com googleads.g.doubleclick.net ws.hotjar.com metrics.hotjar.io csp.threatview.app www.notcutts.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com https://www.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com self data: static.klaviyo.com *.craftyclicks.co.uk *.cc-cdn.com *.klarnacdn.net https://fonts.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.salesfire.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.craftyclicks.co.uk *.cc-cdn.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.craftyclicks.co.uk *.cc-cdn.com *.klarna.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.salesfire.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.tawk.to *.happybeds.co.uk *.google.co.uk *.bing.com *.facebook.com *.assets.adobedtm.com *.doubleclick.net *.adnxs.com *.craftyclicks.co.uk *.cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com *.salesfire.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com polyfill.io https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com https://*.gstatic.com *.trustedshops.com *.fontawesome.com *.facebook.net *.assets.adobedtm.com cdn-4.convertexperiments.com/v1/js/10042037-10042596.js *.criteo.com *.getblue.io *.dwin1.com *.bing.com *.roeyecdn.com cdn.jsdelivr.net/emojione/2.2.7/lib/js/emojione.min.js *.craftyclicks.co.uk *.cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.salesfire.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com *.tawk.to *.craftyclicks.co.uk *.cc-cdn.com https://static.klaviyo.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.salesfire.co.uk *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.cloudflare.com *.twitter.com *.twimg.com *.doubleclick.net *.criteo.com *.tawk.to wss://*.tawk.to api.retargeted.co *.bing.com *.craftyclicks.co.uk *.cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io *.salesfire.co.uk *.smartmetrics.co.uk *.stripe.com klarna.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.happybeds.co.uk/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.paddypallin.com.au data: *.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net *.paypal.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://*.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.paddypallin.com.au https://*.facebook.com https://*.google.com *.braintree-api.com *.braintreegateway.com *.dotdigital-pages.com *.dotdigital.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.google.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.twitter.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://img.youtube.com p.typekit.net *.ftcdn.net *.behance.net data: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.paddypallin.com.au *.nextopia.net https://*.zipmoney.com.au https://*.facebook.com *.data-dynamic.net https://api.feefo.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com *.google.com *.google.com.au *.google.co.in *.zip.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.searchspring.net/intellisuggest/is.min.js https://*.zip.com.au *.paddypallin.com.au *.nextopia.net *.ecomm-nav.com https://*.zipmoney.com.au *.nextopiasoftware.com connect.facebook.net https://*.safelinks.protection.outlook.com/ *.zdassets.com *.barilliance.com *.barilliance.net *.newrelic.com *.nr-data.net *.google.com https://*.cloudfront.net *.zopim.com *.afterpay.com *.braintree-api.com *.braintreegateway.com https://api.feefo.com https://register.feefo.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.afterpaycdn.com *.squarecdn.com *.cash.app www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.nextopia.net *.googleapis.com *.gstatic.com *.hotjar.com *.jsdelivr.net app.anyroad.com static.hotjar.com static.klaviyo.com stats.g.doubleclick.net *.google.co.in cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://www.googletagmanager.com tagmanager.google.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.paddypallin.com.au data: https://fonts.googleapis.com *.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net https://p.typekit.net *.nextopia.net *.cloudfront.net *.afterpay.com *.paypal.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app cdn.nextopia.net *.zip.co cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.paddypallin.com.au *.zdassets.com *.paypal.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://beacon.searchspring.io/beacon *.zopim.com *.google-analytics.com *.googleapis.com https://*.zipmoney.com.au *.paddypallin.com.au https://*.cloudfront.net https://*.zip.co https://*.zip.com.au *.nr-data.net *.zendesk.com *.zdassets.com *.afterpay.com *.braintreegateway.com https://api.feefo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.nextopia.net *.barilliance.net www.barilliance.net api.barilliance.net stats.g.doubleclick.net *.hotjar.io static.hotjar.com ws15.hotjar.com capig.stape.gl static.klaviyo.com widget-mediator.zopim.com *.google.co.in webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.cloudflare.com *.twitter.com *.twimg.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri *.wein.plus;connect-src *.wein.plus *.googleapis.com *.googletagmanager.com;child-src *.wein.plus;default-src 'none';media-src *.wein.plus;form-action *.wein.plus;img-src *.wein.plus data:;font-src *.wein.plus data: *.gstatic.com;manifest-src *.wein.plus;style-src *.wein.plus 'self' 'unsafe-inline';style-src-elem *.wein.plus 'unsafe-inline' *.google.com;script-src *.wein.plus 'self' 'unsafe-inline' *.etracker.com;script-src-elem *.wein.plus 'unsafe-inline' *.googletagmanager.com *.google.com *.etracker.com 1 default-src data: blob: https: 'unsafe-eval' 'unsafe-inline'; object-src 'none';worker-src 'self' https://dev.visualwebsiteoptimizer.com/ blob: data:; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com *.fontawesome.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.dotdigital-pages.com *.dotdigital.com https://www.trustedsite.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.weltpixel.com lpcdn.lpsnmedia.net https://*.liveperson.net https://*.lpsnmedia.net https://va-s.c.liveperson.net https://lpcdn.lpsnmedia.net https://static.addtoany.com/menu/sm.23.html https://amc.demdex.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.trackedlink.net https://cdn.ywxi.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com lpcdn.lpsnmedia.net *.worthingtondirect.com *.adentifi.com *.linkedin.com *.bing.com *.google.pl *.google.com *.facebook.com *.doubleclick.net https://*.liveperson.net https://*.lpsnmedia.net https://worthingtondirect.com https://www.worthingtondirect.com https://lpcdn.lpsnmedia.net https://d1zloi9myumgkb.cloudfront.net https://static-1.worthingtondirect.com https://s3.amazonaws.com https://amcglobal.sc.omtrdc.net https://amc.demdex.net https://dpm.demdex.net https://cm.everesttech.net https://cdnjs.cloudflare.com/ajax/libs/galleriffic/2.0.1/css/loader.gif data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://unpkg.com/react@18/umd/react.production.min.js https://unpkg.com/react-dom@18/umd/react-dom.production.min.js *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://cdn.ywxi.net https://www.trustedsite.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com assets.shipperhq.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com *.liveperson.net *.lpsnmedia.net cdn.ywxi.net https://cdn.jsdelivr.net/npm/swiper@11/ *.licdn.com *.bing.com *.invocacdn.com *.facebook.net https://*.liveperson.net https://*.lpsnmedia.net https://va-s.c.liveperson.net https://lptag.liveperson.net https://va.v.liveperson.net https://static.addtoany.com/menu/page.js https://lpcdn.lpsnmedia.net https://js-agent.newrelic.com/nr-1208.min.js https://accdn.lpsnmedia.net https://bam.nr-data.net https://js-agent.newrelic.com/nr-1209.min.js https://js-agent.newrelic.com/nr-1210.min.js https://assets.shipperhq.com/shq-checkout_0.1.85.js https://www.gstatic.com/recaptcha/releases/tftmXwdbgCvrXiHxr5HGbIaL/recaptcha__uk.js https://js-agent.newrelic.com https://web-sdk.aptrinsic.com/api/aptrinsic.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com assets.shipperhq.com *.trustpilot.com tagmanager.google.com https://cdn.jsdelivr.net/npm/swiper@11/ https://maxcdn.bootstrapcdn.com https://assets.shipperhq.com https://web-sdk.aptrinsic.com/style.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.liveperson.net https://*.lpsnmedia.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://s3-us-west-2.amazonaws.com/mfesecure-public/ https://www.trustedsite.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com rms.shipperhq.com wss://rms.shipperhq.com/ ovs.shipperhq.com https://www.google-analytics.com *.amazonaws.com *.linkedin.com lpcdn.lpsnmedia.net *.adentifi.com *.google-analytics.com *.doubleclick.net *.bing.com *.google.pl https://*.liveperson.net https://*.lpsnmedia.net https://bam.nr-data.net https://amcglobal.sc.omtrdc.net wss://rms.shipperhq.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.es mws.amazonservices.fr api.comapi.com webchat.dotdigital.com *.authorize.net yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com https://dpm.demdex.net https://esp-m.aptrinsic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.twitter.com *.gstatic.com *.cloudflare.com https://css.zohocdn.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.vimeo.com *.gstatic.com https://salesiq.zohopublic.eu https://translate.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com cdn.doofinder.com *.cloudflare.com *.klarna.com *.ytimg.com *.doubleclick.net *.gstatic.com https://salesiq.zohopublic.eu https://salesiq.zoho.eu *.mastercard.com https://static.hotjar.com https://*.zohopublic.eu https://*.zohocdn.com https://www.google.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.doofinder.com *.fontawesome.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.twitter.com https://salesiq.zohopublic.eu https://salesiq.zoho.eu https://js.zohocdn.com https://postcodeanywhere.co.uk https://static.zohocdn.com https://static.hotjar.com crm.zoho.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.avada.io www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com *.fontawesome.com https://css.zohocdn.com *.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com unsafe-inline assets.braintreegateway.com https://fonts.bunny.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.gstatic.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com *.google-analytics.com https://salesiq.zohopublic.eu https://salesiq.zoho.eu https://translate.google.com https://translate.googleapis.com wss://vts.zohopublic.eu https://*.g.doubleclick.net https://*.googlesyndication.com https://*.google.com https://*.google.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://get.geojs.io *.avada.io *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://cdn.consentmanager.net www.etracker.de de.etracker.com https://delivery.consentmanager.net https://use.typekit.net/eho0yem.js cdn.consentmanager.net delivery.consentmanager.ne use.typekit.net c.delivery.consentmanager.net https://doo.net https://www.doo.net https://wirvwsth.pi-asp.de https://widget.surveymonkey.com https://ajax.googleapis.com https://code.etracker.com/code/e.js code.etracker.com/code/e.js https://code.etracker.com/t.js code.etracker.com/t.js https://code.etracker.com/v1/consent-banners/N8Kcr3/icon https://code.etracker.com/v2/consent-banners/N8Kcr3/banner https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://doo.net https://www.doo.net https://wirvwsth.pi-asp.de https://widget.surveymonkey.com https://ajax.googleapis.com https://code.etracker.com/code/e.js code.etracker.com/code/e.js https://code.etracker.com/t.js code.etracker.com/t.js https://code.etracker.com/v1/consent-banners/N8Kcr3/icon https://code.etracker.com/v2/consent-banners/N8Kcr3/banner https://cdnjs.cloudflare.com; frame-ancestors 'self' https://doo.net https://www.doo.net https://wirvwsth.pi-asp.de https://widget.surveymonkey.com https://ajax.googleapis.com 1 base-uri 'self'; connect-src 'self' https://cms.mirka.com https://*.applicationinsights.azure.com https://js.monitor.azure.com/scripts/ https://consent.cookiebot.com https://consentcdn.cookiebot.com https://edge.fullstory.com https://rs.fullstory.com https://www.googletagmanager.com https://*.google-analytics.com https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/$rpc/ https://maps.googleapis.com/maps_api_js_slo/log https://smc-lp.s4hana.ondemand.com https://api.mavenoid.com/api/graphql https://plausible.io/api/event https://www.google.com/ccm/ https://pagead2.googlesyndication.com/ccm/ https://www.google.com/pagead/ https://px.ads.linkedin.com/ https://www.googleadservices.com/pagead/set_partitioned_cookie https://www.facebook.com/; frame-ancestors 'self' https://cms.mirka.com; frame-src 'self' https://consentcdn.cookiebot.com https://www.youtube.com https://mirka.paperturn-view.com https://www.paperturn-view.com https://www.paperturn.com https://player.bilibili.com https://www.googletagmanager.com https://www.facebook.com/ https://open.spotify.com/; object-src 'none'; worker-src 'self'; report-to csp-endpoint 1 font-src https://*.googleapis.com https://fast.wistia.com *.fontawesome.com *.googleapis.com *.gstatic.com blog.avery.ca data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://dpotest.print.avery.ca https://*.avery.ca self *.canadapost-postescanada.ca *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.canadapost.ca https://sso.epost.ca blog.avery.ca 'self' 'unsafe-inline'; frame-ancestors blog.avery.ca 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com accounts.google.com blog.avery.ca 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.facebook.com https://www.google.ca/ads/ga-audiences https://*.doubleclick.net https://assets.avery.ca https://*.wistia.com https://bat.bing.com https://c.bing.com/ https://c.clarity.ms/ https://dpotest.print.avery.ca https://*.avery.ca https://*.avery.com self https://s3.amazonaws.com https://averycamedia.blob.core.windows.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com mageside.com *.canadapost.ca *.canadapost-postescanada.ca *.googleapis.com *.gstatic.com *.trackedlink.net blog.avery.ca data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://fast.wistia.net https://fast.wistia.com https://*.glancecdn.net https://bat.bing.com https://*.clarity.ms https://*.facebook.net https://*.pingdom.net https://*.livechatinc.com https://api.ipstack.com https://*.jquery.com/* https://*.avery.ca https://static.cloudflareinsights.com/beacon.min.js https://ws1.postescanada-canadapost.ca/js/addresscomplete-2.50.min.js https://pulse.clickguard.com/s/acckzZHxHmJmO/astNWLAlQk0ke js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.google.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal accounts.google.com *.fontawesome.com blog.avery.ca 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.wistia.com https://*.googleapis.com https://ws1.postescanada-canadapost.ca/css/addresscomplete-2.50.min.css unsafe-inline assets.braintreegateway.com *.fontawesome.com *.googleapis.com accounts.google.com blog.avery.ca 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.avery.ca https://*.facebook.com blog.avery.ca 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.doubleclick.net https://fast.wistia.net https://*.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io/ https://pipedream.wistia.com https://distillery.wistia.com https://*.avery.ca https://*.glance.net https://*.clarity.ms/collect https://*.facebook.net https://www.facebook.com/tr/ https://rum-collector-2.pingdom.net https://*.livechatinc.com https://pulse.clickguard.com https://bat.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com accounts.google.com blog.avery.ca 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blog.avery.ca http: https: blob: 'self' 'unsafe-inline'; default-src blog.avery.ca 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.stape.io *.fontawesome.com *.googleapis.com * data: *.oct8ne.com instantcredit.net test.instantcredit.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de * www.paycomet.com api.paycomet.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com *.google.com.ua *.google.co.uk *.stape.io * *.oct8ne.com www.paycomet.com api.paycomet.com https://plumrocket.com *.sendcloud.sc *.jsdelivr.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com eu1-doofinderuser.s3.amazonaws.com us1-doofinderuser.s3.amazonaws.com *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.doubleclick.net *.stape.io * https://www.magezon.com *.oct8ne.com instantcredit.net test.instantcredit.net *.amazonaws.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.fontawesome.com *.googleapis.com *.avada.io * *.oct8ne.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com *.sendcloud.sc *.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com * instantcredit.net test.instantcredit.net *.sendcloud.sc *.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.google.com *.stape.io https://get.geojs.io *.avada.io * *.oct8ne.com instantcredit.net test.instantcredit.net *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: 'unsafe-inline'; font-src 'self' https: data: moz-extension ms-browser-extension; img-src 'self' http: data: s3.amazonaws.com; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com/ajax/libs/axe-core https://www.google.com/recaptcha/api.js https://ssl.google-analytics.com/ga.js https://js-agent.newrelic.com; script-src-elem 'self' https: 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com/ajax/libs/axe-core https://www.google.com/recaptcha/api.js https://ssl.google-analytics.com/ga.js https://js-agent.newrelic.com; style-src 'self' https: 'unsafe-inline'; frame-src 'self' https:; media-src 'self' data:; worker-src 'self' blob:; connect-src 'self' https://bam.nr-data.net wss://127.0.0.1:* wss://localhost:* https://rum.browser-intake-us5-datadoghq.com; report-uri /csp_violations/report 1 default-src 'self' data: *.facebook.com *.google.com.au *.tpc.googlesyndication.com *.stats.g.doubleclick.net *.google.co.in *.tgtag.io *.youtube.com *.abtasty.com *.gstatic.com *.googleapis.com *.amazonaws.com *.powerfront.com *.exacttarget.com *.adimo.co *.adimouat.co *.amazonaws.com *.formstack.com *.clarity.ms *.bing.com *.adswizz.com *.spotify.com *.googletagmanager.com *.adnxs.com *.aidemsrv.com *.criteo.com *.pinimg.com *.omguk.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.cquotient.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com; script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.site.com *.flippingbook.com *.criteo.net *.cquotient.com *.adyen.com *.doubleclick.net *.hotjar.com *.google.com *.googleapis.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.paypal.com *.paypalobjects.com *.facebook.net *.googletagmanager.com *.datatoolscloud.net.au *.igodigital.com *.salesforceliveagent.com *.serving-sys.com *.force.com *.tiqcdn.com *.rezdy.com *.polyfill.io *.cloudflare.com *.subscribepro.com *.dwin1.com *.criteo.com *.adnxs.com *.salesforce.com *.wayin.com *.typekit.net *.ooyala.com *.licdn.com *.getwisp.co *.omneo.io *.vimeo.com *.formstack.com *.thefork.com.au *.resy.com *.tealiumiq.com *.yimg.com *.go2cloud.org *.adobe.com *.cloudfront.net *.sc-static.net sc-static.net *.adsrvr.org *.googleoptimize.com *.googleanalytics.com *.bing.com *.facebook.com *.google.com.au *.tpc.googlesyndication.com *.stats.g.doubleclick.net *.google.co.in *.onelink-edge.com *.inside-graph.com *.fouanalytics.com *.tgtag.io *.youtube.com *.byspotify.com *.abtasty.com *.tryzens.com *.powerfront.com *.exacttarget.com blob: *.adimo.co *.adimouat.co *.amazonaws.com *.clarity.ms *.bing.com *.adswizz.com *.spotify.com *.aidemsrv.com *.pinimg.com *.omguk.com commerceops.tryzens-analytics.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.cquotient.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com *.dyntrk.com unpkg.com; style-src 'self' data: 'unsafe-inline' 'unsafe-hashes' *.site.com *.adyen.com *.googleapis.com *.force.com *.omneo.io *.subscribepro.com *.datatoolscloud.net.au *.salesforceliveagent.com *.ooyala.com *.formstack.com *.thefork.com.au *.go2cloud.org *.sc-static.net *.google.com *.google-analytics.com *.bing.com *.facebook.com *.google.com.au *.tpc.googlesyndication.com *.stats.g.doubleclick.net *.google.co.in *.inside-graph.com *.fouanalytics.com *.tgtag.io *.youtube.com *.byspotify.com *.abtasty.com *.gstatic.com *.powerfront.com *.exacttarget.com *.adimo.co *.adimouat.co *.amazonaws.com *.clarity.ms *.adswizz.com *.spotify.com *.googletagmanager.com *.adnxs.com *.aidemsrv.com *.criteo.com *.pinimg.com *.omguk.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.cquotient.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com; img-src 'self' data: *.penfolds.com *.site.com *.cloudfront.net *.flippingbook.com *.adyen.com *.doubleclick.net *.facebook.com *.adform.net *.mediavine.com *.postrelease.com *.360yield.com *.twiago.com *.adscale.de *.1rx.io *.meba.kr *.rubiconproject.com *.aralego.com *.daum.net *.adsrvr.org *.dotomi.com *.contextweb.com *.admixer.co.kr *.adsymptotic.com *.smrtb.com *.bnmla.com *.tpmn.co.kr *.zemanta.com *.stackadapt.com *.kakao.com *.toast.com *.outbrain.com *.addthis.com *.gstatic.com *.google-analytics.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.bidswitch.net *.salesforce.com *.googletagmanager.com *.googleapis.com *.paypal.com *.mookie1.com *.igodigital.com *.adnxs.com *.googleadservices.com *.zenaps.com *.placeholder.com *.facebook.net *.3lift.com *.ad-stir.com *.adtdp.com *.advertising.com *.bing.com *.casalemedia.com *.clmbtech.com *.criteo.com *.dmxleo.com *.ivitrack.com *.mgid.com *.omnitagjs.com *.pubmatic.com *.rlcdn.com *.sharethrough.com *.smartadserver.com *.socdm.com *.stickyadstv.com *.taboola.com *.tapad.com *.yahoo.com *.yieldmo.com *.dable.io *.adingo.jp *.gssprt.jp *.microad.jp *.demandware.net *.media.net *.openx.net *.smaato.net *.smartclip.net *.yieldlab.net *.teads.tv *.ants.vn *.adswizz.com *.serving-sys.com *.unsplash.com *.typekit.net *.linkedin.com *.vimeocdn.com *.hotjar.com *.mathtag.com *.tealiumiq.com *.yimg.com *.go2cloud.org *.tpc.googlesyndication.com *.stats.g.doubleclick.net *.inside-graph.com *.fouanalytics.com *.tgtag.io *.youtube.com *.abtasty.com *.amazonaws.com *.powerfront.com *.exacttarget.com blob: *.adimo.co *.adimouat.co *.amazonaws.com *.formstack.com *.clarity.ms *.bing.com *.spotify.com *.aidemsrv.com *.pinimg.com *.omguk.com *.cquotient.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com *.dyntrk.com cdn.n.dynstc.com; font-src 'self' data: *.site.com *.sfdcstatic.com *.gstatic.com *.typekit.net *.hotjar.com *.ooyala.com *.formstack.com *.go2cloud.org *.inside-graph.com *.fouanalytics.com *.byspotify.com *.abtasty.com *.googleapis.com *.powerfront.com *.exacttarget.com blob: *.adimo.co *.adimouat.co *.amazonaws.com *.clarity.ms *.bing.com *.adswizz.com *.spotify.com *.googletagmanager.com *.adnxs.com *.aidemsrv.com *.facebook.com *.criteo.com *.pinimg.com *.omguk.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.cquotient.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com; connect-src 'self' *.site.com *.analytics.google.com analytics.google.com *.flippingbook.com *.hotjar.com *.hotjar.io *.serving-sys.com *.paypal.com *.tryzens-analytics.com:12280 *.tryzens-analytics.com:12443 *.google-analytics.com *.googleapis.com *.tealiumiq.com *.facebook.net *.demandware.net *.ooyala.com *.getomneo.com *.force.com wss: *.yimg.com *.adobe.io *.snapchat.com *.onelink-edge.com *.inside-graph.com *.fouanalytics.com *.youtube.com *.byspotify.com *.abtasty.com https://google.com *.google.com *.adyen.com *.powerfront.com *.exacttarget.com *.adimo.co *.adimouat.co *.amazonaws.com *.formstack.com *.clarity.ms *.bing.com *.adswizz.com *.spotify.com *.googletagmanager.com *.adnxs.com *.aidemsrv.com *.facebook.com *.criteo.com *.pinimg.com *.omguk.com *.cquotient.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com commerceops.tryzens-analytics.com; frame-src 'self' *.adsrvr.org *.vintagejournal.co *.doubleclick.net *.paypalobjects.com *.adyen.com *.hotjar.com *.facebook.com *.criteo.net *.paypal.com *.google.com *.force.com *.rezdy.com *.matterport.com *.criteo.com *.vimeo.com *.wayin.com *.typekit.net *.ooyala.com *.snazzymaps.com https://snazzymaps.com *.spotify.com *.exacttarget.com *.sfmc-content.com *.thefork.com.au *.lafourchette.com *.resy.com vimeo.com *.serving-sys.com *.flipsnack.com *.adobe.com *.opinionstage.com *.cloudfront.net *.penfolds.com *.snapchat.com *.bing.com *.inside-graph.com *.fouanalytics.com *.youtube.com *.byspotify.com *.abtasty.com *.gstatic.com *.googleapis.com *.amazonaws.com *.powerfront.com *.exacttarget.com *.adimo.co *.adimouat.co *.amazonaws.com *.formstack.com *.clarity.ms *.adswizz.com *.spotify.com *.googletagmanager.com *.adnxs.com *.aidemsrv.com *.pinimg.com *.omguk.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.cquotient.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com; worker-src 'self' blob: *.datatoolscloud.net.au *.adyen.com *.cloudflare.com *.cquotient.com *.dwin1.com *.force.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.igodigital.com *.licdn.com *.paypal.com *.paypalobjects.com *.rezdy.com *.salesforceliveagent.com *.serving-sys.com *.tiqcdn.com *.polyfill.io *.doubleclick.net *.facebook.net 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.getwisp.co *.criteo.com *.subscribepro.com *.youtube.com *.powerfront.com *.exacttarget.com *.adimo.co *.adimouat.co *.amazonaws.com *.formstack.com *.clarity.ms *.bing.com *.adswizz.com *.spotify.com *.adnxs.com *.aidemsrv.com *.facebook.com *.pinimg.com *.omguk.com *.cquotient.com *.abtasty.com *.bing.com *.cellardoor.co *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.force.com *.fouanalytics.com *.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.igodigital.com *.linkedin.com *.omneo.io *.penfolds.cn *.penfolds.com *.salesforce.com *.salesforceliveagent.com *.spotify.com *.subscribepro.com *.tealiumiq.com *.tiqcdn.com *.vimeocdn.com *.wolfblass.com *.pinterest.com *.linkedin.com *.licdn.com *.smartadserver.com;; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/tweau-cspdata; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net; script-src 'nonce-ca4593d7c632498490bd90c0bbd7b18c' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net; style-src 'self' 'nonce-ca4593d7c632498490bd90c0bbd7b18c' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.playlostark.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://d3irh93dd5ckql.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=147-6007992-3913607:rid=4A4D1E690F1240588533:sn=www.playlostark.com 1 base-uri 'self'; form-action 'self'; default-src 'self'; connect-src 'self' data: https://stats.nederhost.nl/ https://zammad.nederhost.nl/ wss://zammad.nederhost.nl/; frame-ancestors 'none'; frame-src 'self'; img-src 'self' data:; report-to csp-endpoint; report-uri /_/report_csp_violation; script-src 'self' 'nonce-P9y2TeUnAg6kYZnX' 'unsafe-eval' https://stats.nederhost.nl/ https://cdn.matomo.cloud/stats.nederhost.nl/ https://zammad.nederhost.nl/; style-src 'self' data: 'nonce-P9y2TeUnAg6kYZnX' https://zammad.nederhost.nl/; style-src-attr 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com *.hotjar.com fonts.googleapis.com cdn.cookiehub.eu https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.networkmerchants.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com googleads.g.doubleclick.net secure.livechatinc.com *.weltpixel.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.amazonaws.com bat.bing.com cdn.ywxi.net blob *.instantsearchplus.com *.bbb.org cdn.livechat-files.com *.facebook.com *.hotjar.com *.clarity.ms *.bing.com *.google.com.ar www.doubleclick.net cdn.cookiehub.eu p.brsrvr.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.networkmerchants.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.certcapture.com *.fontawesome.com *.livechatinc.com bat.bing.com *.clarity.ms 199001.tctm.co *.facebook.net *.facebook.com *.cokertirecompany.com *.hotjar.com e.zip-corvette.com www.googletagservices.com www.doubleclick.net cdn.cookiehub.eu cdn.brcdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.networkmerchants.com *.certcapture.com *.bootstrapcdn.com static-autocomplete.fastsimon.com ping.fastsimon.com settings.fastsimon.com static-grid.fastsimon.com *.typekit.net cdn.cookiehub.eu cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://www.zip-corvette.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.clarity.ms api.livechatinc.com bat.bing.com api.fastsimon.com suggest.instantsearchplus.com suggest.fastsimon.com static-autocomplete.fastsimon.com static-grid.fastsimon.com ping.fastsimon.com settings.fastsimon.com stats.g.doubleclick.net bam.nr-data.net 199001.tctm.co *.facebook.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com googleads.g.doubleclick.net cdn.cookiehub.eu c.ba.contentsquare.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' data: 'unsafe-inline' https://*.googleapis.com https://*.googletagmanager.com https://*.google-analytics.com https://*.cookiebot.com https://*.doubleclick.net https://*.googletagservices.com https://*.youtube.com https://*.vimeo.com https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline' *.googleapis.com https://*.typekit.net; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.cookiebot.com https://securepubads.g.doubleclick.net https://*.googletagservices.com https://i.ytimg.com https://*.google.nl https://*.google.com https://*.typekit.net https://*.googleapis.com https://*.gstatic.com https://secure.gravatar.com; font-src 'self' data: https://fonts.gstatic.com https://*.typekit.net https://*.wp.com; frame-src https://*.youtube.com https://*.youtube-nocookie.com https://*.vimeo.com https://*.cookiebot.com https://*.doubleclick.net https://*.googletagservices.com https://*.googletagmanager.com https://challenges.cloudflare.com; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://*.cookiebot.com https://*.vimeo.com https://*.google.com https://*.google.nl https://*.doubleclick.net https://*.googleapis.com https://yoast.com; object-src 'none'; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn2.hubspot.net resources.paytrail.com *.google.fi data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.paytrail.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.tawk.to *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de pay.google.com/ *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com bat.bing.com www.facebook.com www.google.co.uk www.google.com googleads.g.doubleclick.net www.googletagmanager.com www.gstatic.com embed.tawk.to fonts.gstatic.com translate.googleapis.com translate.google.com *.clarity.ms *.bing.com tawk.link *.sagepay.com *.paypal.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.googletagmanager.com apis.google.com googleads.g.doubleclick.net www.gstatic.com bat.bing.com www.buzzcateringsupplies.com connect.facebook.net cdn.jsdelivr.net embed.tawk.to translate.google.com translate.googleapis.com translate-pa.googleapis.com www.clarity.ms *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com www.buzzcateringsupplies.com *.tawk.to www.gstatic.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.google.co.uk www.googleadservices.com *.g.doubleclick.net maps.googleapis.com *.tawk.to wss://*.tawk.to translate.googleapis.com translate-pa.googleapis.com bat.bing.com *.clarity.ms region1.google-analytics.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.cloudflare.com *.magentocommerce.com *.razorpay.com *.paypal.com *.cloudfront.net *.vimeocdn.com *.ssl-images-amazon.it *.facebook.net *.facebook.com *.ksearchnet.com *.ccavenue.com *.klevu.com *.twitter.com *.golfoy.com golfoy.com *.googletagmanager.com *.youtube.com *.ads-twitter.com *.google.com *.licdn.com *.heatmap.it *.prism.app-us1 *.linkedin.com *.doubleclick.net *.google.co.in *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.doubleclick.net *.vimeocdn.com https://www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.addthis.com *.facebook.com *.twitter.com api.razorpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.cloudflare.com https://golfoy.com *.golfoy.com cdn.golfoy.com t.co *.magentocommerce.com *.razorpay.com *.paypal.com *.cloudfront.net *.ssl-images-amazon.it *.facebook.net *.facebook.com *.ksearchnet.com *.ccavenue.com *.klevu.com *.twitter.com golfoy.com *.ads-twitter.com *.google.com *.licdn.com *.heatmap.it *.prism.app-us1 *.linkedin.com *.doubleclick.net *.google.co.in www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.addthisedge.com https://firebasestorage.googleapis.com https://maps.gstatic.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ diffuser-cdn.app-us1.com prism.app-us1.com *.cloudflare.com *.magentocommerce.com *.razorpay.com *.paypal.com *.cloudfront.net *.ssl-images-amazon.it *.facebook.net *.facebook.com *.ksearchnet.com *.ccavenue.com *.klevu.com *.twitter.com *.golfoy.com golfoy.com *.googletagmanager.com *.ads-twitter.com *.google.com *.licdn.com *.heatmap.it *.prism.app-us1 *.linkedin.com *.doubleclick.net *.google.co.in https://www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.avada.io *.shopify.com https://maps.googleapis.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com https://golfoy.com *.golfoy.com cdn.golfoy.com *.googleapis.com *.bulkgate.com *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.magentocommerce.com *.razorpay.com *.paypal.com *.cloudfront.net *.vimeocdn.com *.ssl-images-amazon.it *.facebook.net *.facebook.com *.ksearchnet.com *.ccavenue.com *.klevu.com *.twitter.com *.golfoy.com golfoy.com *.googletagmanager.com *.youtube.com *.ads-twitter.com *.google.com *.licdn.com *.heatmap.it *.linkedin.com *.doubleclick.net *.t.co *.prism.app-us1.com *.diffuser-cdn.app-us1.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ekr.zdassets.com/ https://get.geojs.io *.avada.io https://maps.googleapis.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com *.wizzy.ai wss://sockets.wizzy.ai *.wizsearch.in wss://sockets.wizsearch.in 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.thuis.nl *.camcammer.com *.sensemakers.com *.test.paysafe.com *.cloudflare.com *.exoclick.com cdn.pushcrew.com *.ingest.sentry.io *.paysafe.com *.google.com *.google.nl *.google.sr *.google.be *.google.gr *.google.fr *.google-analytics.com stats.g.doubleclick.net *.doubleclick.net *.slack-edge.com *.googletagmanager.com analytics.sensemakers.nl *.hotjar.com *.hotjar.io; connect-src 'self' 'unsafe-inline' 'unsafe-eval' wss://*.thuis.nl/ wss://*.sensemakers.com wss://ws.hotjar.com/ *.sensemakers.com stats.g.doubleclick.net *.ingest.sentry.io analytics.sensemakers.nl *.google.com *.google.nl *.google.sr *.google.be *.google.gr *.google.fr *.analytics.google.com stats.g.doubleclick.net *.hotjar.io *.hotjar.com *.test.paysafe.com *.paysafe.com *.thuis.nl *.google-analytics.com; img-src * 'self' data: https: blob: https; font-src * 'self' data:; report-uri https://analytics.sensemakers.nl/csp/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.voltlighting.com *.google.com *.cloudfront.net *.amazonaws.com *.klevu.com *.fontawesome.com *.googleapis.com *.socialannex.com *.amplighting.com voltlighting.com *.voltlighting.com *.hotjar.com *.bazaarvoice.com *.ksearchnet.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.google.com *.gstatic.com www.facebook.com *.amazonaws.com *.amplighting.com voltlighting.com *.voltlighting.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.gstatic.com www.facebook.com *.googletagmanager.com *.googleapis.com *.amazonaws.com *.paypalobjects.com amc.demdex.net fast.amc.demdex.net nsg.symantec.com *.hotjar.com www.pinterest.com *.twitter.com *.socialannex.net *.amplighting.com voltlighting.com nytrng.com *.attn.tv *.guarantee-cdn.com *.fls.doubleclick.net *.googlesyndication.com td.doubleclick.net app.fastbots.ai 12521576.fls.doubleclick.net ssl.kaptcha.com www.youtube.com www.google.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.weltpixel.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.voltlighting.com *.googleusercontent.com *.google.com *.klevu.com bat.bing.com www.facebook.com connect.facebook.net www.google.co.in *.amazonaws.com dpm.demdex.net amc.demdex.net *.visualwebsiteoptimizer.com *.powerreviews.com nsg.symantec.com *.wpengine.com cdn.socialannex.com *.cloudinary.com *.gravatar.com *.adobedtm.com *.amplighting.com voltlighting.com *.voltlighting.com *.trackedlink.net *.b0e8.com *.guarantee-cdn.com *.clarity.ms *.bing.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net wt.rqtrk.eu id5-sync.com *.paypalobjects.com track.hubspot.com d7keiwzj12p9.cloudfront.net ad.doubleclick.net adservice.google.com cdn-assets.affirm.com s3.amazonaws.com m.media-amazon.com 'self' blob: cdn.bfldr.com storage-us-gcs.bfldr.com cdn.userway.org yt3.ggpht.com www.youtube.com www.gstatic.com guarantee-cdn.com volt.dev csi.gstatic.com cm.everesttech.net graph.facebook.com business.facebook.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.ksearchnet.com https://redchamps.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.adobe.com js-na1.hs-scripts.com bat.bing.com *.gstatic.com *.klevu.com www.facebook.com *.cloudfront.net *.doubleclick.net *.powerreviews.com unpkg.com *.visualwebsiteoptimizer.com *.amazonaws.com *.googletagmanager.com *.googleapis.com nsg.symantec.com a.opmnstr.com bam.nr-data.net bam-cell.nr-data.net cdn.socialannex.com *.hotjar.com *.instagram.net cdn.plyr.io stackpath.bootstrapcdn.com dn.jsdelivr.net code.jquery.com *.socialannex.com *.amplighting.com voltlighting.com *.voltlighting.com *.bc0a.com cdn.attn.tv guarantee-cdn.com cdn.b0e8.com *.clarity.ms *.lfeeder.com shop.pe *.shop.pe wt.rqtrk.eu cdn.id5-sync.com *.blackcrow.ai *.bttrack.com *.google.co.in *.trackedlink.net *.googleadservices.com *.trackedweb.net *.authorize.net *.sandbox.paypal.com analytics.tiktok.com tpc.googlesyndication.com js.hs-scripts.com js.hs-analytics.net js.hs-banner.com *.cardinalcommerce.com static.elfsight.com js.hscollectedforms.net js.usemessages.com cdn.userway.org api.userway.org bigsur.ai consents-cf.bc0a.com d2mjzob2nc713b.cloudfront.net cdn1.affirm.com pixel.api.blokid.com addshoppers.s3.amazonaws.com shopper.shop.pe static.cloudflareinsights.com r.wdfl.co static-na.payments-amazon.com ssl.kaptcha.com *.facebook.com *.google-analytics.com js.klevu.com app.fastbots.ai apis.google.com cdn.bc0a.com connect.facebook.net static.doubleclick.net www.google.com www.gstatic.com js-agent.newrelic.com cdn.nytrng.com universe-static.elfsightcdn.com graph.facebook.com business.facebook.com https://maps.googleapis.com maps.googleapis.com *.ksearchnet.com *.kaptcha.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com display.ugc.bazaarvoice.com www.voltlighting.com *.google.com *.klevu.com *.powerreviews.com *.gstatic.com *.cloudfront.net *.amazonaws.com stats.g.doubleclick.net *.socialannex.com *.amplighting.com voltlighting.com *.voltlighting.com *.hotjar.com cdn.userway.org app.fastbots.ai *.fontawesome.com www.youtube.com *.ksearchnet.com *.tagmanager.google.com *.googletagmanager.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com voltlighting.tt.omtrdc.net bat.bing.com *.gstatic.com *.amazonaws.com *.googletagmanager.com *.googleapis.com *.dotdigital.com dpm.demdex.net amcglobal.sc.omtrdc.net *.cardinalcommerce.com *.trackedlink.net *.trackedweb.net stats.g.doubleclick.net get.geojs.io *.powerreviews.com api.omappapi.com *.wpengine.com stats.ksearchnet.com *.ksearchnet.com *.demdex.net *.visualwebsiteoptimizer.com *.amplighting.com *.voltlighting.com *.bc0a.com *.clarity.ms *.google-analytics.com *.analytics.google.com *.g.doubleclick.net events.attentivemobile.com lb.eu-1-id5-sync.com id5-sync.com *.hotjar.io *.blackcrow.ai *.authorize.net core.service.elfsight.com *.hubspot.com *.hscollectedforms.net *.elfsight.com *.safeopt.com voltlighting.wpengine.com ixfd2-api.bc0a.com statsjs.klevu.com www.affirm.com cdn-assets.affirm.com api.prod.bigsur.ai voltlighting.attn.tv firebaseremoteconfig.googleapis.com app.shop.pe dp70uvwpivouv.cloudfront.net api.userway.org cdn.userway.org cdn77.api.userway.org apay-us.amazon.com shopper.shop.pe ssl.kaptcha.com *.resolvepay.com www.youtube.com googleads.g.doubleclick.net jnn-pa.googleapis.com play.google.com app.fastbots.ai bam.nr-data.net www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com *.klevu.com *.kaptcha.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src www.voltlighting.com www.google-analytics.com pixel.tracking.blokid.com www.google.com bat.bing.com events.attentivemobile.com commerce.adobedc.net network-a.bazaarvoice.com apay-us.amazon.com app.fastbots.ai bam.nr-data.net tracker.affirm.com www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.voltlighting.com/; report-to report-endpoint; 1 font-src *.amazonaws.com *.cloudfront.net *.fontawesome.com fonts.googleapis.com *.googleapis.com *.gstatic.com fonts.gstatic.com google.com gstatic.com *.hotjar.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://seo.mageplaza.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors cf.dev-gorgany.com cf.gorgany.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.google.com/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.addthis.com cf.dev-gorgany.com cf.gorgany.com apptrian.com *.hotjar.com xtento.com creativecdn.com *.googletagmanager.com *.creativecdn.com *.doubleclick.net www.xtento.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.magezon.com *.amazonaws.com *.cloudfront.net * maps.gstatic.com maps.google.com cf.dev-gorgany.com cf.gorgany.com www.google.com.ua www.google.de www.xtento.com cdn.xtento.com *.alothemes.com *.magepow.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.google.com/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.amazonaws.com *.cloudfront.net *.fontawesome.com *.googleapis.com *.gstatic.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com https://static.addtoany.com * js-agent.newrelic.com *.doubleclick.net cf.dev-gorgany.com cf.gorgany.com *.hotjar.com *.googletagmanager.com https://accounts.google.com www.xtento.com cdn.xtento.com *.alothemes.com *.magepow.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.amazonaws.com *.cloudfront.net *.fontawesome.com cf.dev-gorgany.com cf.gorgany.com fonts.googleapis.com https://accounts.google.com *.alothemes.com *.magepow.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.amazonaws.com *.cloudfront.net *.addthis.com *.esputnik.com esputnik.com maps.googleapis.com *.analytics.google.com *.doubleclick.net cf.dev-gorgany.com cf.gorgany.com *.googleadservices.com *.google-analytics.com paypalobjects.com paypal.com youtube.com *.googletagmanager.com xtento.com player.vimeo.com sandbox.paypal.com *.google.com *.creativecdn.com *.hotjar.io *.hotjar.com ws.hotjar.com *.alothemes.com *.magepow.com *.facebook.net 'self' 'unsafe-inline'; child-src cf.dev-gorgany.com cf.gorgany.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem 'self' https://*.visa.com https://*.bc.earlywarning.com https://bc.earlywarning.com https://*.mastercard.com https://api-mastercard-src.nd.nudatasecurity.com https://*.discover.com https://*.discover-src.com https://*.discovercard.com https://*.americanexpress.com https://*.aexp-static.com https://*.google-analytics.com https://*.googleapis.com https://*.googletagmanager.com https://*.doubleclick.net https://payments.google.com https://translate.google.com https://*.amazonaws.com https://spay.samsung.com https://cdnjs.cloudflare.com; font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://d1cwup7r903a1d.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.magezon.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com magefan.com cm.magefan.com https://scontent.cdninstagram.com https://firebasestorage.googleapis.com *.meetanshi.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' https://*.visa.com https://*.bc.earlywarning.com https://bc.earlywarning.com https://*.mastercard.com https://api-mastercard-src.nd.nudatasecurity.com https://*.discover.com https://*.discover-src.com https://*.discovercard.com https://*.americanexpress.com https://*.aexp-static.com https://*.google-analytics.com https://*.googletagmanager.com https://*.doubleclick.net https://payments.google.com https://translate.google.com https://*.amazonaws.com https://spay.samsung.com https://cdnjs.cloudflare.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.avada.io *.shopify.com 'unsafe-inline' *.tapfiliate.com cdn.routeapp.io https//fonts.googleapis.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com https://cdn.searchspring.net/intellisuggest/is.min.js maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com 'self' https://*.visa.com https://*.bc.earlywarning.com https://bc.earlywarning.com https://*.aexp-static.com https://*.assets.mastercard.com https://*.discover.com https://*.discover-src.com https://*.discovercard.com https://*.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com https://fonts.bunny.net 'unsafe-inline' https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://graph.instagram.com https://get.geojs.io *.avada.io 'self' api.route.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com https://beacon.searchspring.io/beacon 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src *.bimco.org *.cookiebot.com *.dotdigital-pages.com *.doubleclick.net *.googletagmanager.com 'self';font-src *.gstatic.com data: 'self';img-src data: https: 'self';script-src https: 'self' 'strict-dynamic' 'unsafe-eval' 'nonce-bV8t0YWymqfRK2Y+nGDQygtn';connect-src https: 'self';style-src https: 'self' 'unsafe-inline';default-src 'self' 1 font-src 'self' data:; default-src 'none'; base-uri 'none'; connect-src 'self' *.algolia.net *.algolianet.com *.algolia.io; worker-src 'none'; style-src 'unsafe-inline' *; object-src 'none'; img-src blob: data: *; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-MJXGczhJbBJ9nUBXd5mj1w=='; media-src * 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://js-eu1.hubspot.com/ https://consent.cookiefirst.com/ https://www.googleoptimize.com/ https://www.googletagmanager.com/ https://googletagmanager.com https://tagmanager.google.com https://track.gaconnector.com/ https://leadbooster-chat.pipedrive.com https://static.hotjar.com/ https://js-eu1.hs-scripts.com https://js-eu1.hs-analytics.net/ https://js-eu1.usemessages.com/ https://js-eu1.hs-banner.com/ https://www.google.com/ https://www.gstatic.com/ https://script.hotjar.com https://js-eu1.hsforms.net https://calendly.com/ https://cdn.jsdelivr.net; connect-src 'self' wss://ws.hotjar.com/ https://content.hotjar.io/ https://track.gaconnector.com/ https://consent.cookiefirst.com/ https://api-eu1.hubspot.com https://edge.cookiefirst.com https://region1.google-analytics.com/ https://pagead2.googlesyndication.com/ https://leadbooster-chat.pipedrive.com/ https://forms-eu1.hsforms.com/ https://api.mapbox.com/ https://events.mapbox.com/; img-src 'self' https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://track-eu1.hubspot.com/ https://secure.gravatar.com/ https://forms-eu1.hsforms.com/ https://s.w.org/ https://www.googletagmanager.com/ https://ps.w.org/ https://www.admincolumns.com data:; style-src 'self' 'unsafe-inline' https://api.fontshare.com/ https://consent.cookiefirst.com/ https://calendly.com/ https://fonts.googleapis.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://cdn.fontshare.com/ https://leadbooster-chat.pipedrive.com/ data:; frame-src https://www.google.com https://app-eu1.hubspot.com/ 'self'; 1 font-src https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors localhost:* *.motive.co 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.googletagmanager.com/ *.google.com/ *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com js.monei.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.connectif.cloud ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.magezon.com *.motive.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.connectif.cloud chimpstatic.com downloads.mailchimp.com *.list-manage.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.google.com/ *.motive.co *.cloudflare.com js.monei.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.connectif.cloud http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io http://dpm.demdex.net *.motive.co api.monei.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.google-analytics.com go.trustpayments.com *.onetrust.com *.fontawesome.com *.gstatic.com *.googleapis.com *.cloudflareinsights.com *.trustpilot.com *.zdassets.com *.google.com *.omniconvert.com *.googletagmanager.com *.licdn.com *.facebook.net *.hotjar.com *.cloudflare.com *.yoast.com *.dropbox.com *.live.net ; style-src 'self' 'unsafe-inline' *.onetrust.com *.fontawesome.com *.gstatic.com *.googleapis.com; style-src-elem * 'self' 'unsafe-inline'; img-src 'self' data: 'unsafe-inline' *.linkedin.com *.google.com *.google.co.uk *.onetrust.com *.gstatic.com *.gravatar.com *.trustpayments.com *.zdassets.com *.facebook.com *.google-analytics.com *.google.com.mt; font-src 'self' data: 'unsafe-inline' *.gstatic.com *.trustpayments.com *.fontawesome.com; connect-src 'self' 'unsafe-inline' *.onetrust.com *.google.com *.zendesk.com *.clarity.ms *.omniconvert.com *.fontawesome.com *.cloudflareinsights.com *.zdassets.com *.yoast.com *.linkedin.com *.doubleclick.net *.hotjar.io *.google-analytics.com; media-src 'self' 'unsafe-inline' data:; object-src 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; frame-src 'self' 'unsafe-inline' *.trustpilot.com *.google.com; worker-src 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; base-uri 'self'; manifest-src 'self' 'unsafe-inline'; report-uri https://www.trustpayments.com/csp-violation-report/ 1 default-src https: data: blob:; script-src https: blob: 'unsafe-inline' 'unsafe-eval' https://cmp.osano.com; style-src https: 'unsafe-inline'; connect-src https: wss:; form-action 'self' www.facebook.com forms.hsforms.com; object-src 'self'; base-uri 'self'; 1 frame-src *.youtube.com 1 font-src instantcredit.net test.instantcredit.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io instantcredit.net test.instantcredit.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com instantcredit.net test.instantcredit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com instantcredit.net *.instantcredit.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' *.cquotient.com *.dixa.io *.facebook.com *.forter.com *.global-e.com *.johnvarvatos.com *.klaviyo.com acsbapp.com app.pendo.io assets.ntcacdn.net bat.bing.com cdn-ukwest.onetrust.com cdn.jsdelivr.net container.pepperjam.com d16fk4ms6rqz1v.cloudfront.net dlthst9q2beh8.cloudfront.net googleads.g.doubleclick.net pendo-static-5872700213952512.storage.googleapis.com siteperformancetest.net tag.rmp.rakuten.com www.googletagmanager.com www2.bglobale.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=5YuyL3Y7z4teTbMmrn82O_LwPav0z74J2GgwJUeo67E-1765933752-1.0.1.1-JStS99v2IRRdDLJoqRovg79hLmVMdaf_3noK9LapJ4e44RUQAtr8ysrUc1mQMPo2gAm9ES4Q.vfdSL0HBCBqNZHphJSAa4hqSOSq8jLJVqq0akwgaJ6EIy1qAAuD2V_huGQss08AsFqGRujVABKilajzeD40rKBM9LWZqYmKsXtkjAsECOi..9NBCgz2NonwUtdnv9Zn1nVaCHbDkkSAFw; report-to cf-khtapdfafigumxbh 1 font-src data: *.gstatic.com oct8necdneu.azureedge.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com *.ladesk.com *.nr-data.net *.newrelic.com *.payments-amazon.com *.connectif.cloud *.google.com *.bing.com *.botsrv2.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.ladesk.com *.nr-data.net *.newrelic.com *.payments-amazon.com *.connectif.cloud *.google.com *.bing.com *.botsrv2.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.vimeo.com *.oct8ne.com *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.ladesk.com *.nr-data.net *.newrelic.com *.payments-amazon.com *.connectif.cloud *.google.com *.bing.com botsrv2.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.ladesk.com *.nr-data.net *.newrelic.com *.payments-amazon.com *.connectif.cloud *.bing.com *.botsrv2.com https://static.linguise.com https://forms-eu1.hsforms.com https://perf-eu1.hsforms.com https://imgsct.cookiebot.com https://track-eu1.hubspot.com https://pagead2.googlesyndication.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.adyen.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'unsafe-inline' *.ladesk.com *.payments-amazon.com *.connectif.cloud *.bing.com *.botsrv2.com *.sealmetrics.com https://static.linguise.com https://js-eu1.hsforms.net https://js.hs-scripts.com https://js-eu1.hs-scripts.com https://js-eu1.hsadspixel.net https://js-eu1.usemessages.com https://js-eu1.hs-banner.com https://js-eu1.hs-analytics.net https://js-eu1.hscollectedforms.net https://js-eu1.hubspot.com https://pagead2.googlesyndication.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.ladesk.com *.nr-data.net *.newrelic.com *.payments-amazon.com *.connectif.cloud *.google.com *.bing.com *.botsrv2.com cdnjs.cloudflare.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'none' 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.adyen.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.ladesk.com *.payments-amazon.com *.connectif.cloud *.bing.com botsrv2.com https://forms-eu1.hsforms.com https://api.linguise.com https://api-eu1.hubspot.com https://forms-eu1.hscollectedforms.net https://cta-eu1.hubspot.com https://api-eu1.hubapi.com https://pagead2.googlesyndication.com https://invitejs.trustpilot.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.measureup.com/pr-csp/report/add/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com fonts.googleapis.com maxcdn.bootstrapcdn.com common-fonts.abtasty.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.weltpixel.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com cdn.cookielaw.org dp8v87cz8a7qa.cloudfront.net flagpedia.net *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com t4.my-probance.one try.abtasty.com cdn.facil-iti.app api.beeroot.io cdn.epoq.de rs1.epoq.de cdn.cookielaw.org client-scripts.fitle.com sdk.fitle.com pagead2.googlesyndication.com cdn.fibbl.com qa-assistant.abtasty.com teddytor.abtasty.com bexley-fr.arc.epoq.de epoq-systems.de client.get-potions.com appstatic.quanta.io bat.bing.com *.gstatic.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cash.app maxcdn.bootstrapcdn.com cdn.epoq.de player.vimeo.com common-fonts.abtasty.com teddytor.abtasty.com epoq-systems.de *.fontawesome.com *.gstatic.com *.nosto.com *.nos.to assets.braintreegateway.com tagmanager.google.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com * maps.googleapis.com bexley-privacy.my.onetrust.com cdn.cookielaw.org dcinfos-cache.abtasty.com pagead2.googlesyndication.com api.fitle.com blob: www.gstatic.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; default-src 'none'; object-src 'self'; media-src 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src https://www.youtube.com; img-src 'self' data: https://www.google-analytics.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'nonce-091fc4cef943f076295636dcc9b68f88a3df176f' 'sha256-NeueIEO8rwnaeJW0jYHRwrarPP+KzGzhk6xBJ06ntlw=' https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://maps.googleapis.com; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.co.uk ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.co.uk *.spreadshirt.co.uk ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.co.uk ; font-src 'self' https: data: *.spreadshirt.co.uk ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.co.uk ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.co.uk ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' data: 'self' blob: www.google-analytics.com www.googletagmanager.com ajax.googleapis.com www.google.com js.klevu.com www.gstatic.com *.cloudmaestro.com www.googleadservices.com googleads.g.doubleclick.net; report-uri /.webscale/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self' 'unsafe-inline'; report-uri https://rev-a-shelf.com/csp/index/report; report-to report-endpoint; default-src 'self' 'unsafe-inline' 'unsafe-eval'; child-src http: https: blob: 'self' 'unsafe-inline' assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com; connect-src 'self' 'unsafe-inline' dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com https://ct.pinterest.com https://stats.g.doubleclick.net https://m.addthis.com https://www.paypalobjects.com https://www.chasepaymentechhostedpay-var.com *.facebook.com https://bam.nr-data.net/ wss://ws.hotjar.com/ https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudflare.com *.googleapis.com *.addthis.com *.graph.instagram.com *.aptrinsic.com https://searchserverapi.com https://dpm.demdex.net *.hotjar.io https://bam-cell.nr-data.net/ 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.googletagmanager.com *.doubleclick.net *.google.ca *.google.com.mx *.braintreegateway.com https://maps.googleapis.com; manifest-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline' *.adobe.com; object-src 'self'; style-src 'self' 'unsafe-inline' *.adobe.com fonts.googleapis.com *.certcapture.com https://static.rev-a-shelf.com *.rev-a-shelf.com https://static.trescolighting.com https://fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.aptrinsic.com https://searchserverapi.com; script-src 'self' 'unsafe-eval' 'nonce-aTZvNjJvMmw4dXpjNnFhOWgwdWlhejF2Y2hmdjdmbGI=' 'nonce-bGlscmN6NDJic2VrNGJtcTV1Y3VkcXk0eGp2Z3picng=' 'sha256-UMrwMsNK5sO+p3F0aT6Hw7vIQCR131ROgVA5fMIHr4w=' 'sha256-gM3INQ3RIP/oY17YQwg7u7A93bTctVg1pzIyOz+cJ/Y=' 'sha256-LlqoHgLxPrfiN2MxpkG8C989z7x2mHIHTMMTTD/E0OM' 'sha256-9HXDQYYCK6Ux68i7qX/BDffkw+qFTzFKGKsGRMhRYg0=' *.commerce-payment-services.com *.certcapture.com https://cdn1.ebizcharge.net *.cdn-apple.com *.disqus.com *.braintreegateway.com https://maps.googleapis.com https://maps.gstatic.com; img-src data: data: 'self' 'unsafe-inline' assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com https://static.rev-a-shelf.com *.rev-a-shelf.com https://s3.amazonaws.com/ https://www.facebook.com https://ct.pinterest.com https://static.trescolighting.com https://cdn.klarna.com/ https://www.google.co.in/ *.adobedtm.com https://tresco-lighting-layout-images.s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com *.aptrinsic.com storage.googleapis.com https://searchserverapi.com https://img.youtube.com/ https://images.salsify.com/ https://searchanise-ef84.kxcdn.com *.youtube.com trescolighting.com *.googletagmanager.com *.google.ca *.google.com.mx s3.us-east-1.amazonaws.com/assets.trescolighting.com/images/lightinglayoutform/catalog-specs-image.png *.amazonaws.com/assets.trescolighting.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://maps.gstatic.com https://maps.googleapis.com; frame-src mailto: 'self' 'unsafe-inline' fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com https://ct.pinterest.com https://s7.addthis.com https://www.chasepaymentechhostedpay-var.com *.facebook.com *.issuu.com https://www.google.com https://www.youtube.com https://youtube.com https://www.ytimg.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.addthis.com *.pinterest.com https://searchserverapi.com *.googletagmanager.com www.paypalobjects.com; frame-ancestors 'self' *.certcapture.com google.com; form-action 'self' 'unsafe-inline' geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://searchserverapi.com; font-src data: data: 'self' 'unsafe-inline' fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://static.rev-a-shelf.com *.rev-a-shelf.com https://static.trescolighting.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.cloudflare.com https://searchserverapi.com www.paypalobjects.com https://fonts.googleapis.com; script-src-elem 'self' 'nonce-aTZvNjJvMmw4dXpjNnFhOWgwdWlhejF2Y2hmdjdmbGI=' 'nonce-bGlscmN6NDJic2VrNGJtcTV1Y3VkcXk0eGp2Z3picng=' 'sha256-pEPkw2gqZHzBkthmOWxqnol8ClG12G199Dw3nT+pDb0=' 'sha256-ABlQ06egcTt9+4rrvQsST7Q7TeAo5iDj0jYlxv+VZPo=' 'sha256-t7HU6t3yHm1Yl/MG0g+0/1/eG/hXpaLYlXkLob0jN+w=' 'sha256-pGChAVRNB6/2sc/FkmpjRh3kMtSBM4abHmVSiKoLHXE=' 'sha256-7k81SbkyyBTFk6YccVLGQElU4x6brDYmpk9Puob3g/8=' 'sha256-ObEaVru4l21dF2oobOPLiz6uR0zenjySeVYH1TVtth4=' 'sha256-/2i5N0FfkYMaQ14EMRwoNtht9CQAlqBAOEy85wFWDV0=' 'sha256-WvcjCAO1NybNRQvogNNsPmZzD1ed5ij+8+ea6IcDzM0=' 'sha256-aUaBdX+Dkc/SsetrUbS41PY1tLi89PFjf9FDEkMr4Wk=' 'sha256-hnsGmuwSHRQPTtyIDFlF0cyx2JzXlMwiMaQHUw7AiR4=' 'sha256-LlqoHgLxPrfiN2MxpkG8C989z7x2mHIHTMMTTD/E0OM=' 'sha256-jOPUuh40bYUkNwdPg9/KVSHKnnvCdU3PPQxRfO/Hw3s=' 'sha256-9HXDQYYCK6Ux68i7qX/BDffkw+qFTzFKGKsGRMhRYg0=' 'sha256-40i/giXk+KGoARzqKG92xgRIEWPqbC9yHT5qga7Wlyo=' 'sha256-KhOr8lNBsfYcRLPRirTZ1tXOi+ZBNlGXZ+QN8/iFTkE=' 'sha256-1ozuCt5fPv779wJQEWXLF2gXag+V1bnu3hmAhDbY0Cg=' 'sha256-J16qEvJfRzusU0DZremppxvWkCWYD4JoqsC4cIJeO6Q=' 'sha256-BJAE1Y5A33mFMprdlxqghbZYnuF/0kSZ92Df4LtzoCw=' 'sha256-d9KgqyS8aTDiVyoh9llE3o6R30o/W3Cidf967elQFfA=' 'sha256-ji9536TfK2EyjaggbOD6Q0V/pUYXFaizqdBRrTk9y/M=' 'sha256-M0fEEBIMnZ4+E2frNPPPp1anmifnbL65XzPzP2SzdR0=' 'sha256-AmfschZEuIg8qaygYvUNUqB/ZEXfhqLldlaFf5dsxrg=' 'sha256-f5g6BkxJ1yWIe/gRp3R+jf8SkUVo9bSekseH2x1cB+k=' 'sha256-XCjHBpaJ2MMTK2D60LwYW7MoiXEyygSUv2OWOfB4GsI=' 'sha256-bnoagQ4sHTFTe9LkTwWgICYn+h7iVhK9tqmp5gQ2wts=' 'sha256-LUEESa896v9DQyxeJ6N4kdA24eAeHXw35AF5ejMdzag=' 'sha256-TUkxntqDKcwfh/oJd3/fRO0Co9jQ2KdZHBU8oyYtxks=' 'sha256-WXUnM8H8wlAa+Bkl8LV8c8FAqzYA2Lm034EouIF0m/Q=' 'sha256-rHufDnCeYVG9tMSYUA3D79sfbgC0AQJghN5jsFZlNE0=' 'sha256-L8Ad3/5p9o8+SNAqIq1T/rmCj0k7NxZDGuFDkh3M76k=' 'sha256-JTvveE01dCdYJoGC7Krj6DHMZg1oXMMdZwLrPDSunjA=' 'sha256-kSZaTLgs02vtrIi+BMzjIeGvT5hsBj/EXemRbXdbOXQ=' 'sha256-acaEWH422KBbXWw9yfor2cT2eZwOq1BXhdsxjIZ8M5o=' 'sha256-GAjmaehDsJH2jDoKMtZaYsCWJI2Ugs8esNnVYk0k3f0=' 'sha256-DKXqMWZ8QmFbTXyYpHblJUN9dVAOD9GRBrWT5mZzvgw=' https://script.hotjar.com/ https://static.hotjar.com/ https://www.googletagmanager.com/gtm.js js-agent.newrelic.com/ https://www.google.com/recaptcha/api.js *.paypal.com https://www.paypalobjects.com/webstatic/r/fb/fb-all-prod.pp.min.js https://js-agent.newrelic.com/nr-spa-1.267.0.min.js *.paypalobjects.com https://payments-sdk.live.commerce-payment-services.com *.youtube.com *.braintreegateway.com; 1 style-src 'self' 'unsafe-inline' https://fonts.gstatic.com; default-src 'self' 'nonce-bR5s27oWRUgmTC9aPFZNIw==' https://equityzen.com https://accounts.google.com/gsi/ http://js.hs-analytics.net http://platform.twitter.com http://static.ads-twitter.com http://widget.intercom.io http://widget.trustpilot.co http://widget.trustpilot.com https://*.bing.com https://*.clarity.ms https://*.clickcease.com https://*.cloudfront.net https://*.facebook.com https://*.google.com https://google.com https://*.hsforms.com https://*.ingest.sentry.io https://*.intercomcdn.com https://*.jsdelivr.net https://*.linkedin.com https://*.reddit.com https://*.redditstatic.com https://*.salesloft.com https://*.sentry.io https://*.stripe.com https://accounts.google.com https://ajax.googleapis.com https://analytics.google.com https://analytics.twitter.com https://api-iam.intercom.io https://api-js.mixpanel.com https://api.hubapi.com https://api.mixpanel.com https://api.sealionproxy.com https://app.hellosign.com https://app.hubspot.com https://cdnjs.cloudflare.com https://ci5.googleusercontent.com https://connect.facebook.net https://cta-service-cms2.hubspot.com https://files.readme.io https://fonts.googleapis.com https://fonts.gstatic.com https://forms.hscollectedforms.net https://js.hs-banner.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.hubspotfeedback.com https://kemcho-dev.s3.amazonaws.com https://kemcho-staging.s3.amazonaws.com https://kemcho.s3.amazonaws.com https://maxcdn.bootstrapcdn.com https://myip.duoduodev.com https://oss.maxcdn.com https://perf-na1.hsforms.com https://scout-cdn.salesloft.com https://stats.g.doubleclick.net https://t.co https://td.doubleclick.net https://track.hubspot.com https://www.finra.org https://www.google-analytics.com https://www.googleapis.com https://www.googletagmanager.com wss://nexus-websocket-a.intercom.io http://fonts.googleapis.com http://maxcdn.bootstrapcdn.com https://assets.calendly.com/ https://js.hubspot.com https://js.intercomcdn.com https://accounts.google.com/gsi/style 'unsafe-eval'; style-src-elem 'self' 'unsafe-inline' http://fonts.googleapis.com http://maxcdn.bootstrapcdn.com https://assets.calendly.com/ https://js.hubspot.com https://js.intercomcdn.com https://accounts.google.com/gsi/style 1 default-src https:; script-src 'unsafe-inline' https:; style-src 'unsafe-inline' https:; object-src 'none'; img-src 'self' data: https:; font-src data: https:; frame-ancestors 'none'; block-all-mixed-content; report-uri https://lingvist.report-uri.com/r/d/csp/reportOnly 1 font-src *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.google.com *.youtube.com maps.googleapis.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.google.com *.facebook.com maps.googleapis.com lightwidget.com *.maps.gstatic.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com maps.googleapis.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.googleapis.com *.placeholder.com *.maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com maps.googleapis.com *.facebook.net cdn.lightwidget.com *.instagram.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.googleapis.com *.placeholder.com *.maps.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com *.maps.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.youtube.com maps.googleapis.com facebook.net *.maps.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.meetanshi.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://*.gstatic.com www.apptrian.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com *.meetanshi.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://minicar-parts.nl https://mylivechat.com https://uk.mylivechat.com https://integrations.etrusted.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com www.apptrian.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.meetanshi.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://www.postcode-checkout.nl/api/international/v1/autocomplete/* https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https://*.widget.trengo.eu https://www.clarity.ms https://consent.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://uk.mylivechat.com https://integrations.etrusted.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com https://*.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com www.apptrian.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.meetanshi.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://www.postcode-checkout.nl/api/international/v1/autocomplete/* *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https://*.widget.trengo.eu https://inc.minicar-parts.nl https://*.clarity.ms https://*.cookiebot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.experimentation.dev https://forms-eu1.hsforms.com/* https://*.hsforms.com https://www.youtube.com https://*.hubspot.com https://*.usemessages.com https://*.l-expert-comptable.com https://googletagmanager.com https://www.googletagmanager.com https://l-expert-comptable.akimeo.app https://*.hsleadflows.net https://open.spotify.com/ https://*.typeform.com; script-src 'self' https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.experimentation.dev https://forms-eu1.hsforms.com/* https://*.hsforms.com https://www.youtube.com https://*.hubspot.com https://*.usemessages.com https://*.l-expert-comptable.com https://googletagmanager.com https://www.googletagmanager.com https://l-expert-comptable.akimeo.app https://*.hsleadflows.net https://open.spotify.com/ https://*.typeform.com cdn.jsdelivr.net cdn.rawgit.com https://cdnjs.cloudflare.com https://github.com https://www.google.com mdbootstrap.com; style-src 'self' https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.experimentation.dev https://forms-eu1.hsforms.com/* https://*.hsforms.com https://www.youtube.com https://*.hubspot.com https://*.usemessages.com https://*.l-expert-comptable.com https://googletagmanager.com https://www.googletagmanager.com https://l-expert-comptable.akimeo.app https://*.hsleadflows.net https://open.spotify.com/ https://*.typeform.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdnjs.cloudflare.com mdbootstrap.com use.fontawesome.com; form-action * 1 default-src https: data: wss: blob: 'unsafe-inline' 'unsafe-eval'; report-uri /csp-violation-report.php 1 default-src https:; connect-src https: ws://10.1.13.34; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; font-src https: 'self' data:; img-src 'self' data: https: https://zradio.org; style-src 'self' https: 'unsafe-inline'; object-src 'none'; frame-src 'self' blob:; report-uri https://csp.zradio.org/ 1 font-src cash-f.squarecdn.com fonts.googleapis.com fonts.gstatic.com zenloop-assets.s3.eu-west-1.amazonaws.com assets.zenloop.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com www.zenaps.com *.fls.doubleclick.net amc.demdex.net *.hotjar.com *.facebook.com *.trustpilot.com *.criteo.com *.criteo.net *.cleverpush.com *.justspices.de *.justspices.es *.justspices.co.uk *.sovendus.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com maps.gstatic.com *.googletagmanager.com *.trustedshops.com *.facebook.com *.justspices.de *.justspices.es *.justspices.co.uk *.justspices.com *.criteo.com a.twiago.com ad.360yield.com ad.sxp.smartclip.net ad.yieldlab.net ads.stickyadstv.com cdn.stickyadstv.com cm.adform.net contextual.media.net criteo-partners.tremorhub.com criteo-sync.teads.tv exchange.mediavine.com i.liadm.com ih.adscale.de cotads.adscale.de match.sharethrough.com matching.ivitrack.com pixel.rubiconproject.com public-prod-dspcookiematching.dmxleo.com s.ad.smaato.net secure.adnxs.com ib.adnxs.com visitor.omnitagjs.com x.bidswitch.net *.analytics.yahoo.com ads.yahoo.com *.doubleclick.net eb2.3lift.com r.casalemedia.com rtb-csync.smartadserver.com simage2.pubmatic.com sync.outbrain.com *.bing.com *.clarity.ms i.geistm.com *.taboola.com *.google.com *.google.de d3k81ch9hvuctc.cloudfront.net www.awin1.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com www.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com s7.addthis.com *.google.com cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.hotjar.com *.trustedshops.com *.facebook.net *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.criteo.net *.criteo.com *.datatables.net *.shopgate.com *.bing.com cdn.cookielaw.org *.onetrust.com *.pinterest.com s.pinimg.com analytics.tiktok.com *.clarity.ms static.cleverpush.com *.taboola.com www.dwin1.com ssl.geoplugin.net sleeknotecustomerscripts.sleeknote.com static.spott.ai *.sovendus.com the.sciencebehindecommerce.com zenloop-website-overlay-production.s3.amazonaws.com website-overlay.zenloop.com *.fullstory.com *.justspices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.googleapis.com *.trustpilot.com cdn.jsdelivr.net *.klaviyo.com *.adyen.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.facebook.com *.justspices.de *.justspices.es *.justspices.co.uk *.justspices.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com ekr.zdassets.com/ maps.googleapis.com maps.gstatic.com *.hotjar.com *.hotjar.io *.zendesk.com *.clarity.ms bat.bing.com cdn.cookielaw.org *.noibu.com wss://input.noibu.com justspices-privacy.my.onetrust.com *.onetrust.com *.criteo.com stats.g.doubleclick.net *.taboola.com *.facebook.com static-forms.klaviyo.com *.cleverpush.com *.sovendus.com *.trustpilot.com *.trustedshops.com *.zenloop.com zenloop-website-overlay-production.s3.amazonaws.com *.sciencebehindecommerce.com trustbadge.api.etrusted.com *.fullstory.com *.justspices.de *.google-analytics.com *.pinterest.com analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self'; script-src 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com https://static.klaviyo.com *.cloudfront.net *.aws.dev *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de yotpo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.doubleclick.net www.facebook.com *.affirm.com *.affirm.ca *.weltpixel.com www.xtento.com landofcoder.com yotpo.com order.buywithprime.amazon.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.twitter.com *.ads-twitter.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.affirm.com *.affirm.ca www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com yotpo.com https://cdn.cookielaw.org *.aws.dev https://dev.visualwebsiteoptimizer.com https://assets.adobedtm.com https://www.medalsofamerica.com http://www-stg.medalsofamerica.com http://moaopensource.mw2consulting.com/ http://www.mw2consulting.com/ connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.cdninstagram.com *.fbcdn.net *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.twitter.com *.ads-twitter.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.affirm.com *.affirm.ca widget.freshworks.com m2epro.freshdesk.com www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com landofcoder.com yotpo.com https://order.buywithprime.amazon.com *.hiconversion.com globalshopex.com https://cdn.cookielaw.org https://loader.wisepops.com https://wisepops.net *.cloudfront.net https://shop.pe https://shopper.shop.pe https://seal.networksolutions.com https://cdn.noibu.com https://addstrap-ui.addshoppers.com https://addshoppers.s3.amazonaws.com https://dev.visualwebsiteoptimizer.com *.avada.io connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com yotpo.com *.cloudfront.net https://addstrap-ui.addshoppers.com *.aws.dev *.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline';, connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.twitter.com *.ads-twitter.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com www.facebook.com *.facebook.net *.affirm.com *.affirm.ca widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com landofcoder.com yotpo.com https://cdn.cookielaw.org https://app.shop.pe *.aws.dev https://geolocation.onetrust.com https://manage.safeopt.com *.obviyo.net https://featureassets.org https://prodregistryv2.org https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: www.google.com www.googletagmanager.com www.youtube.com fonts.googleapis.com fonts.gstatic.com www.googletagmanager.com connect.facebook.net c.imedia.cz c.seznam.cz translate.google.com www.gstatic.com cdn.voiceflow.com translate-pa.googleapis.com hypedigitaly.github.io api.ipify.org general-runtime.voiceflow.com cm4-production-assets.s3.amazonaws.com translate.googleapis.com region1.google-analytics.com h.seznam.cz tim.abirun.eu www.google-analytics.com quickchart.io extranet.kr-vysocina.cz www.vys-edu.cz kalendar.kr-vysocina.cz utils.hypedigitaly.ai www.ksusv.cz i.ytimg.com *.kr-vysocina.cz ci3.googleusercontent.com ajax.googleapis.com translate.google.com hypedigitaly.github.io c.imedia.cz cdn.voiceflow.com; report-uri /vismo/csp-reports.asp 1 default-src 'none';script-src 'nonce-bc91cf83-3c68-457b-974d-8f7c95f5ff95' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.ee https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.ee/eum-collector/report/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.stripe.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com guarantee-cdn.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net bat.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com guarantee-cdn.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net bat.bing.com beacon-v2.helpscout.net *.helpscout.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com *.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app d3hb14vkzrxvla.cloudfront.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.qualitymobilevideo.com/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'strict-dynamic' https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net data: https://*.openstreetmap.org 'report-sample' 'nonce-Sv6K_HxsK_QG9D-LZ7VVfQLZ8l8JoHDKx6nJeRzYFeL59OtkvODnww'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://www.google.com https://google.com https://www.google.ch data: https://i.vimeocdn.com https://*.openstreetmap.org; base-uri 'self'; frame-src https://www.googletagmanager.com https://player.vimeo.com; style-src-elem 'self' 'nonce-Sv6K_HxsK_QG9D-LZ7VVfQLZ8l8JoHDKx6nJeRzYFeL59OtkvODnww' 'report-sample'; object-src 'none'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://google.com https://vimeo.com https://player.vimeo.com data: https://*.openstreetmap.org; style-src 'self' 'report-sample'; report-uri https://axc.biz/@http-reporting?csp=report&requestTime=1765936632681601&requestHash=d373664a6375b8eeeca58104058e6925ba1e26fb 1 font-src *.tawk.to fonts.gstatic.com *.facebook.com *.fontawesome.com *.googleapis.com *.gstatic.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' pilot-payflowlink.paypal.com *.yotpo.com *.facebook.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.facebook.com *.criteo.net *.criteo.com/ *.tawk.to checkout.tabby.ai *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.visa.com *.tawk.to cdn.jsdelivr.net *.tawk.link *.google.com *.google.nl *.google.be *.google-analytics.com *.google.com.pk *.google.com.uae *.bing.com *.facebook.com *.gstatic.com *.bidswitch.net *.adnxs.com *.doubleclick.net *.krxd.net *.criteo.com *.aralego.net *.bluekai.com *.smaato.net *.outbrain.com *.mediavine.com *.rlcdn.com *.360yield.com *.adingo.jp *.dable.io *.socdm.com *.yahoo.com *.taboola.com *.yieldmo.com *.pubmatic.com *.stickyadstv.com *.casalemedia.com *.3lift.com *.smartadserver.com *.sharethrough.com *.rubiconproject.com *.media.net *.teads.tv *.aralego.com cdn.tamara.co cdn.tamara.co/widget-v2/assets/tamara-grad-en.ac5bf912.svg www.facebook.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.visa.com *.mastercard.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.tawk.to embed.tawk.to/_s/v4/app.* *.cdn.jsdelivr.net *.criteo.net *.doubleclick.net *.bing.com *.criteo.com *.jsdelivr.net *.cloudflareinsights.com *.google-analytics.com *.facebook.com cdn.tamara.co *.click2buy.com *.clic2drive.com *.clic2buy.com https://widget.driverreviews.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.facebook.net connect.facebook.net checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.googletagmanager.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net 'self' data: *.facebook.com *.fontawesome.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.tawk.to wss://*.tawk.to *.doubleclick.net *.google.com *.googleapis.com *.google-analytics.com *.facebook.com cdn.tamara.co https://widget.driverreviews.com https://get.geojs.io *.avada.io checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' * data: blob:; style-src 'self' 'unsafe-inline' *; img-src 'self' data: *; font-src 'self' * data:; connect-src 'self' *; frame-src 'self' *; frame-ancestors 'self'; report-uri https://fundraisingbox.com 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com platform.twitter.com td.doubleclick.net 13605183.fls.doubleclick.net www.google.com cdn.octadesk.com *.infonet.com.py *.infonet.com.py:8888/ https://vpos.infonet.com.py:8888/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com static.tacdn.com ad.doubleclick.net www.google.com.py adservice.google.com c.clarity.ms c.bing.com cellshop.com.py integration-5ojmyuq-qoiivjresdo6e.us-5.magentosite.cloud cdn.leadster.com.br *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google.co.in https://desa.infonet.com.py:8035/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com connect.facebook.net twitter.com platform.twitter.com static.addtoany.com static.cloudflareinsights.com js-agent.newrelic.com www.tripadvisor.com unpkg.com www.tripadvisor.es www.google.com static.tacdn.com www.gstatic.com www.clarity.ms www.jscache.com vpos.infonet.com.py www.tripadvisor.com.br cdn.octadesk.com *.cellshop.com.py *.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com tagmanager.google.com ssl.google-analytics.com *.infonet.com.py:8888/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.tacdn.com tagmanager.google.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com stats.addtoany.com *.infonet.com.py:8888 *.infonet.com.py bam.nr-data.net t.clarity.ms *.analytics.google.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.com https://viacep.com.br https://www.viacep.com.br https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com bam.nr-data.net t.clarity.ms commerce.adobedc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://gateway.zscloud.net gateway.zscalerthree.net zscaler.net https://*.pcipal.cloud https://*.stripe.com/ blob:; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.pcipal.cloud https://www.google.com accounts.google.com https://www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://fonts.googleapis.com/css2 *.walkme.com https://gateway.zscloud.net gateway.zscalerthree.net zscaler.net https://*.cardinalcommerce.com/ https://*.stripe.com/ https://pay.google.com/ https://*.paysafe.com https://api.test.paysafe.com https://applepay.cdn-apple.com/ https://www.datadoghq-browser-agent.com/ blob:; frame-src * data: 'report-sample'; style-src 'self' 'unsafe-inline' *.walkme.com https://fonts.googleapis.com/css; report-uri https://pcipal.report-uri.com/r/d/csp/reportOnly; connect-src 'self' wss://pcipal.cloud wss://*.pcipal.cloud https://*.pcipal.cloud:* *.walkme.com https://kg668dbov0.execute-api.us-east-1.amazonaws.com/stag/log https://*.apm.eu-west-1.aws.found.io:* https://*.cardinalcommerce.com/ https://pcipal.report-uri.com/ https://*.stripe.com/ https://google.com/pay https://www.google.com/pay https://pay.google.com/ https://www.google.com/recaptcha/ https://*.paysafe.com https://api.test.paysafe.com https://browser-intake-datadoghq.eu/; font-src * data:; object-src 'none'; 1 default-src amplitude.com *.amplitude.com cash.app *.cash.app cloudflare.com *.cloudflare.com cloudflareinsights.com *.cloudflareinsights.com datatables.net *.datatables.net doubleclick.net *.doubleclick.net google-analytics.com *.google-analytics.com google.com *.google.com googletagmanager.com *.googletagmanager.com jquery.com *.jquery.com paypal.com *.paypal.com sentry.io *.sentry.io tiny.cloud *.tiny.cloud tinymce.com *.tinymce.com citconpay.com *.citconpay.com facebook.net *.facebook.net google.co.uk *.google.co.uk kcp.co.kr *.kcp.co.kr ngrok-free.app *.ngrok-free.app sift.com *.sift.com 'unsafe-inline' 'unsafe-eval' 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=gnbWNniEjXyCi9q5JO9vYS78PyHoCCCohjX7BmddtEU-1765933371.8144202-1.0.1.1-JlJbN20SMe6aDz5RXFRVW24OKUftNQfI7ecuPtqELDDgzK8imi_KvLxeQf8O9QwCq3qOwobkOdI01rGCys5JCeBXB3wDO_HXM4U3XZBiRYY.aHHdMus0.zD.73l.NwBC9vbs.gP1hOqFOfRqegzRiFTI6B3RQ.RoS5qMvXFaLAef5N9NDIaEqqRxmdWoq4RO; report-to cf-nghpgohylmhafuld 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com self www.google.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com www.google.com www.gstatic.com apis.google.com accounts.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com flagpedia.net *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.googleapis.com *.gstatic.com accounts.google.com *.fontawesome.com *.sharethis.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com accounts.google.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com accounts.google.com *.sharethis.com www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com *.googleapis.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.hipay-tpp.com *.hipay.com *.googleapis.com *.klarna.com https://www.googletagmanager.com/ *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: https://www.google.de https://www.facebook.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.hipay.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com https://www.facebook.com https://connect.facebook.net https://cdn.cookie-script.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com *.klarna.com *.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hipay.com *.googleapis.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.addthis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-eval' blob: 'self' *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 default-src 'self' https://*.uestra.de https://cloud.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://img.youtube.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://cloud.ccm19.de https://elma.gvh.de; base-uri 'self' https://*.uestra.de; frame-src 'self' blob: https://*.youtube.com/ https://gvh.demo.hafas.cloud https://gvh.hafas.de https://abo.gvh.de https://cloud.ccm19.de https://deutschlandticket.gvh.de https://transport.novafind.eu/; media-src 'self' blob:; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://cloud.ccm19.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de https://stats.uestra.de 'report-sample'; font-src 'self' data: https://fonts.gstatic.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://stats.uestra.de https://elma.gvh.de; connect-src 'self' https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://stats.uestra.de https://elma.gvh.de; object-src 'self' blob: https://*.uestra.de; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://relaunch.uestra.de https://*.webit.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://www.uestra.de https://relaunch.uestra.de https://stats.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://elma.gvh.de 'report-sample'; frame-ancestors 'self' https://*.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de; form-action 'self'; report-uri https://www.uestra.de/@http-reporting?csp=report&requestTime=1765935018646409&requestHash=85d7360a2faa9efdc4740657a900452f9b9ce9c3 1 script-src * 'self' 'unsafe-inline' 1 connect-src 'self' https://b.clarity.ms https://bat.bing.com https://ekr.zdassets.com https://numberbarn.zendesk.com wss://api.smooch.io; default-src 'none'; font-src 'report-sample' 'self' https://fonts.gstatic.com; form-action 'report-sample' 'self'; frame-ancestors 'report-sample' 'self'; frame-src 'self' https://js.stripe.com https://www.google.com; img-src 'report-sample' 'self' data: https://bat.bing.com https://px.ads.linkedin.com https://static.zdassets.com https://www.facebook.com https://www.google.com; report-to default; report-uri https://www.tierra.net/special/report/csp; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.googleapis.com https://api.smooch.io https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://js.stripe.com https://snap.licdn.com https://static.zdassets.com https://www.clarity.ms https://www.clearhello.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.googleapis.com 1 default-src 'self'; script-src 'self' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data:; object-src 'none'; frame-ancestors 'none'; report-to csp-endpoint; report-uri https://www.llb.li/rest/weak/logs/csp-reports 1 object-src 'none'; connect-src 'self' *.playboyplus.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.playboyplus.com join.gammasecure.com; script-src 'self' *.playboyplus.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.playboyplus.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; frame-src 'self' www.youtube.com challenges.cloudflare.com td.doubleclick.net outlook.office365.com fast.wistia.net fast.wistia.com; worker-src 'self' blob:; child-src 'self' blob: www.youtube.com; script-src 'self' https: 'strict-dynamic' 'unsafe-inline' wasm-eval fast.wistia.net fast.wistia.com 'nonce-Vcn97S2wjmVZpBHy04ncVA=='; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https: wss: *.sentry.io; base-uri 'none'; report-uri https://o92134.ingest.us.sentry.io/api/218571/security/?sentry_key=c01e0509572348fca8b65b3fe0ad16f3 1 default-src https: 'self' *.facebook.net *.googletagmanager.com *.bizibly.com *.doubleclick.net https://*.intercomcdn.com https://*.datadoghq-browser-agent.com; font-src 'self' https://*.intercomcdn.com *.fontawesome.com data:; base-uri 'none'; object-src data: 'unsafe-eval'; img-src 'self' data: * ; script-src https: 'self' 'unsafe-eval' 'unsafe-inline' http://*.google-analytics.com http://*.gstatic.com http://*.bing.com http://*.googleadservices.com http://*.hs-scripts.com http://*.bizible.com *.facebook.net *.googletagmanager.com http://*.fontawesome.com http://*.outbrain.com blob:; style-src https: 'self' *.fontawesome.com 'unsafe-inline'; report-to /rest/trackers/csp; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.facebook.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.createsend1.com *.scene7.com *.klarna.com https://www.googletagmanager.com/ *.facebook.com *.facebook.net https://plumrocket.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.googlesyndication.com *.hopewiser.com *.scene7.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.facebook.com *.facebook.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://magento.com https://developer.adobe.com *.adobedtm.com *.bradford.link *.criteo.net *.createsend1.com *.cardinalcommerce.com *.doubleclick.net *.facebook.net *.googletagmanager.com *.godaddy.com *.hotjar.com *.scene7.com *.sub2tech.com *.paypalobjects.com *.xtento.com widget.freshworks.com m2epro.freshdesk.com *.preprodservices.crif-online.ch *.services.crif-online.ch *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.facebook.com *.avada.io *.trustpilot.com www.xtento.com cdn.xtento.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://cloud.hopewiser.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://developer.adobe.com *.googlesyndication.com https://maps.googleapis.com *.scene7.com widget.freshworks.com m2epro.freshdesk.com *.preprodservices.crif-online.ch *.services.crif-online.ch *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.bglobale.com *.global-e.com *.klarnacdn.net *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://api.ometria.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trustpilot.com https://vars.hotjar.com https://www.paypalobjects.com https://lpcdn.lpsnmedia.net *.bglobale.com *.global-e.com *.hub-box.com *.klarna.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://media.festive-lights.com https://www.festive-lights.com https://trk.ometria.com https://bat.bing.com https://www.google.com https://www.google.co.uk https://www.facebook.com https://paypal-eu-arh.cloudiq.com https://lpcdn.lpsnmedia.net https://t.co cookie-cdn.cookiepro.com https://www.magezon.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com maps.gstatic.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com https://static.hotjar.com https://script.hotjar.com https://widget.trustpilot.com https://invitejs.trustpilot.com https://www.googletagmanager.com https://cdn.ometria.com https://cdn.cookielaw.org https://ajax.googleapis.com https://festi11112.pcapredict.com https://static.ads-twitter.com https://bat.bing.com https://connect.facebook.net https://www.gstatic.com https://googleads.g.doubleclick.net https://stglite.bglobale.com https://paypal-eu-arh.cloudiq.com https://paypal-eu-cdn.cloudiq.com https://accdn.lpsnmedia.net https://va.v.liveperson.net https://lpcdn.lpsnmedia.net https://static-eu.payments-amazon.com https://analytics.twitter.com *.cloudflare.com graph.facebook.com js-agent.newrelic.com *.mention-me.com https://cookie-cdn.cookiepro.com *.pinterest.com *.tiktok.com *.pinimg.com *.stackadapt.com *.adsrvr.org *.trustpilot.com *.bglobale.com *.global-e.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.googletagmanager.com tagmanager.google.com https://browser.sentry-cdn.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://optanon.blob.core.windows.net https://stglite.bglobale.com *.trustpilot.com *.bglobale.com *.global-e.com *.klarnacdn.net *.klevu.com *.ksearchnet.com assets.braintreegateway.com tagmanager.google.com fonts.google.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.co.uk https://stats.g.doubleclick.net https://payments-uk.amazon.com *.algolia.io cdn.cookielaw.org cdn.ometria.com https://cookie-cdn.cookiepro.com *.pinterest.com *.tiktok.com *.hub-box.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.googletagmanager.com https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com *.livechatinc.com *.acsbap.com *.acsbapp.com https://acsbapp.com/apps/app/dist/fonts/ *.fontawesome.com *.stripecdn.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com www.googletagmanager.com www.google-analytics.com *.icims.eu www.youtube.com cookiepedia.co.uk www.linkedin.com www.google.co.uk www.instagram.com onlinelibrary.wiley.com www.alzheimer-europe.org *.livechatinc.com *.trustpilot.com *.trustpilot.net *.apetito.integration-5ojmyuq-lhjhdamkykkd6.eu-3.magentosite.cloud *.wiltshirefarmfoods.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com vars.hotjar.com www.facebook.com www.linkedin.com www.google.co.uk www.instagram.com onlinelibrary.wiley.com www.alzheimer-europe.org *.livechatinc.com *.trustpilot.com *.trustpilot.net *.apetito.integration-5ojmyuq-lhjhdamkykkd6.eu-3.magentosite.cloud *.wiltshirefarmfoods.com td.doubleclick.net pagead2.googlesyndication.com analytics.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.vimeocdn.com i.ytimg.com www.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.amplience.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.yotpo.com p.adsymptotic.com bat.bing.com www.facebook.com cdn-ukwest.onetrust.com *.livechatinc.com cookiesuksouth.blob.core.windows.net www.google.co.in www.google-analytics.com px.ads.linkedin.com cookiepedia.co.uk www.linkedin.com www.google.co.uk www.instagram.com onlinelibrary.wiley.com www.alzheimer-europe.org *.wiltshirefarmfoods.com *.trustpilot.com *.trustpilot.net *.apetito.integration-5ojmyuq-lhjhdamkykkd6.eu-3.magentosite.cloud *.postcodeanywhere.co.uk acsbap.com acsbapp.com *.acsbap.com *.acsbapp.com https://cdn.acsbapp.com/apps/app/dist/media/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.adobe.io *.commerce-payment-services.com *.magento-ds.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.youtube.com *.vimeo.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com *.cardinalcommerce.com geo.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.onetrust.com *.livechatinc.com static.hotjar.com www.gstatic.com *.trackedlink.net *.stripe.com *.trustpilot.com maps.googleapis.com *.pcapredict.com snap.licdn.com connect.facebook.net bat.bing.com secure.leadforensics.com js-agent.newrelic.com script.hotjar.com ict.infinity-tracking.net cookiepedia.co.uk www.linkedin.com www.google.co.uk www.instagram.com onlinelibrary.wiley.com www.alzheimer-europe.org *.trustpilot.net *.bam.nr-data.net *.apetito.integration-5ojmyuq-lhjhdamkykkd6.eu-3.magentosite.cloud *.wiltshirefarmfoods.com *.dwin1.com acsbap.com acsbapp.com *.acsbap.com *.acsbapp.com https://acsbapp.com/apps/app/dist/ https://acsbapp.com/apps/app/assets/js/ td.doubleclick.net pagead2.googlesyndication.com *.conoret.com https://services.postcodeanywhere.co.uk https://cdn.mouseflow.com https://cdn.cookielaw.org *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.postcodeanywhere.co.uk *.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.ideal-postcodes.co.uk *.stripe.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com maps.googleapis.com *.onetrust.com *.livechatinc.com bam.nr-data.net in.hotjar.com ict.infinity-tracking.net stats.g.doubleclick.net bat.bing.com www.youtube.com cookiepedia.co.uk www.linkedin.com www.google.co.uk www.instagram.com onlinelibrary.wiley.com www.alzheimer-europe.org *.trustpilot.com *.trustpilot.net *.apetito.integration-5ojmyuq-lhjhdamkykkd6.eu-3.magentosite.cloud *.wiltshirefarmfoods.com acsbap.com acsbapp.com *.acsbap.com *.acsbapp.com *.wikipedia.org/w/api.php https://process.acsbapp.com/apps/app/ https://cdn.acsbapp.com/resources/ https://cdn.acsbapp.com/cache/app/ https://cdn.acsbapp.com/config/ https://acsbapp.com/apps/app/assets/js/ td.doubleclick.net pagead2.googlesyndication.com analytics.google.com https://services.postcodeanywhere.co.uk https://o2.mouseflow.com https://www.google.com https://cdn.cookielaw.org klarna.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self'; report-uri https://infosupport.com/csp-report-endpoint; 1 default-src 'self'; script-src 'self' https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://*.googletagmanager.com https://cdn.evgnet.com/beacon/gesacu/gesa_prod/scripts/evergage.min.js https://d10lpsik1i8c69.cloudfront.net https://secure.node7seat.com/js/219777.js https://connect.facebook.net https://snap.licdn.com/li.lms-analytics/insight.min.js https://www.redditstatic.com/ads/pixel.js https://app.truconversion.com/ https://tags.srv.stackadapt.com/events.js https://app.leadsrx.com/visitor.js https://collector-37937.tvsquared.com/tv2track.js https://acsbapp.com https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://qvdt3feo.com/events.js https://api.alpharank.io https://tools.luckyorange.com 'nonce-ca5f5aea04'; script-src-attr 'nonce-ca5f5aea04' https://d10lpsik1i8c69.cloudfront.net/js/clickstream.js; style-src 'self' https://d10lpsik1i8c69.cloudfront.net https://tags.srv.stackadapt.com https://tagmanager.google.com/ https://fonts.googleapis.com/ 'unsafe-inline'; connect-src 'self' https://analytics.google.com https://*.analytics.google.com https://stats.g.doubleclick.net/g/collect https://app.leadsrx.com https://gesacu.us-1.evergage.com https://pixel.alpharank.io https://px.ads.linkedin.com https://pubsub.googleapis.com https://*.luckyorange.net wss://*.visitors.live wss://visitors.live https://cdn.acsbapp.com https://www.redditstatic.com https://tags.srv.stackadapt.com; img-src 'self' https://collector-37937.tvsquared.com https://d10lpsik1i8c69.cloudfront.net https://px.ads.linkedin.com https://www.google.com/pagead/1p-user-list/ https://alb.reddit.com/rp.gif https://www.facebook.com https://www.googletagmanager.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion https://ssl.gstatic.com/ data:; media-src 'self' https://d10lpsik1i8c69.cloudfront.net; frame-src 'self' https://td.doubleclick.net/; font-src 'self' data:; base-uri 'self'; manifest-src 'self'; object-src 'none'; worker-src blob: ; 1 font-src *.fontawesome.com https://fonts.bunny.net *.searchspring.io facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com ywxi.net *.ywxi.net bootstrapcdn.com *.bootstrapcdn.com storelocatorwidgets.com *.storelocatorwidgets.com purityassets.com *.purityassets.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.searchspring.io listrakbi.com *.listrakbi.com purityassets.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.searchspring.io facebook.com *.facebook.com facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com amazonaws.com *.amazonaws.com ywxi.net *.ywxi.net pinterest.com *.pinterest.com purityassets.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.searchspring.io elfsightcdn.com *.elfsightcdn.com facebook.com *.facebook.com facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com cloudfront.net *.cloudfront.net ywxi.net *.ywxi.net purityassets.com *.purityassets.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ utt.impactcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://cdn.searchspring.net/intellisuggest/is.min.js *.searchspring.io facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrak.com *.listrak.com listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com amazonaws.com *.amazonaws.com ywxi.net *.ywxi.net googleapis.com *.googleapis.com storelocatorwidgets.com *.storelocatorwidgets.com purityassets.com *.purityassets.com *.godaddy.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline *.searchspring.io facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com ywxi.net *.ywxi.net bootstrapcdn.com *.bootstrapcdn.com storelocatorwidgets.com *.storelocatorwidgets.com mapbox.com *.mapbox.com purityassets.com *.purityassets.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com purityassets.com *.purityassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com https://beacon.searchspring.io/beacon *.searchspring.io facebook.com *.facebook.com facebook.net *.facebook.net visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com elfsight.com *.elfsight.com acsbapp.com *.acsbapp.com northbeam.io *.northbeam.io listrakbi.com *.listrakbi.com refersion.com *.refersion.com bing.com *.bing.com amazonaws.com *.amazonaws.com ywxi.net *.ywxi.net purityassets.com *.purityassets.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://track.hubspot.com https://www.googletagmanager.com about https://forms.hsforms.com https://forms-na1.hsforms.com https://p.typekit.net https://www.seopress.org https://cdn.userway.org https://px.ads.linkedin.com https://really-simple-ssl.com https://perf-na1.hsforms.com https://stgwp.parkstreet.com https://www.google.co.kr https://www.google.nl https://www.google.com.ph https://8095717.fs1.hubspotusercontent-na1.net https://www.google.ie https://www.google.fr https://www.google.com.br https://www.google.com.pr https://www.google.co.in https://www.google.com.mx https://www.google.co.uk https://www.google.co.jp https://www.google.it https://www.google.pt https://www.google.com.do https://media.komonews.com https://i.ytimg.com https://cdn.datatables.net https://www.google.co.id https://www.google.com.au https://www.google.bs https://www.google.com.sg https://resources2.news.com.au https://www.google.ca https://www.google.com.om https://www.thedrinksbusiness.com https://www.google.de https://www.winespectator.com https://www.google.co.th https://www.google.co.nz https://www.google.com.vn https://www.google.pl https://www.google.com.gh https://www.google.com.ng https://www.google.com.eg https://www.google.com.bd https://www.google.com.co https://cdn.honey.io https://www.google.es https://svcs.tql.com https://www.google.ae https://www.google.com.pk https://www.google.ru https://www.google.se https://www.google.com.hk https://www.google.iq https://www.google.com.pe https://imgick.pennlive.com https://imgick.lehighvalleylive.com https://www.thespiritsbusiness.com https://www.browndailyherald.com https://www.winefashionista.com https://decanter.media.ipcdigital.co.uk https://www.google.ge https://www.googleadservices.com https://www.google.dk https://www.google.com.ar blob: https://www.google.cl https://i.aroq.com https://encrypted-tbn0.gstatic.com https://www.google.lt https://translate.google.com https://www.google.com.tw https://www.google.hn https://pbs.twimg.com https://www.google.by https://static6.businessinsider.com https://maps.googleapis.com https://www.gannett-cdn.com https://stats.g.doubleclick.net https://cdn.gretawire.foxnewsinsider.com https://www.google.at https://www.google.ch https://www.cogminy.org https://www.google.com.ua https://www.google.co.ao https://sphotos-a.xx.fbcdn.net https://www.azcentral.com https://www.google.tn https://www.trbimg.com https://www.google.si https://www.google.com.ec https://photos.washingtonexaminer.biz https://www.google.bg https://www.google.hu https://www.google.dm https://fonts.gstatic.com https://www.google.com.ni https://www.google.com.bo https://www.google.com.kh https://www.google.com.bh https://bloximages.chicago2.vip.townnews.com https://c.o0bg.com https://blog.breckenridge.com https://media.skynews.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' data: https://cdnjs.cloudflare.com https://cdn.datatables.net https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://static.hotjar.com https://js.hsforms.net https://cdn.userway.org https://js.hscollectedforms.net https://use.typekit.net https://js.hs-scripts.com https://js.hs-banner.com https://googleads.g.doubleclick.net https://js.hs-analytics.net https://js.hsadspixel.net https://script.hotjar.com https://snap.licdn.com https://maps.googleapis.com https://www.buzzsprout.com https://js.hubspot.com https://static.hsappstatic.net http://cdnjs.cloudflare.com http://js.hs-scripts.com blob: http://bdimg.share.baidu.com http://cdn.datatables.net http://js.hsforms.net http://www.gstatic.com https://connect.facebook.net http://use.typekit.net https://www.google-analytics.com http://www.google.com https://yastatic.net 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://cdn.datatables.net https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://static.hotjar.com https://js.hsforms.net https://cdn.userway.org https://js.hscollectedforms.net https://use.typekit.net https://js.hs-scripts.com https://js.hs-banner.com https://googleads.g.doubleclick.net https://js.hs-analytics.net https://js.hsadspixel.net https://script.hotjar.com https://snap.licdn.com https://maps.googleapis.com https://www.buzzsprout.com https://js.hubspot.com https://static.hsappstatic.net http://cdnjs.cloudflare.com http://js.hs-scripts.com blob: http://bdimg.share.baidu.com http://cdn.datatables.net http://js.hsforms.net http://www.gstatic.com https://connect.facebook.net http://use.typekit.net https://www.google-analytics.com http://www.google.com https://yastatic.net ; style-src 'self' 'unsafe-inline' https://cdn.datatables.net https://www.gstatic.com https://fonts.googleapis.com https://cdn.userway.org https://www.parkstreet.com https://adblockers.opera-mini.net ; style-src-elem 'self' 'unsafe-inline' https://cdn.datatables.net https://www.gstatic.com https://fonts.googleapis.com https://cdn.userway.org https://www.parkstreet.com https://adblockers.opera-mini.net ; font-src 'self' https://use.typekit.net https://fonts.gstatic.com https://stgwp.parkstreet.com https://cdn.userway.org https://r2cdn.perplexity.ai data:; frame-src 'self' https://forms.hsforms.com https://static.hsappstatic.net https://www.google.com https://app.hubspot.com https://www.youtube.com https://open.spotify.com https://td.doubleclick.net https://www.googletagmanager.com https://embed.podcasts.apple.com https://view.vzaar.com https://www.thespiritsbusiness.com https://www.buzzsprout.com https://cdn.userway.org https://www.thedrinksbusiness.com blob:; connect-src 'self' https://api.userway.org https://analytics.google.com https://forms.hsforms.com https://api.hubapi.com https://www.googleadservices.com https://www.google-analytics.com https://stats.g.doubleclick.net https://forms.hscollectedforms.net https://cdn.userway.org https://cdn.linkedin.oribi.io https://maps.googleapis.com https://ai.elegantthemes.com https://vc.hotjar.io https://content.hotjar.io https://cta-service-cms2.hubspot.com https://api.rankmath.com https://cdn77.api.userway.org https://px.ads.linkedin.com https://region1.analytics.google.com https://hubspot-forms-static-embed.s3.amazonaws.com https://www.google.com.ph https://www.googletagmanager.com https://metrics.hotjar.io https://www.google.ca https://www.google.co.jp https://www.google.com.mx https://perf-na1.hsforms.com https://www.google.com.au https://www.google.co.kr https://www.google.com.om https://www.google.co.in https://www.google.fr https://www.google.com.vn https://www.google.com.ng https://www.google.it https://www.google.com.br https://www.google.co.uk https://localhost https://www.google.cl https://www.google.com.ar https://cdnjs.cloudflare.com https://www.google.es https://www.google.gr https://www.google.com.co https://www.google.com.tr https://www.google.com.pr https://www.google.ie https://www.google.de https://www.google.co.il https://www.google.com.sv https://www.google.com.pa https://www.google.com.pk https://www.google.al https://static.hsappstatic.net https://www.google.com.ec https://www.google.be https://www.google.nl https://www.google.com.pe https://www.google.co.th https://www.google.ae https://www.google.hr; worker-src 'self' blob:; report-uri https://www.parkstreet.com/wp-json/rsssl/v1/csp?rsssl_apitoken=831554005; 1 frame-ancestors 'none'; report-uri https://vault.gostatera.com/collect/csp 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net https://www.googletagmanager.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua maps.gstatic.com 1rx.io *.1rx.io 360yield.com *.360yield.com 3lift.com *.3lift.com adnxs.com *.adnxs.com billiger.de *.billiger.de bing.com *.bing.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com google.de *.google.de idealo.com *.idealo.com media.net *.media.net omnitagjs.com *.omnitagjs.com roeye.com *.roeye.com roeyecdn.com *.roeyecdn.com sharethrough.com *.sharethrough.com smartadserver.com *.smartadserver.com taboola.com *.taboola.com teads.tv *.teads.tv tremorhub.com *.tremorhub.com twiago.com *.twiago.com uimserv.net *.uimserv.net usd.de *.usd.de usercentrics.eu *.usercentrics.eu yieldlab.net *.yieldlab.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://a.timeshop24.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com bing.com *.bing.com criteo.com *.criteo.com cdnsrv.de *.cdnsrv.de clickcease.com *.clickcease.com df-srv.de *.df-srv.de fatmedia.io *.fatmedia.io facebook.net *.facebook.net id5-sync.com *.id5-sync.com kuponacdn.de *.kuponacdn.de livechatinc.com *.livechatinc.com pinimg.com *.pinimg.com roeyecdn.com *.roeyecdn.com shopgate.com *.shopgate.com uicdn.com *.uicdn.com usercentrics.eu *.usercentrics.eu googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://www.dwin1.com https://a.timeshop24.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com livechatinc.com *.livechatinc.com pinterest.com *.pinterest.com usercentrics.eu *.usercentrics.eu *.wepowerconnections.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://a.timeshop24.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://js.stripe.com https://ipinfo.io https://*.google.com https://*.fullstory.com https://*.ads-twitter.com https://*.googleapis.com https://*.googletagmanager.com https://www.googleadservices.com https://*.google-analytics.com https://*.cookiebot.com https://cdn.jsdelivr.net https://api.mapbox.com https://utt.impactcdn.com https://sandbox.na.zuora.com https://*.industriousoffice.com https://*.industriousofficedev.com https://www.industriousoffice.com https://api.wire.threatspike.com https://connect.facebook.net https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://fast.ssqt.io 'nonce-MDUxZDJkMWItMTE5ZC00MDU2LTg0Y2MtNzA3MzU5ZTY1MTdm' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://www.gstatic.com; img-src 'self' https: data: blob:; media-src 'self' https://*.industriousoffice.com https://*.industriousofficedev.com https://videos.ctfassets.net; font-src 'self' data:; connect-src 'self' https://js.stripe.com https://*.stripe.com https://*.sentry.io https://ipinfo.io https://*.cookiebot.com https://*.fullstory.com https://api.mapbox.com https://events.mapbox.com https://signin.delta.com https://signin-si.delta.com https://loyalty-api.delta.com https://loyalty-api-si.delta.com https://*.industriousoffice.com https://*.industriousofficedev.com https://cognito-idp.us-east-1.amazonaws.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.google.com https://www.google.ca https://www.google.fr https://www.google.de https://www.google.nl https://www.google.be https://www.google.at https://www.google.ie https://www.google.bg https://www.google.fi https://www.google.ae https://www.google.gt https://www.google.es https://www.google.ro https://www.google.cm https://www.google.is https://www.google.rs https://www.google.co.uk https://www.google.co.jp https://www.google.co.in https://www.google.co.za https://www.google.co.kr https://www.google.co.id https://www.google.co.nz https://www.google.co.th https://www.google.co.ke https://www.google.co.il https://www.google.com.au https://www.google.com.br https://www.google.com.mx https://www.google.com.sg https://www.google.com.hk https://www.google.com.tr https://www.google.com.ar https://www.google.com.ph https://www.google.com.co https://www.google.com.my https://www.google.com.vn https://www.google.com.tw https://www.google.com.bd https://www.google.com.pa https://www.google.com.gt https://www.googleadservices.com https://*.ads.linkedin.com https://realtyads.com https://stats.g.doubleclick.net https://www.facebook.com https://d.impct.site https://app.referralsaasquatch.com https://ast.ssqt.io https://analytics.google.com https://googleads.g.doubleclick.net https://px.ads.linkedin.com; frame-src https://js.stripe.com https://hooks.stripe.com https://*.cookiebot.com https://www.youtube-nocookie.com https://www.youtube.com https://my.matterport.com https://truetour.app https://biganto.com https://mpembed.com https://calendly.com https://*.googletagmanager.com https://www.google.com https://www.facebook.com https://livetour.istaging.com https://realtyads.com; object-src 'none'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://test.zuora.com https://www.zuora.com https://sandbox.na.zuora.com https://www.facebook.com; frame-ancestors 'none'; upgrade-insecure-requests; report-uri https://o324732.ingest.us.sentry.io/api/4504752743448576/security/?sentry_key=3d26569fc077452e88bda467c0177338; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.typekit.net maxcdn.bootstrapcdn.com data: https://cdn.honey.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.verify.monzo.com https://*.arcot.com *.hsforms.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://*.demdex.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.weltpixel.com https://*.doubleclick.net *.google.com/ https://*.hotjar.com *.addthis.com https://*.paypal.com https://*.braintreegateway.com *.kaptcha.com *.cardinalcommerce.com *.doubleclick.net *.verify.monzo.com https://secure.livechatinc.com https://tpc.googlesyndication.com *.hsforms.net https://*.channelcentral.net https://*.arcot.com *.hsforms.com *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com https://*.omtrdc.net dpm.demdex.net https://cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.doubleclick.net *.google.com https://*.google.co.uk https://*.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com https://www.magezon.com *.google.co.in *.googletagmanager.com *.techbuyer.com *.techbuydev1.dev.iwebcloud.co.uk https://api.feefo.com *.vzaar.com https://techbuyer.gumlet.io https://bat.bing.com https://t.co https://*.hsforms.com https://track.hubspot.com https://consent.linksynergy.com https://consent.nxtck.com https://consent.mediaforge.com https://consent.jrs5.com https://consent.dc-storm.com https://www.googletagmanager.com https://www.google.fr https://www.google.com.eg https://www.google.de https://www.google.com.my https://www.google.co.id https://www.google.com.au https://www.google.co.nz https://www.google.ie https://www.google.ch https://www.google.at https://www.google.nl https://www.google.es https://www.google.com.ua https://www.google.com.tr https://www.google.com.tw https://www.google.tn https://www.google.co.in https://www.google.com.pk https://www.google.com.ng https://www.google.co.jp https://www.google.be https://www.google.co.mz https://www.google.ca https://www.google.com.vn https://www.google.com.hk https://www.google.ro https://www.google.it https://www.google.hr https://www.google.pl https://www.google.co.kr https://www.google.com.ph https://www.google.co.ke https://i.ytimg.com https://cdn.honey.io https://*.livechatinc.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://connect.facebook.net connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com *.google.com/ https://www.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.moatads.com *.addthis.com *.facebook.net *.google-analytics.com *.addthisedge.com *.cardinalcommerce.com *.doubleclick.net *.zdassets.com *.hoolah.co *.nmgassets.com https://*.feefo.com *.cookiefirst.com *.verify.monzo.com https://*.wisepops.com *.hsforms.com https://*.ads-twitter.com https://bat.bing.com https://secure.feed5mown.com https://o2.mouseflow.com https://cdn.mouseflow.com https://*.livechatinc.com https://cdn.oribi.io https://js.hs-analytics.net https://js.hscollectedforms.net https://js.hs-banner.com https://assets.revlifter.io https://analytics.twitter.com https://*.nofraud.com https://d-ipv6.mmapiws.com *.hsforms.net https://js.hs-scripts.com https://cdn.noibu.com https://cdn.raygun.io https://*.braintreegateway.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://*.googleapis.com https://*.typekit.net https://static.klaviyo.com maxcdn.bootstrapcdn.com *.cookiefirst.com *.verify.monzo.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.feefo.com *.vzaar.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net https://*.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ https://stats.g.doubleclick.net *.addthis.com *.amazonaws.com https://*.braintreegateway.com *.cardinalcommerce.com *.nmgplatform.com https://*.feefo.com *.cookiefirst.com *.verify.monzo.com https://o2.mouseflow.com https://www.google-analytics.com *.hsforms.com https://*.livechatinc.com https://bat.bing.com https://adservice.google.com https://www.google.com https://*.demdex.net https://*.mmapiws.com https://forms.hubspot.com https://input.noibu.com wss://input.noibu.com https://analytics.google.com https://api.raygun.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /csp-log.php; report-to csp-log-endpoint; default-src 'self'; style-src 'self' 'unsafe-inline' https://static.tegut.com/ *.typekit.com *.typekit.net https://fast.fonts.net/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.usercentrics.eu *.typekit.com *.typekit.net https://static.tegut.com/ https://maps.googleapis.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://googleads.g.doubleclick.net/ https://connect.facebook.net/ https://www.facebook.com/ https://analytics.tiktok.com/ https://www.youtube.com/ https://www.googleadservices.com/ https://www.google.com https://www.google.hu https://www.google.lu/ https://www.google.de/ https://www.google.at/ https://www.google.pl/ https://ad1.adfarm1.adition.com/ https://cdn.scarabresearch.com/ https://static.scarabresearch.com/ https://bat.bing.com/ https://s.pinimg.com/ https://s2.adform.net/ https://track.adform.net/ https://ct.pinterest.com/ https://track.adform.net/ https://assets.pinterest.com/; img-src 'self' data: https://static.tegut.com/ https://*.usercentrics.eu https://www.google.com https://www.google.hu https://www.google.lu/ https://www.google.de/ https://www.google.at/ https://www.google.pl/ https://www.facebook.com/ https://www.google-analytics.com/ https://tegut.maps.dmknet.de/ https://ad.doubleclick.net/ https://googleads.g.doubleclick.net/ https://bat.bing.com/ https://www.googletagmanager.com/ https://maps.gstatic.com/ https://log.pinterest.com/; object-src 'self' https://*.usercentrics.eu https://static.tegut.com/ blob:; connect-src 'self' data: https://*.usercentrics.eu https://maps.googleapis.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://www.facebook.com/ https://region1.google-analytics.com/ https://recommender.scarabresearch.com/ https://www.google.com https://www.google.hu https://www.google.lu/ https://www.google.de/ https://www.google.at/ https://www.google.pl/ https://analytics.tiktok.com/ https://webchannel-content.eservice.emarsys.net/ https://ct.pinterest.com/ https://bat.bing.net/ https://bat.bing.com/ https://www.googleadservices.com/; font-src 'self' data: https://static.tegut.com/ https://use.typekit.com/; frame-src https://jackpot.tegut.com/ https://www.youtube-nocookie.com/ https://12761294.fls.doubleclick.net/ https://www.facebook.com/ https://ct.pinterest.com/ https://td.doubleclick.net/ https://www.googletagmanager.com/; 1 default-src 'self' https://www.rpharms.com https://eu-admin.eventscloud.com https://assets-tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://staging-service.rpharms.com https://tracking.crazyegg.com https://cdn.linkedin.oribi.io https://api.usabilla.com https://strapi-uat.rpharms.com https://webchat.dotdigital.com https://www.google.co.uk https://kit.fontawesome.com https://www.facebook.com https://pagead2.googlesyndication.com https://region1.google-analytics.com https://www.google-analytics.com https://cdn.cookielaw.org https://stats.g.doubleclick.net https://geolocation.onetrust.com https://region1.analytics.google.com https://gtm-np33kgp-njqyn.uc.r.appspot.com https://privacyportal-eu.onetrust.com https://r1.trackedweb.net https://script.crazyegg.com https://ka-p.fontawesome.com https://ka-f.fontawesome.com; frame-src 'self' https://forms.office.com/ https://www.google.com/ https://my.matterport.com/ https://webchat.dotdigital.com/ https://player.vimeo.com/ https://w.soundcloud.com/ https://cse.google.com https://www.youtube.com/ https://td.doubleclick.net/ https://www.facebook.com/; script-src 'self' https://eu-admin.eventscloud.com https://cdn01.jotfor.ms https://cdn03.jotfor.ms https://cdn02.jotfor.ms https://form.jotform.com https://api.usabilla.com https://partner.googleadservices.com https://webchat.dotdigital.com https://unpkg.com http://cdnjs.cloudflare.com https://player.vimeo.com http://clients1.google.com http://www.google-analytics.com http://cse.google.com http://www.googletagmanager.com http://rum.monitis.com https://cse.google.com https://www.google.com https://www.google-analytics.com https://connect.facebook.net https://cdn.cookielaw.org https://script.crazyegg.com https://snap.licdn.com https://googleads.g.doubleclick.net http://static.trackedweb.net http://w.usabilla.com https://kit.fontawesome.com 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https://eu-admin.eventscloud.com https://cdn.jsdelivr.net https://cdn.materialdesignicons.com https://cdn03.jotfor.ms https://cdn02.jotfor.ms https://cdn01.jotfor.ms https://d6tizftlrpuof.cloudfront.net https://webchat.dotdigital.com http://cdnjs.cloudflare.com http://cdn.rawgit.com https://use.fontawesome.com https://www.google.com https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://eu-admin.eventscloud.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://d6tizftlrpuof.cloudfront.net https://use.fontawesome.com https://fonts.gstatic.com https://ka-f.fontawesome.com https://ka-p.fontawesome.com data:; img-src * data:; 1 style-src-elem w.vi.skadtec.com euc-widget.freshworks.com tags.srv.stackadapt.com static-tracking.klaviyo.com maxcdn.bootstrapcdn.com *.klarnaservices.com x.klarnacdn.net fonts.googleapis.com 'self' 'unsafe-inline' ff.kis.v2.scr.kaspersky-labs.com gc.kis.v2.scr.kaspersky-labs.com me.kis.v2.scr.kaspersky-labs.com static.trbo.com static.klaviyo.com cdn.jsdelivr.net; script-src-elem www.ladenzeile.de 3001.scriptcdn.net pix.hyj.mobi www.hammer.de euc-widget.freshworks.com t.adcell.com pagead2.googlesyndication.com connect.facebook.net analytics.tiktok.com collect.bannercrowd.net containertags.belboon.com bat.bing.com cdn.alevco.de neso.r.niwepa.com pluto.r.powuta.com s.kk-resources.com unpkg.com cdn-quick-ar.threedy.ai hammersport.trafft.com www.googletagmanager.com *.klarnaservices.com commerce.adobedtm.com maps.googleapis.com magento-recs-sdk.adobe.net *.cptrack.de secure.pay1.de www.google.com *.gstatic.com d.ratepay.com *.payments-amazon.com static-tracking.klaviyo.com static.klaviyo.com l.ecn-ldr.de *.trbo.com *.usercentrics.eu *.hammer.de www.googleadservices.com widgets.trustedshops.com *.ad-srv.net x.klarnacdn.net containertags.belboon.de *.hotjar.com *.adform.net ai.trk42.net *.retargeted.co pikkasrv.com analytics.bestofluck.io *.gsitrix.com tags.srv.stackadapt.com 'self' 'unsafe-inline' [Filtered]: app.usercentrics.eu blob: cdn.adt357.net cdn.jsdelivr.net content.cptrack.de eu-library.klarnaservices.com ff.kis.v2.scr.kaspersky-labs.com gc.kis.v2.scr.kaspersky-labs.com googleads.g.doubleclick.net infird.com me.kis.v2.scr.kaspersky-labs.com portal.threedy.ai secured-pixel.com static-na.payments-amazon.com static.getback.ch tm.ad-srv.net tm704.ad-srv.net tm710.ad-srv.net tm716.ad-srv.net tm717.ad-srv.net track.adform.net ubaslome.maynhtml.com valuesportal.com www.getback.ch www.google-analytics.com xeldurap.peazheut.com *.newrelic.com trk.cytelligence.io www.youtube.com rast.hammer-fitness.at bat.bing-int.com; font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.gstatic.com data: ray.st w.vi.skadtec.com account.affilitizer.com cdn.scite.ai moz-extension: *.klarnacdn.net http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io d3dc1lgancj6l0.cloudfront.net *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com http://*.facebook.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.hammer-fitness.at www.hammer-fitness.ch www.hammer-fitness.be www.hammer-fitness.nl www.hammer.de 'self' 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de browserstart.org link.shoplooks.com osak.com r.secprf2.com qimp.net hammer-fitness.at bat.bing.com vently.com tatrck.com monetoad.com de.kweriee.com as.ad4m.at yaketar.com findarios.com *.ddev.site jsctool.com *.sendinblue.com sibautomation.com *.trbo.com containertags.belboon.com roxxtraxx.de *.ad-srv.net td.doubleclick.net pluto.r.powuta.com hammersport.trafft.com r.adserver01.de player.flipsnack.com nakoona.com ptclk.com www.linkbux.com neso.r.niwepa.com r.linksprf.com hammer.de oponas.com t.adcell.com bcsgsrv.com hammer-fitness.ch adnx.de quick-ar.threedy.ai www.facebook.com hammer-fitness.nl c1.adform.net such.de caclk.com osm.klarnaservices.com t.hammer.de 127.0.0.1:20489 admin.rewardoo.com affiliate.grabasaving.com atlas.r.akipam.com browsak.com clcktrck.com discountheld.de duertry.com everydaysi.com gateway.zscloud.net go.adt246.net hipodi.com janus.r.jakuli.com r.perfsimpl.com rast.hammer.de shopbuttler.com support.google.com vently.org www.hammer.de www.pickalink.com www.searchfor.org xgs.bdo.gi:8090 yazary.com *.klarna.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com/ http://*.facebook.com https://*.facebook.com secure.pay1.de payments.amazon.de www.jsctool.com js.playground.klarna.com www.xtento.com https://recaptcha.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com files.shoop.de www.google.pl www.google.nl www.google.dk www.google.lu www.google.com.hk www.google.mk www.google.ch www.google.no www.google.pt www.google.it www.google.es www.google.ae www.google.co.in www.google.com.bo *.ddev.site *.hammer.de *.hammer-fitness.at *.hammer-fitness.ch *.hammer-traning.se *.trbo.com widgets.trustedshops.com ai.trk42.net *.usercentrics.eu www.zenaps.com www.facebook.com bat.bing.net x.bidswitch.net bat.bing.com *.casalemedia.com www.google.de region1.analytics.google.com neso.r.niwepa.com s.ad.smaato.net pixel.rubiconproject.com sync.outbrain.com e1.emxdgt.com lh3.ggpht.com pluto.r.powuta.com translate.google.com www.hammerworkouts.de stats.g.doubleclick.net www.google.se w.vi.skadtec.com www.google.at server.seadform.net www.google.co.uk ad.yieldlab.net ih.adscale.de *.pubmatic.com *.openx.net *.adform.net *.smartadserver.com *.connectad.io *.loopme.me *.360yield.com *.1rx.io router.infolinks.com *.rmp.rakuten.com *.doubleclick.net unsafe-inline s.c.appier.net capi.connatix.com api.qrserver.com cdn.retailads.net cdn.valuesportal.com cnv.adt644.net connect.facebook.net d3k81ch9hvuctc.cloudfront.net dsum-sec.casalemedia.com lh3.google.com lh3.googleusercontent.com mitarchive.info my.productfruits.com ncr.preqservices.com s.kelkoogroup.net s3-eu-central-1.amazonaws.com st-filebanking.igstatic.com static.wixstatic.com t.adcell.com www.econda-monitor.de www.google.ba www.google.be www.google.bg www.google.ca www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.za www.google.com.au www.google.com.br www.google.com.do www.google.com.eg www.google.com.gi www.google.com.lb www.google.com.na www.google.com.om www.google.com.ph www.google.com.pk www.google.com.py www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.ee www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.jo www.google.li www.google.lt www.google.md www.google.ro www.google.rs www.google.ru www.google.si www.google.sk www.google.sn www.google.tn magefan.com cm.magefan.com maps.gstatic.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.linkedin.com https://*.linkedin.com http://*.facebook.com https://*.facebook.com http://www.google.com/ https://www.google.com/ http://www.google.de/ https://www.google.de/ https://www.googletagmanager.com http://www.googletagmanager.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://widgets.trustedshops.com/ cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com *.disqus.com https://img.youtube.com www.xtento.com cdn.xtento.com sync.inmobi.com blob: www.hammer-fitness.nl www.google.com.tr *.google-analytics.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de hammersport.trafft.com *.ddev.site *.hammer.de *.hammer-fitness.at *.hammer-fitness.ch *.hammer-traning.se *.sendinblue.com sibautomation.com *.emailsys1a.net *.trbo.com *.usercentrics.eu widgets.trustedshops.com content.cptrack.de t.adcell.com l.ecn-ldr.de containertags.belboon.de *.adform.net ai.trk42.net s.retargeted.co pix.hyj.mobi pikkasrv.com analytics.bestofluck.io *.gsitrix.com *.ad-srv.net trk.cytelligence.io tags.srv.stackadapt.com qvdt3feo.com cdn.alevco.de neso.r.niwepa.com pluto.r.powuta.com analytics.tiktok.com bat.bing.com collect.bannercrowd.net containertags.belboon.com connect.facebook.net cdn-quick-ar.threedy.ai s.kk-resources.com unsafe-inline bat.bing-int.com blob: cdn.adt357.net cdn.jsdelivr.net portal.threedy.ai static.getback.ch unpkg.com valuesportal.com www.getback.ch maps.googleapis.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://connect.facebook.net/ https://snap.licdn.com/li.lms-analytics/insight.min.js http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com http://www.google.com/recaptcha/ https://widgets.trustedshops.com/ secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.disqus.com *.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tags.srv.stackadapt.com euc-widget.freshworks.com static-tracking.klaviyo.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com d.ratepay.com d.payla.io dr.payla.io *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com static.trbo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com w.vi.skadtec.com www.hammerworkouts.de data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.ddev.site *.hammer.de *.hammer-fitness.at *.hammer-fitness.ch *.hammer-traning.se *.sendinblue.com sibautomation.com maps.googleapis.com *.usercentrics.eu *.econda-monitor.de t.adcell.com *.gsitrix.com analytics.bestofluck.io tags.srv.stackadapt.com bat.bing.net bat.bing.com region1.analytics.google.com www.google.se stats.g.doubleclick.net region1.google-analytics.com analytics.tiktok.com api.retargeted.co www.facebook.com quick-ar.threedy.ai static.trbo.com api.bannercrowd.net s.kelkoogroup.net www.google.com euc-widget.freshworks.com api-js.datadome.co api.killadsapi.com salesviewer.org api.global-data-lab.com api.solarspireconsulting.com hammer.freshdesk.com api.datacloudstat.com api.socialsolutionapp.com adtonus.com api.adtraction.net api.ipify.org api.smartblocker.org api.trustedshops.com api.video-adblock.com blob: cnv.adt644.net code.jquery.com data: go.adt246.net my.productfruits.com ncrfiles.s3.us-central-1.wasabisys.com overbridgenet.com rktds.net update.adblock360.org www.google.dk www.google.no api.qrserver.com cdn.retailads.net cdn.valuesportal.com connect.facebook.net d3k81ch9hvuctc.cloudfront.net dsum-sec.casalemedia.com googleads.g.doubleclick.net lh3.google.com lh3.googleusercontent.com mitarchive.info ncr.preqservices.com s3-eu-central-1.amazonaws.com st-filebanking.igstatic.com static.wixstatic.com www.econda-monitor.de www.google.ba www.google.be www.google.bg www.google.ca www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.za www.google.com.au www.google.com.br www.google.com.do www.google.com.eg www.google.com.gi www.google.com.lb www.google.com.na www.google.com.om www.google.com.ph www.google.com.pk www.google.com.py www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.ee www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.jo www.google.li www.google.lt www.google.md www.google.ro www.google.rs www.google.ru www.google.si www.google.sk www.google.sn www.google.tn x.bidswitch.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com http://salesviewer.org/ userlike-cdn-widgets.s3-eu-west-1.amazonaws.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com bat.bing-int.com analytics-ipv6.tiktokw.us google.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.paypalobjects.com https://lindtusa.rlvs.co.uk https://ghirardelli.slgnt.us https://optmize.google.com https://www.instagram.com https://rscmakehappy.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://mcprod.russellstover.com https://mediacdn.espssl.com/2824/Shared/Modal/chocolate.png https://www.linkedin.com https://*.linkedin.com/ https://px.ads.linkedin.com *.googleadservices.com *.russellstover.com https://www.google-anaytics.com https://www.googletagmanager.com https://optimize.google.com *.bazaarvoice.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.youtube.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com 'unsafe-inline' https://optimize.google.com 'unsafe-inline' https://www.instagram.com https://www.lindt-spruengli.com/media/target/VAPI.min.js https://www.lindt-spruengli.com/media/target/at.js https://www.lindt-spruengli.com/* https://cdn.attn.tv 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://cloud.typography.com https://optimize.google.com https://fonts.googleapis.com 'unsafe-inline' 'unsafe-inline' https://use.typekit.net/qqa8ami.css *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://vc.hotjar.io https://cdn.linkedin.oribi.io *.russellstover.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com https://geolocation.onetrust.com https://bat.bing.com https://events.attentivemobile.com https://lindt-us.attn.tv 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.contractorcommerce.com 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 1merchantacsstag.cardinalcommerce.com payments.securetrading.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.youtube.com https://player.vimeo.com https://vars.hotjar.com/ webservices.securetrading.net cdn.eu.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://ebizmarts-website.s3.amazonaws.com www.opayo.co.uk www.sagepay.co.uk https://firebasestorage.googleapis.com gstatic.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com https://devdocs.magento.com https://magento.com https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com *.avada.io webservices.securetrading.net cdn.eu.trustpayments.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://maxcdn.bootstrapcdn.com https://use.typekit.net https://p.typekit.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com https://devdocs.magento.com https://www.google-analytics.com https://stats.g.doubleclick.net https://get.geojs.io *.avada.io o402164.ingest.sentry.io analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.jsdelivr.net https://supersociedades.gov.co https://*.fontawesome.com https://fonts.gstatic.com; connect-src 'self' https://*.nr-data.net https://shyrka-prod.s3.amazonaws.com https://*.newrelic.com https://*.mypurecloud.com https://*.use1.pure.cloud wss://*.mypurecloud.com wss://*.use1.pure.cloud https://*.fontawesome.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.jsdelivr.net https://www.youtube.com https://*.bootstrapcdn.com https://supersociedades.gov.co https://*.nr-data.net https://*.newrelic.com https://*.mypurecloud.com https://*.use1.pure.cloud https://kit.fontawesome.com https://ajax.googleapis.com https://*.cloudflare.com https://maxcdn.bootstrapcdn.com https://*.twitter.com https://www.instagram.com; media-src 'self' https://*.mypurecloud.com https://*.use1.pure.cloud; object-src 'none'; child-src 'self' https://www.facebook.com https://*.mypurecloud.com https://*.use1.pure.cloud https://www.youtube.com https://superwas.supersociedades.gov.co https://www.linkedin.com https://*.twitter.com https://www.instagram.com; img-src 'self' https://www.supersociedades.gov.co https://*.mypurecloud.com https://*.use1.pure.cloud data:; frame-ancestors 'self'; style-src 'self' 'unsafe-inline' https://*.mypurecloud.com https://*.cloudflare.com https://*.jsdelivr.net https://supersociedades.gov.co https://fonts.googleapis.com https://fonts.gstatic.com; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.kxcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com www.cadetdirect.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com *.googlesyndication.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com www.cadetdirect.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.cadetdirect.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com www.xtento.com www.cadetdirect.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com google.com *.fbcdn.net *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com www.cadetdirect.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.googleapis.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com www.cadetdirect.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com google.com *.kxcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com maxcdn.bootstrapcdn.com assets.braintreegateway.com www.cadetdirect.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.cadetdirect.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.cadetdirect.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.cadetdirect.com http: https: blob: 'self' 'unsafe-inline'; default-src www.cadetdirect.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' unpkg.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://static.hotjar.com https://script.hotjar.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.googletagmanager.com https://snap.licdn.com https://googleads.g.doubleclick.net https://maps.googleapis.com unpkg.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; frame-ancestors 'self'; report-uri https://www.vopak.com/cspreport 1 font-src data: safepay.asiabill.com testpay.asiabill.com sandbox-pay.asiabill.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net safepay.asiabill.com testpay.asiabill.com sandbox-pay.asiabill.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com safepay.asiabill.com testpay.asiabill.com sandbox-pay.asiabill.com accounts.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://static.afterpay.com https://site-assets.afterpay.com/ maps.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com safepay.asiabill.com testpay.asiabill.com sandbox-pay.asiabill.com cdn.polyfill.io accounts.google.com maps.googleapis.com https://accounts.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com safepay.asiabill.com testpay.asiabill.com sandbox-pay.asiabill.com cdn.polyfill.io accounts.google.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ magento-cloudflare.jetrails.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://images.unsplash.com magefan.com cm.magefan.com *.ytimg.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://track.hubspot.com https://forms.hsforms.com https://s.ytimg.com *.google.com *.google.co.in *.doubleclick.net https://www.facebook.com https://bat.bing.com https://api.shutterstock.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ https://maps.googleapis.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.newrelic.com https://js.hs-scripts.com https://js.hscollectedforms.net https://js.usemessages.com https://js.hsadspixel.net https://js.hs-banner.com https://js.hs-analytics.net https://js-na1.hs-scripts.com https://pf-cdn.printfriendly.com https://cdn.printfriendly.com http://cdn.printfriendly.com https://www.printfriendly.com https://connect.facebook.net https://bat.bing.com https://383433.tctm.co https://static.cloudflareinsights.com *.reviews.io *.reviews.co.uk https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://stats.g.doubleclick.net *.cloudflare.com https://forms.hscollectedforms.net/ *.google-analytics.com *.nr-data.net https://api.hubspot.com https://api.hubapi.com https://api.shutterstock.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com https://staticfiles.solutiontree.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.olark.com *.trustedshops.com *.googleapis.com https://fast.fonts.net *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.authorize.net https://fast.wistia.net https://www.googletagmanager.com secure.authorize.net test.authorize.net 1eaf.cardinalcommerce.om www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com *.yotpo.com https://mkt.solution-tree.com https://mkt.solutiontree.com https://mkt.marzanoresources.com *.olark.com *.facebook.com https://bid.g.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.ksearchnet.com store.paradoxlabs.com https://staticfiles.solutiontree.com https://cloudfront-s3.solutiontree.com https://marzano-s3.solutiontree.com https://mediafiles.solutiontree.com https://solutiontree.s3.amazonaws.com https://px.ads.linkedin.com https://t.co https://www.google.com https://www.google.co.in https://www.facebook.com https://d.adroll.com https://log.olark.com https://dc.ads.linkedin.com https://googleads.g.doubleclick.net https://dsum-sec.casalemedia.com https://pixel.rubiconproject.com https://pixel.advertising.com https://sync.outbrain.com https://simage2.pubmatic.com https://ads.yahoo.com https://sync.taboola.com https://eb2.3lift.com https://p.adsymptotic.com https://ups.analytics.yahoo.com https://soltreemrls3.s3-us-west-2.amazonaws.com fpdbs.paypal.com t.paypal.com fpdbs.sandbox.paypal.com *.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com *.olark.com https://soltreemrls3.s3.us-west-2.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.klevu.com *.ksearchnet.com *.authorize.net https://cdn.raygun.io https://staticfiles.solutiontree.com *.googletagmanager.com https://connect.facebook.net https://s.adroll.com https://snap.licdn.com https://static.ads-twitter.com https://script.crazyegg.com https://analytics.twitter.com https://d.adroll.com https://fast.wistia.com https://fast.wistia.net https://static.olark.com https://pi.pardot.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net secure.authorize.net test.authorize.net *.google.co.in *.facebook.com *.olark.com/ *.pardot.com/ *.cloudflare.com *.twitter.com *.google.com *.linkedin.com *.twimg.com *.gstatic.com *.paypalobjects.com *.paypal.com *.bootstrapcdn.com www.paypalobjects.com js.braintreegateway.com t.paypal.com *.cardinalcommerce.com www.sandbox.paypal.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.klevu.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com https://mkt.solution-tree.com https://mkt.solutiontree.com https://mkt.marzanoresources.com https://static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klevu.com *.ksearchnet.com https://staticfiles.solutiontree.com https://s.adroll.com *.olark.com https://fast.fonts.net/ *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.klevu.com *.ksearchnet.com *.authorize.net https://api.raygun.io https://staticfiles.solutiontree.com https://stats.g.doubleclick.net https://script.crazyegg.com https://www.facebook.com https://s.adroll.com https://d.adroll.com https://tracking.crazyegg.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com client-analytics.sandbox.braintreegateway.com client-analytics.braintreegateway.com *.braintree-api.com *.yotpo.com *.olark.com *.crazyegg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-d69e83b16be04541b8ffd1b87c56ed9f1a1473d916254c1249ec03ca1ae5acc5' 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' *.google-analytics.com *.googletagmanager.com *.google.com *.gstatic.com *.googleapis.com *.bing.com *.pcapredict.com *.dwin1.com lantern.roeyecdn.com services.postcodeanywhere.co.uk *.facebook.net; object-src 'none'; base-uri 'none'; report-uri /includes/csp_report.php 1 default-src 'self'; script-src https: 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com kit.fontawesome.com *.hsadspixel.net *.hs-analytics.net js.hscta.net *.hubspot.com static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net www.garp.org *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com; style-src 'self' 'unsafe-inline' *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net cdn2.hubspot.net www.garp.org static.hsappstatic.net; img-src https: 'self' 'unsafe-eval' js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com s3-us-west-2.amazonaws.com; font-src 'self' ka-p.fontawesome.com; connect-src 'self' *.google.com *.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net *.vidyard.com *.fontawesome.com content.hotjar.io *.hotjar.com wss://wsp14.hotjar.com wss://wsp43.hotjar.com/api/v2/client/ws stats.g.doubleclick.net static.libsyn.com cdn.linkedin.oribi.io *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com bat.bing.com hm.baidu.com; object-src 'none'; media-src 'self'; frame-src html5-player.libsyn.com forms.hsforms.com *.hubspot.com *.hs-sites.com *.hubspot.net play.hubspotvideo.com www.garp.org *.hsforms.net *.hsforms.com *.googletagmanager.com *.twitter.com *.facebook.com fast.wistia.net *.youtube.com; base-uri 'self'; report-to /csp-violation-report-endpoint/; 1 font-src https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https:; connect-src 'self' https:; media-src 'self' https:; object-src 'none'; frame-src 'self' https:; report-uri /csp-report-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com *.googleapis.com *.cloudflare.com *.google-analytics.com *.twitter.com *.twimg.com *.global-e.com *.yotpo.com *.klevu.com data: *.mention-me.com *.daylesford.com *.ksearchnet.com *.fontawesome.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com *.twitter.com *.bglobale.com *.hotjar.com *.hotjar.io *.duel.me *.vimeo.com *.shipperhq.com *.ometria.com *.ometria.email *.addtoany.com/ *.pinterest.com *.visualwebsiteoptimizer.com *.daylesford.com *.cookiebot.com *.luckyorange.com *.googletagmanager.com *.mention-me.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com https://*.gstatic.com *.googleapis.com *.cloudflare.com *.google.com *.google.co.uk maps.googleapis.com *.google-analytics.com *.googleadservices.com *.global-e.com *.yotpo.com yotpo-stool.s3.amazonaws.com *.doubleclick.net *.ometria.com *.postcodeanywhere.co.uk *.shipperhq.com *.klevu.com *.daylesford.com *.kaltura.com *.pinterest.com *.facebook.net *.facebook.com *.sendtric.com *.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com cdn.pushcrew.com wingify-assets.s3.amazonaws.com chart.googleapis.com *.rakuten.com track.linksynergy.com *.cookiebot.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com magefan.com cm.magefan.com *.disqus.com *.luckyorange.com *.ksearchnet.com *.contentsquare.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com https://maps.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com *.googleapis.com *.gstatic.com *.cloudflare.com *.google-analytics.com *.googletagmanager.com *.gtm.daylesford.com maps.googleapis.com *.twitter.com *.twimg.com *.bglobale.com *.yotpo.com js-agent.newrelic.com *.doubleclick.net *.ometria.com *.hotjar.com *.hotjar.io *.duel.me *.postcodeanywhere.co.uk *.pcapredict.com *.shipperhq.com *.zdassets.com www.bugherd.com *.klevu.com *.addtoany.com *.zendesk.com *.kaltura.com *.pinterest.com *.pinimg.com *.facebook.net *.sendtric.com *.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com cdn.pushcrew.com *.rakuten.com track.linksynergy.com *.adobedtm.com *.googleadservices.com *.cookiebot.com tagmanager.google.com *.disqus.com 'unsafe-eval' gtm.daylesford.com tools.luckyorange.com loader.usehero.com cdn.usehero.com *.contentsquare.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com *.mention-me.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.cloudflare.com *.google.com *.gstatic.com *.google-analytics.com *.googleapis.com 'self' data: *.twitter.com *.typekit.net *.twimg.com getfirebug.com *.yotpo.com *.postcodeanywhere.co.uk *.shipperhq.com *.klevu.com *.myfonts.net *.zendesk.com *.facebook.net *.sendtric.com *.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com cdn.pushcrew.com s3.amazonaws.com *.rakuten.com track.linksynergy.com *.daylesford.com *.cookiebot.com tagmanager.google.com fonts.google.com tools.luckyorange.com *.ksearchnet.com *.adyen.com https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com/ *.zendesk.com *.kaltura.com *.daylesford.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.cloudflare.com *.google-analytics.com *.twitter.com *.twimg.com *.yotpo.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.postcodeanywhere.co.uk *.shipperhq.com wss://rms.shipperhq.com wss://widget-mediator.zopim.com *.zdassets.com *.ksearchnet.com *.zendesk.com *.pinterest.com *.sendtric.com *.yes track.linksynergy.com *.daylesford.com *.cookiebot.com *.googlesyndication.com *.analytics.google.com *.googletagmanager.com *.luckyorange.com dev.visualwebsiteoptimizer.com api.usehero.com *.contentsquare.net api.addressy.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.mention-me.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.gstatic.com *.typekit.net *.trustedshops.com *.trustpilot.com *.googleapis.com *.klaviyo.com *.zip.co data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.paymentexpress.com *.windcave.com *.klaviyo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app winathuntingandfishing.co.nz *.laybuy.com *.addthis.com *.facebook.com huntingandfishing.freshdesk.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com *.paymentexpress.com *.windcave.com www.xtento.com *.doubleclick.net *.issuu.com app.redpepperdigital.net *.afterpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://img.youtube.com *.cloudflare.com *.cloudfront.net https://cdn.klarna.com *.gstatic.com *.paypal.com *.afterpay.com https://s.ytimg.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.cdninstagram.com *.instagram.com *.facebook.net *.facebook.com *.clarity.ms *.bing.com t.zip.co static.zipmoney.com.au *.paymentexpress.com *.windcave.com www.xtento.com cdn.xtento.com *.google.co.nz *.zip.co partpayassets.blob.core.windows.net tags.srv.stackadapt.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.cloudflare.com *.cloudfront.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.intercomcdn.com *.intercom.io *.addthis.com *.addthisedge.com *.moatads.com *.facebook.net *.clarity.ms *.freshworks.com s3.amazonaws.com/assets.freshdesk.com/ static.zipmoney.com.au zip.co *.paymentexpress.com *.windcave.com www.xtento.com cdn.xtento.com *.hotjar.com *.zip.co zipmoney.com.au app.redpepperdigital.net tags.srv.stackadapt.com *.google.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io static.afterpay.com/ *.squarecdn.com *.cash.app https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.typekit.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.freshworks.com s3.amazonaws.com/assets.freshdesk.com/ *.zip.co tags.srv.stackadapt.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cdninstagram.com *.instagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.cloudfront.net foursixty.com *.paypal.com *.googleapis.com *.addthis.com *.addthisedge.com *.moatads.com *.intercom.io *.cdninstagram.com *.instagram.com *.clarity.ms *.doubleclick.net *.freshworks.com google.com *.hotjar.io *.zip.co tags.srv.stackadapt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'wasm-unsafe-eval' 'unsafe-eval' *.gstatic.com *.vimeo.com *.onetrust.com adobedc.demdex.net assets.adobedtm.com cdn.cookielaw.org service.force.com www.datadoghq-browser-agent.com *.salesforceliveagent.com maps.googleapis.com static.cloud.coveo.com js.web-2-tel.com www.youtube.com e.issuu.com cdnjs.cloudflare.com cdn.userway.org gallery-prod8.sprinklr.com platform.twitter.com 'unsafe-inline'; connect-src 'self' 'wasm-unsafe-eval' *.onetrust.io *.userway.org *.gstatic.com *.onetrust.com adobedc.demdex.net cdn.plot.ly *.vimeo.com *.coveo.com api.geoapify.com *.googleapis.com edge.adobedc.net js.web-2-tel.com cdn.cookielaw.org rum.browser-intake-datadoghq.com data:; img-src 'self' *.smilegeneration.com i.ytimg.com i.vimeocdn.com s7d9.scene7.com cdn.cookielaw.org maps.googleapis.com maps.gstatic.com 1.smilegeneration.com image.isu.pub thumb.sprinklr.com data: blob: 'unsafe-inline'; frame-src 'self' *.google.com *.epichosted.com *.smilegenerationmychart.com e.issuu.com player.vimeo.com www.youtube.com service.force.com; style-src 'self' service.force.com e.issuu.com *.userway.org gallery-prod8.sprinklr.com static.cloud.coveo.com fonts.googleapis.com 'unsafe-inline'; font-src 'self' *.userway.org fonts.gstatic.com static.isu.pub platform.twitter.com storage.googleapis.com *.coveo.com www.sfdcstatic.com data:; worker-src blob:; frame-ancestors 'self' https://www.smilegenerationmychart.com https://mychart-np.et1079.epichosted.com; 1 frame-ancestors 'self'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=puba63db3f96a1d5bb789394101974def5f&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env:production 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://assets.royalbagspa.com.au https://fonts.gstatic.com https://static.zipmoney.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google.com https://pay.google.com https://assets.royalbagspa.com.au https://fonts.gstatic.com https://static.zipmoney.com.au https://static.elfsight.com/ zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://assets.royalbagspa.com.au https://site-assets.afterpay.com https://lh3.googleusercontent.com https://www.google.com https://www.google.co.in https://www.facebook.com https://www.gstatic.com https://www.google-analytics.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://assets.royalbagspa.com.au https://static.elfsight.com https://www.gstatic.com https://t.labs.au.edge.zip.co https://apps.elfsight.com https://static.zipmoney.com.au https://www.google.com https://www.googletagmanager.com https://connect.facebook.net https://js.braintreegateway.com *.google.com https://www.google-analytics.com https://static.cloudflareinsights.com *.zip.co *.zipmoney.com.au *.demdex.net *.omtrdc.net *.afterpay-beta.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ *.squarecdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com https://assets.royalbagspa.com.au https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com static.sandbox.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.clearpay.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.zipmoney.com.au https://assets.royalbagspa.com.au https://apps.elfsight.com https://service-reviews-ultimate.elfsight.com *.zip.co https://www.google-analytics.com https://stats.g.doubleclick.net https://payments.braintree-api.com https://client-analytics.braintreegateway.com *.elfsight.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.googleapis.com *.gstatic.com *.static.klaviyo.com static.klaviyo.com *.klevu.com *.ksearchnet.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.curalate.com js-agent.newrelic.com bam.nr-data.net *.googletagmanager.com *.googleanalytics.com https://www.merchante-solutions.com https://hostedpayments.merchante.com https://merchantacsstag.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://elements.sandbox.fortis.tech https://elements.fortis.tech www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.curalate.com js-agent.newrelic.com bam.nr-data.net *.googletagmanager.com *.googleanalytics.com *.doubleclick.net www.activemerchandiser.com my.matterport.com ct.pinterest.com *.cdn-lg.accentdecor.com https://www.googletagmanager.com/ magento-cloudflare.jetrails.com www.youtube.com *.google.com/ https://merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com maps.gstatic.com https://www.magezon.com *.curalate.com js-agent.newrelic.com bam.nr-data.net *.googletagmanager.com *.googleanalytics.com developers.google.com maps.googleapis.com *.accentdecor.com *.doubleclick.net ct.pinterest.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://developer.adobe.com https://magento.com https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com *.curalate.com *.mailchimp.com *.paypal.com *.googletagmanager.com *.googleanalytics.com *.merchante-solutions.com *.adobetm.com *.braintreegateway.com *.yotpo.com js-agent.newrelic.com bam.nr-data.net chimpstatic.com eastprodcdn.azureedge.net mc.us1.list-manage.com *.accentdecor.com maps.googleapis.com *.fullstory.com s.pinimg.com *.cloudfront.net *.static.cloudflareinsights.com static.cloudflareinsights.com *.googleads.g.doubleclick.net googleads.g.doubleclick.net *.ajax.cloudflare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.curalate.com js-agent.newrelic.com bam.nr-data.net *.googletagmanager.com *.googleanalytics.com *.accentdecor.com *.static-tracking.klaviyo.com static-tracking.klaviyo.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://developer.adobe.com https://elements.sandbox.fortis.tech https://elements.fortis.tech www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.curalate.com *.amazonpay.com *.amazon.com js-agent.newrelic.com bam.nr-data.net *.googletagmanager.com *.googleanalytics.com *.accentdecor.com maps.googleapis.com *.fullstory.com *.velaro.com ct.pinterest.com *.analytics.google.com *.google-analytics.com https://analytics.google.com *.cloudflareinsights.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com https://writer.cardinalcommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.googleapis.com *.narvar.com *.narvar.qa *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cybersource.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com *.cash.app www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cybersource.com landofcoder.com *.buywithprime.amazon.com *.pinterest.com *.livechatinc.com *.afterpay.com *.googletagmanager.com www.googletagmanager.com *.cardinalcommerce.com *.doubleclick.net *.adtrafficquality.google https://*.exacttarget.com *.herokuapp.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.narvar.com *.narvar.qa *.online-metrix.net getrockerbox.com *.googletagmanager.com tagmanager.google.com *.google.com ssl.gstatic.com *.cardinalcommerce.com *.google.rs ep1.adtrafficquality.google https://pagead2.googlesyndication.com *.herokuapp.com *.virtuelabs.com *.virtueflourish.com *.virtueprofessional.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.certcapture.com *.exponea.com utt.impactcdn.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.authorize.net landofcoder.com *.buywithprime.amazon.com *.bloomreach.com getrockerbox.com *.googletagmanager.com tagmanager.google.com *.livechatinc.com *.evgnet.com *.tiktok.com *.bing.com *.facebook.net *.upsellit.com *.cdn-apple.com *.cloudfront.net *.iesnare.com *.cloudflare.com *.evergage.com https://utt.impactcdn.com https://cdn.impactcdn.com *.collect.igodigital.com https://7295774.collect.igodigital.com https://script.hotjar.com https://*.exacttarget.com https://*.shopmy.us *.herokuapp.com *.virtuelabs.com *.virtueflourish.com *.virtueprofessional.com https://www.googletagmanager.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-eval' 'nonce-MGZjcTZ4YTVpeGtydnk2c2Z5ZDY4NW1idmNoamRpejA=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8=' 'sha256-F9ZjdH6KZZ/OQYCXuVrhU9s4UhLIRpF8vfMBhSoSXFE=' 'sha256-xBBj7y2m2odaO1eEHhqtWa5krtIC4XwfNI7nxM/at+Y=' 'sha256-XtBpUSZu52CP7zsoqr85SHz2B8lKfNjFwxDWepGFWqk=' 'sha256-yUMYwnLESbaXoS7OTnNOz4jRL/etTRlzd9EXBxAJ8uU=' 'sha256-Umf4XdDT2jU+W6kBElYNVCfHdypDvQ+hP0N25TF8spw=' 'sha256-fxIIiV/UkD1qBH84xOcYKL2Udw95xiIuZ8dCqyBgqkw=' 'sha256-sCNgwSOg1ilvVplXvgrvrmp0pEugiAg6BLdsMXn3EVE=' 'sha256-QwDPTOv7DnssR14XIEwQveE176ZTtI+2O9ODcXlA6No=' 'sha256-x+21YgSzPwcXB65O7nXIpUsWFLsVdoPUSdOEolX00Lk='; style-src fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.cash.app *.certcapture.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.narvar.com *.narvar.qa *.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.certcapture.com *.exponea.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.authorize.net landofcoder.com *.bloomreach.com *.google-analytics.com *.doubleclick.net *.tiktok.net *.googletagmanager.com *.iesnare.com *.cloudflare.com *.evergage.com *.virtuelabs.com ep1.adtrafficquality.google t.getletterpress.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com https://aa.agkn.com https://*.shopmy.us *.herokuapp.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' https://s1749.t.eloqua.com data: 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://img.en25.com/i/elqCfg.min.js https://img.en25.com/i/elqCfg.min.js https://www.googletagmanager.com/gtm.js https://www.google-analytics.com/analytics.js ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; connect-src https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; 1 default-src 'self'; script-src 'self' https://platform.twitter.com https://static.hotjar.com https://connect.facebook.net https://use.fontawesome.com https://www.google-analytics.com https://bat.bing.com https://snap.licdn.com https://googleads.g.doubleclick.net https://script.hotjar.com; img-src 'self' https://bat.bing.net https://www.sportvisserijnederland.nl https://www.googleadservices.com; frame-src 'self' https://www.youtube.com https://platform.twitter.com https://syndication.twitter.com facebook.com https://14588724.fls.doubleclick.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com; font-src 'self' https://fonts.googleapis.com https://use.fontawesome.com; object-src 'none'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com wp.peugeot-saveurs.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com wp.peugeot-saveurs.com 'self' 'unsafe-inline'; frame-ancestors wp.peugeot-saveurs.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ *.fls.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com secure-gateway.hipay-tpp.com *.hipay.com wp.peugeot-saveurs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com wp.peugeot-saveurs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com secure-gateway.hipay-tpp.com *.hipay.com mpsnare.iesnare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com wp.peugeot-saveurs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com fonts.googleapis.com *.hipay.com https://static.klaviyo.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com wp.peugeot-saveurs.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com data: mpsnare.iesnare.com wp.peugeot-saveurs.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://the.sciencebehindecommerce.com maps.googleapis.com *.hipay.com wss://mpsnare.iesnare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ wp.peugeot-saveurs.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com wp.peugeot-saveurs.com http: https: blob: 'self' 'unsafe-inline'; default-src wp.peugeot-saveurs.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /csp_report;base-uri 'self';default-src 'self' blob: data: js.intercomcdn.com intercom.help *.intercom.io intercom-sheets.com www.intercom-reporting.com www.youtube.com player.vimeo.com fast.wistia.net fonts.gstatic.com *.hotjar.com www.facebook.com bid.g.doubleclick.net googleads.g.doubleclick.net https://*.googlesyndication.com *.fontawesome.com www.google.com assets.nflxext.com accounts.google.com *.googleapis.com https://dev-ipg.icards.eu https://api2.amplitude.com/2/httpapi https://*.clarity.ms *.paypal.com *.sandbox.paypal.com;object-src 'self' blob: neterra.tv *.neterra.tv;style-src 'self' 'unsafe-inline' https://googleads.g.doubleclick.net fonts.googleapis.com https://tagmanager.google.com https://fonts.googleapis.com ia.media-imdb.com https://api2.amplitude.com/2/httpapi;img-src * https: data:;connect-src 'self' neterra.tv payments.neterra.tv wss://elk-stats.neterra.tv 127.0.0.1:8999 staging.neterra.tv *.google-analytics.com analytics.google.com *.analytics.google.com region1.analytics.google.com *.googlesyndication.com http://sumo.com *.sumo.com *.hotjar.com www.google.bg www.google.com stats.g.doubleclick.net *.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io uploads.intercomcdn.com uploads.intercomusercontent.com *.neterra.tv:443 www.facebook.com *.fontawesome.com csi.gstatic.com fundingchoicesmessages.google.com securepubads.g.doubleclick.net https://dev-ipg.icards.eu https://api2.amplitude.com/2/httpapi sumome.com *.sumome.com www.sandbox.paypal.com https://*.mdc.akamaized.net https://*.google.com https://www.clarity.ms https://www.paypal.com https://*.clarity.ms www.google.co.uk https://adservice.google.com https://*.visualwebsiteoptimizer.com;script-src blob: 'self' 'unsafe-inline' 'unsafe-eval' *.geotrust.com www.geotrust.com www.gstatic.com ia.media-imdb.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net *.googlesyndication.com p.media-imdb.com *.facebook.com *.facebook.net *.sumo.com *.hotjar.com *.intercom.io js.intercomcdn.com https://www.googletagmanager.com https://adservice.google.bg https://adservice.google.com https://www.googletagservices.com *.fontawesome.com appleid.cdn-apple.com apis.google.com partner.googleadservices.com www.google.com securepubads.g.doubleclick.net fundingchoicesmessages.google.com *.googleapis.com *.google.com *.2mdn.net https://dev-ipg.icards.eu https://api2.amplitude.com/2/httpapi https://*.clarity.ms https://*.sumome.com *.paypal.com static.cloudflareinsights.com www.youtube.com load.sumome.com sumome.com https://www.paypalobjects.com https://*.visualwebsiteoptimizer.com https://*.tiny.cloud;form-action 'self' https://neterra.tv www.facebook.com epay.bg www.epay.bg demo.epay.bg https://dev-ipg.icards.eu https://api2.amplitude.com/2/httpapi *.paypal.com;media-src 'self' *.neterra.tv neterra.tv *.googlevideo.com *.googleapis.com https://api2.amplitude.com/2/httpapi *.clarity.ms blob: *.mdc.akamaized.net;font-src 'self' data: fonts.intercomcdn.com *.fontawesome.com fonts.gstatic.com;frame-src 'self' data: td.doubleclick.net www.google.com tpc.googlesyndication.com googleads.g.doubleclick.net pagead2.googlesyndication.com www.youtube.com https://www.paypalobjects.com https://accounts.google.com 1 font-src *.cookiefirst.com *.azureedge.net *.google-analytics.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cetelem.es *.cookiefirst.com *.facebook.com *.google-analytics.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.weltpixel.com https://backoffice-eu.oct8ne.com *.cookiefirst.com *.facebook.com *.google-analytics.com *.googleapis.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://sandbox.sequracdn.com https://live.sequracdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cetelem.es *.google.es *.facebook.com *.azureedge.net *.google-analytics.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://sandbox.sequracdn.com https://live.sequracdn.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cetelem.es *.sharethis.com *.cookiefirst.com *.facebook.net *.hotjar.com *.adobedtm.com *.oct8ne.com *.google-analytics.com *.googleapis.com wss://ws.hotjar.com landofcoder.com *.mgt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://sandbox.sequracdn.com https://live.sequracdn.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cetelem.es *.cookiefirst.com *.fontawesome.com unsafe-inline tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cetelem.es https://vc-service.saleago.com *.google.com *.cookiefirst.com *.hotjar.io *.hotjar.com *.oct8ne.com *.facebook.com *.analytics.google.com *.google-analytics.com *.doubleclick.net *.googletagmanager.com/ *.googleapis.com landofcoder.com https://get.geojs.io *.mgt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com https://sandbox.sequracdn.com https://live.sequracdn.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com https://*.gstatic.com *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.pcapredict.com *.jellybooks.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com * *.adyen.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com/ *.nosto.com *.nos.to *.pcapredict.com *.jellybooks.com *.wesupply.xyz *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.nosto.com *.nos.to *.visualwebsiteoptimizer.com *.pcapredict.com *.jellybooks.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.nosto.com *.nos.to *.visualwebsiteoptimizer.com *.pcapredict.com *.jellybooks.com *.cloudflare.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://fonts.googleapis.com/ webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.nosto.com *.nos.to *.pcapredict.com *.jellybooks.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.nosto.com *.nos.to *.pcapredict.com *.jellybooks.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://34dfd997-cd9a-4714-8e13-90912cb2b216.sansec.watch/; report-to report-endpoint; 1 default-src https:; connect-src https: wss:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' *.google.com fonts.googleapis.com static.pazaruvaj.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net maxcdn.bootstrapcdn.com ssl.ceneo.pl s.kk-resources.com elnino.daktela.com www.wiarygodneopinie.pl ts.tradetracker.net cdn.foxentry.cz www.parfemy-elnino.cz geowidget.inpost.pl www.googletagmanager.com smartsuppcdn.com cdn.luigisbox.com *.demandware.net; object-src 'self'; img-src 'self' https: data:; font-src https: data:; frame-ancestors 'self' *.creativecdn.com *.hotjar.com *.googletagmanager.com; worker-src 'self' blob:; report-uri https://elnino.report-uri.com/r/d/csp/enforce 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com *.cloudflare.com *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.doubleclick.net *.doubleclick.com *.gstatic.com *.akamaihd.net *.ebayimg.com *.ebay.com.au *.ebay.de *.google.com *.facebook.com *.googleapis.com *.gstatic-cache.com *.fbanalytics.org *.pinterest.com *.amplitude.com *.criteo.com *.googlesyndication.com *.ucweb.com www.googletagmanager.com www.googleadservices.com wss://127.0.0.1:* *.google-analytics.com *.graphitevault.com *.bing.com www.facebook.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data: *.alexa.com; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' 'unsafe-inline' https://* data: blob:; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/brwweb/brwweb_default?id=5376931874526678043&rid=t6awqpfgehmq%3C%3Dawqpfgehmq%2B0503%3F4212e(rbpv75%3A(2%7F%603%3E-19b29f3e874-0x1606#pd 1 default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self'; connect-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.fontawesome.com *.gstatic.com maxcdn.bootstrapcdn.com static.klaviyo.com cdn.userway.org cloud.productimize.com v2.zopim.com data: *.yotpo.com unpkg.com netdna.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com globalshopex.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://api.boldcommerce.com *.authorize.net *.meetanshi.com https://accounts.google.com https://amc.demdex.net/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.hotjar.com h.online-metrix.net imgs.signifyd.com disqus.com platform.twitter.com www.google.com globalshopex.com email.blauer.com cdn.userway.org w3.cdn.anvato.net imgs.cdn-btsg.com td.doubleclick.net/ landofcoder.com *.weltpixel.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.gstatic.com https://static.boldcommerce.com https://static.xx.fbcdn.net *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ store.paradoxlabs.com *.meetanshi.com https://meetanshi.com/media/logo.png 'self' data: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.google.com *.googleadservices.com *.googletagmanager.com *.rfksrv.com p.yotpo.com i.imgur.com region1.analytics.google.com *.online-metrix.net v2.zopim.com * *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com f.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleapis.com www.gstatic.com https://api.boldcommerce.com https://static.xx.fbcdn.net https://connect.facebook.net cdnjs.cloudflare.com https://cashier.boldcommerce.com/assets/experience/flow_sdk.js *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.meetanshi.com *.google.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com *.googleadservices.com *.tiktok.com *.klaviyo.com *.hotjar.com script.crazyegg.com seal.digicert.com imgs.signifyd.com region1.analytics.google.com fresnel.vimeocdn.com triggeredmail.appspot.com *.rfksrv.com cdn.scarabresearch.com *.cloudfront.net *.crazyegg.com *.bing.com static.zdassets.com v2.zopim.com seal.websecurity.norton.com *.yotpo.com bam.nr-data.net bam-cell.nr-data.net *.disquscdn.com platform.twitter.com cdn.userway.org z.moatads.com v1.addthisedge.com widget-mediator.zopim.com *.clarity.ms www.bluecore.com wickedreports.com widget.wickedreports.com globalshopex.com *.getattribution.net measure.getattribution.net *.wickedreports.com track.wickedreports.com snap.licdn.com *.zendesk.com *.smooch.io *.cdn-btsg.com/ imgs.cdn-btsg.com px.ads.linkedin.com *.gstatic.com landofcoder.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://static.klaviyo.com https://accounts.google.com/gsi/style https://fonts.googleapis.com/css maxcdn.bootstrapcdn.com *.klaviyo.com netdna.bootstrapcdn.com f.vimeocdn.com c.disquscdn.com/ *.cloudfront.net *.yotpo.com unpkg.com rfk-staticfiles-prod.s3.amazonaws.com *.googletagmanager.com cdn.userway.org *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleapis.com https://api.boldcommerce.com https://api.staging.boldcommerce.com https://cashier.boldcommerce.com https://graph.facebook.com https://secure.boldcommerce.com https://secure.staging.boldcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.meetanshi.com https://accounts.google.com/gsi/status https://accounts.google.com/gsi/log https://oauth2.googleapis.com/tokeninfo *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.clarity.ms *.tiktok.com *.klaviyo.com *.hotjar.com *.hotjar.io wss://*.hotjar.com syndication.twitter.com google.com www.google.com 21vod-adaptive.akamaized.net player-telemetry.vimeo.com fiddler.brontops.com recommender.scarabresearch.com ekr.zdassets.com wss://widget-mediator.zopim.com imgs.signifyd.com bam.nr-data.net *.crazyegg.com *.yotpo.com *.disqus.com *.bing.com region1.analytics.google.com *.doubleclick.net *.paypal.com cdn.userway.org api.userway.org bt.signifyd.com bt.signifyd.com:11103 bam-cell.nr-data.net wickedreports.com widget.wickedreports.com *.getattribution.net measure.getattribution.net *.wickedreports.com track.wickedreports.com *.zendesk.com wss://*.zendesk.com *.smooch.io cdn.linkedin.oribi.io imgs.cdn-btsg.com px.ads.linkedin.com t.elasticsuite.io landofcoder.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.blauer.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.scite.ai https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com www.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.doubleclick.net *.facebook.com *.googletagmanager.com www.google.ae www.google.at www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.za www.google.com.ar www.google.com.au www.google.com.br www.google.com.co www.google.com.ec www.google.com.hk www.google.com.ly www.google.com.mx www.google.com.my www.google.com.ng www.google.com.pa www.google.com.pe www.google.com.pk www.google.com.pr www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ge www.google.gr www.google.hr www.google.ht www.google.hu www.google.ie www.google.it www.google.kz www.google.lt www.google.lv www.google.nl www.google.pl www.google.pt www.google.se www.google.si www.google.sk https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.google.com www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.doubleclick.net *.facebook.net *.googletagmanager.com *.hotjar.com *.zdassets.com https://browser.sentry-cdn.com *.kaptcha.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.cloudflare.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.typeform.com www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://chimpstatic.com gtm.narescue.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com downloads.mailchimp.com *.fonts.net *.googletagmanager.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.tagmanager.google.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.bamboohr.com *.doubleclick.net *.facebook.com *.hotjar.com *.hotjar.io *.zdassets.com www.google.ae www.google.at www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.za www.google.com.au www.google.com.br www.google.com.co www.google.com.mx www.google.com.my www.google.com.pk www.google.com.pr www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.cz www.google.de www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ge www.google.gr www.google.ht www.google.it www.google.lv www.google.nl www.google.pl www.google.pt www.google.se www.google.sk https://*.ingest.sentry.io *.kaptcha.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.run.app *.typeform.com https://imgs.signifyd.com gtm.narescue.com https: 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://2a23ab1b-97ea-4c5d-acc0-9b094bdc7879.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; default-src 'self' https://*.concern.net https://*.concern.org.uk https://*.systemseed.host https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://*.gstatic.com https://*.cookiebot.com https://*.stripe.com https://*.sociablekit.com https://*.rollbar.com https://*.raisely.com https://*.fundraiseup.com https://*.paypal.com https://*.paypalobjects.com https://*.autoaddress.ie https://maxcdn.bootstrapcdn.com 'nonce-ss2mwTTuxMERKMXqm7VwXg==' 'strict-dynamic' https:; connect-src 'self' https: wss:; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data:; font-src 'self' https: data:; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; form-action 'self' https://*.facebook.com; frame-src 'self' https:; report-uri https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub91b897b2a14e748cb0371152f548c32c&dd-evp-origin=content-security-policy&ddsource=csp-report-IE-v5 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.theflowspace.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.bootstrapcdn.com *.hsappstatic.net *.ivaws.com *.ravecapture.com s3.amazonaws.com trustspot-app-assets.s3.amazonaws.com trustspot.io https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com fonts.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.attn.tv *.bing.com *.doubleclick.net *.facebook.com *.googletagmanager.com *.livechatinc.com *.opendns.com *.paypalobjects.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.authorize.net https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com https://aheadworks.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.attentivemobile.com *.attn.tv *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googleadservices.com *.googletagmanager.com *.imgix.net *.ivaws.com *.paypalobjects.com *.ravecapture.com *.trustspot.io *.ytimg.com ravecapture-app-assets.s3.amazonaws.com s3.amazonaws.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.li www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mk www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tn https://connect.facebook.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://img.youtube.com guarantee-cdn.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com *.affirm.com *.affirm.ca https://cdn.attn.tv https://events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net *.addthis.com *.algolia.net *.algolianet.com *.attn.tv *.authorize.net *.bing.com *.doubleclick.net *.facebook.net *.fullstory.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.gstatic.com *.klaviyo.com *.livechatinc.com *.paypal.com *.ravecapture.com trustspot.io https://hogworkz.com https://static-tracking.klaviyo.com https://app.ravecapture.com https://hogworkz.attn.tv https://js-agent.newrelic.com https://bam.nr-data.net widget.freshworks.com m2epro.freshdesk.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.cloudflare.com guarantee-cdn.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net *.bootstrapcdn.com *.gstatic.com *.klaviyo.com *.ravecapture.com s3.amazonaws.com trustspot.io widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.googleapis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com *.affirm.com *.affirm.ca *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.attentivemobile.com *.authorize.net *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.googleadservices.com *.googletagmanager.com *.imgix.net *.klaviyo.com *.livechatinc.com *.ravecapture.com ravecapture-app-assets.s3.amazonaws.com trustspot.io www.google.ae www.google.al www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.vi www.google.co.za www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gh www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mk www.google.mn www.google.mu www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn https://events.attentivemobile.com https://bam.nr-data.net https://hogworkz.com widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com 'unsafe-inline'; img-src 'self' https://images.medaviebc.ca https://images.protectionplusbenefits.ca https://dev.visualwebsiteoptimizer.com https://r2.visualwebsiteoptimizer.com https://forms.hsforms.com https://track.hubspot.com https://media.msg.dotomi.com https://docs.medaviebc.ca https://docs.protectionplusbenefits.ca https://login.dotomi.com https://perf-na1.hsforms.com https://www.google.com https://www.google.ca https://px.ads.linkedin.com https://www.facebook.com https://www.google-analytics.com https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://i.vimeocdn.com https://maps.gstatic.com https://raw.githubusercontent.com https://maps.googleapis.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ca https://googleads.g.doubleclick.net https://google.com googleads.g.doubleclick.net www.google.com google.com https://ad.doubleclick.net https://ade.googlesyndication.com https://r3.visualwebsiteoptimizer.com https://qc.croixbleue.ca https://sdk.privacy-center.org https://r1.visualwebsiteoptimizer.com https://pluginicons.craft-cdn.com https://s3.us-east-1.amazonaws.com https://www.linkedin.com https://pluginscreenshots.craft-cdn.com https://s3.ca-central-1.amazonaws.com https://forms-na1.hsforms.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://pro.fontawesome.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://pro.fontawesome.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://tagmanager.google.com https://fonts.googleapis.com https://cdn.appdynamics.com https://js.hs-scripts.com https://static.hotjar.com https://dev.visualwebsiteoptimizer.com https://js.stripe.com https://code.jquery.com https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com https://js.hsbanner.com https://js.hscollectedforms.net https://js.hs-analytics.net https://js.hs-banner.com https://js.hubspot.com https://js.hsleadflows.net https://js.hsadspixel.net https://script.hotjar.com https://s.pinimg.com https://js.adsrvr.org https://www.google-analytics.com https://extend.vimeocdn.com https://googleads.g.doubleclick.net https://ct.pinterest.com https://connect.facebook.net https://snap.licdn.com https://www.vimeo.com https://vimeo.com https://maps.googleapis.com https://maps.googleapis.com https://cdn.datatables.net https://*.googletagmanager.com https://www.googleadservices.com www.googleadservices.com www.google.com google.com www.googletagmanager.com https://www.google.com www.googleadservices.com googleads.g.doubleclick.net https://f.vimeocdn.com https://sdk.privacy-center.org https://api.privacy-center.org https://urldefense.com https://js.hsforms.net blob:; connect-src 'self' https://dev.visualwebsiteoptimizer.com https://www.google-analytics.com https://pdx-col.eum-appdynamics.com https://r2.visualwebsiteoptimizer.com https://forms.hscollectedforms.net https://api.hubapi.com https://cta-service-cms2.hubspot.com https://stats.g.doubleclick.net https://ct.pinterest.com https://forms.hubspot.com https://px.ads.linkedin.com https://resource-navigator-mbc.herokuapp.com https://google.com https://maps.googleapis.com https://api.medavie.bluecross.ca https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ca https://r3.visualwebsiteoptimizer.com https://pagead2.googlesyndication.com https://api.privacy-center.org https://r1.visualwebsiteoptimizer.com https://feed-proxy.craftcms.com https://api.craftcms.com https://forms.hsforms.com; frame-src 'self' https://*.medaviebc.ca https://js.stripe.com https://td.doubleclick.net https://insight.adsrvr.org https://ct.pinterest.com https://player.vimeo.com https://www.googletagmanager.com https://bid.g.doubleclick.net bid.g.doubleclick.net td.doubleclick.net https://match.adsrvr.org; object-src 'none'; report-uri https://staging.medaviebc.ca/csp-report-endpoint.php 1 connect-src *.bundesregierung.de analytics.bundesregierung.de 'self' https://hls-hd.myrasec.de ; style-src *.bundesregierung.de 'self' 'unsafe-inline' ; script-src *.bundesregierung.de 'self' ; script-src-elem 'self' *.bundesregierung.de 'nonce-kBN33dq0KPPPBpJ4uaihQoyjoaZyCY2wV7BI4bXDCQrzPGQJHao5yyyD0aubDDsqvAXfycNJBqQGQCWMcEYrf488vod8irNXJ5GK5JxFU2bOGmPM4dtU2AxLgnm+ZT9SByjIzZ9h1egJ8NPG8I3dXxC2N3eT1yHOXcFwx2t629Y=' ; frame-src *.bundesregierung.de 'self' ; media-src *.bundesregierung.de 'self' http://video.bundesregierung.de https://zdf-hls-18.akamaized.net ; frame-ancestors *.bundesregierung.de 'self' ; img-src 'self' *.bundesregierung.de https://*.tile.openstreetmap.de data: ; default-src *.bundesregierung.de 'self' ; font-src *.bundesregierung.de 'self' ; report-uri https://www.bundeskanzler.de/service/csp-report ; 1 default-src 'self'; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: data:; style-src 'self' https: data:; connect-src 'self' https: data: wss:; frame-src https: 'self' 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net https://widgets.trustedshops.com integrations.etrusted.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://seo.mageplaza.com www.facebook.com *.copernica.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com https://www.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://*.dpdconnect.nl *.dpdconnect.nl service2.loyaltyinabox.com *.pinterest.com www.facebook.com www.youtube.com view.publitas.com www.google.com www.google.nl www.google.de *.google.com maps.google.com chat.babypark.nl *.doubleclick.net td.doubleclick.net googleads.g.doubleclick.net widget.trustpilot.com *.cookiebot.com *.cookiebot.eu chatwidget-prod.web.app www.googletagmanager.com sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl folders.baby-dump.nl platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.klevu.com *.ksearchnet.com www.babypark.nl www.babypark.de www.babydeals.be dehoevebuitenleven.nl m2.babypark.mavendev.com m2.babypark-de.mavendev.com www.ikenik.nl m2.ikenik.mavendev.com m2.babydump.mavendev.com m2.babydump-de.mavendev.com www.google.com www.google.nl www.google.de www.google.com.ua www.facebook.com ct.pinterest.com www.googletagmanager.com www.zenaps.com www.awin1.com static.zdassets.com *.bing.com *.bing.net www.thuiswinkel.org i.ytimg.com img.youtube.com blob: lantern.roeye.com *.clarity.ms *.cookiebot.com *.cookiebot.eu integrations.etrusted.com stats.g.doubleclick.net sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: maps.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://*.dpdconnect.nl js.klevu.com *.ksearchnet.com *.avada.io www.googletagmanager.com checkout.buckaroo.nl *.clarity.ms lantern.roeyecdn.com widgets.trustedshops.com web-sdk.smartlook.com www.dwin1.com s.pinimg.com connect.facebook.net static.buckaroo.nl view.publitas.com api.360productviewer.com googleads.g.doubleclick.net bat.bing.com bat.bing.net static.zdassets.com js-agent.newrelic.com *.livechatinc.com bam.eu01.nr-data.net chat.babypark.nl widget.trustpilot.com *.pinterest.com *.hotjar.com *.hotjar.io *.cookiebot.com *.cookiebot.eu integrations.etrusted.com chatwidget-prod.web.app twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com *.gstatic.com maps.googleapis.com https://widgets.trustedshops.com *.yotpo.com sst.baby-dump.nl https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net checkout.buckaroo.nl integrations.etrusted.com chatwidget-css.web.app maxcdn.bootstrapcdn.com unsafe-inline *.googleapis.com *.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com integrations.etrusted.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.clarity.ms *.pinterest.com *.doubleclick.net stats.g.doubleclick.net googleads.g.doubleclick.net manager.eu.smartlook.cloud ekr.zdassets.com wss://widget-mediator.zopim.com api.360productviewer.com www.facebook.com livechat.fabulor.eu bam.eu01.nr-data.net region1.analytics.google.com *.google.com *.hotjar.com *.hotjar.io analytics.google.com bat.bing.com bat.bing.net *.cookiebot.com *.cookiebot.eu *.copernica.com integrations.etrusted.com api.ipify.org www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.yotpo.com sst.baby-dump.nl https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com https://maps.googleapis.com https://gateway.moneris.com https://gatewayt.moneris.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.bounceexchange.com *.google-analytics.com *.gstatic.com likeshop.me *.global-e.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.nosto.com *.nos.to *.bounceexchange.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca *.authorize.net *.nosto.com *.nos.to www.xtento.com *.facebook.com insight.adsrvr.org match.adsrvr.org *.signifyd.com *.online-metrix.net *.doubleclick.net *.cookiebot.com *.bounceexchange.com *.office365.com *.google.com *.google.lv *.bglobale.com *.global-e.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ store.paradoxlabs.com *.nosto.com *.nos.to www.xtento.com cdn.xtento.com *.bounceexchange.com *.bouncex.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.googleapis.com *.facebook.com connect.facebook.net www.google.lv *.bing.com *.lafayette148ny.com *.signifyd.com *.online-metrix.net *.postcodeanywhere.co.uk *.doubleclick.net heapanalytics.com *.heapanalytics.com *.bizrate.com *.dashhudson.com likeshop.me *.atdmt.com *.cdnwidget.com *.bglobale.com *.global-e.com *.clarity.ms *.cloudfront.net *.cookiebot.com *.rakuten.com *.linksynergy.com *.xg4ken.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net sandbox-assets.secure.checkout.visa.com *.nosto.com *.nos.to www.xtento.com cdn.xtento.com *.googletagmanager.com www.google.com www.google.lv www.gstatic.com *.bing.com *.upsellit.com connect.facebook.net *.sociomantic.com js.adsrvr.org *.algolianet.com *.algolia.net *.signifyd.com *.pcapredict.com *.addressy.com *.bizrate.com *.googleapis.com *.heapanalytics.com *.zdassets.com tag.wknd.ai *.bounceexchange.com *.dashhudson.com *.luckyorange.com *.cookiebot.com *.securedvisit.com *.pingdom.net *.cloudfront.net *.newrelic.com *.nr-data.net klear.com *.mczbf.com *.bglobale.com *.global-e.com *.clarity.ms cdn.noibu.com *.salesforce.com api.smooch.io *.online-metrix.net *.fbot.me *.rakuten.com *.linksynergy.com *.xg4ken.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.nosto.com *.nos.to *.bounceexchange.com *.googleapis.com *.addressy.com *.bizrate.com *.bglobale.com *.global-e.com *.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.nosto.com *.nos.to *.signifyd.com *.signifyd.com:* *.addressy.com *.bing.com *.bounceexchange.com *.bouncex.net *.zdassets.com *.zendesk.com *.zopim.com *.doubleclick.net *.google-analytics.com *.googleapis.com likeshop.me *.heapanalytics.com wss: *.luckyorange.net *.cookiebot.com *.cdnbasket.net *.cdnwidget.com *.pingdom.net *.nr-data.net *.facebook.com klear.com *.mczbf.com *.sjwoe.com *.clarity.ms input.noibu.com cdn.noibu.com www.google.com *.analytics.google.com *.salesforce.com *.fbot.me https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.bounceexchange.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' feedback-eu1.hubapi.com feedback.hubapi.com *.hubspotfeedback.com *.hs-scripts.com *.hsforms.com *.hsforms.net *.hsleadflows.net *.hscollectedforms.net *.hubspot.net *.hs-banner.com *.usemessages.com *.hsadspixel.net *.hs-analytics.net js.hscta.net js-eu1.hscta.net *.hubspot.com static.hsappstatic.net 'strict-dynamic' 'nonce-4AUNV+m69+gqoW6OsD8QPQ=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://static.hsappstatic.net; font-src 'self' *.hubspotusercontent-eu1.net; img-src 'self' data: 'unsafe-inline' *.chemaxon.com *.googletagmanager.com *.s3.amazonaws.com t.co *.twitter.com *.linkedin.com *.google.hu *.google.com *.hsappstatic.net *.facebook.com *.hsforms.com *.hsforms.net cdn2.hubspot.net *.hubspot.net no-cache.hubspot.com js.hscta.net js-eu1.hscta.net *.hubspot.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net; connect-src 'self' *.linkedin.com wss://ws.hotjar.com *.hotjar.com *.hotjar.io googleads.g.doubleclick.net *.google.com *.google-analytics.com chemaxon.matomo.cloud *.hubapi.com *.hsforms.com js.hscta.net js-eu1.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net; frame-src https://chemaxon.com https://www.youtube.com https://td.doubleclick.net/ *.hubspot.com *.hs-sites.com *.hs-sites-eu1.com *.hubspot.net play.hubspotvideo.com play-eu1.hubspotvideo.com *.hsforms.net *.hsforms.com; object-src 'none'; base-uri 'self'; form-action 'self' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.google.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.googleapis.com blueskytechmage.com mageblueskytech.com placehold.jp ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.avada.io *.shopify.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://d3faxe7oklbtyz.cloudfront.net downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com js.mollie.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com https://maps.googleapis.com *.disqus.com js.mollie.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://app.zinrelo.com app.zinrelo.com https://cdn.zinrelo.com/js/all.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://maps.googleapis.com https://player.vimeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.feedbackcompany.com *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.newrelic.com www.xtento.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.feedbackcompany.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.feedbackcompany.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.feedbackcompany.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://d088f4f9-ddea-4faf-b7bc-b7ce45ac64e7.sansec.watch/; report-to report-endpoint; 1 default-src 'none'; child-src 'self'; connect-src 'self'; font-src 'self' https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/; frame-src 'self'; img-src 'self' data:; script-src-elem 'self' 'unsafe-inline' 'nonce-edd4936d-db98-4e72-a97d-60f2c3de15a9' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-edd4936d-db98-4e72-a97d-60f2c3de15a9' ; style-src-elem 'self' 'unsafe-inline' 'nonce-edd4936d-db98-4e72-a97d-60f2c3de15a9' ; style-src 'self' 'unsafe-inline' 'nonce-edd4936d-db98-4e72-a97d-60f2c3de15a9' ; report-to stott-security-endpoint; 1 font-src *.fontawesome.com fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.videoly.net *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://a.klaviyo.com *.listrakbi.com maps.gstatic.com maps.googleapis.com *.ggpht *.ytimg.com *.wistia.com *.wistia.net store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.listrakbi.com https://static-tracking.klaviyo.com https://ipinfo.io 'unsafe-inline' maps.googleapis.com *.videoly.co *.youtube-nocookie.com *.ytimg.com *.wistia.com *.wistia.net *.videoly.net *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.listrakbi.com *.fontawesome.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://fast.a.klaviyo.com https://a.klaviyo.com https://ipinfo.io maps.googleapis.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.videoly.co *.youtube-nocookie.com *.youtube.com *.ytimg.com *.wistia.com *.wistia.net *.videoly.net *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.criteo.com *.google.fr googleads.g.doubleclick.net *.googletagmanager.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.facebook.com *.metaffiliation.com *.rubiconproject.com sync.outbrain.com sync-t1.taboola.com rtb-csync.smartadserver.com eb2.3lift.com ad.360yield.com simage2.pubmatic.com r.casalemedia.com criteo-sync.teads.tv contextual.media.net cm.adform.net visitor.omnitagjs.com match.sharethrough.com matching.ivitrack.com ads.stickyadstv.com cdn.stickyadstv.com exchange.mediavine.com s.ad.smaato.net cm.g.doubleclick.net ads.yahoo.com *.analytics.yahoo.com secure.adnxs.com ib.adnxs.com c.bing.com e1.emxdgt.com public-prod-dspcookiematching.dmxleo.com i.liadm.com i6.liadm.com criteo-partners.tremorhub.com gum.criteo.com dis.criteo.com x.bidswitch.net ad.yieldlab.net beacon.krxd.net s.thebrighttag.com *.google.com *.google.fr openstreetmap.org *.avis-verifies.com *.netreviews.eu *.skeepers.io sync-criteo.ads.yieldmo.com id5-sync.com *.googletagmanager.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net maps.googleapis.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.facebook.net *.criteo.com *.criteo.net *.metaffiliation.com *.social-media-system.com *.cartsguru.io *.google.com *.gstatic.com *.avis-verifies.com *.matomo.cloud *.jquery.com *.cloudflare.com *.googletagmanager.com unpkg.com *.unpkg.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net maps.gstatic.com fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.googleapis.com *.cloudflare.com *.googletagmanager.com maxcdn.bootstrapcdn.com fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.facebook.com integration.carts.guru *.google-analytics.com *.analytics.google.com *.matomo.cloud *.google.com *.doubleclick.net *.googlesyndication.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src integration.carts.guru cdn.cartsguru.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: fonts.googleapis.com *.klevu.com *.ksearchnet.com dhv2ziothpgrr.cloudfront.net *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://static.zdassets.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * bid.g.doubleclick.net zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com dhv2ziothpgrr.cloudfront.net t.zip.co static.zipmoney.com.au static.zip.co www.xtento.com cdn.xtento.com *.yotpo.com *.inside.chat *.au.inside.chat www7.au.inside.chat *.powerfront.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.googletagmanager.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com js.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com googleads.g.doubleclick.net analytics.google.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://static.zdassets.com static.zipmoney.com.au static.zip.co zip.co www.xtento.com cdn.xtento.com *.yotpo.com *.inside.chat *.au.inside.chat www7.au.inside.chat *.powerfront.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net *.yotpo.com *.googleapis.com *.inside.chat *.au.inside.chat www7.au.inside.chat *.powerfront.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com *.inside.chat *.au.inside.chat www7.au.inside.chat *.powerfront.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.au.inside.chat *.inside.chat *.powerfront.com www.googleadservices.com analytics.google.com www.googletagmanager.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://ekr.zdassets.com https://tedscameras.zendesk.com https://widget-mediator.zopim.com wss://widget-mediator.zopim.com *.yotpo.com www7.au.inside.chat 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.inside.chat *.au.inside.chat www7.au.inside.chat *.powerfront.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' cdn2.hubspot.net *.hubspot.com *.hubspotusercontent10.net js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hs-banner.net *.hsforms.net *.hsforms.com static.hsappstatic.net js.hubspotfeedback.com feedback.hubapi.com js.usemessages.com *.vidyard.com cdnjs.cloudflare.com cdnjs.cloudflare.com 10921146.fls.doubleclick.net plausible.io *.hotjar.com *.hotjar.io *.qualified.com bttrack.com *.googletagmanager.com *.force.com *.thycotic.com *.centrify.com *.bidr.io *.rlcdn.cm t.co *.twitter.com burly.io *.clickagy.com *.doubleclck.net *.zoominfo.com lltrck.com facebook.com *.facebook.net *.redditstatic.com *.linkedin.com *.licdn.com *.demandbase.com *.zoominfo.com 'strict-dynamic' 'nonce-RqHPHt5ao81jx3gB+cDQNw==' 1 default-src * data: ; script-src * 'unsafe-inline' 'unsafe-eval' cdn.matomo.cloud diateam.matomo.cloud; style-src * 'unsafe-inline' data: ; frame-ancestors 'self' ; frame-src 'self' www.google.com platform.twitter.com syndication.twitter.com www.youtube.com; block-all-mixed-content; report-uri https://www.diateam.net/.csp/report 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleapis.com *.gstatic.com https://*.hotjar.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.certcapture.com https://config.gorgias.io https://assets.gorgias.chat https://imgsct.cookiebot.com magefan.com cm.magefan.com https://img.youtube.com *.gstatic.com *.facebook.com *.reddit.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.disqus.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.certcapture.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com fonts.googleapis.com fonts.gstatic.com https://*.hotjar.com 'unsafe-inline' https://config.gorgias.chat https://assets.gorgias.chat https://config.gorgias.io https://us-east1-898b.gorgias.chat https://storage.gorgias.chat https://api.gorgias.work cdn.jsdelivr.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://pagead2.googlesyndication.com unsafe-inline https://js-agent.newrelic.com https://*.amplitude.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net *.disqus.com https://cdn.jsdelivr.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.stripe.network *.stripecdn.com *.amazon.com *.googleapis.com *.gstatic.com https://*.hotjar.com 'unsafe-inline' cdn.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com https://cdn.jsdelivr.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.certcapture.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.googleapis.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://config.gorgias.chat https://assets.gorgias.chat https://config.gorgias.io https://us-east1-898b.gorgias.chat wss://us-east1-898b.gorgias.chat https://storage.gorgias.chat https://api.gorgias.work https://consentcdn.cookiebot.com https://pagead2.googlesyndication.com https://*.amplitude.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src assets.gorgias.chat 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com *.amazonaws.com *.feefo.com *.bglobale.com *.global-e.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action *.twitter.com *.facebook.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline' *.cardinalcommerce.com *.paypal.com; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarnaservices.com *.braintreegateway.com *.authorize.net *.cloudfront.net *.klarna.com *.bglobale.com *.global-e.com www.googletagmanager.com js.mollie.com assets.braintreegateway.com pay.google.com * https://www.google.com 'self' 'unsafe-inline' *.cardinalcommerce.com *.paypal.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net www.paypalobjects.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.awin1.com *.zenaps.com *.cloudflare.com *.feefo.com *.bing.com *.clarity.ms *.postcodeanywhere.co.uk *.cookiebot.com *.roeye.com https://www.google.com.vn https://www.google.com https://googleads.g.doubleclick.net *.facebook.net connect.facebook.net *.dycdn.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.bglobale.com *.global-e.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net https://www.mollie.com assets.braintreegateway.com data: 'self' 'unsafe-inline' *.cardinalcommerce.com *.paypal.com *.cloudfront.net *.klaviyo.com; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net includestest.ccdc02.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com *.cloudflare.com *.twitter.com *.google.com *.feefo.com *.postcodeanywhere.co.uk *.cloudfront.net *.googlecommerce.com *.zdassets.com *.trackedweb.net *.clarity.ms *.pcapredict.com *.bing.com https://*.zopim.com *.hub-box.com *.roeyecdn.com http://*.postcodeanywhere.co.uk *.cloudflareinsights.com *.cookiebot.com *.cookie-script.com *.luigisbox.com wss://*.freshrelevance.com am.freshrelevance.com *.freshrelevance.com *.jsdelivr.net connect.facebook.net *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net *.klarna.com *.klarnacdn.net x.klarnacdn.net *.bglobale.com *.global-e.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.klarnaservices.com *.avada.io *.gstatic.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://apis.google.com 'self' 'unsafe-inline' 'unsafe-eval' *.cardinalcommerce.com *.paypal.com *.klaviyo.com; style-src *.adobe.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.postcodeanywhere.co.uk *.klarnacdn.net *.klaviyo.com *.feefo.com register.feefo.com *.luigisbox.com *.jsdelivr.net *.bglobale.com *.global-e.com *.fontawesome.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.clarity.ms 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.paypalobjects.com https://maps.googleapis.com https://player.vimeo.com https://the.sciencebehindecommerce.com *.dycdn.net wss://*.dycdn.net *.zdassets.com *.feefo.com *.clarity.ms *.bing.com *.zendesk.com wss://*.zopim.com *.trackedweb.net *.postcodeanywhere.co.uk *.googlesyndication.com pagead2.googlesyndication.com *.luigisbox.com wss://*.freshrelevance.com am.freshrelevance.com *.freshrelevance.com *.jsdelivr.net *.cookiebot.com *.facebook.com *.facebook.net wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net api.addressy.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com google.com 'self' 'unsafe-inline' *.cardinalcommerce.com *.paypal.com *.klaviyo.com; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://db38adbe-f042-4c70-8ba5-48c5a02c8abc.sansec.watch/; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.fontawesome.com *.sugarfreeshops.com https://analytics.ahrefs.com/ *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.cardlink.gr *.alphaecommerce.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.google.com *.doubleclick.net *.klarna.com *.sugarfreeshops.com *.grxchange.gr *.skroutz.gr skroutz.gr *.criteo.com criteo.com *.criteo.net criteo.net *.cookiebot.com cookiebot.com *.boxnow.gr boxnow.gr https://analytics.ahrefs.com/ *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.sugarfreeshops.com *.trustmark.gr trustmark.gr *.contactpigeon.com contactpigeon.com *.dmxleo.com dmxleo.com *.bidswitch.net bidswitch.net *.adnxs.com adnxs.com *.smartadserver.com smartadserver.com *.taboola.com taboola.com *.sharethrough.com sharethrough.com *.omnitagjs.com omnitagjs.com *.casalemedia.com casalemedia.com *.criteo.com criteo.com *.1rx.io 1rx.io *.id5-sync.com id5-sync.com *.360yield.com 360yield.com *.unrulymedia.com unrulymedia.com *.cookiebot.com cookiebot.com google.gr *.google.gr https://analytics.ahrefs.com/ *.adman.gr *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io 'unsafe-inline' data: *.sugarfreeshops.com *.weezmo.com *.skroutz.gr *.linkwi.se *.addsauce.com snapppt.com *.adman.gr *.trustmark.gr trustmark.gr *.criteo.com criteo.com *.criteo.net criteo.net skroutz.gr *.contactpigeon.com contactpigeon.com *.cookiebot.com cookiebot.com tiktok.com *.tiktok.com eyefitu.com *.eyefitu.com azure.com *.azure.com https://analytics.ahrefs.com/ *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.klarnacdn.net *.fontawesome.com *.sugarfreeshops.com *.contactpigeon.com contactpigeon.com https://analytics.ahrefs.com/ *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.sugarfreeshops.com https://analytics.ahrefs.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net *.google.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io *.sugarfreeshops.com *.adman.gr *.contactpigeon.com contactpigeon.com *.criteo.com criteo.com *.skroutz.gr skroutz.gr tiktok.com *.tiktok.com *.cookiebot.com cookiebot.com eyefitu.com *.eyefitu.com azure.com *.azure.com visualstudio.com *.visualstudio.com https://analytics.ahrefs.com/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com contactpigeon.com https://analytics.ahrefs.com/ 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.googleapis.com *.mauboussin.fr data: * *.fontawesome.com maxcdn.bootstrapcdn.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.google.com *.mauboussin.fr * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.getalma.eu *.gstatic.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ api-qa.payplug.com secure-qa.payplug.com *.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com *.googleapis.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://secure-magenta.dalenys.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com cdn.jsdelivr.net *.googleapis.com *.gstatic.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com https://cdn-qa.payplug.com https://secure-magenta.dalenys.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.googleapis.com/ *.mauboussin.fr * *.fontawesome.com maxcdn.bootstrapcdn.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.googleapis.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.gstatic.com *.mauboussin.fr *.criteo.net *.pinterest.com *.googletagmanager.com *.snapppt.com *.360yield.com * 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: fonts.gstatic.com *.cloudmaestro.com *.punchout2go.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net *.punchout2go.com 'self' data: *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.punchout2go.com 'self' data: 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.certcapture.com *.doubleclick.net *.facebook.com events.blackthorn.io *.punchout2go.com *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.gstatic.com *.googleapis.com *.certcapture.com maps.googleapis.com www.googletagmanager.com www.google.com *.cloudmaestro.com *.doubleclick.net *.scene7.com *.bakerdist.com bam.nr-data.net *.punchout2go.com https://firebasestorage.googleapis.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com cdnjs.cloudflare.com cdn.jsdelivr.net static.cloudflareinsights.com unpkg.com *.onetrust.com cdn.cookielaw.org maps.googleapis.com *.punchout2go.com *.tradecentric.com cdn.polyfill.io *.cloudmaestro.com js-agent.newrelic.com bam.nr-data.net *.authorize.net *.bakerdist.com static.zdassets.com cdn.rudderlabs.com events.blackthorn.io *.avada.io *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com cdnjs.cloudflare.com *.cloudmaestro.com *.punchout2go.com *.tradecentric.com *.bakerdist.com *.fontawesome.com https://fonts.bunny.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src *.punchout2go.com *.tradecentric.com *.buyerquest.net bam.nr-data.net 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com *.googleapis.com *.certcapture.com *.bakerdist.com bam.nr-data.net *.authorize.net cdn.cookielaw.org *.scene7.com lkx760tcl7.execute-api.us-east-1.amazonaws.com www.facebook.com wss://widget-mediator.zopim.com static.cloudflareinsights.com bakerdist.zendesk.com ekr.zdassets.com bkuatdmbogssdi.dataplane.rudderstack.com bkprodukgnhabu.dataplane.rudderstack.com api.rudderstack.com geolocation.onetrust.com privacyportal.onetrust.com boltgw-uat.cardconnect.com:* boltgw.cardconnect.com:* *.punchout2go.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.girlfriendsfilms.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.girlfriendsfilms.com join.gammasecure.com; script-src 'self' *.girlfriendsfilms.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.girlfriendsfilms.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * checkout.postfinance.ch *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com checkout.postfinance.ch *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.postfinance.ch cdn.ampproject.org www.gstatic.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com www.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com cdn.ampproject.org www.googleapis.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; object-src 'none'; script-src 'strict-dynamic' 'report-sample' https: 'unsafe-inline' 'nonce-5a2e9dad32c3b4c5bb8cd2b249e03575'; report-uri https://o109800.ingest.sentry.io/api/1323222/security/?sentry_key=23c48c605cea4da7b42d295927d29b7a 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.hoffmanaudiofhartford.com/api/csp-report; report-to csp-endpoint 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-ePsVUaHOyH13Pw4InRjlhiYNG' 'strict-dynamic' 'report-sample'; report-uri https://onehack.us/csp_reports; frame-ancestors 'self'; manifest-src 'self' 1 font-src maxcdn.bootstrapcdn.com https://www.gstatic.com https://fonts.gstatic.com http://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com *.sagepay.com *.opayo.eu.elavon.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com https://fonts.bunny.net www.poundwholesale.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.sagepay.com *.opayo.eu.elavon.com *.stripe.com *.stripe.network *.google.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.poundwholesale.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.poundwholesale.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ sibautomation.com *.sagepay.com *.opayo.eu.elavon.com *.salesfire.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com account.fetchify.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com www.poundwholesale.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.godaddy.com https://www.facebook.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com *.salesfire.co.uk *.stripe.com *.stripe.network *.google.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.poundwholesale.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net https://cdn.doofinder.com https://sibautomation.com https://cdn.ywxi.net *.godaddy.com connect.facebook.net https://cdnjs.cloudflare.com *.vimeo.com https://maps.google.com *.sagepay.com *.opayo.eu.elavon.com *.salesfire.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.gstatic.com www.poundwholesale.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com https://stackpath.bootstrapcdn.com https://maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.sagepay.com *.opayo.eu.elavon.com *.salesfire.co.uk *.typekit.net fonts.googleapis.com *.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com cc-cdn.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com www.poundwholesale.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://www.gstatic.com https://fonts.gstatic.com http://cdnjs.cloudflare.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.poundwholesale.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com eu1-search.doofinder.com https://in-automate.sendinblue.com https://www.google-analytics.com *.amazonaws.com https://cdn.ywxi.net https://in.hotjar.com https://www.facebook.com https://cdnjs.cloudflare.com https://maps.google.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.salesfire.co.uk *.smartmetrics.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com www.poundwholesale.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.poundwholesale.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.poundwholesale.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-mTtCTNyjdDz45qJYa4nKzg==' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: fonts.googleapis.com *.stape.io *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cookiebot.com *.cookiebot.eu business.facebook.com libs.hipay.com *.hipay-tpp.com *.hipay.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.google.it *.cookiebot.com *.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com business.facebook.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com *.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cookiebot.com *.cookiebot.eu *.tiktok.com *.matomo.cloud *.paypal.com https://payments-sdk.live.commerce-payment-services.com chimpstatic.com downloads.mailchimp.com *.list-manage.com business.facebook.com cdn.lordicon.com js-agent.newrelic.com bam.nr-data.net *.hipay.com mpsnare.iesnare.com libs.hipay.com *.hipay-tpp.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.stape.io maps.googleapis.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com libs.hipay.com *.hipay.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com stats.g.doubleclick.net googleads.g.doubleclick.net *.google-analytics.com *.googlesyndication.com *.cookiebot.com *.cookiebot.eu *.analytics.tiktok.com *.stape.net business.facebook.com cdn.lordicon.com stage-data.hipay.com bam.nr-data.net *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.doubleclick.net *.stape.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com *.yotpo.com *.acsbapp.com https://script.hotjar.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com https://plumrocket.com *.hsforms.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com https://plumrocket.com *.weltpixel.com *.google.com/ *.hsforms.net *.nice-incontact.com *.doubleclick.net *.hsforms.com *.bing.com *.fullstory.com *.facebook.com *.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://images.unsplash.com *.cenpos.net *.cenpos.com https://www.magezon.com *.hsforms.com *.travers.com *.bing.com *.hubspot.com *.clarity.ms *.facebook.com *.yotpo.com *.cloudfront.net *.google.com *.google.co.in *.hubspotusercontent00.net *.fullstory.com *.acsbapp.com *.googletagmanager.com *.applicant-tracking.com *.linkedin.com *.hubspotusercontent-na1.net https://script.hotjar.com *.google-analytics.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com polyfill.io https://maps.googleapis.com *.cenpos.com *.cenpos.net *.google.com *.gstatic.com *.cardinalcommerce.com *.googletagmanager.com *.avada.io *.google.com/ *.pingdom.net *.hsforms.net *.hsforms.com *.yotpo.com *.luckyorange.com *.bing.com *.clarity.ms *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hsleadflows.net https://acsbapp.com/apps/app/dist/js/app.js *.nice-incontact.com *.facebook.net *.cloudfront.net *.doubleclick.net *.fullstory.com *.topgradinghire.com *.jquery.com *.applicant-tracking.com *.licdn.com *.lfeeder.com *.hscollectedforms.net *.hubspot.com https://static.hotjar.com https://script.hotjar.com *.google-analytics.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.cloudflare.com *.jsdelivr.net *.googleapis.com *.yotpo.com *.cloudfront.net *.bing.com *.google.com *.fullstory.com *.topgradinghire.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.algolia.net *.algolianet.com *.insights.algolia.io https://maps.googleapis.com https://player.vimeo.com insights.algolia.io https://get.geojs.io *.avada.io *.pingdom.net *.clarity.ms *.doubleclick.net *.luckyorange.net *.luckyorange.com wss://realtime.luckyorange.com *.acsbapp.com *.hubspot.com *.hubapi.com *.googleapis.com *.visitors.live wss://in.visitors.live/ *.yotpo.com *.facebook.com *.hsforms.com *.amazonaws.com *.bing.com *.google.com *.fullstory.com *.visitors.live/ajax *.visitors.live/server-time https://in.hotjar.com https://content.hotjar.io https://csmetrics.hotjar.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google-analytics.com *.googletagmanager.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: *.stamped.io maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.worldpay.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.com.ua *.google.co.uk *.meetanshi.com www.youtube.com *.livechatinc.com *.paypal.com pay.google.com *.braintreegateway.com *.kaptcha.com www.paypalobjects.com *.affirm.com www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.doubleclick.net *.meetanshi.com maps.googleapis.com maps.gstatic.com www.facebook.com www.gstatic.com *.cloudfront.net www.google.pl *.stamped.io *.paypal.com *.amazonaws.com *.userway.org verify.authorize.net scontent.cdninstagram.com *.affirm.com *.routeapp.io *.bing.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com f.vimeocdn.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net *.meetanshi.com maps.googleapis.com maps.gstatic.com connect.facebook.net www.google.com http://translate.google.com translate.googleapis.com www.gstatic.com includes.ccdc02.com static.zdassets.com cdn.inspectlet.com *.stamped.io *.livechatinc.com *.userway.org *.paypal.com pay.google.com www.klarnapayments.com *.affirm.com *.routeapp.io *.bing.com cdn.ampproject.org *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.googletagmanager.com *.stamped.io www.klarnapayments.com www.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.google.com *.meetanshi.com *.paypal.com *.authorize.net ekr.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com hn.inspectlet.com stamped.io *.braintree-api.com *.braintreegateway.com www.paypalobjects.com *.livechatinc.com *.userway.org graph.instagram.com *.affirm.com *.route.com *.bing.com cdn.ampproject.org *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' http://cdn.parsely.com http://maps.googleapis.com https://stats.wp.com/ https://www.google.com/ https://www.googletagmanager.com https://www.gstatic.com/ https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;; object-src 'self'; base-uri 'self'; connect-src 'self' https://maps.googleapis.com https://mapsresources-pa.googleapis.com https://www.google.com/; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://heyzine.com https://www.google.com https://player.vimeo.com/; img-src 'self' data: https://drive-thirdparty.googleusercontent.com https://maps.gstatic.com https://mapsresources-pa.googleapis.com; manifest-src 'self'; media-src 'self'; worker-src 'none' 1 default-src 'self' 'unsafe-inline' forms-na1.hsforms.com staticcontent.fxstreet.com https://www.youtube.com https://assets.app.lmax.com https://login-lmax.my.site.com https://img.youtube.com https://mtfclosingprices.lmax.com; font-src * data:; script-src 'unsafe-inline' 'unsafe-eval' *; frame-src 'self' forms-na1.hsforms.com staticcontent.fxstreet.com https://www.youtube.com https://assets.app.lmax.com https://login-lmax.my.site.com https://img.youtube.com https://mtfclosingprices.lmax.com; img-src 'self' forms-na1.hsforms.com staticcontent.fxstreet.com https://www.youtube.com https://assets.app.lmax.com https://login-lmax.my.site.com https://img.youtube.com https://mtfclosingprices.lmax.com data:; connect-src *; frame-ancestors 'self' forms-na1.hsforms.com staticcontent.fxstreet.com https://www.youtube.com https://assets.app.lmax.com https://login-lmax.my.site.com https://img.youtube.com https://mtfclosingprices.lmax.com; media-src 'self' forms-na1.hsforms.com staticcontent.fxstreet.com https://www.youtube.com https://assets.app.lmax.com https://login-lmax.my.site.com https://img.youtube.com https://mtfclosingprices.lmax.com data:; style-src-elem 'unsafe-inline' *; report-uri https://www.silicontrade.uk/wp-json/csp/v1/report; 1 font-src fonts.gstatic.com use.typekit.net data: *.hotjar.com github.com cdn.honey.io *.photoslurp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.redsys.es facebook.com *.adyen.com *.redsys.com *.pinterest.com sas.redsys.es *.facebook.com sas.redsys.com checkoutshopper-live.adyen.com checkoutshopper-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.google.com *.addthis.com *.kampyle.com facebook.com docs.google.com *.facebook.com *.pinterest.es *.pinterest.com service.force.com *.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com blob: *.w3.org *.bing.com c.bing.com *.hotjar.com *.paypal.com bat.bing.com *.clarity.ms *.google.fr facebook.com *.kampyle.com *.gstatic.com *.ladybird.nl *.google.com *.fbcdn.net *.cookiepro.com *.pinterest.com *.pronovias.com *.facebook.com *.google.es *.photoslurp.com *.googleapis.com *.sanpatrick.com *.nicolemilano.com *.cdninstagram.com instagram.com *.verawangbride.com *.whiteonebridal.com *.googletagmanager.com scontent.fmad7-1.fna.fbcdn.net click.s50.exacttarget.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com unpkg.com *.force.com bat.bing.com *.adyen.com *.pinimg.com *.google.com *.hotjar.com *.tiktok.com dropbox.com gstatic.com *.clarity.ms *.moatads.com *.addthis.com *.kampyle.com *.gstatic.com *.dropbox.com *.cookiepro.com *.facebook.net *.facebook.com facebook.net *.photoslurp.com *.googleapis.com *.salesforce.com *.addthisedge.com *.secure.force.com http://polyfill.io service.force.com bam.eu01.nr-data.net *.nicolemilano.com *.empathybroker.com x.empathy.co x.staging.empathy.co *.lightning.force.com analytics.tiktok.com *.googletagmanager.com googletagmanager.com *.salesforceliveagent.com static.lightning.force.com *.la3-c1cs-fra.salesforceliveagent.com d.la3-c1cs-fra.salesforceliveagent.com pronoviasgroup.my.salesforce.com *.pinterest.com player.vimeo.com *.criteo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.honey.io *.kampyle.com *.force.com *.photoslurp.com service.force.com *.nicolemilano.com gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net *.photoslurp.com player.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io wss: bat.bing.com *.force.com *.tiktok.com *.google.com *.hotjar.io *.clarity.ms *.vimeo.com d.clarity.ms h.clarity.ms *.kampyle.com *.hotjar.com google.com vc.hotjar.io ws7.hotjar.com *.instagram.com *.cookiepro.com *.pinterest.com *.amazonaws.com client.rum.us-east-1.amazonaws.com sts.eu-west-1.amazonaws.com ws16.hotjar.com ws20.hotjar.com ws22.hotjar.com ws23.hotjar.com ws33.hotjar.com ws34.hotjar.com *.facebook.com *.googleapis.com *.photoslurp.com *.secure.force.com bam.eu01.nr-data.net *.empathybroker.com x.empathy.co x.staging.empathy.co stats.g.doubleclick.net *.google-analytics.com api.empathybroker.com api.empathy.co api.staging.empathy.co *.cardinalcommerce.com api-staging.empathybroker.com pronoviasgroupcti.secure.force.com analytics.pangle-ads.com properties *.onetrust.com *.criteo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://cdn.checkout.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.twitter.com *.google.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.beautyamora.com cdn.beautyamora.com.au g-image.beautyamora.com cdn.beautyamora.co.uk *.google.com.hk *.pinterest.com c.clarity.ms c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com https://cdn.checkout.com *.klarnacdn.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk *.helpscout.net *.g.doubleclick.net *.pinimg.com *.pinterest.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.checkout.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com unsafe-inline cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk *.g.doubleclick.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.pdffiller.com pdffiller.com *.quora.com *.doubleclick.net *.bing.com *.bing.net *.yahoo.com *.yimg.com *.pinterest.com *.pinimg.com *.twitter.com *.ads-twitter.com *.licdn.com *.linkedin.com *.facebook.com *.facebook.net *.paypal.com *.paypalobjects.com *.checkout.com *.braintreegateway.com *.braintree-api.com *.stripe.com *.stripecdn.com *.stripe.network *.rocketgate.com *.mrkhub.com *.privacy-mgmt.com *.clarity.ms *.zoominfo.com *.smartlook.com *.trustpilot.com *.shopperapproved.com *.google.com google.com *.googletagmanager.com *.gstatic.com *.googleapis.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.upsellit.com *.capterra.com *.vimeocdn.com *.tiktok.com *.hcaptcha.com *.cookiebot.com api.imotech.video *.cdn-apple.com *.dropbox.com *.live.net *.go-mpulse.net *.jquery.com *.cloudflare.com *.taboola.com; style-src 'self' 'unsafe-inline' *.pdffiller.com pdffiller.com *.google.com google.com *.googleapis.com *.gstatic.com; frame-src 'self' *.pdffiller.com pdffiller.com *.signnow.com signnow.com *.airslate.com airslate.com *.uslegal.com uslegal.com *.uslegalforms.com uslegalforms.com *.airslate-pmnt-hub.com *.braintreegateway.com *.paypal.com *.checkout.com *.stripe.com *.cdn-apple.com *.google.com google.com *.googletagmanager.com *.youtube.com *.vimeo.com *.facebook.com *.trustpilot.com *.privacy-mgmt.com *.pinterest.com api.imotech.video *.cookiebot.com; frame-ancestors 'self' *.pdffiller.com pdffiller.com *.signnow.com signnow.com *.airslate.com airslate.com *.uslegal.com uslegal.com *.uslegalforms.com uslegalforms.com; report-uri /api_v3/security_report/cspViolationsReport?appKey=p7qaigqhhep0.csp.report 1 default-src 'self'; media-src 'self'; connect-src 'self' https://vpncdn.protonweb.com https://account.proton.me https://account.protonvpn.com https://telemetry.protonvpn.com *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' https://vpncdn.protonweb.com; style-src 'self' 'unsafe-inline' https://vpncdn.protonweb.com; font-src 'self' https://vpncdn.protonweb.com; img-src 'self' data: blob: https:; frame-src 'self' data: blob: https://www.youtube-nocookie.com https://www.openstreetmap.org; object-src 'self' data: blob:; child-src 'self' data: blob:; report-uri https://reports.proton.me/reports/csp; frame-ancestors 'self'; 1 font-src https://cdnjs.cloudflare.com https://static.photoslurp.com *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com https://www.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://connect.facebook.net https://www.facebook.com https://www.google.com https://www.google.ch https://m.photoslurp.com https://static.photoslurp.com cdn.flbx.io *.cloudfront.net https://www.magezon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://connect.facebook.net https://static.photoslurp.com jquery.sellxed.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.getflowbox.com *.google.com/ *.gstatic.com maps.googleapis.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.photoslurp.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://stats.g.doubleclick.net https://api.photoslurp.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.getflowbox.com http://dpm.demdex.net www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.hotjar.com *.fontawesome.com *.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com *.klarna.com *.hotjar.com js.mollie.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.googleapis.com maps.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.hotjar.com www.dpd.co.uk https://www.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.hotjar.com www.dpd.co.uk api.dpdgroup.co.uk *.pcapredict.com services.postcodeanywhere.co.uk js.mollie.com *.trustpilot.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com widget.freshworks.com m2epro.freshdesk.com www.dpd.co.uk services.postcodeanywhere.co.uk *.fontawesome.com *.trustpilot.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.hotjar.com *.hotjar.io wss://*.hotjar.com/api/v2/client/ws www.dpd.co.uk api.dpdgroup.co.uk *.pcapredict.com services.postcodeanywhere.co.uk *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src static.leathercollection.com fonts.gstatic.com www.paypalobjects.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src td.doubleclick.net ct.pinterest.com js.stripe.com b.stripecdn.com pay.google.com newassets.hcaptcha.com m.stripe.network fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com platform.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src media.leathercollection.com static.leathercollection.com leathercollection.com leathercollection.co.uk leathercollection.com.au eleather.it leathercollection.ch leathercollection.co.za leathercollection.jp leathercollection.nz leathercollection.ru leathercollection.se leathercollection.ca leathercollection.de leathercollection.es leathercollection.fr motospeeds.com app.fera.ai cdn.fera.ai media.fera.ai www.facebook.com www.google.com www.google.com.pk i.ytimg.com js.stripe.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net data: *.paypal.com *.typekit.net *.gstatic.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com pinterest.com assets.pinterest.com syndication.twitter.com *.facebook.com data: 'self' 'unsafe-inline'; script-src static.leathercollection.com leathercollection.com leathercollection.co.uk leathercollection.com.au eleather.it leathercollection.ch leathercollection.co.za leathercollection.jp leathercollection.nz leathercollection.ru leathercollection.se leathercollection.ca leathercollection.de leathercollection.es leathercollection.fr motospeeds.com app.fera.ai cdn.fera.ai www.googletagmanager.com s.pinimg.com static.zdassets.com connect.facebook.net googleads.g.doubleclick.net ct.pinterest.com www.google.com www.gstatic.com js.stripe.com b.stripecdn.com pay.google.com hcaptcha.com newassets.hcaptcha.com m.stripe.network assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com analytics.google.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com twitter.com platform.twitter.com static.addtoany.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src static.leathercollection.com media.leathercollection.com leathercollection.com leathercollection.co.uk leathercollection.com.au eleather.it leathercollection.ch leathercollection.co.za leathercollection.jp leathercollection.nz leathercollection.ru leathercollection.se leathercollection.ca leathercollection.de leathercollection.es leathercollection.fr motospeeds.com app.fera.ai cdn.fera.ai js.stripe.com b.stripecdn.com *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com www.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src media.leathercollection.com static.leathercollection.com leathercollection.com leathercollection.co.uk leathercollection.com.au eleather.it leathercollection.ch leathercollection.co.za leathercollection.jp leathercollection.nz leathercollection.ru leathercollection.se leathercollection.ca leathercollection.de leathercollection.es leathercollection.fr motospeeds.com app.fera.ai cdn.fera.ai ekr.zdassets.com ct.pinterest.com leathercollection.zendesk.com js.stripe.com merchant-ui-api.stripe.com r.stripe.com api.stripe.com api2.hcaptcha.com api.hcaptcha.com m.stripe.com analytics.google.com www.pinterest.com stats.g.doubleclick.net www.facebook.com googleads.g.doubleclick.net wss://widget-mediator.zopim.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com stats.addtoany.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.googleapis.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src media.leathercollection.com static.leathercollection.com leathercollection.com leathercollection.co.uk leathercollection.com.au eleather.it leathercollection.ch leathercollection.co.za leathercollection.jp leathercollection.nz leathercollection.ru leathercollection.se leathercollection.ca leathercollection.de leathercollection.es leathercollection.fr motospeeds.com app.fera.ai cdn.fera.ai static.zdassets.com ekr.zdassets.com leathercollection.zendesk.com *.zopim.com zendesk-eu.my.sentry.io v2assets.zopim.io wss://widget-mediator.zopim.com r.stripe.com apis.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com bablas.co.uk www.bablas.co.uk fonts.cdnfonts.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com https://live.opayo.eu.elavon.com https://acs.gc.at https://acs.gc.be https://acs.gc.bg https://acs.gc.hr https://acs.gc.cy https://acs.gc.cz https://acs.gc.dk https://acs.gc.ee https://acs.gc.fi https://acs.gc.fr https://acs.gc.de https://acs.gc.gr https://acs.gc.hu https://acs.gc.ie https://acs.gc.it https://acs.gc.lv https://acs.gc.lt https://acs.gc.lu https://acs.gc.mt https://acs.gc.nl https://acs.gc.pl https://acs.gc.pt https://acs.gc.ro https://acs.gc.sk https://acs.gc.si https://acs.gc.es https://acs.gc.se https://acs.gc.co.uk https://acs.gc.ge https://acs2.ufc.at https://acs2.ufc.be https://acs2.ufc.bg https://acs2.ufc.hr https://acs2.ufc.cy https://acs2.ufc.cz https://acs2.ufc.dk https://acs2.ufc.ee https://acs2.ufc.fi https://acs2.ufc.fr https://acs2.ufc.de https://acs2.ufc.gr https://acs2.ufc.hu https://acs2.ufc.ie https://acs2.ufc.it https://acs2.ufc.lv https://acs2.ufc.lt https://acs2.ufc.lu https://acs2.ufc.mt https://acs2.ufc.nl https://acs2.ufc.pl https://acs2.ufc.pt https://acs2.ufc.ro https://acs2.ufc.sk https://acs2.ufc.si https://acs2.ufc.es https://acs2.ufc.se https://acs2.ufc.co.uk https://acs2.ufc.ge https://safekey-3.americanexpress.com https://acs2.libertybank.ge *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://calendly.com https://assets.calendly.com https://www.google.com https://www.googletagmanager.com https://td.doubleclick.net https://platform.twitter.com https://www.facebook.com https://www.paypal.com https://acs2.ufc.ge https://acs2.ufc.co.uk https://acs2.ufc.com https://acs.gc.ge https://acs.gc.co.uk https://acs.gc.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.weltpixel.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io api.feefo.com www.google.co.uk bat.bing.com syndication.twitter.com register.feefo.com www.bablas.co.uk pagead2.googlesyndication.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.facebook.com pinterest.com assets.pinterest.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.syndication.tiekinetix.net *.calendly.com syndication.tiekinetix.net api.feefo.com static.hotjar.com ajax.googleapis.com register.feefo.com *.cloudflare.com script.hotjar.com consent.cookiefirst.com edge.cookiefirst.com connect.facebook.net www.gstatic.com *.g.doubleclick.net bat.bing.com platform.twitter.com www.reviewcentre.com pcls1.craftyclicks.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com *.disqus.com *.googleapis.com *.gstatic.com twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com consent.cookiefirst.com register.feefo.com cdnjs.cloudflare.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.googleapis.com *.gstatic.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com stats.g.doubleclick.net consent.cookiefirst.com www.google-analytics.com edge.cookiefirst.com pagead2.googlesyndication.com api.cookiefirst.com analytics.google.com api.feefo.com collect.feefo.com syndication.twitter.com www.facebook.com vc.hotjar.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src pagead2.googlesyndication.com stats.g.doubleclick.net bat.bing.com *.google.com www.paypal.com analytics.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://sandbox.payfast.co.za https://www.payfast.co.za/eng/process *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com/ *.doubleclick.net *.facebook.com *.tawk.to *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.tiktok.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://www.magezon.com * https://widgets.payflex.co.za *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.tiktok.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com * https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.payflex.co.za *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.tiktok.com *.google-analytics.com *.facebook.com *.facebook.net *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://unpkg.com https://cdnjs.cloudflare.com https://bam.nr-data.net https://checkout-sdk.sezzle.com https://widget.sezzle.com https://js.authorize.net https://jstest.authorize.net https://pay.google.com https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://www.google.com https://*.google.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.cloudfront.net https://*.cloudflareinsights.com https://*.cloudflare.com https://challenges.cloudflare.com https://*.judge.me https://hook.us1.make.com https://make.com https://at3tactical.com https://*.at3tactical.com https://js-agent.newrelic.com https://advertiserpro.flexoffers.com https://maps.googleapis.com https://maps.gstatic.com https://*.masterffl.com https://cdn.avmws.com https://*.armanet.us https://*.jst.ai https://*.justuno.com https://*.ottertext.com https://*.helpscout.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://advertiserpro.flexoffers.com https://maps.googleapis.com https://*.cloudflare.com https://*.masterffl.com https://cdn.avmws.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.armanet.us https://*.jst.ai https://*.justuno.com https://*.ottertext.com https://*.helpscout.net; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://*.cloudflare.com data: https://*.jst.ai; img-src 'self' data: blob: https: https://d34uoa9py2cgca.cloudfront.net https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.googleusercontent.com https://*.gstatic.com https://maps.googleapis.com https://maps.gstatic.com https://*.cloudflare.com https://*.masterffl.com https://cdn.avmws.com https://*.helpscout.net; connect-src 'self' https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://bam.nr-data.net https://gateway.sezzle.com https://sandbox.gateway.sezzle.com https://js.authorize.net https://api2.authorize.net https://apitest.authorize.net https://jstest.authorize.net https://apple-pay-gateway-cert.apple.com https://cdn.jsdelivr.net https://hook.us1.make.com https://*.judge.me https://js-agent.newrelic.com https://*.cloudflare.com https://challenges.cloudflare.com https://maps.googleapis.com https://*.masterffl.com https://cdn.avmws.com https://www.google.com https://*.google.com https://*.jst.ai https://*.armanet.us https://*.justuno.com https://*.ottertext.com https://*.helpscout.net; frame-src 'self' https://js.authorize.net https://accept.authorize.net https://test.authorize.net https://checkout-sdk.sezzle.com https://widget.sezzle.com https://www.youtube.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.cloudflare.com https://challenges.cloudflare.com https://maps.googleapis.com https://*.masterffl.com https://cdn.avmws.com https://www.google.com https://*.google.com https://*.jst.ai https://*.ottertext.com https://*.helpscout.net; form-action 'self' https://js.authorize.net https://accept.authorize.net https://test.authorize.net https://*.judge.me https://*.cloudflare.com https://*.masterffl.com https://*.helpscout.net https://*.ottertext.com; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.weltpixel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://www.youtube.com https://ct.pinterest.com https://pixel-sync.sitescout.com *.pitai.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com https://extendcoreoffersprod-offersthemelogobucketeb21afa-1lr7le13dvgtp.s3.amazonaws.com magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com www.mypillow.com https://www.mypillow.com https://trkn.us https://bat.bing.com https://obs.segreencolumn.com https://pixel.sitescout.com *.riskified.com *.pitai.io *.listrakbi.com https://mediacdn.espssl.com *.google.com *.google.pl https://static-na.payments-amazon.com https://t.co/ https://analytics.twitter.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.helloextend.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.hsforms.net *.hsforms.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net data: *.mypillow.com *.listrakbi.com https://bat.bing.com https://analytics.tiktok.com *.zdassets.com https://www.youtube.com https://sdk.helloextend.com https://static.cloudflareinsights.com https://script.hotjar.com *.listrak.com https://s.pinimg.com https://www.google-analytics.com/analytics.js https://obs.segreencolumn.com https://franktpin.pitai.io https://beacon.riskified.com https://tags.srv.stackadapt.com *.basis.net https://ct.pinterest.com https://pixel-sync.sitescout.com https://a.ads.rmbl.ws https://sandbox-api.epicpay.com *.hotjar.com *.noibu.com *.segreencolumn.com https://static.ads-twitter.com/ https://api.epicpay.com/ https://maps.googleapis.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com https://tags.srv.stackadapt.com *.listrakbi.com https://kit.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://*.helloextend.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net https://input.noibu.com https://obs.segreencolumn.com wss://input.noibu.com *.zdassets.com *.analytics.google.com https://ct.pinterest.com *.pitai.io *.listrak.com *.listrakbi.com https://tags.srv.stackadapt.com *.riskified.com *.breadgateway.net *.doubleclick.net *.hotjar.io https://bat.bing.com wss://ws.hotjar.com/ https://mystorellc.zendesk.com/ https://maps.googleapis.com/ https://cdn.noibu.com/collect-worker.js 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com 'self' data: 3efe134ec6.nxcli.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 3efe134ec6.nxcli.io 'self' 'unsafe-inline'; frame-ancestors 3efe134ec6.nxcli.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com platform.twitter.com *.yotpo.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.twitter.com *.facebook.com *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com *.weltpixel.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.yotpo.com https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com *.adroll.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.google.co.uk *.twitter.com *.twimg.com *.ytimg.com *.herokuapp.com *.pooldawg.com *.bing.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.reddit.com 3efe134ec6.nxcli.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.plugins.emarsys.net *.scarabresearch.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com twitter.com platform.twitter.com *.yotpo.com *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com d2z0bn1jv8xwtk.cloudfront.net *.adroll.com js-agent.newrelic.com bam.nr-data.net *.klaviyo.com *.googleadservices.com *.gstatic.com *.google-analytics.com *.bing.com *.mountain.com *.criteo.net *.criteo.com *.conversionwax.com *.attn.tv js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.yotpo.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu static.ctctcdn.com *.klaviyo.com *.google.com *.googletagmanager.com assets.braintreegateway.com tagmanager.google.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.scarabresearch.com *.eservice.emarsys.net https://static.klaviyo.com static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com d.adroll.com bam.nr-data.net *.klaviyo.com *.doubleclick.net *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com 3efe134ec6.nxcli.io http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 3efe134ec6.nxcli.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://www.google.com https://dnnapi.com https://stats-api.flockler.app https://api.flockler.app https://plugins.flockler.com https://maps.googleapis.com https://www.google-analytics.com https://vimeo.com https://issuu.com https://code.jquery.com https://sentry.issuu.com https://api.flockler.com https://translate.googleapis.com; font-src 'self' data: https://dnnapi.com https://use.fontawesome.com https://fonts.gstatic.com https://use.typekit.net; frame-src 'self' https://www.youtube-nocookie.com https://e.issuu.com https://maps.google.com https://www.google.com https://platform.twitter.com https://syndication.twitter.com https://player.vimeo.com https://www.youtube.com https://livestream.com https://vimeo.com https://media-api.flockler.com https://*.cloudflarestream.com; img-src 'self' data: blob: https://flockler.com https://fl-1.cdn.flockler.com https://media-api.flockler.com https://s3.amazonaws.com/ https://supporting-cast.blubrry.net https://scontent-sjc3-1.cdninstagram.com https://scontent.cdninstagram.com https://d31hzlhk6di2h5.cloudfront.net https://dnnapi.com https://images.e2ma.net https://fonts.googleapis.com https://maps.googleapis.com https://www.google-analytics.com https://fonts.gstatic.com https://maps.gstatic.com https://www.hw.com https://code.jquery.com https://psb.twimg.com https://abs-0.twimg.com https://platform.twitter.com https://syndication.twitter.com https://i.vimeocdn.com https://ajax.googleapis.com https://*.cdninstagram.com https://www.googletagmanager.com https://*.xx.fbcdn.net https://www.gstatic.com; report-to cspEndpoint; report-uri https://www.hw.com/about/Content-Security-Policy; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://fl-1.cdn.flockler.com https://ajax.aspnetcdn.com https://cdnjs.cloudflare.com https://dnnapi.com https://www.google.com https://fonts.googleapis.com https://maps.googleapis.com https://www.google-analytics.com https://www.gstatic.com https://graph.instagram.com https://e.issuu.com https://code.jquery.com https://cdn.syndication.twimg.com https://platform.twitter.com https://player.vimeo.com https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' https://plugins.flockler.com https://ajax.aspnetcdn.com https://cdnjs.cloudflare.com https://dnnapi.com https://e.issuu.com https://www.google.com/ https://fonts.googleapis.com https://maps.googleapis.com https://www.google-analytics.com https://www.gstatic.com https://graph.instagram.com https://code.jquery.com https://cdn.syndication.twimg.com https://platform.twitter.com https://player.vimeo.com https://www.googletagmanager.com https://cdn.datatables.net https://translate.google.com https://translate-pa.googleapis.com https://translate.googleapis.com; style-src 'self' 'unsafe-inline' https://use.fontawesome.com https://fonts.googleapis.com https://www.gstatic.com https://code.jquery.com https://ajax.googleapis.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://plugins.flockler.com https://use.fontawesome.com https://fonts.googleapis.com https://www.google-analytics.com https://www.gstatic.com https://code.jquery.com https://ajax.googleapis.com https://use.typekit.net https://p.typekit.net; media-src 'self' https://media-api.flockler.com https://content.blubrry.com https://media.blubrry.com https://player.vimeo.com https://download-video.akamaized.net; style-elem 'self' https://use.typekit.net; 1 img-src 'self' www.googletagmanager.com https://www.google-analytics.com data: https://script.hotjar.com http://script.hotjar.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://go.pardot.com http://static.hotjar.com https://static.hotjar.com https://script.hotjar.com addtocalendar.com cdn.jsdelivr.net https://cdnjs.cloudflare.com mdbootstrap.com snap.licdn.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://go.pardot.com http://static.hotjar.com https://static.hotjar.com https://script.hotjar.com https://socomec.containers.piwik.pro https://try.abtasty.com addtocalendar.com cdn.jsdelivr.net https://cdnjs.cloudflare.com mdbootstrap.com snap.licdn.com; style-src 'self' 'unsafe-inline' addtocalendar.com cdn.jsdelivr.net fonts.googleapis.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://socomec.containers.piwik.pro https://try.abtasty.com addtocalendar.com cdn.jsdelivr.net fonts.googleapis.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors https://*.walmart.com https://dev.walmart.com:4200 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com *.careem-pay.com *.klevu.com *.ksearchnet.com *.stape.io *.fontawesome.com https://fonts.bunny.net maps.googleapis.com fonts.intercomcdn.com maxcdn.bootstrapcdn.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com maps.googleapis.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://js.checkout.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.b-cdn.net *.tap.company *.careem-pay.com platform.twitter.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io maps.googleapis.com checkout.tabby.ai 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.b-cdn.net pinterest.com assets.pinterest.com syndication.twitter.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.stape.io https://firebasestorage.googleapis.com maps.googleapis.com livecdn.petzone.com storage.inhabitad.com petzone.com www.google.co.in downloads.intercomcdn.com js.intercomcdn.com statsjs.klevu.com analytics.tiktok.com flagpedia.net checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.tamara.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://*.checkout.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.b-cdn.net *.careem-pay.com *.cloudflare.com twitter.com platform.twitter.com *.klevu.com *.ksearchnet.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io maps.googleapis.com polyfill.io googleapis.com delivery.inhabitad.com static.cloudflareinsights.com widget.intercom.io js.intercomcdn.com statsjs.klevu.com https://statsjs.klevu.com stape.petzone.com www.clarity.ms scripts.clarity.ms analytics.tiktok.com cdn.decibelinsight.net checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.tamara.co https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com *.b-cdn.net *.klevu.com *.ksearchnet.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net maps.googleapis.com storage.inhabitad.com maxcdn.bootstrapcdn.com *.gstatic.com *.tamara.co https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tamara.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com https://js.checkout.com *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.dev.tap.company *.tap.company *.klevu.com *.ksearchnet.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://get.geojs.io *.avada.io wss://nexus-websocket-a.intercom.io maps.googleapis.com 'self' https://api.petzone.com delivery.inhabitad.com static.cloudflareinsights.com cloudflareinsights.com api-iam.intercom.io nexus-websocket-a.intercom.io *.intercom.io f.clarity.ms www.clarity.ms analytics.tiktok.com collection.decibelinsight.net capig.stape.cloud www.gstatic.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.tamara.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://maps.googleapis.com/; report-to report-endpoint; 1 font-src https://www.google.com *.force.com https://sh-exp-ck.app.intuit.com https://analytics.google.com https://fonts.gstatic.com/ https://accounts.creditkarma.com 'self' https://stats.g.doubleclick.net https://td.doubleclick.net https://translation.googleapis.com https://unpkg.com blob: https://help.creditkarma.com https://support.creditkarma.com https://portal.creditkarma.com https://support.helpcenter.ca https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://google-analytics.com https://creditkarma1.my.salesforce-scrt.com data:; report-to sfdc-csp-ep; report-uri https://creditkarma1.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D1U000000rAl3&networkId=0DM1U000000e6Hq&type=communities 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com geowidget.easypack24.net 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://sandbox.blpaczka.com https://send.blpaczka.com pudofinder.dpd.com.pl https://www.googletagmanager.com/ *.facebook.com pay.google.com apm.przelewy24.pl secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com ruch-osm.sysadvisors.pl p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io secure.przelewy24.pl http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com magefan.com cm.magefan.com static.przelewy24.pl www.gstatic.com gstatic.com static.payu.com geowidget.easypack24.net maps.googleapis.com *.hsforms.net *.hsforms.com 'self' data: *.groomershop.pl *.groomershop.eu www.google.pl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ ruch-osm.sysadvisors.pl amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://sandbox.blpaczka.com https://send.blpaczka.com secure.przelewy24.pl http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.googleapis.com sandbox.przelewy24.pl pay.google.com apm.przelewy24.pl secure.payu.com secure.snd.payu.com geowidget.easypack24.net *.hsforms.net *.hsforms.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com ruch-osm.sysadvisors.pl fonts.googleapis.com secure.przelewy24.pl maxcdn.bootstrapcdn.com geowidget.easypack24.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.groomershop.pl *.groomershop.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ruch-osm.sysadvisors.pl *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://sandbox.blpaczka.com https://send.blpaczka.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com secure.payu.com merch-prod.snd.payu.com api-pl-points.easypack24.net maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com places.googleapis.com *.groomershop.pl *.groomershop.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com data: *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com scontent.* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ display.ugc.bazaarvoice.com *.fontawesome.com assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9ca91a39-e0b9-4d19-844a-182a33f11f35.sansec.watch/; report-to report-endpoint; 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://siteimproveanalytics.com/ https://snap.licdn.com/ https://tr.snapchat.com/config/ https://connect.facebook.net/ https://sc-static.net/ https://unpkg.com/ https://js.monitor.azure.com/scripts/b/ai.2.gbl.min.js https://code.highcharts.com/ https://api.kartverket.no/ https://embed.typeform.com/ https://historier.ks.no/ https://*.vo.msecnd.net/ https://ajax.aspnetcdn.com/ https://code.jquery.com/ https://*.cloudfront.net/ https://*.gosquared.com/ https://web103.reachmee.com/ https://dl.episerver.net/ https://www.youtube.com/ https://cloud.highcharts.com/ https://e.infogram.com/ https://public.tableau.com/ https://s.infogram.com/ https://cloud-api.highcharts.com/ https://amp.azure.net/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com embed.typeform.com dl.episerver.net amp.azure.net; img-src 'self' https://imgsct.cookiebot.com/ https://www.google-analytics.com/ https://px.ads.linkedin.com/ https://www.facebook.com/ https://www.googletagmanager.com/ https://i.ytimg.com/ https://px4.ads.linkedin.com/ https://historier.ks.no/ https://airtable.com/ https://*.airtable.com/ https://*.global.siteimproveanalytics.io/ https://ssl.siteimprove.com/ https://www.google.com/ https://www.google.no/ https://stats.g.doubleclick.net/ https://dl.episerver.net/; connect-src 'self' https://consentcdn.cookiebot.com/ https://region1.google-analytics.com/ https://www.google-analytics.com/ https://px.ads.linkedin.com/wa/ https://tr.snapchat.com/ https://tr6.snapchat.com/ https://statistikk.ks.no/ https://dc.services.visualstudio.com/ https://api.kartverket.no/ https://historier.ks.no/ https://cloud-api.highcharts.com/ https://dev.ks.statistikk.no/ https://statistikk-test.ks.no/ https://stats.g.doubleclick.net/ https://hotell.difi.no/ https://ws.geonorge.no/ https://cdn.linkedin.oribi.io/; font-src 'self' https://region1.google-analytics.com/ https://www.google-analytics.com/ https://px.ads.linkedin.com/wa/ https://tr.snapchat.com/p https://tr6.snapchat.com/p https://fonts.gstatic.com/s/materialicons/v143/flUhRq6tzZclQEJ-Vdg-IuiaDsNcIhQ8tQ.woff2 https://fonts.gstatic.com/s/materialicons/v143/flUhRq6tzZclQEJ-Vdg-IuiaDsNc.woff2; object-src 'self' ; media-src 'self' https://historier.ks.no/ https://airtable.com/ https://*.airtable.com/; frame-src 'self' https://consentcdn.cookiebot.com https://tr.snapchat.com/ https://www.youtube.com/ https://player.pippa.io/ https://embed.acast.com/ https://e.infogram.com/ https://form.typeform.com/ https://learning.elucidat.com/ https://ahmonday.com/ https://www.ahmonday.com/ https://historier.ks.no/ https://airtable.com/ https://*.airtable.com/ https://consent.cookiebot.com/ https://login.windows.net/ https://login.microsoftonline.com/ https://app.everviz.com/ https://player.acast.com/ https://play.acast.com/ https://ksagenda.trippelm.tv/ https://ks-kart.carto.com/ https://video.qbrick.com/ https://player.vimeo.com/ https://vimeo.com/ https://livestream.com/ https://sway.cloud.microsoft/ https://sway.office.com/ https://app.powerbi.com/ https://web103.reachmee.com/ https://cloud.highcharts.com/ https://ivks.dev.bouvet.no/ https://youtube.com/ https://www.youtube.com/ https://ks-test.imagevault.app/ https://ks.imagevault.app/ https://iv.nytest.ks.no/ https://iv.nyprod.ks.no/ https://public.tableau.com/ https://s.infogram.com/ https://cloud-api.highcharts.com/ https://forms.office.com/ https://office.com/ https://create.plandisc.com/; child-src 'self' ; form-action 'self' ; frame-ancestors 'self' ; base-uri 'self' ; worker-src 'self' ; manifest-src 'self' ; navigate-to 'self' ; report-uri https://www.ks.no/api/reporting/; report-to csp-endpoint; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' www.clarity.ms js.braintreegateway.com assets.braintreegateway.com www.paypalobjects.com *.paypal.com songbird.cardinalcommerce.com https://client.rum.us-east-1.amazonaws.com https://integrations.etrusted.com https://apps.mypurecloud.ie https://cookie-cdn.cookiepro.com https://pay.google.com/gp/p/js/pay.js https://services.postcodeanywhere.co.uk/js/address-3.91.min.js static.cloudflareinsights.com https://ajax.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://bat.bing.com https://*.tradedoubler.com https://cdn.studentbeans.com https://googleads.g.doubleclick.net https://bat.bing.com/p/action/5035386.js https://www.paypal.com https://loader.wisepops.com https://wisepops.net https://widget.trustpilot.com https://widgets.trustedshops.com https://tag.mention-me.com https://static.mention-me.com https://*.klarnacdn.net https://*.criteo.com maps.googleapis.com https://www.googleadservices.com https://www.google.com https://ob.segreencolumn.com https://obs.segreencolumn.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.googleapis.com https://services.postcodeanywhere.co.uk https://integrations.etrusted.com; object-src 'none'; base-uri 'self'; connect-src 'self' api.lenstore.co.uk api.lenstore.de api.lenstore.it api.lenstore.fr api.lenstore.es https://*.clarity.ms/collect https://*.mypurecloud.ie dataplane.rum.eu-west-1.amazonaws.com https://cognito-identity.eu-west-1.amazonaws.com/ api.braintreegateway.com client-analytics.braintreegateway.com https://*.etrusted.com https://auth.split.io https://cookie-cdn.cookiepro.com https://klarna.com https://*.klarnaevt.com https://x.klarnacdn.net https://*.klarna.com https://events.split.io https://google.com https://pay.google.com https://google.com/pay https://*.braintree-api.com https://sdk.split.io https://streaming.split.io https://www.paypal.com https://www.sandbox.paypal.com https://www.google.com/ccm/collect https://*.google-analytics.com *.analytics.google.com https://*.wisepops.com https://wisepops.net https://obs.segreencolumn.com cardinalcommerce.com *.cardinalcommerce.com https://privacyportal.cookiepro.com *.trustedshops.com trustedshops.com services.postcodeanywhere.co.uk sts.eu-west-1.amazonaws.com bat.bing.net *.doubleclick.net wss://am.freshrelevance.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' *; img-src 'self' assets.lenstore.co.uk assets.lenstore.de assets.lenstore.it assets.lenstore.fr assets.lenstore.es data: assets.braintreegateway.com checkout.paypal.com https://c.clarity.ms https://www.gstatic.com https://integrations.etrusted.com https://www.paypalobjects.com https://cookie-cdn.cookiepro.com https://bat.bing.com https://www.google.com https://www.google.co.uk https://criteo-partners.tremorhub.com/ https://x.bidswitch.net https://cm.g.doubleclick.net/pixel https://ib.adnxs.com/getuid https://r.casalemedia.com/rum https://gum.criteo.com https://id5-sync.com/ https://ad.360yield.com https://contextual.media.net https://exchange.mediavine.com/usersync/push https://jadserve.postrelease.com https://sync.outbrain.com/cookie-sync https://simage2.pubmatic.com/AdServer/Pug https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://eb2.3lift.com https://ad.yieldlab.net https://sync.1rx.io https://dis.criteo.com https://sync.targeting.unrulymedia.com https://www.google-analytics.com/collect https://x.klarnacdn.net https://services.postcodeanywhere.co.uk trustedshops.com; manifest-src 'self'; media-src 'self'; worker-src 'none' blob; report-uri https://api.lenstore.co.uk/event/csp-report 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.sagepay.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sagepay.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io flagpedia.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.gstatic.com maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.sagepay.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.gstatic.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.gstatic.com maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ *.sagepay.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com places.googleapis.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net cdn.knightlab.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com stats.g.doubleclick.net *.facebook.com www.gstatic.com *.googlesyndication.com *.google.it data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.facebook.com *.facebook.it *.facebook.net *.google.it *.googleadservice.com *.google-analytics.com cdn.knightlab.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com cdn.knightlab.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.facebook.com *.facebook.it *.facebook.net *.google.it *.googlesyndication.com *.googletagmanager.com *.gstatic.com cdn.knightlab.com *.youtube.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-/8LcgP/0k0mrTkm7qxLjKQ=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self' siteminder.okta.com *.oktacdn.com; connect-src 'self' siteminder.okta.com siteminder-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com siteminder.kerberos.okta.com siteminder.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'nonce-bOBxv03Qvf6LMjhW8zHXXQ' 'unsafe-eval' 'self' 'report-sample' siteminder.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-bOBxv03Qvf6LMjhW8zHXXQ' 'self' 'report-sample' siteminder.okta.com *.oktacdn.com; frame-src 'self' siteminder.okta.com siteminder-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' siteminder.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' siteminder.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://tools.siteminder.systems https://siteminder--uat--c.sandbox.vf.force.com https://siteminder.vf.force.com https://siteminder.lightning.force.com https://siteminder--uat.sandbox.lightning.force.com https://tableau.siteminder.com 1 font-src *.fontawesome.com edwineurope.app.baqend.com *.googleapis.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.weltpixel.com consentcdn.cookiebot.com ct.pinterest.com www.googletagmanager.com td.doubleclick.net www.xtento.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com bat.bing.com ct.pinterest.com www.google.co.ma cdn.edwin-europe.com www.google.de imgsct.cookiebot.com www.xtento.com cdn.xtento.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com edwineurope.app.baqend.com consent.cookiebot.com bat.bing.com cdn.scarabresearch.com script.hotjar.com static.hotjar.com s.pinimg.com a.opumo.net consentcdn.cookiebot.com ct.pinterest.com analytics.tiktok.com www.xtento.com cdn.xtento.com https://www.googletagmanager.com tagmanager.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com s7.addthis.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com blob: tagmanager.google.com d.ratepay.com d.payla.io dr.payla.io *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.youtube.com mcprod.edwin-europe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.nlservice.edwin-europe.com:8443/subscribe edwineurope.app.baqend.com ipapi.co a.opumo.net ct.pinterest.com consentcdn.cookiebot.com stats.g.doubleclick.net region1.google-analytics.com region1.analytics.google.com recommender.scarabresearch.com https://www.google-analytics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ekr.zdassets.com/ https://get.geojs.io *.avada.io payments.amazon.de d.ratepay.com jsctool.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: 'self' data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' vars.hotjar.com *.braintreegateway.com tst.kaptcha.com hemsync.clickagy.com *.google.com https://*.moneris.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.visualwebsiteoptimizer.com 'self' data: js.hsforms.net track.hubspot.com cds.taboola.com *.magidglove.com maps.gstatic.com seal.digicert.com black.bird.eu cdn.klarna.com *.facebook.com connect.facebook.net *.bing.com *.googletagmanager.com code.visitor-track.com *.google.com *.google.co.in dev.visualwebsiteoptimizer.com *.hsforms.com forms-na1.hsforms.com *.jwpltx.com *.jwpsrv.com/ *.jwplatform.com *.jwplayer.com *.payu.in *.linkedin.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.contextual.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.criteo-sync.teads.tv *.3lift.com *.yahoo.com *.socdm.com *.casalemedia.com *.dable.io *.stickyadstv.com *.360yield.com *.rlcdn.com *.mediavine.com *.outbrain.com *.pubmatic.com *.smaato.net *.clmbtech.com *.aralego.com *.emxdgt.com *.bbb.org *.unrulymedia.com *.adingo.jp *.1rx.io *.criteo.com *.adingo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval' blob: *.cloudfront.net *.uat-rfk.magidglove.com *.rfk.magidglove.com js.hs-scripts.com js.hsforms.net forms.hsforms.com js.hs-analytics.net js.hs-banner.com *.hotjar.com *.taboola.com *.facebook.net clients-liveguide01us.netop.com maps.googleapis.com bam.nr-data.net seal.digicert.com *.facebook.com *.bing.com dev.visualwebsiteoptimizer.com cdn.jsdelivr.net *.mczbf.com *.hsleadflows.net *.google.com *.jwplatform.com ssl.p.jwpcdn.com *.jwplayer.com *.bootstrapcdn.com *.progmxs.com *.upsellit.com *.noibu.com *.hsadspixel.net *.criteo.com *.adnxs.com secure.adnxs.com *.snap.licdn.com js.zi-scripts.com ws.zoominfo.com tags.clickagy.com *.datadome.co *.adingo.com *.zi-scripts.com *.magidglove.com *.hs-scripts.com https://*.moneris.com/ *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline' d26opx5dl8t69i.cloudfront.net rfk-staticfiles-uat.s3.amazonaws.com rfk-staticfiles-prod.s3.amazonaws.com cdn.jsdelivr.net *.cloudfront.net *.gstatic.com *.bootstrapcdn.com *.googleapis.com https://*.moneris.com/ *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' data: blob: *.jwpplayer.com *.jwpsrv.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' *.taboola.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com *.doubleclick.net bam.nr-data.net in.hotjar.com dev.visualwebsiteoptimizer.com *.sjwoe.com *.mczbf.com *.hsforms.com *.hubspot.com *.cloudfront.net gstatic.com settings.luckyorange.net *.jwplatform.com *.jwpsrv.com/ *.jwplayer.com *.hotjar.io *.noibu.com input.noibu.com *.criteo.com *.hubapi.com *.visualwebsiteoptimizer.com *.googlesyndication.com aorta.clickagy.com hemsync.clickagy.com js.zi-scripts.com ws.zoominfo.com *.datadome.co *.unrulymedia.com *.adingo.com *.zi-scripts.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.affirm.com *.affirm.ca *.b0e8.com magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.affirm.com *.affirm.ca *.b0e8.com *.bc0a.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net tagmanager.google.com fonts.google.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com qa-api.magedevteam.com *.affirm.com *.affirm.ca api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.stripe.com *.google.com *.opayo.eu.elavon.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.google.com *.opayo.eu.elavon.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.stripe.com *.google.com *.opayo.eu.elavon.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.paypal.com *.opayo.eu.elavon.com *.globalpay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com www.xtento.com cdn.xtento.com staging.quba.com www.google.co.in www.facebook.com *.clarity.ms c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.stripe.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.opayo.eu.elavon.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com static.hotjar.com www.clarity.ms cdnjs.cloudflare.com script.hotjar.com connect.facebook.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.stripe.com *.google.com downloads.mailchimp.com *.opayo.eu.elavon.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com *.stripe.com *.google.com *.paypal.com *.opayo.eu.elavon.com https://google.com/pay api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com stats.g.doubleclick.net u.clarity.ms p.clarity.ms ws.hotjar.com content.hotjar.io n.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' static.greenmountainpower.com chat.greenmountainpower.com chat.greenmountainpower.com:8085 cdnjs.cloudflare.com challenges.cloudflare.com cdn-global.configcat.com www.googletagmanager.com www.google-analytics.com www.google.com www.gstatic.com api.mapbox.com *.statuspage.io unpkg.com; script-src-elem 'self' 'unsafe-inline' static.greenmountainpower.com chat.greenmountainpower.com chat.greenmountainpower.com:8085 cdnjs.cloudflare.com challenges.cloudflare.com cdn-global.configcat.com www.googletagmanager.com www.google-analytics.com www.google.com www.gstatic.com api.mapbox.com *.statuspage.io unpkg.com; style-src 'self' 'unsafe-inline' static.greenmountainpower.com fonts.googleapis.com cdnjs.cloudflare.com api.mapbox.com; font-src 'self' data: static.greenmountainpower.com fonts.gstatic.com api.mapbox.com; img-src 'self' data: blob: static.greenmountainpower.com accountphotos.greenmountainpower.com chat.greenmountainpower.com chat.greenmountainpower.com:8085 billreport.greenmountainpower.com billreportdev.greenmountainpower.com outages.greenmountainpower.com outagestst.greenmountainpower.com secure.gravatar.com api.mapbox.com *.statuspage.io www.googletagmanager.com s3.amazonaws.com 4dseguzfz1.execute-api.us-east-1.amazonaws.com dlgixp6rjafta.cloudfront.net; connect-src 'self' api.greenmountainpower.com api2.greenmountainpower.com apitst.greenmountainpower.com chat.greenmountainpower.com chat.greenmountainpower.com:8085 wss://chat.greenmountainpower.com:8085 billreport.greenmountainpower.com billreportdev.greenmountainpower.com www.google-analytics.com analytics.google.com region1.google-analytics.com www.googletagmanager.com www.google.com cdn-global.configcat.com *.sentry.io events.mapbox.com api.mapbox.com *.statuspage.io internet.speedpay.com batinternet.speedpay.com tokenservice.speedpay.com sptest144aa.speedpay.com api.experianaperture.io cdnjs.cloudflare.com unpkg.com; frame-src 'self' chat.greenmountainpower.com billreport.greenmountainpower.com billreportdev.greenmountainpower.com challenges.cloudflare.com outlook.office365.com www.googletagmanager.com www.google.com gmp.maps.arcgis.com *.statuspage.io; worker-src 'self' blob:; media-src 'self' data: blob: chat.greenmountainpower.com chat.greenmountainpower.com:8085; form-action 'self' internet.speedpay.com batinternet.speedpay.com; object-src 'self'; frame-ancestors 'none'; base-uri 'self'; report-uri https://o4505959029932032.ingest.us.sentry.io/api/4509112744280064/security/?sentry_key=8f1fbd2775ecb8f29f50b62a05e8c2f7&sentry_environment=production; report-to csp-endpoint 1 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.barkerandstonehouse.co.uk *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.bootstrapcdn.com 'unsafe-inline' data: static.sizebay.technology *.moengage.com fonts.googleapis.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com connect.facebook.net www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://js.checkout.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://c.sharethis.mgr.consensu.org gumi.criteo.com rivafashion.api.useinsider.com www.googletagmanager.com td.doubleclick.net fledge.eu.criteo.com static.criteo.net static.sizebay.technology ams.creativecdn.com js.checkout.com tr.snapchat.com *.moengage.com https://www.googletagmanager.com/ checkout.tabby.ai 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.tamara.co www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com *.meetanshi.com *.cloudflare.com www.rivafashion.com sentinel.api.useinsider.com t.co www.google.co.in analytics.twitter.com ad.360yield.com pixel.rubiconproject.com s.ad.smaato.net ade.clmbtech.com contextual.media.net sync-t1.taboola.com simage2.pubmatic.com eb2.3lift.com sync-criteo.ads.yieldmo.com x.bidswitch.net dis.criteo.com r.casalemedia.com c.bing.com criteo-sync.teads.tv rtb-csync.smartadserver.com idsync.rlcdn.com sync.outbrain.com cs.adingo.jp cdn.aralego.net tg.socdm.com adx.dable.io sync.targeting.unrulymedia.com cm.adgrx.com sync.aralego.com public-prod-dspcookiematching.dmxleo.com tr.snapchat.com cm.g.doubleclick.net sync.1rx.io/ image-eu.moengage.com ib.adnxs.com ads.stickyadstv.com *.moengage.com moe-email-campaigns.s3.amazonaws.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.tamara.co https://cdn.checkout.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.cloudflareinsights.com static.cloudflareinsights.com web-sdk.ackoo.app *.api.useinsider.com tags.creativecdn.com *.cloudflare.com *.twitter.com *.fontawesome.com static.ads-twitter.com widget.eu.criteo.com ams.creativecdn.com sc-static.net static.sizebay.technology dynamic.criteo.com rivafashion.api.useinsider.com app.link cdn.branch.io analytics.tiktok.com www.gstatic.com cdn.moengage.com sslwidget.criteo.com cdn.checkout.com js-agent.newrelic.com tr.snapchat.com vfr-v3-production.sizebay.technology http://www.googletagmanager.com/ https://www.googletagmanager.com/ libraries.unbxdapi.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tamara.co https://cdn.checkout.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.bootstrapcdn.com www.rivafashion.com goselljslib.b-cdn.net static.sizebay.technology *.moengage.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tamara.co *.moengage.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.tamara.co https://js.checkout.com *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.api.useinsider.com api2.branch.io mug.criteo.com ams.creativecdn.com www.rivafashion.com segment.api.useinsider.com hit.api.useinsider.com measurement-api.criteo.com tr6.snapchat.com static.sizebay.technology tr.snapchat.com js.checkout.com stats.g.doubleclick.net get.geojs.io sdk-02.moengage.com api.ipify.org api.allorigins.win bam.eu01.nr-data.net *.twitter.com carrier.useinsider.com unification.useinsider.com analytics.tiktok.com vfr-v3-production.sizebay.technology *.moengage.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.rivafashion.com www.google.com tr6.snapchat.com *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.rivafashion.com/; report-to report-endpoint; 1 font-src *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.authorize.net *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.gstatic.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.authorize.net *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.authorize.net *.google-analytics.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: 'unsafe-inline' 'unsafe-eval' data: 1 font-src *.fontawesome.com https://fonts.bunny.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.adobedtm.com *.feefo.com *.cookiebot.com *.hotjar.com *.google.co.in www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.adobedtm.com *.feefo.com *.cookiebot.com *.hotjar.com media.ltmuseumshop.co.uk *.google.co.in www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.plugins.emarsys.net *.scarabresearch.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.adobedtm.com *.feefo.com *.cookiebot.com *.hotjar.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.google.co.in www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.feefo.com *.google.co.in 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.scarabresearch.com *.eservice.emarsys.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.adobedtm.com *.feefo.com *.cookiebot.com *.hotjar.com *.doubleclick.net *.googleapis.com *.google-analytics.com *.google.co.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://online.flippingbook.com/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net *.easypack24.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.klarna.com https://geowidget-app.inpost.pl/ https://lilou-configurator.netlify.app exchange.mediavine.com ams.creativecdn.com tags.creativecdn.com *.criteo.com *.criteo.net facebook.com 'unsafe-inline' data: 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.trackedlink.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com static.payu.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.cdninstagram.com *.google.pl google.com google.pl *.criteo.com *.criteo.net https: data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com secure.payu.com secure.snd.payu.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://d3bo67muzbfgtl.cloudfront.net https://sentry.lilou.pl *.avada.io *.shopify.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.sentry-cdn.com exchange.mediavine.com unpkg.com *.mapbox.com furgonetka.pl *.hotjar.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.wp.pl *.clickonometrics.pl bat.bing.com tags.creativecdn.com ams.creativecdn.com lib.onet.pl sgqcvfjvr.onet.pl events.onet.pl events.ocdn.eu clarity.ms *.clarity.ms 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com cdngazeta.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com assets.braintreegateway.com *.klarnacdn.net https://d3bo67muzbfgtl.cloudfront.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.easypack24.net *.openstreetmap.org lilouparis.test lilou.test *.lilouparis.com *.lilou.pl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://api.edrone.me https://sentry.lilou.pl https://get.geojs.io *.avada.io *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.sentry-cdn.com *.wp.pl exchange.mediavine.com bat.bing.com bat.bing.net ams.creativecdn.com tags.creativecdn.com measurement-api.criteo.com api-s.edrone.me events.ocdn.eu *.googleadservices.com *.google.pl *.googletagmanager.com health.ems.onet.pl content.hotjar.io hotjar.com wss://ws.hotjar.com *.onet.pl analytics-ipv6.tiktokw.us *.gazeta.pl clk.leadexpert.pl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com bat.bing.com google.com exchange.mediavine.com www.googletagmanager.com tags.creativecdn.com ams.creativecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src 'report-sample' 'self' 'nonce-8b3319671c58f486ac15af6d61f5f927' 'sha256-Uar6/o6bHxLbvYdSPaAi9aPBl0o2QLBH4YZtTV7Yh9U=' *.forcloudcdn.com *.forter.com analytics.tiktok.com analytics.twitter.com app.link cdn.branch.io connect.facebook.net dkupaw9ae63a8.cloudfront.net googleads.g.doubleclick.net maps.googleapis.com sc-static.net static.ads-twitter.com tools.luckyorange.com tr.snapchat.com websdk.appsflyer.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.youtube.com; style-src 'self' 'unsafe-inline' *.forcloudcdn.com fonts.googleapis.com; connect-src https: wss:; img-src data: https:; font-src data: https:; frame-src 'self' bid.g.doubleclick.net bytedance: fordeal: sslocal: tr.snapchat.com tr6.snapchat.com www.facebook.com www.youtube.com; object-src 'none'; child-src 'self' blob:; base-uri 'none'; report-uri https://dot.fordeal.ae/api/csp-reports?who=client_customer&app=fordeal 1 default-src https: data: 'unsafe-inline' 'unsafe-eval' wss://*.hotjar.com blob: wss://*.hotjar.io blob:; report-uri https://fantastic.report-uri.com/r/d/csp/reportOnly 1 font-src *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com *.fontawesome.com www.nighthawkcustom.com fonts.gstatic.com pro.fontawesome.com fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.iubenda.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com cdn.userway.org *.authorize.net *.weltpixel.com *.doubleclick.net *.typeform.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com https://*.gstatic.com *.iubenda.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com www.nighthawkcustom.com nighthawkcustom.com yt3.ggpht.com www.gstatic.com phosphor.utils.elfsightcdn.com cdn.userway.org l.sharethis.com platform-cdn.sharethis.com *.facebook.com *.reddit.com *.google-analytics.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://*.gstatic.com *.iubenda.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net cdn.userway.org www.nighthawkcustom.com cs.iubenda.com cdn.iubenda.com static.klaviyo.com static.elfsight.com static-tracking.klaviyo.com www.google.com www.gstatic.com platform-api.sharethis.com buttons-config.sharethis.com *.authorize.net *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.typeform.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.googletagmanager.com *.fontawesome.com www.nighthawkcustom.com cdn.jsdelivr.net fonts.cdnfonts.com pro.fontawesome.com cdn.userway.org www.gstatic.com *.tagmanager.google.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.iubenda.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog region1.analytics.google.com www.nighthawkcustom.com fast.a.klaviyo.com static-forms.klaviyo.com core.service.elfsight.com idb.iubenda.com googleads.g.doubleclick.net api.userway.org jnn-pa.googleapis.com rr1---sn-gqn-jawz.googlevideo.com storage.elfsight.com cdn.userway.org cdn77.api.userway.org l.sharethis.com *.authorize.net *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.nighthawkcustom.com www.google.ro play.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.sandbox.paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://troquer.zendesk.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.sandbox.paypal.com *.paypalobjects.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://sealserver.trustwave.com *.zdassets.com https://diffuser-cdn.app-us1.com https://prism.app-us1.com https://api.smooch.io *.signifyd.com https://h64.online-metrix.net https://embed.typeform.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.sandbox.paypal.com *.paypalobjects.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com *.typeform.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://troquer.zendesk.com *.zdassets.com wss://api.smooch.io *.signifyd.com *.typeform.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.sandbox.paypal.com *.paypalobjects.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.creativecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-wZ8YwMsmVJLTypcb1ZoHRg' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com geowidget.easypack24.net fonts.gstatic.com *.tophifi.pl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.googlesyndication.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.google.com/ pay.google.com play.google.com *.autopay.eu *.weltpixel.com *.cookiebot.com *.cookiebot.eu creativecdn.com *.criteo.com td.doubleclick.net www.googletagmanager.com *.tophifi.pl tbs.tradedoubler.com www.youtube.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.magezon.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu https://*.openstreetmap.org *.google-analytics.com *.bing.com *.clarity.ms *.cookiebot.com *.usercentrics.eu *.g.doubleclick.net geowidget.easypack24.net www.facebook.com www.google.pl *.google.com *.googleapis.com pagead2.googlesyndication.com *.googletagmanager.com *.gstatic.com ssl.ceneo.pl *.tophifi.pl *.user.com *.facebook.com *.reddit.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com/ *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com cdn.jsdelivr.net analytics.ahrefs.com *.bing.com ssl.ceneo.pl *.clarity.ms static.cloudflareinsights.com *.cookiebot.com *.cookiebot.eu *.criteo.com dc.cux.io geowidget.easypack24.net connect.facebook.net *.google.com maps.googleapis.com www.gstatic.com ec.monplat-cdn.com *.tophifi.pl wrap.tradedoubler.com *.user.com wss://tophifi.user.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com *.autopay.eu *.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net geowidget.easypack24.net tagmanager.google.com fonts.googleapis.com googletagmanager.com *.tophifi.pl *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src video.cdninstagram.com *.user.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.google-analytics.com https://*.openstreetmap.org analytics.ahrefs.com *.clarity.ms *.cookiebot.com *.cookiebot.eu *.criteo.com *.g.doubleclick.net api-shipx-pl.easypack24.net www.facebook.com *.google.com *.googleapis.com pagead2.googlesyndication.com *.googletagmanager.com csr.onet.pl *.tophifi.pl tophifi.user.com wss://tophifi.user.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'nonce-fFmeRzfC-1TY9NfOcDcjuSnBvIGuAOUnLkaUTYKQP70_xuAR7GeyXg' 'wasm-unsafe-eval' https://matomo.ecchr.eu 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://imgsct.cookiebot.com https://*.gstatic.com https://*.googleapis.com https://*.google.com https://*.googleusercontent.com https://*.ggpht.com https://www.facebook.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://consentcdn.cookiebot.com https://newassets.hcaptcha.com https://loa.ecchr.eu/ https://loa-staging.ecchr.eu/ https://spenden.twingle.de/; worker-src 'self' blob:; script-src-elem 'self' 'unsafe-inline' https://consent.cookiebot.com https://consentcdn.cookiebot.com https://matomo.ecchr.eu https://connect.facebook.net https://*.googleapis.com https://js.hcaptcha.com https://spenden.twingle.de 'report-sample'; media-src 'self' data:; style-src-elem 'self' 'unsafe-inline' blob: https://*.googleapis.com https://*.gstatic.com 'report-sample'; connect-src data: https://consent.cookiebot.com https://consentcdn.cookiebot.com https://matomo.ecchr.eu/ https://newassets.hcaptcha.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://www.facebook.com; font-src 'self' data: https://fonts.gstatic.com; report-uri https://www.ecchr.eu/@http-reporting?csp=report&requestTime=1765935037758997&requestHash=bb64ec5153ea00b9f7618d7a84e0598826d91e5f 1 font-src fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net *.google.com/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://www.magezon.com https://images.unsplash.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.googletagmanager.com tagmanager.google.com js.klevu.com *.ksearchnet.com *.google.com/ roomle.com www.roomle.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com tagmanager.google.com fonts.google.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://cdn.consentmanager.net https://delivery.consentmanager.net form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.klevu.com *.ksearchnet.com roomle.com www.roomle.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://0194013f-df36-4016-80d8-7168d8f03fc1.sansec.watch/; report-to report-endpoint; 1 default-src 'self' https:; font-src 'self' https: data: https://fonts.googleapis.com https://fonts.gstatic.com https://kit.fontawesome.com https://rsms.me; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.quilljs.com https://unpkg.com https://cdnjs.cloudflare.com https://api.mapbox.com https://js.stripe.com https://s3.amazonaws.com/cdn.hellosign.com https://assets.calendly.com https://js.csvbox.io https://cdn.segment.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.rollbar.com https://x.clearbitjs.com https://widget.intercom.io https://code.upscope.io https://cdn.inspectlet.com https://rum-static.pingdom.net https://kit.fontawesome.com; style-src 'self' https: 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.quilljs.com https://cdnjs.cloudflare.com https://api.mapbox.com https://assets.calendly.com https://fonts.googleapis.com https://rsms.me; connect-src 'self' https: ws: wss: https://api.mixpanel.com https://cdn.segment.com https://api.rollbar.com https://ws.inspectlet.com https://hn.inspectlet.com https://api-iam.intercom.io https://*.csvbox.io https://*.hellosign.com; frame-src 'self' https: https://calendly.com https://*.csvbox.io https://*.hellosign.com https://www.googletagmanager.com https://www.youtube.com https://player.vimeo.com https://*.loom.com; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua 'self' data: data: *.magentocommerce.com *.zonos.com *.yotpo.com yotpo.com www.yotpo.com *.fontawesome.com *.authorize.net *.facebook.net *.facebook.com *.bootstrapcdn.com *.hubspot.com *.mailchimp.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com *.dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com xtento.com *.xtento.com *.cloudmaestro.com *.unpkg.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.sandbox.paypal.com *.paypal.com *.paypalobjects.com *.youtube.com *.apptrian.com www.apptrian.com *.vimeo.com *.use.typekit.net *.cloudfront.net *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com *.pinimg.com *.pinterest.com *.involve.me 'self' * data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.yotpo.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.iglobalstores.com *.authorize.net *.spreedly.com *.hubspot.com *.getbread.com paypal.com *.braintree-api.com *.addthis.com www.youtube.com *.online-metrix.net *.signifyd.com *.demdex.net *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.yotpo.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.g.doubleclick.net *.cloudmaestro.com vimeo.com *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com *.involve.me 'self' c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.google.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua 'self' data: *.magentocommerce.com *.zonos.com *.yotpo.com yotpo.com www.yotpo.com *.ytimg.com *.s3.amazonaws.com *.amazonaws.com *.klaviyo.com *.g.doubleclick.net *.hubspot.com *.authorize.net *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.signifyd.com *.e.aa.online-metrix.net *.bbb.org *.facebook.net *.facebook.com *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com *.secure.force.com *.mailchimp.com *.demdex.net *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com xtento.com *.xtento.com px.ads.linkedin.com bat.bing.com pippio.com *.cloudmaestro.com www.sandbox.paypal.com *.events.bouncex.net *.fls.doubleclick.net 11158761.fls.doubleclick.net tr2.smarterhq.io *.smarterhq.io js.authorize.net ssl.kaptcha.com *.kaptcha.com www.shareasale.com *.shareasale.com *.bouncex.net ciqtracking.com *.doubleclick.net *.pinimg.com *.pinterest.com *.involve.me 'self' * https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.cloudflare.com *.cloudflareinsights.com *.jsdelivr.net *.trustedshops.com *.usercentrics.eu *.cardinalcommerce.com *.ccdc02.com *.authorize.net *.spreedly.com *.zonos.com *.yotpo.com *.bootstrapcdn.com *.newrelic.com bam.nr-data.net *.nr-data.net *.zopim.com *.facebook.net *.facebook.com *.zdassets.com *.klaviyo.com *.zendesk.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com fast.a.klaviyo.com *.hubspot.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.cookielaw.org *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.onetrust.com paypal.com *.signifyd.com *.g.doubleclick.net *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com *.braintree-api.com chimpstatic.com *.mailchimp.com mc.us18.list-manage.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com undefined/api/v2/sites/74088/recordings/content unpkg.com *.unpkg.com *.cloudfront.net d1n00d49gkbray.cloudfront.net/wknd/wknd_cartridge.js tr2.smarterhq.io *.apptrian.com hello.zonos.com staticw2.yotpo.com brainmd.com stats.g.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.go2sdk.com ciqtracking.com *.doubleclick.net *.crazyegg.com *.tiktok.com *.convertcart.com *.havasedge.com *.criteo.com *.wknd.ai *.kaltura.com *.clickcease.com *.userway.org shop.pe *.shop.pe www.clarity.ms *.amazonaws.com *.olark.com *.ordergroove.com *.pinimg.com *.pinterest.com *.involve.me 'self' https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.magentocommerce.com *.zonos.com *.yotpo.com *.fontawesome.com getfirebug.com *.klaviyo.com *.bootstrapcdn.com *.authorize.net display.ugc.bazaarvoice.com *.signifyd.com *.facebook.net *.facebook.com *.mailchimp.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com www.sandbox.paypal.com *.fls.doubleclick.net 11158761.fls.doubleclick.net tr2.smarterhq.io *.smarterhq.io js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com *.involve.me 'self' * https://static.klaviyo.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.zdassets.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com *.yotpo.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net *.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com *.pinimg.com *.pinterest.com *.involve.me 'self' * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.google-analytics.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.authorize.net *.zonos.com *.yotpo.com *.cloudflare.com *.jsdelivr.net *.trustedshops.com *.usercentrics.eu *.facebook.net *.facebook.com *.newrelic.com bam.nr-data.net *.nr-data.net *.zopim.com *.zdassets.com *.klaviyo.com *.zendesk.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com fast.a.klaviyo.com *.hubspot.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.cookielaw.org *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.onetrust.com paypal.com *.signifyd.com *.g.doubleclick.net *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com chimpstatic.com *.mailchimp.com *.demdex.net *.tinymce.com cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com *.linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com undefined/api/v2/sites/74088/recordings/content unpkg.com *.unpkg.com *.cloudfront.net d1n00d49gkbray.cloudfront.net/wknd/wknd_cartridge.js tr2.smarterhq.io *.apptrian.com hello.zonos.com staticw2.yotpo.com brainmd.com stats.g.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net *.go2sdk.com ciqtracking.com *.doubleclick.net *.crazyegg.com *.tiktok.com *.convertcart.com *.havasedge.com *.criteo.com *.wknd.ai *.kaltura.com *.clickcease.com *.userway.org shop.pe *.shop.pe www.clarity.ms *.clarity.ms *.amazonaws.com *.olark.com *.ordergroove.com *.pinimg.com *.pinterest.com *.involve.me 'self' https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ o.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' data: https://cdn.rawgit.com https://fonts.gstatic.com https://ka-p.fontawesome.com https://pro.fontawesome.com https://www.erblearn.org https://fonts.typekit.net https://maxcdn.bootstrapcdn.com https://use.fontawesome.com https://cdn.jsdelivr.net; img-src * data:; script-src 'unsafe-eval' 'unsafe-inline' 'self' https://cdn.datatables.net https://cdn.erblearn.org https://cdn.jsdelivr.net https://code.jquery.com/jquery-3.5.1.min.js https://kit.fontawesome.com/8e16178960.js https://cdn.jsdelivr.net https://kit.fontawesome.com/3a3e8d3071.js https://www.googletagmanager.com/gtag/js https://use.fontawesome.com/cdc1a032d4.js http://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.7/umd/popper.min.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/4rwLQsl5N_ccppoTAwwwMrEN/recaptcha__en.js https://kendo.cdn.telerik.com/2021.3.1109/js/jszip.min.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://connect.facebook.net; style-src 'unsafe-inline' 'self' https://cdn.datatables.net https://cdn.erblearn.org https://cdn.rawgit.com https://fonts.googleapis.com https://pro.fontawesome.com https://fonts.typekit.net https://use.fontawesome.com https://kendo.cdn.telerik.com https://cdn.jsdelivr.net https://maxcdn.bootstrapcdn.com/ https://fast.fonts.net https://code.jquery.com; frame-src https://www.facebook.com https://player.vimeo.com; connect-src 'unsafe-inline' 'self' https://ka-p.fontawesome.com https://worldtimeapi.org https://www.google-analytics.com https://stats.g.doubleclick.net; 1 font-src *.bradfords.co.uk *.monetate.net *.gstatic.com https://*.typekit.net *.sagepay.com *.opayo.eu.elavon.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.sagepay.com *.opayo.eu.elavon.com *.stripe.com *.stripe.network *.google.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://*.doubleclick.net https://*.braintreegateway.com https://*.paypal.com https://*.laybuy.com https://*.trustpilot.com https://*.cookiebot.com https://*.affiliatefuture.com *.bradfords.co.uk https://*.google.com https://*.hotjar.com *.sagepay.com *.opayo.eu.elavon.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.paypal.com https://*.visualwebsiteoptimizer.com https://*.bazaarvoice.com https://*.laybuy.com https://*.bing.com https://*.cookiebot.com *.bradfords.co.uk *.monetate.net https://*.doubleclick.net https://*.google.co.uk https://*.cloudfront.net *.sagepay.com *.paypal.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com *.trackedlink.net *.stripe.com *.stripe.network www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://*.googleapis.com *.google.com https://www.gstatic.com https://*.cloudfront.net https://*.google-analytics.com https://*.doubleclick.net https://*.paypal.com https://*.trustpilot.com https://*.zdassets.com https://*.crazyegg.com https://*.prommt.com https://*.salesfire.co.uk https://smct.co https://*.smct.co https://*.convertize.io https://*.visualwebsiteoptimizer.com https://*.elfsight.com *.affiliatefuture.com https://*.cookiebot.com https://*.envolvetech.com https://*.clarity.ms https://*.bing.com https://*.elfsightcdn.com *.bradfords.co.uk *.monetate.net https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.hotjar.com https://secure.leadforensics.com *.sagepay.com *.opayo.eu.elavon.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com display.ugc.bazaarvoice.com https://*.cloudfront.net https://*.klevu.com https://*.prommt.com *.bradfords.co.uk *.monetate.net *.google.com https://*.typekit.net *.sagepay.com *.opayo.eu.elavon.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.cloudfront.net https://*.zdassets.com *.bradfords.co.uk 'self' 'unsafe-inline'; manifest-src *.bradfords.co.uk 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://*.freshdesk.com https://*.hotjar.com wss://*.hotjar.com https://*.googleapis.com wss://*.zopim.com https://*.google.com https://google.com https://*.salesfire.co.uk https://*.smartmetrics.co.uk https://*.zdassets.com https://*.zendesk.com https://*.appspot.com https://*.increasingly.co https://*.indicative.com https://*.googlesyndication.com https://*.google-analytics.com https://*.cookiebot.com https://*.elfsight.com https://core.service.elfsight.com https://*.bing.com https://*.clarity.ms https://*.bazaarvoice.com *.bradfords.co.uk *.monetate.net https://*.adobedc.net https://*.nr-data.net *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; object-src 'none'; connect-src 'self' https: https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https: https://www.googletagmanager.com; img-src 'self' https: https://www.googletagmanager.com https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com data:; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https: https://fonts.gstatic.com data:; script-src 'self' https: 'unsafe-eval' 'nonce-ubwRWynIenIscgoS8r39TQ=='; report-uri /csp_violations 1 default-src 'self'; base-uri 'self'; connect-src 'self' *.insight.sitefinity.com wss://*.hotjar.com *.hotjar.io dc.services.visualstudio.com www.google-analytics.com analytics.google.com *.analytics.google.com www.google.com/ccm/collect *.eloqua.com *.pingdom.net *.googleapis.com *.hsforms.com *.hubspot.com api.bing.microsoft.com media.imi.chat s.yimg.com; font-src 'self' data: media.imi.chat fonts.gstatic.com static.hsappstatic.net; frame-ancestors 'self'; form-action 'self' forms.hsforms.com; media-src 'self'; img-src 'self' data: i.vimeocdn.com www.google-analytics.com *.eloqua.com *.googleapis.com *.hsforms.com track.hubspot.com www.googletagmanager.com maps.gstatic.com ad.doubleclick.net www.google.com/pagead/ www.facebook.com/tr www.facebook.com/tr/ www.facebook.com/privacy_sandbox/ sp.analytics.yahoo.com; object-src 'none'; frame-src 'self' vimeo.com www.youtube.com *.hsforms.com media.imi.chat player.vimeo.com www.googletagmanager.com apis.google.com www.google.com/recaptcha/ td.doubleclick.net 8826991.fls.doubleclick.net; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com *.googleapis.com media.imi.chat use.fortawesome.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' az416426.vo.msecnd.net cdnjs.cloudflare.com *.googleapis.com www.google.com/recaptcha/ *.insight.sitefinity.com www.google-analytics.com media.imi.chat use.fortawesome.com *.eloqua.com www.youtube.com *.pingdom.net js.hubspot.com *.en25.com *.hotjar.com www.googletagmanager.com api.midmark.com apis.google.com www.gstatic.com js.hsforms.net js.hs-scripts.com js.hs-analytics.net js.hs-banner.com cdn.inpwrd.net origin.acuityplatform.com e.acuityplatform.com connect.facebook.net googleads.g.doubleclick.net s.yimg.com; worker-src 'self'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://midmark.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com https://*.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://www.facebook.com https://payflowlink.paypal.com https://www.mollie.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.nrcwebwinkel.nl https://www.facebook.com https://web.facebook.com https://bid.g.doubleclick.net https://payflowlink.paypal.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://td.doubleclick.net https://www.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com flagpedia.net https://www.mollie.com www.google.com.ua www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://imgsct.cookiebot.com https://imgsct.cookiebot.eu https://static-na.payments-amazon.com https://www.paypalobjects.com https://m.media-amazon.com https://bat.bing.com https://www.facebook.com https://www.google.com https://google.com https://www.google.co.in https://googleads.g.doubleclick.net *.fastcloudnetwork.com https://*.hotjar.com https://dev.visualwebsiteoptimizer.com https://load.sst.nrcwebwinkel.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com consent.cookiebot.com consentcdn.cookiebot.com consent.cookiebot.eu consentcdn.cookiebot.eu https://bat.bing.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://www.googletagmanager.com/ https://*.voyado.com https://*.hotjar.com https://*.redeal.se https://*.privacy-center.org/ https://www.mollie.com https://dev.visualwebsiteoptimizer.com https://js-agent.newrelic.com https://load.sst.nrcwebwinkel.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com https://*.hotjar.com https://*.voyado.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://consentcdn.cookiebot.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://consent.cookiebot.eu https://*.voyado.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://dev.visualwebsiteoptimizer.com https://www.mollie.com https://*.privacy-center.org https://bam.eu01.nr-data.net https://load.sst.nrcwebwinkel.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.girlsway.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.girlsway.com join.gammasecure.com; script-src 'self' *.girlsway.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.girlsway.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.klarnacdn.net *.klevu.com *.ksearchnet.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.iubenda.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.iubenda.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.klarna.com *.klarnacdn.net x.klarnacdn.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.iubenda.com *.klarnaservices.com js.klevu.com *.ksearchnet.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com tracking.trovaprezzi.it www.trovaprezzi.it https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.feedaty.com *.fontawesome.com downloads.mailchimp.com assets.braintreegateway.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.iubenda.com *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.frizbit.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com *.disqus.com *.avada.io *.oppwa.com oppwa.com *.peachpayments.com *.yotpo.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.frizbit.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net oppwa.com *.oppwa.com *.peachpayments.com *.yotpo.com *.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.frizbit.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net cdnstatic.edises.it cdn.edises.it *.cloudflare.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.tiktok.com cdnstatic.edises.it cdn.edises.it *.clarity.ms *.criteo.net *.criteo.com stats.g.doubleclick.net *.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com https://firebasestorage.googleapis.com *.tiktok.com cdnstatic.edises.it cdn.edises.it *.clarity.ms *.criteo.net *.criteo.com stats.g.doubleclick.net *.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com flagpedia.net blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io *.tiktok.com cdnstatic.edises.it cdn.edises.it *.clarity.ms *.criteo.net *.criteo.com stats.g.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com maps.googleapis.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com www.gstatic.com beacon.riskified.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net cdnstatic.edises.it cdn.edises.it *.cloudflare.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com https://get.geojs.io *.avada.io *.tiktok.com cdnstatic.edises.it cdn.edises.it *.clarity.ms *.criteo.net *.criteo.com stats.g.doubleclick.net *.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com www.google.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.hotjar.com *.typekit.net https://static.klaviyo.com *.tawk.to https://nibble.website https://*.nibble.website https://*.preprod.nibble.website https://fonts.gstatic.com https://fonts.googleapis.com *.salesfire.co.uk *.klarnacdn.net fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.hotjar.com *.salesfire.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ bat.bing.com *.ads.linkedin.com *.linkedin.com embed.tawk.to https://nibble.website https://*.nibble.website https://*.preprod.nibble.website www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk *.commerce-connector.com *.salesfire.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.linkedin.com *.smartmetrics.co.uk *.salesfire.co.uk *.bing.com *.hotjar.com *.trustpilot.com *.tawk.to https://nibble.website https://*.nibble.website https://*.preprod.nibble.website js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net *.pcapredict.com https://www.commerce-connector.com *.commerce-connector.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.typekit.net *.trustpilot.com *.tawk.to https://nibble.website https://*.nibble.website https://*.preprod.nibble.website https://fonts.gstatic.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com services.postcodeanywhere.co.uk *.salesfire.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://nibble.website https://*.nibble.website https://*.preprod.nibble.website 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ bat.bing.com *.salesfire.co.uk *.hotjar.io *.smartmetrics.co.uk *.linkedin.com *.pingdom.net *.tawk.to wss://*.tawk.to https://nibble.website https://*.nibble.website https://*.preprod.nibble.website api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.klimaworld.com *.trustedshops.com *.fontawesome.com *.gstatic.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klimaworld.com img.idealo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.magezon.com *.trustedshops.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.facebook.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com challenges.cloudflare.com *.klimaworld.com *.doofinder.com *.iadvize.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustedshops.com cdnjs.cloudflare.com *.disqus.com *.googletagmanager.com *.facebook.net *.google.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.klimaworld.com *.doofinder.com unsafe-inline assets.braintreegateway.com *.trustedshops.com *.fontawesome.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klimaworld.com *.doofinder.com *.iadvize.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.trustedshops.com *.google-analytics.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.trustedshops.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com data: *.fontawesome.com *.azureedge.net *.oct8ne.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com ecommerce.raiffeisen.al *.upc.ua 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com *.instagram.com www.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.addtoany.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com *.googleapis.com *.cdninstagram.com *.trackedlink.net magefan.com cm.magefan.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.disqus.com *.cloudflare.com *.amazonaws.com *.facebook.com *.doubleclick.net *.pinterest.com *.taboola.com r1-t.trackedlink.net *.azureedge.net oct8necdneu.azureedge.net *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://bank.paysera.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com connect.facebook.net *.googleapis.com *.gstatic.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.disqus.com *.cloudflare.com *.doubleclick.net *.facebook.net *.addtoany.com *.oct8ne.com *.taboola.com js.klevu.com *.ksearchnet.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net *.addtoany.com maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.doubleclick.net *.facebook.com *.oct8ne.com *.gstatic.com *.cloudflare.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io http://dpm.demdex.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.vivid.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.vivid.com join.gammasecure.com; script-src 'self' *.vivid.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.vivid.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 style-src 'self' 'unsafe-inline' https://engine.styla.com https://fast.fonts.net https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://delivery-assets.squarelovin.com https://fonts.googleapis.com https://cdn.parcellab.com https://www.gstatic.com https://cdn.behamics.com; connect-src 'self' https://*.strellson.com https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.kameleoon.io https://*.kameleoon.eu https://blackbit-styla.s3.eu-central-1.amazonaws.com https://*.styla.com https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://tracking-api.squarelovin.com https://www.paypal.com https://*.adyen.com https://*.clarity.ms https://ad.doubleclick.net https://*.bing.com https://*.bing.net https://ct.pinterest.com https://px.ads.linkedin.com https://ib.adnxs.com/pixie/up https://www.facebook.com https://connect.facebook.net https://*.hotjar.io wss://ws.hotjar.com https://analytics.tiktok.com https://google.com https://*.google.com https://*.analytics.google.com https://*.googleapis.com https://api.parcellab.com https://bt.fraud0.com https://recommender.scarabresearch.com https://in.hotjar.com https://*.behamics.com; base-uri 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; object-src 'none'; worker-src 'self' https://strellson.com https://*.strellson.com blob:; frame-src 'self' https://strellson.com https://*.strellson.com https://app.usercentrics.eu https://web.cmp.usercentrics.eu https://player.vimeo.com https://www.google.com https://td.doubleclick.net https://*.fls.doubleclick.net https://pay.google.com https://www.paypal.com https://*.adyen.com https://*.global-e.com https://www.facebook.com https://bat.bing.com; media-src 'self' https://strellson.com https://*.strellson.com data: https://styla-prod-us.imgix.net https://cdn.kameleoon.com https://cdn-vid.squarelovin.com; frame-ancestors 'self' https://strellson.com https://*.strellson.com; img-src 'self' https://strellson.com https://*.strellson.com blob: data: https://www.googletagmanager.com https://*.analytics.google.com https://*.google.com https://www.google.ch https://www.google.de https://www.google.fr https://www.google.at https://www.google.pt https://www.google.hu https://www.google.it https://www.google.ee https://www.google.pl https://www.google.lt https://www.google.hr https://www.google.co.uk https://www.google.nl https://www.google.be https://stats.g.doubleclick.net https://www.googleadservices.com https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.api.service.cmp.usercentrics.eu https://styla-prod-us.imgix.net https://s3.global-e.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://cdn.squarelovin.com https://cdn-vid.squarelovin.com https://*.adyen.com https://*.cdn.adyen.com https://*.clarity.ms https://*.hotjar.com https://www.paypalobjects.com https://icons.parcellab.com https://www.gstatic.com https://fast.fonts.net https://*.bing.com https://*.bing.net https://ad.doubleclick.net https://googleads.g.doubleclick.net https://*.google-analytics.com https://*.vimeocdn.com https://www.facebook.com https://ib.adnxs.com https://px.ads.linkedin.com https://secure.adnxs.com https://lantern.roeye.com https://static.kameleoon.com https://icons.parcellab.com https://bt.fraud0.com https://analytics.tiktok.com; default-src 'self' https://strellson.com https://*.strellson.com; font-src 'self' data: https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://fast.fonts.net https://fonts.gstatic.com https://s3.global-e.com https://script.hotjar.com; report-uri https://strellson.com/csp/report; report-to csp-endpoint; 1 default-src 'self' https:; font-src 'self' use.typekit.net/af/ d1p8b7m2zl7a4f.cloudfront.net d2e0vf92j9kzr0.cloudfront.net/ cdn.myalex.com/ localhost:* host.docker.internal:* data:; img-src 'self' https: d2e0vf92j9kzr0.cloudfront.net/ d1p8b7m2zl7a4f.cloudfront.net cdn.usersnap.com/classic/ localhost:* host.docker.internal:* data:; object-src 'none'; script-src 'self' https: d2e0vf92j9kzr0.cloudfront.net/ d1p8b7m2zl7a4f.cloudfront.net cdn.usersnap.com/classic/ chat.myalex.com/widget.js localhost:* host.docker.internal:* 'unsafe-eval' 'unsafe-inline'; style-src 'self' https: localhost:* host.docker.internal:* p.typekit.net/p.css d2e0vf92j9kzr0.cloudfront.net/ data: d1p8b7m2zl7a4f.cloudfront.net use.typekit.net/nwy7lbs.css cdn.myalex.com/ 'unsafe-inline'; frame-src 'self' https: login.myalex.com localhost:* host.docker.internal:* chat.datatrough.com/; connect-src 'self' https: localhost:* host.docker.internal:* ingest-dev.jellydevs.com/ data: audio.myalex.com/ d2e0vf92j9kzr0.cloudfront.net d1p8b7m2zl7a4f.cloudfront.net; media-src 'self' https: d1p8b7m2zl7a4f.cloudfront.net d2e0vf92j9kzr0.cloudfront.net/; report-uri https://picwell.sentry.io/projects/alex-api/?issuesType=all&project=4506039022583808 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net *.ascompany.gr *.channelsight.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.magedeploy.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.vivapayments.com *.twitter.com *.magedeploy.com *.ascompany.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ascompany.gr *.cookiebot.com *.contactpigeon.com www.googletagmanager.com *.twitter.com *.magedeploy.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com *.ascompany.gr *.contactpigeon.com *.google.gr *.cookiebot.com *.hsforms.net *.hsforms.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.magedeploy.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.vivapayments.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.ascompany.gr *.contactpigeon.com 'self' data: *.cookiebot.com *.channelsight.com js.monitor.azure.com analytics.tiktok.com *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com *.magedeploy.com *.unpkg.com cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net *.ascompany.gr *.channelsight.com *.contactpigeon.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.magedeploy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com www.facebook.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.ascompany.gr *.contactpigeon.com maps.googleapis.com stats.g.doubleclick.net *.cookiebot.com dc.services.visualstudio.com *.channelsight.com analytics.tiktok.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.twimg.com *.magedeploy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-7dbeabe1ce20789f28c7d397fd531f4214c57a2a7d93dca1ffc0e926e9f83e2a' assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com www.xtento.com cdn.xtento.com secure.payu.com secure.snd.payu.com https://cdnjs.cloudflare.com *.packeta.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl *.facebook.net *.allekurier.pl *.hsforms.net *.hsforms.com *.gstatic.com 'self' *.trustpilot.com 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8=' 'sha256-F20iqiqGicuuiFlhCPv0sBKJFT9sCplzelbf57o8GsI=' 'sha256-syV/eNOnvdKZkC4mI0Qgl6a+j1+UDhVcxAdH9K2eMUw='; style-src *.adobe.com fonts.googleapis.com *.autopay.eu *.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.typekit.net *.gstatic.com 'self' 'unsafe-inline' *.trustpilot.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu www.xtento.com cdn.xtento.com static.payu.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.przelewy24.pl gstatic.com puccini.pl *.puccini.pl puccini.cz *.puccini.cz puccini.hu *.puccini.hu puccini.ro *.puccini.ro puccini.sk *.puccini.sk puccini.ua *.puccini.ua *.allekurier.pl *.wittchen.com *.hsforms.net *.hsforms.com 'self' data: 'self'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com secure.payu.com merch-prod.snd.payu.com *.packeta.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self'; media-src *.adobe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com play.google.com *.autopay.eu www.xtento.com secure.payu.com merch-prod.snd.payu.com *.dhl.pl *.dhl24.com.pl *.packeta.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * apm.przelewy24.pl *.googletagmanager.com 'self' *.trustpilot.com; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: 'self'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com 'self'; frame-ancestors pay.google.com; object-src 'self'; 1 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://code.highcharts.com https://use.typekit.net https://www.google-analytics.com https://analytics.google.com https://ssl.google-analytics.com https://platform.twitter.com https://www.googletagmanager.com https://default.salsalabs.org https://*.salsalabs.org https://code.jquery.com https://device.maxmind.com https://*.dwcdn.net https://datawrapper.dwcdn.net https://*.googleapis.com; connect-src 'self' https://analytics.google.com https://*.google-analytics.com https://*.doubleclick.net https://*.mmapiws.com https://device.maxmind.com https://*.salsalabs.org; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com https://nycfuture.org https://*.nycfuture.org https://www.google.co.kr https://syndication.twitter.com https://p.typekit.net https://*.google.com; style-src 'self' https://use.typekit.net https://p.typekit.net https://code.jquery.com https://fonts.googleapis.com https://default.salsalabs.org; font-src 'self' https://use.typekit.net https://fonts.gstatic.com https://default.salsalabs.org data:; frame-src 'self' https://www.youtube.com https://platform.twitter.com https://datawrapper.dwcdn.net; form-action 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; report-uri /csp-report.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.bootstrapcdn.com js.klevu.com *.finance-calculator.co.uk *.klarnacdn.net *.klevu.com *.ksearchnet.com *.magentocommerce.com *.googleapis.com *.cloudfront.net fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com *.paypal.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com https://plumrocket.com www.facebook.com 1merchantacsstag.cardinalcommerce.com payments.securetrading.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.instagram.com https://www.google.com *.doubleclick.net *.facebook.com assets.braintreegateway.com tst.kaptcha.com c.paypal.com www.paypalobjects.com *.zopim.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.finance-calculator.co.uk *.deko.finance *.dekopay.com *.dekopay.org *.klarnacdn.net https://plumrocket.com *.magentocommerce.com cdn.dnky.co *.hotjar.com www.facebook.com *.trustpilot.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud x.klarnacdn.net *.pinterest.com *.pinterdev.com commerce-app.pintergration.com webservices.securetrading.net cdn.eu.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cdninstagram.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bing.com *.clarity.ms js.klevu.com cdn-cookieyes.com *.trackedlink.net *.finance-calculator.co.uk *.dekopay.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.magentocommerce.com *.cloudfront.net https://*.gstatic.com www.google.nl connect.onlinesucces.nl px.ads.linkedin.com *.googleapis.com www.linkedin.com linkedin.com gallery.mailchimp.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.instagram.com 'self' *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com bat.bing.com js.klevu.com *.clarity.ms c.paypal.com chimpstatic.com cdn-cookieyes.com *.hotjar.com sentry.bigeyedeers.dev browser.sentry-cdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.finance-calculator.co.uk *.dekopay.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com *.magentocommerce.com *.cloudfront.net maps.googleapis.com *.increasingly.co *.increasingly.com *.googleapis.com cdn.dnky.co api.comapi.com snap.licdn.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com www.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net www.googleoptimize.com *.paypal.com js.klarna.com *.eu-library.klarnaservices.com/lib.js *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.mouseflow.com *.webgains.io https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com player.vimeo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://apis.google.com webservices.securetrading.net cdn.eu.trustpayments.com songbirdstag.cardinalcommerce.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.bootstrapcdn.com *.typekit.net js.klevu.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com 'self' *.magentocommerce.com *.cloudfront.net cdn.dnky.co *.fontawesome.com *.mailchimp.com *.finance-calculator.co.uk *.trustpilot.com cdn.jsdelivr.net *.paypal.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co https://fonts.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com *.zopim.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.sandbox.braintree-api.com *.clarity.ms *.cookieyes.com cdn-cookieyes.com *.doubleclick.net *.trustpilot.com *.hotjar.com *.googlesyndication.com sentry.bigeyedeers.dev *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.finance-calculator.co.uk *.dekopay.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.cloudfront.net *.magentocommerce.com commerce.adobedc.net api.comapi.com *.googleapis.com *.zdassets.com *.hotjar.io *.zopim.com wss://*.zopim.com www.feedbackcompany.com *.zendesk.com *.eu-library.klarnaservices.com/lib.js *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com o402164.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.cembrapay.ch cembrapay.ch 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.cembrapay.ch cembrapay.ch landofcoder.com maps.googleapis.com chart.googleapis.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com test.saferpay.com www.saferpay.com saferpay.com ai.stoeckli.ch red-mud-07164bb03-test.westeurope.5.azurestaticapps.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net https://www.magezon.com cembrapay.ch www.cembrapay.ch www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://rum.hlx.page www.cembrapay.ch cembrapay.ch landofcoder.com maps.googleapis.com chart.googleapis.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com *.googletagmanager.com tagmanager.google.com https://7258763.collect.igodigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.cembrapay.ch cembrapay.ch landofcoder.com maps.googleapis.com chart.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com ai.stoeckli.ch red-mud-07164bb03-test.westeurope.5.azurestaticapps.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.cembrapay.ch cembrapay.ch test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.affirm.com *.affirm.ca *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io *.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com stats.addtoany.com www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com stagescycling.com *.stagescycling.com *.bing.com *.clarity.ms *.cloudflare.com data: *.freshworks.com *.google.co.uk google.com *.googleapis.com *.googleusercontent.com googletagmanager.com tagmanager.google.com about: *.klaviyo.com *.sleeknote.com *.googleadservices.com *.pinterest.com *.pinimg.com *.termly.io www.google.it 'self' 'unsafe-inline'; report-uri https://stagescycling.com/en_us/csp_report_watch; child-src *.certcapture.com stagescycling.com *.stagescycling.com *.cloudflare.com *.youtube.com *.google.co.uk *.google.com google.com *.gstatic.com *.googleapis.com *.googleusercontent.com *.doubleclick.net *.googlesyndication.com www.googletagmanager.com googletagmanager.com tagmanager.google.com data: blob: *.arcot.com *.pinterest.com *.pinimg.com http: https: blob: 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com acsbapp.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com payflowlink.paypal.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com *.google.com *.braintreegateway.com *.paypal.com google.com www.googletagmanager.com *.certcapture.com *.dotdigital-pages.com *.dotdigital.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com d1l7z5ofrj6ab8.cloudfront.net payflowlink.paypal.com googleads.g.doubleclick.net data: *.google.co.in *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.certcapture.com *.trackedlink.net *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.keekaroo.com *.specialtomato.com *.adaptivemall.com *.adaptivemall.ca app.certcapture.com nxtuploads.s3.amazonaws.com i.imgur.com verify.authorize.net *.bizrate.com blob: *.bing.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com fonts.gstatic.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.nextopia.net *.ecomm-nav.com www.gstatic.com www.google.com checkout.getbread.com app.certcapture.com www.adaptivemall.com staging.adaptivemall.com vector.nextopiasoftware.com verify.authorize.net bat.bing.com js-agent.newrelic.com connect.facebook.net d1l7z5ofrj6ab8.cloudfront.net *.bizrate.com bam.nr-data.net *.googleadservices.com acsbapp.com https://cdn.searchspring.net/intellisuggest/is.min.js *.googletagmanager.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.nextopia.net *.ecomm-nav.com fonts.gstatic.com maxcdn.bootstrapcdn.com app.certcapture.com *.bizrate.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com app.certcapture.com happyfoxchat.com bam.nr-data.net *.bizrate.com stats.g.doubleclick.net cdn.acsbapp.com acsbapp.com https://beacon.searchspring.io/beacon *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.nextopia.net *.ecomm-nav.com fonts.gstatic.com fonts.googleapis.com checkout.getbread.com www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net bat.bing.com app.certcapture.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.linkedin.com linkedin.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com 'self'; frame-src bid.g.doubleclick.net youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com landofcoder.com www.paypal.com www.sandbox.paypal.com www.youtube.com *.hotjar.com *.google.com www.facebook.com www.linkedin.com linkedin.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com youtube.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.hsforms.net *.hsforms.com 'self' data: fpdbs.paypal.com fpdbs.sandbox.paypal.com s.ytimg.com t.paypal.com www.google-analytics.com www.paypal.com www.paypalobjects.com px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com www.linkedin.com linkedin.com googletagmanager.com www.facebook.com master-7rqtwti-mnyjem72y4b5c.eu-5.magentosite.cloud img.youtube.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ landofcoder.com *.disqus.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com js.braintreegateway.com t.paypal.com video.google.com www.paypal.com www.paypalobjects.com www.sandbox.paypal.com google.com www.google.com gstatic.com www.gstatic.com *.googleapis.com *.hotjar.com *.fontawesome.com connect.facebook.net apis.google.com www.linkedin.com linkedin.com platform.linkedin.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com *.googleapis.com *.gstatic.com *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com landofcoder.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.fontawesome.com www.google-analytics.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.clickdimensions.com *.permaleads.ch *.mouseflow.com *.smart-business-intuition.com *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'unsafe-inline' 'self' data:; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' cloud.typography.com cdn.cookielaw.org cdn.jsdelivr.net js-agent.newrelic.com *.google-analytics.com munchkin.marketo.net *.nbme.org https://qvdt3feo.com/ *.qvdt3feo.com *.googletagmanager.com snap.licdn.com *.vimeocdn.com *.mktoutil.com *.verasafe.com *.hotjar.com *.facebook.net *.doubleclick.net verasafe.com *.google.com *.gstatic.com *.cloudflare.com tags.srv.stackadapt.com srv.stackadapt.com ap.srv.stackadapt.com east.srv.stackadapt.com uw.srv.stackadapt.com eu.srv.stackadapt.com player.vimeo.com https://unpkg.com/; script-src-elem 'self' 'unsafe-inline' 'wasm-unsafe-eval' cloud.typography.com cdn.cookielaw.org cdn.jsdelivr.net js-agent.newrelic.com *.google-analytics.com munchkin.marketo.net *.nbme.org https://qvdt3feo.com/ *.qvdt3feo.com *.googletagmanager.com snap.licdn.com *.vimeocdn.com *.mktoutil.com *.verasafe.com *.hotjar.com *.facebook.net *.doubleclick.net verasafe.com *.google.com *.gstatic.com *.cloudflare.com tags.srv.stackadapt.com srv.stackadapt.com ap.srv.stackadapt.com east.srv.stackadapt.com uw.srv.stackadapt.com eu.srv.stackadapt.com player.vimeo.com https://unpkg.com/; style-src 'self' 'unsafe-inline' cloud.typography.com *.pantheonsite.io *.nbme.org *.verasafe.com *.hotjar.com *.facebook.net *.doubleclick.net *.stackadapt.com *.gstatic.com *.cloudflare.com *.google.com fonts.googleapis.com googletagmanager.com tags.srv.stackadapt.com https://unpkg.com/; img-src 'self' 'unsafe-inline' data: *.truste.com *.linkedin.com cdn.cookielaw.org *.stackadapt.com tags.srv.stackadapt.com *.google-analytics.com *.googletagmanager.com *.vimeocdn.com *.verasafe.com *.hotjar.com *.facebook.net *.doubleclick.net *.facebook.com *.gstatic.com *.google.com *.googleadservices.com *.googleads.g.doubleclick.net *.google.co *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; frame-src 'unsafe-inline' player.vimeo.com *.youtube.com *.nbme.org *.pantheonsite.io *.googletagmanager.com *.google.com *.gstatic.com *.facebook.com; font-src 'self' 'unsafe-inline' data: *.typography.com *.gstatic.com *.cloudflare.com *.google.com use.typekit.net; connect-src 'self' *.nbme.org cdn.cookielaw.org privacyportal.onetrust.com bam.nr-data.net *.mktoresp.com px.ads.linkedin.com *.google-analytics.com *.onetrust.com *.mktoutil.com *.hotjar.com *.facebook.com *.googleadservices.com vc.hotjar.io ws.hotjar.com *.hotjar.io *.google.com wss://ws.hotjar.com *.googletagmanager.com www.google.com *.conversionsapigateway.com tags.srv.stackadapt.com srv.stackadapt.com ap.srv.stackadapt.com east.srv.stackadapt.com uw.srv.stackadapt.com eu.srv.stackadapt.com *.a.run.app player.vimeo.com *.verasafe.com; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com https://www.magezon.com *.klarna.com *.sargarme.com *.awd-it.co.uk *.google.com *.google.co.uk *.facebook.com *.dycdn.net *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com *.adobe.io magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.net *.klarna.com *.klarnaservices.com *.webgains.io instant.page webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com cdn.jsdelivr.net cdnjs.cloudflare.com *.klarnacdn.net x.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.klarnacdn.net webchat.dotdigital.com webchat.staging.dotdigital.com cdn.jsdelivr.net cdnjs.cloudflare.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.imgur.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnaservices.com *.doubleclick.net *.smartmetrics.co.uk webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net *.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e123f666-3955-4cf2-a104-3830ab3a94ec.sansec.watch/; report-to report-endpoint; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-VelTv4L9xFchib_hqx9fgQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-/qBCps8hqM/DP2ctgxA96YKnU5g=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline' static.klaviyo.com bat.bing.com giantmicrobes.com *.giantmicrobes.com *.stripecdn.com klarna.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://www.youtube.com https://www.youtube-nocookie.com https://*.cloudfront.net js.stripe.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.tiktok.com *.certcapture.com js.stripe.com *.google.ca *.google.com.eg analytics.google.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline' *.attn.tv portal.brandlock.io giantmicrobes.attn.tv t.co *.t.co analytics.twitter.com facebook.com *.facebook.com bat.bing.com giantmicrobes.com *.giantmicrobes.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.tiktok.com *.certcapture.com s.pinimg.com cdn.ywxi.net seal.godaddy.com *.jst.ai aly.jst.ai my.jst.ai connect.facebook.net static.cloudflareinsights.com *.dwin1.com *.bing.com *.fontawesome.com cdn.attn.tv static.ads-twitter.com static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com https://a.klaviyo.com https://telemetrics.klaviyo.com/ portal.brandlock.io d3uz7fhqos37j7.cloudfront.net ct.pinterest.com *.google.com.eg giantmicrobes.attn.tv bat.bing.com 'self' 'unsafe-inline' giantmicrobes.com *.giantmicrobes.com https://static.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline' giantmicrobes.com *.giantmicrobes.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.tiktok.com *.certcapture.com aly.jst.ai s3-us-west-2.amazonaws.com connect.facebook.net *.pinterest.com *.cloudflareinsights.com www.google-analytics.com analytics.google.com *.google.com.eg static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com https://a.klaviyo.com https://telemetrics.klaviyo.com/ ekr.zdassets.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.authorize.net *.cardinalcommerce.com *.stripe.com klarna.com *.klarnacdn.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net portal.brandlock.io bat.bing.com events.attentivemobile.com stats.g.doubleclick.net *.attn.tv giantmicrobes.attn.tv 'self' 'unsafe-inline' giantmicrobes.com *.giantmicrobes.com https://static.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ api.braintreegateway.com assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.fontawesome.com https://assets.brevo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.sibforms.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io https://*.herder.cat https://cdn.dev.herder.cat https://cdn.stag.herder.cat https://cdn.herdereditorial.com *.twitter.com *.facebook.com google.es *.google.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net blob: https://www.googletagmanager.com https://*.google-analytics.com https://*.herder.cat https://cdn.dev.herder.cat https://cdn.stag.herder.cat https://cdn.herdereditorial.com https://sibforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.facebook.net *.ads-twitter.com sibautomation.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com blob: *.herder.cat store.dev.herder.cat store.stag.herder.cat *.herdereditorial.com https://*.herder.cat https://store.dev.herder.cat https://store.stag.herder.cat https://*.herdereditorial.com *.fontawesome.com https://sibforms.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io https://*.google-analytics.com https://*.herder.cat https://cdn.dev.herder.cat https://cdn.stag.herder.cat https://cdn.herdereditorial.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com in-automate.brevo.com facebook.com *.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.onetrust.com *.lively.li *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com/tr/ *.webengage.com *.webengage.co *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.freshchat.com https://www.facebook.com *.trustpilot.com https://caratlane.demdex.net *.google.com *.criteo.com/ *.rudderstack.com *.rudderlabs.com *.webengage.com *.webengage.co *.lively.li wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.zego.im *.coolzcloud.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * speedsize.com *.speedsize.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.caratlane.us *.caratlane.com *.webengage.com *.webengage.co *.google.co.in *.google.com *.bing.com *.adsrvr.org *.pinterest.com wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.cloudfront.net *.aralego.net *.bidswitch.net *.criteo.com *.media.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.yahoo.net *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.adgrx.com *.adnxs.com *.yieldmo.com *.clmbtech.com *.smaato.net *.pubmatic.com *.outbrain.com *.rlcdn.com *.360yield.com *.doubleclick.net *.stickyadstv.com *.aralego.com *.lively.li *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.s3.ap-south-1.amazonaws.com *.adform.net *.zego.im *.coolzcloud.com *.klarnacdn.net *.klarna.com *.steelhousemedia.com *.1rx.io *.clarity.ms *.mediawallahscript.com *.omnitagjs.com *.dmxleo.com *.liadm.com *.mediavine.com *.postrelease.com *.revcontent.com *.sharethrough.com *.tapad.com *.tremorhub.com *.bluekai.com *.agkn.com *.tpmn.co.kr *.emxdgt.com *.unrulymedia.com *.krxd.net *.stackadapt.com *.cookielaw.org *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com speedsize.com *.speedsize.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.freshchat.com *.gstatic.com *.facebook.com *.trustpilot.com *.criteo.com *.criteo.net https://bam.nr-data.net *.google.com https://maps.googleapis.com https://maps.googleapis.com/maps-api-v3/api/js/46/8/intl/en_gb/common.js https://maps.googleapis.com/maps-api-v3/api/js/46/8/intl/en_gb/util.js https://www.google.com/recaptcha/api2/webworker.js *.caratlane.com *.rudderstack.com *.rudderlabs.com *.webengage.com *.webengage.co *.mountain.com *.bing.com *.clarity.ms *.lively.li *.pinimg.com *.stackadapt.com https://qvdt3feo.com *.klarnaservices.com *.klarna.com wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.zego.im *.coolzcloud.com *.attn.tv *.hotjar.com https://static.hotjar.com http://ipinfo.io *.googleapis.com *.pinterest.com *.onetrust.com *.cookielaw.org *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.googletagmanager.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.freshchat.com *.webengage.com *.webengage.co *.stackadapt.com *.lively.li *.klarnacdn.net wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.zego.im *.coolzcloud.com *.amazonaws.com *.onetrust.com *.google.com *.fontawesome.com unsafe-inline assets.braintreegateway.com speedsize.com *.speedsize.com *.trustpilot.com 'self' 'unsafe-inline'; object-src *.caratlane.us 'self' 'unsafe-inline'; media-src *.adobe.com *.caratlane.us *.lively.li wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.zego.im *.coolzcloud.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.freshchat.com *.doubleclick.net https://www.facebook.com https://bam.nr-data.net https://sslwidget.criteo.com/event https://widget.us.criteo.com/event *.caratlane.com *.rudderstack.com *.rudderlabs.com *.webengage.com *.webengage.co *.caratlane.us *.stackadapt.com *.clarity.ms *.googleapis.com *.criteo.com *.mountain.com *.pinterest.com *.facebook.net wss://253ul4moik.execute-api.ap-south-1.amazonaws.com *.klarnaevt.com *.klarna.com *.lively.li *.execute-api.ap-south-1.amazonaws.com *.webflow.com *.gumlet.io *.coolzcloud.com wss://accesshub-wss.coolzcloud.com *.zego.im wss://accesshub-wss.zego.im *.zegocloud.com wss://accesshub-wss.zegocloud.com wss://weblogger1793642705-api.coolzcloud.com *.amazonaws.com *.us-global-uscl.s3.us-east-2.amazonaws.com *.us-global-uscl.s3.amazonaws.com *.attn.tv *.attentivemobile.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.klarnaservices.com *.trustpilot.com *.onetrust.com cdn.cookielaw.org *.stripe.com klarna.com *.klarnacdn.net *.device.stripe-terminal-local-reader.net:4443/protojsonservice/JackRabbitService *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://maps.googleapis.com https://maps.gstatic.com imgsct.cookiebot.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com consent.cookiebot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://www.googletagmanager.com https://*.cloudfront.net https://static.hotjar.com https://bat.bing.com/bat.js https://js.hs-scripts.com https://*.fs1.hubspotusercontent-na1.net https://script.hotjar.com https://static.hsappstatic.net https://tracking.g2crowd.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hsleadflows.net https://js.hubspot.com https://bat.bing.com https://www.google-analytics.com https://snap.licdn.com https://cdn2.hubspot.net https://code.jquery.com https://js.zi-scripts.com 'strict-dynamic' 'nonce-VopJGpv1JgGjmVAT9kZmvw=='; style-src 'self' 'unsafe-inline' https://cdn2.hubspot.net/ https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://273774.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com https://7052064.fs1.hubspotusercontent-na1.net; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com https://cdn2.hubspot.net https://maxcdn.bootstrapcdn.com https://info.juicetactics.com; img-src 'self' https://no-cache.hubspot.com https://cdn2.hubspot.net https://cdnjs.cloudflare.com https://info.juicetactics.com https://bat.bing.com https://px.ads.linkedin.com https://forms-na1.hsforms.com https://perf.hsforms.com https://forms-na1.hsforms.com https://www.google-analytics.com https://perf-na1.hsforms.com https://track.hubspot.com https://www.google.com https://assets.capterra.com https://*.fs1.hubspotusercontent-na1.net https://fs.hubspotusercontent00.net https://f.hubspotusercontent00.net https://www.googletagmanager.com https://forms.hubspot.com; frame-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com https://cdn2.hubspot.net https://maxcdn.bootstrapcdn.com https://td.doubleclick.net/ https://platform.twitter.com/ https://meetings.hubspot.com/ https://play.hubspotvideo.com/ https://www.g2.com/ https://www.youtube.com/ https://forms.hsforms.com https://forms.hubspot.com; child-src; connect-src 'self' blob: https://settings.luckyorange.net https://app.hubspot.com https://cta-service-cms2.hubspot.com https://px.ads.linkedin.com wss://ws.hotjar.com https://content.hotjar.io https://cta-service-cms2.hubspot.com https://js.hs-banner.com https://px.ads.linkedin.com https://pagead2.googlesyndication.com https://www.google-analytics.com https://forms.hubspot.com https://api.hubapi.com https://analytics.google.com https://www.google.com https://googleads.g.doubleclick.net https://forms-na1.hubspot.com https://metrics.hotjar.io https://bat.bing.com https://tracking.g2crowd.com https://stats.g.doubleclick.net https://forms.hsforms.com https://js.zi-scripts.com https://ws.zoominfo.com https://cp.hubspot.com; object-src 'none'; manifest-src 'none'; media-src 'self'; form-action 'self' https://forms.hsforms.com https://forms.hubspot.com; frame-ancestors 'none'; worker-src 'self'; upgrade-insecure-requests; block-all-mixed-content 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.googleapis.com *.cloudflare.com *.twitter.com *.certcapture.com *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com https://applepay.cdn-apple.com/jsapi/v1/assets/1.0.0/fonts/en-US.woff https://applepay.cdn-apple.com/jsapi/v1/assets/1.0.0/fonts/en-US.woff2 https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.bc0a.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.certcapture.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.certcapture.com *.amazonaws.com *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.bc0a.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.googleapis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.certcapture.com *.amazonaws.com *.twimg.com *.vimeocdn.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net analytics.google.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com b.stats.paypal.com data.adxcel-ec2.com www.lionsden.com pixel.sitescout.com pixel.tapad.com secure.adnxs.com insight.adsrvr.org bob.dmpxs.com segment.prod.bid segment.prod.bidr.io su.addthis.com match.adsrvr.org ads.scorecardresearch.com eb2.3lift.com match.sync.ad.cpe.dotomi.com tags.rd.linksynergy.com dmp.truoptik.com i.liadm.com *.bc0a.com www.yextstatic.com us.yextevents.com tags.srv.stackadapt.com https://www.mollie.com www.sandbox.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.certcapture.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.zendesk.com http://www.w3.org/2000/svg https://js-agent.newrelic.com/ https://bam.nr-data.net/ *.sharethis.com https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.basis.net *.cdn.bc0a.com *.secure.wufoo.com *.wufoo.com *.consents-cf.bc0a.com *.bc0a.com acsbapp.com *.acsbapp.com tags.srv.stackadapt.com js.adsrvr.org sites.yext.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.certcapture.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.bc0a.com tags.srv.stackadapt.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.certcapture.com *.amazonaws.com *.zopim.com *.zopim.io https://static.zdassets.com/ https://bam.nr-data.net/ *.sharethis.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.bc0a.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com www.google-analytics.com *.cloudflare.com *.twitter.com *.certcapture.com *.amazonaws.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://stats.g.doubleclick.net *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.bc0a.com acsbapp.com *.acsbapp.com tags.srv.stackadapt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src 'self' blob:; script-src-elem 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' blob: *.cookiefirst.com *.hotjar.com *.chimpstatic.com chimpstatic.com *.googletagmanager.com *.trustpilot.com *.stripe.com *.vimeo.com *.clerk.io *.facebook.net *.facebook.com *.cloudflareinsights.com *.google-analytics.com *.googleadservices.com *.doubleclick.net *.gstatic.com *.googleapis.com vimeo.com *.jquery.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' blob: *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.cookiefirst.com *.adobe.com *.clerk.io downloads.mailchimp.com cc-cdn.com assets.braintreegateway.com *.trustpilot.com tagmanager.google.com *.vimeo.com *.jquery.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com 'self' data: blob: *.bootstrapcdn.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.stripe.com stripe.com 'self' 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com account.fetchify.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' blob: *.vimeo.com *.clerk.io *.facebook.com *.facebook.net *.cloudflareinsights.com *.trustpilot.com widget.trustpilot.com *.doubleclick.net js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com images.unsplash.com 'self' blob: *.cloudflare.com *.googleadservices.com *.google-analytics.com i.vimeocdn.com *.cdninstagram.com *.facebook.com *.clerk.io *.demdex.net *.sc.omtrdc.net *.everesttech.net *.google.com *.doubleclick.net *.paypalobjects.com *.ytimg.com *.mailchimp.com track.sweetanalytics.com www.mollie.com https://redchamps.com *.hsforms.net *.hsforms.com *.cookiefirst.com consent.cookiefirst.com www.google.co.uk *.google.co.uk *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://api.clerk.io https://cdn.clerk.io *.chimpstatic.com downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'report-sample' 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.braintreegateway.com *.cloudflare.com static.cloudflareinsights.com pay.google.com *.google-analytics.com *.googletagmanager.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.gstatic.com *.instagram.com *.paypal.com *.paypalobjects.com *.link.com player.vimeo.com vimeo.com *.cookiefirst.com consent.cookiefirst.com *.hotjar.com static.hotjar.com script.hotjar.com chimpstatic.com *.trustpilot.com widget.trustpilot.com invitejs.trustpilot.com *.clerk.io api.clerk.io custom.clerk.io connect.facebook.net track.sweetanalytics.com blob: js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com cc-cdn.com *.fontawesome.com 'report-sample' 'self' 'unsafe-inline' blob: *.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.gstatic.com *.cookiefirst.com consent.cookiefirst.com *.clerk.io assets.braintreegateway.com *.trustpilot.com tagmanager.google.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'self' 'unsafe-inline'; media-src *.adobe.com 'self' blob: 'unsafe-inline' *.cdninstagram.com *.instagram.com *.facebook.com *.vimeo.com *.vimeocdn.com vod-adaptive-ak.vimeocdn.com https://vod-adaptive-ak.vimeocdn.com *.youtube.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' *.cloudflare.com maps.googleapis.com *.craftyclicks.co.uk region1.analytics.google.com *.cookiefirst.com consent.cookiefirst.com edge.cookiefirst.com *.trustpilot.com widget.trustpilot.com *.google-analytics.com *.doubleclick.net *.facebook.com *.facebook.net https://*.facebook.com/* *.instagram.com graph.instagram.com *.vimeocdn.com vod-adaptive-ak.vimeocdn.com https://vod-adaptive-ak.vimeocdn.com blob: *.clerk.io *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.googleapis.com *.cloudflareinsights.com track.sweetanalytics.com *.braintree-api.com t.elasticsuite.io *.hsforms.net *.hsforms.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval' data: arclight.vimeo.com lensflare.vimeo.com vod-adaptive-ak.vimeocdn.com https://vod-adaptive-ak.vimeocdn.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 worker-src *.google.com *.zzz-worker-src.com blob:; font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com *.klaviyo.com *.zzz-font-src.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.boatoutfitters.com *.outdoornativitysets.com *.buildasurface.com *.osano.com *.bazaarvoice.com *.list-manage.com *.zzz-form-action.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.zzz-frame-ancestors.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com *.demdex.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.boldcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * photos.pixlee.co js.mollie.com *.boatoutfitters.com *.outdoornativitysets.com *.buildasurface.com *.osano.com *.smartsheet.com *.wufoo.com *.doubleclick.net *.google.com ct.pinterest.com *.paylocity.com paypalobjects.com www.paypalobjects.com vimeo.com www.vimeo.com www.youtube.com *.zzz-frame-src.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io widgets.automizely.com widgets.automizely.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.boldcommerce.com https://static.xx.fbcdn.net https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com wac.edgecastcdn.net *.klevu.com *.ksearchnet.com https://www.mollie.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com *.boatoutfitters.com *.outdoornativitysets.com *.buildasurface.com boatoutfitters.com outdoornativitysets.com buildasurface.com *.osano.com *.bazaarvoice.com *.bing.com bat.bing.com cdn.cookielaw.org optanon.blob.core.windows.net *.azurewebsites.net *.pointmediatracker.com *.linkedin.com *.ads.linkedin.com *.reddit.com *.bidswitch.net *.adnxs.com *.mediawallahscript.com *.casalemedia.com *.criteo.com *.stickyadstv.com *.360yield.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.revcontent.com *.rubiconproject.com *.smartadserver.com *.taboola.com *.tapad.com *.teads.tv *.tremorhub.com *.clmbtech.com *.tpmn.co.kr *.3lift.com *.1rx.io *.agkn.com *.crwdcntrl.net *.adsrvr.org *.tpmn.io *.gorgias.chat *.redinuid.imrworldwide.com *.targeting.unrulymedia.com *.lijit.com *.mathtag.com *.prod.bidr.io *.mrtnsvr.com *.liadm.com *.turnto.com *.userway.org *.nrich.ai *.dmxleo.com *.cloudfront.net *.rezync.com *.turn.com *.rfihub.com pippio.com *.pippio.com *.blisspointmedia.com *.simpli.fi *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com *.clarity.ms *.zzz-img-src.com *.zebco.com *.certcapture.com *.criteo.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com https://api.boldcommerce.com https://static.xx.fbcdn.net https://connect.facebook.net https://cdnjs.cloudflare.com https://cashier.boldcommerce.com/assets/experience/flow_sdk.js https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.turnto.com *.klevu.com *.ksearchnet.com js.mollie.com *.googletagmanager.com tagmanager.google.com *.boatoutfitters.com *.outdoornativitysets.com *.buildasurface.com *.osano.com *.wufoo.com wufoo.com cdn.cookielaw.org *.hotjar.com bat.bing.com *.azurewebsites.net *.newrelic.com *.zdassets.com s.pinimg.com analytics.tiktok.com ct.pinterest.com utt.impactcdn.com *.gorgias.chat *.licdn.com *.redditstatic.com *.jst.ai *.criteo.com *.pixeltracker.co *.invocacdn.com *.cloudfront.net *.upfluence.co *.spn.so *.userway.org *.123formbuilder.com *.123contactform.com *.amplitude.com *.tctm.co *.googleapis.com *.gstatic.com *.google.com google.com *.ggpht.com *.googleusercontent.com video.google.com www.youtube.com www.google.com/recaptcha www.gstatic.com/recaptcha static.hotjar.com *.clarity.ms googleads.g.doubleclick.net js-agent.newrelic.com analytics.google.com payments.braintree-api.com business.facebook.com pixel-config.reddit.com cdn-ws.turnto.com js.klevu.com statsjs.klevu.com vpsy1npuua.execute-api.us-east-1.amazonaws.com we.turnto.com eucs30v2.ksearchnet.com rr4---sn-5uaezny6.googlevideo.com stats.ksearchnet.com photos.pixlee.co unpkg.com zdticketintegration.boatoutfitters.com *.agkn.com *.zzz-script-src.com spn.so *.id5-sync.com *.certcapture.com js.zi-scripts.com upf.ai *.doubleclick.net blob: data: unsafe-eval https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.magento-datasolutions.com *.magento-ds.com widgets.automizely.com widgets.automizely.io https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.turnto.com *.klevu.com *.ksearchnet.com tagmanager.google.com fonts.google.com *.userway.org *.cloudflare.com *.zzz-style-src.com *.certcapture.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.secureserver.net *.zzz-media-src.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com *.snplow.net commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com commerce.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io api.automizely.com api.automizely.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.attn.tv events.attentivemobile.com https://api.boldcommerce.com https://api.staging.boldcommerce.com https://cashier.boldcommerce.com https://graph.facebook.com https://secure.boldcommerce.com https://secure.staging.boldcommerce.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.turnto.com *.klevu.com *.ksearchnet.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.boatoutfitters.com *.outdoornativitysets.com *.buildasurface.com *.osano.com cdn.cookielaw.org stats.g.doubleclick.net *.hotjar.io bat.bing.com geolocation.onetrust.com *.azurewebsites.net bam.nr-data.net *.zdassets.com analytics.tiktok.com ct.pinterest.com *.gorgias.chat *.ads.linkedin.com *.reddit.com *.redditstatic.com *.pixeltracker.co *.invoca.net *.criteo.com *.jst.ai *.userway.org *.amazonaws.com *.amplitude.com *.googleapis.com *.gstatic.com assets.adobedtm.com www.googleadservices.com js.braintreegateway.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.googletagmanager.com www.google.com/recaptcha www.gstatic.com/recaptcha static.hotjar.com *.clarity.ms googleads.g.doubleclick.net js-agent.newrelic.com analytics.google.com payments.braintree-api.com business.facebook.com ipv6check.ksearchnet.com stats.ksearchnet.com zdticketintegration.boatoutfitters.com *.zzz-connect-src.com *.tiktokw.us *.datadome.co *.certcapture.com wss://ws.hotjar.com/api/v2/client/ws wss://*.gorgias.chat data: blob: wss://zdticketintegration.boatoutfitters.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-fUIoSw0hKKcnBgw5ZEjXNw==' 'self' cdn.orsted.com *.googletagmanager.com *.app.cookieinformation.com cdn.appdynamics.com *.googletagmanager.com *.gstatic.com *.googleoptimize.com www.googleadservices.com *.googleapis.com *.bing.com *.doubleclick.net *.t.co *.pardot.com *.youtube.com *.linkedin.com *.twitter.com *.globenewswire.com *.23video.com delivery.twentythree.com orsted.containers.piwik.pro orsted.piwik.pro *.crazyegg.com unpkg.com cs.lf-discover.com *.puzzel.com *.arcgis.com code.jquery.com *.lfeeder.com orsted-global-graduate-programme.simplecast.com omny.fm cdnjs.cloudflare.com *.bootstrapcdn.com *.defgo.com *.defgo.net *.vimeo.com presscloud.com *.ritzau.dk *.simplecast.com *.elnet.danskenergi.dk *.sli.do *.audioboom.com *.licdn.com *.adsrvr.org *.soundcloud.com *.google.com *.google.com.my *.google.nl *.google.dk *.facebook.net; style-src 'nonce-fUIoSw0hKKcnBgw5ZEjXNw==' 'self' cdn.orsted.com fonts.googleapis.com; style-src-attr 'unsafe-inline' cdn.orsted.com; img-src 'self' data: cdn.orsted.com *.azureedge.net *.youtube.com *.23video.com delivery.twentythree.com www.googletagmanager.com *.lfeeder.com *.linkedin.com *.doubleclick.net *.pardot.com; media-src 'self' blob: cdn.orsted.com *.youtube.com *.23video.com delivery.twentythree.com; font-src 'self' data: fonts.gstatic.com cdn.orsted.com; frame-src *.app.cookieinformation.com *.youtube.com *.23video.com delivery.twentythree.com *.google.com *.google.nl *.googletagmanager.com *.doubleclick.net *.pardot.com; connect-src *.app.cookieinformation.com *.euroland.com *.eum-appdynamics.com *.googletagmanager.com *.google.com *.doubleclick.net *.googleadservices.com *.crazyegg.com *.linkedin.com orsted.piwik.pro *.pardot.com; worker-src 'self'; 1 worker-src 'self'; font-src www.paypalobjects.com 'self' dodenhof.app.baqend.com fonts.gstatic.com *.gstatic.com 'self' data: *.varify.io data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ 'self' *.jotform.com *.weltpixel.com *.google.com/ secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.googletagmanager.com *.doubleclick.net *.trustpilot.com *.scratcher.io *.criteo.com *.criteo.net *.online-metrix.net *.facebook.com *.varify.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' *.online-metrix.net ake-e2ee.s3.amazonaws.com render.barcodes.systems dodenhof.app.baqend.com https://images.unsplash.com https://www.magezon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.hsforms.net *.hsforms.com 'self' data: www.google.co.bw www.google.com.ua www.google.com.af *.criteo.net www.google.com.ar www.google.com.tj www.google.com.gh www.google.az *.consentmanager.net www.google.com.ly www.google.bg www.google.co.uz www.google.com.my www.google.com.pk www.google.com.gi www.google.gr www.google.fr www.google.com.ng www.google.com.cy www.google.co.id www.google.com.qa www.google.com.co www.google.com.tw www.google.com.om www.google.cv www.google.tn www.google.com.sg www.google.nl www.google.co.in www.google.ge *.ggpht.com www.google.lk www.google.by www.google.com.lb www.google.at www.google.al *.emarsys.net www.google.ro www.google.no www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.com.pa www.google.co.ve www.google.ae www.google.pl www.google.com.tr www.google.com.kw www.google.dk www.google.com.np www.google.com.uy www.google.se www.google.pt www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn www.google.com.bn www.google.ru www.google.jo *.trustpilot.net www.google.co.cr www.google.it www.google.co.zm www.google.com.et www.google.ch www.google.ee www.google.com.py *.facebook.net www.google.hu *.trustpilot.com www.google.sm www.google.iq www.google.ca www.google.com.na www.google.li www.google.com.mm www.google.md www.google.co.jp *.criteo.com www.google.am www.google.de www.google.cl www.google.es www.google.co.za www.google.lt www.google.is www.google.sc www.google.co.nz www.google.lu www.google.co.uk www.google.com.do www.google.com.eg www.google.com.gt www.google.co.ma www.google.la www.google.com.br www.google.com.bd www.google.tm www.google.fi www.google.sk www.google.co.ug www.google.kz www.google.com.ph www.google.je www.google.co.tz www.google.com.au www.google.si www.google.mn www.google.bs www.google.lv www.google.com.ec www.google.com.mt www.google.ba www.google.mk www.google.me www.google.com.kh www.google.com.sa www.google.kg www.google.so www.google.cz www.google.co.th www.google.co.kr www.google.dz www.google.ci www.google.mv www.google.com.vn www.google.ps www.google.com.hk data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' *.online-metrix.net *.scarabresearch.com dodenhof.app.baqend.com https://maps.googleapis.com *.google.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.hsforms.net *.hsforms.com *.gstatic.com *.trustpilot.com https://browser.sentry-cdn.com *.varify.io *.criteo.com *.consentmanager.net *.pay1.de *.sentry-cdn.com d5yoctgpv4cpx.cloudfront.net *.tag-monitoring.com *.baqend.com *.scratcher.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src d.ratepay.com d.payla.io dr.payla.io *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' dodenhof.app.baqend.com *.scarabresearch.com h.online-metrix.net https://maps.googleapis.com https://player.vimeo.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app t.elasticsuite.io *.hsforms.net *.hsforms.com https://*.ingest.sentry.io 127.0.0.1 *.online-metrix.net *.tag-monitoring.com *.trustpilot.com localhost *.criteo.com *.facebook.com ake-e2ee.s3.amazonaws.com *.emarsys.net *.sentry-cdn.com *.consentmanager.net p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.varify.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' *.googleapis.com *.criteo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; base-uri 'self' 'unsafe-inline'; report-uri https://1e8f5bec-f9ea-40a5-b847-cd8990d97b94.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.ads-twitter.com *.googleapis.com *.paypal.com https://cdn.klarna.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://player.vimeo.com https://bat.bing.com https://analytics.tiktok.com https://dev.elganso.com https://cdn.elganso.com https://www.elganso.com https://prerender.io https://use.typekit.net https://www.googletagmanager.com https://fonts.gstatic.com https://pagead2.googlesyndication.com https://td.doubleclick.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google.co.in 'self' data: blob: 'unsafe-inline' data: *.cloudflare.com https://cdn.klarna.com t.co https://s.ytimg.com https://player.vimeo.com https://bat.bing.com https://analytics.tiktok.com https://dev.elganso.com https://cdn.elganso.com https://www.elganso.com https://prerender.io https://use.typekit.net https://www.googletagmanager.com https://fonts.gstatic.com https://pagead2.googlesyndication.com https://www.google.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google.com/ *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com *.avada.io maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com tagmanager.google.com ssl.google-analytics.com *.cloudflare.com *.trustedshops.com *.usercentrics.eu *.naiz.fit *.twitter.com ads-twitter.com *.aplazame.com https://player.vimeo.com https://bat.bing.com https://analytics.tiktok.com https://dev.elganso.com https://cdn.elganso.com https://www.elganso.com https://prerender.io https://use.typekit.net https://www.googletagmanager.com https://fonts.gstatic.com https://pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com *.cloudflare.com *.googleapis.com *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com ws: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.analytics.google.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.cloudflare.com *.googleapis.com https://player.vimeo.com https://bat.bing.com https://analytics.tiktok.com https://dev.elganso.com https://cdn.elganso.com https://www.elganso.com https://prerender.io https://use.typekit.net https://www.googletagmanager.com https://fonts.gstatic.com https://pagead2.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://player.vimeo.com https://bat.bing.com https://analytics.tiktok.com https://dev.elganso.com https://cdn.elganso.com https://www.elganso.com https://prerender.io https://use.typekit.net https://www.googletagmanager.com https://fonts.gstatic.com https://pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com www.034motorsport.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.yotpo.com www.034motorsport.com 'self' 'unsafe-inline'; frame-ancestors www.034motorsport.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com www.034motorsport.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.affirm.com *.affirm.ca maps.gstatic.com validate.fishpig.co.uk 'self' data: * flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com www.034motorsport.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.googleapis.com *.avada.io * assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com www.034motorsport.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.yotpo.com www.034motorsport.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com www.034motorsport.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.googleapis.com https://get.geojs.io *.avada.io www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com www.034motorsport.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com www.034motorsport.com http: https: blob: 'self' 'unsafe-inline'; default-src www.034motorsport.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com checkout.tabby.ai *.smartlook.com *.smartlook.cloud *.tiktok.com *.snapchat.com *.facebook.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.smartlook.com *.smartlook.cloud *.tiktok.com *.snapchat.com *.facebook.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com polyfill.io *.googleapis.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com s7.addthis.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com connect.facebook.net www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.smartlook.com *.smartlook.cloud *.tiktok.com *.snapchat.com *.facebook.net *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com *.fontawesome.com maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.googleapis.com *.ngenius-payments.com *.sandbox.ngenius-payments.com api-gateway.sandbox.ngenius-payments.com ekr.zdassets.com/ checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.smartlook.com *.smartlook.cloud *.tiktok.com *.snapchat.com *.facebook.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-fEex5J5go7UEqoHktsOR+89z/DRwdqUdSVhDjbXYv+M=' 'unsafe-eval' 'strict-dynamic' https:; frame-ancestors 'self'; report-uri https://www.thonhotels.com/api/ContentSecurityViolation/; report-to csp-endpoint; object-src 'self'; base-uri 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com/gtm.js https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/script.js https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/banner.js https://www.googletagmanager.com/gtag/js https://player.vimeo.com/api/player.js https://www.google.com/recaptcha/api.js https://www.gstatic.com:*; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net/npm/@glidejs/glide@3.6.0/dist/css/glide.core.min.css https://fonts.googleapis.com/css2 https://use.typekit.net/wtm0jxv.css https://p.typekit.net/p.css; img-src 'self' data: image/svg+xml https://cdn-cookieyes.com/assets/images/revisit.svg https://cdn-cookieyes.com/assets/images/close.svg https://cdn-cookieyes.com/assets/images/poweredbtcky.svg https://www.googletagmanager.com:*; font-src 'self' data: https://fonts.gstatic.com:* https://use.typekit.net:* application/x-font-woff; connect-src https://www.google.com/ccm/collect https://log.cookieyes.com/api/v1/log https://www.google-analytics.com/g/collect https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/rFE9TVe8.json https://www.google-analytics.com/privacy-sandbox/register-conversion https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/config/wC2wr8GQ.json https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/translations/m3Rl7gng.json https://cdn-cookieyes.com/client_data/94a4f13a0cb959b98cc4a48f/audit-table/k_7S_mH5.json https://pagead2.googlesyndication.com/ccm/collect; frame-src https://www.googletagmanager.com/ https://player.vimeo.com/ https://cloud.fully.holmesmurphy.com/ https://www.google.com/; worker-src blob: https://www.holmesmurphy.com/5efe1b50-d93c-47e3-86b9-cab1697897e7 1 font-src 'self' https://cdnjs.cloudflare.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://use.fontawesome.com https://widgets.trustedshops.com https://media2.supermagnete.de https://www.supermagnete.de data:; frame-src 'self' https://*.amazon.com https://*.datatrans.com https://*.payments-amazon.com https://button.aftership.com https://payments-amazon.de https://payments.amazon.de https://payments.amazon.es https://payments.amazon.fr https://payments.amazon.it https://w.soundcloud.com https://www.facebook.com https://www.google.com https://www.youtube-nocookie.com https://www.googletagmanager.com; img-src 'self' https://* * data:; script-src 'self' https://*.google-analytics.com *.google-analytics.com https://*.aftership.com https://*.amazon.com https://*.datatrans.com https://*.payments-amazon.com https://ajax.googleapis.com https://apis.google.com https://bat.bing.com https://bat.bing-int.com https://cdn.jsdelivr.net/npm/canvas-confetti@1.9.2/ https://cdn.jsdelivr.net/npm/choices.js@11.0.6/ https://cdn.kiprotect.com https://cdnjs.cloudflare.com https://code.jquery.com https://feedback.shopvote.de https://googleads.g.doubleclick.net https://oss.maxcdn.com https://payments.amazon.de https://payments.amazon.es https://payments.amazon.fr https://payments.amazon.it https://*.googlesyndication.com https://widgets.trustedshops.com https://*.etrusted.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://media2.supermagnete.de https://www.supermagnete.de 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https://ajax.googleapis.com https://cdnjs.cloudflare.com https://feedback.shopvote.de https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net/npm/choices.js@11.0.6/ https://use.fontawesome.com https://widgets.trustedshops.com https://*.etrusted.com https://www.google.com/uds/ https://www.googletagmanager.com/debug/ https://www.gstatic.com/charts/ https://media2.supermagnete.de https://www.supermagnete.de 'unsafe-inline' data:; report-uri https://supermagnete.report-uri.com/r/d/csp/reportonly 1 script-src 'nonce-FaU4zz_NuyA8axNmcxNXwA' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://s3.amazonaws.com https://request.purview.net https://chimpstatic.com https://js.hs-scripts.com https://player.vimeo.com https://scripts.mediavine.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn-images.mailchimp.com https://cdn2.editmysite.com https://static.hsappstatic.net; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://cdn-images.mailchimp.com https://horosproject.us21.list-manage.com https://secure.gravatar.com https://cdn2.editmysite.com https://track.hubspot.com; frame-src https://horosproject.us21.list-manage.com https://player.vimeo.com; connect-src 'self' https://request.purview.net https://www.google-analytics.com https://track.hubspot.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' https://horosproject.us21.list-manage.com; frame-ancestors 'self'; upgrade-insecure-requests; report-uri /csp-violation-report-endpoint/ 1 script-src 'self' 'unsafe-hashes' 'unsafe-inline' *.discoverearly.com d.la3-c1-ia2.salesforceliveagent.com invitejs.trustpilot.com js.stripe.com service.force.com widget.trustpilot.com www.google.com www.gstatic.com www.avivasysbio.com www.genwaybio.com static.avivasysbio.com admin.avivasysbio.com 'unsafe-eval' static.avivasysbio.com static.hotjar.com www.googletagmanager.com snippets.freshchat.com wchat.freshchat.com www.google-analytics.com script.hotjar.com js-agent.newrelic.com; report-uri /.webscale/csp-report 1 default-src 'self'; connect-src corvirtus.com 'self'; frame-src www.facebook.com; script-src-elem ajax.aspnetcdn.com cdnsrc.asp.net www.google-analytics.com connect.facebook.net 'self'; style-src-elem maxcdn.bootstrapcdn.com fonts.googleapis.com 'self' 'sha256-o6wSC15InKzMdQsAjlOwalELkGSpN0I4/fzIfw2Ckvg='; font-src maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com 'self'; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com js.mollie.com *.trustpilot.com *.googletagmanager.com sst.parfumerie.nl ct.pinterest.com www.facebook.com widget.trustpilot.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com flagpedia.net https://www.mollie.com *.hsforms.net *.hsforms.com *.cdn.imgeng.in 'self' data: www.google.com.ua *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://images.parfumerie.nl sst.parfumerie.nl https://ct.pinterest.com https://s.pinimg.com www.facebook.com https://analytics.tiktok.com nd3wrk1b.cdn.imgeng.in lantern.roeye.com www.google.nl cdn-cookieyes.com bat.bing.com *.analytics.google.com www.google.be/ads/ga-audiences stats.g.doubleclick.net https://sst.parfumerie.nl data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net use.typekit.net *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com maps.googleapis.com js.mollie.com *.hsforms.net *.hsforms.com *.cdn.imgeng.in *.google.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com sst.parfumerie.nl https://s.pinimg.com https://connect.facebook.net https://analytics.tiktok.com cdn-cookieyes.comm static.klaviyo.com widget.trustpilot.com invitejs.trustpilot.com static-tracking.klaviyo.com www.dwin1.com s.pinimg.com d5yoctgpv4cpx.cloudfront.net cdn-cookieyes.com lantern.roeyecdn.com analytics.tiktok.com ct.pinterest.com bat.bing.com connect.facebook.net product-library.widgets.scentxp.net/index.iife.js scentbot.widgets.scentxp.net/index.iife.js https://sst.parfumerie.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.gstatic.com *.adobedtm.com *.cdn.imgeng.in *.googleapis.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com commerce.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.sentry.io https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.gstatic.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com sst.parfumerie.nl https://graph.facebook.com https://analytics.tiktok.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com widget.trustpilot.com ct.pinterest.com cdn-cookieyes.com directory.cookieyes.com log.cookieyes.com analytics-ipv6.tiktokw.us bat.bing.net bat.bing.com y1e7qslep5.execute-api.eu-west-2.amazonaws.com https://sst.parfumerie.nl 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com bat.bing.com log.cookieyes.com commerce.adobedc.net analytics.tiktok.com bat.bing.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://parfumerie.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://accounts.google.com https://*.google.com https://*.hotjar.com https://vars.hotjar.com https://www.facebook.com https://*.criteo.com https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com public.montonio.com https://www.facebook.com https://www.google.com https://www.google.ee https://www.google-analytics.com rx.apotheka.ee data: http: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com public.montonio.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://www.gstatic.com rx.apotheka.ee http: https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com rx.apotheka.ee http: https: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://www.google-analytics.com https://stats.g.doubleclick.net rx.apotheka.ee http: https: wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src 'self' data: fonts.gstatic.com *.flightio.com at.alicdn.com; frame-ancestors 'self' *.flightio.com; report-uri https://flightiorp.report-uri.com/r/d/csp/reportOnly; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.fontawesome.com https://static.ctctcdn.com https://www.google.com https://www.gstatic.com https://t.sharethis.com https://platform-api.sharethis.com https://www.googletagmanager.com https://www.google-analytics.com https://s3-us-west-2.amazonaws.com https://crm.bloomerang.co https://ajax.aspnetcdn.com https://aacdn.nagich.com https://access.nagich.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com https://ws.sharethis.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://use.fontawesome.com https://static.ctctcdn.com https://aacdn.nagich.com https://www.google.com https://www.gstatic.com https://t.sharethis.com https://platform-api.sharethis.com https://www.googletagmanager.com https://www.google-analytics.com https://s3-us-west-2.amazonaws.com https://crm.bloomerang.co https://ajax.aspnetcdn.com https://access.nagich.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com https://ws.sharethis.com; style-src 'self' https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://cloud.typography.com https://cdnjs.cloudflare.com https://use.fontawesome.com https://static.ctctcdn.com https://ws.sharethis.com https://aacdn.nagich.com https://access.nagich.com; frame-ancestors 'self' 1 default-src 'self'; connect-src 'self' https://cdn-ilecmmd.nitrocdn.com https://amp.azure.net https://www.google.com https://to.getnitropack.com https://ka-f.fontawesome.com; script-src 'unsafe-inline' 'self'; 1 object-src 'none'; connect-src 'self' *.devilsfilm.com *.famedigital.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.devilsfilm.com *.famedigital.com join.gammasecure.com; script-src 'self' *.devilsfilm.com *.famedigital.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.devilsfilm.com *.famedigital.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.googleapis.com *.gstatic.com data: *.klevu.com *.ksearchnet.com *.bootstrapcdn.com *.klaviyo.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.google.com.qa www.google.com.co www.google.com.tw www.google.tn www.google.tt www.google.nl www.google.co.in d3k81ch9hvuctc.cloudfront.net *.ssa.gov www.google.lk *.bing.net www.google.ro www.google.rs *.yahoo.com www.google.ie www.google.co.ke www.google.com.pa www.google.co.ve www.google.com.tr www.google.dk www.google.com.np www.google.se www.google.pt www.google.be www.google.com.mx www.google.ru www.google.it www.google.ch www.google.com.pr www.google.ca www.google.md www.google.co.jp www.google.de www.google.com.ni www.google.es www.google.co.za www.google.lt www.google.co.uk www.google.com.do www.google.com.eg www.google.co.ma *.google.com www.google.com.br www.google.com.bd www.google.sk *.visualwebsiteoptimizer.com www.google.com.ph www.google.co.tz www.google.com.au www.google.mk *.adelixir.com www.google.com.sa www.google.cz www.google.co.th www.google.co.kr *.bing.com www.google.com.vn www.google.co.vi www.google.com.ar *.doubleclick.net www.google.rw www.google.bg www.google.com.my www.google.com.pk www.google.gr www.google.fr www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.yimg.com *.luckyorange.com *.vantivcnp.com *.online-metrix.net *.klaviyo.com *.visualwebsiteoptimizer.com *.doubleclick.net *.adelixir.com *.google.com *.bing.com *.ssa.gov 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.trustpilot.com tagmanager.google.com *.klaviyo.com *.ssa.gov *.bootstrapcdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.doubleclick.net www.google.cz www.google.com.pr www.google.com.bd www.google.com.ni www.google.es *.bing.com www.google.com.pk *.datadome.co www.google.md www.google.ie www.google.com.vn www.google.co.ve www.google.lk *.yimg.com www.google.co.kr *.bing.net www.google.be www.google.com.pa www.google.nl www.google.bg www.google.com.mx www.google.fr www.google.co.in www.google.com.au www.google.com.sa www.google.ca *.luckyorange.com www.google.it www.google.com.ng www.google.com.ph www.google.co.ma www.google.com.co www.google.mk 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1461ad04-9e14-46c4-9a93-7108d3bf8283.sansec.watch/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com media.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net rt.flix360.com media.flixfacts.com magento-1482700-5635152.cloudwaysapps.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.plugins.emarsys.net *.scarabresearch.com *.avada.io *.shopify.com *.google.com/ maps.googleapis.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com media.flixfacts.com media.flixcar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com *.google.com *.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com media.flixfacts.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com magento-1482700-5635152.cloudwaysapps.co media.flixfacts.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.scarabresearch.com *.eservice.emarsys.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com media.flixfacts.com media.flixcar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://*.wp.com/ https://fonts.googleapis.com/; img-src 'self' data: https://*.wp.com/ https://secure.gravatar.com/ https://*.w.org/ ; font-src 'self' data: https://*.wp.com/ https://fonts.gstatic.com/; connect-src 'self' https://www.google-analytics.com/ ; frame-src 'self' https://*.wp.com/ ‘unsafe-inline’;script-src 'self' https://www.googletagmanager.com/ https://*.wp.com/ ; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://elements.sandbox.fortis.tech https://elements.fortis.tech 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://developer.adobe.com https://magento.com https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://developer.adobe.com https://elements.sandbox.fortis.tech https://elements.fortis.tech https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://static.iadvize.com/ https://media.flixfacts.com *.fontawesome.com applepay.cdn-apple.com https://fonts.gstatic.com *.alothemes.com *.magepow.com googlepay.cdn-google.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://static.addtoany.com https://www.google.com/ https://service.loadbee.com/ https://vars.hotjar.com/ https://static.rolex.com/ https://retailers.rolex.com/ https://media.flixfacts.com *.webengage.co https://corners.rolex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net https://static.iadvize.com/ https://fstatic.iadvize.com/ https://www.facebook.com https://www.google.com https://www.google.co.in https://googleads.g.doubleclick.net https://www.googletagmanager.com https://media.flixfacts.com https://m.media-amazon.com https://www.darwishholding.com/ https://theqa.qa metrics.rolex.com maps.googleapis.com smetrics.rolex.com *.disqus.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://cobrowsing-ha.iadvize.com/ https://fstatic.iadvize.com/ https://static.iadvize.com/ https://halc.iadvize.com https://api.iadvize.com/ https://static.addtoany.com https://www.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://graph.facebook.com https://widgets.pinterest.com https://cdn.loadbee.com/js/loadbee_integration.js https://static.hotjar.com https://script.hotjar.com https://static.rolex.com https://retailers.rolex.com http://media.flixfacts.com https://test-gateway.mastercard.com https://ap-gateway.mastercard.com/ https://starpay-easy.starboss.biz/ https://www.qpay.gov.qa/ https://m.media-amazon.com https://connect.facebook.net https://analytics.tiktok.com/ *.webengage.com applepay.cdn-apple.com https://corners.rolex.com maps.googleapis.com *.disqus.com *.alothemes.com *.magepow.com googlepay.cdn-google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://halc.iadvize.com/ https://static.iadvize.com/ https://media.flixfacts.com https://test-gateway.mastercard.com https://ap-gateway.mastercard.com/ https://starpay-easy.starboss.biz/ https://www.qpay.gov.qa/ *.fontawesome.com *.googleapis.com *.addtoany.com *.alothemes.com *.magepow.com assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://m.media-amazon.com https://media.flixfacts.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://cobrowsing-ha.iadvize.com/ https://halc.iadvize.com https://api.iadvize.com/ https://static.iadvize.com/ https://stats.g.doubleclick.net https://bam.nr-data.net https://availability.loadbee.com https://analytics.google.com https://in.hotjar.com https://vc.hotjar.io https://static.rolex.com https://retailers.rolex.com https://static.addtoany.com https://media.flixfacts.com https://stats.addtoany.com https://m.media-amazon.com c.webengage.com assets.adobedtm.com maps.googleapis.com http://dpm.demdex.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' https://www.digita.fi/app/themes/digita/dist/scripts/polyfills-7cba9be83f88d2e3c65e.js https://assets.juicer.io/embed-no-jquery.js https://bot.leadoo.com/bot/dynamic.js https://connect.facebook.net/en_US/fbevents.js https://consent.cookiebot.com/uc.js https://consentcdn.cookiebot.com/consentconfig/57cc69b8-8520-4aa6-ac3a-0ee5e2311b97/state.js https://eu2.snoobi.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/980469902/ https://mktdplp102cdn.azureedge.net/public/latest/js/ws-tracking.js https://sc.lfeeder.com/lftracker_v1_bElvO73X0YV4ZMqj.js https://script.hotjar.com/modules.8da33a8f469c3b5ffcec.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.hotjar.com/c/hotjar-1971876.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://consent.cookiebot.com/57cc69b8-8520-4aa6-ac3a-0ee5e2311b97/cc.js https://www.googletagmanager.com/gtm.js https://bot.leadoo.com/i/al/lanlt.js https://www.google-analytics.com/plugins/ua/linkid.js https://bot.leadoo.com/bot/chat.js https://v1.bot.leadoo.com/bot/chat.js https://consent.cookiebot.com/logconsent.ashx https://www.googletagmanager.com/gtag/destination https://connect.facebook.net/signals/config/234079757978399 https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/EGbODne6buzpTnWrrBprcfAY/recaptcha__en.js;connect-src 'self' https://consent.app.cookieinformation.com/api/consent www.google-analytics.com ajax.googleapis.com www.google.com google.com gstatic.com www.gstatic.com connect.facebook.net facebook.com policy.app.cookieinformation.com https://policy.app.cookieinformation.com https://yoast.com https://anl.leadoo.com https://bot.leadoo.com https://consentcdn.cookiebot.com https://px.ads.linkedin.com https://region1.analytics.google.com https://res.leadoo.com https://v1.bot.leadoo.com https://www.google-analytics.com https://www.google.com https://www.google.de https://googleads.g.doubleclick.net/pagead/landing https://stats.g.doubleclick.net/g/collect;style-src 'self' 'unsafe-hashes' 'unsafe-inline' https://assets.juicer.io https://fonts.googleapis.com https://res.leadoo.com;object-src 'none';base-uri 'self';font-src 'self' data: https://fonts.gstatic.com https://res.leadoo.com https://static.juicer.io;frame-src 'self' https://policy.app.cookieinformation.com https://www.google.com https://consentcdn.cookiebot.com https://mapservice.digita.fi https://td.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com;img-src 'self' data: https://2bbf3fdcc12f467e83bc10c46bd1dc7a.svc.dynamics.com https://eu2.snoobi.com https://ia.leadoo.com https://imgsct.cookiebot.com https://px.ads.linkedin.com https://res.leadoo.com https://tr.lfeeder.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.google.de https://www.googletagmanager.com https://www.google.fi/ads/ga-audiences https://www.google.fi/pagead/1p-user-list/980469902/;manifest-src 'self';media-src 'self';worker-src 'self' blob:; 1 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com https://*.moneris.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.moneris.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://*.moneris.com/ maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src _ 'self'; script-src _ 'self' 'unsafe-inline' blob: https://www.googletagmanager.com https://_.zopim.io https://tag.clearbitscripts.com https://static.cloudflareinsights.com https://widget.clutch.co https://widget.trustpilot.com https://nitroscripts.com; style-src _ 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; img-src _ 'self' data: https://www.google.com https://_.googleapis.com https://_.gstatic.com _.google.com _.googleusercontent.com; https://imagedelivery.net https://images.dmca.com https://widget.trustpilot.com; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net https://_.nitrocdn.com; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://widget.clutch.co https://widget.trustpilot.com; object-src 'none'; connect-src 'self' https://www.google-analytics.com https://www.google.com https://i.clarity.ms https://_.zopim.io wss://\_.zopim.com https://\*.zendesk.com https://api.ipify.org https://ekr.zdassets.com https://to.getnitropack.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://www.einpresswire.com; upgrade-insecure-requests; worker-src 'self' blob:; 1 base-uri 'self';default-src 'self';font-src 'self' https://use.typekit.net https://assets.iwgplc.com https://fonts.gstatic.com https:;connect-src 'self' https://analytics.google.com https://assets.iwgplc.com https://www.google.com https://maps.googleapis.com https://px.ads.linkedin.com https://www.facebook.com https://www.googleadservices.com https://google.com https://www.googletagmanager.com https://connect.facebook.net https://cdn.segment.com https://*.maze.co https://*.hcaptcha.com https://*.analytics.google.com https://*.google-analytics.com https://*.doubleclick.net https://*.applicationinsights.azure.com https://*.amplitude.com https://*.worldpay.com https://*.worldline-solutions.com https://*.psp-solutions.com https://*.paymentiq.io https://*.elevenlabs.io wss://*.elevenlabs.io https://api.myregus.com https://we-prod-pantheon-applinux-api-01.azurewebsites.net;style-src-elem 'self' https://p.typekit.net https://use.typekit.net https://fonts.googleapis.com https://www.googletagmanager.com https://www.gstatic.com 'unsafe-inline' https:;style-src 'self' https://p.typekit.net https://use.typekit.net https://fonts.googleapis.com https://www.googletagmanager.com https://www.gstatic.com 'unsafe-inline' https:;media-src 'self' data:;img-src 'self' data: https://www.googletagmanager.com http://assets.regus.com https://assets.regus.com https://b98.yahoo.co.jp https://maps.googleapis.com https://maps.gstatic.com https://px.ads.linkedin.com https://www.google.com https://payments.worldpay.com https://assets.iwgplc.com https://www.facebook.com https://s188399297.t.eloqua.com https://fonts.gstatic.com https://connect.facebook.net https://*.doubleclick.net https:;frame-src 'self' https://newassets.hcaptcha.com https://www.facebook.com/ https://www.googletagmanager.com https://login.live.com https://*.doubleclick.net https://*.worldpay.com https://*.worldline-solutions.com https://*.psp-solutions.com https://*.paymentiq.io;form-action 'self' https://www.facebook.com;script-src 'nonce-77zYMTFbOUvw+qDVRjd88Q==' 'strict-dynamic' 'unsafe-eval';report-uri /csp-violation-report 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net maxcdn.bootstrapcdn.com *.cookiebot.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.cookiebot.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.cookiebot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com validator.swagger.io *.awin1.com *.zenaps.com *.wepowerconnections.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cookiebot.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.sandbox.paypal.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.klarnaservices.com player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cookiebot.com *.yotpo.com https://chimpstatic.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.cookiebot.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cookiebot.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-JV4ehUCclhJIfBJfyz7mWQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.klevu.com *.ksearchnet.com cdn.userway.org *.userway.org *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com www.facebook.com platform.twitter.com https://plumrocket.com cdn.userway.org *.userway.org js.mollie.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.klevu.com *.ksearchnet.com cdn.userway.org *.userway.org store.paradoxlabs.com https://firebasestorage.googleapis.com https://www.mollie.com media.sezzle.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.plugins.emarsys.net *.scarabresearch.com connect.facebook.net twitter.com platform.twitter.com js.klevu.com *.ksearchnet.com cdn.userway.org *.userway.org *.authorize.net widget.freshworks.com m2epro.freshdesk.com https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com *.avada.io js.mollie.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.klevu.com *.ksearchnet.com cdn.userway.org *.userway.org widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.cdnfonts.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.scarabresearch.com *.eservice.emarsys.net *.klevu.com *.ksearchnet.com cdn.userway.org *.userway.org api.userway.org *.authorize.net widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://shoesme.b-cdn.net https://d1givitoj7uukl.cloudfront.net https://static.dhlparcel.nl https://digitvjot7uukl.cloudfront.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com *.fontawesome.com https://widgets.trustedshops.com www.shoesme.nl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.shoesme.nl 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.shoesme.nl 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.shoesme.nl 'self' 'unsafe-inline'; img-src https://shoesme.b-cdn.net https://api.taggrs.io https://bat.bing.com https://www.google.nl https://*.addsauce.com https://*.usercentrics.eu assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://maps.googleapis.com https://maps.gstatic.com https://www.mollie.com https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.shoesme.nl data: 'self' 'unsafe-inline'; script-src https://shoesme.b-cdn.net https://sst.shoesme.nl https://*.omappapi.com https://static.zdassets.com https://www.clarity.ms https://*.cookiebot.eu https://*.addsauce.com https://*.hotjar.com https://*.zopim.com https://*.copernica.com https://snapppt.com https://*.segmentify.com https://bat.bing.com https://*.pinimg.com https://*.googleapis.com https://*.sgmntfy.com https://*.clarity.ms https://*.pinterest.com https://static.dhlparcel.nl assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://static.dhlecommerce.nl https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.shoesme.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://shoesme.b-cdn.net https://*.omappapi.com https://*.segmentify.com https://d1givitoj7uukl.cloudfront.net https://static.dhlparcel.nl https://digitvjot7uukl.cloudfront.net *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.shoesme.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://static.zdassets.com https://addsauce-static-alt.b-cdn.net *.adobe.com www.shoesme.nl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src https://shoesme.b-cdn.net https://*.clarity.ms https://sst.shoesme.nl https://shoesmeinternationalbv.zendesk.com https://*.pinterest.com https://bat.bing.com https://*.omappapi.com wss://*.copernica.com https://ekr.zdassets.com wss://*.zopim.com https://consentcdn.cookiebot.eu https://*.copernica.com https://dev.visualwebsiteoptimizer.com https://*.segmentify.com https://*.addsauce.com https://static.dhlparcel.nl dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com autocomplete2.postdirekt.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site www.shoesme.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.shoesme.nl http: https: blob: 'self' 'unsafe-inline'; default-src www.shoesme.nl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.vivapayments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.boxnow.gr https://www.googletagmanager.com *.skroutz.gr 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://firebasestorage.googleapis.com *.googletagmanager.com *.google.com *.google.gr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.vivapayments.com *.avada.io *.shopify.com https://www.octocom.ai https://go.linkwi.se https://ping.contactpigeon.com https://zevioo.com *.googletagmanager.com *.skroutz.gr *.boxnow.gr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.bunny.net *.googletagmanager.com *.zevioo.com https://zevioo.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://get.geojs.io *.avada.io *.zevioo.com https://zevioo.com *.skroutz.gr *.boxnow.gr *.google.gr 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.google-analytics.com *.google.com *.bing.com *.facebook.com *.clarity.ms data: *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.youtube.com *.cdn.jsdelivr.net *.atbnd.com *.tiktok.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app; connect-src 'self' *.google.com *.cookielaw.org *.doubleclick.net cdn.cookielaw.org *.clarity.ms *.hotjar.com *.google-analytics.com *.nr-data.net *.onetrust.com *.bing.com *.hotjar.io *.taboola.com *.googlesyndication.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.empathy.co *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.cdn.jsdelivr.net *.atbnd.com *.linkedin.com *.licdn.com *.visualwebsiteoptimizer.com *.tiktok.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app https://www.google-analytics.com https://www.googletagmanager.com; font-src 'self' *.gstatic.com *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.cdn.jsdelivr.net *.atbnd.com *.tiktok.com *.analytics.tiktok.com *.facebook.com; frame-src 'self' *.hotjar.com *.addtoany.com *.doubleclick.net *.cookielaw.org *.facebook.com *.totalenergies.es *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.youtube.com *.cdn.jsdelivr.net *.atbnd.com *.googletagmanager.com *.tiktok.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app; img-src 'self' *.google-analytics.com *.google.com *.bing.com *.facebook.com *.clarity.ms data: *.b26net.com *.invibes.com *.acquia-sites.com *.quantserve.com *.mookie1.com *.cookielaw.org *.adnxs.com *.google.es *.googletagmanager.com *.doubleclick.net *.analytics.google.com *.g.doubleclick.net *.googlesyndication.com *.empathy.co https://totalenergies.com *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.google.com.uy *.cdn.jsdelivr.net *.atbnd.com *.linkedin.com *.licdn.com *.visualwebsiteoptimizer.com *.totalenergies.es *.tiktok.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app about: https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-eval' *.cloudflare.com *.addtoany.com *.unpkg.com *.fontwesome.com *.quantserve.com *.taboola.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.cdn.jsdelivr.net *.atbnd.com https://totalenergies.com *.tiktok.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app cdn.jsdelivr.net cdnjs.cloudflare.com https://ajax.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com https://static.addtoany.com https://www.google.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com *.newrelic.com *.facebook.net *.bing.com *.unpkg.com *.cookielaw.org *.google-analytics.com *.doubleclick.net *.mookie1.com *.hotjar.com *.nr-data.net *.clarity.ms *.quantcount.com *.quantserve.com *.kaspersky-labs.com *.empathy.co *.taboola.com trc-events.taboola.com *.googlesyndication.com *.totalenergies.es *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.youtube.com *.cdn.jsdelivr.net *.atbnd.com *.linkedin.com *.licdn.com *.gstatic.com *.google.com *.tiktok.com *.visualwebsiteoptimizer.com *.analytics.tiktok.com *.bat.bing.net *.analytics-ipv6.tiktokw.us *.mpc-prod-18-s6uit34pua-uc.a.run.app cdn.jsdelivr.net cdnjs.cloudflare.com https://ajax.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com https://static.addtoany.com https://www.google.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.cloudflare.com *.jsdelivr.net https://unpkg.com *.fontawesome.com *.cdn.jsdelivr.net *.atbnd.com *.tiktok.com *.analytics.tiktok.com *.facebook.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://use.fontawesome.com; style-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.googleapis.com *.cloudflare.com *.jsdelivr.net *.fontawesome.com *.cdn.jsdelivr.net *.atbnd.com *.licdn.com *.tiktok.com *.analytics.tiktok.com *.facebook.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://use.fontawesome.com; frame-ancestors 'self' 1 script-src 'self' 'nonce-/S0irV4jiQ0dA3xx/GioGqqXOQ+O7hEbBxhebec1B3k=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'none';script-src 'nonce-f91445a0-f727-4805-b407-be3710784670' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.mariacasino.dk https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.mariacasino.dk/eum-collector/report/csp-report; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.livechatinc.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.lightboxcdn.com ezup.com *.ezup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.twitter.com *.payfabric.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.salesforce.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.stripe.com stripe.com *.bolt.com connect.bolt.com *.transifex.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com www.google.com *.google.com *.doubleclick.net www.facebook.com *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com chart.googleapis.com *.youtube.com/ *.payfabric.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.livechatinc.com *.artifi.net gum.criteo.com *.criteo.net *.pepperjam.com *.pepperjamnetwork.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.salesforce.com *.bolt.com *.criteo.com *.transifex.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.certcapture.com connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.payfabric.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ezup.nl ezup.fr ezup.eu ezup.de *.cookiepro.com ezup.com *.ezup.com *.inspectlet.com *.google.com.sg *.bing.com *.linkedin.com *.stickyadstv.com *.smartadserver.com *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.taboola.com *.teads.tv *.3lift.com *.yahoo.com *.socdm.com *.criteo.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.mediavine.com *.outbrain.com *.pubmatic.com *.clmbtech.com *.yieldmo.com *.bluekai.com *.aralego.com *.adhaven.com *.sitescout.com *.tapad.com *.deepintent.com *.smaato.net *.everesttech.net *.krxd.net *.aralego.net *.crwdcntrl.net *.1rx.io *.artifi.net *.searchspring.io *.cloudfront.net *.ivitrack.com *.liadm.com *.postrelease.com *.revcontent.com *.tremorhub.com *.mediawallahscript.com *.omnitagjs.com *.agkn.com *.tpmn.co.kr *.yotpo.com dhv2ziothpgrr.cloudfront.net *.rqtrk.eu *.adsrvr.org *.addthis.com *.nr-data.net *.pippio.com *.boast.io *.amazonaws.com blob: *.bolt.com *.emxdgt.com *.yahoo.net *.googlesyndication.com *.bidr.io *.lightboxcdn.com *.googleusercontent.com *.placeholder.com google.com *.tpmn.io *.lijit.com *.turn.com *.rezync.com *.rfihub.com pippio.com thrtle.com *.visualwebsiteoptimizer.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com chart.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.payfabric.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.searchspring.net/intellisuggest/is.min.js *.searchspring.io *.cookiepro.com *.livechatinc.com *.artifi.net *.maxmind.com *.bing.com *.pepperjam.com *.licdn.com *.criteo.com *.inspectlet.com *.ezup.com *.pardot.com *.envolvetech.com *.zoominfo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.boast.io *.bolt.com *.lightboxcdn.com *.jquery.com *.visa.com *.jsdelivr.net *.visualwebsiteoptimizer.com *.posthog.com *.transifex.net *.transifex.com *.id5-sync.com *.reddit.com *.redditstatic.com *.impactcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.certcapture.com webchat.dotdigital.com webchat.staging.dotdigital.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.lightboxcdn.com *.ezup.com *.visa.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com maps.googleapis.com chart.googleapis.com *.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.ezup.com blob: *.bolt.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com chart.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.nr-data.net *.newrelic.com *.ampproject.org *.payfabric.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://beacon.searchspring.io/beacon *.cookiepro.com *.searchspring.io geoip-js.com *.inspectlet.com *.doubleclick.net *.livechatinc.com *.oribi.io *.trustpilot.com *.criteo.com *.appspot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.zoominfo.com *.boast.io *.amazonaws.com *.bolt.com *.googlesyndication.com *.googleusercontent.com *.lightboxcdn.com *.linkedin.com *.visualwebsiteoptimizer.com *.transifex.net *.posthog.com *.reddit.com *.sjv.io 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langara.ca; script-src 'self' 'unsafe-inline' https://sites.langara.ca https://iweb.langara.ca https://www.googletagmanager.com https://www.google-analytics.com https://js-agent.newrelic.com https://code.tidio.co https://langara.lndo.site https://seckit-langarscript-src-elema.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://cdn.jsdelivr.net https://langaratest.h5p.com https://langara.h5p.com https://public.tableau.com https://langara.libwizard.com https://api3-ca.libcal.com https://lgapi-ca.libapps.com https://unpkg.com https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://connect.facebook.net https://script.crazyegg.com https://analytics.tiktok.com https://www.redditstatic.com https://tags.srv.stackadapt.com https://sc-static.net https://tr.snapchat.com https://snap.licdn.com https://script.crazyegg.com blob: https://bbox.blackbaudhosting.com https://payments.blackbaud.com https://www.google.com https://www.gstatic.com https://widget.lightcastcc.com; object-src 'self' fonts.googleapis.com fonts.gstatic.com *.googletagmanager.com *.google-analytics.com https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://lgapi-ca.libapps.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://tags.srv.stackadapt.com https://bbox.blackbaudhosting.com; img-src 'self' data: https://cdnjs.cloudflare.com https://www.google-analytics.com https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://public.tableau.com https://www.googleadservices.com https://www.google.ca https://www.google.com https://googleads.g.doubleclick.net https://www.facebook.com https://tr.snapchat.com https://px.ads.linkedin.com https://alb.reddit.com https://www.googletagmanager.com https://www.googletagmanager.so https://www.googletagmanager.mx https://tracking.crazyegg.com https://*.googletagmanager.com https://www.google.com.tw https://px4.ads.linkedin.com https://bbox.blackbaudhosting.com https://www.linkedin.com https://www.google.co.jp https://connect.facebook.net https://www.google.fr https://www.google.com.br; media-src 'self' https://code.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io; frame-src 'self' https://sites.langara.ca https://iweb.langara.ca https://www.youtube.com https://code.tidio.co https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langaratest.h5p.com https://langara.h5p.com https://public.tableau.com https://forms.office.com https://login.microsoftonline.com https://langara.libwizard.com https://outlook.office365.com https://www.googletagmanager.com https://tr.snapchat.com https://alb.reddit.com https://bbox.blackbaudhosting.com https://bbox.blackbaudhosting.com https://www.google.com https://www.facebook.com https://widget.lightcastcc.com; frame-ancestors 'self' https://sites.langara.ca https://iweb.langara.ca https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://www.google.com/; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://code.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://lgapi-ca.libapps.com; connect-src 'self' https://www.google.com https://www.google-analytics.com https://bam.nr-data.net https://code.tidio.co wss://socket.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langara.libcal.com https://lgapi-ca.libapps.com https://unpkg.com https://analytics.google.com https://stats.g.doubleclick.net https://analytics.tiktok.com https://tr.snapchat.com https://tags.srv.stackadapt.com https://www.redditstatic.com https://analytics-ipv6.tiktokw.us https://www.google.ca https://pixel-config.reddit.com https://tr6.snapchat.com https://www.googleadservices.com https://script.crazyegg.com https://px.ads.linkedin.com https://assets-tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://*.crazyegg.com https://www.facebook.com https://www.googletagmanager.com https://region1.google-analytics.com https://www.google.fr https://www.google.com.br; report-uri /report-csp-violation 1 script-src 'nonce-INijWvWneo24xpHjWg2GGQ5uR0zIEUam' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' 'self' https: http:; report-uri /.netlify/functions/__csp-violations 1 default-src 'self' cdn.yellowmessenger.com fonts.gstatic.com www.g2.com; script-src 'self' f.vimeocdn.com js-agent.newrelic.com cdn.yellowmessenger.com pi.pardot.com bam.nr-data.net go.leadspace.com cdnjs.cloudflare.com sfc.leadspace.com www.googletagmanager.com cmp.osano.com www.google-analytics.com googleads.g.doubleclick.net snap.licdn.com stats.sa-as.com metadata-static-files.sfo2.cdn.digitaloceanspaces.com connect.facebook.net tracking.g2crowd.com static.hotjar.com www.g2.com script.hotjar.com platform.twitter.com static.ads-twitter.com; style-src 'self' cdn.jsdelivr.net fonts.googleapis.com cdnjs.cloudflare.com www.g2.com; img-src 'self' www.g2.com px.ads.linkedin.com media-exp1.licdn.com stats.sa-as.com px4.ads.linkedin.com www.google.com p.adsymptotic.com www.facebook.com cdn.yellowmessenger.com 1 font-src *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.bootstrapcdn.com data: *.fontawesome.com https://www.google.com https://www.gstatic.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.twitter.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com *.youtube.com *.trustpilot.com *.yotpo.com *.addthis.com https://connect.facebook.net 'self'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io *.cloudflare.com https://static.pay.nl *.gstatic.com *.google.com *.google.nl *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net *.youtube.com https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com *.pay.nl *.yotpo.com solwininfotech.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com *.youtube.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.trustpilot.com googleads.g.doubleclick.net s7.addthis.com *.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com https://z.moatads.com https://v1.addthisedge.com *.addthis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.google-analytics.com https://stats.g.doubleclick.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.google.co.in *.facebook.com stats.g.doubleclick.net translations.piggy.eu maps.googleapis.com ekr.zdassets.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.e-tailors.nl/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.com *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net https://use.fontawesome.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.com *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.com *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net https://use.fontawesome.com https://fonts.googleapis.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net https://olegnax.com https://api.instagram.com https://graph.instagram.com/ api.amplitude.com stats.g.doubleclick.net www.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.data-8.co.uk *.ai-shopassistant.com *.clerk.io *.lenehans.ie *.klaviyo.com *.google.ie *.google.ru *.google.com *.google.co.uk *.doubleclick.net *.trustpilot.com *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.gstatic.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net 'self' data: www.searchanise.com *.searchserverapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com meetanshi.com *.multisafepay.com https://pay.google.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.meetanshi.com meetanshi.com *.multisafepay.com https://pay.google.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedaty.com *.disqus.com https://firebasestorage.googleapis.com *.meetanshi.com meetanshi.com *.multisafepay.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedaty.com upstream.heidipay.com sbx-upstream.heidipay.io *.disqus.com *.google.com *.avada.io *.meetanshi.com meetanshi.com *.multisafepay.com https://pay.google.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.doofinder.com downloads.mailchimp.com *.feedaty.com *.google.com https://fonts.bunny.net *.multisafepay.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com *.doofinder.com wss://*.doofinder.com *.feedaty.com upstream.heidipay.com sbx-upstream.heidipay.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.meetanshi.com meetanshi.com *.multisafepay.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.amplitude.com stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://*.salemove.com https://*.glia.com; connect-src 'self' wss://*.salemove.com https://*.salemove.com wss://*.glia.com https://*.glia.com https://*.twilio.com wss://*.twilio.com; media-src 'self' https://*.salemove.com https://*.glia.com; style-src 'self' https://*.salemove.com https://*.glia.com; font-src 'self' data:; img-src 'self' blob: data: https://*.salemove.com https://*.glia.com; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.yandex.ru *.bigland.ru *.marquiz.ru *.video.cloud.yandex.net *.google.com *.gstatic.com vk.com top-fwz1.mail.ru *.roistat.com; connect-src 'self' wss://moigektar.ru *.google.com wss://mc.yandex.ru mc.yandex.ru privacy-cs.mail.ru *.roistat.com sentry.bug.land; img-src 'self' data: blob: *.yandex.ru *.bigland.ru vk.com top-fwz1.mail.ru *.roistat.com storage.yandexcloud.net *.google.com yandex.ru; frame-src 'self' *.google.com *.marquiz.ru runtime.video.cloud.yandex.net *.yandex.ru *.roistat.com; font-src 'self'; media-src 'self' storage.yandexcloud.net; style-src 'self' 'unsafe-inline'; report-uri /api/security/log-csp-violation; report-to csp-endpoint 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:; script-src 'self' https://*.googletagmanager.com 'nonce-bf8ff8c8c27ffd66d66e37a99cb1fcf3' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; style-src 'self' 'nonce-bf8ff8c8c27ffd66d66e37a99cb1fcf3' https://fonts.googleapis.com; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; frame-ancestors 'self'; 1 default-src 'self' syndication.twitter.com; script-src js.suedtirolerland.it 'unsafe-inline' 'unsafe-eval' player.peer.tv stats.peer.biz platform.twitter.com apis.google.com; connect-src 'self' stats.peer.biz; img-src 'self' data: images2.suedtirolerland.it css.suedtirolerland.it www.hotel-guide.it player.peer.tv stats.peer.biz carto.peer.biz www.gravatar.com syndication.twitter.com api.trustyou.com; style-src 'self' 'unsafe-inline' css.suedtirolerland.it js.suedtirolerland.it; font-src css.suedtirolerland.it; frame-src 'self' player.peer.tv www.facebook.com platform.twitter.com apis.google.com accounts.google.com www.youtube.com; child-src 'self' player.peer.tv www.facebook.com platform.twitter.com apis.google.com accounts.google.com www.youtube.com; report-uri https://csp-report.peer.biz/reportOnly/index 1 font-src *.cloudflare.com *.youtube.com *.twitter.com *.gstatic.com *.typekit.net *.mail.ru *.twimg.com *.trustedshops.com *.googleapis.com data: *.flocktory.com *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com *.youtube.com *.chatra.io *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.twitter.com *.youtube.com *.yandex.md *.flocktory.com *.mail.ru *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my *.google.com gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.twitter.com *.yandex.md *.flocktory.com *.mail.ru *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my *.google.com gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.cloudflare.com *.youtube.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.nr-data.net *.mail.ru *.googletagmanager.com *.bi.owox.com *.google.com *.google.ru *.flocktory.com *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com vk.com *.maps.yandex.net *.yandex.ru *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.youtube.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.newrelic.com *.nr-data.net *.omtrdc.net *.googletagmanager.com *.jsdelivr.net *.flocktory.com *.mail.ru *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com vk.com *.api-maps.yandex.ru *.suggest-maps.yandex.ru *.maps.yandex.net *.yandex.ru https://yastatic.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.youtube.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jsdelivr.net *.flocktory.com *.mail.ru *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cloudflare.com *.youtube.com *.twitter.com *.paypal.com *.twimg.com *.google-analytics.com *.nr-data.net *.mail.ru *.dadata.ru *.demdex.net *.ipify.org *.yandex.ru ymetrica1.com *.bi.owox.com *.google.com *.yandex.md *.flocktory.com *.chatra.io *.adhigh.net *.weborama.fr *.acstat.com *.advcake.com *.cnt.my gdeslon.ru *.gdeslon.ru *.indoleads.com *.vk.com stats.g.doubleclick.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://checkout.culqi.com https://connect.facebook.net https://maps.googleapis.com https://platform.twitter.com https://static-content.vnforapps.com https://unpkg.com https://www.google.com https://www.instagram.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://ojo-publico.com; style-src-attr 'self'; frame-ancestors * 1 default-src 'self'; connect-src 'self' https://accounts.google.com https://maps.googleapis.com https://hotspotparking.com https://www.google.com; font-src 'self' https://fonts.gstatic.com https://hotspotparking.com data:; form-action 'self' https://hotspotparking.com; frame-src 'self' https://www.google.com https://accounts.google.com https://libs.na.bambora.com https://www.htsp.ca https://esqa.moneris.com https://gatewayt.moneris.com https://*.s3.ca-central-1.amazonaws.com https://www.okotoks.ca; img-src 'self' https://hotspotparking.com data: https://*.s3.ca-central-1.amazonaws.com https://maps.googleapis.com https://maps.gstatic.com blob: https://demo.dev.hotspotparking.com https://fonts.gstatic.com; script-src 'self' 'unsafe-eval'; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://hotspotparking.com https://appleid.cdn-apple.com https://www.gstatic.com https://libs.na.bambora.com https://www.google.com https://accounts.google.com https://cdn.datatables.net https://maps.googleapis.com https://www.google-analytics.com https://gatewayt.moneris.com https://cdn.jsdelivr.net https://html2canvas.hertzen.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://hotspotparking.com https://accounts.google.com https://cdn.datatables.net https://fonts.googleapis.com; report-uri https://hotspot.report-uri.com/r/t/csp/reportOnly 1 default-src 'self';script-src 'self' 'unsafe-inline';style-src 'self' 'unsafe-inline';img-src 'self' data:;font-src 'self' https;connect-src 'self';media-src 'self';object-src 'none';frame-src 'self';frame-ancestors 'self';form-action 'self';base-uri 'self';manifest-src 'self';worker-src 'self';child-src 'self';navigate-to 'self';prefetch-src 'self';upgrade-insecure-requests;report-uri https://8myolwo6cb.execute-api.us-west-1.amazonaws.com/v1/csp-report; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net https://widgets.trustedshops.com integrations.etrusted.com *.cloudflare.com *.twitter.com *.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' data: *.yotpo.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://seo.mageplaza.com www.facebook.com *.copernica.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com https://www.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://*.dpdconnect.nl *.dpdconnect.nl service2.loyaltyinabox.com *.pinterest.com www.facebook.com www.youtube.com view.publitas.com www.google.com www.google.nl www.google.de *.google.com maps.google.com chat.babypark.nl *.doubleclick.net td.doubleclick.net googleads.g.doubleclick.net widget.trustpilot.com *.cookiebot.com *.cookiebot.eu chatwidget-prod.web.app www.googletagmanager.com sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl folders.baby-dump.nl *.twitter.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.klevu.com *.ksearchnet.com www.babypark.nl www.babypark.de www.babydeals.be dehoevebuitenleven.nl m2.babypark.mavendev.com m2.babypark-de.mavendev.com www.ikenik.nl m2.ikenik.mavendev.com m2.babydump.mavendev.com m2.babydump-de.mavendev.com www.google.com www.google.nl www.google.de www.google.com.ua www.facebook.com ct.pinterest.com www.googletagmanager.com www.zenaps.com www.awin1.com static.zdassets.com *.bing.com *.bing.net www.thuiswinkel.org i.ytimg.com img.youtube.com blob: lantern.roeye.com *.clarity.ms *.cookiebot.com *.cookiebot.eu integrations.etrusted.com stats.g.doubleclick.net sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://*.dpdconnect.nl js.klevu.com *.ksearchnet.com *.avada.io www.googletagmanager.com checkout.buckaroo.nl *.clarity.ms lantern.roeyecdn.com widgets.trustedshops.com web-sdk.smartlook.com www.dwin1.com s.pinimg.com connect.facebook.net static.buckaroo.nl view.publitas.com api.360productviewer.com googleads.g.doubleclick.net bat.bing.com bat.bing.net static.zdassets.com js-agent.newrelic.com *.livechatinc.com bam.eu01.nr-data.net chat.babypark.nl widget.trustpilot.com *.pinterest.com *.hotjar.com *.hotjar.io *.cookiebot.com *.cookiebot.eu integrations.etrusted.com chatwidget-prod.web.app *.cloudflare.com *.google.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com https://widgets.trustedshops.com *.yotpo.com sst.babypark.de https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net checkout.buckaroo.nl integrations.etrusted.com chatwidget-css.web.app *.cloudflare.com *.googleapis.com *.google.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu maxcdn.bootstrapcdn.com unsafe-inline https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com integrations.etrusted.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io *.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.clarity.ms *.pinterest.com *.doubleclick.net stats.g.doubleclick.net googleads.g.doubleclick.net manager.eu.smartlook.cloud ekr.zdassets.com wss://widget-mediator.zopim.com api.360productviewer.com www.facebook.com livechat.fabulor.eu bam.eu01.nr-data.net region1.analytics.google.com *.google.com *.hotjar.com *.hotjar.io analytics.google.com bat.bing.com bat.bing.net *.cookiebot.com *.cookiebot.eu *.copernica.com integrations.etrusted.com api.ipify.org *.cloudflare.com *.twitter.com *.twimg.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.yotpo.com sst.babypark.de https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 base-uri 'self'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubbc97f311fa4b760aa9d5cff03790e285&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=production; font-src 'self' fast.fonts.net fonts.gstatic.com *.fontawesome.com d2m21dzi54s7kp.cloudfront.net cdnjs.cloudflare.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' d2m21dzi54s7kp.cloudfront.net *.googletagmanager.com *.addthis.com *.addthisedge.com *.informz.net *.adroll.com *.snapengage.com *.bugherd.com *.facebook.com *.bootstrapcdn.com cdnjs.cloudflare.com polyfill.io *.moatads.com *.fontawesome.com *.google-analytics.com *.licdn.com *.googleapis.com *.facebook.net; media-src 'self'; object-src 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; report-uri https://www.medicalguardian.com/mg-csp-endpoint/csp-report.php 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.klarnacdn.net fonts.googleapis.com *.wistia.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.wistia.net *.criteo.com *.pinterest.com fast.wistia.com fast.wistia.net https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.wistia.com *.wistia.net *.google.com *.criteo.com cdn.cookielaw.org *.braintreegateway.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klaviyo.com *.wistia.com *.wistia.net *.zdassets.com *.criteo.com *.criteo.net cdn.id5-sync.com *.pinimg.com *.pinterest.com *.braintree-api.com *.levelaccess.net *.cookielaw.org *.clarity.ms *.amazonaws.com *.liadm.com *.pinterest.co *.sentry-cdn.com *.impactcdn.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app assets.braintreegateway.com *.klarnacdn.net https://static.klaviyo.com fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com stats.g.doubleclick.net www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kmail-lists.com *.klarnauserservices.com *.zendesk.com *.zdassets.com *.zopim.com wss://*.zendesk.com wss://*.zopim.com *.litix.io *.criteo.com *.id5-sync.com *.eu-1-id5-sync.com google-analytics.com *.google-analytics.com *.pinterest.com *.signifyd.com pagead2.googlesyndication.com privacyportal.onetrust.com geolocation.onetrust.com *.wistia.com *.wistia.net *.levelaccess.net *.cookielaw.org *.clarity.ms *.amazonaws.com *.liadm.com *.pinterest.co *.usbrowserspeed.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' media1.jpc.de wom.de; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; script-src 'self' media1.jpc.de wom.de 'nonce-9dD8cA8hOk5kH57AyfMj47ZS8AN+Acbiz1Ibn/18mZMyBJhS2WmvqC3OxBS7STlsqxQGpNEzMry+g489bSVCog==' 'report-sample'; style-src 'self' media1.jpc.de wom.de 'report-sample' 'unsafe-inline'; font-src 'self' media1.jpc.de wom.de; img-src 'self' media1.jpc.de wom.de data:; connect-src 'self' media1.jpc.de wom.de https://use.jpc.de; report-uri /csp/; report-to csp-endpoint 1 font-src https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.youtube-nocookie.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com pay.google.com pay-accept.bm.pl pay.bm.pl cards-accept.bm.pl cards.bm.pl *.hotjar.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.doubleclick.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com cards-accept.bm.pl cards.bm.pl pay.google.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.hotjar.com https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com pay-accept.bm.pl pay.bm.pl cards-accept.bm.pl cards.bm.pl *.googleapis.com *.przelewy24.pl https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.doubleclick.net http://localhost:10003/socket.io/ https://localhost:10003/socket.io/ wss://localhost:10003/socket.io/ http://localhost:10003/broadcast/ http://localhost:10003/consumer http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com ws://localhost:10003 https://localhost:10003/broadcast https://localhost:10003/consumer 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gls.com *.szybkapaczka.pl *.gls-poland.com/ https://*.easypack24.net https://fonts.bunny.net fonts.googleapis.com https://*.typekit.net https://font.static.useinsider.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ secure.payu.com merch-prod.snd.payu.com https://parcelshop.dhl.pl https://pudofinder.dpd.com.pl https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.gls-poland.com/ https://*.dpd.com.pl/ https://*.dpd.cz/ www.facebook.com platform.twitter.com https://consentcdn.cookiebot.com https://*.livechatinc.com https://secure-fra.livechatinc.com https://creativecdn.com https://fitanu.api.useinsider.com https://ams.creativecdn.com https://*.doubleclick.net https://api.dpd.cz/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ static.payu.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.gls-poland.com.pl/ https://*.easypack24.net https://*.inpost.pl https://trustmate.io https://firebasestorage.googleapis.com quickchart.io img.youtube.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://fitanu.com https://*.paynow.pl https://*.cookiebot.com https://*.glami.pl https://*.bing.com https://google.pl https://image.useinsider.com https://*.google.pl https://log.api.useinsider.com https://*.adnxs.com https://cm.g.doubleclick.net https://*.creativecdn.com https://*.udmserve.net https://*.rubiconproject.com https://*.wp.pl https://*.teads.tv https://*.taboola.com https://*.adscale.de https://*.3lift.com https://*.outbrain.com https://*.smartadserver.com https://*.yieldmo.com https://*.openx.net https://*.360yield.com https://*.33across.com https://*.seedtag.com https://sync.go.sonobi.com https://*.nexx360.io https://*.clarity.ms https://*.casalemedia.com https://*.lijit.com https://*.omnitagjs.com https://*.media.net https://*.loopme.me https://onetag-sys.com https://*.mgid.com https://*.ad.smaato.net https://*.rmp.rakuten.com https://*.visx.net http://*.credit-agricole.pl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ secure.payu.com secure.snd.payu.com https://*.googlesyndication.com https://pagead2.googlesyndication.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ https://unpkg.com https://cdn.jsdelivr.net https://api.mapbox.com https://*.easypack24.net https://trustmate.io *.snrbox.com https://c.seznam.cz https://cz.im9.cz https://sk.im9.cz *.avada.io *.shopify.com connect.facebook.net twitter.com platform.twitter.com https://*.paynow.pl https://*.intum.com https://*.demoup.com https://cdn.intum.com https://*.cookiebot.com https://*.clarity.ms https://*.azureedge.net https://*.livechatinc.com https://*.wp.pl https://*.dmdi.pl https://*.savecart.pl https://*.goadservices.com https://*.bing.com https://*.dwin1.com https://glamipixel.com https://trafficscanner.pl https://*.cloudflareinsights.com https://fitanu.api.useinsider.com/ https://tags.creativecdn.com https://script.ar-mtch1.com https://eitri.api.useinsider.com https://*.allekurier.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.szybkapaczka.pl *.gls-poland.com/ https://cdn.jsdelivr.net https://*.easypack24.net https://api.mapbox.com https://trustmate.io *.snrcdn.net https://fonts.bunny.net fonts.gstatic.com https://assets.api.useinsider.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ secure.payu.com merch-prod.snd.payu.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ https://*.easypack24.net https://api.mapbox.com https://events.mapbox.com https://trustmate.io *.snrbox.com https://get.geojs.io *.avada.io https://*.demoup.com https://mycliplister.com https://*.google-analytics.com https://*.livechatinc.com https://googleads.g.doubleclick.net https://ams.creativecdn.com https://lt.ar-mtch1.com https://*.cookiebot.com https://*.useinsider.com https://*.clarity.ms https://*.bing.com https://*.inpost.pl 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https: https://www.google-analytics.com https://cdn.amplitude.com 'unsafe-eval' 'unsafe-inline' data: 'nonce-ZTzKNvNnCkb5Z2WLDbiG0w=='; worker-src blob: data:; report-uri https://us.sentry.io/api/4506690010480640/security/?sentry_key=aab2498373841041d6b48d721aefbdc1&sentry_environment=production&sentry_release=65deeb3f2dabb2b4bfe610722dc106d146560985 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https:; frame-src 'self' https://www.google.com; connect-src 'self' https://www.google.com; object-src 'none'; base-uri 'self' 1 default-src 'none'; base-uri 'none'; report-uri /browser-report; report-to default; frame-ancestors 'none'; script-src https: 'unsafe-inline'; connect-src https:; style-src 'self' https://*.escapio.com 'unsafe-inline'; media-src data:; img-src https: data:; frame-src https:; font-src 'self' https://*.escapio.com https://fonts.gstatic.com data: 1 object-src 'none'; connect-src 'self' *.21naturals.com *.21members.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.21naturals.com *.21members.com join.gammasecure.com; script-src 'self' *.21naturals.com *.21members.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.21naturals.com *.21members.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.tawk.to *.gstatic.com *.kxcdn.com *.powerreviews.com *.googletagmanager.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net *.google-analytics.com web-2-tel.com *.unpkg.com unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.tawk.to testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.tawk.to https://js.stripe.com/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.google.com/recaptcha/ *.gstatic.com/recaptcha/ *.powerreviews.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net *.google-analytics.com web-2-tel.com *.unpkg.com unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.tawk.to cdn.jsdelivr.net *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net m.media-amazon.com *.visualwebsiteoptimizer.com *.powerreviews.com https://meetanshi.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net *.google-analytics.com web-2-tel.com *.unpkg.com unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in *.googletagmanager.com tawk.link res.cloudinary.com *.rakuten.com *.linksynergy.com *.xg4ken.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.tawk.to cdn.jsdelivr.net https://checkout.stripe.com/checkout.js https://js.stripe.com/v3/ *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com unpkg.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.visualwebsiteoptimizer.com *.powerreviews.com *.googletagmanager.com *.stripe.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net *.google-analytics.com web-2-tel.com *.unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in 'unsafe-inline' mpsnare.iesnare.com res.cloudinary.com acds-events.adobe.io *.rakuten.com *.linksynergy.com *.xg4ken.com *.kaptcha.com *.mgt.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com 'unsafe-inline' assets.braintreegateway.com *.tawk.to cdn.jsdelivr.net *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.powerreviews.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net *.google-analytics.com web-2-tel.com *.unpkg.com unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in *.googletagmanager.com *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.tawk.to 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.tawk.to wss://*.tawk.to https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.powerreviews.com *.visualwebsiteoptimizer.com *.bing.com *.googlecommerce.com *.web-2-tel.com *.doubleclick.net web-2-tel.com *.unpkg.com unpkg.com *.amazonaws.com amazonaws.com google.co.in *.google.co.in *.kaptcha.com https://get.geojs.io *.mgt.com *.google-analytics.com analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self' keio.okta.com *.oktacdn.com; connect-src 'self' keio.okta.com keio-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com keio.kerberos.okta.com keio.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-v_M-C_67PWnTR73BpNa_Xg' 'unsafe-eval' 'self' 'report-sample' keio.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-v_M-C_67PWnTR73BpNa_Xg' 'self' 'report-sample' keio.okta.com *.oktacdn.com; frame-src 'self' keio.okta.com keio-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' keio.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' keio.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com https://plugin-magento-ui.glopalservice.com *.klarnacdn.net *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; frame-ancestors *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.trustpilot.com *.weltpixel.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.pixriot.com *.storeimaging.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.trustpilot.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.klarnacdn.net https://static.klaviyo.com *.trustpilot.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; object-src *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; media-src *.adobe.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; manifest-src *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.pixriot.com *.storeimaging.com *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; child-src *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com http: https: blob: 'self' 'unsafe-inline'; default-src *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.americanexpress.com *.visa.com *.mastercard.com https://www.rsa3dsauth.co.uk https://sg-3ds-vdm.wlp-acs.com postfinance.ch *.postfinance.ch *.paypal.com *.stripe.com squareup.com *.squareup.com *.chase.com *.bankofamerica.com *.wellsfargo.com *.hsbc.com *.cic.fr *.amex.com *.nyse.com 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com *.drankgigant.nl *.drankgigant.de 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com www.googletagmanager.com widget.trustpilot.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com www.google.nl www.google.be www.google.de data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com static.buckaroo.nl checkout.buckaroo.nl d5yoctgpv4cpx.cloudfront.net invitejs.trustpilot.com widget.trustpilot.com cdn.optimizely.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com checkout.buckaroo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com google.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 script-src-elem *.cfjump.com *.popupsmart.com embedsocial.com *.preezie.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com; font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com *.gstatic.com data: 'self' 'unsafe-inline' 'unsafe-eval'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com t.zip.co static.zipmoney.com.au static.zip.co *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com *.riskified.com *.bing.com *.legitscript.com data: 'self' 'unsafe-inline' 'unsafe-eval'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.zipmoney.com.au static.zip.co zip.co *.cfjump.com *.popupsmart.com embedsocial.com *.preezie.com *.bazaarvoice.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net static.afterpay.com/ *.squarecdn.com *.cash.app display.ugc.bazaarvoice.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com embedsocial.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.popupsmart.com *.bazaarvoice.com *.demdex.net *.riskified.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' securitasapp.securitasdev.trendhosting.ch; script-src-elem 'self' 'unsafe-inline' securitasapp.securitasdev.trendhosting.ch www.googletagmanager.com pastahr.dev maps.googleapis.com googleadservices.com cdnjs.cloudflare.com www.google-analytics.com www.google.com www.gstatic.com googleads.g.doubleclick.net connect.facebook.net snap.licdn.com consent.cookiebot.eu consent.cookiebot.eu/%2A consentcdn.cookiebot.eu consentcdn.cookiebot.eu/%2A player.vimeo.com 'report-sample'; style-src-elem 'self' 'unsafe-inline' securitasapp.securitasdev.trendhosting.ch fonts.googleapis.com 'report-sample'; img-src 'self' data: i.ytimg.com px.ads.linkedin.com px4.ads.linkedin.com googleads.g.doubleclick.net maps.googleapis.com maps.gstatic.com ad.doubleclick.net i.vimeocdn.com www.facebook.com google.com google.ch img.sct.eu1.usercentrics.eu img.sct.eu1.usercentrics.eu/%2A; font-src 'self' data: fonts.gstatic.com; connect-src www.google.com securitasapp.securitasdev.trendhosting.ch px.ads.linkedin.com pagead2.googlesyndication.com www.securitas.ch region1.google-analytics.com maps.googleapis.com consentcdn.cookiebot.eu; frame-src securitasapp.securitasdev.trendhosting.ch www.youtube-nocookie.com pastahr.dev 6494580.fls.doubleclick.net td.doubleclick.net player.vimeo.com www.securitas.ch www.google.com www.googletagmanager.com www.youtube.com 13442904.fls.doubleclick.net snap.licdn.com consentcdn.cookiebot.eu; report-uri https://www.securitas.ch/@http-reporting?csp=report&requestTime=1765943997130657&requestHash=fb9e2e3b1fb8b2dfec3dd6606d83e049bd92121e 1 default-src 'self'; frame-ancestors https://cms-stage.mediashop.bloomreach.cloud https://cms.mediashop.bloomreach.cloud 'self'; frame-src 'self' https://*.doubleclick.net meine-einkaufswelt.prod.welocal.cloud http://www.meine-einkaufswelt.tv https://www.meine-einkaufswelt.tv https://*.paypal.com *.usercentrics.eu youtube.com www.youtube.com; object-src 'none'; base-uri 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.scarabresearch.com meine-einkaufswelt.prod.welocal.cloud http://www.meine-einkaufswelt.tv *.nosto.com *.cloudfront.net https://*.paypal.com *.usercentrics.eu https://cdn.tms.www.mediashop.tv https://tms.www.mediashop.tv www.youtube.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: *.usercentrics.eu https://tms.www.mediashop.tv https://i.ytimg.com; font-src 'self' data: https:; connect-src 'self' https: https://recommender.scarabresearch.com https://webchannel-content.eservice.emarsys.net *.nosto.com https://*.paypal.com *.usercentrics.eu https://tms.www.mediashop.tv; media-src 'self' data: blob: https:; 1 font-src use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com *.googleapis.com *.gstatic.com likeshop.me *.klaviyo.com fontsfree.net *.jsdelivr.net *.cloudflare.com *.amazonaws.com s3-eu-west-1.amazonaws.com www.malinandgoetz.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * static11-jquery.com js2-cloudbase.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.yotpo.com swellrewards.com *.swellrewards.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wesupply.xyz https://wesupplylabs.com static11-jquery.com js2-cloudbase.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.linksynergy.com *.bounceexchange.com *.squareup.com *.clarity.ms *.googleadservices.com likeshop.me *.dashhudson.com *.google.co.in *.google.com *.bouncex.net *.cdnwidget.com *.cloudfront.net pippio.com *.bidr.io *.adroll.com *.bing.com *.openx.net *.bidswitch.net *.yahoo.com *.adnxs.com *.rlcdn.com *.cookielaw.org *.tapad.com *.dashsocial.com static11-jquery.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com *.clarity.ms *.tiktok.com *.cookielaw.org *.wknd.ai *.aptrinsic.com *.google.com *.googleapis.com *.googleadservices.com *.dashhudson.com *.bounceexchange.com acsbap.com acsbapp.com *.cloudfront.net *.googletagmanager.com *.klaviyo.com *.knocdn.com northbeam.io *.northbeam.io *.bing.com *.pinimg.com *.postie.com *.adroll.com *.adnxs.com *.pinterest.com *.rakuten.com *.rmp.rakuten.com *.dstillery.com *.media6degrees.com *.linksynergy.com https://www.malinandgoetz.com/ https://www.malinandgoetz.com/* static11-jquery.com js2-cloudbase.com *.shopmy.us static.shopmy.us 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com tagmanager.google.com *.stripe.network *.stripecdn.com *.googleapis.com *.bounceexchange.com *.aptrinsic.com *.klaviyo.com *.jsdelivr.net *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.google.com *.googleusercontent.com static11-jquery.com js2-cloudbase.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com *.ipinfo.io ekr.zdassets.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.clarity.ms *.tiktok.com *.aptrinsic.com *.googleapis.com likeshop.me acsbap.com acsbapp.com *.doubleclick.net *.cloudflare.com *.likeshop.me *.acsbapp.com *.cdnbasket.net *.cdnwidget.com *.bouncex.net *.knocommerce.com *.grin.co *.getletterpress.com *.agkn.com *.malinandgoetz.com tte-prod.telemetry.vaultdcr.com *.vaultdcr.com *.adroll.com *.adnxs.com *.pinterest.com *.cookielaw.org https://www.malinandgoetz.com/ https://www.malinandgoetz.com/* static11-jquery.com js2-cloudbase.com *.shopmy.us api.shopmy.us 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.githubusercontent.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ www.google.com *.meetanshi.com *.doubleclick.net *.googletagmanager.com *.yotpo.com https://meetanshi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.swagger.io *.adobedtm.com *.demdex.net *.magentocommerce.com *.doubleclick.net *.google.com *.ytimg.com *.meetanshi.com *.yotpo.com *.bing.com *.googleapis.com *.solutionsstores.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png https://meetanshi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com *.googleapis.com *.yotpo.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.shopify.com player.vimeo.com *.meetanshi.com https://meetanshi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com widget.freshworks.com m2epro.freshdesk.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu *.googleapis.com *.demdex.net *.cardinalcommerce.com *.meetanshi.com *.yotpo.com *.freshworks.com *.freshdesk.com *.avada.io *.stripe.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.bing.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io https://meetanshi.com klarna.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https: policy.app.cookieinformation.com; font-src https:; frame-src https:; img-src 'self' data: https:; manifest-src 'self' https:; media-src 'self' https:; script-src 'unsafe-inline' https: maps.google.com; style-src 'unsafe-inline' https:; worker-src https:; base-uri https:; form-action https:; frame-ancestors 'self' https:; report-uri https://www.version2.dk/log-report-uri/reportOnly 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.outdoorcap.com outdoorcap.my.salesforce.com data: *.gstatic.com holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com holbal.formstack.com *.hsforms.net *.hsforms.com *.kbmax.com *.hotjar.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.sharethis.com *.outdoorcap.com outdoorcap.my.salesforce.com *.paypal.com *.duosecurity.com *.gstatic.com *.google.com holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com *.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com *.outdoorcap.com outdoorcap.my.salesforce.com *.facebook.com *.facebook.net *.pinterest.com *.google.com *.googleapis.com *.gstatic.com *.googletagmanager.com holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com *.hotjar.com track.hubspot.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.sharethis.com *.googleapis.com player.vimeo.com *.outdoorcap.com outdoorcap.my.salesforce.com service.force.com *.salesforceliveagent.com *.googletagmanager.com *.google.com *.gstatic.com holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com dh98j2ed63lww.cloudfront.net *.hotjar.com *.hsadspixel.net js.hs-scripts.com js.hs-analytics.net js.hs-banner.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.outdoorcap.com outdoorcap.my.salesforce.com *.googleapis.com *.gstatic.com holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.adobe.io performance.typekit.net *.sentry.io *.sharethis.com *.googleapis.com *.outdoorcap.com outdoorcap.my.salesforce.com *.google-analytics.com https://stats.g.doubleclick.net holbal.formstack.com *.hsforms.net *.hsforms.com *.zoomcats.com *.kbmax.com *.hotjar.com api.hubapi.com *.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src sw-assets.ekomiapps.de *.contentbird-convert.com https://static.unzer.com https://applepay.cdn-apple.com https://www.gstatic.com https://fonts.gstatic.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.fontawesome.com https://geowidget.easypack24.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net *.usercentrics.eu td.doubleclick.net *.pinterest.com *.criteo.com www.sovendus-connect.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net https://www.googletagmanager.com/ https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ https://www.google.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://geowidget-app.inpost.pl/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.josera.de *.foodforplanet.de *.trbo.com sw-assets.ekomiapps.de *.usercentrics.eu www.google.de *.analytics.google.com bat.bing.com *.g.doubleclick.net ib.adnxs.com region1.google-analytics.com rtb-csync.smartadserver.com a.twiago.com sync-t1.taboola.com pixel.quantserve.com ad.360yield.com sync.1rx.io *.criteo.com sync.targeting.unrulymedia.com *.wepowerconnections.com lantern.roeye.com *.contilla.de *.contentbird-convert.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.awin1.com *.zenaps.com https://ssl.ceneo.pl http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net 'unsafe-inline' foodf11123.pcapredict.com *.trbo.com *.usercentrics.eu cdn.jsdelivr.net tierspuren.online *.upsellit.com *.cptrack.de lantern.roeyecdn.com *.brandswap.com brandswaptag.azureedge.net api.contester.net sw-assets.ekomiapps.de s.pinimg.com bat.bing.com *.facebook.net *.criteo.com *.criteo.net googleads.g.doubleclick.net www.clarity.ms secure.quantserve.com ad4m.at *.pinterest.com rules.quantcount.com *.sovendus.com *.contilla.de *.contentbird-convert.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://ssl.ceneo.pl widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.amplifyapp.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net https://www.google.com https://www.gstatic.com s7.addthis.com *.snrbox.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.avada.io https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src sw-assets.ekomiapps.de *.contentbird-convert.com widget.freshworks.com m2epro.freshdesk.com *.snrcdn.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.fontawesome.com https://geowidget.easypack24.net https://geowidget.inpost.pl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.josera.de tierspuren.online region1.google-analytics.com tagapi.brandswap.com sw-assets.ekomiapps.de *.usercentrics.eu www.google.com *.analytics.google.com *.googlesyndication.com googleads.g.doubleclick.net *.pinterest.com *.criteo.com *.clarity.ms *.sovendus.com *.googletagmanager.com bat.bing.com www.google.de *.contentbird-convert.com www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ ekr.zdassets.com/ *.snrbox.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com api.addressy.com https://get.geojs.io *.avada.io *.easypack24.net *.inpost.pl *.openstreetmap.org 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https: wss:; default-src 'self'; font-src 'self' data: https://fonts.gstatic.com https://defi-promo.volet.com https://cdn.megabonus.com/fonts/; frame-src 'self' https://consentcdn.cookiebot.eu https://consentcdn.cookiebot.com https://challenges.cloudflare.com https://calendly.com https://verify.walletconnect.org https://mc.yandex.ru https://mc.yandex.com; img-src 'self' data: blob: https:; manifest-src 'self'; media-src 'self' https://blog.static.volet.com data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://defi-promo.volet.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://connect.facebook.net https://eu-assets.i.posthog.com https://mc.yandex.com https://mc.yandex.ru https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' blob: https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://mc.yandex.com https://mc.yandex.ru https://connect.facebook.net https://eu-assets.i.posthog.com https://defi-promo.volet.com https://consent.cookiebot.eu https://challenges.cloudflare.com https://*.kaspersky-labs.com; style-src 'self' 'unsafe-inline' https://defi-promo.volet.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://defi-promo.volet.com https://www.gstatic.com https://www.gstatic.com:443 https://*.kaspersky-labs.com; worker-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://csp.volet.com/csp-reports; report-to csp-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.pwc.com https://assets.adobedtm.com https://*.akamaihd.net https://platform.twitter.com https://*.demdex.net https://*.twing.com https://www.googletagmanager.com https://cm.everesttech.net https://optanon.blob.core.windows.net https://pwc.sc.omtrdc.net https://syndication.twitter.com https://www.googleoptimize.com https://cdn.cookielaw.org https://www.google-analytics.com https://stats.g.doubleclick.net https://script.crazyegg.com https://pbs.twimg.com https://cdn.syndication.twimg.com https://www.google.com https://www.google.ca https://accounts.google.com https://www.youtube.com https://i.ytimg.com https://jwpltx.com https://ssl.gstatic.com https://ton.twimg.com https://www.google.com.tr https://www.pwc.nl https://www.pwc.co.uk http://download.pwc.com https://apis.google.com https://ssl.p.jwpcdn.com https://www.gstatic.com https://ton.twimg.com data:; 1 default-src 'self'; base-uri 'self'; font-src 'self' https: data:; img-src 'self' data: https:; object-src 'none'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; frame-src 'self'; frame-ancestors 'self'; media-src 'self'; script-src 'self' https: 'unsafe-inline' http://connect.facebook.net/en_US/sdk.js https://connect.facebook.net/en_US/sdk.js; report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=trusted-mfe@v1.1&sentry_environment=prod 1 default-src null 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src *.authorize.net *.bing.com *.cloudflare.com *.compliancesigns.com *.doubleclick.net *.googleadservices.com *.google.com *.googlecommerce.com *.googletagmanager.com *.hotjar.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hscollectedforms.net *.hsforms.net *.hs-scripts.com *.hubspot.com *.licdn.com *.payments-amazon.com *.searchspring.io *.searchspring.net *.shopperapproved.com *.tctm.co *.trustpilot.com *.turnto.com *.usemessages.com *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com *.googletagmanager.com *.shopperapproved.com *.turnto.com *.hubspot.com *.searchspring.io *.usemessages.com *.hs-analytics.net *.hotjar.com *.google.com *.googleadservices.com *.googlecommerce.com *.licdn.com *.hsadspixel.net *.authorize.net *.hs-scripts.com *.trustpilot.com *.doubleclick.net *.tctm.co *.bing.com *.payments-amazon.com *.compliancesigns.com *.searchspring.net *.hsforms.net *.cloudflare.com *.youtube.com *.hscollectedforms.net *.hs-banner.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.cloudflare.com *.compliancesigns.com *.googletagmanager.com *.turnto.com *.visualwebsiteoptimizer.com app.vwo.com *.turnto.com *.cloudflare.com *.compliancesigns.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src *.compliancesigns.com compliancesigns.com *.bing.com *.doubleclick.net *.googleadservices.com google.com *.google.com *.googletagmanager.com *.hscollectedforms.net *.hubspot.com *.linkedin.com *.payments-amazon.com *.searchspring.io *.searchspring.net *.shopperapproved.com *.turnto.com *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io *.googletagmanager.com *.hscollectedforms.net *.turnto.com google.com *.payments-amazon.com *.hubspot.com *.doubleclick.net *.linkedin.com *.google.com *.shopperapproved.com *.googleadservices.com *.searchspring.io *.searchspring.net *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; connect-src *.authorize.net *.bing.com *.compliancesigns.com *.doubleclick.net *.googleadservices.com *.google.com google.com *.googletagmanager.com *.hotjar.com *.hscollectedforms.net *.hubspot.com *.linkedin.com *.payments-amazon.com *.searchspring.io *.turnto.com *.visualwebsiteoptimizer.com app.vwo.com *.hotjar.com *.compliancesigns.com *.payments-amazon.com *.bing.com *.hscollectedforms.net google.com *.linkedin.com *.searchspring.io *.doubleclick.net *.turnto.com *.hubspot.com *.googleadservices.com *.licdn.com *.authorize.net *.google.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; font-src *.cloudflare.com *.compliancesigns.com *.hotjar.com *.compliancesigns.com *.cloudflare.com *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src null 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.bing.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-src *.authorize.net *.authorize.net *.bing.com *.cloudflare.com *.doubleclick.net *.google.com *.googletagmanager.com *.hotjar.com *.hsforms.net *.hubspot.com *.trustpilot.com *.youtube.com *.visualwebsiteoptimizer.com app.vwo.com *.google.com *.doubleclick.net *.cloudflare.com *.hsforms.net *.youtube.com *.hotjar.com *.trustpilot.com *.googletagmanager.com *.hubspot.com *.authorize.net *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes';report-uri https://9d5bcf97-219a-452a-a7ad-f99e63b52def.sansec.watch/ 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://belco-prod.s3-eu-central-1.amazonaws.com https://cdn.flbx.io https://firebasestorage.googleapis.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://cdn.belco.io https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com *.avada.io *.shopify.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://*.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com wss://chat.belco.io https://cdn.belco.io https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com *.gorgias.chat *.fontawesome.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com https://seo.mageplaza.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.typekit.net services.postcodeanywhere.co.uk *.aerin.com www.aerin.com foursixty.com scontent.cdninstagram.com bam.nr-data.net google.co.in www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://imgs.signifyd.com https://*.online-metrix.net *.facebook.com *.bing.com *.google.co.in *.google.com cdn-cookieyes.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.typekit.net *.newrelic.com *.nr-data.net secure-a.vimeocdn.com *.paypal.com foursixty.com *.aftership.com *.pcapredict.com services.postcodeanywhere.co.uk *.gorgias.chat polyfill.io *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com *.hotjar.com acsbapp.com *.facebook.net *.attn.tv *.bing.com *.google.co.in *.google.com *.audioeye.com *.px-cloud.net cdn-cookieyes.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.typekit.net foursixty.com services.postcodeanywhere.co.uk *.googleapis.com *.gorgias.chat *.fontawesome.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.audioeye.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nr-data.net *.braintree-api.com *.paypal.com *.signifyd.com foursixty.com *.aftership.com services.postcodeanywhere.co.uk metrics.foursixty.com *.gorgias.chat stats.g.doubleclick.net *.amplitude.com thm.visa.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google.com google.com https://imgs.signifyd.com *.hotjar.com *.hotjar.io *.acsbapp.com *.attentivemobile.com *.attn.tv wss://ws.hotjar.com *.facebook.com *.commercepartnerhub.com commercepartnerhub.com cdn-cookieyes.com *.cookieyes.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.gorgias.chat 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: 'unsafe-inline' c.bongo4u.com; script-src 'self' data: 'unsafe-inline' c.bongo4u.com blob: 'unsafe-eval' bongo4u.com *.bongo4u.com *.emerge2.com *.google.com *.gstatic.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com *.yahooapis.com *.mailchimp.com *.list-manage.com chimpstatic.com *.ipify.org jsonip.com *.amazonaws.com/downloads.mailchimp.com/ *.jquery.com *.hotjar.com acsbapp.com *.bootstrapcdn.com googleads.g.doubleclick.net *.elfsight.com *.createsend1.com *.roomvo.com; connect-src 'self' data: 'unsafe-inline' c.bongo4u.com comments.emerge2.com util.emerge2.com bongo4u.com *.emerge2.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.ca *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.doubleclick.net *.facebook.com *.hotjar.io *.hotjar.com acsbapp.com *.acsbapp.com *.elfsight.com createsend.com *.ipify.org *.mailchimp.com *.catalog-display.com *.roomvo.com *.opencagedata.com *.googleusercontent.com; frame-src 'self' data: 'unsafe-inline' c.bongo4u.com bongo4u.com *.google.com *.google.ca *.googleapis.com *.googletagmanager.com *.youtube.com *.youtu.be *.facebook.com *.twitter.com *.twimg.com *.instagram.com *.yahoo.com *.catalog-display.com *.shortstack.com *.pgtb.me *.formstack.com *.list-manage.com *.doubleclick.net *.orgill.com *.orgill.ca *.adobe.com *.hotjar.com *.storefrontcloud.io *.roomvo.com *.loom.com; object-src 'self' data: 'unsafe-inline' c.bongo4u.com blob: *.apple.com *.macromedia.com; img-src 'self' https: data: blob: c.bongo4u.com *.bongo4u.com *.ytimg.com *.orgill.com android-webview-video-poster; media-src 'self' https: data: c.bongo4u.com; style-src 'self' data: 'unsafe-inline' c.bongo4u.com bongo4u.com *.bongo4u.com *.googletagmanager.com *.google.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.bootstrapcdn.com *.twitter.com *.twimg.com *.mailchimp.com *.cloudflare.com/ajax/libs/; font-src 'self' data: 'unsafe-inline' c.bongo4u.com *.googleapis.com fonts.gstatic.com *.bootstrapcdn.com fonts.cdnfonts.com *.googleusercontent.com *.cloudflare.com/ajax/libs/ *.hotjar.com *.acsbapp.com; report-uri https://util.emerge2.com/csp_violations_tracker.php; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net https://*.dpdconnect.nl *.addthis.com *.multisafepay.com https://pay.google.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.faslet.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.multisafepay.com https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://*.dpdconnect.nl *.faslet.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.faslet.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.multisafepay.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.icl-group.com ajax.googleapis.com *.google.com *.googletagmanager.com *.google-analytics.com *.gstatic.com www.gstatic.com *.facebook.com *.facebook.net *.licdn.com *.allyable.com cdn.jsdelivr.net cdnjs.cloudflare.com widget.tagembed.com cloud.tagbox.com player.vimeo.com icl2021ir.q4web.com maps.googleapis.com www.tiktok.com sf16-website-login.neutral.ttwstatic.com *.clarity.ms widget.intercom.io js.intercomcdn.com; connect-src 'self' *.icl-group.com *.google.com *.google-analytics.com *.googletagmanager.com *.facebook.com *.facebook.net *.ads.linkedin.com *.allyable.com icl2021ir.q4web.com api.taggbox.com widget.tagembed.com cloud.tagbox.com ipapi.co maps.googleapis.com *.clarity.ms api-iam.intercom.io; style-src 'self' 'unsafe-inline' *.icl-group.com cdn.jsdelivr.net widget.tagembed.com cloud.tagbox.com fonts.googleapis.com sf16-website-login.neutral.ttwstatic.com; font-src 'self' data: cloud.taggbox.com *.gstatic.com *.icl-group.com cloud.tagbox.com; img-src 'self' data: blob: *.googletagmanager.com px.ads.linkedin.com portal.allyable.com s.w.org *.tile.openstreetmap.org *.icl-group.com *.allyable.com *.facebook.com *.facebook.net cdn.taggbox.com cloud.tagbox.com *.w.org *.elementor.com *.tagembed.com; media-src 'self' *.icl-group.com cdn.tagbox.com; frame-src 'self' portal.allyable.com player.vimeo.com www.google.com www.gstatic.com leap13.github.io www.youtube.com; worker-src 'self' blob:; report-uri https://www.icl-group.com/csp-report 1 default-src 'none' ; manifest-src 'self' ; object-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com/ajax/libs/gsap/ *.googleapis.com/ https://www.google-analytics.com/ https://cookie-cdn.cookiepro.com ; style-src 'self' 'unsafe-inline' https://www.gstatic.com/recaptcha/ https://fonts.googleapis.com/ ; img-src 'self' data: https://maps.gstatic.com/ *.cdninstagram.com/ https://cookie-cdn.cookiepro.com/ https://www.facebook.com/tr/ https://www.google-analytics.com/ https://maps.googleapis.com/ ; font-src 'self' data: https://fonts.gstatic.com/ ; connect-src 'self' https://maps.googleapis.com/ https://stats.g.doubleclick.net/ region1.google-analytics.com/ https://cookie-cdn.cookiepro.com/ https://geolocation.onetrust.com/ https://www.google-analytics.com/ ; media-src 'self' ; form-action 'self' https://www.facebook.com/tr/ ; frame-src 'self' https://www.google.com/ ; report-to csp-endpoint 1 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://widget.weezevent.com https://www.googletagmanager.com https://www.google-analytics.com 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https://secure.gravatar.com; connect-src 'self' https://www.google-analytics.com; frame-src 'self' https://new-liste-exposants.hubj2c.com https://www.google.com; 1 font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.klevu.com *.ksearchnet.com *.zopim.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com *.cloudflare.com *.typekit.net *.trustedshops.com cake-editor-v2.pages.dev use.fontawesome.com fonts.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com magento-cloudflare.jetrails.com *.klarna.com js.mollie.com *.hotjar.com *.criteo.com *.criteo.net *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.ytimg.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.gstatic.com *.googleapis.com www.apptrian.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.zopim.com *.zopim.io *.alothemes.com *.magepow.com flagpedia.net https://www.mollie.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.cloudflare.com *.googleadservices.com *.google-analytics.com bat.bing.com *.lightemporium.com *.usercentrics.eu *.facebook.com *.google.de *.bidswitch.net *.doubleclick.net *.adnxs.com *.360yield.com *.media.net *.outbrain.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.criteo.com *.krxd.net *.thebrighttag.com *.yahoo.com *.casalemedia.com *.emxdgt.com *.yieldmo.com *.yieldlab.net *.tremorhub.com *.pubmatic.com *.mediavine.com *.ivitrack.com *.id5-sync.com *.omnitagjs.com *.adform.net *.3lift.com *.teads.tv *.twiago.com cake-editor-v2.pages.dev *.deinetorte.de *.kaltura.com *.pingdom.net *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com *.zopim.com *.zdassets.com *.alothemes.com *.magepow.com maps.googleapis.com js.mollie.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.cloudflare.com *.google-analytics.com *.twimg.com bat.bing.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.tiktok.com *.facebook.net *.hotjar.com *.deinetorte.de *.pingdom.net *.criteo.com cake-editor-v2.pages.dev sos-de-fra-1.exo.io *.kaltura.com *.yotpo.com swellrewards.com *.swellrewards.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.cloudflare.com *.googleapis.com *.typekit.net *.trustedshops.com *.usercentrics.eu cake-editor-v2.pages.dev *.deinetorte.de *.yotpo.com swellrewards.com *.swellrewards.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com *.zdassets.com *.zopim.com widget-mediator.zopim.com *.alothemes.com *.magepow.com www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.cloudflare.com *.zendesk.com *.tiktok.com *.facebook.com *.pingdom.net *.google-analytics.com *.doubleclick.net *.deinetorte.de *.googlesyndication.com *.adverfly.de ukl5xfabz8.execute-api.eu-central-1.amazonaws.com *.kaltura.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.deinetorte.de/; report-to report-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/passwords_google 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.multisafepay.com assets.myparcel.nl *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://browser.sentry-cdn.com *.cookiebot.com *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com cdn.jsdelivr.net *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.multisafepay.com cdn.jsdelivr.net *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io *.googlesyndication.com *.multisafepay.com api.myparcel.nl cdn.jsdelivr.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src *.force.com https://player.vimeo.com 'self' https://stats.g.doubleclick.net *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es https://*.springcm.com *.adnxs.com https://alpixtrack.com *.adis.ws https://www.gstatic.com https://view.ceros.com https://cti-client.talkdeskapp.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr https://insight.adsrvr.org https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net https://ssl.gstatic.com *.google.com *.youtube.nl https://service.force.com/embeddedservice/ https://s.yimg.com https://fast.wistia.net *.quip.com *.arkoselabs.com https://*.docusign.net https://api.mixpanel.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com https://*.mytalkdesk.com *.youtube.com.br https://deltadentalwi.file.force.com https://assets.ceros.com *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://checkoutshopper-live.adyen.com/ https://*.clm.docusign.mil *.sfdcfc.net *.doubleclick.net https://maps.a.forceusercontent.com *.youtube.ca https://location.force.com *.krxd.net *.vidyard.com https://connect.facebook.net https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://tags.tiqcdn.com https://na254.salesforce.com https://cdn.embedly.com https://media.ceros.com https://www.google.com/recaptcha/ https://bat.bing.com https://js.stripe.com/ https://www.sandbox.paypal.com https://sp.analytics.yahoo.com https://*.clmfed.docusign.com https://*.a.forceusercontent.com/lightningmaps/ https://www.googletagmanager.com *.wistia.net https://www.google-analytics.com https://pixel.sitescout.com *.salesforce.com *.youtube.pl; report-to sfdc-csp-ep; report-uri https://deltadentalwi.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00DA0000000IEY9&networkId=0DM0H000000Cie4&type=communities 1 default-src 'self'; report-uri https://api.sendsteps.com/csp-reports; connect-src https://salesiq.zohopublic.eu https://region1.google-analytics.com https://px.ads.linkedin.com https://cdn.linkedin.oribi.io https://www.facebook.com https://api.sendsteps.com https://bam.nr-data.net https://stats.g.doubleclick.net https://www.google-analytics.com https://region1.analytics.google.com https://www.google.fr https://www.google.dk https://www.google.com.tr https://www.google.com.be https://www.google.com.nl; font-src 'self'; img-src 'self' https://dev.visualwebsiteoptimizer.com https://cdn.sendsteps.com https://px.ads.linkedin.com https://www.facebook.com https://www.google.com https://www.google.com.au https://www.google.fr https://www.google.nl https://www.google.dk https://www.google.co.in https://www.google.co.za https://www.googletagmanager.com https://www.google.co.id data:; script-src 'self' 'unsafe-eval'; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://static.hotjar.com https://consent.cookiebot.com https://maillist-manage.eu https://salesiq.zoho.eu https://ma.zoho.eu https://consent.cookiebot.com https://dev.visualwebsiteoptimizer.com https://www.googletagmanager.com https://snap.licdn.com https://connect.facebook.net https://www.google-analytics.com https://www.googleoptimize.com https://sendc.scdn4.secure.raxcdn.com https://*.newrelic.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://sendc.scdn4.secure.raxcdn.com; object-src 'none'; media-src https://sendsteps-cdn-bucket.s3.eu-central-1.amazonaws.com; frame-src https://consentcdn.cookiebot.com 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-BWb4+5GMfGBP26D+b7mcxw=='; report-uri https://send.hsbrowserreports.com/csp/report 1 script-src 'self' blob: https://prod-bk-web.gb.rbi.tools/en/static/js/vendor.7a5c123f.js https://prod-bk-web.gb.rbi.tools/en/static/js/main.d33b77a8.js https://prod-bk-web.gb.rbi.tools/en/static/js/runtime.97c878a0.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.gb.rbi.tools/en/static/js/vendor.f0fbada7.js https://prod-bk-web.gb.rbi.tools/en/static/js/main.dcc223e5.js https://prod-bk-web.gb.rbi.tools/en/static/js/runtime.b282f60d.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 worker-src *.useinsider.com *.api.useinsider.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.fontawesome.com *.useinsider.com *.api.useinsider.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://plumrocket.com *.useinsider.com *.api.useinsider.com landofcoder.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.trackedlink.net *.ddlnk.net *.useinsider.com *.api.useinsider.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.useinsider.com *.api.useinsider.com landofcoder.com static.zipmoney.com.au static.zip.co zip.co https://www.horseland.com.au 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com assets.braintreegateway.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.googleapis.com *.useinsider.com *.api.useinsider.com 'self' 'unsafe-inline'; object-src *.useinsider.com *.api.useinsider.com landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.sharethis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://*.useinsider.com https://*.api.useinsider.com wss://*.useinsider.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.facebook.com *.adsrvr.org www.google.com.au *.bing.com *.criteo.com sq-trk.gammaplatform.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com libraries.unbxdapi.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal facebook.net connect.facebook.net facebook.com delta.pedders.com.au js.adsrvr.org *.bing.com *.criteo.com sq-trk.gammaplatform.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com libraries.unbxdapi.com cdnjs.cloudflare.com *.cloudfront.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com delta.pedders.com.au *.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com search.unbxd.io tracker.unbxdapi.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com https://fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.online-metrix.net www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.addtoany.com vimeo.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.cookielaw.org *.doubleclick.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ testflex.cybersource.com flex.cybersource.com *.online-metrix.net www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com js-agent.newrelic.com static.zdassets.com api.eu-1.smooch.io cdn.cookielaw.org static.addtoany.com *.googleapis.com *.typography.com *.onetrust.com *.segmentify.com *.sgmntfy.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://cdn.cookielaw.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.addtoany.com cloud.typography.com *.segmentify.com *.sgmntfy.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com thm.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ http://dpm.demdex.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com avocahelp.zendesk.com cdn.cookielaw.org api.eu-1.smooch.io bam.nr-data.net geolocation.onetrust.com widget-mediator.zopim.com privacyportaluat.onetrust.com *.zopim.com wss://widget-mediator.zopim.com *.doubleclick.net *.googleapis.com *.google-analytics.com *.segmentify.com *.sgmntfy.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com https://cdnjs.cloudflare.com *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com horace.com cdn.kustomerapp.com static.klaviyo.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.klarna.com js.stripe.com js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net https://www.google.com td.doubleclick.net www.facebook.com tr.snapchat.com tr6.snapchat.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.sharethis.com https://images.unsplash.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com https://maps.googleapis.com https://maps.gstatic.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com maps.googleapis.com maps.gstatic.com horace.com www.facebook.com bat.bing.net c.contentsquare.net cdn.cookielaw.org bat.bing.com www.google.fr cdn.prod2.kustomerhostedcontent.com www.google.es www.google.us www.google.co.uk www.google.de www.google.ir tr.snapchat.com tr6.snapchat.com https://firebasestorage.googleapis.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com cdn.jsdelivr.net https://maps.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net js.stripe.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com https://cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net maps.googleapis.com https://www.google.com https://www.gstatic.com cdn.cookielaw.org horace.com browser.sentry-cdn.com polyfill-fastly.io static.klaviyo.com connect.facebook.net try.abtasty.com static-tracking.klaviyo.com www.artfut.com bat.bing.com www.tag4arm.com t.contentsquare.net static.affilae.com sc-static.net analytics.tiktok.com www.clarity.ms cdn.amplitude.com cdn.kustomerapp.com ajax.cloudflare.com tr.snapchat.com k-aeu1.contentsquare.net porjs.com *.klarnaservices.com *.avada.io *.shopify.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sharethis.com cdn.jsdelivr.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.tagmanager.google.com *.googletagmanager.com horace.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src download-video-ak.vimeocdn.com player.vimeo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.almapay.com https://maps.googleapis.com https://player.vimeo.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app maps.googleapis.com horace.com region1.analytics.google.com cdn.cookielaw.org o4508795589427200.ingest.de.sentry.io fast.a.klaviyo.com static-forms.klaviyo.com v.clarity.ms j.clarity.ms ariane.abtasty.com try.abtasty.com dcinfos-cache.abtasty.com region1.google-analytics.com horace.api.kustomerapp.com k-aeu1.contentsquare.net www.google-analytics.com tr.snapchat.com tr6.snapchat.com s.clarity.ms bat.bing.net c.contentsquare.net www.tag4arm.com matomo.horace.app api.eu.amplitude.com porjs.com *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io https://nominatim.openstreetmap.org https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src horace.com bat.bing.com bat.bing.net c.contentsquare.net k-aeu1.contentsquare.net v.clarity.ms j.clarity.ms googleads.g.doubleclick.net www.tag4arm.com matomo.horace.app tr6.snapchat.com analytics.tiktok.com www.google.fr www.google.com porjs.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' data: cdn.cookielaw.org cdn.sanity.io https://www.google-analytics.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.google.com https://www.google.co.uk https://google.com https://ssl.gstatic.com https://www.gstatic.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com www.zego.com; connect-src 'self' api.segment.io app.launchdarkly.com b79fd5h4.api.sanity.io cdn.cookielaw.org cdn.segment.com clientstream.launchdarkly.com events.launchdarkly.com geolocation.onetrust.com jscloud.net privacyportal-de.onetrust.com https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://googletagmanager.com https://www.google.com https://www.google.co.uk https://google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://www.googleadservices.com www.zego.com; script-src 'self' 'unsafe-inline' cdn.cookielaw.org cdn.segment.com d.la1-c2-lo2.salesforceliveagent.com d.la1-core1.sfdc-5pakla.salesforceliveagent.com jscloud.net service.force.com widget.trustpilot.com www.youtube.com https://www.google.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net www.zego.com; style-src 'self' 'unsafe-inline' service.force.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com www.zego.com; frame-src 'self' service.force.com widget.trustpilot.com www.youtube.com https://www.googletagmanager.com; font-src 'self' data: https://fonts.gstatic.com www.zego.com; frame-ancestors 'none'; report-uri https://o53180.ingest.us.sentry.io/api/4507583918637056/security/?sentry_key=3a1e5c7ad4a38458d3a2ba8757c90d2f&sentry_release=zego-website-cms&sentry_environment=production; report-to csp-endpoint; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.yotpo.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.yotpo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudflare.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.yotpo.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://scanova.report-uri.com/r/d/csp/reportOnly; default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://qcg-media.s3.us-west-2.amazonaws.com *.visualwebsiteoptimizer.com *.raygun.io *.cookie-script.com *.quora.com *.doubleclick.com *.woopra.com *.jsdelivr.net *.g2crowd.com *.subscribers.com script.tapfiliate.com *.googletagmanager.com *.google.com *.gstatic.com *.google-analytics.com *.licdn.com *.zdassets.com *.zopim.com scripts.iconnode.com *.bing.com *.clarity.ms *.picreel.com *.pcrl.co *.facebook.net googleads.g.doubleclick.net infinity-public-js.500apps.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com; img-src 'self' data: https://qcg-media.s3.us-west-2.amazonaws.com *.visualwebsiteoptimizer.com https://ap1-infinity-user-data.s3.amazonaws.com *.clarity.ms *.google.com *.google.co.in *.bing.com *.googletagmanager.com *.google-analytics.com *.quora.com *.g2crowd.com *.linkedin.com *.facebook.com *.amazonaws.com; font-src 'self' *.gstatic.com; connect-src 'self' *.execute-api.us-west-2.amazonaws.com *.raygun.io *.googlesyndication.com *.scanova.io *.visualwebsiteoptimizer.com *.woopra.com *.clarity.ms *.google-analytics.com *.doubleclick.net *.zdassets.com scanova.zendesk.com *.g2crowd.com *.subscribers.com *.zopim.com wss://widget-mediator.zopim.com *.iconnode.com frstre.com *.linkedin.com *.oribi.io *.google.com *.google.co.in tracking-api.g2.com facebook.com www.facebook.com; frame-src 'self' *.google.com *.youtube.com *.doubleclick.net *.facebook.net *.googletagmanager.com td.doubleclick.net; base-uri 'self'; frame-ancestors 'self'; worker-src 'self' blob:; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.twitter.com *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint *.paypal.com *.kaptcha.com *.google.com *.mention-me.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint www.apptrian.com www.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint *.paypal.com *.pureclarity.net *.google.com *.chimpstatic.com www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.mention-me.com maps.googleapis.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.braintreegateway.com *.csp-reporting-service.com *.braintree-api.com *.csp-reporting-service.com/my-project/endpoint *.pureclarity.net www.apptrian.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.mention-me.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google.com google.com landofcoder.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 200.12.146.183/ 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://vpos.infonet.com.py:8888 https://vpos.infonet.com.py https://desa.infonet.com.py:8035 https://desa.infonet.com.py https://www.bancard.com.py https://bancard.com.py www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://vpos.infonet.com.py https://vpos.infonet.com.py:8888 https://www.bancard.com.py https://bancard.com.py www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.zdassets.com *.zendesk.com *.embluemail.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.zdassets.com *.zendesk.com *.embluemail.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zendesk.com *.embluemail.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' www.google-analytics.com; font-src 'self' fonts.gstatic.com use.fontawesome.com; frame-src 'self' platform.twitter.com syndication.twitter.com www.google.com; img-src 'self' data: w3.org/svg/2000 google-analytics.com syndication.twitter.com www.googletagmanager.com; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-inline' ajax.googleapis.com code.jquery.com connect.facebook.net platform.twitter.com www.google.com www.google-analytics.com www.googletagmanager.com www.gstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' fonts.googleapis.com use.fontawesome.com; worker-src 'none'; default-src 'self' 'report-sample'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://recaptcha.google.com/recaptcha/ https://www.google.com https://www.google.com/recaptcha/;script-src 'nonce-3c75f2b5d16a4c85bb9f69419f75ca67' https://www.mypremisehealth.com 'self' https://www.google.com https://www.googletagmanager.com/gtag/js?id=G-HNEDQ0L1ZB;img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.mypremisehealth.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.afterpay.com *.sandbox.paypal.com *.cardinalcommerce.com *.dev.rvvuptech.com *.rvvup.com www.apple.com apple.com browser-intake-datadoghq.com browser-intake-datadoghq.eu *.google-analytics.com api.craftyclicks.co.uk *.bronto.com *.brontops.com pcls1.craftyclicks.co.uk *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk app.termly.io bat.bing.net bat.bing.com storage.googleapis.com event-service-jtdpxp3bfa-ew.a.run.app q.clarity.ms data.anglingactive.co.uk backend.shopbox.ai a.clarity.ms i.clarity.ms y.clarity.ms v.clarity.ms l.clarity.ms h.clarity.ms d.clarity.ms e.clarity.ms f.clarity.ms o.clarity.ms m.clarity.ms j.clarity.ms k.clarity.ms s.clarity.ms n.clarity.ms b.clarity.ms z.clarity.ms eu.consent.api.termly.io *.shopbox.ai *.anglingactive.co.uk fm.trackdesk.com translate.googleapis.com www.google.co.uk www.google.com report.clarity.ms googleads.g.doubleclick.net pagead2.googlesyndication.com www.google.ie anglingactive.co.uk fonts.googleapis.com fonts.gstatic.com www.facebook.com stats.g.doubleclick.net www.anglingactive.co.uk region1.analytics.google.com region1.google-analytics.com www.clarity.ms scripts.clarity.ms 'self' 'unsafe-inline'; report-uri https://www.anglingactive.co.uk/csp_report_watch; child-src *.paypal.com assets.braintreegateway.com c.paypal.com www.anglingactive.co.uk http: https: blob: 'self' 'unsafe-inline'; base-uri www.anglingactive.co.uk 'self' 'unsafe-inline'; 1 default-src 'self' *.roche.com *.roche.net *.gene.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.roche.com *.roche.net *.gene.com cdn.walkme.com apis.google.com tpc.googlesyndication.com api.html5media.info workdevapp.com cdn-js.net gdata.youtube.com twitter.com geolocation.onetrust.com api.flickr.com graph.facebook.com sharecdn.social9.com maps.googleapis.com use.typekit.com munchkin.marketo.net img.en25.com w.likebtn.com cdn.mathjax.org sadmin.brightcove.com cdnjs.cloudflare.com releases.flowplayer.org script.crazyegg.com wi.likebtn.com pepperglobal.com analytics.twitter.com cdn.blueconic.net connect.facebook.net fullstory.com script.hotjar.com gnntch.blueconic.net rules.quantcount.com secure.quantserve.com static.hotjar.com www.youtube.com www.googletagmanager.com www.google-analytics.com google-analytics.com *.gstatic.com static.ads-twitter.com sjs.bizographics.com *.linkedin.com www.google.com w.soundcloud.com s.ytimg.com *.cloudflareaccess.com *.salesforceliveagent.com https://*.roche.com:8080 https://cdnjs.org https://service.force.com/* cdn.cookielaw.org static.cloudflareinsights.com googleads.g.doubleclick.net 7232514.collect.igodigital.com; style-src * 'self' 'unsafe-inline'; img-src * 'self' data:; font-src * 'self' data:; connect-src * 'self'; media-src * 'self' data:; object-src 'self'; child-src 'self' *.roche.com *.roche.net *.gene.com *.facebook.net qpcr.probefinder.com *.force.com *.hotjar.com www.facebook.com www.google.com www.googletagmanager.com www.youtube.com; frame-src 'self' *.roche.com *.roche.net *.gene.com www.youtube.com sites.google.com *.cloudfront.net *.facebook.net *.arcot.com live.sagepay.com player.vimeo.com tpc.googlesyndication.com players.brightcove.net qpcr.probefinder.com *.eloqua.com *.hotjar.com *.soundcloud.com *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.mendeley.com *.force.com https://cdn.walkme.com/*; worker-src 'self' *.roche.com *.roche.net *.gene.com; frame-ancestors 'self' *.roche.com *.roche.net *.gene.com datastudio.google.com sites.google.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com *.cloudflareworkers.com; form-action 'self' *.roche.com *.roche.net *.gene.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com; base-uri 'self' *.roche.com *.roche.net *.gene.com *.secure.roche.com; report-uri https://ayba8dhs.uriports.com/reports/report; report-to default 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com *.google.com *.googletagmanager.com data: *.akamaized.net https://cdn.shopify.com *.fastsimon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com *.amazon.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.amazonaws.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com google.com www.googletagmanager.com *.yotpo.com *.amazon.com *.dotdigital-pages.com *.dotdigital.com www.xtento.com https://www.google.com https://www.p65warnings.ca.gov *.google.com *.googletagmanager.com *.paypal.com *.g.doubleclick.net *.fls.doubleclick.net *.braintreegateway.com *.dnky.co *.paypalobjects.com https://elements.sandbox.fortis.tech https://elements.fortis.tech *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.b0e8.com *.yotpo.com *.ssl-images-amazon.com www.xtento.com cdn.xtento.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com www.google.co.in *.doubleclick.net https://ping-dot-acp-magento.appspot.com https://acp-magento.appspot.com https://cdn1-gae-ssl-default.akamaized.net *.instantsearchplus.com webchat.dotdigital.com https://ultimate-dot-acp-magento.appspot.com *.googleusercontent.com *.landmsupply.com https://t.powerreviews.com https://services.powerequipment.honda.com https://www.rockyboots.com https://m.media-amazon.com https://contentgrid.homedepot-static.com https://res.cloudinary.com *.google-analytics.com *.google.co.in *.privacysandbox.googleadservices.com *.clarity.ms *.stats.paypal.com *.sandbox.paypal.com *.g.doubleclick.net *.paypalobjects.com *.powerreviews.com *.akamaized.net *.gfycat.com *.bing.com https://meetanshi.com/media/logo.png ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.b0e8.com *.bc0a.com *.authorize.net *.yotpo.com *.payments-amazon.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com chimpstatic.com https://ping-dot-acp-magento.appspot.com https://acp-magento.appspot.com https://cdn1-gae-ssl-default.akamaized.net *.googleapis.com webchat.dotdigital.com https://ultimate-dot-acp-magento.appspot.com *.newrelic.com https://bam.nr-data.net https://www.gstatic.com https://www.google.com https://ui.powerreviews.com https://static.powerreviews.com https://mpsnare.iesnare.com https://www.googleoptimize.com https://cdn-4.convertexperiments.com *.appspot.com api.fastsimon.com bam.nr-data.net *.powerreviews.com *.google.com *.gstatic.com *.braintreegateway.com *.paypal.com *.googleadservices.com *.g.doubleclick.net *.dnky.co *.google-analytics.com *.googletagmanager.com *.paypalobjects.com *.hotjar.com *.clarity.ms *.netdna-ssl.com *.amazonaws.com downloads.mailchimp.com *.list-manage.com https://developer.adobe.com https://magento.com https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech *.kaptcha.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.yotpo.com *.googleapis.com stats.g.doubleclick.net www.google-analytics.com *.google.com *.googletagmanager.com fonts.googleapis.com *.gstatic.com https://cdn1-gae-ssl-default.akamaized.net https://ui.powerreviews.com *.fastsimon.com *.dnky.co *.powerreviews.com *.akamaized.net *.mailchimp.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.authorize.net *.yotpo.com *.amazon.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.doubleclick.net *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com wss: *.paypal.com https://bam.nr-data.net https://ui.powerreviews.com *.powerreviews.com *.fastsimon.com *.instantsearchplus.com *.google-analytics.com *.sandbox.braintree-api.com *.nr-data.net *.appspot.com *.dotdigital.com *.clarity.ms *.hotjar.io *.convertexperiments.com https://developer.adobe.com https://elements.sandbox.fortis.tech https://elements.fortis.tech *.kaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self'; font-src 'self' data:; img-src 'self' data:; script-src 'self'; style-src 'self'; report-uri https://teratorium.uriports.com/reports/report; report-to default 1 object-src 'none'; script-src 'unsafe-inline' 'self' 'unsafe-eval' blob: localhost host.docker.internal:59000 unpkg.com cdn.jsdelivr.net *.githubusercontent.com *.hellobar.com *.googletagmanager.com *.google-analytics.com *.totalenergies.be *.force.com *.salesforce.com *.salesforce-sites.com *.my.site.com *.my.salesforce-scrt.com *.bing.com *.google.com *.googleapis.com *.doubleclick.net *.trustcommander.net *.youtube.com maps.gstatic.com *.lampiris.be *.optimizely.com *.amazonaws.com *.contentsquare.net *.pinimg.com *.sentry-cdn.com *.trustcommander.net *.pingdom.net *.facebook.net *.pinterest.com *.agconsult.com *.alchemer.eu *.teads.tv *.outbrain.com *.adlooxtracking.com *.licdn.com *.aticdn.net 1 report-uri https://www.schweitzer-online.de/iconparc/webmed/StoreFront/contentSecurityPolicyReport.ipm; default-src 'self'; script-src 'self' https://*.schweitzer-online.de https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://player.vimeo.com https://appjs.blickinsbuch.de 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https://*.schweitzer-online.de https://search.lereto.com https://*.googletagmanager.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.google.com https://pagead2.googlesyndication.com https://*.google.de https://www.googleadservices.com https://google.com; style-src 'self' https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://*.schweitzer-online.de https://fonts.gstatic.com data: data:; img-src https://* https://*.googletagmanager.com https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.google.com https://*.google.de https://googleads.g.doubleclick.net https://www.google.com https://pagead2.googlesyndication.com https://www.googleadservices.com https://google.com data:; form-action 'self' https://secure.payengine.de; frame-src 'self' https://player.vimeo.com https://www.book2look.com https://www.bic-media.com https://search.lereto.com https://mailing2.schweitzer-online.de https://sfi.snackz.ai https://develop.sfi.snackz.ai https://www.googletagmanager.com https://td.doubleclick.net; frame-ancestors 'self'; 1 default-src 'self' https://gapi.storyblok.com https://api.storyblok.com https://a.storyblok.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.wistia.com https://*.wistia.net netlify-cdp-loader.netlify.app 'unsafe-inline' blob: data:; script-src 'nonce-t3kYXECOyTWk5gS4huelZAZmZclYvBQl' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' 'unsafe-inline' 'unsafe-eval' https://*.hotjar.com https://*.storyblok.com https://netlify-rum.netlify.app https://*.wistia.com https://*.wistia.net https://src.litix.io *.visualwebsiteoptimizer.com app.vwo.com https://www.googletagmanager.com https://tagmanager.google.com https://*.onetrust.com https://*.google-analytics.com d.adroll.com s.adroll.com d.adroll.mgr.consensu.org dsum-sec.casalemedia.com eb2.3lift.com googleads.g.doubleclick.net p.adsymptotic.com px.ads.linkedin.com px4.ads.linkedin.com pixel.advertising.com pixel.rubiconproject.com image2.pubmatic.com simage2.pubmatic.com snap.licdn.com sync.outbrain.com sync.taboola.com trc.taboola.com ads.yahoo.com ups.analytics.yahoo.com www.facebook.com connect.facebook.net idsync.rlcdn.com ib.adnxs.com x.bidswitch.net https://js.driftt.com https://widget.drift.com *.livechatinc.com *.youtube.com *.google.com *.livechat-static.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.hotjar.com https://fast.wistia.com https://*.onetrust.com *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com https://www.googletagmanager.com https://tagmanager.google.com *.livechatinc.com *.youtube.com *.google.com blob:; img-src 'self' https://*.hotjar.com https://*.storyblok.com https://*.wistia.com https://*.wistia.net *.visualwebsiteoptimizer.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com https://*.onetrust.com https://*.doubleclick.net https://*.bing.com https://*.google-analytics.com www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com d.adroll.com s.adroll.com d.adroll.mgr.consensu.org dsum-sec.casalemedia.com eb2.3lift.com googleads.g.doubleclick.net p.adsymptotic.com px.ads.linkedin.com px4.ads.linkedin.com pixel.advertising.com pixel.rubiconproject.com image2.pubmatic.com simage2.pubmatic.com snap.licdn.com sync.outbrain.com sync.taboola.com trc.taboola.com ads.yahoo.com ups.analytics.yahoo.com www.facebook.com connect.facebook.net idsync.rlcdn.com ib.adnxs.com x.bidswitch.net *.livechatinc.com *.youtube.com *.google.com *.livechat-files.com *.livechat-static.com data:; connect-src 'self' https://*.storyblok.com https://*.wistia.com https://*.wistia.net https://*.algolia.net *.visualwebsiteoptimizer.com app.vwo.com ingesteer.services-prod.nsvcs.net https://*.onetrust.com https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://*.google.com https://*.bing.com https://*.litix.io https://*.doubleclick.net https://gapi.storyblok.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://www.googletagmanager.com px.ads.linkedin.com px4.ads.linkedin.com www.facebook.com connect.facebook.net www.google.com.au; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://*.hotjar.com https://*.wistia.com data:; object-src 'self' *.livechatinc.com *.youtube.com *.google.com; frame-src 'self' https://gapi.storyblok.com app.netlify.com netlify-cdp-loader.netlify.app https://*.vwo.com https://*.youtube-nocookie.com https://dev.visualwebsiteoptimizer.com https://fast.wistia.com https://fast.wistia.net https://td.doubleclick.net app.vwo.com *.visualwebsiteoptimizer.com https://js.driftt.com https://widget.drift.com https://info.leap.com.au *.livechatinc.com x.adroll.com; worker-src 'self' blob:; media-src 'self' https://*.wistia.com https://*.wistia.net *.livechatinc.com *.youtube.com *.google.com *.livechat-static.com https://js.driftt.com https://widget.drift.com blob: data:; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://app.storyblok.com; script-src-elem 'self' 'unsafe-inline' *.visualwebsiteoptimizer.com app.vwo.com https://pi.pardot.com s.adroll.com https://*.wistia.com https://*.bing.com https://*.onetrust.com https://netlify-rum.netlify.app; script-src-attr 'self' 'unsafe-inline'; child-src *.livechatinc.com *.youtube.com *.google.com blob:; upgrade-insecure-requests; report-uri /.netlify/functions/__csp-violations 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.oct8ne.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.google.com/ *.doubleclick.net *.facebook.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com *.gstatic.com maps.googleapis.com maps.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://cdn.clerk.io https://www.magezon.com intpaye.netsgroup.com *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://api.clerk.io https://cdn.clerk.io s7.addthis.com *.oct8ne.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com ekr.zdassets.com/ *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-58517287-9e6e-43c9-8a0c-22145fc0bec8' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.mariacasino.se https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.mariacasino.se/eum-collector/report/csp-report; 1 font-src *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com account.fetchify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.google.com *.google.fr *.google.ie *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com *.cloudfront.net *.civiccomputing.com *.cartcontents.com *.noibu.com *.hotjar.com *.googleapis.com *.apple.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'unsafe-hashes'; style-src *.adobe.com cc-cdn.com *.fontawesome.com *.cdn-apple.com https://www.duffells.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.doubleclick.net *.googleapis.com *.civiccomputing.com wss://am.freshrelevance.com *.dycdn.net *.cloudfront.net *.freshrelevance.com *.noibu.com wss://input.noibu.com *.google.com https://pay.google.com *.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src *.force.com https://player.vimeo.com https://content.instrumentation.getconga.com 'self' https://stats.g.doubleclick.net https://*.vertexgpsaxis.com *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://vertex.my-fulfillment.com *.cybersource.com *.youtube.es https://*.springcm.com *.adis.ws https://www.gstatic.com https://composer.congamerge.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://pay.google.com *.vimeo.com *.youtube.jp https://template-vertex.my-fulfillment.com bcove.video https://vrtx-mosaic.my.site.com *.youtube.fr https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com https://data.instrumentation.getconga.com *.youtube.com *.brightcove.net https://vrtx-mosaic.file.force.com https://ssl.gstatic.com *.youtube.nl https://*.vonage.com https://service.force.com/embeddedservice/ https://*.congaplatform.com https://fast.wistia.net *.quip.com *.arkoselabs.com https://*.docusign.net https://api.mixpanel.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com *.youtube.com.br *.salesforce-experience.com https://*.newvoicemedia.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://fonts.gstatic.com https://checkoutshopper-live.adyen.com/ https://*.clm.docusign.mil *.sfdcfc.net *.youtube.ca https://location.force.com https://fonts.googleapis.com *.vidyard.com https://vrtx-mosaic.my.salesforce-scrt.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://usa356.sfdc-yfeipo.salesforce.com https://*.clmfed.docusign.com https://*.a.forceusercontent.com/lightningmaps/ https://privacyportal.onetrust.com https://www.googletagmanager.com *.wistia.net https://www.google-analytics.com *.salesforce.com *.youtube.pl; report-to sfdc-csp-ep; report-uri https://vrtx-mosaic.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D36000001HCc8&networkId=0DMHp000000OnQg&type=communities 1 default-src 'none'; manifest-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com *.pusher.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://ssl.gstatic.com https://accounts.google.com https://apis.google.com https://www.gstatic.com https://www.google.com https://static.zuora.com https://static.userguiding.com/ *.fullstory.com https://cdn.jsdelivr.net https://cdn.pendo.io https://pendo-static-4789186942795776.storage.googleapis.com https://content-4789186942795776.static.pendo.io https://data.pendo.io https://content.product.canopytax.com https://data.product.canopytax.com https://app.pendo.io https://*.pusher.com https://unpkg.com https://www.google-analytics.com https://js.sentry-cdn.com https://browser.sentry-cdn.com https://static.userguiding.com https://d2yyd1h5u9mauk.cloudfront.net https://surveys-web.delighted.com https://static.zdassets.com https://cdn.jsdelivr.net/npm/react@18.3.1/umd/react.production.min.js https://cdn.jsdelivr.net/npm/react-dom@18.3.1/umd/react-dom.production.min.js https://cdn.jsdelivr.net/npm/react-dom@18.3.1/umd/react-dom-server.browser.production.min.js https://cdn.jsdelivr.net/npm/react-router-dom@6.30.1/dist/umd/react-router-dom.production.min.js https://cdn.jsdelivr.net/npm/react-hook-form@7.53.0/dist/index.umd.min.js https://cdn.jsdelivr.net/npm/lodash@4.17.15/lodash.min.js https://cdn.jsdelivr.net/npm/moment@2.24.0/moment.min.js https://cdn.jsdelivr.net/npm/luxon@3.4.3/build/amd/luxon.min.js https://cdn.jsdelivr.net/npm/prop-types@15.7.2/prop-types.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs-operators.min.js https://cdn.jsdelivr.net/npm/single-spa@5.5.5/lib/system/single-spa.min.js https://cdn.jsdelivr.net/npm/single-spa-canopy@3.1.0/lib/system/single-spa-canopy.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/named-exports.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/named-register.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/use-default.min.js https://cdn.jsdelivr.net/npm/jquery@2.2.4/dist/jquery.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs-shared.min.js; script-src-elem 'unsafe-inline' *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com *.pusher.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://ssl.gstatic.com https://accounts.google.com https://apis.google.com https://www.gstatic.com https://www.google.com https://static.zuora.com https://static.userguiding.com/ *.fullstory.com https://cdn.jsdelivr.net https://cdn.pendo.io https://pendo-static-4789186942795776.storage.googleapis.com https://content-4789186942795776.static.pendo.io https://data.pendo.io https://content.product.canopytax.com https://data.product.canopytax.com https://app.pendo.io https://*.pusher.com https://unpkg.com https://www.google-analytics.com https://js.sentry-cdn.com https://browser.sentry-cdn.com https://static.userguiding.com https://d2yyd1h5u9mauk.cloudfront.net https://surveys-web.delighted.com https://static.zdassets.com https://cdn.jsdelivr.net/npm/react@18.3.1/umd/react.production.min.js https://cdn.jsdelivr.net/npm/react-dom@18.3.1/umd/react-dom.production.min.js https://cdn.jsdelivr.net/npm/react-dom@18.3.1/umd/react-dom-server.browser.production.min.js https://cdn.jsdelivr.net/npm/react-router-dom@6.30.1/dist/umd/react-router-dom.production.min.js https://cdn.jsdelivr.net/npm/react-hook-form@7.53.0/dist/index.umd.min.js https://cdn.jsdelivr.net/npm/lodash@4.17.15/lodash.min.js https://cdn.jsdelivr.net/npm/moment@2.24.0/moment.min.js https://cdn.jsdelivr.net/npm/luxon@3.4.3/build/amd/luxon.min.js https://cdn.jsdelivr.net/npm/prop-types@15.7.2/prop-types.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs-operators.min.js https://cdn.jsdelivr.net/npm/single-spa@5.5.5/lib/system/single-spa.min.js https://cdn.jsdelivr.net/npm/single-spa-canopy@3.1.0/lib/system/single-spa-canopy.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/system.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/amd.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/named-exports.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/named-register.min.js https://cdn.jsdelivr.net/npm/systemjs@6.15.1/dist/extras/use-default.min.js https://cdn.jsdelivr.net/npm/jquery@2.2.4/dist/jquery.min.js https://cdn.jsdelivr.net/npm/@esm-bundle/rxjs/system/rxjs-shared.min.js; connect-src *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://api.intercom.io https://api-iam.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io https://nexus-long-poller-a.intercom.io https://nexus-long-poller-b.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com wss://*.pusher.com wss://*.pusherapp.com https://*.pusher.com https://*.pusherapp.com https://stat.userguiding.com/ https://api.userguiding.com/ https://user.userguiding.com/ https://metrics.userguiding.com/ https://static.userguiding.com/ https://sdk.userguiding.com *.fullstory.com https://rum-http-intake.logs.datadoghq.com https://rum.browser-intake-datadoghq.com/api/v2/rum https://web.delighted.com https://surveys-web.delighted.com https://localhost:* http://localhost:* wss://localhost:* https://ielocal:* https://static.zdassets.com https://ekr.zdassets.com https://ekr.zendesk.com https://canopytax.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://canopytax.zendesk.com wss://*.zopim.com https://o4504080391733248.ingest.sentry.io/ https://api-js.mixpanel.com https://canopy.thoughtspot.cloud https://checkoutshopper-live-us.adyen.com https://checkoutshopper-live.adyen.com https://data.pendo.io https://pendo-static-4789186942795776.storage.googleapis.com https://content-4789186942795776.static.pendo.io https://data.product.canopytax.com https://content.product.canopytax.com https://app.pendo.io; form-action *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://intercom.help https://api-iam.intercom.io; media-src https://js.intercomcdn.com https://v2assets.zopim.io https://static.zdassets.com; child-src blob: *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://checkoutshopper-live.adyen.com https://checkoutshopper-live-us.adyen.com; frame-src *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://accounts.google.com https://www.google.com https://www.zuora.com https://apisandbox.zuora.com https://canopy.page.link https://ls.userguiding.com https://canopy.thoughtspot.cloud/ https://checkoutshopper-live-us.adyen.com https://app.pendo.io https://portal.pendo.io; style-src 'unsafe-inline' https://ssl.gstatic.com https://fonts.googleapis.com https://fonts.google.com/ https://cdn.canopytax.com https://pendo-io-static.storage.googleapis.com https://pendo-static-4789186942795776.storage.googleapis.com https://content-4789186942795776.static.pendo.io https://content.product.canopytax.com https://app.pendo.io; style-src-elem 'unsafe-inline' https://ssl.gstatic.com https://fonts.googleapis.com https://fonts.google.com/ https://cdn.canopytax.com; img-src data: blob: *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://messenger-apps.intercom.io https://*.intercom-attachments.com https://la.www4.irs.gov https://csi.gstatic.com https://static.userguiding.com/ https://v2assets.zopim.io https://canopytax.zendesk.com https://checkoutshopper-live.adyen.com https://f.hubspotusercontent40.net https://cdn.pendo.io https://data.pendo.io https://pendo-static-4789186942795776.storage.googleapis.com https://content-4789186942795776.static.pendo.io https://content.product.canopytax.com https://data.product.canopytax.com https://app.pendo.io; font-src data: *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com https://js.intercomcdn.com https://fonts.intercomcdn.com https://fonts.googleapis.com https://fonts.gstatic.com http://fonts.gstatic.com https://static.userguiding.com https://cdn.pendo.io; worker-src blob: *.canopytax.com *.clientportal.com https://www.getcanopy.com https://us-central1-metal-appliance-191920.cloudfunctions.net https://beanstalk-production.s3.amazonaws.com https://beanstalk-production.s3-us-west-2.amazonaws.com https://beanstalk-production.s3.us-west-2.amazonaws.com https://s3-us-west-2.amazonaws.com https://canopy-cme-migrations.s3.amazonaws.com; frame-ancestors 'self' https://app.canopytax.com https://*.clientportal.com https://app.pendo.io; upgrade-insecure-requests; report-uri https://app.canopytax.com/_/csp-reports 1 default-src 'none'; media-src 'self'; object-src 'none'; worker-src 'self' blob:; child-src 'self' blob:; manifest-src 'self'; base-uri 'none'; form-action 'self'; img-src 'self' data: *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; frame-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; frame-ancestors 'none'; script-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org 'unsafe-inline'; style-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; connect-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; upgrade-insecure-requests 1 object-src 'none'; connect-src 'self' *.adulttime.xxx *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.adulttime.xxx *.adulttime.com join.gammasecure.com; script-src 'self' *.adulttime.xxx *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.adulttime.xxx *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src https:; connect-src https: 'unsafe-eval' 'unsafe-inline' wss://pubsubsec.usedesk.ru; script-src https: 'unsafe-eval' 'unsafe-inline' pubsubsec.usedesk.ru; style-src https: 'unsafe-inline' pubsubsec.usedesk.ru; img-src https: data:; font-src https: data:; report-uri /csp-report 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gold-collagen.com *.klaviyo.com wordpress-603805-2583042.cloudwaysapps.com *.hotjar.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://cdnjs.cloudflare.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com *.google.com *.cookiebot.com tracead.com *.smct.io *.pubxtags.com *.cloudfront.net *.facebook.com *.referralcorner.com *.referralcandy.com *.revenuehunt.com *.hubspot.com *.hs-sites.com *.hubspot.net *.hubspotvideo.com *.hsforms.net *.hsforms.com *.hotjar.com *.gotolstoy.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.trackedlink.net *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.co.uk *.postcodeanywhere.co.uk *.ojrq.net *.bing.com *.facebook.com *.hubspot.com *.clarity.ms privymktg.com *.hsforms.com google-analytics.com *.smct.co *.cloudfront.net *.cookiebot.com *.cdninstagram.com *.klaviyo.com *.hscta.net *.hubspot.net *.hsforms.net *.revenuehunt.com *.cloudflare.com *.hotjar.com *.gotolstoy.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.impactcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.google-analytics.com *.googletagmanager.com *.revenuehunt.com *.pcapredict.com *.postcodeanywhere.co.uk *.cloudfront.net foursixty.com *.facebook.com *.klaviyo.com *.hs-scripts.com *.hsadspixel.net *.hs-analytics.net *.hscta.net *.hubspot.com *.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hubspotfeedback.com *.cloudflareinsights.com *.cookiebot.com widget.privy.com bat.bing.com cdn.subscribers.com www.dwin1.com amplify.outbrain.com www.clarity.ms cdn.mouseflow.com *.hotjar.com tracead.com *.outbrain.com smct.co *.simplybook.it *.gotolstoy.com unpkg.com/isotope-layout@3/dist/isotope.pkgd.min.js *.referralcandy.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://cdnjs.cloudflare.com *.trustpilot.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.postcodeanywhere.co.uk foursixty.com *.typekit.net *.privy.com *.facebook.com facebook.com *.klaviyo.com *.hubspot.net *.hotjar.com *.gotolstoy.com *.stripe.network *.stripecdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.sjv.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.doubleclick.net *.postcodeanywhere.co.uk *.trustpilot.com foursixty.com *.facebook.com *.hubapi.com *.hscta.net *.hubspot.com *.hubspot.net *.hscollectedforms.net *.hsforms.com bat.bing.com api.privy.com cdn.subscribers.com consentcdn.cookiebot.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.outbrain.com *.clarity.ms www.google.co.uk *.gotolstoy.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5148347479da3459658221e6e4e6815c.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: https://*.sovendus.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com https://app-wallee.com https://paymentshub.weareplanet.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.cookiebot.com maps.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://*.sovendus.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.disqus.com tracking.moevenpick-wein.com *.cookiebot.com maps.googleapis.com newsletter.moevenpick-wein.de http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://*.sovendus.com https://www.sovopt.com https://static.sovopt.com https://www.getback.ch https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com consent.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com https://static.getback.ch https://*.sovendus.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com tracking.moevenpick-wein.com *.cookiebot.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://app-wallee.com https://paymentshub.weareplanet.com https://assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.accesstrade.in *.accesstrade.in.th https://static.klaviyo.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.accesstrade.in *.accesstrade.in.th https://*.2c2p.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.accesstrade.in *.accesstrade.in.th *.weltpixel.com https://vars.hotjar.com https://bid.g.doubleclick.net *.facebook.com *.doubleclick.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.accesstrade.in *.accesstrade.in.th https://i.ibb.co https://googleads.g.doubleclick.net https://www.google.com https://www.google.co.th https://www.facebook.com https://www.google.com.vn *.cloudfront.net *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.accesstrade.in *.accesstrade.in.th https://js-agent.newrelic.com https://bam.nr-data.net https://connect.facebook.net *.hotjar.com https://www.google.com https://www.google.com.vn https://www.google.co.th https://googleads.g.doubleclick.net *.clarity.ms *.cardinalcommerce.com *.adobetm.com https://www.googleadservices.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.klaviyo.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com *.accesstrade.in *.accesstrade.in.th https://www.googletagmanager.com/ fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.accesstrade.in *.accesstrade.in.th *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.accesstrade.in *.accesstrade.in.th https://stats.g.doubleclick.net https://bam.nr-data.net https://in.hotjar.com https://www.facebook.com *.clarity.ms *.ap.stape.info ap.stape.info analytics.pangle-ads.com analytics-ipv6.tiktokw.us *.hotjar.io *.google.com *.google.co.th *.google.com.vn *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com cdn.checkout.com *.global-e.com *.bglobale.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.twitter.com *.google.com *.trustpilot.com *.checkout.com *.bglobale.com *.global-e.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.google.com *.google.co.uk *.zopim.com *.doubleclick.net d23yuld0pofhhw.cloudfront.net *.googletagmanager.com *.global-e.com *.newrelic.com *.bglobale.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.googletagmanager.com *.googlecommerce.com *.doubleclick.net *.trustpilot.com *.zopim.com *.zdassets.com *.payments-amazon.com *.amazon.com *.local.com maps.googleapis.com *.checkout.com *.paypal.com *.bglobale.com *.global-e.com https://unpkg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.googletagmanager.com tagmanager.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.fontawesome.com *.checkout.com *.bglobale.com *.global-e.com https://static.klaviyo.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.zdassets.com *.zopim.com *.amazon.com 'self' wss: *.checkout.com *.google-analytics.com *.doubleclick.net *.paypalobjects.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.googleapis.com https://client.crisp.chat https://fonts.gstatic.com https://ws.colissimo.fr https://applepay.cdn-apple.com applepay.cdn-apple.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com fonts.gstatic.com https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com *.monetico-services.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com https://www.youtube.com https://form.typeform.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.monetico-services.com api-qa.payplug.com secure-qa.payplug.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.gstatic.com *.doubleclick.net *.imgix.net *.twic.pics *.googleapis.com https://images.unsplash.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org https://image.crisp.chat https://assets.fintecture.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://secure-magenta.dalenys.com https://firebasestorage.googleapis.com https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.net *.facebook.com *.imgix.net *.axept.io *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.googleapis.com https://maps.googleapis.com https://client.crisp.chat https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.connectif.cloud applepay.cdn-apple.com https://cdn.payplug.com https://cdn-qa.payplug.com *.avada.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com fonts.googleapis.com https://client.crisp.chat https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://secure-magenta.dalenys.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.axept.io *.google-analytics.com *.google.com *.doubleclick.net *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://ws.colissimo.fr *.onyourmap.com https://*.mapbox.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://nominatim.openstreetmap.org https://*.onyourmap.com *.monetico-services.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.connectif.cloud https://get.geojs.io *.avada.io maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net https://fonts.gstatic.com cdn.almapay.com *.googleapis.com *.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ www.google.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com unpkg.com/@googlemaps/markerclusterer/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.googleapis.com *.gstatic.com *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net https://maps.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com unpkg.com/@googlemaps/markerclusterer/ https://cdnjs.cloudflare.com https://maps.googleapis.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net https://fonts.googleapis.com fonts.googleapis.com *.certcapture.com downloads.mailchimp.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://places.googleapis.com/ https://maps.googleapis.com/ 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src unpkg.com/@googlemaps/markerclusterer/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.cookiebot.com static.klaviyo.com *.newrelic.com *.queue-it.net *.yotpo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.cookiebot.com *.adsrvr.org *.smct.io *.newrelic.com *.doubleclick.net *.cloudfront.net *.queue-it.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.cookiebot.com *.bing.com *.newrelic.com *.clarity.ms cdn.noibu.com *.cloudfront.net x.klarnacdn.net *.queue-it.net www.google.co.uk alb.reddit.com www.facebook.com *.yotpo.com ads-twitter.com *.ads-twitter.com *.twitter.com t.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.cookiebot.com *.hotjar.com *.bing.com *.webgains.io *.clarity.ms *.tiktok.com *.adsrvr.org *.stackadapt.com *.smct.co smct.co *.smct.io *.noibu.com *.upsellit.com *.scriptcdn.net *.redditstatic.com *.queue-it.net rum.hlx.page *.abtasty.com *.yotpo.com ads-twitter.com *.ads-twitter.com *.twitter.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cookiebot.com *.newrelic.com static.klaviyo.com static-tracking.klaviyo.com *.noibu.com *.queue-it.net *.yotpo.com *.fontawesome.com https://static.klaviyo.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://instagram.fdel27-5.fna.fbcdn.net https://instagram.fdel27-4.fna.fbcdn.net https://instagram.fdel27-3.fna.fbcdn.net https://instagram.fdel27-2.fna.fbcdn.net https://instagram.fdel27-1.fna.fbcdn.net https://scontent-lcy1-1.cdninstagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.cookiebot.com *.clarity.ms *.tiktok.com *.googlesyndication.com *.amazonaws.com cdn.noibu.com wss://*.noibu.com input.noibu.com *.tiktokw.us *.reddit.com *.redditstatic.com *.bing.com *.queue-it.net widget.trustpilot.com *.smct.io rum.hlx.page *.datadome.co adsmeasurement.com www.facebook.com *.abtasty.com *.yotpo.com ads-twitter.com *.ads-twitter.com *.twitter.com *.ideal-postcodes.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com places.googleapis.com www.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.globalpay.com https://fonts.gstatic.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.globalpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.trustpilot.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://google.com/pay https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://270363f4-8181-4deb-9681-5d3de892b01b.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://widget.intercom.io https://js.intercomcdn.com https://a.quora.com https://connect.facebook.net https://mc.yandex.ru https://bat.bing.com https://static.ads-twitter.com https://www.redditstatic.com https://top-fwz1.mail.ru https://www.clarity.ms https://analytics.tiktok.com https://telegram.org https://googleads.g.doubleclick.net https://vk.com https://www.clarity.ms https://www.redditstatic.com; style-src 'self' 'unsafe-inline' https://widget.intercom.io; style-src-elem 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; img-src 'self' data: https: https://a.quora.com https://c.admetr.ru https://mc.yandex.ru https://vk.com https://q.quora.com https://www.google.ru; connect-src 'self' https: wss: https://api-iam.intercom.io https://analytics.google.com https://www.google-analytics.com https://connect.facebook.net https://mc.yandex.ru https://sc-static.net https://widget.intercom.io https://dolphin-anty.com dolphin-anty.net https://telegram.org https://www.google.com https://stats.g.doubleclick.net; font-src 'self' data: https:; object-src 'none'; frame-src 'self' https://www.googletagmanager.com https://td.doubleclick.net https://widget.intercom.io; frame-ancestors 'none'; base-uri 'self'; worker-src 'self' blob:; form-action 'self'; upgrade-insecure-requests; report-uri https://dolphin-anty.com/csp_report.php; 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.sendcloud.sc *.jsdelivr.net https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.sooqr.com *.spotlersearch.com https://www.mollie.com *.amazonaws.com epc.het-magazijn.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://maps.googleapis.com https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.mollie.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://*.ingest.sentry.io https://ipinfo.io https://www.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://widgets.trustedshops.com *.fontawesome.com *.googleapis.com *.gstatic.com instantcredit.net test.instantcredit.net *.fonts.googleapis.com data: *.cloudflare.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de * www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors * 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de * www.paycomet.com api.paycomet.com *.google.com *.addthis.com *.pinterest.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com eu1-doofinderuser.s3.amazonaws.com us1-doofinderuser.s3.amazonaws.com * instantcredit.net test.instantcredit.net *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com cdn.doofinder.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io * www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.fontawesome.com instantcredit.net test.instantcredit.net *.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.doofinder.com * instantcredit.net *.instantcredit.net *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com https://www.gstatic.com https://cdnjs.cloudflare.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com www.google.com https://www.youtube.com https://form.typeform.com https://www.googletagmanager.com/ js.mollie.com https://www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com https://accounts.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.bird.eu https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudimg.io *.google.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io js.mollie.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://accounts.google.com *.cloudimg.io *.scaleflex.it *.googletagmanager.com tagmanager.google.com *.smartsuppchat.com *.axept.io widget-v3.smartsuppcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com https://accounts.google.com https://www.gstatic.com tagmanager.google.com fonts.google.com widget-v3.smartsuppcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://nominatim.openstreetmap.org http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://accounts.google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.smartsuppchat.com *.smartsuppcdn.com *.axept.io wss://websocket-visitors.smartsupp.com ws.colissimo.fr 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.adobe.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.addthis.com *.facebook.com *.twitter.com landofcoder.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://meetanshi.com/media/logo.png magefan.com cm.magefan.com *.addthisedge.com *.twitter.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com guarantee-cdn.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com *.fontawesome.com *.googleapis.com *.gstatic.com landofcoder.com *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.typeform.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.apptrian.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.adobe.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com landofcoder.com *.google-analytics.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.livechatinc.com *.plyr.io https://widgets.trustedshops.com https://integrations.etrusted.com *.klarnacdn.net https://fonts.bunny.net *.alothemes.com *.magepow.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.net *.facebook.com https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.iubenda.com *.googletagmanager.com *.pinterest.com *.livechatinc.com *.facebook.net *.facebook.com *.linkedin.com *.googleapis.com *.klarna.com https://www.googletagmanager.com/ secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net cdn.livechat-files.com *.iubenda.com pixel.mathtag.com sync.mathtag.com *.trustedshops.com *.linkedin.com *.google.de *.facebook.net *.facebook.com *.livechatinc.com *.yahoo.com *.truoptik.com *.pinterest.com maps.gstatic.com *.ytimg.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://widgets.trustedshops.com https://integrations.etrusted.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.clarity.ms *.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com api.braintreegateway.com client-analytics.braintreegateway.com *.adobedtm.com *.iubenda.com chimpstatic.com *.roomvo.com *.trustedshops.com *.livechatinc.com *.cloudflare.com *.getsitecontrol.com *.pinimg.com *.mouseflow.com *.doubleclick.net *.licdn.com *.facebook.net *.facebook.com *.yimg.com *.teads.tv *.pinterest.com *.getsitectrl.com *.klarna.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ downloads.mailchimp.com *.list-manage.com https://widgets.trustedshops.com https://integrations.etrusted.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.avada.io *.alothemes.com *.magepow.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com cdn.klarna.com jsctool.com d.payla.io c.paypal.com pay.google.com api.sandbox.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets-qa.trustedshops.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com downloads.mailchimp.com https://widgets.trustedshops.com https://integrations.etrusted.com *.klarnacdn.net https://fonts.bunny.net *.alothemes.com *.magepow.com d.ratepay.com d.payla.io dr.payla.io assets.braintreegateway.com *.googleapis.com *.gstatic.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.clarity.ms api.braintreegateway.com client-analytics.braintreegateway.com *.google-analytics.com *.gstatic.com *.googletagmanager.com cdn.eye-able.com *.iubenda.com *.roomvo.com chimpstatic.com *.trustedshops.com *.livechatinc.com *.cloudflare.com *.getsitecontrol.com *.pinimg.com *.mouseflow.com *.doubleclick.net *.licdn.com *.facebook.net *.facebook.com *.yimg.com *.teads.tv *.pinterest.com *.getsitectrl.com *.linkedin.oribi.io *.linkedin.com *.klarnaevt.com *.klarna.com *.noembed.com *.plyr.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.etrusted.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com api.sandbox.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://integrations.etrusted.site landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.dasimport.nl https://www.googletagmanager.com https://connect.facebook.net https://static.cloudflareinsights.com https://kit.fontawesome.com https://cdn-4.convertexperiments.com https://challenges.cloudflare.com https://app.youshouldask.ai https://www.google-analytics.com https://region1.google-analytics.com https://googleads.g.doubleclick.net https://cdn-cookieyes.com https://snap.licdn.com https://www.clarity.ms https://scripts.clarity.ms https://bat.bing.com https://pixel.byspotify.com https://bgmin.cdn.billygrace.com https://www.google.com https://www.gstatic.com https://www.googleoptimize.com; style-src 'self' 'unsafe-inline' https://*.dasimport.nl https://fonts.googleapis.com https://app.youshouldask.ai; img-src 'self' data: blob: https://*.dasimport.nl https://www.google.com https://www.google.nl https://www.google-analytics.com https://region1.google-analytics.com https://region1.analytics.google.com https://www.googletagmanager.com https://www.googleadservices.com https://www.facebook.com https://i.vimeocdn.com https://lh3.googleusercontent.com https://player.vimeo.com https://app.youshouldask.ai https://cdn-cookieyes.com https://px.ads.linkedin.com https://bat.bing.com; font-src 'self' https://*.dasimport.nl https://fonts.gstatic.com https://kit.fontawesome.com https://ka-p.fontawesome.com https://app.youshouldask.ai data:; connect-src 'self' https: wss: https://*.dasimport.nl https://www.google-analytics.com https://region1.google-analytics.com https://region1.analytics.google.com https://www.googletagmanager.com https://static.cloudflareinsights.com https://cdn-4.convertexperiments.com https://challenges.cloudflare.com https://app.youshouldask.ai https://www.google.com https://www.gstatic.com; frame-src 'self' https://*.dasimport.nl https://player.vimeo.com https://www.youtube.com https://www.facebook.com https://www.google.com https://www.gstatic.com https://challenges.cloudflare.com https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'self' https://*.dasimport.nl; report-uri /csp-report.php; 1 default-src 'self' data: 'unsafe-eval' 'unsafe-inline' https://*.baidu.com http://*.baidu.com https://*.baidustatic.com http://*.baidustatic.com https://*.hao123.com http://*.hao123.com https://*.bdstatic.com http://*.bdstatic.com https://*.hao123img.com http://*.hao123img.com https://*.hao222.com http://*.hao222.com https://*.baidu.cn http://*.baidu.cn https://*.shifen.com http://*.shifen.com https://*.bdimg.com http://*.bdimg.com https://*.bcebos.com http://*.bcebos.com https://dwz.cn http://dwz.cn; img-src * data:; media-src * data:; report-uri /hao123_api/csp/report 1 connect-src 'self' *.giveffect.com *.googleapis.com doublethedonation.com *.paypal.com *.google.com *.google.ca *.linkedin.com *.google-analytics.com *.g2crowd.com *.doubleclick.net *.hscollectedforms.net *.hubspot.com *.facebook.com *.facebook.net *.adroll.com *.googleadservices.com *.gstatic.com *.calendly.com calendly.com wss://widget-mediator.zopim.com vimeo.com *.hsforms.com; default-src 'none'; font-src * data:; frame-src 'self' *.giveffect.com h.online-metrix.net *.google.com *.stripe.com *.paypal.com *.youtube.com *.doubleclick.net *.paypalobjects.com *.vimeo.com *.adroll.com *.facebook.com *.calendly.com calendly.com; img-src * blob: data:; media-src * blob: data:; object-src 'self'; script-src 'self' *.giveffect.com 'unsafe-inline' 'unsafe-eval' giveffect-assets.s3.amazonaws.com cdnjs.cloudflare.com connect.facebook.net *.googleapis.com *.google.com cdn.jsdelivr.net doublethedonation.com/api/js/ *.paypal.com *.stripe.com www.gstatic.com *.bootstrapcdn.com *.calendly.com calendly.com code.jquery.com d3js.org h64.online-metrix.net js.hscollectedforms.net cdn.datatables.net *.twitter.com *.hs-scripts.com *.hs-banner.com www.googletagmanager.com *.google-analytics.com snap.licdn.com *.g2crowd.com *.hubspot.com *.paypalobjects.com *.hs-analytics.net *.adroll.com *.vimeo.com; style-src 'self' 'unsafe-inline' giveffect-assets.s3.amazonaws.com *.googleapis.com cdnjs.cloudflare.com doublethedonation.com *.calendly.com cdn.jsdelivr.net *.bootstrapcdn.com fonts.googleapis.com *.googletagmanager.com; report-uri https://www.giveffect.com/csp_reports 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com paymentpage.axepta.bnpparibas *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cl.avis-verifies.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org t.mydialoginsight.com axeptio.imgix.net *.openstreetmap.org https://maps.googleapis.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.magento-datasolutions.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ static.axept.io cdn.jsdelivr.net *.axept.io *.cabesto.com https://cdnjs.cloudflare.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cdn.jsdelivr.net *.cabesto.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.wonderpush.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.openstreetmap.org https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com data: *.google.com https://fonts.bunny.net 'self' data: www.dufrio.com.br data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com www.dufrio.com.br 'self' 'unsafe-inline'; frame-ancestors www.dufrio.com.br 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co *.hotjar.com *.facebook.com *.trustpilot.com *.criteo.com *.mercadopago.com *.mercadolibre.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io www.dufrio.com.br *.voxus.tv *.btg360.com.br *.criteo.net *.awin1.com *.zenaps.com td.doubleclick.net *.yandex.ru *.orpen.com.br *.mainadv.com *.datalivemarketing.com.br www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://images.unsplash.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.google-analytics.com ssl.gstatic.com www.gstatic.com *.ebit.com.br *.ebitempresa.com.br *.mercadopago.com *.mlstatic.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com cdn.mundipagg.com api.pagar.me *.caravelx.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: www.dufrio.com.br *.dufrio.com.br s3.amazonaws.com newimgebit-a.akamaihd.net *.bing.com *.google.com.br *.adnxs.com *.mercadopago.com.br *.btg360.com.br *.criteo.com *.mediavine.com *.bluekai.com *.adgrx.com *.casalemedia.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.sharethrough.com *.rubiconproject.com *.media.net *.doubleclick.net *.bidswitch.net *.emxdgt.com *.yieldmo.com *.clmbtech.com *.socdm.com *.omnitagjs.com *.stickyadstv.com *.360yield.com *.ivitrack.com *.liadm.com *.outbrain.com *.pubmatic.com *.revcontent.com *.tremorhub.com *.awin1.com *.zenaps.com *.yahoo.net *.postrelease.com *.aralego.com *.aralego.net *.dmxleo.com *.clearsale.com.br *.yandex.ru *.clarity.ms *.microsoftonline.com *.caravel.store *.orpen.com.br *.unrulymedia.com *.live.sma.ia.br *.agkn.com sync.1rx.io dufrio-my.sharepoint.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com *.paypal.com *.googletagmanager.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com tagmanager.google.com *.ebit.com.br *.mercadopago.com *.mlstatic.com 3ds2.pagar.me 3ds2-sdx.pagar.me connect.facebook.net js.huggy.chat *.avada.io *.hsforms.net *.hsforms.com www.dufrio.com.br self s3.amazonaws.com *.voxus.com.br *.bing.com *.btg360.com.br *.adcart.com.br *.dwin1.com *.afilio.com.br *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.clearsale.com.br *.cloudflareinsights.com *.k-analytix.com *.yandex.ru unsafe-inline *.dufrio.com.br *.cloudfront.net *.orpen.com.br *.tiktok.com *.datalivemarketing.com.br 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net tagmanager.google.com fonts.google.com *.ebit.com.br *.mercadopago.com *.google.com webfonts.huggy.cloud https://fonts.bunny.net *.gstatic.com www.dufrio.com.br s3.amazonaws.com *.orpen.com.br 'self' 'unsafe-inline'; object-src www.dufrio.com.br 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com www.dufrio.com.br 'self' 'unsafe-inline'; manifest-src www.dufrio.com.br 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com *.analytics.google.com *.googletagmanager.com https://hits-banner-cloud-function.azurewebsites.net *.mercadopago.com maps.googleapis.com *.mercadolibre.com api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br pay.sandbox.google.com wss://ct-socket.huggy.app widget.huggy.io https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com www.dufrio.com.br *.reclameaqui.com.br *.voxus.tv *.voxus.com.br *.loggly.com *.ipify.org *.google.com.br *.criteo.com *.bing.com *.us-east-2.on.aws *.sciencebehindecommerce.com *.wepowerconnections.com *.akamaihd.net *.konduto.com *.mailbiz.one *.cloudfront.net *.tiktok.com *.pangle-ads.com *.yandex.ru *.tiktokw.us *.datalivemarketing.com.br wss://mc.yandex.ru/solid.ws wss://socket.live.sma.ia.br/ws wss://socket.live.sma.ia.br/ws/ 'self' 'unsafe-inline'; child-src www.dufrio.com.br http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.dufrio.com.br *.google.com.br 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.dufrio.com.br 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-1466b485-e735-45de-afbc-415666b4c825' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.ie https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.ie/eum-collector/report/csp-report; 1 default-src 'self' *.empowerfcu.com analytics.google.com *.google-analytics.com *.inpwrd.net *.outbrain.com *.salemove.com api.glia.com autolink.io efraudprevention.net empowerfculocator.wave2.io fonts.googleapis.com fonts.gstatic.com stats.g.doubleclick.net tags.srv.stackadapt.com www.googletagmanager.com; child-src www.culookup.com www.youtube.com; connect-src data: *.twilio.com connect.facebook.net *.googleapis.com www.google.com; font-src data: cdn.fontshare.com use.fontawesome.com; img-src blob: data: assets.orb.alkamitech.com i.ytimg.com images l.facebook.com www.livenation.com translate.google.com ui.autolink.io; media-src data:; script-src connect.facebook.net; script-src-elem blob: ajax.cloudflare.com apis.google.com; style-src blob:; style-src-elem use.fontawesome.com; form-action 'self' my.empowerfcu.com; frame-src *.efraudprevention.net empowerfculocator.wave2.io td.doubleclick.net tel www.culookup.com www.googletagmanager.com www.youtube.com content.inpwrd.net www.optoutprescreen.com; frame-ancestors 'self' *.empowerfcu.com *.zagclients.net; report-to https://empower.report-uri.com/r/t/csp/wizard 1 font-src *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.mondu.ai/ *.mondu.local localhost:*/ https://www.googletagmanager.com/ *.nosto.com *.nos.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com ratenkauf.easycredit.de *.mondu.ai/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://redchamps.com https://widgets.trustedshops.com https://integrations.etrusted.com *.nosto.com *.nos.to magefan.com cm.magefan.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io ratenkauf.easycredit.de *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://widgets.trustedshops.com https://integrations.etrusted.com jsd-widget.atlassian.com *.nosto.com *.nos.to maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com d.ratepay.com d.payla.io dr.payla.io https://widgets.trustedshops.com https://integrations.etrusted.com *.nosto.com *.nos.to *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com ratenkauf.easycredit.de http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.trustedshops.com *.etrusted.com jsd-widget.atlassian.com api-private.atlassian.com *.nosto.com *.nos.to api.friendlycaptcha.com eu-api.friendlycaptcha.eu maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.ca/api/csp-report; report-to csp-endpoint 1 block-all-mixed-content;script-src 'self' https://*.vistek.ca https://*.klaviyo.com https://*.criteo.com https://*.doubleclick.net https://*.google.com https://*.googleadbuilder.Services.com https://*.googlesyndication.com https://*.googletagbuilder.Services.com https://*.yahoo.com https://*.klarnaservices.com https://acsbapp.com https://ajax.aspnetcdn.com https://apis.google.com https://cdn.browsiprod.com https://connect.facebook.net https://cdn.jsdelivr.net https://content.linkedin.com https://cdn.logrocket.io https://cdn.lr-ingest.io https://forms.hsforms.com https://googleads.g.doubleclick.net https://graph.facebook.com https://google-analytics.com https://googletagmanager.com https://js.facebook.com https://js.hs-analytics.net https://js.hs-banner.com https://js-na1.hs-scripts.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.hsforms.net https://js.hsleadflows.net https://js.hubspotfeedback.com https://js.usemessages.com https://js.hubspot.com https://osm.klarnabuilder.Services.com https://platform.linkedin.com https://query.yahooapis.com https://sslwidget.criteo.com https://static.criteo.net https://ssl.google-analytics.com https://snap.licdn.com https://static-exp1.licdn.com https://s.yimg.com https://tagmanager.google.com https://www.google-analytics.com https://www.googleadbuilder.Services.com https://www.googletagmanager.com https://static.www.turnto.com https://vistek.bamboohr.com/ https://www.gstatic.com https://s3.amazonaws.com https://www.paypalobjects.com https://x.klarnacdn.net https://js.klarna.com https://cdn.equalweb.com https://www.googleadservices.com https://www.paypal.com https://maps.googleapis.com https://code.jquery.com https://aq.flippenterprise.net 'unsafe-eval' 'unsafe-inline';style-src 'self' *.licdn.com *.google.com cdn.jsdelivr.net fonts.googleapis.com www.googletagmanager.com static.www.turnto.com x.klarnacdn.net vistek.bamboohr.com static.klaviyo.com static-tracking.klaviyo.com aq.flippenterprise.net 'unsafe-inline';child-src 'self' blob: *.googlesyndication.com *.google.com *.facebook.com *.doubleclick.net *.criteo.net *.criteo.com app.hubspot.com connect.facebook.net forms.hsforms.com js.hsadspixel.net js.hscollectedforms.net js.usemessages.com www.googletagmanager.com aq.flippenterprise.net;form-action 'self' *.google.com *.facebook.com connect.facebook.net forms.hsforms.com forms.hubspot.com https://*.cardinalcommerce.com;object-src *.googlesyndication.com;frame-ancestors 'self';frame-src 'self' https://www.youtube.com https://gum.criteo.com https://fledge.us.criteo.com/ https://accounts.google.com https://www.turnto.com https://static.www.turnto.com https://forms.hsforms.com https://www.google.com https://www.google.ca https://www.googletagmanager.com https://www.sandbox.paypal.com https://www.paypal.com https://js.playground.klarna.com https://js.klarna.com https://*.cardinalcommerce.com https://googleads.g.doubleclick.net https://app.hubspot.com https://td.doubleclick.net https://bid.g.doubleclick.net https://aq.flippenterprise.net;worker-src 'self' blob: www.google.com;base-uri 'self' *.yahoo.com;report-uri /error/csp 1 default-src 'self' data:; connect-src 'self' app.termageddon.com my.vonagebusiness.com my.yoast.com www.google-analytics.com graph.facebook.com www.facebook.com analytics.google.com stats.g.doubleclick.net region1.google-analytics.com analytics.google.com/g/collect stats.g.doubleclick.net/g/collect www.googletagmanager.com/a; font-src 'self' data: fonts.gstatic.com www.local-marketing-reports.com/vendor/ss-standard/ss-standard.ttf www.local-marketing-reports.com/vendor/ss-standard/ss-standard.woff; frame-src 'self' brainstormforce.github.io fast.wistia.net js.stripe.com m.stripe.network m.stripe.com q.stripe.com maps.google.com platform.twitter.com www.facebook.com www.google.com www.linkedin.com www.youtube.com calendly.com www.local-marketing-reports.com; img-src 'self' blob: cdn.pressidium.com data: devel1 embedwistia-a.akamaihd.net i.ytimg.com media-exp1.licdn.com s3.amazonaws.com secure.gravatar.com static-exp1.licdn.com syndication.twitter.com terzettoalive.onpressidium.com www.facebook.com www.google-analytics.com www.googletagmanager.com assets.calendly.com ps.w.org analytics.google.com stats.g.doubleclick.net www.gstatic.com media-exp2.licdn.com static-exp2.licdn.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' app.termageddon.com apis.google.com assets.calendly.com badges.linkedin.com cdn.jsdelivr.net cdnjs.cloudflare.com connect.facebook.net data: developers.google.com js.stripe.com platform.linkedin.com platform.twitter.com s3.amazonaws.com www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com www.youtube.com ajax.cloudflare.com www.local-marketing-reports.com/m/assets-v2/lead-gen/js/external/widget-embeder.js www.local-marketing-reports.com/m/assets-v2/lead-gen/js/external/widget-builder.js; script-src 'self' 'unsafe-eval' 'unsafe-inline' ajax.cloudflare.com connect.facebook.net www.google-analytics.com www.googletagmanager.com js.stripe.com apis.google.com s3.amazonaws.com www.youtube.com assets.calendly.com app.termageddon.com cdnjs.cloudflare.com www.gstatic.com www.google.com developers.google.com platform.linkedin.com badges.linkedin.com www.local-marketing-reports.com data:; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *; style-src 'self' 'unsafe-eval' 'unsafe-inline'; form-action 'self' www.facebook.com/tr/; frame-ancestors 'self'; base-uri 'self'; object-src 'none'; worker-src 'self' blob:; report-uri https://trivalleyinternet1techsupport.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' https://accesswidget-log-receiver.acsbapp.com https://cdn.acsbapp.com https://eu-cdn.acsbapp.com https://eu.acsbapp.com https://syndication.teleborsa.it https://ka-f.fontawesome.com/ https://*.animasgr.it https://funds.previnet.it https://www.epheso.com/ https://funds.previnet.it https://www.google.com/ https://*.iubenda.com/ data:; connect-src 'self' https://cdn.acsbapp.com/ https://cdn.linkedin.oribi.io https://eu.acsbapp.com https://eu-process.acsbapp.com https://eu-cdn.acsbapp.com https://process.acsbapp.com https://cdn.acsbapp.com https://www.google-analytics.com https://*.iubenda.com https://ka-f.fontawesome.com/ https://stats.g.doubleclick.net https://plausible.io https://vimeo.com https://www.google.com/recaptcha/ https://anima-forms-api.apps.animasgr.it/; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://snap.licdn.com https://eu.acsbapp.com https://acsbapp.com https://kit.fontawesome.com https://www.epheso.com/ https://funds.previnet.it https://www.gstatic.com/ https://*.iubenda.com/ https://www.google.com/ https://assets.contactlab.it https://chatbot-prod.animasgr.it https://www.googletagmanager.com https://www.google-analytics.com https://ssl.p.jwpcdn.com/ https://*.animasgr.it https://plausible.io https://player.vimeo.com/; img-src 'self' data: https://px.ads.linkedin.com https://eu-cdn.acsbapp.com https://cdn.acsbapp.com https://www.google.com/ https://www.google.it/ https://www.google-analytics.com/ https://prd.jwpltx.com/ https://www.googletagmanager.com/ https://*.vimeocdn.com/; media-src 'self' data: blob: https://eu-web1.acsbapp.com https://web1.acsbapp.com https://*.animasgr.it; frame-src 'self' https://funds.previnet.it/ https://player.vimeo.com/ https://www.google.com/recaptcha/ https://syndication.teleborsa.it; 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.authorize.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com mageside.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.kaptcha.com *.disqus.com *.authorize.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-f3a3a26baed4c145843bec96b3dc0d8d' https://www.horlogeforum.nl/logs/ https://www.horlogeforum.nl/sidekiq/ https://www.horlogeforum.nl/mini-profiler-resources/ https://eu5.dh-cdn.net/assets/ https://eu5.dh-cdn.net/brotli_asset/ https://www.horlogeforum.nl/extra-locales/ https://www.horlogeforum.nl/highlight-js/ https://www.horlogeforum.nl/javascripts/ https://www.horlogeforum.nl/plugins/ https://www.horlogeforum.nl/theme-javascripts/ https://www.horlogeforum.nl/svg-sprite/ https://www.googletagmanager.com/gtm.js 'sha256-8uAKDaK4QxxCeYZl0Wxad2Nnj2tgKyA14hYBh66pnn0=' https://www.googletagmanager.com; worker-src 'self' https://eu5.dh-cdn.net/assets/ https://eu5.dh-cdn.net/brotli_asset/ https://www.horlogeforum.nl/javascripts/ https://www.horlogeforum.nl/plugins/; frame-ancestors 'self'; manifest-src 'self' 1 default-src *;img-src * 'self' data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; style-src 'self' 'unsafe-inline' *; report-uri https://c5a1a5b5d860b1da42fe273191b03f67.report-uri.com/r/d/csp/wizard 1 default-src 'self' 'unsafe-inline' *.VLeBooks.com *.vlereader.com; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.vlebooks.com *.vlereader.com apis.google.com cdn.segment.com/next-integrations/actions www.google-analytics.com www.googletagmanager.com; script-src-elem 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.vlebooks.com *.vlereader.com apis.google.com cdn.segment.com/next-integrations/actions www.google-analytics.com www.googletagmanager.com; style-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.VLeBooks.com *.vlereader.com ajax.aspnetcdn.com fonts.googleapis.com; style-src-attr 'report-sample' 'self' 'unsafe-inline' ; style-src-elem 'report-sample' 'self' 'unsafe-inline' assets.braintreegateway.com fonts.googleapis.com/css; child-src 'self' blob:; connect-src 'self' 'unsafe-inline' 'unsafe-eval' *.VLeBooks.com *.vlereader.com https://region1.google-analytics.com https://www.google-analytics.com *.idm.oclc.org/ *.qmul.ac.uk/ *.open.ac.uk/ *.bath.ac.uk/ *.uwtsd.ac.uk/ *.bolton.ac.uk/; font-src 'self' 'unsafe-inline' data: *.VLeBooks.com *.vlereader.com ajax.aspnetcdn.com cdn.jsdelivr.net cdn.scite.ai fonts.gstatic.com static.preply.com; frame-ancestors 'self' *.vlereader.com *.vlebooks.com www.vlebooks.com; frame-src 'report-sample' 'self' *.vlebooks.com *.vlereader.com; img-src 'self' blob: data: https: *.VLeBooks.com *.vlereader.com *.dmmserver.com *.gardners.com http://jackets.gardners.com ; object-src 'none'; base-uri 'self'; manifest-src 'self' *.idm.oclc.org/pwa_manifest.json *.qmul.ac.uk *.open.ac.uk *.bath.ac.uk *.uwtsd.ac.uk *.bolton.ac.uk; media-src 'self'; worker-src blob:; report-uri https://679259fe8ff833a6e12adf10.endpoint.csper.io?v=9; 1 object-src 'none';base-uri 'self';script-src 'nonce-YgZueqZw3C79x/S4f0LE' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 font-src *.cloudflare.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.useinsider.com *.api.useinsider.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.youtube.com *.g.doubleclick.net *.facebook.com *.facebook.net *.useinsider.com *.api.useinsider.com appservice.ezcat.com.tw 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.g.doubleclick.net *.facebook.com *.facebook.net *.awoo.org *.tigerfly.tw *.awoo.com *.useinsider.com *.api.useinsider.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://mas.astralweb.com.tw *.facebook.com *.facebook.net *.cloudflare.com *.ytimg.com *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.magentocommerce.com *.gstatic.com *.cloudfront.net *.google.com *.google.com.tw *.useinsider.com *.api.useinsider.com *.line.me data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.net *.cloudflare.com *.twitter.com *.fontawesome.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.google.com *.zdassets.com *.g.doubleclick.net *.facebook.com *.awoo.org *.tigerfly.tw *.awoo.com *.useinsider.com *.api.useinsider.com *.line-scdn.net *.avada.io https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.useinsider.com *.api.useinsider.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.useinsider.com *.api.useinsider.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.google-analytics.com *.googletagmanager.com *.zendesk.com *.zopim.com *.zdassets.com *.gstatic.com wss://widget-mediator.zopim.com *.cardinalcommerce.com *.awoo.org *.tigerfly.tw *.awoo.com *.useinsider.com *.api.useinsider.com wss://*.useinsider.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.com.tw *.facebook.com *.facebook.net *.awoo.org *.tigerfly.tw *.awoo.com *.useinsider.com *.api.useinsider.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src https://content.vistana.com 'self' https://stats.g.doubleclick.net https://checkoutshopper-test.adyen.com/ https://www.facebook.com https://pal-test.adyen.com https://track.sv.rkdms.com https://*.clicktale.net https://c.az.contentsquare.net https://images.securedvisit.com https://assets.adobedtm.com https://api.securedvisit.com https://*.contentsquare.com https://pay.google.com https://track.securedvisit.com https://dpm.demdex.net blob: https://t.contentsquare.net/uxa/f3e2b0b1cfa35.js https://zn3wuecdqd6sxvlyu-marriottvacationclub.siteintercept.qualtrics.com/WRSiteInterceptEngine/ 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval' 'unsafe-inline' https://payments.salesforce.com/ https://content.securedvisit.com https://siteintercept.qualtrics.com https://googleads.g.doubleclick.net https://mvwvo--exppod2--c.sandbox.vf.force.com https://checkoutshopper-live.adyen.com/ https://s32171.pcdn.co https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://privacy-portal-mvwc-cdn.my.onetrust.com https://maps.a.forceusercontent.com https://connect.facebook.net https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://geolocation.onetrust.com https://*.kampyle.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://mordev.112.2o7.net https://mvwvo--exppod2--c.sandbox.vf.force.com/resource/1669023906000/x7smvtestimage https://s20426.pcdn.co https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://cdn.cookielaw.org/ https://bat.bing.com https://js.stripe.com/ https://cdn.tt.omtrdc.net https://t.contentsquare.net https://www.googletagmanager.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js https://*.contentsquare.net; report-to sfdc-csp-ep; report-uri https://mvwvo.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4x000006sQxi&networkId=0DM4x000000dPWp&type=communities 1 script-src 'nonce-DT9zF1K5qBgB1iOr8qeLsZw7vvtZxduyeGGRsS5RusE=' 'unsafe-eval' 'strict-dynamic' https:; frame-ancestors 'self'; report-uri https://www.thonhotels.no/api/ContentSecurityViolation/; report-to csp-endpoint; object-src 'self'; base-uri 'self' 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-820b5f684fec4ed7913aa2b55d54ed74' https://epic-mychartprod.coh.org 'self';img-src https://* 'self' blob: data:;style-src https://epic-mychartprod.coh.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self'; object-src 'none'; manifest-src 'self'; media-src 'self'; worker-src blob:; frame-ancestors 'self' https://sms.hollandsnieuwe.nl https://vodafoneziggo.portal.mobilewater.nl https://act.ziggo.nl https://act.vodafone.nl; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.google-analytics.com https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://www.gstatic.com https://cdn.conversationalsdevelopment.nl https://api.seamly-app.com https://static.cloudflareinsights.com https://www.dwin1.com https://lantern.roeyecdn.com https://www.awin1.com https://bat.bing.com https://embed.binkies3d.com https://az589851.vo.msecnd.net https://cdn.blueconic.net https://vodafoneziggo.blueconic.net https://ct.contentsquare.net https://t.contentsquare.net https://connect.facebook.net https://platform.linkedin.com https://nebula-cdn.kampyle.com https://cdn.cookielaw.org https://d5yoctgpv4cpx.cloudfront.net https://sc-static.net https://www.sc.pages03.net https://tr.snapchat.com https://static.customersaas.com https://static-accept.customersaas.com https://cloud.51degrees.com https://the.sciencebehindecommerce.com https://cdn.amplitude.com; connect-src 'self' https://login.hollandsnieuwe.nl https://nebula-cdn.kampyle.com https://www.google.com https://googleads.g.doubleclick.net https://srm.ba.contentsquare.net https://k-aeu1.contentsquare.net https://q-aeu1.contentsquare.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com https://stats.g.doubleclick.net https://*.googlesyndication.com https://cdn.conversationalsdevelopment.nl https://api.seamly-app.com wss://api.seamly-app.com https://api.digitalcx.com https://embed.binkies3d.com https://az589851.vo.msecnd.net https://binkiesproductionweu.servicebus.windows.net https://vodafoneziggo.blueconic.net https://c.contentsquare.net https://udc-neb.kampyle.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal-de.onetrust.com https://p2iqhncxyh.execute-api.eu-central-1.amazonaws.com https://o245079.ingest.sentry.io https://tr.snapchat.com https://tr6.snapchat.com https://tms.data.hollandsnieuwe.nl https://api.prod.dcat.ziggo.io https://www.vodafone.nl https://hollandsnieuwe.billing.nl https://api-accept.customersaas.com https://static-accept.customersaas.com https://cloud.51degrees.com https://the.sciencebehindecommerce.com https://cdn.amplitude.com https://api.eu.amplitude.com; img-src 'self' blob: data: https://www.tracebuzz.com https://az589851.vo.msecnd.net https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://www.google.nl https://googleads.g.doubleclick.net https://api.seamly-app.com https://lantern.roeye.com https://www.awin1.com https://bat.bing.com https://c.contentsquare.net https://www.facebook.com https://udc-neb.kampyle.com https://cdn.cookielaw.org https://www.pages03.net https://is-accept.customersaas.com https://static.customersaas.com https://d35v9wsdymy32b.clouvdfront.net https://www.wepowerconnections.com; frame-src 'self' https://*.fls.doubleclick.net https://*.doubleclick.net https://www.awin1.com https://nebula-cdn.kampyle.com https://tr.snapchat.com https://*.googletagmanager.com; font-src 'self' data: https://cdn.conversationalsdevelopment.nl https://static.customersaas.com; style-src 'self' 'unsafe-inline' https://api.seamly-app.com https://static.customersaas.com https://d1r5etm691cejh.cloudfront.net; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=0TzDC8mxxZ2YB20_taMv1LptI8K97AJkb4YP9tccDPk-1707906598-1-Afy3yZhc08_yVv_Cfhfz1rf1gOMzf_NyAb8jiOVdfjNmh68AlIM8LFk5Sli-2KoYZkNCAoCRN7M2HfDwTk_nHT-LO7kSkEvGVfwlWOW4ACpo_1objwrdvoAdJw_ttEWBp9pXdVeLyjeP0kbKj-rZHN4IZ4_RVSBe3cL1GJld-B5D; report-to cf-csp-endpoint; 1 object-src 'none'; connect-src 'self' *.famedigital.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.famedigital.com join.gammasecure.com; script-src 'self' *.famedigital.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.famedigital.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 worker-src blob: *.pinterest.com *.facebook.com *.google.com *.google.com.hk *.bing.com *.stripe.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.kxcdn.com *.pinterest.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.stripe.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.googleapis.com *.bing.com *.googleadservices.com *.google-analytics.com *.pinterest.com *.googletagmanager.com *.webgains.io *.doubleclick.net *.stripe.com *.cookiebot.com www.awin1.com *.facebook.com *.twitter.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.fbcdn.net *.pinterest.com *.adobedtm.com www.google.co.uk www.awin1.com blob: *.stripe.com *.facebook.com *.google.com.hk *.bing.com cdn.trustpilot.net *.cookiebot.com *.shareasale.com *.sc-static.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.addthisedge.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com cdn.ampproject.org connect.facebook.net *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.ads-twitter.com *.bing.com *.pinimg.com *.googleadservices.com *.google-analytics.com *.pinterest.com *.googletagmanager.com *.webgains.io *.facebook.com td.doubleclick.net *.stripe.com *.cookiebot.com *.adobedtm.com *.snapchat.com *.sc-static.net www.dwin1.com www.google.co.uk www.awin1.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com s7.addthis.com *.facebook.net *.twitter.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.pinterest.com downloads.mailchimp.com *.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.pinterest.com *.facebook.com *.google.com.hk *.bing.com *.stripe.com *.cookiebot.com *.doubleclick.net *.snapchat.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com ekr.zdassets.com/ klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com www.googleadservices.com www.googletagmanager.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; form-action 'self' https://www.mycvcreator.com; upgrade-insecure-requests; script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://accounts.google.com https://www.googletagmanager.com https://telegram.org; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com; img-src 'self' data: https://www.google-analytics.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; frame-src https://www.google.com https://recaptcha.google.com https://accounts.google.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.klarna.com *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.excelclothing.com *.facebook.com *.google.co.uk *.google.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.clerk.io *.doubleclick.net *.facebook.net *.jsdelivr.net *.omappapi.com *.pcapredict.com *.webgains.io *.zdassets.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io player.vimeo.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mailchimp.com *.omappapi.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.doubleclick.net *.omappapi.com *.zendesk.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com https://get.geojs.io *.avada.io *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.certcapture.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.fontawesome.com *.googleapis.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.certcapture.com downloads.mailchimp.com *.fontawesome.com assets.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://static.klaviyo.com https://cdn.jsdelivr.net https://*.adobe.com https://fonts.googleapis.com https://*.doubleclick.net https://*.facebook.com https://fonts.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.fontawesome.com https://maxcdn.bootstrapcdn.com https://fonts.bunny.net https://fonts.static.com https://*.nosto.com https://*.nos.to https://assets.braintreegateaway.com https://*.cloudfront.net https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net; font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com https://fonts.bunny.net fonts.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.innoship.ro *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://event.2performant.com https://ams.creativecdn.com https://www.gstatic.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org * https://www.magezon.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com quickchart.io img.youtube.com *.nosto.com *.nos.to www.google.com.ua preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://ss.tezyo.ro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com * *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.googleapis.com https://www.gstatic.com/ *.avada.io *.shopify.com *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com https://cdn.otter.ro https://ss.tezyo.ro 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.adobe.com fonts.googleapis.com *.googleapis.com https://*.doubleclick.net https://*.facebook.com *.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com *.tiktok.com https://*.fontawesome.com maxcdn.bootstrapcdn.com https://*.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://fonts.bunny.net fonts.gstatic.com https://*.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://fonts.static.com https://*.nos.to https://assets.braintreegateaway.com https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net https://www.google.com/ *.doubleclick.net *.googlesyndication.com *.tiktok.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro static.klaviyo.com cdn.jsdelivr.net https://tezyo.zendesk.com https://ekr.zdassets.com https://*.zendesk.com https://*.zdassets.com https://event.2performant.com https://tidytracking.com https://ss.tezyo.ro 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://stackpath.bootstrapcdn.com data: https://provape.com https://fonts.gstatic.com https://fonts.googleapis.com https://cdn.agechecker.net https://cdn.userway.org *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com *.authorize.net www.searchanise.com *.searchserverapi.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.google.com https://verifypass.com https://vars.hotjar.com https://cdn.userway.org https://widget.trustpilot.com 'unsafe-inline' data: *.google.com *.google.com.ua *.google.co.uk www.facebook.com platform.twitter.com *.authorize.net www.searchanise.com *.searchserverapi.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://provape.com https://www.google.com.ua https://www.google.com https://www.google.nl https://shareasale.com https://cdn.routeapp.io https://www.google.co.uk https://img.agechecker.net https://cdn.userway.org https://c.clarity.ms https://c.bing.com *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.doubleclick.net https://img.youtube.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com store.paradoxlabs.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cache.validage.com cloud.validage.com https://cdn.agechecker.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://searchserverapi.com https://static.cloudflareinsights.com https://static.zdassets.com https://www.googletagmanager.com https://www.dwin1.com https://cdn.clerk.io https://api.clerk.io https://static.hotjar.com https://script.hotjar.com https://ajax.cloudflare.com https://d5yoctgpv4cpx.cloudfront.net https://cdn.userway.org https://cdn.verifypass.com https://www.clarity.ms https://cdnjs.cloudflare.com https://widget.trustpilot.com s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io connect.facebook.net twitter.com platform.twitter.com *.authorize.net searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cache.validage.com cloud.validage.com static-tracking.klaviyo.com unsafe-inline downloads.mailchimp.com https://static.klaviyo.com https://stackpath.bootstrapcdn.com https://provape.com https://cdn-asset.optimonk.com https://cdn.userway.org https://fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com cache.validage.com cloud.validage.com https://vc.hotjar.io www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://provape.zendesk.com wss://widget-mediator.zopim.com https://cdn77.api.userway.org https://in.hotjar.com wss://ws30.hotjar.com https://front.optimonk.com https://jfapiprod.optimonk.com https://cdn-renderer.optimonk.com wss://ws.hotjar.com https://content.hotjar.io https://api.agechecker.net https://api.userway.org https://cdn.userway.org https://q.clarity.ms https://o.clarity.ms ekr.zdassets.com/ *.google-analytics.com *.google.com https://get.geojs.io *.avada.io *.authorize.net api.amplitude.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem https://*.magentosite.cloud https://purdys.local https://*.purdys.local https://purdys.com https://*.purdys.com https://*.listrakbi.com https://*.azureedge.net https://*.bootstrapcdn.com 'unsafe-inline' https://*.yotpo.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/; script-src-elem https://*.magentosite.cloud https://purdys.local https://*.purdys.local https://purdys.com https://*.purdys.com https://*.hotjar.com https://*.searchspring.io https://*.searchspring.net https://*.azureedge.net https://www.googletagmanager.com https://acsbapp.com https://*.blob.core.windows.net https://*.listrakbi.com https://*.listrak.com 'self' https://*.licdn.com https://*.bing.com https://*.pinimg.com https://*.pinterest.com https://*.pepperjam.com https://*.tctm.co https://*.facebook.net https://*.youtube.com https://*.jsdelivr.net 'unsafe-inline' https://*.newrelic.com https://*.googleapis.com *.bing.com *.calendly.com *.clarity.ms *.doubleclick.net *.facebook.net *.google.com *.googleadservices.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.inspectlet.com *.jsdelivr.net *.kaltura.com *.licdn.com *.listrak.com *.listrakbi.com *.newrelic.com *.paypal.com *.paypalobjects.com *.pepperjam.com *.pinimg.com *.pinterest.com *.searchspring.net *.searchspring.io *.tctm.co *.tiktok.com *.twitter.com *.yotpo.com *.youtube.com acsbapp.com *.cloudfront.net *.azureedge.net *.blob.core.windows.net sc-static.net tagmanager.google.com analytics.google.com unpkg.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/; font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com https://*.googleapis.com https://*.gstatic.com data: https://*.fontawesome.com maxcdn.bootstrapcdn.com https://*.magentosite.cloud https://purdys.local https://*.purdys.local https://purdys.com https://*.purdys.com https://*.cloudflare.com https://maxcdn.bootstrapcdn.com https://*.yotpo.com https://*.azureedge.net 'unsafe-inline' https://*.cloudfront.net *.flaticon.com sc-static.net https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ dhv2ziothpgrr.cloudfront.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com maps.googleapis.com maps.gstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com maps.googleapis.com maps.gstatic.com *.addthis.com https://*.moneris.com/ *.meetanshi.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.yotpo.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com https://www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.meetanshi.com https://meetanshi.com/media/logo.png www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.magentosite.cloud purdys.local *.purdys.local *.bing.com *.clarity.ms *.doubleclick.net *.ggpht.com *.google.com *.googleusercontent.com *.inspectlet.com *.kaltura.com *.linkedin.com *.listrakbi.com *.pinterest.com *.searchspring.net *.twitter.com *.yandex.ru *.yotpo.com *.azureedge.net *.blob.core.windows.net swiperjs.com https://purdys.com https://*.purdys.com https://*.bing.com https://*.google.com 'self' https://*.google.ca https://*.linkedin.com https://*.cloudfront.net https://*.listrakbi.com https://*.searchspring.io https://*.doubleclick.net https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.net *.klaviyo.com *.google-analytics.com *.googletagmanager.com dhv2ziothpgrr.cloudfront.net guarantee-cdn.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://*.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net https://*.moneris.com/ *.meetanshi.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.magentosite.cloud https://purdys.com https://*.purdys.com *.googletagmanager.com tagmanager.google.com *.google.com *.facebook.net unpkg.com https://*.searchspring.io https://acsbapp.com https://*.blob.core.windows.net https://*.listrakbi.com 'self' acsbapp.com *.bing.com *.calendly.com *.clarity.ms *.doubleclick.net *.googleadservices.com *.googleoptimize.com *.hotjar.com *.inspectlet.com *.jsdelivr.net *.kaltura.com *.licdn.com *.listrak.com *.listrakbi.com *.paypalobjects.com *.pepperjam.com *.pinimg.com *.pinterest.com *.searchspring.net *.searchspring.io *.tctm.co *.tiktok.com *.twitter.com *.yotpo.com *.cloudfront.net *.azureedge.net *.blob.core.windows.net sc-static.net https://purdys.local https://*.purdys.local https://*.hotjar.com https://*.azureedge.net https://*.licdn.com https://*.bing.com https://*.pinimg.com https://*.tctm.co 'unsafe-inline' https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ *.redditstatic.com *.reddit.com *.ads-twitter.com *.klaviyo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://cdn.searchspring.net/intellisuggest/is.min.js *.cloudflare.com guarantee-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net https://*.moneris.com/ *.fontawesome.com maxcdn.bootstrapcdn.com 'unsafe-inline' assets.braintreegateway.com https://*.azureedge.net https://*.listrakbi.com https://*.yotpo.com *.cloudflare.com *.googletagmanager.com *.gstatic.com *.jsdelivr.net *.listrakbi.com *.azureedge.net *.blob.core.windows.net https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ *.tagmanager.google.com dhv2ziothpgrr.cloudfront.net *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com maps.googleapis.com maps.gstatic.com *.bing.com *.gstatic.com *.kaltura.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://*.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.meetanshi.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.magentosite.cloud https://purdys.local https://*.purdys.local *.bing.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.googleadservices.com *.googleoptimize.com *.googletagmanager.com *.hotjar.io *.inspectlet.com *.jsdelivr.net *.kaltura.com *.licdn.com *.pepperjam.com *.pinimg.com *.tctm.co acsbapp.com *.cloudfront.net *.azureedge.net *.blob.core.windows.net www.google.ae www.google.am www.google.at https://purdys.com https://*.purdys.com https://*.listrakbi.com https://*.acsbapp.com https://*.pinterest.com https://*.linkedin.com https://*.velaro.com https://*.nr-data.net https://*.searchspring.io https://*.doubleclick.net https://*.hotjar.com https://*.tiktok.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.net *.klaviyo.com *.run.app dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://beacon.searchspring.io/beacon *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f0d1d91f-01e4-4d5d-a8d9-5469b5b19d14.sansec.watch/; report-to report-endpoint; 1 font-src 'self' https://*.kxcdn.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.kxcdn.com https://cdnjs.cloudflare.com https://connect.facebook.net https://googleads.g.doubleclick.net https://includes.ccdc02.com/cardinalcruise/ https://js.braintreegateway.com https://songbird.cardinalcommerce.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.kxcdn.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com; child-src 'self' https://staticxx.facebook.com https://bid.g.doubleclick.net; img-src 'self' data: https:; report-uri /api/v0.1.0/security-report/csp; connect-src 'self' https:; object-src 'self' https://*.kxcdn.com; default-src 'self'; frame-src 'self' https://*.cardinalcommerce.com https://*.kxcdn.com https://assets.braintreegateway.com https://bid.g.doubleclick.net https://checkout.paypal.com https://connect.facebook.net https://staticxx.facebook.com https://www.facebook.com 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com https://*.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; 1 worker-src 'self' blob:; font-src https: data: 'self' https://*.yieldify-production.com fonts.gstatic.com *.gstatic.com fonts.gstatic.com *.finance-calculator.co.uk *.klarnacdn.net maxcdn.bootstrapcdn.com use.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com https://plumrocket.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.braintree-api.com songbird.cardinalcommerce.com *.rsa3dsauth.com *.klarna.com *.facebook.com *.twitter.com *.googleapis.com *.bazaarvoice.com *.hotjar.com *.highstreettv.com *.gfsdeliver.com *.mitel.io *.ccdc02.com *.kaptcha.com *.freshrelevance.com https://d1y9qtn9cuc3xw.cloudfront.net https://d81mfvml8p5ml.cloudfront.net https://dkpklk99llpj0.cloudfront.net https://ds9p2a60lh6fp.cloudfront.net https://dn1i8v75r669j.cloudfront.net *.cloudflare.com/ajax/libs/ouibounce/0.0.12/ouibounce.min.js https://c1.dycdn.net/k8vnay8w/ https://c1.dycdn.net/k8vnay8w *.gocertify.me *.rsa3dsauth.co.uk *.americanexpress.com *.aexp-static.com *.apata.io yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.splitit.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.clearpay.co.uk https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.braintree-api.com https: 'self' https://*.yieldify.com 'about:blank' *.americanexpress.com *.aexp-static.com *.apata.io account.fetchify.com *.cookiebot.com *.klarna.com *.finance-calculator.co.uk *.deko.finance *.dekopay.com *.dekopay.org yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.splitit.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.afterpay.com *.clearpay.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.kaptcha.com§ https: data: 'self' https://*.yieldify.com https://*.yieldify-production.com *.americanexpress.com *.aexp-static.com *.apata.io *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com *.dycdn.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.finance-calculator.co.uk *.dekopay.com 'self' data: yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.splitit.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.convertexperiments.com *.adalyser.com *.klarnacdn.net https://*.yieldify.com 'unsafe-inline' *.facebook.net *.facebook.com *.twitter.com *.ads-twitter.com *.bing.com *.convertexperiment.com *.highstreettv.com *.reevoo.com *.google.com google.com/pay *.doubleclick.net *.googletagmanager.com *.trustpilot.com *.dwin1.com *.bootstrapcdn.com *.cloudflare.com *.google-analytics.com *.fontawesome.com *.gstatic.com *.criteo.com *.criteo.net *.bazaarvoice.com *.tiktok.com *.amazon.co.uk *.googleapis.com *.ipstatp.com wss://*.hotjar.com *.hotjar.com *.hotjar.io *.webtrends-optimize.com *.ibytedtos.com *.gfsdeliver.com *.mitel.io *.cardinalcommerce.com *.paypalobjects.com *.ccdc02.com *.braintreegateway.com *.kaptcha.com *.freshrelevance.com https://d1y9qtn9cuc3xw.cloudfront.net https://d81mfvml8p5ml.cloudfront.net https://d81mfvml8p5ml.cloudfront.net/k8vnay8w.js https://dkpklk99llpj0.cloudfront.net https://ds9p2a60lh6fp.cloudfront.net https://dn1i8v75r669j.cloudfront.net *.cloudflare.com/ajax/libs/ouibounce/0.0.12/ouibounce.min.js https://c1.dycdn.net/k8vnay8w/ https://c1.dycdn.net/k8vnay8w https://c.flx1.com *.zenaps.com *.googlesyndication.com *.gocertify.me 'self' 'report-sample' *.mateti.net *.journeyfurther.com *.americanexpress.com *.aexp-static.com *.apata.io tagmanager.google.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net am.freshrelevance.com *.cookiebot.com *.klarna.com *.finance-calculator.co.uk *.dekopay.com *.klarnaservices.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.splitit.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src display.ugc.bazaarvoice.com *.afterpay.com/ *.squarecdn.com unsafe-inline assets.braintreegateway.com https: data: 'self' 'report-sample' 'unsafe-inline' *.americanexpress.com *.aexp-static.com *.apata.io tagmanager.google.com fonts.google.com cc-cdn.com *.klarnacdn.net maxcdn.bootstrapcdn.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com *.splitit.com 'self' 'unsafe-inline'; object-src *.mitel.io 'self' 'unsafe-inline'; media-src 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.braintreegateway.com *.getbraintree.com *.payments-amazon.com *.payments-uk.amazon.com *.craftyclicks.co.uk *.convertexperiments.com *.criteo.com https://*.yieldify.com *.yieldify-production.com https://yieldify.connectorengine.com *.facebook.net *.facebook.com *.twitter.com *.ads-twitter.com *.bing.com *.convertexperiment.com *.reevoo.com google.com/pay *.googletagmanager.com *.trustpilot.com *.dwin1.com *.bazaarvoice.com *.bootstrapcdn.com *.criteo.net *.cloudflare.com *.google-analytics.com *.fontawesome.com *.gstatic.com *.doubleclick.net *.tiktok.com *.googleapis.com wss://*.hotjar.com *.hotjar.com *.hotjar.io *.webtrends-optimize.com *.gfsdeliver.com *.mitel.io *.ccdc02.com *.freshrelevance.com wss://am.freshrelevance.com/ https://d1y9qtn9cuc3xw.cloudfront.net https://d81mfvml8p5ml.cloudfront.net https://dkpklk99llpj0.cloudfront.net https://ds9p2a60lh6fp.cloudfront.net https://dn1i8v75r669j.cloudfront.net *.cloudflare.com/ajax/libs/ouibounce/0.0.12/ouibounce.min.js https://c1.dycdn.net/k8vnay8w/ https://c1.dycdn.net/k8vnay8w *.highstreettv.com *.gocertify.me 'self' *.amplitude.com *.mateti.net *.journeyfurther.com *.americanexpress.com *.aexp-static.com *.apata.io *.deko-uat.com *.analytics.google.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.dycdn.net am.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.finance-calculator.co.uk *.dekopay.com *.klarnaservices.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.splitit.com *.sentry.io *.amazonaws.com logs.browser-intake-datadoghq.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.kaptcha.com https://*.yieldify.com 'about:blank' http: https: blob: 'self' 'unsafe-inline'; default-src *.klarnaevt.com *.klarna.com *.klarnacdn.net *.braintreegateway.com *.braintree-api.com *.getbraintree.com *.amazon.com *.payments-amazon.com *.payments-uk.amazon.com *.facebook.com *.cloudflare.com *.paypal.com *.bazaarvoice.com *.gfsdeliver.com *.mitel.io *.cardinalcommerce.com *.ccdc02.com *.freshrelevance.com https://d1y9qtn9cuc3xw.cloudfront.net https://d81mfvml8p5ml.cloudfront.net https://dkpklk99llpj0.cloudfront.net https://ds9p2a60lh6fp.cloudfront.net https://dn1i8v75r669j.cloudfront.net *.cloudflare.com/ajax/libs/ouibounce/0.0.12/ouibounce.min.js https://c1.dycdn.net/k8vnay8w/ https://c1.dycdn.net/k8vnay8w *.highstreettv.com https://*.yieldify.com https://*.yieldify-production.com 'self' *.americanexpress.com *.aexp-static.com *.apata.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; report-uri https://62c41891d268e140f15015db.endpoint.csper.io?v=0;; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'nonce-Jgo1jPunQTcvjP2VQlQSDw==' 'unsafe-inline' https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline' *; img-src * data:; font-src * data:; connect-src *; frame-src 'self' https://challenges.cloudflare.com; frame-ancestors 'none'; upgrade-insecure-requests; worker-src 'self'; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubb28ba93eb59013963476c6dd6c190040&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to csp-datadog 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com/ js.mollie.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.lightwidget.com chimpstatic.com www.google.com vars.hotjar.com *.paypalobjects.com *.walkerslater.com *.prod-walkerslater.devitdelight.com *.cookiepro.com *.onetrust.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com https://www.magezon.com https://www.mollie.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cdninstagram.com services.postcodeanywhere.co.uk *.cloudiq.com *.google.co.uk *.google.com *.walkerslater.com *.prod-walkerslater.devitdelight.com *.cookiepro.com *.onetrust.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com *.google.com/ js.mollie.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.lightwidget.com *.cdninstagram.com chimpstatic.com www.google.com www.gstatic.com walke11142.pcapredict.com services.postcodeanywhere.co.uk *.hotjar.com *.cloudiq.com *.cookiepro.com *.onetrust.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.trustpilot.com services.postcodeanywhere.co.uk *.cookiepro.com *.onetrust.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com services.postcodeanywhere.co.uk *.cookiepro.com *.onetrust.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src cdn.cookielaw.org 'unsafe-hashes' 'sha256-5lSQFTOMNNoGBLbrC6eUxpYeuyBQW52hLO9rR85ASEA=' https: http: 'nonce-OS9C9rRFJQrM8SC/K7wGW429lr630USekcRRxqQ3hj0=' 'unsafe-eval' 'unsafe-inline';object-src 'none';frame-ancestors 'none';base-uri 'none';report-uri /api/csp-report 1 default-src 'self' data: https://*.whatstove.co.uk https://*.g.doubleclick.net https://www.google-analytics.com https://*.checkout.com https://*.google.com https://*.gstatic.com https://*.youtube.com https://*.googletagmanager.com https://*.googleoptimize.com https://*.reviews.co.uk https://*.pinterest.com https://*.googleapis.com https://*.reviews.co.uk; img-src 'self' data: https://*.whatstove.co.uk https://*.checkout.com https://*.gstatic.com https://*.googletagmanager.com https://*.reviews.co.uk https://*.pinterest.com https://*.googleapis.com https://*.reviews.co.uk https://*.google.com https://*.google.nl https://*.google.co.uk https://*.stovesonline.co.uk; font-src 'self' https://*.gstatic.com https://*.cloudfront.net; script-src 'self' 'nonce-h9vPCOnM0W8=' 'strict-dynamic'; style-src 'self' 'nonce-h9vPCOnM0W8=' data: https://*.whatstove.co.uk https://*.googleapis.com https://cdn.checkout.com; object-src 'none'; base-uri 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://www.whatstove.co.uk/csp-report; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.richcall.io *.getflowbox.com *.hotjar.com creativecdn.com *.cookiebot.com *.criteo.net *.criteo.com *.datatrics.com *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com www.apptrian.com *.cloudfront.net *.hipex.cloud *.bing.com *.cheqzone.com *.pinterest.com *.clarity.ms *.yahoo.com *.criteo.net *.criteo.com *.datatrics.com *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com mageside.com https://www.mollie.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com www.apptrian.com *.richcall.io *.getflowbox.com *.cookiebot.com *.pinimg.com *.criteo.net *.hotjar.com *.zdassets.com *.bing.com *.cheqzone.com *.clarity.ms *.criteo.com *.datatrics.com unpkg.com *.unpkg.com *.adcalls.nl *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.googleapis.com js.mollie.com tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com *.zdassets.com *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com www.apptrian.com *.richcall.io *.getflowbox.com *.zendesk.com *.zdassets.com *.pinterest.com *.clarity.ms *.cheqzone.com *.hotjar.com *.zopim.com *.datatrics.com *.doubleclick.net *.adcalls.nl wss://widget-mediator.zopim.com/ *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src *.richcall.io *.getflowbox.com *.meubelo.nl *.fonteyn.nl *.fonteyn.dev *.fonteyn.co.uk *.folm.de *.fonteynspas.com *.fonteynspas.de *.fonteynspas.co.uk *.fonteyntuinhuizen.nl http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; script-src 'self'; connect-src *.azurewebsites.net *.auth0.com https://cdn.contentful.com; style-src 'unsafe-inline' 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: images.ctfassets.net; frame-src 'self' *.auth0.com; frame-ancestors 'self'; form-action 'self'; 1 default-src 'self' informer.okta.com sso.scheduleexpress.com *.oktacdn.com; connect-src 'self' informer.okta.com informer-admin.okta.com sso.scheduleexpress.com *.oktacdn.com *.mixpanel.com *.mapbox.com informer.kerberos.okta.com https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' informer.okta.com sso.scheduleexpress.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' informer.okta.com sso.scheduleexpress.com *.oktacdn.com; frame-src 'self' informer.okta.com informer-admin.okta.com sso.scheduleexpress.com login.okta.com *.vidyard.com; img-src 'self' informer.okta.com sso.scheduleexpress.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' informer.okta.com sso.scheduleexpress.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' http://scheduleexpress.com 1 default-src *; script-src *; style-src *; img-src *; 1 font-src *.klarnacdn.net *.typekit.net *.fonts.smct.io *.akamaihd.net *.gstatic.com *.google.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.liveperson.net *.pinterest.com *.vimeo.com *.lpsnmedia.net *.formstack.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.apptrian.com ct.pinterest.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com *.silentnightbrands-gb.attn.tv *.bazaarvoice.com *.collector-20390.tvsquared.com *.bat.bing.com *.onetrust.com *.google.com *.cdn.smct.io *.cdn.smct.co *.ctfassets.net *.placeholder.com *.photorank.me *.quantserve.com *.ometria.com *.data-8.co.uk *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com www.pinterest.com s.pinimg.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com *.smct.co *.js.smct.io *.bat.bing.com *.rules.quantcount.com *.script.hotjar.com *.lantern.roeyecdn.com *.cdn.attn.tv *.cdn.sub2tech.com *.collector-20390.tvsquared.com *.static.hotjar.com *.dwin1.com *.google.com *.sharethis.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.googleapis.com *.bazaarvoice.com *.onetrust.com *.trustpilot.com *.ometria.com *.liveperson.net *.quantserve.com *.doubleclick.net *.lpsnmedia.net *.akamaihd.net *.data-8.co.uk *.pinterest.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com display.ugc.bazaarvoice.com *.klarnacdn.net https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.fonts.smct.io *.akamaihd.net *.data-8.co.uk *.gstatic.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com ct.pinterest.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com ct.pinterest.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com connect.facebook.net graph.facebook.com *.ws.hotjar.com *.data-8.co.uk *.content.hotjar.io *.ipl.smct.io *.firehose.eu-west-1.amazonaws.com *.silentnightbrands-gb.attn.tv *.googleads.g.doubleclick.net *.events.attentivemobile.com *.onetrust.com *.akamaihd.net *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com https://premier.trustcommerce.com;script-src 'nonce-4db81a05586b4163a265fd60f7d45950' https://elriomychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://elriomychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src https://client.crisp.chat https://cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net https://jqwidgets.com http://jquerygrid.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://maps.google.com/ *.authorize.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://image.crisp.chat cdn.jsdelivr.net https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://client.crisp.chat cdn.jsdelivr.net *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://client.crisp.chat cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: https://cdnjs.cloudflare.com https://*.swaven.com/ data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://*.facebook.com/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ https://*.doubleclick.net/ https://*.swaven.com/ https://app.trustt.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://*.adnxs.com/ https://axeptio.imgix.net/ https://*.bing.com/ https://*.clarity.ms/ https://*.google.fr/pagead/ https://*.leanature.com/media/ https://mcstaging2.leanature.fr/media/ https://*.cloudfront.net/ https://*.swaven.com/ https://app.trustt.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://*.adnxs.com/ https://*.amazon-adsystem.com/ https://*.axept.io/ https://*.bing.com/ https://*.clarity.ms/ https://*.leanature.com/ https://*.newrelic.com/ https://*.mikmak.ai/ https://static-sb.com/js/ https://*.swaven.com/ https://*.tiktok.com https://*.iadvize.com https://app.trustt.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.googleapis.com/gtv-videos-bucket https://app.trustt.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.adnxs.com/ https://*.amazon-adsystem.com/ https://*.bing.com/ https://*.leanatureboutique.com/ https://*.swaven.com/ https://*.axept.io/ https://*.clarity.ms/ https://*.google-analytics.com/ https://*.google.com/pagead/ https://googleads.g.doubleclick.net/ https://*.nr-data.net/ https://*.paa-reporting-advertising.amazon/ https://social-sb.com/ https://*.tiktok.com https://*.iadvize.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval'; style-src * 'report-sample' 'unsafe-inline'; worker-src *; base-uri *; form-action *; frame-ancestors * 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' data: consent.cookiebot.com consentcdn.cookiebot.com www.googletagmanager.com *.pinterest.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com www.haarshop.nl integrations.etrusted.com interface.mailcampaigns.nl *.cloudfront.net app.youshouldask.ai bat.bing.net *.bing.com imgsct.cookiebot.com haarshop.nl cdn.flbx.io at19.net *.google.nl google.nl https://maps.googleapis.com https://maps.gstatic.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.magmodules.eu *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com 'self' data: 'unsafe-eval' interface.mailcampaigns.nl connect.getflowbox.com widgets.trustedshops.com cdnjs.cloudflare.com *.cookiebot.com app.youshouldask.ai bat.bing.com bgmin.cdn.billygrace.com selfservice.robinhq.com robincontentdesktop.blob.core.windows.net sgtm.haarshop.nl gum.criteo.com az416426.vo.msecnd.net mapix.marvelpixel.io *.beslist.nl *.cloudfront.net *.container.webgains.link *.pinimg.com *.clarity.ms *.pinterest.com *.webgains.io https://static.dhlecommerce.nl *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com squeezely.tech www.squeezely.tech *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com 'self' data: integrations.etrusted.com interface.mailcampaigns.nl app.youshouldask.ai https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' data: cdn.flbx.io haarshop.nl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com https://player.vimeo.com 'self' data: gateway.getflowbox.com api-acc.paazl.com app.youshouldask.ai b.billypx.com bat.bing.net *.bing.com consentcdn.cookiebot.com dc.services.visualstudio.com a.getflowbox.com *.marvelpixel.io *.amazonaws.com *.clarity.ms google.nl *.google.nl interface.mailcampaigns.nl *.beslist.nl *.pinterest.com *.tiktokw.us *.vo.msecnd.net https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com squeezely.tech *.squeezely.tech *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 object-src 'none'; connect-src 'self' *.nextdoorstudios.com *.asgmax.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.nextdoorstudios.com *.asgmax.com join.gammasecure.com; script-src 'self' *.nextdoorstudios.com *.asgmax.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.nextdoorstudios.com *.asgmax.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.storepoint.co https://widget.storepoint.co *.googleapis.com *.google.co.uk https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.co.in *.storepoint.co https://widget.storepoint.co *.googleapis.com *.google.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com *.cloudflare.com *.amazonaws.com *.mouseflow.com *.smooch.io *.googleapis.com www.gstatic.com www.google.com static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com www.xtento.com cdn.xtento.com js.squareup.com js.afterpay.com nd.squarecdn.com js.squareupsandbox.com sandbox.web.squarecdn.com web.squarecdn.com portal.sandbox.afterpay.com portal.afterpay.com cdn.plaid.com sandbox.kit.cash.app kit.cash.app *.storepoint.co *.gdoubleclick.net *.google.co.uk https://widget.storepoint.co https://hosted.mastersoftgroup.com/harmony/rest/au/generateID https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ songbirdstag.cardinalcommerce.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.typekit.net *.cash.app *.squarecdn.com *.storepoint.co https://widget.storepoint.co *.googleapis.com *.google.co.uk https://static.klaviyo.com assets.braintreegateway.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googlesyndication.com *.zdassets.com *.zendesk.com wss://api.smooch.io/faye *.storepoint.co https://widget.storepoint.co *.googleapis.com *.google.co.uk https://hosted.mastersoftgroup.com/harmony/rest/au/generateID https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.hardx.com *.xempire.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.hardx.com *.xempire.com join.gammasecure.com; script-src 'self' *.hardx.com *.xempire.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.hardx.com *.xempire.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://code.jquery.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://static-m.meteo.cat; font-src 'self' https://fonts.gstatic.com; 1 default-src 'self' https: data: 1 default-src 'self'; base-uri 'self'; img-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://img.youtube.com https://*.clarity.ms https://c.bing.com https://i.bojoko.ca https://bojoko.ca/assets; media-src 'self' https://i.bojoko.com; script-src 'report-sample' 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://static.cloudflareinsights.com https://cdn-4.convertexperiments.com https://*.clarity.ms 'sha256-ZUDX9Z+y1rWudy0ln+zV0AsrZoVsm3aQhzUY359l8FM=' 'sha256-Zu9ZHvBSKzZyXjZrz4AX9EWoBfFbXk/x/UxqJDROcHc=' https://bojoko.ca/assets 'sha256-p6okEBqgErPTJtg2nCg31voW7A23QV0fN+BRir9dQaE='; style-src 'report-sample' 'self' 'unsafe-inline' https://bojoko.ca/assets; object-src 'none'; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://region1.google-analytics.com https://region1.analytics.google.com https://plausible.bojoko.com https://cdn-4.convertexperiments.com https://*.clarity.ms; frame-src 'self' https://www.youtube-nocookie.com/embed/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; frame-ancestors 'none'; worker-src 'none'; report-uri https://bojoko.endpoint.csper.io; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com https://media.flixcar.com https://media.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * consentcdn.cookiebot.com service.giosg.com static.hotjar.com https://www.googletagmanager.com https://tracking.veikonkone.fi 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.klevu.com *.ksearchnet.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn2.hubspot.net resources.paytrail.com *.visualwebsiteoptimizer.com bat.bing.com imgsct.cookiebot.com where-to-buy.co strack.where-to-buy.co *.videoly.co rt.flix360.com media.flixcar.com https://www.veikonkone.fi https://www.google.fi/ https://tracking.veikonkone.fi https://cdn.giosgusercontent.com https://embed-ssl.wistia.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://browser.sentry-cdn.com *.klevu.com *.ksearchnet.com https://api.unifaun.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com *.visualwebsiteoptimizer.com api.custobar.com consentcdn.cookiebot.com consent.cookiebot.com bat.bing.com service.giosg.com *.hotjar.com app.kuvio.io *.videoly.co where-to-buy.co payment-widget.avarda.com payment-widget.stage.avarda.com media.flixfacts.com media.flixcar.com https://js.klevu.com https://cdn.jsdelivr.net https://prod.flixgvid.flix360.io https://globalcdn.interactiondesigner.giosg.com https://js.klevu.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com https://cdn.jsdelivr.net https://media.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.paytrail.com tracking.veikonkone.fi service.giosg.com checkout-api.avarda.com stage.checkout-api.avarda.com *.hotjar.io media.flixcar.com bat.bing.com api.kuvio.io https://api.custobar.com https://9cfc0d92-bc44-495e-b48c-f1d005cf1d55.interactions.giosgusercontent.com https://consentcdn.cookiebot.com https://api.giosg.com https://0ab79cf7-f195-4696-8ae4-d038878b095c.interactions.giosgusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' *.appmaster.io https://analytics.google.com https://*.analytics.google.com https://www.google-analytics.com https://forms.hsforms.com https://maps.googleapis.com https://stats.g.doubleclick.net www.google.com; font-src 'self' data: https: ; img-src 'self' data: blob: https: ; media-src 'self' data: blob: https: ; object-src 'none'; frame-src 'self' *.appmaster.io *.recaptcha.net *.youtube.com widget.canny.io; base-uri 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.appmaster.io *.hsforms.net https://maps.googleapis.com/maps/api/js https://www.googletagmanager.com/gtag/js https://www.gstatic.com/recaptcha/ *.recaptcha.net *.canny.io; manifest-src 'self'; script-src-elem 'self' 'unsafe-inline' *.appmaster.io *.hs-scripts.com *.hs-analytics.net *.hs-banner.com www.googletagmanager.com chat.appmaster.io; style-src 'self' 'unsafe-inline' 'report-sample' *.appmaster.io https://fonts.googleapis.com; worker-src data: blob: studio.appmaster.io; report-uri https://s.appmaster.io/api/3/security/?sentry_key=f3a1f5e566804120856802b6ba1adda8; report-to apms; 1 default-src 'self'; script-src 'self' https://euc-widget.freshworks.com https://cdn.polyfill.io; style-src 'self' https://euc-widget.freshworks.com; connect-src 'self'; img-src 'self' data: https://images.ctfassets.net; base-uri 'self'; form-action 'self' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua 'self' data: data: *.magentocommerce.com *.zonos.com *.yotpo.com yotpo.com www.yotpo.com *.fontawesome.com *.authorize.net *.facebook.net *.facebook.com *.bootstrapcdn.com *.hubspot.com *.mailchimp.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com *.dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com xtento.com *.xtento.com *.cloudmaestro.com *.unpkg.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.sandbox.paypal.com *.paypal.com *.paypalobjects.com *.youtube.com *.apptrian.com www.apptrian.com *.vimeo.com *.use.typekit.net *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com 'self' * data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.reviews.io *.reviews.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.iglobalstores.com *.authorize.net *.spreedly.com *.hubspot.com *.getbread.com paypal.com *.braintree-api.com *.addthis.com www.youtube.com *.online-metrix.net *.signifyd.com *.demdex.net *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.yotpo.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.g.doubleclick.net *.cloudmaestro.com vimeo.com *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com 'self' www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.b0e8.com https://images.unsplash.com *.cloudfront.net *.reviews.io *.reviews.co.uk magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.google.com www.google-analytics.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua 'self' data: *.magentocommerce.com *.zonos.com *.yotpo.com yotpo.com www.yotpo.com *.ytimg.com *.s3.amazonaws.com *.amazonaws.com *.klaviyo.com *.g.doubleclick.net *.hubspot.com *.authorize.net *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.signifyd.com *.e.aa.online-metrix.net *.bbb.org *.facebook.net *.facebook.com *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com *.secure.force.com *.mailchimp.com *.demdex.net *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com www.xtento.com cdn.xtento.com px.ads.linkedin.com bat.bing.com pippio.com *.cloudmaestro.com *.events.bouncex.net *.fls.doubleclick.net 11158761.fls.doubleclick.net tr2.smarterhq.io *.smarterhq.io js.authorize.net ssl.kaptcha.com *.kaptcha.com www.shareasale.com *.shareasale.com *.bouncex.net ciqtracking.com *.doubleclick.net widget.reviews.io jsstore.s3-us-west-2.amazonaws.com *.s3-us-west-2.amazonaws.com 'self' * *.hsforms.net *.hsforms.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.b0e8.com *.bc0a.com https://maps.googleapis.com *.reviews.io *.reviews.co.uk *.disqus.com *.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.cloudflare.com acsbapp.com *.impactcdn.com *.trustedshops.com *.usercentrics.eu *.cardinalcommerce.com *.ccdc02.com *.authorize.net *.spreedly.com *.zonos.com *.yotpo.com *.bootstrapcdn.com bam.nr-data.net *.zopim.com *.facebook.net *.facebook.com *.zdassets.com *.klaviyo.com *.zendesk.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com fast.a.klaviyo.com *.hubspot.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.cookielaw.org *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.onetrust.com paypal.com *.signifyd.com *.g.doubleclick.net *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com *.braintree-api.com chimpstatic.com *.mailchimp.com mc.us18.list-manage.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com undefined/api/v2/sites/74088/recordings/content unpkg.com *.unpkg.com *.cloudfront.net d1n00d49gkbray.cloudfront.net/wknd/wknd_cartridge.js tr2.smarterhq.io *.apptrian.com hello.zonos.com staticw2.yotpo.com brainmd.com stats.g.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.go2sdk.com ciqtracking.com *.doubleclick.net script.crazyegg.com *.crazyegg.com js.adsrvr.org cdn.attn.tv container.pepperjam.com forms.hscollectedforms.net js.hscollectedforms.net salsify-ecdn.com fs19.formsite.com *.s3.amazonaws.com *.amazonaws.com s3.amazonaws.com s3-us-west-2.amazonaws.com *.execute-api.us-west-2.amazonaws.com alocdn.com b-code.liadm.com *.liadm.com api.retention.com cdn.oribi.io www.snapengage.com www.mnpa6gtrk.com shop.pe *.shop.pe static.cloudflareinsights.com cdn.cookie.pii.ai widget.reviews.io 'self' *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://cdn.jsdelivr.net assets.braintreegateway.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.magentocommerce.com *.zonos.com *.yotpo.com *.fontawesome.com getfirebug.com *.klaviyo.com *.bootstrapcdn.com *.authorize.net display.ugc.bazaarvoice.com *.signifyd.com *.facebook.net *.facebook.com *.mailchimp.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com www.sandbox.paypal.com *.fls.doubleclick.net 11158761.fls.doubleclick.net tr2.smarterhq.io *.smarterhq.io js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com widget.reviews.io 'self' * data: tagmanager.google.com fonts.google.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.zdassets.com *.tinymce.com *.tiny.cloud cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com *.yotpo.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com *.fls.doubleclick.net 11158761.fls.doubleclick.net js.authorize.net *.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net ciqtracking.com 'self' * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com https://maps.googleapis.com https://player.vimeo.com *.cloudfront.net *.reviews.io *.reviews.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.gstatic.com *.adobedtm.com *.acsbapp.com *.impactcdn.com *.ccdc02.com *.authorize.net *.zonos.com *.yotpo.com *.cloudflare.com *.jsdelivr.net *.trustedshops.com *.usercentrics.eu *.facebook.net *.facebook.com bam.nr-data.net *.zopim.com *.zdassets.com *.klaviyo.com *.zendesk.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com fast.a.klaviyo.com *.hubspot.com wss://widget-mediator.zopim.com *.widget-mediator.zopim.com *.cookielaw.org *.bazaarvoice.org *.bazaarvoice.com display.ugc.bazaarvoice.com *.getbread.com *.onetrust.com paypal.com *.signifyd.com *.g.doubleclick.net *.addthis.com *.collect.igodigital.com *.salesforceliveagent.com *.moatads.com *.addthisedge.com *.la1-c2-iad.salesforceliveagent.com *.la1-c2-ord.salesforceliveagent.com chimpstatic.com *.mailchimp.com *.demdex.net *.tinymce.com cdn.iglobalstores.com *.licdn.com *.bing.com dwin1.com www.dwin1.com *.bounceexchange.com linkedin.com *.adsymptotic.com p.adsymptotic.com *.cdnbasket.net *.cdnwidget.com *.iglobalstores.com yotpo.com www.yotpo.com xtento.com *.xtento.com *.cloudmaestro.com undefined/api/v2/sites/74088/recordings/content unpkg.com *.unpkg.com d1n00d49gkbray.cloudfront.net/wknd/wknd_cartridge.js tr2.smarterhq.io *.apptrian.com hello.zonos.com staticw2.yotpo.com brainmd.com stats.g.doubleclick.net js.authorize.net ssl.kaptcha.com *.kaptcha.com *.bouncex.net *.go2sdk.com ciqtracking.com *.doubleclick.net retail-client-events-service.internal.salsify.com script.crazyegg.com salsify-ecdn.com forms.hscollectedforms.net js.hscollectedforms.net events.attentivemobile.com *.attentivemobile.com shelterlogic-us.attn.tv *.attn.tv shelterlogic.sjv.io *.sjv.io tracking.crazyegg.com assets-tracking.crazyegg.com *.crazyegg.com api.retention.com b-code.liadm.com *.liadm.com *.execute-api.us-west-2.amazonaws.com manage.safeopt.com app.shop.pe alocdn.com shopper.shop.pe cdn.cookie.pii.ai geo.pii.ai consent-api.pii.ai api.reviews.io *.bc0a.com 'self' t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://*.svea.com https://*.vipps.no https://*.trustly.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com https://*.svea.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com vjs.zencdn.net player.vimeo.com https://*.svea.com chimpstatic.com downloads.mailchimp.com *.list-manage.com static.lipscore.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com wapi.lipscore.com users.lipscore.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; font-src https://pim.varmefag.no *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: fonts.gstatic.com static.lipscore.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; style-src https://pim.varmefag.no *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com vjs.zencdn.net fonts.googleapis.com downloads.mailchimp.com static.lipscore.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; img-src https://pim.varmefag.no assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com static.lipscore.com blob: img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; 1 default-src 'self' *.umbraco.com https://stats.g.doubleclick.net *.wandel.nl *.avond4daagse.nl *.pinterest.com *.cookiebot.com *.google-analytics.com packages.umbraco.org our.umbraco.org www.gravatar.com our.umbraco.com *.akamaized.net *.vimeo.com *.vimeocdn.com https://youtu.be https://www.youtube.com cdnjs.cloudflare.com *.facebook.com *.hotjar.com *.hotjar.io; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com wandel.blueconic.net *.avond4daagse.nl *.umbraco.com https://s.pinimg.com https://snap.licdn.com https://connect.facebook.net *.wandel.nl https://script.hotjar.com https://static.hotjar.com https://wandel.blueconic.net https://cdn.blueconic.net *.cookiebot.com ajax.aspnetcdn.com www.googletagmanager.com www.google-analytics.com www.google.com www.gstatic.com https://tagmanager.google.com https://spotlerscript.com https://maps.googleapis.com https://t.spotlerleads.nl cdnjs.cloudflare.com cdn.jsdelivr.net www.google-analytics.com www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.avond4daagse.nl cdn.blueconic.net static.hotjar.com script.hotjar.com www.google-analytics.com *.pinimg.com *.facebook.net *.facebook.com cdn.jsdelivr.net www.googletagmanager.com *.wandel.nl wandel.blueconic.net *.cookiebot.com *.atleta.cc; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com *.umbraco.com *.typekit.net *.wandel.nl https://tagmanager.google.com https://fonts.googleapis.com cdnjs.cloudflare.com; img-src 'self' data: *.umbraco.com *.pinterest.com *.umbraco.com *.facebook.com *.facebook.net *.linkedin.com www.gravatar.com umbraco.tv our.umbraco.org our.umbraco.com dashboard.umbraco.org https://i.ytimg.com https://csi.gstatic.com https://maps.gstatic.com www.gravatar.com umbraco.tv *.googleapis.com www.google-analytics.com stats.g.doubleclick.net https://ssl.gstatic.com https://www.gstatic.com cdnjs.cloudflare.com *.azureedge.net *.wandel.nl *.googletagmanager.com *.facebook.com wandel.gxcloud.net www.github.com www.bing.com *.vimeocdn.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; font-src 'self' data: *.umbraco.com *.cookiebot.com https://use.typekit.net https://fonts.gstatic.com data: cdnjs.cloudflare.com *.avast.com *.facebook.net; frame-src 'self' *.umbraco.com https://www.pinterest.com https://vars.hotjar.com *.cookiebot.com youtu.be www.youtube.com www.google.com https://player.vimeo.com *.pinterest.com *.facebook.com *.googletagmanager.com https://atleta.cc; connect-src 'self' https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com wandel.blueconic.net *.avond4daagse.nl *.facebook.com *.hotjar.com *.hotjar.io code.jquery.com *.cookiebot.com *.umbraco.com; 1 font-src *.googleapis.com *.gstatic.com data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net https://www.trustedsite.com *.trustpilot.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://cdn.ywxi.net guarantee-cdn.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://cdn.ywxi.net https://www.trustedsite.com *.trustpilot.com *.cloudflare.com guarantee-cdn.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://s3-us-west-2.amazonaws.com/mfesecure-public/ https://www.trustedsite.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com v2.zopim.com embed.tawk.to *.commerce-connector.com *.flixcar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sameday.ro c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.2performant.com *.doubleclick.net *.pinterest.com *.force.com *.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io tracker.aqurate.ai https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com v2assets.zopim.io *.google.ro *.facebook.com *.widgetwhats.com tawk.link compari.ro ct.pinterest.com *.flix360.com *.flixcar.com *.flix360.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tracker.aqurate.ai *.sameday.ro unpkg.com/map-fanbox-points@0.0.5/umd/map-fanbox-points.js https://maps.googleapis.com https://player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.zdassets.com v2.zopim.com *.facebook.net *.facebook.com attr-2p.com *.widgetwhats.com chimpstatic.com embed.tawk.to *.jsdelivr.net *.hotjar.com *.arukereso.com *.gstatic.com *.clarity.ms *.themarketer.com *.pinimg.com *.pinterest.com *.enzuzo.com cdn-cookieyes.com *.googlesyndication.com *.commerce-connector.com *.force.com *.salesforceliveagent.com aqurate.ai *.flixcar.com *.flix360.io *.flixfacts.com popupsmart.com *.sharethis.com *.tiktok.com *.omniconvert.com *.2performant.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sameday.ro assets.braintreegateway.com *.googleapis.com *.widgetwhats.com embed.tawk.to *.googletagmanager.com tpc.googlesyndication.com *.cloudfront.net *.commerce-connector.com *.force.com *.popupsmart.com popupsmart.com *.flixcar.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com tracker.aqurate.ai *.fancourier.ro https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com ekr.zdassets.com wss://widget-mediator.zopim.com pagead2.googlesyndication.com *.google.ro googleads.g.doubleclick.net stats.g.doubleclick.net region1.analytics.google.com *.2performant.com *.widgetwhats.com zdata-ro-bellabike.s3.eu-west-1.amazonaws.com *.tawk.to kfea.zendesk.com api.edrone.me *.themarketer.com *.pinterest.com *.clarity.ms *.commerce-connector.com *.facebook.com *.hotjar.com *.hotjar.io *.google-analytics.com *.sharethis.com *.enzuzo.com *.flixcar.com *.tiktok.com *.omniconvert.com region1.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src widget-mediator.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: 'unsafe-inline' *.google-analytics.com *.okta.com *.networkhealth.com networkhealth.com *.facebook.com *.google.com *.doubleclick.net networkhealthfdb.adaptiverx.com *.cloudflare.com *.googleapis.com *.gstatic.com *.googleapis.com *.oktacdn.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.google.com *.gstatic.com www.google-analytics.com *.networkhealth.com *.cloudflare.com *.facebook.net *.doubleclick.net *.googleapis.com *.oktacdn.com *.okta.com; connect-src 'self' *.networkhealth.com *.okta.com; object-src 'self' *.networkhealth.com; frame-ancestors 'self' *.adaptiverx.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.bootstrapcdn.com *.edrone.me *.googleapis.com *.google.com/recaptcha *.google-analytics.com https://cdnjs.cloudflare.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.payline.com *.gstatic.com *.google.com/recaptcha *.google.com *.google-analytics.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.payline.com *.criteo.com *.facebook.net *.gstatic.com *.edrone.me *.cloudfront.net *.googleapis.com *.trustedshops.com *.google.com/recaptcha *.hotjar.com *.google-analytics.com *.cookiebot.com *.addthis.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.dhl.pl *.dhl24.com.pl *.packeta.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.cookiebot.com https://img.youtube.com https://i.ytimg.com *.google-analytics.com *.googleadservices.com *.google.pl *.ssl.gstatic.com *.edrone.me *.cloudfront.net *.googleapis.com *.trustedshops.com *.google.com/recaptcha https://csr.onet.pl *.inistrack.net *.pixel.wp.pl https://pixel.wp.pl/api *.clarity.ms https://t.co *.bing.com *.yahoo.com *.criteo.com https://x.bidswitch.net https://ib.adnxs.com https://secure.adnxs.com https://contextual.media.net https://pixel.rubiconproject.com https://match.sharethrough.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://sync-criteo.ads.yieldmo.com https://criteo-partners.tremorhub.com https://eb2.3lift.com https://cm.adform.net https://visitor.omnitagjs.com https://r.casalemedia.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://ad.yieldlab.net https://dpm.demdex.net https://beacon.krxd.net https://a.twiago.com https://s.thebrighttag.com https://static.paynow.pl *.disqus.com *.addthisedge.com *.twitter.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com 'self' 'unsafe-inline' data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.ssl.google-analytics.com *.googleadservices.com *.criteo.com *.criteo.net *.savecart.pl *.trustedshops.com *.edrone.me *.cloudfront.net *.googleapis.com http://www.google.com/recaptcha/api.js https://www.google.com/recaptcha/api.js *.goadservices.com *.onet.pl *.tagmanager.google.com https://ocdn.eu *.cardinalcommerce.com *.hotjar.com https://live-chat.chatbotize.com/chatbotize-entrypoint.min.js *.pixel.wp.pl https://pixel.wp.pl/w/tr.js https://pixel.wp.pl *.inistrack.net https://cdn.jsdelivr.net/npm/@finsweet/cookie-consent@1/fs-cc.js *.cookiebot.com *.bing.com *.twitter.com *.inis360.com *.cdngazeta.com *.cdngazeta.pl cdngazeta.pl *.googleoptimize.com *.clarity.ms https://artemis-cdn.ocdn.eu https://p.gsitrix.com https://o.gsitrix.com/sys.php https://bam.eu01.nr-data.net https://static.ads-twitter.com https://analytics.tiktok.com https://ec.monplat-cdn.com *.luigisbox.com https://static.paynow.pl https://cdnjs.cloudflare.com *.disqus.com *.addthis.com *.moatads.com *.addthisedge.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com *.easypack24.net *.inpost.pl *.packeta.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' googleadservices.com cdn.luigisbox.com 'unsafe-eval' dwin1.com awin1.com zenaps.com the.sciencebehindecommerce.com *.clickonometrics.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.bootstrapcdn.com *.edrone.me *.trustedshops.com *.google.com/recaptcha *.tagmanager.google.com *.google-analytics.com *.cookiebot.com *.savecart.pl *.luigisbox.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' cdn.luigisbox.com imgsct.cookiebot.com fonts.googleapis.com cdnjs.cloudflare.com widgets.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src https://tolpapl.savecart.pl 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.edrone.me *.trustedshops.com *.google.com/recaptcha http://d3bo67muzbfgtl.cloudfront.net/externals *.cardinalcommerce.com *.onet.pl *.hotjar.com https://www.googleapis.com/pagespeedonline *.googleapis.com *.savecart.pl *.cookiebot.com *.clarity.ms https://p.gsitrix.com https://bam.eu01.nr-data.net https://clk.leadexpert.pl https://analytics.tiktok.com *.luigisbox.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.packeta.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-eval' pixel.wp.pl dwin1.com awin1.com zenaps.com the.sciencebehindecommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill.io https://unpkg.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.googleapis.com *.almapay.com localhost *.louispion.fr *.evermaps.io *.octipas.net https://cdnjs.cloudflare.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com localhost *.louispion.fr *.evermaps.io *.octipas.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.doubleclick.net *.facebook.com *.criteo.com *.leadplace.fr *.pinterest.com *.vimeo.com *.rolex.com localhost *.louispion.fr *.evermaps.io *.octipas.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.googletagmanager.com/ js.mollie.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://images.unsplash.com *.cookielaw.org *.stickyadstv.com *.bing.com *.facebook.com *.teads.tv *.rubiconproject.com *.dmxleo.com *.liadm.com *.outbrain.com *.taboola.com *.smartadserver.com *.3lift.com *.360yield.com *.pubmatic.com *.casalemedia.com *.media.net *.adform.net *.omnitagjs.com *.sharethrough.com *.ivitrack.com *.mediavine.com *.smaato.net *.doubleclick.net *.yahoo.com *.emxdgt.com *.tremorhub.com *.adnxs.com *.analytics.yahoo.com *.bidswitch.net *.criteo.com *.thebrighttag.com *.krxd.net *.yieldmo.com id5-sync.com *.yieldlab.net *.pinterest.com *.rolex.com *.googletagmanager.com *.doubleclick.net px.ads.linkedin.com *.bing.net localhost *.louispion.fr *.evermaps.io *.octipas.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.mollie.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com data: 'self' 'unsafe-inline' 'strict-dynamic'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page cdn.jsdelivr.net *.googleapis.com *.gstatic.comm https://maps.googleapis.com player.vimeo.com maps.googleapis.com *.googletagmanager.com *.cookielaw.org *.early-birds.fr *.msecnd.net *.onetrust.com *.beeroot.io *.bing.com *.facebook.net *.facebook.com advgame.fr *.cloudfront.net *.teads.tv *.doubleclick.net *.clarity.ms *.criteo.net *.criteo.com *.adnxs.com *.leadplace.fr *.pinimg.com *.h1d3n0tsoo-staging-easiwebforms.net *.easiconnect.io *.adleadevent.com *.rolex.com *.booxi.eu *.naver.net payment.direct.worldline-solutions.com *.hotjar.com *.hotjar.io wisepops.net louispion.fr.bhglmag2.dnd.fr rqz-galerieslafayette.com.bhglmag2.dnd.fr *.louispion.fr *.rqz-galerieslafayette.com payment.preprod.direct.worldline-solutions.com rum.hlx.page localhost *.evermaps.io *.octipas.net https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.mollie.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.googletagmanager.com localhost *.louispion.fr *.evermaps.io *.octipas.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.fontawesome.com 'self' 'unsafe-inline'; object-src localhost *.louispion.fr *.evermaps.io 'self' 'unsafe-inline'; media-src *.adobe.com localhost *.louispion.fr *.evermaps.io *.youtube-nocookie.com *.octipas.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.almapay.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com ct.pinterest.com *.google.fr *.gstatic.comm *.cookielaw.org *.onetrust.com *.clarity.ms *.advalo.com *.teads.tv *.beeroot.io *.bing.com *.pinterest.com *.googlesyndication.com *.adleadevent.com *.abstractapi.com *.data.gouv.fr *.rolex.com *.adobedtm.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com wisepops.com *.wisepops.com wisepops.net *.wisepops.net louispion.fr.bhglmag2.dnd.fr rqz-galerieslafayette.com.bhglmag2.dnd.fr *.louispion.fr *.rqz-galerieslafayette.com payment.preprod.direct.worldline-solutions.com payment.direct.worldline-solutions.com *.googletagmanager.com px.ads.linkedin.com *.bing.net *.adnxs.com *.adsrvr.org localhost *.evermaps.io *.octipas.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://nominatim.openstreetmap.org payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'strict-dynamic'; child-src localhost *.louispion.fr *.evermaps.io assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; frame-ancestors 'self'; base-uri 'self'; object-src 'none'; img-src 'self' https: data:; script-src 'self' https:; style-src 'self' https:; font-src 'self' https: data:; connect-src 'self' https:; 1 default-src www.askmid.com; script-src www.askmid.com 'unsafe-inline' 'unsafe-eval'; style-src www.askmid.com 'unsafe-inline' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cleverreach.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://analytics.google.com https://*.usercentrics.eu https://vimeo.com https://*.vimeocdn.com https://*.youtube.com https://*.googleapis.com https://*.googletagmanager.com https://tagmanager.google.com js.mollie.com https://app.storyblok.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://*.googleapis.com *.cloudfront.net https://app.usercentrics.eu https://googleads.g.doubleclick.net https://www.googleadservices.com https://analytics.google.com https://*.vimeocdn.com https://www.mollie.com https://api.mapbox.com *.storyblok.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.googleapis.com *.gstatic.com https://googleads.g.doubleclick.net https://analytics.google.com https://*.usercentrics.eu https://*.youtube.com https://vimeo.com https://*.googleapis.com *.googletagmanager.com tagmanager.google.com https://*.storyblok.com js.mollie.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.storyblok.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://*.googleapis.com https://*.usercentrics.eu https://www.googleadservices.com https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com autocomplete2.postdirekt.de *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.beleuchtungdirekt.de data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.beleuchtungdirekt.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.beleuchtungdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b428c232-f415-4fb2-b456-fef23ba335ec.sansec.watch/; report-to report-endpoint; 1 default-src * 'unsafe-eval' 'unsafe-inline' 'unsafe-dynamic' data: filesystem: about: blob: ws: wss: 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com *.fonts.googleapis.com data: *.cloudflare.com *.elfsight.com https://cdn.aplazame.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com www.google.com *.addthis.com *.pinterest.com *.elfsight.com js.monei.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com cdn.doofinder.com magefan.com cm.magefan.com https://www.magezon.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.elfsight.com https://files.elfsightcdn.com https://lh3.googleusercontent.com https://cdn.aplazame.com https://www.paypalobjects.com https://www.redsys.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com *.google.com/ *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com https://www.termsfeed.com *.elfsight.com https://kit.fontawesome.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com https://cdn.aplazame.com https://pay.google.com js.monei.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.doofinder.com maxcdn.bootstrapcdn.com *.elfsight.com https://cdn.aplazame.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com *.doofinder.com wss://*.doofinder.com *.cloudflare.com *.addthis.com *.graph.instagram.com *.google-analytics.com *.elfsight.com https://core.service.elfsight.com https://api.aplazame.com https://sec.inercia.com api.monei.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval' ; report-uri https://fr.tuto.com/a_reportcsp/log 1 frame-src 'self' https://embed.tawk.to/ https://plugins.tawk.to; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.7.0/jquery.min.js https://embed.tawk.to/ https://ajax.googleapis.com/ajax/libs/jquery/1.11.0/ cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net mdbootstrap.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.7.0/jquery.min.js https://embed.tawk.to/ https://ajax.googleapis.com/ajax/libs/jquery/1.11.0/jquery.min.js cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net mdbootstrap.com; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.7.0/jquery.min.js https://embed.tawk.to/ cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net mdbootstrap.com use.fontawesome.com; frame-ancestors 'self' static.addtoany.com https://embed.tawk.to/ 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com https://www.magezon.com flagpedia.net https://www.mollie.com https://api.mapbox.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com *.gstatic.com maps.googleapis.com js.mollie.com *.hsforms.net *.hsforms.com *.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu www.gstatic.com maps.googleapis.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com *.sleeknote.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com landofcoder.com maps.googleapis.com chart.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * checkoutshopper-test.adyen.com www.youtube.com consentcdn.cookiebot.com vars.hotjar.com s.acquire.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com js.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com maps.googleapis.com checkoutshopper-test.adyen.com www.w3.org s.acquire.io admin.expivi.net d33o7r96pw821t.cloudfront.net *.clarity.ms analytics.sleeknote.com *.commerce-connector.com staging-lecot.vaimo.net *.cookiebot.com *.facebook.com *.bing.com *.google.com.ua *.lecot.be data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com checkoutshopper-live.adyen.com/ pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com js.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com ajax.googleapis.com r1-t.trackedlink.net js-agent.newrelic.com admin.expivi.net consent.cookiebot.com security-hub.vaimo.network static.hotjar.com rum-static.pingdom.net script.hotjar.com consentcdn.cookiebot.com bam-cell.nr-data.net s.acquire.io sleeknote.com sleeknotestaticcontent.sleeknote.com sleeknotecustomerscripts.sleeknote.com connect.facebook.net *.lecot.be *.clarity.ms https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com script.hotjar.com https://js.klevu.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com data: sleeknote.com sleeknotestaticcontent.sleeknote.com lecot.be 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com *.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com bam-cell.nr-data.net eucs23.ksearchnet.com stats.klevu.com app.acquire.io www.expivi.net security-hub.vaimo.network static.hotjar.com rum-static.pingdom.net script.hotjar.com rum-collector-2.pingdom.net in.hotjar.com stats.g.doubleclick.net consentcdn.cookiebot.com *.facebook.com s.acquire.io sleeknote.com sleeknotestaticcontent.sleeknote.com googleads.g.doubleclick.net *.cloudfront.net *.expivi.net wss://s.acquire.io *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com *.fontawesome.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.certcapture.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * calendly.com *.google.com *.cappasity.com www.facebook.com https://api.intellimize.co https://117202619.intellimizeio.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.webdamdb.com *.rectorseal.com rectorseal.com *.img-us3.com *.amazon.com *.amazonaws.com *.cloudfront.net *.linkedin.com *.google.com *.adsymptotic.com 'self' data: *.cappasity.com www.facebook.com *.hubspot.com *.hsforms.com maps.gstatic.com maps.googleapis.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com landofcoder.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.calendly.com *.cloudfront.net *.licdn.com *.googletagmanager.com connect.facebook.net *.fullstory.com js-na1.hs-scripts.com js.hs-banner.com js.hsadspixel.net js.hs-analytics.net static.oktopost.com oktopost.rectorseal.com polyfill-fastly.io js.hubspot.com *.hsforms.com *.hsforms.net 'unsafe-eval' https://*.intellimize.co maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.typekit.net 'unsafe-inline' tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io cdn.ampproject.org *.googleapis.com *.certcapture.com landofcoder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.hubapi.com *.doubleclick.net *.fullstory.com *.google-analytics.com px.ads.linkedin.com *.hubspot.com *.hsforms.com *.hsforms.net https://api.intellimize.co https://log.intellimize.co maps.googleapis.com *.facebook.net 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net 'self' data: *.google.com *.google.co.in https://fonts.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.chimpstatic.com *.googleadwordswidget.com *.nr-data.net *.newrelic.com *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.cloudfront.net www.youtube-nocookie.com *.google.com *.cloudflare.com *.chimpstatic.com *.googleadwordswidget.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube-nocookie.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.weltpixel.com *.cloudfront.net https://www.google.com https://www.google.co.in *.cloudflare.com *.trustpilot.com *.flashingblinkylights.com *.fullstory.com *.googleadwordswidget.com *.nr-data.net *.newrelic.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.youtube-nocookie.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.cloudfront.net *.google.com *.google.co.in *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.magentocommerce.com *.flashingblinkylights.com *.herokuapp.com *.cloudflare.com *.doubleclick.net *.chimpstatic.com *.fullstory.com *.googleadwordswidget.com *.nr-data.net *.newrelic.com https://meetanshi.com/media/logo.png blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube-nocookie.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudfront.net *.paypal.com *.google.co.in *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.paypalobjects.com *.fullstory.com fullstory.com *.trustpilot.com *.springbot.com *.gstatic.com *.chimpstatic.com *.cloudflare.com *.hellobar.com chimpstatic.com *.googleadwordswidget.com *.googleapis.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com guarantee-cdn.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.cloudfront.net *.paypal.com www.youtube-nocookie.com *.googleapis.com *.google.com *.google.co.in *.cloudflare.com *.bootstrapcdn.com *.flashingblinkylights.com *.fullstory.com *.googleadwordswidget.com *.nr-data.net *.newrelic.com *.fontawesome.com *.gstatic.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com assets.braintreegateway.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudfront.net www.youtube-nocookie.com *.google.co.in *.fullstory.com *.cloudflare.com *.flashingblinkylights.com *.chimpstatic.com *.googleadwordswidget.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.mmapiws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /api/v1/csp-report; connect-src 'self' https://*.google-analytics.com https://*.googleapis.com https://www.googletagmanager.com https://www.facebook.com https://analytics.tiktok.com https://api.maptiler.com https://api.typeform.com https://*.consentmanager.net https://*.pinterest.com; default-src 'self'; script-src 'self' 'unsafe-inline' https://*.google-analytics.com https://*.consentmanager.net https://www.googletagmanager.com https://analytics.tiktok.com https://s.pinimg.com https://embed.typeform.com https://www.gstatic.com https://connect.facebook.net https://cdn.jsdelivr.net https://ct.pinterest.com https://*.googleapis.com https://*.google.com https://*.trustpilot.com; style-src 'self' 'unsafe-inline' https://embed.typeform.com https://fonts.googleapis.com https://www.gstatic.com https://*.consentmanager.net; font-src 'self' https://fonts.gstatic.com; img-src data: 'self' https://*.consentmanager.net https://www.googletagmanager.com https://www.facebook.com https://*.google.com https://*.openstreetmap.org https://*.gstatic.com https://i.ytimg.com; frame-src https://www.youtube-nocookie.com https://ct.pinterest.com https://form.typeform.com https://widget.trustpilot.com https://www.facebook.com; media-src 'self' blob:; worker-src 'self' blob:; 1 default-src 'self' hairboutique.com *.hairboutique.com *.cloudfront.net *.tribalfusion.com *.exponential.com *.googletagmanager.com *.googleapis.com g.adspeed.net pagead2.googlesyndication.com googleads.g.doubleclick.net tpc.googlesyndication.com www.google.com; img-src *; frame-ancestors 'self'; object-src *; report-uri report_uri.php; script-src * 'unsafe-inline' 'unsafe-eval'; font-src 'unsafe-inline' kit.fontawesome.com * data; style-src 'unsafe-inline' hairboutique.com *.hairboutique.com;script-src-elem 'unsafe-inline' hairboutique.com *.hairboutique.com *.googlesyndication.com securepubads.g.doubleclick.net kit.fontawesome.com pagead2.googlesyndication.com adservice.google.com partner.googleadservices.com d31qbv1cthcecs.cloudfront.net www.googletagmanager.com www.google-analytics.com tpc.googlesyndication.com;connect-src 'self' 'unsafe-inline' *.hairboutique.com www.google-analytics.com pagead2.googlesyndication.com tpc.googlesyndication.com; 1 script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' * data: blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * api.bazaarvoice.com stg.api.bazaarvoice.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.awin1.com *.zenaps.com *.fls.doubleclick.net display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.trustpilot.com landofcoder.com https://pay.google.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.facebook.com https://lantern.roeyecdn.com https://lantern.roeye.com https://network-eu-stg-a.bazaarvoice.com https://apps.bazaarvoice.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page *.googleapis.com *.gstatic.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.trustpilot.com landofcoder.com https://api.bluecore.com https://connect.facebook.net https://siteassets.bluecore.com https://www.facebook.com https://lantern.roeyecdn.com https://apps.bazaarvoice.com *.bazaarvoice.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval' * data: blob: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app display.ugc.bazaarvoice.com *.fontawesome.com https://static.klaviyo.com *.trustpilot.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com * *.googleapis.com *.ipinfo.io *.wepowerconnections.com https://the.sciencebehindecommerce.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com https://siteassets.bluecore.com https://onsitestats.bluecore.com https://pay.google.com https://google.com/pay 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-pNmxuTVRQdDJ6bu0HXn8pw=='; style-src 'self' https://square-fonts-production-f.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.klaviyo.com *.googletagmanager.com *.google.com.ua maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io *.bing.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com cdn.naturamarket.ca *.pingdom.net *.google.com *.googletagmanager.com *.google.com.ua https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com *.pingdom.net *.klaviyo.com *.pinimg.com *.mczbf.com *.hotjar.com *.pinterest.com *.googleapis.com *.addthis.com *.googletagmanager.com *.google.com.ua https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com business.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klaviyo.com *.googletagmanager.com *.google.com.ua https://static.klaviyo.com assets.braintreegateway.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com cdn.naturamarket.ca *.pingdom.net *.googletagmanager.com *.google.com.ua 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.pingdom.net *.klaviyo.com *.doubleclick.net *.pinterest.com *.googleapis.com *.hotjar.io *.googletagmanager.com *.google.com.ua https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com business.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com checkout.getbread.com *.paypal.com *.google-analytics.com *.mmapiws.com *.doubleclick.net *.searchspring.io *.turnto.com bat.bing.com datalayer.jumpfly.com *.mouseflow.com *.nr-data.net *.newrelic.com *.google.com *.clarity.ms analytics.google.com tgscript.s3.amazonaws.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com js.klevu.com data: *.shopperapproved.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.iadvize.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.shopperapproved.com *.authorize.net *.twitter.com *.facebook.com connect.facebook.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net *.liveperson.net checkout.getbread.com *.doubleclick.net *.lpsnmedia.net *.google.com *.googletagmanager.com *.facebook.com platform.twitter.com td.doubleclick.net *.twitter.com *.google.co.in www.xtento.com photos.pixlee.co *.weltpixel.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.paypalobjects.com airtable.com *.lightingwarehouse.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io widgets.automizely.com widgets.automizely.io https://www.shopperapproved.com *.trackedlink.net *.klevu.com *.ksearchnet.com https://maps.gstatic.com https://maps.googleapis.com *.ftcdn.net *.behance.net https://images.unsplash.com *.googleadservices.com blob: https://meetanshi.com/media/logo.png *.cloudflare.com *.gstatic.com *.google.com *.google.co.in *.facebook.com *.klarna.com *.google-analytics.com *.paypal.com * *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net stats.g.doubleclick.net d.adroll.com pixel.advertising.com pixel.rubiconproject.com simage2.pubmatic.com dsum-sec.casalemedia.com ads.yahoo.com eb2.3lift.com sync.outbrain.com trc.taboola.com x.bidswitch.net/sync ib.adnxs.com idsync.rlcdn.com us-u.openx.net ups.analytics.yahoo.com segments.company-target.com sync.tidaltv.com *.trustgaurd.com content.sprinklerwarehouse.com bat.bing.com www.xtento.com cdn.xtento.com wac.edgecastcdn.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io https://www.shopperapproved.com https://direct.shopperapproved.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/ *.authorize.net *.liveperson.net *.lpsnmedia.net cdn.searchspring.net checkout.getbread.com *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.google.com www.gstatic.com bat.bing.com *.mouseflow.com services.nofraud.com *.doubleclick.net widgets.turnto.com js.klevu.com stats.g.doubleclick.net static.trackedweb.net tgscript.s3.amazonaws.com *.clarity.ms platform.twitter.com connect.facebook.net cdn-ws.turnto.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.paypalobjects.com *.paypal.com chimpstatic.com s.adroll.com d.adroll.com d.adroll.mgr.consensu.org *.bootstrapcdn.com player.vimeo.com content.sprinklerwarehouse.com www.xtento.com cdn.xtento.com *.turnto.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com googletagmanager.com *.lightingwarehouse.com code.jquery.com *.sprinklerwarehouse.com *.vimeo.com *.shopperapproved.com *.breadpayments.com *.gstatic.com accdn.lpsnmedia.net lpcdn.lpsnmedia.net static.elfsight.com halc.iadvize.com cdn.brcdn.com *.iadvize.com elfsightcdn.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com cdn.searchspring.net widgets.turnto.com js.klevu.com tgscript.s3.amazonaws.com *.bootstrapcdn.com *.turnto.com tagmanager.google.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com cdn.dnky.co *.yotpo.complete content.sprinklerwarehouse.com *.lightingwarehouse.com *.nr-data.net *.iadvize.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.lpsnmedia.net data: *.trustguard.com content.sprinklerwarehouse.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.automizely.com api.automizely.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com https://maps.googleapis.com *.authorize.net *.lpsnmedia.net data: *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.google.co.in *.facebook.com checkout.getbread.com *.mmapiws.com *.doubleclick.net *.searchspring.io *.turnto.com bat.bing.com datalayer.jumpfly.com *.mouseflow.com *.clarity.ms tgscript.s3.amazonaws.com content.sprinklerwarehouse.com *.facebook.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.lightingwarehouse.com adservice.google.com fonts.googleapis.com core.service.elfsight.com maps.googleapis.com *.fontawesome.com halc.iadvize.com api.iadvize.com cdn.brcdn.com services.nofraud.com learn.sprinklerwarehouse.com p.brsrvr.com *.iadvize.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src checkout.getbread.com *.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: *.gstatic.com oct8necdneu.azureedge.net *.klarnacdn.net *.hspvst.com *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.hspvst.com 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com *.hspvst.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.langshop.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.vimeo.com *.oct8ne.com *.cookiebot.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.hspvst.com *.doubleclick.net www.xtento.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://images.unsplash.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.ggpht *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.tapad.com *.rlcdn.com *.reson8.com *.cookiebot.com *.rawgit.com *.jsdelivr.net *.hspvst.com hspvst.com *.w55c.net w55c.net hotjar.com *.hotjar.com *.arkeero.net *.kelkoogroup.net *.mailchimp.com adroll.com *.adroll.com *.mmgo.io awin.com motionmailapp.com google.pt *.google.pt *.bidswitch.net *.outbrain.com *.openx.net *.rubiconproject.com *.pubmatic.com *.yahoo.com *.taboola.com *.adnxs.com *.3lift.com *.casalemedia.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.adyen.com *.klarna.com *.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adsmurai.com *.criteo.com *.hspvst.com hspvst.com *.w55c.net w55c.net hotjar.com *.hotjar.com *.arkeero.net *.kelkoogroup.net *.mailchimp.com *.amazonaws.com adroll.com *.adroll.com *.mmgo.io awin.com motionmailapp.com *.kk-resources.com *.googlesyndication.com www.xtento.com cdn.xtento.com *.stripe.com klarna.com *.klarnaevt.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com *.klarnacdn.net unsafe-inline assets.braintreegateway.com *.googletagmanager.com *.hspvst.com hspvst.com *.w55c.net w55c.net *.arkeero.net *.kelkoogroup.net *.mailchimp.com adroll.com *.adroll.com *.mmgo.io awin.com motionmailapp.com 'self' 'unsafe-inline'; object-src *.hspvst.com 'self' 'unsafe-inline'; media-src *.adobe.com *.hspvst.com 'self' 'unsafe-inline'; manifest-src *.hspvst.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.adyen.com *.googleapis.com *.cookiebot.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.hspvst.com *.adroll.com *.adsmurai.com *.googlesyndication.com *.stripe.com klarna.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.hspvst.com http: https: blob: 'self' 'unsafe-inline'; default-src *.hspvst.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.hspvst.com 'self' 'unsafe-inline'; 1 base-uri 'self'; child-src 'self'; connect-src 'self' sicoob.com.br *.sicoob.com.br google.com *.google.com google-analytics.com *.google-analytics.com googleadservices.com *.googleadservices.com clarity.ms *.clarity.ms; default-src 'self' sicoob.com.br *.sicoob.com.br; font-src 'self'; frame-src 'self'; media-src 'self'; script-src 'self' sicoob.com.br *.sicoob.com.br google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com gstatic.com *.gstatic.com google.com *.google.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=1RMfiNGTRCcHYAE5tDwQPJct3FD8RQK2vCfH_0RFVkw-1765946864-1.0.1.1-rRlnOjr.gRVtQyhGani6rlW0sQ53n2sELjRl5aNBn1WNYiocTw.K79ceQa12fy2wx30cze93FuqOrTDdG5UCCLwVoH1wWNMfp22wMtvSroq3z2x_8pJXF_2WDn6w4Jct5pK2RZaZJw2bW2phd2XkiM_tnylkSO7VQ9QzUZgT1qFFAkedBEIhJ.3Y4rBFxA3fKx9ZKSUiDYjqND_SZGPmyg; report-to cf-uqgogkgefxvcjtah 1 img-src *.force.com slack-imgs-mil-dev.com 'self' https://stats.g.doubleclick.net https://gmibboxtopstrial2020.file.force.com https://img.youtube.com https://payments.salesforce.com/icons/ https://cdn.cookielaw.org https://login.salesforce.com/icons/ https://www.gstatic.com *.slack-edge-gov.com https://contactus.boxtops4education.com *.my-salesforce.com *.cloudinary.com https://www.google.com https://analytics.google.com https://generalmills.us-4.evergage.com *.amazonaws.com https://preferences-mgr.trustarc.com blob: slack-imgs.com https://cdnjs.cloudflare.com slack-gov-dev.com *.sfdcstatic.com *.twimg.com https://preferences.trustarc.com https://securepubads.g.doubleclick.net https://pagead2.googlesyndication.com *.slack.com https://www.paypal.com *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://gmibboxtopstrial2020--devsfec.sandbox.my.site.com *.salesforce-experience.com https://na248.salesforce.com/icons/ https://*.cloudfunctions.net slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://devsfec-genmills.cs217.force.com https://www.gstatic.com/recaptcha/ https://geolocation.onetrust.com https://csi.gstatic.com https://www.google.co.in https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://i.vimeocdn.com https://privacyportal.onetrust.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://*.adyen.com slack-imgs.mil https://gmibboxtopstrial2020.my.salesforce.com data:; report-to sfdc-csp-ep; report-uri https://gmibboxtopstrial2020.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D5Y0000024od9&networkId=0DM5Y000000OLrC&type=communities 1 object-src 'none'; script-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://static.addtoany.com https://unpkg.com https://www.google.com https://www.recaptcha.net; script-src-elem * 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem * 'unsafe-inline'; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src https: 'unsafe-inline' 'unsafe-eval' data: about: blob: wss://*.tawk.to; report-uri /_resources/php/csp-report.php 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com checkout-static-next.razorpay.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com td.doubleclick.net www.paypalobjects.com api.razorpay.com *.payglocal.com *.payglocal.in *.pinterest.com *.google.com *.addthis.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://images.unsplash.com www.facebook.com www.google.co.in cdn.razorpay.com *.adobedtm.com *.facebook.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://maps.googleapis.com static.cloudflareinsights.com ajax.cloudflare.com connect.facebook.net *.doubleclick.net *.google.co.in checkout-static-next.razorpay.com codedrop.uat.payglocal.in checkout.razorpay.com www.xtento.com *.pinterest.com *.pinimg.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.facebook.net www.termsfeed.com *.addthis.com *.moatads.com *.addthisedge.com *.avada.io *.uat.payglocal.in/simple.js cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com www.google.com *.google-analytics.com *.doubleclick.net *.razorpay.com *.payglocal.com *.payglocal.in *.pinterest.com *.facebook.com *.googleadservices.com *.googletagmanager.com *.addthis.com https://get.geojs.io *.avada.io lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com www.paypal.com *.payglocal.com *.payglocal.in checkout-static-next.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com c.statcounter.com googleads.g.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com www.statcounter.com embed.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com www.gstatic.com embed.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org www.googleapis.com www.statcounter.com c.statcounter.com embed.tawk.to www.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' blob: data: https://ad.doubleclick.net https://ade.googlesyndication.com https://bat.bing.com https://cdn.cookielaw.org https://connect.facebook.net https://fonts.gstatic.com https://googleads.g.doubleclick.net https://i.ytimg.com https://lhr1.qualtrics.com https://maps.googleapis.com https://maps.gstatic.com https://pagead2.googlesyndication.com https://pubads.g.doubleclick.net https://px.ads.linkedin.com https://px4.ads.linkedin.com https://s3.amazonaws.com https://siteintercept.qualtrics.com https://stats.g.doubleclick.net https://storage.googleapis.com https://translate.google.com https://wpm.ccmp.eu https://www.facebook.com https://www.google.ae https://www.google.at https://www.google.be https://www.google.bg https://www.google.ca https://www.google.ch https://www.google.co.id https://www.google.co.in https://www.google.co.ke https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.za https://www.google.co.zw https://www.google.com https://www.google.com.au https://www.google.com.bd https://www.google.com.br https://www.google.com.cy https://www.google.com.gi https://www.google.com.hk https://www.google.com.mt https://www.google.com.my https://www.google.com.ng https://www.google.com.np https://www.google.com.ph https://www.google.com.pk https://www.google.com.qa https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.vn https://www.google.de https://www.google.dk https://www.google.es https://www.google.fr https://www.google.gg https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.im https://www.google.it https://www.google.je https://www.google.kz https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.se https://www.googleadservices.com https://www.googletagmanager.com https://www.linkedin.com; script-src-elem 'self' 'unsafe-inline' blob: https://app.optimizely.com https://bat.bing.com https://cdn.cookielaw.org https://cdn.gbqofs.com https://cdn.jsdelivr.net https://cdn.optimizely.com https://cdn3.optimizely.com https://cdnjs.cloudflare.com https://connect.facebook.net https://ff.kis.v2.scr.kaspersky-labs.com https://gc.kis.v2.scr.kaspersky-labs.com https://js.monitor.azure.com https://maps.googleapis.com https://me.kis.v2.scr.kaspersky-labs.com https://sc-static.net https://script.infinity-tracking.com https://siteintercept.qualtrics.com https://snap.licdn.com https://unpkg.com https://web-sdk-eu.aptrinsic.com https://widget.trustpilot.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://zn7umza3pq82vcil4-nfumutual.siteintercept.qualtrics.com; worker-src 'self' blob:; script-src-attr 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://bat.bing.com https://cdn.cookielaw.org https://cdn.gbqofs.com https://cdn.jsdelivr.net https://cdn.optimizely.com https://cdnjs.cloudflare.com https://connect.facebook.net https://js.monitor.azure.com https://maps.googleapis.com https://rialto-gms.s3.amazonaws.com https://script.infinity-tracking.com https://siteintercept.qualtrics.com https://snap.licdn.com https://widget.trustpilot.com https://www.clickcease.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://zn7umza3pq82vcil4-nfumutual.siteintercept.qualtrics.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://ff.kis.v2.scr.kaspersky-labs.com https://fonts.googleapis.com https://gc.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com; style-src 'self' 'unsafe-inline'; connect-src 'self' data: wss: https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://bat.bing.com https://bat.bing.net https://c1001.report.gbss.io https://cdn.cookielaw.org https://esp-eu.aptrinsic.com https://fonts.googleapis.com https://fonts.gstatic.com https://fts.lon.infinity-tracking.com https://geolocation.onetrust.com https://ict.infinity-tracking.net https://logx.optimizely.com https://maps.googleapis.com https://maps.gstatic.com https://monitor.clickcease.com https://nas.lon.infinity-tracking.com https://pagead2.googlesyndication.com https://privacyportal-eu.onetrust.com https://px.ads.linkedin.com https://region1.analytics.google.com https://region1.google-analytics.com https://rum.optimizely.com https://s.qualtrics.com https://siteintercept.qualtrics.com https://stats.g.doubleclick.net https://tapi.optimizely.com https://translate-pa.googleapis.com https://translate.googleapis.com https://web.lon.infinity-tracking.com https://www.facebook.com https://www.google-analytics.com https://www.google.ch https://www.google.co.in https://www.google.co.nz https://www.google.co.uk https://www.google.com https://www.google.com.bd https://www.google.com.co https://www.google.com.hk https://www.google.com.ng https://www.google.com.ph https://www.google.com.sg https://www.google.de https://www.google.es https://www.google.fr https://www.google.gg https://www.google.ie https://www.google.im https://www.google.je https://www.google.nl https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.se https://www.googleadservices.com https://www.googletagmanager.com; frame-src 'self' http://13822689.fls.doubleclick.net.x.7fb9ff97023e304fe5089b604f226d2e776e.d0452329.id.opendns.com http://8047475.fls.doubleclick.net.x.6c605f67053a9048aa09deb0691692c92a11.d0452329.id.opendns.com http://td.doubleclick.net.x.a59ad4430722e043e60b0370fb79dd7e0a94.d045227d.id.opendns.com https://11385707.fls.doubleclick.net https://13822689.fls.doubleclick.net https://8047475.fls.doubleclick.net https://a22654210373.cdn.optimizely.com https://login.microsoftonline.com https://nfumutual.qualtrics.com https://td.doubleclick.net https://toolkit.financialexpress.net https://widget.trustpilot.com https://www.google.com https://www.googletagmanager.com https://www.recaptcha.net https://www.youtube.com; font-src 'self' data: https://app.optimizely.com https://dhm5hy2vn8l0l.cloudfront.net https://fonts.gstatic.com https://pouch-global-font-assets.s3.eu-central-1.amazonaws.com https://use.fontawesome.com https://use.typekit.net; media-src 'self' data:; default-src 'self' https: wss:; base-uri 'self'; child-src 'self'; form-action 'self' https://nfumutual.qualtrics.com; frame-ancestors 'self'; manifest-src 'self' https://www.nfumutual.co.uk; object-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.sagepay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sagepay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com flagpedia.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.sagepay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.sagepay.com www.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' http://*.hs-scripts.com https://*.googletagmanager.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hubspot.com https://*.springernature.com https://*.user.com; script-src-attr 'unsafe-hashes' 'sha256-bwK6T5wZVTANitXbrTsel7kl/PyCjCd/Dq5Qoz3imjM='; style-src 'self' 'unsafe-inline' https://*.typekit.net; img-src 'self' data: https:; connect-src 'self' https://*.hubspot.com https://*.user.com https://*.googletagmanager.com https://*.google-analytics.com wss://macmillan-english.user.com; font-src 'self' data: https://*.typekit.net; frame-src https://*.buzzsprout.com https://*.youtube-nocookie.com; frame-ancestors 'none'; report-to csp-report; report-uri /csp-report 1 font-src pro.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.doubleclick.net *.iubenda.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com empressmills-uat.preview3.co.uk *.empressmills.co.uk www.google.co.uk *.google-analytics.com *.googletagmanager.com *.iubenda.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.gstatic.com *.googletagmanager.com *.hotjar.com *.iubenda.com empressmills-uat.preview3.co.uk *.empressmills.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com empressmills-uat.preview3.co.uk *.empressmills.co.uk pro.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ form-assets.mailchimp.com *.intuit.com *.amazonaws.com googleads.g.doubleclick.net www.google.co.uk *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.hotjar.com wss://*.hotjar.com *.hotjar.io *.iubenda.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-g1DV2w-Y71PZRyVLhWCLaQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.addthis.com js.mollie.com *.crazyegg.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com maps.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com cdn.doofinder.com magefan.com cm.magefan.com *.disqus.com * *.sooqr.com *.spotlersearch.com flagpedia.net https://www.mollie.com ts.tradetracker.net www.magmodules.eu https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.crazyegg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io cdn.doofinder.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com * *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.mollie.com tm.tradetracker.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.crazyegg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.doofinder.com https://fonts.googleapis.com https://cdn.jsdelivr.net *.fontawesome.com *.sooqr.com *.spotlersearch.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.crazyegg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com chat.askly.me 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.doofinder.com wss://*.doofinder.com *.sooqr.com *.spotlersearch.com www.gstatic.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.amazonaws.com chat.askly.me https://sessions.chat.askly.me wss://sessions.chat.askly.me/ *.crazyegg.com https://integrations.etrusted.com/ *.hotjar.io/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.crazyegg.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://chat.askly.me/widget/ 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https:; img-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self'; report-to wizard 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.lndo.site *.weprovide.shop script.hotjar.com unpkg.com use.typekit.net *.triggerbee.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io landofcoder.com maps.googleapis.com chart.googleapis.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.lndo.site *.weprovide.shop dtm.cando.eu vars.hotjar.com ct.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com 'self' data: www.google.nl *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com cdn.flbx.io *.cloudfront.net 'self' blob: data http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.lndo.site *.weprovide.shop maps.google.com maps.googleapis.com mailing.deli-home.nl *.clarity.ms *.omappapi.com ct.pinterest.com cdn.cookielaw.org *.cando.eu skantrae.com *.weekampdeuren.nl dev.visualwebsiteoptimizer.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.getflowbox.com landofcoder.com maps.googleapis.com chart.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.lndo.site *.weprovide.shop cdnjs.cloudflare.com code.jquery.com optanon.blob.core.windows.net geolocation.onetrust.com *.omappapi.com bam.nr-data.net cdn.cookielaw.org js-agent.newrelic.com s.pinimg.com *.hotjar.com *.clarity.ms cdn.leadinfo.net ct.pinterest.com dev.visualwebsiteoptimizer.com *.triggerbee.com *.myvisitors.se 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.trustpilot.com *.lndo.site *.weprovide.shop optanon.blob.core.windows.net a.omappapi.com cdn.cookielaw.org p.typekit.net skantrae.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.getflowbox.com *.googleapis.com landofcoder.com maps.googleapis.com chart.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.lndo.site *.weprovide.shop *.cando.eu bam.nr-data.net *.clarity.ms *.omappapi.com ct.pinterest.com sp.spheremall.com *.hotjar.com *.hotjar.io wss://*.hotjar.com cdn.cookielaw.org geolocation.onetrust.com dev.visualwebsiteoptimizer.com *.triggerbee.com gethatch.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.hotjar.com *.typekit.net *.sagepay.com *.globalpay.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hotjar.com *.facebook.net *.facebook.com *.nosto.com *.nos.to *.sagepay.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com/ *.hotjar.com *.youtube.com *.addthis.com *.trustpilot.com *.facebook.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com *.nosto.com *.nos.to cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.sagepay.com account.fetchify.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.bing.com *.google.com *.google.co.uk *.cutwel.co.uk https://images.unsplash.com *.trackedlink.net *.nosto.com *.nos.to *.paypal.com *.sagepay.com ebizmarts-website.s3.amazonaws.com *.globalpay.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.gstatic.com *.googletagmanager.com *.hotjar.com *.zdassets.com *.trackedlink.net *.addthis.com *.trustpilot.com *.moatads.com *.addthisedge.com *.googleadservices.com *.doubleclick.net *.tctm.co *.bing.com *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.dynamicnumbers.mediahawk.co.uk *.nosto.com *.nos.to cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.sagepay.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.myfonts.net *.typekit.net *.googleapis.com *.nosto.com *.nos.to cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.sagepay.com cc-cdn.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hotjar.com *.hotjar.io *.zdassets.com *.zopim.com *.doubleclick.net *.google-analytics.com *.tctm.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com dn.mediahawk.co.uk *.nosto.com *.nos.to webchat.dotdigital.com webchat.staging.dotdigital.com *.paypal.com *.sagepay.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://127a7be8-dabe-43cf-ac5b-05045433d417.sansec.watch/; report-to report-endpoint; 1 script-src-elem *.cfjump.com *.popupsmart.com embedsocial.com *.preezie.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com; font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com *.gstatic.com data: 'self' 'unsafe-inline' 'unsafe-eval'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com t.zip.co static.zipmoney.com.au static.zip.co *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com *.riskified.com *.bing.com *.legitscript.com data: 'self' 'unsafe-inline' 'unsafe-eval'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.zipmoney.com.au static.zip.co zip.co *.cfjump.com *.popupsmart.com embedsocial.com *.preezie.com *.bazaarvoice.com https://apps.bazaarvoice.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net static.afterpay.com/ *.squarecdn.com *.cash.app display.ugc.bazaarvoice.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com embedsocial.com *.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network-stg.bazaarvoice.com network.bazaarvoice.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.popupsmart.com *.bazaarvoice.com *.demdex.net *.riskified.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-336e6c33-948e-4730-ab5c-8e527a9052d7' https: data: https://js.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://siteintercept.qualtrics.com https://browser.sentry-cdn.com https://*.siteintercept.qualtrics.com https://www.googletagmanager.com https://js.monitor.azure.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://cdn.jsdelivr.net https://more.suse.com; img-src 'self' https: data: https://fast.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://fast.wistia.net https://fast.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com; connect-src 'self' https: wss: https://cdn.cookielaw.org https://distillery.wistia.com https://siteintercept.qualtrics.com https://dc.services.visualstudio.com https://fast.wistia.com https://fast.wistia.net https://pipedream.wistia.com wss://ws.qualified.com https://embed-ssl.wistia.com https://apple.dxcloud.episerver.net https://cdn.jsdelivr.net https://js.monitor.azure.com wss://ws.qualified.com; font-src 'self' https: data: https://fonts.gstatic.com https://fast.wistia.net; object-src 'none' ; media-src 'self' https: blob: ; frame-src 'self' https: ; form-action 'self' https://suselinux.fra1.qualtrics.com; frame-ancestors 'self' ; base-uri 'none' ; report-uri https://www.suse.com/api/reporting/; report-to csp-endpoint; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com cdn.knightlab.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com stats.g.doubleclick.net www.gstatic.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.fbcdn.net scontent.cdninstagram.com *.ytimg.com *.feedaty.com *.iubenda.com magefan.com cm.magefan.com *.facebook.com https://firebasestorage.googleapis.com * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com player.vimeo.com/api/player.js www.vimeo.com *.vimeocdn.com *.youtube.com/iframe_api https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.google.com/recaptcha *.googletagmanager.com *.google-analytics.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.youtube.com *.feedaty.com *.iubenda.com s7.addthis.com *.facebook.net *.avada.io * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.knightlab.com *.gstatic.com *.googleapis.com *.google.com *.kxcdn.com *.feedaty.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com googleads.g.doubleclick.net www.facebook.com/ https://*.clarity.ms https://*.doubleclick.net https://*.googlesyndication.com https://idb.iubenda.com/csdata *.feedaty.com *.iubenda.com ekr.zdassets.com/ *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.youtube.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.sharethis.com *.certcapture.com *.userway.org www.google.com www.google.fr googleads.g.doubleclick.net *.join-stories.com *.stories.studio https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://meetanshi.com/media/logo.png www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.adobedtm.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com *.certcapture.com *.userway.org *.queue-it.net queue.musart.com www.facebook.com js-agent.newrelic.com *.axept.io *.join-stories.com *.stories.studio https://maps.googleapis.com/maps/api/mapsjs https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.youtube.com player.vimeo.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.fontawesome.com *.certcapture.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com video-previews.elements.envatousercontent.com *.join-stories.com *.stories.studio *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.certcapture.com *.userway.org *.google-analytics.com *.axept.io bam.nr-data.net *.join-stories.com *.stories.studio https://maps.googleapis.com/maps/api/mapsjs https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdn.plyr.io noembed.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com 'self' data: *.bootstrapcdn.com *.doubleclick.net *.nr-data.net *.bobcatparts.com *.fontawesome.com *.googleadservices.com *.google.com *.facebook.net *.facebook.com *.paypal.com *.paypalobjects.com *.google.com.ua data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net *.braintree-api.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com/ *.google-analytics.com *.affirm.com *.newrelic.com *.nr-data.net *.fontawesome.com *.googleadservices.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.com.ua *.braintree-api.com *.authorize.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.certcapture.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.magentocommerce.com data: *.google.com *.doubleclick.net *.googleapis.com *.newrelic.com *.nr-data.net *.fontawesome.com *.googleadservices.com *.google-analytics.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.com.ua *.klaviyo.com *.google.com *.google.nl *.kickfire.com *.121getsitdone.com *.firespring.com magefan.com cm.magefan.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com/ *.google.com.ua *.google-analytics.com *.affirm.com *.gstatic.com *.googleapis.com *.fontawesome.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.facebook.com *.paypalobjects.com *.braintree-api.com *.amazonaws.com *.livechatinc.com *.multiview.com *.kickfire.com *.simpli.fi *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.certcapture.com assets.braintreegateway.com *.bootstrapcdn.com *.google.com.ua *.newrelic.com *.nr-data.net *.fontawesome.com *.googleadservices.com *.facebook.net *.facebook.com *.paypal.com *.paypalobjects.com *.googletagmanager.com *.datatables.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.affirm.com *.fontawesome.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.com.ua *.googleapis.com *.authorize.net 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: blob:; object-src 'none'; script-src 'self' 'nonce-'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https: *.bugsnag.com; report-uri /csp-violation-report-endpoint 1 font-src fonts.gstatic.com *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net fonts.cdnfonts.com use.typekit.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube-nocookie.com *.youtube.com *.braintreegateway.com player.vimeo.com pilot-payflowlink.paypal.com *.googletagmanager.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com https://www.google.com/recaptcha/ *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src *.googleapis.com *.gstatic.com stats.g.doubleclick.net www.google.com www.facebook.com www.googletagmanager.com *.adobe.com googleads.g.doubleclick.net analytics.google.com *.vimeocdn.com *.youtube.com maps.googleapis.com *.yandex.ru *.roma.rs assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com bid.g.doubleclick.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com i.ytimg.com p.typekit.net *.paypal.com *.typekit.net validator.swagger.io https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com connect.facebook.net googleads.g.doubleclick.net stats.g.doubleclick.net *.yandex.com *.roma.rs assets.adobedtm.com *.adobe.com www.googleadservices.com *.vimeocdn.com *.clarity.ms *.youtube.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net fonts.cdnfonts.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.avada.io dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com https://get.geojs.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.hivissupply.com *.google.com *.fontawesome.com *.yotpo.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.facebook.net *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.crazyegg.com *.facebook.com *.listrakbi.com *.wufoo.com *.delighted.com *.sharethis.com *.livechatinc.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.wufoo.com *.delighted.com *.sharethis.com *.livechatinc.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.certcapture.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.hivissupply.com *.livechatinc.com *.yotpo.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.crazyegg.com *.facebook.com *.listrakbi.com *.wufoo.com *.delighted.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.hivissupply.com *.yotpo.com *.livechatinc.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.google.com *.crazyegg.com *.facebook.com *.listrakbi.com *.cloudfront.net *.wufoo.com *.delighted.com *.sharethis.mgr.consensu.org www.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com a.ads.rmbl.ws www.redditstatic.com pixel-config.reddit.com alb.reddit.com guarantee-cdn.com *.reddit.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.hivissupply.com *.fontawesome.com *.googleapis.com *.cloudflare.com *.cloudfront.net *.livechatinc.com *.listrakbi.com *.gstatic.com *.yotpo.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.crazyegg.com *.facebook.com *.wufoo.com *.delighted.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com a.ads.rmbl.ws www.redditstatic.com pixel-config.reddit.com alb.reddit.com guarantee-cdn.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.certcapture.com https://static.klaviyo.com assets.braintreegateway.com *.hivissupply.com *.fontawesome.com *.googleapis.com *.google.com *.cloudflare.com *.cloudfront.net *.livechatinc.com *.listrakbi.com *.paypal.com *.yotpo.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.facebook.net *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.crazyegg.com *.facebook.com *.wufoo.com *.delighted.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com *.tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.hivissupply.com *.yotpo.com *.livechatinc.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.facebook.net *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.google.com *.crazyegg.com *.facebook.com *.listrakbi.com *.wufoo.com *.delighted.com *.sharethis.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.hivissupply.com *.yotpo.com *.arqspin.com *.klaviyo.com *.googletagmanager.com *.bing.com *.crazyegg.net *.doubleclick.net *.googleadservices.com *.google-analytics.com *.crazyegg.com *.facebook.com *.listrakbi.com *.wufoo.com *.delighted.com *.livechatinc.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com a.ads.rmbl.ws www.redditstatic.com pixel-config.reddit.com alb.reddit.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com *.delighted.com *.sharethis.com *.livechatinc.com *.redploy.com *.sharethis.mgr.consensu.org *.xtento.com *.kaltura.com *.clarity.ms *.licdn.com *.linkedin.com *.adsymptotic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://www.tv5unis.ca/csp-report;default-src 'self' *.googlesyndication.com ;script-src 'self' 'unsafe-eval' 'unsafe-inline' *.2mdn.net *.amazon-adsystem.com *.adsafeprotected.com *.doubleclick.net *.facebook.com *.facebook.net *.google.ca *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.googletagservices.com *.adtrafficquality.google *.crwdcntrl.net *.id5-sync.com *.scorecardresearch.com *.google-analytics.com *.gstatic.com *.hotjar.com *.tagman.ca *.pinimg.com *.tiktok.com *.tv5unis.ca cdn.ampproject.org sdk.privacy-center.org snap.licdn.com tag.aticdn.net sc-static.net *.uidapi.com *.jsdelivr.net ;style-src 'self' 'unsafe-inline' *.tv5unis.ca fonts.googleapis.com ;img-src 'self' data: *.adsafeprotected.com *.doubleclick.net *.facebook.com *.google.ca *.google.com *.googleusercontent.com *.google-analytics.com *.googlesyndication.com *.scorecardresearch.com *.adtrafficquality.google *.linkedin.com *.tiktok.com *.tv5unis.ca p.adsymptotic.com bcp.crwdcntrl.net platform-lookaside.fbsbx.com sdk.privacy-center.org https://api.tv5unis.ca ;media-src 'self' blob: *.2mdn.net *.llnw.net *.uplynk.com *.gvt1.com ;frame-src 'self' *.doubleclick.net *.facebook.com *.firebaseapp.com/ *.google.com *.googlesyndication.com *.googleadservices.com *.adtrafficquality.google ads.pubmatic.com imasdk.googleapis.com vars.hotjar.com tr.snapchat.com ;font-src 'self' data: fonts.gstatic.com ;connect-src 'self' *.2mdn.net *.adnxs.com *.amazon-adsystem.com *.amazon-adsystem.com *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.google.ca *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.googletagservices.com *.adtrafficquality.google *.gstatic.com *.gvt1.com *.linkedin.com *.llnw.net *.tagman.ca *.scorecardresearch.com *.tiktok.com *.tv5unis.ca *.uplynk.com bcp.crwdcntrl.net cdn.ampproject.org cdn.jsdelivr.net licensing.bitmovin.com platform-lookaside.fbsbx.com sc-static.net sdk.privacy-center.org sentry.io snap.licdn.com static.hotjar.com tag.aticdn.net *.uidapi.com vendorlist.consensu.org https://api.tv5unis.ca ;worker-src 'self' blob: ;form-action 'self' www.facebook.com tr.snapchat.com ; 1 script-src cdn.cookielaw.org 'unsafe-hashes' 'sha256-5lSQFTOMNNoGBLbrC6eUxpYeuyBQW52hLO9rR85ASEA=' https: http: 'nonce-plMX3mBQKdcmKBmleF+F0xSjHKYYxtSfRxTBML4Ollw=' 'unsafe-eval' 'unsafe-inline';object-src 'none';frame-ancestors 'none';base-uri 'none';report-uri /api/csp-report 1 font-src *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com assets.braintreegateway.com fonts.googleapis.com https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.au/api/csp-report; report-to csp-endpoint 1 object-src 'self'; script-src 'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl/; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://statistiek.rijksoverheid.nl/matomo.js; style-src 'self'; style-src-elem 'self' 'unsafe-inline'; frame-ancestors 'self'; report-uri https://www.examenblad.nl/log-report-uri/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.co.in/ https://bat.bing.com/ https://alb.reddit.com/ https://www.facebook.com/ https://cdn.routeapp.io/ https://c.clarity.ms/ *.clarity.ms/ https://c.bing.com/ https://admin.titanrig.com:10790/ https://admin.titanrig.com/ *.cloudflareinsights.com https://www.ekwb.com *.ekwb.com www.google.ca data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js s7.addthis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.hotjar.com www.redditstatic.com www.googleoptimize.com https://bat.bing.com/ https://www.clarity.ms/ https://scripts.clarity.ms/ https://connect.facebook.net/ *.newrelic.com https://www.google.co.in/ https://www.google.com/ https://c.bing.com/ *.cloudflareinsights.com https://paypal.adtag.where.com/ *.nofraud.com sibautomation.com *.adobedtm.com www.google.ca 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com ekr.zdassets.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.clarity.ms/ *.hotjar.io *.algolia.io https://bam.nr-data.net/ *.googlesyndication.com https://pagead2.googlesyndication.com/ *.facebook.com *.mmapiws.com *.doubleclick.net *.reddit.com *.brevo.com https://www.redditstatic.com/ wss://ws.hotjar.com/ *.nofraud.com https://bat.bing.com *.bing.com https://www.google.co.in *.google.co.in bat.bing.com www.google.ca 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.googleapis.com https://script.hotjar.com https://fonts.gstatic.com https://use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com https://www.paypal.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com ipinfo.io https://vars.hotjar.com https://4914179.fls.doubleclick.net https://pixel.mathtag.com www.facebook.com https://bid.g.doubleclick.net ssl.widgets.webengage.com https://zc2ab3220.webengage.co https://z2024bb90.webengage.co googletagmanager.com td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://www.google.com https://www.google.co.in https://ds0rwwup944qj.cloudfront.net https://www.googletagmanager.com https://www.facebook.com https://script.hotjar.com https://images.notifications-icommkt.com https://www.gstatic.com https://www.paypal.com https://www.sandbox.paypal.com https://www.e-compreahora.com https://connect.facebook.net https://ssl.widgets.webengage.com https://cdn.cookielaw.org https://dgn3cmgewqdgl.cloudfront.net https://afiles.webengage.com https://maps.gstatic.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page landofcoder.com ipinfo.io https://d12zyq17vm1xwx.cloudfront.net https://static.hotjar.com https://script.hotjar.com https://www.google.com https://js-agent.newrelic.com https://bam-cell.nr-data.net https://script.crazyegg.com https://connect.facebook.net https://googleads.g.doubleclick.net https://storage.cdn.braindw.com https://s.braindw.com https://www.paypal.com https://www.sandbox.paypal.com https://externalassets.icommarketing.com https://ssl.widgets.webengage.com https://cdn.cookielaw.org https://cdnjs.cloudflare.com https://c.webengage.com https://static.zdassets.com https://bam.nr-data.net https://use.fontawesome.com https://maps.googleapis.com cdn.widgets.webengage.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com 'self' 'unsafe-inline'; object-src landofcoder.com ipinfo.io 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com landofcoder.com ipinfo.io https://s.braindw.com https://stats.g.doubleclick.net https://notifications-icommkt.com https://in.hotjar.com wss://ws14.hotjar.com https://script.crazyegg.com https://www.facebook.com https://bam-cell.nr-data.net https://www.google-analytics.com https://unileverbrazil.demdex.net https://surveystats.hotjar.io https://u.braindw.com https://track-icommkt.com https://gstatic.com https://vc.hotjar.io wss://ws12.hotjar.com wss://ws2.hotjar.com https://ws12.hotjar.com https://ws2.hotjar.com https://www.paypal.com https://www.sandbox.paypal.com https://p.braindw.com https://connect.facebook.net https://cdn.cookielaw.org https://c.webengage.com https://ekr.zdassets.com https://martech2364.zendesk.com https://bam.nr-data.net https://maps.googleapis.com https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://privacyportal-eu.onetrust.com/request/v1/consentreceipts 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem 'self' 'unsafe-inline' static.queue-it.net assets.queue-it.net metrics.nhm.ac.uk www.nhm.ac.uk static.hotjar.com script.hotjar.com *.redditstatic.com s.pinimg.com ct.pinterest.com connect.facebook.net tags.affiliatefuture.com analytics.tiktok.com assets.adobedtm.com edge.adobedc.net r1-t.trackedlink.net *.googletagmanager.com *.google-analytics.com; font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.weltpixel.com www.xtento.com https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net https://images.unsplash.com www.nhmshop.co.uk www.nhm.ac.uk *.facebook.com *.tiktok.com *.reddit.com *.google.co.uk *.gstatic.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com tagmanager.google.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://maps.googleapis.com https://player.vimeo.com pagead2.googlesyndication.com static.queue-it.net assets.queue-it.net metrics.nhm.ac.uk www.nhm.ac.uk *.hotjar.io *.hotjar.com *.redditstatic.com *.reddit.com s.pinimg.com ct.pinterest.com connect.facebook.net tags.affiliatefuture.com analytics.tiktok.com assets.adobedtm.com edge.adobedc.net *.googletagmanager.com *.google-analytics.com *.doubleclick.net https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.slant.co *.zohocdn.com *.flaticon.com *.cdnfonts.com *.alicdn.com *.jsdelivr.net *.hsappstatic.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.newrelic.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com *.opendns.com *.youshouldask.ai google.com amazingoriental.com *.bing.com *.instagram.com *.cookiebot.com *.googletagmanager.com *.sharethis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.multisafepay.com www.google.co.id www.google.com.qa www.google.com.bh www.google.com.co www.google.gg www.google.lk www.google.by www.google.gl www.google.hr www.google.com.pg www.google.bt www.google.com.np www.google.com.pe www.google.co.il www.google.jo www.google.it www.google.co.zm *.sharethis.com www.google.com.et www.google.ch www.google.hu www.google.com.pr www.google.li www.google.md www.google.am www.google.im www.google.es www.google.td www.google.is www.google.com.bo www.google.lu www.google.co.ma www.google.dm www.google.co.ls www.google.mn www.google.com.ec www.google.ba www.google.me www.google.com.kh www.google.co.th *.bing.com www.google.com.vn www.google.ps www.google.com.hk www.google.fm www.google.rw www.google.com.cy www.google.cv *.instagram.com www.google.tt www.google.ge www.google.com.lb *.bing.net www.google.ro amazingoriental.com www.google.no www.google.cd www.google.co.ve www.google.dk *.alicdn.com www.google.mg www.google.hn www.google.ru www.google.com.bn www.google.ml www.google.com.cu www.google.com.ni www.google.com.eg www.google.com.gt www.google.la www.google.com.br instagram.com www.google.com.jm www.google.je www.google.com.mt www.google.kg *.youshouldask.ai www.google.so www.google.mv www.google.com.af www.google.co.mz www.google.com.sl www.google.com.pk www.google.gr www.google.com.tw www.google.tn www.google.com.sg www.google.co.in www.google.ad www.google.at www.google.vu www.google.al www.google.rs www.google.ie www.google.co.ke www.google.cm www.google.mw www.google.com.pa www.google.ae google.com www.google.pl www.google.com.fj www.google.com.kw www.google.pt www.google.be www.google.com.mx www.google.mu www.google.com.sb www.google.co.cr www.google.ee www.google.com.py www.google.iq www.google.ca www.google.gy www.google.co.jp www.google.sr www.google.de www.google.to www.google.lt www.google.com.do *.cashbackxl.nl www.google.co.zw *.google.com www.google.fi www.google.sk www.google.co.ug www.google.com.ph www.google.co.tz www.google.ga www.google.tg www.google.si www.google.lv *.clarity.ms www.google.com.sa www.google.bj www.google.dj www.google.dz www.google.ci www.google.com.ua www.google.com.ar www.google.com.gh www.google.co.uz www.google.com.my www.google.fr www.google.com.ng www.google.com.om www.google.nl www.google.ws *.amazingoriental.com s3.amazonaws.com www.google.com.sv www.google.com.tr www.google.com.uy www.google.se www.google.co.ao www.google.com.na www.google.sn www.google.com.mm *.cookiebot.com www.google.cl www.google.co.za www.google.gm www.google.sc bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.co.nz www.google.com.bz www.google.co.uk www.google.com.bd www.google.ht www.google.ki www.google.cf www.google.kz www.google.com.au www.google.bs www.google.mk www.google.cz www.google.co.kr www.google.az www.google.com.ly www.google.com.gi data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.multisafepay.com https://pay.google.com *.instagram.com *.youshouldask.ai *.sharethis.com googletagmanager.com *.clarity.ms *.g4ui.com *.yandex.net *.cookiebot.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.multisafepay.com *.youshouldask.ai 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io *.multisafepay.com t.elasticsuite.io www.google.ae www.google.mn *.clarity.ms www.google.ie www.google.co.kr www.google.cl www.google.co.cr www.google.com.mx www.google.co.il www.google.co.in *.yandex.net www.google.am www.google.no www.google.com.tw www.google.lt www.google.com.tr www.google.hr www.google.la www.google.ru www.google.sk www.google.com.sg www.google.it www.google.co.th www.google.mk www.google.lv www.google.com.gh www.google.com.ar www.google.gr www.google.com.lb www.google.lu www.google.com.pk www.google.md www.google.com.hk www.google.sn *.crwdcntrl.net *.instagram.com www.google.pt www.google.co.uk www.google.co.jp www.google.com.br www.google.co.id *.alicdn.com www.google.com.cy *.sharethis.com www.google.si www.google.ee www.google.es *.cookiebot.com www.google.ge www.google.sr www.google.se www.google.pl www.google.com.vn www.google.de www.google.co.ve www.google.co.za *.bing.net www.google.be www.google.co.ke www.google.tn *.bing.com www.google.nl www.google.ch www.google.bg www.google.rs www.google.com.ua www.google.fr www.google.gy www.google.bt www.google.dk www.google.gm www.google.ca www.google.com.eg www.google.me www.google.ga www.google.al *.youshouldask.ai www.google.com.ph www.google.co.ma www.google.com.my www.google.cz localhost www.google.ro www.google.com.np www.google.at google.com www.google.lk www.google.fi www.google.ba www.google.jo www.google.hu www.google.ps www.google.mv www.google.com.om www.google.com.kw *.google.com www.google.com.au www.google.ml www.google.com.sa www.google.is www.google.com.ng www.google.com.co www.google.com.mt 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1839b17e-08af-4229-a4fd-23c2b476d361.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com widgets.trustedshops.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cleverreach.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudfront.net https://cdn.consentmanager.net https://delivery.consentmanager.net https://d.delivery.consentmanager.net *.google.de *.google.com *.facebook.com https://widgets.trustedshops.com https://b.delivery.consentmanager.net https://bat.bing.com magefan.com cm.magefan.com *.sooqr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.pay1.de x.klarnacdn.net m.media-amazon.com static-eu.payments-amazon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://d.delivery.consentmanager.net https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://connect.facebook.net https://widgets.trustedshops.com https://cognito-identity.eu-central-1.amazonaws.com https://b.delivery.consentmanager.net https://bat.bing.com https://www.clarity.ms *.sooqr.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widgets.trustedshops.com maxcdn.bootstrapcdn.com *.fontawesome.com *.sooqr.com assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://d.delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://*.google-analytics.com https://*.analytics.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://region1.google-analytics.com https://cognito-identity.eu-central-1.amazonaws.com https://cdn1.api.trustedshops.com https://y.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.yotpo.com *.klarnacdn.net www.ekstralys.no data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://*.svea.com https://*.vipps.no https://*.trustly.com www.ekstralys.no 'self' 'unsafe-inline'; frame-ancestors www.ekstralys.no 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com www.xtento.com https://*.svea.com www.ekstralys.no 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.cloudfront.net www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com ts.tradetracker.net www.magmodules.eu www.ekstralys.no data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com *.klarna.com *.klarnacdn.net *.criteo.net *.criteo.com *.facebook.net *.google-analytics.com *.amazon.co.uk *.amazon.com *.payments-amazon.com cookie-script.com s.kk-resources.com *.livechatinc.com bat.bing.com js.adsrvr.org sc-static.net *.hotjar.com *.snapchat.com *.sleeknote.com https://*.dibspayment.eu www.xtento.com cdn.xtento.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.svea.com *.klarnaservices.com tm.tradetracker.net www.ekstralys.no 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com downloads.mailchimp.com *.klarnacdn.net *.fontawesome.com www.ekstralys.no 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.ekstralys.no 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.klarnaevt.com *.amazon.co.uk *.amazon.com *.payments-amazon.com *.doubleclick.net *.google-analytics.com *.snapchat.com *.criteo.com *.klarnacdn.net *.klarna.com *.klarnaservices.com www.ekstralys.no 'self' 'unsafe-inline'; child-src www.ekstralys.no http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.ekstralys.no 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.falconstudios.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.falconstudios.com join.gammasecure.com; script-src 'self' *.falconstudios.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.falconstudios.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.fontawesome.com fonts.gstatic.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.merchante-solutions.com https://hostedpayments.merchante.com https://merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://elements.sandbox.fortis.tech https://elements.fortis.tech https://merchantacsstag.cardinalcommerce.com *.weltpixel.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com js-agent.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com https://developer.adobe.com https://magento.com https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com bam.nr-data.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com bam.nr-data.net *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com https://developer.adobe.com https://elements.sandbox.fortis.tech https://elements.fortis.tech https://api.merchante-solutions.com https://cert.merchante-solutions.com https://testapi.merchante-solutions.com https://writer.cardinalcommerce.com rs.fullstory.com edge.fullstory.com stats.g.doubleclick.net https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com use.typekit.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://www.googletagmanager.com/ *.klarna.com www.facebook.com platform.twitter.com *.freshchat.com www.paypalobjects.com *.google.com *.addthis.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://images.unsplash.com *.trackedlink.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.feefo.com *.postcodeanywhere.co.uk *.clarity.ms registry.blockmarktech.com www.google.co.uk www.google.fr www.google.se www.google.rs *.bing.net *.googlesyndication.com *.roeye.com *.awin1.com *.c.bing.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com polyfill.io *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.klarna.com *.klarnacdn.net *.klarnaservices.com s7.addthis.com connect.facebook.net twitter.com platform.twitter.com *.google.com maps.googleapis.com *.feefo.com cdn.cookie-script.com wchat.freshchat.com *.moatads.com *.addthisedge.com *.addthis.com *.pcapredict.com *.postcodeanywhere.co.uk *.googletagmanager.com *.clarity.ms *.hotjar.com *.bing.com *.dwin1.com *.awin1.com *.roeyecdn.com *.sciencebehindecommerce.com *.fullstory.com *.cloudflareinsights.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.freshchat.com cdnjs.cloudflare.com *.postcodeanywhere.co.uk *.typekit.net register.feefo.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ data 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com ekr.zdassets.com/ *.feefo.com *.trustpilot.com *.addthis.com *.postcodeanywhere.co.uk *.amazonaws.com *.clarity.ms *.google-analytics.com *.hotjar *.bing.net *.googlesyndication.com *.wepowerconnections.com *.sciencebehindecommerce.com www.google.co.uk *.stripe.com klarna.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com bo.maisonic.com self https: 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com https://applepay.cdn-apple.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.gstatic.com axeptio.imgix.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://www.magezon.com cdn.doofinder.com pim.avidsen.com network-eu-stg-a.bazaarvoice.com network-eu-a.bazaarvoice.com maisonic.com *.maisonic.com www.mageworx.com www.magezon.com apps.bazaarvoice.com action.metaffiliation.com *.ad4m.at track.adform.net adservice.google.com ad.doubleclick.net img.metaffiliation.com r.adserver01.de flagpedia.net https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.axept.io apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.google.com/ cdn.doofinder.com static.axept.io sibautomation.com cdn.brevo.com static.cloudflareinsights.com cdnjs.cloudflare.com eu1-config.doofinder.com secure.payplug.com cdn.payplug.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ awsapis3.netreviews.eu auth.skeepers.io api.skeepers.io cl-pbr.cxr.skeepers.io znl.maisonic.com tag.beyable.com ad4m.at pixel.bsmartdata.com front.activation.beyable.com www.clarity.ms scripts.clarity.ms *.gstatic.com maps.googleapis.com https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com display.ugc.bazaarvoice.com *.doofinder.com *.fontawesome.com cdnjs.cloudflare.com cdn.doofinder.com maxcdn.bootstrapcdn.com *.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com api.axept.io client.axept.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.doofinder.com wss://*.doofinder.com static.axept.io apps-stg.bazaarvoice.com in-automate.brevo.com cloudflareinsights.com cdnjs.cloudflare.com eu1-api.doofinder.com stats.g.doubleclick.net region1.analytics.google.com region1.google-analytics.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ awsapis3.netreviews.eu auth.skeepers.io api.skeepers.io cl-pbr.cxr.skeepers.io znl.maisonic.com tag.beyable.com ad4m.at pixel.bsmartdata.com *.clarity.ms www.gstatic.com maps.googleapis.com https://cl-pbr.cxr.skeepers.io/ https://nominatim.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src api.axept.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-inline' https://*.googleapis.com https://*.hubspot.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hscta.net https://*.usemessages.com https://*.sharethis.com https://*.wistia.com https://*.google-analytics.com https://www.googletagmanager.com; style-src 'report-sample' 'self' 'unsafe-inline' https://*.googleapis.com https://*.sharethis.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://*.hubspot.com https://*.hs-banner.com https://*.sharethis.com https://*.crwdcntrl.net https://*.ltmsphrcl.net https://*.wistia.com https://*.google-analytics.com https://www.googletagmanager.com https://www.google.com; frame-src 'self' https://*.wistia.com https://*.sharethis.com https://www.google.com; img-src 'self' data: https://*.hubspotusercontent-na1.net https://*.hsforms.com https://*.gravatar.com https://*.sharethis.com https://*.hubspot.com https://wpengine.com https://www.googletagmanager.com; manifest-src 'self'; media-src 'self'; worker-src 'self' blob:; report-uri https://6915f6be6969e21dc176bf00.endpoint.csper.io?v=3; 1 font-src *.gstatic.com *.authorize.net *.cardinalcommerce.com *.adobedtm.com *.yotpo.com 'self' data: *.cloudfront.net *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.addthis.com *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.google.com *.facebook.com *.facebook.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io blob: *.gstatic.com *.googleapis.com https://meetanshi.com/media/logo.png 'self' data: *.png *.jpg *.jpeg *.cloudfront.net *.yotpo.com *.cdninstagram.com *.facebook.com *.facebook.net *.google.com *.google.lk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.google.com *.gstatic.com *.googleapis.com *.authorize.net *.cardinalcommerce.com *.cloudfront.net *.facebook.net *.newrelic.com *.nr-data.net *.googletagmanager.com *.yotpo.com cdn.rawgit.com *.zdassets.com *.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.cloudfront.net *.yotpo.com unsafe-inline assets.braintreegateway.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.googleapis.com *.google-analytics.com *.cardinalcommerce.com *.amazon.com *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonservices.com *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.trackedweb.net *.nr-data.net *.instagram.com *.dotdigital.com *.comapi.com *.paypal.com *.cloudfront.net *.facebook.com *.facebook.net *.doubleclick.net *.zdassets.com *.zendesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com google.com ws: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.sagepay.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.awin1.com *.zenaps.com *.fls.doubleclick.net https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.elfsightcdn.com *.feefo.com *.onetrust.com lantern.roeye.com *.sweetanalytics.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.elfsight.com euwa.puzzel.com *.feefo.com berrythompson.innocraft.cloud *.puzzel.com *.onetrust.com *.sweetanalytics.com unpkg.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cloudflarestream.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.puzzel.com *.feefo.com *.elfsight.com berrythompson.innocraft.cloud *.onetrust.com *.sweetanalytics.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a19bde59-13ef-45e6-afd8-1c13b7fc2c39.sansec.watch/; report-to report-endpoint; 1 frame-src 'self'; object-src 'none'; script-src 'self' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com https://www.google.com maps.google.com platform.instagram.com platform.twitter.com 'nonce-vREXxDmQieOA9qQXy8A2eA'; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com https://www.google.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com maps.googleapis.com maps.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net blob: https://*.ximasoftware.com/ https://*.hubspot.com/ https://*.linkedin.com/ magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://*.hs-scripts.com/ https://*.hs-banner.com/ https://*.hs-analytics.net/ https://*.hsadspixel.net/ https://*.hscollectedforms.net/ https://*.ximasoftware.com/ https://*.gstatic.com/ https://*.google.com/ https://*.fontawesome.com/ https://*.clarity.ms/ https://*.stackadapt.com/ https://*.licdn.com/ https://*.jsdelivr.net/ https://*.pinimg.com/ https://*.amazonaws.com/ https://*.newrelic.com/ https://*.pinterest.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.hsforms.net *.hsforms.com https://www.google.com *.gstatic.com https://www.gstatic.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com display.ugc.bazaarvoice.com https://*.ximasoftware.com/ https://*.stackadapt.com/ unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.ximasoftware.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.hs-scripts.com/ https://*.hs-banner.com/ https://*.hs-analytics.net/ https://*.hsadspixel.net/ https://*.hscollectedforms.net/ https://*.hubapi.com/ https://*.linkedin.com/ https://*.ximasoftware.com/ https://*.gstatic.com/ https://*.google.com/ https://*.fontawesome.com/ https://*.clarity.ms/ https://*.stackadapt.com/ https://*.licdn.com/ https://*.jsdelivr.net/ https://*.pinimg.com/ https://*.newrelic.com/ https://*.pinterest.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.hotjar.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mitec.com.mx *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mitec.com.mx 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mitec.com.mx *.e-pago.com.mx www.threedsecurempi.com *.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com *.pidesalud.com *.pidederma.com *.farmaciasespecializadas.com *.google.com *.google.com.mx *.bing.com *.clarity.ms *.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com *.mitec.com.mx https://cdnjs.cloudflare.com https://static.hotjar.com https://script.hotjar.com/modules.28e3191d8757c557b4b7.js https://www.clarity.ms https://bat.bing.com https://cdn.mouseflow.com *.hotjar.com *.gstatic.com *.adobe.io cdn.mxpnl.com cdn.brevo.com scripts.clarity.ms *.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mitec.com.mx https://bam.nr-data.net https://bam-cell.nr-data.net https://stats.g.doubleclick.net *.mouseflow.com *.clarity.ms *.appspot.com wss://ws.hotjar.com/ *.hotjar.com *.hotjar.io live.store-locator.nx.iwdfun.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src https://fonts.gstatic.com fonts.gstatic.com data: https://ws.colissimo.fr https://static.lyra.com/static/ *.gstatic.com *.stape.io *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.instagram.com www.google.com https://www.youtube.com https://form.typeform.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * api.socloz.com storage.googleapis.com *.doubleclick.net sibautomation.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.googleapis.com *.cdninstagram.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com placehold.co *.google.fr *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.stape.io https://static.addtoany.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.socloz.com storage.googleapis.com *.axept.io sibautomation.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://static.lyra.com/static/ *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com *.google.com *.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://nominatim.openstreetmap.org https://maps.googleapis.com https://*.onyourmap.com https://*.mapbox.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ *.google-analytics.com *.google.com *.stape.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.axept.io *.brevo.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: *.gstatic.com oct8necdneu.azureedge.net *.oct8ne.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com consentcdn.cookiebot.com *.vimeo.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.cookiebot.com *.ggpht *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.distriplac.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ consent.cookiebot.com polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.adyen.com *.hotjar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com preassets.empathybroker.com x.empathy.co x.staging.empathy.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com consentcdn.cookiebot.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.adyen.com *.googleapis.com *.cookiebot.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com distriplac.com *.empathybroker.com *.empathy.co *.staging.empathy.co 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src *; frame-src *; img-src * data:; object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net https://www.paypalobjects.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://commercehub-secure-data-capture.fiservapps.com https://prod.api.fiservapps.com https://cert.api.fiservapps.com https://assets.adobedtm.com https://www.paypal.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net data: https://assets.adobedtm.com https://images.unsplash.com blob: 'self' * *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://rum.hlx.page https://commercehub-secure-data-capture.fiservapps.com https://prod.api.fiservapps.com https://cert.api.fiservapps.com https://assets.adobedtm.com https://maps.googleapis.com https://rum.hlx.page/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js https://www.paypal.com https://www.paypalobjects.com https://www.sandbox.paypal.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://assets.adobedtm.com https://www.paypalobjects.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: data: 'self' * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adobedc.net *.demdex.net https://assets.adobedtm.com https://maps.googleapis.com https://player.vimeo.com https://www.paypal.com https://www.paypalobjects.com https://www.sandbox.paypal.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 'self' 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri /csp-report-endpoint.php 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' https://acc.locaties.partou.nl https://bat.bing.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://connect.facebook.net https://fpp.partou.nl https://googleads.g.doubleclick.net https://locaties.partou.nl https://projects.elitechnology.com https://www.googleadservices.com https://www.googletagmanager.com; style-src 'report-sample' 'self' 'unsafe-inline' https://acc.locaties.partou.nl https://locaties.partou.nl; object-src 'none'; base-uri 'self'; connect-src 'self' https://backoffice-api.acc.locaties.partou.nl https://backoffice-api.locaties.partou.nl wss://backoffice-api.acc.locaties.partou.nl wss://backoffice-api.locaties.partou.nl wss://cxcomlive-webconvwa-weu.azurewebsites.net https://bat.bing.com https://consentcdn.cookiebot.com https://fpp.partou.nl https://*.google-analytics.com https://www.google.com https://googleads.g.doubleclick.net https://region1.analytics.google.com; font-src 'self' data: https://acc.locaties.partou.nl https://locaties.partou.nl https://www.cm.com; frame-src 'self' https://consentcdn.cookiebot.com https://www.youtube.com; img-src 'self' data: https://bat.bing.com https://img.youtube.com https://imgsct.cookiebot.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://tiles.stadiamaps.com https://www.facebook.com https://www.googletagmanager.com https://www.google.com https://www.google.nl; manifest-src 'self'; media-src 'self'; worker-src blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: *.fontawesome.com https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://youtube.com/ *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.googletagmanager.com/ sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://vimeo.com/ https://player.vimeo.com/ https://www.google.com/ https://analytics.google.com https://googleads.g.doubleclick.net https://connect.facebook.net http://www.brildor.com https://*.cookiebot.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.googleapis.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://www.brildor.com/ https://cdn.trust.reviews https://*.cookiebot.com https://*.google.com https://*.google.es https://lh3.googleusercontent.com http://stats.g.doubleclick.net/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com https://www.google-analytics.com/ googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://unpkg.com https://browser.sentry-cdn.com https://www.gstatic.com/ https://js-agent.newrelic.com https://bam-cell.nr-data.net http://www.sandbox.paypal.com http://www.paypal.com https://analytics.google.com https://ssl.google-analytics.com http://stats.g.doubleclick.net/ https://googleads.g.doubleclick.net https://cdn.connectif.cloud https://connect.facebook.net http://www.brildor.com https://app.trust.reviews https://*.cookiebot.com https://*.reskyt.com js.mollie.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.trust.reviews *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com/ www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://*.ingest.sentry.io https://*.google.com/ https://www.gstatic.com/ https://analytics.google.com https://*.googlesyndication.com https://*.googleapis.com https://js-agent.newrelic.com https://bam-cell.nr-data.net http://www.sandbox.paypal.com http://www.paypal.com https://googleads.g.doubleclick.net https://eu3-api.connectif.cloud https://connect.facebook.net http://*.brildor.com https://*.brildor.com https://sentry.brildor.es api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com https://static.dhlecommerce.nl https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://www.googletagmanager.com/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.trustpilot.com 'self' 'unsafe-inline'; img-src cdn.verfwinkel.nl data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://maps.googleapis.com https://maps.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://img.youtube.com https://www.mollie.com data: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://static.dhlecommerce.nl http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://cdn.jsdelivr.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://hcaptcha.com https://*.hcaptcha.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://*.hotjar.com:* https://aggregator.service.usercentrics.eu https://analytics.tiktok.com https://api.omappapi.com https://api.trustpilot.com https://api.usercentrics.eu https://bat.bing.com https://ct.pinterest.com https://graphql.usercentrics.eu https://pagead2.googlesyndication.com https://services.ottonova.de https://ssl.google-analytics.com https://sst.ottonova.de https://stats.g.doubleclick.net https://*.hotjar.io https://trc-events.taboola.com https://www.google-analytics.com wss://*.hotjar.com; font-src 'self' data: https://fonts.gstatic.com https://script.hotjar.com; frame-src 'self' https://gum.criteo.com https://hal9000.redintelligence.net https://static.criteo.net https://tr.snapchat.com https://www.awin1.com https://vars.hotjar.com https://www.youtube.com; img-src 'self' data: https:; script-src 'self' 'nonce-424d4e4d062fe9fa8330da0a769e4c98' 'unsafe-eval' 'report-sample' 'strict-dynamic'; style-src 'self' 'unsafe-inline' 'report-sample' https://fonts.googleapis.com; base-uri 'none'; report-uri https://ottonova.report-uri.com/r/d/csp/reportOnly 1 font-src *.gstatic.com 'self' data: *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.googleapis.com *.hotjar.com *.typekit.net cdn.curator.io static.klaviyo.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.youtube-nocookie.com www.google.com *.chatra.io *.hotjar.com *.facebook.com *.trustpilot.com *.kiyoh.com *.pinterest.com *.criteo.com *.cookiefirst.com www.googletagmanager.com tm-plugin-test.azurewebsites.net demo.topmatsxxl.com plugin.topmatsxxl.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com * scontent.fzty3-2.fna.fbcdn.net alb.reddit.com p.typekit.net www.facebook.com curator-assets.b-cdn.net data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.chimpstatic.com downloads.mailchimp.com *.list-manage.com use.typekit.net *.cloudflare.com *.twitter.com *.fontawesome.com *.elfsight.com *.chatra.io *.jsdelivr.net chimpstatic.com *.facebook.com *.doubleclick.net *.trustpilot.com s.pinimg.com *.zdassets.com *.google-analytics.com *.feedbackcompany.com *.facebook.net *.hotjar.com *.mailchimp.com *.curator.io *.typekit.net *.clarity.ms *.leadinfo.net *.criteo.com www.googletagmanager.com *.googleadservices.com consent.cookiefirst.com *.cookiefirst.com www.datadoghq-browser-agent.com bat.bing.com *.tidio.co *.tidiochat.com *.iubenda.com js-agent.newrelic.com cdn.curator.io sleeknotecustomerscripts.sleeknote.com www.redditstatic.com embed.sendcloud.sc cdn.jsdelivr.net www.gstatic.com https://www.googletagmanager.com tagmanager.google.com www.google.com analytics.google.com unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net *.googleapis.com 'unsafe-inline' data: *.curator.io *.cookiefirst.com fonts.googleapis.com maxcdn.bootstrapcdn.com pay.multisafepay.com cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src curatorio.s3.amazonaws.com curator-assets.b-cdn.net video-lga3-2.cdninstagram.com video-iad3-1.xx.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.cloudflare.com *.elfsight.com *.instacloud.io *.google-analytics.com *.google.com *.doubleclick.net *.hotjar.com *.hotjar.io ct.pinterest.com *.paypal.com *.zdassets.com *.zendesk.com *.feedbackcompany.com *.curator.io *.clarity.ms *.leadinfo.net *.cookiefirst.com gtm-mm85h6s-nzi2m.uc.r.appspot.com www.google-analytics.com www.google.com maps.googleapis.com *.livechatinc.com dev.visualwebsiteoptimizer.com www.googletagmanager.com pagead2.googlesyndication.com region1.analytics.google.com consent.cookiefirst.com www.redditstatic.com pixel-config.reddit.com edge.cookiefirst.com sendcloud-checkout-static-data.sendcloud.sc https://www.google-analytics.com analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com k.clarity.ms analytics.sleeknote.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com *.googleapis.com *.cloudflare.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.shopperapproved.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.hotjar.com https://plumrocket.com *.weltpixel.com *.doubleclick.net *.facebook.com *.google.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.shopperapproved.com https://*.hotjar.com *.klevu.com *.ksearchnet.com *.gstatic.com tvspix.com google.com *.google.com *.adsrvr.org *.doubleclick.net *.googleapis.com *.facebook.com *.amplifieddigitalagency.com *.bing.com *.bing.net *.facebook.net *.google-analytics.com *.googleadservices.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.shopperapproved.com https://direct.shopperapproved.com https://*.hotjar.com https://connect.facebook.net https://bat.bing.com js.klevu.com *.ksearchnet.com *.googleapis.com *.google.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.hotjar.com *.facebook.net *.cloudflare.com *.bing.com cxppusa1formui01cdnsa01-endpoint.azureedge.net *.paypal.com *.amplifieddigitalagency.com *.doubleclick.net *.google-analytics.com *.klevu.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com tagmanager.google.com *.cloudflare.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.paypal.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.klevu.com *.ksearchnet.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://www.google-analytics.com *.doubleclick.net *.googleapis.com *.google.com *.facebook.net google.com *.hotjar.io *.hotjar.com *.googleadservices.com *.google-analytics.com *.facebook.com *.gstatic.com *.bing.net *.cloudflare.com *.paypal.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.paypal.com *.googleadservices.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; base-uri 'self' 'unsafe-inline'; report-uri https://14050275-8828-4f9f-b9b6-e1d4d98e6996.sansec.watch/; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; report-uri https://zenpark.com/csp-violation-report-endpoint 1 font-src *.cloudflare.com *.typekit.net *.trustedshops.com *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com youtu.be *.vimeo.com *.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu blob: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.google-analytics.com *.google.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com s7.addthis.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu fonts.googleapis.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.paypal.com *.googleapis.com ekr.zdassets.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.cloudmaestro.com www.reedssports.com cdn.reedssports.com rum-static.pingdom.net a-52365312.cdn.ns8ds.com widget-mediator.zopim.com *.dotdigital-pages.com r2.dotdigital-pages.com r2-t.trackedlink.net www.google-analytics.com *.google.com www.gstatic.com *.addthis.com *.moatads.com *.addthisedge.com *.newrelic.com *.nr-data.net *.com.imgeng.in *.miss.imgeng.in a-52365312.nscontrol.com googleads.g.doubleclick.net www.googletagmanager.com www.googleadservices.com connect.facebook.net *.integrator.io js.authorize.net google-analytics.com www.google-analytics.com player.vimeo.com www.youtube.com cdn.dnky.co *.reedsvipdeals.com/* app.viralsweep.com cdn.sift.com static.zdassets.com *.turnto.com maps.googleapis.com js.klevu.com; report-uri /.webscale/csp-report 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com maps.google.com maps.googleapis.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src *.gstatic.com *.typekit.net https://*klaviyo.com *.jaguarlandroverclassic.com *.jaguar.co.uk *.landrover.co.uk https://*.klevu.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.doubleclick.net https://www.google.com https://*.hotjar.com consentcdn.cookiebot.com consentcdn.cookiebot.eu https://*.freshchat.com *.visualwebsiteoptimizer.com *.jaguarlandroverclassic.com *.jaguar.co.uk *.landrover.co.uk *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.doubleclick.net https://www.google.com https://www.google.co.uk *.cloudfront.net imgsct.cookiebot.com imgsct.cookiebot.eu *.landrover.co.uk *.jaguar.co.uk https://*.postcodeanywhere.co.uk https://*.clarity.ms https://*.bing.com *.visualwebsiteoptimizer.com *.jaguarlandroverclassic.com https://*.klaviyo.com https://*.facebook.net https://*.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.postcodeanywhere.co.uk https://www.googletagmanager.com https://www.google.com *.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com consent.cookiebot.com consent.cookiebot.eu https://www.gstatic.com https://googleads.g.doubleclick.net https://script.crazyegg.com https://*.freshchat.com https://*.cookiebot.com https://*.coremetrics.com https://*.bing.com https://*.clarity.ms https://*.landrover.co.uk https://*.jaguar.co.uk *.visualwebsiteoptimizer.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.googleapis.com *.typekit.net https://*.postcodeanywhere.co.uk https://*.freshchat.com *.jaguarlandroverclassic.com *.jaguar.co.uk *.landrover.co.uk *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu https://*.hotjar.io https://*.doubleclick.net https://*.google-analytics.com https://script.crazyegg.com https://*.postcodeanywhere.co.uk https://*.clarity.ms https://*.cookiebot.com *.visualwebsiteoptimizer.com *.jaguarlandroverclassic.com *.jaguar.co.uk *.landrover.co.uk https://*.mida.so *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://staticw2.yotpo.com data: *.webtrends-optimize.com *.azurewebsites.net *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * core.spreedly.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; frame-ancestors 'self' 'unsafe-eval' 'strict-dynamic'; frame-src secure.authorize.net test.authorize.net *.demdex.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com https://checkout-sandbox.getbread.com https://checkout.getbread.com *.google.com https://vars.hotjar.com https://www.facebook.com https://www.youtube.com *.stackadapt.com https://www.paypal.com https://gum.criteo.com/ *.affirm.com *.webtrends-optimize.com *.azurewebsites.net *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * core.spreedly.com *.yotpo.com swellrewards.com *.swellrewards.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://cdn.searchspring.net https://dev.visualwebsiteoptimizer.com https://cdn.cookielaw.org https://d.impactradius-event.com https://checkout-sandbox.getbread.com https://checkout.getbread.com https://a-60239872.cdn.ns8ds.com https://commerce.adobedtm.com https://www.facebook.com https://p.yotpo.com *.ns8ds.com *.loggly.com https://www.google.com *.google.com *.stackadapt.com *.webtrends-optimize.com *.azurewebsites.net *.affirm.com *.affirm.ca https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com swellrewards.com *.swellrewards.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.sandbox.paypal.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com cdn.ampproject.org raw.githubusercontent.com *.affirm.com https://static.scarabresearch.com https://static.addtoany.com https://geolocation.onetrust.com https://cdn.searchspring.net https://dev.visualwebsiteoptimizer.com https://cdn.cookielaw.org https://d.impactradius-event.com https://checkout-sandbox.getbread.com https://checkout.getbread.com https://a-60239872.cdn.ns8ds.com https://commerce.adobedtm.com https://a-42369024.cdn.ns8ds.com https://cdn.scarabresearch.com https://d22q3dafggn5rg.cloudfront.net https://a-42369024.nscontrol.com https://staticw2.yotpo.com https://www.googletagmanager.com *.loggly.com *.bing.com *.adobe.net *.facebook.net *.hotjar.com *.criteo.net *.criteo.com *.google.com https://resources.xg4ken.com https://www.googlecommerce.com https://www.paypal.com *.stackadapt.com *.webtrends-optimize.com *.azurewebsites.net *.convertexperiments.com *.zdassets.com *.newrelic.com *.affirm.ca *.plugins.emarsys.net *.scarabresearch.com https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com core.spreedly.com *.subscribepro.com www.gstatic.com *.yotpo.com swellrewards.com *.swellrewards.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://tags.srv.stackadapt.com https://cdn.searchspring.net https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://staticw2.yotpo.com *.stackadapt.com *.webtrends-optimize.com *.azurewebsites.net https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com *.subscribepro.com www.gstatic.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; object-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; connect-src www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com cdn.ampproject.org https://bam-cell.nr-data.net https://tracker.affirm.com https://sandbox.affirm.com https://recommender-eu.scarabresearch.com https://webchannel-content.eservice.emarsys.net *.searchspring.net https://dev.visualwebsiteoptimizer.com https://cdn.cookielaw.org https://d.impactradius-event.com https://checkout-sandbox.getbread.com https://checkout.getbread.com https://a-60239872.cdn.ns8ds.com https://commerce.adobedtm.com https://www.facebook.com https://staticw2.yotpo.com https://commerce.adobedc.net https://www.google-analytics.com https://stats.g.doubleclick.net https://recommender.scarabresearch.com https://in.hotjar.com https://w2.yotpo.com *.searchspring.io *.google.com *.affirm.com *.stackadapt.com *.webtrends-optimize.com *.azurewebsites.net *.zendesk.com https://ekr.zdassets.com https://bam.nr-data.net *.affirm.ca *.scarabresearch.com *.eservice.emarsys.net https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.subscribepro.com core.spreedly.com *.yotpo.com swellrewards.com *.swellrewards.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; base-uri 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; 1 default-src https: data: 'unsafe-inline' 'unsafe-eval' blob: wss:; report-uri https://7ee2a4f517b54c13812e54076aefcb7d.myssl-uri.com/api/csp-report 1 script-src 'self' https://cdn.suitableshop.net https://bat.bing.com https://d5yoctgpv4cpx.cloudfront.net https://tggng.suitableshop.nl 'unsafe-inline' ; 1 font-src *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net https://plumrocket.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.awin1.com *.zenaps.com *.wepowerconnections.com *.akamaihd.net *.ebit.com.br *.ebitemptresa.com.br www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.ebit.com.br www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.k-analytix.com *.cloudfront.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.ebit.com.br *.googleapis.com *.cloudfront.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.akamaihd.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.konduto.com *.edrone.me api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.kidsnews.com.au/csp-reports 1 script-src-elem webcache.datareporter.eu webcache-eu.datareporter.eu https://apis.google.com static.zdassets.com buerostuhl24.app.baqend.com www.dwin1.com unpkg.com widget.trustpilot.com bat.bing.com invitejs.trustpilot.com lantern.roeyecdn.com www.googletagmanager.com s.pinimg.com s.kk-resources.com ct.beslist.nl dynamic.criteo.com data.bureaustoel24.nl www.google.com connect.facebook.net widgets.trustedshops.com googleads.g.doubleclick.net www.gstatic.com static.trbo.com api-v4.trbo.com sslwidget.criteo.com integrations.etrusted.com static.hotjar.com data.buerostuhl24.com secure.pay1.de script.hotjar.com tm708.ad-srv.net tm706.ad-srv.net tm.ad-srv.net ct.pinterest.com tm716.ad-srv.net data.sillasdeoficina24.es static-eu.payments-amazon.com cdn.jsdelivr.net snap.licdn.com tm710.ad-srv.net data.buerostuhl24.at tm701.ad-srv.net data.hjh-office.fr tm720.ad-srv.net data.hjh-office.se data.buerostuhl24.ch tm722.ad-srv.net tm712.ad-srv.net sibforms.com widget-mediator.zopim.com data.hjh-office.fi tm702.ad-srv.net tm724.ad-srv.net tm723.ad-srv.net tm709.ad-srv.net tm718.ad-srv.net tm707.ad-srv.net tm715.ad-srv.net tm711.ad-srv.net data.hjh-office.it tm719.ad-srv.net tm704.ad-srv.net tm703.ad-srv.net tm721.ad-srv.net www.moebel.de www.awin1.com data.hjh-office.dk 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem https://webcache.datareporter.eu https://webcache-eu.datareporter.eu webcache-eu.datareporter.eu integrations.etrusted.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com webcachex-eu.datareporter.eu https://widgets.trustedshops.com https://integrations.etrusted.com *.fontawesome.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com https://plumrocket.com *.yotpo.com www.sillasdeoficina24.es www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.awin1.com *.zenaps.com *.fls.doubleclick.net secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com www.xtento.com https://plumrocket.com *.trustpilot.com *.yotpo.com gum.criteo.com ct.pinterest.com collect.trbo.com fledge.eu.criteo.com tm708.ad-srv.net td.doubleclick.net tm706.ad-srv.net tm722.ad-srv.net ad.ad-srv.net my.meetergo.com tm710.ad-srv.net tm720.ad-srv.net gumi.criteo.com static.criteo.net tm718.ad-srv.net tm701.ad-srv.net tm716.ad-srv.net tm702.ad-srv.net tm712.ad-srv.net tm723.ad-srv.net www.facebook.com tm707.ad-srv.net tm715.ad-srv.net tm711.ad-srv.net tm704.ad-srv.net tm703.ad-srv.net tm721.ad-srv.net tm719.ad-srv.net tm709.ad-srv.net www.instagram.com www.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.awin1.com *.zenaps.com *.wepowerconnections.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net https://widgets.trustedshops.com https://integrations.etrusted.com *.pixriot.com *.storeimaging.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com 'self' data: *.yotpo.com buerostuhl24.app.baqend.com www.buerostuhl24.at www.facebook.com bat.bing.net www.google.nl lantern.roeye.com bat.bing.com www.buerostuhl24.com visitor.omnitagjs.com rtb-csync.smartadserver.com r.casalemedia.com id5-sync.com x.bidswitch.net ib.adnxs.com ad.360yield.com gum.criteo.com sync-t1.taboola.com cm.g.doubleclick.net px.ads.linkedin.com img.idealo.com www.google.de a.twiago.com matching.ivitrack.com www.hjh-office.se www.buerostuhl24.ch collect.trbo.com www.bureaustoel24.nl www.google.co.in static.trbo.com contextual.media.net sync.outbrain.com match.sharethrough.com jadserve.postrelease.com sync.1rx.io exchange.mediavine.com simage2.pubmatic.com pixel.rubiconproject.com eb2.3lift.com sync-criteo.ads.yieldmo.com criteo-partners.tremorhub.com e1.emxdgt.com dis.criteo.com ad.yieldlab.net criteo-sync.teads.tv www.hjh-office.fi www.google.ch px4.ads.linkedin.com www.hjh-office.it www.google.es www.google.at s.kelkoogroup.net www.google.it pagead2.googlesyndication.com v2assets.zopim.io www.google.be data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.adyen.com tagmanager.google.com https://www.googletagmanager.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.datareporter.eu *.plugins.emarsys.net *.scarabresearch.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://widgets.trustedshops.com https://integrations.etrusted.com data.hjh-office.fr www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.gstatic.com *.trustpilot.com *.yotpo.com https://apis.google.com buerostuhl24.app.baqend.com static.zdassets.com data.buerostuhl24.com static.hotjar.com tm706.ad-srv.net tm.ad-srv.net script.hotjar.com unpkg.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://webcache.datareporter.eu d.ratepay.com d.payla.io dr.payla.io https://widgets.trustedshops.com https://integrations.etrusted.com *.fontawesome.com *.gstatic.com *.trustpilot.com *.yotpo.com webcache-eu.datareporter.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com https://www.google-analytics.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.datareporter.eu *.scarabresearch.com *.eservice.emarsys.net payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.trustedshops.com *.etrusted.com *.pixriot.com *.storeimaging.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.yotpo.com ekr.zdassets.com ct.pinterest.com hjhoffice.zendesk.com buerostuhl24.app.baqend.com data.bureaustoel24.nl wss://widget-mediator.zopim.com bat.bing.net data.hjh-office.dk px.ads.linkedin.com data.buerostuhl24.com vc.hotjar.io pagead2.googlesyndication.com data.buerostuhl24.at measurement-api.criteo.com payments-de.amazon.com data.sillasdeoficina24.es bat.bing.com data.hjh-office.fr data.hjh-office.se data.buerostuhl24.ch ct.beslist.nl ws://localhost:12387 sslwidget.criteo.com data.hjh-office.fi www.facebook.com data.hjh-office.it d158d42c.sibforms.com s.kelkoogroup.net invitejs.trustpilot.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.buerostuhl24.com/rest/all/V1/cspmanager/frontend_report; 1 default-src https:;script-src https: 'self' 'strict-dynamic' 'nonce-bb59a7d4964b9b3660dce2372ca6770ec8fdc4c183b024cc20f645f102aed502' 'unsafe-inline' 'unsafe-eval' 'report-sample';style-src https: 'unsafe-inline';img-src https: data:;connect-src https: wss:;font-src https: data:;object-src 'none';media-src https: blob: data:;frame-src https: null data: blob:;child-src 'self' https:;form-action 'self';frame-ancestors https://my.firespring.com;base-uri 'self' https://insights.sitesearch360.com;worker-src 'self' blob:;manifest-src 'self' https://cdn.firespring.com;report-uri /csp_log?n=1 1 default-src 'self'; child-src 'self'; connect-src 'self' *.cookielaw.org *.dhl.com *.onetrust.com *.obi4wan.com *.obi4wan.ai matomo.dhlexpress.nl dhl-routing.prosodie.com *.clarity.ms collector.leadinfo.net api.leadinfo.com collector4.leadinfo.net region1.analytics.google.com www.google-analytics.com google-analytics.com www.google.com www.googletagmanager.com stats.g.doubleclick.net region1.google-analytics.com googleads.g.doubleclick.net www.googleadservices.com https://matomo.dhlexpress.nl/; font-src 'self' fonts.gstatic.com; frame-src 'self' *.googletagmanager.com *.dhl.com feedback.usabilla.com *.cookielaw.org *.onetrust.com about: data: *.youtube-nocookie.com *.youtube.com https://www.google.com; img-src 'self' data: *.cookielaw.org matomo.dhlexpress.nl *.googletagmanager.com googleads.g.doubleclick.net www.google.nl fonts.gstatic.com unpkg.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io vawidget-eu.dhl.com express-resource.dhl.com cdn.leadinfo.net cdn.delivr.net www.googleadservices.com www.google.com; media-src 'self' *.youtube.com; object-src 'none'; script-src 'self' 'report-sample' *.googletagmanager.com https://vawidget-eu.dhl.com *.cookielaw.org *.onetrust.com *.mopinion.com deploy.mopinion.com matomo.dhlexpress.nl https://unpkg.com *.clarity.ms www.googletagmanager.com unpkg.com matomo.js vawidget-eu.dhl.com cdn.leadinfo.net cdn.delivr.net cdn.cookielaw.org express-resource.dhl.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io googleads.g.doubleclick.net https://cdn.cookielaw.org https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io 'unsafe-inline' https://matomo.dhlexpress.nl/; script-src-elem 'self' 'unsafe-inline' *.clarity.ms https://www.googletagmanager.com https://unpkg.com https://matomo.dhlexpress.nl/matomo.js https://vawidget-eu.dhl.com www.googletagmanager.com unpkg.com matomo.dhlexpress.nl matomo.js vawidget-eu.dhl.com cdn.leadinfo.net cdn.delivr.net cdn.cookielaw.org express-resource.dhl.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io *.cookielaw.org *.onetrust.com *.mopinion.com deploy.mopinion.com https://cdn.cookielaw.org https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io; style-src 'self' 'report-sample' 'unsafe-inline' *.clarity.ms www.googletagmanager.com unpkg.com matomo.dhlexpress.nl matomo.js vawidget-eu.dhl.com cdn.leadinfo.net cdn.delivr.net cdn.cookielaw.org express-resource.dhl.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io *.cookielaw.org *.onetrust.com *.mopinion.com deploy.mopinion.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com data: *.bglobale.com *.global-e.com maxcdn.bootstrapcdn.com *.amazonaws.com *.bootstrapcdn.com *.livechatinc.com www.softstarshoes.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.softstarshoes.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.softstarshoes.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.bglobale.com *.global-e.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.addthis.com www.softstarshoes.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bglobale.com *.global-e.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com magefan.com cm.magefan.com *.softstarshoes.com www.softstarshoes.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.bglobale.com *.global-e.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.mailchimp.com *.list-manage.com *.addthis.com *.addthisedge.com *.pinterest.com *.googletagmanager.com *.facebook.net *.google.com *.cloudflare.com chimpstatic.com *.braintreegateway.com *.cloudflareinsights.com *.livechatinc.com *.gorgias.chat www.softstarshoes.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.bglobale.com *.global-e.com assets.braintreegateway.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com www.softstarshoes.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.softstarshoes.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.addthis.com www.softstarshoes.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com www.softstarshoes.com http: https: blob: 'self' 'unsafe-inline'; default-src www.softstarshoes.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: *.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net *.stockinstore.net *.freshworks.com *.cloudflare.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net https://*.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com *.stockinstore.net *.freshworks.com *.cloudflare.com https://www.googletagmanager.com https://api.payway.com.au *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://img.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://*.cloudfront.net https://www.whitworths.com.au https://*.paypal.com https://*.zipmoney.com.au www.facebook.com *.data-dynamic.net *.stockinstore.net *.freshworks.com *.cloudflare.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.au *.googleapis.com *.gstatic.com *.trackedlink.net https://firebasestorage.googleapis.com mageside.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.ecomm-nav.com https://*.zipmoney.com.au www.facebook.com *.zdassets.com *.barilliance.com *.barilliance.net chimpstatic.com snapui.searchspring.io *.stockinstore.net *.freshworks.com *.cloudflare.com *.whitworths.com.au https://*.googletagmanager.com https://data.stats.tools *.payway.com.au https://cdn.searchspring.net/intellisuggest/is.min.js *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com data: https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net https://p.typekit.net *.stockinstore.net *.freshworks.com *.cloudflare.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com dewb2o4n4daau.cloudfront.net 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://*.cloudfront.net https://*.zip.co https://maps.googleapis.com stockinstore.net *.stockinstore.net *.freshworks.com *.cloudflare.com *.searchspring.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.au *.freshdesk.com https://beacon.searchspring.io/beacon *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.livechatinc.com email.filmtools.com *.contivio.com use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.shopperapproved.com *.facebook.com email.filmtools.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.facebook.com *.eventbrite.com docs.google.com *.livechatinc.com email.filmtools.com *.weltpixel.com *.punchout2go.com *.tradecentric.com *.googletagmanager.com *.doubleclick.net https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca *.trackedlink.net https://www.shopperapproved.com *.amazon-adsystem.com *.filmtools.com *.facebook.net *.facebook.com maps.googleapis.com maps.gstatic.com *.zmags.com bam.nr-data.net email.filmtools.com *.contivio.com *.shopperapproved.com *.answerbase.com *.reddit.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://www.shopperapproved.com https://direct.shopperapproved.com *.livechatinc.com connect.facebook.net *.eventbrite.com *.zmags.com bam.nr-data.net email.filmtools.com *.contivio.com *.shopperapproved.com *.answerbase.com https://unpkg.com *.punchout2go.com *.tradecentric.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com webchat.dotdigital.com webchat.staging.dotdigital.com *.zmags.com email.filmtools.com *.contivio.com *.shopperapproved.com *.answerbase.com use.fontawesome.com *.punchout2go.com *.tradecentric.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.livechatinc.com email.filmtools.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.doubleclick.net maps.googleapis.com *.zmags.com bam.nr-data.net *.livechatinc.com email.filmtools.com *.googlesyndication.com *.facebook.com *.shopperapproved.com *.answerbase.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: cdnjs.cloudflare.com cloud.tagbox.com *.cloudflare.com https://fonts.gstatic.com *.slant.co *.tagbox.com *.taggbox.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.google.com challenges.cloudflare.com *.cloudflare.com maps.googleapis.com maps.gstatic.com *.pinterest.com *.snapchat.com *.tagbox.com *.taggbox.com *.twitter.com www.googletagmanager.com www.youtube.com *.googleapis.com *.google.com *.weltpixel.com *.authorize.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com *.cloudflare.com fonts.googleapis.com plant.gertens.com plants.gertens.com *.qscaping.com *.snapchat.com *.tagbox.com *.taggbox.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.hsforms.net *.hsforms.com 'self' data: *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ challenges.cloudflare.com apis.google.com cdn.jsdelivr.net cloud.tagbox.com *.cloudflare.com s.pinimg.com *.pinterest.com *.shipperhq.com sc-static.net *.snapchat.com *.tagbox.com *.taggbox.com analytics.tiktok.com *.twitter.com www.google.com www.gstatic.com assets.shipperhq.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.hsforms.net *.hsforms.com *.google.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com cloud.tagbox.com *.cloudflare.com https://fonts.googleapis.com maps.googleapis.com maps.gstatic.com static.klaviyo.com *.tagbox.com *.taggbox.com *.typekit.net assets.shipperhq.com https://static.klaviyo.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.cloudflare.com *.facebook.com *.klaviyo.com *.pinterest.com *.snapchat.com *.tagbox.com *.taggbox.com *.tiktok.com www.google.com rms.shipperhq.com https://rms.shipperhq.com wss://rms.shipperhq.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net ovs.shipperhq.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com *.alothemes.com *.magepow.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.facebook.com *.dotdigital-pages.com *.dotdigital.com *.weltpixel.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com *.trackedlink.net *.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://scontent-bom1-1.cdninstagram.com/ https://scontent-bom1-2.cdninstagram.com https://scontent-bom1-2 ftcdn.net https://scontent-bom1-2.xx.fbcdn.net/ *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ email.nueskes.com connect.facebook.net script.crazyegg.com bat.bing.com em.nueskes.com dx.mountain.com js.adsrvr.org *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://apis.google.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://scontent-bom1-2.cdninstagram.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com secure.windriverfinancialgateway.com connect.facebook.net script.crazyegg.com tracking.crazyegg.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.jsdelivr.net https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.monetico-services.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.mageside.com mageside.com jeulin.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.gstatic.com sdk.privacy-center.org https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.mediascience.fr *.jsdelivr.net https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.monetico-services.com api.privacy-center.org https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.ampproject.net https://www.youtube.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://i.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.ampproject.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.ampproject.org *.ampproject.net https://connect.facebook.net https://www.google-analytics.com https://www.facebook.com/tr 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net https://www.googletagmanager.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua maps.gstatic.com 1rx.io *.1rx.io 360yield.com *.360yield.com 3lift.com *.3lift.com adnxs.com *.adnxs.com billiger.de *.billiger.de bing.com *.bing.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com google.de *.google.de idealo.com *.idealo.com media.net *.media.net omnitagjs.com *.omnitagjs.com roeye.com *.roeye.com roeyecdn.com *.roeyecdn.com sharethrough.com *.sharethrough.com smartadserver.com *.smartadserver.com taboola.com *.taboola.com teads.tv *.teads.tv tremorhub.com *.tremorhub.com twiago.com *.twiago.com uimserv.net *.uimserv.net usd.de *.usd.de usercentrics.eu *.usercentrics.eu yieldlab.net *.yieldlab.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://a.timeshop24.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com bing.com *.bing.com criteo.com *.criteo.com cdnsrv.de *.cdnsrv.de clickcease.com *.clickcease.com df-srv.de *.df-srv.de fatmedia.io *.fatmedia.io facebook.net *.facebook.net id5-sync.com *.id5-sync.com kuponacdn.de *.kuponacdn.de livechatinc.com *.livechatinc.com pinimg.com *.pinimg.com roeyecdn.com *.roeyecdn.com shopgate.com *.shopgate.com uicdn.com *.uicdn.com usercentrics.eu *.usercentrics.eu googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://www.dwin1.com https://a.timeshop24.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com livechatinc.com *.livechatinc.com pinterest.com *.pinterest.com usercentrics.eu *.usercentrics.eu *.wepowerconnections.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://a.timeshop24.de 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: ; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' ; script-src-elem 'self' https: 'unsafe-inline' 'unsafe-eval' ; style-src 'self' https: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data: ; form-action 'self' https: 'unsafe-inline' 'unsafe-eval'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://console.accessibleweb.com https://maxcdn.bootstrapcdn.com https://polyfill-fastly.io https://static.addtoany.com https://unpkg.com https://www.google.com mdbootstrap.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com https://use.fontawesome.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 object-src 'none'; base-uri 'self'; report-uri https://www.yespark.fr/csp-violation-report-endpoint 1 default-src 'self' pure.okta.com *.oktacdn.com; connect-src 'self' pure.okta.com pure-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com pure.kerberos.okta.com pure.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-iNEYkVMkLNk56kgIo0n2ow' 'unsafe-eval' 'self' 'report-sample' pure.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-iNEYkVMkLNk56kgIo0n2ow' 'self' 'report-sample' pure.okta.com *.oktacdn.com; frame-src 'self' pure.okta.com pure-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' pure.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' pure.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com *.typekit.net *.trustedshops.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.gstatic.com data: 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.syfpos.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.addthis.com *.pinterest.com syf.demdex.net *.syfpos.com *.syf.com *.trustpilot.com landofcoder.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.affirm.com *.affirm.ca *.cloudflare.com https://cdn.klarna.com *.syfpayments.com *.paypal.com https://s.ytimg.com *.usercentrics.eu yt3.ggpht.com cdn.files-text.com raw.githubusercontent.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com *.googleapis.com magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.hsforms.net *.hsforms.com 'self' data: *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com *.facebook.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.affirm.com *.affirm.ca *.cloudflare.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.pitbullaudio.com *.livechatinc.com *.recapture.io *.syfpayments.com *.elfsight.com stats.g.doubleclick.net *.braintree-api.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.recapture.io *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com *.trustpilot.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cloudflare.com stats.g.doubleclick.net *.typekit.net *.trustedshops.com *.usercentrics.eu *.syfpayments.com *.klarnacdn.net https://static.klaviyo.com *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.syfpos.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.affirm.com *.affirm.ca *.cloudflare.com stats.g.doubleclick.net *.paypal.com *.elfsight.com *.livechatinc.com *.syfpayments.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com https://app.recapture.io *.googleapis.com *.addthis.com https://graph.instagram.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net landofcoder.com *.facebook.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com googleapis.com data: https://www.googletagmanager.com *.googleapis.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.book2look.com static.addtoany.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.openstreetmap.org https://maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.tile.openstreetmap.org connect.ekomi.de google.com google.at www.google.at www.book2look.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ jquery.sellxed.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com www.google.com www.gstatic.com static.addtoany.com connect.ekomi.de cdn.public.n1ed.com appjs.blickinsbuch.de www.blickinsbuch.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.gstatic.com www.book2look.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com googleapis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com www.googleapis.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net *.openstreetmap.org https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com google-analytics.com doubleclick.net stats.g.doubleclick.net www.book2look.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=zF9PPkH4vfSdXNTVS3KhJcwa_AL2xUK3WLvt8oOXbho-1765948586-1.0.1.1-a2jxzz.RZ3u.z0FtmQjftaAqdnmFe882KsZzR1xvzy1r.gcbUv0LClWwbYFrYw6B5yBDRUk29qjkGnA7AeK0lFVVAJQBmVDaBO8VhRjKzsNxUdKsMpJ2BTgCTGpHBBk2wXqQF93j5W37aTmESoON2s_IZqAVIERlGscjt4a397nxa0gbZqg1nN38QcYs0RtE; report-to cf-csp-endpoint 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com static.rayher.com https://static.unzer.com https://applepay.cdn-apple.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action *.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * *.pinterest.com *.googletagmanager.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.clarity.ms *.rayher.com *.bing.com https://*.bing.net *.pinterest.com *.facebook.com https://www.google.com https://www.google.de https://lantern.roeye.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googleapis.com *.google.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.rayher.com *.clarity.ms *.bing.com connect.facebook.net *.pinimg.com www.dwin1.com *.taboola.com https://lantern.roeyecdn.com https://matomo.rayher.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com static.rayher.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google.com google.com *.rayher.com *.clarity.ms https://*.googlesyndication.com *.pinterest.com *.taboola.com https://*.g.doubleclick.net *.bing.com https://*.bing.net https://*.facebook.com https://*.googleapis.com https://*.mapbox.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; connect-src 'self' bwia.okta.com bwia-admin.okta.com bwlogin.iaproducers.com *.oktacdn.com *.mixpanel.com *.mapbox.com bwia.kerberos.okta.com bwia.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com; frame-src 'self' bwia.okta.com bwia-admin.okta.com bwlogin.iaproducers.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' bwia.okta.com bwlogin.iaproducers.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' bwia.okta.com bwlogin.iaproducers.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://www.bwproducers.com 1 default-src 'self'; object-src 'none'; report-to csp; report-uri https://www.taskeasy.com/utility/content-security-policy/report; 1 default-src 'self' http://cdn.auth0.com https://cdn.auth0.com https://cdn.eu.auth0.com;style-src 'self' 'unsafe-inline' https://ton.twimg.com https://platform.twitter.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' http://cdn.auth0.com https://cdn.auth0.com https://cdn.eu.auth0.com https://dalelane.eu.auth0.com http://embed-assets.wakelet.com http://platform.twitter.com https://cdn.syndication.twimg.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://browser.sentry-cdn.com https://scripts.withcabin.com/hello.js https://machinelearningforkids.co.uk;frame-src 'self' http://embed.wakelet.com https://syndication.twitter.com https://platform.twitter.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://login.machinelearningforkids.co.uk;img-src 'self' https://auth0.com http://cdn.auth0.com https://cdn.auth0.com https://cdn.eu.auth0.com https://pbs.twimg.com https://ton.twimg.com https://platform.twitter.com https://syndication.twitter.com data: blob: https://* http://*;worker-src 'self' blob:;font-src 'self' data:;connect-src 'self' https://sentry.io https://ping.withcabin.com https://mlforkids-newnumbers.j8ahcaxwtd1.au-syd.codeengine.appdomain.cloud https://mlforkids-newnumbers.j8clybxvjr0.us-south.codeengine.appdomain.cloud https://mlforkids-newnumbers.j8ayd8ayn23.eu-de.codeengine.appdomain.cloud https://mlforkids-newnumbers.1re3wh44gzos.eu-de.codeengine.appdomain.cloud https://login.machinelearningforkids.co.uk;base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests 1 script-src 'self' https://api.s10h.io/ surfly.com google.com www.google.com www.gstatic.com ajax.aspnetcdn.com cdn.moengage.com cdnjs.cloudflare.com kit.fontawesome.com maps.googleapis.com connect.facebook.net edge.fullstory.com *.googletagmanager.com *.tagmanager.google.com *.google-analytics.com *.analytics.google.com *.googleadservices.com *.g.doubleclick.net; script-src-elem 'self' 'unsafe-inline' https://api.s10h.io/ surfly.com google.com *.googletagmanager.com *.tagmanager.google.com *.google-analytics.com *.analytics.google.com *.googleadservices.com *.g.doubleclick.net bat.bing.com cdn.lr-in.com cdnjs.cloudflare.com connect.facebook.net kit.fontawesome.com edge.fullstory.com www.google-analytics.com cdn.moengage.com app-cdn.moengage.com ajax.aspnetcdn.com maps.googleapis.com www.google.com www.gstatic.com ssl.google-analytics.com translate.google.com www.googleadservices.com; style-src-elem 'self' 'unsafe-inline' surfly.com google.com fonts.bunny.net fonts.googleapis.com app-cdn.moengage.com cdnjs.cloudflare.com; style-src-attr 'unsafe-inline'; img-src 'self' data: app-cdn.moengage.com bat.bing.com www.facebook.com www.gstatic.com images.ctfassets.net maps.gstatic.com *.googletagmanager.com *.googleapis.com *.google-analytics.com *.g.doubleclick.net google.com *.google.com *.analytics.google.com stats.g.doubleclick.net image.moengage.com www.google.co.in www.google.com.au www.google.com.mx www.google.sc fonts.gstatic.com streetviewpixels-pa.googleapis.com translate.google.com api.fillr.com www.google.co.id www.google.com.br; font-src 'self' fonts.bunny.net data: app-cdn.moengage.com fonts.gstatic.com ka-p.fontawesome.com themes.googleusercontent.com; connect-src 'self' https://api.s10h.io/ surfly.com https://checkip.amazonaws.com/ app-cdn.moengage.com edge.fullstory.com ka-p.fontawesome.com kit.fontawesome.com sdk-01.moengage.com *.google-analytics.com *.analytics.google.com *.googleadservices.com *.g.doubleclick.net *.googletagmanager.com *.google.com google.com analytics.google.com adservice.google.com rs.fullstory.com bat.bing.com maps.googleapis.com dashboard-01.moengage.com properties www.facebook.com translate.googleapis.com google.com translate-pa.googleapis.com; frame-src 'self' https://www.googletagmanager.com surfly.com cdn.moengage.com td.doubleclick.net *.g.doubleclick.net google.com www.google.com gateway.zscaler.net gateway.zscalerone.net gateway.zscalerthree.net gateway.zscalertwo.net gateway.zscloud.net; worker-src 'self' blob:; frame-ancestors 'self'; media-src ; report-uri https://lendmark.report-uri.com/r/d/csp/wizard 1 font-src *.gstatic.com *.googleapis.com *.googleadservices.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com haven-bucket-pro.s3.ap-southeast-2.amazonaws.com static.afterpay.com static.sandbox.afterpay.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com chart.googleapis.com *.meetanshi.com google.com gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com td.doubleclick.net static.afterpay.com static.sandbox.afterpay.com connect.studentbeans.com form.typeform.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 5878927.fls.doubleclick.net convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms www.studentbeans.com accounts.studentbeans.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com *.googleapis.com *.ggpht.com magefan.com cm.magefan.com *.meetanshi.com maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: mc3.endota-staging.com.au mcstaging3.endota.com.au m2.getsitecontrol.com site-assets.afterpay.com site-assets.sandbox.afterpay.com email.endotaspa.com.au endotaspa.com.au www.google.com.au haven-bucket-pro.s3.amazonaws.com hubstg.endota.com.au www.google.co.in haven-bucket-pro.s3.ap-southeast-2.amazonaws.com bat.bing.com track.linksynergy.com cdn.giftflick.com.au sdk.giftflick.com.au yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com haven-bucket-pro.s3-ap-southeast-2.amazonaws.com meetanshi.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com *.googleadservices.com maps.googleapis.com chart.googleapis.com *.meetanshi.com google.com gstatic.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com tag.rmp.rakuten.com www.googleoptimize.com static.zdassets.com l.getsitecontrol.com s2.getsitecontrol.com hub-frontend.endotaspa.com.au embed.typeform.com bat.bing.com analytics.tiktok.com js-agent.newrelic.com assets.zendesk.com cdn.studentbeans.com widget-mediator.zopim.com www.giftflick.com.au giftflick.com.au sdk.giftflick.com.au yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.gstatic.com *.googleapis.com *.googleadservices.com *.stripe.network *.stripecdn.com *.amazon.com api.mapbox.com cdn.klokantech.com embed.typeform.com sdk.giftflick.com.au cdn.giftflick.com.au yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.giftflick.com.au static.zdassets.com convertexperiments.com *.convertexperiments.com clarity.ms *.clarity.ms 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com js.sandbox.afterpay.com js.afterpay.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com *.googleadservices.com maps.googleapis.com chart.googleapis.com *.meetanshi.com google.com gstatic.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com l.getsitecontrol.com ekr.zdassets.com events.getsitectrl.com cdn.klokantech.com api.maptiler.com admin3.endota-staging.com.au admin.endota.com.au stats.g.doubleclick.net staging.admin.endota.com.au endota.zendesk.com widget-mediator.zopim.com bam.nr-data.net tools.endota.com.au geocoder.tilehosting.com wss://widget-mediator.zopim.com bat.bing.com api.giftflick.com.au cdn.giftflick.com.au analytics.tiktok.com static.sandbox.afterpay.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com weltpixelhelp.zendesk.com api.typeform.com www.google.com convertexperiments.com *.convertexperiments.com www.google.co.in clarity.ms *.clarity.ms www.studentbeans.com accounts.studentbeans.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors https://www.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://widget.trustpilot.com https://consentcdn.cookiebot.com/ https://www.googletagmanager.com/ *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.gransier.nl www.2wheelshop.eu https://imgsct.cookiebot.com *.sooqr.com *.spotlersearch.com maps.gstatic.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.google.com widget.freshworks.com m2epro.freshdesk.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io https://widget.trustpilot.com https://consent.cookiebot.com https://pagead2.googlesyndication.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com maps.googleapis.com www.gstatic.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.fontawesome.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sooqr.com *.spotlersearch.com maxcdn.bootstrapcdn.com www.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com stats.g.doubleclick.net widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io https://pagead2.googlesyndication.com https://www.googletagmanager.com/ *.sooqr.com *.spotlersearch.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.gstatic.com fonts.googleapis.com celebrosnlp.com cdnjs.cloudflare.com assets.reviews.io Source-search.celebros.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors cdn.jsdelivr.net *.twyn.com *.tawk.to wss://*.tawk.to 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ secure.novalnet.de customers.barzahlen.de customers-sandbox.barzahlen.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://sandbox.crefopay.de https://api.crefopay.de *.amazon.com *.payments-amazon.com *.wesupply.xyz https://wesupplylabs.com *.tawk.to cdn.jsdelivr.net *.twyn.com tawk.to wss://*.tawk.to *.facebook.com *.doubleclick.net *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.payments-amazon.com *.media-amazon.com www.gstatic.com wss://*.tawk.to *.tawk.to tawk.link cdn.jsdelivr.net *.source-werbeartikel.com www.google.ge *.tawk.link bat.bing.com brandingcalculator.source-werbeartikel.com app.promotron.com *.facebook.com *.google.pl *.google.de px.ads.linkedin.com assets.reviews.io *.analytics.google.com *.gstatic.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com celebrosnlp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.novalnet.de cdn.barzahlen.de applepay.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.payments-amazon.com https://sandbox.crefopay.de/ https://api.crefopay.de https://code.jquery.com/jquery-3.3.1.min.js https://cdnjs.cloudflare.com/ajax/libs/jquery.maskedinput/1.4.1/jquery.maskedinput.js *.cloudflare.com *.convertexperiments.com tawk.to *.tawk.to https://www.googletagmanager.com https://www.google.com/pagead/ twyn.com *.twyn.com cdn.jsdelivr.net ai2.celebros-analytics.com app.promotron.com cdn.mouseflow.com www.gstatic.com bat.bing.com connect.facebook.net cdn.leadinfo.net snap.licdn.com *.source-werbeartikel.com *.data.source-werbeartikel.com *.klaviyo.com *.clarity.ms widget.reviews.io js.intercomcdn.com widget.intercom.io *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com unpkg.com *.doubleclick.net pantone-color.source-werbeartikel.com celebrosnlp.com ai.celebros-analytics.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.convertexperiments.com https://embed.tawk.to *.tawk.to fonts.googleapis.com cdnjs.cloudflare.com assets.reviews.io app.intercom.com widget.reviews.io *.reviews.io *.tagmanager.google.com *.googletagmanager.com pantone-color.source-werbeartikel.com celebrosnlp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com embed.tawk.to *.tawk.to tawk.link *.twyn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com payport.novalnet.de secure.novalnet.de api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://sandbox.crefopay.de https://api.crefopay.de *.amazon.com *.tawk.to wss://*.tawk.to *.twyn.com *.doubleclick.net *.leadinfo.net *.googleadservices.com www.google.com www.google.ge *.leadinfo.com stats.g.doubleclick.net app.promotron.com tagging.source-werbeartikel.com *.google.pl *.google.de *.google-analytics.com *.mouseflow.com *.source-werbeartikel.com *.ads.linkedin.com *.linkedin.com *.klaviyo.com *.clarity.ms api.reviews.io widget.reviews.io api-iam.intercom.io bat.bing.com lg.hyr.so wss://*.intercom.io *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.run.app pantone.develop stage-pantone-color.source-werbeartikel.com pantone-color.source-werbeartikel.com *.celebros.com *.celebros.com:446 *.celebros-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.convertexperiments.com stats.g.doubleclick.net *.tawk.to *.source-werbeartikel.com collector.leadinfo.net api.leadinfo.com bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https://www.google.com chrome-extension: 'unsafe-eval' 'unsafe-inline' 'unsafe-inline' https://yastatic.net https://www.googletagmanager.com https://api-maps.yandex.ru https://www.gstatic.com 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://mc.yandex.ru chrome-extension: https://www.facebook.com https://www.googletagmanager.com; object-src 'self'; report-uri /cspreportonly; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://challenges.cloudflare.com https://ajax.cloudflare.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https: https://challenges.cloudflare.com; media-src 'self' https: blob:; worker-src 'self' blob:; frame-src 'self' https://www.googletagmanager.com https://challenges.cloudflare.com/ https://player.vimeo.com https://vimeo.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.fontawesome.com *.klaviyo.com *.hotjar.com *.paypalobjects.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com js.mollie.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.bing.com *.brandlock.io c.clarity.ms a.omappapi.com *.hotjar.com *.comboink.com *.compandsave.com *.tomatoink.com *.amazonaws.com *.cloudfront.net *.cloudflare.com https://shareasale.com https://shareasales.com et.resellerratings.com cdn-assets.affirm.com lantern.roeyecdn.com lantern.roeye.com *.google.com stats.g.doubleclick.net https://firebasestorage.googleapis.com https://images.unsplash.com magefan.com cm.magefan.com https://www.mollie.com www.google.com.ua https://load.yqxg4.compandsave.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.noibu.com *.zdassets.com *.gstatic.com *.clarity.ms *.bing.com *.hotjar.com *.compandsave.com *.pinimg.com *.omappapi.com *.klaviyo.com *.rudderlabs.com *.zendesk.com *.googleapis.com *.pinterest.com https://portal.afterpay.com *.rudderstack.com *.resellerratings.com *.brevo.com https://sibautomation.com https://www.dwin1.com lantern.roeyecdn.com *.avada.io *.shopify.com https://maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com js.mollie.com https://load.yqxg4.compandsave.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app assets.braintreegateway.com *.fontawesome.com *.omappapi.com *.typekit.net *.klaviyo.com cdn.jsdelivr.net https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.noibu.com wss://input.noibu.com *.pinterest.com *.clarity.ms *.zdassets.com *.rudderstack.com *.zendesk.com *.omappapi.com *.doubleclick.net *.zopim.com wss://widget-mediator.zopim.com *.googleapis.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com wss://pod-13.zendesk.com https://portal.afterpay.com *.brandlock.io *.algolia.io *.gstatic.com *.resellerratings.com dp70uvwpivouv.cloudfront.net https://in-automate.brevo.com https://fast.a.klaviyo.com https://static-forms.klaviyo.com yqxg4.compandsave.com https://get.geojs.io *.avada.io https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://load.yqxg4.compandsave.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://fresh-tracks-canada.uriports.com/reports/report; report-to default 1 font-src https://cdn.riverty.design/ *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ uc8.tv https://documents.riverty.com/ consentcdn.cookiebot.com https://www.googletagmanager.com/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src cdn.annadiva.nl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ *.googleapis.com https://*.gstatic.com imgsct.cookiebot.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com *.multisafepay.com maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ *.googleapis.com https://*.gstatic.com https://widget-acc.paazl.com www.googleoptimize.com d36mpcpuzc4ztk.cloudfront.net consent.cookiebot.com consentcdn.cookiebot.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.voyado.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.multisafepay.com https://pay.google.com maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://widget-acc.paazl.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ *.googleapis.com https://widget-acc.paazl.com chat.freshdesk.com consentcdn.cookiebot.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'self' https://payments.salesforce.com/ https://stats.g.doubleclick.net https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://cdn.cookielaw.org https://code.jquery.com/ https://checkoutshopper-live.adyen.com/ https://www.avrfreaks.net https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://assets.adobedtm.com https://microchip.data.adobedc.net https://pay.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://dpm.demdex.net blob: https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://microchip--forumdev1--c.visualforce.com/resource https://cdn.mouseflow.com https://microchip.tt.omtrdc.net import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval'; report-to sfdc-csp-ep; report-uri https://microchip.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Do0000000KAkK&networkId=0DM3l000000TRuT&type=communities 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.webwinkelkeur.nl maxcdn.bootstrapcdn.com static.lipscore.com *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.google.nl *.webwinkelkeur.nl *.usercentrics.eu img.sct.eu1.usercentrics.eu bat.bing.net bat.bing.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.demdex.net id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.1rx.io sync.targeting.unrulymedia.com magefan.com cm.magefan.com *.disqus.com static.lipscore.com blob: img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com *.dhlecommerce.nl *.cookiebot.eu *.cookiebot.com *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.calendly.com *.beslist.nl *.pinimg.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.pinterest.com *.disqus.com static.lipscore.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com widget.tagembed.com api.taggbox.com cdn.tagbox.com static.dhlecommerce.nl maxcdn.bootstrapcdn.com static.lipscore.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.pinterest.com *.criteo.com *.beslist.nl widget.tagembed.com api.taggbox.com cdn.tagbox.com wapi.lipscore.com users.lipscore.com *.pay.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.halfords.nl/paynl/csp/report; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.doubleclick.net *.onetrust.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://images.unsplash.com *.ctfassets.net *.arvesta.eu *.google.be *.adnxs.com *.bing.com *.gstatic.com *.googleapis.com *.cookielaw.org *.facebook.com *.clarity.ms *.onetrust.com https://www.mollie.com 'self' data: *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://maps.googleapis.com *.hotjar.com *.googleoptimize.com *.bing.com *.facebook.net *.adnxs.com gtmadapter-node-cbjg5cz5hq-ew.a.run.app *.clarity.ms *.googleapis.com *.npmcdn.com *.convertexperiments.com *.cookielaw.org *.onetrust.com *.voyado.com js.mollie.com *.google.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.typekit.net *.npmcdn.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://core.helloretail.com https://helloretailcdn.com https://maps.googleapis.com https://player.vimeo.com *.cookielaw.org *.doubleclick.net *.clarity.ms gtmadapter-node-cbjg5cz5hq-ew.a.run.app *.googleapis.com *.npmcdn.com *.hotjar.com *.onetrust.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: ace.de *.ace.de ace-clubinitiative.de *.ace-clubinitiative.de 360yield.com 3lift.com adform.net adnxs.com adsrvr.org agkn.com bidr.io bidswitch.net bing.com bugsnag.com bussgeldrechner.org casalemedia.com clarity.ms clmbtech.com co.kr cookielaw.org criteo.com *.criteo.com demdex.net dmxleo.com doubleclick.net *.doubleclick.net dwin1.com facebook.net *.facebook.net finanzcheck.de *.finanzcheck.de fwmrm.net ggpht.com google.com *.google.com googleadservices.com googlesyndication.com googletagmanager.com *.googletagmanager.com gsitrix.com gstatic.com *.gstatic.com ioadentifi.com *.ioadentifi.com liadm.com media.net mediavine.com mediawallahscript.com outbrain.com pippio.com postrelease.com pubmatic.com revcontent.com rezync.com rfihub.com roeye.com roeyecdn.com rubiconproject.com smartadserver.com springserve.com stape.net stapecdn.com stickyadstv.com taboola.com tapad.com teads.tv thrtle.com tpmn.io tremorhub.com turn.com ubembed.com unrulymedia.com usemaxserver.de *.usemaxserver.de w55c.net yahoo.com *.yahoo.com youtube.com *.youtube.com ytimg.com; frame-ancestors 'self' ace.de *.ace.de ace-clubinitiative.de *.ace-clubinitiative.de; 1 default-src 'self' bard.edu www.bard.edu inside.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org; form-action 'self' bard.edu www.bard.edu tools.bard.edu connect.bard.edu opensocietyuniversitynetwork.org ghea21.org; base-uri 'self' bard.edu www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org; font-src 'self' data: www.bard.edu opensocietyuniversitynetwork.org ghea21.org fonts.gstatic.com *.fontawesome.com cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org fonts.googleapis.com *.fontawesome.com tagmanager.google.com www.google.com *.technolutions.net static.ctctcdn.com cdnjs.cloudflare.com *.curator.io; script-src 'self' 'unsafe-inline' 'report-sample' www.bard.edu tools.bard.edu connect.bard.edu explore.bard.edu opensocietyuniversitynetwork.org ghea21.org code.jquery.com player.vimeo.com *.fontawesome.com www.google-analytics.com ssl.google-analytics.com *.googletagmanager.com tagmanager.google.com www.google.com cse.google.com googleads.g.doubleclick.net connect.facebook.net consent.cookiebot.com cdn.unibuddy.co www.youvisit.com *.technolutions.net analytics.tiktok.com *.curator.io; img-src 'self' data: bard.edu www.bard.edu inside.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org www.facebook.com trck.youvisit.com ssl.gstatic.com www.gstatic.com www.google.com *.google-analytics.com *.googletagmanager.com curator-assets.b-cdn.net; connect-src 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org *.google-analytics.com *.analytics.google.com analytics.google.com www.google.com *.googletagmanager.com *.doubleclick.net *.technolutions.net analytics.tiktok.com *.curator.io; media-src 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org player.vimeo.com *.vimeocdn.com www.buzzsprout.com curator-assets.b-cdn.net; object-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org; child-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org www.youtube.com www.youtube-nocookie.com player.vimeo.com unibuddy.co popcard.unibuddy.co cdn.youvisit.com e.issuu.com; frame-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org www.youtube.com www.youtube-nocookie.com player.vimeo.com *.googletagmanager.com *.doubleclick.net unibuddy.co popcard.unibuddy.co cdn.youvisit.com e.issuu.com; frame-ancestors 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org; 1 base-uri 'self'; form-action 'self' https://forms.hsforms.com/; frame-ancestors 'self' https://form.texarkanacollege.edu; connect-src https://api.hubapi.com https://stats.g.doubleclick.net https://forms.hubspot.com https://api.hubspot.com https://www.google-analytics.com https://hubspot-forms-static-embed.s3.amazonaws.com https://maps.googleapis.com https://td.doubleclick.net/; default-src 'none'; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://app.hubspot.com https://js.hsforms.net https://www.google.com https://bid.g.doubleclick.net https://td.doubleclick.net/ https://www.googletagmanager.com/; img-src 'self' https://track.hubspot.com https://www.google.com https://www.google-analytics.com https://www.youtube.com https://perf.hsforms.com; media-src 'self' https://www.youtube.com https://vimeo.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://www.google-analytics.com https://www.gstatic.com https://www.google.com https://js.hsforms.net https://js.hs-analytics.net https://js-na1.hs-scripts.com https://js.hsleadflows.net https://js.hsadspixel.net https://js.hs-banner.com https://js.usemessages.com/ https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://forms.hsforms.com; script-src-elem 'self' 'unsafe-inline' https://www.gstatic.com https://www.google.com https://www.google-analytics.com https://js.hsforms.net https://js.hs-analytics.net https://js-na1.hs-scripts.com https://js.hsleadflows.net https://js.hsadspixel.net https://js.hs-banner.com https://js.usemessages.com/ https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://forms.hsforms.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com ; 1 report-to slardar-endpoint; script-src 'unsafe-eval' 'report-sample' 'nonce-e73058afe9fa8ed0bead7a7768e4f9a5-argus' 'strict-dynamic'; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-to csp-endpoint 1 script-src-elem 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem 'self' 'unsafe-inline'; font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.stripe.com www.inweddingdress.com 'self' 'unsafe-inline'; form-action *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.google.com *.addthis.com *.pinterest.com *.stripe.com *.paypal.com www.youtube.com 'self' 'unsafe-inline'; img-src data: * 'self' 'unsafe-inline'; script-src www.paypalobjects.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.stripe.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com https://graph.instagram.com *.stripe.com www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src https: 'unsafe-inline'; report-uri https://api.mp.pl/csp-violation/ 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://mychart-nchmd.org https://nchmd.org https://nchstaging.wpengine.com;frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-2922d47bf34f497593bf235e82339a5c' https://mychart-nchmd.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart-nchmd.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self'; img-src 'self' data: https://www.datocms-assets.com https://image.mux.com https://*.usercentrics.eu https://app.usercentrics.eu https://*.myshopify.com https://cdn.shopify.com; script-src 'self' https://www.googletagmanager.com https://web.cmp.usercentrics.eu http://privacy-proxy.usercentrics.eu 'unsafe-inline' https://*.usercentrics.eu https://app.usercentrics.eu https://www.google.com https://app.cituro.com https://wtb-tag.mikmak.ai https://www.gstatic.com; style-src 'self' 'unsafe-inline'; font-src 'self' https: data:; connect-src 'self' https://www.googletagmanager.com https://stream.mux.com http://privacy-proxy.usercentrics.eu https://privacy-proxy.usercentrics.eu https://v1.api.service.cmp.usercentrics.eu https://*.usercentrics.eu https://app.usercentrics.eu https://app.cituro.com https://www.google.com https://www.google.com/* https://ricolagroupag--devservice.sandbox.my.salesforce.com https://*.mux.com https://*.myshopify.com; frame-src https://www.googletagmanager.com https://web.cmp.usercentrics.eu https://*.usercentrics.eu https://app.usercentrics.eu https://app.cituro.com https://www.google.com https://www.google.com/* https://*.myshopify.com; media-src 'self' blob: https://stream.mux.com https://*.usercentrics.eu https://app.usercentrics.eu https://*.myshopify.com; report-uri /.netlify/functions/csp-reporting-endpoint; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=3ckCmjJH68g0yqOoH1EsQuIfuingtRNbG2Sylkr_MbDFxipaO0zJGS3VWfRz87bAqBs=&policy_id=71&user_id=&request_id=5bc76fdb-a00f-4d60-92a1-f29b81e0845c; report-to csp-endpoint-ckcmjjhgyqoohesquifuingtrnbgsylkrmbdfxipaozjgsvwfrzbaqbs; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net 'self' data: js.klevu.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de 'self' www.google.com 'self' *.affirm.com 'self' *.vimeo.com 'self' *.sharethis.mgr.consensu.org 'self' *.sharethis.com drive.google.com *.wufoo.com *.paypal.com *.braintreegateway.com *.dnky.co *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com hello.zonos.com js.klevu.com *.paypal.com cdn.datamanager.arinet.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de chimpstatic.com *.adroll.com *.adroll.mgr.consensu.org *.facebook.net *.affirm.com *.gstatic.com www.google.com *.sharethis.com *.wufoo.com *.linkedin.com *.licdn.com js.klevu.com hello.zonos.com cdn.iglobalstores.com assets.shipperhq.com *.paypal.com *.trackedlink.net *.dnky.co js-agent.newrelic.com bam.nr-data.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com maps.googleapis.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com 'self' *.sharethis.com *.licdn.com js.klevu.com assets.shipperhq.com *.dnky.co cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.adroll.com *.doubleclick.net 'self' *.sharethis.com hello.zonos.com rms.shipperhq.com wss://rms.shipperhq.com *.braintree-api.com *.paypal.com *.braintreegateway.com *.dotdigital.com *.ksearchnet.com bam.nr-data.net maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google.com google.com ovs.shipperhq.com wss://rms.shipperhq.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.example.com/; report-to report-endpoint; 1 default-src 'none' form-action 'none' frame-ancestors 'self' https://*.blackbookcloud.com; report-uri https://blackbook.report-uri.com/r/d/csp/enforce 1 default-src 'self' http: https: data: blob: 'unsafe-eval' 'unsafe-inline'; frame-ancestors 'self' https://*.test.voxteneo.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.googleapis.com *.fontawesome.com *.bootstrapcdn.com https://fonts.gstatic.com https://static.payzen.eu/static/ *.twimg.com *.trustedshops.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.twitter.com *.addthis.com https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: blob: *.cloudflare.com *.www.googleadservices.com *.www.google-analytics.com *.twitter.com *.assets.adobedtm.com *.amcglobal.sc.omtrdc.net *.dpm.demdex.net *.cm.everesttech.net *.widgets.magentocommerce.com *.googleads.g.doubleclick.net *.bid.g.doubleclick.net *.analytics.google.com *.t.paypal.com *.fpdbs.paypal.com *.fpdbs.sandbox.paypal.com *.i.ytimg.com *.validator.swagger.io *.klarna.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.b.stats.paypal.com *.dub.stats.paypal.com *.assets.braintreegateway.com *.c.paypal.com *.checkout.paypal.com *.mcstaging.alcarrito.com https://cdn-int.safecharge.com https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://secure.safecharge.com/ https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ *.hsforms.net *.hsforms.com *.www.google.com.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cloudflare.com *.twitter.com *.google-analytics.com *.fontawesome.com apis.google.com code.iconify.design *.geostag.cardinalcommerce.com *.1eafstag.cardinalcommerce.com *.geoapi.cardinalcommerce.com *.1eafapi.cardinalcommerce.com *.songbird.cardinalcommerce.com *.includestest.ccdc02.com *.googleadservices.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.t.paypal.com *.s.ytimg.com *.googleapis.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.trackedlink.net *.js.braintreegateway.com *.assets.braintreegateway.com *.c.paypal.com *.pay.google.com *.api.braintreegateway.com *.api.sandbox.braintreegateway.com *.client-analytics.braintreegateway.com *.client-analytics.sandbox.braintreegateway.com *.songbirdstag.cardinalcommerce.com https://magento.com https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://cdn-int.safecharge.com https://play.google.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.twimg.com *.hsforms.net *.hsforms.com *.chart.apis.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.fontawesome.com *.bootstrapcdn.com https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://fonts.googleapis.com https://static.payzen.eu/static/ *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.cdn.connectif.cloud 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflare.com *.twitter.com *.operacionmayo.com *.audiosmadres.onrender.com https://sdkmon.safecharge.com https://ppp-test.safecharge.com https://ppp-test.nuvei.com https://secure.safecharge.com https://play.google.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://unpkg.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://unpkg.com *.typekit.net *.certcapture.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; frame-src youtube.com vimeo.com; base-uri 'self'; report-uri https://webhook.site/csf-webhook 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: logger.scot.nhs.uk *.fontawesome.com use.typekit.net *.google.com *.google.co.uk *.googleapis.com themes.googleusercontent.com *.gstatic.com code.jquery.com yui.yahooapis.com *.bootstrapcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com www.youtube-nocookie.com player.vimeo.com i.vimeocdn.com cdn.jwplayer.com content.jwplatform.com prd.jwpltx.com *.jwpcdn.com *.jwpsrv.com *.civiccomputing.com cc.cdn.civiccomputing.com secure.gravatar.com public.tableau.com www.openstreetmap.org browser-update.org s.w.org www.geoplugin.net *.wp.com hcaptcha.com *.hcaptcha.com www.careopinion.org.uk www.patientopinion.org.uk assets.nhs.uk www.travelinescotland.com *.nhslothian.scot *.nhslothian.scot.nhs.uk secure.worldpay.com www.dermatology.nhs.scot noop.style; worker-src 'self' www.google.com; frame-ancestors 'self'; base-uri 'self'; report-to csp-endpoint; report-uri https://web-reports.scot.nhs.uk/api/v1/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com consentcdn.cookiebot.com https://*.dpdconnect.nl www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://belco-prod.s3-eu-central-1.amazonaws.com https://images.unsplash.com imgsct.cookiebot.com s.w.org bat.bing.com www.google.nl ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.belco.io consent.cookiebot.com consentcdn.cookiebot.com js-agent.newrelic.com ct.beslist.nl www.gstatic.com/recaptcha/ www.google.com/recaptcha/ cdn.belco.io *.dpdconnect.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com static.klaviyo.com https://static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com/ a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com integrations.etrusted.com integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com analytics.tiktok.com www.clarity.ms cdn.leadinfo.net www.clickcease.com bat.bing.com https://*.dpdconnect.nl https://static.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://pay.google.com https://integrations.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.googleapis.com downloads.mailchimp.com https://static.klaviyo.com *.storyblok.com *.multisafepay.com assets.braintreegateway.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com wss://chat.belco.io https://cdn.belco.io consentcdn.cookiebot.com 1.1.1.1/ *.leadinfo.net api.leadinfo.com bat.bing.net bat.bing.com analytics.tiktok.com s.clarity.ms https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src https://www.stokesstores.com/ https://load.measure.stokesstores.com/ https://apis.google.com/ https://static.klaviyo.com/ https://api.heyday.ai/ https://static-tracking.klaviyo.com/ https://cdn.attn.tv/ https://bat.bing.com/ https://www.clarity.ms/ https://pixel.byspotify.com/ https://woobox.com/ https://input.noibu.com/ https://cdn.noibu.com/ https://js-agent.newrelic.com/; style-src 'self' blob: https: 'unsafe-inline' https://www.stokesstores.com/; img-src data: http: https:; object-src 'none'; base-uri 'none'; child-src 'self'; font-src 'self' fonts.gstatic.com static.klaviyo.com; frame-src assets.braintreegateway.com www.google.com www.youtube.com www.youtu.be www.vimeo.com https://creatives.attn.tv https://webchat.heyday.ai 1 connect-src 'self' *.njea.org fastaction.ngpvan.com ka-p.fontawesome.com maps.googleapis.com njea.us-6.evergage.com secure.ngpvan.com www.facebook.com www.google-analytics.com advocator.ngpvan.com rum.browser-intake-us5-datadoghq.com addressvalidation.googleapis.com region1.google-analytics.com clientstream.launchdarkly.com d2rol5dpdbtxxu.cloudfront.net overbridgenet.com properties readaloud.googleapis.com translate.googleapis.com www.googletagmanager.com d3hb14vkzrxvla.cloudfront.net embedr.flickr.com my.yoast.com oob.script.ac static.everyaction.com; font-src 'self' data: fonts.gstatic.com ka-p.fontawesome.com static.everyaction.com cdnjs.cloudflare.com cdn.fontshare.com maxcdn.bootstrapcdn.com njea.us-6.evergage.com; form-action 'self' *.njea.org njea.microsearch.net www.facebook.com sendy.njeasites.net; frame-ancestors 'self'; frame-src 'self' players.brightcove.net player.vimeo.com static.deledao.com www.youtube.com platform.twitter.com useast2-www.securly.com www.facebook.com *.njea.org blob: *.njea.org pixel-sync.sitescout.com app.njea.civicengine.com authenticate.ibotta.com useast-www.securly.com www.google.com; img-src 'self' blob: d3rse9xjbp8270.cloudfront.net data: fonts.gstatic.com maps.googleapis.com maps.gstatic.com *.njea.org pixel.sitescout.com secure.gravatar.com secure.ngpvan.com www.facebook.com www.googletagmanager.com www.njeaconvention.org nvadvimg.blob.core.windows.net static.everyaction.com cdn.gravity.com cdn.honey.io connect.facebook.net d1aqhv4sn5kxtx.cloudfront.net s.w.org translate.google.com code.jquery.com connect.advancedcustomfields.com gravitywiz.com i.vimeocdn.com khms0.googleapis.com khms1.googleapis.com live.staticflickr.com pd.w.org ps.w.org theeventscalendar.com www.admincolumns.com www.relevanssi.com; object-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' app.njea.civicengine.com *.njea.org cdn.evgnet.com cdn.jsdelivr.net connect.facebook.net js.verygoodvault.com kit.fontawesome.com maps.googleapis.com static.everyaction.com www.googletagmanager.com d3rse9xjbp8270.cloudfront.net platform.twitter.com blob: cdn.evergage.com infird.com njea.us-6.evergage.com sc-static.net up.pixel.ad beacon-v2.helpscout.net cdnjs.cloudflare.com embedr.flickr.com secured-pixel.com widgets.flickr.com yoast.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' www.googletagmanager.com cdn.evgnet.com connect.facebook.net kit.fontawesome.com app.njea.civicengine.com js.verygoodvault.com maps.googleapis.com static.everyaction.com *.njea.org up.pixel.ad; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' app.njea.civicengine.com cdn.jsdelivr.net fonts.googleapis.com static.everyaction.com blob: cdn.honey.io maxcdn.bootstrapcdn.com njea.us-6.evergage.com nvlupin.blob.core.windows.net www.gstatic.com ajax.googleapis.com code.jquery.com; style-src 'self' fonts.googleapis.com 'unsafe-inline' app.njea.civicengine.com static.everyaction.com; worker-src 'self' blob: data:;report-uri https://3cb976b9b941b9481fde11b688309e13.report-uri.com/r/d/csp/wizard 1 script-src-elem *.eu-6.magentosite.cloud *.lamaisonvalmont.com *.bglobale.com *.global-e.com *.payments-amazon.com *.cookielaw.org *.abtasty.com *.bing.com *.clarity.ms *.doubleclick.net *.facebook.net *.googletagmanager.com *.rakuten.com *.tkrconnector.com googleapis.com *.googleapis.com 'self' 'unsafe-inline'; font-src *.bglobale.com *.global-e.com *.fontawesome.com *.gstatic.com 'self' data: *.cloudflare.com *.makeupar.com *.rakuten.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com *.global-e.com *.americanexpress.com *.arcot.com *.creditmutuel.fr *.mercurypaymentservices.it *.nexi.it *.nexigroup.com *.redsys.es *.rsa3dsauth.co.uk *.rsa3dsauth.com *.securesuite.co.uk *.securesuite.net *.cardinalcommerce.com facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com www.google.com *.bglobale.com *.global-e.com checkout.postfinance.ch fragranceprofiler-storieveneziane.com *.qualifioapp.com *.sproutvideo.com *.timify.com *.webotit.ai *.3dsecure-csas.cz *.americanexpress.com *.arcot.com *.asseco-see.hr *.cardinalcommerce.com *.cic.fr *.cooppank.ee *.creditmutuel.fr *.dnp-cdms.jp *.mercurypaymentservices.it *.nexi.it *.redsys.es *.rsa3dsauth.co.uk *.rsa3dsauth.com *.secure.lcl.fr *.securesuite.net *.sparkasse.at *.criteo.com *.criteo.net doubleclick.net *.doubleclick.net facebook.com *.facebook.com *.googlesyndication.com tracead.com *.tracead.com *.trustcommander.net tk.lamaisonvalmont.com youtu.be *.youtu.be youtube-nocookie.com pay.google.com *.nexigroup.com *.securesuite.co.uk *.wlp-acs.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com *.bglobale.com *.global-e.com https://images.unsplash.com checkout.postfinance.ch 'self' data: s3s.fr *.s3s.fr *.amazonaws.com *.makeupar.com *.shipup.co *.googleusercontent.com adsrvr.org *.adsrvr.org *.baidu.com bing.com *.bing.com boxclone.com *.clarity.ms *.criteo.net http://sync.commander1.com/ commander1.com *.commander1.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com *.facebook.net *.fillr.com goldenbees.fr *.goldenbees.fr google-analytics.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com linksynergy.com *.linksynergy.com sync.smartadserver.com tagcommander.com *.tagcommander.com *.tiktok.com *.trustcommander.net *.google.ad *.google.ae *.google.af *.google.ag *.google.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.nr-data.net abtasty.com *.abtasty.com quanta.io *.quanta.io google.com *.google.com *.googleapis.com gstatic.com *.gstatic.com lamaisonvalmont.com *.lamaisonvalmont.com *.cookielaw.org data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.adyen.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bglobale.com *.global-e.com https://maps.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ checkout.postfinance.ch *.google.com *.gstatic.com *.tagcommander.com *.trustcommander.net *.amazonaws.com *.cloudflare.com *.makeupar.com *.qualifio.com *.qualifioapp.com *.rewardstyle.com *.shipup.co *.timify.com *.webotit.ai adition.com *.adition.com adnxs.com *.adnxs.com adventori.com *.adventori.com bing.com *.bing.com boxclone.com clarity.ms *.clarity.ms commander1.com *.commander1.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.net *.facebook.net *.giocdn.com googleadservices.com *.googleadservices.com *.googlesyndication.com hublosk.com jullyambery.net nxtck.com *.nxtck.com rakuten.com *.rakuten.com tiktok.com *.tiktok.com tracead.com *.tracead.com conoret.com newrelic.com nr-data.net *.hotjar.com *.tkrconnector.com abtasty.com *.abtasty.com quanta.io *.quanta.io googleapis.com *.googleapis.com youtube.com *.cookielaw.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.bglobale.com *.global-e.com *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudflare.com *.shipup.co 'self' 'unsafe-inline'; object-src *.youtube.com 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ t.elasticsuite.io *.google-analytics.com *.trustcommander.net fondationvalmont.com *.cloudflare.com *.ipify.org *.makeupar.com *.shipup.co *.valmontcosmetics.com *.global-e.com *.hotjar.com wss://*.hotjar.com *.tkrconnector.com bing.com *.bing.com commander1.com *.commander1.com clarity.ms *.clarity.ms *.doubleclick.net *.facebook.com google.com *.google.com *.googlesyndication.com *.googletagmanager.com *.stape.net tiktok.com *.tiktok.com tk.lamaisonvalmont.com yandex.ru *.google.ad *.google.ae *.google.af *.google.ag *.google.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw nr-data.net abtasty.com *.abtasty.com *.hotjar.io noembed.com *.noembed.com quanta.io *.quanta.io plyr.io *.plyr.io googleapis.com *.googleapis.com *.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://valmont.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://js.stripe.com/ https://static.cloudflareinsights.com/ https://az416426.vo.msecnd.net/scripts/a/ https://www.googletagmanager.com/gtag/ https://www.google-analytics.com/analytics.js; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com/ https://fonts.googleapis.com/; img-src 'self' data: https://www.aisolutions.co.uk/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://i.ytimg.com/vi/; font-src 'self' https://fonts.gstatic.com/ https://cdnjs.cloudflare.com/; frame-src 'self' https://www.youtube.com/ https://www.youtube-nocookie.com/ https://www.google.com/ https://js.stripe.com/; connect-src 'self' https://www.googleapis.com/customsearch/ https://www.google.com/recaptcha/ https://apps.toolkitcs.com/log/ https://dc.services.visualstudio.com/v2/ https://7ixtke6ehh.execute-api.us-east-1.amazonaws.com/prod https://region1.google-analytics.com/ https://www.google-analytics.com/; upgrade-insecure-requests; block-all-mixed-content; base-uri 'self'; report-to report-to-ais; report-uri https://r.aisns.uk/u/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.googletagmanager.com *.facebook.net www.termsfeed.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-fcww87obU9M8S4QWA9nagw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 worker-src https://ecom.dev.acima.in https://ecom.sandbox.acima.in https://ecom.learning.acima.in https://ecom.preflight.acima.in https://ecom.acima.com https://ecom.acimacredit.com blob:; font-src *.fontawesome.com *.affirm.com *.bolt.com *.livechatinc.com *.reviews.io *.klaviyo.com *.cloudfront.net *.reviews.co.uk https://fonts.gstatic.com maxcdn.bootstrapcdn.com https://d1cwup7r903a1d.cloudfront.net fonts.gstatic.com www.elementwheels.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk *.facebook.com www.elementwheels.com 'self' 'unsafe-inline'; frame-ancestors www.elementwheels.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.bolt.com *.facebook.com *.google.com *.hotjar.com *.livechatinc.com *.paytomorrow.com *.reviews.io *.reviews.co.uk *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.elementwheels.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com validate.fishpig.co.uk *.aggle.net *.bing.com *.bolt.com *.clarity.ms *.facebook.com *.google.com *.inspectlet.com *.livechatinc.com *.livechat-files.com *.reviews.io *.ytimg.com *.paytomorrow.com cdn.files-text.com *.cloudfront.net *.reviews.co.uk https://helloextend-static-assets.s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net www.elementwheels.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://localhost:9002 https://ecom.dev.acima.in https://ecom.sandbox.acima.in https://ecom.sandbox.acima.com https://ecom.sandbox.acimacredit.com https://ecom.learning.acima.in https://ecom.preflight.acima.in https://ecom.acima.com https://ecom.acimacredit.com self js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.aggle.net *.bing.com *.bolt.com *.clarity.ms *.clickcease.com *.doubleclick.net *.facebook.net *.google.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.inspectlet.com *.livechatinc.com *.newrelic.net *.newrelic.com *.nr-data.net *.reviews.io *.snapfinance.com ecom.sandbox.acimacredit.com protection-widget.route.com *.termly.io *.reviews.co.uk https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paytomorrow.com cdn.routeapp.io https//fonts.googleapis.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.klaviyo.com unpkg.com www.elementwheels.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.bolt.com *.googleapis.com fonts.googleapis.com *.gstatic.com *.livechatinc.com *.reviews.io *.klaviyo.com secure.checkout.visa.com *.cloudfront.net *.reviews.co.uk https://fonts.googleapis.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.paytomorrow.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net *.tagmanager.google.com *.googletagmanager.com www.elementwheels.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com www.elementwheels.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com http://localhost:9002 wss://magento.test:9002 https://ecom.dev.acima.in https://ecom.sandbox.acima.in https://ecom.sandbox.acimacredit.com https://ecom.learning.acima.in https://ecom.preflight.acima.in https://ecom.acima.com https://ecom.acimacredit.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.affirm.com *.affirm.ca connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.aggle.net *.authorize.net *.bolt.com *.clarity.ms *.doubleclick.net *.google-analytics.com *.hotjar.com *.inspectlet.com *.livechatinc.com ws://127.0.0.1:35729 *.nr-data.net *.reviews.io wss://ws.hotjar.com *.hotjar.io *.facebook.com ecom.sandbox.acimacredit.com *.paytomorrow.com protection-widget.route.com *.lab.amplitude.com *.termly.io *.route.com *.cloudfront.net *.reviews.co.uk https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.route.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.run.app www.elementwheels.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.elementwheels.com http: https: blob: 'self' 'unsafe-inline'; default-src www.elementwheels.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.zopim.com *.zopim.io *.techgeese.com *.google.com *.klaviyo.com *.fabglassandmirror.com https://*.google.com *.yotpo.com *.convertexperiments.com *.flipsnack.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.braintreepayments.com *.klaviyo.com *.techgeese.com *.callrail.com *.zoominfo.com *.pinimg.com *.facebook.net *.hotjar.com *.tiktok.com *.mczbf.com *.pinterest.com *.yotpo.com https://*.google.com *.doubleclick.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors self *.youtube.com *.sandbox.paypal.com www.paypal.com *.twitter.com *.techgeese.com *.klaviyo.com *.adobe.com *.google.com *.yotpo.com *.flipsnack.com www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.techgeese.com *.klaviyo.com *.yotpo.com *.flipsnack.com www.google.com www.gstatic.com apis.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.amazon.com *.braintreepayments.com *.klaviyo.com *.techgeese.com *.fabglassandmirror.com *.facebook.com *.facebook.net *.mailchimp.com *.yotpo.com *.cloudfront.net *.googleapis.com *.amazonaws.com fab.glass https://*.google.com *.kaltura.com *.google.com.pk *.hubspot.com *.hsforms.com *.flipsnack.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com report-sample self unsafe-eval unsafe-inline inline unsafe-hashes nonce prodregistryv2.org featureassets.org *.klarna.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.googleapis.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.jsdelivr.net *.facebook.com *.amazon.com *.braintreepayments.com *.techgeese.com *.klaviyo.com *.wisernotify.com *.fabglassandmirror.com *.kaltura.com *.yotpo.com *.callrail.com *.zoominfo.com *.pinimg.com *.facebook.net *.hotjar.com wss://ws.hotjar.com/ *.hotjar.io *.tiktok.com *.mczbf.com *.pinterest.com *.paypal.com *.swellrewards.com *.ytimg.com https://*.google.com *.leadsy.ai *.apollo.io https://aplo-evnt.com *.hs-scripts.com *.hs-banner.com *.hs-analytics.net static.cloudflareinsights.com *.hubspot.com *.convertexperiments.com *.flipsnack.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.kaltura.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com *.amazon.com *.braintreepayments.com *.techgeese.com *.klaviyo.com *.fabglassandmirror.com *.wisernotify.com *.yotpo.com *.callrail.com *.zoominfo.com *.pinimg.com *.facebook.net *.hotjar.com *.tiktok.com *.mczbf.com *.pinterest.com https://*.google.com *.convertexperiments.com *.flipsnack.com https://static.klaviyo.com *.google.com assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.techgeese.com *.kaltura.com *.flipsnack.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com *.kaltura.com prodregistryv2.org featureassets.org *.cloudfront.net www.google-analytics.com *.cloudflare.com *.twitter.com *.facebook.com *.gstatic.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://stats.g.doubleclick.net *.googletagmanager.com *.braintree.com *.klaviyo.com googleads.g.doubleclick.net *.callrail.com *.zoominfo.com *.pinimg.com *.facebook.net *.hotjar.com *.tiktok.com *.mczbf.com *.pinterest.com *.techgeese.com admin.techgeese.com wss://techgeese.com:6001/ *.wisermapp.com *.azurewebsites.net wss://ws.hotjar.com/ *.hotjar.io *.fabglassandmirror.com api.rollbar.com *.yotpo.com https://*.google.com *.bing.com https://aplo-evnt.com *.hubspot.com *.convertexperiments.com *.flipsnack.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.fabglassandmirror.com/csp; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://cdn.tivly.com https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com https://fraudguard.tivly.com https://www.googletagmanager.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://analytics.google.com https://region1.analytics.google.com https://bat.bing.com https://create.leadid.com https://deviceid.trueleadid.com https://create.lidstatic.com https://js.zi-scripts.com https://ws.zoominfo.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://us.app.unleash-hosted.com https://*.cloudfront.net https://d2ydlkypr5z8li.cloudfront.net https://solutions.invocacdn.com https://maps.googleapis.com https://connect.facebook.net https://www.nextinsure.com https://*.atlassian.net https://js-agent.newrelic.com https://www.gstatic.com https://cdnjs.cloudflare.com https://app.jazz.co; connect-src 'self' https://*.optimizely.com https://fraudguard.tivly.com https://us.app.unleash-hosted.com https://js.zi-scripts.com https://ws.zoominfo.com https://analytics.google.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://create.leadid.com https://info.leadid.com https://bam.nr-data.net https://bat.bing.com https://bat.bing.net https://*.twilio.com wss://*.twilio.com https://www.google.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.cloudfront.net https://pnapi.invoca.net https://*.invoca.net https://www.nextinsure.com https://maps.googleapis.com https://google.com https://d2ydlkypr5z8li.cloudfront.net; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.honey.io https://www.gstatic.com; img-src 'self' data: blob: https://cdn.optimizely.com https://*.tivly.com https://*.cloudfront.net https://d2ydlkypr5z8li.cloudfront.net https://*.thehartford.com https://bat.bing.com https://bat.bing.net https://googleads.g.doubleclick.net https://www.google.com https://www.google.ca https://www.google.co.uk https://www.google.de https://www.google.it https://www.google.ie https://www.google.mx https://www.google.com.pr https://www.google.com.bd https://www.google.com.ph https://www.google.com.pk https://www.google.nl https://www.google.hn https://www.google.co.in https://www.google.co.jp https://www.google.gr https://www.googleadservices.com https://maps.googleapis.com https://maps.gstatic.com https://cdn.nextinsure.com https://create.leadid.com https://cdn.honey.io https://translate.google.com https://fonts.gstatic.com https://www.googletagmanager.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://www.facebook.com; frame-src 'self' https://*.optimizely.com https://deviceid.trueleadid.com https://*.cloudfront.net https://www.googletagmanager.com https://create.leadid.com https://info.leadid.com https://recruiting.paylocity.com https://www.google.com; form-action 'self' https://create.leadid.com https://info.leadid.com https://tivly.com https://www.tivly.com https://tivly.okta.com https://commercialinsurance.okta.com https://www.nextinsure.com; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; report-uri https://fwfuik6zl2.execute-api.us-east-2.amazonaws.com/default/csp-report-collector 1 script-src 'self' 'unsafe-eval' https://use.fontawesome.com https://www.googletagmanager.com https://cdn.jsdelivr.net https://static.ctctcdn.com https://translate.googleapis.com https://cdnjs.cloudflare.com https://www.weps.org; script-src-elem 'self' 'unsafe-inline' translate.google.com www.google.com www.gstatic.com static.ctctcdn.com www.googletagmanager.com cdn.jsdelivr.net www.google-analytics.com translate.googleapis.com bam.nr-data.net js-agent.newrelic.com cdn.gtranslate.net https://cdnjs.cloudflare.com https://www.weps.org; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://use.fontawesome.com https://www.weps.org; style-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net translate.googleapis.com static.ctctcdn.com www.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://use.fontawesome.com https://www.weps.org; frame-ancestors 'self' 1 default-src 'self'; frame-src 'self' googletagmanager.com *.googletagmanager.com localizedirect.cdn.gridly.com *.gridly.com; script-src 'nonce-KPq0ttLDtHK2wz8WutLCyDk/jpwqhae1' 'unsafe-eval' 'unsafe-inline' 'self' https: http: 'self' 'unsafe-inline' 'unsafe-hashes'; script-src-attr 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' localizedirect.cdn.gridly.com *.gridly.com googletagmanager.com *.googletagmanager.com googleapis.com *.googleapis.com hsforms.net *.hsforms.net hsforms.com *.hsforms.com onetrust.com *.onetrust.com doubleclick.net *.doubleclick.net; connect-src 'self' hsforms.net *.hsforms.net hsforms.com *.hsforms.com onetrust.com *.onetrust.com google.com *.google.com doubleclick.net *.doubleclick.net; img-src * data:; media-src * data:; style-src 'self' 'unsafe-inline' localizedirect.cdn.gridly.com *.gridly.com fonts.googleapis.com google.com *.google.com hsforms.net *.hsforms.net hsforms.com *.hsforms.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' localizedirect.cdn.gridly.com *.gridly.com fonts.googleapis.com hsforms.net *.hsforms.net hsforms.com *.hsforms.com; font-src 'self' data: fonts.gstatic.com; base-uri 'self'; form-action 'self'; report-uri /.netlify/functions/__csp-violations 1 font-src *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com use.typekit.net staticw2.yotpo.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com *.gstatic.com https://fonts.bunny.net *.alothemes.com *.magepow.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com https://seo.mageplaza.com gtech.semafoneservices.com gtech.semafonetest.com *.yotpo.com 'self' connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors widget.trustpilot.com front.optimonk.com cdn.cookielaw.org *.stripe.com stripe.com; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net *.stripe.com https://www.google.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com widget.trustpilot.com config1.veinteractive.com www.facebook.com www.youtube.com gtech.semafoneservices.com gtech.semafonetest.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com/ *.yotpo.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.sharethis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com reporting.gtech.co.uk secure.adnxs.com bat.bing.com pixel.mediaiqdigital.com www.facebook.com www.google.co.uk ct.pinterest.com adservice.google.com x.bidswitch.net widget.trustpilot.com fonts.googleapis.com staticw2.yotpo.com ad.doubleclick.net cookiee1.veinteractive.com www.gtech.co.uk 9032256.fls.doubleclick.net www.pinterest.com img.youtube.com connect.facebook.net www.googletagmanager.com veads.veinteractive.com *.teads.tv *.smartadserver.com *.casalemedia.com *.seedtag.com *.emxdgt.com *.pubmine.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.yotpo.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://pixel.nudgify.com *.stripe.com https://www.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com widget.trustpilot.com eu-west.app.koopid.ai config1.veinteractive.com bat.bing.com cdn.mouseflow.com front.optimonk.com connect.facebook.net c5.adalyser.com cdn.cookielaw.org resources.xg4ken.com pxl.jivox.com p.teads.tv s.pinimg.com www.googletagservices.com pagead2.googlesyndication.com gs-cdn.optimonk.com px.veinteractive.com a.volvelle.tech ad.doubleclick.net 8282528.fls.doubleclick.net *.mention-me.com js-agent.newrelic.com bam-cell.nr-data.net consent.cookiefirst.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.yotpo.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com www.facebook.com graph.facebook.com business.facebook.com *.trustpilot.com https://www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com *.fontawesome.com p.typekit.net use.typekit.net eu-west.app.koopid.ai widget.trustpilot.com fonts.googleapis.com consent.cookiefirst.com https://static.klaviyo.com *.yotpo.com *.googleapis.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.nudgify.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com https://data.nudgify.com *.stripe.com *.google.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cdn.cookielaw.org o2.mouseflow.com googleads4.g.doubleclick.net front.optimonk.com jfapiprod.optimonk.com ct.pinterest.com cookiee1.veinteractive.com sessionapi.veinteractive.com dtrc.veinteractive.com bam-cell.nr-data.net *.teads.tv consent.cookiefirst.com edge.cookiefirst.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.yotpo.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.cloudflare.com *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.cloudfront.net https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com www.google.com *.gstatic.com maps.googleapis.com *.cloudflare.com *.trustedshops.com *.usercentrics.eu www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.cloudflare.com getfirebug.com *.yotpo.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.cloudflare.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: assets.quadpay.com static.klaviyo.com *.cloudflare.com *.intelligencebank.com *.slant.co *.fonts.net *.zip.co *.alicdn.com *.tql.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.sharethis.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com ws.sharethis.com t.sharethis.com livetour.istaging.com *.facebook.com calculator.redarc.com.au cdn.intelligencebank.com e.issuu.com issuu.com *.doubleclick.net *.moz.com *.paypalobjects.com localhost *.googletagmanager.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net *.adyen.com *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com flagpedia.net 'self' data: site-assets.afterpay.com mcprod.redarcelectronics.com maps.google.com maps.gstatic.com maps.googleapis.com l.sharethis.com p.adsymptotic.com assets.quadpay.com calculator.redarc.com.au linkedin.com *.linkedin.com cdn.jsdelivr.net d3k81ch9hvuctc.cloudfront.net logs-01.loggly.com *.bing.net https://*.bing.com *.clarity.ms *.facebook.com *.intelligencebank.com *.kaltura.com www.google.com.au www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bt www.google.bj www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.so www.google.sr www.google.tg www.google.tl www.google.tn www.google.tt www.google.vu www.google.cv www.google.hn www.google.md www.google.ml *.googletagmanager.com *.typekit.net www.google.ad www.google.bs www.google.ci www.google.co.ls www.google.com.ag www.google.com.bo www.google.com.sl www.google.com.sv www.google.com.tj www.google.dj www.google.dm www.google.ki www.google.la www.google.mv www.google.nr www.google.sc www.google.sn www.google.tm *.tql.com www.google.gm www.google.ne www.google.ws www.google.gl www.google.kg *.doubleclick.net meetanshi.com retail.mcprod.redarcelectronics.com trade.mcprod.redarcelectronics.com trade.redarcelectronics.com retail.mcstaging.redarcelectronics.com trade.mcstaging.redarcelectronics.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.adyen.com https://rum.hlx.page *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.afterpay.com ws.sharethis.com t.sharethis.com staticw2.yotpo.com snap.licdn.com d10lpsik1i8c69.cloudfront.net *.facebook.net https://*.bing.com clarity.microsoft.com *.clarity.ms calculator.redarc.com.au *.zip.co api.emailjs.com dashboard.emailjs.com *.issuu.com *.quantcount.com *.quantserve.com *.klaviyo.com cdn.jsdelivr.net *.impactcdn.com *.adobedtm.com *.doubleclick.net *.hotjar.com *.intelligencebank.com *.kaltura.com *.googletagmanager.com *.yottaa.com *.paypalobjects.com bam.nr-data.net rapid-cdn.yottaa.com *.rapid-cdn.yottaa.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com *.typekit.net *.intelligencebank.com ws.sharethis.com static-tracking.klaviyo.com static-forms.klaviyo.com calculator.redarc.com.au cdn.jsdelivr.net static.klaviyo.com *.fonts.net *.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com res.cloudinary.com cdn.intelligencebank.com *.kaltura.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.adyen.com *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com www.gstatic.com maps.googleapis.com t.elasticsuite.io *.google-analytics.com l.sharethis.com firebase.googleapis.com firestore.googleapis.com firebaseinstallations.googleapis.com *.afterpay.com *.doubleclick.net settings.luckyorange.net cdn.linkedin.oribi.io google.com frstre.com *.facebook.com *.facebook.net bat.bing.com *.us.zip.co *.googletagmanager.com timezone.abstractapi.com cdn.intelligencebank.com api.emailjs.com dashboard.emailjs.com *.issuu.com static-forms.klaviyo.com cdn.optimizely.com api.quadpay.com data.stbuttons.click api-js.datadome.co redarcelectronics.pxf.io redarcelectronicscreator.pxf.io *.bing.net *.clarity.ms *.crwdcntrl.net *.hotjar.com *.hotjar.io wss://*.hotjar.com *.linkedin.com localhost www.google.ae www.google.at www.google.ba www.google.be www.google.bg www.google.by www.google.ca www.google.cg www.google.ch www.google.cl www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.br www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.gg www.google.gr www.google.gy www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.lk www.google.lt www.google.lu www.google.mw www.google.mk www.google.mu www.google.mn www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sr www.google.tl www.google.tg www.google.tt www.google.ge www.google.ht www.google.lv www.google.ml *.typekit.net *.yottaa.net www.google.ad www.google.al www.google.am www.google.cd www.google.ci www.google.cm www.google.co.uz www.google.com.ag www.google.com.bo www.google.com.bz www.google.com.et www.google.com.gi www.google.com.kh www.google.com.ly www.google.com.mt www.google.com.sb www.google.com.sl www.google.com.sv www.google.com.tj www.google.dm www.google.hn www.google.im www.google.ki www.google.kz www.google.la www.google.me www.google.mg www.google.nr www.google.sn www.google.so www.google.tn www.google.vu www.google.az www.google.bj www.google.bs www.google.gm www.google.li www.google.md www.google.ws bam.nr-data.net *.yottaa.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ae1dd06c-57cf-4693-8c31-6e29ccc59bf2.sansec.watch/; report-to report-endpoint; 1 default-src * 'unsafe-inline' 'unsafe-eval'; report-to report; report-uri /?_task=background&_action=csp_report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com https://widgets.trustedshops.com 'self' data: https://static.unzer.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com www.google.com *.klarna.com *.google.com/ sc.bausep.de vars.hotjar.com ssl.hurra.com cdn.consentmanager.net googletagmanager.com www.paypalobjects.com googleads.g.doubleclick.net payment.unzer.com *.phoenix-media.cloud https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.sharethis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://www.magezon.com googleadservices.com *.consentmanager.net widgets.trustedshops.com static.unzer.com google.com www.google.de paypal.com sc.bausep.de *.bausep.de bs-magento2-master.phoenix-media.cloud *.bing.com *.bing.net *.phoenix-media.cloud *.hsforms.net *.hsforms.com 'self' data: https://static.unzer.com *.online-metrix.net https://www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com ssl.hurra.com googletagmanager.com *.consentmanager.net widgets.trustedshops.com *.hotjar.com *.g.doubleclick.net payment.unzer.com *.bausep.de *.bing.com *.phoenix-media.cloud *.hsforms.net *.hsforms.com *.gstatic.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.klarnacdn.net *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.bausep.de ssl.hurra.com *.hotjar.com googletagmanager.com google.de www.google.de www.google.com *.g.doubleclick.net payment.unzer.com *.bing.com *.bing.net *.phoenix-media.cloud t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://geowidget.easypack24.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ pay.google.com play.google.com *.autopay.eu https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.trefl.com *.pinterest.com *.doubleclick.net *.facebook.com *.google.com *.issuu.com *.salesmanago.pl *.wedare.pl www.google.co.uk www.google.pl youtube.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://firebasestorage.googleapis.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.trefl.com *.amazonaws.com *.usercentrics.eu *.doubleclick.net *.facebook.com *.fbcdn.net *.googleapis.com *.googlesyndication.com *.gstatic.com *.ibb.co *.wedare.pl *.yandex.ru www.google.ae www.google.al www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.in www.google.co.jp www.google.co.kr www.google.co.nz www.google.co.uk www.google.co.za www.google.com.au www.google.com.bd www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.hk www.google.com.lb www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ph www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.lt www.google.lv www.google.md www.google.me www.google.mg www.google.nl www.google.no www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn www.google.pl yastatic.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com https://cdn.polyfill.io https://browser.sentry-cdn.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org mapa.orlenpaczka.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.avada.io *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.analyticharbor.com/ *.trefl.com *.usercentrics.eu *.googleapis.com *.pinimg.com *.pinterest.com *.addthis.com *.bing.com *.doubleclick.net *.facebook.net *.googlesyndication.com *.wedare.pl tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.autopay.eu *.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com sandbox-easy-geowidget-sdk.easypack24.net *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trefl.com *.googletagmanager.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com https://*.ingest.sentry.io *.easypack24.net *.inpost.pl *.openstreetmap.org nominatim.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://get.geojs.io *.avada.io *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analyticharbor.com/ *.pinterest.com *.trefl.com https://www.sentry.macopedia-dev.pl *.amazonaws.com https://js-agent.newrelic.com *.doubleclick.net *.googleapis.com *.facebook.com *.google.com *.googlesyndication.com *.saleago.com *.usercentrics.eu google.com www.google.ae www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.in www.google.co.kr www.google.co.nz www.google.co.uk www.google.com.do www.google.com.ec www.google.com.hk www.google.com.lb www.google.com.mx www.google.com.my www.google.com.tr www.google.com.tw www.google.com.ua www.google.cz www.google.de www.google.dk www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.lt www.google.mg www.google.nl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.tn www.google.pl *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e784be6e-bb2f-4390-bb3c-a4e377629b11.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net static.lipscore.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.vipps.no 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.lipscore.com blob: img.youtube.com mageside.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.vipps.no ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://api.clerk.io https://cdn.clerk.io chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarnaservices.com *.klarnacdn.net x.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.lipscore.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.fontawesome.com graph.instagram.com *.vipps.no tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com *.klarnacdn.net https://static.klaviyo.com static.lipscore.com *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarnauserservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ wapi.lipscore.com users.lipscore.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudflare.com *.vipps.no 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://checkout.vipps.no/; report-to report-endpoint; 1 default-src 'none'; script-src 'report-sample' 'unsafe-inline' 'self' https://js.stripe.com/ https://www.googletagmanager.com/ https://bat.bing.com/ https://www.dwin1.com/16164.js https://analytics.tiktok.com/i18n/ https://connect.facebook.net/ https://cdn.cookielaw.org/scripttemplates/otSDKStub.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/850511572/; style-src 'report-sample' 'unsafe-inline' 'self'; form-action 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://cdn.cookielaw.org/ https://region1.google-analytics.com/ https://www.google-analytics.com/ https://www.google.com/ https://zunl7r6b5x-dsn.algolia.net/ https://testingu72jz6o2va-dsn.algolia.net/ https://pagead2.googlesyndication.com/ https://privacyportal-de.onetrust.com/ https://region1.analytics.google.com/ https://stats.g.doubleclick.net/ https://analytics.tiktok.com/; font-src 'self' data:; frame-src 'self' https://js.stripe.com/ https://www.googletagmanager.com/ https://td.doubleclick.net/; frame-ancestors 'self'; child-src 'none'; img-src 'self' https://cdn.cookielaw.org/ https://eu-images.contentstack.com/ https://bat.bing.com/ https://www.google.co.uk/ https://www.googletagmanager.com/ https://www.facebook.com/; manifest-src 'self'; media-src 'self'; worker-src 'none'; upgrade-insecure-requests; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/transparency_google 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.dopplepay.com *.finance-calculator.co.uk *.s3.eu-west-2.amazonaws.com *.dekopay.org *.deko-uat.com *.amazonaws.com *.cookiebot.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.dopplepay.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.doubleclick.net *.facebook.com *.googlesyndication.com *.dopplepay.com *.clearpay.co.uk account.fetchify.com *.finance-calculator.co.uk *.deko.finance *.dekopay.org *.deko-uat.com www.facebook.com platform.twitter.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.roeye.com *.dopplepay.com *.afterpay.com *.clearpay.co.uk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com s3.eu-west-1.amazonaws.com *.cookiebot.com https://firebasestorage.googleapis.com flagpedia.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.pbffinancecalculator.info cdn.shopify.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.dopplepay.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com cc-cdn.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com dekowallet-feature-assets.s3.eu-west-2.amazonaws.com *.blackhorseflexpay.co.uk/ 'self' data: *.cookiebot.com www.google.co.uk *.avada.io *.shopify.com maps.googleapis.com connect.facebook.net twitter.com platform.twitter.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.dopplepay.com *.afterpay.com/ *.squarecdn.com downloads.mailchimp.com cc-cdn.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.cookiebot.com *.typekit.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.dopplepay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk 'self' data: *.cookiebot.com *.googletagmanager.com *.typekit.net https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info wss://*.staging-pbffinancecalculator.info wss://*.pbffinancecalculator.info *.paybyfinance.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; 1 default-src 'self'; script-src 'self' https://assets.adobedtm.com https://personalization-engine.hebsdigital.com https://script.gethovr.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'unsafe-inline'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; report-uri https://0de1690401080beb6cd3acd39f2ce22f.report-uri.com/r/d/csp/reportOnly; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com *.zopim.io https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com https://applepay.cdn-apple.com/jsapi/v1/assets/1.0.0/fonts/en-US.woff https://applepay.cdn-apple.com/jsapi/v1/assets/1.0.0/fonts/en-US.woff2 https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.certcapture.com *.clarity.ms *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.cloudfront.net *.nr-data.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.zendesk.com http://www.w3.org/2000/svg https://js-agent.newrelic.com/ https://bam.nr-data.net/ *.sharethis.com *.googleapis.com https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.cdn.datatables.net *.authorize.net *.clarity.ms js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.facebook.net *.doubleclick.net *.linkedin.com *.bayengage.com *.targetbay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net assets.braintreegateway.com *.klaviyo.com https://static.klaviyo.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io https://static.zdassets.com/ https://bam.nr-data.net/ *.sharethis.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.certcapture.com https://www.facebook.com www.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.doubleclick.net *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.applepay.cdn-apple.com https://maps.google.com *.livechatinc.com *.crwdcntrl.net *.authorize.net *.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.bayengage.com *.targetbay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io https://www.google-analytics.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com https://fonts.bunny.net www.factory-direct-flooring.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.facebook.com *.arcot.com *.securesuite.co.uk *.mycardsecure.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.wlp-acs.com * www.factory-direct-flooring.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com *.facebook.net www.factory-direct-flooring.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.hotjar.com *.facebook.com *.addthis.com *.arcot.com *.securesuite.co.uk *.pinterest.com *.mycardsecure.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com www.youtube.com www.factory-direct-flooring.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net *.bing.com *.pinterest.com *.google.co.uk *.limely.co.uk *.gravatar.com *.googletagmanager.com *.postcodeanywhere.co.uk *.addthis.com *.factory-direct-flooring.co.uk *.carpetworlduk.co.uk *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adobedtm.com www.factory-direct-flooring.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cardinalcommerce.com *.googletagmanager.com *.facebook.net apis.google.com cdn.livechatinc.com *.hotjar.com *.bing.com *.pinimg.com *.pcapredict.com *.postcodeanywhere.co.uk *.pinterest.com *.addthis.com *.addthisedge.com *.gstatic.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com www.youtube.com player.vimeo.com www.factory-direct-flooring.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com *.googleapis.com *.postcodeanywhere.co.uk *.gstatic.com *.fontawesome.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com https://fonts.bunny.net assets.braintreegateway.com *.trustpilot.com www.factory-direct-flooring.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com *.google.com www.factory-direct-flooring.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cardinalcommerce.com *.googleapis.com *.pinterest.com *.hotjar.com wss://*.hotjar.com wss://*.hotjar.com/ *.hotjar.io *.postcodeanywhere.co.uk *.facebook.com *.doubleclick.net *.bing.com *.addthis.com *.reviews.co.uk api.amplitude.com stats.g.doubleclick.net www.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com cdn.plyr.io noembed.com www.factory-direct-flooring.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.factory-direct-flooring.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.factory-direct-flooring.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://factorydirectflooring.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.google.com/ https://www.youtube.com www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.magezon.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.disqus.com *.avada.io *.shopify.com *.google.com/ www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://cdn.cookielaw.org https://www.bnpparibas.de https://brasil.bnpparibas; script-src 'self' 'unsafe-eval' https://fast.wistia.com https://beacon-v2 https://analyticsgroupcom.bnpparibas.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas ajax.googleapis.com www.googletagmanager.com googletagmanager.com tagmanager.google.com 'sha256-77WmSGVq6PlE+/dOVkQSZGQWCrUBl6KIyLWH507dV1o=' 'sha256-1n5k85V+yfNkk7Pd+G/nJITXsGJtMZPMLnU5q7WRQvM=' 'sha256-F+QMJISS2IIkRUd2a+c+u1owMqMSoidCaHFDAmzUgOo=' 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' 'sha256-yZHeusBmoqYSsqdm5ylf993dfqVyosFaYa5gueKZDsA=' 'sha256-rjfSUjIA2A20p4lATAefLLG7Fy7VJssnkJ+SnJ2TXNo=' 'sha256-tYfO42nmjgLnGFpnKZhoGOgw7wYzBfiiMQiHjx6Nrb8=' 'sha256-RWn1w3BKiDlDNbD6vM1kYLpeWCwwWPkob0LMWJ2gKJk=' 'sha256-mgXUb77dTWZ3bbByk1ylyG//4/zPGMJ5l7eUWmvonZ0=' 'sha256-fPXetwWx4258jL256OrNtQQyvFVR4/BotkeZKtfk54Q=' 'sha256-yElBEKucE35qwHf8qWcAvqD25zOJ7TqTptcHyzGhOxw=' 'sha256-n1mhU8dmPJrwvRiPgHP/YQB7tK6Kx4rupnPq6FBFios=' 'sha256-qcT/R0HkWUs2DMxvtvcMobUms6Z5/fPtfgUe2hN67gE='; style-src 'self' 'unsafe-inline' data: https://fonts.googleapis.com https://www.gstatic.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://s.w.org https://wp-rocket.me https://c.tile.openstreetmap.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org blob: https://www.google.com/pagead/landing https://ade.googlesyndication.com https://pagead2.googlesyndication.com https://ad.doubleclick.net https://contrib.territories.bnpparibas https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas secure.gravatar.com www.gravatar.com i.ytimg.com data: www.googletagmanager.com; connect-src 'self' https://bnp-privacy.my.onetrust.com https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://yoast.com https://cdn.cookielaw.org https://o173685.ingest.sentry.io https://analyticsgroupcom.bnpparibas.com https://contrib.territories.bnpparibas https://www.google.com/pagead/landing https://pagead2.googlesyndication.com https://adservice.google.com https://sourcemap.devowl.io https://sourcemap.devowl.io/real-media-library/4.22.47/adb9a2f4ef22d5d85978840bd322bf76/index.js.map www.googletagmanager.com; font-src 'self' data: https://fonts.gstatic.com https://fast.wistia.com https://github.com/google/fonts https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.gstatic.com fonts.googleapis.com data:; media-src 'self' https://asset.mediahub.bnpparibas https://upload.wikimedia.org https://broadcast.mediahub.bnpparibas data: https://mediahub.group.echonet https://my.mediahub.bnpparibas https://my.mediahub.bnpparibas/AssetLink/1cwfu8n4ki414p6d240ff18r41ver00j.mp4 https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas; frame-src 'self' https://www.youtube.com https://wp-rocket.me https://open.spotify.com https://www.youtube-nocookie.com https://centric.bnpparibas.com https://13179764.fls.doubleclick.net https://td.doubleclick.net https://gateway.zscalertwo.net https://remove.video https://mozbar.moz.com www.youtube.com www.googletagmanager.com; child-src 'self' www.youtube.com www.googletagmanager.com; worker-src 'self' blob:; 1 script-src 'self' blob: https://prod-bk-web.za.rbi.tools/en/static/js/vendor.bdf258b5.js https://prod-bk-web.za.rbi.tools/en/static/js/main.22aad758.js https://prod-bk-web.za.rbi.tools/en/static/js/runtime.329333a1.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.za.rbi.tools/en/static/js/vendor.244f467f.js https://prod-bk-web.za.rbi.tools/en/static/js/main.4145f136.js https://prod-bk-web.za.rbi.tools/en/static/js/runtime.cbe9ab6f.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 worker-src pay.google.com; script-src-elem webcache.datareporter.eu webcache-eu.datareporter.eu 'self' *.steinbach-group.com *.stage-m-steinbach.ecxdev.io maps.googleapis.com *.google.com *.paypal.com *.cdn-apple.com *.unzer.com *.online-metrix.net *.gstatic.com 'unsafe-inline'; style-src-elem https://webcache.datareporter.eu https://webcache-eu.datareporter.eu 'self' 'unsafe-inline' *.steinbach-group.com *.stage-m-steinbach.ecxdev.io maps.googleapis.com 'unsafe-inline'; font-src webcachex-eu.datareporter.eu *.fontawesome.com *.gstatic.com 'self' data: *.unzer.com https://static.unzer.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.unzer.com pay.google.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ www.xtento.com *.bing.com *.doubleclick.net *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' data: maps.gstatic.com *.steinbach-group.com *.stage-m-steinbach.ecxdev.io *.unzer.com pay.google.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com www.xtento.com cdn.xtento.com *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.facebook.net *.ggpht.com *.googleadservices.com *.google-analytics.com *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tn www.google.tt *.google.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.steinbach.at *.tiktok.com *.tiktokw.us data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.datareporter.eu https://browser.sentry-cdn.com *.google.com *.gstatic.com maps.googleapis.com *.unzer.com pay.google.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval' *.adform.net *.bing.com *.facebook.net *.google-analytics.com *.googleapis.com *.googleoptimize.com *.googletagmanager.com *.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.datareporter.eu *.fontawesome.com *.googleapis.com *.gstatic.com *.unzer.com 'self' 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.datareporter.eu https://*.ingest.sentry.io t.elasticsuite.io *.google-analytics.com maps.googleapis.com *.unzer.com pay.google.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.googleadservices.com *.googleapis.com *.google.com *.googlesyndication.com *.tiktok.com *.tiktokw.us 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://224a4760-907d-4a1a-ab19-67da6774c1ae.sansec.watch/; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klevu.com *.ksearchnet.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://*.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com https://accounts.google.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.klevu.com *.ksearchnet.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.multisafepay.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.attn.tv events.attentivemobile.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.klevu.com *.ksearchnet.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com https://accounts.google.com https://www.gstatic.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com cdn.jsdelivr.net unsafe-inline assets.braintreegateway.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com https://accounts.google.com https://www.gstatic.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com https://accounts.google.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.useinsider.com https://www.gstatic.com https://fonts.gstatic.com https://*.typekit.net https://fonts.googleapis.com *.alicdn.com *.bazaarvoice.com *.googleusercontent.com *.homehardware.com.au *.hotjar.com *.hsappstatic.net *.slant.co *.zip.co *.alipayobjects.com *.cloudflare.com *.fontawesome.com *.fonts.net *.fontshare.com *.googleapis.com *.migaku.com *.mitre10.com.au *.qantas.com *.ziplyne.com *.crisp.chat data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://app.contentful.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.useinsider.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.mitre10.com.au https://*.openstreetmap.org https://scontent.cdninstagram.com https://tracker.unbxdapi.com *.dotomi.com *.eyeota.net *.googleapis.com *.mitre10.com.au *.openx.net *.pubmatic.com www.google.bf www.google.ca www.google.ch www.google.cm www.google.co.ck www.google.co.id www.google.co.in www.google.co.kr www.google.co.nz www.google.co.ug www.google.co.uk www.google.co.za www.google.co.zm www.google.com.au www.google.com.bd www.google.com.fj www.google.com.gh www.google.com.hk www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.sa www.google.com.sg www.google.com.tw www.google.com.vn www.google.de www.google.dk www.google.es www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.nl www.google.pl www.google.rs www.google.se *.amazon-adsystem.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bt www.google.by www.google.ci www.google.cl www.google.co.bw www.google.co.cr www.google.co.il www.google.co.jp www.google.co.ke www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.th www.google.co.tz www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.co www.google.com.do www.google.com.ec www.google.com.eg www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.pr www.google.com.qa www.google.com.sb www.google.com.sl www.google.com.tr www.google.com.ua www.google.com.uy www.google.cz www.google.dz www.google.ee www.google.fi www.google.ge www.google.gg www.google.hn www.google.im www.google.iq www.google.jo www.google.ki www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mk www.google.mu www.google.mw www.google.no www.google.pt www.google.ro www.google.ru www.google.sc www.google.si www.google.sk www.google.sn www.google.tn www.google.tt www.google.vu www.google.ws zip.co *.afterpay.com *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.cursors-4u.net *.google.com *.googleusercontent.com *.pinterest.com *.qualtrics.com *.shopback.com *.snapchat.com *.zipmoney.com.au dakotaram.com s3.amazonaws.com web-cockroach.herokuapp.com www.google.ad www.google.al www.google.as www.google.az www.google.bj www.google.bs www.google.cd www.google.cg www.google.co.ao www.google.com.af www.google.com.ag www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.bz www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.mm www.google.com.ni www.google.com.om www.google.com.py www.google.com.sv www.google.com.vc www.google.cv www.google.dj www.google.fm www.google.ga www.google.gm www.google.gy www.google.ht www.google.is www.google.je www.google.kg www.google.kz www.google.me www.google.mg www.google.ml www.google.mn www.google.mv www.google.nr www.google.ps www.google.rw www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to yastatic.net *.alicdn.com *.googleadservices.com www.google.com.gi www.google.dm www.google.gl www.google.nu www.google.pn www.google.sh www.google.td *.ctfassets.net www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co *.hsforms.net *.hsforms.com https://images.ctfassets.net https://images.secure.ctfassets.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.plugins.emarsys.net *.scarabresearch.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://libraries.unbxdapi.com https://d21gpk1vhmjuf5.cloudfront.net https://s3.amazonaws.com/downloads.mailchimp.com/js/goal.min.js https://cdn.optimizely.com https://rum.optimizely.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.zip.co https://cdn.scarabresearch.com *.cloudflare.com *.dotomi.com *.googleapis.com *.newrelic.com *.unbxdapi.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.hotjar.com *.mitre10.com.au *.shophumm.com.au *.zip.co *.zipmoney.com.au d21gpk1vhmjuf5.cloudfront.net https://d3m8huu8gvuyn3.cloudfront.net/rex_template_content/unbxd_rex_template_sdk.js *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.instagram.com *.p-a.io *.particularaudience.com *.pinimg.com *.pinterest.com *.qualtrics.com *.snapchat.com *.tableau.com consentag.eu dakotaram.com googletagmanager.com nexuspublications.com.au sc-static.net *.crisp.chat *.walkme.com *.humm-au.com static.cloudflareinsights.com www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co *.hsforms.net *.hsforms.com https://cdn.jsdelivr.net/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com display.ugc.bazaarvoice.com *.useinsider.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com https://*.typekit.net https://maps.googleapis.com https://libraries.unbxdapi.com *.typekit.net *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co *.bazaarvoice.com *.fontawesome.com *.fonts.net *.mitre10.com.au 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.mitre10.com.au *.youtube.com *.globalshop.com.au https://videos.ctfassets.net https://videos.secure.ctfassets.net 'self' 'unsafe-inline'; manifest-src *.useinsider.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.sharethis.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.scarabresearch.com *.eservice.emarsys.net *.useinsider.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://search.unbxd.io https://www.instagram.com https://graph.instagram.com https://*.sandbox.afterpay.com https://api.sandbox.zipmoney.com.au https://api.zipmoney.com.au https://*.sandbox.zip.co https://*.zip.co *.googleapis.com *.nr-data.net *.typekit.net localhost www.google.co.id www.google.co.in www.google.co.nz www.google.co.za www.google.com.au www.google.com.bd www.google.com.fj www.google.com.hk www.google.com.ph www.google.com.sa www.google.com.sg www.google.de www.google.dk www.google.hu www.google.pt www.google.rs *.bazaarvoice.com *.crwdcntrl.net *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxd.io *.zip.co *.zipmoney.com.au www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bf www.google.bt www.google.by www.google.ca www.google.ch www.google.cl www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pe www.google.com.pk www.google.com.qa www.google.com.sb www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.ie www.google.it www.google.jo www.google.la www.google.lk www.google.lv www.google.mu www.google.nl www.google.no www.google.pl www.google.ro www.google.ru www.google.se www.google.sk www.google.tn www.google.tt www.google.vu www.google.ws *.alicdn.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.mitre10.com.au *.p-a.io *.particularaudience.com *.pinterest.com *.qualtrics.com *.snapchat.com *.stbuttons.click *.unbxdapi.com www.google.al www.google.az www.google.bg www.google.bs www.google.cd www.google.ci www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.il www.google.co.mz www.google.co.zm www.google.com.bh www.google.com.bn www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.kw www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.om www.google.com.pa www.google.com.pg www.google.com.pr www.google.com.sv www.google.com.uy www.google.ga www.google.gm www.google.gy www.google.ht www.google.iq www.google.je www.google.kg www.google.kz www.google.lt www.google.lu www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mv www.google.mw www.google.nr www.google.ps www.google.rw www.google.sc www.google.si www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to zip.co *.crisp.chat www.google.as www.google.bj www.google.cg www.google.cm www.google.co.ls www.google.com.af www.google.com.bo www.google.com.gi www.google.com.py www.google.com.vc www.google.dm www.google.im www.google.is www.google.ki www.google.ml www.google.nu www.google.pn *.walkme.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.useinsider.com a.tribalfusion.com aa.agkn.com ad.turn.com ads.dotomi.com ads.scorecardresearch.com ads.stickyadstv.com aorta.clickagy.com ap.lijit.com bh.contextweb.com bpi.rtactivate.com c1.adform.net capi.connatix.com ce.lijit.com cm.g.doubleclick.net cms.analytics.yahoo.com cms.quantserve.com contextual.media.net cookies.nextmillmedia.com crb.kargo.com creativecdn.com cs.admanmedia.com cs.openwebmp.com csync.loopme.me dclk-match.dotomi.com dm-us.hybrid.ai dmp.brand-display.com dp-sync.dotomi.com dpm.demdex.net dsum-sec.casalemedia.com e1.emxdgt.com eb2.3lift.com edgedl.me.gvt1.com eu-u.openx.net exchange-match.mediaplex.com gw-iad-bid.ymmobi.com i.liadm.com i.w55c.net i6.liadm.com ib.adnxs.com id.rlcdn.com idpix.media6degrees.com idsync.live.streamtheworld.com idsync.rlcdn.com image2.pubmatic.com image4.pubmatic.com image8.pubmatic.com login.dotomi.com login-ds.dotomi.com match.adsby.bidtheatre.com match.adsrvr.org match.deepintent.com match.justpremium.com match.prod.bidr.io match.sharethrough.com match.sync.ad.cpe.dotomi.com openx-ums.acuityplatform.com openx.adhaven.com openx2-match.dotomi.com oxp.mxptint.net p.rfihub.com partners.tremorhub.com pippio.com pixel-sync.sitescout.com pixel.adsafeprotected.com pixel.rubiconproject.com pixel.tapad.com pm.w55c.net pmp.mxptint.net pr-bh.ybp.yahoo.com ps.eyeota.net pubmatic-match.dotomi.com px.ads.linkedin.com px.owneriq.net rtb-csync.smartadserver.com rtb.adentifi.com rtb.openx.net s.ad.smaato.net s.amazon-adsystem.com s.tribalfusion.com server.cpmstar.com simage2.pubmatic.com ssbsync.smartadserver.com stags.bluekai.com sync-tm.everesttech.net sync.1rx.io sync.bfmio.com sync.crwdcntrl.net sync.ipredictive.com sync.mathtag.com sync.search.spotxchange.com sync.smartadserver.com sync.srv.stackadapt.com sync.targeting.unrulymedia.com t.adx.opera.com tags.bluekai.com tr.blismedia.com u.openx.net um.simpli.fi ups.analytics.yahoo.com us-east.ads.audio.thisisdax.com us-u.openx.net us.ck-ie.com vop.sundaysky.com x.bidswitch.net yahoo-match.dotomi.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://67a80eb9-c7b9-48b5-86c1-b4eafb6424c2.sansec.watch/; report-to report-endpoint; 1 frame-ancestors 'self';block-all-mixed-content;default-src 'self';script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://maps-api-ssl.google.com https://www.youtube.com https://*.matomo.cloud https://letscast.fm https://cdn.weglot.com https://download.digiaccess.org https://recaptcha.net https://www.googletagmanager.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://userlike-cdn-umm.b-cdn.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://www.google.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.gstatic.com https://www.gstatic.com/recaptcha/ https://www.recaptcha.net https://assets.familienservice.de https://*.eye-able.com https://maps.google.com https://player.vimeo.com https://maps.googleapis.com https://googleads.g.doubleclick.net; script-src-elem 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.eye-able-cdn.com https://*.eye-able.com https://*.letscast.fm https://letscast.fm https://www.recaptcha.net https://www.gstatic.com https://cdn.weglot.com https://cdn.matomo.cloud https://*.digiaccess.org https://familienservice.matomo.cloud https://*.eye-able-cdn.com www.google.com; style-src-elem 'self' 'unsafe-inline' https://*.eye-able-cdn.com https://*.eye-able.com https://*.letscast.fm https://letscast.fm https://cdn.weglot.com assets.familienservice.de www.googletagmanager.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://letscast.fm cdn.weglot.com https://*.eye-able-cdn.com https://*.eye-able.com https://assets.familienservice.de https://fonts.googleapis.com;object-src 'none';frame-src 'self' https://www.yumpu.com https://www.googletagmanager.com https://www.youtube.com *.recaptcha.net *.google.com recaptcha.net https://*.vimeo.com/ https://letscast.fm;child-src 'self';img-src 'self' https://*.eye-able-cdn.com https://*.eye-able.com https://familienservice.matomo.cloud https://googleads.g.doubleclick.net https://maps-api-ssl.google.com https://www.google.de https://www.google.ie https://www.google.it https://www.google.at https://www.googletagmanager.com data: www.familienservice.de https://google.de https://www.google.de https://www.google.com https://*.letscast.fm www.gstatic.com/recaptcha https://userlike-cdn-operators.userlike.com/ https://*.eye-able-cdn.com https://*.eye-able.com https://maps.gstatic.com https://maps.google.com;font-src 'self' https://userlike-cdn-umm.b-cdn.net https://fonts.gstatic.com;connect-src 'self' wss://umd.userlike.com/ https://google.com https://cdn-api-weglot.com https://assets.familienservice.de/ https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.userlike.com https://*.matomo.cloud https://stats.g.doubleclick.net https://*.analytics.google.com https://www.google.com https://letscast.fm *.weglot.com api.digiaccess.org https://maps.googleapis.com;manifest-src 'self';base-uri 'self';form-action 'self' https://*.cleverreach.com;media-src 'self' data www.familienservice.de;prefetch-src 'self';worker-src 'self' www.recaptcha.net; report-uri https://csplog-www-production.familienservice.de/log; report-to reporter 1 object-src 'none'; script-src 'self' 'report-sample' addtocalendar.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io https://unpkg.com platform.twitter.com; style-src 'self' 'report-sample' addtocalendar.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src https://widgets.trustedshops.com *.gstatic.com fonts.gstatic.com https://x.klarnacdn.net *.getflowbox.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.trustpilot.com widget.trustpilot.com creativecdn.com www.googletagmanager.com consentcdn.cookiebot.com td.doubleclick.net sts.buddhatobuddha.com ct.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com inv-nets.admixer.net us.ck-ie.com www.facebook.com www.google.nl bat.bing.com t.squeezely.tech imgsct.cookiebot.com sync.e-planning.net sync.console.adtarget.com.tr onetag-sys.com cm.mgid.com s-cs.rmp.rakuten.com region1.analytics.google.com region1.google-analytics.com sync.connectad.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com https://js.klarna.com https://js.playground.klarna.com *.getflowbox.com widget.trustpilot.com integrations.etrusted.com connect.getflowbox.com v1.widget.futy.io invitejs.trustpilot.com consent.cookiebot.com connect.facebook.net static.hotjar.com s.pinimg.com www.dwin1.com squeezely.tech creativecdn.com bat.bing.com consentcdn.cookiebot.com ct.pinterest.com static.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com tagmanager.google.com fonts.google.com https://x.klarnacdn.net *.getflowbox.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://js.playground.klarna.com https://*.klarnaevt.com https://*.playground.klarnaevt.com *.getflowbox.com region1.analytics.google.com api.widget.futy.io widget.trustpilot.com consentcdn.cookiebot.com ct.pinterest.com sts.buddhatobuddha.com www.google.com pagead2.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.buddhatobuddha.com *.buddhatobuddha.com bat.bing.com bat.bing.net www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-80edf453-12d1-44e6-8b3f-c05a9ce6e1fd' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.be https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.be/eum-collector/report/csp-report; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.twitter.com *.google.com *.youtube.com maps.googleapis.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.twitter.com *.google.com *.youtube.com *.facebook.com maps.googleapis.com lightwidget.com *.maps.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.googleapis.com *.placeholder.com *.maps.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com *.facebook.net cdn.lightwidget.com *.instagram.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.googleapis.com *.placeholder.com *.maps.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com *.maps.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com facebook.net *.maps.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net self data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://store.plumrocket.com pal-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com self *.doubleclick.net *.criteo.com *.easydmp.net *.snapchat.com https://store.plumrocket.com https://accounts.google.com checkoutshopper-test.adyen.com pal-test.adyen.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com self *.bing.com *.paypal.com *.google.fr *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.cookielaw.org *.snapchat.com checkoutshopper-test.adyen.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com self sc-static.net *.abtasty.com *.jsdelivr.net *.gstatic.com *.facebook.net *.tiktok.com *.googleapis.com *.easydmp.net *.vzbl.eu *.aticdn.net *.m1by1.com *.woosmap.com *.doubleclick.net *.cookielaw.org *.snapchat.com *.valiuz.com *.mediarithmics.com *.prediggo.services https://accounts.google.com checkoutshopper-test.adyen.com 'self' 'unsafe-eval' 'nonce-a3g0M3hqZ3Z1YnN3emkzNzhocXM2dTl5YTJ1cG1pMjE=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com self *.gstatic.com *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.snapchat.com https://accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com self *.snapchat.com *.cookielaw.org *.abtasty.com *.googleapis.com *.vzbl.eu *.criteo.com *.easydmp.net *.xiti.com *.valiuz.com *.doubleclick.net *.mediarithmics.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.bing.com *.criteo.net *.snapchat.com *.netvigie.com *.xiti.com *.valiuz.com *.googletagmanager.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cetelem.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cetelem.es magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cetelem.es *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cetelem.es *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cetelem.es https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com checkout.iwdagency.com td.doubleclick.net *.paypalobjects.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.gstatic.com unpkg.com *.braintreegateway.com *.cdn-apple.com *.paypal.com *.paypalobjects.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js http://www.googletagmanager.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com https://checkout.iwdagency.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-eval' 'unsafe-inline' *.admedia.com *.adsrvr.org advanced.neuro-id.com *.analytics-sm.com analytics-sm.com analytics.tiktok.com api-js.mixpanel.com api.amplitude.com api.glia.com api.measureone.com api.salemove.com api.yotpo.com arttrk.com *.arttrk.com auth.split.io bat.bing.com bcdn.integration.projectcorvette.us bcwup.integration.projectcorvette.us browser-intake-datadoghq.com cdn.amplitude.com cdn.lr-ingest.com cdn.plaid.com cdn.tiny.cloud client-logger.salemove.com dn.neuroid.cloud ekr.zdassets.com gabihelp.zendesk.com gabihelp1605922745.zendesk.com glia-applets.com globalsiteanalytics.com google.com googleadservices.com js.stripe.com js.verygoodvault.com js3.verygoodvault.com kluster.salemove.com *.kochava.com libs.glia.com libs.salemove.com logs.neuro-id.com nexus.ensighten.com pt.ispot.tv pubsub.salemove.com rc.dn.neuroid.cloud receiver.neuroid.cloud region1.analytics.google.com region1.google-analytics.com *.rokt.com rum.browser-intake-datadoghq.com sc-static.net scripts.neuro-id.com sdk.split.io session-replay.browser-intake-datadoghq.com siteintercept.qualtrics.com smarty.insurance.experian.com smarty.staging.gabi.com smetrics1.experian.com static.zdassets.com staticw2.yotpo.com stats.g.doubleclick.net storage.googleapis.com streaming.split.io *.tapad.com tms.experian.com tr.snapchat.com us-autocomplete-pro.api.smarty.com us-autocomplete-pro.api.smartystreets.com vgs-collect-keeper.apps.verygood.systems wss://kluster.salemove.com wss://pubsub.salemove.com www.google-analytics.com www.google.ca www.google.co.in www.google.co.uk www.google.com www.google.com.mx www.google.com.ph www.google.com.pr www.googleadservices.com www.googletagmanager.com www.routingnumbers.info zn3ibrpkldazquxaq-consumerinfo.siteintercept.qualtrics.com blob:; img-src * data: blob:; style-src 'self' 'unsafe-inline' *.admedia.com *.adsrvr.org analytics-sm.com *.analytics-sm.com analytics.tiktok.com arttrk.com *.arttrk.com auth.split.io cdn.honey.io cdn.jsdelivr.net cdn.tiny.cloud cdnjs.cloudflare.com fonts.googleapis.com glia-applets.com google.com googleadservices.com hello.myfonts.net *.kochava.com libs.glia.com libs.salemove.com pt.ispot.tv *.rokt.com sc-static.net sdk.split.io smetrics1.experian.com staticw2.yotpo.com storage.googleapis.com streaming.split.io *.tapad.com tr.snapchat.com www.google.co.uk www.gstatic.com www.tiny.cloud; font-src 'self' cdn.gabi.com fonts.gstatic.com hello.myfonts.net static.zip.co staticw2.yotpo.com www.tiny.cloud data:; frame-src 'self' 10178839.fls.doubleclick.net 6375438.fls.doubleclick.net api.measureone.com cdn.plaid.com js.stripe.com js.verygoodvault.com js3.verygoodvault.com *.rokt.com www.facebook.com; media-src 'self' glia-applets.com libs.glia.com libs.salemove.com; report-to https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub6266f5d846cb5713666132c0f0ffe817&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env:production; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub6266f5d846cb5713666132c0f0ffe817&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env:production; 1 script-src-elem *.google.com www.courseduck.com *.luckyorange.com static.klaviyo.com d10lpsik1i8c69.cloudfront.net static-tracking.klaviyo.com connect.facebook.net tags.srv.stackadapt.com www.googletagmanager.com www.google.com www.gstatic.com maps.googleapis.com www.googleadservices.com www.google-analytics.com qvdt3feo.com ff.kis.v2.scr.kaspersky-labs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem www.courseduck.com hello.myfonts.net *.luckyorange.com d10lpsik1i8c69.cloudfront.net static-tracking.klaviyo.com fonts.googleapis.com static.klaviyo.com p.typekit.net use.typekit.net tags.srv.stackadapt.com courseduck.com cdn.honey.io ff.kis.v2.scr.kaspersky-labs.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com static.klaviyo.com www.courseduck.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com youtu.be *.vimeo.com *.addthis.com https://www.googletagmanager.com/ *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.weltpixel.com td.doubleclick.net www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu blob: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com www.gstatic.com magefan.com cm.magefan.com www.google.ca d10lpsik1i8c69.cloudfront.net www.facebook.com connect.facebook.net d3k81ch9hvuctc.cloudfront.net d35y46dv539h1e.cloudfront.net www.edgenyc.com ussconstitutionmuseum.org www.google.co.uk www.greaterclevelandaquarium.com www.google.nl translate.google.com muzemerch.com www.seattleaquarium.org www.neaq.org zooknoxville.org stats.g.doubleclick.net cdn.honey.io www.google.co.nz www.google.ro www.google.ch intrepidmuseum.org www.google.com.co www.indianapoliszoo.com www.google.co.jp www.okaquarium.org www.google.fr www.google.be www.google.com.bo www.google.de tags.srv.stackadapt.com www.google.com.au 360chicago.com www.phoenixzoo.org lsc.org planetarium.unionstation.org sciencecity.unionstation.org www.naplesgarden.org www.google.ee www.google.com.mx www.google.si www.google.gr www.google.com.br www.google.se www.google.it www.catholic.edu perot-m.imgix.net storage.googleapis.com www.google.hu www.google.ie www.google.pl www.google.com.my www.google.at www.google.al www.google.com.tw www.google.fi www.google.co.th www.google.co.za www.google.cz www.google.co.kr www.google.cl www.google.no www.google.com.pr www.google.com.hk www.google.com.tr www.google.com.pe www.google.es www.google.com.qa www.google.com.mt maps.googleapis.com www.google.dk www.google.co.cr www.google.com.ec www.google.co.in www.google.pt lh3.googleusercontent.com www.google.com.sv www.zooknoxville.org www.google.com.pk www.google.com.cu www.google.com.ng www.google.co.id www.google.lt www.google.is www.nwtrek.org www.google.com.ph www.google.com.ar www.google.dz www.google.ru www.google.bg www.google.sc www.google.co.ve www.google.com.eg data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io maps.googleapis.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cdn-apple.com *.google-analytics.com static.klaviyo.com tools.luckyorange.com static-tracking.klaviyo.com www.google.com www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ tags.srv.stackadapt.com connect.facebook.net d10lpsik1i8c69.cloudfront.net qvdt3feo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com www.courseduck.com static.klaviyo.com use.typekit.net p.typekit.net www.gstatic.com tags.srv.stackadapt.com static-tracking.klaviyo.com hello.myfonts.net cdn.honey.io courseduck.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.luckyorange.com settings.luckyorange.com fast.a.klaviyo.com static-forms.klaviyo.com settings.luckyorange.net www.facebook.com tags.srv.stackadapt.com localhost:12387 www.google.ca api-js.datadome.co www.google.nl region1.google-analytics.com www.google.com.bo www.google.co.jp www.google.com.br www.google.be www.google.com.co www.google.co.uk www.google.at www.google.com.tw www.google.com.au www.google.com.hk www.google.fr ws://localhost:12387 www.google.com.tr www.google.pl www.google.com.pe www.google.ie www.google.com.mx stats.g.doubleclick.net www.google.co.ve 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' hippieartesanatos.com *.hippieartesanatos.com wake-components.fbitsstatic.net hippieartesanatos.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.g.doubleclick.net *.hippieartesanatos.com.br *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.sizebay.technology *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com mailbiz.one *.mailbiz.one *.jsdelivr.net cdn.jsdelivr.net *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.clarity.ms *.visa.com *.smarthint.co *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.hippieartesanatos.com hippieartesanatos.com; report-uri https://pub-csp.fbits.net/17e17b05-7eb5-413c-8e48-1267faa3074f; report-to https://pub-csp.fbits.net/17e17b05-7eb5-413c-8e48-1267faa3074f; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://pro.fontawesome.com https://www.tolvnow.com data: *.fontawesome.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net 'self' *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com https://d2d7do8qaecbru.cloudfront.net https://google.com https://ls.smct.io https://www.mercadolibre.com https://www.tolvnow.com https://tracker.tolvnow.com connect.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.pagaleve.io *.pagaleve.com.br c.paypal.com checkout.paypal.com assets.braintreegateway.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://h.online-metrix.net *.d.aa.online-metrix.net https://p.afilio.com.br https://newimgebit-a.akamaihd.net https://amcglobal.sc.omtrdc.net https://assets.adobedtm.com https://assets.braintreegateway.com https://*.behance.net https://c.bing.com https://b.stats.paypal.com https://c.paypal.com https://checkout.paypal.com https://c.clarity.ms https://o.clarity.ms https://cm.everesttech.net https://connect.facebook.net https://conectiva.io https://*.d.aa.online-metrix.net https://device.clearsale.com.br https://receiver.posclick.dinamize.com https://dpm.demdex.net https://dub.stats.paypal.com https://events.smct.co https://www.facebook.com/privacy_sandbox/ https://www.facebook.com/tr/ https://fpdbs.paypal.com https://fpdbs.sandbox.paypal.com https://*.ftcdn.net *.analytics.google.com https://www.google.com.br https://www.google.com/pagead/ https://ssl.gstatic.com https://googletagmanager.com https://*.mlstatic.com https://*.mercadopago.com https://mercadopago.com.br https://*.mercadopago.com.br https://*.mercadolibre.com https://*.mercadolibre.com.br https://*.mercadolivre.com https://www.paypal.com https://*.paypal.com https://www.paypalobjects.com https://www.sandbox.paypal.com https://t.paypal.com https://tracker.tolvnow.com https://p.typekit.net https://validator.swagger.io https://*.vimeocdn.com https://widgets.magentocommerce.com https://i.ytimg.com connect.facebook.net *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br *.mercadopago.com.br *.mlstatic.com *.pagaleve.com.br www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com *.vimeocdn.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.cdn-apple.com *.magento-datasolutions.com https://h.online-metrix.net https://h.online-metrix.net/fp/tags.js *.cardinalcommerce.com https://assets.adobedtm.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://api.edrone.me https://api-s.edrone.me https://app.cartstack.com.br https://assets.braintreegateway.com https://bam.nr-data.net https://c.paypal.com https://*.cardinalcommerce.com https://clarity.ms https://www.clarity.ms https://d3bo67muzbfgtl.cloudfront.net https://d2vfa2a1j2oldr.cloudfront.net https://d3vhsxl1pwzf0p.cloudfront.net https://dgk28ckagqims.cloudfront.net https://commerce.adobedtm.com https://commerce.adobe.net https://*.commerce-quick-checkout.com https://connect.facebook.net https://device.clearsale.com.br https://receiver.posclick.dinamize.com https://www.feedrapp.info https://geostag.cardinalcommerce.com https://google.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://tagmanager.google.com https://includestest.ccdc02.com https://js-agent.newrelic.com https://js.braintreegateway.com https://js.smct.io https://magento-recs-sdk.adobe.net https://*.mercadopago.com https://mercadopago.com.br https://*.mercadopago.com.br https://*.mercadolibre.com https://*.mercadolibre.com.br https://*.mercadolivre.com https://*.mlstatic.com https://*.nr-data.net https://www.paypal.com https://www.paypalobjects.com https://www.sandbox.paypal.com https://t.paypal.com https://*.paypal.com https://imgs.ebit.com.br https://*.ebit.com.br https://sdk.mercadopago.com https://secure.afilio.com.br https://smct.co https://*.smct.co https://songbird.cardinalcommerce.com https://songbirdstag.cardinalcommerce.com https://s.ytimg.com https://tracker.tolvnow.com https://tracker5.tolvnow.com https://unpkg.com https://use.typekit.net https://*.vimeocdn.com https://v18dxapjmd.execute-api.eu-west-1.amazonaws.com https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtm.js https://z.clarity.ms *.conectiva.io conectiva.io *.hotjar.com script.hotjar.com *.tolvnow.com tracker4.tolvnow.com static.trustvox.com.br https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://static.trustvox.com.br connect.facebook.net *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br *.mercadopago.com.br *.mlstatic.com *.pagaleve.com.br js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://assets.adobedtm.com https://clarity.ms https://d3bo67muzbfgtl.cloudfront.net https://cdn.dnky.co https://pro.fontawesome.com https://getfirebug.com https://fonts.googleapis.com https://webchat.dotdigital.com https://www.tolvnow.com https://tracker.tolvnow.com *.fontawesome.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'none'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.nr-data.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.magento-datasolutions.com *.magento-ds.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://assets.adobedtm.com https://amcglobal.sc.omtrdc.net https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://api.edrone.me https://api-s.edrone.me https://api.mercadopago.com https://api.mercadolibre.com https://api.performa.ai https://assets.braintreegateway.com https://bam.nr-data.net https://c.bing.com https://*.cardinalcommerce.com https://*.clarity.ms https://n.clarity.ms https://o.clarity.ms https://l.clarity.ms https://z.clarity.ms https://d3vhsxl1pwzf0p.cloudfront.net https://d3bo67muzbfgtl.cloudfront.net https://dgk28ckagqims.cloudfront.net https://d2vfa2a1j2oldr.cloudfront.net https://commerce.adobedtm.com https://commerce.adobe.net https://newimgebit-a.akamaihd.net https://*.akamaihd.net https://connect.facebook.net https://www.google.com https://www.google.com/ccm/collect https://*.google-analytics.com https://googleads.g.doubleclick.net https://www.feedrapp.info https://firehose.eu-west-1.amazonaws.com https://geostag.cardinalcommerce.com https://analytics.google.com https://stats.g.doubleclick.net https://includestest.ccdc02.com https://js-agent.newrelic.com https://js.braintreegateway.com https://*.mercadopago.com https://mercadopago.com.br https://*.mercadolibre.com https://*.mercadolivre.com https://*.mlstatic.com https://*.nr-data.net https://www.paypal.com https://www.paypalobjects.com https://receiver.posclick.dinamize.com https://songbird.cardinalcommerce.com https://js.smct.io https://*.smct.co https://tracker.tolvnow.com https://tracker5.tolvnow.com https://unpkg.com https://use.typekit.net https://*.vimeocdn.com wss://v18dxapjmd.execute-api.eu-west-1.amazonaws.com https://www.facebook.com https://api.ipify.org https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://static.trustvox.com.br connect.facebook.net https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://commerce.adobedc.net https://n.clarity.ms 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.clover.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com checkout.sandbox.dev.clover.com checkout.clover.com *.clover.com *.authorize.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com checkout.sandbox.dev.clover.com checkout.clover.com fhc-usa.com staging-aws.fhc-usa.com *.clover.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com checkout.sandbox.dev.clover.com checkout.clover.com *.clover.com *.authorize.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com checkout.sandbox.dev.clover.com checkout.clover.com *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.affirm.com *.affirm.ca *.getbread.com *.breadpayments.com *.rbcpayplan.com *.authorize.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.metalcloak.com *.armoredworks.com *.affirm.com *.affirm.ca *.getbread.com *.breadpayments.com *.rbcpayplan.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com *.disqus.com *.avada.io *.shopify.com *.authorize.net *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.affirm.com *.affirm.ca *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io *.authorize.net *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' *.gstatic.com use.fontawesome.com cdnjs.cloudflare.com cdn.jsdelivr.net; img-src 'self' data: *.eventdata.co.uk *.eventdata.uk eventdata.uk *.google-analytics.com px.ads.linkedin.com connect.facebook.com connect.facebook.net syndication.twitter.com; script-src-elem 'self' 'unsafe-hashes' 'unsafe-inline' *.eventdata.co.uk *.eventdata.uk eventdata.uk pay.dnapayments.com *.googletagmanager.com *.google-analytics.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.tiny.cloud app.webreg.me snap.licdn.com connect.facebook.net use.fontawesome.com platform.linkedin.com platform.twitter.com; script-src 'self' 'unsafe-hashes' 'unsafe-inline' connect.facebook.net; style-src 'self' *.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net *.eventdata.co.uk *.eventdata.uk eventdata.uk connect.facebook.net; style-src-elem 'self' 'unsafe-inline' *.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net *.eventdata.co.uk *.eventdata.uk eventdata.uk connect.facebook.net; style-src-attr 'unsafe-hashes' 'unsafe-inline'; worker-src 'self' blob:; frame-ancestors 'self'; connect-src 'self' *.google-analytics.com stats.g.doubleclick.net app.gleanin.com connect.facebook.com www.gov.uk; frame-src www.booking.com platform.twitter.com pay.dnapayments.com; report-uri https://qtq417pr.uriports.com/reports/report; report-to default 1 default-src 'self'; script-src 'self' 'unsafe-inline' *.gstatic.com cdnjs.cloudflare.com cdn.jsdelivr.net github.com *.staticflickr.com nominatim.openstreetmap.org matomo1.telmedia.fr; style-src 'unsafe-inline' *.pasdecalais.fr; img-src 'self' data: map.telmedia.fr; frame-src *.youtube.com *.youtube.fr; report-uri /report-csp-violation 1 default-src 'self' https:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; connect-src 'self' https://jv22carpcpzxxp5upcllfh2hzy0xbfjo.lambda-url.us-west-2.on.aws https://*.doubleclick.net https://cdn.segment.com https://secure.adnxs.com https://*.nitrocdn.com https://analytics.google.com https://www.googleadservices.com https://*.litix.io https://embedwistia-a.akamaihd.net https://js.hs-banner.com https://js.hs-analytics.net https://api.segment.io https://js.hs-scripts.com https://8o8h5taxx2-dsn.algolia.net https://*.google-analytics.com https://forms.hsforms.com https://cdn.linkedin.oribi.io wss://nexus-websocket-a.intercom.io https://api-iam.intercom.io https://api.intercom.io https://widget.intercom.io https://apps-api.getwarmly.com https://*.ingest.sentry.io https://*.fontawesome.com https://*.wistia.com https://*.wistia.net https://*.chilipiper.com https://*.linkedin.com https://api.hubspot.com https://unpkg.com https://to.getnitropack.com https://www.google.com https://pixel-config.reddit.com https://www.redditstatic.com https://conversions-config.reddit.com https://edge.fullstory.com https://rs.fullstory.com https://tag.clearbit.com https://tag.clearbitscripts.com https://snap.licdn.com https://lltrck.com https://js.hsforms.net; font-src 'self' data: https://*.nitrocdn.com https://*.wistia.com www.loom.com https://fonts.intercomcdn.com https://fonts.gstatic.com; frame-src 'self' blob: about: data: https://intercom-sheets.com https://www.youtube.com https://www.googleadservices.com https://www.stackhawk.com https://player.vimeo.com https://www.googletagmanager.com https://*.wistia.net https://*.wistia.com https://www.loom.com https://*.chilipiper.com; img-src 'self' data: https://*.nitrocdn.com https://*.adsymptotic.com https://images.ctfassets.net https://lltrck.com https://track.hubspot.com https://*.google-analytics.com https://*.google.com https://forms.hsforms.com https://js.intercomcdn.com https://static.intercomassets.com https://*.wistia.com https://*.wistia.net https://www.linkedin.com https://px4.ads.linkedin.com https://px.ads.linkedin.com https://www.googletagmanager.com https://forms-na1.hsforms.com https://forms.hsforms.com https://downloads.intercomcdn.com https://www.google.com https://www.google-analytics.com https://alb.reddit.com; manifest-src 'self' https://accounts.google.com; media-src 'self' blob: https://js.intercomcdn.com https://*.wistia.com https://embedwistia-a.akamaihd.net https://www.stackhawk.com; worker-src 'self' blob:; script-src-elem 'self' 'unsafe-inline' blob: https://*.nitrocdn.com https://nitroscripts.com https://www.googletagmanager.com https://kit.fontawesome.com https://unpkg.com https://snap.licdn.com https://widget.intercom.io https://scout-cdn.salesloft.com https://lltrck.com https://cdn.segment.com https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.chilipiper.com https://edge.fullstory.com https://tag.clearbitscripts.com https://www.redditstatic.com https://js.intercomcdn.com https://browser.sentry-cdn.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.doubleclick.net https://www.google.com https://*.googletagmanager.com https://*.google-analytics.com https://snap.licdn.com https://*.wistia.com https://*.litix.io https://analytics.google.com https://widget.intercom.io https://accounts.google.com https://cdn.segment.com https://js.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://lltrck.com https://js.intercomcdn.com https://scout-cdn.salesloft.com https://*.google.com https://forms.hsforms.com https://ajax.googleapis.com https://*.wistia.net https://www.googleadservices.com https://js.hsforms.net https://*.chilipiper.com https://unpkg.com https://*.fullstory.com https://tag.clearbit.com https://www.redditstatic.com https://to.getnitropack.com https://nitroscripts.com; style-src 'self' 'unsafe-inline' https://*.nitrocdn.com https://fonts.googleapis.com https://cdn.jsdelivr.net;;report-to default-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com commerce.adobedtm.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ www.google.com *.magento-ds.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com commerce.adobedtm.com commerce.adobedc.net *.snplow.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de webchat.dotdigital.com *.flixcar.com *.accvent.com *.forzaups.com *.1worldsync.com *.syndigo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.facebook.com *.facebook.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ts.tradetracker.net www.magmodules.eu magefan.com cm.magefan.com *.facebook.com *.facebook.net https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com tm.tradetracker.net *.facebook.com *.facebook.net *.googletagmanager.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.alothemes.com *.magepow.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.facebook.net *.google-analytics.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; child-src 'self' *.websiteni.com blob:; connect-src 'self' lottie.host *.googleapis.com *.facebook.net *.pay.com api.staging.pay.com api.pay.com matomo.mckinneycompetitions.com *.google-analytics.com *.cloudflare.com *.jsdelivr.net *.typekit.net *.unpkg.com *.culchiecomps.com; default-src 'self'; font-src 'self' fonts.gstatic.com fonts.googleapis.com *.jsdelivr.net *.cloudflare.com data: *.typekit.net *.cdn-apple.com; form-action 'self' www.facebook.com; frame-ancestors 'self' *.youtube.com *.youtube-nocookie.com; frame-src 'self' *.trustpilot.com *.pay.com universal.staging.pay.com universal.pay.com *.cardinalcommerce.com *.youtube.com *.youtube.com *.youtube-nocookie.com *.googletagmanager.com *.facebook.com; img-src 'self' mckinneycompetitions.com imagedelivery.net maps.gstatic.com maps.googleapis.com data: *.google.com *.facebook.com *.facebook.net *.googletagmanager.com *.google.co.uk *.google-analytics.com; media-src 'self'; object-src 'self'; script-src 'self' unpkg.com widget.trustpilot.com lottie.host fonts.googleapis.com maps.googleapis.com *.jquery.com *.cloudflare.com *.jsdelivr.net 'unsafe-inline' *.datatables.net 'unsafe-eval' *.lakedistrictgiveaways.co.uk *.facebook.net *.pay.com js.staging.pay.com www.googletagmanager.com matomo.mckinneycompetitions.com *.cdn-apple.com *.checkout.com *.doubleclick.net; style-src 'self' *.cloudflare.com *.jsdelivr.net fonts.googleapis.com widget.trustpilot.com lottie.host 'unsafe-inline' *.datatables.net maps.googleapis.com *.typekit.net; manifest-src 'self'; 1 base-uri 'self'; default-src 'self'; connect-src 'self' https://*.onetrust.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.co https://*.google-analytics.com https://www.googleadservices.com https://adservice.google.com https://www.facebook.com https://*.google-analytics.com; frame-ancestors 'none'; font-src 'self' data: 'unsafe-inline' https://fcdn.thg-corporate.com/; frame-src 'self' https://*.googletagmanager.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://player.vimeo.com https://*.vimeocdn.com https://*.facebook.com; img-src 'self' https://cdn.cookielaw.org https://fcdn.thg-corporate.com/ https://*.googletagmanager.com https://*.google-analytics.com https://www.facebook.com; child-src 'self'; script-src 'self' 'strict-dynamic' https://cdn.cookielaw.org https://cookie-cdn.cookiepro.co https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.googletagmanager.com https://*.google-analytics.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' data: https://fonts.googleapis.com https://fcdn.thg-corporate.com/; object-src 'none'; script-src-elem https://cdn.cookielaw.org https://cookie-cdn.cookiepro.co https://*.google.com https://www.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://connect.facebook.net; worker-src 'none'; media-src 'self' https://fcdn.thg-corporate.com/ https://*.gstatic.com; report-uri https://csp.thehut.net/cspReport.txt 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.sirv.com *.boldr.dev *.typekit.net https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: v2.zopim.com static.klaviyo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com account.fetchify.com https://www.googletagmanager.com/ platform.twitter.com www.xtento.com www.google.com/recaptcha/ www.paypalobjects.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.googleadservices.com www.google-analytics.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ pinterest.com assets.pinterest.com syndication.twitter.com *.sirv.com *.youtube.com www.xtento.com cdn.xtento.com stats.g.doubleclick.net www.google.com/ads/ga-audiences www.google.co.uk/ads/ga-audiences cdn.sensorydirect.com https://s.ytimg.com *.feefo.com *.vzaar.com log.pinterest.com v2.zopim.com bat.bing.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googleadservices.com www.google-analytics.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io twitter.com platform.twitter.com *.sirv.com player.vimeo.com *.klaviyo.com js.datadome.co www.xtento.com cdn.xtento.com www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.usersnap.com *.clerk.io *.feefo.com chimpstatic.com v2.zopim.com static.zdassets.com assets.pinterest.com bat.bing.com/ *.getsitecontrol.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cc-cdn.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.sirv.com *.klaviyo.com *.typekit.net https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.sirv.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.google-analytics.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.sirv.com vimeo.com *.youtube.com blob: *.klaviyo.com api-js.datadome.co *.google-analytics.com stats.g.doubleclick.net *.feefo.com widget-mediator.zopim.com ekr.zdassets.com wss://widget-mediator.zopim.com *.getsitecontrol.com *.getsitecontrol.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com 'self' data: *.skroutz.gr *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.bing.com *.zdassets.com *.google.com *.google.gr use.typekit.net *.converse.com *.soundestlink.com *.googletagmanager.com *.klarna.com *.pennie.gr *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.contactpigeon.com *.newrelic.com *.nr-data.net *.klarnacdn.net https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.google.gr *.facebook.com *.skroutz.gr *.zopim.com *.cloudflare.com *.converse.com *.klarna.com www.facebook.com *.contactpigeon.com *.pennie.gr *.moosend.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net widget-v3.boxnow.gr/ widget-v5.boxnow.cy cdn.dnky.co *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com *.skroutz.gr *.zopim.com *.cloudflare.com *.google.gr *.sandbox.paypal.com *.twitter.com *.converse.com td.doubleclick.net *.soundestlink.com widget-v3.boxnow.gr *.googletagmanager.com *.pinterest.com *.klarna.com *.contactpigeon.com www.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.gstatic.com *.googleapis.com *.google.com *.acscourier.net *.omnisnippet1.com *.omnisendlink.com *.google.gr *.google.nl *.google.co.in connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.gstatic.com *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.skroutz.gr *.moosend.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.io *.doubleclick.net *.converse.com *.soundestlink.com *.mastercard.com https://trustmark.gr *.tiktok.com *.contactpigeon.com *.pennie.gr www.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com https://omnisnippet1.com https://wt.soundestlink.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com *.paypal.com *.google.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytic.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com *.skroutz.gr *.moosend.com *.adobedtm.com *.cloudflare.com *.google.gr *.vimeo.com *.converse.com *.soundestlink.com widget-v3.boxnow.gr *.unpkg.com boxlockersloadfiles.blob.core.windows.net region1.analytics.google.com *.omnisnippet1.com *.omnisendlink.com *.pinimg.com *.pinterest.com *.klarna.com 'self' data: *.tiktok.com *.pennie.gr www.facebook.com *.doubleclick.net *.google-analytics.com *.contactpigeon.com https://trustmark.gr/badge/dist/index.js https://static.adman.gr/adman.js https://greca.adman.gr int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io connect.facebook.net graph.facebook.com business.facebook.com https://omnisnippet1.com https://forms.soundestlink.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net *.skroutz.gr *.zopim.com *.moosend.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.converse.com *.soundestlink.com *.unpkg.com *.googletagmanager.com *.klarna.com www.googleadservices.com www.google-analytics.com vimeo.com *.pennie.gr *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.contactpigeon.com *.newrelic.com *.nr-data.net *.hotjar.com *.klarnacdn.net https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.google.gr *.zopim.com *.skroutz.gr *.klarna.com *.cloudflare.com *.converse.com 'self' data: *.contactpigeon.com *.pennie.gr *.moosend.com 'self' 'unsafe-inline'; manifest-src *.pennie.gr 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google.gr *.paypal.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net https://stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.clarity.ms connect.facebook.net *.datatrics.com *.skroutz.gr region1.analytics.google.com *.cloudflare.com *.converse.com *.soundestlink.com boxlockersloadfiles.blob.core.windows.net wss://*.hotjar.com *.pinterest.com *.omnisendlink.com *.klarna.com *.googleadservices.com *.googleapis.com *.gstatic.com *.mastercard.com *.google.com *.googletagmanager.com *.tiktok.com *.contactpigeon.com *.pennie.gr https://googleads.g.doubleclick.net/ api.zevioo.com https://pagead2.googlesyndication.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io www.facebook.com graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'unsafe-inline' 'self' *.facebook.com *.google.com *.gstatic.com *.bbb.org *.authorize.net *.google-analytics.com *.googleadservices.com *.googleapis.com *.doubleclick.net *.hcaptcha.com *.cloudflare.com *.klaviyo.com *.trustpilot.com *.googletagmanager.com *.bing.com *.cloudflareinsights.com *.facebook.net; frame-ancestors 'self'; img-src 'self' data: *.rightwayparking.com *.google.com *.bing.com *.facebook.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.doubleclick.net *.gstatic.com *.authorize.net *.bbb.org; default-src https: 'unsafe-inline' 'self' *.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.g.doubleclick.net *.hcaptcha.com *.cloudflare.com *.klaviyo.com *.trustpilot.com *.googletagmanager.com *.bing.com *.cloudflareinsights.com *.facebook.net *.strip.com; 1 font-src *.googleapis.com *.gstatic.com data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com *.gstatic.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src caixabankresearch.com *.caixabankresearch.com clarity.ms *.clarity.ms doubleclick.net *.doubleclick.net everviz.com *.everviz.com google-analytics.com *.google-analytics.com google.com *.google.com google.es *.google.es googletagmanager.com *.googletagmanager.com gstatic.com *.gstatic.com highcharts.com *.highcharts.com jsdelivr.net *.jsdelivr.net polyfill.io *.polyfill.io; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=tI0o_whHhWiPU7pno5uB4mTQ0DOY2PPDT7TVrQA5uOU-1765934369.7720132-1.0.1.1-QWfDnMVxNAm09wYq8FN2fTA5H44rhZP7masd4YASgAsOw_vSeW1ylD6VztE3S5Ueeeu6ZlfbOxFRy16SMLhwa4I5kWS65LkP60dEdhoEOyiiFSqPlGKxNnqDpGEfCbPyUzgI7x4Ri_oGDw6N8JTOkBh.i0wcjik_zLwLcSZMDMvpzdb6I_iJyX5UQpUXk..o3lL0Cu7yZbybOiFHkAAqog; report-to cf-wpyauwraijliqodi 1 report-uri https://csp.threatview.app/report; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.googleapis.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com 'self' data: *.cngln.com *.paypalobjects.com http://cngln.com https://cngln.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com *.cash.app *.affirm.com *.affirm.ca *.klarna.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.criteo.com *.demdex.net *.sumo.com *.360vr.ie *.facebook.com *.afterpay.com *.wesupply.xyz https://wesupplylabs.com *.cngln.com http://cngln.com https://cngln.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afterpay.com/ *.cash.app *.affirm.com *.affirm.ca *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.wdgtest.com *.glencara.com *.shopperapproved.com *.bing.com *.zdassets.com *.everesttech.net *.omtrdc.net *.zopim.io *.feefo.com *.facebook.com *.googletagmanager.com *.clarity.ms *.google.lt *.cngln.com *.usercentrics.eu http://cngln.com https://cngln.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.affirm.com *.affirm.ca *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net https://cdn.jsdelivr.net *.avada.io *.shopify.com *.fontawesome.com *.googleapis.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sumome.com *.sumo.com *.shopperapproved.com *.zdassets.com *.bing.com *.criteo.net *.criteo.com *.feefo.com *.cloudflare.com *.paysafe.com *.facebook.net http://unpkg.com https://unpkg.com *.facebook.com *.zopim.com *.google.lt *.clarity.ms *.smartlook.com *.cngln.com *.cloudflareinsights.com *.unpkg.com unpkg.com *.usercentrics.eu http://cngln.com https://cngln.com *.zendesk.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.cash.app *.klarnacdn.net *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com *.cngln.com http://cngln.com https://cngln.com https://www.shopperapproved.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.cngln.com http://cngln.com https://cngln.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.affirm.com *.affirm.ca *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com http://sumo.com https://sumo.com *.bing.com *.feefo.com *.demdex.net *.facebook.com *.amazonaws.com *.paysafe.com *.clarity.ms *.smartlook.com *.smartlook.cloud *.cngln.com wss://*.zendesk.com *.usercentrics.eu http://cngln.com https://cngln.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com https://use.typekit.net https://fonts.gstatic.com/ https://p.typekit.net/ https://fonts.googleapis.com/ *.cdnfonts.com *.fontawesome.com *.klaviyo.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com https://www.rsa3dsauth.co.uk/ *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://widget.trustpilot.com/ https://consentcdn.cookiebot.com/ https://www.rsa3dsauth.co.uk/ www.xtento.com *.doubleclick.net *.facebook.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afd.co.uk www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://media.jtatkinson.co.uk/ https://imgsct.cookiebot.com/ www.xtento.com cdn.xtento.com *.cookiebot.com *.doubleclick.net *.facebook.com *.facebook.net *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bi www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tn www.google.tt www.google.ws *.googletagmanager.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com polyfill.io *.afd.co.uk www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widget.trustpilot.com/ https://consent.cookiebot.com https://consentcdn.cookiebot.com www.xtento.com cdn.xtento.com *.cookiebot.com *.doubleclick.net *.facebook.net *.googleapis.com *.googletagmanager.com *.klaviyo.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.trustpilot.com https://use.typekit.net https://fonts.gstatic.com/ https://p.typekit.net/ https://fonts.googleapis.com/ *.fontawesome.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.klaviyo.com *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://apps.afd.co.uk www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://consentcdn.cookiebot.com https://consent.cookiebot.com *.algolia.io *.algolia.net *.algolianet.com *.datadome.co *.doubleclick.net *.facebook.com *.google-analytics.com *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.sr www.google.tn www.google.tt *.klaviyo.com *.samsung.com *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b3c2c731-63d3-4340-a29a-f72f0bda06ca.sansec.watch/; report-to report-endpoint; 1 default-src 'self' https://www.googletagmanager.com/; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-ecedb85bc7404a4fb8324b2c28ddf450' https://myconnection.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://myconnection.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' data: blob: https://*.s3.us-east-2.amazonaws.com https://s3.us-east-2.amazonaws.com https://*.ender.com https://ender.com https://googletagmanager.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.stripe.com; connect-src 'self' https://*.ender.com https://*.ingest.us.sentry.io https://www.google-analytics.com https://edge.fullstory.com https://rs.fullstory.com https://api.sentry.io https://maps.googleapis.com https://*.googleapis.com https://maps.gstatic.com https://api.stripe.com https://*.s3.us-east-2.amazonaws.com https://s3.us-east-2.amazonaws.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://production.plaid.com/; font-src 'self' https://fonts.gstatic.com data:; frame-src https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com https://app.hellosign.com https://cdn.plaid.com; script-src 'self' 'unsafe-inline' https://*.js.stripe.com https://cdn.jsdelivr.net https://js.stripe.com https://maps.googleapis.com https://cdn.plaid.com https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://*.googletagmanager.com http://edge.fullstory.com https://cdn.hellosign.com; worker-src 'self' blob:; child-src 'self' blob:; object-src 'none'; frame-ancestors 'none'; report-to csp-endpoint; report-uri https://dev.ender.com/csp/reports 1 font-src *.azureedge.net https://use.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: instantcredit.net test.instantcredit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com www.google.com www.gstatic.com apis.google.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io camo.githubusercontent.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypalobjects.com *.google.com *.google.es *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.googleapis.com cdn-cookieyes.com *.paycomet.com *.vimeo.com *.facebook.net *.facebook.com cdn-images.mailchimp.com c.clarity.ms *.bing.com *.mcusercontent.com *.azureedge.net https://firebasestorage.googleapis.com flagpedia.net blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com instantcredit.net test.instantcredit.net *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.paypalobjects.com *.googleadservices.com *.googleadservices.es *.google-analytics.com *.googletagmanager.com *.googleapis.com *.g.doubleclick.net *.tiktok.com *.paycomet.com *.facebook.net *.facebook.com cdn-cookieyes.com *.clarity.ms *.authorize.net 'self' data: *.oct8ne.com *.hotjar.com *.sentry-cdn.com *.bing.com *.googlesyndication.com *.google.com *.gstatic.com *.avada.io *.shopify.com maps.googleapis.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.bootstrapcdn.com *.klaviyo.com https://use.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com instantcredit.net test.instantcredit.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.paypal.com *.demdex.net *.cookieyes.com cdn-cookieyes.com *.tiktok.com *.clarity.ms *.google.com *.googleadservices.es *.google-analytics.com *.googletagmanager.com *.googleapis.com *.doubleclick.net *.oct8ne.com *.hotjar.com *.hotjar.io *.klaviyo.com *.googleadservices.com *.cardinalcommerce.com *.paypalobjects.com *.googlesyndication.com *.ingest.sentry.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com google.com instantcredit.net *.instantcredit.net *.facebook.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://prod.radiozamaneh.org https://s3.eu-de.cloud-object-storage.appdomain.cloud/static-reflection/ https://static-reflection.netlify.app https://i.zamaneh.media https://*.contentinsights.com https://*.smartocto.com https://www.googleapis.com https://attestation.android.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://*.googlesyndication.com https://csi.gstatic.com https://*.adtrafficquality.google; font-src 'self'; img-src 'self' https://i.zamaneh.media https://*.contentinsights.com https://i.ytimg.com https://www.google.com https://*.doubleclick.net https://*.googlesyndication.com data:; script-src 'self' 'unsafe-inline' *; style-src 'self' 'unsafe-inline'; frame-src https://platform.twitter.com https://www.youtube-nocookie.com https://www.instagram.com https://w.soundcloud.com https://www.google.com https://*.googlesyndication.com https://www.googleadservices.com https://securepubads.g.doubleclick.net; report-uri https://snfbtd92.uriports.com/reports/report; report-to policy 1 script-src * 'unsafe-inline' 'unsafe-eval'; script-src-attr 'self' 'unsafe-inline'; script-src-elem * 'unsafe-inline'; style-src * 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hs-scripts.com www.googletagmanager.com *.hs-banner.com *.usemessages.com *.hsadspixel.net *.hs-analytics.net *.hsleadflows.net yoast.com *.hsappstatic.net *.hsforms.net *.hiss3lark.com *.googleapis.com *.hubspot.com *.cookiebot.com *.whizeo.com *.licdn.com *.doubleclick.net *.hotjar.com; style-src 'self' *.googleapis.com *.typekit.net 'unsafe-inline'; font-src 'self' fonts.gstatic.com use.typekit.net data:; frame-src *.myairops.com *.hubspot.com *.hsforms.com *.cookiebot.com *.doubleclick.net *.googletagmanager.com; connect-src 'self' www.google-analytics.com *.hubspot.com *.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com region1.google-analytics.com *.hubapi.com *.whizeo.com *.linkedin.com *.google.com *.hotjar.com *.hotjar.io yoast.com ws:; img-src 'self' 'unsafe-inline' *.hubspot.com secure.gravatar.com *.hsforms.com *.cookiebot.com *.linkedin.com *.google.com *.google.co.uk data:; worker-src 'self' blob:; report-uri https://x0k4afwe.uriports.com/reports/report; report-to default 1 default-src 'self' https:; object-src 'none'; connect-src 'self' https: https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https: https://www.googletagmanager.com; img-src 'self' https: https://www.googletagmanager.com https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com data:; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https: https://fonts.gstatic.com data:; script-src 'self' https: 'unsafe-eval' 'nonce-xG1dgFh7Yk+jt3Al7OrA+w=='; report-uri /csp_violations 1 default-src 'self' 'nonce-41tUlN7zbytThgO/YibBWA==' blob: data: ws: wss: finsight.com *.finsight.com *.finsight.com www.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.googleapis.com unpkg.com *.amazonaws.com *.twilio.com *.zoom.us *.metered.ca ws.zoominfo.com snap.licdn.com px.ads.linkedin.com cdn.linkedin.oribi.io *.frontapp.com sessions.bugsnag.com *.turbobridge.com *.sentry.io https://otel.use1.workload.production.finsight-operations-live.com; script-src 'self' 'report-sample' 'nonce-41tUlN7zbytThgO/YibBWA==' 'strict-dynamic' ; style-src 'self' 'report-sample' 'unsafe-inline' blob: finsight.com *.finsight.com *.finsight.com www.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.googleapis.com unpkg.com *.amazonaws.com *.twilio.com *.zoom.us *.metered.ca ws.zoominfo.com snap.licdn.com px.ads.linkedin.com cdn.linkedin.oribi.io *.frontapp.com sessions.bugsnag.com *.turbobridge.com *.sentry.io https://otel.use1.workload.production.finsight-operations-live.com; base-uri 'self'; script-src-elem 'self' 'report-sample' 'nonce-41tUlN7zbytThgO/YibBWA==' www.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.googleapis.com unpkg.com *.amazonaws.com *.twilio.com *.zoom.us *.metered.ca ws.zoominfo.com snap.licdn.com px.ads.linkedin.com cdn.linkedin.oribi.io *.frontapp.com sessions.bugsnag.com *.turbobridge.com *.sentry.io https://otel.use1.workload.production.finsight-operations-live.com; frame-ancestors 'self' https://finsight.com https://users.finsight.com https://dealroadshow.finsight.com https://condor.finsight.com https://manager.finsight.com https://dealvdr.com https://loansend.com https://17g5.com https://investorset.com https://verisend.com https://researchroom.com https://evercall.co https://api.finsight.com https://assets.finsight.com https://openmarket.finsight.com https://allocate.finsight.com https://creditflowresearch.com https://stage20.quantumcf.com https://www.quantumcf.com https://bi-staging.quantumcf.com; report-uri /browser/csph-analytics; report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com 'self' data: *.threatview.app data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.threatview.app 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net *.threatview.app 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ *.dotdigital-pages.com *.dotdigital.com www.google.com *.certcapture.com https://www.googletagmanager.com/ *.authorize.net *.doubleclick.net *.weltpixel.com paypalobjects.com *.paypalobjects.com *.adroll.com *.threatview.app 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.certcapture.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.facebook.com *.google.co.in ups.analytics.yahoo.com *.bidswitch.net *.openx.net *.adnxs.com *.bing.com *.listrakbi.com *.clarity.ms 'self' data: *.ads.linkedin.com *.linkedin.com *.adroll.com *.yahoo.com *.analytics.yahoo.com lhasaoms.com listrakbi.com *.tapad.com *.threatview.app data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.authorize.net *.lhasaoms.com *.facebook.net *.bing.com *.clarity.ms *.listrakbi.com https://www.googletagmanager.com tagmanager.google.com *.adroll.com *.licdn.com wisepops.net *.wisepops.com lhasaoms.com *.threatview.app 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com *.bootstrapcdn.com *.listrakbi.com *.trackedweb.net *.googleapis.com *.gstatic.com tagmanager.google.com *.threatview.app 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.threatview.app 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.certcapture.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.authorize.net *.clarity.ms *.bing.com *.google-analytics.com https://www.google-analytics.com *.adroll.com *.linkedin.com *.threatview.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.threatview.app 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com dhv2ziothpgrr.cloudfront.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.certcapture.com *.finelinens.com https://www.facebook.com *.affirm.com www.finelinens.com admin.finelinens.com *.lltrck.com https://www.google.pl https://redchamps.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ dhv2ziothpgrr.cloudfront.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com https://tags.tiqcdn.com https://s7.addthis.com https://static.zdassets.com https://connect.facebook.net https://cdnjs.cloudflare.com/ *.hotjar.com *.attn.tv *.attentivemobile.com *.hotjar.io *.cloudflareinsights.com www.finelinens.com admin.finelinens.com *.lltrck.com https://ai-search-portal.gscadmin.com *.termly.io https://staticw2.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.certcapture.com https://www.googletagmanager.com https://static.klaviyo.com dhv2ziothpgrr.cloudfront.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://static.zdassets.com www.finelinens.com admin.finelinens.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.certcapture.com https://ekr.zdassets.com wss://widget-mediator.zopim.com https://region1.google-analytics.com https://finelinens.zendesk.com *.attn.tv *.attentivemobile.com *.hotjar.io *.hotjar.com wss://ws.hotjar.com https://dp70uvwpivouv.cloudfront.net www.finelinens.com admin.finelinens.com https://ai-search-portal.gscadmin.com *.termly.io *.googlesyndication.com https://staticw2.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://*.dnafactory.it https://*.dnalab.online *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.dnafactory.it https://*.dnalab.online https://*.yahoo.net https://*.criteo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://*.dnafactory.it https://*.dnalab.online https://*.yahoo.net https://*.criteo.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.revolut.com *.google.com *.cdn-apple.com google.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com https://cdn.clerk.io *.feedaty.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.feedaty.com https://*.dnafactory.it https://*.dnalab.online https://*.omappapi.com https://*.liberotech.it https://liberotech.it https://*.bing.com https://*.yahoo.net https://*.criteo.com https://*.krxd.net https://*.thebrighttag.com https://*.doubleclick.net https://*.bidswitch.net https://*.adnxs.com https://*.media.net https://*.rubiconproject.com https://*.smartadserver.com https://*.taboola.com https://*.teads.tv https://*.3lift.com https://*.adform.net https://*.omnitagjs.com https://*.casalemedia.com https://id5-sync.com https://*.360yield.com https://*.ivitrack.com https://*.mediavine.com https://*.postrelease.com https://*.outbrain.com https://*.pubmatic.com https://*.sharethrough.com https://*.tremorhub.com https://*.yieldlab.net https://*.yieldmo.com https://*.emxdgt.com https://*.kelkoogroup.net https://*.1rx.io https://*.unrulymedia.com/ https://firebasestorage.googleapis.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.clerk.io https://cdn.clerk.io *.feedaty.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.clerk.io https://*.feedaty.com https://*.dnafactory.it https://*.dnalab.online https://*.facebook.net https://*.criteo.com https://*.omappapi.com https://*.addthis.com https://*.bing.com https://*.kk-resources.com https://*.twenga.it https://*.yandex.ru https://*.yandex.com https://*.yahoo.net https://*.googlesyndication.com *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com *.revolut.com *.google.com *.cdn-apple.com google.com https://*.trovaprezzi.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com *.doofinder.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com https://*.feedaty.com https://*.dnafactory.it https://*.dnalab.online https://*.omappapi.com https://*.yahoo.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.multisafepay.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.dnafactory.it https://*.dnalab.online https://*.yahoo.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.feedaty.com *.doofinder.com wss://*.doofinder.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.feedaty.com https://*.dnafactory.it https://*.dnalab.online google.com https://google.com https://*.google-analytics.com https://*.omappapi.com https://*.liberotech.it https://liberotech.it https://*.scalapay.com https://*.yandex.ru https://*.yandex.com https://*.criteo.com https://*.yahoo.net https://*.googlesyndication.com https://*.kelkoogroup.net https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; report-uri https://www.mangelot-hosting.nl/cspro-report.php; frame-src 'self' https://*.google.com; connect-src 'self' https://*.mangelot-hosting.nl https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.ipify.org https://stats.g.doubleclick.net https://www.google.com https://*.speedtest.clouvider.net; font-src 'self' https://*.mangelot-hosting.nl https://*.gstatic.com https://cdn.linearicons.com https://cdn.mangelot-hosting.nl data:; script-src 'self' https://*.mangelot-hosting.nl https://www.googletagmanager.com https://www.gstatic.com https://*.google.com https://yoast.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.mangelot-hosting.nl https://cdn.linearicons.com https://fonts.googleapis.com https://www.gstatic.com 'unsafe-inline'; img-src 'self' blob: https://*.mangelot-hosting.nl data: https://*.google.nl https://*.google.com https://www.abuseipdb.com https://ps.w.org https://*.gravatar.com; media-src 'self' https://*.mangelot-hosting.nl; object-src 'none'; form-action 'self' https://mangelot-hosting.nl https://www.mangelot-hosting.nl https://*.mangelot-hosting.nl; frame-ancestors 'self'; worker-src 'self' blob:; default-src 'self' https://*.mangelot-hosting.nl 1 default-src 'self' https:; script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'sha256-FgsRaC2wBMgmedvk2SXcGKsyBm50noDD3zf6UJRVP7k=' 'sha256-sIipYTcDXago7BpGL7wl7yB1iyTRXgSUHMp2v3kNC4I=' 'sha256-2Qvq1ZFy2JexWoTCsWb3nXre5pYhIM6l1B98+1EqIlc=' 'sha256-Rsmtt0AsshyP5tiWY1DxT2qh/HpD6r5kvaGCeicOiWQ=' 'sha256-1xuiy3MqFFVkOxnVMJ3DhLzEgZsJVXKwvM1aQ3m67FU=' 'sha256-D9AOuhvW2pdpSpw5pcjiiGRL2wIJlo803FQriOAeJQA=' 'sha256-9fUduH8H6H2qqoIUT9CZTWSWc3qy8gAzpn6PpB2vlsc=' 'sha256-5qYFuvhns+xjRODaV9/ehkmO/8NzZaAcNWTuzup3yUA=' 'sha256-vdLoM684v2tlPllVwTa6zCbIIaJV17lcDPV+vQE1jkE=' 'sha256-OfPAsCm/8I9s314sbXuIAbU5vl5iefFBgEMKVFAeRLw=' 'sha256-Ch5ldUlPTacuox1ug3oUOGNJcvIb7m1xEzlsxVYSzLY=' 'sha256-VFMgclD6e3bBOHH9570M8KQ7e0WGZJKxshOciJ7vxYA=' 'sha256-4pddxvOWXRP/eY8qInSuIyad1dVUQDMV35GYRMdWl0M=' 'sha256-GYNiwrOA+cdO5DjYkz3C1hF4qOJkPNui5I+oAGXswQM=' 'sha256-Xl3KAp9nsVVEV64As4eztFIxtx/n4fbkEgxCgs8fniE=' 'sha256-aEf2gs+Z0gX8jabqlKcEdFYyn7NrW2yzMWj3YZY8hXI=' https://widget.iflat.io https://apimacro.interstroi.com.ru https://code.jivo.ru https://*.roistat.com https://cdn.botfaqtor.ru https://st.top100.ru https://counter.rambler.ru https://mc.yandex.ru https://smartcaptcha.yandexcloud.net https://api-maps.yandex.ru https://yastatic.net; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https://counter.rambler.ru https://mc.yandex.ru https://yastatic.net https://files.jivosite.com https://code.jivo.ru; font-src 'self' data: https:; connect-src 'self' https://mc.yandex.md https://iflat.io https://cnt.rambler.ru https://kraken.rambler.ru https://5-182-5-41.botfaqtor.ru https://node-sber1-az1-24.jivosite.com https://telemetry.jivosite.com https://gw.botfaqtor.ru https://code.jivo.ru https://mc.yandex.ru wss://mc.yandex.ru wss://vi-sber1-23.jivosite.com; report-uri /csp-reports; 1 font-src *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.google.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.google.ca www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.app.goo.gl *.hotjar.com *.newrelic.com *.nr-data.net *.google-analytics.com https://diffuser-cdn.app-us1.com/ https://prism.app-us1.com/ www.google.ca www.google.com songbirdstag.cardinalcommerce.com c.paypal.com js.braintreegateway.com assets.braintreegateway.com api.braintreegateway.com client-analytics.braintreegateway.com *.cloudflare.com *.fontawesome.com *.twitter.com *.twimg.com *.trustedshops.com scontent.cdninstagram.com cdn.lightwidget.com pay.google.com api.sandbox.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.gstatic.com *.usercentrics.eu *.google.com maps.googleapis.com lightwidget.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.app.goo.gl *.hotjar.io wss://ws.hotjar.com/ *.newrelic.com *.nr-data.net *.google-analytics.com https://diffuser-cdn.app-us1.com/ https://prism.app-us1.com/ www.google.ca www.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.blc.edu https://*.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://www.google.com https://www.gstatic.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://*.blc.edu https://fonts.googleapis.com https://use.typekit.net https://*.adobe.com; img-src 'self' data: blob: https://*.blc.edu https://*.cloudflare.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.facebook.com https://i.ytimg.com; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://*.adobe.com https://*.blc.edu; frame-src 'self' https://www.youtube.com https://www.google.com https://*.blc.edu; connect-src 'self' https://*.blc.edu https://www.google-analytics.com https://www.googletagmanager.com https://www.facebook.com; 1 script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; report-uri /csp-report 1 font-src i.icomoon.io fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.googletagmanager.com ct.pinterest.com www.facebook.com *.adobedtm.com *.omniture.com *.matomo.org *.hotjar.com *.crazyegg.com tags.tiqcdn.com *.facebook.net snap.licdn.com platform.linkedin.com *.twitter.com cdn.taboola.com trc.taboola.com cdn.optimizely.com cdn.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com *.salesforce.com *.exacttarget.com chimpstatic.com mc.us1.list-manage.com *.sendgrid.com hubspot.com hsforms.com hs-analytics.net assets.pinterest.com *.instagram.com static.zdassets.com static.zendesk.com widget.intercom.io api.intercom.io js.driftt.com js-agent.newrelic.com cdn.cookielaw.org cdn.onetrust.com *.cookiebot.com *.tiktok.com *.klaviyo.com *.bing.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com maps.gstatic.com maps.googleapis.com www.facebook.com *.omniture.com *.mxpnl.com *.matomo.org *.hotjar.com *.crazyegg.com snap.licdn.com platform.linkedin.com *.twitter.com cdn.taboola.com trc.taboola.com cdn.optimizely.com cdn.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com *.salesforce.com *.exacttarget.com chimpstatic.com mc.us1.list-manage.com *.sendgrid.com hubspot.com hsforms.com hs-analytics.net assets.pinterest.com *.instagram.com static.zdassets.com static.zendesk.com widget.intercom.io api.intercom.io cdn.cookielaw.org cdn.onetrust.com *.cookiebot.com *.tiktok.com *.klaviyo.com *.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ moogento.com *.moogento.com *.multisafepay.com https://redchamps.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com *.hotjar.com *.facebook.net s.pinimg.com ct.pinterest.com *.omniture.com *.adobedtm.com *.mxpnl.com *.matomo.org *.crazyegg.com tags.tiqcdn.com snap.licdn.com platform.linkedin.com *.twitter.com cdn.taboola.com trc.taboola.com cdn.optimizely.com cdn.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com *.salesforce.com *.exacttarget.com chimpstatic.com mc.us1.list-manage.com *.sendgrid.com hubspot.com hsforms.com hs-analytics.net assets.pinterest.com *.instagram.com static.zdassets.com static.zendesk.com widget.intercom.io api.intercom.io js.driftt.com js-agent.newrelic.com cdn.cookielaw.org cdn.onetrust.com *.cookiebot.com *.tiktok.com *.klaviyo.com *.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ l2.moogento.com *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src i.icomoon.io fonts.googleapis.com *.typekit.net *.google-analytics.com analytics.google.com *.omniture.com *.adobedtm.com *.mxpnl.com *.matomo.org *.hotjar.com *.crazyegg.com tags.tiqcdn.com *.facebook.net snap.licdn.com platform.linkedin.com *.twitter.com cdn.taboola.com trc.taboola.com cdn.optimizely.com cdn.visualwebsiteoptimizer.com dev.visualwebsiteoptimizer.com *.salesforce.com *.exacttarget.com chimpstatic.com mc.us1.list-manage.com *.sendgrid.com hubspot.com hsforms.com hs-analytics.net assets.pinterest.com *.instagram.com static.zdassets.com static.zendesk.com widget.intercom.io api.intercom.io js.driftt.com js-agent.newrelic.com cdn.cookielaw.org cdn.onetrust.com *.cookiebot.com *.tiktok.com *.klaviyo.com *.bing.com https://static.klaviyo.com *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com stats.g.doubleclick.net maps.googleapis.com ct.pinterest.com www.facebook.com *.hotjar.io *.google.com *.googleadservices.com pagead2.googlesyndication.com *.omniture.com *.mxpnl.com *.matomo.org *.hotjar.com *.crazyegg.com *.facebook.net snap.licdn.com platform.linkedin.com *.twitter.com trc.taboola.com dev.visualwebsiteoptimizer.com *.salesforce.com *.exacttarget.com chimpstatic.com mc.us1.list-manage.com *.sendgrid.com hubspot.com hsforms.com hs-analytics.net *.pinterest.com *.instagram.com static.zdassets.com static.zendesk.com widget.intercom.io api.intercom.io js.driftt.com bam.nr-data.net rum-static.pingdom.net *.cookiebot.com *.tiktok.com *.klaviyo.com *.bing.com api-js.datadome.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.multisafepay.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' platform.instagram.com www.instagram.com google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: fonts.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: secure.gravatar.com www.gravatar.com data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com www.googletagmanager.com; connect-src 'self' www.google-analytics.com stats.g.doubleclick.net ampcid.google.com analytics.google.com about: www.googletagmanager.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; object-src * ; media-src * ; frame-src 'self' www.instagram.com www.googletagmanager.com; manifest-src * ; child-src 'self' www.googletagmanager.com; worker-src * ; base-uri * ; form-action * ; frame-ancestors * ; prefetch-src * ; block-all-mixed-content; report-uri https://flagee.cloud?gdsih-csp-report; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io *.googleapis.com *.stamped.io *.gstatic.com *.shopassistant-ai.com preeziestaticcontent.blob.core.windows.net blob.core.windows.net core.windows.net windows.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.localhost.com *.paymentexpress.com *.windcave.com cdn1.stamped.io 'self' 'unsafe-inline'; frame-ancestors cdn1.stamped.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.localhost.com *.paymentexpress.com *.windcave.com *.doubleclick.net *.ladesk.com *.laybuy.com *.authorize.net *.cardinalcommerce.com *.weltpixel.com www.google.com/recaptcha *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co *.nos.to * *.afterpay.com *.shopassistant-ai.com cdn1.stamped.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io *.ladesk.com *.googleapis.com *.laybuy.com *.trackjs.com *.paypal.com *.mailchimp.com *.klaviyo.com *.nos.to *.gstatic.com * *.shopassistant-ai.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ api.addressfinder.io https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com chimpstatic.com downloads.mailchimp.com *.list-manage.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.avada.io cdn1.stamped.io stamped.io *.afterpay.com *.klaviyo.com *.ladesk.com *.googleapis.com *.trackjs.com cdn.trackjs.com *.nr-data.net script.hotjar.com static.hotjar.com www.google.com maps.googleapis.com assests.adobetm.com polyfill.io cdn-stamped-io.azureedge.net www.gstatic.com *.vimeo.com f.vimeocdn.com *.ytimg.com *.youtube.com www.youtube.com *.facebook.com *.facebook.net *.clarity.ms www.clarity.ms * *.shopassistant-ai.com https://www.googletagmanager.com tagmanager.google.com preeziecdn.azureedge.net *.azureedge.net portal.afterpay.com https://c.bing.com https://www.clarity.ms https://*.clarity.ms clarity.microsoft.com *.microsoft.com www.clarity.ms/tag data: https://www.clarity.ms/tag/ https://www.clarity.ms/tag/* www.clarity.ms/tag/* *.clarity.ms/tag/* clarity.ms/tag/* vimeocdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com downloads.mailchimp.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io *.googleapis.com *.stamped.io *.shopassistant-ai.com tagmanager.google.com static.klaviyo.com 'self' 'unsafe-inline'; object-src cdn1.stamped.io 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src cdn1.stamped.io 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ get.geojs.io *.avada.io cdn1.stamped.io stamped.io *.klaviyo.com *.googleapis.com *.stamped.io *.trackjs.com *.azurewebsites.net *.shopassistant-ai.com https://www.google-analytics.com *.clarity.ms www.clarity.ms stats.g.doubleclick.net bam.nr-data.net in.hotjar.com *.hotjar.com prod-api-v1-core.azurewebsites.net azurewebsites.net 'self' 'unsafe-inline'; child-src cdn1.stamped.io http: https: blob: 'self' 'unsafe-inline'; default-src https://c.bing.com https://www.clarity.ms https://*.clarity.ms clarity.microsoft.com *.microsoft.com www.clarity.ms www.clarity.ms/tag *.clarity.ms data: https://www.clarity.ms/tag/ https://www.clarity.ms/tag/* www.clarity.ms/tag/* *.clarity.ms/tag/* clarity.ms/tag/* cdn1.stamped.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri cdn1.stamped.io 'self' 'unsafe-inline'; 1 worker-src 'none'; font-src 'self' data: https://maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com 'self' https://js.stripe.com *.google.com *.weltpixel.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.adobedtm.com *.cloudflare.com *.googleadservices.com *.google-analytics.com maps.googleapis.com *.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.ratepay.com https://maps.googleapis.com https://player.vimeo.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.adobedtm.com *.avada.io amcglobal.sc.omtrdc.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com *.cardinalcommerce.com songbirdstag.cardinalcommerce.com *.commerce-payment-services.com *.cloudflare.com *.cloudflareinsights.com *.google-analytics.com googletagmanager.com *.googletagmanager.com apis.google.com *.googleapis.com *.googleadservices.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.gstatic.com/recaptcha https://www.google.com/recaptcha google.com *.google.com *.google.com/ https://maps.googleapis.com/maps/api/js *.instagram.com jscloud.net klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.magento-ds.com *.paypalobjects.com c.paypal.com *.paypal.com sandbox.paypal.com *.sandbox.paypal.com https://js.stripe.com/v3/ *.stripe.com *.link.com *.typekit.net use.typekit.net *.smarketer.de https://connect.facebook.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com 'report-sample' 'self' 'unsafe-inline' https://maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com https://maps.googleapis.com https://player.vimeo.com 'self' *.cloudflare.com 'self' https://maps.googleapis.com *.facebook.com jscloud.net *.smarketer.de https://stats.g.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 default-src 'self' https://region1.analytics.google.com https://www.google-analytics.com https://region1.google-analytics.com; frame-src 'self' https://player.vimeo.com/ https://www.youtube.com/ https://ticketco.events https://virtualtourcompany.co.uk https://www.myridinglife.com https://marketplace.umbraco.com/ https://td.doubleclick.net https://www.google.com https://tr.snapchat.com https://app.geckoform.com; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://bat.bing.com https://sc-static.net https://connect.facebook.net https://cdn.akro.io https://static.hotjar.com https://analytics.tiktok.com https://tags.srv.stackadapt.com https://googleads.g.doubleclick.net https://app.geckoform.com https://script.hotjar.com https://tr.snapchat.com https://www.clarity.ms https://discoveruni.gov.uk https://widget.discoveruni.gov.uk https://cc.cdn.civiccomputing.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; connect-src 'self' https://stats.g.doubleclick.net https://region1.analytics.google.com https://sessions.bugsnag.com https://notify.bugsnag.com https://tr.snapchat.com https://analytics.tiktok.com https://e.clarity.ms https://w.clarity.ms https://x.clarity.ms https://discoveruni.gov.uk *.du-widget.com https://tr6.snapchat.com https://analytics.pangle-ads.com https://www.google.com https://content.hotjar.io https://googleads.g.doubleclick.net https://apikeys.civiccomputing.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://clapi.civiccomputing.com wss://ws.hotjar.com; font-src 'self' fonts.gstatic.com data:; img-src https: data:; media-src https: data:; 1 default-src 'self' *.across.to across.to wss://api.blocknative.com; font-src 'self' fonts.gstatic.com assets.vercel.com data:; img-src 'self' *.walletconnect.com assets.vercel.com data:; connect-src wss://*.walletconnect.com *.walletconnect.com wss://api.blocknative.com mainnet.infura.io *.across.to across.to *.wallet.coinbase.com *.alchemy.com *.infura.io api2.amplitude.com *.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' platform.twitter.com vercel.live; style-src 'self' 'unsafe-inline'; frame-src 'self' vercel.live platform.twitter.com *.walletconnect.com; frame-ancestors 'self'; report-uri https://umaproject.uriports.com/reports/report; report-to default 1 default-src data: 'self' 'unsafe-inline' 'unsafe-eval' *.clockwisemd.com *.amazonaws.com *.livehelpnow.net wss://app.livehelpnow.net *.polyfill.io *.googleapis.com *.jsdelivr.net code.jquery.com *.gstatic.com *.google.com *.bootstrapcdn.com healthsparq.com *.healthsparq.com *.googletagmanager.com *.typekit.net *.bing.com *.clarity.ms *.doubleclick.net *.googleoptimize.com *.google-analytics.com *.callrail.com unpkg.com *.facebook.net *.googlesyndication.com *.spinutech.com *.sitescout.com addsearch.com *.addsearch.com *.cloudfront.net *.searchcdn.com *.browserstack.com wss://*.browserstack.com *.linkedin.oribi.io; img-src * 'self' data:; media-src 'self' s3.amazonaws.com; frame-ancestors 'self'; object-src 'none'; form-action 'self' *.spinutech.com accounts.google.com *.facebook.com; base-uri 'self'; report-uri https://services.spinudev.com/csp/cspreport; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-QDVnOFkYQyS0PYs/yMehwbD5rpA=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.adyen.com *.surveysparrow.com 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com *.kustom.co *.surveysparrow.com *.pinterest.com *.echatsoft.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com flagpedia.net *.cloudflare.com *.klarna.com *.kustom.co *.klarnaevt.com *.googleadservices.com *.google-analytics.com *.google.dk *.google.de *.google.fr *.google.hk *.google.it *.google.co.jp *.google.com.my *.google.no *.google.com.sg *.google.co.kr *.google.com.tw *.google.co.th *.google.co.uk *.google.se *.google.pl *.google.nl *.ytimg.com *.zdassets.com *.zendesk.com *.zopim.com *.adyen.com *.naver.com *.pinterest.com *.surveysparrow.com *.baidu.com *.bdimg.com *.rainbowred.com *.twitter.com *.yahoo.co.jp https://t.co https://yotpo-editor-production.s3.amazonaws.com 'self' data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com *.avada.io *.shopify.com maps.googleapis.com *.cloudflare.com *.cloudflareinsights.com https://chimpstatic.com https://s3.amazonaws.com/downloads.mailchimp.com/ *.googleoptimize.com *.googleapis.com *.twimg.com *.fontawesome.com *.zdassets.com *.zendesk.com *.zopim.com *.klarna.com *.kustom.co *.surveysparrow.com *.naver.net *.naver.com *.tiktok.com *.pinimg.com *.baidu.com *.bdimg.com *.echatsoft.com *.dwin1.com *.ads-twitter.com *.fibbl.com *.yahoo.co.jp addrevenue.io *.addrevenue.io *.pinterest.com 'self' 'self' data: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.zdassets.com *.zendesk.com *.zopim.com *.adyen.com *.echatsoft.com *.typekit.net *.baidu.com *.yahoo.co.jp 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.zendesk.com *.zopim.com *.adyen.com 'self' 'self' data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.cloudflare.com *.googleapis.com *.zendesk.com *.adyen.com *.klarna.com *.kustom.co *.klarnaevt.com *.surveysparrow.com *.naver.com *.pinterest.com *.tiktok.com *.twitter.com *.echatsoft.com *.typekit.net https://static.zdassets.com https://ekr.zdassets.com https://gstatic.com https://*.zopim.com wss://*.zopim.com wss://*.echatsoft.com *.baidu.com *.bdimg.com *.yahoo.co.jp 'self' 'self' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' data: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self' https://avo.africa https://ad.doubleclick.net;frame-ancestors https://*.tt.omtrdc.net https://*.adobe.com https://*.onecart.co.za https://*.nedbank.co.za https://*.nedsecure.co.za https://*.numetro.co.za https://*.avo.africa https://*.wakago.net https://avo.africa https://dash.cloudflare.com https://*.cleverwebserver.com https://*.payflex.co.za https://*.pgcoza.biz https://dpm.demdex.net https://test.avo.africa https://accounts.google.com https://8908578.fls.doubleclick.net https://td.doubleclick.net https://accounts.google.com/ https://accounts.google.com/gsi/client/ https://accounts.google.com/gsi/style/ https://8908578.fls.doubleclick.net/ https://accounts.google.com/gsi/client https://test.avo.africa/;font-src 'self' data: https://*.avo.africa https://fonts.gstatic.com https://*.appsflyer.com https://cdn.scite.ai https://use.typekit.net https://cdn.megabonus.com https://js-cdn.dynatrace.com/ https://avo.tvst.travel/ https://static.zohocdn.com/;style-src 'self' 'unsafe-inline' https://accounts.google.com/gsi/style https://*.google.com https://*.google.com/ https://*.breezyx.space https://*.breezyx.space/;style-src-elem 'self' 'unsafe-inline' data: https://*.avo.africa https://*.google.com https://fonts.googleapis.com https://*.cloudflare.com https://adblockers.opera-mini.net https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com https://accounts.google.com https://cdn.honey.io https://*.google.com/ https://accounts.google.com/ https://accounts.google.com/gsi/client/ https://accounts.google.com/gsi/style/;connect-src 'self' properties: wss://*.avo.africa https://*.avo.africa https://*.doubleclick.net https://edge.adobedc.net https://play-lh.googleusercontent.com https://www.googletagmanager.com https://appleid.cdn-apple.com https://*.facebook.net https://*.facebook.com https://*.google.com https://*.adobedc.net https://*.adobedtm.com https://*.gstatic.com https://*.browser-intake-datadoghq.eu https://analytics.tiktok.com https://*.doubleclick.net https://adobedc.demdex.net https://dpm.demdex.net https://www.google.co.uk https://nedbank.d3.sc.omtrdc.net https://*.cleverwebserver.com https://*.googleapis.com https://analytics.twitter.com https://t.co https://*.ads-twitter.com https://www.google.co.za https://www.google.co.in https://www.google.sk https://googleads.g.doubleclick.net https://*.cloudflare.com https://*.googleadservices.com https://*.pgcoza.biz https://*.payflex.co.za https://*.appsflyer.com https://*.onelink.me https://*.opendns.com https://nedbanklimited.tt.omtrdc.net https://security.it.nednet.co.za ws://localhost:12387 https://www.google-analytics.com https://www.makro.co.za https://www.google.com https://www.avo.africa https://service.gstatic-cache.com https://maps.googleapis.com https://cr-input.mxpnl.net wss://localhost:9888 https://metrics-dra.dt.dbankcloud.cn https://gjtrack.ucweb.com https://overbridgenet.com https://google.com https://www.google.com/ https://*.google.com/ https://googleads.g.doubleclick.net/ https://t.co/ https://analytics.twitter.com/ https://bf31087tmv.bf.dynatrace.com https://www.avo.africa/ https://www.googleadservices.com https://*.googleadservices.com https://www.googleadservices.com/ https://notify.bugsnag.com https://personal.nedbank.co.za https://www.google.com/pagead/1p-conversion/ https://www.google.com/ccm/ https://accounts.google.com/ https://accounts.google.com/gsi/client/ https://accounts.google.com/gsi/style/ https://js-cdn.dynatrace.com/ https://mpc-prod-2-1053047382554.us-central1.run.app/events https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://mpc-prod-2-1053047382554.us-central1.run.app/events/ https://gateway.zscloud.net https://cdn.taboola.com/scripts/ https://js-cdn.dynatrace.com/jstag/ https://demo-1.conversionsapigateway.com/events/ https://demo-1.conversionsapigateway.com/events https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://nedbanklimited.tt.omtrdc.net/ https://websdk.appsflyer.com/ https://websdk.appsflyer.com/ https://connect.facebook.net https://connect.facebook.net/ https://mpc-prod-15-s6uit34pua-uw.a.run.app/events/ https://mpc-prod-15-s6uit34pua-uw.a.run.app/events https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ ;child-src 'self' https://*.avo.africa;manifest-src 'self' https://*.avo.africa;media-src 'self' https://*.avo.africa;script-src-attr 'self' 'unsafe-inline' https://*.avo.africa https://js-cdn.dynatrace.com/;object-src 'self' https://*.avo.africa;worker-src 'self' https://*.avo.africa;frame-src 'self' https://centinelapi.cardinalcommerce.com https://*.nedbank.co.za https://mozbar.moz.com https://*.google.com https://*.doubleclick.net https://nedbank.demdex.net https://*.paygate.co.za https://*.avo.africa https://*.cleverwebserver.com https://*.payflex.co.za https://*.pgcoza.biz https://activitymap.adobe.com https://www.facebook.com https://nedbanklimited.tt.omtrdc.net https://*.googletagmanager.com https://acs21.nedsecure.co.za https://3d.dpopayments.io https://api.dpopayments.io https://block.opendns.com https://bpb.opendns.com https://3dsbrowser.capitecbank.co.za https://authentication.cardinalcommerce.com https://3ds2.standardbank.co.za https://foriseu-vbv.mycardplace.com https://acsab.bankserv.co.za https://acsabsa.bankserv.co.za https://verify.monzo.com https://acstutuka.bankserv.co.za https://apm-rum-sgp.inf.miui.com https://gateway.zscalertwo.net https://secure.paygate.co.za https://dsecure.tymedigital.com https://acs-challenge.apata.io https://safekey-1.americanexpress.com https://eu.3ds.acssecure.com https://secure2.arcot.com https://*.google.com/ https://accounts.google.com https://connect.facebook.net https://blockedpage.visa.com https://gateway.zscaler.net https://js-cdn.dynatrace.com/ https://security.it.nednet.co.za/ https://acs.capitec.za1.3ds.entersekt.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://dsecure.tymedigital.com:9643 https://acsemid.bankserv.co.za https://gateway.zscloud.net https://emv3dsauth.secureacs.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://acs.nedbank.za1.3ds.entersekt.com/ https://acs.za1.3ds.entersekt.com/ https://secure-acs2ui-bk2-indblr-blrtdc.wibmo.com/ https://acs.capitalone.com/ https://acs2.3ds.modirum.com/ https://acssasfin.bankserv.co.za/ https://translate.googleapis.com/ https://client.cardinaltrusted.com/;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.avo.africa https://*.google.com/gsi/client https://assets.adobedtm.com https://websdk.appsflyer.com https://analytics.tiktok.com https://appleid.cdn-apple.com https://*.facebook.net https://*.doubleclick.net https://nedbank.d3.sc.omtrdc.net https://static.ads-twitter.com https://*.googleadservices.com https://www.googletagmanager.com https://*.cleverwebserver.com https://*.payflex.co.za https://secure.pgcoza.biz https://maps.googleapis.com https://*.google.com/ https://assets.adobedtm.com/;img-src 'self' 'unsafe-inline' blob: data: *;script-src-elem 'self' 'unsafe-inline' blob: https://*.gstatic.com https://*.cleverwebserver.com https://appleid.cdn-apple.com https://*.google.com https://*.google.com.na https://static.ads-twitter.com https://nedbank.d3.sc.omtrdc.net https://assets.adobedtm.com https://www.googletagmanager.com https://analytics.tiktok.com https://*.doubleclick.net https://*.facebook.net https://*.googleapis.com https://*.googleads.com https://*.googleadservices.com https://*.payflex.co.za https://*.pgcoza.biz https://*.appsflyer.com https://*.cloudflare.com https://activitymap.adobe.com https://cdn.jsdelivr.net https://unpkg.com https://www.google.com https://nedbanklimited.tt.omtrdc.net https://security.it.nednet.co.za https://googleads.g.doubleclick.net https://maps.googleapis.com https://gc.kis.v2.scr.kaspersky-labs.com https://connect.facebook.net https://www.avo.africa https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://www.datadoghq-browser-agent.com https://www.googleadservices.com https://websdk.appsflyer.com https://mainf.global-cache.online https://infird.com http://www.clarity.ms https://u.clarity.ms https://cdn.segment.com https://cdn.alsgp0.fds.api.mi-img.com https://c.clarity.ms https://www.google.com/ https://*.google.com/ https://googleads.g.doubleclick.net/ https://js-cdn.dynatrace.com https://www.avo.africa https://www.avo.africa/ https://assets.adobedtm.com/ https://accounts.google.com https://connect.facebook.net https://gateway.zscaler.net https://secured-pixel.com https://www.google.com/pagead/1p-conversion/ https://www.google.com/ccm/ https://accounts.google.com/ https://accounts.google.com/gsi/client/ https://accounts.google.com/gsi/style/ https://js-cdn.dynatrace.com/ https://websdk.appsflyer.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://connect.facebook.net/en_US/sdk.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/ https://gateway.zscloud.net https://cdn.taboola.com/scripts/ https://js-cdn.dynatrace.com/jstag/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://accounts.google.com/gsi/client https://www.googletagmanager.com/gtag/ https://nedbanklimited.tt.omtrdc.net/ https://static.ads-twitter.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/; 1 default-src 'self'; base-uri 'self'; connect-src 'self' *.google-analytics.com *.analytics.google.com *.cloudflare.com *.eesa.lh; font-src use.fontawesome.com 'self'; frame-src www.youtube.com www.google.com; img-src 'self' *.google-analytics.com *.analytics.google.com *.googletagmanager.com; object-src 'none'; script-src 'self' www.googletagmanager.com *.cloudflare.com *.google.com 'strict-dynamic' 'unsafe-inline' 'nonce-TJyxr96977+Bi8a42mfyfg=='; style-src 'self' use.fontawesome.com *.cloudflare.com 'unsafe-inline' 'nonce-TJyxr96977+Bi8a42mfyfg=='; report-uri /csp/report 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.adbr.io *.googleapis.com *.amicafarmacia.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.amicafarmacia.com 'self' 'unsafe-inline'; frame-ancestors *.adabra.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.trustpilot.com *.criteo.com *.cookiebot.com *.hotjar.com *.adbr.io *.amicafarmacia.com service.force.com ad4m.at *.ad4m.at *.ad-srv.net *.mateti.net *.awin1.com *.zenaps.com *.tncid.app *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.google.de *.google.it *.bing.com *.adbr.io maps.googleapis.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.stickyadstv.com *.criteo.com criteo-partners.tremorhub.com *.analytics.yahoo.com *.adnxs.com *.smartadserver.com *.smartclip.net *.rubiconproject.com *.outbrain.com *.casalemedia.com *.360yield.com *.pubmatic.com *.yahoo.com *.taboola.com *.tapad.com *.advertising.com *.sharethrough.com *.3lift.com *.revcontent.com *.addthis.com *.postrelease.com *.amicafarmacia.com *.smaato.com *.smaato.net *.liadm.com *.adform.net *.teads.tv *.bidswitch.net *.media.net *.omnitagjs.com *.ivitrack.com *.yieldmo.com *.dmxleo.com *.clarity.ms amicafarmacia.shop *.ad4m.at *.yieldlab.net *.adscale.de *.mediavine.com id5-sync.com *.thebrighttag.com *.krxd.net *.rlcdn.com *.twiago.com *.awin1.com *.zenaps.com *.tncid.app *.weborama.fr *.exelator.com *.thenewco.id *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.hsforms.net *.hsforms.com *.flavedo.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ *.google.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trustpilot.com *.criteo.com *.criteo.net *.newrelic.com *.cookiebot.com bam.nr-data.net *.google.de *.google.it *.bing.com *.hotjar.com *.adbr.io *.googleapis.com *.zdassets.com *.cloudflareinsights.com *.nr-data.net *.amicafarmacia.com *.amicafarmacia.shop amicafarmacia.shop *.zopim.com *.kk-resources.com *.noibu.com *.flx1.com *.clarity.ms *.shippypro.com service.force.com *.salesforceliveagent.com *.salesforce.com ad4m.at *.cookieless-data.com *.mateti.net *.scalapay.com analytics-manager.com *.awin1.com *.zenaps.com www.dwin1.com the.sciencebehindecommerce.com js.sddan.com trk.datnova.com sdk.privacy-center.org api.privacy-center.org *.tncid.app ced.sascdn.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.connectif.cloud *.development.scalapay.com *.staging.scalapay.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.cloudflare.com *.adbr.io *.amicafarmacia.com *.shippypro.com service.force.com *.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com cdn.dnky.co webchat.dotdigital.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com bam.nr-data.net *.doubleclick.net *.trustpilot.com pagead2.googlesyndication.com consentcdn.cookiebot.com *.adbr.io *.nr-data.net *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.cloudflareinsights.com *.amicafarmacia.com *.amicafarmacia.shop *.noibu.com wss://input.noibu.com *.flx1.com *.clarity.ms *.kk-resources.com secure.force.com *.wt-eu02.net *.hotjar.com *.mateti.net *.adyen.com *.google.it sdk.privacy-center.org api.privacy-center.org *.tncid.app ced.sascdn.com *.smartadserver.com *.googleapis.com *.shippypro.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.connectif.cloud t.elasticsuite.io *.hsforms.net *.hsforms.com *.citrusad.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.cloudflareinsights.com https://*.pingdom.net https://pingdom.net https://*.googletagmanager.com https://*.google.com https://google.com https://*.gstatic.com https://gstatic.com https://*.googleapis.com https://googleapis.com https://*.facebook.net https://facebook.net; script-src-elem 'self' 'unsafe-inline' https://*.cloudflareinsights.com https://*.pingdom.net https://pingdom.net https://*.googletagmanager.com https://*.google.com https://google.com https://*.gstatic.com https://gstatic.com https://*.googleapis.com https://googleapis.com https://*.dinkytown.net https://dinkytown.net https://*.vimeo.com https://vimeo.com https://*.cloudflare.com https://cloudflare.com https://*.jsdelivr.net https://jsdelivr.net https://*.linkedin.com https://linkedin.com https://*.google-analytics.com https://google-analytics.com https://*.wufoo.com https://wufoo.com https://*.facebook.net https://facebook.net; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://googleapis.com; style-src-elem 'self' 'unsafe-inline' https://*.googleapis.com https://googleapis.com https://*.dinkytown.net https://dinkytown.net https://*.jsdelivr.net https://jsdelivr.net https://*.honey.io https://honey.io https://*.gstatic.com https://gstatic.com https://*.cloudflare.com https://cloudflare.com; style-src-attr 'self' 'unsafe-inline'; font-src 'self' data: https://*.gstatic.com https://gstatic.com https://*.wp.com https://wp.com https://*.slant.co https://slant.co https://*.cloudflare.com https://cloudflare.com; connect-src 'self' https://*.google-analytics.com https://google-analytics.com https://*.pingdom.net https://pingdom.net https://*.google.com https://google.com https://*.gstatic.com https://gstatic.com https://*.googleapis.com https://googleapis.com https://*.bpas.com https://bpas.com https://*.googletagmanager.com https://*.yoast.com https://yoast.com; img-src 'self' data: blob: https://*.googletagmanager.com https://*.googleapis.com https://googleapis.com https://*.gstatic.com https://gstatic.com https://*.google.com https://google.com https://*.shortpixel.ai https://shortpixel.ai https://*.bpas.com https://bpas.com https://*.google-analytics.com https://google-analytics.com https://*.vimeocdn.com https://vimeocdn.com https://*.honey.io https://honey.io https://*.gravatar.com https://gravatar.com https://*.fooplugins.com https://fooplugins.com https://*.wpengine.com https://wpengine.com; frame-src 'self' https://*.google.com https://google.com https://*.vimeo.com https://vimeo.com https://*.wufoo.com https://wufoo.com https://*.dinkytown.net https://dinkytown.net https://*.monday.com https://monday.com https://*.docusign.net https://docusign.net https://tpa.fsastore.com; media-src 'self' data:; worker-src 'self' blob:; report-uri https://csp-reporter.carbon-094.workers.dev/; 1 frame-src 'self' https://www.youtube.com/ https://player.vimeo.com/ https://tally.so/; font-src 'self'; object-src 'none'; script-src 'strict-dynamic' https://internet-up.ably-realtime.com/ 'nonce-9pyx2flC2uTNOAg6rOR/Qw=='; style-src 'self' 'unsafe-inline'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; report-uri https://www.bilateralstimulation.io/api/csp-violation; report-to csp-endpoint 1 default-src 'self' *.clarity.ms *.bing.com; connect-src 'self' *.katalogmarzen.pl *.bing.com *.clarity.ms *.cookiebot.com *.doubleclick.net *.getresponse.com *.google-analytics.com *.google.com *.google.pl *.googletagmanager.com *.googlesyndication.com *.googleadservices.com *.stape.tech *.tiktok.com *.tiktokw.us *.hotjar.com wss://ws.hotjar.com *.facebook.com; frame-src 'self' *.cookiebot.com *.doubleclick.net *.googletagmanager.com *.google.com *.inpost.pl *.youtube.com *.facebook.com; img-src 'self' *.katalogmarzen.pl data: *.bing.com *.clarity.ms *.cookiebot.com *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.google.pl *.googletagmanager.com *.googleadservices.com *.youtube.com *.openstreetmap.org *.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.com *.clarity.ms *.cookiebot.com *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gr-cdn-e.eu *.gr-cdn.com *.gr-wcon.com *.gstatic.com *.getresponse.com *.hotjar.com *.inpost.pl *.katalogmarzen.pl *.tiktok.com; style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.googleapis.com *.inpost.pl; font-src 'self' data: *.gstatic.com; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com *.paypalobjects.com storage.googleapis.com *.livechatinc.com *.kaptcha.com *.doubleclick.net *.instagram.com sibautomation.com *.brevo.com *.sibforms.com cutlistevo.com *.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.google.com *.google.co.uk paypal-eu-arh.cloudiq.com *.bing.com *.googletagmanager.com *.cloudfront.net *.yotpo.com *.clarity.ms *.luckyorange.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.googletagmanager.com *.googleoptimize.com *.livechatinc.com *.facebook.net *.bing.com paypal-eu-cdn.cloudiq.com *.cloudfront.net *.craftyclicks.co.uk *.luckyorange.com *.clarity.ms *.qeryz.net *.instagram.com *.debugbear.com *.sendinblue.com sibautomation.com *.brevo.com https://cdn.jsdelivr.net/npm/@growthbook/growthbook/dist/bundles/index.js *.trustpilot.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.cloudfront.net *.luckyorange.com *.myfonts.net *.stackpathcdn.com *.trustpilot.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.craftyclicks.co.uk pcls1.craftyclicks.co.uk http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.google-analytics.com stats.g.doubleclick.net *.luckyorange.com settings.luckyorange.net wss://realtime.luckyorange.com wss://visitors.live wss://in.visitors.live *.facebook.com *.clarity.ms qeryz.com *.googleapis.com *.googlesyndication.com *.brevo.com *.debugbear.com *.growthbook.io *.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com account.fetchify.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.googletagmanager.com td.doubleclick.net www.google.com widget.reviews.co.uk www.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.google.co.uk googleads.g.doubleclick.net bat.bing.com images.mcafeesecure.com www.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com s7.addthis.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com googletagmanager.com www.googletagmanager.com *.googletagmanager.com bat.bing.com googleads.g.doubleclick.net region1.analytics.google.com www.google.com widget.reviews.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cc-cdn.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk ekr.zdassets.com/ https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com region1.analytics.google.com googleads.g.doubleclick.net www.google.com bat.bing.com api.reviews.co.uk 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' rundel.de www.rundel.de *.wirth-horn.de api.db-ip.com unpkg.com www.gstatic.com www.google.com *.paypal.com www.paypalobjects.com connect.facebook.net https://www.google-analytics.com https://www.youtube-nocookie.com 'unsafe-eval' 'unsafe-inline'; img-src data: *; media-src data: *; frame-src *; child-src blob: *; font-src data: 'self' https://fonts.gstatic.com https://fonts.googleapis.com; report-uri /api/csp-report 1 default-src 'none'; block-all-mixed-content; child-src vars.hotjar.com; connect-src 'self' api.foyer.lu www.foyer.lu analytics.foyer.lu saf-api.foyer.lu datadog-proxy.foyer.lu stats.g.doubleclick.net googleads.g.doubleclick.net www.googletagmanager.com www.google-analytics.com *.analytics.google.com analytics.google.com ssl.google-analytics.com adservice.google.com www.google.com maps.googleapis.com pagead2.googlesyndication.com api.iadvize.com halc.iadvize.com static.iadvize.com www.facebook.com consentcdn.cookiebot.com *.hotjar.com:* vc.hotjar.io:* surveystats.hotjar.io wss://*.hotjar.com; font-src 'self' data: static.foyer.lu fonts.gstatic.com use.fontawesome.com; frame-src 'self' halc.iadvize.com www.google.com www.googletagmanager.com www.facebook.com www.youtube.com vars.hotjar.com consentcdn.cookiebot.com; img-src 'self' data: *; manifest-src 'self'; media-src 'self' data:; object-src www.foyer.lu www.cmpli.lu; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: analytics.foyer.lu www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com maps.googleapis.com developers.google.com translate.googleapis.com www.googleoptimize.com stats.g.doubleclick.net translate.googleapis.com opt-out.ferank.eu code.jquery.com tarteaucitron.io halc.iadvize.com static.iadvize.com npmcdn.com cdn.jsdelivr.net static.cdn.prismic.io tarteaucitron.io track.adform.net connect.facebook.net snap.licdn.com s2.adform.net actorssl-5637.kxcdn.com halc.iadvize.com consent.cookiebot.com consentcdn.cookiebot.com script.hotjar.com static.hotjar.com platform.twitter.com cdnjs.cloudflare.com ajax.googleapis.com cdn.svgator.com; style-src 'unsafe-inline' 'self' static.foyer.lu fonts.googleapis.com translate.googleapis.com cdn.jsdelivr.net opt-out.ferank.eu tarteaucitron.io cdn.jsdelivr.net platform.twitter.com; worker-src 'self'; report-uri https://api.foyer.lu/sentry/api/237/security/?sentry_key=29cea24f640d436fa4430bc6d0195cb9&sentry_environment=ir-CSP-php-p&sentry_release=1.0.20; 1 connect-src 'self' https://luxuryflooring.co.uk https://www.google-analytics.com https://*.google.ad https://*.google.ae https://*.google.al https://*.google.am https://*.google.as https://*.google.at https://*.google.az https://*.google.ba https://*.google.be https://*.google.bf https://*.google.bg https://*.google.bi https://*.google.bj https://*.google.bs https://*.google.bt https://*.google.by https://*.google.ca https://*.google.cat https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.co.ao https://*.google.co.bw https://*.google.co.ck https://*.google.co.cr https://*.google.co.id https://*.google.co.il https://*.google.co.in https://*.google.co.jp https://*.google.co.ke https://*.google.co.kr https://*.google.co.ls https://*.google.co.ma https://*.google.co.mz https://*.google.co.nz https://*.google.co.th https://*.google.co.tz https://*.google.co.ug https://*.google.co.uk https://*.google.co.uz https://*.google.co.ve https://*.google.co.vi https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.com.af https://*.google.com.ag https://*.google.com.ar https://*.google.com.au https://*.google.com.bd https://*.google.com.bh https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.com.bz https://*.google.com.co https://*.google.com.cu https://*.google.com.cy https://*.google.com.do https://*.google.com.ec https://*.google.com.eg https://*.google.com.et https://*.google.com.fj https://*.google.com.gh https://*.google.com.gi https://*.google.com.gt https://*.google.com.hk https://*.google.com.jm https://*.google.com.kh https://*.google.com.kw https://*.google.com.lb https://*.google.com.ly https://*.google.com.mm https://*.google.com.mt https://*.google.com.mx https://*.google.com.my https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.com.np https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.com.pr https://*.google.com.py https://*.google.com.qa https://*.google.com.sa https://*.google.com.sb https://*.google.com.sg https://*.google.com.sl https://*.google.com.sv https://*.google.com.tj https://*.google.com.tr https://*.google.com.tw https://*.google.com.ua https://*.google.com.uy https://*.google.com.vc https://*.google.com.vn https://*.google.cv https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.dz https://*.google.ee https://*.google.es https://*.google.fi https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.gy https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.ie https://*.google.im https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.jo https://*.google.kg https://*.google.ki https://*.google.kz https://*.google.la https://*.google.li https://*.google.lk https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.mn https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.ne https://*.google.nl https://*.google.no https://*.google.nr https://*.google.nu https://*.google.pl https://*.google.pn https://*.google.ps https://*.google.pt https://*.google.ro https://*.google.rs https://*.google.ru https://*.google.rw https://*.google.sc https://*.google.se https://*.google.com https://www.googletagmanager.com https://*.googleapis.com https://*.analytics.google.com api.craftyclicks.co.uk *.omappapi.com bat.bing.com bat.bing.net https://bat.bing-int.com ct.pinterest.com ekr.zdassets.com stats.g.doubleclick.net www.roomvo.com *.nr-data.net www.facebook.com www.sandbox.paypal.com *.paypal.com display.popt.in https://www.instagram.com *.hubspot.com api.hubapi.com api.hubspot.com js.usemessages.com js.hsleadflows.net js.hs-banner.com js.hubspotfeedback.com js.hsadspixel.net js.hs-analytics.net js.hs-scripts.com forms.hsforms.com https://a.klaviyo.com https://fast.a.klaviyo.com https://*.klaviyo.com https://*.veinteractive.com https://*.ve.com https://forms.hscollectedforms.net https://api.retargeted.co/ https://api.webgains.io https://logs.convertexperiments.com https://*.convertexperiments.com https://10041910.metrics.convertexperiments.com https://click.prod.mplat-ppcprotect.com https://pclick.prod.mplat-ppcprotect.com/ https://pclick.prod.mplat-ppcprotect.com https://luxury-flooring.s3.amazonaws.com https://googleads.g.doubleclick.net https://consentcdn.cookiebot.com https://*.googlesyndication.com https://*.google-analytics.com https://publicsuffix.org/list/public_suffix_list.dat https://www.clarity.ms https://*.bing.com https://*.clarity.ms https://api-js.datadome.co https://hubspot-forms-static-embed.s3.amazonaws.com https://www.googleadservices.com https://analytics.tiktok.com https://yoast.com/feed/widget/ https://api.bannercrowd.net https://analytics-ipv6.tiktokw.us ; font-src 'self' data: https://luxuryflooring.co.uk fonts.gstatic.com v2.zopim.com *.googleapis.com https://a.omappapi.com https://static.klaviyo.com ; form-action 'self' https://luxuryflooring.co.uk www.facebook.com ct.pinterest.com forms.hsforms.com forms.hubspot.com ; frame-src 'self' data: www.facebook.com www.googletagmanager.com https://*.google.com https://*.google.co.uk https://*.google.in www.powr.io www.roomvo.com bid.g.doubleclick.net https://ct.pinterest.com/ tr.pinterest.com www.pinterest.co.uk www.pinterest.com www.pinterest.de www.pinterest.ie www.pinterest.se za.pinterest.com player.vimeo.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.wesupply.xyz *.weltpixel.com gsa://onpageload *.hubspot.com https://*.hsforms.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.usemessages.com https://js.hsforms.net https://widget.trustpilot.com https://12301984.fls.doubleclick.net https://12506955.fls.doubleclick.net https://www.youtube.com https://consentcdn.cookiebot.com https://js.stripe.com https://td.doubleclick.net https://admin.revenuehunt.com https://event.getblue.io https://consentcdn.cookiebot.com https://impact.carma.earth https://www.youtube-nocookie.com ; frame-ancestors 'self' ; img-src 'self' data: https://luxuryflooring.co.uk bat.bing.com bat.bing.net www.facebook.com www.paypalobjects.com www.roomvo.com workers.cloudflare.com *.omappapi.com www.pinterest.com ct.pinterest.com log.pinterest.com www.instagram.com www.gstatic.com s.ytimg.com *.vimeocdn.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validate.fishpig.co.uk *.paypal.com *.roomvo.com www.xtento.com cdn.xtento.com connect.facebook.net img.luxuryflooringandfurnishings.co.uk secure.gravatar.com track.hubspot.com https://*.google.com https://maps.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.google.co.uk https://*.google.ie https://*.google.im https://www.googleadservices.com https://www.googletagmanager.com *.hubspot.com forms.hsforms.com *.nr-data.net https://share.hsforms.com https://perf.hsforms.com https://js.hsforms.net https://a.klaviyo.com https://static.klaviyo.com https://px.ads.linkedin.com https://www.linkedin.com https://prf.hn https://*.prf.hn https://12301984.fls.doubleclick.net https://ad.doubleclick.net https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://luxury-flooring.s3.amazonaws.com https://googleads.g.doubleclick.net https://imgsct.cookiebot.com/ https://*.googlesyndication.com https://c.bing.com https://*.clarity.ms https://*.ytimg.com https://forms-na1.hsforms.com https://*.convertexperiments.com https://admin.revenuehunt.com https://*.tribalfusion.com ; object-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' https://luxuryflooring.co.uk *.omappapi.com *.nr-data.net bat.bing.com bat.bing.net cdn.roomvo.com connect.facebook.net googleads.g.doubleclick.net s.pinimg.com static.cloudflareinsights.com cdnjs.cloudflare.com ajax.cloudflare.com static.zdassets.com www.google-analytics.com www.google.com www.googleadservices.com www.googleoptimize.com www.googletagmanager.com www.gstatic.com www.powr.io js-agent.newrelic.com *.nr-data.net maps.googleapis.com video.google.com www.youtube.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.sagepay.com www.xtento.com cdn.xtento.com tagmanager.google.com a.omappapi.com s.pinimg.com apiv2.popupsmart.com ssl.google-analytics.com google.co.uk optimize.google.com www.google.co.uk cdn.popt.in https://js.hs-scripts.com https://js.hsleadflows.net https://js.hs-banner.com https://js.hsadspixel.net https://js.hubspotfeedback.com https://js.usemessages.com https://js.hs-analytics.net https://js.hscollectedforms.net https://js.hsforms.net https://js-na1.hs-scripts.com https://forms.hsforms.com https://*.klarnacdn.net https://*.klarnaservices.com https://static-tracking.klaviyo.com https://static.klaviyo.com https://widget.trustpilot.com https://config1.veinteractive.com https://s.retargeted.co https://snap.licdn.com https://woobox.com https://cdn-4.convertexperiments.com https://js.stripe.com https://analytics.webgains.io https://admin.revenuehunt.com https://collect.bannercrowd.net https://client.prod.mplat-ppcprotect.com https://ct.pinterest.com https://event.getblue.io https://widget.getblue.io https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.clarity.ms https://analytics.fatmedia.io https://no-cdn.convertexperiments.com https://analytics.tiktok.com https://a.tribalfusion.com https://s.tribalfusion.com https://bat.bing-int.com https://cdn.jsdelivr.net/npm/swiper@11/ https://scripts.clarity.ms ; style-src 'self' 'unsafe-inline' https://luxuryflooring.co.uk fonts.googleapis.com www.googletagmanager.com *.googleapis.com tagmanager.google.com translate.googleapis.com optimize.google.com https://static.klaviyo.com https://a.omappapi.com https://*.veinteractive.com https://static-tracking.klaviyo.com https://cdn.jsdelivr.net/npm/swiper@11/ ; child-src app.hubspot.com forms.hsforms.com js.hsadspixel.net js.hscollectedforms.net js.usemessages.com ; worker-src 'self' blob: ; default-src 'self' ; base-uri https://luxuryflooring.co.uk; report-uri https://uktf.report-uri.com/r/t/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com data: *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com scontent.* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ display.ugc.bazaarvoice.com *.fontawesome.com assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://25839c8b-6d91-4819-9e40-a90276f15ff7.sansec.watch/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: consent.cookiebot.com consentcdn.cookiebot.com www.googletagmanager.com *.googletagmanager.com tagmanager.google.com www.recaptcha.net www.google.com accounts.google.com *.doubleclick.net *.gstatic.com *.googlesyndication.com www.instagram.com graph.instagram.com platform.instagram.com static.cdninstagram.com connect.facebook.net www.facebook.com *.fbcdn.net *.facebook.net analytics.tiktok.com sc-static.net snap.licdn.com tr.snapchat.com www.youtube.com vimeo.com player.vimeo.com vimeocdn.com visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com *.azureedge.net watermelon.ai chatwidget-prod.web.app fonts.googleapis.com *.aanmelder.nl connexys.nl cdnjs.cloudflare.com *.hotjar.com secured-pixel.com *.secured-pixel.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: consent.cookiebot.com consentcdn.cookiebot.com www.googletagmanager.com *.googletagmanager.com tagmanager.google.com www.recaptcha.net www.google.com accounts.google.com *.doubleclick.net *.gstatic.com *.googlesyndication.com www.instagram.com graph.instagram.com platform.instagram.com static.cdninstagram.com connect.facebook.net www.facebook.com *.fbcdn.net *.facebook.net analytics.tiktok.com sc-static.net snap.licdn.com tr.snapchat.com www.youtube.com vimeo.com player.vimeo.com vimeocdn.com visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com *.azureedge.net watermelon.ai chatwidget-prod.web.app fonts.googleapis.com *.aanmelder.nl connexys.nl cdnjs.cloudflare.com *.hotjar.com secured-pixel.com *.secured-pixel.com; style-src 'self' https: fonts.googleapis.com cdnjs.cloudflare.com 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; img-src 'self' https: data: blob: akamaized.net cdninstagram.com amazonaws.com fonts.gstatic.com storage.googleapis.com zadkine-production-images-356480229392.s3.eu-central-1.amazonaws.com watermelon.ai imgsct.cookiebot.com; font-src 'self' https: data: fonts.gstatic.com; connect-src 'self' https: consent.cookiebot.com consentcdn.cookiebot.com www.googletagmanager.com *.googletagmanager.com visualwebsiteoptimizer.com watermelon.ai mktdplp102cdn.azureedge.net chatwidget-prod.web.app *.hotjar.com wss://*.hotjar.com connect.facebook.net www.facebook.com *.facebook.net; frame-src 'self' https: www.youtube.com vimeo.com consent.cookiebot.com consentcdn.cookiebot.com *.gstatic.com *.googlesyndication.com connexys.nl bookings.zenchef.com; object-src 'none'; frame-ancestors 'self'; form-action 'self' https:; base-uri 'self'; report-uri /csp-reports 1 default-src 'self' https://d2rbodpj0xodc.cloudfront.net https://d14jf0tks233zb.cloudfront.net https://d3edmilwjwx4oz.cloudfront.net https://s3.amazonaws.com/print-sample-media/;script-src 'self' 'unsafe-inline' https://www.google-analytics.com https://cdn.cookielaw.org https://cdn.cookielaw.org https://www.googletagmanager.com https://connect.facebook.net https://bat.bing.com https://websdk.appsflyer.com https://analytics.tiktok.com https://s.pinimg.com https://www.clarity.ms https://ct.pinterest.com;connect-src 'self' https://cdn.cookielaw.org https://sdk.iad-07.braze.com/api/v3/data/ https://websdk.appsflyer.com https://wa.appsflyer.com https://analytics.tiktok.com *.steller.co https://maps.googleapis.com/ https://o4505319465156608.ingest.sentry.io/ https://geolocation.onetrust.com/ https://forms.hscollectedforms.net/ *.clarity.ms/ https://bat.bing.com/ https://ct.pinterest.com https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net https://cdn.ampproject.org https://privacyportal.onetrust.com https://www.facebook.com https://d2rbodpj0xodc.cloudfront.net https://banner.appsflyer.com https://creatives-cdn.appsflyer.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.*;script-src-elem 'self' 'unsafe-inline' https://cdn.cookielaw.org https://websdk.appsflyer.com/ https://analytics.tiktok.com/ https://connect.facebook.net http://bat.bing.com/bat.js https://fonts.googleapis.com https://maps.googleapis.com https://js.hs-scripts.com/ https://js.hs-banner.com/ https://js.hs-scripts.com/ http://js.hs-scripts.com/ https://js.hs-analytics.com/ https://js.hs-analytics.net/ https://forms.hscollectedforms.net/ https://js.hscollectedforms.net/ https://js-na1.hs-scripts.com/ *.clarity.ms https://bat.bing.com/ https://s.pinimg.com https://www.googletagmanager.com https://cdn.ampproject.org https://ct.pinterest.com https://appleid.cdn-apple.com https://accounts.google.com https://www.clarity.ms https://googleads.g.doubleclick.net;style-src 'self' 'unsafe-inline';style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://accounts.google.com;img-src 'self' data: https://d2rbodpj0xodc.cloudfront.net https://d14jf0tks233zb.cloudfront.net https://d3edmilwjwx4oz.cloudfront.net https://s3.amazonaws.com/print-sample-media/ https://*;font-src 'self' data: https://d2rbodpj0xodc.cloudfront.net https://d14jf0tks233zb.cloudfront.net https://d3edmilwjwx4oz.cloudfront.net https://s3.amazonaws.com/print-sample-media/ https://fonts.googleapis.com https://s3.amazonaws.com/giphyscripts/ https://use.fontawesome.com/ https://fonts.gstatic.com/ https://cdn.appsflyer.com;media-src 'self' blob: https://d2rbodpj0xodc.cloudfront.net https://d14jf0tks233zb.cloudfront.net https://d3edmilwjwx4oz.cloudfront.net https://s3.amazonaws.com/print-sample-media/;child-src 'self' https://*.facebook.com;frame-src 'self' https://*.facebook.com https://*.vimeo.com https://ct.pinterest.co https://ct.pinterest.com https://accounts.google.com https://accounts.google.co https://td.doubleclick.net;frame-ancestors 'self';report-uri /site/cspreport; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv7%3F2(bjik%3E-19b2ab129a0-0x2a03#pd 1 font-src *.gstatic.com 'self' data: stats.g.doubleclick.net *.facebook.com *.cloudflare.com *.twitter.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com https://int-ecommerce.nexi.it/ecomm/XPayBuild/ https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.fls.doubleclick.net www.facebook.com *.awin1.com *.zenaps.com *.twitter.com *.addthis.com https://int-ecommerce.nexi.it/ https://hal9000.redintelligence.net/ https://ad4m.at/frame.html *.hotjar.com *.criteo.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bird.eu *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com https://ecommerce.nexi.it/ecomm/payment/img/visa.svg https://ecommerce.nexi.it/ecomm/payment/img/mastercard.svg https://ecommerce.nexi.it/ecomm/payment/img/logoNexiLarge.png https://ecommerce.nexi.it/ecomm/payment/img/maestro.svg https://form.jotform.com/ https://www.google.it/ https://as.ad4m.at/ad/ https://r.adserver01.de/rt/ *.taboola.com/ https://track.adform.net/ https://ads.creative-serving.com/ https://adservice.google.it/ https://secure.adnxs.com/ https://events.jotform.com/jsform/ *.favicon.ico https://cdn.jotfor.ms/assets/img/logo/logo-new@1x.png https://cdn.jotfor.ms/favicon.ico https://tr.outbrain.com/unifiedPixel https://criteo-partners.tremorhub.com/ https://contextual.media.net/ https://ad.360yield.com/ https://jadserve.postrelease.com https://simage2.pubmatic.com/ https://ib.adnxs.com/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://visitor.omnitagjs.com/ https://s.thebrighttag.com *.criteo.com/ *.analytics.yahoo.com/ https://beacon.krxd.net/ https://x.bidswitch.net/ https://e1.emxdgt.com/ *.ads.yieldmo.com https://ad.yieldlab.net/ https://match.sharethrough.com/ https://sync.outbrain.com/ https://exchange.mediavine.com/ https://matching.ivitrack.com/ https://id5-sync.com cdn.doofinder.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.awin1.com www.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.cloudflare.com *.twitter.com googletagmanager.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.nr-data.net js-agent.newrelic.com cdn.scalapay.com int-ecommerce.nexi.it form.jotform.com ad4m.at *.taboola.com *.hotjar.com *.outbrain.com static.criteo.net static.hotjar.com cdn.jotfor.ms dynamic.criteo.com *.smct.io *.smct.co https://smct.co/ *.iubenda.com hits-i.iubenda.com *.mainadv.com *.openapi.it *.cardinalcommerce.com cdn.doofinder.com ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.cloudflare.com *.twitter.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com https://form.jotform.com/ *.jotfor.ms *.doofinder.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://www.wepowerconnections.com/ https://the.sciencebehindecommerce.com *.cloudflare.com *.twitter.com *.paypal.com *.nr-data.net https://int-ecommerce.nexi.it/ *.hotjar.com https://stats.g.doubleclick.net/j/collect *.criteo.com https://trc-events.taboola.com/1052370/log/3/unip https://firehose.eu-west-1.amazonaws.com https://hits-i.iubenda.com/write https://cognito-identity.eu-west-1.amazonaws.com/ https://tr.outbrain.com/ *.openapi.it *.cardinalcommerce.com *.doofinder.com wss://*.doofinder.com int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com google.com maps.googleapis.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://integration-5ojmyuq-zgzvw2kr4mr5m.eu-5.magentosite.cloud/italiano; report-to report-endpoint; 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com/ *.yotpo.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://maps.googleapis.com *.yotpo.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' https://prototype.local.next.helmholtz-munich.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://*.dzd-ev.de https://images.admiralcloud.com https://prototype.local.next.helmholtz-munich.de; base-uri 'self'; frame-src 'self' https://player.vimeo.com https://www.youtube-nocookie.com https://view.genial.ly https://view.genially.com; connect-src 'self' https://*.dzd-ev.de wss://*.dzd-ev.de/ https://sentry2.in2code.de/api/62/security/ wss://prototype.local.next.helmholtz-munich.de/ https://hmwa.helmholtz-munich.de; style-src 'self' 'unsafe-inline' 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://prototype.local.next.helmholtz-munich.de 'report-sample'; script-src-elem 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de https://hmwa.helmholtz-munich.de 'report-sample'; font-src 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de; report-uri https://sentry2.in2code.de/api/62/security/?sentry_key=c8671bb1cf909cd134a5b859fc8d36e1 1 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.networkmerchants.com www.google.com www.facebook.com *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.networkmerchants.com *.gstatic.com *.googleapis.com *.facebook.com *.olark.com *.disqus.com https://img.youtube.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.networkmerchants.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ connect.facebook.net *.facebook.com *.olark.com secure.networkmerchants.com *.disqus.com *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.networkmerchants.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.networkmerchants.com *.googleapis.com *.olark.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src static.hsappstatic.net; media-src greenpeace.org.au *.greenpeace.org.au; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data:; base-uri 'self'; form-action 'self' https://www.facebook.com https://forms.hsforms.com *.hubspot.com; font-src greenpeace.org.au *.greenpeace.org.au www.greenpeace.org fonts.gstatic.com maxcdn.bootstrapcdn.com use.fontawesome.com https://*.hubspotusercontent30.net https://8586633.fs1.hubspotusercontent-na1.net https://script.hotjar.com https://vc.hotjar.io https://cdn-custom.optimonk.com data:; frame-src *; connect-src 'self' https://analytics.greenpeace.org.au *.hubspot.com *.doubleclick.net js.hs-banner.com https://adservice.google.com analytics.google.com https://*.analytics.google.com *.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.hotjar.com https://metrics.hotjar.io https://stripe-payments-dot-gpap-engineering.appspot.com https://bat.bing.com https://www.facebook.com https://www.greenpeace.org.au https://*.hotjar.com https://vc.hotjar.io https://content.hotjar.io https://events.hotjar.io https://surveystats.hotjar.io wss://*.hotjar.com https://forms.hsforms.com https://api.hubspot.com https://cta-service-cms2.hubspot.com https://forms.hubspot.com https://cp.hubspot.com https://ec.instapagemetrics.com https://heatmap-events-collector.instapage.com https://www.google.com https://www.google.com.au/ads/ga-audiences https://pagead2.googlesyndication.com https://api.omappapi.com https://sentry.io https://pixels.spotify.com https://api.stripe.com https://analytics.tiktok.com https://cds.taboola.com https://trc.taboola.com https://trc-events.taboola.com https://psb.taboola.com https://pips.taboola.com https://*.convertexperiments.com https://px.ads.linkedin.com https://*.optimonk.com; report-uri https://o196544.ingest.sentry.io/api/6683985/security/?sentry_key=223a0fdbcdce4e2aadda1caa22c16eab 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.connectif.cloud https://cdn.slaask.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://use.fontawesome.com; img-src 'self' data: blob: https://www.google-analytics.com https://cdn.connectif.cloud https://stats.g.doubleclick.net https://cf-assets.www.cloudflare.com https://cdn.simpleicons.org; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://cdn.connectif.cloud https://stats.g.doubleclick.net https://default67716c2b936d44caa86ff66f3dfe8c.9c.environment.api.powerplatform.com; frame-src 'self' https://www.googletagmanager.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https://everywan.com 1 font-src https://js.klevu.com *.googleapis.com *.hotjar.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.hotjar.com https://9957200.fls.doubleclick.net https://danv01ao0kdr2.cloudfront.net https://dj3zaulksz6yg.cloudfront.net *.brandlock.io *.braintreegateway.com *.klarna.com https://accounts.google.com *.mention-me.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.incontinencechoice.co.uk https://prod.choiceadmin.co.uk https://staging.choiceadmin.co.uk https://admin.vivactive.com https://trk.ometria.com *.brandlock.io https://www.google.com https://bat.bing.com https://pixel.quantserve.com https://www.facebook.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://s3-eu-west-1.amazonaws.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.ometria.com cdnjs.cloudflare.com https://js.klevu.com/ https://bat.bing.com https://secure.quantserve.com https://www.gstatic.com https://connect.facebook.net https://dj3zaulksz6yg.cloudfront.net *.brandlock.io https://cdn-ukwest.onetrust.com https://geolocation.onetrust.com https://songbirdstag.cardinalcommerce.com https://www.googleoptimize.com https://cdn.oribi.io https://app.factors.ai https://rules.quantcount.com https://googleads.g.doubleclick.net https://www.clarity.ms https://www.clarity.ms/tag/ *.googleapis.com https://www.googletagmanager.com/gtag/js *.klarna.com *.klarnacdn.net https://accounts.google.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://tag.rmp.rakuten.com *.klevu.com *.ksearchnet.com *.mention-me.com *.yotpo.com swellrewards.com *.swellrewards.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cc-cdn.com assets.braintreegateway.com *.googleapis.com *.hotjar.com https://accounts.google.com https://www.gstatic.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://payments.sandbox.braintree-api.com https://api.sandbox.braintreegateway.com https://origin-analytics-sand.sandbox.braintree-api.com/ https://danv01ao0kdr2.cloudfront.net *.brandlock.io https://cdn-ukwest.onetrust.com https://privacyportal-uk.onetrust.com *.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://geolocation.onetrust.com *.hotjar.com *.hotjar.io wss://*.hotjar.com https://api.factors.ai https://b.clarity.ms https://y.clarity.ms/collect *.googleapis.com *.klarnaevt.com https://accounts.google.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.klevu.com *.ksearchnet.com *.mention-me.com *.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f720cf68-df7d-4a7b-a5e9-4e537ae99361.sansec.watch/; report-to report-endpoint; 1 default-src 'self' infoblox.okta.com *.oktacdn.com; connect-src 'self' infoblox.okta.com infoblox-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com infoblox.kerberos.okta.com infoblox.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-qbDsPehPPvAhLxQtp3WccQ' 'unsafe-eval' 'self' 'report-sample' infoblox.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' infoblox.okta.com *.oktacdn.com; frame-src 'self' infoblox.okta.com infoblox-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: api-76e5adb9.duosecurity.com; img-src 'self' infoblox.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' infoblox.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.sandbox.paypal.com *.youtube.com *.paypal.com *.googleadservices.com *.google-analytics.com *.google.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.googleapis.com *.placeholder.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.google.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.googleapis.com *.placeholder.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cdninstagram.com *.google.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com cdn.lightwidget.com lightwidget.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.instagram.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.placeholder.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.addtoany.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.youtube.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de http://dpm.demdex.net *.cloudflare.com *.twitter.com *.twimg.com *.youtube.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com cdn.lightwidget.com lightwidget.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-eM05HV61OnhJG86YLgxWJA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' 'unsafe-inline' https://px.ads.linkedin.com/ https://alleima.maps.arcgis.com/ https://*.alleima.com/ https://vimeo.com/ https://*.googlesyndication.com/ https://mb.cision.com/ https://*.doubleclick.net/ https://dl.episerver.net https://player.vimeo.com https://*.cookielaw.org/ https://alleima.matomo.cloud/ https://dc.services.visualstudio.com/ https://www.google.com/ https://www.googletagmanager.com/ https://*.google-analytics.com/ https://snap.licdn.com/ https://googleads.g.doubleclick.net/ https://static.ads-twitter.com/ https://*.hotjar.com/ https://connect.facebook.net/ https://*.outbrain.com/ https://tr.outbrain.com/ https://*.onetrust.com/ https://cdn.linkedin.oribi.io/ wss://ws.hotjar.com https://*.hotjar.io/ https://*.datablocks.se https://*.zdassets.com/ https://*.zendesk.com/ https://*.zopim.com/ wss://*.zopim.com/ https://pui.episerver.net/ https://*.highcharts.com https://www.facebook.com/; img-src 'self' https://*.baidu.com/ https://*.zopim.io/ https://static.zdassets.com/ https://cdn.cookielaw.org/ https://mb.cision.com/ https://px.ads.linkedin.com/ https://www.google.com/ https://www.google.se/ https://t.co/ https://analytics.twitter.com/ https://*.outbrain.com/ https://www.facebook.com/ https://www.googletagmanager.com/ https://px4.ads.linkedin.com/ https://*.vimeocdn.com/ https://*.hotjar.com/ https://cdn.matomo.cloud/ https://maps.googleapis.com/ data:; script-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' https://www.googletagmanager.com/ https://cdn.cookielaw.org/; script-src-elem 'self' 'unsafe-inline' https://assets.alleima.com/ https://webassets.azurewebsites.net/ https://*.baidu.com/ https://*.monitor.azure.com/ https://*.vimeo.com/ https://code.highcharts.com/ https://dl.episerver.net/ https://*.cookielaw.org/ https://cdn.matomo.cloud/ https://alleima.matomo.cloud/ https://az416426.vo.msecnd.net/ https://www.google.com/ https://www.gstatic.com/ https://www.googletagmanager.com/ https://*.google-analytics.com/ https://snap.licdn.com/ https://googleads.g.doubleclick.net/ https://static.ads-twitter.com/ https://*.hotjar.com/ https://connect.facebook.net/ https://*.outbrain.com/ https://*.onetrust.com/ https://cdn.linkedin.oribi.io/ wss://ws.hotjar.com https://*.hotjar.io/ https://*.datablocks.se https://*.zdassets.com/ https://*.zendesk.com/ wss://*.zopim.com https://*.zopim.com https://code.jquery.com/jquery-3.7.1.min.js; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net/ https://stackpath.bootstrapcdn.com/ https://alleima.matomo.cloud/ https://*.datablocks.se/; media-src 'self' https://static.zdassets.com/ https://mb.cision.com/ https://player.vimeo.com https://download-video.akamaized.net/ report-to csp-endpoint 1 script-src 'nonce-9d37c57b25e548a966f36535d13c9f613d0f2273ee602394d95b724bd0612ba5' 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' *.google-analytics.com *.googletagmanager.com *.google.com *.gstatic.com *.googleapis.com *.bing.com *.pcapredict.com *.dwin1.com lantern.roeyecdn.com services.postcodeanywhere.co.uk *.facebook.net; object-src 'none'; base-uri 'none'; report-uri /includes/csp_report.php 1 font-src https://fonts.gstatic.com *.gstatic.com *.bootstrapcdn.com *.tawk.to data: eadn-wc05-6548239.nxedge.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca *.weltpixel.com *.tawk.to static.addtoany.com *.braintreegateway.com eadn-wc05-6548239.nxedge.io *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca cdn.jsdelivr.net *.tawk.to *.google.com *.google.ca eadn-wc05-6548239.nxedge.io https://firebasestorage.googleapis.com *.facebook.com flagpedia.net tawk.link s3.amazonaws.com/ *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.kaptcha.com *.tawk.to cdn.jsdelivr.net static.addtoany.com graph.facebook.com eadn-wc05-6548239.nxedge.io *.avada.io *.shopify.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.bootstrapcdn.com cdn.jsdelivr.net eadn-wc05-6548239.nxedge.io *.fontawesome.com https://fonts.bunny.net *.addtoany.com maxcdn.bootstrapcdn.com *.gstatic.com *.tawk.to *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.affirm.com *.affirm.ca *.kaptcha.com *.google-analytics.com stats.g.doubleclick.net *.tawk.to wss://*.tawk.to eadn-wc05-6548239.nxedge.io https://get.geojs.io *.avada.io http://dpm.demdex.net www.gstatic.com maps.googleapis.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bird.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.facebook.net gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://scripting.tracify.ai https://beacon.tracify.ai https://ip4.tracify.ai https://ip6.tracify.ai https://app.usercentrics.eu https://api.usercentrics.eu https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://api.sovendus.com http://api.sovendus.com https://identification-api.sovendus.com https://sentry.meeva.de https://js-eu1.hs-scripts.com https://js-eu1.hs-analytics.com https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.com https://static-eu.payments-amazon.com https://x.klarnacdn.net https://pp.payengine.de https://pptest.payengine.de https://www.paypal.com https://www.sandbox.paypal.com https://h.online-metrix.net https://cdn.contentflow.net https://d3vhkre7yfpe3v.cloudfront.net https://prd-streamer.osp.live https://*.ad-srv.net http://*.ad-srv.net https://p.gsitrix.com https://o.gsitrix.com https://www.clarity.ms https://scripts.clarity.ms https://static.hotjar.com https://script.hotjar.com https://metrics.hotjar.io https://analytics.fatmedia.io https://analytics2.fatmedia.io https://bt.fraud0.com https://www.wepowerconnections.com https://s.uicdn.com http://s.uicdn.com https://a1.nggx.io https://analytics.bestofluck.io https://connect.facebook.net https://www.facebook.com https://s.pinimg.com https://ct.pinterest.com https://bat.bing.com https://shopin.bellissy.de http://shopin.bellissy.de https://lantern.roeyecdn.com https://lantern.roeye.com https://*.fls.doubleclick.net https://adservice.google.com https://www.google.com https://www.google.de https://www.googleadservices.com https://www.dwin1.com https://www.awin1.com https://cdn.wowing.io https://www.usemaxserver.de https://www.youtube.com https://d.ratepay.com; style-src 'self' 'unsafe-inline' https://d.ratepay.com https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://www.googletagmanager.com https://www-channel21-de.transaktionsplattform.de https://www.channel21.de https://js.klarna.com https://pay.google.com https://www.paypal.com https://www.sandbox.paypal.com https://api.sovendus.com https://cdn.wowing.io https://www.facebook.com https://ct.pinterest.com https://*.fls.doubleclick.net https://bid.g.doubleclick.net https://www.usemaxserver.de https://static-eu.payments-amazon.com https://x.klarnacdn.net https://pp.payengine.de https://pptest.payengine.de https://www.paypal.com https://www.sandbox.paypal.com https://h.online-metrix.net https://*.ad-srv.net http://*.ad-srv.net; connect-src 'self' https://www.channel21.de https://strapi.channel21.de https://shop.channel21.de https://scripting.tracify.ai https://beacon.tracify.ai https://ip4.tracify.ai https://ip6.tracify.ai https://app.usercentrics.eu https://api.usercentrics.eu https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://api.sovendus.com http://api.sovendus.com https://identification-api.sovendus.com https://sentry.meeva.de https://js-eu1.hs-scripts.com https://js-eu1.hs-analytics.com https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.com https://static-eu.payments-amazon.com https://x.klarnacdn.net https://pp.payengine.de https://pptest.payengine.de https://www.paypal.com https://www.sandbox.paypal.com https://h.online-metrix.net https://cdn.contentflow.net https://d3vhkre7yfpe3v.cloudfront.net https://prd-streamer.osp.live https://strapi.channel21.de https://medusa.channel21.de https://shop.projekte.meeva.de https://services.transaktionsplattform.de https://*.ad-srv.net http://*.ad-srv.net https://p.gsitrix.com https://o.gsitrix.com https://www.clarity.ms https://scripts.clarity.ms https://static.hotjar.com https://script.hotjar.com https://metrics.hotjar.io https://analytics.fatmedia.io https://analytics2.fatmedia.io https://bt.fraud0.com https://www.wepowerconnections.com https://s.uicdn.com http://s.uicdn.com https://a1.nggx.io https://analytics.bestofluck.io https://connect.facebook.net https://www.facebook.com https://s.pinimg.com https://ct.pinterest.com https://bat.bing.com https://shopin.bellissy.de http://shopin.bellissy.de https://lantern.roeyecdn.com https://lantern.roeye.com https://*.fls.doubleclick.net https://adservice.google.com https://www.google.com https://www.google.de https://stats.g.doubleclick.net; media-src 'self' https: blob:; worker-src 'self' blob:; manifest-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self' https://www.paypal.com https://www.sandbox.paypal.com; report-uri https://sentry.meeva.de/api/59/security/?sentry_key=93bed88609fe9af32f473a6008ee4be1; report-to csp-endpoint; upgrade-insecure-requests 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-ZDIwNzc4NTMtMTE2MC00NGNiLWFkOTQtMDAyYTM4ZmM0MDhj' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src *.googleapis.com *.gstatic.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com fonts.gstatic.com *.directplant.nl *.googleusercontent.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action www.routexl.com *.facebook.com *.directplant.nl 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.paypal.com *.trustpilot.com *.newrelic.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.aiden.cx *.bing.com *.cookiebot.com *.facebook.com *.google.com google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com bat.bing.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.baidu.com *.cookiebot.com directplant.nl *.directplant.nl *.facebook.net *.ggpht.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bj www.google.by www.google.ca www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.uz www.google.co.za www.google.co.zm www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mk www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.td www.google.tn google.com *.googlesyndication.com *.googleusercontent.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com bat.bing.com api.ipify.org *.trustpilot.com *.hsforms.net *.hsforms.com *.google.com https://widgets.trustedshops.com https://integrations.etrusted.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.aiden.cx *.cookiebot.com *.directplant.nl *.google-analytics.com *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com *.directplant.nl 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.googleapis.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com bat.bing.com www.feedbackcompany.com www.routexl.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.aiden.cx *.cookiebot.com *.directplant.nl *.facebook.com www.google.al www.google.at www.google.be www.google.bg www.google.ca www.google.ch www.google.cl www.google.co.cr www.google.co.in www.google.co.jp www.google.co.ma www.google.com.au www.google.com.br www.google.com.eg www.google.com.lb www.google.com.mt www.google.com.om www.google.com.ph www.google.com.pk www.google.com.py www.google.com.sa www.google.com.tr www.google.com.tw www.google.com.ua www.google.co.nz www.google.co.th www.google.co.uk www.google.co.uz www.google.co.za www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hr www.google.hu www.google.ie www.google.im www.google.it www.google.je www.google.la www.google.lt www.google.lu www.google.lv www.google.md www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.se www.google.si www.google.sk www.google.sr *.google.com google.com *.googlesyndication.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://159deafb-d168-41e7-a7b8-8d8b5d09888c.sansec.watch/; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; report-uri https://www.psru.ac.th/newweb2023/2023?gdsih-csp-report; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.clarity.ms https://d1wi3p9y2i20go.cloudfront.net https://assets.orangehealth.in https://n.clarity.ms https://connect.facebook.net https://api-js.mixpanel.com https://assets.loginwithamazon.com; img-src 'self' 'unsafe-inline' https://d1wi3p9y2i20go.cloudfront.net https://oh-prod-assets.s3.ap-south-1.amazonaws.com https://assets.orangehealth.in https://www.facebook.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.co.in https://www.googleadservices.com https://www.googletagmanager.com https://c.clarity.ms https://c.bing.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://assets.orangehealth.in https://d1wi3p9y2i20go.cloudfront.net https://oh-prod-assets.s3.ap-south-1.amazonaws.com; 1 base-uri 'self'; default-src data: *.youtube.com *.youtu.be *.vimeo.com *.vimeocdn.com cdn.alireviews.io cdn.jsdelivr.net cdn.rawgit.com *.alicdn.com google.com *.google.com *.google.se *.gstatic.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.googleadservices.com *.weaverse.workers.dev *.weaverse.io *.shopify.com *.myshopify.com app.kiwisizing.com *.lipscore.com *.willdesk.com stackpath.bootstrapcdn.com 'self' 'nonce-41ae0339dd9b3ca659118ce805af90dc' https://cdn.shopify.com https://shopify.com; frame-ancestors google.com *.google.com *.google.se *.gstatic.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.googleadservices.com; style-src fonts.gstatic.com *.weaverse.workers.dev *.weaverse.io *.shopify.com *.myshopify.com app.kiwisizing.com *.lipscore.com *.willdesk.com stackpath.bootstrapcdn.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src vimeo.com geolocation-db.com cdn.jsdelivr.net google.com *.google.com *.google.se *.gstatic.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.googleadservices.com *.weaverse.workers.dev *.weaverse.io *.shopify.com *.myshopify.com app.kiwisizing.com *.lipscore.com *.willdesk.com stackpath.bootstrapcdn.com 'self' https://cdn.shopify.com/ https://monorail-edge.shopifysvc.com https://checkout.baltzar.com https://baltzar.myshopify.com; script-src data: *.youtube.com *.youtu.be *.vimeo.com cdn.alireviews.io cdn.jsdelivr.net *.alicdn.com google.com *.google.com *.google.se *.gstatic.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.googleadservices.com *.weaverse.workers.dev *.weaverse.io *.shopify.com *.myshopify.com app.kiwisizing.com *.lipscore.com *.willdesk.com stackpath.bootstrapcdn.com 'nonce-41ae0339dd9b3ca659118ce805af90dc'; font-src data: fonts.gstatic.com *.weaverse.workers.dev *.weaverse.io *.shopify.com *.myshopify.com app.kiwisizing.com *.lipscore.com *.willdesk.com stackpath.bootstrapcdn.com 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cleverreach.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ *.fls.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.awin1.com *.zenaps.com *.google.com *.klarna.com secure.pay1.de *.hotjar.com *.modehaus.dev *.page2flip.de js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.cloudfront.net https://*.etracker.com https://*.etracker.de https://www.magezon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net flagpedia.net s3.eu-central-1.amazonaws.com scontent-ham3-1.cdninstagram.com ix.a8.styla.com *.modehaus.de my.page2flip.de *.etracker.de *.google.de x.bidswitch.net www.clarity.ms *.casalemedia.com *.sitecockpit.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net m.media-amazon.com static-eu.payments-amazon.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://*.etracker.com https://*.etracker.de *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com maps.googleapis.com *.modehaus.de *.modehaus2.de *.baltz.de *.etracker.com *.etracker.de api.signalize.com graph.instagram.com *.styla.com styla.com *.page2flip.de *.hotjar.com *.adcell.com *.ad-srv.net cdnjs.cloudflare.com *.hyj.mobi *.bidswitch.net *.casalemedia.com *.smaato.net *.marker.io *.axonix.com *.adform.net *.hotjar.io *.clarity.ms *.sitecockpit.com *.bing.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com cdn.klarna.com jsctool.com d.payla.io www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com *.google.com maxcdn.bootstrapcdn.com *.styla.com cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.de *.doubleclick.net *.googlesyndication.com *.tiktok.com *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com https://*.etracker.de *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.gstatic.com maps.googleapis.com *.modehaus.de *.baltz.de *.etracker.de *.styla.com *.pay1.de *.page2flip.de *.adcell.com *.picalike.com *.hotjar.com wss://ws.hotjar.com *.hotjar.io *.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.googleapis.com *.coastalbusiness.com *.twitter.com *.yotpo.com *.fontawesome.com *.zohocdn.com *.pagesense.io *.zohostatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.coastalbusiness.com *.yotpo.com *.facebook.com yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com www.google.com *.affirm.com *.affirm.ca *.coastalbusiness.com *.twitter.com *.addthis.com *.google.com *.facebook.com *.ubembed.com *.leasestation.com *.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com yotpo.com *.wesupply.xyz https://wesupplylabs.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.gstatic.com *.googleapis.com *.trackedlink.net *.ddlnk.net *.affirm.com *.affirm.ca *.coastalbusiness.com *.googleadservices.com *.google-analytics.com *.zaius.com *.twitter.com *.adelixir.com t.co 'self' blob: *.bing.com *.pinterest.com *.google.com *.facebook.com *.amazonaws.com *.quickspark.com salesiq.zohopublic.com *.zoho.com *.zohocdn.com *.campaign-image.com *.maillist-manage.com *.pagesense.io *.zohostatic.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com polyfill.io https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.twitter.com *.google-analytics.com *.google.com *.googletagmanager.com *.addthis.com *.zdassets.com *.mouseflow.com *.hiss3lark.com d1igp3oop3iho5.cloudfront.net z.moatads.com v1.addthisedge.com *.facebook.com *.facebook.net *.googleadservices.com *.pinimg.com *.bing.com *.ads-twitter.com *.quickspark.com *.ubembed.com *.adelixir.com *.doubleclick.net *.linkedin.com *.cloudflareinsights.com *.pinterest.com *.newrelic.com *.nr-data.net *.zoho.com *.zohocdn.com *.zohopublic.com *.maillist-manage.com *.pagesense.io *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com yotpo.com *.cloudflare.com *.yotpo.com swellrewards.com *.swellrewards.com https://www.coastalbusiness.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.coastalbusiness.com *.googleapis.com *.twitter.com *.quickspark.com *.fontawesome.com css.zohocdn.com *.pagesense.io *.zohostatic.com *.stripe.network *.stripecdn.com *.amazon.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.coastalbusiness.com *.zaius.com *.zdassets.com *.zohostatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com qa-api.magedevteam.com *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.googleapis.com *.affirm.com *.affirm.ca *.coastalbusiness.com *.twitter.com *.zdassets.com *.addthis.com *.amazonaws.com coastalbusiness.zendesk.com wss://widget-mediator.zopim.com *.google-analytics.com *.doubleclick.net *.pinterest.com *.ubembed.com *.yotpo.com *.nr-data.net salesiq.zohopublic.com wss://vts.zohopublic.com *.zohopublic.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src *.googleapis.com *.gstatic.com fonts.gstatic.com *.kxcdn.com maxcdn.bootstrapcdn.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.google.com.ua *.fbcdn.net *.ringostat.net blob: magefan.com cm.magefan.com *.disqus.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com quickchart.io img.youtube.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.ringostat.com *.disqus.com cdn.jsdelivr.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.ringostat.net maxcdn.bootstrapcdn.com cdn.jsdelivr.net fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com www.google.com www.google.com.ua *.ringostat.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com/gtm.js https://*.purechat.com https://prod.purechatcdn.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; script-src-attr 'self'; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://pista.rs https://www.pistafashion.rs https://pistafashion.b-cdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com http://s7.addthis.com s.adroll.com d.adroll.com mc.yandex.ru js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.facebook.com *.facebook.net mc.yandex.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ariba.com app.instapunchout.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.ariba.com app.instapunchout.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr flagpedia.net https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn2.hubspot.net resources.paytrail.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com applepay.cdn-apple.com http://www.cchobby.dk https://www.cchobby.dk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com applepay.cdn-apple.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://nominatim.openstreetmap.org www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.paytrail.com autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.trustpilot.com *.hotjar.com *.pcapredict.com *.psplugin.com *.postcodeanywhere.co.uk *.googleapis.com *.cardinalcommerce.com www.googletagmanager.com www.google-analytics.com js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.trustpilot.com *.hotjar.com *.pcapredict.com *.psplugin.com squeezely.tech assets.sitescdn.net googleads.g.doubleclick.net *.postcodeanywhere.co.uk *.googleapis.com *.cardinalcommerce.com consent.cookiebot.com pay.google.com www.paypalobjects.com www.paypal.com www.googletagmanager.com www.google-analytics.com js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net; worker-src 'self' *.psplugin.com blob:; frame-src consentcdn.cookiebot.com *.trustpilot.com *.hotjar.com *.braintreegateway.com www.googletagmanager.com *.doubleclick.net checkout.paypal.com pay.google.com *.cardinalcommerce.com *.paypal.com; frame-ancestors 'self' *.psplugin.com 1 object-src 'none'; connect-src 'self' *.agentredgirl.com *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.agentredgirl.com *.adulttime.com join.gammasecure.com; script-src 'self' *.agentredgirl.com *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.agentredgirl.com *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com https://hpp.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://secure-test.worldpay.com/shopper/3ds/ddc.html https://secure.worldpay.com/shopper/3ds/ddc.html https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://pay.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://pay.google.com https://secure-test.worldpay.com https://hpp.worldpay.com/ https://www.paypal.com/sdk/js *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.openstreetmap.org https://maps.googleapis.com *.cloudflare.com magefan.com cm.magefan.com *.trackedlink.net *.disqus.com https://v2assets.zopim.io https://static.zdassets.com *.klevu.com *.ksearchnet.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com *.googlesyndication.com https://www.google.com/recaptcha/api.js *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://www.paypal.com/sdk/js *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.disqus.com https://static.zdassets.com https://ekr.zdassets.com https://chadwickshelp.zendesk.com https://*.zopim.com wss://chadwickshelp.zendesk.com wss://*.zopim.com webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn.jsdelivr.net js.klevu.com *.ksearchnet.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com https://fonts.googleapis.com/css webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn.jsdelivr.net *.klevu.com *.ksearchnet.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.openstreetmap.org https://www.google.com/pay https://pay.google.com/gp/p/web_manifest.json https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/ https://google.com/pay *.worldpay.com https://hpp.worldpay.com/app/hpp/135-0/telemetry https://hpp.worldpay.com/app/hpp/135-0/payment/paypalsmartbutton/continue https://www.paypal.com/sdk/js https://payments.worldpay.com/app/hpp/135-0/telemetry/iframe *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://static.zdassets.com https://ekr.zdassets.com https://chadwickshelp.zendesk.com https://*.zopim.com wss://chadwickshelp.zendesk.com wss://*.zopim.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://static.addtoany.com/ *.dotdigital-pages.com *.dotdigital.com *.affirm.com *.affirm.ca cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.affirm.com *.affirm.ca https://firebasestorage.googleapis.com https://www.magezon.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net scontent-sea1-1.cdninstagram.com scontent.cdninstagram.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page https://static.addtoany.com/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.affirm.com *.affirm.ca cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.avada.io *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.affirm.com *.affirm.ca webchat.dotdigital.com webchat.staging.dotdigital.com https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://imgs.signifyd.com api.livechatinc.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; script-src 'nonce-e00e412a458a435882e5d8d7c4c2872a' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; style-src 'self' 'nonce-e00e412a458a435882e5d8d7c4c2872a' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=143-4177664-8853401:rid=2CA3CFAB8CEE401591D3:sn=www.amazongamestudios.com 1 font-src fonts.gstatic.com use.typekit.net *.livechatinc.com *.googlesyndication.com *.klaviyo.com *.cloudfront.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ api.sensepass.com api.sandbox.sensepass.com pay.sensepass.com pay.sandbox.sensepass.com ecom.sandbox.sensepass.com ecom.sensepass.com cdn.roomvo.com *.doubleclick.net/ *.publitas.com *.livechatinc.com *.googlesyndication.com *.pinterest.com *.klaviyo.com *.cloudfront.net *.facebook.com *.paycomonline.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ pay.sensepass.com *.visualwebsiteoptimizer.com *.livechatinc.com *.googlesyndication.com *.google.co.in *.facebook.com *.jaipurliving.com *.klaviyo.com *.cloudfront.net *.taboola.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googletagmanager.com tagmanager.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klear.com klear.com js.sensepass.com sensepass.com cdn.roomvo.com *.livechatinc.com *.googlesyndication.com *.publitas.com *.visualwebsiteoptimizer.com cnstrc.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cdn.livechatinc.com *.newrelic.com *.facebook.net *.hotjar.com *.pinimg.com *.taboola.com *.pinterest.com *.google.com *.gstatic.com *.klaviyo.com *.cloudfront.net *.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.braintreegateway.com tagmanager.google.com fonts.google.com https://static.klaviyo.com *.publitas.com *.klaviyo.com *.cloudfront.net *.taboola.com *.facebook.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klear.com klear.com www.roomvo.com cdn.livechatinc.com *.googlesyndication.com cnstrc.com bam.nr-data.net *.google.com *.doubleclick.net *.taboola.com *.pinterest.com wss://ws.hotjar.com *.hotjar.com *.hotjar.io *.gstatic.com *.klaviyo.com *.cloudfront.net *.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://*.haco.nu https://*.pinterest.com js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://www.haco.nu https://*.taggrs.io https://*.haco.nu https://www.mollie.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net https://*.cookiefirst.com https://*.pinimg.com https://*.clarity.ms https://*.pinterest.com js.mollie.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://*.cookiefirst.com https://*.pinimg.com https://*.clarity.ms *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://*.googlesyndication.com https://*.haco.nu https://*.amazonaws.com https://*.pinterest.com https://*.cookiefirst.com https://*.clarity.ms *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gricegunshop.com https://maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.gricegunshop.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js-agent.newrelic.com https://www.googleoptimize.com *.avada.io *.shopify.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.gricegunshop.com https://maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.gricegunshop.com https://bam.nr-data.net https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e9a3e5c9-ee3e-4f4f-9dd4-386287fd71e8.sansec.watch/; report-to report-endpoint; 1 font-src https://*.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.klaviyo.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.googletagmanager.com *.doubleclick.net *.redintelligence.net *.trustpilot.com *.googlesyndication.com *.dwin1.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://*.gstatic.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com blob: *.google.com *.google.co.uk *.gstatic.com *.googlesyndication.com *.bing.com *.bing.net *.cloudflare.com *.cloudfront.net *.roeye.com *.freshchat.com *.clarity.ms *.wisepops.com wisepops.net *.soreto.com *.tiktok.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.avada.io *.shopify.com *.google.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.tiktok.com *.taboola.com *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.withcubed.com *.roeyecdn.com *.klaviyo.com *.trustpilot.com *.visualwebsiteoptimizer.com *.payments-amazon.com fw-cdn.com cdn-sitegainer.com *.ip-api.com *.cloudflare.com *.cloudfront.net *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.ytimg.com *.googleapis.com *.vimeo.com *.freshchat.com *.hotjar.com *.hsforms.net *.hsforms.com https://snippets.freshchat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ cc-cdn.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com data: *.googleapis.com *.googlesyndication.com *.typekit.net *.seersco.com *.klaviyo.com *.freshchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.taboola.com *.tiktok.com *.tiktokw.us *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.awinblackfriday.com *.freshchat.com *.amazonaws.com *.googletagmanager.com *.dwin1.com *.trustpilot.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com fonts.googleapis.com *.fontawesome.com fonts.bunny.net use.typekit.net p.typekit.net cdnjs.cloudflare.com cdn.jsdelivr.net cdn.doofinder.com cc-cdn.com static.klaviyo.com; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com p.typekit.net fonts.bunny.net static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com www.henrykrank.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.henrykrank.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com live.opayo.eu.elavon.com *.opayo.co.uk *.elavon.com secure7.arcot.com *.arcot.com www.googletagmanager.com www.henrykrank.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io cdn.doofinder.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com d3k81ch9hvuctc.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.doofinder.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com cdnjs.cloudflare.com cdn.jsdelivr.net eu1-config.doofinder.com trackcmp.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com cdnjs.cloudflare.com cdn.jsdelivr.net use.typekit.net p.typekit.net cdn.doofinder.com static.klaviyo.com static-tracking.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.henrykrank.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doofinder.com wss://*.doofinder.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io m2.staging.henrykrank.com.cfstack.com m2.dev.henrykrank.com.cfstack.com henrykrank.com www.henrykrank.com api-js.datadome.co cdnjs.cloudflare.com 'self' 'unsafe-inline'; child-src www.henrykrank.com http: https: blob: 'self' 'unsafe-inline'; default-src www.henrykrank.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.espssl.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.googleapis.com *.bootstrapcdn.com *.cloudflare.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.ladesk.com *.twitter.com *.google.co.in *.kaptcha.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com *.espssl.com *.payments-amazon.com *.listrakbi.com *.pinterest.com *.facebook.com *.google.com *.google.co.in *.klarna.com *.twitter.com *.ytimg.com stats.g.doubleclick.net *.connect.facebook.net pixel.advertising.com *.googletagmanager.com *.twimg.com *.placehold.it blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com cdnjs.cloudflare.com *.pinterest.com *.listrakbi.com *.listrak.com *.ladesk.com s.pinimg.com *.facebook.net *.twitter.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com connect.facebook.net *.googletagmanager.com static-na.payments-amazon.com js-agent.newrelic.com *.jquery.com 'self' js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdnjs.cloudflare.com *.jquery.com *.espssl.com *.fontawesome.com *.typekit.net https://use.typekit.net *.listrakbi.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.youtube.com *.bootstrapcdn.com 'unsafe-inline' unsafe-inline assets.braintreegateway.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.listrakbi.com *.doubleclick.net *.algolia.io *.pinterest.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com *.braintree-api.com *.amazon.com bam.nr-data.net *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de 'self' 'unsafe-inline'; child-src 'self' blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://actionis.report-uri.com/a/d/g; report-to report-endpoint; 1 default-src 'self'; report-uri /csp-report-endpoint 1 default-src 'self'; base-uri 'self'; block-all-mixed-content; object-src 'none'; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://*.googletagservices.com https://*.google-analytics.com https://*.airasia.com https://*.apiairasia.com https://*.airasia.cn https://*.google.com https://www.gstatic.com https://www.recaptcha.net https://*.widerplanet.com http://*.widerplanet.com https://d2r1yp2w7bby2u.cloudfront.net https://sg1.clevertap-prod.com https://static.cloudflareinsights.com https://*.clarity.ms https://*.doubleclick.net https://*.googlesyndication.com http://static.clevertap.com https://*.adtrafficquality.google https://cdn.moengage.com https://cdn.ampproject.org https://www.gstatic.com https://ajax.googleapis.com https://js.hcaptcha.com https://cdn-ima.33across.com https://oa.openxcdn.net https://static.criteo.net https://invstatic101.creativecdn.com https://tags.crwdcntrl.net https://cdnjs.cloudflare.com https://websdk.appsflyer.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.airasia.com https://*.airasia.cn https://www.gstatic.com; img-src 'self' https: data:; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com data:; connect-src 'self' https://*.apiairasia.com https://*.airasia.com https://*.airasia.cn https://airasia.ck123.io https://airasia.gw-dv.vip https://ls.cdn-gw-dv.vip https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://sg1.clevertap-prod.com https://*.doubleclick.net https://*.googlesyndication.com https://*.google.com https://api.34.8.215.20.nip.io https://ingestfnt-us.dsp-api.moloco.com https://api.vidi.co https://*.adtrafficquality.google https://www.recaptcha.net wss://chatbot.airasia.com https://bcp.crwdcntrl.net https://oajs.openx.net/ https://pixelfnt-us.dsp-api.moloco.com/ https://rc.conviva.com/ https://3e89bbb8ef74ef58e62f5df202a002d76aa3d9bf.appgw.conviva.com/ https://rcg.conviva.com/ https://websdk.appsflyer.com; frame-src 'self' https://*.google.com https://www.recaptcha.net https://*.doubleclick.net https://*.googlesyndication.com https://*.googleadservices.com https://*.googletagmanager.com https://*.widerplanet.com https://*.adtrafficquality.google https://pixelfnt-us.dsp-api.moloco.com https://ls.cdn-gw-dv.vip https://gumi.criteo.com/ https://google-bidout-d.openx.net/ https://newassets.hcaptcha.com/ https://*.airasia.cn https://*.airasia.com; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.unpkg.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.authorize.net checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com challenges.cloudflare.com *.instagram.com *.cdninstagram.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.unpkg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ media.sezzle.com maps.gstatic.com https://widget.freshworks.com https://www.strikeindustries.com *.instagram.com *.cdninstagram.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.unpkg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net sandbox-assets.secure.checkout.visa.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com maps.googleapis.com challenges.cloudflare.com https://classic.avantlink.com https://www.googletagmanager.com https://maps.googleapis.com https://widget.freshworks.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.unpkg.com https://static.klaviyo.com fonts.cdnfonts.com *.gstatic.com https://widget.freshworks.com *.instagram.com *.cdninstagram.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.unpkg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com maps.googleapis.com *.gstatic.com https://widget.freshworks.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.trackedlink.net *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com www.google.com.ua data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://0c5a6b9b-11e6-49ac-992d-110c7fe8fa86.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es https://www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es https://redchamps.com maps.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es maps.googleapis.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 default-src 'self' litium.revolutionrace.se fbcdn.revolutionrace.se wss://fbcdn.revolutionrace.se *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.se *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 default-src 'self' *.alkompis.se; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.alkompis.se *.google.com *.twitter.com *.cloudflarestream.com *.vimeo.com *.youtube.com *.googleadservices.com *.googlesyndication.com *.doubleclick.net *.youtube.com *.termly.io *.googletagmanager.com *.facebook.net *.google *.ampproject.org *.cookiebot.com *.holid.io; style-src 'self' 'unsafe-inline' *.alkompis.se *.googleapis.com; connect-src 'self' *.alkompis.se *.termly.io *.cookiebot.com *.google-analytics.com *.googlesyndication.com *.google.com *.doubleclick.net *.google *.adform.net *.holid.io; font-src 'self' data: *.alkompis.se *.gstatic.com; media-src 'self' data: *.alkompis.se; frame-src 'self' *.twitter.com *.soundcloud.com *.youtube.com *.googletagmanager.com *.facebook.com *.adtrafficquality.google *.cloudflarestream.com *.vimeo.com *.zendesk.com *.googlesyndication.com *.doubleclick.net *.google.com *.holid.io *.rubiconproject.com *.cookiebot.com; img-src 'self' data: *.alkompis.se *.vimeocdn.com *.adtrafficquality.google *.ytimg.com *.facebook.com *.googlesyndication.com *.google.com *.google.se *.doubleclick.net *.googletagmanager.com *.cookiebot.com; 1 default-src 'self' *.aswo.com *.euras.com *.aswo.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.aswo.com *.euras.com *.aswo.net ; style-src 'self' 'unsafe-inline' *.aswo.com *.euras.com *.aswo.net ; img-src 'self' 'unsafe-inline' *.aswo.com *.euras.com *.aswo.net data: ; font-src 'self' 'unsafe-inline' *.aswo.com *.euras.com *aswo.net ; connect-src 'self' *.aswo.com *.euras.com *aswo.net ; object-src 'self' 'unsafe-inline' *.aswo.com *.euras.com *.aswo.net ; report-uri /log881.php; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net 'self' data: https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://geowidget-app.inpost.pl/ *.weltpixel.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com facebook.com *.cookiebot.com creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.awin1.com *.zenaps.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: https://maps.gstatic.com https://maps.googleapis.com *.facebook.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.bing.com garett.com.pl google.pl facebook.com trustmate.io www.google.pl *.clarity.ms blob: *.credit-agricole.pl lantern.roeye.com *.googlesyndication.com awin1.com google.com s3-eu-west-1.amazonaws.com salesmanago.s3-eu-west-1.amazonaws.com conversionlabs.net.pl *.cookiebot.com *.trustmate.io img.sct.eu1.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.google.com https://maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.cookiebot.com rum.uptime.com *.buybox.click *.cloudflare.com *.hotjar.com bat.bing.com *.callpage.io trustmate.io analytics.tiktok.com *.clickonometrics.pl *.clarity.ms *.dwin1.com callpage.io *.roeyecdn.com *.googlesyndication.com awin1.com *.cookiebot.eu https://scripts.luigisbox.com https://cdn.luigisbox.com *.luigisbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl tagmanager.google.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.callpage.io *.cloudfront.net trustmate.io sandbox-easy-geowidget-sdk.easypack24.net *.luigisbox.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net *.callpage.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://the.sciencebehindecommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://maps.googleapis.com *.facebook.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com stats.g.doubleclick.net *.cookiebot.com *.googlesyndication.com stream.cloud.witbee.com *.cloudflare.com rum.uptime.com *.callpage.io vc-service.saleago.com googleads.g.doubleclick.net analytics.tiktok.com *.clarity.ms wss://*.salesmanago.com wss://*.hotjar.com *.hotjar.io delivery.clickonometrics.pl trustmate.io facebook.com *.cookiebot.eu https://api.luigisbox.com https://live.luigisbox.com https://app.luigisbox.com *.luigisbox.com analytics-ipv6.tiktokw.us 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com *.google.com *.facebook.com *.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'report-sample' https://www.googletagmanager.com https://www.google-analytics.com https://cse.google.com https://www.google.com https://ep2.adtrafficquality.google 'sha256-kbSBue5+KI3QyDT+Y49cVpozCxbtP52DMNRotJOx+nY=' cdnjs.cloudflare.com https://ai.ocelotbot.com; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://ai.ocelotbot.com https://www.google.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' maps.googleapis.com ssl.google-analytics.com www.googletagmanager.com maps.google.com wasm-eval connect.facebook.net verify.uk.littlepay.com; frame-ancestors 'self' http://www.rslcontent.co.uk; report-uri https://tbkb01.report-uri.com/r/t/csp/reportOnly; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.addthis.com *.authorize.net *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com player.vimeo.com 'sha256-QDGDb+WeOOB5b/eBI08w60MMT++33NXP7SyPW/nkAF0=' 'sha256-M+S/HK4OygEmE9PBu/Hiiktl8vyfcalDUU5cBHr0Olo=' 'sha256-cYzSldWkkFjiVyFgVK5ncCuGq6uuTBkiG9iwn/gVCWM=' *.authorize.net *.cloudflare.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.addthis.com *.authorize.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; object-src 'none'; script-src 'report-sample' https: 'nonce-MjI1Nzk1NzQ0OSw0MjQzNTI5NA==' 'unsafe-eval' 'strict-dynamic'; report-uri https://csp.canva.com/_cspreport?ro=true&requestId=9af40aeb7ae82157&app=devdocs; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com *.typekit.net *.sharethis.com www.ilfordphoto.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn www.ilfordphoto.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.ilfordphoto.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn www.xtento.com www.ilfordphoto.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.stripe.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ store.paradoxlabs.com *.typekit.net *.sharethis.com www.xtento.com cdn.xtento.com www.ilfordphoto.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.sharethis.com *.typekit.net www.xtento.com cdn.xtento.com www.ilfordphoto.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.typekit.net www.ilfordphoto.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.ilfordphoto.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.stripe.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net *.typekit.net *.sharethis.com stats.g.doubleclick.net www.ilfordphoto.com 'self' 'unsafe-inline'; child-src www.ilfordphoto.com http: https: blob: 'self' 'unsafe-inline'; default-src www.ilfordphoto.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net script.hotjar.com *.gstatic.com *.livechatinc.com use.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com esqa.moneris.com www3.moneris.com *.sharethis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.livechatinc.com *.hotjar.com *.doubleclick.net *.moneris.io *.pinterest.com vgdelivery.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net maps.googleapis.com *.sharethis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' blob: bat.bing.com *.bing.net *.analytics.yahoo.com www.facebook.com maps.gstatic.com www.gstatic.com script.hotjar.com *.doubleclick.net *.everythingwine.ca ws1.postescanada-canadapost.ca *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net esqa.moneris.com www3.moneris.com maps.googleapis.com developers.google.com *.sharethis.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com null *.livechatinc.com *.hotjar.com script.crazyegg.com www.facebook.com *.yimg.com cdn.livesession.io *.doubleclick.net *.bing.com *.clarity.ms cdn.livechatinc.com ws1.postescanada-canadapost.ca unpkg.com *.gorgias.chat *.dyn-rev.app *.pinimg.com *.pinterest.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com ws1.postescanada-canadapost.ca *.googleapis.com *.gstatic.com use.fontawesome.com https://static.klaviyo.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.sharethis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.yimg.com script.crazyegg.com *.clarity.ms *.livesession.io google.com www.google.com pay.google.com *.analytics.google.com maps.googleapis.com *.hotjar.io *.hotjar.com wss://ws.hotjar.com *.livechatinc.com *.everythingwine.ca *.doubleclick.net unpkg.com *.gorgias.chat gorgias.win gorgias-convert.com *.dyn-rev.app *.pinterest.com *.bing.com *.bing.net ws1.postescanada-canadapost.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.googletagmanager.com stats.g.doubleclick.net www.paypal.com www.paypalobjects.com js.stripe.com connect.facebook.net static.addtoany.com www.googleadservices.com static.cloudflareinsights.com ajax.cloudflare.com googleads.g.doubleclick.net www.google.com servicepoints.sendcloud.sc www.gstatic.com cdn.jsdelivr.net analytics.tiktok.com static.olark.com assets.olark.com knrpc.olark.com maps.google.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net static.olark.com; img-src 'self' data: www.google-analytics.com stats.g.doubleclick.net www.paypal.com www.paypalobjects.com connect.facebook.net googleads.g.doubleclick.net www.google.com www.facebook.com analytics.tiktok.com log.olark.com; connect-src 'self' www.google-analytics.com www.paypal.com securepayments.paypal.com api.braintreegateway.com js.stripe.com api.stripe.com www.google.com www.google.fr region1.analytics.google.com www.merchant-center-analytics.goog www.googleadservices.com analytics.tiktok.com cdn.jsdelivr.net analytics-ipv6.tiktokw.us knrpc.olark.com api.getalma.eu maps.google.com maps.googleapis.com; font-src 'self' fonts.gstatic.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net data: static.olark.com/; frame-src 'self' www.paypal.com payments.amazon.com servicepoints.sendcloud.sc www.google.com www.youtube.com www.facebook.com static.addtoany.com www.googletagmanager.com static.olark.com; object-src 'none'; media-src 'self' static.olark.com; form-action 'self' www.paypal.com securepayments.paypal.com secure.payplug.com www.facebook.com 1 upgrade-insecure-requests; report-to https://f761a3114dffe4f5bac4f0780391ab.0d.environment.api.powerplatform.com:443/powerautomate/automations/direct/workflows/f07330bb13c841fa9a524497a65cba07/triggers/manual/paths/invoke?api-version=1&sp=triggersmanualrun&sv=1.0&sig=Rq_odGxsqXourHOCLMou32o_ksfuBzfv6mDKXdtCd-w;; report-uri https://f761a3114dffe4f5bac4f0780391ab.0d.environment.api.powerplatform.com:443/powerautomate/automations/direct/workflows/f07330bb13c841fa9a524497a65cba07/triggers/manual/paths/invoke?api-version=1&sp=triggersmanualrun&sv=1.0&sig=Rq_odGxsqXourHOCLMou32o_ksfuBzfv6mDKXdtCd-w;; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.monetico-services.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.monetico-services.com https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.criteo.com *.canva.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.iadvize.com *.hsforms.net *.hsforms.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.openstreetmap.org https://maps.googleapis.com *.disqus.com 'self' data: *.cookielaw.org/ *.matomo.cloud *.hotjar.com *.clarity.ms *.google.com *.google.fr *.google.de *.googletagmanager.com *.doubleclick.net *.facebook.com *.facebook.net *.criteo.com *.affilae.com *.dialoginsight.com *.stripe.com *.worldline-solutions.com *.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.iadvize.com *.hsforms.net *.hsforms.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.disqus.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.gstatic.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.cookielaw.org/ *.matomo.cloud *.hotjar.com *.clarity.ms *.google.fr *.google.de *.googletagmanager.com *.facebook.com *.facebook.net *.criteo.com *.affilae.com *.dialoginsight.com *.worldline-solutions.com *.cookielaw.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.monetico-services.com *.iadvize.com t.elasticsuite.io *.hsforms.net *.hsforms.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.openstreetmap.org https://maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.cookielaw.org/ *.onetrust.com/ *.matomo.cloud *.hotjar.com *.clarity.ms *.google.fr *.google.de *.googletagmanager.com *.doubleclick.net *.facebook.com *.facebook.net *.criteo.com *.affilae.com *.dialoginsight.com *.worldline-solutions.com *.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src *.gemaire.com; font-src *.fontawesome.com use.typekit.net fonts.gstatic.com www.cvent-assets.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.weltpixel.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com *.certcapture.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gemaire.com www.google.pl cdn.cookielaw.org *.scene7.com/ maps.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.avada.io *.gemaire.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.cookielaw.org cdn.rudderlabs.com js-agent.newrelic.com survey.survicate.com service.force.com gemaire.my.salesforce.com *.salesforceliveagent.com www.cvent.com www.cvent-assets.com maps.googleapis.com *.google-analytics.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.gemaire.com use.typekit.net p.typekit.net fonts.googleapis.com fonts.gstatic.com www.cvent-assets.com service.force.com gemaire.secure.force.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.certcapture.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.gemaire.com browser-intake-datadoghq.com cdn.cookielaw.org *.google-analytics.com *.algolia.net *.algolianet.com stats.g.doubleclick.net api.rudderstack.com bam.nr-data.net js-agent.newrelic.com *.dataplane.rudderstack.com maps.googleapis.com www.cvent.com *.scene7.com *.onetrust.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' seatgeek.okta.com *.oktacdn.com; connect-src 'self' seatgeek.okta.com seatgeek-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com seatgeek.kerberos.okta.com seatgeek.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-ktQelx_AmqugJqz2rY1W2Q' 'unsafe-eval' 'self' 'report-sample' seatgeek.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-ktQelx_AmqugJqz2rY1W2Q' 'self' 'report-sample' seatgeek.okta.com *.oktacdn.com; frame-src 'self' seatgeek.okta.com seatgeek-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: api-680e7385.duosecurity.com; img-src 'self' seatgeek.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' seatgeek.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://seatgeekadmin.com 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com *.google.com/ https://www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.bird.eu https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.myhealth1st.com.au; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://snap.licdn.com/li.lms-analytics/insight.min.js https://snap.licdn.com/li.lms-analytics/insight.old.min.js https://tr.outbrain.com/cachedClickId https://amplify.outbrain.com/cp/obtp.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net https://wave.outbrain.com/mtWavesBundler/handler/00d37644637179e79c1002bdb62e1e289e https://js.sentry-cdn.com https://browser.sentry-cdn.com https://www.google-analytics.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://api.mapbox.com; connect-src 'self' https://api.mapbox.com https://amplify.outbrain.com/topics https://tr.outbrain.com/unifiedPixel https://www.google.com/ccm/collect https://px.ads.linkedin.com https://events.mapbox.com https://analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://*.myhealth1st.com.au; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://images.ctfassets.net/h3fal7pd5dgs/4dKiJe3tZrGjwKtTh5UajX/* https://assets.myhealth1st.com.au/* https://www.google.com.au/ads/ga-audiences https://www.googletagmanager.com/td https://px.ads.linkedin.com/collect https://www.facebook.com https://*.myhealth1st.com.au https://www.google-analytics.com https://www.google.com.au/ads/* data:; worker-src 'self' blob:; frame-src 'self' https://www.googletagmanager.com https://td.doubleclick.net; report-uri /contentSecurityPolicy/report 1 script-src-elem 'self' browser-update.org cdn.celerantwebservices.com cdn.polyfill.io cdn.rawgit.com developer.livehelpnow.net edge1.certona.net f.monetate.net metopera.prospect2.com se.monetate.net www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com www.res-x.com ajax.googleapis.com cdnjs.cloudflare.com connect.facebook.net webservices.celerant.com me.kis.v2.scr.kaspersky-labs.com api.bdustatic.com blob: browseye-toolbar.appspot.com cdn.jsdelivr.net data: ff.kis.v2.scr.kaspersky-labs.com gc.kis.v2.scr.kaspersky-labs.com get663.com infimv.com int-mmourya-1.monetate.org marketer.monetate.net sb.monetate.net ssl.google-analytics.com t7a.g4ui.com www.babylist.com www.googie-anaiytics.com www.googleadservices.com apis.google.com translate-pa.googleapis.com translate.google.com translate.googleapis.com 'unsafe-inline' cdn.leafletjs.com; script-src 'self' browser-update.org cdn.celerantwebservices.com cdn.jsdelivr.net cdn.polyfill.io cdn.rawgit.com developer.livehelpnow.net edge1.certona.net f.monetate.net metopera.prospect2.com se.monetate.net www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com www.res-x.com ajax.googleapis.com blob: browser.amobi.in cdnjs.cloudflare.com self wasm-eval www.googie-anaiytics.com data: ssl.google-analytics.com www.googleadservices.com sb.monetate.net 'unsafe-eval' 'unsafe-inline'; style-src-elem 'self' cdn.rawgit.com developer.livehelpnow.net fonts.bunny.net fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.celerantwebservices.com cdnjs.cloudflare.com browseye-toolbar.appspot.com cdn.honey.io cdn.jsdelivr.net data: ff.kis.v2.scr.kaspersky-labs.com gc.kis.v2.scr.kaspersky-labs.com marketer.monetate.net me.kis.v2.scr.kaspersky-labs.com www.gstatic.com 'unsafe-inline' cdn.leafletjs.com; style-src 'self' cdn.jsdelivr.net cdn.rawgit.com developer.livehelpnow.net fonts.bunny.net fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.honey.io cdnjs.cloudflare.com self www.gstatic.com 'unsafe-inline'; worker-src blob:; script-src-attr 'unsafe-inline'; style-src-attr 'unsafe-inline'; report-uri https://celerantwebservices.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:; script-src 'self' https://*.googletagmanager.com 'nonce-712822e7efc1d8addf87aac7028f9b5d' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; style-src 'self' 'nonce-712822e7efc1d8addf87aac7028f9b5d' https://fonts.googleapis.com; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; frame-ancestors 'self'; 1 font-src *.klarnacdn.net maxcdn.bootstrapcdn.com https://static.unzer.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://payment.unzer.com/ https://payment.heidelpay.com/ https://sbx-payment.heidelpay.com/ https://h.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.unzer.com *.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.unzer.com https://applepay.cdn-apple.com https://code.jquery.com https://h.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://h.online-metrix.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com *.hsappstatic.net *.jsdelivr.net *.preply.com *.slant.co *.fonts.net *.yotpo.com *.zip.co *.zopim.com unpkg.com *.alicdn.com https://www.gstatic.com https://fonts.gstatic.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com https://*.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googletagmanager.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com *.yotpo.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com 'self' data: https://*.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.trackedlink.net *.afterpay.com *.bing.com *.bing.net *.clarity.ms *.facebook.com *.ggpht.com *.google.com *.pinterest.com *.prreqcroab.icu *.quantserve.com *.rlets.com *.stackadapt.com *.yotpo.com *.zip.co prreqcroab.icu www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bj www.google.ca www.google.cd www.google.ch www.google.cl www.google.cm www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.lk www.google.lt www.google.lu www.google.lv www.google.me www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.tn www.google.tt zip.co *.googleapis.com *.zopim.com www.google.as www.google.bs www.google.bt www.google.by www.google.ci www.google.co.ao www.google.co.ck www.google.co.ls www.google.com.af www.google.com.bz www.google.com.ec www.google.com.gi www.google.com.ly www.google.com.mm www.google.com.ni www.google.com.pa www.google.com.py www.google.com.sl www.google.com.tj www.google.com.uy www.google.com.vc www.google.dm www.google.ga www.google.je www.google.kg www.google.kz www.google.la www.google.md www.google.mg www.google.ps www.google.sh www.google.so www.google.sr www.google.tl www.google.to www.google.vu www.google.ws *.google-analytics.com *.googleadservices.com *.magentocommerce.com *.trackedweb.net google.com www.google.bf www.google.co.mz www.google.co.vi www.google.com.cu www.google.gg www.google.gm www.google.li www.google.ml www.google.nr *.zipmoney.com.au www.google.tg *.vimeo.com *.jquery.com www.google.gl www.google.tm connect.facebook.net graph.facebook.com business.facebook.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com https://*.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.afterpay.com *.bing.com *.clarity.ms *.cometlytrack.com *.fullstory.com *.newrelic.com *.pinimg.com *.pinterest.com *.quantcount.com *.quantserve.com *.rlets.com *.stackadapt.com *.yotpo.com *.zdassets.com *.zip.co *.zipmoney.com.au *.zopim.com localhost unpkg.com *.google.com *.googleapis.com googletagmanager.com savingsslider-a.akamaihd.net eckersleys.snapforms.com.au *.googleadservices.com *.instagram.com *.vimeo.com d18eg7dreypte5.cloudfront.net connect.facebook.net graph.facebook.com business.facebook.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com unsafe-inline assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.stackadapt.com *.fonts.net *.yotpo.com https://fonts.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.google-analytics.com www.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.afterpay.com *.bing.com *.bing.net *.clarity.ms *.cometlytrack.com *.fullstory.com *.localiq.com *.nr-data.net *.openfpcdn.io *.pinterest.com *.quantcount.com *.rlets.com *.stackadapt.com *.zdassets.com *.zendesk.com *.zip.co *.zipmoney.com.au *.zopim.com wss://widget-mediator.zopim.com localhost www.google.ae www.google.al www.google.am www.google.at www.google.be www.google.bg www.google.bj www.google.ca www.google.cd www.google.ch www.google.cl www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.br www.google.com.do www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.es www.google.fi www.google.fm www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.lk www.google.lt www.google.lu www.google.lv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.sc www.google.se www.google.si www.google.tt *.facebook.com savingsslider-a.akamaihd.net www.google.ad www.google.as www.google.az www.google.ba www.google.bt www.google.by www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.ls www.google.co.ug www.google.com.bn www.google.com.co www.google.com.cy www.google.com.ec www.google.com.et www.google.com.gi www.google.com.kh www.google.com.ly www.google.com.mm www.google.com.ni www.google.com.pa www.google.com.pr www.google.com.py www.google.com.sl www.google.com.sv www.google.com.uy www.google.dm www.google.ee www.google.gy www.google.jo www.google.kz www.google.la www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.ps www.google.rw www.google.sk www.google.sn www.google.sr www.google.tl www.google.tn www.google.to www.google.vu www.google.ws *.googleadservices.com *.prreqcroab.icu *.quantserve.com prreqcroab.icu www.google.cm www.google.co.uz www.google.co.vi www.google.com.bo www.google.com.cu www.google.gg www.google.gm www.google.kg www.google.ml www.google.nr zip.co www.google.com.bz www.google.sh www.google.tg www.google.je *.jquery.com connect.facebook.net graph.facebook.com business.facebook.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.zip.co *.clarity.ms *.stackadapt.com 'self' 'unsafe-inline'; report-uri https://463a2327-4119-4a41-98e3-32586d517d30.sansec.watch/; report-to report-endpoint; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.gstatic.com *.fontawesome.com *.tawk.to https://cdnjs.cloudflare.com/ajax/ https://maxcdn.bootstrapcdn.com/ data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ sandbox.cashfree.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com api.razorpay.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io cashfreelogo.cashfree.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net magefan.com cm.magefan.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.razorpay.com *.tawk.to cdn.jsdelivr.net https://cdn.uvdesk.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ sdk.cashfree.com *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.youtube.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com checkout.razorpay.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.googletagmanager.com *.fontawesome.com unsafe-inline *.tawk.to fonts.googleapis.com cdn.jsdelivr.net https://cdnjs.cloudflare.com/ajax/ https://maxcdn.bootstrapcdn.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com lumberjack.razorpay.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src https://fonts.googleapis.com https://fonts.gstatic.com https://cdnjs.cloudflare.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.cepd.tech *.dozapotek.se maxcdn.bootstrapcdn.com fonts.gstatic.com static.lipscore.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com https://cdn.cookiesaur.com https://www.fass.se https://cert.tryggehandel.net *.google.se *.google.com *.google.pl *.cepd.tech *.dozapotek.se https://images.unsplash.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com static.lipscore.com blob: img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.klarna.com https://static.lipscore.com https://cert.tryggehandel.net https://tryggehandel.net https://cdn.cookiesaur.com https://app.cookiesaur.com https://static.redeal.se https://connect.facebook.net *.funktionstjanster.se *.klarnacdn.net *.google.se *.google.com *.cepd.tech *.dozapotek.se *.newrelic.com *.nr-data.net *.googletagmanager.com tagmanager.google.com static.lipscore.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.lipscore.com https://cdnjs.cloudflare.com *.klarnacdn.net *.google.se *.google.com *.cepd.tech *.dozapotek.se maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com static.lipscore.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.cepd.tech *.dozapotek.se 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com https://cdn.cookiesaur.com https://app.cookiesaur.com *.nr-data.net *.doubleclick.net *.googlesyndication.com *.cepd.tech *.dozapotek.se *.google-analytics.com *.analytics.google.com *.googletagmanager.com wapi.lipscore.com users.lipscore.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src script-src-elem 'self' https://www.googletagmanager.com https://www.clubtrac.co.uk/cdn/widget/loader.min.js; script-src 'self' https://www.googletagmanager.com https://www.clubtrac.co.uk/cdn/widget/loader.min.js 'nonce-mcw0htj8dvopab514k2n7ir96u3yzeqg'; connect-src 'self' https://*.google.com https://maps.gstatic.com https://*.google-analytics.com https://www.googletagmanager.com https://cdn.tiny.cloud https://maps.googleapis.com; img-src 'self' https://maps.googleapis.com https://*.google-analytics.com https://maps.gstatic.com https://sp.tinymce.com https://www.googletagmanager.com https://scottishrunningguide.com https://northernrunningguide.com https://midlandsrunningguide.com https://southernrunningguide.com data: blob:; style-src 'self' https://fonts.googleapis.com https://ajax.googleapis.com https://maps.googleapis.com https://cdn.tiny.cloud 'unsafe-inline'; frame-src https://www.youtube.com https://maps.googleapis.com https://*.google.com https://www.clubtrac.co.uk https://*.sibforms.com; font-src 'self' https://fonts.gstatic.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; report-to csp-endpoint; report-uri https://runabc.co.uk/csp-violation-report.php; 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.nosto.com *.nos.to 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.nosto.com *.nos.to *.dotdigital-pages.com *.dotdigital.com *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.nosto.com *.nos.to *.trackedlink.net magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.nosto.com *.nos.to *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.nosto.com *.nos.to *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.mention-me.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-V08BNnpNVXacL62q7SmGnQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 report-to novy_csp;report-uri https://novy.report-uri.com/r/d/csp/reportOnly;default-src 'self';base-uri 'self';frame-ancestors 'none';frame-src https://*.youtube.com https://www.youtube-nocookie.com https://*.cookiebot.com https://*.googletagmanager.com https://td.doubleclick.net https://*.fls.doubleclick.net https://ct.pinterest.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://*.hs-sites-eu1.com;script-src 'nonce-FRcV+DO7IU2tgtGDG92Mog==' 'strict-dynamic' https://*.googletagmanager.com https://tagmanager.google.com https://maps.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googleadservices.com https://*.cookiebot.com https://www.youtube.com https://*.facebook.net https://*.hotjar.com https://*.bing.com https://*.pinimg.com https://*.hs-banner.com https://*.hs-analytics.net https://js.hsadspixel.net https://js.hsleadflows.net https://js.hscollectedforms.net https://*.hubspot.com https://ct.pinterest.com https://*.usemessages.com 'report-sample' 'unsafe-eval';style-src 'self' 'report-sample' https://fonts.googleapis.com https://googletagmanager.com https://tagmanager.google.com 'unsafe-inline';style-src-elem 'self' 'report-sample' https://fonts.googleapis.com https://cdnjs.cloudflare.com 'unsafe-inline';img-src 'self' data: https://i.ytimg.com https://imgsct.cookiebot.com https://maps.googleapis.com https://*.gstatic.com https://www.facebook.com https://connect.facebook.net https://bat.bing.com https://www.google.com https://www.google.be https://www.google.de https://www.google.nl https://www.google.lu https://www.google.fr https://www.google.es https://www.google.it https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.cz https://www.google.co.uk https://www.google.co.il https://www.google.ie https://www.google.at https://www.google.ee https://www.google.se https://www.google.si https://www.google.sk https://www.google.sn https://www.google.py https://www.google.ca https://www.google.ch https://www.google.com.mt https://www.google.com.py https://*.hsforms.com https://*.g.doubleclick.net https://ad.doubleclick.net https://*.hubspot.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googlesyndication.com https://exceptions.hs-embed-reporting.com;font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/;connect-src 'self' https://*.cookiebot.com https://*.googletagmanager.com https://www.google.com https://www.google.be https://www.google.de https://www.google.nl https://www.google.lu https://www.google.fr https://www.google.es https://www.google.it https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.cz https://www.google.co.uk https://www.google.co.il https://www.google.ie https://www.google.at https://www.google.ee https://www.google.se https://www.google.si https://www.google.sk https://www.google.sn https://www.google.py https://www.google.ca https://www.google.ch https://www.google.com.mt https://www.google.com.py https://*.hubapi.com https://analytics.google.com https://*.analytics.google.com https://*.google-analytics.com https://www.googleadservices.com/ https://*.g.doubleclick.net https://ad.doubleclick.net https://maps.googleapis.com https://ct.pinterest.com https://*.hubspot.com https://*.hsforms.com/embed/ https://forms.hscollectedforms.net wss://ws.hotjar.com https://*.hotjar.io https://bat.bing.com https://*.googlesyndication.com https://www.facebook.com;object-src 'none';worker-src 'none';form-action 'self';manifest-src 'self';media-src 'self'; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=18688&v=v1.0&payload=NQYe0s18mY9nS25t8urQrtqv-BkKl5DcpXqYDopMhWzvzwiUS_k4SH6d4zQ0YUPYCblXBVfsjszuO03W5cogxUr3QBHUQiikbySXe1LI27m3MoUpExwoIw9BYdFM7is2_bmZTgSF6Cwyo_jDjgX8scAZfWcpjUWd7SowJMtCal3HywTyhWpVcHPyhrE1PEOF_gi17Kby0mwaQLpdMJMWyQ==; 1 worker-src media.evapo.co.uk static.evapo.co.uk; font-src unity.agechecked.com *.fontawesome.com *.hotjar.com *.hotjar.io lantern.roeyecdn.com lantern.roeye.com *.feefo.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com static.dwcdn.net maxcdn.bootstrapcdn.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.feefo.com maps.gstatic.com maps.googleapis.com storage.googleapis.com s3.eu-west-2.amazonaws.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com widget-mediator.zopim.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net lantern.roeyecdn.com lantern.roeye.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com prtpe.com test.prtpe.com evapo.us10.list-manage.com *.psp-solutions.com *.yotpo.com evapo.co.uk 'self' 'unsafe-inline'; frame-ancestors evapo.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net https://*.wepowerconnections.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.feefo.com maps.gstatic.com maps.googleapis.com storage.googleapis.com s3.eu-west-2.amazonaws.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com widget-mediator.zopim.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net lantern.roeyecdn.com lantern.roeye.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com prtpe.com test.prtpe.com oppwa.com test.oppwa.com unity.agechecked.com *.salesfire.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.google.com/ https://www.youtube.com www.facebook.com platform.twitter.com *.weltpixel.com *.yotpo.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io unity.agechecked.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.awin1.com *.zenaps.com https://*.wepowerconnections.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feefo.com maps.gstatic.com maps.googleapis.com storage.googleapis.com s3.eu-west-2.amazonaws.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com widget-mediator.zopim.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net lantern.roeyecdn.com lantern.roeye.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com prtpe.com test.prtpe.com www.googletagmanager.com datawrapper.dwcdn.net *.salesfire.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.magezon.com magefan.com cm.magefan.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.gstatic.com *.yotpo.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ unity.agechecked.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com jquery.sellxed.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feefo.com maps.gstatic.com maps.googleapis.com storage.googleapis.com s3.eu-west-2.amazonaws.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com widget-mediator.zopim.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.google-analytics.com lantern.roeyecdn.com lantern.roeye.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com paypal-eu-cdn.cloudiq.com eu-test.oppwa.com eu-prod.oppwa.com prtpe.com test.prtpe.com script.crazyegg.com datawrapper.dwcdn.net *.salesfire.co.uk *.smartmetrics.co.uk assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com/ connect.facebook.net twitter.com platform.twitter.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com evapo.co.uk https://chimpstatic.com media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unity.agechecked.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.hotjar.com *.hotjar.io lantern.roeyecdn.com lantern.roeye.com *.feefo.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com prtpe.com test.prtpe.com pt.dwcdn.net static.dwcdn.net *.salesfire.co.uk unsafe-inline maxcdn.bootstrapcdn.com *.typekit.net fonts.googleapis.com tagmanager.google.com *.yotpo.com *.googleapis.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com widget-mediator.zopim.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net lantern.roeyecdn.com lantern.roeye.com *.feefo.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline'; manifest-src media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com unity.agechecked.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://the.sciencebehindecommerce.com https://*.wepowerconnections.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.feefo.com maps.gstatic.com maps.googleapis.com storage.googleapis.com s3.eu-west-2.amazonaws.com *.zdassets.com *.sharethis.com cdn.subscribers.com evapo.zendesk.com wss://widget-mediator.zopim.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.google-analytics.com lantern.roeyecdn.com lantern.roeye.com player.vimeo.com bcp.crwdcntrl.net *.google.com *.google.lv *.google.com.uk cdn.cleanhub.io www.cleanhub.com script.crazyegg.com datawrapper.dwcdn.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.salesfire.co.uk *.smartmetrics.co.uk https://www.google-analytics.com *.yotpo.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com https://*.wepowerconnections.com assets.braintreegateway.com c.paypal.com evapo.co.uk media.evapo.co.uk static.evapo.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src evapo.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.gstatic.com hooks.stripe.com *.braintreegateway.com *.kaptcha.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com bat.bing.com cdn.jsdelivr.net *.google.com *.google.de *.bitpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ landofcoder.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com bat.bing.com connect.facebook.net google.co.in widget.trustpilot.com *.google.com *.gstatic.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com landofcoder.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com www.facebook.com *.google-analytics.com *.doubleclick.net *.analytics.google.com *.googletagmanager.com *.youtube.com *.youtu.be 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' data: https://*.openstreetmap.org app.23degrees.io matomo.ifw-kiel.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org *.trade.ifw-kiel.de http://*.ifw-kiel.de *.ifw-kiel.de corona-datenmonitor-ifw-kiel.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.ifw-kiel.de app.23degrees.io www.tagesschau.de www.facebook.com webcast.streambuzzer.com playout.3qsdn.com g24media.de 21e87844.sibforms.com; style-src-elem 'self' 'sha256-ZHuIQHi6NyMM8SsxXGIT+7n2ngsgurzDCCcFY7LqPVA=' 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org matomo.ifw-kiel.de; report-uri https://www.kielinstitut.de/@http-reporting?csp=report&requestTime=1765948057878592&requestHash=b97a7c11e10d18e2f0640a1f8ab7f7f92b404ca4 1 default-src www.creatudominio.com 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net *.doubleclick.net *.googlesyndication.com *.google.com *.addthis.com *.sharethis.com *.pinterest.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.consentmanager.net https://delivery.consentmanager.net blob: *.google.com *.google.de *.google.at *.google.ch *.google.it *.google.fr *.google.nl *.google.pl *.google.co.uk *.google.lu *.google.cz *.googlesyndication.com *.doubleclick.net *.paypal.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.sharethis.com *.pinterest.com *.cdninstagram.com https://img.youtube.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.google.com *.gstatic.com *.googleads.g.doubleclick.net *.doubleclick.net *.paypal.com *.googlesyndication.com *.googleapis.com *.addthis.com *.sharethis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com s7.addthis.com *.avada.io js.mollie.com *.hsforms.net *.hsforms.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.fontawesome.com *.gstatic.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.google.com *.google-analytics.com *.doubleclick.net *.paypal.com *.cloudflare.com *.googleapis.com *.addthis.com *.sharethis.com *.cardinalcommerce.com *.graph.instagram.com ekr.zdassets.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io storage.googleapis.com magefan.com cm.magefan.com blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.garciadepou.com cdn-cookieyes.com/ www.google.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com adobedtm.com *.doofinder.com *.oct8ne.com *.cookieyes.com cdn-cookieyes.com *.facebook.net s.kk-resources.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com storage.googleapis.com assets.braintreegateway.com *.doofinder.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.oct8ne.com *.doofinder.com *.cookieyes.com cdn-cookieyes.com *.facebook.net s.kk-resources.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com static.lipscore.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.bootstrapcdn.com *.kindlycdn.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com *.hotjar.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com *.playground.kustom.co *.kustom.co 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.klarna.com *.klarnaevt.com *.klarnacdn.net static.lipscore.com blob: img.youtube.com magefan.com cm.magefan.com *.klevu.com *.ksearchnet.com *.facebook.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.klarna.com *.klarnacdn.net static.lipscore.com *.klarnaservices.com js.klevu.com *.ksearchnet.com *.hotjar.com *.getflowbox.com *.spinnaker-js.com *.facebook.com *.facebook.net *.kindlycdn.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com *.playground.kustom.co *.kustom.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com static.lipscore.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.bootstrapcdn.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.klarnaevt.com wapi.lipscore.com users.lipscore.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klevu.com *.ksearchnet.com *.hotjar.com *.g.doubleclick.net *.spinnaker-js.com *.kindlycdn.com *.cookieinformation.com *.app.cookieinformation.com *.doubleclick.net *.td.doubleclick.net *.googletagmanager.com *.cevoid.com *.gallery.cevoid.com *.embed.cevoid.com *.api.cevoid.com *.granit.com *.playground.kustom.co *.kustom.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com/friendly-challenge@0.9.8/widget.module.min.js https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.youtube.com https://www.youtube-nocookie.com https://cdn.matomo.cloud https://juwi.matomo.cloud https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/ https://snap.licdn.com/li.lms-analytics/insight.min.js 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://juwi.matomo.cloud https://imgsct.cookiebot.com/ https://tile.openstreetmap.org https://www.facebook.com/tr/ https://www.facebook.com/privacy_sandbox/pixel/register/trigger/ https://px.ads.linkedin.com/collect https://px4.ads.linkedin.com/collect data:; base-uri 'self'; frame-src 'self' https://consentcdn.cookiebot.com https://www.youtube-nocookie.com https://www.facebook.com; media-src 'self'; style-src 'self' 'unsafe-inline' https://juwi.matomo.cloud https://unpkg.com 'report-sample'; font-src 'self'; worker-src 'self' blob: 'report-sample'; connect-src 'self' https://consentcdn.cookiebot.com https://consent.cookiebot.com https://juwi.matomo.cloud https://api.friendlycaptcha.com https://api.friendlycaptcha.com/api/v1/puzzle https://www.facebook.com/privacy_sandbox/topics/registration/ https://px.ads.linkedin.com/attribution_trigger https://px.ads.linkedin.com/wa/; report-uri https://www.juwi.de/@http-reporting?csp=report&requestTime=1765946003142961&requestHash=747a59aaae9facb2be46f7324d6557ae99ca0b81 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.portlandmaps.com *.rose.portland.local:* *.portlandoregon.gov *.portland.gov *.bootstrapcdn.com *.jquery.com *.typekit.net *.arcgisonline.com *.arcgisonline.com *.arcgis.com arcg.is *.geocortex.com *.odot.state.or.us *.multco.us gis.oregonmetro.gov navigator.state.or.us *.mapbox.com *.openstreetmap.org *.opentopomap.org *.tableau.com *.ssl.fastly.net cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.googleapis.com *.gstatic.com *.googleusercontent.com www.google-analytics.com www.googletagmanager.com tagmanager.google.com *.nr-data.net js-agent.newrelic.com fontlibrary.org use.fontawesome.com *.tiles.wmflabs.org *.loop11.com *.rawgit.com *.imgur.com *.amazonaws.com connect.facebook.net cdn.rawgit.com dojotoolkit.org; frame-ancestors 'self' *.portlandmaps.com *.portlandoregon.gov *.portland.gov; object-src 'none'; report-uri https://portlandmaps.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' blob: wss: data: https:; img-src 'self' data: blob: https: android-webview-video-poster android-webview https://assets.badenova.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: https: https://www.googletagmanager.com https://connect.facebook.net; script-src-elem 'self' 'unsafe-inline' https: https://cdn.tagcommander.com https://connect.facebook.net https://widgets.trustedshops.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://static.badenova.de; connect-src 'self' wss: https:; style-src 'self' 'unsafe-inline' data: https:; frame-src 'self' data: https:; report-uri https://o569815.ingest.sentry.io/api/5716003/security/?sentry_key=ba1ca883ccf34f2db27be1ed29aedfa3 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.klaviyo.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com/ *.google.com *.googletagmanager.com *.doubleclick.net *.redintelligence.net *.trustpilot.com *.googlesyndication.com *.dwin1.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net blob: *.google.com *.google.co.uk *.gstatic.com *.googlesyndication.com *.bing.com *.bing.net *.cloudflare.com *.cloudfront.net *.roeye.com *.freshchat.com *.clarity.ms *.wisepops.com wisepops.net *.soreto.com *.linkedin.com *.tiktok.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com polyfill.io *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com *.avada.io *.shopify.com *.google.com/ *.gstatic.com maps.googleapis.com google.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.tiktok.com *.taboola.com *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.withcubed.com *.roeyecdn.com *.klaviyo.com *.trustpilot.com *.visualwebsiteoptimizer.com *.payments-amazon.com fw-cdn.com cdn-sitegainer.com *.ip-api.com *.cloudflare.com *.cloudfront.net *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.ytimg.com *.googleapis.com *.vimeo.com *.freshchat.com *.licdn.com *.pinimg.com *.linkedin.com *.pinterest.com *.cloudflareinsights.com https://snippets.freshchat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cc-cdn.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com data: *.googleapis.com *.googlesyndication.com *.typekit.net *.seersco.com *.klaviyo.com *.freshchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.taboola.com *.tiktok.com *.tiktokw.us *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.awinblackfriday.com *.freshchat.com *.amazonaws.com *.googletagmanager.com *.dwin1.com *.licdn.com *.pinimg.com *.pinterest.com *.linkedin.com *.google-analytics.com *.trustpilot.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' 'unsafe-inline' data: *.adtrafficquality.google *.google.com csi.gstatic.com *.googlesyndication.com vimeo.com publickeyservice.keys.adm-services.goog completelyretail-single-property-signup.s3.eu-west-2.amazonaws.com accounts.google.com *.completelyretail.co.uk browser-intake-datadoghq.eu www.datadoghq-browser-agent.com *.google-analytics.com *.googleapis.com vitals.vercel-insights.com *.googletagmanager.com; report-to datadog 1 font-src fonts.bunny.net cdnjs.cloudflare.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://www.paypal.com e.jachensen.nl td.doubleclick.net www.kiyoh.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com www.jachensen.nl trengo.s3.eu-central-1.amazonaws.com www.google.nl blob: secure.adnxs.com bat.bing.com c.bing.com www.awin1.com www.facebook.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com col1.wiqhit.com cdn.widget.trengo.eu code.jquery.com cdnjs.cloudflare.com static.widget.trengo.eu www.mandad.nl s.codepen.io widget.prod.faslet.net www.clarity.ms connect.facebook.net bat.bing.com ct.beslist.nl www.dwin1.com analytics.tiktok.com js-agent.newrelic.com lantern.roeyecdn.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl jac-hensen.github.io fonts.googleapis.com use.fontawesome.com www.mandad.nl fonts.bunny.net www.jachensen.nl js-agent.newrelic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com region1.google-analytics.com api.widget.trengo.eu region1.analytics.google.com api.faslet.net www.google.com google.com ct.beslist.nl f.clarity.ms o.clarity.ms bat.bing.com analytics.tiktok.com bam.nr-data.net lantern.roeye.com hal9000.redintelligence.net col1.wiqhit.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.youtube.com/ *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.meetanshi.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.avada.io *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: *.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.kaltura.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.zdassets.com *.kaltura.com chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.googleapis.com *.zendesk.com *.zdassets.com *.signifyd.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com localhost:35729 yui.yahooapis.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-NrpHxaG_aLqptr4RFQIXvg'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-NrpHxaG_aLqptr4RFQIXvg'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self'; report-uri https://uk3hg0f8.uriports.com/reports/report 1 frame-ancestors 'none';object-src 'none';base-uri 'none';frame-src 'self' https://ct.pinterest.com https://cr.dm.ilmarinen.fi https://www.googletagmanager.com https://www.facebook.com https://www.google.com https://*.googlesyndication.com https://player.vimeo.com https://*.doubleclick.net https://*.surveypal.com https://www.youtube.com;default-src 'unsafe-eval' 'unsafe-inline' 'self' data: https: blob: 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://client.crisp.chat *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cloudflare.com *.trustpilot.com *.cdnfonts.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://images.unsplash.com https://image.crisp.chat *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com *.doubleclick.net *.googletagmanager.com d17lvj5xn8sco6.cloudfront.net *.facebook.com cwberry.s3-eu-west-1.amazonaws.com www.google.co.uk *.crisp.chat *.facebook.net *.trustpilot.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://client.crisp.chat *.stripe.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com www.xtento.com cdn.xtento.com *.crisp.chat unpkg.com *.cloudflare.com *.noibu.com *.facebook.net *.doubleclick.net *.jsdelivr.net *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com https://client.crisp.chat *.stripe.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com assets.braintreegateway.com *.trustpilot.com *.crisp.chat 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src *.doorvisualiser.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.stripe.com *.sagepay.com *.opayo.eu.elavon.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.trustpilot.com *.epostcode.com *.noibu.com *.doubleclick.net *.google-analytics.com *.crisp.chat *.facebook.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://388b1011-c31a-4e04-adf4-d061d9b5b59c.sansec.watch/; report-to report-endpoint; 1 worker-src https://www.google.com/recaptcha/api2/ https://www.smilemakers.com blob: 'self'; font-src fonts.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://web-modules-de-na1.niceincontact.com *.cloudflare.com *.bootstrapcdn.com *.gstatic.com *.fontawesome.com https://smilemakers.com https://smilemakerscanada.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com core.spreedly.com https://smilemakers.us19.list-manage.com 'self' 'unsafe-inline'; frame-ancestors *.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com core.spreedly.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://web-modules-de-na1.niceincontact.com https://smi.az1.qualtrics.com https://otc.az1.qualtrics.com *.google.com https://smilemakers.com https://bat.bing.com *.bing.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com *.gstatic.com https://px.ads.linkedin.com https://www.facebook.com https://www.google.co.in https://www.googletagmanager.com https://connect.facebook.net https://api.bluecore.app/api/ https://cdnjs.cloudflare.com https://www.smilemakers.com/media/ https://www.smilemakers.com/smk_inc/ *.cloudflare.com *.zopim.com *.qualtrics.com https://www.smilemakers.com https://smilemakerscanada.com https://bat.bing.com *.bing.com https://www.smilemakerscanada.com/static/ https://www.smilemakerscanada.com/media/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com www.apptrian.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com core.spreedly.com *.subscribepro.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com https://web-modules-de-na1.niceincontact.com https://snap.licdn.com https://cmp.osano.com https://www.smilemakers.com https://api.bluecore.com https://livechat-static-de-na1.niceincontact.com https://script.crazyegg.com https://cdn.quantummetric.com https://www.google-analytics.com https://connect.facebook.net https://bat.bing.com *.bing.com https://e.monetate.net https://se.monetate.net https://f.monetate.net https://dx.mountain.com https://px.mountain.com https://gs.mountain.com/gs https://core.spreedly.com/iframe/ https://s3.amazonaws.com https://www.datadoghq-browser-agent.com *.google.com https://static.cloudflareinsights.com *.crazyegg.com *.zdassets.com *.foresee.com *.qualtrics.com *.fontawesome.com https://js-agent.newrelic.com *.bluecore.com *.cloudflareinsights.com *.newrelic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.subscribepro.com tagmanager.google.com https://web-modules-de-na1.niceincontact.com https://fonts.googleapis.com/css https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://e.monetate.net https://script.crazyegg.com https://cdn-images.mailchimp.com *.googleapis.com *.monetate.net *.crazyegg.com *.foresee.com *.zdassets.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.zopim.com https://fonts.gstatic.com https://www.smilemakers.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com *.subscribepro.com core.spreedly.com https://www.google-analytics.com *.google.com https://app-de-na1.niceincontact.com https://web-modules-de-na1.niceincontact.com https://www.smilemakers.com https://analytics.google.com https://ingest.quantummetric.com https://www.google.com/recaptcha/api2/ https://channels-de-na1.niceincontact.com https://siteassets.bluecore.com https://px.ads.linkedin.com wss://chat-gw-de-na1.niceincontact.com https://location-de-na1.niceincontact.com https://cdnjs.cloudflare.com https://consent.api.osano.com https://stats.g.doubleclick.net/g/ https://100.20.58.101 https://34.215.155.61 https://44.238.122.172 https://35.85.84.151 https://35.160.46.251 https://44.228.85.26 *.cloudflare.com *.zopim.com wss://*.zopim.com *.crazyegg.com *.zdassets.com *.foresee.com *.qualtrics.com https://www.datadoghq-browser-agent.com https://bam.nr-data.net https://onsitestats.bluecore.com https://api.bluecore.app https://site.bluecore.com *.bluecore.com https://bat.bing.com *.bing.com https://cdn.quantummetric.com *.quantummetric.com *.cloudflareinsights.com *.newrelic.com https://cmp.osano.com https://www.facebook.com/privacy_sandbox https://digital-oauth-de-na1.niceincontact.com https://js-agent.newrelic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; form-action 'self'; default-src 'self'; connect-src 'self' data: https://stats.nederhost.nl/ https://zammad.nederhost.nl/ wss://zammad.nederhost.nl/; frame-ancestors 'none'; frame-src 'self'; img-src 'self' data:; report-to csp-endpoint; report-uri /_/report_csp_violation; script-src 'self' 'nonce-YIliWEflWdcrFLUz' 'unsafe-eval' https://stats.nederhost.nl/ https://cdn.matomo.cloud/stats.nederhost.nl/ https://zammad.nederhost.nl/; style-src 'self' data: 'nonce-YIliWEflWdcrFLUz' https://zammad.nederhost.nl/; style-src-attr 'unsafe-inline'; 1 default-src 'self'; frame-src 'self' *.schellman.com *.hubspot.com *.hs-sites.com *.hubspot.net *.hsforms.com *.hsforms.net *.wistia.net platform.twitter.com insight.adsrvr.org play.hubspotvideo.com 216294.hs-sites.com match.adsrvr.org googletagmanager.com; frame-ancestors 'self'; script-src 'self' 'unsafe-hashes' schellman.com *.schellman.com *.clickagy.com *.cookielaw.org *.hsforms.net *.hs-scripts.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hubspot.com *.usemessages.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.com *.hubspotfeedback.com *.googleapis.com *.wistia.com *.wistia.net *.zoominfo.com *.fs1.hubspotusercontent-na1.net *.cloudfront.net *.sentry-cdn.com *.googletagmanager.com googletagmanager.com www.google-analytics.com jotform.com jotform.pro cookie-cdn.cookiepro.com cdnjs.cloudflare.com js.adsrvr.org js.usemessages.com js.zi-scripts.com js.hscta.net snap.licdn.com www.clarity.ms px.ads.linkedin.com static.hsappstatic.net feedback.hubapi.com 'strict-dynamic' 'nonce-rHgo1F+cVh8PSqX6j9Hbnw=='; style-src 'self' *.schellman.com *.fs1.hubspotusercontent-na1.net *.googletagmanager.com fonts.googleapis.com tagmanager.google.com cdnjs.cloudflare.com use.fontawesome.com fonts.googleapis.com cdn2.hubspot.net static.hsappstatic.net blob: 'unsafe-inline'; img-src 'self' *.schellman.com *.hsforms.net *.clickagy.com *.wistia.com *.wistia.net *.hubspot.net *.hubspot.com *.hsforms.com *.onetrust.com *.clarity.ms *.linkedin.com linkedin.com px.ads.linkedin.com googletagmanager.com *.googletagmanager.com *.google-analytics.com cdn.cookielaw.org cookie-cdn.cookiepro.com s3.amazonaws.com/fortyten-orlando js.hscta.net static.hsappstatic.net data:; connect-src 'self' schellman.com *.schellman.com *.hsforms.com *.hubspot.com *.litix.io *.hubapi.com *.hs-banner.com *.hscollectedforms.net *.onetrust.com *.clarity.ms *.wistia.com *.wistia.net *.clickagy.com *.zoominfo.com *.workato.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com cdnjs.cloudflare.com cdn.cookielaw.org cookie-cdn.cookiepro.com google-analytics.com js.zi-scripts.com px.ads.linkedin.com js.hscta.net insight.adsrvr.org; worker-src blob:; font-src 'self' *.schellman.com fonts.googleapis.com fonts.gstatic.com *.wistia.com *.wistia.net use.fontawesome.com cdnjs.cloudflare.com data:; object-src 'none'; media-src 'self' blob:; form-action 'self'; base-uri schellman.com 1 font-src fonts.gstatic.com fonts.googleapis.com *.fontawesome.com data: *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com *.cookiebot.com *.trustpilot.com *.hotjar.com www.youtube.com www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bluebirdday.io *.misterb.com *.misterjock.com *.google.com *.google.nl www.google.nl www.facebook.com *.cloudfront.net *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.googletagmanager.com tagmanager.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com *.fontawesome.com *.cookiebot.com *.trustpilot.com *.doubleclick.net *.hotjar.com connect.facebook.net www.facebook.com secure.authorize.net test.authorize.net *.vimeo.com *.sharethis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com v2.zopim.com *.cloudflareinsights.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com tagmanager.google.com unsafe-inline assets.braintreegateway.com *.klaviyo.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com *.cookiebot.com *.hotjar.com *.klaviyo.com *.doubleclick.net *.googleapis.com/ stats.g.doubleclick.net *.google-analytics.com *.hotjar.io *.googlesyndication.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de fonts.gstatic.com *.twitter.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com https://www.theirishjewelrycompany.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.gstatic.com *.google.com *.google.co.in *.google.com.ua https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net *.youtube.com https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com stats.g.doubleclick.net/ *.twitter.com *.google.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com *.youtube.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.google.co.in *.facebook.com stats.g.doubleclick.net/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' use.typekit.net www.williamashley.com www.google.com *.google-analytics.com www.googletagmanager.com connect.facebook.net *.pinimg.com *.livechatinc.com www.googleadservices.com googleads.g.doubleclick.net www.gstatic.com assets.pinterest.com *.cloudmaestro.com maps.googleapis.com tpc.googlesyndication.com static.zdassets.com; report-uri /.webscale/csp-report 1 default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: *.googlesyndication.com *.doubleclick.net *.facebook.com www.google-analytics.com vc.hotjar.io *.facebook.net *.hotjar.com *.hotjar.io tag.perfectaudience.com pixel-geo.prfct.co ekr.zdassets.com *.zendesk.com www.google.com wss://widget-mediator.zopim.com shielded.co.nz ampcid.google.co.nz fonts.gstatic.com v2assets.zopim.io www.googletagmanager.com koi-3qn7bghifk.marketingautomation.services static.zdassets.com secure.adnxs.com adservice.google.com analytics.google.com www.google.co.nz cdnjs.cloudflare.com ampcid.google.com www.google.com.au www.googletagservices.com; form-action *.facebook.com; frame-ancestors 'self' ; 1 default-src ; script-src 'self' 'unsafe-inline' 'unsafe-eval' alfainsurance.com www.alfainsurance.com *.google-analytics.com maps.googleapis.com *.googleapis.com *.googletagmanager.com https://unpkg.com/vue@3.5.12/dist/vue.esm-browser.prod.js https://unpkg.com/vue@3.5.12/dist/vue.esm-browser.js *.cloudflare.com *.godaddy.com *.oktacdn.com *.amazon-adsystem.com *.facebook.net *.googleadservices.com *.google.com *.gstatic.com *.tvsquared.com *.oraclecloud.com *.custhelp.com *.rightnowtech.com; style-src 'self' 'unsafe-inline' alfainsurance.com www.alfainsurance.com fonts.googleapis.com *.oktacdn.com *.cloudflare.com *.alfainsurance.com *.oktacdn.com alfamutual--tst.custhelp.com; img-src 'self' data: alfainsurance.com www.alfainsurance.com *.google-analytics.com *.godaddy.com *.mdhv.io *.adxcel-ec2.com *.facebook.com *.tvsquared.com *.doubleclick.net *.google.com *.googletagmanager.com *.analyticowl.com *.arttrk.com *.oktacdn.com *.oraclecloud.com *.custhelp.com; font-src 'self' alfainsurance.com www.alfainsurance.com fonts.gstatic.com *.oktacdn.com; connect-src 'self' http://localhost:* ws://localhost:* localhost alfainsurance.com www.alfainsurance.com www.google.com *.google.com maps.googleapis.com *.oraclecloud.com *.amazon-adsystem.com *.alfainsurance.com *.paa-reporting-advertising.amazon *.doubleclick.net *.google-analytics.com *.custhelp.com *.googletagmanager.com www.googletagmanager.com googletagmanager.com; frame-src 'self' alfainsurance.com www.alfainsurance.com *.youtube.com *.googletagmanager.com *.doubleclick.net *.where2getit.com *.custhelp.com *.google.com;object-src 'none';base-uri 'self';form-action 'self' *.alfainsurance.com alfainsurance.com www.alfainsurance.com;frame-ancestors 'self' alfainsurance.com www.alfainsurance.com;report-uri /csp-violation-report;upgrade-insecure-requests; block-all-mixed-content; 1 font-src fonts.gstatic.com use.typekit.net fonts.yieldify-production.com staticw2.yotpo.com p.yotpo.com *.audioeye.com bat.bing.com *.fontawesome.com *.alothemes.com *.magepow.com https://fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com td.doubleclick.net *.audioeye.com platform.twitter.com www.google.com p.yotpo.com bat.bing.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://s7.addthis.com https://platform.twitter.com https://bid.g.doubleclick.net *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.google.com.br www.facebook.com bat.bing.com p.yotpo.com assets-v2.yieldify.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.alothemes.com *.magepow.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://bat.bing.com https://www.google.com https://www.google.com.ar *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.attn.tv events.attentivemobile.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.googleoptimize.com cdn.attn.tv static.klaviyo.com bat.bing.com container.pepperjam.com s3-us-west-2.amazonaws.com connect.facebook.net static-tracking.klaviyo.com staticw2.yotpo.com td.yieldify.com b-code.liadm.com wisepops.net unpkg.com custom.yieldify.com js-agent.newrelic.com *.audioeye.com cdn.wisepops.com platform.twitter.com www.google.com www.gstatic.com s7.addthis.com p.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.alothemes.com *.magepow.com https://connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.clarity.ms https://s7.addthis.com https://bat.bing.com https://platform.twitter.com https://z.moatads.com https://loader.wisepops.com https://v1.addthisedge.com https://googleads.g.doubleclick.net https://widgets.pinterest.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com use.typekit.net p.typekit.net staticw2.yotpo.com *.audioeye.com www.w3schools.com p.yotpo.com https://static.klaviyo.com *.fontawesome.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.attn.tv events.attentivemobile.com fast.a.klaviyo.com static-forms.klaviyo.com td.yieldify.com a.klaviyo.com fonts.googleapis.com rp4.liadm.com v2.dc.yieldify.com wisepops.net whitemountainfootwear.attn.tv bam.nr-data.net gateway.yieldify-production.com activity.wisepops.com staticw2.yotpo.com syndication.twitter.com p.yotpo.com *.execute-api.us-west-2.amazonaws.com *.liadm.com tracking.wisepops.com bat.bing.com *.audioeye.com alocdn.com a.usbrowserspeed.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://popup.wisepops.com https://d.clarity.ms https://activity.wisepops.com https://stats.g.doubleclick.net https://api-public.addthis.com *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com bam.nr-data.net www.google.com events.attentivemobile.com google.com commerce.adobedc.net *.audioeye.com www.paypal.com p.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.authorize.net cdn.userway.org *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.userway.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.authorize.net cdn.userway.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com cdn.userway.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com widget.thuiswinkel-cdn.org data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com consent.cookiebot.com *.freshchat.com consentcdn.cookiebot.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com imgsct.cookiebot.com *.google.com.ua *.google.com.nl api.taggrs.io widget.thuiswinkel-cdn.org px.ads.linkedin.com bat.bing.com sst.officecentre.nl https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com consent.cookiebot.com static.zdassets.com wss://widget-mediator.zopim.com consentcdn.cookiebot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org eu.fw-cdn.com *.freshchat.com bat.bing.com sst.officecentre.nl https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.typekit.net *.freshchat.com static-tracking.klaviyo.com widget.thuiswinkel-cdn.org https://static.klaviyo.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com ekr.zdassets.com wss://widget-mediator.zopim.com consentcdn.cookiebot.com widget.trustpilot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org app-euc.freshmarketer.com widgetcontent.thuiswinkel-cdn.org sst.officecentre.nl px.ads.linkedin.com bat.bing.com ws://127.0.0.1:35729/livereload https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://use.typekit.net data: *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com https://www.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com data: 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.affirm.com *.affirm.ca *.certcapture.com https://dpm.demdex.net data: *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com https://gateway.woodmizer.com https://bid.g.doubleclick.net *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.payu.com merch-prod.snd.payu.com *.googleapis.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net https://cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io https://amcglobal.sc.omtrdc.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.affirm.com *.affirm.ca *.certcapture.com https://res.cloudinary.com https://black.bird.eu http://dpm.demdex.net http://amc.demdex.net https://www.googletagmanager.com https://www.google.com.br https://*.google.com *.cloudflare.com https://*.gstatic.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com https://wcs.naver.com *.trackedlink.net https://woodmizer.ca px.ads.linkedin.com *.woodmizer.com *.fontawesome.com *.trackedweb.net *.yotpo.com beta.woodmizer.com https://uploads.commoninja.com https://insight.adsrvr.org https://bat.bing.com https://www.google.com.pk *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com maps.gstatic.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://*.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.affirm.com *.affirm.ca *.certcapture.com https://js-agent.newrelic.com https://bam.nr-data.net https://assets.adobedtm.com https://www.googletagmanager.com *.google-tag-manager.com *.google-analystics-universal.com https://googleads.g.doubleclick.net data: https://*.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com https://www.google-analytics.com https://*.twimg.com https://*.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net https://www.paypalobjects.com https://www.paypal.com https://chimpstatic.com *.youtube.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com https://wcs.naver.com https://wcs.naver.net https://r2-t.trackedlink.net https://r2.trackedweb.net http://static.trackedweb.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://px.ads.linkedin.com snap.licdn.com px.ads.linkedin.com *.woodmizer.com graph.facebook.com *.cardinalcommerce.com *.authorize.net js.braintreegateway.com *.paypal.com *.googletagmanager.com https://*.google.com *.cloudflare.com *.yotpo.com *.cloudfront.net *.commoninja.com *.bing.com *.hotjar.com https://apps.usw2.pure.cloud https://analytics.google.com https://www.sandbox.paypal.com https://t.paypal.com https://s.ytimg.com https://*.vimeocdn.com https://*.twitter.com https://*.facebook.com https://*.hotjar.com https://js.braintreegateway.com https://assets.braintreegateway.com *.klarna.com https://*.klarnacdn.net https://*.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://*.dotdigital-pages.com https://webchat.dotdigital.com https://*.commoninja.com https://*.bootstrapcdn.com https://*.authorize.net https://*.bing.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://challenges.cloudflare.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com *.googleapis.com www.xtento.com cdn.xtento.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.cloudinary.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net https://static.klaviyo.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com px.ads.linkedin.com *.woodmizer.com https://res.cloudinary.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.affirm.com *.affirm.ca *.certcapture.com https://bam.nr-data.net https://dpm.demdex.net https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com http://static.trackedweb.net https://r2.trackedweb.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com px.ads.linkedin.com *.woodmizer.com *.adobedtm.com https://*.google.com *.yotpo.com https://cdn.commoninja.com https://api-cdn.usw2.pure.cloud https://www.commoninja.com https://*.hotjar.io *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com secure.payu.com merch-prod.snd.payu.com *.googleapis.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com www.googletagmanager.com *.veritas.at *.consentmanager.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://www.magezon.com https://*.consentmanager.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://rum.hlx.page s7.addthis.com https://*.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu ekr.zdassets.com/ https://identity.veritas.at/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.commerce-connector.com *.typekit.net */csp/report/uri/ *.hotjar.com *.hotjar.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.wahl.com *.userway.org *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.wahl.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com *.wahl.com; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.adsrvr.org *.hotjar.com *.hotjar.io */csp/report/uri/ *.hubspot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wahl.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app fonts.googleapis.com display.ugc.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com *.klarnacdn.net *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.powerreviews.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.bootstrapcdn.com *.wahlclipper.com *.jsdelivr.net *.postcodeanywhere.co.uk *.commerce-connector.com *.typekit.net */csp/report/uri/ unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com www.gstatic.com cdn.weglot.com *.wahl.com *.userway.org 'self' 'unsafe-inline'; object-src *.wahl.com 'self' 'unsafe-inline'; media-src *.adobe.com *.wahl.com 'self' 'unsafe-inline'; manifest-src *.wahl.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com *.amazonaws.com google.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com stats.g.doubleclick.net ct.pinterest.com *.google-analytics.com *.whatcounts.com siteanalytics.whatcounts.com https://siteanalytics.whatcounts.com *.amazonaws.com/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.powerreviews.com *.nr-data.net *.wahlclipper.com *.syndigo.com *.postcodeanywhere.co.uk wss://ws41.hotjar.com *.commerce-connector.com */csp/report/uri/ wss://*.hotjar.com *.hotjar.com *.hotjar.io *.hubspot.com *.hubapi.com *.hs-banner.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.link.com x.clarity.ms cdn.cookielaw.org forms.hscollectedforms.net geolocation.onetrust.com api.userway.org cdn77.api.userway.org cdn.userway.org api.weglot.com cdn.weglot.com https://cdn-api-weglot.com *.wahl.com *.hsforms.net *.hsforms.com *.clarity.ms *.pcapredict.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; base-uri *.wahl.com 'self' 'unsafe-inline'; script-src https://pxl.jivox.com https://secure.adnxs.com https://apps.bazaarvoice.com/ cdn.weglot.com 0409890c10.translations.weglot.io assets.adobedtm.com *.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com 'self' 'unsafe-inline' sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com static.cloudflareinsights.com cdnjs.cloudflare.com google.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com *.powerreviews.com *.newrelic.com js-agent.newrelic.com *.googletagmanager.com https://www.googletagmanager.com/gtm.js bat.bing.com *.google-analytics.com *.googleoptimize.com https://www.googleoptimize.com/optimize.js *.trustedsite.com *.cloudflare.com *.twitter.com *.fontawesome.com *.nr-data.net *.wahlclipper.com *.googleapis.com *.jsdelivr.net *.bluesnap.com *.webcollage.net *.syndigo.com *.adsrvr.org *.hotjar.com *.hotjar.io *.pcapredict.com *.postcodeanywhere.co.uk *.commerce-connector.com *.amazonaws.com/ */csp/report/uri/ *.redditstatic.com *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.usemessages.com *.hs-analytics.net *.hsadspixel.net *.hsleadflows.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com www.clarity.ms cdn.cookielaw.org js.hubspot.com cdn.userway.org svht.tradedoubler.com swrap.tradedoubler.com *.wahl.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src static.hsappstatic.net https://ad.doubleclick.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobedtm.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.google.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.essentialaccessibility.com *.wahlanimal.com s.ytimg.com *.google.com.mx *.google-analytics.com ct.pinterest.com bat.bing.com *.google.co.in *.cloudflare.com *.wahlclipper.com *.powerreviews.com *.googletagmanager.com *.cloudfront.net *.webcollage.net *.syndigo.cloud *.postcodeanywhere.co.uk */csp/report/uri/ *.reddit.com *.hsforms.com *.hubspot.com *.google.com.in *.payments-amazon.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com c.clarity.ms cdn.cookielaw.org cdn.userway.org *.wahl.com *.magecomp.com *.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; default-src https://de.wahl.com https://fr.wahl.com https://nl.wahl.com https://eu.wahl.com https://es.wahl.com https://jp.mcprod.wahl.com *.wahl.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src www.paypalobjects.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com portal.bulkgate.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com portal.bulkgate.com services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com portal.bulkgate.com https://www.googletagmanager.com https://widgets.onlinesizing.bike *.resurs.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com portal.bulkgate.com https://www.google.fi https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://px.ads.linkedin.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.facebook.com https://maps.googleapis.com https://maps.gstatic.com flagpedia.net cdn2.hubspot.net resources.paytrail.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ portal.bulkgate.com *.gstatic.com https://analytics.tiktok.com https://tiktok.com https://embed.trustmary.com https://d3qhsf9lmfcusu.cloudfront.net https://assets.zendesk.com https://static.zdassets.com https://www.clarity.ms https://scripts.clarity.ms https://e.clarity.ms https://snap.licdn.com https://widgets.onlinesizing.bike https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.googletagmanager.com *.facebook.net *.fontawesome.com *.googleapis.com https://maps.googleapis.com https://cdnjs.cloudflare.com maps.googleapis.com services.paytrail.com *.resurs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://www.googletagmanager.com tagmanager.google.com *.googleapis.com portal.bulkgate.com *.gstatic.com *.fontawesome.com https://static.klaviyo.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com portal.bulkgate.com *.gstatic.com https://doubleclick.net https://stats.g.doubleclick.net https://www.doubleclick.net https://google.com https://www.google.com https://pagead2.googlesyndication.com https://www.facebook.com https://capig.stape.de https://d.clarity.ms https://embed.trustmary.io https://ekr.zdassets.com wss://widget-mediator.zopim.com https://electrobikehelp.zendesk.com https://e.clarity.ms https://px.ads.linkedin.com https://api.onlinesizing.bike https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io https://maps.googleapis.com www.gstatic.com maps.googleapis.com *.paytrail.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bglobale.com *.global-e.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.cloudflare.com fonts.googleapis.com 'unsafe-inline' data: static.paddockspares.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.bglobale.com *.global-e.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * widget.trustpilot.com lpcdn.lpsnmedia.net *.paypalobjects.com secure.livechatinc.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.bglobale.com *.global-e.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ services.postcodeanywhere.co.uk magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.cloudflare.com *.mdoq.io *.ibottles.co.uk *.google.com *.google.co.uk media.paddockspares.com static.paddockspares.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.bglobale.com *.global-e.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.liveperson.net *.lpsnmedia.net *.livechatinc.com bam.nr-data.net static.paddockspares.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.bglobale.com *.global-e.com https://static.klaviyo.com api.addressy.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com tagmanager.google.com fonts.google.com *.cloudflare.com *.bootstrapcdn.com static.paddockspares.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.cloudflare.com stats.g.doubleclick.net bam.nr-data.net *.livechatinc.com static.paddockspares.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://zero1.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' airtools-loomis.prod-mid-euw3.investis.com captcha.loomis.com cdn.cookielaw.org cdnjs.cloudflare.com code.jquery.com irs.tools.investis.com www.googletagmanager.com; script-src 'self' 'nonce-5wYwmJ3v3cj8yjI4uVSFLbqlacA=' 'sha384-11cX+Naw18bPoIYxEkQI+DltxbxL5/5L0krcoW8ObmMGsC3OiLBkmZjXSWPrrjYh' captcha.loomis.com *.googleapis.com cdn.cookielaw.org cdnjs.cloudflare.com code.jquery.com loomis.jobbase.io loomis.onlyfy.jobs www.googletagmanager.com www.google.com www.gstatic.com googleads.g.doubleclick.net pagead2.googlesyndication.com connect.facebook.net snippet.capybara.lmc.cz www.googleadservices.com loomis-dk.containers.piwik.pro; style-src 'self' 'unsafe-inline' captcha.loomis.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googleapis.com snippet.capybara.lmc.cz; img-src 'self' data: captcha.loomis.com cdn.cookielaw.org cdn-endpoint-sitecorecdn-es-01.azureedge.net px.ads.linkedin.com www.facebook.com www.googleadservices.com www.googletagmanager.com img.icons8.com media.licdn.com 1.bp.blogspot.com cdn.theorg.com googleads.g.doubleclick.net maps.gstatic.com *.googleapis.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; connect-src 'self' 'unsafe-inline' data: airtools-loomis.prod-mid-euw3.investis.com *.google.com google.com px.ads.linkedin.com *.google-analytics.com captcha.loomis.com cdn.cookielaw.org privacyportal-de.onetrust.com geolocation.onetrust.com api.capybara.lmc.cz www.googleadservices.com www.google.se www.facebook.com *.googleapis.com; font-src 'self' 'unsafe-inline' fonts.gstatic.com snippet.capybara.lmc.cz; frame-src 'self' airtools-loomis.prod-mid-euw3.investis.com irs.tools.investis.com loomis.onlyfy.jobs td.doubleclick.net www.youtube.com www.youtube-nocookie.com otp.investis.com otp.tools.investis.com view.genially.com *.google.com *.googletagmanager.com google.com googletagmanager.com publish.ne.cision.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; 1 font-src www.paypalobjects.com fonts.googleapis.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com 'self' data: 'unsafe-inline' data: *.jsdelivr.net *.jotfor.ms *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.jotform.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.paypal.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cookiebot.com *.jotform.io *.jotform.com *.doubleclick.net *.pinterest.com *.cxpress.io *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com log.pinterest.com ssl.google-analytics.com maps.googleapis.com maps.gstatic.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com blob: 'unsafe-inline' data: *.google.com *.google.pt *.facebook.com *.www.google.com *.jotfor.ms *.jotform.com *.googleapis.com *.avada.io *.weglot.com placehold.jp *.hubspot.com *.hsforms.com *.userguiding.com *.cookiebot.com *.clarity.ms *.bing.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.consentmanager.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.gstatic.com t.trackedlink.net assets.pinterest.com maps.googleapis.com ssl.google-analytics.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.fontawesome.com *.cookiebot.com *.googletagmanager.com *.facebook.net *.cloudflareinsights.com *.hipay.com *.hipay-tpp.com *.iesnare.com *.cloudflare.com *.jotform.com *.jotfor.ms *.cookiefirst.com *.jsdelivr.net *.hotjar.com *.googleapis.com *.instagram.com *.twitter.com *.weglot.com *.hs-scripts.com *.usemessages.com *.hs-analytics.net *.hs-banner.com *.hscollectedforms.net *.userguiding.com/ *.tiktok.com *.buckaroo.nl *.pinimg.com *.clarity.ms *.livechatinc.com *.pinterest.com *.bing.com *.consentmanager.net *.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.freshchat.com *.typekit.net *.jsdelivr.net *.hipay.com *.gstatic.com *.jotfor.ms *.weglot.com *.buckaroo.nl *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.iesnare.com 'unsafe-inline' data: 'self' data: data: *.googleadservices.com *.google-analytics.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com log.pinterest.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.link.com *.amazon.com *.google-analytics.com *.doubleclick.net *.cookiebot.com *.hipay.com wss://mpsnare.iesnare.com/star *.analytics.google.com *.cookiefirst.com *.hotjar.com *.googleapis.com *.weglot.com cdn-api-weglot.com *.klaviyo.com *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.userguiding.com *.tiktok.com *.clarity.ms *.pinterest.com *.bing.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://bestpractice.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'report-sample' 'self' https://script.hotjar.com/modules.855de5fca5328fca5328f4d913a.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.7/umd/popper.min.js https://code.jquery.com/jquery-3.3.1.slim.min.js https://form-cdn.pardot.com/js/piUtils.js https://go.leonardoworldwide.com/analytics https://js.driftt.com https://maps.googleapis.com/maps-api-v3/api/js/47/7a/infowindow.js https://pi.pardot.com/analytics https://script.hotjar.com/modules.b840cee57f816b17fc8e.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js https://static.hotjar.com/c/hotjar-1643127.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js https://js.driftt.com/include/1644433200000/mpc4rt8urpbb.js https://script.hotjar.com/modules.acfce7141cd3503e3221.js https://p.adsymptotic.com https://www.leonardoworldwide.com/ https://pi.pardot.com/pd.js https://js.driftt.com/include/1644433800000/mpc4rt8urpbb.js;style-src 'unsafe-inline' 'report-sample' 'self' http: https: fonts.googleapis.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://pro.fontawesome.com;object-src 'none';base-uri 'self'; connect-src 'unsafe-inline' 'unsafe-eval' 'self' https://in.hotjar.com https://maps.googleapis.com https://stats.g.doubleclick.net; font-src 'self' data: http: https: fonts.googleapis.com themes.googleusercontent.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://pro.fontawesome.com;frame-src 'self' https://go.leonardoworldwide.com https://js.driftt.com https://vars.hotjar.com https://www.youtube.com; img-src 'self' data: http: https: *.gravatar.com http://www.leonardoworldwide.com https://i.ytimg.com https://leonardo.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.google.ca https://www.google.com;manifest-src https://p.adsymptotic.com https://www.leonardoworldwide.com/ 'self'; media-src 'self';report-uri https://61fc42604ac1af58c416405b.endpoint.csper.io/?v=0;worker-src 'self' 'unsafe-inline' 'unsafe-eval' 'none'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com https://www.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com cash-f.squarecdn.com https://cdn.riverty.design/ data: https://fonts.gstatic.com https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com * uc8.tv 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube-nocookie.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com * uc8.tv https://documents.riverty.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com *.cloudflare.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com * https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ imgsct.cookiebot.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net https://maps.gstatic.com http://maps.gstatic.com https://maps.googleapis.com http://maps.googleapis.com https://www.google-analytics.com https://www.google.com https://www.google.nl https://www.google.be https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl https://cdn.riverty.design http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com https://www.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.adyen.com pay.google.com *.payments-amazon.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ consent.cookiebot.com blob: https://www.google.com https://ssl.google-analytics.com https://maps.googleapis.com https://ecookie.nl https://www.ecookie.nl https://www.googletagmanager.com https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl *.convertexperiments.com *.voyado.com *.faslet.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.cash.app https://fonts.googleapis.com http://fonts.googleapis.com https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://flirtcreativity.com https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com vimeo.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com * uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ https://maps.googleapis.com https://stats.g.doubleclick.net https://www.google-analytics.com/ https://www.open32.nl https://test.open32.nl https://acceptance.open32.nl https://www.silvercreek.nl https://test.silvercreek.nl https://acceptance.silvercreek.nl https://admin.b32groep.nl https://test.b32groep.nl https://acceptance.b32groep.nl *.voyado.com *.faslet.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/; report-to report-endpoint; 1 font-src *.gstatic.com *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.stripe.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.useinsider.com hit.api.useinsider.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.stripe.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.useinsider.com hit.api.useinsider.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com *.trustpilot.com *.addtoany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com http://dpm.demdex.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pixriot.com *.storeimaging.com *.facebook.com *.reddit.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.avada.io *.shopify.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.pixriot.com *.storeimaging.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action 'self'; report-to csp-report; report-uri https://csp-report-receiver.atoka.io/report/atoka-production/ 1 default-src 'self' https:; connect-src *; font-src *; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.za/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net https://geowidget.easypack24.net 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: www.facebook.com/ bat.bing.net region1.analytics.google.com www.google.pl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com mail.desportivo.pl recostream.com trustmate.io 'sha256-gP1oNVTXBLfgTvNe/Fqkv6tcF4UVivtUXBKTYUUjkmc=' 'sha256-xrzx3VAUiE9YjZB6FTwbudERC18Hn8TWBp/5cZ5mu4Q=' 'sha256-QqMxYirdvmGWDghmc28HatqqDMWBMZF4Bo05rxgzHA4=' 'sha256-M1gyCA1OxlRXKeam1PtXmXNrwxUiPS2no8eJafmPHcw=' 'sha256-VauVwPyzKQJVB4JO0GY2KyPY7+3Ms6SIioUcusfJKdw=' 'sha256-ftxLHMNQKDsafHI5+QkFdcTvZj3AKuTMgt+LdIR9muc=' 'sha256-9hYTzaA9DDOQTiC1QkHH2mwKOp/n6xeB7aNM4KNAbK4=' 'sha256-sFjNEEgXewbvYtfdtF0q220nc3MRABC/ee3WKnw7cJo=' 'sha256-wgKgZXfnlNUfpqsC0ftJiX13R1Ypa5fbk64p7Q3jX3Y=' 'sha256-65DEwAH4V2XNW7nTnVZxmS/4cNFkWPXrtMLKVB6CXlg=' 'sha256-Gq0ymyi115HXafhBJHpN6BpOMqu/OsnGFQtTfad1soc=' 'sha256-ndJGwLDQahNctVNA6j6wqNGGNk3v5Ar2YX0PqXcUlyU=' 'sha256-07Pd3rfUurk1QYw9viTNB1wyxLuYRII41GW5cNzPIuQ=' 'sha256-l1dZUePoutyb8m22eKsbL+Ak2Ppw02qEm3ltY3E61BE=' an.gr-wcon.com us-an.gr-cdn.com 'sha256-R3ElzeGsi4VM1mSrEGi52r9WCpo6Hj1lmJVCcWIxa3g=' 'sha256-FZo0+9k2Upqwve84C5aShQkutPerAOMMlHWxdSbRFSw=' connect.facebook.net bat.bing.com 'sha256-H30t1+h5cSjM5hvPb2jlOZpTe8pxaMu9ES2nZkhkZlc=' 'sha256-+R/CMLea10rdFcdJCRvDjf9kPFvf88n37QVjmYMkWbo=' 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com trustmate.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.klarnaservices.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.packeta.com stream.cloud.witbee.com j.clarity.ms google.pl *.analytics.google.com consentcdn.cookiebot.com googleads.g.doubleclick.net static.payu.com *.facebook.net *.facebook.com app2.recostream.com ga2.getresponse.com/ bam.nr-data.net clk.leadexpert.pl www.google.com pixel.wp.pl popups1-show.getresponse.com ts.getresponse.pl popups1-s.getresponse.com pagead2.googlesyndication.com metrics.desportivo.pl metrics.desportivo.cz metrics.desportivo.de *.desportivo.sk *.desportivo.ro *.bing.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://p.typekit.net https://use.typekit.net; style-src-elem 'self' 'unsafe-inline' https://p.typekit.net https://use.typekit.net; script-src 'self' 'unsafe-inline'; font-src 'self' https://www.bayreuther-festspiele.de https://use.typekit.net; img-src 'self' data:; worker-src blob:; report-uri https://csp-rep.tmt.de/csp-report; report-to csp-endpoint 1 font-src 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' syndication.twitter.com; script-src js.trentino.com 'unsafe-inline' 'unsafe-eval' player.peer.tv stats.peer.biz platform.twitter.com apis.google.com; connect-src 'self' stats.peer.biz; img-src 'self' data: images2.trentino.com css.trentino.com www.hotel-guide.it player.peer.tv stats.peer.biz carto.peer.biz www.gravatar.com syndication.twitter.com api.trustyou.com; style-src 'self' 'unsafe-inline' css.trentino.com js.trentino.com; font-src css.trentino.com; frame-src 'self' player.peer.tv www.facebook.com platform.twitter.com apis.google.com accounts.google.com www.youtube.com; child-src 'self' player.peer.tv www.facebook.com platform.twitter.com apis.google.com accounts.google.com www.youtube.com; report-uri https://csp-report.peer.biz/reportOnly/index 1 base-uri 'self'; connect-src 'self' translate.googleapis.com google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com myccpay.com *.myccpay.com paynearme.com *.paynearme.com; default-src 'self'; font-src 'self' data: https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://use.typekit.net https://croissant-services-data-public-assets-us-east-2-production.s3.us-east-2.amazonaws.com gstatic.com *.gstatic.com; form-action 'self' https://translate.googleapis.com https://www.creditviewdashboard.com https://creditviewsv-test.ctf.tuint.com; frame-src 'self' https://www.paynearme-sandbox.com https://www.paynearme.com; img-src 'self' data: https://analytics.twitter.com https://bat.bing.com https://sp.analytics.yahoo.com https://t.co https://images.totalcardinc.com https://images.staging.totalcardinc.com https://images.dev.totalcardinc.com https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com https://translate.google.com https://fonts.gstatic.com https://api.fillr.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com myccpay.com *.myccpay.com paynearme.com *.paynearme.com pure.cloud *.pure.cloud secured-pixel.com *.secured-pixel.com totalcardinc.com *.totalcardinc.com; style-src 'self' https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://www.paynearme-sandbox.com https://www.paynearme.com https://fonts.googleapis.com 'sha256-7VXlcg/uSZugHSa6UtIG2/44ju460LiO4M0CyQfraX8='; worker-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=QjseK2Ds_.gY6TkBckwvnOIoRP2DJZqV0MQM4XVrgj4-1765938007.4070833-1.0.1.1-YcehprvFim1uzicdeSW7oGkyEORzx17Hv3ewJS8h6vXd8zYYRNQd_8QvTAk7zZgPjPa61q.3LJ2tMV9Q8A5U.Geow6vTUd8RH5MXZpWVrpKw9pGMWQJzJkg17cJ7kNE_53Zsddg7hPA6NospvlPvtrGb6wMuY74WYA2ZP2HxJM0plPpdJ9Pu6jepuBUElYFT; report-to cf-xlejxlouylczittm 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.livechatinc.com fonts.mailerlite.com fonts.googleapis.com *.icomoon.io *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 1merchantacsstag.cardinalcommerce.com payments.securetrading.net *.securetrading.net *.trustpayments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.weltpixel.com *.livechatinc.com *.securetrading.net *.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com *.secure.checkout.visa.com thm.visa.com *.mastercard.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk magefan.com cm.magefan.com *.iceheadshop.co.uk *.livechat-files.com *.mlcdn.com *.mailerlite.com *.google.hr *.google.co.uk *.google.co.th *.google.com *.convertcart.com *.facebook.com *.disqus.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com gstatic.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com unpkg.com *.reviews.io *.reviews.co.uk *.livechatinc.com *.convertcart.com *.facebook.net *.taboola.com *.disqus.com https://getaddress.io webservices.securetrading.net cdn.eu.trustpayments.com *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com *.cardinalcommerce.com *.mastercard.com *.hsforms.net *.hsforms.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk assets.mlcdn.com *.icomoon.io *.mailerlite.com data: *.fontawesome.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.iceheadshop.co.uk *.convertcart.com *.livechatinc.com *.fixer.io *.doubleclick.net *.taboola.com https://api.getaddress.io o402164.ingest.sentry.io google.com/pay t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' https://www.google-analytics.com; style-src 'self'; script-src 'self' https://www.google-analytics.com https://ssl.google-analytics.com; connect-src: 'self' https://www.google-analytics.com; report-uri https://www.net-ing.com/csp/; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com maxcdn.bootstrapcdn.com font.static.useinsider.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * www.facebook.com https://plumrocket.com *.amazon.co.uk *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.facebook.com www.youtube.com s7.addthis.com c.paypal.com assets.braintreegateway.com tst.kaptcha.com templespa.api.useinsider.com https://plumrocket.com *.paypalobjects.com *.criteo.com *.criteo.net td.doubleclick.net block.opendns.com e.issuu.com *.googletagmanager.com *.js.stripe.com hooks.stripe.com *.yotpo.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com * www.facebook.com *.templespa.com b.stats.paypal.com c.paypal.com dub.stats.paypal.com services.postcodeanywhere.co.uk stats.g.doubleclick.net bat.bing.com consent.linksynergy.com www.google.co.uk ut.ra.linksynergy.com nypi.dc-storm.com consent.nxtck.com consent.mediaforge.com consent.jrs5.com consent.dc-storm.com tcrnbekl.cdn.imgeng.in px.ads.linkedin.com ut.rd.linksynergy.com www.linkedin.com *.useinsider.com cx.atdmt.com https://images.unsplash.com *.disqus.com https://img.youtube.com cdn.cookielaw.org *.pubmatic.com *.doubleclick.net x.bidswitch.net ib.adnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com sync.1rx.io id5-sync.com *.360yield.com matching.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.adform.net *.unrulymedia.com *.media-amazon.com *.payments-amazon.com *.imgeng.in *.dmxleo.com *.google.ie *.google.co.in *.formstack.com *.google.com.au *.google.de *.google.com.tr track.linksynergy.com cdn.superpayments.com *.storyblok.com *.cdn.imgeng.in *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com connect.facebook.net s7.addthis.com js.braintreegateway.com c.paypal.com z.moatads.com v1.addthisedge.com m.addthis.com *.pcapredict.com assets.zendesk.com static.zdassets.com widget-mediator.zopim.com apps.elfsight.com services.postcodeanywhere.co.uk www.google.com www.gstatic.com js-agent.newrelic.com songbirdstag.cardinalcommerce.com bat.bing.com d2uor4thmqxhbf.cloudfront.net tag.rmp.rakuten.com bam.nr-data.net snap.licdn.com analytics.tiktok.com cdn.cookielaw.org geolocation.onetrust.com *.api.useinsider.com bam-cell.nr-data.net *.disqus.com paypal-eu-cdn.cloudiq.com *.criteo.com *.vimeo.com eval *.googletagmanager.com *.templespa.com *.yotpo.com *.formstack.com *.bc0a.com *.superpayments.com js.stripe.com *.stripecdn.com *.stripe.network cdn.superpayments.com *.cdn.imgeng.in 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app maxcdn.bootstrapcdn.com cloud.typography.com services.postcodeanywhere.co.uk assets.api.useinsider.com *.templespa.com *.formstack.com *.adobedtm.com *.cdn.imgeng.in *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * static.zdassets.com/ ekr.zdassets.com templespa.zendesk.com wss://widget-mediator.zopim.com services.postcodeanywhere.co.uk stats.g.doubleclick.net cdn.cookielaw.org analytics.tiktok.com m.addthis.com bat.bing.com *.api.useinsider.com bam-cell.nr-data.net carrier.useinsider.com *.criteo.com px.ads.linkedin.com *.onetrust.com *.googlesyndication.com *.doubleclick.net *.google-analytics.com *.amazon.com *.eu01.nr-data.net *.useinsider.com *.facebook.com measurement-api.criteo.com *.yotpo.com *.templespa.com *.bc0a.com *.superpayments.com *.analytics.google.com featureassets.org prodregistryv2.org *.seondnsresolve.com *.storyblok.com *.lambda-url.ap-south-1.on.aws web-sdk.smartlook.com cdn.segment.com api.stripe.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' data: *.cloudflare.com *.twitter.com *.google.com *.facebook.com *.twimg.com *.trustedshops.com *.bootstrapcdn.com *.olark.com *.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.yotpo.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com www.googletagmanager.com *.authorize.net *.twitter.com *.googleapi.com *.paypalobjects.com *.olark.com *.doubleclick.net *.cloudfront.net https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src 'self' data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com *.yotpo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.google.com *.googleadservices.com *.googletagmanager.com *.cloudflare.com *.googleapis.com *.google.com.vn *.klarna.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com *.sharethis.com *.snapengage.com *.olark.com *.signifyd.com *.doubleclick.net *.cloudfront.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.yotpo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.authorize.net *.cloudflare.com *.twitter.com *.facebook.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.sharethis.com *.digicert.com *.aweber.com *.googleapis.com *.snapengage.com *.olark.com *.doubleclick.net *.cloudfront.net https://h64.online-metrix.net *.signifyd.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.google.com *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com *.bootstrapcdn.com *.olark.com *.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.olark.com *.cloudfront.net *.cdn.gritautomation.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.yotpo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com stats.g.doubleclick.net *.authorize.net *.cloudflare.com *.twitter.com *.twimg.com *.facebook.com *.sharethis.com *.olark.com bt.signifyd.com:11103 *.doubleclick.net *.cloudfront.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://acsbapp.com https://snap.licdn.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://static.ads-twitter.com https://analytics.twitter.com https://connect.facebook.net https://cdn.cookielaw.org https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://cdnsecakmi.kaltura.com https://cdnapisec.kaltura.com http://cdnapi.kaltura.com https://cfvod.kaltura.com https://www.google-analytics.com https://cdn.jsdelivr.net https://script.crazyegg.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://bam.nr-data.net https://hm.baidu.com/hm.js https://www.clarity.ms https://www.googleadservices.com blob: https://vjs.zencdn.net/5.0/video.min.js https://analytics.tiktok.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' https: data; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://fonts.googleapis.com https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://script.crazyegg.com https://static.cloudflareinsights.com https://cdnapisec.kaltura.com https://cfvod.kaltura.com https://vjs.zencdn.net/5.0/video-js.min.css https://analytics.tiktok.com; frame-ancestors 'self'; report-uri /de-de/report-csp-violation 1 font-src *.fontawesome.com fonts.gstatic.com https://geowidget.easypack24.net *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.bootstrapcdn.com *.alothemes.com *.magepow.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl *.twitter.com www.facebook.com connect.facebook.net 'self' graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors pay.google.com *.youtube.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.youtube.com *.youtube-nocookie.com pay.google.com apm.przelewy24.pl https://geowidget-app.inpost.pl/ *.twitter.com *.google.com *.addthis.com youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * secure.payu.com merch-prod.snd.payu.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com * static.przelewy24.pl www.gstatic.com gstatic.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com www.google.pl *.gstatic.com ssl.ceneo.pl cdn.samito.co commerce-connector.com www.commerce-connector.com *.googleapis.com *.facebook.com *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js * sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.snrbox.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com fonts.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.snrcdn.net *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src *.youtube.com 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com https://maps.googleapis.com https://player.vimeo.com sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl google.com www.google.com pay.google.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.cloudflare.com *.twitter.com *.paypal.com bam.nr-data.net *.googleapis.com googleads.g.doubleclick.net *.saleago.com stats.g.doubleclick.net *.snrbox.com *.google-analytics.com *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com secure.payu.com merch-prod.snd.payu.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://olimpstore.pl/; report-to report-endpoint; 1 default-src 'none'; script-src 'self' 'unsafe-eval' wasm-eval acsbapp.com cosmo.kmbsus.com jam4.sapjam.com kit.fontawesome.com script.crazyegg.com www.google-analytics.com https://www.googletagmanager.com/gtm.js self view.ceros.com www.google.com www.gstatic.com www.mykonicaminolta.com; script-src-elem 'self' 'unsafe-inline' acsbapp.com cdn.tiny.cloud cloud.tinymce.com cosmo.kmbsus.com jam4.sapjam.com kit.fontawesome.com platform.twitter.com script.crazyegg.com view.ceros.com www.google-analytics.com www.google.com www.googletagmanager.com cdnjs.cloudflare.com code.jquery.com app-sjo.marketo.com connect.facebook.net ww.pagespeed-mod.com get663.com blob: mainf.global-cache.online maxcdn.bootstrapcdn.com assets0-jam4.sapjam.com snap.licdn.com; script-src-attr 'unsafe-inline' www.mykonicaminolta.com; style-src 'self' 'unsafe-inline' cdn.honey.io self; style-src-elem 'self' 'unsafe-inline' cdn.tiny.cloud stackpath.bootstrapcdn.com cdn.honey.io fonts.googleapis.com hello.myfonts.net www.gstatic.com maxcdn.bootstrapcdn.com assets0-jam4.sapjam.com; style-src-attr 'unsafe-inline' www.mykonicaminolta.com; img-src 'self' data: analytics.google.com jam4.sapjam.com portalstage.konicabt.com sp.tinymce.com stats.g.doubleclick.net syndication.twitter.com wapps.mykonicaminolta.com www.google-analytics.com www.google.ca www.google.co.in www.google.com www.google.com.sv www.googletagmanager.com www.google.com.mx www.google.com.pr kmbs.konicaminolta.us kmbscontent.konicaminolta.us www.google.co.jp www.google.co.uk www.google.co.vi www.google.de www.google.tt blob: cdn.honey.io www.google.com.co www.google.be www.google.com.ar www.google.com.au www.google.com.br www.google.com.gt www.google.com.sg www.google.it www.google.co.kr fonts.gstatic.com www.google.cl mikkiload.com www.google.co.id www.google.co.ma www.google.co.mz www.google.co.za www.google.com.bo www.google.com.my www.google.com.np www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.vn www.google.cz www.google.es www.google.fr www.google.gr www.google.pl i.ytimg.com ok7static.oktacdn.com region1.analytics.google.com www.google.ae www.google.at www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.nz www.google.co.th www.google.co.ug www.google.com.ec www.google.com.jm www.google.com.py www.google.com.qa www.google.com.uy www.google.dk www.google.hu www.google.no www.google.rs www.google.se www.google.sr www.google.com.lb www.google.com.ly www.google.mg www.google.sk www.google.ba www.google.ch www.google.co.tz www.google.com.bh www.google.com.do www.google.com.kw www.google.com.mm www.google.com.mt www.google.gg www.google.gy www.google.ie www.google.is www.google.jo www.google.ro www.google.ru www.google.si; font-src 'self' data: cdn.tiny.cloud ka-p.fontawesome.com fonts.gstatic.com static.zip.co themes.googleusercontent.com www.slant.co; connect-src 'self' *.cloudfront.net acsbapp.com analytics.google.com cdn.acsbapp.com cdn.tiny.cloud ka-p.fontawesome.com kit.fontawesome.com script.crazyegg.com stats.g.doubleclick.net tracking.crazyegg.com www.google-analytics.com www.google.ca accesswidget-log-receiver.acsbapp.com assets-tracking.crazyegg.com pagestates-tracking.crazyegg.com backend.acsbapp.com www.googletagmanager.com feed.jquery-plugins.net region1.analytics.google.com www.google.co.in www.google.co.vi wapps.mykonicaminolta.com www.google.com.mx www.google.com.pr www.google.de www.google.cl www.google.com.sv api.awesomeblocker.com api.highdataanalytics.com data: www.google.com.br www.google.com.gt www.google.cz api.ginger-analytics.com cdnml.global-cache.online overbridgenet.com service.gstatic-cache.com www.google.at www.google.co.cr www.google.co.id www.google.co.jp www.google.co.uk www.google.com.ar www.google.com.my www.google.com.pe www.google.com.ph www.google.com.vn www.google.es www.google.it www.google.sr www.google.tt www.google.com.ly api.amcreativemedia.com api.fbanalytics.org api.global-data-lab.com api.mkmediaworks.com www.google.co.ao www.google.co.za www.google.com.co www.google.com.do www.google.com.ec www.google.com.jm www.google.com.mt www.google.pl; media-src 'self' data:; object-src 'self'; child-src blob:; frame-src 'self' *.opendns.com crmweb.mykonicaminolta.com jam4.sapjam.com onlineglobal.konicaminolta.net platform.twitter.com players.brightcove.net td.doubleclick.net view.ceros.com www.youtube.com block.opendns.com gateway.zscaler.net dmh-root-sso-banner-prod.goworks.com.au performancemanager4.successfactors.com syndication.twitter.com wapps.mykonicaminolta.com www.kmdealerconnect.com aip6ygczm.accounts.ondemand.com home.allcovered.com accounts.google.com m.youtube.com www.bizhubvcare.com www.googletagmanager.com gateway.zscalerthree.net kmbs.konicaminolta.us; worker-src blob:; frame-ancestors 'self'; form-action 'self' lms.konicaminolta.com sms.mykonicaminolta.com wapps.mykonicaminolta.com www.buyerslab.com onyxweb.mykonicaminolta.com crmweb.mykonicaminolta.com ndf.mykonicaminolta.com kmbscorpit.service-now.com; report-uri https://0b3b4954796ea786489a35680dfb724f.report-uri.com/r/t/csp/wizard 1 font-src *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net *.fontawesome.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.clerk.io *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.clerk.io https://cdn.clerk.io *.stripe.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io *.stripe.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.stripe.com *.google.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.paypalobjects.com www.sheds.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no https://www.facebook.com www.sheds.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.sheds.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de https://www.google.com https://www.google.co.uk https://googleads.g.doubleclick.net https://www.facebook.com www.sheds.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network https://www.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com https://www.facebook.com https://www.google.co.uk https://bat.bing.net www.sheds.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io *.cloudflareinsights.com https://connect.facebook.net https://googleads.g.doubleclick.net https://bat.bing.com www.sheds.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com www.sheds.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.sheds.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io https://stats.g.doubleclick.net https://bat.bing.net www.sheds.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.sheds.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ www.sheds.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self' *.smartenergygb.org; connect-src 'self' *.smartenergygb.org *.clarity.ms *.doubleclick.net *.google.co.uk *.google.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.linkedin.com *.reciteme.com *.snapchat.com *.teads.tv *.webtrends-optimize.com *.webtrends-optimize.workers.dev analytics.tiktok.com api.getaddress.io capig.tandpgroup.com cdn-ukwest.onetrust.com ct.pinterest.com geolocation.onetrust.com google.com pixel-config.reddit.com privacyportal-uk.onetrust.com s.yimg.com www.redditstatic.com tr.blismedia.com i0lne9atrk.execute-api.eu-west-2.amazonaws.com o4506903028891648.ingest.us.sentry.io; default-src 'self' *.smartenergygb.org *.clarity.ms marketplace.umbraco.com our.umbraco.com; font-src 'self' data: *.smartenergygb.org *.clarity.ms *.hotjar.com *.reciteme.com fonts.gstatic.com; frame-ancestors 'self' *.smartenergygb.org *.vimeo.com *.youtube.com vimeo.com youtube.com; frame-src 'self' *.smartenergygb.org *.clarity.ms *.doubleclick.net *.googletagmanager.com *.teads.tv *.youtube.com ct.pinterest.com form.typeform.com insight.adsrvr.org smartenergygb.viznav.liquona.com tr.snapchat.com youtube.com; form-action 'self' *.smartenergygb.org; img-src 'self' data: *.smartenergygb.org *.adalyser.com *.adswizz.com *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.google.co.uk *.google.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.linkedin.com *.nextdoor.com *.reciteme.com *.teads.tv *.webtrends-optimize.com ads-twitter.com ads-api.twitter.com alb.reddit.com analytics.twitter.com cdn-ukwest.onetrust.com dashboard.umbraco.com google.com googletagmanager.com i.ytimg.com our.umbraco.com sp.analytics.yahoo.com t.co tr.blismedia.com; media-src 'self' *.smartenergygb.org *.clarity.ms *.reciteme.com; object-src 'self' *.smartenergygb.org *.clarity.ms; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.smartenergygb.org *.adalyser.com *.clarity.ms *.doubleclick.net *.google.co.uk *.google.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.nextdoor.com *.reciteme.com *.teads.tv *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.youtube.com ads-twitter.com ads-api.twitter.com analytics.tiktok.com analytics.twitter.com cdn.jsdelivr.net cdn-ukwest.onetrust.com cdnjs.cloudflare.com code.jquery.com connect.facebook.net ct.pinterest.com googletagmanager.com js.adsrvr.org platform.twitter.com s.pinimg.com s.yimg.com sc-static.net sitepixel.blis.com snap.licdn.com static.ads-twitter.com static.cloudflareinsights.com tr.snapchat.com translations.signapsesolutions.com unpkg.com www.redditstatic.com youtube.com; style-src 'self' 'unsafe-inline' *.smartenergygb.org *.clarity.ms *.google.co.uk *.google.com *.googletagmanager.com *.hotjar.com *.reciteme.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev fonts.googleapis.com googletagmanager.com 1 script-src-elem *.afterpay.com *.googletagmanager.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com *.adobe.com *.braintree-api.com *.openpay.com.au *.amplitude.com *.dpm.demdex.net *.nr-data.net *.cardinalcommerce.com *.ccdc02.com *.doubleclick.net *.paypal.com *.braintreegateway.com *.googleapis.com *.instagram.com *.unpkg.com *.trustpilot.com *.scarabresearch.com *.zipmoney.com.au *.emarsys.net *.useinsider.com *.zendesk.com cdn.jsdelivr.net *.facebook.net *.squarecdn.com *.hotjar.com 'self' 'unsafe-inline'; font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com dc89tf1ynkwmh.cloudfront.net use.typekit.net font.static.useinsider.com *.typekit.net *.cloudfront.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.iequalchange.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com wss://pod-15.zendesk.com/sc/faye *.afterpay.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.instagram.com www.google.com *.google.com *.trustpilot.com *.braintreegateway.com *.kaptcha.com e.issuu.com nationaltiles.api.useinsider.com nationaltiles-ardemo-eau.azurewebsites.net *.prontoavenue.biz *.hotjar.com data: *.useinsider.com www.youtube-nocookie.com *.iequalchange.com http://www.sandbox.paypal.com *.twitter.com *.dpm.demdex.net *.openpay.com.au 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.cdninstagram.com www.nationaltiles.com.au hnd.stats.paypal.com v2assets.zopim.io scontent-syd2-1.cdninstagram.com static.openpay.com.au log.api.useinsider.com site-assets.afterpay.com nationaltiles-ardemo-eau.azurewebsites.net *.google.com.au *.google.com.vn *.google.com.ph image.useinsider.com *.google.com *.facebook.com *.useinsider.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com unpkg.com widget.trustpilot.com cdn.scarabresearch.com static.zipmoney.com.au widgets.staging.openpay.com.au recommender.scarabresearch.com webchannel-content.eservice.emarsys.net payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com nt.api.useinsider.com *.scarabresearch.com *.zdassets.com *.zendesk.com *.zopim.com nationaltiles.api.useinsider.com hit.api.useinsider.com js-agent.newrelic.com bam-cell.nr-data.net iec.3dcstaging.com.au secure.ewaypayments.com connect.facebook.net *.hotjar.com eitri.api.useinsider.com *.openpay.com.au *.google.com.au *.google.com.vn *.google.com.ph data: *.useinsider.com *.iequalchange.com apps.jobadder.com static.zdassets.com wss://pod-15.zendesk.com/sc/faye *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.braintree-api.com *.amplitude.com *.dpm.demdex.net *.cardinalcommerce.com *.ccdc02.com *.doubleclick.net *.braintreegateway.com *.unpkg.com *.trustpilot.com *.zipmoney.com.au *.emarsys.net cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com assets.api.useinsider.com *.useinsider.com *.cloudflare.com *.braintree-api.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com 'self' 'unsafe-inline'; object-src nationaltiles-ardemo-eau.azurewebsites.net 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com *.zdassets.com nationaltiles-ardemo-eau.azurewebsites.net data: *.useinsider.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com unpkg.com widget.trustpilot.com cdn.scarabresearch.com static.zipmoney.com.au widgets.staging.openpay.com.au recommender.scarabresearch.com webchannel-content.eservice.emarsys.net payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com nt.api.useinsider.com *.scarabresearch.com *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com nationaltiles.api.useinsider.com hit.api.useinsider.com js-agent.newrelic.com bam-cell.nr-data.net iec.3dcstaging.com.au secure.ewaypayments.com socialproof.api.useinsider.com nationaltiles-ardemo-eau.azurewebsites.net api.zipmoney.com.au *.zip.co location.api.useinsider.com carrier.useinsider.com segment.api.useinsider.com stats.g.doubleclick.net *.hotjar.com wss://*.hotjar.com *.hotjar.io abacus.api.useinsider.com data: *.useinsider.com wss://pod-15.zendesk.com/sc/faye *.cloudflare.com *.twitter.com *.twimg.com *.zopim.io *.google-analytics.com https://stats.g.doubleclick.net *.openpay.com.au *.amplitude.com *.dpm.demdex.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.example.com/; report-to report-endpoint; 1 default-src 'self' 'unsafe-eval' 'unsafe-inline' pxl.qccerttest.com *.clarity.ms cdnjs.cloudflare.com *.googleoptimize.com formalyzer.com tracking.leadlander.com fonts.gstatic.com t.sf14g.com *.facebook.com *.facebook.net *.sentry-cdn.com *.google.com maxcdn.bootstrapcdn.com *.googleapis.com ssl.google-analytics.com *.doubleclick.net *.adnxs.com player.vimeo.com code.jquery.com *.netmng.com *.contextweb.com *.quantcount.com *.adsrvr.org *.quantserve.com api.cloudsponge.com collect.cloudsponge.com www.google-analytics.com www.googletagmanager.com use.fontawesome.com platform.twitter.com gng.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.moengage.com cdnjs.cloudflare.com *.googleoptimize.com *.facebook.com *.facebook.net *.sentry-cdn.com *.google.com *.googleapis.com ssl.google-analytics.com *.doubleclick.net *.adnxs.com code.jquery.com www.googletagmanager.com platform.twitter.com *.taboola.com *.clarity.ms *.adsrvr.org *.quantserve.com *.five9.net cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' 'unsafe-hashes' *.moengage.com fonts.bunny.net fonts.googleapis.com cdnjs.cloudflare.com use.fontawesome.com; img-src 'self' data: blob: *.moengage.com moe-email-campaigns.s3.amazonaws.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.adnxs.com *.quantcount.com *.adsrvr.org *.quantserve.com *.tvsquared.com *.taboola.com *.clarity.ms; font-src 'self' data: *.googleapis.com *.moengage.com fonts.gstatic.com fonts.bunny.net use.fontawesome.com; connect-src 'self' *.moengage.com *.facebook.com *.facebook.net *.sentry-cdn.com *.google.com *.googleapis.com ssl.google-analytics.com *.doubleclick.net api.cloudsponge.com collect.cloudsponge.com www.google-analytics.com *.taboola.com *.clarity.ms *.adsrvr.org *.quantserve.com *.five9.net; frame-src 'self' *.moengage.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net player.vimeo.com www.googletagmanager.com *.five9.net *.adsrvr.org; media-src 'self' *.moengage.com 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.globalpay.com https://fonts.gstatic.com *.pricespider.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.globalpay.com *.pricespider.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com *.pricespider.com s7.addthis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com https://fonts.googleapis.com *.pricespider.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://google.com/pay *.pricespider.com ekr.zdassets.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.clarity.ms https://c.bing.com; block-all-mixed-content; child-src https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; connect-src 'self' data: *.intercom.io *.sentry.io wss://nexus-websocket-a.intercom.io https://stats.g.doubleclick.net *.clarity.ms track.hubspot.com static.cloudflareinsights.com vimeo.com; font-src 'self' data: https://js.intercomcdn.com https://fonts.intercomcdn.com; frame-ancestors 'self'; frame-src 'self' youtube.com www.youtube-nocookie.com challenges.cloudflare.com player.vimeo.com; img-src 'self' data: image-cdn.bankoflamps.com i.ytimg.com c.bing.com *.clarity.ms i.vimeocdn.com; media-src 'self' blob-cdn.bankoflamps.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' youtube.com 'nonce-22QRy0YvC1qJXgeqZyd8TCL4l0et6AaGLTbnMaSNxyk=' static.cloudflareinsights.com challenges.cloudflare.com https://js.intercomcdn.com https://widget.intercom.io *.clarity.ms track.hubspot.com 'nonce-OCg8RbQVO8qBLamXJBOfUQ=='; style-src 'self' 'unsafe-inline'; report-uri /csp/report; worker-src 'self' blob: 1 default-src https: 'self' data:; script-src 'unsafe-eval' 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https: 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-1ea8afc9b1734401b2c005cb3b1d4f7e' https://mychart.et1197.epichosted.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart.et1197.epichosted.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self' wss: *.gravatar.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.publicstuff.com *.googletagmanager.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com connect.facebook.net static.addtoany.com https://widgets.nrel.gov *.openstreetmap.org cdn-images.mailchimp.com platform.twitter.com blob:; object-src 'self' 'unsafe-inline' 'unsafe-eval' translate.googleapis.com iframe.publicstuff.com; style-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com *.ctctcdn.com cdn-images.mailchimp.com data: *.typekit.net; img-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com www.facebook.com https://widgets.nrel.gov www.facebook.com *.openstreetmap.org cdn-images.mailchimp.com i.ytimg.com data:; media-src 'self' translate.googleapis.com iframe.publicstuff.com data:; frame-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; frame-ancestors 'self' *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com; child-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; font-src 'self' 'unsafe-inline' 'unsafe-eval' *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com user.govoutreach.com syndication.twitter.com data: *.typekit.net; connect-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com stats.g.doubleclick.net; report-uri /report-csp-violation 1 font-src fonts.googleapis.com fonts.gstatic.com sphinx-m2.ch.trendhosting.cloud *.sphinx-tools.ch https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.googleapis.com maps.gstatic.com sphinx-m2.ch.trendhosting.cloud *.sphinx-tools.ch ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com sphinx-m2.ch.trendhosting.cloud *.sphinx-tools.ch chimpstatic.com downloads.mailchimp.com *.list-manage.com https://www.google.com https://www.gstatic.com *.cloudflare.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com sphinx-m2.ch.trendhosting.cloud *.sphinx-tools.ch downloads.mailchimp.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sphinx-m2.ch.trendhosting.cloud googleads.g.doubleclick.net jnn-pa.googleapis.com *.sphinx-tools.ch https://ipinfo.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src sphinx-m2.ch.trendhosting.cloud play.google.com *.sphinx-tools.ch 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com blob: https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; font-src https: data:; img-src https: data: about: ; connect-src https: wss: 'self'; worker-src https: blob: 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.klevu.com *.ksearchnet.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://cdn.loadbee.com/ https://petertysonelectricals.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * js.mollie.com https://www.googletagmanager.com/ *.addthis.com *.googleapis.com https://service.loadbee.com/ http://www.paypal.com http://www.sandbox.paypal.com *.trustpilot.com petertysonelectricals.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.mollie.com *.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com *.finance-calculator.co.uk *.dekopay.com 'self' data: https://img.youtube.com maps.gstatic.com *.bing.com *.opentracker.net *.clarity.ms *.adtrafficquality.google *.flix360.com *.google.co.uk *.sweetanalytics.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.finance-calculator.co.uk *.dekopay.com *.googleapis.com https://cdn.loadbee.com/js/loadbee_integration.js *.trustpilot.com *.smartsuppchat.com *.facebook.net *.hotjar.com *.bing.com *.clickguardian.app *.opentracker.net *.googlesyndication.com *.cloudfront.net *.cloudflare.com *.smartsuppcdn.com *.dwin1.com *.pinimg.com *.kk-resources.com *.clarity.ms *.pinterest.com *.adtrafficquality.google *.flixfacts.com *.flixcar.com *.sweetanalytics.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com assets.braintreegateway.com maxcdn.bootstrapcdn.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://cdn.jsdelivr.net *.trustpilot.com *.smartsuppcdn.com *.klaviyo.com *.finance-calculator.co.uk *.flixcar.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.addressy.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.finance-calculator.co.uk *.dekopay.com *.googleapis.com https://availability.loadbee.com *.smartsuppchat.com *.hotjar.com *.hotjar.io *.smartsuppcdn.com *.amazonaws.com *.clickguardian.app *.adtrafficquality.google *.smartsupp.com *.googlesyndication.com *.google-analytics.com *.pinterest.com *.clarity.ms wss: *.flixcar.com *.gstatic.com *.google.co.uk *.sweetanalytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' *.corelogic.com https://code.jquery.com/ https://fonts.googleapis.com/ https://maxcdn.bootstrapcdn.com/; font-src 'self' https://fonts.gstatic.com/ https://maxcdn.bootstrapcdn.com/ https://ka-f.fontawesome.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.corelogic.com https://code.jquery.com/ https://www.google-analytics.com/analytics.js https://gateway.foresee.com/ http://gateway.foresee.com/ https://www.googletagmanager.com/ https://content.realquest.com/ https://maxcdn.bootstrapcdn.com/ https://h.online-metrix.net/; img-src 'self' data: *.googleapis.com *.google-analytics.com *.online-metrix.net *.corelogic.com https://gateway.foresee.com/ https://maps.gstatic.com/ https://www.google.com/ https://code.jquery.com/ https://content.realquest.com/ https://www.googletagmanager.com/ https://dummyimage.com/ https://lh3.ggpht.com/; connect-src 'self' *.google-analytics.com *.realquest.com https://stats.g.doubleclick.net/ https://maps.googleapis.com/ https://ka-f.fontawesome.com/; frame-src 'self' *.online-metrix.net *.opendns.com *.realquest.com https://play.vidyard.com/ https://players.brightcove.net/; object-src 'none'; frame-ancestors 'self';report-uri /csp/report-uri; 1 font-src *.hach.de *.oppermann.de *.kombinat-berlin.de *.fonts.net *.ekomi.com *.ekomi.de *.ekomiapps.de *.fontawesome.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static.unzer.com https://applepay.cdn-apple.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com *.hach.de *.oppermann.de *.kombinat-berlin.de *.facebook.com *.facebook.net *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.hach.de *.oppermann.de *.kombinat-berlin.de *.facebook.com *.facebook.net *.uptain.de *.nosto.com *.nos.to https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.wonderchat.io 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.cloudfront.net magefan.com cm.magefan.com *.hach.de *.oppermann.de *.kombinat-berlin.de 'self' data: *.cookielaw.org *.taboola.com *.bing.com *.adform.net *.facebook.com *.facebook.net *.licdn.com *.creative-serving.com *.uptain.de *.doubleclick.net *.doubleclick.com *.linkedin.com *.google.com *.google.de *.google-analytics.com cx.atdmt.com *.ekomi.com *.ekomi.de *.ekomiapps.de *.nosto.com *.nos.to https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com *.disqus.com https://connect.nosto.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.googleapis.com *.gstatic.com jsd-widget.atlassian.com widget.freshworks.com m2epro.freshdesk.com *.hach.de *.oppermann.de *.kombinat-berlin.de *.cookielaw.org *.taboola.com *.bing.com *.adform.net *.facebook.com *.facebook.net *.licdn.com *.creative-serving.com *.uptain.de *.doubleclick.net *.doubleclick.com *.polyfill.io https://browser.sentry-cdn.com *.google-analytics.com *.googleadservices.com *.ekomi.com *.ekomi.de *.ekomiapps.de stage.exdatis.com *.nosto.com *.nos.to *.fontawesome.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net *.wonderchat.io *.disqus.com *.googletagmanager.com www.termsfeed.com https://www.googletagmanager.com https://connect.nosto.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src widget.freshworks.com m2epro.freshdesk.com *.hach.de *.oppermann.de *.kombinat-berlin.de *.fonts.net *.ekomi.com *.ekomi.de *.ekomiapps.de stage.exdatis.com *.fontawesome.com *.nosto.com *.nos.to https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.wonderchat.io *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src stage.exdatis.com *.wonderchat.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de jsd-widget.atlassian.com api-private.atlassian.com widget.freshworks.com m2epro.freshdesk.com *.hach.de *.oppermann.de *.kombinat-berlin.de *.cookielaw.org *.taboola.com *.bing.com *.adform.net *.facebook.com *.facebook.net *.licdn.com *.creative-serving.com *.uptain.de *.doubleclick.net *.doubleclick.com *.google-analytics.com id5-sync.com *.onetrust.com *.ekomi.com *.ekomi.de *.ekomiapps.de stage.exdatis.com wss://stage.exdatis.com *.nosto.com *.nos.to *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.wonderchat.io wss://*.wonderchat.io https://*.ingest.sentry.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://hach-report.uriports.com/reports; report-to report-endpoint; 1 font-src *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://service.xesto.io https://staging-xesto-service.xesto.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com https://service.xesto.io https://staging-xesto-service.xesto.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.gstatic.com fonts.googleapis.com https://service.xesto.io https://staging-xesto-service.xesto.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com tagmanager.google.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://service.xesto.io https://staging-xesto-service.xesto.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cdn.shoptireco.com cdn.shoptireco.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://firebasestorage.googleapis.com *.cdn.shoptireco.com cdn.shoptireco.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com s7.addthis.com *.avada.io *.cdn.shoptireco.com cdn.shoptireco.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cdn.shoptireco.com cdn.shoptireco.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.cdn.shoptireco.com cdn.shoptireco.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com thm.visa.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.cdn.shoptireco.com cdn.shoptireco.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.cdn.shoptireco.com cdn.shoptireco.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-pCkVhMghFJH9YO4hFHYnRmmRR7fMX8cL'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 script-elem-src addwish.com *.hotjar.com; font-src *.cloudflare.com *.bootstrapcdn.com *.flixfacts.com *.flixcar.com *.bricks.plus *.vimeo.com core.helloretail.com *.addwish.com cloud.misterbricks.nl *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ js.mollie.com *.flixcar.com *.bricks.plus *.vimeo.com *.cloudfront.net *.google.com core.helloretail.com *.hotjar.com www.facebook.com cloud.misterbricks.nl *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://www.mollie.com *.cloudflare.com *.cloudfront.net *.flixcar.com *.flixfacts.com *.flix360.com *.bricks.plus *.vimeo.com *.google.com *.google.nl core.helloretail.com *.addwish.com www.facebook.com *.facebook.net *.hipex.cloud cloud.misterbricks.nl connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.mollie.com *.cloudflare.com *.twitter.com *.fontawesome.com *.flixfacts.com *.flixcar.com *.flix360.com *.flix360.io *.bricks.plus *.googletagmanager.com *.newrelic.com *.nr-data.net *.google.com *.gstatic.com *.addwish.com addwish.com *.cloudfront.net core.helloretail.com *.doubleclick.net *.hotjar.com *.hotjar.io www.facebook.com *.facebook.net cloud.misterbricks.nl *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.cloudfront.net *.fontawesome.com *.bootstrapcdn.com *.flixcar.com *.bricks.plus *.vimeo.com core.helloretail.com *.addwish.com addwish.com cloud.misterbricks.nl cdn.dnky.co webchat.dotdigital.com maxcdn.bootstrapcdn.com unsafe-inline *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bricks.plus *.vimeo.com *.akamaized.net core.helloretail.com *.addwish.com cloud.misterbricks.nl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.cloudflare.com *.cloudfront.net *.amazonaws.com *.google.com *.plyr.io *.analytics.google.com *.google-analytics.com *.doubleclick.net *.nr-data.net *.addwish.com core.helloretail.com *.hotjar.com *.flix360.io *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.misterbricks.nl/; report-to report-endpoint; 1 default-src 'self' www.zikg.eu; img-src *; style-src 'unsafe-inline' www.zikg.eu fonts.googleapis.com cdnjs.cloudflare.com; script-src 'unsafe-inline' 'unsafe-eval' www.zikg.eu; font-src 'self' data: www.zikg.eu fonts.gstatic.com fonts.googleapis.com cdnjs.cloudflare.com; 1 default-src 'self' 'unsafe-inline'; script-src 'self' https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/ 'unsafe-inline'; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com/; style-src-elem 'self' https://fonts.googleapis.com/ 'unsafe-inline'; report-to csp-reports; report-uri https://www.transact-online.co.uk/csp_reporting 1 default-src 'self' ; img-src data: *; script-src 'unsafe-inline' 'unsafe-eval' * blob:; font-src data: 'unsafe-inline' *; style-src 'unsafe-inline' *; media-src * blob:; report-uri https://www.senate.be/_csp 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.flixcar.com *.flixfacts.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.monetico-services.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.monetico-services.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com cdn.doofinder.com *.flix360.com *.flix360.io https://images.unsplash.com *.openstreetmap.org *.flixcar.com *.bazaarvoice.com *.jwpsrv.com *.flixfacts.com *.imgix.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com cdn.doofinder.com *.channelsight.com media.flixfacts.com *.flix360.io *.flixcar.com *.cloudflareinsights.com *.gitem.fr fghcx.gitem.fr xvvcw.procie.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com *.doofinder.com *.flixcar.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.monetico-services.com *.doofinder.com wss://*.doofinder.com *.flixcar.com *.openstreetmap.org *.axept.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.inpost.pl *.fontawesome.com https://geowidget.easypack24.net *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com https://seo.mageplaza.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com secure.payu.com merch-prod.snd.payu.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.inpost.pl *.addthis.com js.mollie.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com static.payu.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.trackedlink.net *.inpost.pl tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl https://www.mollie.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ secure.payu.com secure.snd.payu.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.inpost.pl mapa.orlenpaczka.pl s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io js.mollie.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com webchat.dotdigital.com webchat.staging.dotdigital.com *.inpost.pl https://cdn.jsdelivr.net *.fontawesome.com https://geowidget.easypack24.net *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.inpost.pl https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com secure.payu.com merch-prod.snd.payu.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.inpost.pl nominatim.openstreetmap.org ekr.zdassets.com/ https://get.geojs.io *.avada.io *.easypack24.net *.openstreetmap.org *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.inpost.pl *.fontawesome.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ pay.google.com pay-accept.bm.pl pay.bm.pl cards-accept.bm.pl cards.bm.pl *.inpost.pl c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.inpost.pl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.payu.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com cards-accept.bm.pl cards.bm.pl pay.google.com *.google-analytics.com *.googletagmanager.com *.inpost.pl https://cdn.polyfill.io https://browser.sentry-cdn.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com pay-accept.bm.pl pay.bm.pl cards-accept.bm.pl cards.bm.pl *.googleapis.com *.inpost.pl https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.inpost.pl https://*.ingest.sentry.io https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com secure.payu.com merch-prod.snd.payu.com ws: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.sieval.com *.gstatic.com *.googleapis.com *.talkjs.com *.bing.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.sieval.com *.googletagmanager.com *.fls.doubleclick.net *.g.doubleclick.net *.doubleclick.net *.pinterest.com *.talkjs.com widget.trustpilot.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai *.roomvo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.sieval.com *.pinimg.com *.pinterest.com *.facebook.net *.facebook.com google.com *.google.nl *.google.be *.googleapis.com *.gstatic.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.doubleclick.net *.talkjs.com *.clarity.ms *.bing.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai popup.projects.webpages.one d1zviajkun9gxg.cloudfront.net *.ads.linkedin.com *.roomvo.com maatwerk.carpetright.nl maatwerk.uat.carpetright.nl www.magmodules.eu *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io unpkg.com *.sieval.com www.google.com *.googleapis.com *.gstatic.com *.googleoptimize.com widget.trustpilot.com *.hotjar.com *.hotjar.io *.cloudfunctions.net *.pinimg.com *.facebook.net *.facebook.com *.g.doubleclick.net *.doubleclick.net *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.talkjs.com *.clarity.ms *.bing.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai popup.projects.webpages.one d1zviajkun9gxg.cloudfront.net client.prod.mplat-ppcprotect.com snap.licdn.com *.roomvo.com maatwerk.carpetright.nl maatwerk.uat.carpetright.nl squeezely.tech www.squeezely.tech *.squeezely.tech 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl unpkg.com *.sieval.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.googleoptimize.com *.analytics.google.com *.talkjs.com *.clarity.ms *.bing.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai d1zviajkun9gxg.cloudfront.net *.roomvo.com maatwerk.carpetright.nl maatwerk.uat.carpetright.nl *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.googleapis.com *.gstatic.com *.googleoptimize.com *.analytics.google.com *.talkjs.com *.clarity.ms *.bing.com *.carpetright.nl *.carpetright.be app.youshouldask.ai 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com unpkg.com *.sieval.com *.bing.net www.google.com google.com *.gstatic.com *.googleoptimize.com widget.trustpilot.com *.hotjar.com wss://ws.hotjar.com/ *.hotjar.io *.cloudfunctions.net *.pinimg.com *.pinterest.com *.facebook.net *.facebook.com *.doubleclick.net *.g.doubleclick.net *.googleapis.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.talkjs.com *.clarity.ms *.bing.com *.carpetright.nl *.carpetright.be *.tweakwisenavigator.net *.tweakwisenavigator.com app.youshouldask.ai popup.projects.webpages.one d1zviajkun9gxg.cloudfront.net mailcampaigns.pagency.me click.prod.mplat-ppcprotect.com *.ads.linkedin.com *.roomvo.com maatwerk.carpetright.nl maatwerk.uat.carpetright.nl squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-xSMJrnvDwCMa-R6byuXkdg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-_X3eEWyobXbMyZy0_Mupeg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.sendcloud.sc *.jsdelivr.net https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com *.disqus.com https://cdn.jsdelivr.net *.sendcloud.sc *.jsdelivr.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://cdn.jsdelivr.net *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.oney.io *.staging.oney.io *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hipay-tpp.com *.hipay.com *.googleapis.com *.iubenda.com *.salesmanago.pl *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.hipay.com *.googleapis.com *.oney.io *.staging.oney.io *.sharethis.com *.iubenda.com *.ads.linkedin.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com *.oney.io *.staging.oney.io *.sharethis.com *.iubenda.com *.clarity.ms analytics.tiktok.com snap.licdn.com rum.hlx.page *.googletagmanager.com *.googleadservices.com *.google-analytics.com cdn.scalapay.com b2c-cdn.scalapay.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.hipay.com *.googleapis.com use.typekit.net p.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.oney.io *.staging.oney.io maps.googleapis.com *.sharethis.com *.iubenda.com *.clarity.ms analytics.tiktok.com *.ads.linkedin.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.ch/api/csp-report; report-to csp-endpoint 1 object-src 'none'; script-src 'nonce-gpwKPaXSO9HO7FTtO5WZ4Vyp' 'strict-dynamic' http: https:; base-uri 'none'; 1 base-uri 'self'; object-src 'none'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://*.googletagservices.com https://*.googlesyndication.com https://*.doubleclick.net https://cdn-cookieyes.com https://analytics.tiktok.com https://*.convertexperiments.com https://bat.bing.com https://connect.facebook.net https://scripts.clarity.ms https://www.clarity.ms https://ajax.googleapis.com https://www.datadoghq-browser-agent.com https://www.gstatic.com https://www.google.com https://static.hotjar.com https://script.hotjar.com https://tag.rmp.rakuten.com https://widget.trustpilot.com https://assets.wingbuddy.com https://cdn.jsdelivr.net https://kit.fontawesome.com https://static.cloudflareinsights.com https://cdn.onesignal.com https://api.onesignal.com https://cdnjs.cloudflare.com; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://*.googletagservices.com https://*.googlesyndication.com https://*.doubleclick.net https://cdn-cookieyes.com https://analytics.tiktok.com https://*.convertexperiments.com https://bat.bing.com https://connect.facebook.net https://scripts.clarity.ms https://www.clarity.ms https://ajax.googleapis.com https://www.datadoghq-browser-agent.com https://www.gstatic.com https://www.google.com https://static.hotjar.com https://script.hotjar.com https://tag.rmp.rakuten.com https://widget.trustpilot.com https://assets.wingbuddy.com https://cdn.jsdelivr.net https://kit.fontawesome.com https://static.cloudflareinsights.com https://cdn.onesignal.com https://api.onesignal.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://assets.wingbuddy.com https://cdn.jsdelivr.net https://widget.trustpilot.com https://ka.p.fontawesome.com https://ka-p.fontawesome.com https://www.gstatic.com https://fonts.googleapis.com https://www.google-analytics.com https://www.googletagmanager.com https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://assets.wingbuddy.com https://cdn.jsdelivr.net https://widget.trustpilot.com https://ka.p.fontawesome.com https://ka-p.fontawesome.com https://www.gstatic.com https://fonts.googleapis.com https://www.google-analytics.com https://www.googletagmanager.com https://cdnjs.cloudflare.com; img-src 'self' data: https:; font-src 'self' data: https://assets.wingbuddy.com https://fonts.gstatic.com https://ka.p.fontawesome.com https://ka-p.fontawesome.com; connect-src 'self' https: https://b.clarity.ms https://ad.doubleclick.net https://stats.g.doubleclick.net https://securepubads.g.doubleclick.net https://api.onesignal.com https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https://www.googletagmanager.com https://www.youtube.com https://www.facebook.com https://*.fls.doubleclick.net https://www.google.com https://widget.trustpilot.com https://www.gstatic.com; worker-src 'self' blob:; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net magefan.com cm.magefan.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com https://img.youtube.com https://meetanshi.com/media/logo.png flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ s7.addthis.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com expressentry.melissadata.net/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com ekr.zdassets.com/ www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.paypalobjects.com poolandspawarehouse.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.google.hr *.google.com.au server-side.poolandspawarehouse.com.au cdn.jst.ai 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com poolandspawarehouse.com.au www.facebook.com bat.bing.net *.feefo.com *.digicert.com *.google.com *.google.hr *.google.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com widget.freshworks.com m2epro.freshdesk.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.maxmind.com poolandspawarehouse.com.au *.klaviyo.com *.google.com *.google.hr *.google.com.au www.gstatic.com seal.digicert.com server-side.poolandspawarehouse.com.au connect.facebook.net bat.bing.com cdn.jst.ai my.jst.ai aly.jst.ai 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://static.klaviyo.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com poolandspawarehouse.com.au cdn.jst.ai 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.mmapiws.com poolandspawarehouse.com.au *.klaviyo.com server-side.poolandspawarehouse.com.au *.google.hr *.google.com.au *.google-analytics.com stats.g.doubleclick.net my.jst.ai bat.bing.net aly.jst.ai 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src aly.jst.ai bat.bing.net poolandspawarehouse.com.au 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com *.gstatic.com data: http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io d3dc1lgancj6l0.cloudfront.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com http://*.facebook.com https://*.facebook.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://www.googletagmanager.com/ https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com/ http://*.facebook.com https://*.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com https://cdn.consentmanager.net https://delivery.consentmanager.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.consentmanager.net http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.linkedin.com https://*.linkedin.com http://*.facebook.com https://*.facebook.com http://www.google.com/ http://www.google.de/ https://www.google.de/ https://www.googletagmanager.com http://www.googletagmanager.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://widgets.trustedshops.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://cdn.consentmanager.net https://delivery.consentmanager.net chimpstatic.com downloads.mailchimp.com *.list-manage.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://connect.facebook.net/ https://snap.licdn.com/li.lms-analytics/insight.min.js http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io unsafe-inline userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com http://www.google.com/recaptcha/ https://widgets.trustedshops.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentmanager.net *.googleadservices.com js.mollie.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.baby-born.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://cdn.consentmanager.net https://delivery.consentmanager.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com http://salesviewer.org/ userlike-cdn-widgets.s3-eu-west-1.amazonaws.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com https://www.google.com/ccm/collect 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self' www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ 'self' td.doubleclick.net www.facebook.com 'self' fast.amc.demdex.net www.google.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src 'self' assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'unsafe-inline' *.adobedtm.com data: www.googleadservices.com https://www.selfawb.ro www.google.ro https://www.google.com *.googleadservices.com www.google-analytics.com analytics.google.com *.googletagmanager.com *.openstreetmap.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org maps.gstatic.com fonts.gstatic.com www.gstatic.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net 'report-sample' 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.adobedtm.com connect.facebook.net cdn.ampproject.org pay.google.com *.google-analytics.com googletagmanager.com *.googletagmanager.com apis.google.com *.googleapis.com *.googleadservices.com *.gstatic.com www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.gstatic.com/recaptcha https://www.google.com/recaptcha google.com *.google.com *.google.com/ https://maps.googleapis.com/maps/api/js maps.googleapis.com *.openstreetmap.org *.magento-ds.com use.typekit.net map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.typekit.net www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com www.googletagmanager.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io 'self' 'unsafe-inline' https://google.com/ccm/form-data/844658545 https://google.com/pagead/form-data/844658545 cdn.ampproject.org https://ecommerce.fancourier.ro https://api.fancourier.ro https://www.google.com analytics.google.com www.googleapis.com region1.analytics.google.com www.google-analytics.com https://nominatim.openstreetmap.org map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.googletagmanager.com stats.g.doubleclick.net places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' www.google.ro www.google.com google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=26912&v=v1.0&payload=FSAHmqSHa6wuUd0r-QkGsQbnInCrsPZHNsKp9EHURP1DanUL_Sa6V8rmYTLpBHlWNQQ6X2ZSmTXQvv3FWKn_qmM04Zs4SRDeMbXwdoyRjFEGo0NjDchlKkTnrwu1Ck753Bqy3zsxSEY2OwIbavFxqsbOWFhphYHtNVCXBa5HrXw=; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com static.klaviyo.com fonts.feefo.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.snapfinance.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.doubleclick.net *.facebook.com account.fetchify.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com imgsct.cookiebot.com donaghybros.co.uk google.co.in bat.bing.com media.flixcar.com rt.flix360.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.snapfinance.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com consent.cookiebot.com bat.bing.com s.pinimg.com/ct/ *.livechatinc.com *.hotjar.com/ ct.pinterest.com/static/ct/token_create.js widgets.reevoo.com static.youreko.com/js/partners/gb/donaghy-bros/youreko.energy-review.donaghy-bros.all.min.js media.flixfacts.com/js/loader.js prod.flixgvid.flix360.io/ media.flixcar.com instore.pricespy.co.uk/in.js cdn.loadbee.com/js/loadbee_integration.js static.cloudflareinsights.com/beacon.min.js cdn-cookieyes.com/client_data/f903097f3ec531c15a2be696/script.js cdn-cookieyes.com/client_data/f903097f3ec531c15a2be696/banner.js *.salesfire.co.uk s.kk-resources.com/leadtag.js https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.snapfinance.co.uk https://connect.consents-dev.online https://connect.consents.online *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.typekit.net *.salesfire.co.uk https://static.klaviyo.com cc-cdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.snapfinance.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net ct.pinterest.com bat.bing.com *.hotjar.com/c/ stats.g.doubleclick.net widgets.reevoo.com availability.loadbee.com media.flixcar.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.snapfinance.co.uk https://signup.consents-dev.online https://signup.consents.online https://connect.consents-dev.online https://connect.consents.online https://api.mistho.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.blacksonblondes.com *.dfxtra.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.blacksonblondes.com *.dfxtra.com join.gammasecure.com; script-src 'self' *.blacksonblondes.com *.dfxtra.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.blacksonblondes.com *.dfxtra.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.bootstrapcdn.com *.fontawesome.com maxcdn.bootstrapcdn.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.vimeo.com *.lightwidget.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.youtube.com https://c.paypal.com/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.google.com *.googleadservices.com *.googletagmanager.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.lightwidget.com https://ipinfo.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.fontawesome.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.bootstrapcdn.com https://use.typekit.net https://p.typekit.net assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com stats.g.doubleclick.net https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.ingrid.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klaviyo.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.klaviyo.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.cookielaw.org *.ingrid.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net static.klaviyo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klaviyo.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.cookielaw.org *.onetrust.io *.onetrust.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com https://static.lyra.com/static/ *.fontawesome.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://js.stripe.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ https://secure-magenta.dalenys.com https://redchamps.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com js.stripe.com https://api.lyra.com/api-payment/ https://static.lyra.com/static/ https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://checkout.stripe.com/checkout.js https://js.stripe.com/v3/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://static.lyra.com/static/ *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.zendesk.com *.zdassets.com *.zopim.com connect.facebook.net 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.addthis.com *.pinterest.com www.facebook.com checkout.tabby.ai testourcode.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.facebook.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.zdassets.com *.samma3a.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io maps.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.googletagmanager.com *.facebook.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.zendesk.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com analytics.tiktok.com *.doubleclick.net *.youtube.com *.artfut.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com connect.facebook.net www.googletagmanager.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.samma3a.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.algolia.net *.algolia.com *.algolianet.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.zendesk.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com analytics.tiktok.com *.doubleclick.net *.artfut.com *.youtube.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.eands.com.au *.alicdn.com *.flaticon.com *.fontawesome.com *.slant.co https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.googlesyndication.com api.bazaarvoice.com stg.api.bazaarvoice.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.eands.com.au 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com *.eands.com.au *.criteo.com *.googletagmanager.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.gstatic.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.agkn.com *.360yield.com *.3lift.com *.adnxs.com *.baidu.com *.bazaarvoice.com *.bidswitch.net *.bing.com *.bing.net *.casalemedia.com *.clarity.ms *.criteo.com *.criteo.net *.google.com *.googleadservices.com *.jobadder.com *.mediawallahscript.com *.pinterest.com *.prreqcroab.icu *.quantserve.com *.smartadserver.com *.subzero-wolf.com *.taboola.com *.turn.com *.wisepops.com google.com prreqcroab.icu s3.amazonaws.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bs www.google.by www.google.ca www.google.cd www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gm www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.nr www.google.nu www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tn www.google.to www.google.vu www.google.ws https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal chimpstatic.com downloads.mailchimp.com *.list-manage.com *.eands.com.au *.newrelic.com *.nr-data.net *.googleapis.com *.criteo.net *.criteo.com *.adnxs.com *.bazaarvoice.com *.bing.com *.clarity.ms *.googleadservices.com *.hotjar.com *.jobadder.com *.pinimg.com *.pinterest.com *.quantcount.com *.quantserve.com *.wisepops.com *.zdassets.com googletagmanager.com wisepops.net https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.instagram.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com display.ugc.bazaarvoice.com downloads.mailchimp.com *.eands.com.au *.typography.com *.fontawesome.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src *.eands.com.au 'self' 'unsafe-inline'; media-src *.adobe.com *.eands.com.au *.zdassets.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src *.eands.com.au 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.eands.com.au *.nr-data.net *.newrelic.com *.googleapis.com *.bazaarvoice.com *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.google.com *.googleadservices.com *.hotjar.com *.hotjar.io *.pinterest.com *.quantcount.com *.wisepops.com *.zdassets.com google.com localhost wisepops.net www.google.ad www.google.ae www.google.al www.google.at www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.cd www.google.ch www.google.ci www.google.cl www.google.cn www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.nr www.google.nu www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tl www.google.to www.google.vu www.google.ws https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src *.eands.com.au assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.eands.com.au *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://def893e4-f6e2-42b0-83af-ead3f58ab21a.sansec.watch/; report-to report-endpoint; 1 font-src *.typekit.net fonts.soundestlink.com fonts.gstatic.com *.fontawesome.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com https://cdn.clerk.io https://maps.omnivasiunta.lt www.facebook.com static.hotjar.com script.hotjar.com dynamic.criteo.com sslwidget.criteo.com wt.omnisendlink.com forms.soundestlink.com stats.g.doubleclick.net ad.doubleclick.net *.google.lv measurement-api.criteo.com ib.adnxs.com sync-t1.taboola.com visitor.omnitagjs.com matching.ivitrack.com exchange.mediavine.com sync.outbrain.com sync.1rx.io gum.criteo.com criteo-sync.teads.tv criteo-partners.tremorhub.com sync-criteo.ads.yieldmo.com dis.criteo.com cm.g.doubleclick.net formsv2.soundestlink.com *.google.com *.facebook.com *.twitter.com https://x.bidswitch.net https://rtb-csync.smartadserver.com https://r.casalemedia.com https://id5-sync.com https://ad.360yield.com https://contextual.media.net https://jadserve.postrelease.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://match.sharethrough.com https://eb2.3lift.com https://ad.yieldlab.net https://e1.emxdgt.com https://sync.targeting.unrulymedia.com https://uipglob.semasio.net https://www.google.lt https://www.google.com https://vc.hotjar.io https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org public.montonio.com https://omnisnippet1.com https://wt.soundestlink.com https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com *.instagram.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com https://unpkg.com *.googletagmanager.com connect.facebook.net static.hotjar.com script.hotjar.com dynamic.criteo.com sslwidget.criteo.com wt.omnisendlink.com forms.soundestlink.com stats.g.doubleclick.net *.google.lv measurement-api.criteo.com ib.adnxs.com sync-t1.taboola.com visitor.omnitagjs.com matching.ivitrack.com exchange.mediavine.com sync.outbrain.com sync.1rx.io gum.criteo.com criteo-sync.teads.tv criteo-partners.tremorhub.com sync-criteo.ads.yieldmo.com dis.criteo.com cm.g.doubleclick.net analytics.tiktok.com https://x.bidswitch.net https://rtb-csync.smartadserver.com https://r.casalemedia.com https://id5-sync.com https://ad.360yield.com https://contextual.media.net https://jadserve.postrelease.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://match.sharethrough.com https://eb2.3lift.com https://ad.yieldlab.net https://e1.emxdgt.com https://sync.targeting.unrulymedia.com https://uipglob.semasio.net https://www.google.lt https://vc.hotjar.io s7.addthis.com public.montonio.com https://omnisnippet1.com https://forms.soundestlink.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com api.clerk.io cdn.clerk.io www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com *.typekit.net fonts.soundestlink.com *.fontawesome.com *.googleapis.com https://unpkg.com unsafe-inline assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com https://geocode.arcgis.com ws: *.analytics.google.com static.hotjar.com script.hotjar.com dynamic.criteo.com sslwidget.criteo.com wt.omnisendlink.com forms.soundestlink.com stats.g.doubleclick.net *.google.lv measurement-api.criteo.com ib.adnxs.com sync-t1.taboola.com visitor.omnitagjs.com matching.ivitrack.com exchange.mediavine.com sync.outbrain.com sync.1rx.io gum.criteo.com criteo-sync.teads.tv criteo-partners.tremorhub.com sync-criteo.ads.yieldmo.com dis.criteo.com cm.g.doubleclick.net *.facebook.com google.com *.twitter.com analytics.tiktok.com https://x.bidswitch.net https://rtb-csync.smartadserver.com https://r.casalemedia.com https://id5-sync.com https://ad.360yield.com https://contextual.media.net https://jadserve.postrelease.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://match.sharethrough.com https://eb2.3lift.com https://ad.yieldlab.net https://e1.emxdgt.com https://sync.targeting.unrulymedia.com https://uipglob.semasio.net https://www.google.lt https://www.google.com https://vc.hotjar.io ekr.zdassets.com/ https://www.terminalmappingjs.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com *.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: https://components-bnpl-pe-bbva-moprestamo-com.s3.amazonaws.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.moprestamo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.moprestamo.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.moprestamo.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.moprestamo.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * api-qa.payplug.com secure-qa.payplug.com *.payplug.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org images.join-stories.com https://www.magezon.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.payplug.com dessange.my.join-stories.com https://browser.sentry-cdn.com *.googletagmanager.com *.facebook.net *.avada.io *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com https://cdn-qa.payplug.com https://secure-magenta.dalenys.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com meas.join-stories.com https://*.ingest.sentry.io *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; child-src 'self' data: *.google.com *.googleapis.com *.googletagmanager.com; connect-src 'self' data: *.ceros.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.licdn.net *.passle.net *.typekit.net *.yoshki.com; font-src 'self' data: *.gstatic.com; frame-ancestors 'self' https://view.ceros.com https://ceros.macfarlanes.com/ https://macfarlanes.preview.ceros.com/; frame-src 'self' https://cdn.yoshki.com/; img-src 'self' data: *.buzzsprout.com *.ceros.com *.passle.net *.typekit.net; media-src 'self'; object-src 'self'; script-src 'self' data: *.ceros.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.licdn.net *.passle.net *.typekit.net *.yoshki.com; style-src 'self' data: *.ceros.com *.googleapis.com *.gstatic.com; report-uri https://3chillies.report-uri.com/r/d/csp/reportOnly; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' google.com *.google.com gstatic.com *.gstatic.com jquery.com *.jquery.com mycadmium.com *.mycadmium.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=DjnS6orOhOCngYTjwtkK1eE7_Ba3vJjfV3Trft5nEhw-1765946279.8813581-1.0.1.1-MABvfmmdleL46unK3asCkKNQ9Tf19Snf03EJ6kcC0FTByULs0nfhJbVx7hGsAww207SsJ_jotojGSw3Yd7C_rGNqwYvWsYBZkX0fXYkVZtRPO9wu319m8eNb9VvMFJHkgfK6SIZkPQVSAejVFyrPW3Axd_HkvCnOehB81y9aAS4NEv1wbp0bHqGAuB6kGBNM; report-to cf-xxdwwacdndzihwwx 1 font-src *.googleapis.com *.gstatic.com data: * blob: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com data: blob: *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com * blob: https://static.buckaroo.nl magefan.com cm.magefan.com *.taggrs.io www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com * 'unsafe-inline' 'unsafe-eval' data: blob: https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl *.taggrs.io www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com * 'unsafe-inline' data: blob: https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline' static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com * data: blob: https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://use.typekit.net https://www.goodsalt.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com https://www.goodsalt.com https://td.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com maps.gstatic.com https://www.goodsalt.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://browser.sentry-cdn.com https://cdn.lr-ingest.io maps.googleapis.com https://www.goodsalt.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://www.goodsalt.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io maps.googleapis.com https://www.goodsalt.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'nonce-17c383931e8ad2eaf31240f8fee867aa400b21b8af836418f22f2db0f06b3ccf' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:; img-src 'self' https: data:; base-uri 'none'; frame-ancestors 'self' ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://cdn.userway.org *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com https://td.doubleclick.net www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com https://seal.godaddy.com https://cdn.userway.org https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com https://cdn.userway.org https://www.gstatic.com https://s7.addthis.com https://seal.godaddy.com *.avada.io www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://ajax.googleapis.com https://fonts.googleapis.com https://cdn.userway.org *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://api.userway.org https://cdn.userway.org https://stats.g.doubleclick.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-1e68990b34664fe4b376e05678fd3f0e' https://www.thechristhospitalmychart.com 'self';img-src https://* 'self' blob: data:;style-src https://www.thechristhospitalmychart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com *.googletagmanager.com *.pakketdienstqls.nl 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.apptrian.com imgsct.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com *.multisafepay.com www.xtento.com cdn.xtento.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.klaviyo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com consent.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com *.cookiefirst.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.multisafepay.com tagmanager.google.com fonts.google.com *.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.multisafepay.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.syfpos.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.affirm.com *.affirm.ca *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com syf.demdex.net *.syfpos.com *.syf.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.affirm.com *.affirm.ca *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com *.syfpayments.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.affirm.com *.affirm.ca *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarnaevt.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com *.syfpayments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net assets.braintreegateway.com *.syfpos.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.affirm.com *.affirm.ca *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.sagepay.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.sagepay.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com maps.gstatic.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.sagepay.com maps.googleapis.com www.gstatic.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.sagepay.com www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com data: cdn.checkout.com *.postcodeanywhere.co.uk *.bootstrapcdn.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.securetrading.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.google.com *.trustpilot.com *.checkout.com *.cookiebot.com *.postcodeanywhere.co.uk *.securetrading.net *.doubleclick.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.google.com *.google.co.uk *.zopim.com *.doubleclick.net *.gstatic.com d23yuld0pofhhw.cloudfront.net *.googletagmanager.com *.postcodeanywhere.co.uk *.bing.com *.zdassets.com *.googleapis.com *.lsengineers.co.uk *.google.co.in https://placehold.it *.ayko.com gardenhirespares.co.uk *.placeholder.com placeholder.com http://via.placeholder.com *.arinet.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.googletagmanager.com *.googlecommerce.com *.doubleclick.net *.trustpilot.com *.zopim.com *.zdassets.com *.payments-amazon.com *.amazon.com *.local.com *.googleapis.com *.checkout.com *.pcapredict.com *.trackedweb.net *.cookiebot.com *.adyen.com *.postcodeanywhere.co.uk *.mouseflow.com *.newrelic.com *.nr-data.net *.bing.com *.zendesk.com *.googleadservices.com *.securetrading.net *.zonos.com *.iglobalstores.com *.cookiefirst.com widget.freshworks.com m2epro.freshdesk.com *.arinet.com https://unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.fontawesome.com *.checkout.com *.trackedweb.net *.postcodeanywhere.co.uk *.bootstrapcdn.com *.cookiefirst.com widget.freshworks.com m2epro.freshdesk.com *.arinet.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.zdassets.com *.zopim.com *.amazon.com 'self' wss: *.checkout.com *.trackedweb.net *.postcodeanywhere.co.uk *.google-analytics.com *.doubleclick.net *.nr-data.net *.zendesk.com *.zonos.com *.googleapis.com *.bing.com *.cookiefirst.com widget.freshworks.com m2epro.freshdesk.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.googletagmanager.com/ js.mollie.com www.googletagmanager.com consentcdn.cookiebot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com 'self' data: www.google.fi *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ https://www.mollie.com imgsct.cookiebot.com https://www.maksuturva.fi/ https://test1.maksuturva.fi/ https://payments.maksuturva.fi/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.klevu.com *.ksearchnet.com *.avada.io https://api.unifaun.com js.mollie.com consent.cookiebot.com digitalfeedback.euro.confirmit.com api.custobar.com *.videoly.co payments.maksuturva.fi https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com a.omappapi.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io consentcdn.cookiebot.com www.maksuturva.fi digitalfeedback.euro.confirmit.com https://test1.maksuturva.fi/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src-attr 'none'; script-src 'self' 'unsafe-inline' www.google-analytics.com ajax.googleapis.com; 1 default-src 'none'; media-src 'self'; frame-src 'self' https://*.autopay.io https://stonly.com https://*.stonly.com https://player.vimeo.com *.europe-west1.firebasedatabase.app https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; script-src 'self' *.europe-west1.firebasedatabase.app cdn.ravenjs.com www.google-analytics.com apis.google.com stonly.com https://player.vimeo.com https://plausible.io 'sha256-fwc0mpDa8OHTVGvj46tzJTK/4veec5TxZJQNTFjzBw0=' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ 'unsafe-eval'; connect-src 'self' *.autopay.io *.googleapis.com *.google-analytics.com *.europe-west1.firebasedatabase.app wss://*.europe-west1.firebasedatabase.app sentry.io https://vimeo.com api.pwnedpasswords.com stonly.com *.stonly.com https://plausible.io; img-src 'self' https://storage.googleapis.com/autopay-test-api.appspot.com/ https://storage.googleapis.com/autopay-qa-api.appspot.com/ https://storage.googleapis.com/autopay-prod-api.appspot.com/ https://*.autopay.io/ *.tile.osm.org www.google-analytics.com https://*.vimeocdn.com https://www.gstatic.com data:; style-src 'unsafe-inline' 'self'; font-src data: autopay.io qa.autopay.io test.autopay.io; manifest-src 'self'; frame-ancestors 'self' 1 font-src *.typography.com *.listrakbi.com *.espssl.com/ *.livechatinc.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.livechatinc.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.bing.com *.google.com *.facebook.com *.kaptcha.com *.criteo.com *.criteo.net *.doubleclick.net *.trustpilot.com *.livechatinc.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io store.paradoxlabs.com *.bing.com *.google.com *.facebook.com *.listrakbi.com *.stickyadstv.com *.criteo.com *.tapad.com *.pubmatic.com *.bidswitch.net *.revcontent.com *.addthis.com *.clmbtech.com *.smaato.net *.smartadserver.com *.liadm.com *.postrelease.com *.tremorhub.com *.emxdgt.com *.taboola.com *.sharethrough.com *.360yield.com *.mediavine.com *.yieldmo.com *.outbrain.com *.3lift.com *.media.net *.casalemedia.com *.teads.tv *.adnxs.com *.turn.com pippio.com *.rlcdn.com *.agkn.com *.company-target.com *.bluekai.com *.krxd.net *.rubiconproject.com *.opera.com *.yahoo.com *.jivox.com *.doubleclick.net *.1rx.io *.adsymptotic.com *.nextdoor.com *.tpmn.co.kr *.mediawallahscript.com *.adscale.de *.yieldlab.net *.socdm.com *.omnitagjs.com *.ivitrack.com *.contextweb.com *.rqtrk.eu *.livechatinc.com *.hdis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typography.com *.ywxi.net *.trustpilot.com *.googletagmanager.com *.google-analytics.com *.bing.com *.kaptcha.com *.pepperjam.com *.listrakbi.com *.criteo.com *.criteo.net *.facebook.net *.doubleclick.net *.nextdoor.com *.clarity.ms *.livechatinc.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.typography.com *.listrakbi.com *.espssl.com/ *.livechatinc.com *.hdis.com maxcdn.bootstrapcdn.com unsafe-inline *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazonaws.com *.kaptcha.com *.listrakbi.com *.listrak.com *.doubleclick.net *.criteo.com *.google-analytics.com *.clarity.ms *.facebook.com *.livechatinc.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com https://cdn.idcreator.com *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com https://seo.mageplaza.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.authorize.net https://cdn.justuno.com https://x.adroll.com/ https://idcreator.wufoo.com *.google.com *.addthis.com *.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io store.paradoxlabs.com https://cdn.justuno.com https://c813008.ssl.cf2.rackcdn.com/11192-small.png https://cdn.idcreator.com https://cm.g.doubleclick.net https://www.facebook.com https://www.google.com https://www.google.co.uk https://www.google.com.mx https://www.google.co.in https://www.google.co.ca https://www.google.com.au https://www.google.com.ph https://www.google.com.sg https://www.google.co.za https://www.google.com.br https://www.google.co.nz https://www.google.co.il https://www.google.com.sa https://www.google.com.ar https://www.google.com.co https://www.google.com.vn https://www.google.co.ve https://www.google.com.ua https://www.google.com.tr https://www.google.com.tw https://www.google.com.pk https://www.google.com.my https://www.google.com.pe https://www.shopperapproved.com/thankyou/images/xbutton.gif https://www.shopperapproved.com/thankyou/images/minicheckmark.jpg https://www.shopperapproved.com/thankyou/images/just-powered.png https://www.shopperapproved.com/thankyou/simplestar.png *.cloudfunctions.net *.bidswitch.net *.casalemedia.com *.rlcdn.com *.rubiconproject.com *.outbrain.com *.taboola.com *.adnxs.com *.3lift.com *.yahoo.com *.openx.net *.pubmatic.com https://d.adroll.com https://s.adroll.com https://d.adroll.mgr.consensu.org https://dsum-sec.casalemedia.com https://eb2.3lift.com https://googleads.g.doubleclick.net https://p.adsymptotic.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://pixel.advertising.com https://pixel.rubiconproject.com https://image2.pubmatic.com https://simage2.pubmatic.com https://snap.licdn.com https://sync.outbrain.com https://sync.taboola.com https://trc.taboola.com https://ads.yahoo.com https://ups.analytics.yahoo.com https://connect.facebook.net https://idsync.rlcdn.com https://ib.adnxs.com https://x.bidswitch.net https://www.shopperapproved.com/account/images/2020/sa-logo-02.svg *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.authorize.net *.justuno.com https://cdn.idcreator.com *.facebook.com https://static.cloudflareinsights.com https://static.wufoo.com/scripts/embed/form.js https://www.wufoo.com/scripts/embed/form.js https://www.shopperapproved.com/thankyou/rate/11192.js https://www.shopperapproved.com/thankyou/disable-popup.php https://www.shopperapproved.com/page/js/jquery.noconflict.js https://www.shopperapproved.com/thankyou/initial.php https://d.adroll.com https://s.adroll.com https://d.adroll.mgr.consensu.org https://dsum-sec.casalemedia.com https://eb2.3lift.com https://googleads.g.doubleclick.net https://p.adsymptotic.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://pixel.advertising.com https://pixel.rubiconproject.com https://image2.pubmatic.com https://simage2.pubmatic.com https://snap.licdn.com https://sync.outbrain.com https://sync.taboola.com https://trc.taboola.com https://ads.yahoo.com https://ups.analytics.yahoo.com https://www.facebook.com https://connect.facebook.net https://idsync.rlcdn.com https://ib.adnxs.com https://x.bidswitch.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com https://cdn.idcreator.com https://cdn.justuno.com/ifm_4.1.css https://www.shopperapproved.com/account/css/new_look/custom-survey-error-modal.css *.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://get.geojs.io *.avada.io *.authorize.net *.justuno.com https://analytics.google.com https://www.google.com/pagead/landing https://googleads.g.doubleclick.net/pagead/landing https://cdn.idcreator.com https://stats.g.doubleclick.net *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com trustpilot.com widget.trustpilot.com www.xtento.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net typekit.net www.google.co.uk google.co.uk google.com via.placeholder.com agrilineproducts.com facebook.com www.facebook.com connect.facebook.net www.facebook.com/privacy_sandbox www.google-analytics.com assets.braintreegateway.com checkout.paypal.com b.stats.paypal.com dub.stats.paypal.com www.sandbox.paypal.com cdn.xtento.com www.xtento.com c.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page widget.trustpilot.com js-agent.newrelic.com bam.nr-data.net unpkg.com secure.authorize.net test.authorize.net js.braintreegateway.com video.google.com cdn.xtento.com payments-amazon.com payments-amazon.co.uk payments-amazon.co.jp payments-amazon.jp payments-amazon.it payments-amazon.fr payments-amazon.es trackedlink.net trackedweb.net webchat.dotdigital.com cdn.dnky.co api.comapi.com avada.i yotpo.com staticw2.yotpo.com w2.yotpo.com connect.facebook.net facebook.com www.xtento.com cc-cdn.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com fontawesome.com getfirebug.com cdn.dnky.co webchat.dotdigital.com yotpo.com staticw2.yotpo.com w2.yotpo.com use.typekit.net typekit.net p.typekit.net cc-cdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com paypal.com bam.nr-data.net google-analytics.com stats.g.doubleclick.net google.co.uk api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com fonts.gstatic.com *.magentocommerce.com *.iubenda.com *.zopim.com data: *.b-cdn.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.facebook.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://www.googletagmanager.com/ *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.criteo.com *.criteo.net *.iubenda.com *.youtube-nocookie.com *.youtube.com *.facebook.com cl.avis-verifies.com *.tradedoubler.com a.imgstatics.com https://assets.braintreegateway.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com maps.gstatic.com maps.googleapis.com *.magentocommerce.com *.iubenda.com *.zoorate.com *.feedaty.com *.facebook.com *.google.it *.zopim.com 'self' data: blob: *.rikorda.it *.b-cdn.net googletagmanager.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com maps.googleapis.com cdn.clerk.io api.clerk.io *.magentocommerce.com *.iubenda.com *.criteo.com *.criteo.net *.zoorate.com *.zopim.com *.facebook.com *.facebook.net *.zdassets.com *.sentry-cdn.com *.b-cdn.net *.tradedoubler.com a.imgstatics.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com fonts.googleapis.com *.magentocommerce.com *.iubenda.com *.zoorate.com *.b-cdn.net https://assets.braintreegateway.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.pinterest.com *.pinterdev.com commerce-app.pintergration.com maps.googleapis.com *.magentocommerce.com *.iubenda.com *.zdassets.com wss://*.zopim.com sentry.io 'self' data: blob: *.b-cdn.net *.rikordadev.it *.rikorda.it payments.braintree-api.com client-analytics.braintreegateway.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.b-cdn.net 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com js.stripe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.revolut.com *.google.com *.cdn-apple.com google.com *.gstatic.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.revolut.com *.cdn-apple.com google.com pay.google.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com maps.gstatic.com *.doofinder.com *.facebook.com *.google.it *.google.sm stats.g.doubleclick.net *.kelkoogroup.net *.tradetracker.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.revolut.com *.google.com *.cdn-apple.com google.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com maps.googleapis.com *.adfyier.com *.admediasales.com *.bannercrowd.net sibautomation.com *.clerk.io *.doofinder.com *.hotjar.com *.kk-resources.com *.optimalpeople.fr shop-cart.app *.tradedoubler.com *.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.doofinder.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com *.brevo.com *.doofinder.com wss://eu1-layer.doofinder.com/ wss://eu1-recommendations.doofinder.com/ *.facebook.com wss://ws.hotjar.com/ *.hotjar.io/ *.kelkoogroup.net *.optimalpeople.fr 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com *.hsforms.net *.hsforms.com 'self' data: *.cdninstagram.com *.fbcdn.net *.google.co.in *.sansha.com *.magento2.sansha.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleadservices.com *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.cardinalcommerce.com *.ccdc02.com *.paypalobjects.com *.ytimg.com *.googleapis.com *.vimeo.eu *.vimeo.com *.gstatic.com *.omtrdc.net *.mailchimp.com *.braintreegateway.com *.packeta.com *.app-wallee.com *.cdek.ru *.chronopost.fr *.authorize.net *.stripe.com *.hsforms.net *.hsforms.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.instagram.com maps.googleapis.com klarna.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com embed.tawk.to *.tawk.to *.jsdelivr.net www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com embed.tawk.to *.tawk.to *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com embed.tawk.to *.tawk.to *.jsdelivr.net vsa104.tawk.to vsa94.tawk.to vsa79.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src *.force.com https://player.vimeo.com 'self' https://js.monitor.azure.com https://stats.g.doubleclick.net *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://www.johnsoncontrols.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es https://*.tags.tiqcdn.com https://tyco.widen.net *.adis.ws https://jcibuildings.ca1.qualtrics.com https://www.gstatic.com https://jcibe.file.force.com https://www.upgnetsap.com *.hvacnavigator.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://jcpublic.kzoplatform.com https://pay.google.com https://miller-picking.rpiconnect.net *.vimeo.com *.youtube.jp bcove.video *.youtube.fr https://dc.services.visualstudio.com https://*.a.forceusercontent.com https://player.cloudinary.com https://cdnjs.cloudflare.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net https://*.tealiumiq.com tags.tiqcdn.com *.youtube.nl https://docs.johnsoncontrols.com https://service.force.com/embeddedservice/ https://*.coveo.com https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com https://my.tealiumiq.com *.youtube.com.br https://*.www.google-analytics.com https://siteintercept.qualtrics.com *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://*.selectionnavigator.com https://www.upgnet.com https://checkoutshopper-live.adyen.com/ https://*.walkme.com *.sfdcfc.net https://www.ductedsystemsacademy.com *.youtube.ca https://znefnyywi9pon9a8u-jcibuildings.siteintercept.qualtrics.com https://location.force.com *.vidyard.com https://*.trustarc.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://res.cloudinary.com https://na254.salesforce.com https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://www.kwikstrut.com https://qtoolkit.rpiconnect.net https://*.msecnd.net https://*.qualtrics.com https://*.a.forceusercontent.com/lightningmaps/ https://hvacnavigator.brandmuscle.net *.wistia.net https://www.google-analytics.com *.salesforce.com https://xiecomm.worldpay.com *.youtube.pl https://*.truste.com; report-to sfdc-csp-ep; report-uri https://jcibe.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00DG0000000hBll&networkId=0DM4w000000GsE3&type=communities 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:; script-src 'self' https://*.googletagmanager.com 'nonce-4603a3e4063c3268faad691c9b7ab7c1' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; style-src 'self' 'nonce-4603a3e4063c3268faad691c9b7ab7c1' https://fonts.googleapis.com; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; frame-ancestors 'self'; 1 font-src https://*.salesforceliveagent.com *.force.com https://rx-label-api.scriptsrxpharmacy.com https://fonts.gstatic.com/ 'self' https://scriptsrx.my.salesforce-sites.com https://www.fensolvitotalsolutions.com *.salesforce.com https://scriptsrx.my.site.com blob: https://novospatientsolutions.secure.force.com data:; report-to sfdc-csp-ep; report-uri https://scriptsrx.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D46000000qngH&networkId=0DM8Y000000g2XG&type=communities 1 default-src 'self'; script-src 'self' 'nonce-ivITPTLVODbqAGB1Yu_2N2Ky5KZKcjAAYneU_jcTb_CXwuBVnghebQ' 'strict-dynamic' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data:; base-uri 'self'; font-src 'self' data:; style-src-elem 'self' 'nonce-ivITPTLVODbqAGB1Yu_2N2Ky5KZKcjAAYneU_jcTb_CXwuBVnghebQ' report-sample 'report-sample'; worker-src blob: 'report-sample'; style-src 'self' 'nonce-ivITPTLVODbqAGB1Yu_2N2Ky5KZKcjAAYneU_jcTb_CXwuBVnghebQ' 'report-sample'; connect-src 'self' piwik.f7.de; report-uri https://f7.de/@http-reporting?csp=report&requestTime=1765943670489616&requestHash=6e5e6a307bc4f4eb73d47a6082527d0f7b20f16e 1 report-uri https://sentry.x-onweb.com/api/16/security/?sentry_key=fde8c4b479fa405e8ebe62bcea27a8d8;base-uri 'self';connect-src 'self' https://analytics.x-onweb.com https://sentry.x-onweb.com;default-src 'self';img-src 'self' images.x-onweb.com https://analytics.x-onweb.com;media-src 'self';object-src 'none';script-src 'self' 'nonce-2NxrL0Xsaqh6ujLOgp1CqaLqzVCFAuqV' https://analytics.x-onweb.com;style-src 'self' fonts.googleapis.com 'unsafe-inline';font-src 'self' fonts.gstatic.com 1 font-src *.sitejabber.com *.gstatic.com *.nexcesscdn.net https://fonts.gstatic.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.google.com *.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.com td.doubleclick.net *.dotdigital-pages.com *.dotdigital.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.amazonaws.com *.postcodeanywhere.co.uk *.cloudfront.net *.godaddy.com *.sitejabber.com *.sixity.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.facebook.com *.bing.com *.analytics.yahoo.com *.wistia.com *.nexcesscdn.net google.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.trackedlink.net https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com *.google-analytics.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com data.stats.tools *.googleadservices.com *.googlesyndication.com *.g.doubleclick.net *.googleapis.com *.google.com *.sitejabber.com *.searchspring.net *.capredict.com *.pcapredict.com *.godaddy.com *.addressy.com *.bing.com *.facebook.net *.yimg.com *.pepperjam.com *.wistia.com *.clarity.ms *.nexcesscdn.net *.gstatic.com *.sentry-cdn.com *.klarnacdn.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://*.helloextend.com *.klarna.com *.klarnaservices.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.addressy.com *.sitejabber.com *.searchspring.net *.googleapis.com *.nexcesscdn.net https://fonts.googleapis.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.wistia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com *.addressy.com *.searchspring.io *.sitejabber.com *.googletagmanager.com *.googleadservices.com *.googlesyndication.com *.g.doubleclick.net *.analytics.google.com *.yimg.com *.attentivemobile.com *.wistia.com *.litix.io *.amazonaws.com *.clarity.ms *.bing.com *.nexcesscdn.net google.com/ *.google.com google.com/pay *.klarna.com/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.helloextend.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com analytics.google.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com data: *.wistia.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.doubleclick.net *.googletagmanager.com sketchfab.com *.wistia.net *.wistia.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com magefan.com cm.magefan.com *.hubspot.com *.bing.com *.bing.net *.facebook.com *.elfsight.com *.elfsightcdn.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.clarity.ms tracking.monsido.com *.wistia.net *.wistia.com *.hsforms.net *.hsforms.com *.disqus.com https://img.youtube.com 'self' data: *.gstatic.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ unpkg.com *.osano.com *.hubspot.com js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hscollectedforms.net js.hs-banner.com *.hscollectedforms.net *.sketchfab.com *.bing.com connect.facebook.net *.elfsight.com *.sentry-cdn.com *.clarity.ms app-script.monsido.com *.wistia.net *.wistia.com *.hsforms.net *.hsforms.com *.disqus.com *.google.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net https://app-script.monsido.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.wistia.net *.wistia.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src blob: *.wistia.net *.wistia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.osano.com *.google.com *.wistia.com *.elfsight.com *.bing.com *.bing.net *.doubleclick.net *.hubspot.com *.hubapi.com *.hscollectedforms.net static.hsappstatic.net *.litix.io *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.clarity.ms t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.wistia.net *.wistia.com 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://www.googletagmanager.com https://connect.facebook.net https://cdn-cookieyes.com https://go.pardot.com https://static.hotjar.com https://script.hotjar.com https://plugins.flockler.com cdn.jsdelivr.net https://addevent.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com https://www.google.com mdbootstrap.com; script-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://www.googletagmanager.com https://connect.facebook.net https://cdn-cookieyes.com https://go.pardot.com https://static.hotjar.com https://script.hotjar.com https://plugins.flockler.com cdn.jsdelivr.net https://addevent.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com https://www.google.com mdbootstrap.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://www.googletagmanager.com https://connect.facebook.net https://cdn-cookieyes.com https://go.pardot.com https://static.hotjar.com https://script.hotjar.com https://plugins.flockler.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://www.googletagmanager.com https://connect.facebook.net https://cdn-cookieyes.com https://go.pardot.com https://static.hotjar.com https://script.hotjar.com https://plugins.flockler.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self' sentry.io; connect-src 'self' https://talent-assets.hubstaff.com hubstaff-talent.s3.amazonaws.com maps.googleapis.com securepubads.g.doubleclick.net pagead2.googlesyndication.com cdn.segment.com api.segment.io account.hubstaff.com talent.hubstaff.com ep1.adtrafficquality.google www.gstatic.com translate.googleapis.com csi.gstatic.com www.google-analytics.com overbridgenet.com; font-src hubstafftalent.net https://talent-assets.hubstaff.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: frontdoorcdn.mindverse.ai images.simplycodes.com ray.st static.hsappstatic.net; frame-src *.safeframe.googlesyndication.com www.google.com securepubads.g.doubleclick.net tpc.googlesyndication.com hubstafftalent.net ep2.adtrafficquality.google; img-src 'self' data: https: https://talent-assets.hubstaff.com maps.googleapis.com pagead2.googlesyndication.com blob:; media-src 'self' data:; script-src 'unsafe-eval' 'unsafe-inline' https://talent-assets.hubstaff.com maps.googleapis.com cdn.segment.com securepubads.g.doubleclick.net tpc.googlesyndication.com cdnjs.cloudflare.com ajax.cloudflare.com hubstafftalent.net static.cloudflareinsights.com www.gstatic.com; script-src-attr 'unsafe-inline'; script-src-elem 'unsafe-inline' https://talent-assets.hubstaff.com maps.googleapis.com tpc.googlesyndication.com securepubads.g.doubleclick.net ajax.cloudflare.com cdn.segment.com ep2.adtrafficquality.google static.cloudflareinsights.com www.gstatic.com hubstafftalent.net blob: connect.facebook.net infird.com pagead2.googlesyndication.com; style-src 'unsafe-inline' https://talent-assets.hubstaff.com fonts.googleapis.com maxcdn.bootstrapcdn.com www.gstatic.com; style-src-attr 'unsafe-inline'; style-src-elem 'unsafe-inline' hubstafftalent.net https://talent-assets.hubstaff.com fonts.googleapis.com maxcdn.bootstrapcdn.com adblockers.opera-mini.net www.gstatic.com; report-uri https://hubstaff.report-uri.com/r/t/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.cloudflare.com *.googleapis.com https://www.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com cdn.honey.io *.timpson.com a.omappapi.com z.omappapi.com *.fontawesome.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sandbox.paypal.com *.paypalobjects.com *.timpson-group.co.uk paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.doubleclick.net *.bing.com *.twitter.com https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk paypal.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com birdeye.com *.birdeye.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com *.googlesyndication.com account.fetchify.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.maxphoto.co.uk *.tescophoto.com *.snappysnaps.co.uk photo.asda.com ap.affinity-dev.co.uk *.cloudfront.net blob: *.googleadservices.com *.klarna.com *.lightemporium.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com https://*.google.com google.com *.googleapis.com *.static.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com www.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat analytics.tiktok.com images.timpson.co.uk *.timpsonlocksmiths.co.uk *.timpsonsecurity.co.uk lantern.roeye.com a.omappapi.com z.omappapi.com *.magentocommerce.com birdeye.com *.birdeye.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com g3d-app.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.popupsmart.com *.doubleclick.net cdn.mouseflow.com analytics.tiktok.com a.omappapi.com cdn.studentbeans.com connect.facebook.net birdeye.com *.birdeye.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.google.bg *.facebook.com *.facebook.net *.gstatic.com *.googlesyndication.com *.soreto.com cc-cdn.com g3d-app.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com https://cdnjs.cloudflare.com www.xtento.com cdn.xtento.com https://www.snappysnaps.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu https://fonts.googleapis.com google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net a.omappapi.com *.timpson.com birdeye.com *.birdeye.com assets.braintreegateway.com *.facebook.com *.googlesyndication.com cc-cdn.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.twitter.com *.twimg.com https://*.google.com *.google.co.uk *.google.ie *.google.fr *.google.de *.google.se *.google.nl *.google.dk *.google.it *.google.ca *.google.es google.co.uk *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net api.omappapi.com analytics.tiktok.com analytics-ipv6.tiktokw.us eu01.rec.mouseflow.com *.omappapi.com a.omappapi.com z.omappapi.com kg668dbov0.execute-api.us-east-1.amazonaws.com birdeye.com *.birdeye.com rum.hlx.page *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com *.awinblackfriday.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com g3d-app.com https://ipinfo.io https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report.centralcsp.com/6814d628f6bc10d374666be2; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.googletagmanager.com https://accounts.google.com https://app.productfruits.com https://maps.google.com https://www.bing.com https://r.bing.com https://*.googleapis.com https://js.api.here.com https://traffic.ls.hereapi.com https://*.amap.com https://api-maps.yandex.ru https://yastatic.net https://hst-api.wialon.com;style-src 'self' 'unsafe-inline' https://app.productfruits.com https://fonts.googleapis.com https://r.bing.com;img-src 'self' data: blob: https:;connect-src 'self' https://*.productfruits.com wss://ws2.productfruits.com https://*.google-analytics.com https://maps.googleapis.com https://*.amap.com https://*.mapbox.com https://*.maps.ls.hereapi.com https://vector.hereapi.com https://js.api.here.com https://*.wialon.com https://*.wialon.net blob:;frame-src 'self' https://hst-api.wialon.com https://geocode-maps.wialon.com;form-action 'self' https://hst-api.wialon.com;object-src 'none';frame-ancestors *;worker-src 'self' blob:;font-src 'self' data: https:;media-src 'self' blob: https:; report-uri https://sentry-new.wialon.net/api/91/security/?sentry_key=7ee88f41a9457af92483172d09fb61c4; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.aligent.dev:5173 webchat.dotdigital.com webchat.staging.dotdigital.com https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googleapis.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.aligent.dev:5173 webchat.dotdigital.com webchat.staging.dotdigital.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.kcare.com.au peggs.com.au 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.aligent.dev:5173 wss://*.aligent.dev:5173 https://maps.googleapis.com/maps/api/ webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5e1eb541-9ce3-4111-8f88-16f9b1c99bf5.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com *.klevu.com *.ksearchnet.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com consentcdn.cookiebot.com secure.livechatinc.com *.vimeo.com *.sandbox.paypal.com schulershoes.fullslate.com tst.kaptcha.com *.socialannex.com *.socialannex.net *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://*.gstatic.com *.klevu.com *.ksearchnet.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://redchamps.com *.stats.paypal.com *.sandbox.paypal.com cdn.livechat-files.com schulershoes-magento.s3.amazonaws.com ss-stg-magento.s3.amazonaws.com meetanshi.com maps.googleapis.com *.socialannex.com *.socialannex.net tn.alphonso.tv *.tvsquared.com bat.bing.com www.facebook.com connect.facebook.net cdn.ywxi.net imgsct.cookiebot.com jumbe.zaius.com api.zaius.com guarantee-cdn.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com apis.google.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.klevu.com *.ksearchnet.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.fontawesome.com *.cookiebot.com cdn.ywxi.net cdn.jsdelivr.net *.livechatinc.com acsbapp.com d1igp3oop3iho5.cloudfront.net *.socialannex.com *.socialannex.net maxcdn.bootstrapcdn.com *.cardinalcommerce.com bat.bing.com connect.facebook.com connect.facebook.net *.mountain.com *.tvsquared.com tag.simpli.fi onlinedialogue.s3.amazonaws.com www.trustedsite.com *.clarity.ms *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.vimeo.com *.socialannex.com *.socialannex.net maxcdn.bootstrapcdn.com cdn.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com s3-us-west-2.amazonaws.com *.acsbapp.com tn.alphonso.tv bat.bing.com *.livechatinc.com maps.google.com maps.googleapis.com *.g.doubleclick.net *.socialannex.com *.socialannex.net consentcdn.cookiebot.com www.facebook.com www.facebook.net kg668dbov0.execute-api.us-east-1.amazonaws.com 3.212.39.155 18.210.229.244 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 100.20.58.101 *.clarity.ms s3.amazonaws.com d1igp3oop3iho5.cloudfront.net *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app schuler-apicentral.ddev.site apicentral.local.schulershoes.com schuler-apicentral-main-e92vxj.laravel.cloud apicentral.schulershoes.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-J4iFDd8EY_CZqkm1IsiT5Q' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com https://static.unzer.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com https://*.cookiebot.com www.facebook.com *.trustpilot.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net https://stats.g.doubleclick.net *.googletagmanager.com *.gstatic.com https://www.google.de https://services.postcodeanywhere.co.uk https://*.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://dildoking.de https://*.dildoking.de https://*.cloudfront.net *.hsforms.net *.hsforms.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg https://www.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://*.cookiebot.com https://rec.smartlook.com https://click11202.pcapredict.com https://services.postcodeanywhere.co.uk jsd-widget.atlassian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://js-agent.newrelic.com https://*.channeladvisor.com https://*.payments-amazon.com https://bam.nr-data.net *.hsforms.net *.hsforms.com www.gstatic.com connect.facebook.net *.trustpilot.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://services.postcodeanywhere.co.uk https://static.klaviyo.com www.gstatic.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://clickpool.tt.omtrdc.net https://*.cookiebot.com https://*.smartlook.cloud https://googleads.g.doubleclick.net https://services.postcodeanywhere.co.uk https://pagead2.googlesyndication.com jsd-widget.atlassian.com api-private.atlassian.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.paypal.com https://*.amazon.com https://bam.nr-data.net t.elasticsuite.io *.hsforms.net *.hsforms.com www.googleapis.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ccbuchner.de www.ccbuchner.de https://secure.ogone.com https://ogone.test.v-psp.com captcha.wirth-horn.de cookiemanager.wirth-horn.de whstatistics-api.wirth-horn.de https://www.click-and-teach.de https://www.click-and-study.de https://www.google-analytics.com https://tagmanager.google.com https://www.googletagmanager.com https://www.googleadservices.com https://adservice.google.com *.g.doubleclick.net https://*.googleapis.com https://connect.facebook.net https://www.facebook.com https://www.youtube.com https://www.youtube-nocookie.com https://*.googleusercontent.com https://www.instagram.com 'unsafe-eval' 'unsafe-inline'; img-src data: *; media-src *; font-src data: 'self' https://fonts.gstatic.com https://fonts.googleapis.com https://services.ccbuchner.de; report-uri /csp-report.cfm 1 default-src 'self' https://www.youtube.com; connect-src 'self' https://metrics.hotjar.io https://www.google.com https://content.hotjar.io wss://ws.hotjar.com https://vc.hotjar.io https://stats.g.doubleclick.net https://www.google-analytics.com https://analytics.google.com https://www.googleadservices.com https://load.collect.chat https://www.google.co.in https://api.collect.chat https://secure.ccavenue.com https://googleads.g.doubleclick.net https://jnn-pa.googleapis.com https://play.google.com https://onesignal.com https://*.googlevideo.com https://securegw.paytm.in; img-src 'self' http://myamcat.com https://googleads.g.doubleclick.net https://ssl.google-analytics.com https://connect.facebook.net https://www.google-analytics.com https://www.googletagmanager.com https://www.google.co.in https://www.google.com https://www.facebook.com https://d1igbv7ujk9jkv.cloudfront.net https://d13dtqinv406lk.cloudfront.net https://dujk9xa5fr1wz.cloudfront.net https://s3.amazonaws.com https://www.gstatic.com https://ssl.gstatic.com https://i.ytimg.com https://yt3.ggpht.com https://avatars.collectcdn.com https://collectcdn.com https://dashboard.ccavenue.com https://secure.ccavenue.com https://www.edx.org https://www.udemy.com data:; font-src 'self' https://collectcdn.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://stackpath.bootstrapcdn.com data:; style-src 'self' 'unsafe-inline' https://code.jquery.com https://www.gstatic.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://stackpath.bootstrapcdn.com https://onesignal.com https://secure.ccavenue.com; media-src 'self' https://collectcdn.com https://www.youtube-nocookie.com https://*.googlevideo.com blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://onesignal.com https://ssl.google-analytics.com https://storage.googleapis.com https://widgets.getsitecontrol.com https://www.google-analytics.com https://diffuser-cdn.app-us1.com https://www.googletagmanager.com https://www.gstatic.com https://static.hotjar.com https://s3.amazonaws.com https://collectcdn.com https://script.hotjar.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://code.jquery.com https://connect.facebook.net https://survey.survicate.com https://prism.app-us1.com https://www.google.com https://maxcdn.bootstrapcdn.com https://www.s.ytimg.com https://static.doubleclick.net https://cdn.onesignal.com https://secure.ccavenue.com/scripts/ https://securegw.paytm.in; object-src 'self' http://www.vimeo.com; base-uri 'self'; form-action 'self' 'unsafe-inline' https://www.facebook.com https://www.google.com https://secure.ccavenue.com https://securegw.paytm.in; frame-ancestors 'self'; frame-src 'self' https://bid.g.doubleclick.net https://td.doubleclick.net https://www.facebook.com https://www.google.com https://player.youku.com https://content.googleapis.com https://accounts.google.com 1 font-src data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://connect.ekomi.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://connect.ekomi.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 connect-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com *.clarity.ms *.google.com *.cookiefirst.com *.thuiswinkel-cdn.org s3.eu-west-1.amazonaws.com *.bing.com google.com *.hotjar.io *.google-analytics.com *.facebook.com *.bing.net *.googlesyndication.com *.marker.io *.googleadservices.com *.trustpilot.com *.tiktok.com *.doubleclick.net *.bounce-commerce.de *.thuiswinkel.org *.pinterest.com *.facebook.net *.googletagmanager.com; default-src 'self' 'unsafe-inline' 'unsafe-eval' *.facebook.net www.google.be *.clarity.ms *.googlesyndication.com *.hotjar.com *.googletagmanager.com *.google.com *.tiktok.com *.hotjar.io *.google-analytics.com *.mailplus.nl *.squeezely.tech *.cookiefirst.com *.bounce-commerce.de *.bing.com *.doubleclick.net *.thuiswinkel-cdn.org www.google.de google.com *.bing.net *.googleadservices.com *.pinterest.com www.google.pt *.facebook.com www.google.dk *.gstatic.com www.google.nl; img-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.facebook.com www.google.nl *.squeezely.tech *.thuiswinkel-cdn.org *.bing.net www.google.at s3.amazonaws.com www.google.pl google.com www.google.dk *.gstatic.com www.google.pt www.google.be www.google.ru *.bing.com www.google.it www.google.ch *.mailplus.nl *.facebook.net *.google.com www.google.de *.doubleclick.net *.googlesyndication.com www.google.es *.tiktok.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.co.uk *.cookiefirst.com *.googleadservices.com *.pinterest.com *.clarity.ms www.google.cz www.google.fr; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.multisafepay.com *.pinimg.com *.hotjar.com *.bounce-commerce.de *.clarity.ms *.tiktok.com *.googleadservices.com squeezely.tech *.googlesyndication.com *.mailplus.nl *.trustpilot.com *.doubleclick.net *.pinterest.com *.cookiefirst.com *.thuiswinkel-cdn.org *.google.com *.bing.com vercel.live *.marker.io *.thuiswinkel.org *.facebook.com *.facebook.net; frame-src 'self' 'unsafe-inline' 'unsafe-eval' *.pinterest.com *.thuiswinkel.org *.facebook.com *.trustpilot.com *.googletagmanager.com vercel.live *.thuiswinkel-cdn.org *.google.com google.com *.doubleclick.net *.bing.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.multisafepay.com *.thuiswinkel-cdn.org *.gstatic.com *.cookiefirst.com *.googletagmanager.com; font-src 'self' 'unsafe-inline' 'unsafe-eval' *.thuiswinkel-cdn.org *.gstatic.com; report-uri https://4c3df516-da08-401d-9e6c-648b320e74ec.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com https://css.zohocdn.com/ https://d19ayerf5ehaab.cloudfront.net/ https://d1azc1qln24ryf.cloudfront.net/ https://*.hotjar.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://www.facebook.com/ https://0merchantacsstag.cardinalcommerce.com/ https://1merchantacsstag.cardinalcommerce.com/ *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://widget.reviews.co.uk/ https://gum.criteo.com/ https://*.hotjar.com/ https://www.paypalobjects.com/ https://c.sandbox.paypal.com/ https://tst.kaptcha.com/ *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.google.com/ https://www.google.co.uk/ https://bat.bing.com/ https://www.facebook.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://cm.g.doubleclick.net/ https://r.casalemedia.com/ https://ad.360yield.com/ https://contextual.media.net/ https://exchange.mediavine.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://pixel.rubiconproject.com/ https://match.sharethrough.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://ad.yieldlab.net/ https://cm.adform.net/ https://visitor.omnitagjs.com/ https://gum.criteo.com/ https://id5-sync.com/ https://ad.sxp.smartclip.net/ https://criteo-partners.tremorhub.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://beacon.krxd.net/ https://s.thebrighttag.com/ https://rtb-csync.smartadserver.com/ https://widget.eu.criteo.com/ https://assets.reviews.io/ https://matching.ivitrack.com/ https://www.lyco.co.uk/ https://uat.lyco.co.uk/ https://c.sandbox.paypal.com/ https://services.postcodeanywhere.co.uk/ https://*.google-analytics.com/ https://*.analytics.google.com/ https://*.hotjar.com/ https://imgs.cdn-btsg.com/ https://secure.adnxs.com/ https://bam.nr-data.net/ *.cloudfront.net *.reviews.io *.reviews.co.uk https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com bat.bing.com https://connect.facebook.net/ https://static.criteo.net/ https://widget.reviews.co.uk/ https://salesiq.zoho.eu/ https://analytics.webgains.io/ https://googleads.g.doubleclick.net/ https://www.clarity.ms/ https://*.hotjar.com/ https://sslwidget.criteo.com/ https://js-agent.newrelic.com/ https://js.zohocdn.com/ https://bam.nr-data.net/ https://widget.eu.criteo.com/ https://v2.zopim.com/ https://static.zdassets.com/ https://ekr.zdassets.com/ https://lycod11120.pcapredict.com/ https://services.postcodeanywhere.co.uk/ https://track.webgains.com/ https://songbirdstag.cardinalcommerce.com/ *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.google.com https://www.gstatic.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com https://css.zohocdn.com/ https://widget.reviews.co.uk/ https://d19ayerf5ehaab.cloudfront.net/ https://d1azc1qln24ryf.cloudfront.net/ https://services.postcodeanywhere.co.uk/ https://*.hotjar.com/ data: *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://stats.g.doubleclick.net/ https://l.clarity.ms/ https://salesiq.zoho.eu/ wss://vts.zohopublic.eu/ https://bam.nr-data.net/ https://salesiq.zohopublic.eu/ https://vts.zohopublic.eu/ https://api-cache.reviews.co.uk/ https://api.reviews.co.uk/ https://k.clarity.ms/ https://a.clarity.ms/collect https://region1.analytics.google.com/ wss://*.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ https://api.reviews.io/ https://services.postcodeanywhere.co.uk/ https://api.webgains.io/ https://kg668dbov0.execute-api.us-east-1.amazonaws.com/ https://writer.cardinalcommerce.com/ https://m1.openfpcdn.io/ https://*.google-analytics.com/ https://*.analytics.google.com/ https://ekr.zdassets.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://bfbb229d-bd4f-43f8-9f4d-4b9425ab248a.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.cloudflare.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net apis.google.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googletagmanager.com *.google.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com *.facebook.com *.facebook.net *.adobedc.net *.googleadservices.com *.paypalobjects.com *.geojs.io *.google.co.in widgets.pinterest.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.googletagmanager.com *.google.com/recaptcha/ *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com *.facebook.com *.facebook.net widgets.pinterest.com *.popupsmart.com *.googleadservices.com *.paypal.com *.paypalobjects.com energy-java-2540.my.site.com/ *.picreel.com *.disqus.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cloudflare.com energy-java-2540.my.site.com/ *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com apis.google.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com *.facebook.com *.facebook.net *.adobedc.net *.googleadservices.com *.paypalobjects.com *.geojs.io widgets.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.googletagmanager.com *.picreel.com *.popupsmart.com *.salesforce-scrt.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.google.com https://www.googletagmanager.com https://cdn.migros.ch https://cdnjs.cloudflare.com https://www.gstatic.com; style-src 'self' 'unsafe-inline'; font-src 'self' https://cdn.migros.ch data:; img-src 'self' https://cdn.migros.ch https://secure.gravatar.com data:; frame-src 'self' https://login.migros.ch https://*.activfitness.ch; frame-ancestors 'self' https://login.migros.ch https://*.activfitness.ch https://www.migros.ch; connect-src 'self' https://login.migros.ch; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.bootstrapcdn.com *.jsdelivr.net *.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://*.dpdconnect.nl js.mollie.com *.trustpilot.com *.hotjar.com *.googletagmanager.com *.cookiebot.eu *.pinterest.com *.twitter.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://www.mollie.com https://redchamps.com *.cloudimg.io www.sleiderink.nl staging.sleiderink.nl sleiderinkupd.hypernode.io *.cloudflare.com *.cloudimage.io *.linkedin.com *.adsymptotic.com *.google.nl *.trengo.eu *.bing.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://*.dpdconnect.nl https://browser.sentry-cdn.com js.mollie.com *.cloudimg.io *.scaleflex.it *.cloudflare.com *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.chimpstatic.com *.adobetm.com *.adobe.com polyfill.io *.cookiebot.eu *.bing.com *.clarity.ms *.clarity.ms/collect *.pinimg.com *.pinterest.com *.trengo.eu *.twimg.com *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com *.cloudimg.io *.scaleflex.it *.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io *.cloudflare.com *.pingdom.net *.hotjar.com *.usercentrics.eu *.pinterest.com *.bing.com *.trengo.eu *.clarity.ms *.clarity.ms/collect *.cookiebot.eu *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sleiderink.dev/; report-to report-endpoint; 1 default-src 'self' https: data: 'unsafe-inline';report-uri https://agrian.com/global/csp_report/ 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' assets.ceros.com media.ceros.com view.ceros.com play.vidyard.com assets.vidyard.com www.googletagmanager.com snap.licdn.com up.pixel.ad www.google-analytics.com *.hs-sites.com *.hubspotusercontent-na1.net js.hs-banner.com js.hs-analytics.net js.hubspot.com *.hsappstatic.net js.hscollectedforms.net ajax.googleapis.com googleads.g.doubleclick.net static.doubleclick.net www.google.com vidassets.terminus.services cookie-script.com *.cookie-script.com cdn.rollbar.com kit.fontawesome.com www.gstatic.com www.youtube.com platform.linkedin.com connect.facebook.net platform.twitter.com; object-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.riverty.design/ *.fontawesome.com * robincontentdesktop.blob.core.windows.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com uc8.tv * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com uc8.tv https://documents.riverty.com/ * *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com *.prism.app-us1.com *.prismic.io *.facebook.com * *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com *.prism.app-us1.com *.prismic.io *.googletagmanager.com *.facebook.net * https://widget-acc.paazl.com https://api-acc.paazl.com/ *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com * https://widget-acc.paazl.com https://api-acc.paazl.com/ *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com *.prism.app-us1.com *.prismic.io * https://widget-acc.paazl.com https://api-acc.paazl.com/ *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://4c701c01-85ba-408b-96cc-0fd2ab244242.sansec.watch/; report-to report-endpoint; 1 default-src 'self' data: blob: ; script-src data: blob: 'unsafe-inline' 'unsafe-eval' 'self' https://seal.digicert.com https://www.googletagmanager.com/gtm.js https://cdn.cookielaw.org *.sitejabber.com https://www.youtube.com; style-src 'self' data: blob: 'unsafe-inline' https://fonts.googleapis.com https://static.sitejabber.com; connect-src 'self' data: blob: ws: wss: https://www.sitejabber.com https://cdn.cookielaw.org; img-src 'self' data: blob: 'unsafe-inline' https://seal-dallas.bbb.org https://seal.digicert.com https://static.sitejabber.com https://cdn.cookielaw.org https://secure.gravatar.com; font-src 'self' data: blob: https://fonts.gstatic.com https://static.sitejabber.com; frame-ancestors 'self'; frame-src https://www.youtube.com; report-to ot-reporter; report-uri https://xtvenwskmk.execute-api.us-east-1.amazonaws.com/infosec; 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://*.mcfarlandclinic.com https://*.mgmc.org https://*.mychartiowa.com https://beta---online-checkin-ae65ecrdlq-uc.a.run.app/ https://covid-vaccine-scheduler-dev-ae65ecrdlq-uc.a.run.app https://demosched.mcfarlandclinic.com https://hvprdweb0046.hv.local https://hvprdweb0047.hv.local https://mcfarlandclinic.com https://mychartiowa.com https://prd-mychart03.hv.local https://prd-mychart04.hv.local;frame-src https://* 'self' * epichttp: https://mychart.personapay.com https://pay.instamed.com https://www.google.com https://www.recaptcha.net;script-src https://www.mychartiowa.com 'self' 'unsafe-inline' https://www.google.com https://www.gstatic.com;img-src https://* 'self' * blob: data: https://www.google.com https://www.gstatic.com;connect-src 'self' epichttp: https://www.google.com https://www.gstatic.com;style-src https://www.mychartiowa.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:;report-uri https://www.mcfarlandclinic.com; 1 child-src 'self' https://*.vimeo.com https://*.youtube.com; connect-src 'self' data: *.google-analytics.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://cdn.lordicon.com https://consentcdn.cookiebot.com https://dc.services.visualstudio.com https://esp-eu.aptrinsic.com https://eu01.rec.mouseflow.com https://googleads.g.doubleclick.net https://img.youtube.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://t.co https://translate.googleapis.com https://www.facebook.com https://www.google.com https://www.google.nl https://www.googletagmanager.com https://yuverta.piwik.pro; default-src 'self'; font-src 'self' data: https://cdn.faceworks.nl https://dhm5hy2vn8l0l.cloudfront.net https://fonts.gstatic.com; frame-src 'self' https://consentcdn.cookiebot.com https://manager.emea01.idio.episerver.net https://player.vimeo.com https://stagemarkt.nl https://tr.snapchat.com https://vars.hotjar.com/ https://www.facebook.com https://www.google.com https://www.google.nl https://www.googletagmanager.com https://www.youtube.com; img-src 'self' blob: data: https://*.linkedin.com https://a.emea01.idio.episerver.net https://analytics.tiktok.com https://analytics.twitter.com https://connect.facebook.net https://examenbundel.nl https://fonts.gstatic.com https://googleads.g.doubleclick.net https://i.ytimg.com https://img.youtube.com https://imgsct.cookiebot.com https://maps.googleapis.com https://maps.gstatic.com https://pagead2.googlesyndication.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://t.co https://tr.snapchat.com https://www.facebook.com https://www.google.com https://www.google.nl https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' blob: https://analytics.tiktok.com https://cdn.jsdelivr.net https://cdn.lordicon.com https://cdn.mouseflow.com https://cdnjs.cloudflare.com https://code.jquery.com https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://js.monitor.azure.com https://lf16-tiktok-common.ttwstatic.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com https://pagead2.googlesyndication.com https://s.emea01.idio.episerver.net https://sc-static.net https://snap.licdn.com https://static.ads-twitter.com https://web-sdk-eu.aptrinsic.com https://www.googletagmanager.com https://www.youtube.com https://yuverta.piwik.pro; script-src 'self' 'unsafe-eval' *.google-analytics.com https://*.hotjar.com https://ajax.googleapis.com https://api.emea01.idio.episerver.net https://cdn.jsdelivr.net https://cdn.lordicon.com https://cdn.mouseflow.com https://cdnjs.cloudflare.com/ https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js.monitor.azure.com https://maps.googleapis.com https://s.emea01.idio.episerver.net https://sc-static.net https://snap.licdn.com https://www.googletagmanager.com https://www.youtube.com; style-src-attr 'self' 'unsafe-inline' https://cdn.lordicon.com https://consent.cookiebot.com; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.lordicon.com https://consent.cookiebot.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://web-sdk-eu.aptrinsic.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.lordicon.com https://consent.cookiebot.com https://fonts.googleapis.com https://www.googletagmanager.com; script-src-attr 'unsafe-inline' https://cdn.lordicon.com https://consent.cookiebot.com https://s.emea01.idio.episerver.net https://www.googletagmanager.com; media-src data: https://www.yuverta.nl; manifest-src https://www.yuverta.nl; worker-src blob:; report-to stott-security-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://www.googletagmanager.com https://js.hs-scripts.com https://js-na2.hs-scripts.com https://js-na2.hsadspixel.net https://js-na2.hs-analytics.net https://js-na2.hs-banner.com https://code.jquery.com https://cdn.jsdelivr.net https://googleads.g.doubleclick.net https://www.google-analytics.com https://ajax.googleapis.com https://app.purechat.com https://prod.purechatcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://use.fontawesome.com https://netdna.bootstrapcdn.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://use.fontawesome.com https://netdna.bootstrapcdn.com; img-src 'self' data: https://web.oceansidechamber.com https://seal-central-northern-western-arizona.bbb.org https://www.google.com https://www.google-analytics.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://track-na2.hubspot.com; connect-src 'self' https://cdn.jsdelivr.net https://static.hsappstatic.net https://www.googletagmanager.com https://api-na2.hubapi.com https://www.google.com https://www.google-analytics.com https://www.googleadservices.com https://app.purechat.com https://prod.purechatcdn.com https://widgetapi.purechat.com https://api-cdn.purechat.com https://api.purechat.com; frame-src 'self' https://www.googletagmanager.com https://www.paycomonline.net https://player.vimeo.com; frame-ancestors 'self'; 1 default-src 'self' http://127.0.0.1:8080/ https://*.mrisoftware.com/ https://*.pendo.io/ https:; script-src 'self' 'wasm-unsafe-eval' 'unsafe-eval' 'unsafe-inline' https://*.mrisoftware.com/ https://*.pendo.io/ https:; style-src 'self' 'unsafe-inline' https://*.mrisoftware.com/ https://*.pendo.io/ https://cdn.jsdelivr.net/ https:; img-src 'self' https: data:; report-uri /cspendpoint/ 1 font-src *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.google.com *.doubleclick.net *.googletagmanager.com js.mollie.com landofcoder.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.mk *.google.nl *.facebook.com https://www.mollie.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com/recaptcha/api.js *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.feedbackcompany.com *.cookiecode.nl *.facebook.net *.addthis.com *.googletagmanager.com *.hotjar.com *.tekno.nl js.mollie.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com *.redditstatic.com *.reddit.com unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.nr-data.net *.demdex.net *.feedbackcompany.com *.facebook.com *.cookiecode.nl *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google-analytics.com *.tekno.nl api.addressy.com landofcoder.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ecomwise.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: *.zopim.com *.jotform.com *.jotfor.ms data: 'self' 'unsafe-inline'; form-action *.jotformeu.com *.jotform.com 'self' 'unsafe-inline'; frame-ancestors punchoutcommerce.com *.punchoutcommerce.com ariba.com *.ariba.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.packeta.com *.facebook.com *.jung.de *.cookiebot.com *.google.com *.jotformeu.com *.jotform.com form.jotform.com *.vimeocdn.com *.ytimg.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com 'self' data: blob: *.zopim.com *.seznam.cz *.facebook.com *.google.com fega.pl *.elektrobalt.lt *.elfetex.cz *.jotform.com *.jotfor.ms *.cookiebot.com px.ads.linkedin.com *.google.lt *.google.lv *.google.ee *.google.it *.google.cz *.google.pl *.google.com.ua *.google.sk *.google.si *.google.se *.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.avada.io *.packeta.com *.google.com *.gstatic.com *.zopim.com *.amazonaws.com *.googleapis.com *.googleadservices.com *.facebook.net *.imedia.cz *.seznam.cz *.doubleclick.net *.pingdom.net *.cookiebot.com *.elfsight.com *.zdassets.com *.jotform.com *.jotfor.ms cdnjs.cloudflare.com/ajax/libs/punycode/1.4.1/punycode.js web-sdk.smartlook.com *.clarity.ms snap.licdn.com *.leady.com *.clickcease.com cdn.luigisbox.com *.go-mpulse.net *.ytimg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com *.przelewy24.pl *.jotform.com *.jotfor.ms 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io https://get.geojs.io *.avada.io *.packeta.com stats.g.doubleclick.net wss://widget-mediator.zopim.com *.zendesk.com *.pingdom.net *.zdassets.com *.cookiebot.com *.jotformeu.com *.jotform.com *.smartlook.cloud *.akstat.io *.go-mpulse.net *.vimeocdn.com *.youtube.com *.ytimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.xacus.com *.cdn-apple.com static.zdassets.com *.zendesk.com *.klarnacdn.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.xacus.com static.zdassets.com *.zendesk.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com static.zdassets.com *.zendesk.com *.criteo.com *.criteo.net *.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com 'self' data: *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://cdn.clerk.io *.feedaty.com *.xacus.com *.iubenda.com *.criteo.com *.app-us1.com *.eurostep.it *.clarity.ms *.adnxs.com *.adbutter.net https://trackcmp.net *.google.it *.1rx.io *.bidswitch.net *.taboola.com *.omnitagjs.com *.casalemedia.com *.smartadserver.com *.adform.net https://id5-sync.com *.360yield.com *.ivitrack.com *.mediavine.com *.postrelease.com *.sharethrough.com *.unrulymedia.com *.emxdgt.com *.tremorhub.com *.teads.tv *.rubiconproject.com *.pubmatic.com *.outbrain.com *.3lift.com *.yieldlab.net *.yieldmo.com *.media.net *.bing.com *.bing.net *.licdn.com *.linkedin.com *.worldline-solutions.com *.secured-by-ingenico.com *.klarna.com *.klarnaevt.com *.klarnacdn.net static.zdassets.com *.zendesk.com *.disqus.com https://img.youtube.com *.koongo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com *.xacus.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.iubenda.com *.criteo.com *.app-us1.com *.eurostep.it *.clarity.ms *.adnxs.com *.adbutter.net https://trackcmp.net *.google.it *.clerk.io *.bing.com *.licdn.com *.cdn-apple.com https://ajax.cloudflare.com static.zdassets.com *.zendesk.com *.disqus.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com *.xacus.com static.zdassets.com *.zendesk.com *.klarnacdn.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.feedaty.com *.xacus.com *.akamaized.net *.vimeo.com *.vimeocdn.com *.zdassets.com *.zendesk.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.feedaty.com *.zopim.com wss://widget-mediator.zopim.com *.xacus.com *.iubenda.com *.criteo.com *.app-us1.com *.eurostep.it *.clarity.ms *.adnxs.com *.adbutter.net https://trackcmp.net *.google.it *.clerk.io *.bing.com *.linkedin.com *.zdassets.co *.zdassets.com *.bing.net *.worldline-solutions.com *.klarnaevt.com static.zdassets.com *.zendesk.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.koongo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com fonts.gstatic.com *.fontawesome.com *.miraphone.com 'self' data: *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.powr.io *.google.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.addthis.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://img.youtube.com *.stats.g.doubleclick.net *.facebook.com https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com s7.addthis.com *.avada.io *.google.com *.googletagmanager.com *.gstatic.com *.powr.io *.facebook.net https://player.vimeo.com https://www.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.miraphone.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline *.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.facebook.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://miraphone.report-uri.com/r/d/csp/enforce; report-to report-endpoint; 1 frame-ancestors 'self';block-all-mixed-content;default-src 'self';script-src 'self' data: 'report-sample' 'unsafe-inline' 'unsafe-eval' https://static.zdassets.com https://ekr.zdassets.com https://googleads.g.doubleclick.net https://connect.facebook.net https://kit.fontawesome.com https://maps.googleapis.com https://script.hotjar.com https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.hotjar.com https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js https://secure.gravatar.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://snap.licdn.com;style-src 'self' 'report-sample' 'unsafe-inline' secure.gravatar.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://www.googletagmanager.com;object-src 'none';frame-src 'self' data: atlassian-companion: https://www.youtube.com https://www.google.com https://player.vimeo.com https://www.facebook.com https://td.doubleclick.net;child-src 'self';img-src 'self' data: https://www.googletagmanager.com https://i.vimeocdn.com https://www.linkedin.com https://maps.googleapis.com https://www.googletagmanager.com/a *.gravatar.com https://www.google-analytics.com https://maps.gstatic.com https://px.ads.linkedin.com https://www.facebook.com https://www.google.com https://www.google.com.au https://px4.ads.linkedin.com;font-src 'self' data: https://fonts.gstatic.com https://ka-p.fontawesome.com;connect-src 'self' https://px.ads.linkedin.com https://borderexpress.zendesk.com https://ekr.zdassets.com https://www.google.com.au https://analytics.google.com *.gravatar.com https://yoast.com https://www.google-analytics.com https://stats.g.doubleclick.net https://ka-p.fontawesome.com https://maps.googleapis.com https://www.google-analytics.com https://kit.fontawesome.com https://pagead2.googlesyndication.com https://vc.hotjar.io https://www.facebook.com;manifest-src 'self';base-uri 'self';form-action 'self' https://www.facebook.com ;media-src 'self';worker-src 'self'; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.co.uk https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self'; report-uri /csp-report-endpoint 1 font-src *.googleapis.com *.gstatic.com https://fonts.bunny.net https://*.klaviyo.com https://*.typekit.net https://*.getroster.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google.rs https://www.google.com https://www.googletagmanager.com https://*.cloudfront.net https://*.typekit.net https://*.getroster.com data: 'self' 'unsafe-inline'; script-src https://*.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://facebook.net connect.facebook.net graph.facebook.com business.facebook.com https://*.tiktok.com https://magento.com https://*.klaviyo.com https://www.googletagmanager.com https://*.typekit.net https://*.getroster.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com assets.braintreegateway.com fonts.googleapis.com *.certcapture.com https://static.klaviyo.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.klaviyo.com https://*.tiktok.com https://*.getroster.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.hu https://www.myheritage.hu 'unsafe-eval' 'nonce-577aedd82ca81549f83835c5efe280da' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.hu;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self' *.ccavenue.com *.razorpay.com view.officeapps.live.com www.google.com use.fontawesome.com www.youtube-nocookie.com www.youtube.com; connect-src 'self' *.elitmus.com *.elitmus.net *.nr-data.net sentry.elitmusmail.com *.google-analytics.com www.googletagmanager.com api.mixpanel.com api.github.com/ wss:; font-src 'self' cdn.jsdelivr.net fonts.gstatic.com use.fontawesome.com https: data:; img-src 'self' blob: cdn0.elitmus.net *.amazonaws.com data: https: www.google.com *.google-analytics.com www.googletagmanager.com api.mixpanel.com; object-src 'self' *.amazonaws.com; script-src 'self' blob: 'unsafe-inline' *.newrelic.com *.nr-data.net cdn0.elitmus.net google-analytics.com api.mixpanel.com cdn.jsdelivr.net/bootstrap.daterangepicker/2/daterangepicker.js cdn.jsdelivr.net/momentjs/latest/moment.min.js cdn.ckeditor.com/4.11.3/full/ckeditor.js https: data:; style-src 'self' 'unsafe-inline' cdn0.elitmus.net use.fontawesome.com/releases/v5.0.6/css/all.css cdn.jsdelivr.net/bootstrap/3/css/bootstrap.css cdn.jsdelivr.net/bootstrap.daterangepicker/2/daterangepicker.css https:; report-uri /csp_reports 1 report-to slardar-endpoint; script-src 'unsafe-eval' 'report-sample' 'nonce-094be99fbb258cf40b3ed90e257ca6b9-argus' 'strict-dynamic'; 1 font-src *.sitejabber.com *.gstatic.com *.nexcesscdn.net https://fonts.gstatic.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.facebook.com td.doubleclick.net *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.amazonaws.com *.postcodeanywhere.co.uk *.cloudfront.net *.godaddy.com *.sitejabber.com *.sixityauto.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.facebook.com *.bing.com *.analytics.yahoo.com *.wistia.com *.nexcesscdn.net google.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.trackedlink.net https://helloextend-static-assets.s3.amazonaws.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com *.google-analytics.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com data.stats.tools *.googleadservices.com *.googlesyndication.com *.g.doubleclick.net *.googleapis.com *.google.com *.sitejabber.com *.searchspring.net *.capredict.com *.pcapredict.com *.godaddy.com *.addressy.com *.bing.com *.facebook.net *.yimg.com *.pepperjam.com *.wistia.com *.clarity.ms *.nexcesscdn.net *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://*.helloextend.com *.klarna.com *.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.addressy.com *.sitejabber.com *.searchspring.net *.googleapis.com *.nexcesscdn.net webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.wistia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com *.addressy.com *.searchspring.io *.sitejabber.com *.googletagmanager.com *.googleadservices.com *.googlesyndication.com *.g.doubleclick.net google.com *.google.com *.analytics.google.com *.yimg.com *.attentivemobile.com *.wistia.com *.litix.io *.amazonaws.com *.clarity.ms *.bing.com *.nexcesscdn.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.helloextend.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com data: *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com https://www.google.com www.youtube.com youtube.com wchat.freshchat.com ukpos.webpush.freshchat.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com bat.bing.com www.facebook.com www.xtento.com cdn.xtento.com *.google.com *.google.fr *.google.ie *.google.co.uk *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com https://www.gstatic.com ict.infinity-tracking.net script.crazyegg.com bat.bing.com wchat.freshchat.com api.feefo.com register.feefo.com connect.facebook.net client.prod.mplat-ppcprotect.com https://s3.amazonaws.com/downloads.mailchimp.com/ www.xtento.com cdn.xtento.com *.google.fr *.google.ie *.google.co.uk *.googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net *.ukpos.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com *.fontawesome.com unsafe-inline wchat.freshchat.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com ict.infinity-tracking.net script.crazyegg.com tracking.crazyegg.com bat.bing.com client.prod.mplat-ppcprotect.com click.prod.mplat-ppcprotect.com region1.analytics.google.com https://www.google.co.uk/ads/ data: *.google-analytics.com stats.g.doubleclick.net *.ukpos.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.klaviyo.com *.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.olark.com *.paypal.com https://cdn.accessibly.app https://maps.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.google.com *.addthis.com *.doubleclick.net *.meetanshi.com https://meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.googleadservices.com *.cloudfront.net *.google-analytics.com *.paypal.com *.twitter.com *.olark.com *.vimeo.com *.bing.com *.google.co.in *.doubleclick.net *.googletagmanager.com *.cardinalcommerce.com https://cdn.accessibly.app https://maps.gstatic.com https://firebasestorage.googleapis.com *.meetanshi.com https://meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ apis.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.cloudflareinsights.com *.twitter.com *.google-analytics.com *.googleadservices.com use.typekit.net *.klaviyo.com https://dash.accessibly.app https://cdn.accessibly.app https://maps.googleapis.com *.googletagmanager.com *.cardinalcommerce.com maxcdn.bootstrapcdn.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com widgets.pinterest.com *.olark.com *.callrail.com *.pinimg.com *.hotjar.com *.ipify.org *.noibu.com *.bing.com *.schema.org *.pinterest.com *.yotpo.com *.facebook.net *.meetanshi.com *.paypal.com *.paypalobjects.com s7.addthis.com *.avada.io *.shopify.com https://meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.paypal.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.olark.com *.vimeo.com *.cardinalcommerce.com *.googletagmanager.com https://maps.gstatic.com *.google-analytics.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.olark.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.klaviyo.com *.twitter.com *.paypal.com *.olark.com *.callrail.com *.pinterest.com *.facebook.com *.doubleclick.net *.google-analytics.com *.bing.com *.cardinalcommerce.com https://alt-tags.accessiblyapp.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.meetanshi.com https://meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://code.responsivevoice.org *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com maps.googleapis.com chart.googleapis.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com www.youtube.com js.stripe.com *.hotjar.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com bat.bing.com *.google.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk paypal.com *.feefo.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com *.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com connect.facebook.net js-agent.newrelic.com bam.nr-data.net *.google.com *.feefo.com *.googlecommerce.com *.bing.com *.pingdom.net *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.punchout2go.com services.postcodeanywhere.co.uk fonts.googleapis.com *.typekit.net 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com api.addressy.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.hotjar.com wss://ws.hotjar.com *.hotjar.io *.pingdom.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com 'self' data: *.gstatic.com *.typekit.net *.bootstrapcdn.com *.googleapis.com *.amazonaws.com *.klarnacdn.net *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.hotjar.com app.smartsheet.com www.googletagmanager.com www.google.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' blob: data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://images.unsplash.com *.cloudflare.com *.google-analytics.com *.feefo.com *.sagepay.co.uk ebizmarts-website.s3.amazonaws.com www.google.co.uk www.google.com cdn.klarna.com www.electricradiatorsdirect.co.uk *.ads.linkedin.com *.linkedin.com *.bing.com www.facebook.com www.google.gg www.google.ca www.google.es *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.google-analytics.com *.fontawesome.com *.chimpstatic.com chimpstatic.com *.googletagmanager.com *.gstatic.com *.google.com *.hotjar.com *.bing.com snap.licdn.com secure.vane3alga.com api.feefo.com register.feefo.com *.klarna.com *.klarnaservices.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com maps.googleapis.com cdn.ampproject.org www.gstatic.com *.analytics.google.com *.cloudflareinsights.com *.klaviyo.com *.doubleclick.net *.facebook.net *.crazyegg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.typekit.net *.bootstrapcdn.com *.fontawesome.com *.klarnacdn.net unsafe-inline *.gstatic.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.ideal-postcodes.co.uk *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.doubleclick.net stats.g.doubleclick.net *.google-analytics.com *.hotjar.io *.bing.com www.facebook.com bat.bing.com api.feefo.com register.feefo.com collect.feefo.com *.klarnaevt.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net cdn.ampproject.org *.klaviyo.com *.google.com *.google.co.uk *.linkedin.com *.crazyegg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ignition.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.be/api/csp-report; report-to csp-endpoint 1 font-src *.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com static.userback.io *.cylindo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.carnegiefabrics.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.xtento.com *.twitter.com fast.wistia.net td.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.xtento.com cdn.xtento.com *.pinterest.com *.cloudflare.com *.klarna.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.wistia.com *.elfsight.com *.elfsightcdn.com *.cylindo.com content-v2.cylindo.com *.google.com www.google.com.ua *.linkedin.com carnegiefabrics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.xtento.com cdn.xtento.com fast.wistia.net static.userback.io *.carnegiefabrics.com *.cloudflare.com cookie-cdn.cookiepro.com *.twitter.com *.crazyegg.com *.pardot.com *.pinterest.com *.google-analytics.com *.google.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com js-agent.newrelic.com bam.nr-data.net *.wistia.com *.elfsight.com *.cylindo.com snap.licdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.userback.io *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.cylindo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: *.wistia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com api.userback.io *.stackpathdns.com cookie-cdn.cookiepro.com *.crazyegg.com stats.g.doubleclick.net geolocation.onetrust.com *.google-analytics.com *.cloudflare.com *.twitter.com *.paypal.com bam.nr-data.net *.wistia.com *.elfsight.com *.litix.io *.cylindo.com content-v2.cylindo.com *.linkedin.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.carnegiefabrics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.punchout2go.com *.tradecentric.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.punchout2go.com *.tradecentric.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.brsrvr.com *.bloomreach.cloud forms.hsforms.com track.hubspot.com px.ads.linkedin.com www.facebook.com *.hsforms.com https://www.magezon.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page cdn.brcdn.com js-na1.hs-scripts.com js.hs-analytics.net js.hscollectedforms.net js.hs-banner.com js.hs-scripts.com js.hubspot.com js.hsadspixel.net connect.facebook.net snap.licdn.com *.punchout2go.com *.tradecentric.com *.alothemes.com *.magepow.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.punchout2go.com *.tradecentric.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.dxpapi.com forms.hscollectedforms.net api.hubapi.com cta-service-cms2.hubspot.com px.ads.linkedin.com www.facebook.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: *.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.yotpo.com *.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.consensu.org *.sharethis.com cdn.dnky.co webchat.dotdigital.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.sharethis.com dashboard.feedbucket.app *.ggpht.com maps.gstatic.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.google.com *.sharethis.com cdn.feedbucket.app r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com maps.googleapis.com *.googletagmanager.com *.facebook.net *.avada.io https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com cdn.feedbucket.app cdn.dnky.co webchat.dotdigital.com fonts.googleapis.com/ tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.doubleclick.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com dashboard.feedbucket.app cdn.feedbucket.app r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com maps.googleapis.com/ https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src d.digsgogo.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://hsw.et1267.epichosted.com/HSWeb_PRD/;frame-src https://* 'self' epichttp: https://mychart.personapay.com;script-src 'nonce-d8c9222c522d4842849a272cc2595a4e' https://www.mcleodmychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.mcleodmychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com https://cdnjs.cloudflare.com 'self' data: *.bootstrapcdn.com *.cloudflare.com *.google.fr *.google.com *.vital-agriculture.fr data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ *.meetanshi.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.avis-verifies.com *.google.fr *.google.com *.sibforms.com *.sibautomation.com sibautomation.com *.vital-agriculture.fr *.weltpixel.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.swagger.io *.gstatic.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.meetanshi.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.adobedtm.com *.amasty.com *.bing.com *.braintreegateway.com *.cookielaw.org *.demdex.net *.doubleclick.net *.facebook.com *.google.fr *.google.com *.magentocommerce.com meetanshi.com *.mydialoginsight.com *.paypal.info *.vital-agriculture.fr *.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com *.avada.io *.meetanshi.com https://cdnjs.cloudflare.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com 1map.com *.adobedtm.com *.addtoany.com *.avada.com *.bing.com *.cardinalcommerce.com *.cookielaw.org *.cloudfare.com sdk.privacy-center.org *.facebook.net *.google.fr *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.googlesyndication.com *.matomo.cloud *.trackify.info *.mydialoginsight.com *.newrelic.com *.paypalobjects.com *.piwik.pro *.vital-agriculture.fr https://www.googletagmanager.com tagmanager.google.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.addtoany.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.aptrinsic.com *.bootstrapcdn.com *.braintreegateway.com *.cloudflare.com *.google.fr *.google.com *.googletagmanager.com *.vital-agriculture.fr tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io http://dpm.demdex.net *.meetanshi.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.aptrinsic.com *.braintreegateway.com *.cookielaw.org *.demdex.net stats.g.doubleclick.net *.facebook.net *.google.fr *.googlesyndication.com *.matomo.cloud *.mydialoginsight.com *.onetrust.com *.payone.com *.vital-agriculture.fr *.worldline-solutions.com *.anzworldline-solutions.com.au *.zdassets.com https://www.google-analytics.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.demdex.net *.hubspot.com *.hsforms.com *.hsforms.net wave-utility-stage.azurewebsites.net/ wave-utility.azurewebsites.net/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: *.uber.com *.ubereats.com maps.gstatic.com *.newrelic.com *.nr-data.net *.google.com *.linkedin.com *.salsify.com *.hubspot.com *.hsforms.com i.vimeocdn.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://*.customily.com https://*.amazonaws.com https://*.mapbox.com maps.googleapis.com unpkg.com *.unpkg.com *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.salsify.com *.hubspot.com *.hsforms.com *.hsforms.net *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hubspotfeedback.com *.licdn.com *.usemessages.com api.ipify.org *.elfsight.com f.vimeocdn.com www.gstatic.com *.hotjar.com *.jsdelivr.net *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://*.mapbox.com *.fontawesome.com maxcdn.bootstrapcdn.com f.vimeocdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.newrelic.com *.nr-data.net *.google.com *.salsify.com *.hubspot.com *.hsforms.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: maps.googleapis.com unpkg.com *.unpkg.com *.googletagmanager.com *.doubleclick.net *.googleapis.com *.salsify.com *.linkedin.com *.hubspot.com *.hsforms.com *.hubapi.com *.hscollectedforms.net *.elfsight.com *.cloudflare.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src fresnel-events.vimeocdn.com player-telemetry.vimeo.com commerce.adobedc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.googleapis.com *.gstatic.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com staticw2.yotpo.com cdn1.stamped.io static.klaviyo.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com https://seo.mageplaza.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com *.cash.app *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com t.zip.co app.hubspot.com tr.snapchat.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.googleapis.com *.gstatic.com *.globalpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.secure-afterpay.com.au stats.g.doubleclick.net www.google.com.au staticw2.yotpo.com p.yotpo.com cdn-yotpo-images-production.yotpo.com cfvod.kaltura.com a.klaviyo.com bat.bing.com tr.snapchat.com blob: www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com seal.geotrust.com static.zipmoney.com.au api.instagram.com www.google.com www.gstatic.com staticw2.yotpo.com bam.nr-data.net cdn.inspectlet.com static.klaviyo.com fast.a.klaviyo.com edge.fullstory.com secure.ewaypayments.com v2.zopim.com static.zdassets.com widget-mediator.zopim.com bat.bing.com static.hotjar.com script.hotjar.com browser.sentry-cdn.com unsafe-eval edge.marker.io sc-static.net tr.snapchat.com global-api.afterpay.com js.squarecdn.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com *.cash.app widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com staticw2.yotpo.com cdn1.stamped.io static.klaviyo.com static-tracking.klaviyo.com use.typekit.net p.typekit.net analytics.tiktok.com sc-static.net tr.snapchat.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com stedi.s3.ap-southeast-2.amazonaws.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://google.com/pay https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.zip.co api.zipmoney.com.au staticw2.yotpo.com app.hubspot.com api.hubspot.com payments.braintree-api.com/graphql fast.a.klaviyo.com edge.fullstory.com rs.fullstory.com sales-w7ssk.zendesk.com stedi.zendesk.com widget-mediator.zopim.com ekr.zdassets.com metrics.hotjar.io tr.snapchat.com tr6.snapchat.com api.marker.io api.experianaperture.io *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com stedi.s3.ap-southeast-2.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.rikstv.no wss://*.rikstv.no *.strim.no https://*.launchdarkly.com fonts.gstatic.com https://*.braintree-api.com https://*.braintreegateway.com https://*.paypal.com https://*.cardinalcommerce.com https://geo.cardinalcommerce.com https://*.litix.io https://*.theoplayer.com https://*.sanity.io https://*.nep.ms https://*.telenorcdn.net https://d35a3yqleg4mle.cloudfront.net https://*.sentry.io https://*.google-analytics.com https://*.doubleclick.net https://*.google.com https://*.google.no https://*.googlesyndication.com https://www.googletagmanager.com https://*.clarity.ms https://*.bing.com https://eu.i.posthog.com blob: data: https://*.niceincontact.com https://af-de-web-modules.s3.eu-central-1.amazonaws.com https://*.viaplay.no; script-src 'self' 'unsafe-eval' 'nonce-KfryqFjKiYAuYcquRamZXg==' 'strict-dynamic' 'wasm-unsafe-eval' https://www.clarity.ms https://www.gstatic.com 'report-sample' https://www.paypalobjects.com https://www.paypal.com https://songbird.cardinalcommerce.com; style-src 'self' 'unsafe-inline' https://assets.braintreegateway.com https://web-modules-de-eu1.niceincontact.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubcc16aeced64de99ebc739f17aa7b488f&ddsource=csp-report; report-to csp-endpoint; 1 default-src https://* 'unsafe-inline';font-src 'self' https://* data:;connect-src *;style-src-elem https://* 'unsafe-inline';script-src-elem 'unsafe-inline' 'unsafe-eval' https:;img-src blob://* https://* 'self' data:;script-src 'unsafe-inline' 'unsafe-eval' blob:;frame-src https://*; 1 font-src *.gstatic.com 'self' data: *.googleapis.com *.googletagmanager.com *.google.nl *.jsdeliver.net *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.googleapis.com *.googletagmanager.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.googleapis.com *.googletagmanager.com *.doubleclick.net *.wiqhit.com *.klaviyo.com *.cookiebot.com *.hs-sites-eu1.com *.multisafepay.com https://pay.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.demdex.net *.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com *.googletagmanager.com *.google.nl *.cloudfront.net *.wiqhit.com *.hsforms.net *.hubspot.com *.cookiebot.com *.hsforms.com *.multisafepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ assets.myparcel.nl *.koongo.com *.cloudflare.com *.cdninstagram.com *.klarna.com *.demdex.net *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.trustedshops.com *.google.com *.zopim.com *.bing.com c.clarity.ms *.facebook.net *.doubleclick.net *.facebook.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com *.googletagmanager.com *.google.nl *.wiqhit.com *.klaviyo.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.hubspot.com *.usemessages.com *.hsadspixel.net *.hscollectedforms.net *.hsforms.net *.hsforms.com *.hotjar.com *.cookiebot.com *.googlesyndication.com *.multisafepay.com https://pay.google.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdnjs.cloudflare.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.sentry-cdn.com *.google-analytics.com *.googleadservices.com *.paypalobject.com *.google.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.amazonaws.com *.zdassets.com *.dassets.com *.diffuse.nl *.yotpo.com *.twimg.com chimpstatic.com *.zopim.com *.bing.com *.doubleclick.net maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googletagmanager.com *.klaviyo.com *.jsdeliver.net *.multisafepay.com https://static.klaviyo.com *.fontawesome.com cdn.jsdelivr.net cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.googletagmanager.com *.google.nl *.google.com *.wiqhit.com *.klaviyo.com *.hubspot.com *.hubapi.com *.hscollectedforms.net *.hotjar.com *.hs-scripts.com *.hs-analytics.com *.hsforms.net *.hsforms.com *.googlesyndication.com *.cookiebot.com *.multisafepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.myparcel.nl cdn.jsdelivr.net *.koongo.com *.google-analytics.com *.instagram.com *.doubleclick.net *.demdex.net *.cloudflare.com *.twitter.com *.amazonaws.com *.zdassets.com *.paypal.com *.twimg.com *.zopim.com *.sentry.io wss://widget-mediator.zopim.com client.diffuse.tools 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.nurumassage.com *.fantasymassage.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.nurumassage.com *.fantasymassage.com join.gammasecure.com; script-src 'self' *.nurumassage.com *.fantasymassage.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.nurumassage.com *.fantasymassage.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 object-src 'none'; connect-src 'self' *.roccosiffredi.com *.famedigital.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.roccosiffredi.com *.famedigital.com join.gammasecure.com; script-src 'self' *.roccosiffredi.com *.famedigital.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.roccosiffredi.com *.famedigital.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 connect-src 'self' consent-pref.trustarc.com consent.trustarc.com consent-reporting.trustarc.com *.g.doubleclick.net *.greatag.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com; font-src 'self' fonts.gstatic.com consent.trustarc.com data:; frame-src 'self' consent-pref.trustarc.com *.greatag.com d14qt9b6zkutf5.cloudfront.net *.greatamericaninsurancegroup.com charts.aghost.net www.youtube.com; img-src 'self' consent-pref.trustarc.com consent.trustarc.com consent.truste.com data: *.g.doubleclick.net *.greatag.com img.youtube.com *.dtn.com https://*.googletagmanager.com; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' consent.trustarc.com *.g.doubleclick.net https://*.googletagmanager.com; script-src 'unsafe-eval' 'self' 'unsafe-inline' consent.trustarc.com *.g.doubleclick.net https://*.googletagmanager.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; report-uri https://greatamericancrop.report-uri.com/r/t/csp/reportOnly; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.fls.doubleclick.net *.facebook.com *.awin1.com *.zenaps.com consentcdn.cookiebot.com *.consentcdn.cookiebot.com gum.criteo.com *.gum.criteo.com servedby.flashtalking.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bird.eu www.google.it *.google.it secure.adnxs.com *.secure.adnxs.com *.adnxs.com x.bidswitch.net *.x.bidswitch.net *.bidswitch.net ib.adnxs.com *.ib.adnxs.com ad.360yield.com *.ad.360yield.com *.360yield.com contextual.media.net *.contextual.media.net sync.outbrain.com *.sync.outbrain.com *.outbrain.com pixel.rubiconproject.com *.pixel.rubiconproject.com *.rubiconproject.com match.sharethrough.com *.match.sharethrough.com *.sharethrough.com rtb-csync.smartadserver.com *.rtb-csync.smartadserver.com *.smartadserver.com sync-t1.taboola.com *.sync-t1.taboola.com *.taboola.com criteo-sync.teads.tv *.criteo-sync.teads.tv *.teads.tv eb2.3lift.com *.eb2.3lift.com *.3lift.com ups.analytics.yahoo.com *.ups.analytics.yahoo.com *.analytics.yahoo.com e1.emxdgt.com *.e1.emxdgt.com *.emxdgt.com cm.adform.net *.cm.adform.net *.adform.net visitor.omnitagjs.com *.visitor.omnitagjs.com *.omnitagjs.com r.casalemedia.com *.r.casalemedia.com *.casalemedia.com gum.criteo.com *.gum.criteo.com *.criteo.com matching.ivitrack.com *.matching.ivitrack.com *.ivitrack.com exchange.mediavine.com *.exchange.mediavine.com *.mediavine.com simage2.pubmatic.com *.simage2.pubmatic.com *.pubmatic.com criteo-partners.tremorhub.com *.criteo-partners.tremorhub.com *.tremorhub.com ad.yieldlab.net *.ad.yieldlab.net *.yieldlab.net sync-criteo.ads.yieldmo.com *.sync-criteo.ads.yieldmo.com *.ads.yieldmo.com beacon.krxd.net *.beacon.krxd.net *.krxd.net s.thebrighttag.com *.s.thebrighttag.com *.thebrighttag.com *.igodigital.com id5-sync.com *.id5-sync.com trk.datnova.com *.trk.datnova.com *.datnova.com *.enervit.com *.kleecks-cdn.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.awin1.com www.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com consent.cookiebot.com *.consent.cookiebot.com consentcdn.cookiebot.com *.consentcdn.cookiebot.com *.cookiebot.com *.dwin1.com static.criteo.net *.static.criteo.net enervit.mailmnsa.com *.enervit.mailmnsa.com sslwidget.criteo.com *.sslwidget.criteo.com *.criteo.com js.cookieless-data.com *.js.cookieless-data.com *.cookieless-data.com smct.co *.smct.co js.sddan.com *.js.sddan.com trk.datnova.com *.trk.datnova.com *.datnova.com js-agent.newrelic.com *.js-agent.newrelic.com *.newrelic.com bam.nr-data.net *.bam.nr-data.net 510004521.collect.igodigital.com *.collect.igodigital.com *.teads.tv *.iubenda.com *.kleecks-cdn.com *.kleecks-stats.com cdn.jsdelivr.net *.avada.io *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com *.kleecks-cdn.com https://fonts.bunny.net *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.enervit.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net google.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.google.com googleads.g.doubleclick.net *.googleads.g.doubleclick.net stats.g.doubleclick.net *.stats.g.doubleclick.net region1.analytics.google.com *.region1.analytics.google.com enervit.mailmnsa.com *.enervit.mailmnsa.com consentcdn.cookiebot.com *.consentcdn.cookiebot.com bam.nr-data.net *.bam.nr-data.net *.iubenda.com *.kleecks-stats.com *.algolia.io https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com places.googleapis.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; form-action 'none'; frame-ancestors 'none'; report-uri https://05b05d212ae69f14bc0693ae06b9402c.report-uri.com/r/t/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com region1.analytics.google.com fonts.googleapis.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.niceincontact.com *.hub-box.com *.hotjar.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com *.stripe.com *.stripe.network *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com/ region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com *.niceincontact.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com https://www.magezon.com magefan.com cm.magefan.com *.hotjar.io wss://*.niceincontact.com www.google.co.in *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com *.google.co.uk region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com *.googlesyndication.com *.linkedin.com *.pixriot.com *.storeimaging.com *.disqus.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://img.youtube.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com *.hotjar.io wss://*.niceincontact.com *.porjs.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.aptrinsic.com *.demdex.net porjs.com *.hotjar.com wss://*.zopim.com *.niceincontact.com *.hub-box.com *.licdn.com *.disqus.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com x.klarnacdn.net *.klarnaservices.com *.hsforms.net *.hsforms.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com region1.analytics.google.com fonts.gstatic.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.niceincontact.com *.hub-box.com *.stripe.network *.stripecdn.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.hotjar.io wss://*.niceincontact.com static.zdassets.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.hotjar.io wss://*.niceincontact.com wss://*.zopim.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com *.niceincontact.com *.hub-box.com *.linkedin.com *.pixriot.com *.storeimaging.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com x.klarnacdn.net *.klarnaservices.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.hotjar.io wss://*.niceincontact.com analytics.google.com *.bing.com *.cookiebot.com *.doubleclick.net ekr.zdassets.com *.facebook.com *.facebook.net *.feefo.com *.google.com *.google.co.uk region1.analytics.google.com fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.pcapredict.com *.pinimg.com *.pinterest.com *.postcodeanywhere.co.uk *.salesfire.co.uk browser-update.org *.browser-update.org *.smartmetrics.co.uk stats.g.doubleclick.net tritonshowerscx.zendesk.com *.trustpilot.com www.clarity.ms *.youtube.com *.zdassets.com ekr.zendesk.com *.zopim.com widget-mediator.zopim.com *.tritonshowers.co.uk *.adobedtm.com *.aptrinsic.com *.demdex.net porjs.com wss://*.zopim.com *.hub-box.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp.deploy.co.uk/99aaa83e-494f-4d0c-9af4-63a6d5c1b38a; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.zip.co *.bing.com *.alicdn.com *.baomitu.com *.bazaarvoice.com *.cdnfonts.com *.googleapis.com *.hotjar.com *.hsappstatic.net *.office.net *.slant.co *.zopim.com d1uznvntk80v7s.cloudfront.net unpkg.com *.burnsco.co.nz https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.localhost.com *.paymentexpress.com *.windcave.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com *.cash.app *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.localhost.com *.paymentexpress.com *.windcave.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.googletagmanager.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.sharethis.com https://images.unsplash.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cdninstagram.com *.fbcdn.net *.unbxdapi.com *.bing.com *.google.com.vn *.google.com.au google.com *.adroll.com *.bidswitch.net *.rubiconproject.com *.openx.net *.pubmatic.com *.rlcdn.com *.yahoo.com *.adnxs.com *.casalemedia.com *.company-target.com *.ib-ibi.com *.dotomi.com *.prfct.co *.taboola.com *.addthis.com *.fg8dgt.com *.fzlnk.com *.jivox.com *.acuityplatform.com *.quantserve.com *.apolloprogram.io *.smartadserver.com *.storygize.net *.rezync.com *.rfihub.com *.mediarithmics.com mmtro.com *.1rx.io *.unrulymedia.com *.ctnsnet.com *.33across.com *.3lift.com *.lijit.com *.weborama.fr *.innovid.com *.skimresources.com pippio.com *.securedvisit.com *.insightexpressai.com *.ispot.tv *.swoop.com *.swpsv.com *.crsspxl.com *.acxiomapac.com *.globalwebindex.net *.mrtnsvr.com *.dxkulture.com *.rakuten.com *.semasio.net *.commander1.com *.adstir.com *.twitter.com *.socd.com *.im-apps.net *.rtbiq.com *.mgid.com *.meritb2b.com zdbb.ne *.reson8.com *.adsrvr.org *.clarity.ms *.amazon-adsystem.com *.stackadapt.com *.bluekai.com *.contextweb.com *.kargo.com *.criteo.com *.bidr.io *.exelator.com *.scorecardresearch.com *.turn.com *.w55c.net *.crwdcntrl.net *.walmart.com *.mathtag.com *.sitescout.com *.simpli.fi *.mxptint.net *.media.net *.adentifi.com *.linksynergy.com *.adgrx.com *.ipredictive.com *.tidaltv.com *.tapad.com *.cardlytics.com *.agkn.com *.owneriq.net bttrack.com *.spotify.com *.undertone.com *.tribalfusion.com *.admission.net *.eyeota.net *.ml314.com *.mookie1.com *.afterpay.com www.google.co.in www.google.co.nz www.google.com.hk www.google.com.mx www.google.com.my www.google.com.ph www.google.com.sg www.google.nl www.google.co.jp www.google.co.th www.google.co.uk www.google.com.co www.google.com.pk www.google.com.sa www.google.hu www.google.ie www.google.it www.google.ae www.google.at www.google.az www.google.be www.google.ca www.google.ch www.google.cl www.google.co.id www.google.co.il www.google.co.ke www.google.co.kr www.google.co.tz www.google.co.za www.google.com.ar www.google.com.bd www.google.com.bn www.google.com.br www.google.com.fj www.google.com.kh www.google.com.ly www.google.com.mt www.google.com.ng www.google.com.pg www.google.com.qa www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cv www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.gr www.google.iq www.google.lk www.google.lt www.google.lv www.google.mn www.google.mu www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.so www.google.tl www.google.to *.techrentals.co.nz *.techrentals.com.au www.google.by www.google.cm www.google.co.ma www.google.co.ug www.google.co.uz www.google.co.ve www.google.com.bo www.google.com.kw www.google.com.lb www.google.com.om www.google.com.pe www.google.cz www.google.jo www.google.la www.google.sr www.google.vu *.google-analytics.com *.google.com *.googleadservices.com *.techrentals.com.my *.techrentals.com.sg www.google.ba www.google.bj www.google.bt www.google.ci www.google.co.ao www.google.co.bw www.google.co.mz www.google.co.zm www.google.co.zw www.google.com.au www.google.com.bh www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gt www.google.com.mm www.google.com.np www.google.com.pa www.google.com.pr www.google.com.sb www.google.com.sv www.google.com.uy www.google.ge www.google.hr www.google.is www.google.kz www.google.ml www.google.mw www.google.ne www.google.rw www.google.sc www.google.sk www.google.sn www.google.tn www.google.tt *.alicdn.com *.bazaarvoice.com *.bing.net *.googleapis.com *.imgix.net *.scarabresearch.com *.zopim.com www.google.ad www.google.al www.google.am www.google.as www.google.bf www.google.bs www.google.cd www.google.cg www.google.co.ck www.google.co.cr www.google.co.vi www.google.com.ag www.google.com.bz www.google.com.cu www.google.com.gi www.google.com.jm www.google.com.na www.google.com.ni www.google.com.py www.google.com.sl www.google.com.vc www.google.dm www.google.fm www.google.ga www.google.gg www.google.gl www.google.gm www.google.gy www.google.hn www.google.ht www.google.im www.google.je www.google.kg www.google.ki www.google.lu www.google.md www.google.me www.google.mg www.google.mk www.google.mv www.google.nr www.google.nu www.google.pn www.google.ps www.google.sh www.google.sm www.google.st www.google.tg www.google.tm www.google.ws yastatic.net *.baidu.com *.burnsco.co.nz *.vimeo.com www.google.com.af www.google.td https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.sharethis.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.instagram.com *.newrelic.com *.nr-data.net *.convertexperiments.com *.clarity.ms *.abtasty.com *.pricespider.com *.emarsys.net *.bing.com *.adsrvr.org *.cloudfront.net *.quantserve.com *.adroll.com *.quantcount.com *.online-metrix.net *.zdassets.com *.signifyd.com unpkg.com bpi.zip.co *.jsdelivr.net *.ipify.org *.afterpay.com *.bazaarvoice.com *.googleapis.com *.hotjar.com *.omtrdc.net *.scarabresearch.com *.vimeo.com *.zopim.com *.burnsco.co.nz rum.hlx.page *.plugins.emarsys.net https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com *.cash.app *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com display.ugc.bazaarvoice.com *.zip.co unpkg.com *.bing.com *.typekit.net *.jsdelivr.net *.baomitu.com *.omtrdc.net *.addysolutions.com *.burnsco.co.nz https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cdninstagram.com vimeo.com *.zdassets.com *.vimeocdn.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.sharethis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.openstreetmap.org api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.instagram.com *.googleusercontent.com cdn.jsdelivr.net *.abtasty.com *.nr-data.net *.clarity.ms *.adroll.com *.online-metrix.net *.zipmoney.com.au *.cloudfront.net *.zip.co *.zendesk.com *.mastersoftgroup.com *.zopim.com *.bing.com wss://widget-mediator.zopim.com *.zdassets.com *.addysolutions.com www.google.co.in www.google.co.nz www.google.com.au www.google.com.mx www.google.com.my www.google.com.ph www.google.com.sg www.google.co.jp www.google.co.uk www.google.com.co www.google.com.hk www.google.com.pk www.google.com.sa www.google.hu www.google.it www.google.ae www.google.be www.google.co.id www.google.co.kr www.google.co.th www.google.co.za www.google.com.ar www.google.com.bd www.google.com.bn www.google.com.kh www.google.com.pg www.google.com.tw www.google.com.vn www.google.cv www.google.de www.google.dz www.google.es www.google.iq www.google.lk www.google.mn www.google.pl www.google.ro www.google.ru www.google.so www.google.tl *.crwdcntrl.net www.google.at www.google.az www.google.ca www.google.ch www.google.co.il www.google.co.ug www.google.com.br www.google.com.fj www.google.com.ng www.google.com.pe www.google.com.qa www.google.com.tr www.google.dk www.google.fr www.google.nl www.google.no www.google.vu *.googleadservices.com *.techrentals.com.my *.techrentals.com.sg www.google.bt www.google.by www.google.cl www.google.co.bw www.google.co.ke www.google.co.ma www.google.co.tz www.google.co.zw www.google.com.bo www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.np www.google.com.sb www.google.com.sv www.google.com.ua www.google.cz www.google.ee www.google.ge www.google.gr www.google.ie www.google.jo www.google.kz www.google.la www.google.lt www.google.lv www.google.mu www.google.rs www.google.se www.google.sk www.google.sn www.google.to *.alicdn.com *.amplitude.com *.bazaarvoice.com *.bing.net *.contentsquare.net *.googletagmanager.com *.hotjar.com *.scarabresearch.com *.stbuttons.click localhost servail.com www.google.al www.google.am www.google.as www.google.ba www.google.bg www.google.bs www.google.cg www.google.ci www.google.cm www.google.co.ao www.google.co.ck www.google.co.cr www.google.co.mz www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zm www.google.com.ag www.google.com.bh www.google.com.bz www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gi www.google.com.gt www.google.com.jm www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.ni www.google.com.om www.google.com.pa www.google.com.pr www.google.com.py www.google.com.sl www.google.com.uy www.google.dm www.google.fi www.google.fm www.google.ga www.google.gg www.google.gl www.google.gm www.google.gy www.google.hr www.google.ht www.google.is www.google.ki www.google.lu www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mv www.google.mw www.google.nr www.google.nu www.google.pn www.google.pt www.google.sc www.google.si www.google.sr www.google.st www.google.tn www.google.tt www.google.ws *.addy.co.nz *.burnsco.co.nz *.hotjar.io rum.hlx.page www.google.com.af www.google.hn *.eservice.emarsys.net https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://d94c0886-5f3c-4cfa-bd0f-6b0e89adce4f.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com http://maxcdn.bootstrapcdn.com/font-awesome/ https://widgets.trustedshops.com/ https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.facebook.com/ https://apay-us.amazon.com/ https://payments.amazon.de/ *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.addthis.com *.facebook.com *.twitter.com https://www.facebook.com/ https://bid.g.doubleclick.net/ https://www.jsctool.com/ https://www.pinterest.com/ https://www.pinterest.de/ https://apay-us.amazon.com/ https://ct.pinterest.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.addthisedge.com *.twitter.com https://widgets.trustedshops.com/ https://www.facebook.com/ https://connect.facebook.net/ https://www.google.com/pagead/ https://www.google.de/pagead/ https://www.google.com/ads/ https://www.google.de/ads/ https://googleads.g.doubleclick.net/ https://stats.g.doubleclick.net/ https://www.gstatic.com/ https://ssl.gstatic.com/ https://www.google-analytics.com/ https://www.google.com/ https://bat.bing.com/ https://ct.pinterest.com/ http://tr.outbrain.com/ https://images-na.ssl-images-amazon.com/ https://m.media-amazon.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com https://connect.facebook.net https://www.googletagmanager.com/ https://tagmanager.google.com/ http://widgets.trustedshops.com/ https://googleads.g.doubleclick.net/ https://www.google-analytics.com/ https://ssl.google-analytics.com/ https://www.google.com/ https://www.googleadservices.com/ https://bat.bing.com/ https://secure.pay1.de/ https://d.ratepay.com/ http://d.ratepay.com/ https://s.pinimg.com/ https://amplify.outbrain.com/ http://tr.outbrain.com/ https://wave.outbrain.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com d.ratepay.com d.payla.io dr.payla.io http://maxcdn.bootstrapcdn.com/font-awesome/ https://tagmanager.google.com/ https://fonts.googleapis.com/ unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com https://www.google-analytics.com/ https://region1.analytics.google.com/ https://stats.g.doubleclick.net/ *.trustedshops.com http://d.ratepay.com/ https://ct.pinterest.com/ http://tr.outbrain.com/ https://analytics.fischer-wolle.de/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://shop.fischerwolle-de.gfe20.de/report-csp; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.redditstatic.com www.gstatic.com www.google.com *.klaviyo.com *.shopify.com cdn.attn.tv connect.facebook.net *.google-analytics.com *.googletagmanager.com www.googleadservices.com; style-src 'self' 'unsafe-inline' cdn.shopify.com www.gstatic.com; object-src 'none'; base-uri 'self'; connect-src 'self' www.redditstatic.com *.klaviyo.com *.analytics.google.com analytics.google.com www.google-analytics.com www.googleadservices.com adservice.google.com www.google.com *.googleapis.com *.doubleclick.net *.instagram.com *.shopify.com images.prismic.io events.attentivemobile.com rogallery.attn.tv rogallery-us.attn.tv; font-src 'self' data: rogallery.cdn.prismic.io fonts.gstatic.com cdn.shopify.com static.klaviyo.com; frame-src 'self' td.doubleclick.net submit.jotform.com form.jotform.com creatives.attn.tv www.facebook.com www.googletagmanager.com; img-src 'self' data: blob: alb.reddit.com fonts.gstatic.com cdn.shopify.com events.attentivemobile.com prismic-io.s3.amazonaws.com images.prismic.io www.facebook.com *.google-analytics.com *.g.doubleclick.net *.googletagmanager.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; manifest-src 'self'; media-src 'self'; worker-src 'self' blob: ; report-uri https://csp.hullforge.com/d64a3; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://*.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com js.mollie.com *.multisafepay.com https://pay.google.com *.cookiebot.com *.bing.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://belco-prod.s3-eu-central-1.amazonaws.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://www.mollie.com *.multisafepay.com *.cookiebot.com *.bing.com *.google.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://cdn.belco.io *.belco.io chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.mollie.com *.multisafepay.com https://pay.google.com *.cookiebot.com *.bing.com *.ahrefs.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://*.googleapis.com downloads.mailchimp.com https://fonts.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://chat.belco.io https://cdn.belco.io *.belco.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.multisafepay.com *.cookiebot.com *.bing.com google.com *.ahrefs.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: www.googletagmanager.com; object-src 'none'; script-src 'self' https: 'unsafe-eval' blob: https://www.googletagmanager.com 'sha256-KswlGchel47n7WTeUxBzRtxr7gctpeiJjNnPkN3IEAU=' 'sha256-kOCO9LYFL9BkGKPGI5Y833BJH1SVuyZfTY5U4TOJi4A=' 'nonce-lX8opDVBCpaOQJ8ppiZUaw=='; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https: *; media-src https: blob: data:; child-src blob:; report-uri /csp-report/index 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.hsforms.com *.hotjar.com *.google-analytics.com *.google.com *.bing.com * *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com *.tradecentric.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors *.hsforms.com *.hotjar.com *.google-analytics.com *.google.com *.bing.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hsforms.com *.hotjar.com *.google-analytics.com *.bing.com * c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.punchout2go.com *.tradecentric.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com maps.gstatic.com *.hsforms.com forms-na1.hsforms.com track.hubspot.com mcstaging.ebhorsman.com icon-phone.png spin.adhq.com *.hubspotusercontent-na1.net *.hotjar.com *.google.com *.bing.com * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com maps.googleapis.com *.hsforms.com js.hsforms.net js-eu1.hsforms.net js-agent.newrelic.com js.hs-scripts.com js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net scripts.sirv.com script.hotjar.com static.hotjar.com *.google-analytics.com *.bing.com * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.tradecentric.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.hsforms.com *.hotjar.com cdn.styles.com scripts.sirv.com *.google-analytics.com *.google.com *.bing.com js.usemessages.com * *.fontawesome.com assets.braintreegateway.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.hsforms.com *.hotjar.com media.example.com *.google-analytics.com *.google.com *.bing.com * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com *.hsforms.com forms.hsforms.com bam.nr-data.net forms.hscollectedforms.net spin.adhq.com stats.sirv.com content.hotjar.io ws.hotjar.com *.hotjar.com *.bing.com api.hubspot.com forms-na1.hubspot.com * api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.zoovu.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors ; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com js.mollie.com *.trustpilot.com *.intercom.io *.intercomcdn.com *.cookiebot.com *.facebook.com *.publitas.com *.pinterest.com *.doubleclick.net *.mollie.com *.addthis.com *.force.com *.criteo.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com https://www.mollie.com maps.gstatic.com maps.googleapis.com https://redchamps.com *.bing.com *.google.com *.google.be *.facebook.com *.pinterest.com *.cloudfront.net *.zoovu.com *.tradetracker.net *.doubleclick.net *.googletagmanager.com *.acquire.io *.clarity.ms *.sleepworld.be *.360yield.com *.yieldlab.net *.yieldmo.com *.krxd.net *.demdex.net *.casalemedia.com *.analytics.yahoo.com *.criteo.com *.adnxs.com *.tremorhub.com *.pubmatic.com *.outbrain.com *.mediavine.com *.ivitrack.com *.omnitagjs.com *.adform.net *.3lift.com *.taboola.com *.smartadserver.com *.sharethrough.com *.rubiconproject.com contextual.media.net *.bidswitch.net ts.tradetracker.net www.magmodules.eu *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.avada.io js.mollie.com maps.googleapis.com *.trustpilot.com *.intercom.io *.intercomcdn.com *.cloudflare.com *.cloudflareinsights.com *.cookiebot.com *.acquire.io *.facebook.com *.facebook.net *.pinimg.com *.bing.com *.doubleclick.net *.zoovu.com *.tradetracker.net *.publitas.com *.googleoptimize.com *.addthis.com *.addthisedge.com *.moatads.com *.clarity.ms *.force.com *.cloudfront.net *.salesforceliveagent.com *.clerk.io *.salesforce.com instant.page *.criteo.com https://www.googletagmanager.com tagmanager.google.com tm.tradetracker.net *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com *.trustpilot.com *.intercom.io *.intercomcdn.com *.zoovu.com *.force.com tagmanager.google.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src data: 'self' 'unsafe-inline'; media-src file: data: blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io *.intercom.io *.intercomcdn.com *.doubleclick.net *.acquire.io *.pinterest.com *.bing.com ws: *.zoovu.com *.amazonaws.com *.trustpilot.com *.cookiebot.com *.stape.io *.sleepworld.be *.cwv-insights.com *.clarity.ms *.addthis.com *.google.com *.google.be https://www.google-analytics.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src *; connect-src: plausible.io; report-uri https://o57577.ingest.us.sentry.io/api/4509797941116928/security/?sentry_key=47cecc27bf90c0b8827e8dd08a448a16; report-to csp-endpoint 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.tw/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.hotjar.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com 'self' data: *.tawk.to https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.tawk.to *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.google.com *.google.it *.doubleclick.net *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com 'self' data: maps.gstatic.com *.trustedshops.com *.etrusted.com *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ https://widgets.trustedshops.com https://integrations.etrusted.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.alothemes.com *.magepow.com *.hotjar.com *.iubenda.com *.doubleclick.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com *.tawk.to cdn.jsdelivr.net https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.iubenda.com *.stripe.network *.stripecdn.com *.amazon.com assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.trustedshops.com *.etrusted.com *.tawk.to cdn.jsdelivr.net https://widgets.trustedshops.com https://integrations.etrusted.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.google.it *.analytics.google.com *.iubenda.com *.hotjar.io *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.tawk.to wss://*.tawk.to *.trustedshops.com *.etrusted.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src static.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.google.nl *.google.co.uk *.doubleclick.net *.bing.com *.bing.net *.runconverge.com *.mailchimp.com static.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.doubleclick.net *.googlesyndication.com *.bing.com *.bing.net *.runconverge.com *.svgator.com *.beslist.nl chimpstatic.com *.mailchimp.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.google.nl *.doubleclick.net *.googlesyndication.com *.bing.com *.bing.net *.runconverge.com *.beslist.nl *.intuit.com *.mailchimp.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.cashpresso.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.facebook.com *.cookiebot.com *.trustedshops.com *.googletagmanager.com https://www.google.com https://www.google.at *.aos.cc https://aos.cc *.google.com *.google.de *.google.si *.google.at *.google.it *.google.fr *.google.ch *.google.hu *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.chimpstatic.com downloads.mailchimp.com *.list-manage.com *.facebook.net *.googletagmanager.com *.cookiefirst.com *.cashpresso.com *.mailchimp.com *.jsdelivr.net *.gstatic.com *.google.com *.google.de *.google.si *.google.at *.google.it *.google.fr *.google.ch *.google.hu *.trackedlink.net *.klarna.com *.klarnacdn.net *.klarnaservices.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com *.googletagmanager.com *.cashpresso.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.cookiefirst.com *.cashpresso.com *.chimpstatic.com *.intuit.com *.mailchimp.com *.amazonaws.com *.doubleclick.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.facebook.net payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.throated.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.throated.com join.gammasecure.com; script-src 'self' *.throated.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.throated.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 base-uri 'self'; default-src 'self' data: https: wss:; frame-ancestors https://www.codepen.io/ 'self'; frame-src https://www.googletagmanager.com https://bid.g.doubleclick.net https://td.doubleclick.net https://ct.pinterest.com https://*.stripe.com https://stripe.com https://*.youtube.com https://youtube.com https://www.facebook.com https://player.vimeo.com https://ss.preplounge.com https://consentcdn.cookiebot.com https://preplounge.clients.bbbapi.cloud 'self'; form-action 'self' https://*.facebook.com; block-all-mixed-content true; script-src 'nonce-KWRPNkwtZCpoWnA1LXYrckFlR2kxR2YpNWFFTzc1M0E=' https://www.preplounge.com https://ss.preplounge.com https://consent.cookiebot.com 'strict-dynamic' https: 'unsafe-inline' 'unsafe-eval' 'self'; style-src 'self' data: https: wss: 'unsafe-inline'; img-src * data: blob:; connect-src 'self' https: wss: blob:; worker-src 'self' blob:; report-uri /en/misc/csp-report 1 font-src fonts.gstatic.com use.typekit.net https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.mondu.ai/ *.mondu.local localhost:*/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net https://images.unsplash.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://img.youtube.com *.mondu.ai/ *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com bat.bing.com www.facebook.com www.google.nl www.btndehaas.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.disqus.com https://cdn.jsdelivr.net *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com d5yoctgpv4cpx.cloudfront.net bat.bing.com cdn.cookie-script.com connect.facebook.net js-agent.newrelic.com static.hotjar.com script.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://cdn.jsdelivr.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app p2iqhncxyh.execute-api.eu-central-1.amazonaws.com l.clarity.ms bam.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com bat.bing.com l.clarity.ms bam.nr-data.net www.google.com bat.bing.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob: wss:; script-src 'self' 'nonce-tJCdxFl4XiJAXBrVl0PtIddDN7-_HAvsLSUCWz5qxhx6ytMcjgMrHg' *.googletagmanager.com *.google-analytics.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.doubleclick.net *.googletagmanager.com; style-src-elem 'self' 'nonce-tJCdxFl4XiJAXBrVl0PtIddDN7-_HAvsLSUCWz5qxhx6ytMcjgMrHg' https://fonts.gstatic.com https://fonts.googleapis.com 'report-sample'; script-src-elem 'self' 'nonce-tJCdxFl4XiJAXBrVl0PtIddDN7-_HAvsLSUCWz5qxhx6ytMcjgMrHg' https: 'unsafe-eval' blob: 'report-sample'; connect-src 'self' https: data: blob: wss: *.google.com https://*.googleapis.com https://*.gstatic.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; font-src 'self' https: data: blob: wss: https://fonts.gstatic.com; worker-src 'self' 'nonce-tJCdxFl4XiJAXBrVl0PtIddDN7-_HAvsLSUCWz5qxhx6ytMcjgMrHg' blob:; report-uri https://www.forestpeoples.org/@http-reporting?csp=report&requestTime=1765937174614771&requestHash=d2f0067ac5127303717b87c16f9427089652c34f 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com magento-cloudflare.jetrails.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com *.bayengage.com *.ytimg.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.bayengage.com https://wh.bayengage.com/magento http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com *.bayengage.com https://wh.bayengage.com/magento http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src use.typekit.net fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.iubenda.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com cdn.iubenda.com secure.metricsglobalgateway.com *.iubenda.com *.avada.io *.alothemes.com *.magepow.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com use.typekit.net fonts.googleapis.com *.google-analytics.com https://p.typekit.net https://use.typekit.net secure.metricsglobalgateway.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com secure.metricsglobalgateway.com *.iubenda.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.filthykings.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.filthykings.com join.gammasecure.com; script-src 'self' *.filthykings.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.filthykings.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-5KoOQ4G84e-XrhteG9ixdQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' scontent-itm1-1.cdninstagram.com graph.facebook.com www.facebook.com maps.google.com ep1.adtrafficquality.google analytics.google.com stats.g.doubleclick.net www.google-analytics.com www.google.com stats.ptengine.jp ep2.adtrafficquality.google udify.app www.googletagmanager.com www.youtube.com; img-src 'self' data: c.tile.openstreetmap.org b.tile.openstreetmap.org a.tile.openstreetmap.org maps.google.com ps.w.org s.w.org secure.gravatar.com code.jquery.com scontent-itm1-1.cdninstagram.com www.tripadvisor.com.tw www.googletagmanager.com connect.facebook.net lh3.googleusercontent.com www.tripadvisor.com secure.planmaker.jp www.google.co.jp ep1.adtrafficquality.google clients1.google.com www.facebook.com www.google.com scontent-nrt1-2.cdninstagram.com scontent-nrt1-1.cdninstagram.com scontent-nrt6-1.cdninstagram.com tag.yieldoptimizer.com; form-action 'self' www.facebook.com; script-src 'unsafe-inline' 'self' 'unsafe-eval' blob: unpkg.com wysiwyg.hi5.jp cdn.jsdelivr.net www.gstatic.com www.tripadvisor.com.tw static.mul-pay.jp ajaxzip3.github.io ajax.googleapis.com static.tacdn.com www.jscache.com www.tripadvisor.com www.jscache.com ep2.adtrafficquality.google www.google-analytics.com cse.google.com www.youtube.com googleads.g.doubleclick.net udify.app cdnjs.cloudflare.com js.ptengine.jp www.googletagmanager.com connect.facebook.net www.google.com code.jquery.com; style-src 'unsafe-inline' 'self' emailoctopus.com cdn.jsdelivr.net ajax.googleapis.com code.jquery.com cdnjs.cloudflare.com static.tacdn.com www.google.com netdna.bootstrapcdn.com use.fontawesome.com unpkg.com fonts.googleapis.com; font-src 'self' data: cdnjs.cloudflare.com static.tacdn.com netdna.bootstrapcdn.com use.fontawesome.com fonts.gstatic.com; 1 default-src 'self' https://members.metroplus.org https://providers.metroplus.org https://*.metroplus.org; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' blob: https://bam.nr-data.net/1/NRJS-5b73812c10c5a689dfd https://cdn.jsdelivr.net https://connect.facebook.net https://edge.fullstory.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com/nr-spa-1216.min.js https://js.sentry-cdn.com/eb0ea963074be69694926c62bc6c2527.min.js https://metroplushealth.my.site.com https://nitroscripts.com https://player.vimeo.com https://rs.fullstory.com https://browser.sentry-cdn.com https://secured-pixel.com https://snap.licdn.com https://translate.google.com https://unpkg.com https://www.google.com https://www.googletagmanager.com https://www.redditstatic.com https://www.youtube.com https://yoast.com https://*.googleapis.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.cdnfonts.com https://fonts.googleapis.com https://metroplus.org https://www.gstatic.com; object-src 'none'; base-uri 'self'; connect-src 'self' blob: https://ad.doubleclick.net https://analytics.google.com https://bam.nr-data.net https://dev.visualwebsiteoptimizer.com https://edge.fullstory.com https://f.vimeocdn.com https://googleads.g.doubleclick.net https://insights.algolia.io https://maps.googleapis.com https://my.yoast.com https://o4510035575701504.ingest.us.sentry.io https://pixel-config.reddit.com https://px.ads.linkedin.com https://region1.analytics.google.com https://rs.fullstory.com https://stats.g.doubleclick.net https://to.getnitropack.com https://translate.google.com https://translate.googleapis.com https://translate-pa.googleapis.com https://*.algolianet.com https://wajvr9qcei-dsn.algolia.net https://www.facebook.com https://www.google.com https://www.google.be https://www.google.ca https://www.google.co.in https://www.google.co.nz https://www.google.co.uk https://www.google.com.ar https://www.google.com.bd https://www.google.com.do https://www.google.com.ec https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.sa https://www.google.it https://www.google.lt https://www.google.nl https://www.google.pl https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.redditstatic.com https://yoast.com; font-src 'self' data: https://fast.fonts.net https://fonts.cdnfonts.com https://fonts.gstatic.com https://metroplus.org https://r2cdn.perplexity.ai https://use.typekit.net https://www.slant.co; frame-src 'self' data: https://*.fls.doubleclick.net https://block.opendns.com https://east-webbhtrainingintake-prod.dmzeast.azure.metroplus.org https://filter.techloq.com https://forms.metroplus.org https://forms.office.com https://gateway.zscaler.net https://gateway.zscalerthree.net https://player.vimeo.com https://safe.menlosecurity.com https://translate.googleapis.com https://vimeo.com https://www.googletagmanager.com https://www.wrike.com https://www.youtube.com https://xg.urbanhealthplan.org:8090 https://*.opendns.com; img-src 'self' data: https://ad.doubleclick.net https://alb.reddit.com https://bam.nr-data.net https://connect.facebook.net https://fonts.gstatic.com https://googleads.g.doubleclick.net https://i.vimeocdn.com https://i.ytimg.com https://img.youtube.com https://maps.gstatic.com https://metroplus.org https://px.ads.linkedin.com https://secure.gravatar.com https://staging.metroplus.org https://stats.g.doubleclick.net https://translate.google.com https://*.googleapis.com https://www.facebook.com https://www.google.com https://www.google.be https://www.google.ca https://www.google.ch https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.nz https://www.google.co.uk https://www.google.com.ar https://www.google.com.bd https://www.google.com.do https://www.google.com.ec https://www.google.com.gt https://www.google.com.jm https://www.google.com.mx https://www.google.com.ng https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.qa https://www.google.com.sa https://www.google.com.sg https://www.google.es https://www.google.fr https://www.google.gr https://www.google.it https://www.google.lt https://www.google.nl https://www.google.pl https://www.google.sk https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com; manifest-src 'self' https://metroplus.org; media-src 'self' https://cdn.staywell.com https://fonts.ninja; report-uri https://o4509193025683456.ingest.us.sentry.io/api/4510511239528448/security/?sentry_key=0195a0019c140b42b823ce5e2b1ef440; worker-src blob: https://*.metroplus.org https://metroplus.org; child-src 'self' blob:; 1 font-src fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com *.fontawesome.com data: *.klarnacdn.net https://fonts.bunny.net *.acsbapp.com static.sizebay.technology www.corneliani.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.facebook.com www.corneliani.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io www.corneliani.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com *.klarna.com *.playground.klarna.com calendly.com *.doubleclick.net *.cookiebot.com *.dacast.com *.nextingcompany.com *.2trk.info www.xtento.com static.criteo.net new-shoe-experience.sizebay.technology vfr-v3-production.sizebay.technology measurements-table.sizebay.technology www.corneliani.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://cdn.clerk.io *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com *.klarnaevt.com https://firebasestorage.googleapis.com *.amazonaws.com pixel.quantserve.com *.cloudfront.net cx.atdmt.com *.clerk.io *.1rx.io *.adsymptotic.com *.bing.com *.google.it *.doubleclick.net *.clarity.ms *.calendly.com *.bidswitch.net *.adnxs.com *.adscale.de *.omnitagjs.com *.casalemedia.com *.360yield.com *.yieldlab.net *.media.net *.mediavine.com *.pubmatic.com *.outbrain.com *.rubiconproject.com *.sharethrough.com *.smartclip.net *.tremorhub.net *.tremorhub.com *.3lift.com *.acsbapp.com *.equalweb.com *.smartadserver.com *.taboola.com *.teads.tv *.yahoo.com *.emxdgt.com *.adform.net id5-sync.com *.ivitrack.com *.yieldmo.com *.krxd.net *.thebrighttag.com *.cookiebot.com blob: *.unrulymedia.com www.xtento.com cdn.xtento.com www.google.at www.google.co.ma www.google.co.uk www.google.lv www.google.co.uz www.google.fr www.google.gr www.google.co.in www.google.ro www.google.ie www.google.se connect.facebook.net www.google.be www.google.de www.google.no www.google.com.sa www.google.es www.google.by csm.fr3.eu.criteo.net www.google.dk www.google.ch www.google.cd www.google.sk www.google.cz www.google.co.za www.google.com.ua www.google.pl csm.us5.us.criteo.net www.google.jo csm.nl3.eu.criteo.net www.google.pt www.google.co.il www.google.ba www.google.com.tr www.google.com.co www.google.co.kr www.google.ru www.google.ae www.google.ca www.google.hn www.google.hu www.google.me www.google.iq www.google.com.au www.google.com.mx www.google.com.ph www.google.bg www.google.hr www.google.kg www.google.fi www.google.rs lh3.ggpht.com www.google.az www.google.kz www.google.com.cy www.google.com.eg www.google.com.ng www.google.tn www.facebook.com www.google.com.vn www.google.am static.sizebay.technology www.corneliani.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://api.clerk.io https://cdn.clerk.io *.google.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com *.newrelic.com *.nr-data.net *.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com utt.impactcdn.com *.klarna.com x.klarnacdn.net *.avada.io https://cdn.scalapay.com *.clerk.io *.doubleclick.net/ *.quantserve.com rules.quantcount.com *.adform.net 127.0.0.1 commerce.adobedc.net *.aptrinsic.com *.iubenda.com *.cloudfront.net *.tremorhub.com acsbapp.com *.acsbapp.com *.equalweb.com *.calendly.com *.myfeelback.com *.bing.com clarity.ad *.clarity.ad *.cookiebot.com *.sizebay.technology *.preciso.net www.xtento.com cdn.xtento.com custom.clerk.io dynamic.criteo.com vfr-v3-production.sizebay.technology static.sizebay.technology www.corneliani.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net *.klarnacdn.net https://fonts.bunny.net *.calendly.com *.equalweb.com x.klarnacdn.net static.sizebay.technology vfr-v3-production.sizebay.technology www.corneliani.com 'self' 'unsafe-inline'; object-src www.corneliani.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com https://corneliani.eu-central-1.linodeobjects.com www.corneliani.com 'self' 'unsafe-inline'; manifest-src www.corneliani.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.nr-data.net *.clarity.ms *.facebook.com *.datatrics.com *.klarnaevt.com *.playground.klarnaevt.com *.klarnaservices.com *.playground.klarnaservices.com *.klarnacdn.net x.klarnacdn.net *.klarna.com https://get.geojs.io *.avada.io *.doubleclick.net *.iubenda.com acsbapp.com *.acsbapp.com *.equalweb.com *.myfeelback.com *.googlesyndication.com *.criteo.com *.bing.com *.cookiebot.com *.sizebay.technology maps.googleapis.com translate.googleapis.com www.google.com vfr-v3-production.sizebay.technology www.corneliani.com 'self' 'unsafe-inline'; child-src www.corneliani.com http: https: blob: 'self' 'unsafe-inline'; default-src www.corneliani.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.corneliani.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; 1 default-src 'self'; script-src 'self' 'nonce-ZAeZKrteDJFAV3hVwes3Ai-f7-qBQ_s-7d5j_d3ipXJDbCVbaU1R4A' data: https://*.openstreetmap.org 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.ggpht.com https://*.googleusercontent.com https://piwik.bbaw.de 'sha256-QJhK1t3PbpK4R2y7PrGp942vSpP4VEqfbTkFYEs1yjo=' 'sha256-PKMHQiOkpruXTmR/PCNVaFPE4Rewld/oFM5wp7y0qDc=' 'sha256-F9F0yaA4wMQxEX8h0sM3s1eVneKs7Zy5wY60XzkFiuY=' 'sha256-Woav+1MZpih8Q/UI5sY34DVZwjGLaXtzjtYjzaXGnuo=' 'sha256-A1KDZ6CTgI16YJ4cUNyyCFExM5+Sv4ApvahuZIQRXPA=' 'sha256-iA14rSZJnceodOBl+eFqe/5nM4VjszKoqH4SkTA7pVA=' blob: 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.googleusercontent.com https://*.ytimg.com https://*.vimeocdn.com https://*.bbaw.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com; style-src-elem 'self' 'nonce-ZAeZKrteDJFAV3hVwes3Ai-f7-qBQ_s-7d5j_d3ipXJDbCVbaU1R4A' 'sha256-F9F0yaA4wMQxEX8h0sM3s1eVneKs7Zy5wY60XzkFiuY=' 'sha256-QJhK1t3PbpK4R2y7PrGp942vSpP4VEqfbTkFYEs1yjo=' 'sha256-PKMHQiOkpruXTmR/PCNVaFPE4Rewld/oFM5wp7y0qDc=' 'sha256-Woav+1MZpih8Q/UI5sY34DVZwjGLaXtzjtYjzaXGnuo=' 'sha256-A1KDZ6CTgI16YJ4cUNyyCFExM5+Sv4ApvahuZIQRXPA=' 'sha256-iA14rSZJnceodOBl+eFqe/5nM4VjszKoqH4SkTA7pVA=' 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org https://*.googleapis.com https://*.google.com https://*.gstatic.com https://*.bbaw.de blob:; font-src 'self' https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com 'report-sample'; worker-src 'self' 'nonce-ZAeZKrteDJFAV3hVwes3Ai-f7-qBQ_s-7d5j_d3ipXJDbCVbaU1R4A' data: https://*.openstreetmap.org 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.ggpht.com https://*.googleusercontent.com https://piwik.bbaw.de 'sha256-QJhK1t3PbpK4R2y7PrGp942vSpP4VEqfbTkFYEs1yjo=' 'sha256-PKMHQiOkpruXTmR/PCNVaFPE4Rewld/oFM5wp7y0qDc=' 'sha256-F9F0yaA4wMQxEX8h0sM3s1eVneKs7Zy5wY60XzkFiuY=' 'sha256-Woav+1MZpih8Q/UI5sY34DVZwjGLaXtzjtYjzaXGnuo=' 'sha256-A1KDZ6CTgI16YJ4cUNyyCFExM5+Sv4ApvahuZIQRXPA=' 'sha256-iA14rSZJnceodOBl+eFqe/5nM4VjszKoqH4SkTA7pVA=' blob:; form-action 'self'; report-uri https://www.ethikrat.org/@http-reporting?csp=report&requestTime=1765934477438233&requestHash=0bef986a2c53d91f6ca49cc13c3b52025d6229e0 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.doubleclick.net *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleadservices.com *.analytics.google.com *.googletagmanager.com *.doubleclick.net cdn.cookielaw.org *.linkedin.com *.google.co.in *.facebook.com *.postcodeanywhere.co.uk *.googlesyndication.com bat.bing.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleadservices.com *.analytics.google.com *.googletagmanager.com *.gstatic.com cdn.cookielaw.org connect.facebook.net googleapis.com *.pcapredict.com *.postcodeanywhere.co.uk *.cloudfront.net bat.bing.com *.cloudflareinsights.com *.licdn.com *.mouseflow.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.postcodeanywhere.co.uk maxcdn.bootstrapcdn.com *.nosto.com *.nos.to assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.analytics.google.com *.google.co.in api.addressy.com cdn.cookielaw.org *.pcapredict.com *.postcodeanywhere.co.uk *.googlesyndication.com *.onetrust.com *.licdn.com *.linkedin.com *.nosto.com *.nos.to *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'report-sample' 'nonce-8ht2MVsH67b3' 'strict-dynamic' https: http: 'unsafe-eval'; base-uri 'self'; report-to endpoint-report; report-uri https://membre.carenity.com/csp/report/public; font-src https://www.carenity.com/ data: https://appleid.cdn-apple.com/ https://fonts.gstatic.com ; frame-src https://td.doubleclick.net https://m.youtube.com https://myaccount.google.com https://accounts.google.com/ https://www.googletagmanager.com/ https://www.youtube.com/ https://www.carenity.com/ https://drive.google.com/ https://www.google.com/recaptcha/; object-src https://www.youtube.com/ https://membre.carenity.com/static/docs/; style-src 'unsafe-inline' https://www.carenity.com/ https://www.amcharts.com/ https://ajax.googleapis.com/ https://accounts.google.com/gsi/style https://fonts.googleapis.com https://www.googletagmanager.com https://www.gstatic.com; form-action https://www.carenity.com/ https://membre.carenity.com/; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://customcheckout-uat.bambora.net.au https://customcheckout.bambora.com.au https://www.facebook.com https://www.google.com https://www.google.com.au https://secure.livechatinc.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net *.ftcdn.net *.behance.net data: https://www.google.com https://www.google.com.au https://analytics.sleeknote.com https://cdn.na.bambora.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://cdn.livechatinc.com https://api.livechatinc.com https://sc.lfeeder.com https://js-agent.newrelic.com https://sleeknotecustomerscripts.sleeknote.com https://www.googletagmanager.com https://www.google.com https://www.google.com.au https://www.gstatic.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google-analytics.com https://hosted.mastersoftgroup.com https://customcheckout-uat.bambora.net.au https://customcheckout.bambora.com.au https://www.dwin1.com https://sleeknotestaticcontent.sleeknote.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.google.com https://www.google.com.au https://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io https://bam.nr-data.net https://hosted.mastersoftgroup.com https://api.livechatinc.com https://www.google.com https://www.google.com.au https://www.googleadservices.com https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://tracker.metricool.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://tracker.metricool.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-src 'self'; form-action 'self'; frame-ancestors 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://static.xfarma.it *.fontawesome.com *.googleapis.com https://fonts.bunny.net https://applepay.cdn-apple.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors localhost:* *.motive.co *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.xfarma.it *.xfarma.it https://www.google.it https://bat.bing.com https://c.bing.com https://c.clarity.ms https://pagead2.googlesyndication.com *.facebook.com https://firebasestorage.googleapis.com *.motive.co https://secure-magenta.dalenys.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://www.xfarma.it *.xfarma.it https://bat.bing.com https://cdn.doofinder.com https://d.clarity.ms https://eu1-search.doofinder.com https://pagead2.googlesyndication.com https://plausible.io https://tps.trovaprezzi.it https://www.clarity.ms *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com *.motive.co https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com tracking.trovaprezzi.it www.trovaprezzi.it *.trustpilot.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.xfarma.it *.fontawesome.com https://fonts.bunny.net https://secure-magenta.dalenys.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://connect.facebook.net https://eu1-search.doofinder.com https://www.facebook.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://plausible.io https://pagead2.googlesyndication.com https://static.xfarma.it https://d.clarity.ms https://get.geojs.io *.avada.io *.motive.co *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; img-src 'self' data: https://stats.o74.net; script-src 'self' https://stats.o74.net/piwik.js 'nonce-eU5eDZbaLdpI3rldxL5IPFwNWdfxtwAI' 'unsafe-inline'; style-src 'self' 'nonce-eU5eDZbaLdpI3rldxL5IPFwNWdfxtwAI'; font-src 'self'; connect-src 'self' https://stats.o74.net ; base-uri 'self'; frame-ancestors 'none'; form-action 'self'; report-uri https://cspreporter.o74.net/tell/manpag.es; report-to cspreporter-o74; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://cdn.riverty.design/ use.fontawesome.com cdnjs.cloudflare.com maxcdn.bootstrapcdn.com static.dhlparcel.nl fonts.googleapis.com kit-pro.fontawesome.com fonts.bunny.net cdn.jsdelivr.net zinzi.nl www.zinzi.nl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * uc8.tv www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * uc8.tv https://documents.riverty.com/ *.sharethis.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com marcvanwilligen.nl www.marcvanwilligen.nl *.trustpilot.com *.fls.doubleclick.net view.publitas.com zinzi.prepaidpoint.nl checkoutshopper-test.adyen.com www.facebook.com ct.pinterest.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com uat-secure.pointspay.com secure.pointspay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ *.sharethis.com www.facebook.com *.fls.doubleclick.net www.zinzi.nl *.datatrics.com *.pinterest.com static.sooqr.com maps.googleapis.com maps.gstatic.com checkoutshopper-test.adyen.com ssl.google-analytics.com *.ggpht.com trengo.s3.eu-central-1.amazonaws.com *.sooqr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com uat-secure.pointspay.com secure.pointspay.com www.magmodules.eu *.squeezely.tech ade.googlesyndication.com *.pointspay.com imgsct.cookiebot.com zinzi.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com checkoutshopper-test.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.trustpilot.com marcvanwilligen.nl www.marcvanwilligen.nl *.googletagmanager.com *.widget.trengo.eu connect.facebook.net *.pinterest.com *.datatrics.com static.sooqr.com view.publitas.com maps.googleapis.com ssl.google-analytics.com www.zinzi.nl s.pinimg.com static.dhlparcel.nl widget-acc.paazl.com *.sooqr.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com uat-secure.pointspay.com secure.pointspay.com squeezely.tech www.squeezely.tech *.squeezely.tech *.marcvanwilligen.nl loylfy.test consent.cookiebot.com app.varify.io varify.io widget.paazl.com api.paazl.com api-acc.paazl.com consentcdn.cookiebot.com js-agent.newrelic.com zinzi.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.sharethis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com marcvanwilligen.nl www.marcvanwilligen.nl *.fontawesome.com static.sooqr.com static.dhlparcel.nl https://widget-acc.paazl.com *.sooqr.com assets.braintreegateway.com *.marcvanwilligen.nl fonts.bunny.net *.widget.trengo.eu ct.pinterest.com widget-acc.paazl.com api-acc.paazl.com widget.paazl.com api.paazl.com zinzi.nl www.zinzi.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.widget.trengo.eu *.trengohelp.com stats.g.doubleclick.net *.datatrics.com api-acc.paazl.com *.amazonaws.com maps.googleapis.com ct.pinterest.com https://widget-acc.paazl.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com uat-secure.pointspay.com secure.pointspay.com squeezely.tech *.squeezely.tech pagead2.googlesyndication.com region1.google-analytics.com app.varify.io varify.io widget.paazl.com widget-acc.paazl.com consentcdn.cookiebot.com googleads.g.doubleclick.net/ sst.zinzi.nl api.paazl.com zinzi.nl www.zinzi.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.nl ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.nl *.spreadshirt.nl ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.nl ; font-src 'self' https: data: *.spreadshirt.nl ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.nl ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.nl ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com https://fonts.bunny.net *.yotpo.com *.googleapis.com https://accounts.livechat.com/ *.globewest.com.au *.shopify.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com *.globewest.com.au 'self' 'unsafe-inline'; frame-ancestors *.globewest.com.au 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com *.yotpo.com https://accounts.livechat.com/ *.globewest.com.au 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com *.yotpo.com https://accounts.livechat.com/ *.globewest.com.au *.linkedin.com *.facebook.com *.clarity.ms *.pinterest.com *.nr-data.net *.bing.com *.google.com *.google.com.vn data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://api.addressfinder.io https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com *.cloudflare.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.shopify.com *.bpaygroup.com.au js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.searchspring.net/intellisuggest/is.min.js www.xtento.com cdn.xtento.com *.yotpo.com https://accounts.livechat.com/ https://bam.nr-data.net/* *.facebook.net *.globewest.com.au *.addtoany.com *.hotjar.com *.livechatinc.com *.licdn.com *.pinimg.com *.bing.com *.clarity.ms unpkg.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.addressfinder.io webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com *.googleapis.com *.addtoany.com https://fonts.bunny.net assets.braintreegateway.com *.yotpo.com https://accounts.livechat.com/ *.globewest.com.au 'self' 'unsafe-inline'; object-src https://accounts.livechat.com/ *.globewest.com.au 'self' 'unsafe-inline'; media-src *.adobe.com https://accounts.livechat.com/ *.globewest.com.au 'self' 'unsafe-inline'; manifest-src *.globewest.com.au 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://api.addressfinder.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://dpm.demdex.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://beacon.searchspring.io/beacon *.yotpo.com https://accounts.livechat.com/ https://bam.nr-data.net/* *.globewest.com.au *.linkedin.com *.facebook.com *.clarity.ms *.pinterest.com *.bing.com *.google.com.vn 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com https://bam.nr-data.net/* *.globewest.com.au http: https: blob: 'self' 'unsafe-inline'; default-src https://accounts.livechat.com/ https://bam.nr-data.net/* *.globewest.com.au 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.globewest.com.au 'self' 'unsafe-inline'; 1 font-src *.googleapis.com maxcdn.bootstrapcdn.com *.yoursurprise.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.cookiebot.com *.gstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.buckaroo.nl ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com dev.visualwebsiteoptimizer.com *.yoursurprise.com *.gstatic.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.google-analytics.com bam.nr-data.net dev.visualwebsiteoptimizer.com *.cookiebot.com *.googletagmanager.com *.gstatic.com *.newrelic.com *.googleapis.com yspimages-yoursurprisecom.netdna-ssl.com yspimages.net *.yoursurprise.nl *.yoursurprise.com *.trackedlink.net *.hotjar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tm.tradetracker.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl downloads.mailchimp.com *.googleapis.com maxcdn.bootstrapcdn.com yspimages-yoursurprisecom.netdna-ssl.com *.yoursurprise.nl *.yoursurprise.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com bam.nr-data.net *.yoursurprise.nl *.yoursurprise.com *.gstatic.com *.newrelic.com *.googlesyndication.com *.google.com *.google.ie api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.buckaroo.nl *.googlesyndication.com *.google.com *.google.ie *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://je9qpq.pixum.fr https://xn5xehfzuw.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://je9qpq.pixum.fr https://xn5xehfzuw.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://5b0dfxfhuka0vuk5ju0see3i.httpschecker.net/report 1 font-src *.cloudflare.com *.candid-io.site44.com *.gstatic.com *.typekit.net data: *.googleapis.com fonts.googleapis.com *.hotjar.com *.bootstrapcdn.com *.fontawesome.com * www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors * 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ *.google.com 'self' www.searchanise.com *.searchserverapi.com *.twitter.com https://sandbox.sequracdn.com https://live.sequracdn.com www.blackrecon.com https://live.sequrapi.com *.searchserverapi1.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://www.magezon.com *.blackrecon.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.searchanise.com * *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com *.google.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.typekit.net *.fontawesome.com *.hsforms.net *.hsforms.com *.netdna-ssl.com *.jquery.com *.googleapis.com *.hotjar.com https://searchserverapi.com *.searchanise.com *.blackrecon.com *.googletagmanager.com *.googleadservices.com https://searchserverapi.com/widgets/v1.0/init.js 'self' 'unsafe-inline' 'unsafe-eval' * searchserverapi.com *.sequracdn.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com searchserverapi1.com api.amplitude.com *.twitter.com *.twimg.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.hotjar.com *.cloudflare.com *.googleapis.com *.twimg.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com * www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cloudflare.com *.candid-io.site44.com *.paypal.com *.hsforms.net *.hsforms.com *.googleapis.com *.hotjar.com * api.amplitude.com stats.g.doubleclick.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src * 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem https://*.usercentrics.eu/ https://bestware.com *.bestware.tech local.bestware https://*.googletagmanager.com https://*.google.com https://*.gstatic.com www.google-analytics.com https://*.easycredit.de https://*.klaviyo.com https://widgets.trustedshops.com/ https://*.bing.com/ https://*.facebook.com/ https://*.facebook.net/ https://*.twitter.com/ https://static.ads-twitter.com/ https://*.payments-amazon.com/ https://*.cptrack.de https://survey.survicate.com/ https://analytics.tiktok.com/ https://static.zdassets.com/ 'self' 'unsafe-inline' https://www.paypal.com/ https://*.jquery.com/ https://*.zendesk.com/ https://*.etracker.com https://*.etracker.de; font-src https://*.klaviyo.com https://*.danova.de *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https: https://seo.mageplaza.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com https: https://*.etracker.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https: https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com https://bestware.com *.bestware.tech local.bestware https://app.usercentrics.eu/ https://*.google.de https://google.co.* https://*.bing.com/ https://bat.bing.net/ https://*.twitter.com/ https://*.facebook.com/ https://*.trustedshops.com/ https://*.cloudfront.net/ https://t.co/ https://www.gstatic.com/ https://analytics.tiktok.com/ https://assets.adobedtm.com/ https://*.etracker.com https://*.etracker.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ratenkauf.easycredit.de *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.usercentrics.eu/ https://widgets.trustedshops.com/ https://*.bing.com/ https://*.facebook.net/ https://static.ads-twitter.com/ https://*.jquery.com/ https://*.etracker.com https://*.etracker.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ratenkauf.easycredit.de *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.klaviyo.com https://*.danova.de https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.bestware.com https://bestware.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.analytics.google.com *.google.com google.com *.googlesyndication.com/ https://api.usercentrics.eu/ https://*.doubleclick.net/ https://*.facebook.com/ https://bat.bing.net/ https://analytics.tiktok.com/ https://ekr.zdassets.com/ https://*.zendesk.com/ wss://*.zendesk.com/ https://*.danova.de https://*.etracker.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ratenkauf.easycredit.de t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: cdn.radiall.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net distributors.radiall.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com cdn.radiall.com *.cookiebot.com *.livechatinc.com distributors.radiall.com https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.googleapis.com *.bird.eu cdn.radiall.com *.cookiebot.com *.linkedin.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.radiall.com *.livechatinc.com *.bc0a.com api.brightedge.com snap.licdn.com *.linkedin.oribi.io *.googletagmanager.com *.google-analytics.com analytics.google.com *.doubleclick.net *.cookiebot.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.avada.io *.shopify.com https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.radiall.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.googleapis.com cdn.radiall.com *.linkedin.com *.bc0a.com api.brightedge.com *.google-analytics.com *.doubleclick.net *.cookiebot.com *.linkedin.oribi.io analytics.google.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.trustedshops.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://www.facebook.com/ www.google.com youtu.be *.vimeo.com *.addthis.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net gateway.apaylater.com gateway.atome.sg *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu blob: https://www.magezon.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com gateway.apaylater.com gateway.atome.sg https://connect.facebook.net/ *.cloudflare.com *.google-analytics.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com www.paypal.com www.paypalobjects.com www.sandbox.paypal.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com gateway.apaylater.com gateway.atome.sg *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://socialplugin.facebook.net/ https://www.facebook.com/ *.cloudflare.com *.googleapis.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://static.olark.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * secure.nmi.com secure.networkmerchants.com collectcheckout.com vyapay.transactiongateway.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com secure.nmi.com secure.networkmerchants.com collectcheckout.com vyapay.transactiongateway.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com platform.twitter.com https://plumrocket.com https://accounts.google.com https://static.olark.com https://www.facebook.com https://assets.braintreegateway.com https://ssl.kaptcha.com https://www.google.com https://www.gstatic.com https://www.youtube.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com secure.nmi.com secure.networkmerchants.com collectcheckout.com vyapay.transactiongateway.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com magefan.com cm.magefan.com *.disqus.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://seal-dallas.bbb.org https://www.facebook.com https://log.olark.com https://timepayment.net https://maps.gstatic.com *.cloudfront.net https://www.google.com https://www.google.com.ua https://secure.trust-provider.com/trustlogo/images/popup/seal_bg.gif https://secure.trust-provider.com/trustlogo/images/popup/warranty_level.gif https://www.positivessl.com/images/seals/positivessl_trust_seal_md_167x42.png *.klevu.com *.ksearchnet.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://img.youtube.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.disqus.com https://cdn.jsdelivr.net connect.facebook.net twitter.com platform.twitter.com static.addtoany.com *.googletagmanager.com https://accounts.google.com https://www.gstatic.com https://seal-dallas.bbb.org https://connect.facebook.net https://static.olark.com https://cdn.timepayment.com https://knrpc.olark.com https://api.olark.com https://ajax.googleapis.com https://c.paypal.com https://www.google.com https://secure.trust-provider.com/trustlogo/javascript/trustlogo.js https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js js.klevu.com *.ksearchnet.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.paytomorrow.com *.instagram.com *.maxmind.com secure.nmi.com secure.networkmerchants.com collectcheckout.com vyapay.transactiongateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://accounts.google.com https://www.gstatic.com https://seal-dallas.bbb.org https://static.olark.com https://seal-blue.bbb.org/legacy.min.css *.klevu.com *.ksearchnet.com *.googleapis.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.paytomorrow.com secure.nmi.com https://statsjs.klevu.com https://js.klevu.com https://www.ironcompany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de stats.addtoany.com https://accounts.google.com https://knrpc.olark.com https://payments.braintree-api.com https://client-analytics.braintreegateway.com https://www.paypal.com https://www.google-analytics.com https://stats.g.doubleclick.net *.klevu.com *.ksearchnet.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.instagram.com *.googleusercontent.com *.mmapiws.com secure.nmi.com secure.networkmerchants.com collectcheckout.com vyapay.transactiongateway.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.lampesdirect.fr data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.lampesdirect.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.lampesdirect.fr 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b428c232-f415-4fb2-b456-fef23ba335ec.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; base-uri 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'sha256-UzUNtIZ5hG8ovGepAOrHqczYk0kwcAKKMAD5HEvAZUw=' https://static.cloudflareinsights.com https://*.clarity.ms https://kit.fontawesome.com https://cdn.headwayapp.co https://connect.facebook.net https://js.intercomcdn.com https://api-iam.intercom.io https://widget.intercom.io https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-analytics.net https://js.hs-banner.com https://js.usemessages.com https://*.hsadspixel.net https://*.hs-analytics.net https://js.hscta.net https://js-eu1.hscta.net https://static.hsappstatic.net https://*.hubspot.com https://*.usemessages.com https://*.hs-banner.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://*.hubspot.net https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hsforms.net https://*.hsforms.com https://*.hs-scripts.com https://*.hubspotfeedback.com https://feedback.hubapi.com https://feedback-eu1.hubapi.com https://www.googletagmanager.com https://*.doubleclick.net; style-src 'self' 'unsafe-inline' https://cdn.headwayapp.co https://pro.fontawesome.com https://ka-p.fontawesome.com https://cdn2.hubspot.net https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net; img-src 'self' data: blob: https://pro.fontawesome.com https://ka-p.fontawesome.com https://js.hscta.net https://js-eu1.hscta.net https://no-cache.hubspot.com https://*.hubspot.com https://*.hubspotusercontent00.net https://*.hubspotusercontent10.net https://*.hubspotusercontent20.net https://*.hubspotusercontent30.net https://*.hubspotusercontent40.net https://*.hubspot.net https://cdn2.hubspot.net https://*.hsforms.net https://*.hsforms.com https://www.facebook.com https://www.google.com https://www.google.com.br; font-src 'self' data: https://pro.fontawesome.com https://ka-p.fontawesome.com; connect-src 'self' https://*.3c.plus https://*.clarity.ms https://connect.facebook.net https://widget.intercom.io https://ka-p.fontawesome.com https://pro.fontawesome.com wss://*.intercom.io wss://*.3c.plus wss://*.3c.plus:4443 wss://vox-socket.3c.fluxoti.com:4443 https://*.hubapi.com https://js.hscta.net https://js-eu1.hscta.net https://*.hubspot.com https://*.hs-banner.com https://*.hscollectedforms.net https://*.hsforms.com https://www.google.com https://www.googletagmanager.com https://*.doubleclick.net; media-src 'self' https://*.3c.plus; frame-src 'self' https://headway-widget.net https://www.youtube.com https://www.youtube-nocookie.com https://*.3c.plus https://*.hubspot.com https://*.hs-sites.com https://*.hs-sites-eu1.com https://*.hubspot.net https://play.hubspotvideo.com https://play-eu1.hubspotvideo.com https://*.hsforms.net https://*.hsforms.com https://www.googletagmanager.com https://*.doubleclick.net; frame-ancestors https:; object-src 'none'; worker-src 'self'; 1 default-src 'self';frame-src 'self' https://*.youtube.com https://*.hubspotvideo.com https://*.hubspot.com https://*.google.com https://*.googletagmanager.com https://*.hsforms.com https://*.twitter.com https://*.doubleclick.net;img-src 'self' https://*.hubspotusercontent-na1.net https://*.hubspotvideo.com https://*.google.com https://*.hs-embed-reporting.com https://*.googletagmanager.com https://*.hsforms.com https://*.hubspot.com https://*.linkedin.com https://*.hsappstatic.net https://*.google.co.in https://*.ytimg.com https://*.facebook.com https://*.clarity.ms https://*.bing.com;style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.hubspotusercontent-na1.net https://*.hubspotvideo.com https://*.hubspot.net https://*.hsappstatic.net;connect-src 'self' https://*.hubspotvideo.com https://*.hubspot.com https://*.zi-scripts.com https://*.zoominfo.com https://*.googlesyndication.com https://*.hs-banner.com https://*.hubapi.com https://*.hscollectedforms.net https://*.clarity.ms https://*.hsforms.com https://*.google.com https://*.linkedin.com https://*.google-analytics.com https://*.google.co.in https://*.doubleclick.net;font-src 'self' https://*.gstatic.com https://*.hubspotvideo.com https://*.hubspot.com https://*.hubspotusercontent-na1.net;script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.hubspot.com https://*.googletagmanager.com https://*.clarity.ms https://*.factors.ai https://*.hubspotusercontent-na1.net https://*.hsappstatic.net https://*.hsadspixel.net https://*.hsleadflows.net https://*.usemessages.com https://*.hs-analytics.net https://*.hscollectedforms.net https://*.hs-banner.com https://*.hs-sites.com https://*.zi-scripts.com;object-src 'none';frame-ancestors 'self' 1 report-uri https://csp.vilmos.co.uk/CspReport?header=Content-Security-Policy-Report-Only 'self'; default-src 'self'; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.linkedin.com https://*.googletagmanager.com *.truste.com *.trustarc.com *.trustpilot.com *.bing.com *.adalyser.com https://utt.impactcdn.com *.doubleclick.net *.tiktok.com *.google-analytics.com *.twitter.com *.linkstant.com *.ensighten.com 'unsafe-inline' 'unsafe-eval' *.eloqua.com *.en25.com web-chat.nativechat.com https://cdn.insight.sitefinity.com https://dec.azureedge.net cdn.ampproject.org js.hs-scripts.com js.hs-analytics.net js.hs-banner.com js.hsleadflows.net forms.hubspot.com js.hscollectedforms.net; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com 'unsafe-inline' web-chat.nativechat.com https://cdn.insight.sitefinity.com https://dec.azureedge.net; img-src 'self' *.gstatic.com *.googleapis.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png data: blob: https://*.googletagmanager.com *.adnxs.com *.t.co *.adalyser.com *.googlesyndication.com *.bing.net *.trustarc.com *.adsrvr.org *.google.com *.bing.com *.mathtag.com *.google.co.uk *.twitter.com https://t.co *.doubleclick.net *.insight.adsrvr.org https://uk.protectyourbubble.com *.eloqua.com web-chat.nativechat.com https://cdn.insight.sitefinity.com https://dec.azureedge.net track.hubspot.com js.hsleadflows.net forms.hsforms.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: *.trustarc.com *.truste.com; frame-src 'self' *.trustarc.com *.googletagmanager.com *.trustpilot.com *.doubleclick.net web-chat.nativechat.com forms.hsforms.com; connect-src 'self' data: accounts.google.com *.gstatic.com https://*.googletagmanager.com *.bing.net *.trustarc.com *.googlesyndication.com *.doubleclick.net *.bing.com *.google-analytics.com *.google.com *.tiktokw.us *.tiktok.com *.trustpilot.com *.googleapis.com *.googleadservices.com https://*.insight.sitefinity.com https://*.dec.sitefinity.com forms.hubspot.com *.hsforms.com; media-src 'self' data: blob:; child-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com web-chat.nativechat.com 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.facebook.net https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.affirm.com *.affirm.ca *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.affirm.com *.affirm.ca magefan.com cm.magefan.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.affirm.com *.affirm.ca *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net www.facebook.com https://cdn.consentmanager.net https://delivery.consentmanager.net connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com www.facebook.com *.facebook.net *.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.coinpayments.net www.amsterdamseedcenter.com amsterdamcbdcenter.com https://www.magezon.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.zopim.com *.getresponse.com browser.sentry-cdn.com static.hotjar.com script.hotjar.com static.zdassets.com static.cloudflareinsights.com *.google.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com ekr.zdassets.com support-wyqq9.zendesk.com wss://widget-mediator.zopim.com metrics.hotjar.com metrics.hotjar.io *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com https://www.googleadservices.com https://www.googleoptimize.com https://www.google-analytics.com https://cookie-cdn.cookiepro.com https://munchkin.marketo.net https://script.crazyegg.com https://snap.licdn.com https://bat.bing.com https://googleads.g.doubleclick.net https://trk.techtarget.com https://tag.marinsm.com https://komito.net https://pixel-geo.prfct.co https://www.clarity.ms https://b2btagmgr.azalead.com https://*.adroll.com https://static.addtoany.com; script-src-attr 'self'; script-src-elem 'self' https://www.googletagmanager.com 'sha256-FpNA5qjKVUpZDhy5Gnq9feQZbD33N+EF38yukPxoGas=' 'sha256-As6F+kKnguakKZJhou419i5+OTBMkVhEedCIew0+w6M=' 'sha256-0QANSs7BsNN1shZdeRMPb5HoBlkYS6c9i74X2YRSYvE=' 'sha256-e5l0JnipN+mfcgkwcsxv9nviFTygz9kKxVMGCxUA94s=' 'sha256-5TSo/ossgUVqQiI/8fxPSw8wJ57QLsfqde7c7J6Nw/c=' 'sha256-STi4MOt6ijkbM+hg8YAEqROyVsP46zQWoIrrnxe9Wco=' https://www.googleadservices.com https://www.googleoptimize.com https://www.google-analytics.com https://cookie-cdn.cookiepro.com https://munchkin.marketo.net https://view.ceros.com https://player.vimeo.com https://script.crazyegg.com https://snap.licdn.com https://m.addthis.com https://z.moatads.com https://v1.addthisedge.com 'sha256-3/mNUpqF9X/gMYE+bOG6g8d6I32wdYdWwWuAk90mPCM=' 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' https://bat.bing.com https://googleads.g.doubleclick.net https://trk.techtarget.com https://tag.marinsm.com https://komito.net https://pixel-geo.prfct.co https://www.clarity.ms https://b2btagmgr.azalead.com https://*.adroll.com https://bam.nr-data.net https://js-agent.newrelic.com 'sha256-De2mpaFLR0YDSf4Kwof2qARuqqxurfOvrVuX1nl4SGc=' https://static.addtoany.com; style-src 'self' 'unsafe-inline' https://app-lon05.marketo.com https://cookie-cdn.cookiepro.com https://www.googletagmanager.com https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; worker-src 'self' blob:; frame-ancestors 'self' 1 font-src https://*.gstatic.com *.cdnfonts.com *.cloudflare.com *.flaticon.com *.hotjar.com *.typekit.net *.fontawesome.com https://fonts.gstatic.com *.alothemes.com *.magepow.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.facebook.com *.facebook.net js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com https://*.gstatic.com www.annoushka.com *.bing.com *.bing.net *.clarity.ms *.cookiepro.com *.doubleclick.net *.facebook.com *.google.com *.googleapis.com *.googlesyndication.com *.linksynergy.com *.ometria.com *.paypal.com *.pinterest.com *.stromdev.dk *.webeyez.com alekseon.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.sc www.google.se www.google.si www.google.sk www.google.so www.google.sr www.google.tl www.google.tn www.google.tt www.google.ws *.pinterdev.com *.pinimg.com commerce-app.pintergration.com www.feedoptimise.com cdn.feedoptimise.com *.facebook.net *.alothemes.com *.magepow.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com *.bing.com *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.cookiepro.com *.facebook.com *.facebook.net *.google.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.instagram.com *.jsdelivr.net *.linksynergy.com *.ometria.com *.pinimg.com *.pinterest.com *.rakuten.com *.rmtag.com *.stromdev.dk *.vimeo.com *.webeyez.com *.zdassets.com *.pinterdev.com commerce-app.pintergration.com www.feedoptimise.com cdn.feedoptimise.com *.alothemes.com *.magepow.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ *.cloudflare.com *.googletagmanager.com *.jsdelivr.net *.fontawesome.com https://fonts.googleapis.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.paypal.com *.vimeocdn.com vimeo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com https://maps.googleapis.com https://player.vimeo.com annoushka.zendesk.com *.bing.com *.bing.net *.clarity.ms *.cookiepro.com *.doubleclick.net *.facebook.com *.google-analytics.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.jsdelivr.net *.onetrust.com *.pinterest.com *.webeyez.com *.zdassets.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.me www.google.mg www.google.mk www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn www.google.tt *.pinterdev.com commerce-app.pintergration.com api.addressy.com *.facebook.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.analytics.google.com *.googletagmanager.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a151097b-34c7-4698-ad35-1b435107f987.sansec.watch/; report-to report-endpoint; 1 font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://popsql.com https://popsql.com ; frame-src 'self' https://vercel.live ; media-src 'self' blob: ; script-src 'self' 'unsafe-inline' https://popsql.com https://popsql.com http://cdn.mxpnl.com http://fast.wistia.com http://static.asayer.io http://www.google-analytics.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.googletagmanager.com https://assets.customer.io https://cdn.koala.live https://cdn.segment.com https://cmp.osano.com https://js-na1.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsadspixel.net https://snap.licdn.com https://static.asayer.io https://vercel.live https://www.redditstatic.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.googleapis.com ; worker-src 'self' blob: ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.google-analytics.fr *.facebook.com *.linkedin.com https://axeptio.imgix.net *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.facebook.net *.licdn.com *.axept.io *.hotjar.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.fr *.google-analytics.com *.facebook.com *.doubleclick.net *.oribi.io *.axept.io *.linkedin.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.amazonaws.com *.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.mastercard.com *.gateway.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net *.amazonaws.com *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://static.klaviyo.com unsafe-inline *.mastercard.com *.gateway.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.mastercard.com *.gateway.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.mastercard.com *.gateway.mastercard.com *.klaviyo.com *.google-analytics.com *.google.com *.google.com.lb *.livechatinc.com *.gstatic.com *.googleapis.com *.facebook.net *.facebook.com *.usercentrics.eu *.doubleclick.net *.newrelic.com *.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.globalpay.com *.fontawesome.com https: *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.tidiochat.com www.tradefurniturecompany.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com www.tradefurniturecompany.co.uk 'self' 'unsafe-inline'; frame-ancestors *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk www.tradefurniturecompany.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com *.hotjar.com *.tidiochat.com *.googletagmanager.com www.tradefurniturecompany.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobedtm widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.dycdn.net *.globalpay.com *.pbffinancecalculator.info cdn.shopify.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdnjs.cloudflare.com https: *.trustedshops.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.tidiochat.com *.pinterest.com *.facebook.net *.bing.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com www.tradefurniturecompany.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://code.tidio.co https://widget-v4.tidiochat.com *.hotjar.com *.cloudflare.com *.twitter.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.tidiochat.com *.tidio.co *.pinimg.com *.pinterest.com *.facebook.net *.bing.com *.clarity.ms *.googletagmanager.com tagmanager.google.com www.tradefurniturecompany.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.dycdn.net https://fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'unsafe-inline' https: *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.tidiochat.com *.pinterest.com *.facebook.net tagmanager.google.com fonts.google.com www.tradefurniturecompany.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com widget-v4.tidiochat.com *.tidiochat.com www.tradefurniturecompany.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.dycdn.net *.freshrelevance.com wss://*.freshrelevance.com wss://*.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com https://google.com/pay *.staging-pbffinancecalculator.info *.pbffinancecalculator.info wss://*.staging-pbffinancecalculator.info wss://*.pbffinancecalculator.info *.paybyfinance.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com sentry-new.tidio.co socket.tidio.co api-v2.tidio.co *.google-analytics.com *.analytics.google.com *.googletagmanager.com www.tradefurniturecompany.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.tradefurniturecompany.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.tradefurniturecompany.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magenative.com magenative.cedcommerce.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com checkout.tabby.ai *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.googletagmanager.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://ssl.ingersoll-imc.com https://www.google-analytics.com https://platform.twitter.com https://www.googletagmanager.com https://wpcc.io https://recruitingbypaycor.com; style-src 'self' 'unsafe-inline' http://ssl.ingersoll-imc.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://ajax.googleapis.com https://wpcc.io https://cdn.websitepolicies.io; img-src 'self' https://ssl.ingersoll-imc.com https://www.google-analytics.com https://syndication.twitter.com https://stats.g.doubleclick.net; connect-src 'self' https://syndication.twitter.com https://www.google-analytics.com https://stats.g.doubleclick.net; font-src 'self' https://ssl.ingersoll-imc.com https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com; form-action 'self' https://syndication.twitter.com https://platform.twitter.com; frame-src https://platform.twitter.com https://syndication.twitter.com https://recruitingbypaycor.com/; report-uri https://report.ingersoll-imc.com 1 default-src 'self'; img-src https: http: blob: data:; style-src 'self' 'unsafe-inline' https://scripts.gmod.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://scripts.gmod.de https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://ssl.google-analytics.com https://www.google.com/js/ https://vbg-version.vbulletin.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://scripts.gmod.de https://www.google.com/recaptcha/ https://www.youtube.com; object-src 'none'; upgrade-insecure-requests; report-uri https://tunnat.report-uri.com/r/d/csp/reportOnly 1 font-src maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.freshchat.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.paytabs.com *.paytabs.sa * *.freshchat.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.freshchat.com cdnjs.cloudflare.com js-agent.newrelic.com bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.freshchat.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.freshchat.com bam.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ secure.payu.com merch-prod.snd.payu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com static.payu.com https://maps.gstatic.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ secure.payu.com secure.snd.payu.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.payu.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com secure.payu.com merch-prod.snd.payu.com https://maps.googleapis.com https://places.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://jobs.b-ite.com https://bwp-online.gelsenkirchen.de https://ads.gelsen.net https://ads2.gelsen.net https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de; style-src 'self' 'unsafe-inline' https://bwp-online.gelsenkirchen.de https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://cdn.podigee.com; img-src 'self' https://ads.gelsen.net https://ads.gelsen.net https://webstatistik.gelsenkirchen.de https://server.arcgisonline.com https://*.tile.openstreetmap.org https://geodaten.metropoleruhr.de https://gdi.gelsenkirchen.de https://twebshop.tomas-travel.com https://cdn.podigee.com https://images.podigee-cdn.net https://cs-assets.b-ite.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.youtube.com https://pansite6.gelsenkirchen.de https://ads.gelsen.net https://ads.gelsen.net https://webstatistik.gelsenkirchen.de https://static.b-ite.com https://cs-assets.b-ite.com https://bwp-online.gelsenkirchen.de/ https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://cdn.podigee.com https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de; child-src 'self' https://www.youtube.com https://player.vimeo.com https://www.youtube-nocookie.com https://whitelabel.hotel.de https://tempus-termine.com https://*.gelsenkirchen.de https://player.podigee-cdn.net https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de 1 font-src fonts.gstatic.com use.typekit.net userlike-cdn-umm.b-cdn.net *.trustedshops.com *.gstatic.com 'self' data: data: *.stamped.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ariba.com punchoutcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.ariba.com punchoutcommerce.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.bolt.com https://www.google.com/recaptcha/ *.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com userlike-cdn-umm.b-cdn.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.livechatinc.com *.braintreegateway.com *.kaptcha.com www.paypalobjects.com *.affirm.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net 'self' https://scontent.cdninstagram.com *.bird.eu *.usercentrics.eu *.googletagmanager.com *.gstatic.com bat.bing.com www.google.de *.userlike.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com userlike-store-media-files.s3.amazonaws.com userlike-cdn-web.b-cdn.net *.trustedshops.com https://widgets-qa.trustedshops.com *.googlesyndication.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net 'self' data: maps.googleapis.com maps.gstatic.com www.facebook.com www.gstatic.com www.google.pl *.stamped.io *.amazonaws.com *.userway.org verify.authorize.net scontent.cdninstagram.com *.affirm.com *.routeapp.io *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com f.vimeocdn.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net use.typekit.net *.magento-datasolutions.com *.magento-ds.com *.usercentrics.eu *.googletagmanager.com *.clarity.ms https://matomo.brewes.de api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com userlike-cdn-umm.b-cdn.net bat.bing.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io www.google.com *.gstatic.com maps.googleapis.com maps.gstatic.com connect.facebook.net http://translate.google.com translate.googleapis.com www.gstatic.com includes.ccdc02.com static.zdassets.com cdn.inspectlet.com *.stamped.io *.livechatinc.com *.userway.org www.klarnapayments.com *.affirm.com *.routeapp.io *.trustedshops.com *.etrusted.com *.etrusted.site 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googletagmanager.com *.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com unsafe-inline assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.googleapis.com *.gstatic.com *.stamped.io www.klarnapayments.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' https://scontent.cdninstagram.com *.userlike.com userlike-store-media-files.s3.amazonaws.com userlike-cdn-umm.b-cdn.net static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.magento.com commerce.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.sentry.io *.usercentrics.eu *.googletagmanager.com *.clarity.ms api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://matomo.brewes.de bat.bing.com *.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com userlike-cdn-web.b-cdn.net userlike-cdn-umm.b-cdn.net wss://umd.userlike.com googleads.g.doubleclick.net *.trustedshops.com *.etrusted.com *.etrusted.site *.googlesyndication.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com t.elasticsuite.io *.google-analytics.com *.authorize.net ekr.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com hn.inspectlet.com stamped.io *.braintreegateway.com *.livechatinc.com *.userway.org graph.instagram.com *.affirm.com *.route.com 'self' 'unsafe-inline'; child-src api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com userlike-cdn-umm.b-cdn.net assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' inline 'unsafe-eval' https://www.googletagmanager.com https://public.flourish.studio https://static.axept.io https://challenges.cloudflare.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://www.googletagmanager.com https://static.hotjar.com https://script.hotjar.com https://static.axept.io https://public.flourish.studio https://cdn.addsearch.com https://challenges.cloudflare.com; script-src-attr 'self' 'unsafe-inline' inline https://static.axept.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline' inline; style-src-elem 'self' 'unsafe-inline' https://cdn.addsearch.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://client.axept.io/ https://api.axept.io https://static.axept.io https://www.google-analytics.com https://analytics.google.com https://axeptio.imgix.net https://content.hotjar.io https://vc.hotjar.io https://in.hotjar.com https://script.hotjar.com https://csmetrics.hotjar.com wss://ws.hotjar.com https://api-eu.addsearch.com https://*.google-analytics.com https://*.analytics.google.com https://stats.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://flo.uri.sh https://airtable.com https://app.powerbi.com https://player.rss.com https://www.youtube-nocookie.com https://challenges.cloudflare.com; img-src 'self' data: https://public.flourish.studio https://axeptio.imgix.net https://www.googletagmanager.com https://favicons.axept.io https://cdn.addsearch.com https://i.ytimg.com https://*.gstatic.com https://www.google.at https://www.google.ch https://www.google.no https://www.google.jp https://www.google.fr; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri /fileadmin/CspReportLogger.php 1 default-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net *.fontawesome.com use.typekit.net www.youtube.com www.googletagmanager.com cdnjs.cloudflare.com *.azureedge.net fonts.googleapis.com connect.summitna.com app.powerbi.com *.goo.gl tigunia.zoom.us *.clarity.ms *.convertexperiments.com *.doubleclick.net geoip-js.com *.typekit.net *.google.com *.google.ca *.dynamics.com *.ytimg.com geolocation-db.com geoip-js.com 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.google.com/ https://www.youtube.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.facebook.com https://www.magezon.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com s7.addthis.com *.googletagmanager.com *.facebook.net *.google.com/ *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com ekr.zdassets.com/ *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://www.florius.nl/api/v1.0/CSPReporting/Report?category=report-only; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://images.unsplash.com www.alconlighting.com alconlighting.com www.shopperapproved.com *.google.com www.google.com.ua *.cloudflare.com *.facebook.com *.bing.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://cdnjs.cloudflare.com/ www.shopperapproved.com *.doubleclick.net stats.g.doubleclick.net *.smartlook.com alconlighting.odoo.com *.odoo.com *.pinimg.com *.bing.com *.outbrain.com *.facebook.net *.pinterest.com *.avada.io *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com maxcdn.bootstrapcdn.com www.shopperapproved.com *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.alconlighting.com alconlighting.com blob: data: self 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com manager.eu.smartlook.cloud *.smartlook.cloud *.pinterest.com *.facebook.com stats.g.doubleclick.net https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.affirm.com *.affirm.ca https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com www.youtube.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com https://*.gstatic.com *.affirm.com *.affirm.ca *.bird.eu maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com store.paradoxlabs.com *.adobedtm.com *.adobe.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com * *.cloudflare.com www.youtube.com player.vimeo.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.amazonaws.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com * cdn.plyr.io noembed.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.linearicons.com *.fontawesome.com *.tawk.to maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com gettysburgflagworks.referralrock.com *.adroll.com *.livechatinc.com *.googletagmanager.com *.facebook.com td.doubleclick.net tsdtocl.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com *.google.com *.google.com.vn *.tapad.com *.adroll.com *.reson8.com *.adnxs.com *.livechat-files.com *.taboola.com *.gravatar.com *.gleam.io *.casalemedia.com *.zaius.com ml314.com *.apptrian.com www.sandbox.paypal.com s3.us-east-1.amazonaws.com *.bidswitch.com *.bidswitch.net *.rlcdn.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.openx.com *.openx.net *.company-target.com *.adsrvr.org *.googletagmanager.com *.facebook.net *.liadm.com *.cloudfront.net b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.googleadservices.com *.trustedshops.com *.usercentrics.eu *.jsdelivr.net *.tawk.to *.paypalobjects.com *.paypal.com *.facebook.net chimpstatic.com *.googleapis.com *.googletagmanager.com *.adroll.com *.adroll.mgr.consensu.org *.cloudfront.net gleam.io *.casalemedia.com *.zaius.com s3.us-east-1.amazonaws.com *.google-analytics.com *.gstatic.com cdn.jsdelivr.net *.cloudfront.com unsafe-inline *.livechatinc.com *.hotjar.com *.taboola.com *.gravatar.com *.gleam.io *.cloudflareinsights.com gettysburgflagworks.referralrock.com *.apptrian.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com connect.facebook.net tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com widget.freshworks.com m2epro.freshdesk.com *.linearicons.com *.fontawesome.com *.tawk.to *.cloudfront.net *.googletagmanager.com *.livechatinc.com *.gleam.io *.hotjar.com *.adroll.com *.livechat-files.com *.taboola.com *.gravatar.com *.casalemedia.com *.zaius.com assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com widget.freshworks.com m2epro.freshdesk.com analytics.google.com googleads.g.doubleclick.net stats.g.doubleclick.net *.youtube.com paypal.com *.paypalobjects.com bam.eu01.nr-data.net *.tawk.to *.facebook.net chimpstatic.com *.googleapis.com *.googletagmanager.com *.amazonaws.com *.adroll.com *.adroll.mgr.consensu.org *.taboola.com *.gravatar.com *.gleam.io *.casalemedia.com *.zaius.com s3.us-east-1.amazonaws.com *.hotjar.com *.hotjar.io nexus-websocket-a.intercom.io *.apptrian.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem https://consent.cookiefirst.com https://script.hotjar.com https://static.hotjar.com https://s.pinimg.com; style-src-elem https://consent.cookiefirst.com; font-src https://www.gstatic.com https://fonts.gstatic.com 'self' data: *.fontawesome.com *.webwinkelkeur.nl data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.paypal.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com 'self' https://www.google.com https://us4.campaign-archive.com/ https://js.driftt.com *.webwinkelkeur.nl https://td.doubleclick.net https://ct.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://*.google.nl https://*.googleadservices.com https://*.googlesyndication.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.fls.doubleclick.net https://*.adservice.google.com https://www.mollie.com *.magentocommerce.com https://www.google.nl/ https://www.google.com/ https://www.google-analytics.com/ https://maps.googleapis.com/ https://maps.gstatic.com/ https://robincontentdesktop.blob.core.windows.net https://bat.bing.net https://www.facebook.com https://s.ytimg.com data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://*.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com js.mollie.com 'self' https://stats.g.doubleclick.net https://www.googleadservices.com https://www.google-analytics.com https://region1.google-analytics.com https://www.googletagmanager.com https://*.vimeocdn.com https://*.youtube.com https://*.doubleclick.net *.cloudflare.com https://*.disqus.com https://www.facebook.com https://connect.facebook.net https://*.fontawesome.com/ https://js.driftt.com https://*.webwinkelkeur.nl *.bootstrapcdn.com https://dpm.demdex.net https://amcglobal.sc.omtrdc.net wss://websockets.buckaroo.io/ https://ipinfo.io https://robincontentdesktop.blob.core.windows.net https://selfservice.robinhq.com https://bat.bing.com https://surfly.com https://*.msecnd.net https://consent.cookiefirst.com https://script.hotjar.com https://static.hotjar.com https://cdn.leadinfo.net https://s.pinimg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' https://robin-widget.com *.fontawesome.com https://consent.cookiefirst.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net https://amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://stream.getmetrion.com https://*.googleadservices.com https://*.googletagmanager.com https://*.googletagservices.com https://*.googlesyndication.com https://*.doubleclick.net https://*.google.nl https://*.googlevideo.com https://*.googleusercontent.com https://*.googledomains.com https://*.g.doubleclick.net https://*.fls.doubleclick.net https://*.adservice.google.com 'self' https://stats.g.doubleclick.net googleads.g.doubleclick.net https://www.googleadservices.com https://www.google-analytics.com https://region1.google-analytics.com https://www.googletagmanager.com s.ytimg.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.ggpht.com https://*.cloudflare.com *.disqus.com https://www.facebook.com https://connect.facebook.net https://*.fontawesome.com/ https://js.driftt.com https://*.webwinkelkeur.nl *.bootstrapcdn.com *.adobe.com assets.adobedtm.com https://dpm.demdex.net https://bat.bing.net https://bat.bing.com https://consent.cookiefirst.com https://edge.cookiefirst.com https://vc.hotjar.io https://ct.pinterest.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; object-src 'none'; script-src 'self' https://ajax.googleapis.com https://static.cloudflareinsights.com https://www.google-analytics.com https://s7.addthis.com https://img.reliablegun.com 'unsafe-inline' 'unsafe-eval' 'report-sample'; script-src-elem 'self' https://ajax.googleapis.com https://static.cloudflareinsights.com https://www.google-analytics.com https://s7.addthis.com https://img.reliablegun.com 'unsafe-inline'; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://img.reliablegun.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://img.reliablegun.com; img-src 'self' data: https://img.reliablegun.com https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://www.google-analytics.com https://static.cloudflareinsights.com; frame-src 'self' https://gateway.moneris.com; upgrade-insecure-requests; report-to csp; report-uri https://reports.reliablegun.com/csp 1 font-src *.googleapis.com *.gstatic.com data: *.globalpay.com https://fonts.gstatic.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.yotpo.com www.bedstar.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com www.bedstar.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.bedstar.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com account.fetchify.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.klarna.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com *.yotpo.com www.bedstar.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.globalpay.com https://www.magezon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.google.com www.google.com.ua maps.gstatic.com www.xtento.com cdn.xtento.com *.yotpo.com www.bedstar.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com www.gstatic.com www.xtento.com cdn.xtento.com *.yotpo.com www.bedstar.co.uk server.bedstar.co.uk https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com https://fonts.googleapis.com *.klarnacdn.net unsafe-inline assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com www.bedstar.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.bedstar.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://google.com/pay *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com www.googleapis.com *.yotpo.com www.bedstar.co.uk server.bedstar.co.uk https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.bedstar.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.bedstar.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://* data: https://www.feefo.com https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net *.google.com *.googleusercontent.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://www.google.co.uk https://www.googleadservices.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://eu-prod.inpendium.net data:; script-src 'unsafe-eval' 'unsafe-inline' https://google.com *.google.com https://ssl.google-analytics.com https://www.google-analytics.com https://snap.licdn.com https://*.gstatic.com https://s3.tradingview.com https://*.zdassets.com https://px.ads.linkedin.com https://www.googleadservices.com https://v2.zopim.com https://widget-mediator.zopim.com https://cdnjs.cloudflare.com https://tagmanager.google.com https://*.googletagmanager.com https://cdn.respond.io https://edge.fullstory.com https://cdn.chatapi.net https://*.oppwa.com https://oppwa.com https://p11.techlab-cdn.com https://eu-prod.inpendium.net https: blob:; script-src-elem 'unsafe-eval' 'unsafe-inline' https://google.com *.google.com https://ssl.google-analytics.com https://www.google-analytics.com https://snap.licdn.com https://*.gstatic.com https://s3.tradingview.com https://*.zdassets.com https://px.ads.linkedin.com https://www.googleadservices.com https://v2.zopim.com https://widget-mediator.zopim.com https://cdnjs.cloudflare.com https://tagmanager.google.com https://*.googletagmanager.com https://cdn.respond.io https://edge.fullstory.com https://cdn.chatapi.net https://*.oppwa.com https://oppwa.com https://p11.techlab-cdn.com https://eu-prod.inpendium.net https: blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://use.typekit.net https://p.typekit.net https://cdn.jsdelivr.net https://*.oppwa.com https://oppwa.com https://eu-prod.inpendium.net; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://use.typekit.net https://p.typekit.net https://cdn.jsdelivr.net https://*.oppwa.com https://oppwa.com https://eu-prod.inpendium.net; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://at.alicdn.com https://use.typekit.net; connect-src 'self' *.google.com https://google.com https://*.zdassets.com https://ipmbullion.zendesk.com https://stats.g.doubleclick.net wss://widget-mediator.zopim.com https://px.ads.linkedin.com https://cdn.linkedin.oribi.io https://www.googleadservices.com https://adservice.google.com https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.g.doubleclick.net https://static.zdassets.com https://www.google.co.uk https://edge.fullstory.com https://cdn.chatapi.net https://cdn.respond.io https://rs.fullstory.com https://analytics.google.com https://app.respond.io https://ipapi.co https://eu-prod.inpendium.net https://analytics.tiktok.com https://www.facebook.com https://www.googleadservices.com https://www.google.ca https://www.google.co.id https://www.google.co.in https://www.google.com https://www.google.com.au https://www.google.com.co https://www.google.com.hk https://www.google.com.my https://www.google.com.ph https://www.google.com.pk https://www.google.com.sa https://www.google.com.sg https://www.google.com.tw https://www.google.fr https://www.google.md https://www.google.nl https://www.google.sk data: blob:; media-src 'self' https://static.zdassets.com; frame-src 'self' *.google.com https://s.tradingview.com *.google-analytics.com *.googletagmanager.com https://trade-api.ipm.capital https://www.tradingview-widget.com https://soa.indigopreciousmetals.com https://prod-ipm-soa-frontend.live.ipmbullion.com https://prod-ipm-bsp-frontend.live.ipmbullion.com https://td.doubleclick.net https://cdn.respond.io https://cdn.chatapi.net https://analytics.google.com https://oppwa.com https://ppipe.net/ https://*.ppipe.net https://inpendium.net/ https://*.inpendium.net/ https://paymentauthenticationchallenge10.apac.citibank.com; worker-src blob:; report-uri /csp-report; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-yLr+YbB0G9sd+WYYiNGDUA==' 1 default-src data: 'self';script-src 'self' 'unsafe-eval' https://*.here.com;style-src 'self' 'unsafe-inline' ;object-src 'self' blob:;img-src 'self' data: blob:;connect-src blob: 'self' https://*.here.com;worker-src blob: 1 object-src 'none'; connect-src 'self' *.asgmax.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.asgmax.com join.gammasecure.com; script-src 'self' *.asgmax.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.asgmax.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bglobale.com *.global-e.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.bglobale.com *.global-e.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.bglobale.com *.global-e.com maps.gstatic.com www.xtento.com cdn.xtento.com *.sharethis.com *.doubleclick.net www.kong.it *.googleapis.com www.google.ae www.google.as www.google.at www.google.be www.google.bg www.google.by www.google.ca www.google.ch www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uk www.google.co.vi www.google.co.za www.google.co.zw www.google.com.ar www.google.com.au www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gh www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.mx www.google.com.my www.google.com.om www.google.com.pa www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dj www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.is www.google.it www.google.li www.google.lt www.google.lv www.google.mu www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.sc www.google.se www.google.si www.google.sk *.castellarisrl.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.bglobale.com *.global-e.com maps.googleapis.com www.xtento.com cdn.xtento.com *.sharethis.com *.hotjar.com *.googleapis.com kenect.com resource.kenect.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com assets.braintreegateway.com downloads.mailchimp.com *.bglobale.com *.global-e.com https://fonts.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.sharethis.com *.doubleclick.net *.crwdcntrl.net stbuttons.click *.ltmsphrcl.net *.googleapis.com www.google.as www.google.at www.google.be www.google.by www.google.ca www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.nz www.google.co.th www.google.co.uk www.google.com.ar www.google.com.au www.google.com.br www.google.com.hk www.google.com.mx www.google.com.my www.google.com.pa www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dj www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.it www.google.li www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.ru www.google.sc www.google.se www.google.si www.google.sk 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://98827900-8df7-48df-8bab-e0358eaca440.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com *.demdex.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.doubleclick.net *.hotjar.com consentcdn.cookiebot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de cdn.doofinder.com www.google.com www.google.es *.bing.com *.analytics.yahoo.com *.pinterest.com *.connectif.cloud *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com commerce.adobedtm.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.doofinder.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.doofinder.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * commerce.adobedtm.com commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.doofinder.com wss://*.doofinder.com webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://www.googletagmanager.com/ platform.twitter.com secure.livechatinc.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.certcapture.com connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com https://extendcoreoffersprod-offersthemelogobucketeb21afa-1lr7le13dvgtp.s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com pinterest.com assets.pinterest.com syndication.twitter.com https://img.youtube.com flagpedia.net moogento.com *.moogento.com *.livechatinc.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com widget.freshworks.com m2epro.freshdesk.com https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://cdn.jsdelivr.net cdn.jsdelivr.net twitter.com platform.twitter.com *.gstatic.com maps.googleapis.com l2.moogento.com cdn1.affirm.com sdk.helloextend.com cdn.livechatinc.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.fontawesome.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.certcapture.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com widget.freshworks.com m2epro.freshdesk.com https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.gstatic.com maps.googleapis.com *.livechatinc.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e4d51802-a473-4ed1-8641-fab46596696a.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.jsdelivr.net *.cloudflare.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.amazon.de *.bing.com *.clarity.ms *.protectgroup.com *.theticketmerchant.com.au *.cfjump.com *.gstatic.com *.stripe.com *.cloudflare.com *.signifyd.com *.affyi.com *.fishrobotflower.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.google.com *.gstatic.com *.trustedshops.com *.etrusted.com *.amazon.de *.payments-amazon.de *.bing.com *.clarity.ms *.protectgroup.com *.theticketmerchant.com.au *.cfjump.com *.trustpilot.com *.aptrinsic.com *.cloudflare.com *.signifyd.com *.affyi.com *.fishrobotflower.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.google.com *.google.lv *.googletagmanager.com stats.g.doubleclick.net *.trustedshops.com *.etrusted.com *.amazon.de d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.de *.media-amazon.de *.bing.com *.clarity.ms *.protectgroup.com *.theticketmerchant.com.au *.cfjump.com *.roeye.com *.stripe.com *.cloudflare.com *.signifyd.com *.brilliantlocco.com *.esnlocco.com *.affyi.com *.fishrobotflower.com https://meetanshi.com/media/logo.png flagpedia.net t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com s7.addthis.com chimpstatic.com *.googletagmanager.com *.zip.co *.sandbox.zip.co *.google.com *.trustedshops.com *.etrusted.com *.amazon.de *.payments-amazon.de *.bing.com *.doubleclick.net *.clarity.ms *.protectgroup.com *.theticketmerchant.com.au *.cfjump.com *.trustpilot.com *.chimpstatic.com *.aptrinsic.com *.roeyecdn.com *.cloudflareinsights.com *.cloudflare.com *.signifyd.com *.brilliantlocco.com *.esnlocco.com *.theticketmerchant.co.nz *.affyi.com *.fishrobotflower.com *.avada.io maps.googleapis.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.fontawesome.com tagmanager.google.com cdn.jsdelivr.net *.aptrinsic.com *.stripe.com *.cloudflare.com *.signifyd.com *.affyi.com *.fishrobotflower.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com ekr.zdassets.com/ dpe0djwch8671.cloudfront.net *.sandbox.zip.co *.zip.co *.gstatic.com stats.g.doubleclick.net *.trustedshops.com *.etrusted.com *.amazon.de mws.amazonservices.de *.bing.com *.clarity.ms *.protectgroup.com *.theticketmerchant.com.au *.cfjump.com *.zipmoney.com.au *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es cdn.ampproject.org *.edge.zip.co *.aptrinsic.com *.cloudflare.com *.signifyd.com *.brilliantlocco.com *.esnlocco.com *.affyi.com *.fishrobotflower.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com https://*.googleapis.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.facebook.com https://ct.pinterest.com https://*.cookiebot.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://dailystyle.nl https://*.bing.com https://facebook.com https://www.facebook.com https://ct.pinterest.com https://*.googletagmanager.com https://*.clarity.ms https://at19.net https:/at19.net https://www.google.nl https://www.google.com https://*.googleapis.com https://*.gstatic.com https://*.cookiebot.com https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ flagpedia.net https://redchamps.com *.amazonaws.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://jdt8.net https://www.googletagmanager.com https://tdep.dailystyle.nl https://chimpstatic.com https://diffuser-cdn.app-us1.com https://js-agent.newrelic.com https://bat.bing.com https://s.pinimg.com https://connect.facebook.net https://prism.app-us1.com https://www.clarity.ms https://*.google.com https://*.googleapis.com *.gstatic.com https://*.nr-data.net https://trackcmp.net https://*.cookiebot.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.gstatic.com https://*.googleapis.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com https://www.googletagmanager.com https://tdep.dailystyle.nl https://ct.pinterest.com https://*.clarity.ms https://*.google-analytics.com https://*.nr-data.net https://*.googleapis.com https://*.cookiebot.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.gstatic.com maps.googleapis.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com 'self' data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.revolut.com *.cdn-apple.com *.gstatic.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.google.com maps.googleapis.com maps.gstatic.com https://api.esto.ee https://api.esto.lv https://api.estopay.lt *.unsplash.com/ https://firebasestorage.googleapis.com https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt https://maps.omnivasiunta.lt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.klix.app meetanshi.com *.facebook.com *.gudriem.lv *.kurpirkt.lv *.salidzini.lv *.mailchimp.com *.mcusercontent.com *.fcfpay.com/ unsplash.com/ *.google.lv/ *.hsforms.net *.hsforms.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.google.com maps.googleapis.com https://maps.googleapis.com *.avada.io *.shopify.com https://unpkg.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.revolut.com *.gstatic.com *.facebook.net chimpstatic.com *.mailchimp.com *.list-manage.com *.googletagmanager.com *.hsforms.net *.hsforms.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net https://unpkg.com assets.braintreegateway.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io https://www.terminalmappingjs.com https://geocode.arcgis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com stats.g.doubleclick.net *.facebook.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.klaviyo.com *.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.canadapost.ca https://sso.epost.ca *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.twitter.com *.doubleclick.net *.hotjar.com *.facebook.com *.flixcar.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ mageside.com *.canadapost.ca *.canadapost-postescanada.ca *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.google.ca *.doubleclick.net *.multiluminaire.ca *.facebook.com *.flix360.com *.flixcar.com *.flix360.io *.flixfacts.io *.flixfacts.com *.flixcar.io *.intuit.com *.mcusercontent.com *.privacy-center.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.doubleclick.net *.googletagmanager.com trackcmp.net *.facebook.net *.hotjar.com *.flixcar.com *.flix360.io *.flixfacts.com *.flixgvid.com *.privacy-center.org *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.twimg.com *.hotjar.com *.hotjar.io *.doubleclick.net *.klaviyo.com *.privacy-center.org *.googlesyndication.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.cleverreach.com 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.ad-srv.net hal9000.redintelligence.net test.saferpay.com www.saferpay.com saferpay.com *.google.com *.google.de *.podigee.com *.doubleclick.net platform.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.etracker.com https://*.etracker.de *.awin1.com *.zenaps.com *.wepowerconnections.com *.roeye.com *.sciencebehindecommerce.com test.saferpay.com www.saferpay.com saferpay.com *.strunz.com *.spoc.one *.splendid-prelive.de *.google.de *.google.com secure.adnxs.com *.google-analytics.com *.etracker.com *.etracker.de *.gstatic.com flagpedia.net pinterest.com assets.pinterest.com syndication.twitter.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.etracker.com https://*.etracker.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.ad-srv.net *.bounce-commerce.de *.kuponacdn.de *.fatmedia.io test.saferpay.com www.saferpay.com saferpay.com *.google.com *.gstatic.com *.podigee.com *.etracker.com *.etracker.de maps.googleapis.com twitter.com platform.twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.etracker.de *.wepowerconnections.com https://the.sciencebehindecommerce.com *.bounce-commerce.de test.saferpay.com www.saferpay.com saferpay.com *.demdex.net *.google-analytics.com *.google.com stats.g.doubleclick.net *.etracker.com *.etracker.de *.sciencebehindecommerce.com www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.dwin1.com test.saferpay.com www.saferpay.com saferpay.com strunz.com *.strunz.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.strunz.com/cspreports/report; report-to report-endpoint; 1 font-src *.cloudflare.com fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com cdn.rawgit.com cdn.jsdelivr.net data: maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com cdn.dnky.co *.youtube.com *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com bid.g.doubleclick.net *.googletagmanager.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.bird.eu ebizmarts-website.s3.amazonaws.com *.cloudflare.com www.google.com *.google.com.hk *.google.com.sg *.googleadservices.com www.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com www.linkedin.com linkedin.com www.googletagmanager.com googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net keewah.com *.keewah.com googleads.g.doubleclick.net p.teads.tv 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de chimpstatic.com *.plugins.emarsys.net *.scarabresearch.com *.cloudflare.com google.com www.google.com gstatic.com www.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com *.newrelic.com *.nr-data.net cdn.jsdelivr.net www.googleoptimize.com www.clarity.ms *.datatrics.com *.criteo.net *.criteo.com *.youtube.com cdn.mouseflow.com appleid.cdn-apple.com googleads.g.doubleclick.net assets.emarsys.net p.teads.tv s7.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zopim.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.scarabresearch.com *.eservice.emarsys.net *.cloudflare.com commerce.adobedc.net api.comapi.com analytics.google.com www.google-analytics.com maps.googleapis.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.nr-data.net www.clarity.ms *.facebook.com *.datatrics.com api.ipify.org api.hashify.net vmp.eftpay.com.cn ekr.zdassets.com/ *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.keewah.com/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.hotjar.com *.tidiochat.com *.cookiebot.com *.pcapredict.com *.postcodeanywhere.co.uk maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.superpayments.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.pcapredict.com *.postcodeanywhere.co.uk *.superpayments.com *.stripe.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com *.superpayments.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hotjar.com *.cookiebot.com *.electrical2go.co.uk maps.googleapis.com td.doubleclick.net *.pcapredict.com *.dotdigital-pages.com *.dotdigital.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.superpayments.com *.js.stripe.com *.trustpilot.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.google.co.uk *.hotjar.com *.mailchimp.com *.cloudflare.com *.electrical2go.co.uk electrical2go.co.uk *.google.co.in maps.googleapis.com *.cookiebot.com *.facebook.com *.bing.com *.pcapredict.com *.postcodeanywhere.co.uk *.increasingly.co *.trackedlink.net magefan.com cm.magefan.com *.disqus.com maps.gstatic.com *.superpayments.com *.stripe.com a.storyblok.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://maps.googleapis.com *.hotjar.com *.cookiebot.com *.tidio.co *.tidiochat.com *.electrical2go.co.uk *.clarity.ms *.bing.com *.facebook.net maps.googleapis.com *.increasingly.co *.pcapredict.com *.postcodeanywhere.co.uk *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net https://cdn.searchspring.net/intellisuggest/is.min.js *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.superpayments.com b.stripecdn.com m.stripe.network segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com https://cdn.superpayments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.hotjar.com maps.googleapis.com *.cookiebot.com *.increasingly.co *.pcapredict.com *.postcodeanywhere.co.uk https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.superpayments.com *.stripe.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.tidiochat.com *.electrical2go.co.uk electrical2go.co.uk maps.googleapis.com *.cookiebot.com *.pcapredict.com *.postcodeanywhere.co.uk 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com *.hotjar.com *.cookiebot.com *.tidio.co wss://socket.tidio.co googleads.g.doubleclick.net *.clarity.ms maps.googleapis.com *.trustpilot.com *.increasingly.co *.pcapredict.com *.postcodeanywhere.co.uk *.increasingly.com *.bing.com *.google.co.uk *.searchspring.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://beacon.searchspring.io/beacon *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.superpayments.com stripe.com cognito-idp.eu-west-2.amazonaws.com segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.seondnsresolve.com *.seondfresolver.com *.deviceinfresolver.com *.seonintelligence.com api.storyblok.com web-sdk.smartlook.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp.deploy.co.uk/99aaa83e-4a88-4ed6-893b-2d02806828b8; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' data:; 1 script-src https://higherlogiccloudfront.s3.amazonaws.com https://hl-prod-ca-oc-long-term.s3.amazonaws.com/CNA/ https://hl-prod-ca-oc-download.s3.amazonaws.com/CNA/ https://d1u9edeg3iwvk4.cloudfront.net https://cdn.jsdelivr.net/jquery.slick/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.aspnetcdn.com/ajax/ https://use.fortawesome.com/ https://cdn.informz.net https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com 'self' https://hl-prod-ca-oc-holding-pen.s3.amazonaws.com/CNA/ 'unsafe-eval' https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js; font-src https://hl-prod-ca-oc-long-term.s3.amazonaws.com/CNA/ https://d2x5ku95bkycr3.cloudfront.net https://fonts.googleapis.com/ https://higherlogiccloudfront.s3.amazonaws.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://hl-prod-ca-oc-download.s3.amazonaws.com/CNA/ https://hl-prod-ca-oc-holding-pen.s3.amazonaws.com/CNA/ 'self' https://fonts.gstatic.com/ https://d1u9edeg3iwvk4.cloudfront.net data: https://cdn.jsdelivr.net/jquery.slick/; script-src-elem https://static.filestackapi.com/filestack-js/ https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://ajax.aspnetcdn.com/ajax/ https://static.filestackapi.com/picker/ 'unsafe-eval' 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://www.gstatic.com/recaptcha/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'self' https://securepubads.g.doubleclick.net/; media-src https://hl-prod-ca-oc-long-term.s3.amazonaws.com/CNA/ https://hl-prod-ca-oc-download.s3.amazonaws.com/CNA/ https://hl-prod-ca-oc-stream.s3.amazonaws.com/CNA/ https://d1u9edeg3iwvk4.cloudfront.net https://hl-prod-ca-oc-holding-pen.s3.amazonaws.com/CNA/ 'self'; style-src https://cdnjs.cloudflare.com/ajax/libs/prism/ https://use.fortawesome.com/ 'unsafe-inline' https://cdn.jsdelivr.net/jquery.slick/ https://d3uf7shreuzboy.cloudfront.net/ https://hl-prod-ca-oc-download.s3.amazonaws.com/CNA/ 'self' https://ajax.googleapis.com/ajax/libs/jqueryui/ https://hl-prod-ca-oc-holding-pen.s3.amazonaws.com/CNA/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/ https://hl-prod-ca-oc-long-term.s3.amazonaws.com/CNA/ https://fonts.googleapis.com/ https://d1u9edeg3iwvk4.cloudfront.net; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://www.youtube.com/embed/ https://api.connectedcommunity.org/ 'self' https://securepubads.g.doubleclick.net/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob: https://securepubads.g.doubleclick.net/ https://pagead2.googlesyndication.com/; manifest-src 'self'; img-src https://cdn.jsdelivr.net/jquery.slick/ https://hl-prod-ca-oc-long-term.s3.amazonaws.com/CNA/ https://d1u9edeg3iwvk4.cloudfront.net https://hl-prod-ca-oc-download.s3.amazonaws.com/CNA/ https://static.filestackapi.com/picker/ https://img.youtube.com/vi/ blob: 'self' https://d2x5ku95bkycr3.cloudfront.net https://hl-prod-ca-oc-holding-pen.s3.amazonaws.com/CNA/; object-src 'none'; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors 'self' https://*.connectedcommunity.org/; 1 script-src-elem bat.bing.com scripts.clarity.ms www.clarity.ms; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net *.fonts.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.versapay.com *.paynup.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.twitter.com *.versapay.com *.paynup.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com https://plumrocket.com *.addthis.com *.pinterest.com *.twitter.com *.paynup.com *.versapay.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://www.magezon.com *.cloudflare.com *.klarna.com *.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.facebook.com *.linkedin.com bat.bing.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.lightemporium.com *.usercentrics.eu *.versapay.com *.paynup.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.randallreilly.com *.facebook.net snap.licdn.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com *.datadoghq.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.versapay.com *.paynup.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.ssl.cf1.rackcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io *.cloudflare.com *.addthis.com https://graph.instagram.com *.linkedin.com b.clarity.ms *.twitter.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/magento_os/; report-to report-endpoint; 1 default-src 'none'; report-uri https://senhasegura.report-uri.com/r/d/csp/wizard 1 connect-src https://auth.sdc.dk https://api-proxy-neos.sdc.eu https://azure-sign-p1.sdc.dk data: https://*.dynamicyield.com/ https://*.dynamicyield.eu/ https://*.sdc.dk/ https://*.sdc.eu/ https://api.cludo.com https://bat.bing.com https://cdn.linkedin.oribi.io https://px.ads.linkedin.com https://cloud.lsb.dk https://consent.app.cookieinformation.com https://dc.services.visualstudio.com/ https://policy.app.cookieinformation.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://vimeo.com https://www.google.com https://www.totalkredit.dk/ 'self'; default-src https://api-shared-proxy.sdc.eu https://bundles.lsb.dk 'self'; font-src https://*.dynamicyield.com/ https://*.dynamicyield.eu/ https://fonts.gstatic.com/ 'self'; frame-src https://auth.sdc.dk https://azure-sign-p1.sdc.dk https://app.leaddoubler.com/ https://player.vimeo.com/ https://policy.app.cookieinformation.com https://td.doubleclick.net https://widget.trustpilot.com https://www.googletagmanager.com https://www.youtube.com/ 'self'; img-src *.siteimproveanalytics.io data: https://*.dynamicyield.com/ https://*.dynamicyield.eu/ https://bat.bing.com https://bundles.lsb.dk https://customer.cludo.com https://i.ytimg.com/ https://maps.googleapis.com/ https://maps.gstatic.com/ https://px.ads.linkedin.com/ https://stm.totalkredit.dk/ https://www.google.com https://www.google.dk https://www.google-analytics.com https://www.google-analytics.dk https://www.googletagmanager.com 'self' www.facebook.com; script-src https://*.dynamicyield.com/ https://*.dynamicyield.eu/ https://bat.bing.com https://bundles.lsb.dk https://connect.facebook.net/ https://consent.cookiebot.com/ https://customer.cludo.com https://forms.lsb-kampagne.dk/ https://googleads.g.doubleclick.net https://maps.googleapis.com/ https://player.vimeo.com/ https://policy.app.cookieinformation.com https://policy.app.cookieinformation.com/ https://s.ytimg.com/ https://s2.adform.net https://s3-eu-west-1.amazonaws.com https://siteimproveanalytics.com https://snap.licdn.com https://track.adform.net https://widget.trustpilot.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://www.totalkredit.dk/ https://www.youtube.com/ 'self' 'unsafe-eval' 'unsafe-inline'; style-src https://*.dynamicyield.com/ https://*.dynamicyield.eu/ https://bundles.lsb.dk https://customer.cludo.com https://forms.lsb-kampagne.dk/ https://laanogsparneos.prod.ibn.host/ https://laanogspar-prd.neosbank-envr.com/ https://neosbank-laanogspar-prd.ibn.host/ https://policy.app.cookieinformation.com https://www.totalkredit.dk/ 'self' 'unsafe-inline'; report-uri /api/sdc/security/csp/report; report-to default 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.xtento.com js.mollie.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com bat.bing.com *.google.de *.google.com *.cookiebot.com dt.promostore.de dt.promostore.ch dt.promostore.at dt.promostore.nl dt.pinkcube.de dt.pinkcube.at *.hubspot.com www.facebook.com www.xtento.com cdn.xtento.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.matelso.de *.cloudflare.com *.cloudflareinsights.com *.bing.com *.hotjar.com *.etracker.de *.etracker.com *.doofinder.com *.doubleclick.net *.clarity.ms *.cookiefirst.com *.trustpilot.com dt.promostore.de dt.promostore.ch dt.promostore.at dt.promostore.nl dt.pinkcube.de dt.pinkcube.at *.salesviewer.com *.salesviewer.org https://salesviewer.org *.hs-scripts.com *.hs-analytics.net *.hs-banner.com facebook.net connect.facebook.net www.facebook.com www.xtento.com cdn.xtento.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.cloudflare.com *.doofinder.com *.cookiefirst.com www.facebook.com *.fontawesome.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com *.hotjar.com *.clarity.ms *.matelso.de *.google.de *.google-analytics.com *.cloudflareinsights.com *.bing.com *.bing.net *.hotjar.io *.etracker.de *.etracker.com *.doofinder.com wss://*.doofinder.com *.doubleclick.net wss://*.hotjar.com *.cookiefirst.com *.trustpilot.com dt.promostore.de dt.promostore.ch dt.promostore.at dt.promostore.nl dt.pinkcube.de dt.pinkcube.at *.salesviewer.com *.salesviewer.org https://salesviewer.org *.hs-scripts.com *.hs-analytics.net *.hs-banner.com facebook.net connect.facebook.net www.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'self'; connect-src 'self' https://*.siteimprove.com https://analytics-ipv6.tiktokw.us https://analytics.google.com https://analytics.tiktok.com https://bat.bing.com https://bot.kindly.ai https://chat.kindlycdn.com https://collect-eu-central-1.tealiumiq.com https://consent.app.cookieinformation.com https://contentassistant.eu.siteimprove.com https://ct.pinterest.com https://esp-eu.aptrinsic.com https://ingest.skyra.no https://ingest.staging.skyra.no https://pagead2.googlesyndication.com https://policy.app.cookieinformation.com https://px.ads.linkedin.com https://region1.analytics.google.com https://region1.google-analytics.com https://service-platform.huseierne.no https://sockjs-eu.pusher.com https://sr-huseierne-hsp-signalr-prod.service.signalr.net https://sr-huseierne-hsp-signalr-test.service.signalr.net https://stats.g.doubleclick.net https://tr.snapchat.com https://tr6.snapchat.com https://www.facebook.com https://www.google-analytics.com https://www.google.co.uk https://www.google.com https://www.google.de https://www.google.es https://www.google.nl https://www.google.no https://www.googleadservices.com https://www.googletagmanager.com https://www.huseierne.no wss://sr-huseierne-hsp-signalr-prod.service.signalr.net wss://sr-huseierne-hsp-signalr-test.service.signalr.net wss://ws-eu.pusher.com; default-src 'self'; font-src 'self' data: https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/ https://cdn.jsdelivr.net https://chat.kindlycdn.com https://fonts.gstatic.com; frame-src 'self' https://*.siteimprove.com https://13892171.fls.doubleclick.net https://bli-medlem.huseierne.no https://contentassistant.eu.siteimprove.com https://ct.pinterest.com https://flo.uri.sh https://kommunikasjon.ntb.no https://player.flipsnack.com https://player.vimeo.com https://policy.app.cookieinformation.com https://tr.snapchat.com https://www.googletagmanager.com https://www.youtube-nocookie.com; img-src 'self' data: https://6053746.global.siteimproveanalytics.io https://ade.googlesyndication.com https://bat.bing.com https://connect.facebook.net https://pagead2.googlesyndication.com https://public.flourish.studio https://px.ads.linkedin.com https://static.kindlycdn.com https://stats.g.doubleclick.net https://tr.snapchat.com https://www.google.ae https://www.google.at https://www.google.co.th https://www.google.co.uk https://www.google.com https://www.google.de https://www.google.dk https://www.google.es https://www.google.fi https://www.google.no https://www.google.se https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://analytics.tiktok.com https://bat.bing.com https://chat.kindlycdn.com https://code.jquery.com https://connect.facebook.net https://ct.pinterest.com https://d2df291ti5v5sq.cloudfront.net https://googleads.g.doubleclick.net https://kommunikasjon.ntb.no https://maxcdn.bootstrapcdn.com https://policy.app.cookieinformation.com https://public.flourish.studio https://s.pinimg.com https://sc-static.net https://siteimproveanalytics.com https://snap.licdn.com https://survey.skyra.no https://tags.tiqcdn.com https://tr.snapchat.com https://visitor-service-eu-central-1.tealiumiq.com https://web-sdk-eu.aptrinsic.com https://www.googletagmanager.com https://www.ntbinfo.no https://www.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.siteimprove.com https://contentassistant.eu.siteimprove.com; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://chat.kindlycdn.com https://fonts.googleapis.com https://web-sdk-eu.aptrinsic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; report-to stott-security-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.shopperapproved.com *.disqus.com www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.hcaptcha.com https://www.googletagmanager.com https://maps.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com; script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://js.hcaptcha.com https://www.googletagmanager.com https://maps.googleapis.com https://s.go-mpulse.net *.siteintercept.qualtrics.com https://pi.pardot.com https://connect.facebook.net https://bat.bing.com https://snap.licdn.com https://siteintercept.qualtrics.com https://go.frieslandcampina-foodservice.com https://googleads.g.doubleclick.net https://static.xingcdn.com https://view.publitas.com https://zn40n3kie90teedbt-frieslandcampina.siteintercept.qualtrics.com https://www.youtube.com https://analytics.tiktok.com https://www.googleadservices.com https://dev.visualwebsiteoptimizer.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; worker-src 'self' blob:; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.fontawesome.com *.dynamism.com *.brule.co.jp *.brule.co.kr *.facebook.com *.google.com *.t1.kakaocdn.net *.kakaocdn.net ws16.hotjar.com ws17.hotjar.com in.hotjar.com *.hotjar.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.ably.io *.ably-realtime.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self' https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.google.com *.facebook.com *.g.doubleclick.net *.t1.kakaocdn.net *.kakaocdn.net *.hotjar.com ws16.hotjar.com ws17.hotjar.com in.hotjar.com sketchfab.com *.formlabs.com *.ably.io *.ably-realtime.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.klevu.com *.app-us1.com *.activehosted.com *.dynamism.com *.brule.co.jp *.brule.co.kr *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.twitter.com *.twimg.com *.ytimg.com *.facebook.com *.adobedtm.com *.bing.com *.ads.linkedin.com *.google.co.in *.adsymptotic.com *.facebook.net trackcmp.net *.clarity.ms *.doubleclick.net *.licdn.com *.linkedin.com *.developers.kakao.com *.kakao.com *.hotjar.com static.hotjar.com ws16.hotjar.com ws17.hotjar.com in.hotjar.com *.ably.io *.ably-realtime.com https://dynamism.com https://brule.co.jp https://brule.co.kr *.ksearchnet.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.klevu.com *.app-us1.com *.activehosted.com *.googleadservices.com *.paypalobjects.com *.dynamism.com *.brule.co.jp *.brule.co.kr *.google-analytics.com *.googleoptimize.com *.cloudfront.net *.affiliatly.com *.gstatic.com *.googleapis.com *.kit.fontawesome.com *.kit.fontawesome.com/3befc74afd.js *.adobedtm.com *.authorize.net *.paypal.com *.vimeo.com *.cardinalcommerce.com *.ccdc02.com *.googletagmanager.com *.trackedlink.net *.trackedweb.net *.dotdigital.com *.dnky.co *.comapi.com *.stripe.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.yotpo.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.facebook.com *.bing.com *.ads.linkedin.com *.google.co.in *.adsymptotic.com *.facebook.net trackcmp.net *.clarity.ms *.doubleclick.net *.licdn.com *.t1.kakaocdn.net *.kakaocdn.net ws16.hotjar.com ws17.hotjar.com in.hotjar.com *.hotjar.com static.hotjar.com script.hotjar.com *.ably.io *.ably-realtime.com https://apis.google.com analytics.tiktok.com www.gstatic.com www.google.com js.klevu.com *.ksearchnet.com *.avada.io pay.google.com *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.fontawesome.com *.dnky.co *.dotdigital.com *.klevu.com *.dynamism.com *.brule.co.jp *.brule.co.kr *.facebook.com *.google.com *.t1.kakaocdn.net *.kakaocdn.net *.hotjar.com ws16.hotjar.com ws17.hotjar.com in.hotjar.com *.ably.io *.ably-realtime.com *.ksearchnet.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klevu.com *.app-us1.com *.activehosted.com *.googleadservices.com *.paypalobjects.com *.dynamism.com *.brule.co.jp *.brule.co.kr *.googleoptimize.com *.cloudfront.net *.affiliatly.com *.google-analytics.com *.cardinalcommerce.com *.youtube.com *.googletagmanager.com *.trackedlink.net *.trackedweb.net *.dotdigital.com *.dnky.co *.comapi.com *.stripe.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.yotpo.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.facebook.com *.bing.com *.ads.linkedin.com *.google.co.in *.adsymptotic.com *.facebook.net trackcmp.net *.clarity.ms *.doubleclick.net *.licdn.com *.t1.kakaocdn.net *.kakaocdn.net *.hotjar.com static.hotjar.com ws16.hotjar.com ws17.hotjar.com in.hotjar.com *.linkedin.oribi.io *.hotjar.io *.ably.io *.ably-realtime.com wss://realtime.ably.io wss://ws.hotjar.com https://www.merchant-center-analytics.goog ws://localhost:12387 analytics.tiktok.com analytics-ipv6.tiktokw.us *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline'; child-src 'self' blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klevu.com 'unsafe-inline' https://*.hotjar.com 'unsafe-inline' https://*.hotjar.io 'unsafe-inline' wss://*.hotjar.com 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.facebook.com *.openstreetmap.org https://maps.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googletagmanager.com *.facebook.net https://player.vimeo.com https://www.youtube.com *.hsforms.net *.hsforms.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.openstreetmap.org https://maps.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com login.microsoftonline.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com www.gstatic.com https://www.google.com/recaptcha/ *.adyen.com magento-cloudflare.jetrails.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com policy.app.cookieinformation.com www.googletagmanager.com td.doubleclick.net onskeskyen.dk 'self'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com *.adyen.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.ytimg.com magefan.com cm.magefan.com scontent.cdninstagram.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.navipartner.dk *.googletagmanager.com t.raptorsmartadvisor.com maps.gstatic.com www.google.rs www.google.dk pagead2.googlesyndication.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.google.com www.gstatic.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.adyen.com chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com static.addtoany.com *.fontawesome.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com policy.app.cookieinformation.com *.googletagmanager.com https://script.hotjar.com https://static.hotjar.com https://bi.heyloyalty.com tag.heylink.com static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googletagmanager.com pagead2.googlesyndication.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com *.adyen.com ekr.zdassets.com/ graph.instagram.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com policy.app.cookieinformation.com consent.app.cookieinformation.com maps.googleapis.com pagead2.googlesyndication.com https://stats.g.doubleclick.net www.google.com tracking.heyloyalty.com *.analytics.google.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data: blob: http://*.consultant.ru; script-src 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://o4504880527835136.ingest.sentry.io/api/4504880531898368/security/?sentry_key=5d6c946b43f14f3eb2ae3438f772ecb2 1 child-src id.quicklaunch.io 'self'; connect-src 'self' lcas-dev.lakelandcc.edu lcas.lakelandcc.edu www.lakelandcc.edu myportal-new-dev.lakelandcc.edu myportal.lakelandcc.edu: report-uri https://lakeland.report-uri.com/r/t/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com fonts.googleapis.com newrelic.com www.google.com v2.zopim.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.google.com sbcheckout.payfort.com paymentservices.payfort.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.apptrian.com facebook.com social-plugins.line.me newrelic.com vault.omise.co www.youtube.com youtu.be cdn.moengage.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com maps.gstatic.com *.visa.com www.apptrian.com facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com gourmetegypt.com maps.googleapis.com www.w3.org newrelic.com s.ytimg.com www.google.co.in api.omise.co omise-gateway-production.s3.ap-southeast-1.amazonaws.com v2.zopim.com via.placeholder.com *.gourmetegypt.com moe-email-campaigns.s3.amazonaws.com image.moengage.com www.moengage.com app-cdn.moengage.com *.gourmetlms.com/ image-eu.moengage.com/ cdn.gourmetegypt.com gourmetegyptcdn.s3.eu-west-1.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.visa.com *.mastercard.com www.apptrian.com facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com omise.co cdn.omise.co maps.googleapis.com d.line-scdn.net js-agent.newrelic.com bam-cell.nr-data.net www.google.com www.gstatic.com newrelic.com www.google.co.in f.vimeocdn.com v2.zopim.com static.zdassets.com bam.nr-data.net cdn.moengage.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com newrelic.com www.google.com use.typekit.net p.typekit.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com www.apptrian.com facebook.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com bam-cell.nr-data.net newrelic.com www.google.com youtube.com googletagmanager.com paypal.com bam.nr-data.net stats.g.doubleclick.net maps.googleapis.com wss://widget-mediator.zopim.com ekr.zdassets.com integration.richrelevance.com http://integration.richrelevance.com sdk-01.moengage.com sdk-02.moengage.com sdk-03.moengage.com gateway.richrelevance.com qa-gateway.richrelevance.com staging-gateway.richrelevance.com recs.richrelevance.com loadtest-eu.richrelevance.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src https://player.vimeo.com https://c.bing.com 'self' https://stats.g.doubleclick.net https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://pi.pardot.com https://d.la1-c1-ia5.salesforceliveagent.com https://d.la4-c2-ia5.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://api.paytrace.com https://tagassistant.google.com https://www.gemline.ca https://www.gstatic.com https://d.la4-c2-ia4.salesforceliveagent.com https://www.google.com https://pay.google.com https://analytics.google.com https://go.gemline.com blob: https://thegemgroup.my.salesforce-scrt.com https://www.clarity.ms https://d.la4-c2-ia5.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://d.la4-c2-ia4.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d.la1-core2.sfdc-lywfpd.salesforceliveagent.com https://b2blightga11.my.salesforce.com https://*.salesforceliveagent.com https://b2blightga11--c.documentforce.com https://d.la4-c2-ia5.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://thegemgroup.my.site.com 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval' https://go.gemline.com/emailPreference/e/epc/901091/mnWtAiEbzb0RJ8ToDGbpNthVJ2D6N5Hv6ktfYre-Z4Q/580 'unsafe-inline' https://payments.salesforce.com/ https://p.clarity.ms/collect https://designer.artifi.net https://d.la4-c2-ia4.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://checkoutshopper-live.adyen.com/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://www.gemline.com/ https://scripts.clarity.ms https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.gemline.com https://l.clarity.ms/collect https://c.la1-core2.sfdc-lywfpd.salesforceliveagent.com https://www.googletagmanager.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js https://a.clarity.ms/collect; report-to sfdc-csp-ep; report-uri https://thegemgroup.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D3t000001K38v&networkId=0DM3t000000Q8vH&type=communities 1 font-src cdn.jsdelivr.net fonts.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com *.typekit.net dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ogone.com *.ingenico.com *.v-psp.com *.epdq.co.uk *.postfinance.ch *.paypage.be *.payengine.de *.eupayglobe.com *.tpvecommerce.es *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ogone.com *.ingenico.com *.v-psp.com *.epdq.co.uk *.postfinance.ch *.paypage.be *.payengine.de *.eupayglobe.com *.tpvecommerce.es *.yotpo.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.trustpilot.com https://app.trustt.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr maps.googleapis.com maps.gstatic.com *.yotpo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://app.trustt.io dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net jquery.sellxed.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com *.avada.io maps.googleapis.com www.gstatic.com www.google.com https://cdnjs.cloudflare.com *.yotpo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.trustpilot.com https://app.trustt.io dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.typekit.net *.trustpilot.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://app.trustt.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ogone.com *.ingenico.com *.v-psp.com *.epdq.co.uk *.postfinance.ch *.paypage.be *.payengine.de *.eupayglobe.com *.tpvecommerce.es https://nominatim.openstreetmap.org https://get.geojs.io *.avada.io maps.googleapis.com *.yotpo.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com ws: * dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src https://bbb.test bbbcycling.com; font-src cash-f.squarecdn.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.typekit.net 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com consentcdn.cookiebot.com td.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com * https://images.unsplash.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com *.pon.bike images.pondigital.solutions *.google.nl *.google.com *.mailplus.nl imgsct.cookiebot.com widget.thuiswinkel-cdn.org *.storyblok.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com *.googleapis.com tagmanager.google.com https://www.googletagmanager.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com www.facebook.com chimpstatic.com rum-static.pingdom.net rum-collector-2.pingdom.net consentcdn.cookiebot.com consent.cookiebot.com googleads.g.doubleclick.net widget.thuiswinkel.org widget.thuiswinkel-cdn.org *.clarity.ms restapi.mailplus.nl squeezely.tech *.storyblok.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.typekit.net widget.thuiswinkel-cdn.org *.storyblok.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com devdocs.magento.com rum-collector-2.pingdom.net widgetcontent.thuiswinkel-cdn.org www.google.com *.clarity.ms consent.cookiebot.com consentcdn.cookiebot.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://images.unsplash.com *.disqus.com https://firebasestorage.googleapis.com 'self' data: *.bing.com *.bing.net *.clarity.ms *.google.co.uk *.google.com *.linkedin.com *.test-meter.co.uk data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com unpkg.com https://maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com *.disqus.com *.avada.io https://getaddress.io *.gstatic.com bat.bing.com bat.bing.net *.clarity.ms *.cookie-script.com *.googlesyndication.com snap.licdn.com code.jquery.com *.zdassets.com *.zopim.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com maxcdn.bootstrapcdn.com tagmanager.google.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://checkout.iwdagency.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com https://get.geojs.io *.avada.io https://api.getaddress.io *.google-analytics.com bat.bing.com bat.bing.net *.clarity.ms *.googlesyndication.com *.linkedin.com *.trustpilot.com *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 "default-src 'self' https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.hubspot.com https://*.hsforms.com https://*.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://*.hsadspixel.net https://*.hubapi.com https://js.hscta.net https://js-eu1.hscta.net https://static.hsappstatic.net https://*.usemessages.com https://*.hsleadflows.net https://*.hsforms.net https://*.hubspotfeedback.com https://feedback.hubapi.com https://feedback-eu1.hubapi.com; style-src 'self' 'unsafe-inline' https://*.hubspot.com https://*.hsforms.com https://fonts.googleapis.com https://*.hubspotusercontent00.net https://*.hubspotusercontent-na1.net https://*.hubspotusercontent-eu1.net https://cdn2.hubspot.net; img-src 'self' data: https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net https://*.hubspotusercontent00.net https://*.hubspotusercontent-na1.net https://*.hubspotusercontent-eu1.net https://no-cache.hubspot.com https://js.hscta.net https://js-eu1.hscta.net https://cdn2.hubspot.net https://*.hubspot.net; font-src 'self' https://fonts.gstatic.com https://*.hubspot.com; connect-src 'self' https://*.hubspot.com https://*.hsforms.com https://api.hubapi.com https://*.hubapi.com https://*.hs-banner.com https://js.hscta.net https://js-eu1.hscta.net https://*.hscollectedforms.net; frame-src 'self' https://*.hubspot.com https://*.hsforms.com https://*.hs-sites.com https://*.hs-sites-eu1.com https://*.hubspot.net https://play.hubspotvideo.com https://play-eu1.hubspotvideo.com https://*.hsforms.net; object-src 'none'; base-uri 'self'; form-action 'self' https://*.hubspot.com https://*.hsforms.com;" 1 font-src *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.userway.org *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.userway.org https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.clarity.ms *.addtoany.com *.bootstrapcdn.com *.userway.org *.avada.io *.shopify.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.maxmind.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.userway.org *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.userway.org https://get.geojs.io *.avada.io http://dpm.demdex.net *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.mmapiws.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; frame-src 'self' wine-cult.firebaseapp.com *.youtube.com *.spotify.com *.vimeo.com *.doubleclick.net *.facebook.com *.trkn.us *.googletagmanager.com *.googlesyndication.com vercel.live vercel.com *.instagram.com form.jotform.com *.ctfassets.net *.audioeye.com *.pinterest.com *.stripe.com *.hsforms.com *.hsforms.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.doubleclick.net *.adsrvr.org *.googlesyndication.com *.youtube.com *.spotify.com *.vimeo.com maps.googleapis.com form.jotform.com *.vercel.live *.audioeye.com *.tiktok.com *.adroll.com *.nextdoor.com *.stackadapt.com *.pinterest.com *.pinimg.com *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hs-banner.com snap.licdn.com *.facebook.net *.pixeltracker.co *.stripe.com *.hsforms.net *.hubspotusercontent-na1.net *.hsappstatic.net; child-src 'self' *.youtube.com *.google.com *.spotify.com vercel.live vercel.com; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.googletagmanager.com *.stackadapt.com *.audioeye.com *.hsforms.net *.hubspotusercontent-na1.net; img-src * blob: data:; media-src 'self' *.cdninstagram.com; object-src data: *.ctfassets.net; connect-src *; font-src 'self' data: *.typekit.net fonts.gstatic.com *.audioeye.com *.hsforms.net *.hubspotusercontent-na1.net; frame-ancestors 'self' https://app.contentful.com; 1 default-src 'self' telligen.okta.com *.oktacdn.com; connect-src 'self' telligen.okta.com telligen-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com telligen.kerberos.okta.com telligen.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: art.login.telligen.com cqmv.login.telligen.com jira.login.telligen.com massqex.login.telligen.com pcmt.login.telligen.com qaqc.login.telligen.com qat.login.telligen.com tea.login.telligen.com; script-src 'unsafe-inline' 'nonce-FWROCQ2Fg0-UuJ1w0Vr-Gw' 'unsafe-eval' 'self' 'report-sample' telligen.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' telligen.okta.com *.oktacdn.com; frame-src 'self' telligen.okta.com telligen-admin.okta.com login.okta.com com-okta-authenticator:; img-src 'self' telligen.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com data: blob:; font-src 'self' telligen.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://myqualitrac.com 1 script-src 'strict-dynamic' 'self' 'nonce-tx32UJD0qET8Zt81mXRVLA==' 'report-sample'; report-uri /yusaauth.onmicrosoft.com/B2C_1A_AppSso_SignUp_SignIn/client/cspreport?p=B2C_1A_AppSso_SignUp_SignIn 1 font-src data: fonts.googleapis.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com www.libertysport.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com www.libertysport.com 'self' 'unsafe-inline'; frame-ancestors www.libertysport.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com www.libertysport.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.cdninstagram.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com www.libertysport.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com www.libertysport.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com https://static.klaviyo.com *.yotpo.com *.googleapis.com www.libertysport.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.libertysport.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com www.libertysport.com 'self' 'unsafe-inline'; child-src www.libertysport.com http: https: blob: 'self' 'unsafe-inline'; default-src www.libertysport.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com www.ups.com rms.ups.com maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.ups.com rms.ups.com maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.gstatic.com/ https://*.lisecharmel.com/media/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.ups.com rms.ups.com maps.googleapis.com polyfill.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://*.doofinder.com/ https://*.newrelic.com/ https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com www.ups.com rms.ups.com maps.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com https://*.allfont.net/ https://*.doofinder.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com ws://localhost:9109/ws wss://localhost:9109/ws wss://localhost:9109/ www.ups.com rms.ups.com maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://*.doofinder.com/ https://*.googleapis.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.gstatic.com applepay.cdn-apple.com maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com static.klaviyo.com *.typekit.net *.linksynergy.com analytics.google.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.paypal.com *.cardinalcommerce.com *.securetrading.net *.arcot.com/ *.americanexpress.com/ omnicapital.co.uk/ *.omnicapital.co.uk/ omniporttest.ocrf.co.uk *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com *.app.storyblok.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.rvvuptech.com *.rvvup.com *.afterpay.com *.clearpay.co.uk *.paypal.com *.sandbox.paypal.com cdn.eu.trustpayments.com *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com *.cardinalcommerce.com pay.google.com thm.visa.com *.mastercard.com *.weltpixel.com *.klarna.com *.issuu.com widget.trustpilot.com *.klarnaservices.com omniport.omnicapital.co.uk *.arcot.com/ *.americanexpress.com/ *.facebook.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com applepay.cdn-apple.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.afterpay.com assets.dev.rvvuptech.com assets.rvvup.com *.paypal.com *.sandbox.paypal.com *.stats.paypal.com *.gstatic.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com widgets.dividebuy.co.uk widgets.dividebuysandbox.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net mageside.com maps.googleapis.com cdn-cookieyes.com *.frenchbedroom.co.uk *.trustpilot.net *.trustpilot.com https://d3k81ch9hvuctc.cloudfront.net/company/ShSreF/images/53d7a9d8-704d-45f0-9571-4cfcdc1e1031.png bat.bing.com https://www.google.co.uk *.linksynergy.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.storyblok.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.afterpay.com *.paypal.com *.sandbox.paypal.com checkout.dev.rvvuptech.com checkout.rvvup.com cdn.eu.trustpayments.com *.securetrading.net pay.google.com *.secure.checkout.visa.com *.cardinalcommerce.com *.mastercard.com applepay.cdn-apple.com widgets.dividebuysandbox.co.uk widgets.dividebuy.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com ajax.googleapis.com cdn.jsdelivr.net querybuilder.js.org maps.googleapis.com cdn-cookieyes.com static.cloudflareinsights.com https://www.gstatic.com/wcm/ https://www.gstatic.com/call-tracking/ widget.trustpilot.com *.crazyegg.com bat.bing.com *.rakuten.com *.searchatlas.com d5yoctgpv4cpx.cloudfront.net *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src checkout.dev.rvvuptech.com checkout.rvvup.com fonts.googleapis.com widgets.dividebuy.co.uk widgets.dividebuysandbox.co.uk https://static.klaviyo.com maxcdn.bootstrapcdn.com *.klarnacdn.net querybuilder.js.org netdna.bootstrapcdn.com cdn.jsdelivr.net *.fontawesome.com *.typekit.net static-tracking.klaviyo.com *.tagmanager.google.com *.googletagmanager.com *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ https://maps.googleapis.com https://player.vimeo.com *.afterpay.com *.paypal.com *.sandbox.paypal.com *.sentry.io *.cardinalcommerce.com google.com *.dev.rvvuptech.com *.rvvup.com www.apple.com apple.com browser-intake-datadoghq.com browser-intake-datadoghq.eu api.dividebuysandbox.co.uk api.dividebuy.co.uk api.addressy.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com maps.googleapis.com cdn-cookieyes.com *.cookieyes.com *.crazyegg.com www.google.com https://pagead2.googlesyndication.com/ www.facebook.com d5yoctgpv4cpx.cloudfront.net p2iqhncxyh.execute-api.eu-central-1.amazonaws.com widget.trustpilot.com/ *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.insights.us.algolia.io insights.us.algolia.io *.insights.de.algolia.io insights.de.algolia.io 'self' 'unsafe-inline'; child-src *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.frenchbedroom.co.uk/csp-report; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube-nocookie.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.instagram.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.xtento.com www.facebook.com h.online-metrix.net vars.hotjar.com www.google.com checkoutshopper-test.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.trackedlink.net content.staging.b2c.hirsch.sneakpeek.cc content.develop.b2c.hirsch.sneakpeek.cc *.trustedshops.com www.xtento.com cdn.xtento.com magefan.com cm.magefan.com www.facebook.com www.google.at h.online-metrix.net maps.googleapis.com maps.gstatic.com content.hirschthebracelet.com cx.atdmt.com *.outbrain.com *.ccm19.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.instagram.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com analytics.tiktok.com *.trustedshops.com www.xtento.com cdn.xtento.com connect.facebook.net www.google.com geoip-js.com h.online-metrix.net cdnjs.cloudflare.com js.authorize.net jstest.authorize.net www.gstatic.com static.hotjar.com script.hotjar.com maps.googleapis.com checkoutshopper-test.adyen.com *.outbrain.com *.ccm19.de js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.ccm19.de assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com analytics.tiktok.com content.staging.b2c.hirsch.sneakpeek.cc content.develop.b2c.hirsch.sneakpeek.cc *.analytics.google.com geoip-js.com stats.g.doubleclick.net h.online-metrix.net *.hotjar.com *.hirschthebracelet.com vc.hotjar.io checkoutshopper-test.adyen.com maps.googleapis.com *.google-analytics.com *.ccm19.de api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.ccm19.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://connect.ekomi.de/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://connect.ekomi.de/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com https://*.tawk.to/ *.fontawesome.com fonts.googleapis.com maxcdn.bootstrapcdn.com http://cdnjs.cloudflare.com/ajax/libs/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube.com/ https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://platform-api.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com https://clauem2.arrowtheme.com https://scontent.cdninstagram.com/ https://buttons-config.sharethis.com https://l.sharethis.com https://platform-cdn.sharethis.com https://scontent-ams4-1.cdninstagram.com https://s3.ap-south-1.amazonaws.com/* https://s3.ap-south-1.amazonaws.com https://*.tawk.to flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com */walletsystem/index/applypaymentamount www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com maps.googleapis.com *.trackedlink.net *.maps.gstatic.com *.googletagmanager.com *.googleadservices.com https://connect.facebook.net https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://*.tawk.to https://adtarbo.eywamedia.com/scripts/adtarbo.min.js https://static.getbutton.io/widget-send-button/js/init.js https://adtarbo.eywamedia.com/scripts/adtarbo-core.min.js?v=66.68988515157149 player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://*.tawk.to/ https://s3.ap-south-1.amazonaws.com/* https://s3.ap-south-1.amazonaws.com maxcdn.bootstrapcdn.com assets.braintreegateway.com unsafe-inline http://cdnjs.cloudflare.com/ajax/libs/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://*.tawk.to/ wss://*.tawk.to https://adtarbo.eywamedia.com/ www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com *.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cloudflare.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cookiebot.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com.ua *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.cloudflare.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com imgsct.cookiebot.com *.google.nl *.google.de *.google.fr *.google.com *.bazaarvoice.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.cloudflare.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com maps.googleapis.com *.cookiebot.com sleeknotestaticcontent.sleeknote.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com display.ugc.bazaarvoice.com downloads.mailchimp.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.cloudflare.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com maps.googleapis.com consentcdn.cookiebot.com *.bazaarvoice.com *.run.app analytics.sleeknote.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://fonts.gstatic.com tag.search.sensefuel.live *.fontawesome.com https://cdnjs.cloudflare.com * data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hipay-tpp.com *.hipay.com *.weltpixel.com *.devatics.com *.hypay.com *.criteo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazonaws.com *.criteo.com *.googletagmanager.com *.google-analytics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.doubleclick.net *.tremorhub.com *.dmxleo.com *.advertising.com *.yieldmo.com *.outbrain.com *.taboola.com *.artadserver.com *.3lift.com *.360yield.com *.smartadserver.com *.pubmatic.com *.casalemedia.com *.teads.tv *.media.net *.adform.net *.omnitagjs.com *.sharethrough.com *.ivitrack.com *.stickyadstv.com *.mediavine.com *.smaato.net *.adnxs.com *.bing.com *.yahoo.com *.liadm.com *.imgix.net *.bidswitch.net *.facebook.com * *.pubads.g.doubleclick.net *.google.com *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hipay-tpp.com *.hipay.com *.iesnare.com *.paypal.com secure-gateway.hipay-tpp.com tag.search.sensefuel.live *.axept.io *.abtasty.com fw-cdn.com *.criteo.net *.criteo.com *.googletagmanager.com ssl.google-analytics.com https://www.googletagmanager.com tagmanager.google.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.facebook.net * *.googleads.g.doubleclick.net *.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hipay.com https://fonts.googleapis.com tag.search.sensefuel.live *.hypay.com *.fontawesome.com tagmanager.google.com https://cdnjs.cloudflare.com assets.braintreegateway.com * 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: *.iesnare.com * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.google.fr *.axept.io *.hypay.com *.search.sensefuel.live *.googletagmanager.com *.analytics.google.com https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.doubleclick.net * *.stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com * http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; form-action 'self' https://bam.nr-data.net; frame-ancestors 'self' 'none'; frame-src 'self' https://*.gcs-web.com https://*.convergepay.com https://www.google.com https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://*.doubleclick.net https://*.smartrecruiters.com https://nationalvision.gcs-web.com https://prnewswire2-a.akamaihd.net/; connect-src 'self' https://code.jquery.com https://*.typekit.net https://fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://www.google-analytics.com https://*.smartrecruiters.com https://*.doubleclick.net https://www.googletagmanager.com https://extreme-ip-lookup.com https://*.extreme-ip-lookup.com https://ipmeta.io https://*.ipmeta.io https://bam.nr-data.net https://bucketeer-db2073e4-ac1a-4046-97bf-04dce765dca1.s3.amazonaws.com/public/ https://jobpal-sm.s3.amazonaws.com https://612dedf14e35cd00d7d60304.config.smooch.io https://api.smooch.io wss://api.smooch.io https://cdn.cookielaw.org/ https://cdn.linkedin.oribi.io; script-src 'self' https://code.jquery.com https://www.gstatic.com https://www.google-analytics.com https://ssl.google-analytics.com https://*.smartrecruiters.com 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://www.youtube.com http://www.youtube.com https://*.ytimg.com https://www.googleadservices.com https://www.google.com https://*.doubleclick.net 'unsafe-eval' https://tagmanager.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://jobpal-sm.s3.amazonaws.com https://api.smooch.io https://unpkg.com https://cdn.cookielaw.org/ https://*.convergepay.com/ https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://connect.facebook.net/ https://snap.licdn.com/ https://www.googleoptimize.com/ https://click.appcast.io/; style-src 'self' https://*.typekit.net https://fonts.googleapis.com https://*.smartrecruiters.com https://tagmanager.google.com https://fonts.googleapis.com 'unsafe-inline' https://jobpal-sm.s3.amazonaws.com https://cdnjs.cloudflare.com/; font-src 'self' https://*.typekit.net https://fonts.gstatic.com https://fonts.gstatic.com data: https://jobpal-sm.s3.amazonaws.com 'nonce-aecf3ec333854fa690830bb9abd77379'; img-src 'self' data: https://www.google-analytics.com https://*.smartrecruiters.com https://www.googletagmanager.com https://www.gstatic.com https://ssl.gstatic.com https://*.doubleclick.net https://www.google.com https://*.googleusercontent.com https://ssl.gstatic.com https://bucketeer-db2073e4-ac1a-4046-97bf-04dce765dca1.s3.amazonaws.com/public/ https://media.smooch.io https://i.americasbest.com https://cdn.cookielaw.org/ https://click.appcast.io/ https://px.ads.linkedin.com/ https://www.facebook.com/ https://px4.ads.linkedin.com https://www.multivu.com/national-vision-holdings/*; manifest-src 'self'; media-src 'self' https://jobpal-sm.s3.amazonaws.com; report-uri https://aclens.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/recaptcha/ www.facebook.com platform.twitter.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google-analytics.com *.googleapis.com 'self' data: www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com/recaptcha/ connect.facebook.net twitter.com platform.twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.homoactive.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com 'self' ws: 'self' wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://hyperreal.info https://koks.hyperreal.top; default-src 'none'; font-src 'self'; img-src 'self' https://koks.hyperreal.top https://hyperreal.info; script-src 'self' 'unsafe-inline' https://hyperreal.info; style-src 'self' 'unsafe-inline'; manifest-src 'self' https://hyperreal.info; 1 default-src 'self' *.cookiebot.com https://liveupdate.pimcore.org *.cloudflare.com *.googleapis.com maps.gstatic.com gtm.simplon.com youtube.com *.google.com *.google.at www.youtube.com youtube-nocookie.com geo.dailymotion.com dailymotion.com player.vimeo.com vimeo.com *.kameleoon.com *.doubleclick.net www.facebook.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.hotjar.com https://*.hotjar.io https://connect.facebook.net https://*.unzer.com https://h.online-metrix.net https://pay.google.com e.issuu.com https://www.bodyscanningcrm-cloud.de https://coronavirus.jhu.edu https://experience.arcgis.com https://simplon.factorialhr.de; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com https://use.fontawesome.com https://*.hotjar.com https://*.hotjar.io https://*.unzer.com; img-src * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.google.at *.doubleclick.net gtm.simplon.com maps.googleapis.com www.googletagmanager.com https://cdnjs.cloudflare.com https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.hotjar.com https://*.hotjar.io https://connect.facebook.net www.facebook.com https://*.unzer.com https://h.online-metrix.net https://*.google.com https://*.google.at; style-src 'self' 'unsafe-inline' https://use.fontawesome.com fonts.googleapis.com https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net https://*.hotjar.com https://*.hotjar.io https://*.unzer.com; report-uri /nelmio/csp/report 1 default-src 'self' 'unsafe-inline' https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://images.wegmans.com https://s7d1.scene7.com https://hello.myfonts.net https://dok.js-cdn.dynatrace.com https://cm.everesttech.net https://www.google.com https://ct.pinterest.com https://px.ads.linkedin.com https://www.facebook.com https://connect.facebook.net https://googleads.g.doubleclick.net *.adobedc.com https://di.rlcdn.com https://s.pinimg.com https://snap.licdn.com ; connect-src data: https://meals2go.cert.wegmans.cloud https://meals2go.dev.wegmans.cloud https://meals2go.test.wegmans.cloud *.livediagnostics.monitor.azure.com *.applicationinsights.azure.com https://images.wegmans.com https://meals2go.wegmans.com https://www.meals2go.com https://meals2go.com https://wfm-cmp-functionapp-prod-eastus.azurewebsites.net https://wfm-cmp-functionapp-cert-eastus.azurewebsites.net https://wfm-cmp-functionapp-dev-eastus.azurewebsites.net https://wfm-cmp-functionapp-sandbox-eastus.azurewebsites.net https://cdn.cookielaw.org https://geolocation.onetrust.com https://googleads.g.doubleclick.net https://google.com https://www.google.com https://myaccount.wegmans.com https://stagingmyaccount.wegmans.com https://wegapi.azure-api.net https://wegdevapi.azure-api.net https://wegcertapi.azure-api.net https://*.digitaldevelopment.wegmans.cloud https://mbox.wegmans.com https://app.launchdarkly.com https://events.launchdarkly.com https://*.akstat.io https://*.go-mpulse.net https://dc.services.visualstudio.com https://dpm.demdex.net https://adobedc.demdex.net https://edge.adobedc.net https://clientstream.launchdarkly.com https://js.monitor.azure.com https://s.pinimg.com https://ct.pinterest.com https://px.ads.linkedin.com https://snap.licdn.com https://www.facebook.com https://*.bf.dynatrace.com https://www.googleadservices.com https://dok.js-cdn.dynatrace.com https://cm.everesttech.net https://www.googletagmanager.com https://fonts.gstatic.com https://connect.facebook.net https://hello.myfonts.net https://s7d1.scene7.com https://beacon.riskified.com https://c.riskified.com; script-src 'self' 'unsafe-inline' https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://myaccount.wegmans.com https://*.go-mpulse.net https://cm.everesttech.net https://px.ads.linkedin.com https://s.pinimg.com https://googleads.g.doubleclick.net https://www.google.com https://hello.myfonts.net https://di.rlcdn.com https://connect.facebook.net px.ads.linkedin.com ; script-src-elem 'self' 'unsafe-inline' data: https://images.wegmans.com https://myaccount.wegmans.com https://wfm-cmp-functionapp-prod-eastus.azurewebsites.net https://wfm-cmp-functionapp-cert-eastus.azurewebsites.net https://wfm-cmp-functionapp-dev-eastus.azurewebsites.net https://wfm-cmp-functionapp-sandbox-eastus.azurewebsites.net https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://dok.js-cdn.dynatrace.com https://*.go-mpulse.net https://googleads.g.doubleclick.net https://www.google.com https://www.googleadservices.com https://cm.everesttech.net px.ads.linkedin.com https://px.ads.linkedin.com https://ct.pinterest.com https://www.googletagmanager.com https://connect.facebook.net https://www.facebook.com *.adobedc.com https://assets.adobedtm.com https://di.rlcdn.com https://s.pinimg.com https://snap.licdn.com https://fonts.gstatic.com https://dpm.demdex.net https://hello.myfonts.net https://s7d1.scene7.com https://cdn.cookielaw.org https://beacon.riskified.com; img-src 'self' data: https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://myaccount.wegmans.com https://images.wegmans.com https://images.salsify.com https://cdn.cookielaw.org https://*.akstat.io https://img.riskified.com https://d19hn3jcfcdeky.cloudfront.net https://d17qf54098xvyo.cloudfront.net *.adobedc.com https://di.rlcdn.com https://s.pinimg.com https://ct.pinterest.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.linkedin.com https://www.googletagmanager.com https://s7d1.scene7.com https://cm.everesttech.net https://www.google.com https://www.facebook.com px.ads.linkedin.com https://px.ads.linkedin.com https://dok.js-cdn.dynatrace.com https://fonts.gstatic.com https://dpm.demdex.net https://hello.myfonts.net https://connect.facebook.net https://snap.licdn.com; frame-src 'self' data: https://images.wegmans.com https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://myaccount.wegmans.com https://stagingmyaccount.wegmans.com *.adobedc.com https://login.microsoftonline.com *.aurusepay.com *.auruspay.com https://0324.semafone.cloud https://0324.preprod.semafone.cloud https://di.rlcdn.com https://s.pinimg.com https://connect.facebook.net https://ct.pinterest.com https://wegmans.demdex.net https://snap.licdn.com https://googleads.g.doubleclick.net https://td.doubleclick.net https://www.googletagmanager.com https://dok.js-cdn.dynatrace.com https://cm.everesttech.net https://px.ads.linkedin.com https://fonts.gstatic.com https://www.google.com https://www.facebook.com https://hello.myfonts.net https://s7d1.scene7.com ; style-src-elem 'self' 'unsafe-inline' https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://px.ads.linkedin.com https://hello.myfonts.net; font-src 'self' data: https://meals2go.com https://meals2go.wegmans.com https://www.meals2go.com https://dok.js-cdn.dynatrace.com https://cm.everesttech.net https://www.google.com https://fonts.gstatic.com ; worker-src 'self' blob: ; frame-ancestors 'self' https://googleads.g.doubleclick.net https://td.doubleclick.net ; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-XBwgZq8vvu8Um2Wn84Tl7FCVY' 'strict-dynamic' 'report-sample'; report-uri https://troypointinsider.com/csp_reports; frame-ancestors 'self'; manifest-src 'self' 1 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://maps.googleapis.com https://*.pendo.io https://pendo-io-static.storage.googleapis.com https://stats.pusher.com https://cdn.datatables.net https://cdnjs.cloudflare.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://pendo-static-5749076184662016.storage.googleapis.com https://pendo-io-static.storage.googleapis.com https://static.parcelplatform.com https://stats.pusher.com https://www.google.com https://www.googletagmanager.com https://maps.googleapis.com https://*.pendo.io https://www.gstatic.com https://cdn.datatables.net https://widget.intercom.io https://js.intercomcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.datatables.net; img-src 'self' data: https://www.google.com https://*.googleapis.com https://maps.gstatic.com https://*.collateral360.com https://*.pendo.io https://*.s3.amazonaws.com https://www.googletagmanager.com https://static.parcelplatform.com https://static.intercomassets.com https://*.intercomcdn.com https://content.pendo.spatialstream.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://fonts.intercomcdn.com; connect-src 'self' https://www.google.com https://*.googleapis.com https://stats.g.doubleclick.net https://data.pendo.io https://sockjs-us2.pusher.com wss://ws-us2.pusher.com https://api-iam.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io; frame-src 'self' https://c360parc-datastorage-prod.s3.amazonaws.com https://www.google.com; form-action 'self'; report-to default 1 default-src 'self'; script-src 'self' https://d3e54v103j8qbb.cloudfront.net https://www.letzchat.com https://snap.licdn.com https://player.vimeo.com https://www.youtube.com https://letzchat.pro https://letz.chat https://lionfish-app-u7ksx.ondigitalocean.app https://ajax.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com https://js.intercomcdn.com https://cdn.jsdelivr.net https://js.stripe.com https://widget.intercom.io https://d3iu75986odi10.cloudfront.net 'unsafe-inline'; style-src 'self' https://trustedstyles.example.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://www.letzchat.com 'unsafe-inline'; img-src 'self' data: https://www.letzchat.com https://letzchat.com https://assets-global.website-files.com https://px.ads.linkedin.com https://media.giphy.com https://downloads.intercomcdn.com https://px4.ads.linkedin.com https://i.ibb.co; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://assets.website-files.com data:; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://js.stripe.com; worker-src 'self' blob:; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; connect-src 'self' https://letzchat.pro https://px.ads.linkedin.com https://letzchat.com https://api-iam.intercom.io https://api.emailjs.com; media-src 'self' data:; 1 default-src 'self'; script-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/i/jot https://cdn.syndication.twimg.com/ https://*.clarity.ms https://c.bing.com ; connect-src 'self' https://www.google-analytics.com/ https://api.payu.in/ https://secure.payu.in/ ; img-src 'self' data: https://*.twimg.com https://platform.twitter.com/ https://img.youtube.com/ https://i.ytimg.com/; style-src 'self' https://platform.twitter.com 'unsafe-inline'; font-src 'self' https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://fonts.gstatic.com/; base-uri 'self'; form-action 'self' https://api.payu.in/ https://secure.payu.in/ https://platform.twitter.com/ https://syndication.twitter.com/i/jot/; frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com https://www.google.com/ https://www.youtube.com/ https://www.youtube-nocookie.com/ https://open.spotify.com/; script-src-elem 'self' https://www.youtube.com/ https://www.googletagmanager.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://code.jquery.com/ https://canvasjs.com/assets/script/ https://canvasjs.com/assets/script/ https://cdnjs.cloudflare.com/ajax/libs/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.0/ https://fonts.googleapis.com/ https://www.google-analytics.com/ https://www.googleadservices.com/ https://*.clarity.ms https://c.bing.com 'unsafe-inline'; style-src-elem 'self' https://code.jquery.com/ 'unsafe-inline' https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.0/ https://fonts.googleapis.com/ https://www.google-analytics.com/ https://www.googleadservices.com/ ; script-src-attr 'self' 'unsafe-inline' ; navigate-to 'self' https://api.payu.in/ https://secure.payu.in/ ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com app-sj39.marketo.com *.mktoweb.com *.avis-verifies.com *.tricorbraun.com *.facebook.com *.paypalobjects.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.facebook.com *.bing.com *.linkedin.com *.postcodeanywhere.co.uk *.google.com *.google.com.ua *.bidswitch.net *.rlcdn.com *.casalemedia.com *.openx.net *.outbrain.com *.pubmatic.com *.yahoo.com *.taboola.com *.3lift.com *.adnxs.com *.adroll.com *.rubiconproject.com *.addthis.com *.b-cdn.net *.clarity.ms *.googleapis.com *.ipredictive.com *.company-target.com https://cdn.cookielaw.org *.bizible.com *.bizibly.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.app-sj39.marketo.com *.marketo.com *.marketo.net *.nr-data.net *.newrelic.com *.mktoweb.com *.cookie-script.com *.avis-verifies.com *.licdn.com *.gstatic.com *.tricorbraun.com *.postcodeanywhere.co.uk *.pcapredict.com *.facebook.net *.facebook.com *.bing.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.callrail.com gleam.io *.gleam.io *.zopim.com *.bizible.com *.hotjar.io *.hotjar.com *.adroll.com *.zdassets.com *.curator.io *.clarity.ms *.googleapis.com *.hellobar.com *.snapengage.com *.skeepers.io *.cardinalcommerce.com https://includestest.ccdc02.com https://googleads.g.doubleclick.net *.paypal.com *.paypalobjects.com https://cdn.cookielaw.org https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.marketo.com *.mktoweb.com *.postcodeanywhere.co.uk *.tricorbraun.com *.gleam.io *.curator.io *.fontawesome.com https://static.klaviyo.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.b-cdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.mktoresp.com *.nr-data.net *.newrelic.com *.oribi.io *.doubleclick.net *.callrail.com *.zdassets.com *.zendesk.com wss://*.zopim.com https://*.zopim.com *.adroll.com *.bing.com *.curator.io *.clarity.ms *.ip-api.com *.google.com.ua *.googlesyndication.com *.postcodeanywhere.co.uk https://cdn.cookielaw.org https://px.ads.linkedin.com *.hotjar.io *.hotjar.com wss://*.hotjar.com *.onetrust.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.cleverreach.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.hotjar.com secure.pay1.de/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.cloudfront.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://api.mapbox.com cdn.pay1.de x.klarnacdn.net m.media-amazon.com static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com widgets.trustedshops.com mcstagingmedia.carou.com mcprodmedia.carou.com *.google.com www.google.com.ua ct.pinterest.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.hotjar.com unsafe-inline *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://integrations.etrusted.com widgets.trustedshops.com bam.nr-data.net js-agent.newrelic *.ratepay.com js-agent.newrelic.com s.pinimg.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com d.ratepay.com d.payla.io dr.payla.io maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com/ *.ratepay.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.hotjar.com wss://*.hotjar.com/ bam.nr-data.net www.carou.com stats.g.doubleclick.net vc.hotjar.io ct.pinterest.com analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src-elem 'self' 'unsafe-inline' https://static.zdassets.com https://js.stripe.com https://cdn.segment.com https://dev.visualwebsiteoptimizer.com https://maps.googleapis.com https://analytics.tiktok.com; style-src 'self' 'unsafe-inline'; img-src 'self' data:; frame-src 'self' https://js.stripe.com; media-src 'self' https://static.zdassets.com; connect-src 'self' https://maps.googleapis.com https://api.segment.io https://z3nm41nt3nanc3m0d3.s3.us-east-2.amazonaws.com https://browser-intake-datadoghq.com https://ekr.zdassets.com https://zensurance.zendesk.com https://cdn.segment.com https://duckduckgo.com wss://widget-mediator.zopim.com https://analytics.tiktok.com https://zenstage.wpengine.com; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cytoplan.co.uk *.cloudfront.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors builder.io cdn.builder.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://static.addtoany.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com js.mollie.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com/ *.mention-me.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.mollie.com store.paradoxlabs.com cdn.builder.io *.bing.com *.feefo.com *.cytoplan.co.uk *.livechat-files.com *.visualwebsiteoptimizer.com *.sharethis.com *.cloudfront.net *.trackedlink.net *.dycdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://static.addtoany.com/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com js.mollie.com cdn.builder.io *.livechatinc.com unpkg.com *.clarity.ms *.cytoplan.co.uk ipinfo.io *.google-analytics.com *.trackedweb.net *.feefo.com *.bing.com *.cookiefirst.com *.adroll.com *.visualwebsiteoptimizer.com *.cardinalcommerce.com *.adobe.net *.googletagmanager.com https://www.gstatic.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com cdn.jsdelivr.net/npm/@adobe *.paypal.com *.paypalobjects.com pay.google.com *.braintreegateway.com *.facebook.com *.facebook.net *.trackedlink.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com static.trackedweb.net *.webgains.io *.googlesyndication.com *.sharethis.com *.cloudfront.net *.tangoo.it *.ddlnk.net debug-tracking.dotdigital.internal *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net am.freshrelevance.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.mention-me.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com register.feefo.com *.cytoplan.co.uk *.visualwebsiteoptimizer.com *.cloudfront.net cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://stats.addtoany.com/menu *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.builder.io *.feefo.com *.cookiefirst.com *.demdex.net *.clarity.ms *.livechatinc.com *.visualwebsiteoptimizer.com *.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.sharethis.com *.googlesyndication.com *.cloudfront.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.dycdn.net am.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.mention-me.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com r1.trackedweb.net collect.feefo.com *.cytoplan.co.uk x.clarity.ms secure.livechatinc.com commerce.adobe.io commerce.adobedc.net *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://storage.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://services.postcodeanywhere.co.uk https://storage.googleapis.com https://cdn-cookieyes.com https://www.facebook.com https://syndication.twitter.com https://www.google.com/ https://www.google.co.uk/ https://bat.bing.com https://www.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com https://www.snapengage.com http://storage.googleapis.com https://www.clarity.ms https://cdn-cookieyes.com https://www.facebook.com https://connect.facebook.net https://platform.twitter.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://platform.linkedin.com https://bat.bing.com https://cdn.callrail.com https://js.callrail.com https://analytics.tester.co.uk https://porta11117.pcapredict.com https://services.postcodeanywhere.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com https://services.postcodeanywhere.co.uk assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com https://analytics.tester.co.uk https://*.cookieyes.com https://cdn-cookieyes.com https://*.callrail.com https://*.clarity.ms https://capig.stape.host https://services.postcodeanywhere.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com use.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://api.pre.globalgetnet.com https://api.globalgetnet.com magento-cloudflare.jetrails.com www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com *.getbeamer.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://newimgebit-a.akamaihd.net *.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.getbeamer.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://imgs.ebit.com.br https://newimgebit-a.akamaihd.net *.google.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googletagmanager.com *.facebook.net *.getbeamer.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline use.fontawesome.com *.getbeamer.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://newimgebit-a.akamaihd.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.getbeamer.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com *.fontawesome.com https://fonts.bunny.net www.euroshop.be https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com https://www.google.com www.googletagmanager.com www.google.com ct.pinterest.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com maps.gstatic.com maps.googleapis.com *.disqus.com https://firebasestorage.googleapis.com www.euroshop.be raw.githubusercontent.com www.facebook.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com https://www.gstatic.com maps.googleapis.com https://www.google.com *.disqus.com *.avada.io www.euroshop.be cdnjs.cloudflare.com www.google.com www.gstatic.com connect.facebook.net s.pinimg.com apis.google.com ct.pinterest.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net www.euroshop.be cdn.jsdelivr.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://get.geojs.io *.avada.io www.euroshop.be ct.pinterest.com 7rc2kiath6-dsn.algolia.net payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.euroshop.be pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com https://www.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com log.pinterest.com ssl.google-analytics.com maps.googleapis.com maps.gstatic.com dev.visualwebsiteoptimizer.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com js-agent.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com www.gstatic.com t.trackedlink.net assets.pinterest.com maps.googleapis.com ssl.google-analytics.com dev.visualwebsiteoptimizer.com bam-cell.nr-data.net s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com www.giftomatic.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com log.pinterest.com bam-cell.nr-data.net ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.vercel-insights.com https://*.memberstack.com https://*.algolia.net https://*.algolianet.com https://accounts.google.com https://*.google.com https://*.bitcompare.net https://analytics.ahrefs.com; style-src 'self' 'unsafe-inline' https://accounts.google.com https://*.google.com; img-src 'self' blob: data: https://*.amazonaws.com https://*.bitcompare.net https://bitcompare.net https://accounts.google.com https://*.google.com ; font-src 'self' data:; connect-src 'self' https://*.vercel-insights.com https://*.memberstack.com https://*.algolia.net https://*.algolianet.com https://*.amazonaws.com https://*.bitcompare.net https://bitcompare.net https://accounts.google.com https://*.google.com https://analytics.ahrefs.com wss://*.vercel.live; frame-src 'self' https://*.memberstack.com https://accounts.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; report-uri https://bitcompare.net/api/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * static.olark.com *.facebook.com amc.demdex.net *.certcapture.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.christianlight.com *.visualwebsiteoptimizer.com *.google.com *.windows.net *.facebook.com *.google.ru *.bing.com *.olark.com *.cookielaw.org *.googleapis.com https://*.gstatic.com *.certcapture.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com dev.visualwebsiteoptimizer.com connect.facebook.net bat.bing.com cdn.roirevolution.com js.bronto.com *.olark.com ajax.googleapis.com edge1.certona.net www.res-x.com *.celebros-analytics.com js-agent.newrelic.com bam-cell.nr-data.net *.cookielaw.org *.googleapis.com https://*.gstatic.com *.certcapture.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com use.fontawesome.com uitemplatev3stag.celebros.com static.olark.com www.christianlight.com *.certcapture.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com *.christianlight.com *.cookielaw.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.roirevolution.com *.google-analytics.com *.bronto.com *.olark.com *.doubleclick.net bam-cell.nr-data.net *.cookielaw.org *.onetrust.com *.googleapis.com *.certcapture.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.christianlight.com/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'unsafe-inline' data: *.fontawesome.com https://fonts.gstatic.com 'self' data: *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com https://s7.addthis.com z.moatads.com https://www.youtube.com https://c.paypal.com/ *.google.com/ https://player.vimeo.com https://www.youtube-nocookie.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com *.google.com *.omappapi.com https://www.magezon.com https://redchamps.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com https://s7.addthis.com api.cartstack.com z.moatads.com acsbapp.com a.omappapi.com v1.addthisedge.com m.addthis.com api-public.addthis.com static.hotjar.com static.doubleclick.net script.hotjar.com tools.luckyorange.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com *.google.com/ https://player.vimeo.com https://www.youtube.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com a.omappapi.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com www.apptrian.com cdn.acsbapp.com api.omappapi.com api-public.addthis.com stats.g.doubleclick.net in.hotjar.com wsp34.hotjar.com content.hotjar.io m.addthis.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src *.videsk.io videsk.io videsk.us https://youtube.com; frame-ancestors 'self' *.videsk.io videsk.io videsk.us;block-all-mixed-content;script-src 'self' 'report-sample' 'unsafe-inline' *.videsk.io videsk.io videsk.us https://content.linkedin.com https://challenges.cloudflare.com https://forms.hsforms.com https://google-analytics.com https://googletagmanager.com https://js.hsforms.net https://js.hscollectedforms.net https://js.hs-analytics.net https://js.usemessages.com https://js.hubspotfeedback.com https://js.hsadspixel.net https://js.hs-banner.com https://js.hsleadflows.net https://js-na1.hs-scripts.com https://js.hs-scripts.com https://m.youtube.com https://platform.linkedin.com https://static-exp1.licdn.com https://snap.licdn.com https://ssl.google-analytics.com https://static.cloudflareinsights.com https://tag.clearbitscripts.com https://tagmanager.google.com https://www.youtube.com https://www.google-analytics.com https://www.googletagmanager.com https://x.clearbitjs.com;style-src 'self' 'report-sample' 'unsafe-inline' *;object-src 'none' *.videsk.io videsk.io videsk.us;child-src 'self' *.videsk.io videsk.io videsk.us app.hubspot.com forms.hsforms.com js.usemessages.com js.hscollectedforms.net js.hsadspixel.net www.youtube.com www.googletagmanager.com;base-uri 'self' *.videsk.io videsk.io videsk.us;form-action 'self' *.videsk.io videsk.io videsk.us forms.hubspot.com forms.hsforms.com;worker-src 'self' *.videsk.io videsk.io videsk.us; 1 default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 1 default-src 'self' *.amazonaws.com *.zendesk.com;style-src 'self' 'unsafe-inline' localhost;font-src 'self' localhost blob: data:;script-src 'self' 'unsafe-inline' 'unsafe-eval' static.zdassets.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com consent.cookiebot.com consentcdn.cookiebot.com localhost;object-src 'self'; img-src 'self' *.amazonaws.com *.google-analytics.com *.analytics.google.com www.novalnet.de *.cookiebot.com localhost data: blob:;media-src 'self';connect-src localhost *.zdassets.com *.zendesk.com *.google-analytics.com *.analytics.google.com *.cookiebot.com *.friendlycaptcha.com t.plcnextstore.com 'self';worker-src 'self' *.friendlycaptcha.com blob:;frame-src localhost 'self' proficloud-dev.github.io/plcnextstore-mvp/3pc.html consent.cookiebot.com consentcdn.cookiebot.com blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.lightboxcdn.com *.tidio.co *.tidiochat.com *.fontawesome.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com fast.wistia.net www.facebook.com ct.pinterest.com td.doubleclick.net *.freshchat.com 747659468831792.webpush.freshchat.com *.tidio.co *.tidiochat.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com platform.twitter.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com bat.bing.com *.lightboxcdn.com c.bing.com c.clarity.ms www.facebook.com www.google.co.in ct.pinterest.com dev.visualwebsiteoptimizer.com seal-atlanta.bbb.org *.tidio.co *.tidiochat.com *.disqus.com *.paytomorrow.com connect.facebook.net graph.facebook.com business.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com s.pinimg.com fast.wistia.net *.bing.com *.lightboxcdn.com c.bing.com c.clarity.ms connect.facebook.net *.s.pinimg.com dev.visualwebsiteoptimizer.com js-agent.newrelic.com munchkin.marketo.net www.clarity.ms tools.luckyorange.com www.google.co.in *.tidio.co *.tidiochat.com *.adobe.com *.cardinalcommerce.com *.paypal.com *.bolt.com *.commerce-quick-checkout.com www.gstatic.com/recaptcha/ polyfill.io *.yotpo.com *.clarity.ms tools.luckyorange.com s7.addthis.com www.facebook.com *.authorize.net *.braintreegateway.com *.tidio.co *.tidiochat.com *.fontawesome.com *.braintreegateway.com *.yotpo.com *.googleapis.com *.pushengage.com static.hotjar.com test.popin.to static.popin.to acsbapp.com *.freshchat.com fw-cdn.com script.hotjar.com *.disqus.com *.paytomorrow.com https://storage.googleapis.com graph.facebook.com business.facebook.com twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.lightboxcdn.com *.tidio.co *.tidiochat.com *.fontawesome.com *.braintreegateway.com *.yotpo.com *.googleapis.com *.pushengage.com static.popin.to *.freshchat.com *.paytomorrow.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com analytics.google.com www.googleadservices.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.authorize.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com ct.pinterest.com www.google-analytics.com bat.bing.com stats.g.doubleclick.net u.clarity.ms g.clarity.ms pagead2.googlesyndication.com settings.luckyorange.com *.tidio.co *.tidiochat.com *.bolt.com *.algolia.com *.pinterest.com www.facebook.com connect.facebook.net *.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.yotpo.com fw-cdn.com *.678-xif-269.mktoresp.com dev.visualwebsiteoptimizer.com *.hotjar.io *.acsbapp.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src checkout-sandbox.getbread.com *.tidio.co *.tidiochat.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.typekit.net *.trustedshops.com *.chimpstatic.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.googletagmanager.com *.freshchat.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com *.cloudflare.com https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.chimpstatic.com *.usercentrics.eu *.google.rs *.feefo.com *.onetrust.com *.postcodeanywhere.co.uk https://img.belladinotte.com *.bing.net *.bing.com *.cloudfront.net *.google.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.gstatic.com *.avada.io *.cloudflare.com *.trustedshops.com *.usercentrics.eu *.chimpstatic.com *.instagram.com *.adobedtb.com *.freshchat.com *.feefo.com *.onetrust.com *.klaviyo.com *.adobedtm.com *.pcapredict.com *.postcodeanywhere.co.uk *.bing.com *.matomo.cloud *.lrkt-in.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'unsafe-hashes'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.feefo.com *.postcodeanywhere.co.uk https://img.belladinotte.com *.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.cloudflare.com *.chimpstatic.com *.feefo.com *.onetrust.com *.klaviyo.com *.postcodeanywhere.co.uk *.bing.com *.matomo.cloud *.bing.net *.lrkt-in.com *.googleapis.com *.cloudfront.net *.hotjar.com wss://*.hotjar.com *.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.trustpilot.com *.pinterest.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: bat.bing.com px.ads.linkedin.com *.google.com *.google.co.uk *.doubleclick.net *.facebook.com *.tawk.to *.hsforms.com *.hubspot.com cdn.jsdelivr.net *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.avada.io https://getaddress.io *.google.com *.gstatic.com *.cookie-script.com *.pinimg.com *.typekit.net *.trustpilot.com unpkg.com *.clarity.ms *.adobedtm.com *.adobe.net *.braintreegateway.com *.pinterest.com *.googletagmanager.com *.google-analytics.com *.tawk.to *.facebook.net *.bing.com snap.licdn.com *.doubleclick.net cdn.jsdelivr.net *.hs-scripts.com *.usemessages.com *.hscollectedforms.net *.hs-analytics.net *.hs-banner.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.tawk.to *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://get.geojs.io *.avada.io https://api.getaddress.io *.google-analytics.com ct.pinterest.com *.trustpilot.com *.clarity.ms *.google.co.uk *.tawk.to wss://*.tawk.to px.ads.linkedin.com *.googlesyndication.com *.doubleclick.net *.hubspot.com *.hscollectedforms.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com *.googleapis.com *.adobedc.net *.trackedweb.net *.bing.com *.clarity.ms *.google.com *.tawk.to 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: https://fonts.googleapis.com https://fonts.gstatic.com *.walmartimages.com *.amazonaws.com *.fontawesome.com *.typekit.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.avril.ca *.flippenterprise.net *.wishabi.net *.wishabi.com *.google.ca *.google.com *.bing.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com blob: *.webpushr.com *.flippenterprise.net https://www.google-analytics.com *.stripe.com *.jsdelivr.net *.privacy-center.org *.zdassets.com *.zendesk.com https://*.privacy-center.org *.newrelic.com *.cloudflareinsights.com *.bing.com *.clarity.ms www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.flippenterprise.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://developer.adobe.com *.flippenterprise.net *.launchdarkly.com *.flippback.com *.flipp.com *.doubleclick.net *.webpushr.com *.googlesyndication.com *.privacy-center.org *.zdassets.com *.zendesk.com *.nr-data.net *.clarity.ms https://*.privacy-center.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com ws: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://*.privacy-center.org 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'report-sample' 'self' 'unsafe-inline' data: blob: *.poly.jp poly.9d3259bfa8e0e56ab72a9adff99435b3.r2.cloudflarestorage.com *.imgix.net challenges.cloudflare.com *.pay.jp *.twimg.com cdn.discordapp.com www.googletagmanager.com www.youtube.com *.ytimg.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat;report-to csp-violation-report 1 connect-src 'self' *.doubleclick.net *.facebook.com *.google.com *.google-analytics.com *.mapbox.com *.pinterest.com; font-src 'self'; frame-src *.authorize.net *.doubleclick.net *.facebook.com *.google.com *.hcaptcha.com *.instagram.com *.issuu.com *.pinterest.com *.youtube.com; img-src 'self' *.doubleclick.net *.facebook.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com nugget-markets-01.s3.us-west-1.amazonaws.com *.nuggetmarkets.net *.simpli.fi; script-src-elem 'self' *.authorize.net *.facebook.net *.google-analytics.com *.googletagmanager.com *.hcaptcha.com *.instagram.com *.mapbox.com *.pinimg.com *.pinterest.com *.simpli.fi; style-src-elem 'self' *.mapbox.com; form-action 'self' *.facebook.com; report-uri https://nugget.report-uri.com/r/t/csp/wizard 1 font-src *.fontawesome.com https://static.payzen.eu/static/ *.gstatic.com 'self' data: fonts.googleapis.com fonts.gstatic.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://app.goodays.co https://metrics.flunch-traiteur.fr https://ct.pinterest.com https://try.abtasty.com https://teddytor.abtasty.com https://pixel.rubiconproject.com/tap.php https://ad.avtm.fr https://connect.facebook.net https://www.facebook.com https://api2.abtasty.com https://api.abtasty.com https://o132438.ingest.sentry.io https://common-fonts.abtasty.com https://widgets-images.abtasty.com https://editor-assets.abtasty.com https://sslwidget.criteo.com https://www.criteo.net https://www.criteo.com https://measurement-api.criteo.com https://googleads.g.doubleclick.net https://*.outbrain.com https://*.contentsquare.net https://app.contentsquare.com https://online.flippingbook.com https://k-eu1.az.contentsquare.net https://*.elfsight.com https://jeu.flunch.fr https://applepay.cdn-apple.com/ https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ *.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * maps.google.com maps.googleapis.com critizr.com data: *.axept.io *.addthis.com axeptio.imgix.net *.newrelic.com *.nr-data.net *.moatads.com *.addthisedge.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com magefan.com cm.magefan.com https://bat.bing.com https://sk.ht https://dynamic.criteo.com https://tracking.lqm.io https://s.yimg.com https://snap.licdn.com https://s.pinimg.com https://insight.adsrvr.org https://cdn.linkedin.oribi.io https://pixel.bsmartdata.com https://track.adform.net https://ct.pinterest.com https://px.ads.linkedin.com https://try.abtasty.com https://teddytor.abtasty.com https://pixel.rubiconproject.com/tap.php https://ad.avtm.fr https://ariane.abtasty.com https://dcinfos-cache.abtasty.com https://connect.facebook.net https://www.facebook.com https://api2.abtasty.com https://api.abtasty.com https://o132438.ingest.sentry.io https://common-fonts.abtasty.com https://widgets-images.abtasty.com https://editor-assets.abtasty.com https://sslwidget.criteo.com https://www.criteo.net https://www.criteo.com https://measurement-api.criteo.com https://googleads.g.doubleclick.net https://*.outbrain.com https://*.contentsquare.net https://app.contentsquare.com https://online.flippingbook.com https://k-eu1.az.contentsquare.net https://*.elfsight.com https://jeu.flunch.fr https://applepay.cdn-apple.com/ https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ 'self' data: *.google.com *.mageside.com mageside.com *.disqus.com https://img.youtube.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com *.tile.openstreetmap.org *.axept.io *.addthis.com axeptio.imgix.net *.newrelic.com *.nr-data.net *.moatads.com *.addthisedge.com appsdev.agapes.fr *.agapes.fr blob: data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://partner.flunch-traiteur.fr https://events.sk.ht/flunchtraiteur https://events.sk.ht/flunchtraiteur/lib.js https://bat.bing.com https://metrics.flunch-traiteur.fr https://sk.ht https://dynamic.criteo.com https://tracking.lqm.io https://s.yimg.com https://snap.licdn.com https://s.pinimg.com https://insight.adsrvr.org https://cdn.linkedin.oribi.io https://pixel.bsmartdata.com https://track.adform.net https://ct.pinterest.com https://try.abtasty.com https://teddytor.abtasty.com https://pixel.rubiconproject.com/tap.php https://ad.avtm.fr https://ariane.abtasty.com https://dcinfos-cache.abtasty.com https://connect.facebook.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://www.facebook.com https://api2.abtasty.com https://api.abtasty.com https://o132438.ingest.sentry.io https://common-fonts.abtasty.com https://cdn.jsdelivr.net https://widgets-images.abtasty.com https://editor-assets.abtasty.com https://sslwidget.criteo.com https://www.criteo.net https://www.criteo.com https://measurement-api.criteo.com https://googleads.g.doubleclick.net https://*.outbrain.com https://*.contentsquare.net https://app.contentsquare.com https://online.flippingbook.com https://k-eu1.az.contentsquare.net https://*.elfsight.com https://*.elfsightcdn.com https://jeu.flunch.fr https://cdn.goodays.co/sdk/ https://applepay.cdn-apple.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.google.com/ *.gstatic.com *.google.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.google.com static.axept.io static.critizr.com secure.authorize.net test.authorize.net s7.addthis.com data: *.axept.io *.addthis.com axeptio.imgix.net *.newrelic.com *.nr-data.net *.moatads.com *.addthisedge.com *.matomo.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://cdn.goodays.co https://metrics.flunch-traiteur.fr https://sk.ht https://dynamic.criteo.com https://tracking.lqm.io https://s.yimg.com https://snap.licdn.com https://s.pinimg.com https://insight.adsrvr.org https://cdn.linkedin.oribi.io https://pixel.bsmartdata.com https://track.adform.net https://ct.pinterest.com https://try.abtasty.com https://teddytor.abtasty.com https://pixel.rubiconproject.com/tap.php https://ad.avtm.fr https://ariane.abtasty.com https://dcinfos-cache.abtasty.com https://connect.facebook.net https://www.facebook.com https://api2.abtasty.com https://api.abtasty.com https://o132438.ingest.sentry.io https://common-fonts.abtasty.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com https://widgets-images.abtasty.com https://editor-assets.abtasty.com https://sslwidget.criteo.com https://www.criteo.net https://www.criteo.com https://measurement-api.criteo.com https://googleads.g.doubleclick.net https://*.outbrain.com https://*.contentsquare.net https://app.contentsquare.com https://online.flippingbook.com https://k-eu1.az.contentsquare.net https://*.elfsight.com https://jeu.flunch.fr https://applepay.cdn-apple.com https://static.payzen.eu/static/ *.googleapis.com *.gstatic.com unsafe-inline assets.braintreegateway.com static.critizr.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://metrics.flunch-traiteur.fr https://sk.ht https://dynamic.criteo.com https://tracking.lqm.io https://s.yimg.com https://snap.licdn.com https://s.pinimg.com https://insight.adsrvr.org https://cdn.linkedin.oribi.io https://pixel.bsmartdata.com https://track.adform.net https://ct.pinterest.com https://try.abtasty.com https://teddytor.abtasty.com https://pixel.rubiconproject.com/tap.php https://ad.avtm.fr https://ariane.abtasty.com https://dcinfos-cache.abtasty.com https://connect.facebook.net https://www.facebook.com https://api2.abtasty.com https://api.abtasty.com https://o132438.ingest.sentry.io https://common-fonts.abtasty.com https://widgets-images.abtasty.com https://editor-assets.abtasty.com https://sslwidget.criteo.com https://www.criteo.net https://www.criteo.com https://measurement-api.criteo.com https://googleads.g.doubleclick.net https://*.outbrain.com https://*.contentsquare.net https://app.contentsquare.com https://online.flippingbook.com https://k-eu1.az.contentsquare.net https://*.elfsight.com https://jeu.flunch.fr https://applepay.cdn-apple.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com maps.google.com client.axept.io ekr.zdassets.com t.elasticsuite.io data: *.axept.io *.addthis.com axeptio.imgix.net *.newrelic.com *.nr-data.net *.moatads.com *.addthisedge.com *.matomo.cloud 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net https://static.lyra.com/static/ *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.modehaus.dev data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cleverreach.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ fklingenthal.jobbase.io *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.com *.googleapis.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.googletagmanager.com *.klarna.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ snapwidget.com secure.pay1.de *.hotjar.com *.modehaus.dev *.page2flip.de fklingenthal.jobbase.io fklingenthal.onlyfy.jobs c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.cloudfront.net https://*.etracker.com https://*.etracker.de https://www.magezon.com *.googleadservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ flagpedia.net s3.eu-central-1.amazonaws.com my.page2flip.de app.klingenthal.modehaus.de api.region-bayreuth.de scontent-ham3-1.cdninstagram.com fklingenthal.jobbase.io www.etracker.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://*.etracker.com https://*.etracker.de connect.facebook.net *.googleadservices.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://api.lyra.com/api-payment/ https://static.lyra.com/static/ maps.googleapis.com *.modehaus.de *.modehaus2.de *.klingenthal.de *.etracker.com *.etracker.de snapwidget.com *.widgetwhats.com *.hotjar.com www.etracker.de *.modehaus.dev *.page2flip.de fklingenthal.jobbase.io fklingenthal.onlyfy.jobs api.signalize.com *.hotjar.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net https://static.lyra.com/static/ *.fontawesome.com *.google.com maxcdn.bootstrapcdn.com *.widgetwhats.com *.bootstrapcdn.com *.modehaus.dev fklingenthal.jobbase.io assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com widget.freshworks.com m2epro.freshdesk.com https://*.etracker.de *.googletagmanager.com stats.g.doubleclick.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.gstatic.com maps.googleapis.com *.modehaus.de *.klingenthal.de *.widgetwhats.com *.hotjar.com *.modehaus.dev *.page2flip.de fklingenthal.jobbase.io www.etracker.de wss://*.hotjar.com *.hotjar.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com *.alothemes.com *.magepow.com *.cloudflare.com *.bootstrapcdn.com 'unsafe-inline' data: *.aptrinsic.com amcglobal.sc.omtrdc.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.aptrinsic.com amcglobal.sc.omtrdc.net *.sdiapi.com *.sdiapi.net zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.cloudflare.com *.selby.com.au *.facebook.com *.hifishow.com *.stereonet.show *.aptrinsic.com t.zip.co static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com s7.addthis.com *.alothemes.com *.magepow.com *.cloudflare.com *.twitter.com *.fontawesome.com *.zipmoney.com.au *.googletagmanager.com *.facebook.net *.trackedweb.net *.trackedlink.net *.aptrinsic.com *.zip.co *.sdiapi.com *.sdiapi.net static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.alothemes.com *.magepow.com *.cloudflare.com *.bootstrapcdn.com *.aptrinsic.com amcglobal.sc.omtrdc.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com ekr.zdassets.com/ *.alothemes.com *.magepow.com *.cloudflare.com *.doubleclick.net *.zipmoney.com.au *.trackedweb.net *.zip.co *.aptrinsic.com *.sdiapi.com *.sdiapi.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-uZB2emIsOc54f7zTMunHTQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; frame-src 'self' *; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://files1.vinci-immobilier.com https://files6.vinci-immobilier.com https://www.vinci-immobilier.com https://files3.vinci-immobilier.com https://files2.vinci-immobilier.com; style-src 'self' 'unsafe-inline' *; img-src 'self' data: *; font-src 'self' *; connect-src 'self' https://files1.vinci-immobilier.com https://files6.vinci-immobilier.com https://files3.vinci-immobilier.com https://files2.vinci-immobilier.com https://www.vinci-immobilier.com https://www.vinci-immobilier.com/api/offres https://www.vinci-immobilier.com/api/v4 https://www.vinci-immobilier.com/api/profils https://www.vinci-immobilier.com/api/geo https://www.vinci-immobilier.com/api/marketing https://www.vinci-immobilier.com/api/simulateur 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-BbjaJXPvV8ZxPozYrxRtKHpb4O7N3exh'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 default-src 'self' *.noonpayments.com www.noonpayments.com *.noonpayments.io https://c.go-mpulse.net www.noonpayments.com https://www.noonpayments.com smtpjs.com maxcdn.bootstrapcdn.com; img-src 'self' backend.chatbase.co https://cdnjs.cloudflare.com data:; style-src-elem *;media-src 'self'; frame-src 'self' *.noonpayments.com www.chatbase.co *.statuspage.io https://www.google.com; base-uri 'self'; script-src 'self' *.google-analytics.com www.chatbase.co smtpjs.com https://s.go-mpulse.net www.googletagmanager.com https://www.gstatic.com https://c.go-mpulse.net https://www.google.com/recaptcha/api.js www.googletagmanager.com *.googletagmanager.com *.noonpayments.com *.statuspage.io; style-src-attr *; font-src 'self' data: https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com; style-src 'self' https://www.noonpayments.com *.noonpayments.com *.noonpayments.io https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com; connect-src 'self' *.akstat.io *.google-analytics.com www.chatbase.co https://crm.zoho.com/crm/WebToLeadForm https://c.go-mpulse.net *.akamaihd.net https://www.google-analytics.com https://maxcdn.bootstrapcdn.com; worker-src 'self' blob:; report-uri https://noonpayments.report-uri.com/r/d/csp/reportOnly; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com https://www.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.sirv.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sirv.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.sirv.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.bird.eu cdn.doofinder.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sirv.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.doofinder.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googleapis.com *.twimg.com https://www.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.sirv.com *.axept.io *.doofinder.com *.avada.io https://www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com *.sirv.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doofinder.com wss://*.doofinder.com *.cloudflare.com *.twitter.com *.twimg.com *.sirv.com *.google-analytics.com *.googleapis.com *.axept.io https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://www.googletagmanager.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.authorize.net *.syfpos.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.authorize.net syf.demdex.net *.syfpos.com *.syf.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.bing.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com store.paradoxlabs.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.authorize.net *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com *.syfpos.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com https://www.google-analytics.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ *.authorize.net *.syfpos.com *.syf.com *.d1.sc.omtrdc.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com fonts.googleapis.com assets.ottu.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com sandbox.ottu.net sandbox.ottu.dev assets.ottu.net pay.muscatdutyfree.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com landofcoder.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net assets.ottu.net assets.ottu.dev 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.addtoany.com assets.ottu.net assets.ottu.dev 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com landofcoder.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog http://dpm.demdex.net sentry.ottu.net sdkstudio.ottu.dev sdkstudio.ottu.net sandbox.ottu.dev sandbox.ottu.net pay.muscatdutyfree.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.zmags.com *.zma.gs *.force.com *.userway.org *.fatwin.com *.salesforceliveagent.com *.klaviyo.com *.powerreviews.com *.scene7.com *.cloudflare.com script.crazyegg.com images.getfastr.com js.adsrvr.org stats.g.doubleclick.net googleads.g.doubleclick.net google.co.in *.cloudfront.net *.jquery.com *.cloudinary.com *.magentosite.cloud *.starfurniture.com *.videohub.tv *.bing.com *.google.ro *.bootstrapcdn.com *.onetrust.com blog.starfurniture.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com blog.starfurniture.com 'self' 'unsafe-inline'; frame-ancestors blog.starfurniture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.affirm.com *.affirm.ca *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * https://plumrocket.com blog.starfurniture.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.affirm.com *.affirm.ca www.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.zmags.com *.zma.gs *.force.com *.userway.org *.fatwin.com *.salesforceliveagent.com *.klaviyo.com *.powerreviews.com *.scene7.com *.cloudflare.com script.crazyegg.com images.getfastr.com js.adsrvr.org stats.g.doubleclick.net *.google.co.in *.cloudfront.net *.jquery.com *.cloudinary.com *.adobetm.com *.magentosite.cloud *.starfurniture.com *.videohub.tv *.bing.com *.google.ro turn.com r.turn.com *.facebook.com *.facebook.net facebook.com facebook.net *.turn.com *.cookielaw.org *.wixmp.com *.onetrust.com *.unbxdapi.com *.clarity.ms blog.starfurniture.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.vimeo.com safevisit.online aa.agkn.com *.rkdms.com *.liadm.com *.zmags.com o.clarity.ms *.clarity.ms clarity.ms *.zma.gs *.force.com *.userway.org *.fatwin.com *.salesforceliveagent.com *.klaviyo.com *.powerreviews.com *.scene7.com *.cloudflare.com script.crazyegg.com images.getfastr.com js.adsrvr.org stats.g.doubleclick.net google.co.in *.cloudfront.net *.jquery.com *.cloudinary.com *.adobetm.com adobetm.com assets.adobetm.com *.magentosite.cloud *.starfurniture.com *.videohub.tv *.bing.com facebook.com *.facebook.com *.visiblevisitor.net cdn.visiblevisitor.net overflowworks.com *.overflowworks.com turn.com r.turn.com *.turn.com visiblevisitor.net connect.facebook.com *.facebook.net connect.facebook.net salesforce.com *.salesforce.com my.salesforce.com starfurniture.my.salesforce.com salesforce-sites.com *.salesforce-sites.com my.salesforce-sites.com starfurniture.my.salesforce-sites.com *.google.ro *.cookielaw.org *.unbxdapi.com *.onetrust.com *.safevisit.online *.unbxd.io blog.starfurniture.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com *.zmags.com *.zma.gs *.force.com *.userway.org *.fatwin.com *.salesforceliveagent.com *.klaviyo.com *.powerreviews.com *.scene7.com *.cloudflare.com *.googleapis.com script.crazyegg.com images.getfastr.com js.adsrvr.org stats.g.doubleclick.net googleads.g.doubleclick.net google.co.in *.cloudfront.net *.jquery.com *.cloudinary.com *.magentosite.cloud *.starfurniture.com *.videohub.tv *.bing.com *.google.ro typekit.net *.typekit.net p.typekit.net salesforce.com *.salesforce.com my.salesforce.com starfurniture.my.salesforce.com salesforce-sites.com *.salesforce-sites.com my.salesforce-sites.com starfurniture.my.salesforce-sites.com use.typekit.net *.cookielaw.org *.bootstrapcdn.com *.onetrust.com *.safevisit.online *.unbxdapi.com blog.starfurniture.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blog.starfurniture.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.zmags.com *.zma.gs *.force.com *.userway.org *.fatwin.com *.salesforceliveagent.com *.klaviyo.com *.powerreviews.com *.scene7.com *.cloudflare.com script.crazyegg.com images.getfastr.com js.adsrvr.org stats.g.doubleclick.net googleads.g.doubleclick.net google.co.in *.cloudfront.net *.jquery.com *.cloudinary.com o.clarity.ms *.clarity.ms clarity.ms *.demdex.net *.omtrdc.net *.magentosite.cloud *.starfurniture.com *.videohub.tv *.bing.com *.google.ro *.visiblevisitor.net cdn.visiblevisitor.net google-analytics.com *.google-analytics.com salesforce.com *.salesforce.com my.salesforce.com starfurniture.my.salesforce.com salesforce-sites.com *.salesforce-sites.com my.salesforce-sites.com starfurniture.my.salesforce-sites.com region1.google-analytics.com *.cookielaw.org *.onetrust.com *.unbxdapi.com *.safevisit.online *.unbxd.io *.liadm.com blog.starfurniture.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blog.starfurniture.com http: https: blob: 'self' 'unsafe-inline'; default-src blog.starfurniture.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: 'unsafe-inline' data: 'unsafe-eval'; report-uri https://servix.idnes.cz/log/csp-report.aspx?w=labuznik 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com *.fontawesome.com https://attachments-ldn.imiengage.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ * account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com js.stripe.com *.hotjar.com https://attachments-ldn.imiengage.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net * https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com bat.bing.com *.google.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk *.stephensons.com *.feefo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com connect.facebook.net js-agent.newrelic.com bam.nr-data.net *.google-analytics.com *.googleapis.com googletagmanager.com googleadservices.com *.feefo.com *.cloudflare.com *.zdassets.com https://attachments-ldn.imiengage.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cash.app cc-cdn.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com services.postcodeanywhere.co.uk *.typekit.net *.cloudflare.com *.feefo.com https://attachments-ldn.imiengage.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net * api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://attachments-ldn.imiengage.io https://ekr.zdassets.com *.feefo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' api.addressfinder.io *.google-analytics.com *.googletagmanager.com *.ytimg.com *.youtube.com; script-src-elem 'self' 'unsafe-inline' api.addressfinder.io *.gstatic.com *.google-analytics.com *.googletagmanager.com *.google.com; style-src 'report-sample' 'self' 'unsafe-inline' api.addressfinder.io *.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.google.com *.google.com.au *.google.co.nz *.doubleclick.net *.googletagmanager.com *.google-analytics.com translate.googleapis.com; font-src 'self' fonts.gstatic.com; child-src 'self' *.lawsociety.org.nz *.googletagmanager.com youtube.com *.youtube.com player.vimeo.com staticcdn.co.nz; frame-ancestors 'self'; frame-src 'self' *.youtube.com w.soundcloud.com www.google.com maps.google.co.nz; img-src 'self' *.google.com *.google.co.nz *.google.com.au *.ggpht.com data: *.google-analytics.com *.google.com *.google.com.au *.googletagmanager.com *.gstatic.com *.ytimg.com *.vimeocdn.com staticcdn.co.nz; manifest-src 'self'; media-src 'self'; report-uri https://report-to-api.raygun.com/reports-csp?apikey=GMMydwcssVrny9itMp4jA; worker-src 'none'; 1 font-src 'unsafe-inline' data: *.klarnacdn.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.klarna.com www.xtento.com challenges.cloudflare.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.google.com *.google.co.uk *.klarna.com *.klarnaevt.com *.klarnacdn.net www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://images.unsplash.com https://maps.gstatic.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google-analytics.com *.analytics.google.com *.klarna.com *.klarnacdn.net www.xtento.com cdn.xtento.com challenges.cloudflare.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarnaservices.com s7.addthis.com https://maps.googleapis.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com cc-cdn.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net *.klarnaevt.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnacdn.net *.klarna.com *.klarnaservices.com ekr.zdassets.com/ https://maps.googleapis.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com fonts.googleapis.com *.hotjar.com *.zopim.com data: *.googleapis.com cdn.jsdelivr.net *.tawk.to *.fullstory.com js-agent.newrelic.com bam.nr-data.net *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net https://fonts.bunny.net *.cm.com *.hypernode.io *.cookiebot.com https://widgets.trustedshops.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; frame-ancestors www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.doubleclick.net *.facebook.com *.googlesyndication.com cdn.dnky.co *.hotjar.com/ *.trustpilot.com *.criteo.com *.google.com/recaptcha/ *.addwish.com/ *.helloretail.com *.fullstory.com js-agent.newrelic.com bam.nr-data.net *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net *.etrusted.com *.cookiebot.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://d1pna5l3xsntoj.cloudfront.test https://helloretailcdn.test *.adyen.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com imgsct.cookiebot.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.linkedin.com gallery.mailchimp.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.google-analytics.com *.tawk.to tawk.link *.cloudfront.net *.yotpo.com *.fullstory.com js-agent.newrelic.com bam.nr-data.net *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net https://firebasestorage.googleapis.com *.hypernode.io *.etrusted.com *.cookiebot.com *.bing.net *.bing.com *.merkala.nl *.taggrs.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.ie www.google.com.pe www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://core.helloretail.test https://d1pna5l3xsntoj.cloudfront.test https://helloretailcdn.test *.adyen.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com consent.cookiebot.com *.paypal.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.feedbackcompany.com *.trustpilot.com js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com *.google.com/recaptcha/ *.tawk.to *.addwish.com/scripts/ *.helloretail.com *.cloudfront.net *.fullstory.com *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net *.avada.io *.shopify.com *.digitalcx.com *.hypernode.io *.etrusted.com *.cookiebot.com *.bing.com *.copernica.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://d1pna5l3xsntoj.cloudfront.test https://helloretailcdn.test *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com cdn.dnky.co checkout.buckaroo.nl *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net *.tawk.to *.cloudfront.net *.fullstory.com js-agent.newrelic.com bam.nr-data.net *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net https://fonts.bunny.net *.hypernode.io *.trustedshops.com *.etrusted.com *.cookiebot.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com assets.braintreegateway.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; object-src www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; manifest-src www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com https://core.helloretail.test https://helloretailcdn.test *.adyen.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com bam.nr-data.net *.clarity.ms *.datatrics.com *.tawk.to 'self' ws: 'self' wss: *.addwish.com/ *.helloretail.com *.cloudfront.net *.fullstory.com js-agent.newrelic.com *.robinhq.com *.robincontentdesktop.blob.core.windows.net *.cxcomlive-webconvwebchatwa-weu.azurewebsites.net https://get.geojs.io *.avada.io *.hypernode.io *.cookiebot.com *.bing.net *.bing.com *.copernica.com *.merkala.nl *.trustedshops.com *.etrusted.com https://integrations.etrusted.site api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be http: https: blob: 'self' 'unsafe-inline'; default-src www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.merkala.nl cdn.merkala.nl www.merkala.de www.merkala.be cdn.merkala.be 'self' 'unsafe-inline'; report-uri /csp_reporter.php; report-to report-endpoint; 1 default-src 'self'; connect-src 'self' www.facebook.com stats.g.doubleclick.net *.oribi.io www.google-analytics.com csp.withgoogle.com cdn.jsdelivr.net data:; frame-src 'self' 52.186.34.239 www.facebook.com *.aquawater.com *.youtube.com *.google.com www.googletagmanager.com; img-src 'self' www.linkedin.com t.co analytics.twitter.com www.google-analytics.com px.ads.linkedin.com www.facebook.com i.ytimg.com *.google.com www.googleapis.com *.gstatic.com *.aquaamerica.com data:; script-src 'self' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' snap.licdn.com connect.facebook.net *.googletagmanager.com code.jquery.com *.google.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; script-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; script-src-elem 'self' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'unsafe-hashes' 'unsafe-inline' hello.myfonts.net www.google.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.yotpo.com *.googleapis.com 'self' data: https://staticw2.yotpo.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com https://accounts.google.com https://www.facebook.com https://login.live.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://static.addtoany.com/ *.yotpo.com https://commerce.adobedc.net/ https://googletagmanager.com/ https://us.creativecdn.com/ https://vars.hotjar.com/ https://gum.criteo.com/ https://targeting.voxus.tv/ https://ct.pinterest.com/ https://static.criteo.net/ *.clearsale.com.br https://tatu.virtualjoias.com/ https://www.facebook.com/ https://analytics.twitter.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.disqus.com https://img.youtube.com *.yotpo.com *.hsforms.net *.hsforms.com 'self' data: www.google.com.ua *.virtualjoias.com/* https://virtualjoias.com https://p.yotpo.com/ https://ct.pinterest.com/ https://secure.adnxs.com/ https://s3.amazonaws.com/ https://cdn-yotpo-images-production.yotpo.com/ https://staticw2.yotpo.com/ https://cfvod.kaltura.com/ www.google.com.br *.clearsale.com.br https://www.facebook.com/ https://analytics.twitter.com/ https://t.co/ https://c.clarity.ms/ https://cm.g.doubleclick.net/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://sync-t1.taboola.com/ https://visitor.omnitagjs.com/ https://r.casalemedia.com/ https://gum.criteo.com/ https://ad.360yield.com/ https://contextual.media.net/ https://exchange.mediavine.com/ https://c.bing.com/ https://jadserve.postrelease.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://trends.revcontent.com/ https://pixel.rubiconproject.com/ https://match.sharethrough.com/ https://s.ad.smaato.net/ https://criteo-sync.teads.tv/ https://criteo-partners.tremorhub.com/ https://ade.clmbtech.com/ https://eb2.3lift.com/ https://sync-criteo.ads.yieldmo.com/ https://e1.emxdgt.com/ https://dis.criteo.com/ https://sync.1rx.io/ https://ads.stickyadstv.com/ https://rtb-csync.smartadserver.com/ https://i.liadm.com/ https://sync.targeting.unrulymedia.com/ https://cm.adgrx.com/ https://bat.bing.com/ https://tatu.virtualjoias.com/ https://user-sync.fwmrm.net/ https://aa.agkn.com/ https://public-prod-dspcookiematching.dmxleo.com/ https://load.tatu.virtualjoias.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://static.addtoany.com/ *.disqus.com *.yotpo.com *.pagseguro.com.br *.pagseguro.com *.hsforms.net *.hsforms.com *.gstatic.com https://commerce.adobedc.net/ https://www.googletagmanager.com/ https://js-agent.newrelic.com/ https://static.zdassets.com/ https://ekr.zdassets.com/ wss://virtualjoias.zendesk.com/ https://*.zopim.com/ wss://*.zopim.com/ *.googleapis.com https://*.hotjar.com/ https://staticw2.yotpo.com/ https://www.dwin1.com/ https://s.pinimg.com/ https://cdn.targeting.voxus.com.br/ https://connect.facebook.net/ https://www.facebook.com/ https://analytics.twitter.com/ https://dynamic.criteo.com/ https://static.criteo.net/ https://googleads.g.doubleclick.net/ https://js.sddan.com/ https://aprtn.com/ https://www.rtb123.com/ https://vu.adschoom.com/ https://admaxium.com/ https://ca.enviou.com.br/ https://targeting.voxus.com.br/ https://files1.cybba.solutions/virtualjoias.com/ advcake.dataroyal.com.br https://s3.amazonaws.com/ https://cdnapisec.kaltura.com/ tag.goadopt.io static.ads-twitter.com analytics.tiktok.com n.clarity.ms https://www.clarity.com/ https://www.clarity.ms/ https://sslwidget.criteo.com/ https://ct.pinterest.com/ *.clearsale.com.br https://rum.hlx.page/ https://d335luupugsy2.cloudfront.net/ https://bat.bing.com/ https://scripts.clarity.ms/ https://assets.adobedtm.com/ https://commerce.adobedtm.com/ https://js.magento-datasolutions.com/ https://unpkg.com/@adobe/ https://cdn.jsdelivr.net/npm/@adobe/ https://load.tatu.virtualjoias.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.yotpo.com *.googleapis.com *.gstatic.com https://staticw2.yotpo.com/ https://s3.amazonaws.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/ https://us.creativecdn.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://stats.addtoany.com/menu *.yotpo.com *.pagseguro.com.br *.pagseguro.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://google-analytics.com/ https://commerce.adobedc.net/ https://js-agent.newrelic.com/ https://static.zdassets.com/ https://ekr.zdassets.com/ https://virtualjoias.zendesk.com/ wss://*.zopim.com/ wss://virtualjoias.zendesk.com/ *.nr-data.net/ https://staticw2.yotpo.com/ https://in.hotjar.com/ https://ct.pinterest.com/ https://www.google-analytics.com/ wss://ws2.hotjar.com/ https://targeting.voxus.com.br/ https://api.ipify.org/ *.mercadopago.com https://iosite.reclameaqui.com.br/ api.reclameaqui.com.br analytics.tiktok.com https://v.clarity.ms/ https://analytics.pangle-ads.com/ https://stats.g.doubleclick.net/ *.clearsale.com.br https://www.google.com/ https://w.clarity.ms/ https://disclaimer-api.goadopt.io/ https://d335luupugsy2.cloudfront.net/ https://commerce-int.adobe.io/ https://commerce.adobe.io/ https://dpm.demdex.net/ *.snplow.net/ https://pageview-notify.rdstation.com.br/ https://popups.rdstation.com.br/ https://louren.co.in/ https://i.clarity.ms/ https://analytics-ipv6.tiktokw.us/ https://measurement-api.criteo.com/ https://tatu.virtualjoias.com/g/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://www.facebook.com/ https://analytics.twitter.com/ https://load.tatu.virtualjoias.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com guarantee-cdn.com *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.facebook.com/tr/ cdn.cookielaw.org static.zdassets.com ekr.zdassets.com *.zendesk.com assets.zendesk.com www.google-analytics.com widget-mediator.zopim.com js-agent.newrelic.com bam.nr-data.net maps.gstatic.com maps.googleapis.com www.google.com www.google.es *.hotjar.com *.criteo.com *.criteo.net *.onetrust.com stats.g.doubleclick.net www.googleoptimize.com www.youtube.com www.youtube-nocookie.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.cookielaw.org static.zdassets.com ekr.zdassets.com *.zendesk.com assets.zendesk.com wss://widget-mediator.zopim.com js-agent.newrelic.com bam.nr-data.net maps.gstatic.com maps.googleapis.com www.facebook.com/tr/ www.google.es *.hotjar.com *.criteo.com *.criteo.net *.onetrust.com stats.g.doubleclick.net privacyportal-de.onetrust.com https://www.googletagmanager.com ad.doubleclick.net insight.adsrvr.org 20836339p.rfihub.com www.googleoptimize.com img.youtube.com ade.googlesyndication.com p1.zemanta.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de https://images.unsplash.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com commerce.adobedtm.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.facebook.com/tr/ cdn.cookielaw.org static.zdassets.com ekr.zdassets.com *.zendesk.com assets.zendesk.com widget-mediator.zopim.com js-agent.newrelic.com bam.nr-data.net maps.gstatic.com maps.googleapis.com s.retargeted.co www.google.com www.google.es *.hotjar.com *.criteo.com *.criteo.net stats.g.doubleclick.net www.gstatic.com *.onetrust.com www.clarity.ms bucket.cdnwebcloud.com cdn.taboola.com e.clarity.ms www.dwin1.com/ www.googleoptimize.com js-tag.zemanta.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.facebook.com/tr/ cdn.cookielaw.org static.zdassets.com ekr.zdassets.com *.zendesk.com assets.zendesk.com www.google-analytics.com widget-mediator.zopim.com js-agent.newrelic.com bam.nr-data.net maps.gstatic.com maps.googleapis.com connect.facebook.net www.google.com www.google.es *.hotjar.com *.criteo.com *.criteo.net *.onetrust.com stats.g.doubleclick.net www.googleoptimize.com www.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com commerce.adobedtm.com commerce.adobedc.net *.snplow.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.facebook.com/tr/ cdn.cookielaw.org static.zdassets.com ekr.zdassets.com *.zendesk.com assets.zendesk.com widget-mediator.zopim.com wss://widget-mediator.zopim.com js-agent.newrelic.com bam.nr-data.net maps.gstatic.com maps.googleapis.com www.google.com www.google.es *.hotjar.com wss://*.hotjar.com *.criteo.com *.criteo.net stats.g.doubleclick.net *.onetrust.com pagead2.googlesyndication.com trc.taboola.com e.clarity.ms trc-events.taboola.com www.googleoptimize.com region1.google-analytics.com smart-widget-assets.ekomiapps.de https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.stape.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.stape.io flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdnjs.cloudflare.com payment www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.googleapis.com *.googletagmanager.com *.stape.io *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com intent://payment 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.amazonaws.com *.google.co.in *.fondriest.com https://cdn-cookieyes.com https://s3.us-east-2.amazonaws.com *.googleapis.com *.g.doubleclick.net fondriest-web.s3.amazonaws.com fondriest.com fishsens.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflareinsights.com https://cdn-cookieyes.com https://static.cloudflareinsights.com https://s3.us-east-2.amazonaws.com *.googleapis.com *.g.doubleclick.net cdn.jsdelivr.net demo.convergepay.com www.convergepay.com *.gstatic.com *.avada.io *.shopify.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cookieyes.com https://cdn-cookieyes.com *.google.co.in https://s3.us-east-2.amazonaws.com *.googleapis.com *.g.doubleclick.net cdn.jsdelivr.net fonts.gstatic.com *.fontawesome.com *.google.com *.gstatic.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com fondriest-web.s3.amazonaws.com fondriest.com fishsens.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cookieyes.com https://cdn-cookieyes.com *.google.co.in https://s3.us-east-2.amazonaws.com *.googleapis.com *.g.doubleclick.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com fonts.googleapis.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.criteo.com *.criteo.net *.hotjar.com *.google.com *.google.co.in *.github.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.google.com *.google.co.in magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.google-analytics.com *.google.com *.google.co.in *.googletagmanager.com *.gstatic.com *.hotjar.com *.criteo.com *.criteo.net *.github.io *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com fonts.googleapis.com fast.fonts.net *.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.googletagmanager.com *.cloudflare.com *.paypal.com *.doubleclick.net *.hotjar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-ji0SfrHBB1MLZwZR0JUiTQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://m.stripe.network https://analytics.energynews.pro https://assets.apollo.io https://static.cloudflareinsights.com https://pay.google.com https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://www.googletagservices.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://challenges.cloudflare.com; connect-src 'self' https://api.stripe.com https://m.stripe.com https://m.stripe.network https://hooks.stripe.com https://q.stripe.com https://analytics.energynews.pro https://*.apollo.io https://static.cloudflareinsights.com https://pay.google.com https://maps.googleapis.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google-analytics.com https://www.googletagmanager.com; img-src 'self' data: blob: https://*.stripe.com https://m.stripe.network https://q.stripe.com https://analytics.energynews.pro https://*.doubleclick.net https://*.googlesyndication.com https://i.ytimg.com https://maps.gstatic.com https://www.google.com https://www.gstatic.com https://s.w.org https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://*.stripe.com https://fonts.googleapis.com; frame-src https://js.stripe.com https://checkout.stripe.com https://hooks.stripe.com https://pay.google.com https://www.youtube.com https://player.vimeo.com https://www.google.com https://challenges.cloudflare.com https://billing.stripe.com; font-src 'self' data: https://fonts.gstatic.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; report-uri https://energynews.pro/wp-json/en-csp/v1/report; report-to csp-endpoint 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.kxcdn.com *.fontawesome.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * checkout.tabby.ai 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.fbcdn.net www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.googletagmanager.com ssl.gstatic.com *.google.co.in data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com tagmanager.google.com ssl.google-analytics.com load.gtm.techntoys.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com thm.visa.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.analytics.google.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net load.gtm.techntoys.com https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: fonts.gstatic.com *.yotpo.com *.googleapis.com *.klaviyo.com allamericanswim.com *.wistia.com *.cloudflare.com *.typekit.net *.alicdn.com s3.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudfront.net *.hubspot.com yotpo-editor-production.s3.amazonaws.com thelifeguardstore.com app.webfx.com kiefer.com placehold.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com maps.googleapis.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net *.wistia.com *.marketingcloudfx.com *.kiefer.com *.google.com allamericanswim.com d3k81ch9hvuctc.cloudfront.net *.arenasport.com *.signifyd.com s3.amazonaws.com *.googleapis.com *.googleadservices.com *.hscollectedforms.net *.wistia.net google.com tyr.com *.tyr.com *.cloudflare.com *.certcapture.com *.paypalobjects.com *.doubleclick.net theswimteamstore.net *.bing.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudfront.net globalshopex.com js.hs-scripts.com js.hs-banner.com js.hscollectedforms.net js.hs-analytics.net acsbapp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com maps.googleapis.com *.googletagmanager.com *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net *.sentry-cdn.com *.wistia.com *.cloudflareinsights.com *.crazyegg.com *.certcapture.com s3.amazonaws.com *.googleapis.com *.klaviyo.com *.wistia.net *.cloudflare.com *.signifyd.com *.hs-scripts.com allamericanswim.com *.doubleclick.net *.hs-banner.com *.hs-analytics.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.cloudfront.net static-tracking.klaviyo.com *.fontawesome.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com fonts.googleapis.com tagmanager.google.com fonts.google.com *.yotpo.com *.typekit.net *.certcapture.com *.klaviyo.com *.cloudflare.com allamericanswim.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.bing.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.acsbapp.com *.doubleclick.net forms.hscollectedforms.net settings.luckyorange.net wss://visitors.live wss://in.visitors.live https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://www.google-analytics.com *.analytics.google.com *.googletagmanager.com *.yotpo.com https://imgs.signifyd.com *.googleadservices.com *.sentry.io *.crazyegg.com *.browser-intake-us5-datadoghq.com sentry.io *.wistia.com *.klaviyo.com *.acsbapp.com *.luckyorange.net *.certcapture.com *.datadome.co yotpo.com d3k81ch9hvuctc.cloudfront.net *.signifyd.com acsbapp.com kg668dbov0.execute-api.us-east-1.amazonaws.com *.googleapis.com *.kiefer.com thelifeguardstore.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://7e98474e-5de7-4054-99d8-67792cfeaa79.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com; img-src 'self' data: https://www.google-analytics.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; 1 font-src fonts.gstatic.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.youtube.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.rs www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.tawk.to data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com tagmanager.google.com https://www.googletagmanager.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.adform.net *.jsdelivr.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.tawk.to 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com unsafe-inline assets.braintreegateway.com *.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.ampproject.org https://www.google-analytics.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.tawk.to wss://vsa120.tawk.to www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://widgets.trustedshops.com www.vedder-vedder.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.vedder-vedder.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com *.cookiebot.com *.weltpixel.com *.doubleclick.net *.pinterest.com *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com https://www.mollie.com www.magmodules.eu *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.vedder-vedder.com dev.visualwebsiteoptimizer.com interface.mailcampaigns.nl *.cloudfront.net www.google.nl www.facebook.com integrations.etrusted.com robincontentdesktop.blob.core.windows.net imgsct.cookiebot.com t.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.mollie.com https://widget-acc.paazl.com https://api-acc.paazl.com/ squeezely.tech www.squeezely.tech *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com widget.paazl.com connect.facebook.net integrations.etrusted.com vedderveddernl.api.useinsider.com dev.visualwebsiteoptimizer.com interface.mailcampaigns.nl consentcdn.cookiebot.com az416426.vo.msecnd.net selfservice.robinhq.com www.vedder-vedder.com ct.pinterest.com js-agent.newrelic.com snapppt.com app.addsauce.com s.pinimg.com robincontentdesktop.blob.core.windows.net static.hotjar.com www.gstatic.com script.hotjar.com widgets.trustedshops.com consent.cookiebot.com www.google.com analytics.tiktok.com admin.revenuehunt.com *.cloudfront.net *.webpages.one https://www.googletagmanager.com tagmanager.google.com sst.vedder-vedder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://widget-acc.paazl.com https://api-acc.paazl.com/ https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com widget.paazl.com www.gstatic.com www.vedder-vedder.com interface.mailcampaigns.nl integrations.etrusted.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.vedder-vedder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://widget-acc.paazl.com https://api-acc.paazl.com/ squeezely.tech *.squeezely.tech *.trustedshops.com *.etrusted.com https://integrations.etrusted.site api.paazl.com *.tiktok.com *.googlesyndication.com *.visualstudio.com *.google-analytics.com https://www.google-analytics.com *.doubleclick.net *.pinterest.com *.cookiebot.com *.facebook.com interface.mailcampaigns.nl 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src td.doubleclick.net region1.google-analytics.com googleads.g.doubleclick.net bam.eu01.nr-data.net google.com ct.pinterest.com region1.analytics.google.com consentcdn.cookiebot.com api.paazl.com www.google.com dc.services.visualstudio.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.google.com *.googleapis.com *.fontawesome.com https://cdnjs.cloudflare.com applepay.cdn-apple.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.payplug.com *.dalenys.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net cl.avis-verifies.com www.facebook.com *.container.webgains.link 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.google.fr *.imgix.net cl.avis-verifies.com *.jeujouet.com cdn.doofinder.com https://secure-magenta.dalenys.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com *.google.es *.cloudfront.net aqpxrwhfpr.cloudimg.io connect.facebook.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.jeujouet.com stats.g.doubleclick.net *.google.fr pagead2.googlesyndication.com *.googletagmanager.com *.google-analytics.com *.axept.io connect.facebook.net s.pinimg.com *.pinterest.com analytics.webgains.io apicit.net ai.trk42.net *.container.webgains.link *.imgix.net https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ cdn.doofinder.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.hsforms.net *.hsforms.com *.gstatic.com https://static-sb.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net cdn.dsspn.com static-sb.com api.hrznads.com p.gsitrix.com sdk-set1.com ad.ad-srv.net hal9000.redintelligence.net scripts.clarity.ms www.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.google.com *.fontawesome.com *.doofinder.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com *.googleapis.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com fonts.googleapis.com *.jeujouet.com stats.g.doubleclick.net *.google.fr pagead2.googlesyndication.com *.googletagmanager.com *.axept.io static.axept.io connect.facebook.net s.pinimg.com *.pinterest.com analytics.webgains.io apicit.net ai.trk42.net *.container.webgains.link *.imgix.net *.doubleclick.net https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.doofinder.com wss://*.doofinder.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app api.webgains.io www.facebook.com social-sb.com z.clarity.ms 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://943e93353491f27f34913adf2bf03a92.report-uri.com/r/d/csp/reportOnly; 1 font-src https://cdn.riverty.design/ *.tawk.to fonts.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action uc8.tv *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ uc8.tv https://documents.riverty.com/ td.doubleclick.net https://*.dpdconnect.nl *.tawk.to *.weltpixel.com *.addthis.com *.multisafepay.com https://pay.google.com plausible.io 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ www.weidswonenenslapen.nl www.google.nl www.facebook.com region1.analytics.google.com https://images.unsplash.com *.tawk.to cdn.jsdelivr.net *.gstatic.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ analytics.amitix.nl static.hotjar.com script.hotjar.com widget.trustpilot.com platform.getqonfi.com ct.beslist.nl connect.facebook.net https://*.dpdconnect.nl *.tawk.to cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io *.multisafepay.com https://pay.google.com https://cdnjs.cloudflare.com plausible.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.tawk.to fonts.googleapis.com cdn.jsdelivr.net tagmanager.google.com https://cdn.jsdelivr.net *.fontawesome.com *.multisafepay.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ analytics.amitix.nl www.google.com googleads.g.doubleclick.net region1.analytics.google.com ct.beslist.nl *.tawk.to wss://*.tawk.to https://www.google-analytics.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.multisafepay.com plausible.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ; script-src 'self' 'unsafe-inline' 'strict-dynamic' 'nonce-f9212350-e189-4e8b-b0df-aa14a92bf597' https://consentcdn.cookiebot.com https://analyticsext.trafikverket.se; style-src 'self' 'unsafe-inline' ; img-src 'self' https: data: blob: ; connect-src 'self' https://analyticsext.trafikverket.se https://api.trafikinfo.trafikverket.se https://consentcdn.cookiebot.com https://ext-api.vasttrafik.se; frame-src 'self' https://consentcdn.cookiebot.com; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://s3.ap-southeast-2.amazonaws.com https://maps.gstatic.com data:; script-src 'self' https://*.googleapis.com https://cdn.jsdelivr.net https://unpkg.com https://cdnjs.cloudflare.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://unpkg.com; frame-src 'self' blob: data:; connect-src 'self' https://*.googleapis.com; 1 default-src * 'self'; style-src * 'self' 'unsafe-inline'; img-src * 'self' data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.googletagmanager.com *.seeclickfix.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdn.embedly.com/widgets/platform.js cdnjs.cloudflare.com static.cloudflareinsights.com http://tag.brandcdn.com/privacy tag.brandcdn.com/autoscript/cityofbakersfieldsolidwastedivisio_vgtstk1fovvvvfu9/city_of_bakersfield_solid_waste_divisio.js * 'self' about: 'unsafe-inline' 'unsafe-eval' data:; worker-src * 'self' data: blob: 'unsafe-eval' 'unsafe-inline'; frame-src * 'self'; media-src * 'self' blob:; font-src * 'self' data:; upgrade-insecure-requests; form-action 'self'; frame-ancestors 'self';report-uri /contentsecuritypolicy/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com static.klaviyo.com www.oxygenconcentratorstore.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.affirm.com *.affirm.ca www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de gum.criteo.com fledge.eu.criteo.com fledge.us.criteo.com x.adroll.com widget.trustpilot.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.affirm.com *.affirm.ca d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com bat.bing.com c.bing.com m.media-amazon.com www.gstatic.com segment.prod.bidr.io i.liadm.com cdn-assets.affirm.com d.adroll.com x.adroll.com ib.adnxs.com dsum-sec.casalemedia.com sync.outbrain.com ml314.com us-u.openx.net pixel.rubiconproject.com sync.taboola.com eb2.3lift.com image2.pubmatic.com x.bidswitch.net pixel.tapad.com cdn.ywxi.net criteo-partners.tremorhub.com ad.360yield.com sync-t1.taboola.com simage2.pubmatic.com jadserve.postrelease.com criteo-sync.teads.tv tapestry.tapad.com r.casalemedia.com contextual.media.net exchange.mediavine.com dis.criteo.com sync.targeting.unrulymedia.com aa.agkn.com ade.clmbtech.com ad.tpmn.io www.oxygenconcentratorstore.com www.shareasale.com *.g.doubleclick.net gum.criteo.com ads.stickyadstv.com trends.revcontent.com rtb-csync.smartadserver.com ad.tpmn.co.kr sync.1rx.io www.facebook.com partner.mediawallahscript.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.affirm.com *.affirm.ca www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de device.maxmind.com static.klaviyo.com static-tracking.klaviyo.com static.criteo.net services.nofraud.com bat.bing.com static.cloudflareinsights.com www.google.com www.gstatic.com static-na.payments-amazon.com www.clarity.ms widget.eu.criteo.com apis.google.com js-agent.newrelic.com eastprodcdn.azureedge.net www.dwin1.com solutions.invocacdn.com s.vibe.co d2hrivdxn8ekm8.cloudfront.net acdn.adnxs.com sslwidget.criteo.com action.media6degrees.com s.adroll.com d.adroll.com connect.facebook.net cdn1.affirm.com cdn.ywxi.net widget.trustpilot.com action.dstillery.com www.oxygenconcentratorstore.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://static.klaviyo.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.affirm.com *.affirm.ca *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de device.maxmind.com fast.a.klaviyo.com static-forms.klaviyo.com gum.criteo.com j.clarity.ms apay-us.amazon.com api-visitor-us-east.velaro.com bam.nr-data.net api-main-us-east.velaro.com d-ipv6.mmapiws.com t.vibe.co measurement-api.criteo.com tte-prod.telemetry.vaultdcr.com pnapi.invoca.net api-engagement-us-east.velaro.com dp70uvwpivouv.cloudfront.net x.adroll.com www.google.com www.affirm.com cdn-assets.affirm.com featureassets.org s3-us-west-2.amazonaws.com widget.trustpilot.com prodregistryv2.org ib.adnxs.com services.nofraud.com *.clarity.ms cloudflareinsights.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src j.clarity.ms www.google.com fledge.eu.criteo.com apay-us.amazon.com bat.bing.com bam.nr-data.net fledge.us.criteo.com csm.us5.us.criteo.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://ewniosek.credit-agricole.pl/ https://*.typekit.net https://geowidget.easypack24.net https://wniosek.santanderconsumer.pl fonts.gstatic.com https://trustmate.io https://trustmate.pro *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://ewniosek.credit-agricole.pl/ https://www.facebook.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com self www.google.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com https://ewniosek.credit-agricole.pl/ https://*.googletagmanager.com https://wniosek.eraty.pl https://wniosek.santanderconsumer.pl https://*.hotjar.com https://*.googleapis.com https://*.salesmanago.pl https://*.dpd.com.pl https://*.doofinder.com https://*.clarity.ms https://c.bing.com https://*.cookiebot.eu https://*.cookiebot.com https://payment-widget-sandbox.przelewy24.pl https://payment-widget.przelewy24.pl pay.google.com apm.przelewy24.pl www.gstatic.com apis.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ewniosek.credit-agricole.pl/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com https://roweroza.pl https://sprint-rowery.pl https://stage.roweroza-magento.centuria.pl https://i.ibb.co https://*.usercentrics.eu https://www.google-analytics.com https://www.google.com https://*.googletagmanager.com https://*.sharethis.com https://wniosek.santanderconsumer.pl https://*.googleapis.com https://*.doofinder.com https://*.clarity.ms https://c.bing.com static.przelewy24.pl www.gstatic.com gstatic.com https://trustmate.io https://trustmate.pro *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ apis.google.com cdn.doofinder.com https://connect.facebook.net connect.facebook.net graph.facebook.com business.facebook.com https://ssl.ceneo.pl/ https://ewniosek.credit-agricole.pl/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.typekit.net https://www.google-analytics.com https://platform-api.sharethis.com https://cdn.jsdelivr.net https://cdn.tmtarget.com https://cdnjs.cloudflare.com https://geowidget.easypack24.net https://biznes.furgonetka.pl https://*.googleapis.com https://*.hotjar.com https://wniosek.santanderconsumer.pl https://*.googletagmanager.com https://*.cookiebot.eu https://*.cookiebot.com https://*.newrelic.com https://*.dpd.com.pl https://*.doofinder.com https://*.clarity.ms https://c.bing.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl https://trustmate.io https://trustmate.pro *.googleapis.com *.google.com *.gstatic.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.doofinder.com https://ewniosek.credit-agricole.pl/ https://static.klaviyo.com https://*.typekit.net https://cdn.jsdelivr.net https://geowidget.easypack24.net https://wniosek.santanderconsumer.pl https://cdnjs.cloudflare.com https://*.googletagmanager.com *.googleapis.com https://*.doofinder.com https://*.clarity.ms https://c.bing.com fonts.googleapis.com https://trustmate.io https://trustmate.pro *.fontawesome.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ewniosek.credit-agricole.pl/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.googlesyndication.com https://*.sharethis.com https://*.typekit.net https://*.googleapis.com google.com https://*.analytics.google.com https://stats.g.doubleclick.net https://*.hotjar.com https://*.googletagmanager.com https://*.nr-data.net https://*.doofinder.com https://*.clarity.ms https://c.bing.com sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com https://trustmate.io https://trustmate.pro http://dpm.demdex.net https://www.google.com https://www.gstatic.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com pay.elavonpaymentgateway.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.consentmanager.net pay.elavonpaymentgateway.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.consentmanager.net pay.elavonpaymentgateway.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.consentmanager.net pay.elavonpaymentgateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.consentmanager.net pay.elavonpaymentgateway.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com https://*.gstatic.com https://*.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net https://*.doubleclick.net *.google.com/ https://*.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.salesfire.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://www.magezon.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk https://*.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.visualwebsiteoptimizer.com https://*.feefo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.salesfire.co.uk *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com *.google.com/ https://www.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdn.mida.so https://*.visualwebsiteoptimizer.com https://*.s3.amazonaws.com https://*.salesfire.co.uk https://*.feefo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.salesfire.co.uk tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://*.googleapis.com https://*.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.salesfire.co.uk *.typekit.net fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com api.addressy.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://stats.g.doubleclick.net https://live.smartmetrics.co.uk https://*.mida.so https://*.salesfire.co.uk https://*.google-analytics.com https://*.feefo.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.salesfire.co.uk *.smartmetrics.co.uk *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-b9c31ecb9214449080eabb7989bed56c' https://www.mybmgchart.com 'self';img-src https://* 'self' blob: data:;style-src https://www.mybmgchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://acsbapp.com https://snap.licdn.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://static.ads-twitter.com https://analytics.twitter.com https://connect.facebook.net https://cdn.cookielaw.org https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://cdnsecakmi.kaltura.com https://cdnapisec.kaltura.com http://cdnapi.kaltura.com https://cfvod.kaltura.com https://www.google-analytics.com https://cdn.jsdelivr.net https://script.crazyegg.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://bam.nr-data.net https://hm.baidu.com/hm.js https://www.clarity.ms https://www.googleadservices.com blob: https://vjs.zencdn.net/5.0/video.min.js https://analytics.tiktok.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' https: data; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://fonts.googleapis.com https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://script.crazyegg.com https://static.cloudflareinsights.com https://cdnapisec.kaltura.com https://cfvod.kaltura.com https://vjs.zencdn.net/5.0/video-js.min.css https://analytics.tiktok.com; frame-ancestors 'self'; report-uri /br-pt/report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.anyday.io fonts.cdnfonts.com https://fonts.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cookieinformation.com *.trustpilot.com *.doubleclick.net *.googletagmanager.com pricetag.viabill.com event-client.viabill.com www.xtento.com js.mollie.com *.hotjar.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com maps.googleapis.com maps.gstatic.com *.google.dk *.klarna.com blob: *.anyday.io *.sleeknote.com www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.google.com *.google.ru *.doubleclick.net *.pricerunner.dk *.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com maps.googleapis.com applepay.cdn-apple.com *.cloudfront.net *.helloretail.com *.cookieinformation.com *.trustpilot.com *.getdrip.com *.mouseflow.com *.kickbite.io *.anyday.io *.sleeknote.com pricetag.viabill.com storage.googleapis.com *.clickcease.com www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.addwish.com *.ipaper.io *.hotjar.com chimpstatic.com *.chimpstatic.com *.reaktion.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com applepay.cdn-apple.com *.cloudfront.net *.cdnfonts.com data: storage.googleapis.com *.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com *.ipaper.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.hotjar.com *.zendesk.com *.doubleclick.net *.cookieinformation.com *.heylinkapi.com *.kickbite.io *.sleeknote.com *.clickcease.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.helloretail.com *.addwish.com *.ipaper.io *.reaktion.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.pulsure.dk/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://wsmcdn.audioeye.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/; font-src 'self' https://fonts.gstatic.com/ https://wsv3cdn.audioeye.com https://cdnjs.cloudflare.com data:; img-src 'self' data: https:; connect-src 'self' https://analytics.google.com https://www.google-analytics.com; report-uri https://cspreport.ecampusontario.ca 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com www.xtento.com *.googletagmanager.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com tagmanager.google.com https://www.googletagmanager.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com www.xtento.com cdn.xtento.com *.googletagmanager.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com widgets.sandbox.afterpay.com *.cash.app https://static.addtoany.com/ www.xtento.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.afterpay.com/ *.cash.app https://images.unsplash.com www.xtento.com cdn.xtento.com *.trackedlink.net *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com magefan.com cm.magefan.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: www.google.com.ua t.zip.co static.zipmoney.com.au static.zip.co soy.liquifire.com https://soy.liquifire.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app https://static.addtoany.com/ https://maps.googleapis.com www.xtento.com cdn.xtento.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk maps.googleapis.com *.hsforms.net *.hsforms.com *.gstatic.com static.zipmoney.com.au static.zip.co zip.co https://unpkg.com/swiper/swiper-bundle.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.cash.app cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com *.gstatic.com https://unpkg.com/swiper/swiper-bundle.min.css https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com payments-eu.amazon.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com https://stats.addtoany.com/menu https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce--UmbWEVqdxu8i_F_6LGWag' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://widgets.xsellco.com/ https://x.klarnacdn.net/ *.bathroomtakeaway.com/ 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com/ 'self' 'unsafe-inline'; frame-ancestors https://widgets.xsellco.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://widgets.xsellco.com/ *.facebook.com/ *.ubembed.com *.doubleclick.net *.cookiebot.com *.google.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.bathroomtakeaway.com/ https://c.clarity.ms/ https://c.bing.com/ https://www.facebook.com/ *.google.com/ https://google.com/ https://www.google.com.hk/ *.google.co.uk/ https://www.bathroomtakeaway.co.uk/ *.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com tagmanager.google.com https://www.googletagmanager.com *.facebook.net/ *.facebook.com/ *.bathroomtakeaway.com/ *.bing.com/ https://widgets.xsellco.com/ https://www.clarity.ms/ https://www.googletagmanager.com/ https://eu-library.klarnaservices.com/ *.klarna.com/ *.tiktok.com/ *.doubleclick.net *.ubembed.com *.cookiebot.com *.hotjar.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.trustpilot.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.bathroomtakeaway.com/ https://widgets.xsellco.com/ https://x.klarnacdn.net/ *.doubleclick.net *.ubembed.com downloads.mailchimp.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com https://www.google-analytics.com *.bathroomtakeaway.com/ https://widgets.xsellco.com/ *.doubleclick.net/ https://api.craftyclicks.co.uk/ https://invitejs.trustpilot.com/ *.clarity.ms/ https://evt-eu.klarnaservices.com/ *.klarna.com/ *.klarnaevt.com *.google.com/ *.googlesyndication.com/ https://google.com/ *.facebook.com/ *.cookiebot.com *.tiktok.com/ *.ubembed.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.blue.cl *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.wesupply.xyz https://wesupplylabs.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.blue.cl *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.blue.cl *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: 'unsafe-inline' data: 'unsafe-eval'; report-uri https://servix.idnes.cz/log/csp-report.aspx?w=arome 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com webcachex-eu.datareporter.eu *.fontawesome.com https://static.unzer.com https://applepay.cdn-apple.com webfonts.colop.com *.datareporter.eu webcache-eu.datareporter.eu data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://static-cc.test.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ https://sandbox.clicktopay.auth.visa.com https://clicktopay.visa.com https://sandbox.secure.checkout.visa.com https://secure.checkout.visa.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.colop.com maps.gstatic.com maps.googleapis.com api.colop-online.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com colop.matomo.cloud data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com unpkg.com *.colop.com *.datareporter.eu api.colop-online.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net https://static-v2.unzer.com/v2/ui-components/ colop.matomo.cloud webcache-eu.datareporter.eu cdn.matomo.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maps.googleapis.com *.datareporter.eu *.fontawesome.com assets.braintreegateway.com https://src.mastercard.com https://sandbox.src.mastercard.com https://static-v2.unzer.com/v2/ui-components/ webcache-eu.datareporter.eu webcache.datareporter.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.colop.com api.colop-online.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.matomo.cloud colop.matomo.cloud maps.googleapis.com *.colop.com *.datareporter.eu api.colop-online.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ https://static-cc.test.unzer.com https://static-v2.unzer.com/v2/ui-components/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: data: 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' https://*.adtrafficquality.google https://*.analytics.google.com https://*.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://pagead2.googlesyndication.com https://secure.gravatar.com https://securepubads.g.doubleclick.net https://www.ess-news.com https://www.google.co.uk https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagservices.com https://www.youtube.com; script-src blob: data: 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' https://*.adtrafficquality.google https://*.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://*.wp.com https://pagead2.googlesyndication.com https://secure.gravatar.com https://securepubads.g.doubleclick.net https://www.ess-news.com https://www.google.com https://www.googletagmanager.com https://www.googletagservices.com https://www.youtube.com 1 frame-ancestors *.certcapture.com *.storyblok.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://sis.redsys.es/ pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; media-src https://www.germainedecapuccini.es *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; connect-src https://www.google.com https://region1.analytics.google.com https://pagead2.googlesyndication.com https://analytics.tiktok.com https://capi.gdc.us/events https://cdn.equalweb.com https://access.equalweb.com https://europe-west3-iktracker-397307.cloudfunctions.net https://www.googletagmanager.com https://capi.germainedecapuccini.es https://ev.st.adsmurai.com/ www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.certcapture.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co https://sandbox.sequracdn.com https://live.sequracdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; frame-src https://13128304.fls.doubleclick.net/ https://td.doubleclick.net https://www.googletagmanager.com/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.certcapture.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com https://sandbox.sequracdn.com https://live.sequracdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; font-src https://static.klaviyo.com https://static-es.germainedecapuccini.es https://germaine-de-capuccini.co.uk *.yotpo.com *.googleapis.com *.gstatic.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; script-src https://maps.googleapis.com https://cdn.equalweb.com https://analytics.tiktok.com https://access.equalweb.com https://storage.googleapis.com https://cdn-st.adsmurai.com/ https://cdn.jsdelivr.net/ www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.certcapture.com cdn.doofinder.com yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com https://sandbox.sequracdn.com https://live.sequracdn.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src https://maps.gstatic.com https://maps.googleapis.com https://www.googletagmanager.com https://d3k81ch9hvuctc.cloudfront.net https://ad.doubleclick.net https://ade.googlesyndication.com https://germaine-de-capuccini.ui.smartie.io https://www.germainedecapuccini.es widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com *.certcapture.com cdn.doofinder.com https://images.unsplash.com yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com swellrewards.com *.swellrewards.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com https://sandbox.sequracdn.com https://live.sequracdn.com data: 'self' 'unsafe-inline'; style-src https://fonts.googleapis.com https://access.equalweb.com *.certcapture.com *.doofinder.com yotpo.com *.googleapis.com https://static.klaviyo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.fontawesome.com *.adobe.com *.facebook.com *.facebook.net *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.cloudfront.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudfront.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de www.commercepartnerhub.com *.ap-gateway.mastercard.com *.mastercard.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudfront.net *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com flagpedia.net *.ap-gateway.mastercard.com *.mastercard.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudfront.net checkout.kashier.io *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.fontawesome.com *.googleapis.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com maps.googleapis.com *.ap-gateway.mastercard.com ap-gateway.mastercard.com *.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.facebook.com *.facebook.net *.gstatic.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cloudfront.net *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.adobe.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src *.cloudfront.net assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com use.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com https://shopline.itau.com.br 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.despegar.com/ 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de magento-cloudflare.jetrails.com www.youtube.com *.despegar.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com *.getbeamer.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.ytimg.com *.despegar.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.mundipagg.com api.pagar.me www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.getbeamer.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com apis.google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.despegar.com/ *.googleapis.com *.google.com *.gstatic.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.smarthint.co *.googletagmanager.com *.facebook.net *.getbeamer.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline use.fontawesome.com *.getbeamer.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.despegar.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com http://api.itaushopline.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.mundipagg.com api.pagar.me www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://viacep.com.br/ws/ *.google-analytics.com *.getbeamer.com https://api.mundipagg.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ blog.tilemerchant.ie data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ blog.tilemerchant.ie 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com blog.tilemerchant.ie 'self'; frame-src https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com bid.g.doubleclick.net account.fetchify.com *.google.com/ *.meetanshi.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ *.trustpilot.com www.youtube.com *.weltpixel.com blog.tilemerchant.ie 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://meetanshi.com/media/logo.png *.facebook.com https://www.magezon.com *.meetanshi.com *.tilemerchant.ie https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ *.adobedtm.com *.adobe.com blog.tilemerchant.ie data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com *.googletagmanager.com *.facebook.net *.google.com/ *.meetanshi.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ *.trustpilot.com www.youtube.com player.vimeo.com https://www.googletagmanager.com tagmanager.google.com blog.tilemerchant.ie 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.doofinder.com downloads.mailchimp.com cc-cdn.com https://static.klaviyo.com widget.freshworks.com m2epro.freshdesk.com maxcdn.bootstrapcdn.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ *.trustpilot.com tagmanager.google.com blog.tilemerchant.ie 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.tilemerchant.ie *.amazonaws.com *.googleapis.com blog.tilemerchant.ie 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.doofinder.com wss://*.doofinder.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.meetanshi.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ cdn.plyr.io noembed.com https://www.google-analytics.com blog.tilemerchant.ie 'self' 'unsafe-inline'; child-src blog.tilemerchant.ie http: https: blob: 'self' 'unsafe-inline'; default-src blog.tilemerchant.ie 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; script-src 'self' web-in21.mxradon.com www.googletagmanager.com www.google-analytics.com www.googleadservices.com tr.capterra.com snap.licdn.com static.ads-twitter.com connect.facebook.net cdnjs.cloudflare.com js.zohostatic.com salesiq.zoho.com maxcdn.bootstrapcdn.com googleads.g.doubleclick.net px.ads.linkedin.com api.tiles.mapbox.com scripts.clarity.ms app.factors.ai *.hubspot.com *.hscollectedforms.net *.hs-banner.com *.hs-analytics.net *.hsadspixel.net *.hs-scripts.com *.hsforms.com *.hsforms.net; style-src 'self' 'unsafe-inline' css.zohostatic.com cdnjs.cloudflare.com fonts.googleapis.com; img-src 'self' data: blob: img.zohostatic.com www.google-analytics.com www.facebook.com stats.g.doubleclick.net www.google.com www.google.co.in *.hubspot.com *.hsforms.com *.hsforms.net; font-src 'self' fonts.gstatic.com fonts.googleapis.com; connect-src 'self' api.locus.sh wss://vts.zohopublic.com px.ads.linkedin.com analytics.google.com i.clarity.ms tr.capterra.com api.factors.ai api.mapbox.com *.tiles.mapbox.com *.bablic.com *.hubspot.com *.hscollectedforms.net *.hs-banner.com *.hsforms.com *.hubapi.com *.flostack.io; media-src 'self'; frame-src salesiq.zohopublic.com www.youtube.com www.googletagmanager.com *.hubspot.com *.hsforms.com *.hsforms.net https://19520031.hs-sites.com; worker-src 'self' blob: ; report-uri https://locus.report-uri.com/r/d/csp/reportonly; 1 default-src 'self' https: data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://fundingchoicesmessages.google.com https://googleads.g.doubleclick.net https://adservice.google.com https://www.googletagmanager.com https://www.google-analytics.com; script-src-elem 'self' 'unsafe-inline' https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://fundingchoicesmessages.google.com https://www.googletagmanager.com https://www.google-analytics.com; connect-src 'self' https: wss:; img-src 'self' https: data: blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net data:; frame-src 'self' https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://fundingchoicesmessages.google.com; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests 1 img-src https://higherlogicdownload.s3.amazonaws.com/NASN/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASN/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/NASN/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASN/ https://higherlogicdownload.s3.amazonaws.com/NASN/ https://higherlogiclongterm.s3.amazonaws.com/NASN/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/NASN/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASN/ 'self' https://higherlogiclongterm.s3.amazonaws.com/NASN/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/NASN/ https://higherlogicdownload.s3.amazonaws.com/NASN/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASN/ https://higherlogicstream.s3.amazonaws.com/NASN/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/NASN/ https://higherlogicdownload.s3.amazonaws.com/NASN/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASN/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://*.facebook.com https://*.facebook.com/ https://cdn.openwidget.com/ https://insight.adsrvr.org/ https://d1eoo1tco6rr5e.cloudfront.net/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self' https://*.facebook.com; object-src 'none'; manifest-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.ultra-rouge.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.facebook.com https://ct.pinterest.com *.weltpixel.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.trackedlink.net *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org https://enews.lenotre.fr https://cook.shortest-route.com https://cdn.cookielaw.org https://www.facebook.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com *.lenotre.com https://cdn.cookielaw.org https://bam.nr-data.net *.aticdn.net https://connect.facebook.net https://snap.licdn.com *.hotjar.com *.criteo.net *.criteo.com https://s.pinimg.com *.pinterest.com *.googlesyndication.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com https://maps.googleapis.com https://cdn.cookielaw.org https://bam.nr-data.net https://dmp.lenotre.com https://logs1412.xiti.com *.onetrust.com https://ct.pinterest.com https://region1.analytics.google.com *.linkedin.com *.criteo.com *.doubleclick.net *.google-analytics.com *.googlesyndication.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com fonts.gstatic.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.google.com *.addthis.com *.pinterest.com *.facebook.com *.facebook.net *.fbcdn.net https://connect.facebook.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.googletagmanager.com *.facebook.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com *.googleadservices.com *.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.googleapis.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.facebook.com *.facebook.net *.fbcdn.net http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' upload.dibeo.at asset.dibeo.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; connect-src 'self' upload.dibeo.at asset.dibeo.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; base-uri 'self'; form-action 'self'; img-src 'self' data: upload.dibeo.at asset.dibeo.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; script-src 'self' 'unsafe-inline' upload.dibeo.at asset.dibeo.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; 1 font-src *.gstatic.com *.stape.io *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io *.packeta.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * apm.przelewy24.pl *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.facebook.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io *.packeta.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com fonts.googleapis.com www.gstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io https://get.geojs.io *.avada.io *.packeta.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.ampproject.org www.googleapis.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net https://fonts.gstatic.com data: *.klevu.com *.flixcar.com *.flixfacts.com https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.klarna.com *.klevu.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://briqpay.test *.briqpay.com *.klarna.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.hotjar.com *.klarnaservices.com *.ingrid.com *.klarnaevt.com *.dibspayment.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adnxs.com *.omtrdc.net *.bing.com *.cloudflare.com *.cookiebot.com *.elongroup.se *.elon.se elon.se *.facebook.com *.googleadservices.com *.google-analytics.com *.google.se *.googletagmanager.com *.googleapis.com *.imbox.io *.klevu.com *.klarnaservices.com *.vaimo.net *.ytimg.com *.pricerunner.se *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.jwpsrv.com *.jwplayer.com *.uc.se *.prisjakt.no *.googlesyndication.com *.where-to-buy.co *.clarity.ms *.doubleclick.net *.dialogtrail.com *.lemonpi.io *.facebook.net *.reddit.com *.elon.no *.wistia.com *.videoly.co https://where-to-buy.co https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://briqpay.test *.briqpay.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adnxs.com *.bing.com *.clarity.ms *.cookiebot.com *.depict.ai *.elongroup.se *.facebook.net *.googletagmanager.com *.googleapis.com *.hotjar.com *.imbox.io *.klevu.com *.myvisitors.se *.oribi.io *.pertento.ai *.pinimg.com *.pinterest.com *.testfreaks.com *.charpstar.net *.flixfacts.com *.loadbee.com *.flix360.io *.flixcar.com *.unpkg.com *.dialogtrail.com *.adform.net *.elon.se *.cloudfront.net *.videoly.co *.scaleflex.it *.redditstatic.com *.voyado.com https://unpkg.com https://bf-content.elon.se https://c.bannerflow.net *.ingrid.com *.klarnaevt.com https://www.elon.no 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com *.depict.ai *.dibspayment.eu *.googleapis.com *.gstatic.com *.klevu.com *.flixcar.com https://www.elon.no 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.flixcar.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.adnxs.com *.demdex.net *.clarity.ms *.cookiebot.com *.depict.ai *.dibspayment.eu *.google-analytics.com *.g.doubleclick.net *.hotjar.com *.hotjar.io *.klarnauserservices.com *.ksearchnet.com *.pertento.ai *.pinterest.com security-hub.vaimo.network *.apptus.cloud *.iconify.design *.dialogtrail.com *.flix360.io *.charpstar.net *.loadbee.com *.flixcar.com *.googlesyndication.com *.elon.no *.bing.com *.facebook.com *.reddit.com *.unisvg.com wss://ws.depict.ai wss://headless.dialogtrail.com https://bf-content.elon.se https://c.bannerflow.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch *.tawk.to 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch js.mollie.com *.tawk.to www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch https://www.mollie.com *.tawk.to cdn.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch *.avada.io js.mollie.com *.tawk.to cdn.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com lotharjohn.ch *.lotharjohn.ch lothar-john.ch *.lothar-john.ch autocomplete2.postdirekt.de *.tawk.to wss://*.tawk.to *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; base-uri 'self'; font-src 'self' https: data:; img-src 'self' https: data: https://www.googletagmanager.com; object-src 'none'; script-src 'self' https: 'strict-dynamic' 'nonce-QmFaReAksMjNXCPFq1FdJg=='; style-src 'self' https: 'unsafe-inline'; worker-src 'self' https: blob:; connect-src 'self' https: wss://*.karte.io; frame-ancestors 'self'; report-uri /csp-violation-report-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com *.twitter.com *.zopim.com *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.intercomcdn.com fast.wistia.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.ubteam.com *.ubteam.co.uk *.twitter.com *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.b2clogin.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.networkmerchants.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.wistia.com *.wistia.net *.mercadolibre.com *.google.mu *.twitter.com *.vimeo.com *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.brightcove.net *.authorize.net *.kaptcha.com *.flipsnack.com *.ceros.com www.xtento.com landofcoder.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.networkmerchants.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.co.uk *.paypalobjects.com *.opayo.co.uk 'self' data: *.wistia.com *.wistia.net *.mercadopago.com *.mercadolibre.com *.magentocommerce.com *.ytimg.com www.xtento.com *.authorize.net *.cardinalcommerce.com *.googleadservices.com *.google-analytics.com *.twitter.com *.newrelic.com *.nr-data.net *.googletagmanager.com *.doubleclick.net *.zopim.com https://ryanscomputers.com https://www.ryanscomputers.com *.lenovo.com *.asus.com *.samsung.com *.raxcdn.com *.wikichip.org *.scan.co.uk *.broadcastbruce.com *.akamaihd.net *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr 'self' blob: *.news18.com *.google.mu *.google.co.nz *.google.co.uk *.google.com.ua *.google.com.ph *.klarna.com *.amazonaws.com *.rackcdn.com/ *.google.com.vn/ *.intercomcdn.com *.mcusercontent.com *.intercomassets.com *.linkedin.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.networkmerchants.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.avada.io *.wistia.com *.wistia.net *.google.mu *.mlstatic.com *.sagepay.co.uk www.google.com/recaptcha/api.js js-agent.newrelic.com https://bam.nr-data.net fonts.gstatic.com *.authorize.net *.cardinalcommerce.com *.ccdc02.com *.paypalobjects.com *.ytimg.com *.signifyd.com *.xtento.com *.getfirebug.com *.google-analytics.com *.braintreegateway.com *.zdassets.com *.zopim.com *.akamaihd.net *.googleadservices.com 'unsafe-inline' wss: 'self' data: *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.cloudflareinsights.com *.googletagmanager.com *.embed.typeform.com *.intercom.io *.intercomcdn.com *.ceros.com *.cdnjs.cloudflare.com *.hotjar.com *.licdn.com munchkin.marketo.net *.chatwoot.com *.respond.io connect.facebook.net browser.sentry-cdn.com www.xtento.com cdn.xtento.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.networkmerchants.com assets.braintreegateway.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.getfirebug.com *.google.mu *.mercadopago.com *.zdassets.com *.omtrdc.net *.zopim.com 'unsafe-inline' wss: 'self' data: *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.wistia.com *.wistia.net 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com blob: * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.networkmerchants.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com https://get.geojs.io *.avada.io *.mercadopago.com *.twitter.com *.doubleclick.net *.zdassets.com 'unsafe-inline' wss: *.google-analytics.com *.akamaihd.net *.wistia.com *.wistia.net *.litix.io *.ubteam.com *.ubteam.co.uk *.ubteam.ca *.ubteam.com.au *.ubteam.co.nz *.ubteam.eu *.ubteam.fr *.zendesk.com *.intercom.io *.cdnjs.cloudflare.com *.mktoresp.com *.hotjar.com *.hotjar.io *.linkedin.com *.chatwoot.com *.respond.io landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blob: * http: https: blob: 'self' 'unsafe-inline'; default-src blob: * 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src 'self'; report-uri https://www.the3day.org/site/XFrameViolation 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com js.stripe.com *.hotjar.com *.calendly.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://biocare.webecast.atreemo.uk bat.bing.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk *.cloudflare.com *.klarna.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://tracking.atreemo.com https://bat.bing.com https://www.dwin1.com https://static.hotjar.com https://www.clarity.ms https://cdn.noibu.com https://script.hotjar.com https://services.postcodeanywhere.co.uk https://static.zdassets.com js-agent.newrelic.com bam.nr-data.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.calendly.com *.pcapredict.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com services.postcodeanywhere.co.uk *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.pcapredict.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://p.clarity.ms https://cdn.noibu.com wss://input.noibu.com https://bam.nr-data.net https://services.postcodeanywhere.co.uk https://ekr.zdassets.com https://biocare.zendesk.com wss://widget-mediator.zopim.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.gstatic.com 'unsafe-inline' data: *.cloudflare.com *.googleapis.com *.klevu.com *.zopim.com https://www.gstatic.com *.tawk.to *.jsdelivr.net media.flixfacts.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com *.hana.ondemand.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com *.meetanshi.com *.addthis.com *.pinterest.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.googleapis.com maps.gstatic.com https://www.magezon.com *.meetanshi.com https://meetanshi.com/media/logo.png *.cloudflare.com https://cdn.klarna.com *.youtube.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.klevu.com *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.jsdelivr.net *.facebook.com *.azurewebsites.net app.mobicredwidget.co.za media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://browser.sentry-cdn.com s7.addthis.com https://www.google.com *.meetanshi.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.mouseflow.com *.nr-data.net www.googletagmanager.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net googleads.g.doubleclick.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.cloudflare.com *.klevu.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.ingest.sentry.io ekr.zdassets.com/ *.meetanshi.com *.cloudflare.com *.googleapis.com *.addthis.com https://graph.instagram.com *.testfreaks.com *.ksearchnet.com *.klevu.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthisedge.com *.nr-data.net vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.chilipiper.com https://www.observepoint.com https://browser.sentry-cdn.com; base-uri 'self'; object-src 'none'; worker-src 'self' blob:; script-src 'self' 'sha256-dlNgZtNNCa4ZXu7net3fkSM+7otJCNzSmTYNjZdlT6E=' 'sha256-rSzBQuA9i08JnS8hNeAcGH/4zsF0QdW6WQ3+yaHDBAo=' 'sha256-i0sRbxQ3Fz5/XG0JiYwgibRy/ycnWTmIddOhmfbwcZ8=' 'sha256-XmNPaEKFzELmwzGFC+YA54ulU/cb2JUb5RqWUABHtSI=' 'sha256-uQ14xz9MfP77CFLAHa/RqdOFRRUf44Ceu3ENXhf6V0w=' 'sha256-ipbBoKixwqjquK36IWNLfyxCJva8UyLfGrfvxPHxr38=' 'sha256-Y7sKpiCx7NdRtkIFmmTcPIvZRPCNPe5tkF6SRJswVQs=' 'sha256-WKgFivA8GA/ZBUZym6/vD5z6QHFe9R/uQLZ73UA4QCM=' 'sha256-+N1RLquaY9yhuxRNzz8/XFauzxSzNIGmYrhvohzf4Lg=' 'sha256-/Krh7Owc5JoKFywroDtGswnn7FT5csrAzLXDm7TZES4=' 'sha256-AOzAb0D+NopVNUs+rwCoGMIdVFWlgzrZKsvdebkxDwg=' 'sha256-PeSQzRAeflt2m+bsB4Yx0WqeEARaKnSNIIHVck7ch0Q=' 'sha256-d7iYvnHoVbZpGu4wGvU1Ow48bRzBc5PlFSfhrisP3uA=' 'sha256-grFRjD5ZnW98NQ60BT8S9Ir8/iDt1OUmyx2nJyT7e4g=' 'sha256-iHRqs0WI4QYucjSqCsD+VtgA5z9SKkmTjoQqXvGM5C4=' 'sha256-u/9QNBeXC/olFDBH4mlDIuttNKTP9WjZXdCFKJuS7eo=' 'sha256-x/Nza7GB8Nb8kOWl5dquGLZwAb02LZZLQW64GDef9fw=' 'sha256-nzIilWoC21qlaTsUgBi6IA1nPKGEHHrFs8MkAcfR7e8=' 'sha256-z4Bnf9qq2F5y8OWqpt+acNlmLapBARg0XYrE3wilcU0=' 'sha256-bK8iKFWXdPM1ME+Mu2bIbq1LRu0u2Cqd/60stEeAYOs=' 'sha256-zBC1179gsXAejqjjWOPyA9XBs4GAy4/sSApN6zUWwKc=' 'sha256-g3FxkAYFaPdKPG2MXA7RPokG7VNhYgoErwVS0DO7DK8=' 'sha256-i7u6yOzTrZO0JpEFOkcW0eFswXH3vvjNx/j5jfnt5No=' 'sha256-HB5YbByNv0jT2qaWn3Qi4/vXkubw1lgT28adrdKJAi8=' 'sha256-WE3qPfLV1ShMhkAHwwakCWQlRQmEGJkEGLqwIHw6SBY=' 'sha256-yX5LnBiOP4C3IAPYhb+9TUnnk0iGwhq9UZ67u5b679Y=' 'sha256-tqPvlZRAMf7FlDq+bqZNyfEoTOXRYQ0ab7zqBmqvLpc=' 'sha256-yUXrkvbo8KKgAjKQsgseJ6Fchh4UlWKfAZn/rSjxB4k=' https://app.observepoint.com https://bat.bing.com https://browser.sentry-cdn.com https://cdn.cookielaw.org https://challenges.cloudflare.com https://fonts.googleapis.com https://googleads.g.doubleclick.net https://js.intercomcdn.com https://js.navattic.com https://js.sentry-cdn.com https://js.zi-scripts.com https://munchkin.marketo.net https://observepoint.chilipiper.com https://observepoint.com https://resources.observepoint.com https://scripts.clarity.ms https://snap.licdn.com https://tracking-api.g2.com https://widget.intercom.io https://ws-assets.zoominfo.com https://www.clarity.ms https://www.googletagmanager.com https://www.observepoint.com https://www.youtube.com blob:; style-src 'self' 'sha256-NHpTFA7jy/qeqb5TJ7d2sEwEC9y+JcrHz++3ocdB+Bw=' 'sha256-lIBmVrO4GuQPoKLyObdQFZt8wu5sBZpbLF2rhcjmEX4=' 'sha256-GSdltENf0r/joNf0P3tXCyQ4G8U1K3c64nvEK8wOouI=' 'sha256-gj3hXMTISjefzHKc3LvwPGkgIqBnMTl1JhLIdwcC/O8=' 'sha256-LbZ1Unz/mECrqrf+3CWtpnBrwBH/o0xkJib5D3aXOi0=' 'sha256-HDYY6U2YJ1OY+bJ5Wfjr2rSQUWfvwIH2JVCtfSjiHPM=' 'sha256-qWwxsTFcdIcN78qmlVvZfPMlQLLiEk7put1pv87RdRQ=' 'sha256-lHUKqGdl+4OehsZGVG+FKk+4B6tXm4KELpn17gDOWYI=' 'sha256-46rNwOcaZWVtPyj+fngblqZuG+kDF25rIkM3O5MZ4AE=' 'sha256-4O5P8OJCAAWuszY15Z75GgA9O7IJRX3ylTuIOZXsneo=' 'sha256-ORuKZB3dHBi9O7/3A08h8xLYF7SCk24mVJZrULaM4TY=' https://fonts.googleapis.com blob:; connect-src 'self' https://primary-realtime.intercom-messenger.com https://a.clarity.ms https://v.clarity.ms https://www.observepoint.com https://geolocation.onetrust.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://www.google-analytics.com https://cdn.cookielaw.org https://js.intercomcdn.com https://api-iam.intercom.io https://js.zi-scripts.com https://ws.zoominfo.com https://bat.bing.com https://www.googletagmanager.com https://px.ads.linkedin.com https://snap.licdn.com https://app.navattic.com https://js.navattic.com https://analytics.google.com https://ws-assets.zoominfo.com https://442-mdr-359.mktoresp.com https://munchkin.marketo.net https://www.google.com https://tracking-api.g2.com https://observepoint.com https://resources.observepoint.com https://app.observepoint.com https://www.googleadservices.com https://privacyportal.onetrust.com https://scripts.clarity.ms https://app.observepointstaging.com https://j.clarity.ms https://n.clarity.ms https://o4505801143681024.ingest.us.sentry.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://challenges.cloudflare.com https://*.chilipiper.com; img-src 'self' data: https://s.w.org https://stats.g.doubleclick.net https://www.google-analytics.com https://cdn.cookielaw.org https://px.ads.linkedin.com https://www.google.com https://bat.bing.com https://downloads.intercomcdn.com https://www.googletagmanager.com https://c.clarity.ms https://c.bing.com https://www.linkedin.com https://js.intercomcdn.com https://observepoint.com https://resources.observepoint.com https://googleads.g.doubleclick.net https://content.cdntwrk.com https://static.intercomassets.com https://i.ytimg.com https://i.vimeocdn.com https://f.vimeocdn.com; frame-src 'self' https://www.observepoint.com https://challenges.cloudflare.com https://www.googletagmanager.com https://player.vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://resources.observepoint.com https://widget.intercom.io https://*.chilipiper.com; font-src 'self' https://www.observepoint.com https://fonts.gstatic.com https://fonts.intercomcdn.com https://js.intercomcdn.com https://observepoint.com https://resources.observepoint.com data:; report-to csp; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googleadservices.com https://services.nofraud.com https://unpkg.com/@credit-key/creditkey-js@latest/umd/creditkey-js.js https://bigcommerce.creditkey.com https://cdn11.bigcommerce.com https://microapps.bigcommerce.com https://checkout-sdk.bigcommerce.com https://code.jquery.com https://static.klaviyo.com https://static-tracking.klaviyo.com https://fast.a.klaviyo.com https://www.googletagmanager.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.google.com https://widget.wickedreports.com https://bat.bing.com https://www.clarity.ms https://embed.tawk.to https://cdn.searchspring.net https://cdn1.searchspring.io https://api.bazaarvoice.com https://apps.bazaarvoice.com https://impact.axite.app https://cdnjs.cloudflare.com https://www.recaptcha.net https://cdn.jsdelivr.net https://www.leaseq.com https://js.braintreegateway.com https://applepay.cdn-apple.com https://www.paypal.com https://static-na.payments-amazon.com https://apis.google.com/* https://js.chargebee.com; style-src 'self' 'unsafe-inline' https://cdn11.bigcommerce.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://embed.tawk.to https://cdn.searchspring.net https://microapps.bigcommerce.com https://www.googletagmanager.com; font-src 'self' https://cdn11.bigcommerce.com https://fonts.gstatic.com https://embed.tawk.to https://static.klaviyo.com https://applepay.cdn-apple.com; img-src 'self' data: blob: https://cdn11.bigcommerce.com https://store-raxt2z29l9.mybigcommerce.com https://creditkey-assets.s3-us-west-2.amazonaws.com https://culinarydepotinc.com https://*.culinarydepotinc.com https://m.media-amazon.com https://www.google.com https://www.google.co.il https://bat.bing.com https://static.klaviyo.com https://network-a.bazaarvoice.com https://embed.tawk.to https://cdn.searchspring.net https://www.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://s3.amazonaws.com https://3ww3xl.a.searchspring.io https://img.youtube.com https://c.clarity.ms https://c.bing.com https://fonts.gstatic.com https://dummyimage.com https://www.paypalobjects.com https://cdn-assets.affirm.com https://tawk.link https://d3cgm8py10hi0z.cloudfront.net https://cdn.jsdelivr.net; connect-src 'self' https://cdn11.bigcommerce.com https://bigcommerce.creditkey.com https://sentry.io https://fast.a.klaviyo.com https://a.klaviyo.com https://d-ipv6.mmapiws.com https://static-forms.klaviyo.com https://analytics.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net/ https://bat.bing.com/actionp https://va.tawk.to https://embed.tawk.to wss://*.tawk.to/s/ https://*.clarity.ms/collect https://sftp.culinarydepot.net https://searchspring.io https://*.searchspring.io https://api.bazaarvoice.com https://apps.bazaarvoice.com https://www.recaptcha.net https://www.google.com/ccm/collect https://google.com https://www.google-analytics.com https://culinary-depot.api.axite.app https://network-a.bazaarvoice.com https://track.wickedreports.com https://www.google.co.il https://payments.bigcommerce.com https://payments.braintree-api.com https://client-analytics.braintreegateway.com https://www.paypal.com https://apay-us.amazon.com https://dp70uvwpivouv.cloudfront.net https://sftp.culinarydepot.net/bcapp/calendar https://services.nofraud.com; frame-src 'self' https://checkout.culinarydepotinc.com https://www.google.com https://td.doubleclick.net https://embed.tawk.to https://www.recaptcha.net https://www.googletagmanager.com https://www.youtube.com https://checkout.paypal.com https://www.paypal.com https://js.chargebee.com; object-src 'none'; base-uri 'self'; frame-ancestors 'self' https://checkout.culinarydepotinc.com https://culinarydepotinc.com https://www.culinarydepotinc.com; 1 default-src 'self' *.cumulusmedia.com 'report-sample'; base-uri 'self'; script-src 'strict-dynamic' 'self' 'inline-speculation-rules' *.cumulusmedia.com 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' *.googletagmanager.com 'sha256-GyUsdBtdHKlqtQSzGDSvNCHPdK8s1GO2S2y9jj4oYog=' *.google-analytics.com stats.wp.com 'sha256-+zMjo4vywISTRiN+RDp+W665czd5i8MOxiovBqr69F0=' 'sha256-X7SYke/fTbXP5LTn1g56zfcWCiSzQpGhzSLHvvNm0jo=' form.jotform.com cdn.jotfor.ms *.cookielaw.org 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' *.onetrust.com connect.facebook.net s3.tradingview.com https://www.google.com/recaptcha/ https://challenges.cloudflare.com/turnstile/ 'sha256-riitXBKGtl5y5ccA7GF6ccqJuwEVP5tm8j0ff/fbw9U=' 'sha256-k8zlbQ8Yw3tO1mzGrtP0m5BxCIEa+iH8LXA4dctSEMI=' 'sha256-wBhUGm/Lzl4TA4tJsiguA/vnV9LaNE6plmk4Xn/6/Mw=' 'sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw=' 'sha256-5oZoxPs07HkLGv2K/yyNWiLlCvxwJuQdhXLKg2AXhT0=' 'nonce-hp058PXNXyu5G7vTlrz3rfEm' 'report-sample'; style-src 'self' 'unsafe-inline' *.cumulusmedia.com fonts.googleapis.com cdn.jotfor.ms 'report-sample'; img-src 'self' data: *.cumulusmedia.com *.wp.com *.googletagmanager.com *.google-analytics.com *.cookielaw.org *.jotform.com; font-src 'self' data: *.cumulusmedia.com fonts.gstatic.com https://www.google.com/recaptcha/; connect-src 'self' *.cumulusmedia.com *.google-analytics.com *.doubleclick.net submit.jotform.com *.cookielaw.org *.onetrust.com; object-src 'none'; frame-src 'self' *.cumulusmedia.com *.jotform.com *.youtube.com s.tradingview.com www.tradingview-widget.com challenges.cloudflare.com; report-uri https://www.cumulusmedia.com/wp-admin/admin-ajax.php?action=wpshr 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.knitpro.eu *.lightwidget.com cdn.lightwidget.com *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.knitpro.eu *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypalobjects.com cdn.lightwidget.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.knitpro.eu *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypalobjects.com cdn.lightwidget.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.knitpro.eu *.lightwidget.com cdn.lightwidget.com *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.doubleclick.net *.localhost:12387 *.googletagmanager.com *.paypalobjects.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypalobjects.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.knitpro.eu cdn-static.knitpro.eu cdn-media.knitpro.eu *.lightwidget.com cdn.lightwidget.com *.facebook.net *.google.co.in *.facebook.com *.doubleclick.net *.localhost:12387 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.knitpro.eu cdn-static.knitpro.eu cdn-media.knitpro.eu *.lightwidget.com cdn.lightwidget.com *.facebook.net *.google.co.in *.facebook.com *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.knitpro.eu *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com cdn.lightwidget.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com *.knitpro.eu *.lightwidget.com cdn.lightwidget.com *.facebook.net *.google.co.in *.facebook.com cdn-static.knitpro.eu cdn-media.knitpro.eu *.doubleclick.net *.localhost:12387 *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypalobjects.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.cloudfront.net *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.fls.doubleclick.net www.facebook.com *.google.com consentcdn.cookiebot.eu td.doubleclick.net secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com js.mollie.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://images.unsplash.com stats.g.doubleclick.net *.doubleclick.net *.g.doubleclick.net www.facebook.com *.google.com *.google.de *.googletagmanager.com *.google-analytics.com *.googleusercontent.com bat.bing.com c.clarity.ms c.bing.com *.trustedshops.com *.cookiebot.com integrations.etrusted.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com https://img.youtube.com https://www.mollie.com https://shareasale.com/sale.cfm *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://maps.googleapis.com connect.facebook.net *.google.com *.googletagmanager.com *.google-analytics.com www.gstatic.com bam.nr-data.net bam.eu01.nr-data.net js-agent.newrelic.com tagmanager.google.com consent.cookiebot.com consentcdn.cookiebot.com bat.bing.com www.clarity.ms *.trustedshops.com integrations.etrusted.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io s7.addthis.com https://cdn.jsdelivr.net js.mollie.com https://www.dwin1.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com integrations.etrusted.com d.ratepay.com d.payla.io dr.payla.io https://cdn.jsdelivr.net *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com stats.g.doubleclick.net bam.nr-data.net bam.eu01.nr-data.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.maps.googleapis.com *.google.com *.google.de *.gstatic.com consentcdn.cookiebot.com googleads.g.doubleclick.net www.facebook.com bat.bing.com *.clarity.ms integrations.etrusted.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com ekr.zdassets.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'self'; script-src 'self' 'strict-dynamic' cdn.rawgit.com https://cdn.jsdelivr.net; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://consent.cookiebot.com/uc.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://ajax.googleapis.com https://consentcdn.cookiebot.com https://consent.cookiebot.com/0c7d1786-9e20-4305-9309-7678dc1c935c/cc.js https://eurazeo.actusnews.com/site/cotation_json.php https://consent.cookiebot.com/logconsent.ashx https://go.eurazeo.com/l/436982/2022-04-12/8jjb23 https://consent.cookiebot.com/316c68ee-7904-432f-af9e-89cde666d7ae/cc.js https://consent.cookiebot.com/88ce59b3-59dd-4b97-b3d2-ed7beda8f537/cc.js https://www.googletagmanager.com/gtm.js https://go.eurazeo.com/l/436982/2023-02-06/8kbwn2 https://go.eurazeo.com/l/436982/2023-02-06/8kbwnc cdn.rawgit.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline'; base-uri 'self'; form-action 'self' https://go.eurazeo.com/l/436982/2022-04-12/8jjb23 https://go.eurazeo.com/l/436982/2023-02-06/8kbwn2 https://go.eurazeo.com/l/436982/2023-02-06/8kbwnc; frame-ancestors 'self'; block-all-mixed-content 1 img-src https://higherlogicdownload.s3.amazonaws.com/AAPOS/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AAPOS/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/AAPOS/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AAPOS/ https://higherlogicdownload.s3.amazonaws.com/AAPOS/ https://higherlogiclongterm.s3.amazonaws.com/AAPOS/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/AAPOS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AAPOS/ 'self' https://higherlogiclongterm.s3.amazonaws.com/AAPOS/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/AAPOS/ https://higherlogicdownload.s3.amazonaws.com/AAPOS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AAPOS/ https://higherlogicstream.s3.amazonaws.com/AAPOS/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/AAPOS/ https://higherlogicdownload.s3.amazonaws.com/AAPOS/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AAPOS/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 report-uri /csp-violations; default-src 'self'; font-src * data:; img-src * blob: data:; object-src 'none'; media-src * blob: data:; form-action *; script-src 'self' https://*.kit.com https://*.convertkit.com https://*.stripe.com https://*.intercom.io 'strict-dynamic' 'report-sample' 'unsafe-eval' 'nonce-6q3qxSAwbbXI75VT3AClpg=='; style-src 'self' https: 'unsafe-inline'; connect-src *; child-src * blob:; worker-src 'self' blob: 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.geotrust.com https://www.youtube.com https://vimeo.com *.googletagmanager.com https://www.googletagmanager.com *.g.doubleclick.net *.googleadservices.com *.jivosite.com *.pingdom.net *.google.co.in *.google.com *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.youtube.com *.vimeo.com *.paypalobjects.com https://app.cpscentral.com/ maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com https://www.youtube.com https://vimeo.com *.googletagmanager.com https://www.googletagmanager.com *.g.doubleclick.net *.jivosite.com *.pingdom.net *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.youtube.com *.vimeo.com *.paypalobjects.com https://app.cpscentral.com/ *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.twitter.com *.geotrust.com *.googletagmanager.com https://www.googletagmanager.com *.g.doubleclick.net *.googleadservices.com https://vimeo.com *.jivosite.com *.pingdom.net *.google.co.in *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.vimeo.com *.paypalobjects.com https://app.cpscentral.com/ tokenization.sandbox.accept.blue tokenization.accept.blue api.3dsintegrator.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://www.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.g.doubleclick.net *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://vimeo.com *.googletagmanager.com https://www.googletagmanager.com *.jivosite.com *.pingdom.net *.googleapis.com *.google.co.in *.google.com *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.youtube.com *.vimeo.com *.paypalobjects.com https://www.rapidscansecure.com/ *.clarity.ms *.lfeeder.com *.userway.org https://rapidswholesale.com/ https://app.cpscentral.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com *.geotrust.com *.googletagmanager.com https://www.googletagmanager.com *.g.doubleclick.net *.jivosite.com *.pingdom.net *.googleapis.com *.google.co.in *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.youtube.com *.vimeo.com *.paypalobjects.com *.googleadservices.com *.disqus.com https://www.rapidscansecure.com/ https://www.clarity.ms/ https://sc.lfeeder.com/ https://cdn.userway.org/ https://static.cloudflareinsights.com/ https://cpscentral.ngrok.io/ https://app.cpscentral.com/ https://scripts.clarity.ms/ https://munchkin.marketo.net/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com tokenization.sandbox.accept.blue tokenization.accept.blue api.3dsintegrator.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com *.geotrust.com https://www.youtube.com https://vimeo.com *.googletagmanager.com https://www.googletagmanager.com/ *.g.doubleclick.net *.googleadservices.com *.jivosite.com *.pingdom.net *.google.co.in *.google.com *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.youtube.com *.vimeo.com *.paypalobjects.com https://app.cpscentral.com/ https://cdn.userway.org/ downloads.mailchimp.com tokenization.sandbox.accept.blue tokenization.accept.blue api.3dsintegrator.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://code.jivosite.com/ https://app.cpscentral.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.cloudflare.com *.twitter.com *.twimg.com *.geotrust.com https://www.youtube.com *.youtube.com *.vimeo.com *.paypalobjects.com *.googletagmanager.com https://www.googletagmanager.com *.g.doubleclick.net *.googleadservices.com *.jivosite.com *.pingdom.net *.googleapis.com *.google.co.in *.bing.com *.quickspark.com *.chimpstatic.com https://chimpstatic.com *.roirevolution.com *.clarity.ms *.userway.org wss://vi-ya-3.jivosite.com/ https://app.cpscentral.com/ *.mktoresp.com/ form-assets.mailchimp.com *.intuit.com *.amazonaws.com tokenization.sandbox.accept.blue tokenization.accept.blue api.3dsintegrator.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.mmapiws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://rapidswholesale.com/; report-to report-endpoint; 1 style-src 'unsafe-inline' 'self' fonts.googleapis.com cdn.firebase.com cdnjs.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com d1bhf2byybf5br.cloudfront.net d2e18nuhnog8lh.cloudfront.net intrepid-prod.azureedge.net intrepid-prod-secure.azureedge.net cdn.intrepidagile.com;connect-src 'self' blob: https://*.azureedge.net bam.nr-data.net wss://*.vitalbook.com https://intrepidagile-dev.s3.us-west-2.amazonaws.com https://intrepidagile-dev-secure.s3.us-west-2.amazonaws.com https://intrepidagile-prod-secure.s3.us-west-2.amazonaws.com https://intrepidagile-prod.s3.us-west-2.amazonaws.com https://api.honeybadger.io https://*.vitalbook.com wss://*.firebaseio.com https://*.google-analytics.com https://securetoken.googleapis.com https://*.liveswitch.io wss://*.liveswitch.io https://api.openai.com https://www.youtube.com d1bhf2byybf5br.cloudfront.net d2e18nuhnog8lh.cloudfront.net intrepid-prod.azureedge.net intrepid-prod-secure.azureedge.net cdn.intrepidagile.com;script-src 'self' 'nonce-1a2b989b-c1d3-458e-8076-fb6cd0625aed' 'unsafe-eval' https://challenges.cloudflare.com https://*.google.com https://*.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://*.recaptcha.net https://hcaptcha.com https://*.hcaptcha.com https://ssl.p.jwpcdn.com https://bam.nr-data.net https://js-agent.newrelic.com cdnjs.cloudflare.com cdn.firebase.com https://*.firebaseio.com https://*.vitalbook.com https://*.liveswitch.io wss://*.liveswitch.io https://www.youtube.com;worker-src 'self' blob:;media-src * blob:;frame-src * https://hcaptcha.com https://*.hcaptcha.com;img-src * data:;default-src 'self';font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.p.jwpcdn.com 1 default-src 'self'; block-all-mixed-content; connect-src 'self' wss://de20.zopim.com csi.gstatic.com maps.gstatic.com korrelatie.zendesk.com wss://widget-mediator.zopim.com ekr.zdassets.com veiligthuis.zendesk.com google-analytics.com googleapis.com supporta.cc; font-src 'self' fonts.gstatic.com googleapis.com v2.zopim.com; form-action 'self'; frame-src supporta.cc; img-src 'self' data: www.googletagmanager.com www.google-analytics.com analytics.connectholland.nl v2.zopim.com maps.gstatic.com googleapis.com csi.gstatic.com cdn.supporta.cc; media-src static.zdassets.com; script-src 'self' googletagmanager.com googleoptimize.com google-analytics.com analytics.connectholland.nl v2.zopim.com googleapis.com pg-ws-ggz.custhelp.com static.zdassets.com connect.facebook.net cdn.supporta.cc; style-src 'self' 'unsafe-inline' pg-ws-ggz.widget.custhelp.com 1 default-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=OXmwmhGVpAXmCqv0dhPc4gvkprsLa43U8y6LCBhQu34-1765936481.3995945-1.0.1.1-tfzniqgVhhgDT9ZqBuYc2BMvCxlCcsIRMVSumbyFUaKxMruPSrb7QOEIna1Q56LD4QBC767l.xYql14VYuAdziVxGhQnUeF0EMW6i7FEKqRx0H8wQY3mnfkaE4ATy4H0Hvr1UoLm_4pS3t7emcswVdeS4oqRneOjXeI5LJ0yBkkpLjK.VVi0BHwNxAY9Lvt4Z5wQKyRWTiEPPgiIekC74g; report-to cf-dhupfrafuxemqula 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com self https://dev-3jnwcczu.mrhankeystoys.com https://mrhankeystoys.magentoprojects.net/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.certcapture.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.certcapture.com https://images.unsplash.com magefan.com cm.magefan.com *.amazonaws.com *.mrhankeystoys.com *.google.co.in https://*.gstatic.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.certcapture.com https://maps.googleapis.com *.amazonaws.com *.mrhankeystoys.com *.googleapis.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.certcapture.com *.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com https://maps.googleapis.com https://player.vimeo.com *.mrhankeystoys.com *.googleapis.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.feedbackcompany.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com fonts.bunny.net *.jsdelivr.net *.gstatic.com 'self' data: fonts.gstatic.com *.office.net *.protiplan.nl *.sleeknote.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.feedbackcompany.com *.facebook.com *.protiplan.be *.protiplan.nl 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com *.multisafepay.com https://pay.google.com *.facebook.com *.kiyoh.com api.widget.trengo.eu *.sleak.chat *.sumo.com *.clarity.ms *.youtube-nocookie.com *.pinterest.com *.googletagmanager.com sst.dieetwebshop.nl sst.protiplan.nl *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedbackcompany.com 'self' data: https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.disqus.com *.multisafepay.com *.amazonaws.com *.facebook.com *.google.nl *.sumo.com *.sumome.com *.googletagmanager.com *.taggrs.io sst.dieetwebshop.nl sst.protiplan.nl *.bing.com https://redchamps.com ts.tradetracker.net www.magmodules.eu *.google-analytics.com ssl.gstatic.com www.gstatic.com *.bing.net *.clarity.ms *.doubleclick.net *.facebook.net www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.be www.google.bg www.google.bi www.google.by www.google.ca www.google.cd www.google.ch www.google.cl www.google.co.ao www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bh www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gh www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.ua www.google.co.mz www.google.co.th www.google.co.uk www.google.co.za www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.it www.google.kg www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mn www.google.mu www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tn *.googlesyndication.com *.linkedin.com *.protiplan.be *.protiplan.nl *.sleeknote.com *.trengo.eu data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedbackcompany.com https://api.goaffpro.com https://static.goaffpro.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://browser.sentry-cdn.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.multisafepay.com https://pay.google.com *.facebook.net *.sumome.com *.sumo.com *.trengo.eu *.sleak.chat *.clarity.ms *.pinterest.com *.bufferapp.com *.googletagmanager.com *.google-analytics.com reddit.com *.reddit.com *.cookiecode.nl *.pinimg.com sst.dieetwebshop.nl *.sleeknote.com *.bing.com s7.addthis.com *.gstatic.com tm.tradetracker.net tagmanager.google.com *.doubleclick.net *.goaffpro.com *.googlesyndication.com *.licdn.com *.protiplan.nl *.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src downloads.mailchimp.com *.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com self 'unsafe-inline' *.gstatic.com tagmanager.google.com fonts.google.com fonts.bunny.net *.googletagmanager.com *.protiplan.nl *.sleeknote.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.feedbackcompany.com https://api.goaffpro.com https://static.goaffpro.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ingest.sentry.io ipinfo.io *.google.com *.gstatic.com https://*.googleapis.com hcaptcha.com https://*.hcaptcha.com *.multisafepay.com *.google-analytics.com *.googleapis.com *.hcaptcha.com ekr.zdassets.com *.facebook.net sumome.com sumo.com chimpstatic.com *.trengo.eu *.sleak.chat *.clarity.ms noembed.com *.plyr.io t.elasticsuite.io googleads.g.doubleclick.net stats.g.doubleclick.net ct.pinterest.com api.cookiecode.nl sst.dieetwebshop.nl sst.protiplan.nl *.sleeknote.com *.bing.com 'self' 'unsafe-inline' ekr.zdassets.com/ *.analytics.google.com *.googletagmanager.com *.bing.net *.cookiecode.nl *.doubleclick.net *.facebook.com *.goaffpro.com *.googlesyndication.com *.linkedin.com *.pinterest.com *.protiplan.be *.protiplan.nl *.taggrs.io *.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://648adf35-4f6c-4578-bdd1-a87aef3bfa23.sansec.watch/; report-to report-endpoint; 1 default-src 'self';font-src 'self' https://use.typekit.net https://fonts.gstatic.com;img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.google.com https://www.google.co.uk https://www.google-analytics.com;script-src 'self' 'unsafe-inline' https://www.google.com https://www.google-analytics.com https://maps.googleapis.com;style-src 'self' 'unsafe-inline' https://use.typekit.net/ipl0zeu.css https://fonts.googleapis.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com/ https://www.googleadservices.com/ https://bat.bing.com/ https://celebrosnlp.com/autocompletev6/Clients/KsiInt/output/CelScriptsAC.js https://connect.facebook.net/ https://data.brandible.de/ https://googleads.g.doubleclick.net/ https://integrations.etrusted.com/ https://rns.matelso.de/ https://secure.pay1.de/client-api/js/ajax.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.hotjar.com/ https://script.hotjar.com/ https://widgets.trustedshops.com/ https://www.google.com/recaptcha/ https://static-eu.payments-amazon.com/ https://secure.pay1.de/client-api/ https://www.gstatic.com/ https://cl.avis-verifies.com/ https://d388us03v35p3m.cloudfront.net/js/conversions_min.js https://stats.cleverreach.com/ https://snap.licdn.com/li.lms-analytics/ https://script.brandible.de/; style-src 'self' 'unsafe-inline' https://celebrosnlp.com https://integrations.etrusted.com/ https://widgets.trustedshops.com/; object-src 'none'; base-uri 'self'; connect-src 'self' https:; font-src 'self' https://www.brandible.at/ https://celebrosnlp.com/AutoCompleteV6/Templates/Default/fonts/ https://widgets.trustedshops.com/reviews/tsSticker/fonts/; frame-src 'self' https://td.doubleclick.net https://www.google.com https://www.youtube-nocookie.com https://secure.pay1.de/ https://data.brandible.de/; img-src data: *; manifest-src 'self'; media-src *; worker-src 'none'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-hDV0zYrf0icIizptlJl1FxClwWfG6Zr9'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 font-src https://geowidget.easypack24.net fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://*.sovendus.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://geowidget-app.inpost.pl/ *.weltpixel.com pay.google.com apm.przelewy24.pl https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com visit.vobis.pl *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org static.przelewy24.pl www.gstatic.com gstatic.com https://firebasestorage.googleapis.com https://*.sovendus.com https://ssl.ceneo.pl *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com s7.addthis.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://static.mageads.com/ccxid.js sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.avada.io *.shopify.com https://*.sovendus.com https://www.sovopt.com https://static.sovopt.com https://www.getback.ch https://ssl.ceneo.pl *.tradedoubler.com a.imgstatics.com visit.vobis.pl a.imgstatic.eu/trsdk a.imgstatic.eu/tr_sdk.js *.cloudflare.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://geowidget.easypack24.net https://geowidget.inpost.pl fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://static.getback.ch https://*.sovendus.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com ekr.zdassets.com/ *.easypack24.net *.inpost.pl *.openstreetmap.org sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl google.com www.google.com pay.google.com https://get.geojs.io *.avada.io https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://meet.google.com/_/scs/mss-static/_/js/ https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/hangouts_echo_detector/release/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com/video_effects/effects/ https://www.gstatic.com/meetings_p2p/ https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://meet.google.com/meetsw.js https://meet.google.com/devicesw.js https://meet.google.com/notrodsw.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://meet.google.com/_/scs/mss-static/_/js/k=boq-rtc.MeetingsUi.en_US.UputSJciIHM.2020.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /_/MeetingsUi/cspreport/fine-allowlist 1 worker-src 'none'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: https://*.gstatic.com https://*.typekit.net *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' https://*.paypal.com https://*.paypalobjects.com https://cdn.lightwidget.com https://*.googletagmanager.com https://*.doubleclick.net https://*.g.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src https://assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net https://cm.everesttech.net https://*.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://*.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://validator.swagger.io 'self' https://widgets.magentocommerce.com https://*.googleapis.com https://*.gstatic.com https://www.googleadservices.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.googlesyndication.com https://*.paypal.com https://*.paypalobjects.com https://www.sandbox.paypal.com https://*.braintreegateway.com https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://*.ftcdn.net https://*.behance.net https://*.vimeocdn.com https://i.ytimg.com https://www.facebook.com https://google.com https://*.google.com https://*.google.com.au https://*.google.co.nz https://*.google.co.uk https://*.google.ca https://*.google.com.ph https://*.intuit.com https://mcusercontent.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com https://*.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://*.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com 'self' data: https://www.googleadservices.com https://*.google-analytics.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.google.com https://*.google.com.au https://*.google.co.nz https://*.google.co.uk https://*.google.ca https://*.google.com.ph https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.cardinalcommerce.com https://includestest.ccdc02.com https://*.paypal.com https://www.sandbox.paypal.com https://*.paypalobjects.com https://*.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://cdn.jsdelivr.net https://cdn.lightwidget.com https://*.mailjet.com https://s.ytimg.com https://connect.facebook.net https://www.vimeo.com https://*.vimeocdn.com chimpstatic.com https://*.mailchimp.com https://*.list-manage.com https://*.pinimg.com https://*.pinterest.com *.googleapis.com *.gstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://www.googletagmanager.com tagmanager.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.adobe.com fonts.googleapis.com 'self' data: https://*.gstatic.com https://*.googleapis.com *.fontawesome.com https://*.braintreegateway.com https://*.typekit.net https://cdn.jsdelivr.net https://cdn-images.mailchimp.com https://*.mailchimp.com downloads.mailchimp.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com 'self' data: https://*.google.com https://*.googleapis.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://*.google.com.au https://*.google.co.nz https://*.google.co.uk https://*.google.ca https://*.google.com.ph https://*.googletagmanager.com https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://*.cardinalcommerce.com https://*.paypal.com https://www.sandbox.paypal.com https://*.paypalobjects.com https://pilot-payflowlink.paypal.com https://api.sandbox.paypal.com https://*.braintree-api.com https://*.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://cdn.jsdelivr.net https://*.pinterest.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; frame-ancestors 'self'; report-uri https://p35mk5st.uriports.com/reports/report; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: https://widgets.trustedshops.com d3otxgxltntbw8.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * d3otxgxltntbw8.cloudfront.net www.facebook.com 'self' 'unsafe-inline'; frame-ancestors ; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com https://www.googletagmanager.com/ *.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * d3otxgxltntbw8.cloudfront.net consentcdn.cookiebot.com td.doubleclick.net www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com maps.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com d3otxgxltntbw8.cloudfront.net www.facebook.com bat.bing.com imgsct.cookiebot.com www.google.pl www.google.de px.ads.linkedin.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com landofcoder.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com d3otxgxltntbw8.cloudfront.net consent.cookiebot.com bat.bing.com analytics.webgains.io diffuser-cdn.app-us1.com consentcdn.cookiebot.com prism.app-us1.com trackcmp.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com d3otxgxltntbw8.cloudfront.net 'self' 'unsafe-inline'; object-src landofcoder.com d3otxgxltntbw8.cloudfront.net 'self' data: 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ d3otxgxltntbw8.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com landofcoder.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site d3otxgxltntbw8.cloudfront.net region1.analytics.google.com bat.bing.com www.google.com googleads.g.doubleclick.net consentcdn.cookiebot.com www.google.pl www.google.de pagead2.googlesyndication.com www.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d3otxgxltntbw8.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://geowidget.easypack24.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com landofcoder.com *.google.com/ secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.inpost.pl https://firebasestorage.googleapis.com https://www.magezon.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org https://trustmate.io https://www.clarity.ms *.clarity.ms https://googletagmanager.com https://www.pagead.com *.3mk.pl https://www.facebook.com https://connect.facebook.net https://www.facebook.com/tr/ https://sherlock.ecdp.cloud https://imgsct.cookiebot.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.vimeo.com *.inpost.pl landofcoder.com *.avada.io *.shopify.com *.google.com/ secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org https://trustmate.io https://www.clarity.ms *.clarity.ms https://googletagmanager.com https://www.pagead.com https://www.googleadservices.com/ *.3mk.pl https://connect.facebook.net https://sherlock.ecdp.cloud https://consent.cookiebot.com https://consentcdn.cookiebot.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://geowidget.easypack24.net https://geowidget.inpost.pl https://trustmate.io https://www.clarity.ms *.clarity.ms *.3mk.pl https://googletagmanager.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com https://www.facebook.com graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com landofcoder.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org https://trustmate.io https://www.clarity.ms *.clarity.ms https://googletagmanager.com https://www.pagead.com https://www.googleadservices.com/ *.3mk.pl https://connect.facebook.net https://sherlock.ecdp.cloud https://consentcdn.cookiebot.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://iai-bridge.paxy.pl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://eastus-swscsp.azurewebsites.net/reporting/secure.bpointsaas.it/reportOnly 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local 'self' data: *.googleapis.com *.gstatic.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.google.com *.youtube.com *.twitter.com *.facebook.com *.hotjar.com *.ladesk.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.vimeocdn.com s.ytimg.com data: *.facebook.com *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.cz *.google.sk *.gstatic.com *.googlesyndication.com *.googleapis.com *.twitter.com *.twimg.com *.facebook.net *.ytimg.com *.imedia.cz *.heureka.cz *.heureka.sk *.doubleclick.net im9.cz www.xtento.com cdn.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.googletagmanager.com *.facebook.net maps.googleapis.com *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.google.com *.google.cz *.google-analytics.com *.googleadservices.com *.gstatic.com *.googleapis.com *.googlesyndication.com *.twitter.com *.twimg.com *.facebook.com *.fontawesome.com *.hotjar.com *.doubleclick.net *.imedia.cz *.sentry.io *.sentry-cdn.com *.cookiehub.com cookiehub.net *.cookiehub.eu *.ladesk.com *.biano.sk bianopixel.com *.im9.cz im9.cz *.dognet.sk *.addthis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com maxcdn.bootstrapcdn.com *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.googleapis.com *.gstatic.com *.twitter.com *.twimg.com *.cookiehub.com cookiehub.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.sentry.io *.google-analytics.com *.byvajsnami.cz *.byvajsnami.sk *.vegadesign.cz *.vegadesign.local *.google.com *.google.sk adservice.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.doubleclick.net *.googlesyndication.com *.twitter.com *.twimg.com *.biano.sk *.bianopixel.com *.bianopixel.sk *.cookiehub.net *.cookiehub.eut *.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.byvajsnami.sk *.byvajsnami.cz *.vegadesign.cz *.vegadesign.local 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com userlike-cdn-umm.b-cdn.net *.priv.center *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com userlike-cdn-operators.userlike.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://browser.sentry-cdn.com userlike-cdn-umm.b-cdn.net *.priv.center *.truendo.com matomo.cottonclassics.com js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://*.ingest.sentry.io userlike-cdn-widgets.s3-eu-west-1.amazonaws.com api.userlike.com wss://umd.userlike.com userlike-cdn-umm.b-cdn.net *.truendo.com https://*.sentry.io matomo.cottonclassics.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5158972f-f033-4936-8c48-824117bef6af.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; child-src 'self'; connect-src 'self'; default-src 'self'; font-src 'self'; form-action 'self'; frame-ancestors 'self'; img-src 'self'; manifest-src 'self'; media-src 'self'; navigate-to 'self'; object-src 'none'; script-src 'self'; script-src-attr 'self'; script-src-elem 'self'; style-src 'self'; style-src-attr 'self'; style-src-elem 'self'; worker-src 'self' 1 font-src *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com *.multisafepay.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e72367b9-6e86-4604-bbda-cd4860d727c6.sansec.watch/; report-to report-endpoint; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-hWKHfGVLEmLI/sadqxDxhpQz' http://localhost:5173 https://cosmos.enedis.fr https://www.datadoghq-browser-agent.com;object-src 'self';style-src 'self' 'unsafe-inline' http://localhost:5173 https://fonts.googleapis.com https://cosmos.enedis.fr;img-src 'self' https://cosmos.enedis.fr;font-src 'self' https://fonts.gstatic.com https://cosmos.enedis.fr;connect-src 'self' http://192.168.222.102:8088 https://oasice.enedis.fr https://oasice.edf.fr https://distri-ingepilot.enedis.fr https://distri-ingepilot-sei.edf.fr https://e-travaux.enedis.fr https://cosmos.enedis.fr https://api.e-plans.fr;report-uri /Csp/Report 1 font-src *.zapier.com *.zapier.app *.fontawesome.com *.tidio.co *.gstatic.com *.tagshop.io *.tagshop.ai *.productreview.com.au *.taggshop.io *.taggshop.ai *.cdnfonts.com *.evergage.com *.tagbox.com *.typekit.net *.eurekafurniture.com.au *.fonts.net *.jotfor.ms *.migaku.com *.onlinewebfonts.com *.alicdn.com *.taggbox.com images.latitudepayapps.com imageapi.magebinary.co.nz maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ashleyhome.com.au *.facebook.com *.americanexpress.com *.arcot.com *.cardinalcommerce.com *.mycardsecure.com *.rsa3dsauth.co.uk *.securesuite.co.uk mycardsecure.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.images.latitudepayapps.com *.imageapi.magebinary.co.nz 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors data: *.form.jotform.com *.jotform.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com *.zapier.com *.zapier.app *.taggbox.com *.authorize.net *.pinterest.com *.form.jotform.com *.jotform.com *.doubleclick.net *.jotform.io *.twitter.com *.afterpay.com *.commbank.com.au *.fliphtml5.com *.google.com *.opendns.com noop.style *.commercepartnerhub.com *.facebook.com *.googletagmanager.com google.com *.americanexpress.com *.arcot.com *.avada.io *.cardinalcommerce.com *.mycardsecure.com *.rsa3dsauth.co.uk *.securesuite.co.uk *.zscalerthree.net mycardsecure.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.weltpixel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com https://plumrocket.com https://accounts.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ *.trackedlink.net *.zapier.com *.zapier.app *.magentocommerce.com *.latitudefinancial.com *.adnxs.com *.pinterest.com *.mediaiqdigital.com *.eurekafurniture.com.au *.google.com.vn *.google.com.au *.taggbox.com *.doubleclick.net *.latitudepayapps.com *.gstatic.com *.googleapis.com *.tagshop.io *.tagshop.ai *.ashleyhome.com.au *.facebook.com *.google.com *.jivox.com *.tagbox.com google.com ui-avatars.com www.google.ae www.google.al www.google.am www.google.at www.google.be www.google.bg www.google.by www.google.ca www.google.ch www.google.ci www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.uk www.google.co.za www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.eg www.google.com.fj www.google.com.gh www.google.com.hk www.google.com.kw www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.cz www.google.de www.google.ee www.google.es www.google.fi www.google.fr www.google.gr www.google.hu www.google.ie www.google.iq www.google.it www.google.jo www.google.la www.google.lk www.google.mv www.google.nl www.google.pl www.google.pt www.google.ro www.google.rs www.google.se www.google.si www.google.sk www.google.vu *.eurekastreetfurniture.com.au *.local.com *.yahoo.com eurekastreetfurniture.com.au www.google.cl www.google.co.ck www.google.co.zm www.google.com.af www.google.com.bh www.google.com.ec www.google.com.gt www.google.com.jm www.google.com.kh www.google.com.na www.google.com.pe www.google.com.py www.google.com.sb www.google.com.uy www.google.dk www.google.ge www.google.gg www.google.hn www.google.hr www.google.lt www.google.mk www.google.mn www.google.mu www.google.ws www.google.co.vi www.google.com.pr www.google.lv www.google.no www.google.tt *.jotfor.ms www.google.ba www.google.bt www.google.co.bw www.google.co.cr www.google.co.ls www.google.co.tz www.google.co.ve www.google.com.do www.google.com.ly www.google.dz www.google.gy www.google.kz www.google.me www.google.ru www.google.sc www.google.tl www.google.bs www.google.com.ag www.google.is www.google.sn www.google.to www.google.az www.google.com.et www.google.com.om www.google.gm www.google.ml www.google.sr *.adsrvr.org www.google.co.ao www.google.co.mz www.google.co.ug www.google.com.mm www.google.ga www.google.im www.google.je www.google.lu www.google.ps www.google.rw *.afterpay.com *.trackedweb.net www.google.co.uz www.google.com.bo www.google.com.gi www.google.li www.google.md www.google.mg www.google.nr www.google.tn zip.co *.googleusercontent.com www.google.cv www.google.ht *.googleadservices.com www.google.cm *.ggpht.com www.google.ad *.facebook.net *.fliphtml5.com *.igodigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.zip.co static.zipmoney.com.au www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io https://rum.hlx.page https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.zapier.com *.zapier.app *.taggbox.com *.tidiochat.com *.tidio.co *.authorize.net *.jsdelivr.net *.lfscnp.com *.evgnet.com *.googleapis.com *.facebook.net *.pinimg.com *.adnxs.com *.crazyegg.com *.pinterest.com *.form.jotform.com *.jotform.com *.jotfor.ms *.productreview.com.au *.tagshop.io *.tagshop.ai *.twitter.com *.taggshop.io *.taggshop.ai *.latitudepayapps.com *.jivox.com *.zip.co *.google.com google.com *.commbank.com.au *.doubleclick.net *.evergage.com *.latitudefinancial.com *.tagbox.com *.zipmoney.com.au *.eurekafurniture.com.au *.yimg.com *.googletagmanager.com googletagmanager.com *.addressfinder.io *.afterpay.com *.avada.io *.bing.com *.googleadservices.com *.igodigital.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zipmoney.com.au zip.co https://accounts.google.com https://www.gstatic.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.zapier.com *.zapier.app *.googleapis.com *.jotfor.ms *.tagshop.io *.tagshop.ai *.taggshop.io *.taggshop.ai *.tagbox.com *.evergage.com *.typekit.net *.eurekafurniture.com.au *.fonts.net *.googletagmanager.com *.addressfinder.io *.taggbox.com images.latitudepayapps.com/ imageapi.magebinary.co.nz/ *.fontawesome.com maxcdn.bootstrapcdn.com https://accounts.google.com https://www.gstatic.com 'self' 'unsafe-inline'; object-src noop.style 'self' 'unsafe-inline'; media-src *.adobe.com *.zapier.com *.zapier.app *.tidiochat.com *.tidio.co *.tagshop.ai *.taggbox.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.zapier.com *.zapier.app *.tidio.co wss://socket.tidio.co *.zip.co *.paypal.com *.algolia.io *.google-analytics.com *.livechatinc.com *.form.jotform.com *.crazyegg.com *.tagshop.io *.tagshop.ai *.productreview.com.au *.taggbox.com *.adnxs.com *.pinterest.com *.evergage.com *.google.com.vn *.google.com.au *.google.com *.datadoghq.com *.googleapis.com *.cloudfront.net *.afterpay.com *.jivox.com *.doubleclick.net *.facebook.com *.taggshop.io *.zipmoney.com.au google.com localhost www.google.ae www.google.at www.google.be www.google.ca www.google.ch www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.kr www.google.co.nz www.google.co.th www.google.co.uk www.google.co.za www.google.com.ar www.google.com.bd www.google.com.bn www.google.com.br www.google.com.co www.google.com.fj www.google.com.hk www.google.com.my www.google.com.np www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sg www.google.com.tr www.google.com.tw www.google.cz www.google.de www.google.es www.google.fr www.google.gr www.google.ie www.google.iq www.google.it www.google.jo www.google.lk www.google.mv www.google.nl www.google.pl www.google.pt www.google.sk *.ashleyhome.com.au *.eurekafurniture.com.au *.eurekastreetfurniture.com.au *.yimg.com www.google.al www.google.cl www.google.co.ck www.google.com.af www.google.com.au www.google.com.cy www.google.com.eg www.google.com.gh www.google.com.kh www.google.com.mx www.google.com.na www.google.com.ua www.google.dk www.google.ee www.google.ge www.google.gg www.google.lt www.google.mk www.google.mu www.google.ro www.google.se www.google.vu www.google.co.ke www.google.com.bh www.google.com.kw www.google.com.sa www.google.fi www.google.mn www.google.no www.google.tt www.google.ws www.google.bg www.google.co.bw www.google.co.cr www.google.co.tz www.google.com.ly www.google.com.mt www.google.com.pr www.google.com.sb www.google.kz www.google.rs www.google.ru www.google.sc www.google.tl www.google.bs www.google.co.zm www.google.com.ag www.google.com.bz www.google.com.do www.google.dz www.google.ba www.google.com.ec www.google.sn www.google.sr www.google.to www.google.by www.google.cd www.google.co.ao www.google.co.ma www.google.co.zw www.google.com.jm www.google.com.lb www.google.com.mm www.google.com.ng www.google.com.pe www.google.com.uy www.google.hr www.google.hu www.google.je www.google.la www.google.lv www.google.rw www.google.hn www.google.im www.google.md www.google.nr *.googleadservices.com www.google.co.mz www.google.com.om *.bugsnag.com www.google.me *.alicdn.com www.google.tn www.google.com.et www.google.co.ug www.google.co.uz www.google.com.py www.google.mg ekr.zdassets.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.images.latitudepayapps.com *.imageapi.magebinary.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.eurekastreetfurniture.com.au 'self' 'unsafe-inline'; report-uri https://09b78a4d-2b3c-489e-9e11-19662dc91066.sansec.watch/; report-to report-endpoint; 1 font-src *.youtube.com storage.googleapis.com/rtux-rtux-data-integration-rti/ maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com 'self' data: *.stape.io https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ https://www.googletagmanager.com https://td.doubleclick.net https://bat.bing.com https://ct.pinterest.com https://app-wallee.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.frankenspalter.ch https://images.unsplash.com https://www.magezon.com https://files.alive5.com https://www.googleadservices.com https://www.google.ca https://bat.bing.com https://www.preisvergleich.ch https://app-wallee.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.youtube.com bx-cdn.com/static/bav2.min.js track.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/rti.min.js track.bx-cloud.com/static/rti.min.js bx-cdn.com/static/rti.min.js storage.googleapis.com/rtux-rtux-data-integration-rti/ https://maps.googleapis.com *.google.com/ https://use.fontawesome.com https://assets.adobedtm.com https://*.adobe.com https://www.googleadservices.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://analytics.google.com https://www.googletagmanager.com https://*.newrelic.com https://*.nr-data.net https://*.cardinalcommerce.com https://*.paypal.com https://www.sandbox.paypal.com https://www.paypalobjects.com https://s.ytimg.com https://*.vimeo.com https://*.vimeocdn.com https://www.gstatic.com https://www.google.com https://*.braintreegateway.com https://alive5.com https://*.listrakbi.com https://bat.bing.com https://r-st.wi-platform-cloud.com https://v2.zopim.com https://s.pinimg.com https://static.zdassets.com https://ct.pinterest.com https://script.hotjar.com https://static.hotjar.com https://storage.googleapis.com https://app-wallee.com https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.youtube.com maxcdn.bootstrapcdn.com *.fontawesome.com https://*.adobe.com https://*.fontawesome.com https://assets.braintreegateway.com https://fonts.googleapis.com https://*.gstatic.com https://fonts.bunny.net https://alive5.com https://cdn.listrakbi.com https://storage.googleapis.com https://app-wallee.com *.googleapis.com *.googletagmanager.com *.stape.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com storage.googleapis.com/rtux-rtux-data-integration-rti/ https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.youtube.com track.bx-cloud.com main.bx-cloud.com track-gw1.bx-cloud.com bx-cloud.com main.wi-platform-cloud.com r-st.bx-cloud.com track.bx-cloud.com/track/v2 storage.googleapis.com/rtux-rtux-data-integration-rti/ https://maps.googleapis.com https://player.vimeo.com https://storage.googleapis.com/rtux-rtux-data-integration-rti/ https://ct.pinterest.com https://bat.bing.com https://www.google.com wss://widget-mediator.zopim.com https://frankenspalterest.zendesk.com https://ekr.zdassets.com https://storage.googleapis.com https://app-wallee.com https://assets.secure.checkout.visa.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' guaporepneus.com.br *.guaporepneus.com.br wake-components.fbitsstatic.net guaporepneus.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.g.doubleclick.net *.googletagmanager.com *.google.com.br *.googleadservices.com *.jotfor.ms *.jotform.com *.getnet.com.br api.jotform.com *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.hotjar.io analytics.google.com google.com *.google.com *.hotjar.com metrics.hotjar.io vc.hotjar.io translate.googleapis.com googletagmanager.com googleads.g.doubleclick.net googleadservices.com apis.google.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.guaporepneus.com.br guaporepneus.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.seosuite.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-src www.googletagmanager.com https://connect.bolt.com https://*.bolt.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.twitter.com *.addthis.com *.facebook.com *.mixkit.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; base-uri headlightdepo.com headlightsdepot.com headlamprestoration.com www.discountpartsmonster.com www.google.com parts.americantoyota.com 'self' 'unsafe-inline'; media-src www.bing.com prod-streaming-video-msn-com.akamaized.net ssl.gstatic.com s-static.innovid.com m.media-amazon.com service.rvchat.com dict-dn.pstatic.net fonts.ninja *.adobe.com 'self' 'unsafe-inline'; font-src code.ionicframework.com cdn.honey.io cdn.ivaws.com www.slant.co static.zip.co duckduckgo.com at.alicdn.com t-azmaps.azurelbs.com static3.avast.com puhuiti.oss-cn-hangzhou.aliyuncs.com www.tacomaworld.com www.headlightsdepot.com use.typekit.net simplycodes.com svcs.tql.com 35312385-2e8b-4f12-9f6d-051b45cbddbe de6ae568-06cd-4ef3-bd2f-95324c25c108 ee072aac-1d74-4dde-8f52-366c475f83b6 croissant-services-data-public-assets-us-east-2-production.s3.us-east-2.amazonaws.com images.simplycodes.com themes.googleusercontent.com cdn.scite.ai de1f9189-80b0-4de9-8f24-bbed06fd3bc2 sc-static.net fonts.cdnfonts.com 5b958cef-f97f-4d45-9869-523cf430a43f maxcdn.bootstrapcdn.com cdnjs.cloudflare.com account.affilitizer.com aceify.ai cdn.megabonus.com cdn.ziplyne.com static.hsappstatic.net fonts.gstatic.com migaku-public-data.migaku.com 9edcdc02-2a60-4848-b69c-3914d7e5dc96 f2d7cc05-a340-44a3-b759-3d4f7e835101 6e7f3874-5f08-4aa9-b470-d75f72b7282e cdn.jsdelivr.net c4927bf1-3ae6-4126-9a55-faaf7e3ce4d1 jcmcbmdmfmelmlelagelpfhmohipjjia static.preply.com assets.alicdn.com 2f2ac7e5-6cf1-4510-b3ed-13304c356efb ef1d9e3d-150b-4a00-a3b5-199e09a7a1b0 c8b67a02-2485-4a85-898f-7e6b178bc8d2 static.zohocdn.com unpkg.com cdn-uicons.flaticon.com res-1.cdn.office.net stylesheets.pixiebrix.com fonts.bunny.net r2cdn.perplexity.ai b3e26938-323d-431c-b510-27c82cbe4ca1 261d6510-f003-4e76-a1ff-777a00d81807 837e3089-a6c6-4737-b46a-50910e946806 96380900-aaf2-46f5-abb3-a45fe8bdc86b 3f2fe2db-34e8-488c-90b6-1c1afc92f97e 88e25ded-aa73-4463-b8e6-219f2cd442e4 7765fe7f-eb32-4f97-b671-09c78e68992e stwleprodwus.blob.core.windows.net static.shopback.com *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; style-src www.gstatic.com code.ionicframework.com cdn.honey.io app.certcapture.com maxcdn.bootstrapcdn.com pwm-image.trendmicro.com www.headlightsdepot.com fonts.googleapis.com static-tracking.klaviyo.com markups.kdanmobile.com l-sou.com js-c.etc4.com www.6ppn.com ext.dianxiaobao.net decision.etc4.com tool-bcg.bwe.io www.l-sou.com pwm-image.trendmicro.jp https://connect.bolt.com https://*.bolt.com https://src.mastercard.com *.aexp-static.com *.assets.mastercard.com *.visa.com *.bc.earlywarning.com bc.earlywarning.com *.discover.com *.discover-src.com *.discovercard.com *.googleapis.com *.mastercard.com *.bolt.com *.earlywarning.com *.adobe.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com downloads.mailchimp.com https://static.klaviyo.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googletagmanager.com assets.braintreegateway.com 'self' 'unsafe-inline'; frame-ancestors www.headlightsdepot.com 'self'; object-src connect.bolt.com headlightsdepot.quiq-api.com www.google.com www.youtube.com accounts.google.com gateway.zscaler.net challenges.cloudflare.com noop.style ckr01.leb.k12.in.us static.quiq-cdn.com order.buywithprime.amazon.com dupe.com refid-43baf178-9e2f-4f17-bd51-552fc8d68e83.24c72b3988728ff6c9d6353367592355.resolve-id.block.wandera.com 'self' 'unsafe-inline'; connect-src bam.nr-data.net w.clarity.ms cdn.noibu.com input.noibu.com stats.g.doubleclick.net headlightsdepot.quiq-api.com rum-collector-2.pingdom.net bat.bing.com q.clarity.ms r.clarity.ms x.clarity.ms u.clarity.ms www.google.es t.clarity.ms o.clarity.ms p.clarity.ms s.clarity.ms m.clarity.ms e.clarity.ms j.clarity.ms notify.bugsnag.com z.clarity.ms v.clarity.ms h.clarity.ms www.facebook.com d.clarity.ms y.clarity.ms f.clarity.ms www.clarity.ms b.clarity.ms a.clarity.ms www.google.fr i.clarity.ms k.clarity.ms www.google.ca www.google.com.pr n.clarity.ms www.google.co.ke adservice.google.com www.google.co.nz www.google.ae www.google.co.uk www.google.nl www.google.co.jp www.google.com.pe clientstream.launchdarkly.com www.google.gr www.google.si www.google.com.tr www.google.ru www.google.com.ua cdn.acsbapp.com www.google.bs www.google.com.ag servail.com app.certcapture.com www.google.com.mx translate.googleapis.com api.killadsapi.com api.global-data-lab.com www.google.com.do www.google.com.au www.google.com.tw www.google.jo www.google.com.sa www.google.co.za www.google.co.in www.google.co.ve www.google.com.jm www.google.com.ec get663.com www.google.hr www.google.com.bh w88p9x.com api.datacloudstat.com overbridgenet.com www.google.co.th ad.doubleclick.net www.google.com.br www.google.ch www.google.com.gt www.google.co.cr www.google.hn www.google.cz www.google.sr www.google.co.il www.google.pt www.google.com.ph www.google.co.id www.google.bg www.google.com.sv www.google.lt www.google.ge www.google.tt subwayblaze.com www.google.com.gh sessions.bugsnag.com www.google.com.my www.google.cl www.google.rs www.google.kz www.google.am www.google.de www.google.com.pk www.google.md www.google.dm www.google.fi www.google.com.ng www.google.sn www.google.com.hk www.google.com.ly www.google.com.na www.google.it www.google.vu www.google.tm www.google.al logs.convertexperiments.com 10046935.metrics.convertexperiments.com www.google.ht www.google.kg www.google.no www.google.ie www.google.iq www.google.ro www.google.com.co api.amcreativemedia.com www.google.com.om d1lkfzu2puirk6.cloudfront.net translate-pa.googleapis.com www.google.com.ar www.google.com.lb www.google.com.pa www.google.com.kw www.google.lk www.google.co.kr www.google.com.ni fcgt742.com www.google.lv www.google.co.vi www.google.com.eg www.google.at www.google.com.mt www.google.com.qa www.headlightsdepot.com api.privacy-protector-adblocker.com api.mkmediaworks.com www.google.dz www.google.co.ao www.google.mg www.google.hu www.google.com.bo www.google.com.cy yandex.ru retcode-us-west-1.arms.aliyuncs.com www.google.pl www.google.az api.highdataanalytics.com api.awesomeblocker.com www.google.ee www.google.com.bz www.google.mu wedata.net www.google.co.mz www.google.sk www.i-shunxi.com sourcemaps.quiq.sh www.google.gy www.google.co.ug www.google.me src.mastercard.com secure.checkout.visa.com srcdcf.americanexpress.com content.discovercard.com h.online-metrix.net thm.visa.com www.google.com.sg ecmacore.com www.google.cm www.google.com.et www.google.mn www.google.com.mm g.clarity.ms l.clarity.ms api.fbanalytics.org api.video-adblock.com 127.0.0.1 acsbap.com accesswidget-log-receiver.acsbapp.com new229.com api.socialsolutionapp.com api.global-analytic.com www.google.be www.google.dk o19233.ingest.sentry.io www.google.mk www.google.is api.solarspireconsulting.com www.google.com.kh fonts.googleapis.com maxcdn.bootstrapcdn.com www.google.co.tz api.redirects-4.com gjtrack.ucweb.com www.google.se adtonus.com code.jquery.com rktds.net www.google.by www.google.as www.google.com.fj www.google.co.uz www.google.rw api.ciuvo.com www.bing.com www.google.so everyview.info topodat.info api.software-downloading.com www.google.cd www.google.com.bd api.solaranalyticscorp.com n.emojikeyboardforchrome.com analytics.google.com api.ultimateaderaser.com d3k81ch9hvuctc.cloudfront.net www.google.com.vn www.google.co.ma sbgse.com a.emojikeyboardforchrome.com www.google.ba n.sdmextension.com a.sdmextension.com api-js.datadome.co api.crystal-blocker.com publickeyservice.keys.adm-services.goog api.adblock360.net www.google.com.np readaloud.googleapis.com s3.ap-east-1.amazonaws.com s.pagerefresh-extension.com n.pagerefresh-extension.com upload.wikimedia.org www.google.com www.google.tn api.browsekeeper.com n.wistiaextension.com www.google.com.py sentry.goquiq.com n.noadsadblocker.com t.noadsadblocker.com live.noibu.com apis.google.com resource-proxy.noibu.com s.wistiaextension.com www.google-analytics.com api.rainbowblocker.com update.adblock360.org www.google.tg www.google.com.pg localhost l-sou.com www.google.gm www.google.bj c.colorchanger.net a.colorchanger.net api.vid-adblocker.com cr-input.mxpnl.net www.google.com.bn www.google.sh connect.facebook.net i.abfc-extension.com n.abfc-extension.com www.google.lu www.google.com.af www.google.bt www.google.co.zm infragrid.v.network www.google.ci bat.bing.net www.google.com.uy utq.vvipquan.com hm.baidu.com api.daily-guard.net api.adsfight.com www.google.co.zw s.blipshotextension.com api.earthyandenergy.com cdnmma.global-cache.online tl.ytlogs.ru d2rol5dpdbtxxu.cloudfront.net www.google.ps o622089.ingest.us.sentry.io www.google.co.bw api.freevideoguard.org api.nimblecapture.com r.nimblecapture.com www.google.mw search.standartanalog.com www.google.com.sl www.google.ws sbfse.com cap.nimblecapture.com o0rmue7xt0.execute-api.il-central-1.amazonaws.com api.blocksly.org polyfilljs.org www.google.cv api.aituria.com api.range-offer.com api.extremesecurityadblocker.com www.google.ne m.abu-xt.com prod-website-gateway.fetch.com ext.dianxiaobao.net decision.etc4.com 2ndstllc.com api.tokenmint.global fiendgamers.com api.adblockertool.com api.ginger-analytics.com www.6ppn.com at.alicdn.com www.google.ga www.google.bf www.google.mv www.google.com.tj d1r22q6sxlmkhx.cloudfront.net savingsslider-a.akamaihd.net stickyid-a.akamaihd.net ajax.googleapis.com www.google.com.vc search.firstmacs.com www.google.li www.google.co.ls www.google.ml n8.devzen.site www.google.je www.google.gg n.soundenhancementextension.com fast.a.klaviyo.com static-forms.klaviyo.com www.babylist.com www.google.dj www.google.fm headlightsdepot.com skincareadvertsking.com www.google.la metrics-dra.dt.dbankcloud.cn www.gstatic.com connect.bolt.com oob.script.ac backend.acsbapp.com px.wpk.quark.cn www.google.gl mon.tiktokv.com js-c.etc4.com www.googleadservices.com https://connect.bolt.com https://*.bolt.com https://src.mastercard.com https://src.apis.discover.com local.adblock360.com google.com rum.browser-intake-us5-datadoghq.com fonts.gstatic.com 10.135.209.243 browser-intake-datadoghq.com search.eportalmobile.com singleview.site sevendata.fun cdnmmh.global-cache.online service.gstatic-cache.com www.google.sc adban.net cdn.shopimgs.com digital-cloak.net www.google.tl report.clarity.ms effectssdk.ai error-analytics-sessions-production.shopifysvc.com nip.sinaydove.com www.google.bi uc.gre scripts.clarity.ms static.quiq-cdn.com static.cloudflareinsights.com ep1.adtrafficquality.google cdn.segment.com api.segment.io core-api.thebump.com secdomcheck.online www.google.cg events.binsiad.com dd.binsiad.com www.google.com.cu rum-static.pingdom.net api.disqometer.com dpm.demdex.net amcglobal.sc.omtrdc.net www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com *.google.com *.braintreegateway.com *.braintree-api.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.twimg.com *.google-analytics.com *.g.doubleclick.net *.addthis.com *.pinterest.com blob: https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; script-src cdn.noibu.com www.clarity.ms js-agent.newrelic.com ajax.cloudflare.com bat.bing.com static.cloudflareinsights.com connect.facebook.net rum-static.pingdom.net headlightsdepot.quiq-api.com static.quiq-cdn.com tracking.godatafeed.com www.googletagmanager.com www.headlightsdepot.com connect.bolt.com acsbap.com app.certcapture.com googleads.g.doubleclick.net apis.google.com get663.com infimv.com www.google-analytics.com conoret.com cdn-4.convertexperiments.com no-cdn.convertexperiments.com app.convert.com foodin.site www.google.com static01.tobeecloud.com sc-static.net exhabigou.com www.facebook.net trk.dolbanews.com px.srvcdn.net static.klaviyo.com toolsmagick.com hublosk.com jullyambery.net autroliner.com bootstrap.prod.scoville.dubai.aws.dev z7yj.82omyo.com 3001.scriptcdn.net translate.googleapis.com translate-pa.googleapis.com vacceedpasian.com lottingem.com infirc.com emojikeyboardforchrome.com tracksmall.com rialto-gms.s3.amazonaws.com www.googleadservices.com sdmextension.com noadsadblocker.com themesforytextension.com pagerefresh-extension.com wistiaextension.com appassets.androidplatform.net localhost in.masterquizzes.com l-sou.com colorchanger.net abfc-extension.com www.gstatic.com infird.com utq.vvipquan.com blipshotextension.com mainf.global-cache.online api.nimblecapture.com s3.amazonaws.com ritrag.com abu-xt.com crossydashcom-a.akamaihd.net ext.dianxiaobao.net fiendgamers.com js-c.etc4.com www.6ppn.com mstat.acestream.net decision.etc4.com blobby-boi.github.io js.userflow.com preach645.cloud cdn.optitc.com acsbapp.com search.firstmacs.com secured-pixel.com soundenhancementextension.com cdn.segment.com static-tracking.klaviyo.com lf26-cdn-tos.bytecdntp.com t7a.g4ui.com d3rhd9mxub2k80.cloudfront.net retagro.com images.uc.cn g.alicdn.com edge.eu1.fullstory.com https://connect.bolt.com https://*.bolt.com https://src.mastercard.com sofz9.82omyo.com 10.135.209.243 i7sqe0.82omyo.com s.skimresources.com scripts.clarity.ms www.l-sou.com cdn.mathjax.org embed.tawk.to cdn.mxpnl.com pagead2.googlesyndication.com ep2.adtrafficquality.google sb.scorecardresearch.com static.clmbtech.com static.ads-twitter.com static.chartbeat.com my.hellobar.com survey.survicate.com cdn.parsely.com cdn.cookielaw.org static.hotjar.com script.hotjar.com snap.licdn.com js.hs-scripts.com www.redditstatic.com tags.srv.stackadapt.com mc.yandex.ru cdn.binsiad.com cdn.browsiprod.com static.goquiq.com api.disqometer.com youwanoss.oss-cn-shanghai.aliyuncs.com mikkiload.com shortstack.services.atlassian.com www.myregistry.com assets.adobedtm.com *.adobe.com analytics.google.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.facebook.net https://ajax.googleapis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src www.headlightsdepot.com www.google.co.in www.facebook.com www.google.es bat.bing.com c.clarity.ms www.google.com.tr api.fillr.com www.google.com.au www.google.pl www.google.fr c.bing.com www.google.co.nz www.google.ca www.google.ae www.google.com.pr www.google.co.jp www.google.co.ke storage.googleapis.com www.google.co.th static.afterpay.com www.google.com.sa www.bing.com www.google.com.mx googleads.g.doubleclick.net www.google.co.ve lh3.googleusercontent.com www.google.fi www.google.lk upload.wikimedia.org www.google.com.co www.google.com.pe www.google.bs www.google.com.kw www.google.si www.google.co.id www.google.rs www.google.ie images.capitaloneshopping.com www.google.gr www.google.se cdn.ivaws.com www.google.cz cdn.honey.io www.google.am www.google.iq www.google.ru www.google.com.bo www.google.at www.google.com.lb www.google.com.sg www.google.com.ag app.certcapture.com s3.amazonaws.com www.google.cn www.google.com.tw www.google.is www.google.com.do www.google.com.sv www.google.jo www.google.ne www.google.ge www.google.co.za www.google.com www.google.co.il www.google.com.jm www.google.ee yastatic.net www.google.com.ec www.google.com.pk www.google.hr www.google.com.my www.google.co.kr www.google.com.bh www.google.hn www.google.dk www.google.lv www.google.co.cr content.discovercard.com www.google.com.bz www.google.com.ph www.google.com.pa www.google.com.ni ad.doubleclick.net www.google.az www.google.com.br www.google.ch www.google.com.vn www.google.com.kh www.google.kz www.google.com.om www.google.com.gt www.pdiadmin.work cdn.exchmapdata.com www.google.gy www.google.sr www.google.pt www.google.lt www.google.com.ar www.google.bg www.google.com.ng www.google.tt connect.facebook.net www.google.com.gh www.google.cl www.google.com.qa www.google.com.ly s.cmptch.com www.google.ro www.google.com.bd www.google.md www.google.dm www.google.mw www.google.bj www.google.ml www.google.com.eg www.google.no www.google.je www.google.tn www.google.sn www.google.it www.google.com.hk www.google.co.vi www.google.ci www.google.com.na www.google.co.ug www.google.lu www.google.vu www.google.tm www.google.al www.google.hu abtest-img-upload.s3.eu-west-2.amazonaws.com www.google.ht logs.convertexperiments.com www.google.kg www.google.cm www.google.mk www.google.co.ao www.googletagmanager.com www.google.ba www.google.com.uy www.google.com.mt tpc.googlesyndication.com www.google.sk www.google.com.py www.google.com.cy www.google.com.tj www.google.by www.google.dz www.google.cg www.google.mg m.media-amazon.com i.ebayimg.com www.google.gl www.google.co.ma www.google.gm www.google.co.bw www.google.cd www.google.mu l.mbs.zip www.google.rw www.google.co.mz www.google.me www.google.com.sb d2j6dbq0eux0bg.cloudfront.net www.google.com.et cdn.simplycodes.com www.google.com.af white-mushroom-097d4720f-testing.eastus2.azurestaticapps.net www.google.mn www.google.com.mm d3k81ch9hvuctc.cloudfront.net www.google.com.bn toolsmagick.com www.google.com.fj www.google.co.tz cdn.joinmoolah.com www.google.com.np magecloud.com www.google.as www.google.dj translate.googleapis.com www.google.co.uz www.google.so www.google.com.gi cdn-images.mailchimp.com www.google.li www.google.co.zm www.google.bf dz310nzuyimx0.cloudfront.net images.carid.com www.esptruck.com tracksmall.com www.google.com.pg www.google.com.sl joko-mobile-app-media.s3.eu-west-1.amazonaws.com www.google.com.vc www.google.co.zw responsible-defenders-pages-production.s3.amazonaws.com maxcdn.bootstrapcdn.com www.google.mv i5.walmartimages.com www.google.ga api.v12.estore.catalograck.com www.google.ps www.google.td www.google.tg www.google.cv www.google.sh 2ol9uikb2smmh33igrfuajp3rzdbfn26dexlgukbbe1964cfade0ae5bsac.d.aa.online-metrix.net d1z0mfyqx7ypd2.cloudfront.net www.google.gg www.google.bt cdn.shopify.com bat.bing.net qpdzbdfymkxrfamkovac.supabase.co speechit.pro hm.baidu.com www.google.la www.google.im assets.jivox.com www.google.ws huaban.com thm.visa.com 2ol9uikbvvw5624jk7etmgjmapvmvxbomknoygioe458c65801c51665sac.d.aa.online-metrix.net www.coupert.com bank.gov.ua csi.gstatic.com www.google.co.ls pos.baidu.com www.google.nl cloud-tr.devzen.site dupe.com mc.yandex.ru headlights.com www.google.sc jonypractic.net app.dataspidy.com 2ol9uikbdkqasbim2e2unhyjwhbwnlo7rldi7ng7c2a4320ba2880877sac.d.aa.online-metrix.net static.xx.fbcdn.net www.google.bi performanceparts.ford.com www.couponscdn.com assets.grammarly.com www.google.ad softwaresuggest.imgix.net yt3.ggpht.com www.google.fm cdn.leanlibrary.app favicon.yandex.net www.google.com.cu www.adbstr.com l.facebook.com www.magentocommerce.com throtl.com cdn.menardc.com images.globalindustrial.com static.summitracing.com www.truevalue.com www.landmsupply.com scene7.samsclub.com linqcdn.avbportal.com svcs.tql.com www.searchencrypt.com google.com https://connect.bolt.com https://*.bolt.com https://src.mastercard.com www.googleadservices.com cars245.com images.orgill.com cdn10.bigcommerce.com db73q1dut0rlp.cloudfront.net auxbeam.com www.morimotohid.com cdn-product-images.revolutionparts.io www.yhqdashi.com di2ponv0v5otw.cloudfront.net cdn11.bigcommerce.com da8h1v3w8q6n5.cloudfront.net thumbs.smartframe.io www.google.tl shop.spencehardware.com www.partsgeek.com etc.roboform.com ep1.adtrafficquality.google sb.scorecardresearch.com ping.chartbeat.net t.skimresources.com track-na2.hubspot.com vehiclepartimages.com 2ol9uikbgw2kux4lk7h5utwwgpxnjg6k3kjiuxka46ead17deeeabb11sac.d.aa.online-metrix.net h.online-metrix.net static.rshughes.com m-api-01.coupert.com img.alicdn.com mikkiload.com library.iterable.com d15k2d11r6t6rl.cloudfront.net rockysandstudio.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.google-analytics.com bid.g.doubleclick.net analytics.google.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline';report-uri https://www.headlightsdepot.com/fl32csp/report/; 1 font-src *.googleapis.com *.gstatic.com data: *.stape.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com *.stape.io https://firebasestorage.googleapis.com https://redchamps.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.stape.io https://cdn.jsdelivr.net *.avada.io *.shopify.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gstatic.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com maps.googleapis.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io https://get.geojs.io *.avada.io *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 report-uri /-/csp_report?report_only=true&source=webapp-no-object-src; script-src 'nonce-w7jb9rcutpptnz0jwjr7c3m0s' 'nonce-rvhhfk2oq2dv1prnse45ygy2g' 'self' https: 'strict-dynamic' 'report-sample' 'wasm-unsafe-eval' 'unsafe-inline' https://ssl.gstatic.com https://apis.google.com https://accounts.google.com/gsi/client https://d3ki9tyy5l5ruj.cloudfront.net https://d1gwm4cf8hecp4.cloudfront.net https://d1a3usp4brejtz.cloudfront.net https://d3u0af8znnrzzj.cloudfront.net https://d1dg3ns82tdjz3.cloudfront.net https://d2y3xhxlqzgfzh.cloudfront.net https://oauth.googleusercontent.com https://app.box.com https://platform.twitter.com https://connect.facebook.net https://platform.harvestapp.com https://www.google.com https://docs.google.com https://www.gstatic.com https://www.dropbox.com https://www.paypal.com/sdk/js https://recordwidget.vimeocdn.com https://api.stripe.com https://hooks.stripe.com https://js.stripe.com https://m.stripe.com https://m.stripe.network https://q.stripe.com https://prod-eu1.app.asana.com https://prod-au1.app.asana.com https://prod-jp1.app.asana.com https://prod-me1.app.asana.com https://cdn.cookielaw.org https://861-iiv-735.mktoweb.com https://resources.asana.com https://ccwizard.vertexsmb.com; frame-ancestors 'self' https://teams.integrations.asana.plus https://teams-beta.integrations.asana.plus https://teams-uat.integrations.asana.plus https://teams.microsoft.com https://teams.cloud.microsoft; frame-src 'self' blob: https://www.figma.com https://*.invisionapp.com https://invis.io https://miro.com https://whimsical.com https://www.loom.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.com https://www.canva.com https://xd.adobe.com https://*.looker.com https://lucid.app https://*.okta.com https://*.sharepoint.com https://*.dovetail.com https://*.tableau.com https://airtable.com https://*.mural.co https://help.asana.com https://accounts.google.com https://accounts.google.com/gsi/ https://content.googleapis.com https://www.google.com https://docs.google.com https://fast.wistia.net https://www.dropbox.com https://platform.harvestapp.com https://forms.asana.plus https://forms-server.asana.plus https://local.asana.com https://asana.com https://apisandbox.zuora.com https://test.zuora.com https://www.zuora.com https://www.sandbox.paypal.com https://www.paypal.com https://recordwidget.vimeocdn.com https://api.stripe.com https://hooks.stripe.com https://js.stripe.com https://m.stripe.com https://m.stripe.network https://q.stripe.com https://pixel.asana.com https://d3ki9tyy5l5ruj.cloudfront.net https://prod-eu1.app.asana.com https://prod-au1.app.asana.com https://prod-jp1.app.asana.com https://prod-me1.app.asana.com https://cdn.cookielaw.org https://form.asana.com https://form.asana-gov.com https://form-beta.asana.com https://form-stag.luna-s.org https://localhost.asana.com:3000 https://861-iiv-735.mktoweb.com https://resources.asana.com https://ccwizard.vertexsmb.com https://*.qualtrics.com; worker-src 'self' blob: https://d3ki9tyy5l5ruj.cloudfront.net; child-src 'self' blob: https://d3ki9tyy5l5ruj.cloudfront.net; object-src 'none'; base-uri 'none' 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.cdninstagram.com data: *.kxcdn.com amcglobal.sc.omtrdc.net *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.youtube.com www.facebook.com graph.facebook.com business.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com dpm.demdex.net *.instagram.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-_QmrQZqbh0Kg9nZOuwa1eg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.tawk.to *.cloudflare.com *.googleapis.com *.klevu.com *.zopim.com *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.paygate.co.za/payweb3/process.trans *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.tawk.to *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.tawk.to *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.tawk.to cdn.jsdelivr.net *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.klevu.com *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://browser.sentry-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.oppwa.com oppwa.com *.peachpayments.com *.tawk.to cdn.jsdelivr.net *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com oppwa.com *.oppwa.com *.peachpayments.com cdn.jsdelivr.net *.cloudflare.com *.googleapis.com *.klevu.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com oppwa.com *.oppwa.com *.peachpayments.com *.tawk.to wss://*.tawk.to *.testfreaks.com *.ksearchnet.com *.klevu.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-f4K-N8MRqMb3bGjD3Zd7xg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.mbank.ae https://*.googleapis.com https://translate.googleapis.com https://*.gstatic.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://www.google-analytics.com https://*.googleadservices.com https://*.googlesyndication.com https://pagead2.googlesyndication.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://*.doubleclick.net https://connect.facebook.net https://*.facebook.net https://*.facebook.com https://*.cloudflare.com https://*.youtube.com https://*.vimeo.com https://*.cookiebot.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cdn.userway.org https://*.userway.org https://cdn.yellowmessenger.com https://*.yellowmessenger.com https://r1.cloud.yellow.ai https://*.google.com https://*.google.* https://www.google.com https://www.google.ae https://www.google.co.in https://www.google.com.sa https://*.google.ae https://*.google.com.sa https://*.googleusercontent.com https://www.gstatic.com https://use.typekit.net https://p.typekit.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://connect.facebook.net https://*.googleapis.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://www.google-analytics.com https://*.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://*.gstatic.com https://*.google.com https://*.google.* https://cdn.yellowmessenger.com https://*.yellowmessenger.com https://cdn.userway.org https://*.userway.org https://consent.cookiebot.com https://consentcdn.cookiebot.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://translate.googleapis.com https://*.gstatic.com https://*.cloudflare.com https://*.cookiebot.com https://use.typekit.net https://p.typekit.net https://cdn.userway.org https://cdn.yellowmessenger.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.yellowmessenger.com https://*.yellowmessenger.com https://use.typekit.net https://p.typekit.net https://*.cloudflare.com https://cdn.userway.org https://cdn.yellowmessenger.com; img-src 'self' data: blob: https://*.google.com https://*.google.* https://*.google.co.in https://*.google.ae https://*.google.com.sa https://*.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.googlesyndication.com https://*.doubleclick.net https://www.google.com/ads/* https://www.google.ae/ads/* https://www.google.com/pagead/* https://googleads.g.doubleclick.net/pagead/* https://*.googleusercontent.com https://*.gstatic.com https://*.googletagmanager.com https://*.facebook.com https://*.facebook.net https://*.youtube.com https://*.vimeo.com https://*.cookiebot.com https://cdn.userway.org https://*.userway.org https://cdn-icons-png.flaticon.com https://cdn.yellowmessenger.com https://*.yellowmessenger.com; font-src 'self' data: https://fonts.gstatic.com https://*.cloudflare.com https://use.typekit.net https://p.typekit.net https://cdn.userway.org https://*.userway.org https://cdn.yellowmessenger.com https://*.yellowmessenger.com; connect-src 'self' https://www.mbank.ae https://*.google.com https://*.google.* https://*.google.co.in https://*.google.ae https://*.google.com.sa https://analytics.google.com https://www.google-analytics.com https://www.google.com/ccm/* https://www.google.com/ads/* https://www.google.ae/ads/* https://www.google.com/pagead/* https://*.googleadservices.com https://*.googlesyndication.com https://pagead2.googlesyndication.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://*.doubleclick.net https://*.google-analytics.com https://analytics.google.com https://www.google-analytics.com https://*.googletagmanager.com https://www.googletagmanager.com https://translate.googleapis.com https://*.facebook.com https://*.facebook.net https://connect.facebook.net https://*.cookiebot.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://api.userway.org https://cdn.userway.org https://*.userway.org https://cdn.yellowmessenger.com https://*.yellowmessenger.com https://r1.cloud.yellow.ai wss://r1.cloud.yellow.ai; worker-src 'self' blob: https://cdn.userway.org https://cdn.yellowmessenger.com; frame-src 'self' https://*.youtube.com https://*.vimeo.com https://*.facebook.com https://*.cookiebot.com https://consent.cookiebot.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.google.com https://*.google.* https://*.google.co.in https://*.google.ae https://www.gstatic.com https://cdn.userway.org https://*.userway.org; form-action 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; report-uri https://www.mbank.ae/csp-report-endpoint.php; report-to csp-endpoint 1 default-src 'self' https: data: blob; base-uri 'self'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data: blob; font-src 'self' https: data:; connect-src 'self' https:; frame-src 'self' https:; child-src 'self' https:; worker-src 'self' https:; report-uri /common/vendor/sysChk/csp_report; 1 default-src 'self' https://*.minecraft.jp; script-src 'self' 'unsafe-inline' 'nonce-cttY3wcoQJBjGtmERTYkcg' 'report-sample' https://*.minecraft.jp https://ajax.googleapis.com https://apis.google.com https://connect.facebook.net https://platform.twitter.com; style-src 'self' 'unsafe-inline' https://*.minecraft.jp; img-src 'self' data: https://*.minecraft.jp https://*.gstatic.com https://www.facebook.com; font-src 'self' data:; frame-src https://*.facebook.com https://*.twitter.com; report-uri https://report-uri.appspot.com/987875600540635136?ro=1 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com maps.googleapis.com cdn.rawgit.com/googlemaps/ cdn.jsdelivr.net/gh/googlemaps/ https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.gstatic.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://static.addtoany.com/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' data: 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://stats.g.doubleclick.net https://staticfiles.yviews.com.br https://service.yourviews.com.br https://api.pagar.me https://cdn.mundipagg.com https://img.youtube.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://c.clarity.ms https://newimgebit-a.akamaihd.net https://c.bing.com/ data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://static.addtoany.com/ tagmanager.google.com https://www.googletagmanager.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://www.googleoptimize.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://commerce.adobedtm.com https://js-agent.newrelic.com/ https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://www.clarity.ms/ https://imgs.ebit.com.br/ https://onsite.optimonk.com/ https://cdn-asset.optimonk.com/ https://gs-cdn.optimonk.com/ 'self' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; object-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com https://stats.addtoany.com/menu https://www.google-analytics.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://newimgebit-a.akamaihd.net/ https://w.clarity.ms/ https://front.optimonk.com/ https://cdn-account.optimonk.com/ https://cdn-limit.optimonk.com/ https://jfapiprod.optimonk.com/ 'self' 'unsafe-inline'; child-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' data: 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://td.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' polipet.com.br *.polipet.com.br wake-components.fbitsstatic.net polipet.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.conectiva.io *.sunset.systems *.cartstack.com.br *app.cartstack.com *.performa.ai *.cupom.social *.conectiva.app conectiva.io app.conectiva.io vm.conectiva.io conectiva.app api.performa.ai valid.performa.ai cartstack.com.br app.cartstack.com.br api.cartstack.com.br sunset.systems api.sunset.systems cupom.social app.cupom.social cdn.performa.ai app.cartstack.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com gstatic.com *.koin.com.br *.soclminer.com.br *.ebit.com.br *.btg360.com.br *.socialminer.com *.tiktok.com analytics.tiktok.com *.googletagmanager.com *.g.doubleclick.net googleadservices.com *.instagram.com *.google-analytics.com *.polipet.com.br *.facebook.com facebook.com instagram.com *.google.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gtm-nxl3xbc-mwi2n.uc.r.appspot.com *.uc.r.appspot.com s.pinimg.com ct.pinterest.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.akamaihd.net *.pagbank.com wss://signalr.fbits.net googletagmanager.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com paymentconnectorwakesandbox.cieloecommerce.cielo.com.br paymentconnectorwake.cieloecommerce.cielo.com.br web.fpcs-monitor.com.br device.clearsale.com.br *.fpcs-monitor.com.br h.online-metrix.net *.checkout.fbits.store mpi.braspag.com.br api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.polipet.com.br polipet.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://secure.paygate.co.za/payweb3/process.trans oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com https://plumrocket.com *.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com *.google.com/ oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com *.twitter.com *.freshchat.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://www.magezon.com https://firebasestorage.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com www.xtento.com cdn.xtento.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.google.co.za *.mobicredwidget.co.za safarioutdoorweb2.s3.af-south-1.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com landofcoder.com *.avada.io *.google.com/ *.oppwa.com oppwa.com *.peachpayments.com *.cloudflare.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com www.xtento.com cdn.xtento.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jsdelivr.net *.cloudfront.net *.freshchat.com https://s.clarity.ms/collect https://www.clarity.ms/tag/mnkzg1hhv5 https://s.cartbooster.io/preload *.convertexperiments.com *.sfdr.co *.hotjar.com *.tmtarget.com *.trackmytarget.com https://sfdr.co/sfdr.js *.doofinder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com oppwa.com *.oppwa.com *.peachpayments.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.getfirebug.com *.google.com 'self' data: *.freshchat.com *.jsdelivr.net *.doofinder.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com landofcoder.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.cloudflare.com *.twitter.com *.twimg.com 'self' data: *.mobicredwidget.co.za *.doofinder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.supercoach.com.au/csp-reports 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com platform.twitter.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com www.apptrian.com pinterest.com assets.pinterest.com syndication.twitter.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.google.com.ua maps.gstatic.com https://287e490773.nxcli.io/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com apis.google.com www.apptrian.com twitter.com platform.twitter.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com http://viacep.com.br *.pagseguro.com.br *.pagseguro.com *.smarthint.co maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com www.apptrian.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.pagseguro.com.br *.pagseguro.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.criteo.com *.vamp.gr assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.googletagmanager.com *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com *.newrelic.com *.nr-data.net fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.fontawesome.com 'self' data: *.cloudflare.com *.twitter.com *.twimg.com *.usercentrics.eu *.bing.com *.zdassets.com google.com *.google.gr *.tiktok.com *.linkwi.se pinterest.com *.pinterest.com interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms https://fonts.bunny.net *.revolut.com *.google.com *.cdn-apple.com pay.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.vivapayments.com *.vamp.gr *.criteo.com c.seznam.cz *.facebook.com *.contactpigeon.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.google.gr *.cloudflare.com *.tiktok.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com cdn-cookieyes.com *.clarity.ms 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: widget-v3.boxnow.gr/ widget-v5.boxnow.cy *.vamp.gr *.zopim.com *.criteo.com c.seznam.cz td.doubleclick.net *.contactpigeon.com *.hotjar.com *.facebook.com *.tiktok.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms *.googletagmanager.com google.com *.revolut.com *.google.com *.cdn-apple.com pay.google.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.vamp.gr *.criteo.com c.seznam.cz https://trustmark.gr *.tiktok.com *.contactpigeon.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.googleapis.com *.gstatic.com *.trustedshops.com cdn.jsdelivr.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.doubleclick.net *.facebook.com *.mastercard.com google.com *.google.gr *.googletagmanager.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms https://firebasestorage.googleapis.com https://www.magezon.com *.revolut.com *.google.com *.cdn-apple.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.vivapayments.com https://aqurate.ai *.aqurate.ai *.vamp.gr *.zopim.com *.zdassets.com *.criteo.com c.seznam.cz 'self' data: *.tiktok.com *.googletagmanager.com *.googleapis.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.facebook.net *.facebook.com *.doubleclick.net td.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com *.paypal.com google.com *.hotjar.com *.fontawesome.com *.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.cloudflare.com *.google.gr https://trustmark.gr/badge/dist/index.js https://static.adman.gr/adman.js https://greca.adman.gr go.linkwi.se *.linkwi.se *.pinterest.com interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms *.avada.io *.revolut.com *.google.com *.cdn-apple.com pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.vamp.gr *.criteo.com *.aqurate.ai assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.googletagmanager.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com *.newrelic.com *.nr-data.net *.fontawesome.com *.trustpilot.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.bing.com *.hotjar.com *.tiktok.com *.linkwi.se pinterest.com *.pinterest.com interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.clarity.com cdn-cookieyes.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.vamp.gr *.criteo.com 'self' data: *.contactpigeon.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.google.gr *.cloudflare.com *.tiktok.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms 'self' 'unsafe-inline'; manifest-src *.vamp.gr *.criteo.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.contactpigeon.com *.tiktok.com pinterest.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.aqurate.ai https://aqurate.ai *.vamp.gr *.criteo.com c.seznam.cz *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.mastercard.com google.com *.google.gr *.googletagmanager.com *.tiktok.com *.contactpigeon.com assets.vampfashion.com static.vampfashion.com *.vampfashion.com *.paypal.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net/ *.zdassets.com *.hotjar.com *.hotjar.io *.feedbackcompany.com *.cloudflare.com https://pagead2.googlesyndication.com *.pinterest.com *.linkwi.se interactive-img.com *.interactive-img.com *.simplify.com *.packeta.com *.bing.com *.clarity.com cdn-cookieyes.com *.cookieyes.com *.clarity.ms https://get.geojs.io *.avada.io *.revolut.com *.google.com *.cdn-apple.com pay.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' vetoreditora.com.br *.vetoreditora.com.br wake-components.fbitsstatic.net vetoreditora.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.mlstatic.com *.fbits.net signalrcore.fbits.net wss://signalrcore.fbits.net *.rdstation.com.br *.cloudfront.net *.g.doubleclick.net *.googleadservices.com stats.g.doubleclick.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.vetoreditora.com.br *.pagar.me *.mundipagg.com *.movidesk.com cdnjs.cloudflare.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com popups.rdstation.com.br *.rdstation.com cta-redirect.rdstation.com pageview-notify.rdstation.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.smartlook.com web-sdk.smartlook.com *.cardinalcommerce.com *.rd.services *.yandex.ru *.yandex.com *.yango.com *.webvisor.com *.webvisor.org *.yastatic.net *.smartlook.cloud *.youtube.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.fbitsstatic.net *.cityadstracking.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.vetoreditora.com.br vetoreditora.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.innoship.ro https://*.sameday.ro *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.tile.openstreetmap.org *.openstreetmap.org *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com tagmanager.google.com https://www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.avada.io https://*.sameday.ro https://pa.7w.ro http://pa.7w.ro *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://*.sameday.ro *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com https://www.google-analytics.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://get.geojs.io *.avada.io https://pa.7w.ro http://pa.7w.ro *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com www.vinhosevinhos.com *.bootstrapcdn.com *.smarthint.co *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com www.vinhosevinhos.com *.bootstrapcdn.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.yapay.com.br/ *.cloudfront.net/; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.addthis.com *.doubleclick.net *.google.com https://www.google.com/* *.yapay.com.br/ *.cloudfront.net/ *.pagaleve.io *.pagaleve.com.br c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.magesolution.com *.vinhosevinhos.com *.google.com *.google.com.br *.magesolution.com/* www.vinhosevinhos.com *.facebook.com *.ebit.com.br *.googletagmanager.com *.dnzdns.com *.ebitempresa.com.br *.doubleclick.net *.akamaihd.net *.siteblindado.com *.dinamize.com *.cloudfront.net/ *.yapay.com.br/ *.vindi.com.br/ https://firebasestorage.googleapis.com *.pagaleve.com.br www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googleadservices.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.vimeo.com *.youtube.com *.addthis.com *.paypal.com *.paypalobjects.com *.addthisedge.com *.moatads.com *.facebook.com *.googletagmanager.com *.doubleclick.net *.dinamize.com *.facebook.net *.google.com *.ebit.com.br *.siteblindado.com *.google.com.br www.vinhosevinhos.com https://static.cloudflareinsights.com *.smarthint.co *.yapay.com.br/ *.vindi.com.br/ *.avada.io *.shopify.com http://viacep.com.br *.pagaleve.com.br assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.vinhosevinhos.com *.bootstrapcdn.com *.ebit.com.br *.googletagmanager.com *.smarthint.co https://fonts.bunny.net unsafe-inline tagmanager.google.com 'self' 'unsafe-inline'; object-src *.cloudfront.net/ *.yapay.com.br/ *.vindi.com.br/ 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.addthis.com *.google-analytics.com *.doubleclick.net www.vinhosevinhos.com *.facebook.com *.ebit.com.br *.googletagmanager.com *.azurewebsites.net *.siteblindado.com *.dinamize.com *.analytics.google.com https://analytics.google.com *.smarthint.co *.cloudfront.net/ *.yapay.com.br/ *.vindi.com.br/ https://get.geojs.io *.avada.io www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://apisandbox.redeecommerce.rede.com.br/ https://apiquerysandbox.redeecommerce.rede.com.br/ https://api.redeecommerce.rede.com.br/ https://apiquery.redeecommerce.rede.com.br/ *.dinamize.com *.siteblindado.com *.ebit.com.br https://oauth.bb.com.br/oauth/token https://cobranca.bb.com.br:7101/registrarBoleto https://oauth.hm.bb.com.br/oauth/token https://cobranca.homologa.bb.com.br:7101/registrarBoleto 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.vinhosevinhos.com/; report-to report-endpoint; 1 script-src 'nonce-260bcdebb1b5d8d38c44b8d137815e57ee8259bc2d9fd54ad7b2ac4d78fd11f2' assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com *.disqus.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' *.livechatinc.com *.cookiebot.com *.hotjar.com *.bing.com 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com *.autopay.eu *.googleapis.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu blob: *.disqus.com https://img.youtube.com *.hsforms.net *.hsforms.com 'self' data: 'self' *.cookiebot.com; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' *.cookiebot.com *.googlesyndication.com; media-src *.adobe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com play.google.com *.autopay.eu 'self' *.livechatinc.com *.cookiebot.com *.googletagmanager.com *.doubleclick.net; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com 'self' data: 'self'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self'; 1 manifest-src 'self'; worker-src blob: jsctool.com; script-src 'self' 'strict-dynamic' 'nonce-10c5153cb353632098c411677d21d927' 'unsafe-eval' *.cloudflare.com cdn.trustindex.io; frame-src 'self' *.moon-fachhandel.de *.motion-tm.de *.handytick.de *.talkline.de *.doubleclick.net www.googletagmanager.com *.google.com *.cloudflare.com *.paypal.com *.braintreegateway.com www.facebook.com; media-src data: *.moon-fachhandel.de *.motion-tm.de *.handytick.de *.talkline.de; report-uri https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub5786f9d787e82c3541d0856246b9230e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=production&host=www.handytick.de 1 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; upgrade-insecure-requests; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.stackers.com *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://client.crisp.chat *.klarnacdn.net static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sagepay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com js.stripe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.clearpay.co.uk account.fetchify.com *.klarna.com pay.google.com b.stripecdn.com m.stripe.network td.doubleclick.net www.googletagmanager.com bluegdx.godoxstore.co.uk/ bluelen.lencarta.com *.sagepay.com business.facebook.com *.revolut.com *.cdn-apple.com *.gstatic.com *.trustpilot.com landofcoder.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afterpay.com *.clearpay.co.uk https://image.crisp.chat cdn.doofinder.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ x.klarnacdn.net www.gstatic.com www.google.co.uk https://firebasestorage.googleapis.com https://meetanshi.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com www.google.com.ua https://bluelen.lencarta.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://client.crisp.chat cdn.doofinder.com cc-cdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.klaviyo.com *.googletagmanager.com js.klarna.com static-tracking.klaviyo.com www.google.com www.gstatic.com pay.google.com hcaptcha.com b.stripecdn.com newassets.hcaptcha.com m.stripe.network static.hotjar.com script.hotjar.com analytics.lencarta.com *.googleadservices.com *.google-analytics.com bluegdx.godoxstore.co.uk tagmanager.google.com static.cloudflareinsights.com bluelen.lencarta.com eu1-config.doofinder.com cdn.browsee.io cdn.jsdelivr.net *.sagepay.com *.avada.io *.shopify.com https://www.googletagmanager.com business.facebook.com *.revolut.com cdn.ampproject.org *.trustpilot.com landofcoder.com https://bluelen.lencarta.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.squarecdn.com https://client.crisp.chat *.doofinder.com cc-cdn.com *.klarnacdn.net https://static.klaviyo.com js.stripe.com cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com www.gstatic.com use.fontawesome.com *.trustpilot.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.doofinder.com wss://*.doofinder.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static-forms.klaviyo.com fast.a.klaviyo.com js.klarna.com js.stripe.com pay.google.com merchant-ui-api.stripe.com play.google.com r.stripe.com api.hcaptcha.com m.stripe.com bluegdx.godoxstore.co.uk/g/collect bluelen.lencarta.com/g/collect *.sagepay.com https://get.geojs.io *.avada.io https://www.google-analytics.com business.facebook.com *.revolut.com *.cdn-apple.com *.gstatic.com cdn.ampproject.org www.googleapis.com landofcoder.com https://bluelen.lencarta.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src r.stripe.com eu.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-bG18DdmfRrKH4j2TsABTNPJEelsS5aj9'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.se/api/csp-report; report-to csp-endpoint 1 script-src 'self' 'unsafe-eval' https://js.stripe.com/v3 https://www.googletagmanager.com/ https://www.googleadservices.com https://apis.google.com https://googleads.g.doubleclick.net/ https://js.stripe.com/v3 https://static.cloudflareinsights.com https://connect.facebook.net https://www.youtube.com/iframe_api https://www.youtube.com/s/ https://www.google.com/pagead https://www.gstatic.com/_/mss/boq-identity/ blob:; worker-src 'self' blob:; object-src 'none'; report-uri /api/csp-report?source=kamimain&version=11; 1 img-src https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ 'self' https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicstream.s3.amazonaws.com/CONSERVATIONUS/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src 'self' *;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com http://www.googletagmanager.com https://metrics.fabriquedestyles.com *.googletagmanager.com maps.googleapis.com static.cdn.prismic.io prismic.io vimeo.com https://player.vimeo.com/api/player.js https://player.vimeo.com/ https://i.vimeocdn.com/video/ https://i.vimeocdn.com https://*.attraqt.io https://www.youtube.com/embed https://www.google-analytics.com https://*.hotjar.com/ js.stripe.com *.google.com *.google.fr https://*.facebook.net https://*.googlesyndication.com https://*.googleadservices.com https://*.doubleclick.net https://*.facebook.com *.woosmap.com *.imagino.com blob: https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net *.bing.com *.bing.net *.bing.fr *.microsoft.com *.microsoft.fr *.microsoft.net *.pinterest.com *.pinterest.net *.pinterest.fr;frame-src 'self' maps.googleapis.com *.prismic.io https://player.vimeo.com/ https://www.youtube.com/ https://player.vimeo.com/ https://i.vimeocdn.com/video/ https://i.vimeocdn.com js.stripe.com https://*.doubleclick.net https://*.facebook.com https://*.facebook.net *.woosmap.com *.imagino.com https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net metrics.fabriquedestyles.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.googletagmanager.com *.woosmap.com *.imagino.com https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net;img-src 'self' data: *;font-src 'self' data: *;connect-src 'self' https://vimeo.com/api/ *.hotjar.com maps.googleapis.com *.attraqt.io *.google.com *.doubleclick.net https://*.facebook.net https://www.googletagmanager.com https://metrics.fabriquedestyles.com wss://ws.hotjar.com https://content.hotjar.io https://www.google-analytics.com https://*.google-analytics.com *.analytics.google.com https://vc.hotjar.io https://*.facebook.com *.woosmap.com *.imagino.com https://*.kameleoon.com https://*.kameleoon.io https://*.kameleoon.eu https://*.kameleoon.net *.bing.com *.bing.net *.bing.fr *.microsoft.com *.microsoft.fr *.microsoft.net *.pinterest.com *.pinterest.net *.pinterest.fr;base-uri 'self' *;report-uri /csp/report 1 font-src consent.cookiefirst.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com consent.cookiefirst.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de consent.cookiefirst.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com consent.cookiefirst.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de consent.cookiefirst.com edge.cookiefirst.com api.cookiefirst.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.any-lamp.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.any-lamp.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.any-lamp.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b428c232-f415-4fb2-b456-fef23ba335ec.sansec.watch/; report-to report-endpoint; 1 default-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.%2A.civiccomputing.com *.civiccomputing.com *.clarity.ms *.cloudflare.com *.googletagmanager.com *.jsdelivr.net *.library.wales; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws *.library.wales *.llgc.org.uk *.staticflickr.com *.ticketsource.co.uk fonts.gstatic.com play.google.com syndication.twitter.com translate.google.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.doubleclick.net *.googletagmanager.com *.libanswers.com *.library.wales *.llyfrgell.cymru *.lyfrgell.cymru *.twitter.com div.show hwb.gov.wales sketchfab.com www.canva.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.clarity.ms *.fontawesome.com *.libanswers.com *.library.wales connect.facebook.net fonts.googleapis.com; script-src-elem 'self' 'nonce-0eE8jsPdsAmCDaVNIyAngDGUoxhcNVnKOJ_ORtYYOUYGU-qtVVU6bg' https: 'unsafe-eval' blob: *.%2A.civiccomputing.com *.%2A.v2.scr.kaspersky-labs.com *.civiccomputing.com *.flickr.com *.googletagmanager.com *.libanswers.com adblockers.opera-mini.net connect.facebook.net s3.amazonaws.com wusote.hirizasune.com 'report-sample'; connect-src 'self' https: data: blob: wss: *.google.com https://*.googleapis.com https://*.gstatic.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; font-src 'self' https: data: blob: wss: https://fonts.gstatic.com; worker-src 'self' 'nonce-0eE8jsPdsAmCDaVNIyAngDGUoxhcNVnKOJ_ORtYYOUYGU-qtVVU6bg' blob:; style-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline' 'inline' 'report-sample'; report-uri https://www.library.wales/@http-reporting?csp=report&requestTime=1765935334407160&requestHash=904cf5cc4c8c5c584c4daabd2e67c267cb0536dc 1 font-src *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.sameday.ro *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org https://www.selfawb.ro *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.disqus.com *.avada.io *.shopify.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.sameday.ro *.google.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com https://pa.7w.ro http://pa.7w.ro 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://*.sameday.ro tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ecommerce.fancourier.ro https://nominatim.openstreetmap.org https://get.geojs.io *.avada.io http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com https://www.google-analytics.com https://pa.7w.ro http://pa.7w.ro 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://media.flixcar.com/ *.fontawesome.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.tiktok.com https://ipgtest.monri.com/ https://ipg.monri.com/ https://formtest.wspay.biz/ https://form.wspay.biz/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.googletagmanager.com https://ipgtest.monri.com/ https://ipg.monri.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com rt.flix360.com https://media.flixfacts.com/ https://media.flixcar.com/ *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com https://media.flixfacts.com/ https://media.flixcar.com/ https://ipgtest.monri.com/ https://ipg.monri.com/ *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://media.flixfacts.com/ https://media.flixcar.com/ *.fontawesome.com use.typekit.net p.typekit.net https://ipgtest.monri.com/ https://ipg.monri.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-uri https://1ea1b78a-0b70-4d23-b29e-391034d153e8.sansec.watch/; report-to report-endpoint; 1 script-src-elem *.oct8ne.com *.jsdelivr.net *.payments-amazon.com *.ittweb.net *.googletagmanager.com *.accelasearch.net *.accelasearch.io *.scalapay.com *.google.com *.gstatic.com; font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: *.accelasearch.io *.accelasearch.net *.flixcar.com *.flixfacts.com *.azureedge.net *.yotpo.com live.icecat.biz www.freeshop.it 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.yotpo.com www.freeshop.it 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com www.freeshop.it 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.flixcar.com *.criteo.com https://gum.criteo.com *.agos.it *.shopcall.io *.oct8ne.com *.azureedge.net *.salesmanago.pl https://secure.viewer.zmags.com/ *.googletagmanager.com *.yotpo.com www.freeshop.it 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://images.unsplash.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com validate.fishpig.co.uk *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com maps.gstatic.com https://via.placeholder.com https://widget.zoorate.com *.flixcar.com *.flix360.io *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.yahoo.com *.yahoo.net *.azureedge.net *.id5-sync.com *.google.it *.yotpo.com www.freeshop.it 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.feedaty.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com https://unpkg.com *.flix360.io *.flixcar.com https://widget.zoorate.com *.zendesk.com *.zdassets.com *.accelasearch.io *.accelasearch.net *.iubenda.com *.criteo.com *.criteo.net *.dwin1.com *.jsdelivr.net https://cas.zma.gs/ tracking.trovaprezzi.it www.trovaprezzi.it *.yotpo.com live.icecat.biz www.freeshop.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com *.feedaty.com *.fontawesome.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.stripe.network *.stripecdn.com *.amazon.com https://unpkg.com https://widget.zoorate.com *.accelasearch.io *.accelasearch.net *.flixcar.com *.jsdelivr.net *.freeshop.it https://cas.zma.gs/ *.yotpo.com live.icecat.biz www.freeshop.it 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.freeshop.it 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.feedaty.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.zendesk.com *.zdassets.com *.accelasearch.io *.iubenda.com *.flixcar.com *.oct8ne.com https://analytics.tiktok.com *.criteo.com *.yotpo.com live.icecat.biz www.freeshop.it 'self' 'unsafe-inline'; child-src www.freeshop.it http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com www.freeshop.it 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ js.mollie.com vars.hotjar.com app.usercentrics.eu cdn.lightwidget.com www.xtento.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://www.magezon.com https://www.mollie.com www.google.de *.cdninstagram.com app.usercentrics.eu bat.bing.com lt45.net www.xtento.com cdn.xtento.com www.google.com.ua maps.gstatic.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://unpkg.com *.google.com/ js.mollie.com static.hotjar.com script.hotjar.com bat.bing.com app.usercentrics.eu cdn.lightwidget.com *.clarity.ms cq.reellworld.com www.xtento.com cdn.xtento.com https://cdnjs.cloudflare.com maps.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com dt.reellworld.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com graph.instagram.com in.hotjar.com bat.bing.com graphql.usercentrics.eu api.usercentrics.eu aggregator.service.usercentrics.eu *.clarity.ms cq.reellworld.com www.google.de *.analytics.google.com *.google-analytics.com *.facebook.net dt.reellworld.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com 'self' data: validate.fishpig.co.uk magefan.com cm.magefan.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://cdn.ywxi.net https://verify.authorize.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com sc-static.net *.snapchat.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://cdn.ywxi.net *.livechatinc.com https://d1l7z5ofrj6ab8.cloudfront.net https://acsbapp.com *.cloudflare.com *.trustpilot.com *.polyfill.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com https://fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com sc-static.net *.snapchat.com *.doubleclick.net *.run.app *.typeform.com https://www.merchant-center-analytics.goog https://norgcdnstorage.blob.core.windows.net *.amazonaws.com *.acsbapp.com *.happyfoxchat.com happyfoxchat.com *.windows.net acsbapp.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com tbs.tradedoubler.com wickey.nl *.hotjar.com d3dc1lgancj6l0.cloudfront.net www.paypalobjects.com wickey.gateway.ford.neoday.cloud data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com wickey.us16.list-manage.com *.wickey.us16.list-manage.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.useberry.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com js.mollie.com *.trustpilot.com tbs.tradedoubler.com forms.office.com ct.pinterest.com *.hotjar.com d3dc1lgancj6l0.cloudfront.net www.youtube.com *.mollie.com www.paypalobjects.com *.wickey.de *.durchsichtig.xyz tw.wickey.co.uk tw.wickey.be twr.wickey.fr tw.wickey.gr tw.wickey.at tw.wickey.ch tw.wickey.it tw.wickey.es tw.wickey.pl tw.wickey.dk tw.wickey.cz tw.wickey.se tw.wickey.hu tw.wickey.no tw.wickey.ie tw.wickey.pt tw.wickey.ro tw.wickey.lu tw.wickey.sk tw.wickey.hr tw.wickey.bg tw.wickey.si twr.wickey.nl twr.wickey.de twr.wickey.at twr.wickey.ch twr.wickey.be twr.wickey.it twr.wickey.es twr.wickey.pl twr.wickey.dk twr.wickey.cz twr.wickey.se twr.wickey.hu twr.wickey.no twr.wickey.co.uk twr.wickey.ie twr.wickey.pt twr.wickey.ro twr.wickey.lu twr.wickey.sk twr.wickey.hr twr.wickey.bg twr.wickey.lt twr.wickey.si twr.wickey.gr js.neoday.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io github.blog https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com magefan.com cm.magefan.com https://www.mollie.com *.pixriot.com *.storeimaging.com *.ads.linkedin.com *.google-analytics.com *.bing.com bing.com *.trustedshops.com *.mollie.com *.pinterest.com *.consentmanager.net wickey.de wickey.nl tw.wickey.nl www.google.nl tw.wickey.de tw.wickey.at tw.wickey.ch tw.wickey.lu tw.wickey.fr tw.wickey.co.uk tw.wickey.ie tw.wickey.be tw.wickey.it tw.wickey.es tw.wickey.pt tw.wickey.dk tw.wickey.pl tw.wickey.cz tw.wickey.hu tw.wickey.sk tw.wickey.ro tw.wickey.hr tw.wickey.se tw.wickey.no tw.wickey.fi tw.wickey.bg www.google.fr www.google.de *.hotjar.com d3upe020n1uosc.cloudfront.net www.google.at www.google.ch www.google.lu www.google.co.uk www.google.ie www.google.be www.google.it www.google.es www.google.pt www.google.dk www.google.pl www.google.cz www.google.hu www.google.sk www.google.ro www.google.hr www.google.se www.google.no www.google.fi www.google.bg ik.imagekit.io cst-tag-monitor-2nd-gen-6k3dd6vtka-ew.a.run.app dashboard.edesk.com static.sooqr.com onlinedialogue.s3.eu-west-1.amazonaws.com t.squeezely.tech wickey.ams3.digitaloceanspaces.com wickey-test.ams3.digitaloceanspaces.com d2rfa446ja7yzb.cloudfront.net app.squeezely.tech tw.wickey.si tw.wickey.gr static.spotlersearch.com dy639ytn88nua.cloudfront.net bat.bing.net europe-west1-code-cube.cloudfunctions.net xsellco-blobstore.s3.amazonaws.com twr.wickey.nl twr.wickey.de twr.wickey.at twr.wickey.ch twr.wickey.fr twr.wickey.be twr.wickey.it twr.wickey.es twr.wickey.pl twr.wickey.dk twr.wickey.cz twr.wickey.se twr.wickey.hu twr.wickey.no twr.wickey.co.uk twr.wickey.ie twr.wickey.pt twr.wickey.ro twr.wickey.lu twr.wickey.sk twr.wickey.hr twr.wickey.bg twr.wickey.lt twr.wickey.si twr.wickey.gr *.clarity.ms *.flbx.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com js.mollie.com widgets.trustedshops.com bat.bing.com *.googleadservices.com connect.facebook.net bam.nr-data.net c.delivery.consentmanager.net cdn.consentmanager.net s.pinimg.com analytics.tiktok.com snap.licdn.com hst.tradedoubler.com swrap.tradedoubler.com static.cloudflareinsights.com tracking.s24.com tw.wickey.nl tw.wickey.de tw.wickey.at tw.wickey.ch tw.wickey.lu tw.wickey.fr tw.wickey.co.uk tw.wickey.ie tw.wickey.be tw.wickey.it tw.wickey.es tw.wickey.pt tw.wickey.dk tw.wickey.pl tw.wickey.cz tw.wickey.hu tw.wickey.sk tw.wickey.ro tw.wickey.hr tw.wickey.se tw.wickey.no tw.wickey.fi tw.wickey.bg delivery.consentmanager.net cdn.stape.io *.hotjar.com d3dc1lgancj6l0.cloudfront.net ajax.cloudflare.com d5yoctgpv4cpx.cloudfront.net onlinedialogue.s3.eu-west-1.amazonaws.com widgets.xsellco.com static.sooqr.com dynamic.sooqr.com *.neoday.com js.neoday.com cdn.ablyft.com squeezely.tech analytics.optimalpeople.fr connect.getflowbox.com ct.pinterest.com static.spotlersearch.com spotlersearchanalytics.com dynamic.spotlersearch.com *.wickey.de tr.kickbite.io clarity.ms www.clarity.ms fpp.wickey.nl fpp.wickey.co.uk fpp.wickey.gr fpp.wickey.at fpp.wickey.ch fpp.wickey.fr fpp.wickey.be fpp.wickey.it fpp.wickey.es fpp.wickey.dk fpp.wickey.pl fpp.wickey.cz fpp.wickey.se fpp.wickey.hu fpp.wickey.no fpp.wickey.ie fpp.wickey.pt fpp.wickey.ro fpp.wickey.lu fpp.wickey.sk fpp.wickey.hr fpp.wickey.bg fpp.wickey.lt fpp.wickey.si *.useberry.com stapecdn.com *.clarity.ms twr.wickey.nl twr.wickey.de twr.wickey.at twr.wickey.ch twr.wickey.fr twr.wickey.be twr.wickey.it twr.wickey.es twr.wickey.pl twr.wickey.dk twr.wickey.cz twr.wickey.se twr.wickey.hu twr.wickey.no twr.wickey.co.uk twr.wickey.ie twr.wickey.pt twr.wickey.ro twr.wickey.lu twr.wickey.sk twr.wickey.hr twr.wickey.bg twr.wickey.lt twr.wickey.si twr.wickey.gr wickey.gateway.ford.neoday.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com *.hotjar.com tagmanager.google.com widgets.xsellco.com static.sooqr.com static.spotlersearch.com js.neoday.com wickey.gateway.ford.neoday.cloud 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com d3dc1lgancj6l0.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.pixriot.com *.storeimaging.com ct.pinterest.com *.wickey.de stats.g.doubleclick.net analytics.tiktok.com bam.nr-data.net bat.bing.com www.google.com googleads.g.doubleclick.net region1.analytics.google.com region1.google-analytics.com tw.wickey.nl www.google.nl tw.wickey.de tw.wickey.at tw.wickey.ch tw.wickey.lu tw.wickey.fr tw.wickey.co.uk tw.wickey.ie tw.wickey.be tw.wickey.it tw.wickey.es tw.wickey.pt tw.wickey.dk tw.wickey.pl tw.wickey.cz tw.wickey.hu tw.wickey.sk tw.wickey.ro tw.wickey.hr tw.wickey.se tw.wickey.no tw.wickey.fi tw.wickey.bg www.google.fr www.google.de *.hotjar.com *.hotjar.io wss://*.hotjar.com d3upe020n1uosc.cloudfront.net d3dc1lgancj6l0.cloudfront.net www.google.at www.google.ch www.google.lu www.google.co.uk www.google.ie www.google.be www.google.it www.google.es www.google.pt www.google.dk www.google.pl www.google.cz www.google.hu www.google.sk www.google.ro www.google.hr www.google.se www.google.no www.google.fi www.google.bg rkkck31tec.execute-api.eu-central-1.amazonaws.com widgets.xsellco.com firehose.eu-central-1.amazonaws.com cognito-identity.eu-central-1.amazonaws.com wickey.gateway.ford.neoday.cloud log.ablyft.com analytics.pangle-ads.com analytics.optimalpeople.fr trustbadge.api.etrusted.com gateway.getflowbox.com a.getflowbox.com tw.wickey.si tw.wickey.gr api.trustedshops.com shops-si.trustedshops.com api.trustbadge.etrusted.com px.ads.linkedin.com api.paypal.com *.durchsichtig.xyz tr.kickbite.io bat.bing.net p2iqhncxyh.execute-api.eu-central-1.amazonaws.com j.clarity.ms n.clarity.ms s.clarity.ms k.clarity.ms twr.wickey.fr fpp.wickey.nl u.clarity.ms i.clarity.ms fpp.wickey.co.uk d.clarity.ms fpp.wickey.be fpp.wickey.ch twr.wickey.nl twr.wickey.de twr.wickey.at twr.wickey.ch twr.wickey.be twr.wickey.it twr.wickey.es twr.wickey.pl twr.wickey.dk twr.wickey.cz twr.wickey.se twr.wickey.hu twr.wickey.no twr.wickey.co.uk twr.wickey.ie twr.wickey.pt twr.wickey.ro twr.wickey.lu twr.wickey.sk twr.wickey.hr twr.wickey.bg twr.wickey.lt twr.wickey.si twr.wickey.gr guarantee-log.trustedshops.com ad.doubleclick.net *.clarity.ms fpp.wickey.pt fpp.wickey.ro fpp.wickey.se fpp.wickey.sk fpp.wickey.lt fpp.wickey.si fpp.wickey.hr fpp.wickey.no 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://wickey.de/; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.canadapost.ca https://sso.epost.ca *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.authorize.net api.demo.convergepay.com api.convergepay.com convergepay.com google.com gstatic.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ mageside.com *.canadapost.ca *.canadapost-postescanada.ca https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.authorize.net sandbox-assets.secure.checkout.visa.com api.demo.convergepay.com api.convergepay.com convergepay.com google.com gstatic.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.authorize.net api.demo.convergepay.com api.convergepay.com convergepay.com gstatic.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com *.google.com https://platform.twitter.com https://www.googletagmanager.com https://www.google-analytics.com/ https://www.xj-storage.jp/public-graph/table/AS02420/ https://www.xj-storage.jp/public-graph-at/table/AS02420/ https://www.xj-storage.jp/public-list/ https://cache.dga.jp/s/sanyodk/ https://www.xj-storage.jp/resources/AS02420/ https://al-s.dc-tag.jp/dcam.min.js https://static.ctctcdn.com/js/signup-form-widget/current/signup-form-widget.min.js https://cdnjs.cloudflare.com/ajax/ https://platform.twitter.com/widgets.js https://www.clarity.ms/ https://extend.vimeocdn.com/ga/ https://cdn.cookie.sync.usonar.jp/ https://ip2c.landscape.co.jp/lbcapi/ https://apis.usonar.jp/alog/ https://partner.googleadservices.com/ https://cookie.sync.usonar.jp/v1/ https://www.gstatic.com/ https://kitchen.juicer.cc/ https://cdn.kitchen.juicer.cc/ https://cdn.treasuredata.com/sdk/1.9.1/td.min.js https://cdn.id5-sync.com/api/1.0/id5-api.js https://dmp.im-apps.net/ https://in.treasuredata.com/ https://s.dc-tag.jp/ https://cdn.audiencedata.net/ snap.licdn.com px.ads.linkedin.com px4.ads.linkedin.com p.adsymptotic.com cdn.linkedin.oribi.io gw.linkedin.oribi.io dc.ads.linkedin.com sjs.bizographics.com https://app.trust360.jp/js/consent-multi-language.js https://apisonar.go.usonar.jp/liveaccess/js/call.js https://usa-cooling.sanyodenki.com/pd.js https://usa-servo.sanyodenki.com/pd.js https://unpkg.com/@google/model-viewer/dist/model-viewer.min.js https://unpkg.com/@google/model-viewer/dist/model-viewer-legacy.js https://js.hs-scripts.com/22560505.js https://js.hsforms.net/forms/embed/v2.js https://scripts.clarity.ms/ https://sanyodenkiamerica--agentforce.sandbox.my.site.com/ 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.com.tr https://www.myheritage.com.tr 'unsafe-eval' 'nonce-a77645514641aedec72692bd688c1186' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.com.tr;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.jaggaer.com data: 'self' 'unsafe-inline'; form-action *.paypal.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com https://*.facebook.com t.svtrd.com *.navitor.com *.emjcd.com *.coupahost.com *.fa.ocs.oraclecloud.com *.unimarket.com *.appl.kp.org *.jaggaer.com 'self' 'unsafe-inline'; frame-ancestors statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.google.com *.jaggaer.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.us.confirmit.com cm.everesttech.net *.adobedtm.com https://*.doubleclick.net *.kaltura.com *.pinterest.com insight.adsrvr.org match.adsrvr.org *.linkedin.com *.linkedin.oribi.io https://*.facebook.com *.licdn.com p.adsymptotic.com sjs.bizographics.com s.pinimg.com t.svtrd.com *.powerapps.com https://www.google.com https://*.googlesyndication.com https://tpc.googlesyndication.com googleads.g.doubleclick.net *.jaggaer.com https://*.usercentrics.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.dotomi.com *.us.confirmit.com *.eum-appdynamics.com *.googleapis.com cm.everesttech.net *.adobedtm.com https://*.doubleclick.net *.kaltura.com px.ads.linkedin.com t.co *.pinterest.com bam.nr-data.net *.googleadservices.com *.google.com https://*.twitter.com *.linkedin.com https://*.facebook.com *.instagram.com *.thetradedesk.com *.upsellit.com *.magentocommerce.com maps.gstatic.com *.ggpht.com *.google.co.in t.svtrd.com *.emjcd.com idsync.rlcdn.com https://www.google.com https://*.printful.com https://*.googlesyndication.com *.jaggaer.com https://*.companybox.com https://alb.reddit.com https://*.usercentrics.eu https://cdn.bfldr.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://cdn.appdynamics.com https://www.fedex.com https://www.kaltura.com https://digitalfeedback.us.confirmit.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.us.confirmit.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.yotpo.com cm.everesttech.net *.kaltura.com *.pinterest.com * bam.nr-data.net *.newrelic.com/nr-spa-1210.min.js *.authorize.net *.googleadservices.com *.google-analytics.com js.braintreegateway.com includestest.ccdc02.com cdn.dnky.co insight.adsrvr.org match.adsrvr.org js.adsrvr.org https://*.twitter.com static.ads-twitter.com *.linkedin.com *.linkedin.oribi.io https://*.facebook.com *.instagram.com *.thetradedesk.com *.licdn.com p.adsymptotic.com sjs.bizographics.com s.pinimg.com *.upsellit.com *.emjcd.com https://www.google.com *.coupahost.com *.fa.ocs.oraclecloud.com *.unimarket.com *.appl.kp.org https://*.googlesyndication.com *.jaggaer.com https://*.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.googleapis.com *.jaggaer.com 'self' 'unsafe-inline'; object-src statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.emjcd.com *.jaggaer.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.jaggaer.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.emjcd.com *.jaggaer.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.us.confirmit.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.yotpo.com *.eum-appdynamics.com *.googleapis.com *.qualtrics.com *.omtrdc.net cm.everesttech.net *.adobedtm.com *.tt.omtrdc.net https://*.doubleclick.net cdn.linkedin.oribi.io *.kaltura.com px.ads.linkedin.com t.co smetrics.fedex.com *.pinterest.com *.google-analytics.com insight.adsrvr.org https://*.twitter.com *.linkedin.com https://*.facebook.com *.demdex.net analytics.tiktok.com *.emjcd.com https://www.google.com https://*.printful.com https://*.googlesyndication.com googleads.g.doubleclick.net *.jaggaer.com https://*.companybox.com https://pixel-config.reddit.com https://conversions-config.reddit.com https://www.redditstatic.com https://test-drive-10-s6uit34pua-uc.a.run.app https://analytics-ipv6.tiktokw.us https://*.usercentrics.eu https://mpc-prod-18-s6uit34pua-uc.a.run.app/events/e413553fc3f0447fdf7a46e1280e85669692467156f617106c492397efb8111a 'self' 'unsafe-inline'; child-src statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.jaggaer.com https://*.usercentrics.eu http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.us.confirmit.com *.emjcd.com *.jaggaer.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri statefarm.com statefarm-local.com *.statefarm-local.com:59443 *.sciquest.com *.tulsacc.edu *.mckesson.com *.suntrust.com *.bbt.com *.deloitte.com *.ncsu.edu *.ariba.com *.kaiser.com *.aquiire.net *.vanderbilt.edu *.wayne.edu *.contentsquare.net *.fedex.com *.appdynamics.com *.newrelic.com *.canva.com *.mczbf.com *.afcyhf.com *.anrdoezrs.net *.apmebf.com *.awltovhc.com *.dotomi.com *.dpbolvw.net *.ftjcfx.com *.jdoqocy.com *.kqzyfj.com *.lduhtrp.net *.mjbpab.com *.qksrv.net *.qksz.net *.tkqlhce.com *.tqlkg.com *.awxibrm.com *.cj.com *.cj.mplxtms.com *.commission-junction.com *.sjwoe.com *.cualbr.com *.kdukvh.com *.pkracv.com *.rnsfpw.net *.vofzpwh.com *.yceml.net *.www.cj.conversant.mgr.consensu.org *.www.p.zjptg.com *.emjcd.com *.jaggaer.com 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.klarnacdn.net *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com eadn-wc03-463152.nxedge.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com customneon.com customneon.com.au customneon.co.uk/ eadn-wc02-9281796.nxedge.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self' https://support.customneon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.google.com/ www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.klarna.com *.twitter.com *.consensu.org *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com checkout.bluesnap.com ssl.kaptcha.com portal.afterpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://www.magezon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.co.in lh3.googleusercontent.com phosphor.utils.elfsightcdn.com px.ads.linkedin.com d.adroll.com bat.bing.com *.google.com *.google.com.au eadn-wc02-9281796.nxedge.io *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com apis.google.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.sharethis.com *.googletagmanager.com *.facebook.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com static.elfsight.com apps.elfsight.com maps.googleapis.com cdn.audiencelab.io s.adroll.com d.adroll.com static.zdassets.com cdn.websitepolicies.io snap.licdn.com ssl.kaptcha.com universe-static.elfsightcdn.com sandbox.bluesnap.com ws.bluesnap.com bat.bing.com pixel.dashfi.dev ct.pinterest.com *.clarity.ms ipinfo.io eadn-wc02-9281796.nxedge.io https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.fontawesome.com https://static.klaviyo.com *.klarnacdn.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com cdn.websitepolicies.io eadn-wc02-9281796.nxedge.io tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com *.amazon.com static.elfsight.com apps.elfsight.com service-reviews-ultimate.elfsight.com maps.googleapis.com ekr.zdassets.com pixel.audiencelab.io app.audiencelab.io pro.ip-api.com a.usbrowserspeed.com storage.elfsight.com customneon.zendesk.com stats.g.doubleclick.net d.adroll.com cdn.linkedin.oribi.io core.service.elfsight.com portal.afterpay.com ssl.kaptcha.com custom-neon.ts.r.appspot.com px.ads.linkedin.com www.facebook.com *.clarity.ms pixel.tracking.blokid.com *.google.com.au pixel.dashfi.dev eadn-wc02-9281796.nxedge.io https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com landofcoder.com maps.googleapis.com chart.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.cdninstagram.com *.fbcdn.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com landofcoder.com maps.googleapis.com chart.googleapis.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com widget.freshworks.com m2epro.freshdesk.com landofcoder.com maps.googleapis.com chart.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.tawk.to 'self' data: maxcdn.bootstrapcdn.com *.sagepay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cashfree.com *.cardinalcommerce.com *.ccavenue.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.sagepay.com *.arcot.com *.analytics.com *.googleadservices.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cashfree.com *.cardinalcommerce.com www.googletagmanager.com *.twitter.com *.addthis.com *.doubleclick.net *.embedly.com *.rvvup.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.addtoany.com *.hotjar.com *.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.sagepay.com *.arcot.com *.analytics.com *.googleadservices.com https://lightwidget.com *.chatra.io *.lightwidget.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cashfree.com https://images.unsplash.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.ccavenue.com *.cloudflare.com *.klarna.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.co.in *.jsdelivr.net www.independent4life.co.uk www.logicrays.com www.magecomp.com *.amazonaws.com *.securitymetrics.com *.pinterest.com https://meetanshi.com/media/logo.png www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.sagepay.com ebizmarts-website.s3.amazonaws.com *.analytics.com https://cdn-media.vega.co.in https://cdnmedia.vega.co.in https://breeze.vega.co.in https://breeze-media.vega.co.in data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cashfree.com *.cardinalcommerce.com *.googleapis.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu embed.tawk.to cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.addtoany.com *.adobe.com *.hotjar.com *.clarity.ms *.avada.io *.pinterest.com www.facebook.com graph.facebook.com business.facebook.com *.sagepay.com *.arcot.com *.analytics.com *.lightwidget.com *.chatra.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.jsdelivr.net *.google.com *.addtoany.com maxcdn.bootstrapcdn.com *.sagepay.com *.analytics.com *.googleadservices.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.granberg.se 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cardinalcommerce.com *.cashfree.com *.googleapis.com https://player.vimeo.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.cloudflare.com *.twitter.com *.twimg.com *.tawk.to *.doubleclick.net *.amazonaws.com *.securitymetrics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com wss://ws.hotjar.com/ *.clarity.ms *.hotjar.io *.googleadservices.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.addtoany.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.sagepay.com *.arcot.com *.analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com images.latitudepayapps.com imageapi.magebinary.co.nz *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.images.latitudepayapps.com *.imageapi.magebinary.co.nz *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com checkout.instant.one staging.checkout.instant.one c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com js.instant.one *.fontawesome.com *.googleapis.com *.gstatic.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com fonts.googleapis.com images.latitudepayapps.com/ imageapi.magebinary.co.nz/ *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.instant.one api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src custom.intucdn.com api.instant.one *.images.latitudepayapps.com *.imageapi.magebinary.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: *.fontawesome.com *.adobe.com *.facebook.com *.facebook.net *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://test.oppwa.com/ https://oppwa.com/ https://www.datafast.com.ec/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: https://test.oppwa.com/ https://oppwa.com/ https://www.datafast.com.ec/ magefan.com cm.magefan.com mageside.com www.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.customily.com https://*.amazonaws.com https://*.mapbox.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ s7.addthis.com *.mgt.com www.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.mapbox.com https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ *.fontawesome.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com *.tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.customily.com https://*.amazonaws.com https://*.mapbox.com 'self' data: https://test.oppwa.com/ https://oppwa.com/ https://eu-prod.oppwa.com/ https://www.datafast.com.ec/ ekr.zdassets.com/ https://get.geojs.io *.mgt.com *.adobe.com www.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.youtube.com *.vimeo.com *.vimeocdn.com connect.facebook.net graph.facebook.com business.facebook.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' pxlfsn.co www.google-analytics.com maps.googleapis.com ajax.googleapis.com www.google.com google.com gstatic.com www.gstatic.com connect.facebook.net facebook.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.cdnfonts.com *.cloudflare.com *.bootstrapcdn.com 'unsafe-inline' data: *.fontawesome.com https://fonts.bunny.net *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net www.wwhardware.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com www.wwhardware.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com www.wwhardware.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com platform.twitter.com *.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.yotpo.com www.wwhardware.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com *.wwhardware.com pixel.tapad.com ml314.com *.cloudflare.com *.bing.com *.zonos.com *.marchex.io *.google.com *.pinterest.com *.adroll.com ads.yahoo.com *.bidswitch.net *.adnxs.com *.rlcdn.com *.openx.net *.company-target.com *.instinctiveads.com *.dca0.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.sezzle.com *.yotpo.com dhv2ziothpgrr.cloudfront.net www.wwhardware.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com *.certcapture.com *.cloudflare.com *.twitter.com *.fontawesome.com *.marchex.io *.hotjar.com *.bing.com *.googletagmanager.com *.pinterest.com http://chimpstatic.com *.zonos.com *.adroll.com *.dca0.com *.attn.tv https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdn.jsdelivr.net *.avada.io *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www.wwhardware.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com https://static.klaviyo.com https://fonts.bunny.net assets.braintreegateway.com fonts.cdnfonts.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net www.wwhardware.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.wwhardware.com www.wwhardware.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com a.klaviyo.com *.cloudflare.com *.hotjar.com *.zonos.com *.google-analytics.com *.doubleclick.net *.adroll.com *.dca0.com *.attentivemobile.com *.attn.tv https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www.wwhardware.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com www.wwhardware.com http: https: blob: 'self' 'unsafe-inline'; default-src www.wwhardware.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.wwhardware.com/; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com v2.zopim.com *.klarnacdn.net *.honey.io *.fontawesome.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com https://www.gstatic.com https://fonts.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com www.facebook.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.youtube.com *.youtube-nocookie.com *.pinterest.com *.paypal.com *.google.com assets.braintreegateway.com https://ssl.kaptcha.com *.klarna.com https://js.playground.klarna.com *.criteo.com *.opayo.eu.elavon.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw account.fetchify.com platform.twitter.com *.cdn-apple.com pay.google.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com v2.zopim.com bat.bing.com ct.pinterest.com *.google.gr *.paypal.com *.klarnacdn.net *.clarity.ms *.bing.com *.criteo.com *.yahoo.com *.yahoo.net *.bidswitch.net *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.mediavine.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.adform.net *.omnitagjs.net *.omnitagjs.com id5-sync.com *.ivitrack.com *.tremorhub.com *.yieldlab.net *.yieldmo.com *.krxd.net *.thebrighttag.com *.postrelease.com *.emxdgt.com dividebuy.co.uk *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com https://www.magezon.com pinterest.com assets.pinterest.com syndication.twitter.com *.designer-images.net https://redchamps.com *.revolut.com *.google.com *.cdn-apple.com pay.google.com maps.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.google.com *.google.bg *.googletagmanager.com connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com static.zdassets.com v2.zopim.com s.pinimg.com s.kk-resources.com bat.bing.com *.paypal.com *.google.com *.klarnaservices.com *.klarnacdn.net *.klarna.com *.zopim.com *.clarity.ms searchserverapi.com *.particularaudience.com *.tiktok.com *.criteo.com player.vimeo.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com twitter.com platform.twitter.com *.stat-track.com polyfill.io *.moosend.com *.revolut.com *.cdn-apple.com pay.google.com https://www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klarnacdn.net searchserverapi.com *.honey.io *.finance-calculator.co.uk *.fontawesome.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com maxcdn.bootstrapcdn.com fonts.googleapis.com *.moosend.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net google.com *.doubleclick.net *.googlesyndication.com ekr.zdassets.com wss://widget-mediator.zopim.com ct.pinterest.com stats.g.doubleclick.net bat.bing.com *.braintree-api.com *.paypal.com *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.braintreegateway.com *.clarity.ms *.particularaudience.com *.tiktok.com *.google.com *.zendesk.com *.criteo.com vimeo.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.stat-track.com *.m-pages.com *.m-operations.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.sharethis.com www.xtento.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * *.sharethis.com https://cdn.clerk.io *.openstreetmap.org https://maps.googleapis.com *.cloudfront.net *.facebook.com www.google.it *.clarity.ms *.bing.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com www.google.com.ua data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com https://api.clerk.io https://cdn.clerk.io cdnjs.cloudflare.com *.clerk.io *.clarity.ms connect.facebook.net *.cloudfront.net *.bing.com www.xtento.com cdn.xtento.com *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com network.oliunid.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.openstreetmap.org https://maps.googleapis.com stats.g.doubleclick.net *.clarity.ms *.facebook.com *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com network.oliunid.com https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests ; frame-ancestors *.bytedance.com self *.bytedance.net fanqienovel.com usergrowth.com.cn bytegrowth.com; frame-src bytegrowth.com usergrowth.com.cn fanqienovel.com *.bytedance.net self *.bytedance.com; object-src 'none'; base-uri 'none'; report-to slardar-endpoint; 1 worker-src *.ceneo.pl https://webep1.com https://webetech.pl *.tiktok.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com 'self' data: *.ekomi.com *.cloudflare.com *.bootstrapcdn.com *.twitter.com *.easypack24.net *.google.pl *.google.com *.inpost.pl *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ secure.payu.com merch-prod.snd.payu.com *.ekomi.com *.ceneo.pl *.dpd.com.pl *.cookiebot.com/ *.inpost.pl *.googletagmanager.com *.doubleclick.net *.facebook.com *.tiktok.com https://player.vimeo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com static.payu.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.ekomi.com *.amazonaws.com *.imgur.com *.ekomiapps.de *.tile.osm.org *.cloudflare.com *.githubusercontent.com *.googleadservices.com *.twitter.com *.facebook.com *.magentocommerce.com *.salesmanago.pl *.salesmanago.com *.salesmanago.es *.sysadvisors.pl *.google.pl *.google.com *.cookiebot.com *.inpost.pl *.doubleclick.net blob: *.ceneo.pl *.hotjar.com https://almamed.pl data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com apis.google.com *.gstatic.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io https://cdnjs.cloudflare.com *.payu.com secure.snd.payu.com *.hsforms.net *.hsforms.com *.googletagmanager.com tagmanager.google.com *.ekomi.com *.ekomiapps.de *.hotjar.com *.sysadvisors.pl *.magentocommerce.com *.braintreegateway.com *.githubusercontent.com *.paypall.com *.paypal.com *.cardinalcommerce.com *.authorize.net *.salesmanago.pl *.salesmanago.com *.salesmanago.es *.facebook.net *.facebook.com *.cloudflare.com *.twitter.com *.fontawesome.com *.google-analytics.com *.google.pl *.trustedshops.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com graph.facebook.com *.ekomiapss.de *.easypack24.net *.allekurier.pl *.cookiebot.com *.inpost.pl *.doubleclick.net *.googleadservices.com ssl.ceneo.pl *.pagead.google.com *.pagead.google.pl *.googlesyndication.com *.adservice.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com *.ekomi.com *.ekomiapps.de *.sysadvisors.pl *.cloudflare.com *.bootstrapcdn.com *.ekomiapss.de *.easypack24.net *.google.pl *.google.com *.inpost.pl *.googletagmanager.com *.doubleclick.net *.cookiebot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.ekomi.com *.ekomiapps.de *.cloudflare.com *.tile.osm.org *.openstreetmap.org *.twitter.com *.sysadvisors.pl *.salesmanago.pl *.googleadservices.com *.google.pl *.googlesyndication.com *.cookiebot.com *.saleago.com *.hotjar.com *.doubleclick.net *.inpost.pl wss://ws.hotjar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.ekomi.com *.tile.osm.org *.openstreetmap.org *.paypal.com *.google.pl *.google.com *.inpost.pl *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /zsteam_csp; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.8wines.com *.8wines.de *.8wines.cz *.8wines.it *.8wines.pl *.8wines.nl *.8wines.fr *.8wines.be *.tawk.to *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ www.google.com js.stripe.com *.fls.doubleclick.net *.facebook.com *.awin1.com *.zenaps.com https://accounts.google.com https://bid.g.doubleclick.net *.kaptcha.com/ https://app.usercentrics.eu https://sandbox.bluesnap.com https://ad4m.at https://www.bluesnap.com https://checkout.bluesnap.com https://www.awin1.com https://ad.ad-srv.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.googletagmanager.com x.adroll.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com data: 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com flagpedia.net https://redchamps.com 8wines.com *.8wines.com *.8wines.de *.8wines.cz *.8wines.it *.8wines.pl *.8wines.nl *.8wines.fr *.8wines.be http://bat.bing.com https://www.google.com https://www.google.com.ua https://widgets.trustedshops.com *.inspectlet.com https://t.co https://analytics.twitter.com https://sp.analytics.yahoo.com https://integrations.etrusted.com https://app.usercentrics.eu https://www.heureka.cz https://mywebconect.com https://ad.yieldlab.ne https://as.ad4m.at https://x.bidswitch.net https://dsum-sec.casalemedia.com https://ad.yieldlab.net https://glp8.net https://www.awin1.com https://www.wepowerconnections.com https://usync.vrtcal.com https://rtb-csync.smartadserver.com https://ad.360yield.com https://sync.outbrain.com https://pixel.rubiconproject.com https://inv-nets.admixer.net https://ups.analytics.yahoo.com https://e1.emxdgt.com https://sync-eu.connectad.io https://s.ad.smaato.net https://s.pubmine.com https://ih.adscale.de https://simage2.pubmatic.com https://a.twiago.com https://csync.loopme.me https://ad11.adfarm1.adition.com https://dsum.casalemedia.com https://d3k81ch9hvuctc.cloudfront.net https://uct.service.usercentrics.eu https://c1.adform.net *.adform.net https://sync.1rx.io https://us-u.openx.net x.adroll.com d.adroll.com idsync.rlcdn.com image2.pubmatic.com ml314.com pixel.tapad.com sync.taboola.com eb2.3lift.com ib.adnxs.com um.simpli.fi capi.connatix.com lrp.mxptint.net cs.media.net rtb.adentifi.com c.bing.com tags.rd.linksynergy.com cm.adgrx.com bcp.crwdcntrl.net sync.ipredictive.com sync.tidaltv.com segments.company-target.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com *.google.bg https://www.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://accounts.google.com *.disqus.com maps.googleapis.com 8wines.com *.8wines.com *.8wines.de *.8wines.cz *.8wines.it *.8wines.pl *.8wines.nl *.8wines.fr *.8wines.be *.trustedshops.com https://embed.tawk.to http://bat.bing.com https://googleads.g.doubleclick.net *.tawk.to https://cdn.jsdelivr.net *.inspectlet.com *.bluesnap.com https://static.ads-twitter.com https://integrations.etrusted.com https://app.usercentrics.eu https://analytics.tiktok.com https://s.yimg.com https://s.retargeted.co https://app.ardalio.com https://js.admediasales.com https://s2.adform.net https://track.adform.net https://im9.cz https://static.cloudflareinsights.com https://www.dwin1.com https://pix.hyj.mobi https://analytics.webgains.io https://ad4m.at https://www.awin1.com https://www.wepowerconnections.com https://tm.ad-srv.net https://c.seznam.cz https://ehub.cz https://postback.affiliateport.eu https://tag.facemyads.co https://ct.beslist.nl https://www.google.com https://www.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://widgets.trustedshops.com *.termly.io s.adroll.com d.adroll.com s.kk-resources.com widget.usersnap.com www.clarity.ms trkwwtarget.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com 8wines.com *.8wines.com *.8wines.de *.8wines.cz *.8wines.it *.8wines.pl *.8wines.nl *.8wines.fr *.8wines.be https://fonts.googleapis.com *.jsdelivr.net *.inspectlet.com https://integrations.etrusted.com https://embed.tawk.to *.stripe.network *.stripecdn.com *.amazon.com https://widgets.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://stats.addtoany.com/menu *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.wepowerconnections.com https://the.sciencebehindecommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.gstatic.com maps.googleapis.com 8wines.com *.8wines.com *.8wines.de *.8wines.cz *.8wines.it *.8wines.pl *.8wines.nl *.8wines.fr *.8wines.be https://stats.g.doubleclick.net https://www.google-analytics.com *.tawk.to wss://vsa2.tawk.to https://www.google.com *.inspectlet.com wss://ws.inspectlet.com/ https://integrations.etrusted.com https://googleads.g.doubleclick.net https://s.yimg.com https://analytics.tiktok.com https://api.usercentrics.eu https://aggregator.service.usercentrics.eu https://api.trustedshops.com https://shops-si.trustedshops.com https://api.trustbadge.etrusted.com https://trustbadge.api.etrusted.com https://api.retargeted.co wss://vsa121.tawk.to wss://vsa5.tawk.to wss://vsa32.tawk.to wss://vsa55.tawk.to wss://vsa65.tawk.to https://www.wepowerconnections.com wss://*.tawk.to https://t.affiliateport.eu https://app.ardalio.com https://consent-api.service.consent.usercentrics.eu *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustedshops.com *.etrusted.com app.termly.io u.clarity.m u.clarity.ms d.adroll.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://www.facebook.com/tr/ https://*.google-analytics.com/*/; font-src 'self'; form-action 'self' https://paiement.systempay.fr/vads-payment/ https://www.facebook.com/tr/ https://*.ads.linkedin.com; frame-src https://www.youtube-nocookie.com; img-src 'self' data: https://img.youtube.com https://i.ytimg.com https://ressources.carross.eu https://ressources.carross.local https://www.google-analytics.com https://11599994.fls.doubleclick.net https://ad.doubleclick.net https://www.facebook.com/tr/ https://*.ads.linkedin.com https://www.linkedin.com/px; script-src 'report-sample' 'self' 'unsafe-inline' https://www.googletagmanager.com/gtm.js https://www.google-analytics.com/analytics.js https://www.google-analytics.com/plugins/ua/ec.js https://www.googletagmanager.com/gtag/js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/3051721451810486 https://snap.licdn.com/li.lms-analytics/insight.min.js; style-src 'report-sample' 'self' 'unsafe-inline'; block-all-mixed-content; upgrade-insecure-requests; frame-ancestors; base-uri 'self'; report-uri /csp-parser 1 script-src-elem wardrobesupplies.com *.wardrobesupplies.com assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net assets.braintreegateway.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://static.hotjar.com https://googleads.g.doubleclick.net https://www.clarity.ms https://www.google-analytics.com https://www.google.com https://vendor1.quickspark.com https://cdn.timepayment.com eadn-wc01-211045.nxedge.io js.klevu.com *.klevu.com chimpstatic.com static.klaviyo.com static-tracking.klaviyo.com embed.tawk.to jsappcdn.hikeorders.com js.stripe.com *.stripe.com scripts.clarity.ms www.gstatic.com *.gstatic.com; style-src-elem *.adobe.com assets.braintreegateway.com 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.fontawesome.com *.cloudflare.com *.paypal.com *.stripe.com *.klarna.com *.klevu.com *.yotpo.com; font-src *.klevu.com *.ksearchnet.com *.gstatic.com *.fontawesome.com *.googleapis.com https://www.google.com https://www.gstatic.com https://fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com data: 'self' 'unsafe-inline' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net https://meetanshi.com/media/logo.png www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://shareasale.com/sale.cfm https://plumrocket.com https://cache.addthiscdn.com/ c.clarity.ms *.clarity.ms wardrobesupplies.com *.wardrobesupplies.com 'self' *.yotpo.com 'unsafe-inline' data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.croapp.net chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.dwin1.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com secure.authorize.net test.authorize.net *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' *.yotpo.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline' *.yotpo.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.google-analytics.com *.google.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com wardrobesupplies.com *.wardrobesupplies.com *.yotpo.com 'self' 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net cdn.jsdelivr.net cdn.almapay.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.getalma.eu *.almapay.com/ *.hipay-tpp.com *.hipay.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com cdn.jsdelivr.net *.almapay.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.almapay.com *.hipay.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.almapay.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com https://player.vimeo.com https://www.youtube-nocookie.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com flagpedia.net *.mobbex.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com https://redchamps.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.google.com *.google.fr *.google.ie www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maps.googleapis.com *.mobbex.com https://player.vimeo.com https://www.youtube.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.gstatic.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.gstatic.com *.mobbex.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com tinyblessings.com tinyblessings.com/media https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com *.tinyblessings.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com *.zendesk.com *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com maxcdn.bootstrapcdn.com tagmanager.google.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com *.zendesk.com *.zopim.com wss://*.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; connect-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; script-src https: 'unsafe-eval' 'unsafe-inline'; media-src https: 'self' blob:; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 1 font-src *.fiskejournalen.com *.cloudfront.net https://fonts.gstatic.com *.klarna.com *.kustom.co *.klarnacdn.net *.pji.nu maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://local.fiskejournalen.com *.klarna.com *.kustom.co https://www.googletagmanager.com *.cloudfront.net *.doubleclick.net https://www.facebook.com https://www.google.com *.googlesyndication.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.dycdn.net https://local.fiskejournalen.com *.cloudfront.net *.fiskejournalen.se *.bing.com https://fonts.gstatic.com https://stats.g.doubleclick.net https://www.facebook.com *.google.com *.google.co.in https://apis.google.com *.clarity.ms *.klarna.com *.kustom.co *.klarnaevt.com *.doubleclick.net https://www.googletagmanager.com *.googlesyndication.com *.dialogtrail.com *.amazonaws.com *.cookiepro.com *.streamify.io *.videoly.co https://cdn-cookieyes.com *.klarnacdn.net *.disqus.com https://meetanshi.com/media/logo.png *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com *.fiskejournalen.com *.cloudfront.net https://bat.bing.com *.google.com *.google.co.in *.gstatic.com *.videoly.co https://track.adtraction.com https://static.zdassets.com/ https://apis.google.com https://www.googletagmanager.com https://connect.facebook.net https://www.googleapis.com https://checkoutapi.svea.com *.klarna.com *.kustom.co *.klarnaservices.com *.clarity.ms https://www.google.se securepubads.g.doubleclick.net https://www.gstatic.com *.googlesyndication.com *.googletagservices.com *.tiktok.com https://dialogtrail-prod.s3-eu-west-1.amazonaws.com *.dialogtrail.com *.cookiepro.com *.googleoptimize.com *.pji.nu *.streamify.io *.holid.io https://cdn-cookieyes.com *.klarnacdn.net x.klarnacdn.net *.disqus.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net https://local.fiskejournalen.com *.cloudfront.net https://fonts.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com *.klarna.com *.kustom.co *.klarnacdn.net *.pji.nu *.streamify.io maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src https://local.fiskejournalen.com https://test.fiskejournalen.se *.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com https://local.fiskejournalen.com *.cloudfront.net https://butik.fiskejournalen.se https://butik1.fiskejournalen.se https://static.zdassets.com *.klarna.com *.kustom.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net *.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com https://local.fiskejournalen.com *.cloudfront.net *.klarnaevt.com *.klarna.com *.kustom.co *.klarnaservices.com *.clarity.ms https://www.facebook.com https://www.google.com https://stats.g.doubleclick.net https://www.google-analytics.com https://fiskejournalen.zendesk.com https://widget-mediator.zopim.com wss://widget-mediator.zopim.com *.doubleclick.net *.googlesyndication.com *.google.com *.bing.com *.gstatic.com *.tiktok.com *.dialogtrail.com wss://widget.dialogtrail.com *.cookiepro.com *.onetrust.com *.streamify.io *.jsdelivr.net wss://wss.streamify.io/ https://cdn-cookieyes.com https://log.cookieyes.com *.klarnacdn.net x.klarnacdn.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googlesyndication.com *.cloudfront.net *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com *.fontawesome.com applepay.cdn-apple.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.monetico-services.com consentcdn.cookiebot.com consentcdn.cookiebot.eu c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org magefan.com cm.magefan.com imgsct.cookiebot.com imgsct.cookiebot.eu *.hsforms.net *.hsforms.com *.google.fr *.google.com https://bat.bing.com https://img.youtube.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net consent.cookiebot.com consent.cookiebot.eu s7.addthis.com *.hsforms.net *.hsforms.com widget.azu.levia.ai *.cookiebot.com cdn.almapay.com static.zdassets.com *.zendesk.com *.zopim.com googleads.g.doubleclick.net bat.bing.com *.googletagmanager.com *.facebook.net www.termsfeed.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com api.fontshare.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.monetico-services.com consentcdn.cookiebot.com consentcdn.cookiebot.eu ekr.zdassets.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com https://itjustgood.zendesk.com wss://widget-mediator.zopim.com https://ekr.zdassets.com https://bat.bing.com *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://pixel.veritone-ce.com https://tag.simpli.fi https://www.gstatic.com https://ajax.googleapis.com https://*.googletagmanager.com https://www.googleadservices.com https://js.adsrvr.org https://www.google.com https://googleads.g.doubleclick.net https://ajax.aspnetcdn.com/ https://rules.quantcount.com/ https://secure.quantserve.com/ https://acdn.adnxs.com/ https://unpkg.com/ https://connect.facebook.net/ https://use.typekit.net/ https://tracking-v3.websitealive.com/ https://alive5.com/ https://js.braintreegateway.com/ https://assets.braintreegateway.com/ https://c.paypal.com/ https://widget.surveymonkey.com/ https://collector-22197.us.tvsquared.com/ https://omnisnippet1.com/ https://wt.omnisendlink.com/ https://forms.soundestlink.com/ https://tags.srv.stackadapt.com/ https://s.pinimg.com/ https://ct.pinterest.com/; style-src 'self' https://use.typekit.net/ https://p.typekit.net/ https://tracking-v3.websitealive.com/ https://assets.braintreegateway.com/ https://alive5.com/ https://fonts.googleapis.com/ https://tags.srv.stackadapt.com/ 'unsafe-inline'; connect-src 'self' https://www.googleadservices.com https://wt.omnisendlink.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://google.com https://www.facebook.com/ https://capig.stape.biz/ https://alive5.com/ https://api-v2.alive5.com/ https://performance.typekit.net/ https://api.sandbox.braintreegateway.com/ https://client-analytics.sandbox.braintreegateway.com/ *.braintree-api.com https://forms.soundestlink.com/ https://api.braintreegateway.com/ https://client-analytics.braintreegateway.com/ https://ib.adnxs.com/ https://tags.srv.stackadapt.com/ https://ct.pinterest.com/; font-src 'self' https://use.typekit.net/ https://fonts.gstatic.com/; img-src 'self' data: https: https://arttrk.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://google.com https://p.typekit.net/ https://assets.braintreegateway.com/; frame-src 'self' https://www.googletagmanager.com https://insight.adsrvr.org https://bid.g.doubleclick.net https://td.doubleclick.net/ *.websitealive.com https://alive5.com/ https://assets.braintreegateway.com/ *.paypal.com *.kaptcha.com https://www.facebook.com/ https://ct.pinterest.com/; report-uri https://myplates.report-uri.com/r/d/csp/enforce 1 font-src https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.stripe.com consentcdn.cookiebot.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com content.holmbank.ee https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://map.plugins.itella.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt public.montonio.com self: https://maps.omnivasiunta.lt cdn.modena.ee cms.modena.ee static.hotjar.com *.userway.org www.gemer.ee grade.scandiweb.com imgsct.cookiebot.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://unpkg.com www.facebook.com graph.facebook.com business.facebook.com public.montonio.com js.stripe.com chat.translatewise.com *.hotjar.com *.cookiebot.com *.userway.org www.gemer.ee googletagmanager.com chat.askly.me js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com https://fonts.googleapis.com https://unpkg.com self: *.fontawesome.com maxcdn.bootstrapcdn.com www.gemer.ee *.userway.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.terminalmappingjs.com https://geocode.arcgis.com api.sandbox-card-payments.montonio.com api.card-payments.montonio.com chat.translatewise.com static.hotjar.com consent.cookiebot.com *.userway.org www.gemer.ee www.google.com googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net pagead2.googlesyndication.com chat.askly.me sessions.chat.askly.me wss://sessions.chat.askly.me 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; worker-src blob: https://tobaccofreeflorida.com/; object-src 'none'; script-src 'unsafe-eval' 'self' https://www.googletagmanager.com/ https://connect.facebook.net/ https://static.ads-twitter.com/ https://analytics.tiktok.com/ https://sc-static.net/ https://www.youtube.com/iframe_api https://www.google-analytics.com/ https://maps.googleapis.com/ https://play.google.com/ https://googleads.g.doubleclick.net/ https://tffl.wpengine.com/ https://www.youtube.com/ https://dashboard.chatfuel.com/ https://bat.bing.com/ https://action.media6degrees.com/ https://ajax.googleapis.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/releases/ https://tags.srv.stackadapt.com/ https://siterecruit.comscore.com/ https://code.jquery.com/ https://ajax.aspnetcdn.com/ https://cdn.jsdelivr.net/ https://cdnjs.cloudflare.com/ https://tag.simpli.fi/ https://i.simpli.fi 1 font-src fonts.gstatic.com use.typekit.net https://static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.certcapture.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.magezon.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://d3k81ch9hvuctc.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.google.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://script.crazyegg.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com https://static-tracking.klaviyo.com https://use.typekit.net https://p.typekit.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://script.crazyegg.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.punchout2go.com *.tradecentric.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.tradecentric.com *.birchstreetsystems.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com/ *.punchout2go.com *.tradecentric.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net magefan.com cm.magefan.com https://www.magezon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com/ *.punchout2go.com *.tradecentric.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://acsbapp.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com *.punchout2go.com *.tradecentric.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://cdn.acsbapp.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.tawk.to *.gstatic.com *.reviews.io maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.example 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.example *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.reviews.co.uk *.reviews.io *.flodesk.com https://images.unsplash.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.tawk.to *.jsdelivr.net *.reviews.co.uk *.flodesk.com https://maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.tawk.to *.googleapis.com *.reviews.co.uk *.reviews.io data: maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.example 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.tawk.to wss://*.tawk.to *.reviews.co.uk *.flodesk.com https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://449bcefd-41f7-4be0-9a19-580647f46578.sansec.watch/; report-to report-endpoint; 1 frame-ancestors *.certcapture.com *.authorize.net *.storyblok.com 'self'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://sis.redsys.es/ pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.authorize.net 'self' 'unsafe-inline'; frame-src *.googletagmanager.com *.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.certcapture.com *.authorize.net *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; font-src *.sizebay.technology *.connectif.cloud fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; style-src *.sizebay.technology *.connectif.cloud *.certcapture.com downloads.mailchimp.com *.photoslurp.com *.nosto.com *.doofinder.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; script-src *.clickcease.com *.sleeknote.com *.sizebay.technology www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com *.authorize.net www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src region1.analytics.google.com *.sleeknote.com *.sizebay.technology *.connectif.cloud analytics.tiktok.com *.google.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com *.authorize.net *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.doofinder.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; img-src *.sleeknote.com www.tinycottons.com *.sizebay.technology *.connectif.cloud widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://www.google-analytics.com *.fontawesome.com; font-src 'self' http://fonts.googleapis.com https://fonts.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com http://themes.googleusercontent.com; frame-src 'self' https://www.youtube.com http://www.youtube.com https://www.google.com https://maps.google.com https://player.vimeo.com https://www.facebook.com; img-src * data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://ajax.googleapis.com https://www.google-analytics.com https://ssl.google-analytics.com https://code.jquery.com *.fontawesome.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill.io https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' *.fontawesome.com https://www.google-analytics.com https://ssl.google-analytics.com http://themes.googleusercontent.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill.io https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com; style-src 'self' fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.fontawesome.com *.mailchimp.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; frame-ancestors 'self' 1 script-src-elem https://static.klaviyo.com/ https://js.klevu.com/ https://static-tracking.klaviyo.com/ https://www.shopperapproved.com/ https://bat.bing.com/ https://js.stripe.com/ https://www.paypal.com/ https://html5.dcatalog.com/ https://ct.pinterest.com/ https://cdnjs.cloudflare.com/ https://connect.facebook.net/ https://maps.googleapis.com/ https://mockett.services.answerbase.com/ https://s.pinimg.com/ https://assets.pinterest.com/ https://www.google-analytics.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com/ https://js-agent.newrelic.com/nr-spa-1.293.0.min.js www.paypalobjects.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem https://maxcdn.bootstrapcdn.com/ https://js.klevu.com/ https://fonts.googleapis.com/ https://use.typekit.net/ https://p.typekit.net/ https://cdnjs.cloudflare.com/ https://mockett.services.answerbase.com/ https://data3.answerbase.com/ https://www.shopperapproved.com/ https://www.shopperapproved.com/seal/2253.css static.klaviyo.com static-tracking.klaviyo.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://www.shopperapproved.com/ https://maxcdn.bootstrapcdn.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://www.mockett.com/dmcadmin/swatches/iframe/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io github.blog www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com https://bat.bing.com/ https://www.shopperapproved.com/ https://assets.pinterest.com/ https://data3.answerbase.com/ https://mockett.services.answerbase.com/ https://log.pinterest.com/ https://mockett.com/pub/media/wysiwyg/mockett_sa_milestone_award.png d3k81ch9hvuctc.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com maps.googleapis.com https://m.stripe.network/ https://www.mockett.com/ self 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://statsjs.klevu.com/ https://maps.googleapis.com/ https://mockett.services.answerbase.com/ https://stats.g.doubleclick.net/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.gstatic.com maps.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js chimpstatic.com downloads.mailchimp.com *.list-manage.com *.google.com maps.googleapis.com cdn.rawgit.com/googlemaps/js-marker-clusterer/gh-pages/src/markerclusterer.js cdn.jsdelivr.net/gh/googlemaps/js-marker-clusterer@gh-pages/src/markerclusterer.js code.jquery.com/jquery-3.6.0.min.js cdnjs.cloudflare.com/ajax/libs/knockout/3.5.1/knockout-min.js *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.google-analytics.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://stanleysteemer.com https://static.ads-twitter.com https://analytics.tiktok.com https://widget-prime.rafflecopter.com https://www.googletagmanager.com https://view.ceros.com https://amplify.review-alerts.com https://ajax.googleapis.com https://labs.ceros.com https://api.ipify.org https://sdk.ceros.com https://cdn.chatavise.com https://apps.usw2.pure.cloud https://maps.googleapis.com https://apis.google.com https://cdn.cookielaw.org https://api.ipify.org https://*.api.ipify.org https://www.google-analytics.com https://schema-cf.bc0a.com https://*.audioeye.com https://f.vimeocdn.com https://www.gstatic.com https://fonts.gstatic.com https://marvel-b1-cdn.bc0a.com https://s.pinimg.com https://snap.licdn.com https://connect.facebook.net https://googleads.g.doubleclick.net https://ct.pinterest.com https://static.hotjar.com https://script.hotjar.com https://i.loopme.me https://bat.bing.com https://*.tvsquared.com https://cdn.chatavise.com https://www.googleadservices.com https://www.google.com https://bam.nr-data.net https://js-agent.newrelic.com; connect-src 'self' blob: 'unsafe-inline' https://www.google-analytics.com https://analytics.tiktok.com https://www.facebook.com https://bat.bing.com https://adservice.google.com https://bam.nr-data.net https://maps.googleapis.com https://cdn.cookielaw.org https://analytics.google.com https://*.bc0a.com https://qa.metrics.stanleysteemer.com https://ct.pinterest.com https://*.linkedin.com https://gdpr.loopme.com https://*.audioeye.com https://*.vimeocdn.com https://*.onetrust.com https://*.doubleclick.net https://vimeo.com https://www.google.com https://api.chatavise.com; report-uri https://66787c15d528e3ceb6b0d8fe.endpoint.csper.io/?v=0 1 upgrade-insecure-requests; report-to https://myrgroup.com/csp-report.php;; report-uri https://myrgroup.com/csp-report.php;; 1 Content-Security-Policy: default-src 'self'; script-src 'self' https://js.hs-scripts.com https://js.hsforms.net https://taggbox.com https://*.google-analytics.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://*.hubspotusercontent10.net https://taggbox.com https://*.google-analytics.com; connect-src 'self' https://*.hubspot.com https://*.hsforms.com https://*.hubapi.com https://*.google-analytics.com; object-src 'none'; base-uri 'self'; form-action 'self' https://*.hubspot.com https://*.hsforms.com; frame-ancestors 'self'; upgrade-insecure-requests; 1 base-uri 'self'; connect-src 'self' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://unpkg.com https://data.inform-software.com https://preview.data.inform-software.com https://*.google-analytics.com https://www.googleadservices.com https://player.vimeo.com https://vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://*.leadlab.click https://px.ads.linkedin.com https://www.google.com; default-src 'self'; form-action 'self'; img-src 'self' data: blob: https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://i.vimeocdn.com https://i.ytimg.com https://prod.smassets.net https://px.ads.linkedin.com https://tr.lfeeder.com https://www.googletagmanager.com; media-src 'self' data: blob:; frame-src 'self' https://*.thinglink.com https://*.svc.dynamics.com https://*.mkt.dynamics.com https://outlook.office365.com https://outlook.office.com https://*.azureedge.net https://player.vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://www.openstreetmap.org https://tv.theiet.org https://*.surveymonkey.com https://app.storylane.io https://data.inform-software.com https://preview.data.inform-software.com https://www.googletagmanager.com; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.svc.dynamics.com https://js.storylane.io https://*.surveymonkey.com https://ajax.googleapis.com https://player.vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://www.googletagmanager.com https://*.azureedge.net https://connect.facebook.net https://sc.lfeeder.com 'nonce-8WD1Ty6RZPe3dI7f'; style-src 'self' data: 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; font-src 'self' data: https://cdn.smassets.net https://fonts.gstatic.com; report-uri /site-security/csp-log; worker-src 'self' blob:; 1 font-src *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.networkmerchants.com *.instagram.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.networkmerchants.com *.cdninstagram.com *.klevu.com *.ksearchnet.com https://www.magezon.com https://meetanshi.com bat.bing.com *.hsforms.com track.sweetanalytics.com *.hubspot.com *.facebook.com static.hsappstatic.net *.google.ca scholarschoice.preview.smartebusiness.co.uk *.adroll.com *.bidswitch.net *.rubiconproject.com *.casalemedia.com *.tapad.com *.rlcdn.com *.ml314.com *.openx.net *.outbrain.com *.pubmatic.com *.adnxs.com *.3lift.com *.taboola.com *.amazon-adsystem.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.networkmerchants.com *.instagram.com js.klevu.com *.ksearchnet.com *.google.com/ *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.adroll.com bat.bing.com *.pinimg.com js.hs-scripts.com js.hs-analytics.com js.hs-banner.com js.hsadpixel.com analytics.tiktok.com *.hubspot.com *.usemessages.com track.sweetanalytics.com *.pinterest.com js.hs-analytics.net js.hsadspixel.net applepay.cdn-apple.com static.hsappstatic.net *.hs-sites.com js.hubspot.com *.hsforms.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com cdn.ampproject.org www.gstatic.com *.yotpo.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.networkmerchants.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com www.gstatic.com *.yotpo.com *.googleapis.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.networkmerchants.com *.klevu.com *.ksearchnet.com *.google-analytics.com https://www.google-analytics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.pinterest.com analytics.tiktok.com *.hubspot.com api.hubapi.com track.sweetanalytics.com *.hsforms.com *.adroll.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org www.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app https://www.paypalobjects.com *.weltpixel.com landofcoder.com https://portal.afterpay.com https://placement-api.us.afterpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app blob: eliminator-rc.com *.googleapis.com *.google.com http://*.google.com https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app landofcoder.com ajax.googleapis.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com landofcoder.com https://maps.googleapis.com https://portal.afterpay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://client.crisp.chat *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.wesupply.xyz *.typeform.com *.facebook.com https://load.stracking.weltpixel.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://image.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.crisp.chat v2assets.zopim.io *.zopim.io weltpixel.com www.weltpixel.com *.magento.com *.filestackapi.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.com.kh *.google.cd *.google.cf *.google.cat *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gf *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gp *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.iq *.google.ie *.google.co.il *.google.im *.google.co.in *.google.io *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.com.lc *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.ne *.google.com.nf *.google.com.ng *.google.com.ni *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pk *.google.com.pa *.google.com.pe *.google.com.ph *.google.pl *.google.com.pg *.google.pn *.google.co.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.rs *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.sm *.google.so *.google.st *.google.sr *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tk *.google.tl *.google.tm *.google.to *.google.tn *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.co.za *.google.co.zm *.google.co.zw hn.inspectlet.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://client.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.weltpixel.com *.cloudflare.com *.cloudflareinsights.com *.zdassets.com *.usefomo.com *.fomo.com *.gstatic.com *.vimeo.com *.googleoptimize.com *.inspectlet.com https://tracking.weltpixel.com https://load.stracking.weltpixel.com/ static-tracking.klaviyo.com *.nudgify.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://client.crisp.chat https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com weltpixel.com www.weltpixel.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://www.google-analytics.com *.weltpixel.com capig.weltpixel.com load.stracking.weltpixel.com stracking.weltpixel.com *.a.klaviyo.com *.facebook.com *.zopim.com wss://widget-mediator.zopim.com *.zdassets.com *.zendesk.com *.usefomo.com *.fomo.com https://tracking.weltpixel.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.com.kh *.google.cd *.google.cf *.google.cat *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gf *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gp *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.iq *.google.ie *.google.co.il *.google.im *.google.co.in *.google.io *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.com.lc *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.ne *.google.com.nf *.google.com.ng *.google.com.ni *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pk *.google.com.pa *.google.com.pe *.google.com.ph *.google.pl *.google.com.pg *.google.pn *.google.co.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.rs *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.sm *.google.so *.google.st *.google.sr *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tk *.google.tl *.google.tm *.google.to *.google.tn *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.co.za *.google.co.zm *.google.co.zw *.inspectlet.com wss://ws.inspectlet.com/ t.co *.nudgify.com https://load.stracking.weltpixel.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com static.olark.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.affirm.com *.affirm.ca *.google.com/ www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.affirm.com *.affirm.ca https://www.magezon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net store.paradoxlabs.com insight.adsrvr.org bat.bing.com www.google.co.in log.olark.com static.olark.com img-msg.tb-list.com pixel.rubiconproject.com match.adsrvr.org *.doubleclick.net *.klaviyo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.sharethis.com polyfill.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.google.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com maps.googleapis.com https://cdnjs.cloudflare.com d10lpsik1i8c69.cloudfront.net js.adsrvr.org cdn-in.pagesense.io sf.bayengage.com bat.bing.com app.targetbay.com static.olark.com knrpc.olark.com www.gstatic.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com static.olark.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com settings.luckyorange.net pagesense.zoho.in locationapi.cdn-in.pagesense.io pagesense-collect.zoho.in app.targetbay.com knrpc.olark.com bat.bing.com sfc-api.bayengage.com www.google.co.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.hipay-tpp.com *.hipay.com *.paypal.com *.googleapis.com *.pinterest.com/ widget.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net https://images.unsplash.com *.hipay.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.doubleclick.net *.google.fr *.googleapis.com cdn-cookieyes.com *.cdn-cookieyes.com *.r202.fr *.abtasty.com *.clarity.ms *.pinimg.com *.facebook.net *.bing.com *.facebook.com *.pinterest.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com/maps/api/mapsjs https://maps.googleapis.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdnjs.cloudflare.com *.doubleclick.net *.google.fr *.googleapis.com cdn-cookieyes.com *.cdn-cookieyes.com *.r202.fr *.abtasty.com *.clarity.ms *.pinimg.com *.facebook.net *.bing.com *.facebook.com *.pinterest.com widget.trustpilot.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.hipay.com *.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com/maps/api/mapsjs https://maps.googleapis.com https://player.vimeo.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.doubleclick.net *.google.fr *.googleapis.com cdn-cookieyes.com *.cdn-cookieyes.com *.r202.fr *.abtasty.com *.clarity.ms *.pinimg.com *.facebook.net *.bing.com *.facebook.com *.pinterest.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.klarnacdn.net *.builder.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src *.cookieinformation.com *.hubspot.com *.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trustpilot.com fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.klarna.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.kustom.co www.xtento.com 'self' 'unsafe-inline'; img-src *.sparvinduer.dk *.stape.net *.google.com *.bing.com *.hubspot.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.google.com bid.g.doubleclick.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com imgsct.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://images.unsplash.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.builder.io www.google.com.ua https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.kustom.co www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.cookieinformation.com *.emaerket.dk *.sleeknote.com *.sparxpres.dk *.commoninja.com *.hs-scripts.com *.usemessages.com *.hs-analytics.net *.hs-banner.com *.clarity.ms *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ consent.cookiebot.com https://*.dibspayment.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.builder.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com *.kustom.co www.xtento.com cdn.xtento.com https://chimpstatic.com load.sgtm.sparvinduer.dk https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sparvinduer.dk *.sleeknote.com *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com *.fontawesome.com *.klarnacdn.net *.stripe.network *.stripecdn.com *.amazon.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src ssgtm.sparvinduer.dk *.cookieinformation.com *.sleeknote.com *.mobal.io *.commoninja.com *.hubspot.com *.clarity.ms www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com load.sgtm.sparvinduer.dk dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n.adobe.io *.adobedc.net *.demdex.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.builder.io *.stripe.com klarna.com *.link.com *.amazon.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.kustom.co https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://ajax.cloudflare.com https://ct.pinterest.com https://maps.googleapis.com https://cdn-ukwest.onetrust.com https://connect.facebook.net https://s.pinimg.com https://static-tracking.klaviyo.com https://static.klaviyo.com https://www.googletagmanager.com https://dev.visualwebsiteoptimizer.com; style-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-hashes' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://maps.googleapis.com https://cdn-ukwest.onetrust.com https://ct.pinterest.com https://region1.analytics.google.com https://dev.visualwebsiteoptimizer.com https://www.google.com https://region1.google-analytics.com https://stats.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://dev.visualwebsiteoptimizer.com https://www.instagram.com https://www.youtube.com https://www.google.com https://ct.pinterest.com https://www.facebook.com https://www.googletagmanager.com https://td.doubleclick.net; img-src 'self' https://platform-cdn.sharethis.com https://cdn-ukwest.onetrust.com https://cdn.guides4brides.co.uk https://ct.pinterest.com https://www.facebook.com https://dev.visualwebsiteoptimizer.com https://www.google.co.uk; manifest-src 'self'; media-src 'self'; report-uri https://64a4272d3723daccf205fe62.endpoint.csper.io/?v=1; worker-src 'none'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.brevo.com *.doubleclick.net *.google.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com magefan.com cm.magefan.com https://www.magezon.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.brevo.com https://www.googletagmanager.com *.esputnik.com *.newrelic.com *.google.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.esputnik.com https://esputnik.com *.nr-data.net *.google.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com *.alothemes.com *.magepow.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to *.trustpilot.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.tawk.to cdn.jsdelivr.net *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com *.cloudflare.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.tawk.to cdn.jsdelivr.net *.trustpilot.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com *.alothemes.com *.magepow.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com *.tawk.to cdn.jsdelivr.net *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to wss://*.tawk.to *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.iubenda.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.iubenda.com https://maps.googleapis.com https://maps.google.com https://maps.gstatic.com https://*.tile.openstreetmap.org *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.iubenda.com https://magento.com https://maps.googleapis.com https://maps.google.com https://maps.gstatic.com https://*.zopim.com https://*.zdassets.com https://unpkg.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.iubenda.com https://maps.googleapis.com https://maps.google.com https://maps.gstatic.com https://*.zopim.com https://*.zendesk.com https://*.zdassets.com *.google-analytics.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'report-sample' addtocalendar.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.addtoany.com https://storage.googleapis.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' addtocalendar.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self' https://12992298.fls.doubleclick.net https://t.sharethis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://app-ab30.marketo.com https://cloud-dev.zimmerbiomet.com https://scripts.clarity.ms https://acsbapp.com https://app-sjqe.marketo.com https://munchkin.marketo.net https://t.sharethis.com https://www.clarity.ms https://cdn.mouseflow.com https://bat.bing.com https://buttons-config.sharethis.com https://platform-api.sharethis.com https://players.brightcove.net https://vjs.zencdn.net https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://js.driftt.com https://assets.map.brightcove.com https://personalizedknee.zimmerbiomet.com; style-src 'self' 'unsafe-inline' https://app-ab30.marketo.com https://tags.srv.stackadapt.com https://fonts.googleapis.com https://cdn.cookielaw.org; img-src 'self' data: www.google.com.mx https://dpm.demdex.net https://cm.everesttech.net https://dev.day.com https://c.bing.com https://c.clarity.ms https://hostedseal.trustarc.com https://privacy-policy.truste.com https://www.zimmerbiomet.com https://l.sharethis.com https://zimzbdotcomprod.112.2o7.net https://sync.sharethis.com https://bat.bing.com https://www.facebook.com https://cf-images.us-east-1.prod.boltdns.net https://metrics.brightcove.com https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://personalizedknee.zimmerbiomet.com https://assets.map.brightcove.com; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://v.clarity.ms https://dpm.demdex.net https://zimzbdotcomprod.112.2o7.net https://e.clarity.ms https://metrics.brightcove.com https://bcp.crwdcntrl.net https://ad.doubleclick.net https://cdn.acsbapp.com https://z.clarity.ms https://237-zhg-588.mktoresp.com https://n2.mouseflow.com https://zimmerbiomet.tt.omtrdc.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://manifest.prod.boltdns.net https://l.sharethis.com https://api.ipdata.co https://edge.api.brightcove.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://js.driftt.com https://assets.map.brightcove.com https://personalizedknee.zimmerbiomet.com https://zimmerbiometglobal.my.salesforce.com data:; frame-src 'self' https://zimmer.demdex.net https://app-ab30.marketo.com https://12992298.fls.doubleclick.net https://t.sharethis.com https://www.googletagmanager.com https://*.google.com https://connect.facebook.net https://js.driftt.com https://assets.map.brightcove.com; media-src 'self' blob: https://cloud-dev.zimmerbiomet.com https://assets.map.brightcove.com https://personalizedknee.zimmerbiomet.com data:; form-action 'self' 1 default-src 'self'; img-src 'self' data: http: https: *.gravatar.com; script-src 'self' https://statistics.region-stuttgart.de/ 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://statistics.region-stuttgart.de/; frame-src 'self' https://www.youtube-nocookie.com/; report-uri https://csp-log.d-mind.de/report.php; 1 base-uri 'self'; frame-ancestors 'self'; object-src 'none'; default-src 'self' https: data: blob:; img-src 'self' https: data: blob:; font-src 'self' https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; connect-src 'self' https:; frame-src https:; upgrade-insecure-requests; require-trusted-types-for 'script' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.sendcloud.sc *.jsdelivr.net *.kiyoh.com gtm.sokken-online.nl *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazonaws.com *.taggrs.io gtm.sokken-online.nl https://www.googleadservices.com https://www.google.com https://www.google.nl https://www.google.rs https://consent.cookiefirst.com https://pagead2.googlesyndication.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.sendcloud.sc *.jsdelivr.net cdn.ampproject.org www.gstatic.com *.taggrs.io https://gtm.sokken-online.nl https://static.zdassets.com https://ct.beslist.nl https://consent.cookiefirst.com https://static.hotjar.com https://script.hotjar.com https://widget-mediator.zopim.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.sendcloud.sc *.jsdelivr.net www.gstatic.com *.cookiefirst.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com cdn.ampproject.org www.googleapis.com gtm.sokken-online.nl *.googletagmanager.com ekr.zdassets.com ct.beslist.nl sokken-online.zendesk.com wss://widget-mediator.zopim.com metrics.hotjar.io https://www.googleadservices.com https://googleads.g.doubleclick.net https://ad.doubleclick.net https://adservice.google.com https://www.google.com https://www.google.nl https://www.google.rs *.cookiefirst.com https://pagead2.googlesyndication.com *.socken-online.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: *.gstatic.com 'self' *.abtasty.com *.mews.li *.mews.com; img-src 'self' *.smartadserver.com *.loopme.me *.dotomi.com conversio.s3.eu-west-2.amazonaws.com lpcdn.lpsnmedia.net *.googlesyndication.com sync.targeting.unrulymedia.com ups.analytics.yahoo.com us-east.ads.audio.thisisdax.com ads.stickyadstv.com match.sharethrough.com sync.1rx.io ps.eyeota.net contextual.media.net bh.contextweb.com *.pubmatic.com *.smaato.net *.linkedin.com *.teads.tv *.googleapis.com *.gstatic.com *.mews.li *.mews.com *.bing.com *.duettoresearch.com *.onetrust.com cx.atdmt.com data: *.doubleclick.net *.googleusercontent.com *.quantserve.com *.lockeliving.com *.windows.net *.facebook.com *.google-analytics.com www.google.co.uk www.google.com *.google.nl www.googletagmanager.com www.gstatic.com www.google.ie *.googleapis.com *.ggpht.com; script-src data: blob: 'wasm-unsafe-eval' 'self' 'unsafe-eval' 'unsafe-inline' web-sdk-eu.aptrinsic.com login-ds.dotomi.com https://cdn.jsdelivr.net https://cdn.jsdelivr.net/npm/vue@2 https://unpkg.com/web-vitals@3.5.2/dist/web-vitals.attribution.iife.js https://unpkg.com/web-vitals@3/dist/web-vitals.attribution.iife.js *.googlesyndication.com js.appboycdn.com snap.licdn.com *.treasuredata.com analytics.tiktok.com eu01.in.treasuredata.com p.relay-t.io js.zi-scripts.com ws.zoominfo.com tags.clickagy.com *.mews.com https://pay.datatrans.com/upp/payment/js/secure-fields-1.0.0.js https://www.recaptcha.net https://recaptcha.google.com/recaptcha cdn-ukwest.onetrust.com *.abtasty.com *.onetrust.com *.rollbar.com *.mczbf.com *.msecnd.net cdn.jsdelivr.net/npm/flatpickr *.googleoptimize.com *.teads.tv *.lpsnmedia.net *.triptease.io *.liveperson.net *.googleapis.com *.mews.li *.mews.com *.bing.com *.duettoresearch.com *.onetrust.com *.facebook.net *.doubleclick.net *.quantcount.com *.quantserve.com *.google-analytics.com *.google.com *.googleadservices.com *.googletagmanager.com *.gstatic.com fareharbor.com *.lockeliving.com *.instagram.com *.datatrans.com; style-src *.googleapis.com 'self' 'unsafe-eval' 'unsafe-inline' *.lockeliving.com *.mews.com web-sdk-eu.aptrinsic.com; connect-src https://google.com aorta.clickagy.com *.zoominfo.com *.liveperson.net wss://va.msg.liveperson.net js.zi-scripts.com *.ingest.sentry.io log-api.eu.newrelic.com *.aptrinsic.com *.launchdarkly.com *.googlesyndication.com hemsync.clickagy.com *.treasuredata.com *.googleapis.com *.braze.eu *.rollbar.com *.abtasty.com *.tiktok.com *.linkedin.com *.relay-t.io *.google.com *.sjwoe.com *.mczbf.com *.teads.tv *.triptease.io *.onetrust.com 'self' *.mews.li *.mews.com bat.bing.com *.duettoresearch.com *.visualstudio.com *.doubleclick.net *.facebook.com *.google-analytics.com *.instagram.com; frame-src hemsync.clickagy.com *.teads.tv *.triptease.io *.lpsnmedia.net *.liveperson.net *.google.com *.recaptcha.net *.doubleclick.net *.facebook.com *.googletagmanager.com 'self' fareharbor.com gifer.com pay.datatrans.com *.onetrust.com *.instagram.com *.youtube.com *.clickdimensions.com *.lockeliving.com *.findingedyn.com; media-src *.vimeo.com *.akamaized.net *.lpsnmedia.net; worker-src blob:; child-src blob; default-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.googleapis.com *.gstatic.com *.google.com *.mews.li *.mews.com *.onetrust.com; report-uri https://lockeliving.report-uri.com/r/d/csp/wizard 1 font-src *.klevu.com *.ksearchnet.com *.gstatic.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.braintreegateway.com ssl.kaptcha.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: www.gstatic.com cookie-cdn.cookiepro.com bat.bing.com www.google.pl www.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com cookie-cdn.cookiepro.com consent.cookiebot.com bat.bing.com connect.facebook.net *.clarity.ms https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com https://fonts.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com cookie-cdn.cookiepro.com *.braintreegateway.com *.onetrust.com https://fonts.googleapis.com https://fonts.gstatic.com googleads.g.doubleclick.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' data: inrecruitingfr.intervieweb.it; connect-src 'self' *.google-analytics.com; img-src * data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.google-analytics.com www.gstatic.com www.google.com inrecruitingfr.intervieweb.it; frame-src 'self' inrecruitingfr.intervieweb.it www.gstatic.com recaptcha.google.com; font-src 'self' fonts.googleapis.com data:; report-to csp-collection; report-uri /wp-json/recrutement-pv/v1/csp-reports 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline'; frame-ancestors *.youtube.com salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self'; frame-src bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.twitter.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.addthis.com youtube.com salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.hsforms.net *.hsforms.com www.google.pl ssl.ceneo.pl allekurier.pl icd.pl www.icd.pl cdn.samito.co icdpl.savecart.pl commerce-connector.com www.commerce-connector.com *.impartner.io savecart.pl *.savecart.pl *.cookiebot.com salesbot.trafficwatchdog.pl *.trafficwatchdog.pl data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.avada.io player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com googletagmanager.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com *.googleapis.com graph.facebook.com widgets.pinterest.com bam-cell.nr-data.net js-agent.newrelic.com bam.nr-data.net ssl.ceneo.pl cdn.allekurier.pl *.saleago.com icdpl.savecart.pl *.impartner.io *.hotjar.com savecart.pl *.savecart.pl *.cookiebot.com trafficscanner.pl *.trafficscanner.pl salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.bootstrapcdn.com icdpl.savecart.pl savecart.pl *.savecart.pl salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline'; object-src *.youtube.com salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com www.apptrian.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com bam.nr-data.net *.googleapis.com googleads.g.doubleclick.net *.saleago.com icdpl.savecart.pl stats.g.doubleclick.net *.hotjar.com *.hotjar.io wss://ws.hotjar.com savecart.pl *.savecart.pl *.cookiebot.com trafficscanner.pl *.trafficscanner.pl salesbot.trafficwatchdog.pl *.trafficwatchdog.pl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.icd.pl/; report-to report-endpoint; 1 default-src * data: mediastream: blob: filesystem: about: ws: wss: 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline'; script-src * data: blob: 'sha256-KWDEEoZgBqBbDbgZCGB7PwwF1esGq0IMYVkC8xtGpuo='; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors * data: blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io store.paradoxlabs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src ap.thepayapays.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'none';block-all-mixed-content;default-src 'none';script-src 'none';style-src 'none';object-src 'none';frame-src 'none';child-src 'none';img-src 'none';font-src 'none';connect-src 'none';manifest-src 'none';base-uri 'none';form-action 'none';media-src 'none';prefetch-src 'none';worker-src 'none';report-uri https://sentec.report-uri.com/r/d/csp/reportOnly; 1 script-src 'self' 'strict-dynamic' 'nonce-nodD5NWxGI0WbOS9lhcx3g=='; report-uri https://creal.jp/csp_report; report-to default; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://*.retailrocket.net https://www.google.com https://www.gstatic.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://*.retailrocket.net; img-src 'self' https://*.retailrocket.net https://*.dmi.es https://*.testseek.com https://www.googletagmanager.com data:; style-src 'self' 'unsafe-inline' https://*.retailrocket.net; frame-src https://www.google.com https://www.gstatic.com https://www.youtube.com; report-uri /csp-report/ 1 font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk *.facebook.com *.paymentexpress.com *.windcave.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app https://static.addtoany.com/ *.instagram.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.paymentexpress.com *.windcave.com https://www.googleadservices.com https://www.gstatic.com https://www.google.com https://popup.laybuy.com https://td.doubleclick.net https://placement-api.sandbox.afterpay.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.paymentexpress.com *.windcave.com https://stats.g.doubleclick.net https://www.facebook.com https://www.google.co.nz https://www.google.com https://integration-assets.laybuy.com 'self' data: t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app https://static.addtoany.com/ *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com cdn.jsdelivr.net *.reviews.io *.reviews.co.uk *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.paymentexpress.com *.windcave.com https://chimpstatic.com https://connect.facebook.net https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app https://static.klaviyo.com *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com https://stats.addtoany.com/menu www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://www.google-analytics.com https://stats.g.doubleclick.net https://google.com https://www.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 'unsafe-inline' 'unsafe-eval'; style-src-elem * 'unsafe-inline'; frame-ancestors *; form-action 'self'; script-src-elem * 'unsafe-inline'; connect-src * 'self'; img-src * data:; 1 font-src data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com checkout.postfinance.ch *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com checkout.postfinance.ch *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jquery.sellxed.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com checkout.postfinance.ch *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:;script-src https: 'self' 'strict-dynamic' 'nonce-097dca958f1f3b0884f2a640ccda42fdb7fca188e35add125ef09eb519065147' 'unsafe-inline' 'unsafe-eval' 'report-sample';style-src https: 'unsafe-inline';img-src https: data:;connect-src https: wss:;font-src https: data:;object-src 'none';media-src https: blob: data:;frame-src https: null data: blob:;child-src 'self' https:;form-action 'self';frame-ancestors https://my.firespring.com;base-uri 'self' https://insights.sitesearch360.com;worker-src 'self' blob:;manifest-src 'self' https://cdn.firespring.com;report-uri /csp_log?n=1 1 default-src 'self' https://*.duosecurity.com; font-src 'self' https://ka-p.fontawesome.com https://fonts.gstatic.com https://recollect.a.ssl.fastly.net data:; script-src 'self' 'unsafe-inline' https://events.cityofwinterpark.org https://player.vimeo.com https://f.vimeocdn.com https://kit.fontawesome.com https://www.google-analytics.com https://www.googletagmanager.com https://maps.googleapis.com https://app-script.monsido.com https://recollect.net https://api.recollect.net https://recollect-images.global.ssl.fastly.net https://apps.remembermyjourney.com https://static.elfsight.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://recollect.a.ssl.fastly.net; img-src 'self' https://i.ytimg.com https://i.vimeocdn.com https://www.googletagmanager.com https://maps.gstatic.com https://tracking.monsido.com https://api.recollect.net https://recollect-images.global.ssl.fastly.net https://recollect.a.ssl.fastly.net data:; connect-src 'self' https://player.vimeo.com https://vimeo.com https://f.vimeocdn.com https://ka-p.fontawesome.com https://kit.fontawesome.com https://www.google-analytics.com https://analytics.google.com https://maps.googleapis.com https://core.service.elfsight.com; worker-src 'self' blob:; frame-src 'self' https://events.cityofwinterpark.org https://www.youtube.com https://player.vimeo.com https://api.recollect.net https://g1.ipcamlive.com; 1 font-src *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com account.fetchify.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://images.unsplash.com cdn.doofinder.com https://www.magezon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com https://www.google.co.uk https://bat.bing.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com https://*.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com widget.freshworks.com m2epro.freshdesk.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.authorize.net https://*.braintreegateway.com https://*.cardinalcommerce.com https://*.paypal.com https://*.doofinder.com https://widget.freshworks.com https://m2epro.freshdesk.com https://*.googletagmanager.com *.trustpilot.com https://*.vimeocdn.com https://s.ytimg.com https://cdn-cookieyes.com https://*.hotjar.com https://www.clarity.ms https://bat.bing.com https://static.zdassets.com https://googleads.g.doubleclick.net https://includestest.ccdc02.com https://widget-mediator.zopim.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com https://static.klaviyo.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ekr.zdassets.com https://bat.bing.net https://h.clarity.ms https://flyingspares.zendesk.com wss://widget-mediator.zopim.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.analytics.google.com stats.g.doubleclick.net www.google.co.uk *.facebook.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.onetrust.com *.klarna.com *.klarnacdn.net *.klarnaservices.com widget.freshworks.com m2epro.freshdesk.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klarnacdn.net widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.onetrust.com *.klarnaevt.com *.analytics.google.com stats.g.doubleclick.net *.klarnacdn.net *.klarna.com *.klarnaservices.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://opensociety.report-uri.com/r/d/csp/reportOnly;base-uri 'self';connect-src 'self' https://translate.googleapis.com https://*.googletagmanager.com https://*.google-analytics.com https://*.ingest.sentry.io https://docket.justiceinitiative.org https://justiceinitiative.piwik.pro https://justiceinitiative.containers.piwik.pro https://cdn.matomo.cloud https://theideasletter.matomo.cloud https://cdn-cookieyes.com https://log.cookieyes.com https://*.cookieyes.com;default-src 'self';form-action 'self';img-src 'self' data: https: https://www.gstatic.com https://*.googletagmanager.com https://osjicontent.imgix.net https://*.google-analytics.com;object-src 'self';script-src 'self' 'unsafe-eval' https://translate.googleapis.com https://www.justiceinitiative.org https://cdn.plyr.io/3.4.4/plyr.polyfilled.js https://cdnjs.cloudflare.com/ajax/libs/picturefill/3.0.2/picturefill.min.js https://*.google-analytics.com https://*.googletagmanager.com https://www.youtube.com/iframe_api https://www2.osfound.org/shorten https://*.ingest.sentry.io https://docket.justiceinitiative.org https://justiceinitiative.containers.piwik.pro https://*.justiceinitiative.org https://cdn-cookieyes.com https://log.cookieyes.com https://*.cookieyes.com https://cdn.matomo.cloud https://theideasletter.matomo.cloud 'sha256-fowkKyEQi1SMOmkzKHVR3kVRCxAkb7eITj4LYDwWuwE=' 'sha256-oLlgRvu5927ZsW/Ke7hqoXyWhVhfjYt888/If4Yk6Cc=' 'sha256-zTv/Ocm+3ZUxPK95MsRtR405opnhJuWd8OOOlDOY4jg=' 'sha256-rWd9UEdKeFeLqC7IaJz1wxlZctnoLlCVLl196dQ3XcM=' 'sha256-Wuuo8pjCq8p1DupaB6iKVd7xGXUV2cZ6FNKupyZkqtA=' 'sha256-Yo0rp6K5ZDMBPy3XfvFf6KNJPsyXl4KgVKlu1R1a3xQ=' 'sha256-MM3CG7szGAeVIKY58JGR+X+7xTDccDemqcIY0lQLrX8=' 'sha256-oh6ZTSefRfIBPlcye8dBjlQBkC0A32V1QIb2htJq7ao=' 'sha256-NmZgHsyoB9XJ6Wd+G4VMaoO3gnTIG8KiH+uVcxOeeoc=' 'sha256-qwhoBj+FiypvTPR3eQkqsvLUkSeShbVBRVleFpBWM0g=' 'sha256-ojZToIWnCw4yAO2wwSr0xkCYSoCACGXKKYmr9ZV6u7I=' 'sha256-MK/1crn2Wl/TYQNKpPss5ootd4EotbGRxQsmw+4y1gU=' 'sha256-IobZaBCT4PRq1c9DaVhn7w+Z0rXZcBjmuQBfk+M+z64=' 'sha256-DqrJErZI/7pog0A9GesbTSM9ARg5dFwEiTotQt+PXns=' 'sha256-veJ+ybPvqZmAOLrVwklPodQgAnVnspZnObsF0U42hqo' 'sha256-+fx2G+aE0ETxN+0K/lnVPgcwJBbC7vQs8fcKUg1eWKc=' 'sha256-lGf/YZe+HEzkMEOQc5bjVpCG99fBIWrHzKnAn+UsbmE=' 'nonce-UmeTs3Y1dY87qNEPTCJ97KafPm56II2e';style-src 'self' 'unsafe-inline' https:;frame-src 'self';font-src 'self' https:;media-src 'self' https:;manifest-src 'self';worker-src 'none' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com/analytics.js; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://api.lever.co https://backend.tendermint.com https://www.google-analytics.com; font-src 'self' data: fonts.gstatic.com https://raw.githubusercontent.com; frame-src 'self'; img-src 'self' data: about: blob: https://www.gstatic.com/images/ https://cdn-images-1.medium.com https://d33wubrfki0l68.cloudfront.net https://www.google-analytics.com; manifest-src 'self'; media-src 'self' data:; worker-src 'none'; frame-ancestors 'none'; form-action 'self'; report-uri https://bce8f9ed809bb395c2d2805d76f7e87a.report-uri.com/r/d/csp/reportOnly; 1 font-src www.paypalobjects.com *.fontawesome.com *.bootstrapcdn.com *.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com *.facebook.com *.facebook.net *.doubleclick.net *.google.com.vn *.google-analytics.com *.paypal.com *.googletagmanager.com *.bootstrapcdn.com *.googleadservices.com *.googleapis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.azurewebsites.net https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.facebook.com *.facebook.net *.doubleclick.net *.google.com *.google.com.vn *.google-analytics.com *.paypal.com *.googletagmanager.com *.gstatic.com *.bootstrapcdn.com *.googleadservices.com *.googleapis.com *.azurewebsites.net *.avada.io *.shopify.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com *.facebook.com *.facebook.net *.doubleclick.net *.google.com.vn *.google-analytics.com *.paypal.com *.googletagmanager.com *.bootstrapcdn.com *.googleadservices.com *.googleapis.com https://fonts.bunny.net cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.azurewebsites.net https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem 'self' cdn.jsdelivr.net fonts.googleapis.com *.bootstrapcdn.com *.your-server.de *.dorotheum-juwelier.com *.sentry-cdn.com 'unsafe-inline'; script-src-elem 'self' cdn.jsdelivr.net www.google.com *.googletagmanager.com *.gstatic.com *.google-analytics.com cdn.usersnap.com api.usersnap.com *.facebook.net *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hubspot.com 'unsafe-inline'; font-src *.googleapis.com https://www.gstatic.com *.klarnacdn.net data: *.fontawesome.com fonts.gstatic.com online.swagger.io *.dorotheum-juwelier.com *.slant.co https://widgets.trustedshops.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.dorotheum-juwelier.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com www.google.com *.weltpixel.com https://www.google.com *.facebook.com *.hubspot.com *.usercentrics.eu *.dorotheum-juwelier.com *.livechatinc.com *.googletagmanager.com *.instagram.com *.kabeg.at *.klarnaservices.com *.noel.gv.at *.oebb.at vimeo.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com img.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net *.googleapis.com *.gstatic.com www.apptrian.com *.cdninstagram.com *.fbcdn.net online.swagger.io cdn.usersnap.com cdn.jsdelivr.net www.google.at *.ecxdev.io *.hsforms.com *.hubspot.com *.usercentrics.eu *.cookielaw.org *.dorotheum-juwelier.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.klarna.com *.klarnacdn.net polyfill.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://www.gstatic.com www.apptrian.com *.klarnaservices.com *.avada.io *.fontawesome.com *.usersnap.com https://www.google.com *.payments-amazon.com *.ecxdev.io *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hsforms.net *.hubspot.com *.usemessages.com *.usercentrics.eu *.dorotheum-juwelier.com *.sentry-cdn.com *.clarity.ms *.cookielaw.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-inline'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.fontawesome.com *.dorotheum-juwelier.com *.sentry-cdn.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com www.apptrian.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io api.usersnap.com *.amazon.com *.paypal.com *.google-analytics.com *.hscollectedforms.net *.hsforms.com *.hubspot.com *.usercentrics.eu *.cookielaw.org *.dorotheum-juwelier.com *.sentry.io *.trustedshops.com *.etrusted.com https://integrations.etrusted.site payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.dorotheum-juwelier.com 'self' 'unsafe-inline'; report-uri https://2b973568-2ef7-4890-8ff8-fe126999d884.sansec.watch/; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-sDiH1EB--mhOdssiba1CgA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.superpayments.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.superpayments.com *.stripe.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.superpayments.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.superpayments.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com magefan.com cm.magefan.com https://redchamps.com 'self' data: *.superpayments.com *.stripe.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io *.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.superpayments.com segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com *.superpayments.com *.stripe.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.superpayments.com stripe.com cognito-idp.eu-west-2.amazonaws.com segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.seondnsresolve.com *.seondfresolver.com *.deviceinfresolver.com *.seonintelligence.com *.trustpilot.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com cdn.babymax.nl *.fontawesome.com *.fonts.bunny.net widget.thuiswinkel-cdn.org data: 'self' 'unsafe-inline' https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.twitter.com *.paazl.com cdn.babymax.nl *.googletagmanager.com *.doubleclick.net unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com imgsct.cookiebot.com imgsct.cookiebot.eu *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.paazl.com *.multisafepay.com cdn.babymax.nl bundleconfigurator.babymax.nl *.sleeknote.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.no *.google.com.np *.google.nl *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat blob: files.smartsuppcdn.com widget.thuiswinkel-cdn.org unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ consent.cookiebot.com consent.cookiebot.eu *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.cookiebot.eu *.cookiebot.com *.paazl.com cdn.babymax.nl self *.sleeknote.com *.hotjar.com www.smartsuppchat.com *.smartsuppcdn.com *.thuiswinkel.org *.thuiswinkel-cdn.org g10696554090.co 'unsafe-inline' unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com https://widget-acc.paazl.com https://api-acc.paazl.com/ www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.paazl.com cdn.babymax.nl *.smartsuppcdn.com widget.thuiswinkel-cdn.org 'unsafe-inline' unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://fonts.bunny.net *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn.babymax.nl widget-v3.smartsuppcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu self *.cloudflare.com *.twitter.com *.twimg.com *.paazl.com cdn.babymax.nl *.google.nl *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com wss://*.smartsupp.com *.googlesyndication.com *.doubleclick.net *.hotjar.io *.thuiswinkel-cdn.org *.thuiswinkel.org *.sleeknote.com data: wss://ws.hotjar.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://get.geojs.io *.avada.io *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.paazl.com cdn.babymax.nl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://babymax.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net static.lipscore.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com www.xtento.com *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net static.lipscore.com blob: img.youtube.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com static.lipscore.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com *.cloudflare.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com *.googleapis.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com *.klarnacdn.net static.lipscore.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com wapi.lipscore.com users.lipscore.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.googleapis.com api.lipscore.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com https://server-side-tagging-xga7vfylma-uc.a.run.app *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com *.affirm.com *.affirm.ca *.google.com/ https://td.doubleclick.net https://www.googletagmanager.com https://ct.pinterest.com https://x.adroll.com https://cdn.livechatinc.com https://www.facebook.com https://staging-checkout.creditkey.com https://staging.creditkey.com https://checkout.creditkey.com https://creditkey.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.affirm.com *.affirm.ca cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.magezon.com * store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.affirm.com *.affirm.ca cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.google.com/ https://cdn.customgpt.ai https://cdn.livechatinc.com https://api.livechatinc.com https://s.pinimg.com https://s.adroll.com https://connect.facebook.net https://bat.bing.com https://www.googletagmanager.com https://d.adroll.com https://ct.pinterest.com https://api.openwidget.com https://analytics.tiktok.com https://cdn.trackdesk.com https://unpkg.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.doofinder.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com * unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.affirm.com *.affirm.ca *.doofinder.com wss://*.doofinder.com https://stats.g.doubleclick.net https://region1.analytics.google.com https://ct.pinterest.com https://www.google.com https://app.customgpt.ai https://d.adroll.com https://analytics.tiktok.com https://server-side-tagging-xga7vfylma-uc.a.run.app *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.qq.com *.google-analytics.com *.ytimg.com *.youtube.com *.googletagmanager.com *.baidu.com *.cookieinformation.com *.licdn.com *.facebook.net *.marketingautomation.com *.sleeknote.com *.sharpspring.com *.gstatic.com https: 'unsafe-inline' 'unsafe-eval'; block-all-mixed-content; report-uri https://94f62820d7c43df17e384a74a389587c.report-uri.com/r/t/csp/reportOnly 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com https://fonts.bunny.net use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.kpaytest.com.kw *.kpay.com.kw *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.weltpixel.com cdn.moengage.com/ *.kpaytest.com.kw *.kpay.com.kw http://www.sandbox.paypal.com *.twitter.com checkout.tabby.ai static.addtoany.com/ *.google-analytics.com *.gstatic.com *.pinterest.com *.facebook.com 'self' 'unsafe-inline'; img-src 'self' data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.gstatic.com moe-email-campaigns.s3.amazonaws.com/ image.moengage.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.braintreegateway.com *.amazonaws.com antoine-images.com *.olx.com.lb *.ibb.co cdn-cookieyes.com https://firebasestorage.googleapis.com https://www.magezon.com *.pinterest.com *.facebook.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com cdn.moengage.com/webpush/moe_webSdk.min.latest.js cdn.moengage.com/webpush/modules/inapp.js cdn.moengage.com/webpush/beta/sdk.inapp.cdnHelper.js cdn.moengage.com/webpush/releases/serviceworker_cdn.min.latest.js cdn.moengage.com/webpush/moe_webSdk_cards.min.latest.js cdn.moengage.com/webpush/moe_webSdk_webp.min.latest.js app-cdn.moengage.com/ cdn.moengage.com/release/dc_2/moe_webSdk.min.latest.js *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.cardinalcommerce.com *.doubleclick.net *.paypal.com *.ytimg.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.mastercard.com *.gateway.mastercard.com static.addtoany.com cdn-cookieyes.com *.livechatinc.com 'self' data: *.avada.io *.shopify.com *.pinterest.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cloudflare.com *.googleapis.com *.fontawesome.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com https://fonts.bunny.net use.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sdk-02.moengage.com/ sdk-02.moengage.com *.kpaytest.com.kw *.kpay.com.kw *.cloudflare.com *.twitter.com *.cookieyes.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://stats.g.doubleclick.net checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.cardinalcommerce.com analytics.google.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io cdn-cookieyes.com *.livechatinc.com 'self' data: maps.googleapis.com https://get.geojs.io *.avada.io stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com web.facebook.com www.facebook.com consentcdn.cookiebot.com *.trustpilot.com *.empathy.* https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com storage.googleapis.com forms-eu1.hsforms.com track-eu1.hubspot.com www.google.be www.google.es www.google.com.ar www.facebook.com maps.gstatic.com connect.facebook.net scontent-cdt1-1.cdninstagram.com scontent-cdt2-1.cdninstagram.com scontent-cdg2-1.cdninstagram.com imgsct.cookiebot.com perf-eu1.hsforms.com *.hubspotusercontent-eu1.net *.trustpilot.com *.empathy.* http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com cdn.jsdelivr.net connect.facebook.net js-eu1.hs-scripts.com js-eu1.hs-analytics.net js-eu1.hsadspixel.net js-eu1.hscollectedforms.net js-eu1.hs-banner.com js-eu1.hsleadflows.net searchserverapi.com pixel.convertize.io consent.cookiebot.com consentcdn.cookiebot.com js-eu1.usemessages.com js-eu1.hubspot.com static.hotjar.com script.hotjar.com *.trustpilot.com *.empathy.* http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com cdn.jsdelivr.net *.trustpilot.com *.empathy.* *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com api-eu1.hubapi.com forms-eu1.hubspot.com graph.instagram.com maps.googleapis.com forms-eu1.hscollectedforms.net consentcdn.cookiebot.com pagead2.googlesyndication.com cta-eu1.hubspot.com api-eu1.hubspot.com *.google-analytics.com *.trustpilot.com *.empathy.* http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem *.useinsider.com; script-src-elem www.paidonresults.net youtube.com; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.bootstrapcdn.com *.typekit.net js.klevu.com *.zopim.com xmpp-contact.unlimitedhorizon.co.uk *.useinsider.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com www.soholighting.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com www.facebook.com *.americanexpress.com *.arcot.com *.monzo.com *.securesuite.co.uk authentication-acs.marqeta.com www.soholighting.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.soholighting.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com c.paypal.com *.instagram.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.awin1.com *.zenaps.com assets.braintreegateway.com tst.kaptcha.com www.paypalobjects.com *.zopim.com speedsize.com *.speedsize.com ct.pinterest.com *.freshchat.net *.freshchat.com *.useinsider.com *.arcot.com *.monzo.com *.securesuite.co.uk authentication-acs.marqeta.com account.fetchify.com *.trustpilot.com *.weltpixel.com www.soholighting.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.cdninstagram.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.awin1.com *.zenaps.com *.bing.com *.clarity.ms js.klevu.com cdn-cookieyes.com validate.fishpig.co.uk speedsize.com *.speedsize.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com ct.pinterest.com www.google.co.uk *.googleapis.com *.ggpht *.googlesyndication.com *.sagepay.co.uk xmpp-contact.unlimitedhorizon.co.uk *.useinsider.com *.easyfundraising.org.uk *.wepowerconnections.com *.klevu.com *.ksearchnet.com www.soholighting.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com 'self' bat.bing.com js.klevu.com *.clarity.ms *.newrelic.com *.nr-data.net c.paypal.com chimpstatic.com cdn-cookieyes.com *.hotjar.com sentry.bigeyedeers.dev https://browser.sentry-cdn.com speedsize.com *.speedsize.com cdn.jsdelivr.net unpkg.com cdnjs.cloudflare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ downloads.mailchimp.com *.list-manage.com *.googleapis.com *.googlesyndication.com t.elesi.com porjs.com widget.trustpilot.com s.pinimg.com *.freshchat.net *.freshchat.com xmpp-contact.unlimitedhorizon.co.uk www.paidonresults.net youtube.com widget.freshworks.com m2epro.freshdesk.com *.klevu.com *.ksearchnet.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com www.soholighting.com https://so.soholighting.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.bootstrapcdn.com *.typekit.net js.klevu.com speedsize.com *.speedsize.com https://static.klaviyo.com downloads.mailchimp.com *.freshchat.net *.freshchat.com xmpp-contact.unlimitedhorizon.co.uk *.useinsider.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com tagmanager.google.com www.soholighting.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com speedsize.com *.speedsize.com www.soholighting.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.google-analytics.com *.facebook.com *.facebook.net https://the.sciencebehindecommerce.com *.sandbox.braintree-api.com *.clarity.ms *.nr-data.net *.cookieyes.com cdn-cookieyes.com *.doubleclick.net *.trustpilot.com *.hotjar.com *.googlesyndication.com https://*.ingest.sentry.io speedsize.com *.speedsize.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.google.co.uk www.googleadservices.com ct.pinterest.com *.useinsider.com *.wepowerconnections.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klevu.com *.ksearchnet.com https://www.google-analytics.com www.soholighting.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com www.soholighting.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com elesi.com www.elesi.com cdn.elesi.com static.elesi.com soholighting.com www.soholighting.com cdn.soholighting.com static.soholighting.com lighteningbox.com www.lighteningbox.com cdn.lighteningbox.com static.lighteningbox.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sentry.bigeyedeers.dev/api/6/security/?sentry_key=476f7497936cfb1dfb62eeeaa2a7f1cb; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.weltpixel.com www.google.com www.gstatic.com apis.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com maps.googleapis.com *.amazonaws.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com ajax.googleapis.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net https://fonts.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.sagepay.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.klarna.com *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.sagepay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.gstatic.com *.googleapis.com *.b0e8.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.b0e8.com *.bc0a.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.google.com/ https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.sagepay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.trustpilot.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.trustpilot.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sagepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 script-src 'self' 'nonce-mQ6Ygpc2JHHGGEXJ4USYmw=='; report-uri / 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=968bd653-5e5d-4ddd-bd39-de348e654138; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 script-src 'nonce-2Ncatesi9/jxnipNPMOZMA==' 'report-sample' https://www.french-games.net/cdn-cgi/* https://static.french-games.net/* https://static.cloudflareinsights.com https://challenges.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://pagead2.googlesyndication.com https://adservice.google.com https://googleads.g.doubleclick.net https: 'unsafe-inline'; script-src-elem 'nonce-2Ncatesi9/jxnipNPMOZMA==' https://www.french-games.net/cdn-cgi/* https://static.french-games.net/* https://static.cloudflareinsights.com https://challenges.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://pagead2.googlesyndication.com https://adservice.google.com https://googleads.g.doubleclick.net https: 'unsafe-inline'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; report-uri /ajax/logcsperror 1 frame-ancestors 'self'; report-to csp-report-only; report-uri https://cspreports.realpage.com/api/reports/save/report-only; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.facebook.com *.google.com *.google.com.vn https://stats.g.doubleclick.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.twitter.com *.facebook.com *.google.com *.google.com.vn https://stats.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net *.newrelic.com *.nr-data.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' https://cdn.jollibee.com.vn 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.twitter.com *.facebook.com *.google.com *.google.com.vn https://stats.g.doubleclick.net https://plumrocket.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.gstatic.com *.googleapis.com *.facebook.com *.google.com *.google.com.vn 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googletagmanager.com *.google.com *.googleapis.com *.facebook.com *.google.com.vn https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://connect.facebook.net *.nr-data.net *.newrelic.com *.netcoresmartech.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.facebook.com *.google.com *.google.com.vn *.netcoresmartech.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google-analytics.com *.ip-api.com *.facebook.com *.google.com *.google.com.vn https://stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self'; frame-src 'self'; object-src 'none'; 1 font-src *.googleapis.com *.gstatic.com data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com www.xtento.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.google.com *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.trackedlink.net *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com www.xtento.com cdn.xtento.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.attn.tv events.attentivemobile.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com www.xtento.com cdn.xtento.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.attn.tv events.attentivemobile.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.alothemes.com *.magepow.com https://fonts.googleapis.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trackedlink.net *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.co.uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.unpkg.com https://unpkg.com https://requirejs.org https://maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.alothemes.com *.magepow.com assets.braintreegateway.com https://fonts.googleapis.com https://fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://maps.googleapis.com https://region1.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; report-uri https://stopkillerrobots.org?gdsih-csp-report; 1 default-src 'self' https://*.uestra.de https://cloud.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://img.youtube.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://cloud.ccm19.de https://elma.gvh.de; base-uri 'self' https://*.uestra.de; frame-src 'self' blob: https://*.youtube.com/ https://gvh.demo.hafas.cloud https://gvh.hafas.de https://abo.gvh.de https://cloud.ccm19.de https://deutschlandticket.gvh.de https://transport.novafind.eu/; media-src 'self' blob:; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://cloud.ccm19.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de https://stats.uestra.de 'report-sample'; font-src 'self' data: https://fonts.gstatic.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://stats.uestra.de https://elma.gvh.de; connect-src 'self' https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://stats.uestra.de https://elma.gvh.de; object-src 'self' blob: https://*.uestra.de; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://relaunch.uestra.de https://*.webit.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://www.uestra.de https://relaunch.uestra.de https://stats.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://elma.gvh.de 'report-sample'; frame-ancestors 'self' https://*.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de; form-action 'self'; report-uri https://www.uestra.de/@http-reporting?csp=report&requestTime=1765933705517010&requestHash=e6e810d31d8d8f513697190c01453f61eac24cad 1 img-src https: data:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline' 1 object-src 'none'; connect-src 'self' *.blowpass.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.blowpass.com join.gammasecure.com; script-src 'self' *.blowpass.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.blowpass.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.se ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.se *.spreadshirt.se ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.se ; font-src 'self' https: data: *.spreadshirt.se ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.se ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.se ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 default-src 'self' 'unsafe-inline' www.googletagmanager.com; connect-src 'self' stats.g.doubleclick.net www.google-analytics.com www.facebook.com; font-src 'self' fonts.gstatic.com; form-action 'self' *.facebook.com; frame-src 'self' https://mozbar.moz.com *.twitter.com *.facebook.com *.youtube.com; img-src 'self' blob: *.twitter.com *.facebook.com *.google-analytics.com www.googletagmanager.com data:; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'sha256-t7PRulDBsBN40urjjgytSFhjqGMYT5Kl3fdRE2ubvSE=' 'sha256-vL/UzBZz8IbbPTmdNOgTwTx9iMwsGVM+gcN65JsVkDs=' 'sha256-S0XUzHZoDoB9/hx7r05o2BA44KqBY0GRS7uUeOn7m6w=' 'sha256-HKRD3wb0LE1gQr+YGmAPtJeS7e6cc/VmvLqzykg7RC4=' 'sha256-uFV0NPG/pWXptUbx5XcwBHbhPGDxz/9Y++GGxxJ9COg=' 'sha256-Hx522ue/2keAMYU+UzkDxVexE9HoQ154EbuSno7RyXo=' 'sha256-2NqnatcPqy5jjBXalTpZyJMO/0fUaYUb3ePlviUP4II=' 'sha256-3HKyJTHCclaNd/c73eY3lARVMZ5HhgL//Z4Y9iyZwS0=' 'sha256-tz5dYCqMXXIUZgYND7s9k+WMYO0xLf1k1ao2qJ4SfIg=' 'sha256-LPfty6rGPdwB3t78TnFfkcK5f0bAtVn45Lio4LNK3NI=' 'sha256-UTCVm60QfQFHVOpQI3OLoctvejHNx0+HULCqezCINhY=' 'sha256-UITiqbXyaWS7NpwiFrMIbdXAZy5EXLRUHkpylF4504k=' 'sha256-Vqqy1EC4o2NeucB3SDVgIye7XvqKdlrCBRF2Y8vEbQo=' 'sha256-KjPEOuxv7NuVC7z0lYu6dL4wI0jzM3ITmXypoty3jSw=' 'sha256-VKAaJ2oQNivaQjh0ZN2vS9EPAmX80LShK/wQBqviYk4=' 'sha256-LPfty6rGPdwB3t78TnFfkcK5f0bAtVn45Lio4LNK3NI=' 'sha256-UTCVm60QfQFHVOpQI3OLoctvejHNx0+HULCqezCINhY=' 'sha256-Xj7O0zUcSSSgumEShX6kqyjYSm510v2xE+EL2bbKW9E=' 'sha256-sSOWNIawm+pckUcq4r55z6eSntM9zhX789Fk1No4c80=' 'sha256-JOWRgjcky15TFNId0Eriikp+RUe5xMIjiBWFj28khRI=' 'sha256-KjPEOuxv7NuVC7z0lYu6dL4wI0jzM3ITmXypoty3jSw=' 'sha256-Hx522ue/2keAMYU+UzkDxVexE9HoQ154EbuSno7RyXo=' 'sha256-Afstol4nLODtvjRLyF6XmhANHJHIQi+roPlGB9DC8Ho=' *.facebook.net *.twitter.com *.norton.com *.google-analytics.com *.googletagmanager.com; style-src-attr 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'sha256-VKAaJ2oQNivaQjh0ZN2vS9EPAmX80LShK/wQBqviYk4=' 'sha256-LPfty6rGPdwB3t78TnFfkcK5f0bAtVn45Lio4LNK3NI=' 'sha256-UTCVm60QfQFHVOpQI3OLoctvejHNx0+HULCqezCINhY=' 'sha256-Xj7O0zUcSSSgumEShX6kqyjYSm510v2xE+EL2bbKW9E=' 'sha256-sSOWNIawm+pckUcq4r55z6eSntM9zhX789Fk1No4c80=' 'sha256-JOWRgjcky15TFNId0Eriikp+RUe5xMIjiBWFj28khRI=' 'sha256-KjPEOuxv7NuVC7z0lYu6dL4wI0jzM3ITmXypoty3jSw=' 'sha256-VKAaJ2oQNivaQjh0ZN2vS9EPAmX80LShK/wQBqviYk4=' 'sha256-LPfty6rGPdwB3t78TnFfkcK5f0bAtVn45Lio4LNK3NI=' 'unsafe-eval'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com http://fonts.googleapis.com; object-src 'none'; base-uri 'self'; upgrade-insecure-requests; report-uri https://csp.isecurenet.in/_csp_exim 1 default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; child-src 'self' https://analytics.zoho.eu https://www.google.com; script-src 'self' https://*.google.com https://*.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://sc.lfeeder.com https://cdn.amcharts.com https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://tr-rc.lfeeder.com; connect-src 'self' https://*.google.com https://*.google-analytics.com; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-3Jnzu92C9GJBFHSARwlHTg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 upgrade-insecure-requests; media-src https: blob:; child-src https: blob:; default-src https: wss: 'unsafe-inline' 'unsafe-eval' data:; font-src https: data:; img-src https: data:; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.fontawesome.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ pestweb.com https://*.cardconnect.com/ *.dotdigital-pages.com *.dotdigital.com *.google.com/ *.addthis.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.googleapis.com *.gstatic.com https://www.magezon.com https://cdn.brainier.com https://img.delvenetworks.com cdn.doofinder.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.nr-data.net uat01-ecommerceidentity.cs90.force.com univar--uat01.my.salesforce.com *.hsforms.net *.hsforms.com www.google.com.ua *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://rum.hlx.page *.googleapis.com *.gstatic.com *.rejoiner.com https://*.cloudfront.net https://*.gosquared.com https://sst.veseris.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.disqus.com *.google.com uat01-ecommerceidentity.cs90.force.com univar--uat01.my.salesforce.com *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com sst.veseris.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.fontawesome.com *.typekit.net *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com *.rejoiner.com https://sst.veseris.com *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.stats.g.doubleclick.net *.doubleclick.net *.google-analytics.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.facebook.net sst.veseris.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; 1 upgrade-insecure-requests; default-src 'none'; object-src 'self'; media-src 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src https://www.youtube.com; img-src 'self' data: https://www.google-analytics.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'nonce-782e8cae6de698fd36efeaea472db869cb892280' 'sha256-NeueIEO8rwnaeJW0jYHRwrarPP+KzGzhk6xBJ06ntlw=' https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://maps.googleapis.com; 1 font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com chatwoot.goodwine.ua 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com cdn.jsdelivr.net connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com chatwoot.goodwine.ua multisearch.io *.sentry-cdn.com scripts.claspo.io https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net chatwoot.goodwine.ua *.sentry.io https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com a.plerdy.com multisearch.io chatwoot.goodwine.ua 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com fonts.gstatic.com *.fonts.googleapis.com data: *.cloudflare.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com td.doubleclick.net www.googletagmanager.com https://plumrocket.com *.addthis.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.google.co.in *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io s7.addthis.com www.googletagmanager.com googleads.g.doubleclick.net *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io google.com www.google.com analytics.google.com stats.g.doubleclick.net *.cloudflare.com *.paypal.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https://cdn.jsdelivr.net; script-src-attr 'self'; style-src 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 ; worker-src 'strict-dynamic'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.managed-protection.com https://www.googletagmanager.com; report-uri https://acronis.report-uri.com/r/t/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com api.razorpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://cdn.cookielaw.org cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com *.artfut.com *.googletagmanager.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://23hssicm9.de 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 'unsafe-eval' 'unsafe-inline'; img-src * data: 'unsafe-eval' 'unsafe-inline'; font-src * data: 'unsafe-eval' 'unsafe-inline'; report-uri /report-csp-violation 1 frame-ancestors 'self' goldcoast.admin.opencities.com www.goldcoast.qld.gov.au; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com *.alothemes.com *.magepow.com *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.google.com maps.googleapis.com maps.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://ssl.ceneo.pl ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.alothemes.com *.magepow.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.google.com maps.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://ssl.ceneo.pl chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.alothemes.com *.magepow.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://static.klaviyo.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://editor-api.webflow.com https://featureassets.org https://prodregistryv2.org https://analytics.google.com https://stats.g.doubleclick.net https://aplo-evnt.com https://acsbapp.com https://*.acsbapp.com https://px.ads.linkedin.com https://realtime.webflow.com wss://realtime.webflow.com; font-src data: https://cdn.prod.website-files.com https://d3e54v103j8qbb.cloudfront.net; frame-ancestors 'none'; frame-src https://webflow.com https://form.jotform.com; img-src https://cdn.prod.website-files.com https://d3e54v103j8qbb.cloudfront.net https://linkedin.com https://px.ads.linkedin.com https://uploads-ssl.webflow.com https://daks2k3a4ib2z.cloudfront.net https://secure.gravatar.com; media-src https://cdn.prod.website-files.com; script-src 'unsafe-eval'; script-src-elem 'self' 'sha256-mjdgHR9aXy+6OwAGlNS/XgNcYG1Uhd2U4pl8vi7+XCY=' 'sha256-LkyUzXZ0rZIq9Kc0CH1y91JAi9T8L1oNgK9Qc+PNLkg=' 'sha256-yX//mHTbJDudqi7Y2eOiCDPcF9sfx5o997v1QfEQ9tM=' 'sha256-ZmBFzpltiyz8GeBj/QhfcGVr2qDzPk1Gqxe184exULM=' https://d3e54v103j8qbb.cloudfront.net https://cdn.prod.website-files.com https://www.googletagmanager.com https://form.jotform.com https://cdn.jotfor.ms https://widgets.jotform.io https://cdn.linkstechnology.net https://cdn.jsdelivr.net https://assets.apollo.io https://acsbapp.com https://snap.licdn.com https://analytics.webflow.com; style-src 'unsafe-inline' https://d3e54v103j8qbb.cloudfront.net https://cdn.prod.website-files.com https://cdn.jsdelivr.net; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com s7.addthis.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-xsMCF6V_m5OOLWsON9geag'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-xsMCF6V_m5OOLWsON9geag'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=20531&v=v1.0&payload=k-WT4gQxz0zNXsTJWjuX4KYca6kWcHawgV6KFHIHDG6X4EV78h8LIPTUax8O-0gBwQvdqsyS7UuzyM_gGNLmLTp0OUAz_MLUvcE7y6eqS8aTP7LbQxXytg4SpZq-3SJ2s5vbAA7PkvjBIguH3yubMTgR-V6qfzpDEOOruBFwuG-tm_WI1swq-cOecshvZ6XRiPTgv-S2y9lvMZG1OLIj2Q==; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.no https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com https://webcache.googleusercontent.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com *.facebook.com https://s.ytimg.com *.funstra.com *.doubleclick.net https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cloudflare.com *.facebook.net https://webcache.googleusercontent.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com https://webcache.googleusercontent.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflare.com *.google-analytics.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.funstra.com.au; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.doubleclick.net *.adobedtm.com *.adobe.com *.tawk.to *.sooqr.com *.fontawesome.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cookiebot.com *.weltpixel.com js.mollie.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.google.com *.google.nl *.cookiebot.com *.spotlersearch.com https://www.mollie.com *.googleapis.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.sooqr.com www.magmodules.eu *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.doubleclick.net *.adobedtm.com *.tawk.to *.luckyorange.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.jsdelivr.net *.googletagmanager.com *.googleapis.com *.cookiebot.com *.addthis.com *.hotjar.com *.hotjar.io js.mollie.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com squeezely.tech www.squeezely.tech *.squeezely.tech 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tawk.to *.sooqr.com *.fontawesome.com *.tagmanager.google.com *.googleapis.com *.spotlersearch.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.doubleclick.net *.adobedtm.com *.adobe.com *.googleapis.com *.tawk.to *.luckyorange.com *.sooqr.com *.google-analytics.com wss://* *.cookiebot.com *.hotjar.com *.hotjar.io *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app *.spotlersearch.com squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubdc168fd6fb5f2bf245b09ff737b0112b&ddsource=csp-report&dd-evp-origin=content-security-policy&ddtags=environment%3Aprod%2Ccontinent%3Aeu%2Csource%3Anode%2Cservice%3Afront-office%2CserviceVersion%3A745d939ae34be1d6c9a7ef7dcde866d1572ecceb%2Cpolicy-id%3Alist-all-scripts; 1 font-src *.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.youtube.com/ *.google.com *.google.com.ua *.google.co.uk *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.google.com.ua *.google.co.uk *.doubleclick.net *.facebook.com https://firebasestorage.googleapis.com *.meetanshi.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.google.com *.google.com.ua *.google.co.uk *.googletagmanager.com *.doubleclick.net *.facebook.net www.termsfeed.com *.avada.io *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googletagmanager.com https://fonts.bunny.net *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.nr-data.net *.newrelic.com *.ampproject.org *.google.com https://get.geojs.io *.avada.io *.meetanshi.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://accounts.google.com https://www.facebook.com https://login.live.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.egoi.page egoi.page *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com egoimmerce.e-goi.com *.egoimmerce.e-goi.com egoiapp2.com *.egoiapp2.com https://www.mercadolibre.com https://www.mercadolivre.com magefan.com cm.magefan.com *.disqus.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ e-goi.com *.e-goi.com egoiapp2.com *.egoiapp2.com egoi.site *.egoi.site https://secure.mlstatic.com https://cdn.socket.io *.disqus.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.egoiapp2.com egoiapp2.com *.fontawesome.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org *.googleapis.com egoiapp2.com egoi.page https://api.mercadopago.com https://www.mercadolibre.com https://www.ipag.com.br *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data: blob:; media-src https: blob:; font-src https: data:; report-uri /csp-report 1 font-src *.googleapis.com *.gstatic.com 'unsafe-inline' data: *.klevu.com *.fontawesome.com *.crisp.chat *.typekit.net https://client.crisp.chat *.ksearchnet.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.klevu.com *.fontawesome.com *.imagekit.io *.bing.com *.crisp.chat *.clarity.ms *.cloudfront.net store.paradoxlabs.com https://image.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.klevu.com *.fontawesome.com *.rtrk.chukar.com *.bing.com *.crisp.chat *.clarity.ms *.recipal.com *.newrelic.com https://client.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com *.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klevu.com *.gstatic.com *.googleapis.com *.fontawesome.com *.crisp.chat *.typekit.net *.klaviyo.com https://client.crisp.chat https://static.klaviyo.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.klevu.com *.gstatic.com *.fontawesome.com *.crisp.chat wss://client.relay.crisp.chat *.clarity.ms *.nr-data.net *.stats.g.doubleclick.net *.doubleclick.net https://client.crisp.chat https://plugins.crisp.chat https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://68f5c4fa-6c17-48d5-a3ed-41390ac63269.sansec.watch/; report-to report-endpoint; 1 frame-ancestors 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.cloudmaestro.com www.nightingale.com nightingale.com www.googletagmanager.com acsbap.com acsbapp.com www.google-analytics.com 'unsafe-hashes'; report-uri /.webscale/csp-report 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.certcapture.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.certcapture.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.certcapture.com downloads.mailchimp.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.certcapture.com *.authorize.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.bootstrapcdn.com *.cdn-apple.com *.reviews.io *.cloudflare.com *.gstatic.com *.alicdn.com d19ayerf5ehaab.cloudfront.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.cardinalcommerce.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src *.lloydsbankinggroup.com *.freshchat.com *.paypalobjects.com *.pinterest.com *.google.com *.cookiebot.com www.google.com.mt *.cdn-apple.com *.rvvup.com *.reviews.io *.paypal.com *.youtube.com *.cardinalcommerce.com *.facebook.com www.google.es *.reviews.co.uk *.doubleclick.net *.googletagmanager.com www.google.com.om *.trustpayments.com www.google.co.uk *.typeform.com www.google.fr 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src www.google.com.pk www.google.com.my www.google.com.gi www.google.gr www.google.fr s3-eu-west-1.amazonaws.com www.google.com.ng *.ytimg.com *.googleapis.com www.google.com.cy www.google.co.id www.google.com.qa *.googletagmanager.com www.google.com.co www.google.com.bh www.google.com.tw *.paypal.com www.google.com.om www.google.cv www.google.tn www.google.tt www.google.com.sg *.facebook.com www.google.nl www.google.co.in d3k81ch9hvuctc.cloudfront.net www.google.gg www.google.ge www.google.lk www.google.by www.google.gl www.google.com.lb *.bing.net www.google.at www.google.al www.google.ro s3.amazonaws.com www.google.no www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.cm www.google.mw www.google.com.pa www.google.co.ve *.rvvup.com www.google.ae www.google.com.pg www.google.pl www.google.com.fj www.google.com.tr www.google.com.kw www.google.dk www.google.bt www.google.com.uy www.google.com.np www.google.se www.google.pt www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn *.gumlet.io www.google.com.bn www.google.ru www.google.jo www.google.it www.google.ch www.google.com.et www.google.ee www.google.com.py *.facebook.net www.google.hu www.google.ml d19ayerf5ehaab.cloudfront.net www.google.co.ao *.paypalobjects.com www.google.com.pr *.gstatic.com www.google.iq www.google.ca www.google.li www.google.com.na www.google.sn www.google.gy *.reviews.io www.google.md www.google.com.mm www.google.co.jp www.google.sr *.ometria.com www.google.am www.google.de *.cookiebot.com www.google.cl www.google.to www.google.im *.doubleclick.net www.google.es www.google.co.za www.google.com.ag www.google.lt www.google.is www.google.gm www.google.com.bo www.google.co.nz www.google.lu www.google.co.uk www.google.com.do www.google.co.zw www.google.com.eg *.google.com www.google.co.ma *.trackedweb.net www.google.com.br www.google.com.jm www.google.cg www.google.com.bd *.googleadservices.com www.google.ht www.google.fi www.google.sk www.google.kz www.google.co.ug www.google.com.ph www.google.je *.reviews.co.uk www.google.co.tz www.google.com.au www.google.si www.google.mn www.google.bs www.google.lv www.google.com.mt www.google.ba www.google.mk *.clarity.ms www.google.com.kh www.google.com.sa www.google.so www.google.cz www.google.co.th www.google.co.kr www.google.dz *.bing.com www.google.ci www.google.mv www.google.com.vn www.google.ps www.google.com.hk www.google.sh www.google.co.bw www.google.com.ua www.google.com.ar www.google.com.sl www.google.com.gh www.google.az www.google.rw www.google.com.ly www.google.bg www.google.co.uz data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src *.facebook.net *.cookiebot.com *.adobe.io *.magento-ds.com *.googleapis.com *.gstatic.com *.reviews.io *.clarity.ms *.braintreegateway.com *.googleadservices.com *.ometria.com *.cardinalcommerce.com *.trustpayments.com *.salesfire.co.uk *.klaviyo.com *.cdn-apple.com *.paypalobjects.com *.jquery.com *.mida.so *.doubleclick.net *.pinterest.com *.freshchat.com *.adobedtm.com *.nudgify.com *.cloudflare.com *.google.com *.reviews.co.uk *.bing.com *.adobe.net *.trackedweb.net *.typeform.com unpkg.com *.mplat-ppcprotect.com *.pinimg.com *.crazyegg.com *.paypal.com *.youtube.com *.payments-amazon.com *.jsdelivr.net *.rvvup.com wisepops.net *.cloudflareinsights.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.rvvup.com *.reviews.io *.googleapis.com *.klaviyo.com d19ayerf5ehaab.cloudfront.net cc-cdn.com *.freshchat.com *.jsdelivr.net *.gstatic.com *.bootstrapcdn.com *.reviews.co.uk *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google.com.ph www.google.com.bo www.google.co.ma www.google.com.cy www.google.com.co www.google.com.mt *.clarity.ms *.adobe.io *.googletagmanager.com www.google.com.my www.google.mk www.google.si www.google.cz www.google.com.pr www.google.com.bd d19ayerf5ehaab.cloudfront.net www.google.tt *.craftyclicks.co.uk www.google.com.gh www.google.com.ar www.google.co.uz www.google.co.zw www.google.mw www.google.ae www.google.gr www.google.ro www.google.ci www.google.co.tz www.google.com.np www.google.es www.google.com.lb www.google.lu www.google.com.jm www.google.at *.bing.com *.klaviyo.com *.rvvup.com www.google.com.pk *.datadome.co *.cookiebot.com www.google.bs google.com www.google.gl www.google.ge wisepops.net www.google.sh www.google.com.ag www.google.se www.google.pl www.google.md browser-intake-datadoghq.eu www.google.so *.freshchat.com *.google-analytics.com www.google.com.hk *.facebook.com www.google.ie www.google.com.vn www.google.de *.googleapis.com www.google.mu www.google.co.ve www.google.lk *.mida.so *.reviews.io *.salesfire.co.uk *.reviews.co.uk www.google.co.za www.google.co.kr www.google.fi www.google.kz *.nudgify.com *.smartmetrics.co.uk www.google.com.ly www.google.cg *.bing.net www.google.com.pa www.google.be www.google.im www.google.com.bn *.paypal.com www.google.co.ke *.cardinalcommerce.com *.mplat-ppcprotect.com *.doubleclick.net www.google.com.fj www.google.co.nz www.google.jo www.google.com.pg www.google.nl www.google.ch *.googleadservices.com www.google.az www.google.gg www.google.bg www.google.hn www.google.com.gi www.google.pt www.google.rs www.google.hu www.google.com.mx www.google.com.kh www.google.com.ua www.google.co.il www.google.co.uk www.google.fr www.google.com.sl www.google.co.in *.trustpayments.com *.trackedweb.net www.google.bt www.google.mv www.google.iq www.google.co.jp www.google.co.bw www.google.com.br www.google.no *.google.com www.google.com.om www.google.com.tw www.google.je www.google.com.pe www.google.lt www.google.com.kw www.google.dk www.google.com.tr www.google.hr www.google.co.ug *.adobedc.net www.google.com.au www.google.com.et www.google.sk www.google.gm www.google.com.sa www.google.by kg668dbov0.execute-api.us-east-1.amazonaws.com www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id *.lunio.ai www.google.it www.google.al www.google.com.bh www.google.is www.google.com.mm www.google.com.do www.google.co.th *.pinterest.com www.google.rw *.crazyegg.com www.google.com.ng 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://dbd4205d-b155-4bf5-9c6b-c5a41031bc3b.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.monetate.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.gstatic.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.monetate.net maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.monetate.net *.en25.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.monetate.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com applepay.cdn-apple.com *.revolut.com *.google.com google.com *.cdn-apple.com cdn.polyfill.io pay.google.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.fonts.googleapis.com data: *.cloudflare.com *.yotpo.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io google.com pay.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com business.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.doubleclick.net *.google.it *.googletagmanager.com *.evolv.ai *.pathmonk.com *.visualwebsiteoptimizer.com *.convalytrix.it js.mollie.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com api.payplug.com secure.payplug.com *.revolut.com *.cdn-apple.com cdn.polyfill.io *.gstatic.com webservices.securetrading.net *.addthis.com *.pinterest.com *.trustpilot.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src *.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.googleapis.com *.adobe.com *.demdex.net *.magentocommerce.com *.doubleclick.net google.com *.youtube.co *.paypal.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.doofinder.com business.facebook.com https://images.unsplash.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com *.google.it *.evolv.ai *.pathmonk.com *.visualwebsiteoptimizer.com *.convalytrix.it flagpedia.net https://www.mollie.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io pay.google.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://magento.com *.googleapis.com google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.facebook.com business.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.it *.evolv.ai *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.iubenda.com *.plerdy.com *.analytics.google.com *.pathmonk.com *.visualwebsiteoptimizer.com *.varify.io *.kk-resources.com *.doubleclick.net *.convalytrix.it *.avada.io maps.googleapis.com js.mollie.com *.multisafepay.com https://pay.google.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com api.payplug.com applepay.cdn-apple.com *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io *.development.scalapay.com *.staging.scalapay.com *.scalapay.com webservices.securetrading.net songbirdstag.cardinalcommerce.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doofinder.com cdn.dnky.co webchat.dotdigital.com *.doubleclick.net *.google.com *.google.it *.evolv.ai *.pathmonk.com *.visualwebsiteoptimizer.com *.convalytrix.it *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.multisafepay.com unsafe-inline *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.trustpilot.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.google.com *.google.it *.evolv.ai *.pathmonk.com *.visualwebsiteoptimizer.com *.convalytrix.it 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com business.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.plerdy.com *.doubleclick.net google.com *.google.it *.evolv.ai *.varify.io *.googlesyndication.com *.iubenda.com *.pathmonk.com *.resources.com *.visualwebsiteoptimizer.com *.convalytrix.it https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.multisafepay.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io pay.google.com *.gstatic.com o402164.ingest.sentry.io *.cloudflare.com *.paypal.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.google-analytics.com analytics.google.com *.facebook.net https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src custom.intucdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smarterstore.it/; report-to report-endpoint; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-CtrZVER1c5jJitjPLuQS8ZGBm' 'strict-dynamic'; frame-ancestors 'self'; manifest-src 'self' 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://api.reclameaqui.com.br https://s3.amazonaws.com/raichu-beta/selos https://newimgebit-a.akamaihd.net/ebitBR/medal use.fontawesome.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://www.google.com https://use.typekit.net https://*.konfidency.com.br https://fonts.googleapis.com https://*.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://gyruss.rdops.systems https://www.facebook.com/ https://*.rdstation.com.br https://*.cloudfront.net 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net https://api.reclameaqui.com.br https://chat.directtalk.com.br https://*.konfidency.com.br unsafe-inline https://fonts.gstatic.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://h.online-metrix.net https://td.doubleclick.net https://stape.madeiranit.com.br https://api.reclameaqui.com.br https://maps.google.com/ https://chat.directtalk.com.br unsafe-inline https://*.konfidency.com.br https://www.lojaconfiavel.com https://*.hotjar.com/ https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.googleapis.com https://www.facebook.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://h.online-metrix.net https://ssif1.globalsign.com https://www.globalsign.com https://api.reclameaqui.com.br/* https://s3.amazonaws.com https://newimgebit-a.akamaihd.net/ebitBR/medal www.google.com.br newimgebit-a.akamaihd.net https://fonts.gstatic.com https://stats.g.doubleclick.net http://www.googletagmanager.com https://staticfiles.yviews.com.br https://yv-misc.s3.amazonaws.com https://uploadedfiles.yviews.com.br https://www.google.com https://newimgebit-a.akamaihd.net https://www.ebitempresa.com.br https://empresa.ebit.com.br/ https://chat.directtalk.com.br https://singularbaby.com.br https://*.madeiranit.com.br https://*.konfidency.com.br https://www.google.com.br/ http://www.googleadservices.com http://www.google-analytics.com https://www.facebook.com/ https://*.gstatic.com https://maps.googleapis.com https://*.cloudfront.net/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com https://h.online-metrix.net https://td.doubleclick.net https://stape.madeiranit.com.br https://s3.amazonaws.com https://api.reclameaqui.com.br https://newimgebit-a.akamaihd.net/ebitBR/medal/ https://ssif1.globalsign.com https://www.globalsign.com imgs.ebit.com.br www.clarity.ms unpkg.com reviews.konfidency.com.br d335luupugsy2.cloudfront.net js-agent.newrelic.com https://www.clarity.ms https://*.konfidency.com.br https://maps.googleapis.com http://www.googletagmanager.com https://www.googletagmanager.com https://staticfiles.yviews.com.br https://cdn.siteblindado.com https://api.siteblindado.com https://seal.globalsign.com https://js-agent.newrelic.com https://bam.nr-data.net https://www.gstatic.com https://www.google.com https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js https://imgs.ebit.com.br https://chat.directtalk.com.br https://*.hotjar.com/ https://*.shoptarget.com.br/ https://*.cloudfront.net/ https://*.facebook.net/ https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.googleapis.com https://*.shopback.net/ https://*.shopconvert.com.br/ https://*.rdstation.com.br https://*.cloudfront.net https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://api.reclameaqui.com.br https://s3.amazonaws.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://api.reclameaqui.com.br https://*.konfidency.com.br https://fonts.gstatic.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://viacep.com.br https://www.viacep.com.br http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io www.facebook.com https://www.facebook.com/tr graph.facebook.com business.facebook.com places.googleapis.com https://h.online-metrix.net https://td.doubleclick.net https://stape.madeiranit.com.br https://api.reclameaqui.com.br https://s3.amazonaws.com https://newimgebit-a.akamaihd.net/ebitBR/medal/81589.json bam.nr-data.net https://*.clarity.ms https://*.konfidency.com.br https://api.siteblindado.com https://seal.siteblindado.com.br https://seal.siteblindado.com https://commerce.adobedc.net https://bam.nr-data.net https://www.google.com https://chat.directtalk.com.br wss://am.freshrelevance.com https://*.shoptarget.com.br/ https://*.rdstation.com.br/ https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.googleapis.com https://*.hotjar.io https://content.hotjar.io/ https://*.retargeter.com.br https://*.madeiranit.com.br/ https://ckies.net/ https://*.openfpcdn.io/ https://www.google-analytics.com https://*.rdstation.com.br https://gyruss.rdops.systems https://gtm-kq9xxp7-mjg4y.uc.r.appspot.com/g/collect wss://ws.hotjar.com/api/v2/client/ws 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://newimgebit-a.akamaihd.net/ebitBR/medal/* bam.nr-data.net commerce.adobedc.net unsafe-inline https://*.konfidency.com.br https://fonts.gstatic.com/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com https://cdn.checkout.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.klarnacdn.net *.salesfire.co.uk fonts.gstatic.com data: hello.myfonts.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://js.checkout.com *.klarna.com https://www.googletagmanager.com/ *.twitter.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.salesfire.co.uk tikkurila-dev.prismic.io *.cookiebot.com wisepops.net www.awin1.com td.doubleclick.net *.attn.tv pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarnaevt.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com *.salesfire.co.uk www.photofusion.org www.tikkurila.co.uk images.prismic.io *.prismic.io *.feefo.com v2assets.zopim.io www.google.co.uk www.google.ie *.cookiebot.com www.awin1.com www.tagserve.com lantern.roeye.com bat.bing.com www.wepowerconnections.com events.attentivemobile.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.attn.tv events.attentivemobile.com https://*.checkout.com *.klarnacdn.net *.cdn-apple.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnaservices.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk static.zdassets.com register.feefo.com cdn.noibu.com static.cdn.prismic.io *.googleoptimize.com wisepops.net *.wisepops.net *.gorgias.chat *.cookiebot.com bat.bing.com static.hotjar.com script.hotjar.com lantern.roeyecdn.com *.googlesyndication.com www.awin1.com www.dwin1.com the.sciencebehindecommerce.com api.feefo.com pay.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com cc-cdn.com *.klarnacdn.net *.salesfire.co.uk hello.myfonts.net *.feefo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.attn.tv events.attentivemobile.com https://js.checkout.com *.klarnaevt.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnacdn.net *.klarna.com *.klarnaservices.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.smartmetrics.co.uk ekr.zdassets.com api.feefo.com valttihelp.zendesk.com collect.feefo.com wss://widget-mediator.zopim.com tikkurila-dev.prismic.io wisepops.net *.wisepops.com *.gorgias.chat *.cookiebot.com *.analytics.google.com *.googlesyndication.com *.google-analytics.com ws.hotjar.com content.hotjar.io the.sciencebehindecommerce.com bam.eu01.nr-data.net google.com pay.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /csp/report/log; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.trustedshops.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com vimeo.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io assets.myparcel.nl *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu magefan.com cm.magefan.com *.disqus.com *.sooqr.com https://www.mollie.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com www.rikkoert.nl cdn.riverty.design www.google.nl www.facebook.com static.mailplus.nl content.mailplus.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdnjs.cloudflare.com cdn.jsdelivr.net *.cloudflare.com www.google.com www.gstatic.com *.trustedshops.com *.usercentrics.eu *.disqus.com *.sooqr.com js.mollie.com *.googletagmanager.com tagmanager.google.com app.varify.io varify.io restapi.mailplus.nl widget.trustpilot.com www.clarity.ms s.pinimg.com connect.facebook.net js-agent.newrelic.com ct.pinterest.com tagging.rikkoert.nl tagging.zilverkraamcadeau.nl static.hotjar.com *.optimonk.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.sooqr.com tagmanager.google.com fonts.google.com marcvanwilligen.nl cdn-asset.optimonk.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.myparcel.nl cdn.jsdelivr.net *.cloudflare.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com app.varify.io varify.io stats.g.doubleclick.net cognito-identity.eu-central-1.amazonaws.com ct.pinterest.com bam.eu01.nr-data.net *.optimonk.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com consentcdn.cookiebot.com consentcdn.cookiebot.eu www.facebook.com *.googletagmanager.com www.googletagmanager.com td.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com imgsct.cookiebot.com imgsct.cookiebot.eu *.hsforms.net *.hsforms.com 'self' data: www.facebook.com connect.facebook.net www.google.be *.googletagmanager.com ssl.gstatic.com www.gstatic.com cdn-cookieyes.com www.google.es cdn.connectif.cloud data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com consent.cookiebot.com consent.cookiebot.eu *.hsforms.net *.hsforms.com connect.facebook.net *.googletagmanager.com tagmanager.google.com cdn.connectif.cloud cdn-cookieyes.com static.cloudflareinsights.com pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu t.elasticsuite.io *.hsforms.net *.hsforms.com stats.g.doubleclick.net *.googletagmanager.com pagead2.googlesyndication.com eu5-api.connectif.cloud log.cookieyes.com cdn-cookieyes.com directory.cookieyes.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net https://fonts.gstatic.com cdn.almapay.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com applepay.cdn-apple.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu www.google.com *.avis-verifies.com https://www.googletagmanager.com/ secure-gateway.hipay-tpp.com *.hipay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com lumao.eu *.google.fr *.google.com *.myspectro.io axeptio.imgix.net favicons.axept.io bat.bing.com cdn.wisepops.net *.avis-verifies.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ cdn.doofinder.com openstreetmap.org maps.googleapis.com maps.gstatic.com https://assets.fintecture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.doofinder.com *.myspectro.io static.axept.io bat.bing.com www.clarity.ms cdn.segment.com wisepops.net cdn.wisepops.net cdn.wisepops.com *.avis-verifies.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ cdn.doofinder.com secure-gateway.hipay-tpp.com *.hipay.com mpsnare.iesnare.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com widgets.rr.skeepers.io https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ www.gstatic.com www.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net https://fonts.googleapis.com *.doofinder.com *.hipay.com fonts.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.doofinder.com *.google-analytics.com *.doubleclick.net pagead2.googlesyndication.com tracking.myspectro.io client.axept.io api.axept.io cdn.segment.com api.segment.io *.clarity.ms wisepops.net activity.wisepops.net tracking.wisepops.net wisepops.com activity.wisepops.com tracking.wisepops.com *.hipay-tpp.com bat.bing.com *.avis-verifies.com *.cloudflare.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ wss://*.doofinder.com *.hipay.com wss://mpsnare.iesnare.com widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://www.google-analytics.com https://pagead2.googlesyndication.com/ https://cdn-ukwest.onetrust.com/; font-src 'self' https://use.typekit.net/; frame-src 'self' https://www.googletagmanager.com/; img-src 'self' https://cdn-ukwest.onetrust.com/; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' https://www.googletagmanager.com/ https://cdn-ukwest.onetrust.com/ https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.stripe.com https://services.postcodeanywhere.co.uk https://unpkg.com; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://www.googletagmanager.com/ https://cdn-ukwest.onetrust.com/ https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.stripe.com https://services.postcodeanywhere.co.uk https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://p.typekit.net/ https://cdnjs.cloudflare.com https://services.postcodeanywhere.co.uk https://unpkg.com https://use.typekit.net; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://www.googletagmanager.com/; report-uri https://www.rcot.co.uk/log-report-uri/reportOnly 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com *.criteo.com *.hotjar.com *.pinterest.com *.useinsider.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com https: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com *.ads-twitter.com *.adnxs.com *.api.useinsider.com *.bat.bing.com *.cfjump.com *.clarity.ms *.criteo.com *.dev.visualwebsiteoptimizer.com *.doubleclick.net *.facebook.net *.getsitecontrol.com *.google.com *.googletagmanager.com *.hotjar.com *.inwebr.com *.licdn.com *.newrelic.com *.nr-data.net *.pinimg.com *.redditstatic.com *.roymorgan.com *.thewhiskyclub.com.au *.twitter.com *.zipmoney.com.au *.zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com *.bat.bing.com *.stats.g.doubleclick.net *.clarity.ms *.getsitecontrol.com *.getsitectrl.com *.hotjar.com *.nr-data.net *.pinterest.com *.useinsider.com *.thewhiskyclub.com.au *.zip.co *.zipmoney.com.au *.cdn.linkedin.oribi.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: https://use.fontawesome.com https://fonts.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * google.com gstatic.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.trackedlink.net https://scontent-bom1-1.cdninstagram.com/ https://scontent-bom1-2.cdninstagram.com https://scontent-bom1-2.xx.fbcdn.net https://scontent-bom1-1.xx.fbcdn.net magefan.com cm.magefan.com *.disqus.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com google.com gstatic.com *.cloudflare.com *.google.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com *.googleapis.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.google.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://scontent-bom1-2.cdninstagram.com/ https://scontent-bom1-1.cdninstagram.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://api.sunbit.com/sampling/api/v1/csp-reports?application=my-sunbit&env=dev; default-src 'none'; frame-ancestors 'none'; script-src 'self' https://fpnpmcdn.net https://use1.fptls.com *.sunbit.* *.google.com https://cdnjs.cloudflare.com http://cdnjs.cloudflare.com https://sentry.io *.googletagmanager.com *.google-analytics.com *.datadoghq-browser-agent.com https://www.gstatic.com https://cdn.jsdelivr.net/npm/axios@1.6.2/dist/axios.min.js 'sha256-oNwErqIk8VRSUay1+8A7krM8W1V1Tq/5L14zrrLP8pw=' 'sha256-woAyRoW0yGOEl+CG3XDrIRRr4AqDTWyBET3GMzjr75g=' 'sha256-ThhI8UaSFEbbl6cISiZpnJ4Z44uNSq2tPKgyRTD3LyU=' 'sha256-AF490//jIflwN/2nTDszvAx/KI2V9GJG8gdwvGhO/zw=' 'sha256-8dULgHWW2eIwqjJTAQle9cUf85AipTjC2f9Ks83Sxks=' 'unsafe-eval' http://localhost:3010 http://localhost:3010 sunbit-dev-static.s3-us-west-1.amazonaws.com; style-src 'self' 'unsafe-inline' *.googleapis.com blob:; frame-src data: http://epay *.sunbit.* *.google.com *.googletagmanager.com; child-src *.googletagmanager.com *.mysunbit.* blob:; img-src 'self' data: blob: *.googletagmanager.com *.google-analytics.com *.google.com *.gstatic.com https://www.google.co.il/ https://static.sunbit.*; font-src 'self' *.gstatic.com *.typekit.net data:; connect-src 'self' ws: about: http://api *.sunbit.* *.google.com https://sentry.io *.browser-intake-datadoghq.com *.datadoghq.com *.google-analytics.com www.google-analytics.com *.googletagmanager.com *.datadoghq.com *.datadoghq.eu tls-use1.fpapi.io https://use1.fptls.com/ https://api-js.mixpanel.com/ https://stats.g.doubleclick.net/; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.ggpht.com *.googleusercontent.com https://*.googleadservices.com https://*.googletagmanager.com https://*.axept.io https://cdnjs.cloudflare.com https://*.tradelab.fr https://*.goldenbees.fr https://*.facebook.com https://*.facebook.net https://*.licdn.com https://*.adnxs.com https://*.tiktok.com https://*.indeed.com blob:;; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com; ; img-src 'self' https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.googleusercontent.com https://*.google-analytics.com https://*.googletagmanager.com https://*.talent.com https://axeptio.imgix.net https://*.axept.io https://*.vimeocdn.com https://*.ytimg.com https://*.adsrvr.org https://*.facebook.com https://*.facebook.net https://*.linkedin.com https://*.adnxs.com https://*.doubleclick.net https://*.googlesyndication.com https://*.indeed.com data:;; media-src 'self'; frame-src https://*.google.com https://*.googletagmanager.com https://*.vimeo.com https://*.youtube.com https://*.youtube-nocookie.com https://*.facebook.com https://*.facebook.net;; font-src 'self' https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data:;; connect-src 'self' https://*.googleapis.com https://*.google.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.googleadservices.com https://*.axept.io https://*.facebook.com https://*.facebook.net https://*.tiktok.com https://*.tiktokw.us https://*.linkedin.com data: blob:;; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.bird.eu https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; report-to https://vimeo.com; report-uri https://vimeo.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com static.olark.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com static.olark.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: https://www.google.co.in https://s1.listrakbi.com https://mediacdn.espssl.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net www.google.com.ua *.olark.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com https://assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://cdn.sucuri.net https://connect.facebook.net https://static.hotjar.com adobe.com https://agent.marketingcloudfx.com https://cdn.leadmanagerfx.com https://atkinsandpearce.com https://script.hotjar.com https://cdn.listrakbi.com https://cdnjs.cloudflare.com/ https://m1.listrakbi.com/ https://s1.listrakbi.com/ https://cdn.listrakbi.com/ https://at1.listrakbi.com/ *.cardinalcommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.croapp.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com cdn.inspectlet.com *.olark.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.sucuri.net https://cdn.listrakbi.com/ fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com use.fontawesome.com *.bootstrapcdn.com *.typekit.net static.olark.com *.fontawesome.com assets.braintreegateway.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src https://6p05oh7erdrey3wm.mojostratus.io/ 'self' 'unsafe-inline'; media-src *.adobe.com static.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://agent.marketingcloudfx.com https://t.marketingcloudfx.com https://cdnjs.cloudflare.com stats.g.doubleclick.net https://featureassets.org https://prodregistryv2.org https://vc.hotjar.io https://metrics.hotjar.io wss://ws.hotjar.com https://content.hotjar.io https://cdn.listrakbi.com/ www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com knrpc.olark.com hn.inspectlet.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://bot.io.gravyty.com; object-src 'none'; script-src 'self' 'report-sample' https://bot.io.gravyty.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src https://fontawesome.com/ https://use.fontawesome.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://domain.com https://www.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://domain.com https://www.google.co.in https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.webgains.io *.googleadservices.com *.cardinalcommerce.com *.paypalobjects.com *.googleapis.com *.vimeo.com *.gstatic.com *.google.com static.klaviyo.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://domain.com https://maxcdn.bootstrapcdn.com https://static.klaviyo.com https://use.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://domain.com https://s3-us-west-2.amazonaws.com *.googletagmanager.com *.sandbox.paypal.com https://stats.g.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce-o3UtnOiOexPvZW6SxocN' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://paymentsafe.experianhealth.com;script-src 'nonce-df22834c35e041658ef084070cfe555e' https://www.myaccesshealth.net 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.myaccesshealth.net 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self' litium.revolutionrace.co.uk fbcdn.revolutionrace.co.uk wss://fbcdn.revolutionrace.co.uk *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.co.uk *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 font-src https://www.gstatic.com https://fonts.gstatic.com fonts.gstatic.com *.bootstrapcdn.com *.woonoutlet07.nl data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.cookiebot.com https://plugins.flockler.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://portal.payconiq.com https://static.buckaroo.nl ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.disqus.com *.sooqr.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.cookiebot.com *.adnxs.com https://woonoutlet07.nl https://www.woonoutlet07.nl https://www.woonboulevardpoortvliet.nl https://woonboulevardpoortvliet.nl data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl static.buckaroo.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.sooqr.com *.googletagmanager.com tagmanager.google.com *.cookiebot.com static.hotjar.com https://tagging.woonboulevardpoortvliet.nl https://woonoutlet07.nl https://widget.simplybook.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sooqr.com tagmanager.google.com fonts.google.com *.bootstrapcdn.com https://woonoutlet07.nl/wbp/fonts/stylesheet.css https://www.woonoutlet07.nl/wbp/fonts/stylesheet.css https://www.woonoutlet07.nl/web/css/custom.min.css https://woonoutlet07.nl/web/css/custom.min.css https://woonoutlet07.nl/wbp/css/custom.min.css https://woonoutlet07.nl/wbp/css/custom.dev.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src https://woonoutlet07.nl 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://maps.googleapis.com/maps/api/geocode/json *.googlesyndication.com *.postcode-checkout.nl https://consent.cookiebot.com static.buckaroo.nl *.hotjar.com *.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/health_google 1 object-src 'none'; connect-src 'self' *.clubsextury21.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.clubsextury21.com join.gammasecure.com; script-src 'self' *.clubsextury21.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.clubsextury21.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-8e0dc9356a094de08da3db4687073edb' https://myreidhealth.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://static-map-tiles-api.arcgis.com https://us-api.experian.com/decisionanalytics/crosscore/npb2hjhva2fa/services/v0/applications/3 https://www.google.com/recaptcha/enterprise.js;style-src https://myreidhealth.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com accounts.google.com www.bugherd.com sessions.bugsnag.com wss://ws.pusherapp.com *.pusher.com www.google.co.uk stats.g.doubleclick.net *.hotjar.com *.hotjar.io graph.instagram.com services.postcodeanywhere.co.uk *.zdassets.com wss://widget-mediator.zopim.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'nonce-8de1e39a-0729-473c-be2e-39445156dc15' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline';font-src 'self' https: data:;style-src 'self' https: 'unsafe-inline';img-src https: data:;connect-src 'self' https: wss:;base-uri 'self';worker-src 'self' blob:;manifest-src 'self';frame-ancestors 'self' https://*.unibet.mt https://kindredgroup.custhelp.com/ https://*.kindredtech.net/ https://*.kindredgroup.com/;media-src * blob:;frame-src https:;report-uri https://www.unibet.mt/eum-collector/report/csp-report; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klevu.com *.hotjar.com *.typekit.net *.reviews.io *.cloudfront.net *.topfurniture.co.uk *.icomoon.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.hotjar.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.nosto.com *.nos.to *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.reviews.io *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.google.com/ *.hotjar.com *.addthis.com *.pinterest.com *.reviews.io *.paypalobjects.com *.googletagmanager.com *.finance-calculator.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com js.mollie.com *.nosto.com *.nos.to *.reviews.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.bing.com *.bing.net *.klevu.com *.clarity.ms *.reviews.io *.norton.com *.onetrust.com *.pinterest.com *.cloudfront.net *.klarnacdn.net *.google.co.uk *.topfurniture.co.uk t.co *.twitter.com https://images.unsplash.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com magefan.com cm.magefan.com *.klarna.com *.klarnaevt.com *.ksearchnet.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.mollie.com *.nosto.com *.nos.to *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.bing.com *.bing.net *.klevu.com *.nosto.com *.hotjar.com *.pinimg.com *.tiktok.com *.addthis.com *.clarity.ms *.moatads.com static.ads-twitter.com *.zdassets.com *.pinterest.com *.cloudflare.com *.pcapredict.com *.klarnacdn.net *.reviews.io *.trustpilot.com *.addthisedge.com *.trackedlink.net *.topfurniture.co.uk *.reviews.co.uk *.postcodeanywhere.co.uk https://maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com s7.addthis.com https://cdn.jsdelivr.net x.klarnacdn.net *.klarnaservices.com js.klevu.com *.ksearchnet.com *.avada.io js.mollie.com *.nos.to 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.onetrust.com cdn.cookielaw.org cookie-cdn.cookiepro.com data: *.klevu.com *.icomoon.io *.myfonts.net *.typekit.net *.cloudfront.net *.reviews.io *.topfurniture.co.uk *.reviews.co.uk *.postcodeanywhere.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com https://cdn.jsdelivr.net *.klarnacdn.net *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.nosto.com *.nos.to https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.topfurniture.co.uk 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.bing.com *.bing.net *.zopim.com google.com *.hotjar.com *.tiktok.com *.clarity.ms public.ecologi.com topfurnitureltd.zendesk.com *.onetrust.com *.zdassets.com *.hotjar.io *.cookielaw.org *.pinterest.com wss://widget-mediator.zopim.com *.postcodeanywhere.co.uk *.reviews.io *.topfurniture.co.uk *.reviews.co.uk *.playground.klarnaevt.com https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com ekr.zdassets.com/ x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io *.nosto.com *.nos.to *.cloudfront.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.com.ua https://www.myheritage.com.ua 'unsafe-eval' 'nonce-85175fd9197c7149ab96b2d1dd50c0fd' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.com.ua;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.paypal.com https://www.sandbox.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.trustpilot.com https://www.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://portal.payconiq.com https://static.buckaroo.nl https://www.buckaroo.nl https://www.paypalobjects.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.facebook.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com https://mylivechat.com https://uk.mylivechat.com https://www.google.nl https://tagging.camperpassie.nl data: 'self' 'unsafe-inline'; style-src *.adobe.com fonts.googleapis.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com tagmanager.google.com fonts.google.com *.trustpilot.com https://uk.mylivechat.com https://www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src https://tagging.camperpassie.nl dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://www.sandbox.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://partner.shoparize.com https://partner-cdn.shoparize.com *.googletagmanager.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https://stats.g.doubleclick.net https: 'self' 'unsafe-inline'; script-src https://tagging.camperpassie.nl assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://www.sandbox.paypal.com https://applepay.cdn-apple.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.googletagmanager.com *.facebook.net www.termsfeed.com https://partner-cdn.shoparize.com https://partner.shoparize.com tagmanager.google.com *.trustpilot.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https: 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; img-src 'self' data: https:; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; connect-src 'self' https:; media-src 'self' https:; frame-src 'self' https:; worker-src 'self' blob:; upgrade-insecure-requests; report-to csp; report-uri /csp-report 1 object-src 'none'; script-src * 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline' cdnjs.cloudflare.com https://cdnjs.cloudflare.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src data: 'self' 'unsafe-inline' mail.britishmotormuseum.co.uk https://cdnjs.cloudflare.com/ajax/libs/jquery-migrate/3.5.2/jquery-migrate.min.js https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js platform.twitter.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/820264173/ https://www.google.com/recaptcha/enterprise.js www.gstatic.com cdn.ampproject.org https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.3.4/owl.carousel.js static.hsappstatic.net snap.licdn.com js.hsadspixel.net js.hs-banner.com js.hubspot.com js.hs-analytics.net www.googletagmanager.com www.google-analytics.com js.hscollectedforms.net status.hotjar.com connect.facebook.net static.hotjar.com platform.linkedin.com script.hotjar.com addevent.com cdn.addevent.com www.addevent.com api-na1.hubapi.com app.hubspot.com fonts.googleapis.com maxcdn.bootstrapcdn.com 7052064.fs1.hubspotusercontent-na1.net cdnjs.cloudflare.com i.ytimg.com www.jg-cdn.com www.googleadservices.com perf-na1.hsforms.com track.hubspot.com perf.hsforms.com forms.hsforms.com 5374582.fs1.hubspotusercontent-na1.net cdn2.hubspot.net www.facebook.com px.ads.linkedin.com audioxi-26-adswizz.attribution.adswizz.com https://cdnjs.cloudflare.com/ajax/libs/slick-carousel/1.9.0/ajax-loader.gif no-cache.hubspot.com forms-na1.hsforms.com fonts.gstatic.com bmm.co.uk www.youtube.com youtube.com play.hubspotvideo.com maps.google.com wss://ws.hotjar.com js.hsforms.net forms.hscollectedforms.net api.hubapi.com stats.g.doubleclick.net region1.analytics.google.com analytics.google.com cta-service-cms2.hubspot.com content.hotjar.io region1.google-analytics.com surveystats.hotjar.io in.hotjar.com metrics.hotjar.io vc.hotjar.io ask.hotjar.io cp.hubspot.com www.recaptcha.net www.gstatic.com www.google.co.uk www.google.com www.google.gr www.google.co.th www.google.de www.google.bg www.google.com.br www.google.nl www.google.ie www.google.it www.google.com.my www.google.cl www.google.co.jp www.google.ro; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self' www.facebook.com e500form.bmm.co.uk; report-uri https://csp.bmm.co.uk/report-uri?v=justdef9; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://cdn.clerk.io https://www.magezon.com *.multisafepay.com assets.myparcel.nl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com *.googleapis.com *.gstatic.com *.google.com/ *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com cdn.jsdelivr.net *.multisafepay.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.multisafepay.com api.myparcel.nl cdn.jsdelivr.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.bootstrapcdn.com *.amazonaws.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com www.youtube.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.amazonaws.com *.google.com *.hsforms.com *.googletagmanager.com *.hubspot.com *.hscollectedforms.net *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.googletagmanager.com *.google.com *.gstatic.com *.pardot.com *.athleticknit.com *.algolia.net *.hscollectedforms.net *.hs-analytics.net *.hs-scripts.com *.hs-banner.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.bootstrapcdn.com *.amazonaws.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com servedbyadbutler.com *.google-analytics.com *.doubleclick.net *.algolianet.net *.algolia.net *.algolianet.com *.athleticknit.com *.hscollectedforms.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://widgets.trustedshops.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com *.doubleclick.net *.facebook.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.bing.com *.bing.net *.commerce-connector.com *.cookiebot.com mcusercontent.com www.google.nl www.google.be www.google.co.uk www.google.de www.google.se *.bird.eu www.magmodules.eu *.datatrics.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sooqr.com *.spotlersearch.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.bing.com *.google.com *.googlesyndication.com *.cookiebot.com *.hotjar.com *.livechatinc.com *.datatrics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.gstatic.com static.hotjar.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.fontawesome.com *.sooqr.com *.spotlersearch.com *.multisafepay.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.amazonaws.com *.bing.com *.bing.net *.googlesyndication.com *.hotjar.com *.hotjar.io *.cookiebot.com *.doubleclick.net *.livechatinc.com www.google.nl www.google.be *.datatrics.com *.sooqr.com *.spotlersearch.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://2dd05692-452d-42b4-967a-db13331f8f8f.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com 'self' data: *.zopim.com *.klaviyo.com *.termly.io maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.canadapost.ca https://sso.epost.ca 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * webservices.purolator.com devwebservices.purolator.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.youtu.be *.cardknox.com *.termly.io www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com mageside.com *.canadapost.ca *.canadapost-postescanada.ca *.googleapis.com media.sezzle.com 'self' data: *.zopim.com *.zopim.io *.bbb.org facebook.com *.google-analytics.com *.routeapp.io *.bing.com *.herokuapp.com nextroll.com *.adroll.com *.advertising.com *.casalemedia.com *.rubiconproject.com *.outbrain.com *.pubmatic.com *.yahoo.com *.taboola.com *.3lift.com *.cloudfront.net srstactical.com srstactical.ca *.gorgias.chat *.gorgias.io *.gorgias.work gorgias.win google.ca *.facebook.com *.convertcart.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.termly.io *.zopim.com *.zdassets.com *.widget-mediator.zopim.com *.instagram.com *.mailchimp.com *.chimpstatic.com *.list-manage.com *.adroll.com s.adroll.com *.consensu.org *.cloudfront.net *.adtag.where.com *.paypalobjects.com *.cardknox.com *.routeapp.io *.bing.com *.nofraud.com *.gorgias.chat *.dyn-rev.app *.cloudflareinsights.com *.klarna.com *.klarnacdn.net *.gorgias.io *.gorgias.work gorgias.win *.amplitude.com facebook.com *.facebook.com *.convertcart.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klaviyo.com assets.braintreegateway.com *.fontawesome.com *.googleapis.com fonts.cdnfonts.com *.termly.io *.convertcart.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.synthrone.com *.termly.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com webservices.purolator.com devwebservices.purolator.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com *.convertcart.com *.google-analytics.com *.zopim.com *.zdassets.com widget-mediator.zopim.com wss://widget-mediator.zopim.com *.chimpstatic.com *.route.com *.mmapiws.com *.adroll.com *.gorgias.chat *.gorgias.io *.gorgias.work gorgias.win gorgias-convert.com *.amplitude.com *.termly.io places.googleapis.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klarna.com *.klarnacdn.net *.gorgias.chat *.termly.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.googleapis.com *.google.com *.google.co.uk 'self' data: *.yotpo.com https://enchantwidgets-1358.kxcdn.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.instagram.com *.braintreegateway.com *.google.com *.googleapis.com *.paypalobjects.com *.yotpo.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com account.fetchify.com *.cookiebot.com *.paypalobjects.com *.googleapis.com *.hotjar.com 'self' data: *.yotpo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com/ www.facebook.com platform.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com *.rosemaryandco.com https://rosemaryandco.com *.cloudfront.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.google.com *.google.co.in *.paypalobjects.com *.googletagmanager.com *.twitter.com *.facebook.com *.instagram.com *.sandbox.paypal.com *.googleapis.com *.newrelic.com *.adobedtm.com *.cookiebot.com https://imgsct.cookiebot.com https://www.google.co.uk 'self' data: *.yotpo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cookiebot.com *.cloudfront.net *.braintreegateway.com *.gstatic.com *.bootstrapcdn.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.cardinalcommerce.com *.hotjar.com *.googletagservices.com *.googlesyndication.com *.paypal.com *.paypalobjects.com *.vimeo.com *.twitter.com *.facebook.com *.instagram.com *.cloudflareinsights.com *.cloudflare.com *.sandbox.paypal.com *.googleapis.com https://platform.enchant.com https://enchantwidgets-1358.kxcdn.com *.yotpo.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.google.com/ connect.facebook.net twitter.com platform.twitter.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com *.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.fontawesome.com *.braintreegateway.com *.google.com *.google.co.uk *.sandbox.paypal.com *.googletagmanager.com *.google-analytics.com *.googleapis.com *.yotpo.com assets.braintreegateway.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.paypal.com *.braintreegateway.com *.google.com *.googleapis.com *.gstatic.com *.paypalobjects.com *.yotpo.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.cloudflare.com *.cookiebot.com *.cardinalcommerce.com *.braintree-api.com *.twitter.com *.facebook.com *.instagram.com *.braintreegateway.com *.hotjar.com *.hotjar.io *.paypalobjects.com *.google-analytics.com *.googleapis.com *.sandbox.paypal.com 'self' data: wss://ws.hotjar.com *.yotpo.com *.doubleclick.net *.demdex.net *.omtrdc.net *.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.rosemaryandco.com/; report-to report-endpoint; 1 default-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-SGQBV4x/16R91BgwdbEAaQ==' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; style-src 'self' 'unsafe-inline' *.typeform.com; connect-src 'self' https://cdn.ampproject.org https://consent.bumble.com https://www.googletagmanager.com *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com/pagead *.googlesyndication.com *.typeform.com *.typeformcdn.com; child-src 'self'; font-src 'self' data:; manifest-src 'self'; base-uri 'self'; frame-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; img-src * data: blob: www.googletagmanager.com; media-src * data: blob:; report-uri /jss/csp_report.phtml?token=bumble_team_site&env=production; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net www.eqwep.com *.fontawesome.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com js.stripe.com secure.livechatinc.com b.stripecdn.com newassets.hcaptcha.com m.stripe.network checkout.tabby.ai https://www.googletagmanager.com/ js.mollie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io https://images.unsplash.com www.eqwep.com www.facebook.com cdn-cookieyes.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.disqus.com *.klevu.com *.ksearchnet.com https://meetanshi.com/media/logo.png https://www.mollie.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.google.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com www.eqwep.com js.klevu.com static.klaviyo.com static-tracking.klaviyo.com static.cloudflareinsights.com static.hotjar.com connect.facebook.net cdn.livechatinc.com script.hotjar.com cdn-cookieyes.com api.livechatinc.com js.stripe.com b.stripecdn.com applepay.cdn-apple.com hcaptcha.com m.stripe.network checkout.tabby.ai widgets.tabby.ai cdn.segment.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com *.ksearchnet.com https://z.moatads.com https://cdn.jsdelivr.net *.avada.io js.mollie.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com www.eqwep.com b.stripecdn.com *.fontawesome.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://cdn.jsdelivr.net *.stripe.network *.stripecdn.com *.amazon.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com statsjs.klevu.com www.eqwep.com pagead2.googlesyndication.com cdn-cookieyes.com content.hotjar.io js.stripe.com a.klaviyo.com merchant-ui-api.stripe.com api.stripe.com api.hcaptcha.com m.stripe.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.eqwep.com pagead2.googlesyndication.com log.cookieyes.com ws.hotjar.com api.livechatinc.com *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://*.matomo.cloud https://*.cookiebot.com https://*.cookiebot.eu https://*.readspeaker.com https://*.jsdelivr.net https://*.cookiebot.com https://*.youtube.com https://*.cloudflare.com https://*.googletagmanager.com 'nonce-aXlsa2tnanVrdnVia2l3d2lua3dlcndmYWZucmliemhucnJ3' 'nonce-bXl5bWFqaXVsaXFnZm5qZ2tjdmVjd25lcndvdGZyYXRmYWR5' 'nonce-a29kaGp2and3YW1ldnRxc25hbWdtd2hxdGV1bnBjc2F6dHp4' 'nonce-c2dwcnlmZWVrd3F1YnZ3cW1ubWpucGRucGhldWlmZGpwZWtv' 'nonce-cXpkeXZuc2FtYXd1a3dvY3R3bmV1c29wY3NobW50YnBqeXdw' 'nonce-Z3pjcWx3d2ZjYXNmbXdtaWlrenpuaGRkYW9nY3ZzcW9zYWZz' 'nonce-aXh0Z3Z6Y2ZqbWxoYnV2Z2pyb3BhanNlcHdkYXZlem5rdG1p'; style-src 'self' 'unsafe-inline' https://*.readspeaker.com https://*.typekit.net https://*.cookiebot.com; img-src 'self' https://*.cookiebot.com data:; connect-src 'self' https://*.algolia.net https://*.algolia.io https://*.cookiebot.com https://*.cookiebot.eu https://*.matomo.cloud https://*.typekit.net https://*.readspeaker.com https://*.typekit.net https://*.analytics.google.com; font-src 'self' data: https://*.typekit.net; object-src 'none'; media-src 'self' https://*.mariamiddelares.be; frame-src 'self' https://*.cookiebot.com; form-action 'self'; frame-ancestors https://*.mariamiddelares.be https://*.mijnziekenhuis.be; base-uri 'self'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.webwinkelkeur.nl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.google.nl *.webwinkelkeur.nl *.usercentrics.eu img.sct.eu1.usercentrics.eu bat.bing.net bat.bing.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.demdex.net id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.1rx.io sync.targeting.unrulymedia.com https://www.mollie.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.dhlecommerce.nl *.cookiebot.eu *.cookiebot.com *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.calendly.com *.beslist.nl *.pinimg.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.pinterest.com js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com widget.tagembed.com api.taggbox.com cdn.tagbox.com static.dhlecommerce.nl *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.pinterest.com *.criteo.com *.beslist.nl widget.tagembed.com api.taggbox.com cdn.tagbox.com *.multisafepay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net fonts.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.placeholder.com pc.ba.site-client.com *.zopim.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trustpilot.com *.zdassets.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io maps.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://images.unsplash.com *.gstatic.com magefan.com cm.magefan.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.xtento.com cdn.xtento.com https://img.youtube.com https://api.mapbox.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdn.jsdelivr.net js.mollie.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com *.cloudflare.com cdnjs.cloudflare.com *.feedbackcompany.com *.googleapis.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.facebook.com *.doubleclick.net *.googletagmanager.com *.cookiebot.com *.trustpilot.com js.mollie.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com https://belco-prod.s3-eu-central-1.amazonaws.com *.google.nl *.ytimg.com *.cookiebot.com *.visualwebsiteoptimizer.com *.thuiswinkel-cdn.org *.feedbackcompany.com 'self' data: https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://www.mollie.com https://redchamps.com *.hsforms.net *.hsforms.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.belco.io *.belco.io *.google-analytics.com *.googleadservices.com *.doubleclick.net js-agent.newrelic.com bam-cell.nr-data.net *.hotjar.com *.googlesyndication.com *.beslist.nl *.trustpilot.com *.ahrefs.com *.cookiebot.com *.thuiswinkel.org *.thuiswinkel-cdn.org *.feedbackcompany.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://*.googleapis.com *.bootstrapcdn.com *.cloudflare.com cdnjs.cloudflare.com *.thuiswinkel-cdn.org *.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com *.gstatic.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com wss://chat.belco.io https://cdn.belco.io *.belco.io bam-cell.nr-data.net *.googlesyndication.com *.cookiebot.com *.doubleclick.net *.ahrefs.com *.beslist.nl *.visualwebsiteoptimizer.com *.thuiswinkel-cdn.org *.hotjar.io *.feedbackcompany.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.google-analytics.com *.feedbackcompany.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.facebook.com *.weltpixel.com eadn-wc03-4957627.nxedge.io www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io dev.visualwebsiteoptimizer.com global.ketchcdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com eadn-wc03-4957627.nxedge.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com connect.facebook.net www.xtento.com cdn.xtento.com eadn-wc03-4957627.nxedge.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com dev.visualwebsiteoptimizer.com global.ketchcdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: 'unsafe-inline' 'unsafe-eval' http://www.musicimpressions.de; img-src *; report-uri /csp_log.php 1 default-src 'self'; script-src 'self'; style-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com cdnjs.cloudflare.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.googlesyndication.com *.tiktok.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com *.googletagmanager.com consentcdn.cookiebot.eu www.gstatic.com apis.google.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.tawk.to 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.google.ro *.usercentrics.eu https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com consentcdn.cookiebot.eu consent.cookiebot.eu *.googleapis.com *.fontawesome.com *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com cdnjs.cloudflare.com *.fontawesome.com *.google.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com cdnjs.cloudflare.com consentcdn.cookiebot.eu http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://stats.g.doubleclick.net/j/collect; default-src 'none'; font-src 'self' data:application/x-font-woff https://fonts.gstatic.com https://s0.wp.com/i/noticons/Noticons.ttf *.wp.com https://boards.greenhouse.io; frame-src https://www.podbean.com *.wp.com https://boards.greenhouse.io https://player.vimeo.com https://www.google.com https://widgets.wp.com; img-src 'self' data: https://boards.greenhouse.io https://secure.gravatar.com https://secure.gravatar.com https://*.wp.com https://i0.wp.com https://i1.wp.com https://i2.wp.com https://pixel.wp.com https://www.google-analytics.com *.wp.com *.mailchimp.com *.list-manage.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://boards.greenhouse.io https://cdn.ampproject.org https://player.vimeo.com *.wp.com https://www.gstatic.com/recaptcha/releases/T9w1ROdplctW2nVKvNJYXH8o/recaptcha__en.js https://*.wp.com https://s0.wp.com/wp-content/js/bilmur.min.js https://stats.wp.com/e-202042.js https://www.google-analytics.com/analytics.js https://www.google-analytics.com/plugins/ua/linkid.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/48TunWH-ZrLteSwFVbw6tVnx/recaptcha__en.js https://s0.wp.com/wp-content/mu-plugins/admin-bar/masterbar-overrides/masterbar.css?ver=9.0.2 https://s0.wp.com/i/noticons/noticons.css?ver=20120621 https://hurricanelabs.us1.list-manage.com https://downloads.mailchimp.com https://chimpstatic.com; style-src 'self' 'unsafe-eval' 'unsafe-inline' *.wp.com https://*.wp.com/wp-content/mu-plugins/admin-bar/wpcom-admin-bar.css?ver=9.0.2 https://s0.wp.com/i/noticons/noticons.css?ver=20120621 https://s0.wp.com/wp-content/mu-plugins/admin-bar/masterbar-overrides/masterbar.css?ver=9.0.2 https://s0.wp.com/wp-content/mu-plugins/notes/admin-bar-v2.css?ver=9.0.2-202042 downloads.mailchimp.com; base-uri ; frame-ancestors 'none'; report-uri https://hurricanelabs.report-uri.com/r/d/csp/enforce; report-uri /_/csp-reports 1 default-src 'self'; connect-src 'self' ddaudio.com adservice.google.com listgrowth.ctctcdn.com pro.ip-api.com properties stats.g.doubleclick.net facebook.com www.google-analytics.com google-analytics.com maps.googleapis.com translate.googleapis.com google-analytics.com ad.doubleclick.net www.google.com analytics.google.com; font-src 'self' ddaudio.com use.typekit.net fonts.gstatic.com; frame-src 'self' ddaudio.com www.facebook.com www.google.com www.youtube.com www.googletagmanager.com td.doubleclick.net; img-src 'self' data: android-webview-video-poster ddaudio.com ddaudio.me www.facebook.com i.ytimg.com static.ctctcdn.com static.cloudflareinsights.com ad.doubleclick.net googleads.g.doubleclick.net www.google-analytics.com adservice.google.com maps.gstatic.com maps.googleapis.com translate.google.com www.googletagmanager.com www.gstatic.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.com.ai www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.ms www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.vg www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat; media-src 'self' data: ddaudio.com www.youtube.com; script-src-elem 'self' ddaudio.com connect.facebook.net www.google-analytics.com www.googletagmanager.com www.googleadservices.com static.cloudflareinsights.com cdnjs.cloudflare.com googleads.g.doubleclick.net maps.googleapis.com static.cloudflareinsights.com static.ctctcdn.com www.google.com www.gstatic.com; script-src 'self' ddaudio.com connect.facebook.net static.cloudflareinsights.com www.google-analytics.com www.googletagmanager.com maps.googleapis.com cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' ddaudio.com p.typekit.net static.ctctcdn.com use.typekit.net fonts.googleapis.com; style-src 'self' 'unsafe-inline' ddaudio.com googleads.g.doubleclick.net static.ctctcdn.com www.google.com www.gstatic.com maps.googleapis.com static.cloudflareinsights.com p.typekit.net use.typekit.net; object-src 'none'; report-uri https://ddaudio.report-uri.com/r/d/csp/wizard 1 script-src 'nonce-cd6760beca8e724f47b1b6ff53e00d8e2734a1ad481ffb7e653b38060c8fe900' 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' *.google-analytics.com *.googletagmanager.com *.google.com *.gstatic.com *.googleapis.com *.bing.com *.pcapredict.com *.dwin1.com lantern.roeyecdn.com services.postcodeanywhere.co.uk *.facebook.net; object-src 'none'; base-uri 'none'; report-uri /includes/csp_report.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.oct8ne.com *.abtasty.com oct8necdneu.azureedge.net/ *.peppermoneytest.es *.peppermoney.es 'self' data: widget.pepperfinance.es static-eu.oct8ne.com *.generaloptica.es *.maisoptica.pt data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com *.oct8ne.com www.google.com *.cookiebot.com *.pinterest.com *.hotjar.com *.hotjar.io *.facebook.com *.facebook.net *.bing.com *.peppermoneytest.es *.peppermoney.es *.pepperfinance.es fledge-eu.creativecdn.com ams.creativecdn.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.googleapis.com gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.oct8ne.com www.google.es stats.g.doubleclick.net *.pinterest.com *.facebook.com *.facebook.net *.bing.com *.clarity.ms tracker.metricool.com *.abtasty.com *.amazonaws.com oct8necdneu.azureedge.net/ *.peppermoneytest.es oct8necdneu.azureedge.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: imgsct.cookiebot.com widget.pepperfinance.es *.teads.tv *.generaloptica.es *.maisoptica.pt data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.googleapis.com *.gstatic.com *.plugins.emarsys.net *.scarabresearch.com *.disqus.com *.oct8ne.com *.cookiebot.com www.google.es www.gstatic.com sl.google-analytics.com s.pinimg.com *.pinterest.com *.hotjar.com *.hotjar.io *.facebook.com *.facebook.net *.bing.com *.fittingbox.com js-agent.newrelic.com bam.nr-data.net *.clarity.ms tracker.metricool.com *.abtasty.com *.peppermoneytest.es *.peppermoney.es *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com widget.pepperfinance.es *.outbrain.com p.teads.tv tags.creativecdn.com *.taboola.com s.kk-resources.com wave.outbrain.com *.generaloptica.es *.maisoptica.pt https://storage.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.abtasty.com *.googleapis.com *.gstatic.com *.peppermoneytest.es *.peppermoney.es *.pepperfinance.es *.oct8ne.com oct8necdneu.azureedge.net tags.creativecdn.com *.trustpilot.com assets.braintreegateway.com *.generaloptica.es *.maisoptica.pt 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com www.google.com payments-eu.amazon.com *.googleapis.com *.scarabresearch.com *.eservice.emarsys.net *.oct8ne.com *.cookiebot.com www.google.es www.gstatic.com sl.google-analytics.com *.g.doubleclick.net s.pinimg.com *.pinterest.com *.hotjar.com *.hotjar.io *.facebook.com *.facebook.net *.bing.com *.fittingbox.com js-agent.newrelic.com bam.nr-data.net *.clarity.ms *.abtasty.com *.peppermoneytest.es *.peppermoney.es ams.creativecdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com bam.eu01.nr-data.net *.taboola.com *.outbrain.com *.teads.tv *.generaloptica.es *.maisoptica.pt 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.generaloptica.es *.maisoptica.pt 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.versapay.com *.paynup.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com *.paynup.com *.versapay.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com *.datadoghq.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.versapay.com *.paynup.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://shopline.itau.com.br *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; frame-ancestors *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com 'self' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.clearsale.com.br https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://stats.g.doubleclick.net https://staticfiles.yviews.com.br https://service.yourviews.com.br https://yv-misc.s3.amazonaws.com https://api.pagar.me https://cdn.mundipagg.com https://img.youtube.com https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net https://www.ebitempresa.com.br/ https://*.posclick.dinamize.com https://*.clarity.ms https://*.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.clearsale.com.br https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://www.googleoptimize.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://cdn.awsli.com.br https://*.optimonk.com https://h.online-metrix.net https://commerce.adobedtm.com https://js-agent.newrelic.com/ https://consent.cookiefirst.com/ *.hotjar.com *.hotjar.io *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.amazonaws.com https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net https://*.clarity.ms 'self' https://*.siteblindado.com https://*.posclick.dinamize.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; object-src *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; media-src *.adobe.com *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net https://*.posclick.dinamize.com 'self' 'unsafe-inline'; manifest-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com http://api.itaushopline.com *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.hotjar.com *.hotjar.io ws://ws.hotjar.com *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net https://*.optimonk.com https://*.clarity.ms https://*.siteblindado.com https://*.posclick.dinamize.com https://receiver.posclick.dinamize.com 'self' 'unsafe-inline'; child-src *.clearsale.com.br https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net http: https: blob: 'self' 'unsafe-inline'; default-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://td.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net https://*.dinamize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.uc.r.appspot.com https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://*.rdstation.com.br https://*.cloudfront.net https://*.amazonaws.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://uc.r.appspot.com https://facebook.com https://facebook.com.br https://facebook.net https://rdstation.com.br https://cloudfront.net https://amazonaws.com https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.cloudflare.com *.uploadcare.com *.ucarecdn.com https://uploadcare.com/ https://ucarecdn.com/ *.getblue.io https://*.i-goal.com.br https://*.reclameaqui.com.br https://*.ebit.com.br https://newimgebit-a.akamaihd.net 'self' 'unsafe-inline'; 1 default-src *; script-src * 'unsafe-inline'; style-src * 'unsafe-inline'; img-src * data:; font-src * data:; report-to https://mercedesforum.report-uri.com/r/d/csp/enforce 1 font-src https://fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://player.vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://player.vimeo.com https://www.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://fonts.googleapis.com https://fonts.gstatic.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv75%3A(ntatn-19b29e86239-0x2603#pd 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: https://widgets.trustedshops.com *.tradetracker.net *.tradetracker.com *.hotjar.com *.kickbite.io *.useinsider.com *.trackedlink.net *.ftz.io *.fitizzy.com *.xandres.com *.geojs.io *.cookiebot.com *.cookiebot.eu data: 'self' 'unsafe-inline'; form-action www.facebook.com sc-static.net *.onetrust.com *.useinsider.com *.cookiepro.com *.doubleclick.net tr.snapchat.com *.tradetracker.net *.tradetracker.com *.hotjar.com *.kickbite.io *.trackedlink.net *.ftz.io *.fitizzy.com *.xandres.com *.geojs.io *.cookiebot.com *.cookiebot.eu 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com js.mollie.com www.google.com *.weltpixel.com *.hotjar.com www.facebook.com *.criteo.com view.publitas.com sc-static.net *.eu.freshchat.com *.eu.webpush.freshchat.com static.criteo.net *.onetrust.com *.useinsider.com *.cookiepro.com *.doubleclick.net tr.snapchat.com getflowbox.com app.acuityscheduling.com *.tradetracker.net *.tradetracker.com *.kickbite.io *.pinterest.com *.mollie.com *.trackedlink.net *.ftz.io *.fitizzy.com xandres-help.freshchat.com *.xandres.com *.geojs.io *.adform.net *.cookiebot.com *.cookiebot.eu 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com maps.googleapis.com maps.gstatic.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://www.mollie.com https://api.mapbox.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.doubleclick.net *.cdninstagram.com www.google.be connect.facebook.net www.facebook.net connect.facebook.com www.facebook.com ct.pinterest.com *.pinterest.com *.adform.net *.yieldmo.com *.smaato.net *.rubiconproject.com *.outbrain.com *.bidswitch.net *.adnxs.com *.teads.tv *.yahoo.com *.casalemedia.com *.contextual.media.net *.smartadserver.com *.360yield.com *.openx.net *.pubmatic.com *.taboola.com *.3lift.com *.advertising.com *.adscale.de *.omnitagjs.com *.criteo.com *.socdm.com *.yieldlab.net *.mail.ru *.cloudfront.net *.mollie.com *.ivitrack.com *.media.net *.sharethrough.com ade.clmbtech.com cm.mgid.com sync.e-planning.net ads.stickyadstv.com i.liadm.com ad.sxp.smartclip.net pixel.tapad.com dpm.demdex.net tags.bluekai.com s.thebrighttag.com a.twiago.com sync-tm.everesttech.net idsync.rlcdn.com cdn.stickyadstv.com sync.ad-stir.com jadserve.postrelease.com *.onetrust.com *.useinsider.com *.cookiepro.com bat.bing.com tr.snapchat.com *.getflowbox.com *.wisepops.com *.tradetracker.net *.tradetracker.com *.hotjar.com *.kickbite.io *.google-analytics.com *.analytics.google.com *.trackedlink.net *.xandres.com *.ftz.io *.fitizzy.com *.geojs.io *.cookiebot.com *.cookiebot.eu data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com *.disqus.com js.mollie.com *.google.com www.gstatic.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.elfsight.com connect.facebook.net connect.facebook.com *.hotjar.com *.pinimg.com *.trackedlink.net *.sumo.com *.criteo.net *.criteo.com *.wisepops.com view.publitas.com sc-static.net wchat.eu.freshchat.com assetscdn-wchat.eu.freshchat.com *.eu.webpush.freshchat.com *.onetrust.com *.useinsider.com *.cookiepro.com *.doubleclick.net bat.bing.com embed.acuityscheduling.com *.getflowbox.com *.tiktok.com *.tradetracker.net *.tradetracker.com *.kickbite.io *.mollie.com *.ftz.io *.fitizzy.com d5yoctgpv4cpx.cloudfront.net vimeo.com xandres-help.freshchat.com *.xandres.com *.geojs.io *.adform.net *.cookiebot.com *.cookiebot.eu connect.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com fonts.gstatic.com embed.acuityscheduling.com *.getflowbox.com *.useinsider.com *.wisepops.com wchat.eu.freshchat.com assetscdn-wchat.eu.freshchat.com *.tradetracker.net *.tradetracker.com *.hotjar.com *.kickbite.io *.trackedlink.net *.ftz.io *.fitizzy.com xandres-help.freshchat.com *.xandres.com *.geojs.io *.cookiebot.com *.cookiebot.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.vimeo.com https://maps.googleapis.com https://player.vimeo.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site apps.elfsight.com *.analytics.google.com maps.googleapis.com *.doubleclick.net ct.pinterest.com *.hotjar.com wss://*.hotjar.com *.hotjar.io sumo.com api.instacloud.io *.wisepops.com cicptqmkej.execute-api.eu-west-1.amazonaws.com *.onetrust.com *.useinsider.com *.cookiepro.com *.getflowbox.com *.tiktok.com *.tradetracker.net *.tradetracker.com *.kickbite.io *.trackedlink.net *.ftz.io *.fitizzy.com rkkck31tec.execute-api.eu-central-1.amazonaws.com *.xandres.com *.geojs.io *.adform.net *.cookiebot.com *.cookiebot.eu connect.getflowbox.com 9mn3sm7015.execute-api.eu-west-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.alothemes.com *.magepow.com *.zohocdn.com googletagmanager.com fonts.googleapis.com *.gstatic.com axitech.be *.axitech.be toetsenbordstickers.be *.zohostatic.eu *.icecat.biz data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors facebook.com googletagmanager.com *.googletagmanager.com axitech.be *.axitech.be toetsenbordstickers.be *.doubleclick.net *.zohopublic.eu channext.com *.channext.com google.com *.google.com google.be *.google.be 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com www.facebook.com googletagmanager.com *.googletagmanager.com axitech.be *.axitech.be toetsenbordstickers.be *.doubleclick.net *.zohopublic.eu channext.com *.channext.com *.icecat.biz connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.cloudflare.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://www.magezon.com magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.google.com * blob: *.icecat.biz www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com quickchart.io img.youtube.com flagpedia.net https://www.mollie.com *.koongo.com wsrv.nl *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net google.com *.alothemes.com *.magepow.com *.gstatic.com www.facebook.com *.google.com googletagmanager.com *.googletagmanager.com tagmanager.google.com *.googleadservices.com googlesyndication.com *.googlesyndication.com maillist-manage.eu *.maillist-manage.eu *.zoho.eu crm.zoho.eu ma.zoho.eu salesiq.zoho.eu salesiq.zohopublic.eu *.zohocdn.com bat.bing.com clarity.ms *.clarity.ms strict-dynamic axitech.be *.axitech.be toetsenbordstickers.be *.cloudflareinsights.com *.channext.com *.highcharts.com unpkg.com *.zohostatic.eu *.leady.com *.leadberry.com tiktok.com *.tiktok.com plausible.io *.icecat.biz connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.cloudflare.com js.mollie.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.alothemes.com *.magepow.com *.google.com tagmanager.google.com googletagmanager.com *.googletagmanager.com *.zohocdn.com *.zohostatic.eu axitech.be *.axitech.be toetsenbordstickers.be *.icecat.biz fonts.gstatic.com *.gstatic.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css fonts.google.com 'self' 'unsafe-inline'; object-src data: 'self' 'unsafe-inline'; media-src *.adobe.com facebook.com google.com google.be *.google.be kxoj-zcmp.maillist-manage.eu *.zohocdn.com bat.bing.com axitech.be *.axitech.be toetsenbordstickers.be wsrv.nl *.icecat.biz 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.alothemes.com *.magepow.com *.axitech.be *.gstatic.com *.g.doubleclick.net googlesyndication.com *.googlesyndication.com google.com *.google.com.tr *.google.com *.google.be *.google.nl *.google.de *.google.fr *.google.pl *.google.dk *.google.lu *.google.lk *.google.no *.google.rs *.google.bg *.google.gr *.google.al *.google.ae *.google.com.do *.google.ro *.google.es *.google.co.uk *.google.sk *.google.co.in *.google.hr zohopublic.eu *.zohopublic.eu maillist-manage.eu *.maillist-manage.eu *.zohocdn.com clarity.ms *.clarity.ms bing.com *.bing.com *.bing.net axitech.be toetsenbordstickers.be ws: wss: *.leady.com *.leadberry.com wsrv.nl tiktok.com *.tiktok.com *.tiktokw.us plausible.io *.googleusercontent.com *.icecat.biz www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com *.koongo.com places.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.zohocdn.com *.icecat.biz 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report.axitech.be/cid.php; report-to report-endpoint; 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' ltoh41-fmgbjh75j6hc.cloudmaestro.com www.googletagmanager.com 5c2z2n-fmgbjh75j6hc.cloudmaestro.com translate.google.com script.hotjar.com js.hs-banner.com js.hscollectedforms.net js.hs-analytics.net js.usemessages.com webscalehelp.zendesk.com static.hotjar.com www.google-analytics.com js.hs-scripts.com tags.srv.stackadapt.com translate.googleapis.com js.hsforms.net translate-pa.googleapis.com *.hotjar.com *.hs-banner.com *.hs-analytics.net *.hsforms.com *.googleapis.com *.srv.stackadapt.com; report-uri /.webscale/csp-report 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://fonts.gstatic.com https://www.tuinmeubelshop.nl https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net https://*.dpdconnect.nl https://gum.criteo.com https://secure.livechatinc.com https://www.googletagmanager.com/ www.xtento.com 'self' 'unsafe-inline'; img-src cdn.tuinmeubelshop.nl data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://maps.gstatic.com http://maps.gstatic.com https://maps.googleapis.com http://maps.googleapis.com https://cdn.tuinmeubelshop.nl https://cdn-staging.tuinmeubelshop.nl https://squeezely.tech https://t.squeezely.tech https://www.google.com https://ct.pinterest.com https://www.facebook.com https://www.google.nl https://bat.bing.com https://www.tuinmeubelshop.nl cdn.flbx.io *.cloudfront.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.magmodules.eu *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com data: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.googleapis.com https://www.gstatic.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://*.dpdconnect.nl https://www.google.com https://ssl.google-analytics.com https://www.google-analytics.com https://ecookie.nl https://www.ecookie.nl https://connect.getflowbox.com https://chimpstatic.com https://www.googletagmanager.com http://www.googletagmanager.com https://www.googleadservices.com http://www.googleadservices.com https://bat.bing.com https://s.pinimg.com https://ct.pinterest.com https://connect.facebook.com https://connect.facebook.net https://squeezely.tech https://t.squeezely.tech https://googleads.g.doubleclick.net https://sslwidget.criteo.com https://static.hotjar.com https://www.googleoptimize.com https://ss.tuinmeubelshop.nl https://unpkg.com https://widget.thuiswinkel-cdn.org https://widget.thuiswinkel.org https://cdn.video-dns.com https://app.aiden.cx https://cdn.livechatinc.com https://api.livechatinc.com https://ar-view-zieny.com https://app.varify.io *.getflowbox.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://cdn.jsdelivr.net squeezely.tech www.squeezely.tech *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com http://fonts.googleapis.com https://www.tuinmeubelshop.nl https://cdn.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: * *.video-dns.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://www.google.com https://pagead2.googlesyndication.com https://www.google-analytics.com https://squeezely.tech https://t.squeezely.tech https://ct.pinterest.com https://widgetcontent.thuiswinkel-cdn.org https://mave.io *.video-dns.com wss://metrics.video-dns.com https://ar-view-zieny.com https://api.ar-view-zieny.com https://app.varify.io *.getflowbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ squeezely.tech *.squeezely.tech *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/; report-to report-endpoint; 1 font-src fonts.gstatic.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com *.gstatic.com *.fontawesome.com *.typekit.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com *.yotpo.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de verify.authorize.net bat.bing.com www.facebook.com px.ads.linkedin.com www.googletagmanager.com *.eroswholesale.com store.paradoxlabs.com *.klevu.com *.ksearchnet.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com static.zdassets.com static.cloudflareinsights.com js-agent.newrelic.com connect.facebook.net bat.bing.com static.hotjar.com snap.licdn.com www.googletagmanager.com static-tracking.klaviyo.com static.klaviyo.com js.klevu.com *.ksearchnet.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.authorize.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googletagmanager.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com use.typekit.net p.typekit.net fonts.googleapis.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com unsafe-inline *.typekit.net https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com ekr.zdassets.com eroswholesale.zendesk.com bam.nr-data.net px.ads.linkedin.com *.analytics.google.com *.klevu.com *.ksearchnet.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com ws: https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-wtniSuZ9cqmaJymXtYdKAiyuQ' 'strict-dynamic'; manifest-src 'self' 1 frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; style-src-elem app.leadfox.co blog.clubtissus.com www.clubtissus.com fonts.googleapis.com; form-action www.facebook.com payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com connect.facebook.net graph.facebook.com https://seo.mageplaza.com *.facebook.com 'self' 'unsafe-inline'; img-src www.facebook.com ct.pinterest.com google.com www.google.com www.google.ca admin.thefabricclub.ca assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.apptrian.com facebook.com connect.facebook.net graph.facebook.com *.bird.eu https://firebasestorage.googleapis.com https://www.mollie.com *.gstatic.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src-elem script.hotjar.com www.googletagmanager.com www.clubtissus.com clubtissus.com www.thefabricclub.ca www.google-analytics.com static.hotjar.com www.youtube.com s.pinimg.com google.com connect.facebook.net app.leadfox.co blog.clubtissus.com www.google.com 'sha256-B4yPHKaXnvFWtRChIbabYmUBFZdVfKKXHbWtWidDVF8=-0'; frame-src www.google.com vars.hotjar.com www.facebook.com payflowlink.paypal.com ct.pinterest.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com connect.facebook.net graph.facebook.com js.mollie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; style-src fonts.googleapis.com *.adobe.com https://fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; script-src www.google-analytics.com www.googletagmanager.com www.google.com www.gstatic.com static.hotjar.com s.pinimg.com connect.facebook.net clubtissus.com www.clubtissus.com www.thefabricclub.ca assets.adobedtm.com *.adobe.com www.googleadservices.com googleads.g.doubleclick.net analytics.google.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.apptrian.com facebook.com www.facebook.com graph.facebook.com *.avada.io js.mollie.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src www.google-analytics.com ct.pinterest.com in.hotjar.com stats.g.doubleclick.net ws17.hotjar.com wss://ws17.hotjar.com blog.clubtissus.com rest.leadfox.co app.leadfox.co dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.monetico-services.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.monetico-services.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.criteo.com *.doubleclick.net *.criteo.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com camo.githubusercontent.com eu1-doofinderuser.s3.amazonaws.com us1-doofinderuser.s3.amazonaws.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.doubleclick.net *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.ekomi.de *.pubmatic.com *.bing.com *.aralego.com *.googletagmanager.com *.bidswitch.net *.media.net *.smaato.net *.yahoo.net *.krxd.net *.adnxs.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.3lift.com *.yahoo.com *.socdm.com *.criteo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.mediavine.com *.outbrain.com *.clmbtech.com *.bluekai.com *.yieldmo.com *.zopai88.com *.google.com *.google.com.vn *.teads.tv *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io connect.facebook.net twitter.com platform.twitter.com https://cdnjs.cloudflare.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.ekomi.de *.googletagmanager.com *.bing.com *.criteo.net *.criteo.com *.doubleclick.net *.lgw.io *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.mediavine.com *.outbrain.com *.clmbtech.com *.bluekai.com *.zopai88.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.monetico-services.com *.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.googleapis.com *.doubleclick.net *.geojs.io *.criteo.com *.googleadservices.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.mediavine.com *.outbrain.com *.clmbtech.com *.bluekai.com *.yieldmo.com *.zopai88.com *.googlesyndication.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-Cj5tms_XvY-FP8Ua0AJCaA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' ; frame-src 'self' https://web.cmp.usercentrics.eu https://www.googletagmanager.com https://www.youtube.com ; script-src 'self' https://www.googletagmanager.com https://web.cmp.usercentrics.eu https://*.pipedrive.com https://*.pipedriveassets.com https://cdn.jsdelivr.net ; style-src 'self' 'unsafe-inline' https://*.typekit.net ; img-src 'self' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.usercentrics.eu https://www.w3.org ; font-src 'self' https://fonts.gstatic.com https://use.typekit.net https://*.pipedrive.com ; connect-src 'self' https://*.pipedrive.com https://*.google-analytics.com https://*.googlesyndication.com https://www.googletagmanager.com https://v1.api.service.cmp.usercentrics.eu ; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-Of7vxcoG9uACGlWVYieVAw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.amazonaws.com *.fontplus.jp data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.fontplus.jp p01.mul-pay.jp pt01.mul-pay.jp 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com *.fontplus.jp 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de landofcoder.com *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.demdex.net/ *.youtube.com/ *.fontplus.jp *.googletagmanager.com *.fontplus.js/* static.addtoany.com td.doubleclick.net ct.pinterest.com fledge.teads.tv p.teads.tv *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net/ dpm.demdex.net *.everesttech.net/ *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.tasaki.inc/ www.google.co.jp ct.pinterest.com t.teads.tv cm.teads.tv b99.yahoo.co.jp t.co analytics.twitter.com tr.line.me www.facebook.com i.smartnews-ads.com i6.smartnews-ads.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.googletagmanager.com https://polyfill-fastly.io landofcoder.com *.avada.io *.meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.fontplus.jp static.addtoany.com s.pinimg.com ct.pinterest.com p.teads.tv s.yimg.jp b99.yahoo.co.jp www.clarity.ms static.ads-twitter.com d.line-scdn.net connect.facebook.net taj1.ebis.ne.jp rec.ebis.ne.jp cdn.smartnews-ads.com p01.mul-pay.jp pt01.mul-pay.jp static.mul-pay.jp stg.static.mul-pay.jp 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de madefor.github.io landofcoder.com https://get.geojs.io *.avada.io *.meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com maps.googleapis.com static.addtoany.com *.fontplus.jp adservice.google.com www.google.com ct.pinterest.com cm.teads.tv t.teads.tv am.yahoo.co.jp www.clarity.ms *.clarity.ms c.bing.com stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://devdocs.magento.com https://magento.com *.google.com *.google.ca *.google-analytics.com *.googletagmanager.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.yotpo.com placide.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.yotpo.com placide.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com placide.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com *.affirm.com *.affirm.ca connect.facebook.net graph.facebook.com business.facebook.com https://devdocs.magento.com https://magento.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.googletagmanager.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.net *.facebook.com insight.adsrvr.org *.yotpo.com placide.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.affirm.com *.affirm.ca ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com https://devdocs.magento.com https://magento.com *.google.ca *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.com *.flix360.com https://firebasestorage.googleapis.com *.yotpo.com placide.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.affirm.com *.affirm.ca chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com https://devdocs.magento.com https://magento.com *.google.ca *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.com *.googleadservices.com *.adobedtm.com js.adsrvr.org cdn-cookieyes.com *.flixfacts.com *.flix360.io *.flixcar.com *.milwaukeetool.com *.avada.io *.shopify.com *.yotpo.com placide.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com https://devdocs.magento.com https://magento.com *.google.com *.google.ca *.google-analytics.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.yotpo.com placide.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com placide.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.affirm.com *.affirm.ca form-assets.mailchimp.com *.intuit.com *.amazonaws.com connect.facebook.net graph.facebook.com business.facebook.com https://devdocs.magento.com https://magento.com *.gstatic.com *.google.ca *.googletagmanager.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.facebook.com *.flixcar.com https://get.geojs.io *.avada.io *.yotpo.com placide.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com placide.com http: https: blob: 'self' 'unsafe-inline'; default-src placide.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.doofinder.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com/ *.e-transactions.fr *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://sibautomation.com/ *.criteo.net *.criteo.com *.doubleclick.net *.pinterest.com https://www.googletagmanager.com/ www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.leaderplant.com https://c.clarity.ms/ https://exchange.mediavine.com/ https://id5-sync.com/ https://matching.ivitrack.com/ https://beacon.krxd.net/ https://s.thebrighttag.com/ *.doofinder.com eu1-doofinderuser.s3.amazonaws.com log.pinterest.com *.adnxs.com eb2.3lift.com contextual.media.net sync.outbrain.com sync-t1.taboola.com r.casalemedia.com cm.g.doubleclick.net us-u.openx.net pixel.rubiconproject.com *.yahoo.com s.ad.smaato.net criteo-sync.teads.tv *.criteo.com ad.yieldlab.net *.adscale.de ad.360yield.com cm.adform.net match.sharethrough.com rtb-csync.smartadserver.com x.bidswitch.net idsync.rlcdn.com ums.acuityplatform.com visitor.omnitagjs.com simage2.pubmatic.com pixel.advertising.com *.stickyadstv.com *.yieldmo.com *.impact-ad.jp *.lemmatechnologies.com *.mathtag.com *.brightmountainmedia.com *.postrelease.com *.e-planning.net *.liadm.com *.bing.com *.tremorhub.com *.smartclip.net *.clmbtech.com *.ipredictive.com *.fwmrm.net *.sundaysky.com *.admedo.com *.tribalfusion.com *.google.fr *.ad-stir.com *.bird.eu maps.googleapis.com maps.gstatic.com bat.bing.net s.pinimg.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://js-agent.newrelic.com/ https://sdk.privacy-center.org/ https://bam.eu01.nr-data.net/ https://bat.bing.com/ https://sibautomation.com/ https://cdn.doofinder.com/ https://www.clarity.ms/ https://m.addthis.com https://assets.pinterest.com *.criteo.net *.criteo.com maps.googleapis.com *.pinimg.com *.pinterest.com bat.bing.net s.pinimg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ connect.facebook.net twitter.com platform.twitter.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.doofinder.com/ maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://eu1-layer.doofinder.com/ https://in-automate.sendinblue.com/ https://j.clarity.ms/ https://bam.eu01.nr-data.net/ *.addthis.com maps.googleapis.com *.doofinder.com wss://*.doofinder.com/ *.googlesyndication.com *.google-analytics.com *.brevo.com *.facebook.com googleads.g.doubleclick.net www.googleads.g.doubleclick.net *.clarity.ms *.googleadservices.com *.privacy-center.org *.bing.com *.bing.net *.pinterest.com www.google.fr bat.bing.net s.pinimg.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.leaderplant.com/; report-to report-endpoint; 1 default-src 'self' blob: data:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.matomo.cloud https://connect.facebook.net https://az416426.vo.msecnd.net https://www.googletagmanager.com https://static-resource.com https://cdn-javascript.net https://www.google.com https://tagmanager.google.com https://*.byggforsk.no https://matomojs.trackify.info https://www.youtube.com https://cdn.cookie-script.com https://www.youtube.com https://bat.bing.com https://cdn.cookie-script.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://fonts.googleapis.com https://*.byggforsk.no https://cdn.jsdelivr.net;img-src 'self' https: data: https://*.byggforsk.no https://www.facebook.com;frame-src https://www.youtube.com https://www.facebook.com https://www.googletagmanager.com;font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com;connect-src 'self' https://dc.services.visualstudio.com https://www.facebook.com https://connect.facebook.net https://stats.g.doubleclick.net https://stats.g.doubleclick.net/j/collect https://www.google.com https://www.bing.com https://no.api4load.com https://data.brreg.no https://api.bring.com https://*.byggforsk.no https://sintef.matomo.cloud/matomo.php https://fonts.googleapis.com https://ewrkoyhc.api.sanity.io https://admin.kotobee.com https://consent.cookie-script.com https://bat.bing.com;report-uri https://byggforsk.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com *.bootstrapcdn.com *.cloudflare.com *.contivio.com *.hsappstatic.net *.ivaws.com *.redditstatic.com *.slant.co *.tiktok.com data: *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.adroll.com *.bing.com *.braintreegateway.com *.cloudflare.com *.compton.k12.ca.us *.contivio.com *.criteo.com *.criteo.net *.deledao.com *.doubleclick.net *.facebook.com *.google.com *.googletagmanager.com *.ibosscloud.com *.jotform.com *.liadm.com *.linewize.net *.lsfilter.com *.microsoftonline.com *.netsuite.com *.opendns.com *.securly.com *.shareasale-analytics.com *.shareasale.com *.skimresources.com *.trustpilot.com *.vimeo.com 127.0.0.1 lsrelay-config-production.s3.amazonaws.com vimeo.com www.google.bs www.google.ca www.google.ch www.google.co.cr www.google.co.in www.google.co.nz www.google.co.th www.google.co.uk www.google.com.au www.google.com.br www.google.com.eg www.google.com.mx www.google.com.pr www.google.com.qa www.google.de www.google.es www.google.it www.google.no www.xtento.com *.addthis.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.ablyft.com *.adroll.com *.bing.com *.bing.net *.clarity.ms *.cloudflare.com *.contivio.com *.criteo.net *.dicebear.com *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googleadservices.com *.googletagmanager.com *.ivaws.com *.liadm.com *.mailchimp.com *.pinimg.com *.pinterest.com *.reddit.com *.redditstatic.com *.tiktok.com *.wepowerconnections.com *.ytimg.com d1z0mfyqx7ypd2.cloudfront.net d3k81ch9hvuctc.cloudfront.net google.com shareasale.com www.google.ad www.google.ae www.google.al www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cf www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tm www.google.tn www.google.tt www.google.ws cdn.xtento.com flagpedia.net www.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.33across.com *.ablyft.com *.adroll.com *.amped.io *.bing.com *.boldchat.com *.braintreegateway.com *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.contivio.com *.criteo.com *.doubleclick.net *.dwin1.com *.facebook.net *.fullstory.com *.getgobot.com *.google-analytics.com *.google.com *.googleadservices.com *.googletagmanager.com *.jotfor.ms *.jsdelivr.net *.klaviyo.com *.klevu.com *.liadm.com *.mailchimp.com *.noibu.com *.optiversal.com *.pinterest.com *.redditstatic.com *.rmbl.ws *.smtrk.net *.tiktok.com *.trustpilot.com acsbapp.com unpkg.com xxredda.s3.amazonaws.com *.cardinalcommerce.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net maps.googleapis.com www.xtento.com cdn.xtento.com https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.ablyft.com *.bootstrapcdn.com *.cloudflare.com *.contivio.com *.googleapis.com *.gstatic.com *.klaviyo.com *.rakuten.com xxredda.s3.amazonaws.com https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.contivio.com *.gstatic.com *.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.ablyft.com *.acsbapp.com *.adblocknext.com *.bing.com *.bing.net *.braintreegateway.com *.clarity.ms *.contivio.com *.criteo.com *.datadome.co *.doubleclick.net *.facebook.com *.facebook.net *.getgobot.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.intuit.com *.klaviyo.com *.liadm.com *.mailchimp.com *.moonshot-ai.com *.noibu.com *.reddit.com *.redditstatic.com *.rmbl.ws *.tiktok.com *.tiktokw.us *.trustpilot.com *.wepowerconnections.com 9kvu81ddh3.execute-api.us-east-2.amazonaws.com acsbapp.com d3k81ch9hvuctc.cloudfront.net ipapi.co www.google.ae www.google.al www.google.as www.google.at www.google.be www.google.bg www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cf www.google.ch www.google.cl www.google.cm www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.gi www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ni www.google.com.np www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.kz www.google.la www.google.lk www.google.lt www.google.md www.google.me www.google.mg www.google.mk www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tn www.google.tt ekr.zdassets.com/ www.gstatic.com maps.googleapis.com sp.americanflags.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' http: https:; font-src 'self' https: data:; img-src 'self' http: https: data: blob:; object-src 'none'; connect-src 'self' wss: http: https:; script-src 'self' https: http: 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https: http: 'unsafe-inline'; worker-src blob:; report-uri https://hlidacky.report-uri.com/r/d/csp/reportOnly 1 script-src 'self' 'unsafe-eval' chrome-extension: 'unsafe-inline' https://bitrix.info blob: 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://m.youtube.com chrome-extension: https://www.youtube.com https://dl.metabar.ru https://player.twitch.tv https://mc.yandex.ru https://div.show https://acestream.tv https://emet.news https://emet.live https://loader.media; object-src 'self'; report-uri /cspreportonly; 1 font-src cash-f.squarecdn.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com www.googleapis.com *.stgautopilotapp.com *.autopilotapp.com *.ortto-stg.app *.ortto.app www.123optic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com www.123optic.com 'self' 'unsafe-inline'; frame-ancestors www.123optic.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com widget.trustpilot.com analytics.skroutz.gr *.spotify.com www.xtento.com www.123optic.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * 'self' data: www.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gyazo.com *.ytimg.com *.stgautopilotapp.com *.autopilotapp.com *.ortto-stg.app *.ortto.app *.cloudfront.net maps.gstatic.com www.xtento.com cdn.xtento.com www.123optic.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net www.google-analytics.com *.gstatic.com *.googlesyndication.com https://widget-acc.paazl.com https://api-acc.paazl.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.cloudflare.com cdn.mouseflow.com cdn3l.ink widget.trustpilot.com www.gstatic.com *.paazl.com *.cookiebot.eu bat.bing.com bat.bing-int.com *.clarity.ms analytics.skroutz.gr *.ap3stg.com cdn2l.ink blob: maps.googleapis.com www.xtento.com cdn.xtento.com www.123optic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://widget-acc.paazl.com https://api-acc.paazl.com/ *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com www.google.com *.paazl.com *.ap3prod.com www.123optic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src mediastream: cdn2l.ink www.123optic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://widget-acc.paazl.com https://api-acc.paazl.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.paazl.com *.clarity.ms *.stgautopilotapp.com *.autopilotapp.com *.ortto-stg.app *.ortto.app wss://*.autopilotapp.com wss://*.stgautopilotapp.com wss://*.ortto-stg.app wss://*.ortto.app wss://*.twilio.com *.youtube.com *.ap3prod.com www.123optic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.123optic.com http: https: blob: 'self' 'unsafe-inline'; default-src www.123optic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com *.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.hotjar.com https://v2.zopim.com https://static.zdassets.com https://configusa.veinteractive.com *.disqus.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.hotjar.com https://*.zendesk.com https://*.zdassets.com wss://widget-mediator.zopim.com *.google-analytics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.linkedin.com *.googletagmanager.com *.facebook.net *.facebook.com *.livechatinc.com *.livechat.com *.vimeocdn.com *.vimeo.com *.youtube.com i.ytimg.com *.disqus.com *.avada.io *.adobe.com *.paypal.com *.adobedtm.com *.google.com *.elfsight.com *.googleapis.com *.stripe.network *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net *.ftcdn.net validator.swagger.io validator.behance.net *.youtube-nocookie.com *.demdex.net *.omtrdc.net *.cardinalcommerce.com *.visualwebsiteoptimizer.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ lootly.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.convertful.com *.linkedin.com *.paypalobjects.com *.googletagmanager.com *.facebook.net *.facebook.com *.livechatinc.com *.livechat.com *.vimeocdn.com *.vimeo.com i.ytimg.com *.disqus.com *.avada.io *.fontawesome.com *.gstatic.com *.paypal.com *.adobedtm.com *.google.com *.elfsight.com *.googleapis.com *.stripe.network *.stripecdn.com *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net *.ftcdn.net validator.swagger.io validator.behance.net *.demdex.net *.omtrdc.net *.cardinalcommerce.com *.visualwebsiteoptimizer.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://redchamps.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.bing.com *.linkedin.com *.googletagmanager.com *.facebook.net *.facebook.com *.livechatinc.com *.livechat.com *.vimeo.com *.avada.io *.fontawesome.com *.gstatic.com *.paypal.com *.adobedtm.com *.google.com *.elfsight.com *.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com *.link.com *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net validator.behance.net *.klarna.com *.klarnacdn.net *.klarnaevt.com *.youtube-nocookie.com *.demdex.net *.omtrdc.net *.cardinalcommerce.com *.visualwebsiteoptimizer.com *.google.co.in data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ lootly.io *.disqus.com *.avada.io *.shopify.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.linkedin.com *.hotjar.com *.paypalobjects.com *.bing.com *.licdn.com *.google.co.in *.convertful.com *.visualwebsiteoptimizer.com *.livechatinc.com *.facebook.net *.facebook.com *.livechat.com *.vimeo.com i.ytimg.com *.fontawesome.com *.gstatic.com *.paypal.com *.adobedtm.com *.google.com *.elfsight.com *.googleapis.com *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net *.ftcdn.net validator.swagger.io validator.behance.net *.youtube-nocookie.com *.demdex.net *.omtrdc.net *.cardinalcommerce.com dev.visualwebsiteoptimizer.com universe-static.elfsightcdn.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.linkedin.com *.googletagmanager.com *.facebook.net *.facebook.com *.livechatinc.com *.livechat.com *.vimeocdn.com *.vimeo.com *.youtube.com i.ytimg.com *.disqus.com *.avada.io *.gstatic.com *.paypal.com *.adobedtm.com *.google.com *.elfsight.com *.stripe.com *.link.com *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net *.ftcdn.net validator.swagger.io validator.behance.net *.klarna.com *.klarnacdn.net *.klarnaevt.com *.youtube-nocookie.com *.demdex.net *.omtrdc.net *.cardinalcommerce.com *.visualwebsiteoptimizer.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ lootly.io https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googleadservices.com *.google-analytics.com *.trackcmp.net d3ec9nrakwwpz5.cloudfront.net *.hotjar.io *.hotjar.com wss://ws.hotjar.com *.convertful.com *.linkedin.com *.googletagmanager.com *.facebook.net *.facebook.com *.livechatinc.com *.livechat.com *.vimeocdn.com *.vimeo.com *.youtube.com i.ytimg.com *.disqus.com *.fontawesome.com *.gstatic.com *.adobe.com *.paypal.com *.adobedtm.com *.google.com bam.nr-data.net google.com *.elfsight.com *.googleapis.com *.stripe.network *.stripecdn.com *.lootly.com *.lootly.io *.klaviyo.com *.weltpixel.com *.magentocommerce.com *.doubleclick.net *.ftcdn.net validator.swagger.io validator.behance.net *.youtube-nocookie.com *.demdex.net *.omtrdc.net *.cardinalcommerce.com *.visualwebsiteoptimizer.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://cdn.clerk.io connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.amazonaws.com *.hsforms.net *.hsforms.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://api.clerk.io https://cdn.clerk.io connect.facebook.net graph.facebook.com business.facebook.com https://static.dhlecommerce.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sendcloud.sc *.hsforms.net *.hsforms.com tm.tradetracker.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://api.clerk.io https://cdn.clerk.io https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.multisafepay.com assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=POtfwrRrbai.NJCCyCJUjYR6y_hMkxzYYpSaXNX7Nk4-1765933652-1.0.1.1-oHkb.33tyDFFLsf9V9ktACLgMnXWQr3ypLkghQi43h5g2V.QD1bv2Yc4g13zXQ2HHdfLa4JGzQyJoyARle6yf28XqT2U2QAmvcf.VCJypYxbyC_ZCTQI2QHc1xTOYtQZTQQyBygjTiUU_vTCy4KG3dCt48hum1y9BZ1N85Lsj93uvBu6vP748xMAfw3UDTiS; report-to cf-csp-endpoint 1 “default-src 1 script-src 'strict-dynamic' 'nonce-pZhfzXDJB6Hlo6BkZtGS1Q==' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com googleapis.com data: n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com cdn.jsdelivr.net *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.book2look.com static.addtoany.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.openstreetmap.org https://maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.tile.openstreetmap.org connect.ekomi.de google.com google.at www.google.at www.book2look.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ jquery.sellxed.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com www.google.com www.gstatic.com static.addtoany.com connect.ekomi.de cdn.public.n1ed.com appjs.blickinsbuch.de www.blickinsbuch.de https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com www.book2look.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com googleapis.com www.googleapis.com n1ed.com cloud.n1ed.com o.n1ed.com fm.n1ed.com stackpath.bootstrapcdn.com localhost code.jquery.com noembed.com fonts.googleapis.com suggestqueries.google.com translate.yandex.net flmngr.com cloud.flmngr.com fm.flmngr.com fonts.gstatic.com cdn.jsdelivr.net *.openstreetmap.org https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com google-analytics.com doubleclick.net stats.g.doubleclick.net www.book2look.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com https://petdiscont.cz/ https://petdiscont.sk https://maps.googleapis.com/ https://www.googletagmanager.com https://widget.packeta.com/ https://widget.intime.cz/ https://ajax.googleapis.com/ https://fonts.googleapis.com/ *.gstatic.com https://*.mapy.cz im9.cz *.im9.cz *.youtube.com https://zoovyhodne.cz/ https://krmivazoo.cz/ https://aquazoo.cz *.seznam.cz *.google.com https://stats.g.doubleclick.net https://www.heureka.cz https://www.heureka.sk *.heureka.group https://www.zbozi.cz https://c.seznam.cz https://c.imedia.cz https://www.google-analytics.com *.facebook.net *.facebook.com https://www.facebook.com googleads.g.doubleclick.net https://www.heureka.cz https://www.google.cz *.googleadservices.com https://tracking.srovname.cz *.selltoro.com; report-uri /reportCSP.php 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.bunny.net cdn.jsdelivr.net cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com www.facebook.com interface.mailcampaigns.nl *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.addthis.com js.mollie.com *.multisafepay.com https://pay.google.com https://plumrocket.com www.googletagmanager.com *.doubleclick.net tagging.proforto.be www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.disqus.com https://img.youtube.com https://www.mollie.com *.multisafepay.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com px.ads.linkedin.com bat.bing.com www.google.nl t.squeezely.tech www.facebook.com region1.analytics.google.com www.google.fr *.faslet.net trengo.s3.eu-central-1.amazonaws.com *.mailcampaigns.nl *.doubleclick.net cdn.proforto.be tagging.proforto.be images.prismic.io proforto-cdn.imgix.net https://maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; style-src *.adobe.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.multisafepay.com tagmanager.google.com fonts.google.com fonts.bunny.net *.faslet.net *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.trengo.eu player.vimeo.com *.vimeocdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src https://tagging.proforto.be dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com www.google.com b.billypx.com px.ads.linkedin.com analytics.tiktok.com *.doubleclick.net rkkck31tec.execute-api.eu-central-1.amazonaws.com api.faslet.net cdn.api.prod.faslet.net bat.bing.com bat.bing.net p2iqhncxyh.execute-api.eu-central-1.amazonaws.com pagead2.googlesyndication.com metrics.hotjar.io *.trengo.eu *.convertexperiments.com tagging.proforto.be *.tiktokw.us wss://*.hotjar.com interface.mailcampaigns.nl *.yotpo.com https: 'self' 'unsafe-inline'; script-src https://tagging.proforto.be assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net js.mollie.com *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com cdn-4.convertexperiments.com connect.facebook.net static.hotjar.com script.hotjar.com analytics.tiktok.com bat.bing.com squeezely.tech snap.licdn.com bgmin.cdn.billygrace.com d5yoctgpv4cpx.cloudfront.net widget.prod.faslet.net player.vimeo.com *.trengo.eu localhost:5174 *.proforto.be *.yotpo.com https: 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'none'; connect-src 'self' forms.hsforms.com www.google.com px.ads.linkedin.com region1.analytics.google.com stats.g.doubleclick.net bat.bing.net cta-service-cms2.hubspot.com api.hubapi.com forms.hscollectedforms.net pulse.clickguard.com; form-action 'none'; frame-ancestors 'none'; frame-src https://www.googletagmanager.com https://td.doubleclick.net; img-src 'self' data: forms-na1.hsforms.com px.ads.linkedin.com www.google.es bat.bing.net www.google.com forms.hsforms.com perf-na1.hsforms.com track.hubspot.com; font-src 'self' data:; media-src 'none'; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' js.hsforms.net www.googletagmanager.com bat.bing.com static.hotjar.com snap.licdn.com js.hs-scripts.com www.clarity.ms tracking-api.g2.com pulse.clickguard.com script.hotjar.com js.hscollectedforms.net js.hs-analytics.net js.hsadspixel.net js.hubspot.com js.hs-banner.com googleads.g.doubleclick.net; style-src 'self' 'unsafe-inline' fonts.googleapis.com; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com magefan.com cm.magefan.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.jsdelivr.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src http://pics.senator.com https://senator.onapply.de/feed/render.js 'unsafe-inline' https://consent.cookiebot.com 'self' https://payments.salesforce.com/ https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://cdn.onapply.de/static/shared/js/onapplyCareerSite.js https://public.senator.com https://portal.zakeke.com https://portal.zakeke.com/scripts/integration/api/customizer.js https://cdn.onapply.de/static/shared/css/onapplyCareerSite.css https://checkoutshopper-live.adyen.com/ https://api.zakeke.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://zakeke.blob.core.windows.net https://portal.zakeke.com/scripts/config.js https://cdn.onapply.de https://pay.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ blob: https://senator.onapply.de https://www.google.com/recaptcha/ https://js.stripe.com/ https://consent.cookiebot.com/uc.js import: *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval'; report-to sfdc-csp-ep; report-uri https://senator.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D1t000000DG0F&networkId=0DM68000000fxTP&type=communities 1 default-src 'self' data:; img-src 'self' https://*.laposte.fr; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com data:; script-src 'self'; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com 'unsafe-inline'; style-src-attr 'self' https://fonts.googleapis.com https://fonts.gstatic.com; frame-ancestors 'self'; report-uri https://apostello.uriports.com/reports/report; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.nosto.com *.nos.to *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.nosto.com *.nos.to *.googleapis.com *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.nosto.com *.nos.to *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://www.alexmonroe.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.nosto.com *.nos.to webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com assets.braintreegateway.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.nosto.com *.nos.to *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; block-all-mixed-content; script-src 'unsafe-inline' https:; style-src 'unsafe-inline' https:; img-src https: data: 'self'; object-src https: 'self'; font-src https: 'self'; connect-src https: 'self'; frame-ancestors 'self'; worker-src blob: https: 'self' 1 default-src 'self'; img-src * data:; font-src * data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' https:; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://*.entertix.ro; frame-ancestors 'self'; connect-src 'self' https:; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ moogento.com *.moogento.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ l2.moogento.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com *.cloudflare.com *.bootstrap.com 'self' data: *.googleapis.com *.iwdagency.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.addthis.com https://s7.addthis.com/ *.yotpo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://mas.astralweb.com.tw *.cloudflare.com *.google-analytics.com *.paypalobjects.com *.googleapis.com *.iwdagency.com *.yotpo.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.gstatic.com https://maps.googleapis.com https://www.addthis.com https://s7.addthis.com/ m.addthis.com *.addthisedge.com *.paypalobjects.com *.paypal.com z.moatads.com https://services.sheerid.com/jsapi/SheerID.js https://cdn.jsdelivr.net/npm/@sheerid/jslib@1/sheerid.js *.attn.tv *.attentivemobile.com *.iwdagency.com *.yotpo.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.iwdagency.com *.yotpo.com *.googleapis.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.cardinalcommerce.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@sheerid/jslib@1/sheerid.js https://www.addthis.com *.attn.tv *.attentivemobile.com *.iwdagency.com *.yotpo.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://www.google-analytics.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem 'self' 'unsafe-inline' *.gstatic.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.googletagmanager.com *.cookiebot.com *.cookiebot.eu *.google.com *.youtube.com *.hotjar.com *.bing.com *.newrelic.com *.multisafepay.com *.trustedshops.com *.etrusted.com chatwidget-prod.web.app; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.doubleclick.net *.facebook.com *.fontawesome.com https://widgets.trustedshops.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cardinalcommerce.com *.cookiebot.com *.cookiebot.eu *.doubleclick.net *.googletagmanager.com *.vimeo.com *.facebook.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.swagger.io *.ftcdn.net *.behance.net https://www.magezon.com https://images.unsplash.com *.magentocommerce.com *.google.com *.googleapis.com *.doubleclick.net *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.paypalobjects.com *.ytimg.com *.facebook.com *.facebook.net *.iusercentrics.eu *.bing.net *.etrusted.com *.cookiebot.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com magefan.com cm.magefan.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.cardinalcommerce.com *.googleapis.com *.gstatic.com *.doubleclick.net *.google-analytics.com *.googletagmanager.com *.ytimg.com *.facebook.com *.facebook.net *.avada.io *.hotjar.com *.cookiebot.com *.cookiebot.eu *.multisafepay.com *.trustedshops.com *.etrusted.com *.bing.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gstatic.com *.googleapis.com *.google.com *.magento-ds.com *.magento-datasolutions.com *.fontawesome.com chatwidget-css.web.app *.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com maxcdn.bootstrapcdn.com *.multisafepay.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.cookiebot.com *.cookiebot.eu *.cardinalcommerce.com *.googlesyndication.com *.facebook.com *.facebook.net *.avada.io *.bing.net api.ipify.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' www.scalemodelstore.com; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' www.scalemodelstore.com https://www.google.com www.gstatic.com https://www.googleadservices.com tpc.googlesyndication.com connect.facebook.net; frame-src www.google.com tpc.googlesyndication.com; img-src 'self' data: static.pay.nl www.gstatic.com https://googleads.g.doubleclick.net https://www.google.com rms.ups.com; object-src 'none'; report-uri /csp-violations.php; 1 font-src fonts.gstatic.com *.fuelyourbody.nl *.fuelyourbody.de *.fuelyourbody.be *.fuelyourbody.fr data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com *.fuelyourbody.nl *.fuelyourbody.de *.fuelyourbody.be *.fuelyourbody.fr consentcdn.cookiebot.eu www.googletagmanager.com www.youtube-nocookie.com www.facebook.com app.aiden.cx 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com *.fuelyourbody.nl *.fuelyourbody.de *.fuelyourbody.be *.fuelyourbody.fr d3k81ch9hvuctc.cloudfront.net lh4.googleusercontent.com region1.analytics.google.com www.google.nl www.google.be www.google.de bat.bing.com stats.g.doubleclick.net www.facebook.com *.clarity.ms integrations.etrusted.com connect.facebook.net i.ytimg.com jf79.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'unsafe-eval' 'unsafe-inline' *.fuelyourbody.nl *.fuelyourbody.de *.fuelyourbody.be *.fuelyourbody.fr app.aiden.cx bat.bing.com consent.cookiebot.eu consentcdn.cookiebot.eu d5yoctgpv4cpx.cloudfront.net l.getsitecontrol.com popup.projects.webpages.one s2.getsitecontrol.com script.hotjar.com static.hotjar.com www.clarity.ms scripts.clarity.ms www.feedbackcompany.com analytics.tiktok.com pagead2.googlesyndication.com static.klaviyo.com static-tracking.klaviyo.com connect.facebook.net integrations.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com static.klaviyo.com static-tracking.klaviyo.com integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com *.fuelyourbody.nl *.fuelyourbody.de *.fuelyourbody.be *.fuelyourbody.fr app.aiden.cx bat.bing.com consentcdn.cookiebot.eu l.getsitecontrol.com events.getsitectrl.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com www.feedbackcompany.com www.google.com region1.analytics.google.com analytics.tiktok.com analytics-ipv6.tiktokw.us a.klaviyo.com fast.a.klaviyo.com static-forms.klaviyo.com www.facebook.com *.clarity.ms integrations.etrusted.com vc.hotjar.io api-js.datadome.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 default-src 'self'; object-src 'none'; connect-src 'self' https://*.cookiebot.eu https://*.usercentrics.eu *.googleapis.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.clarity.ms https://vimeo.com https://cdn.trustindex.io https://api.mapbox.com https://events.mapbox.com https://l.getsitecontrol.com https://www.facebook.com/ https://dev.visualwebsiteoptimizer.com https://events.getsitectrl.com/ https://analytics.tiktok.com/ https://*.googlesyndication.com; style-src 'self' 'unsafe-inline' https://cloud.typenetwork.com https://api.mapbox.com https://cdn.trustindex.io https://fonts.googleapis.com/; font-src 'self' https://*.gstatic.com/ https://cdn.trustindex.io https://*.typenetwork.com; frame-src 'self' *; script-src 'strict-dynamic' 'nonce-233f2bb2c55914ab129b66991e30e15d' https://www.tiktok.com; img-src 'self' data: *.gravatar.com https://cdn-cookieyes.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk https://*.gstatic.com/ https://www.facebook.com https://*.clarity.ms https://api.mapbox.com/ https://*.vimeocdn.com https://cdn.trustindex.io https://*.googleusercontent.com https://dev.visualwebsiteoptimizer.com https://c.bing.com/ https://s.w.org/ https://*.getsitecontrol.com https://*.googlesyndication.com https://*.usercentrics.eu https://oxygenactiveplay.ams3.digitaloceanspaces.com/; media-src 'self' https://oxygenactiveplay.ams3.digitaloceanspaces.com/; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests ; block-all-mixed-content ; report-uri https://f62fcbcfedd7edcba581844dc278c328.report-uri.com/r/d/csp/reportOnly; report-to default; 1 default-src 'self' https://*.snowsoftware.io https://*.flexeraeu.flexera.com https://*.eu.pendo.io; frame-src 'self' https://app.pendo.io https://*.eu.pendo.io https://www.youtube.com https://player.vimeo.com https://*.snowsoftware.io;connect-src 'self' https://*.snowatlas.snowsoftware.io https://*.snowatlaseu.snowsoftware.io https://*.snowsoftware.io https://*.eu.pendo.io https://*.execute-api.us-east-1.amazonaws.com https://sts.us-east-1.amazonaws.com https://qbusiness.us-east-1.api.aws wss://qbusiness-websocket.us-east-1.api.aws wss://*.snowsoftware.io https://*.launchdarkly.com https://westeurope-2.in.applicationinsights.azure.com https://js.monitor.azure.com/ https://*.blob.core.windows.net https://*.sumologic.com;script-src 'self' 'unsafe-eval' 'report-sample' https://app.eu.pendo.io https://*.snowatlas.snowsoftware.io https://*.snowatlaseu.snowsoftware.io https://*.snowsoftware.io https://snowsoftware.io https://*.flexera.com https://*.flexeraone.flexera.com https://cdn.pendo.io https://*.sumologic.com; style-src 'self' 'unsafe-inline' 'report-sample' https://*.eu.pendo.io https://*.snowatlaseu.snowsoftware.io https://*.snowsoftware.io; font-src 'self' data: https://*.eu.pendo.io https://*.cdn.eu.pendo.io https://*.snowsoftware.io;img-src 'self' https://*.snowatlas.snowsoftware.io https://*.snowatlaseu.snowsoftware.io https://*.eu.pendo.io https://*.dev-snowsoftware.io https://*.flexera.com data:; 1 font-src www.paypalobjects.com *.klarnacdn.net *.cloudfront.net *.klarna.com *.zdassets.com *.mekster.se *.mekster.no *.firebase.com *.zendesk.com *.gstatic.com *.googleapis.com *.tryggehandel.net *.pji.nu *.prisjakt.nu js.live.kustom.co data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mekster.se *.mekster.no *.facebook.com *.google.com *.trackedweb.net *.criteo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.youtube-nocookie.com www.google.com *.dotdigital-pages.com *.dotdigital.com *.klarna.com *.mekster.se *.mekster.no *.facebook.com *.google.com *.castrol.com *.lubricantadvisor.com *.mobil1.se *.zendesk.com *.thule.com *.criteo.com *.criteo.net td.doubleclick.net *.mpmoil.se *.pji.nu *.klarnaservices.com js.playground.kustom.co *.klarnaevt.com *.googletagmanager.com js.live.kustom.co *.bing.com *.bing.net *.tradedoubler.com *.imgstatics.com *.customerfirst.ai 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io https://images.unsplash.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.mekster.se *.mekster.no *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.google.com *.google.co.in *.ytimg.com *.gstatic.com *.redchamps.com *.cloudfront.net *.firebase.com *.zendesk.com *.googletagmanager.com *.facebook.net google-analytics.com *.googleapis.com *.tryggehandel.net cdn.cookielaw.org *.criteo.net *.criteo.com *.google.se *.google.no *.google.pl *.google.de x.bidswitch.net ib.adnxs.com contextual.media.net pixel.rubiconproject.com rtb-csync.smartadserver.com sync-t1.taboola.com criteo-sync.teads.tv eb2.3lift.com hb.yahoo.net *.adform.net visitor.omnitagjs.com r.casalemedia.com id5-sync.com ad.360yield.com matching.ivitrack.com exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com match.sharethrough.com criteo-partners.tremorhub.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com beacon.krxd.net *.pji.nu *.prisjakt.nu *.googlesyndication.com js.playground.kustom.co *.reddit.com js.live.kustom.co *.simpli.fi *.clarity.ms https://redchamps.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com player.vimeo.com *.mekster.se *.mekster.no *.tradedoubler.com *.bing.com *.bing.net *.google.com *.gstatic.com *.adtraction.com *.adnxs.com *.googletagmanager.com *.facebook.net *.googleapis.com *.firebase.com *.zdassets.com *.zopim.com *.cloudfront.net *.zendesk.com *.criteo.net *.criteo.com *.dotdigital.com *.swagger.com *.doubleclick.net code.jquery.com tagmanager.google.com *.google-analytics.com *.googleadservices.com cdn.cookielaw.org *.onetrust.com *.tryggehandel.net polyfill.io *.clarity.ms cdn.jsdelivr.net *.fullstory.com *.pji.nu *.prisjakt.nu *.googlesyndication.com js.playground.kustom.co *.klarnaevt.com *.redditstatic.com *.unpkg.com unpkg.com *.tiktok.com *.reddit.com js.live.kustom.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.klarnacdn.net *.mekster.se *.mekster.no *.cloudfront.net *.klarna.com *.zdassets.com *.firebase.com *.zendesk.com tagmanager.google.com *.googleapis.com *.googletagmanager.com *.pji.nu *.prisjakt.nu js.live.kustom.co 'self' 'unsafe-inline'; object-src *.mekster.se *.mekster.no *.cloudfront.net *.zendesk.com 'self' 'unsafe-inline'; media-src *.mekster.se *.mekster.no *.klarna.com *.cloudfront.net *.zendesk.com *.zdassets.com *.zopim.com *.klarnaevt.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.vimeo.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.mekster.se *.mekster.no *.bing.com *.bing.net *.facebook.com *.google.com *.doubleclick.net *.zopim.com *.zdassets.com *.zendesk.com *.cloudfront.net *.youtube.com *.firebase.com *.googletagmanager.com cdn.cookielaw.org *.onetrust.com *.clarity.ms *.criteo.com *.fullstory.com *.pji.nu *.googlesyndication.com *.reddit.com *.redditstatic.com js.playground.kustom.co js.live.kustom.co *.tiktok.com 'self' 'unsafe-inline'; child-src *.cloudfront.net http: https: blob: 'self' 'unsafe-inline'; default-src *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.feedbackcompany.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: www.cm.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.googletagmanager.com js.mollie.com www.xtento.com *.freshchat.com *.doubleclick.net *.vekto.nl *.cvtotaal.nl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com *.disqus.com *.feedbackcompany.com 'self' data: *.google.nl https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://img.youtube.com https://www.mollie.com flagpedia.net https://redchamps.com *.hsforms.net *.hsforms.com ts.tradetracker.net www.magmodules.eu www.xtento.com cdn.xtento.com *.visualwebsiteoptimizer.com *.cvtotaal.nl cvtotaal.nl *.eu.com *.mistersales.nu *.bing.com *.windows.net *.taggrs.io *.google.com *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.disqus.com *.feedbackcompany.com *.google.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com s7.addthis.com *.googletagmanager.com tagmanager.google.com js.mollie.com maps.googleapis.com *.hsforms.net *.hsforms.com tm.tradetracker.net www.xtento.com cdn.xtento.com gateway.tweakwisenavigator.net *.freshchat.com *.visualwebsiteoptimizer.com *.clarity.ms *.bing.com *.eu.com *.robinhq.com *.windows.net *.msecnd.net *.digitalcx.com *.vekto.nl *.beslist.nl *.facebook.net *.exatom.io *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com *.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com tagmanager.google.com fonts.google.com maxcdn.bootstrapcdn.com *.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.2/css/fontawesome.min.css *.freshchat.com *.eu.com *.mistersales.nu mistersales.nu *.typeform.com embed.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.eu.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.feedbackcompany.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ekr.zdassets.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com www.gstatic.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com gateway.tweakwisenavigator.net *.visualwebsiteoptimizer.com *.doubleclick.net *.eu.com *.clarity.ms *.visualstudio.com wss://cxcomlive-webconvwa-weu.azurewebsites.net *.cvtotaal.nl *.vekto.nl *.beslist.nl *.exatom.io *.bing.com api.typeform.com wss://webchat-api.digitalcx.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://*.svea.com https://*.vipps.no https://*.trustly.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.trustpilot.com tr.snapchat.com *.playground.klarna.com cdn.klarna.com www.google.com js.klarna.com youtube.com www.youtube.com *.cookiebot.com *.klarna.com *.criteo.com *.hotjar.com *.doubleclick.net https://*.svea.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com polyfill.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.clerk.io widget-mediator.zopim.com dev.visualwebsiteoptimizer.com static.lipscore.com widget.trustpilot.com invitejs.trustpilot.com eu-library.klarnaservices.com sleeknotecustomerscripts.sleeknote.com static.zdassets.com tr.snapchat.com sc-static.net *.algolia.net *.algolianet.com cdn.klarna.com x.klarnacdn.net *.playground.klarna.com tagmanager.google.com www.googletagmanager.com ssl.google-analytics.com www.google.com www.gstatic.com *.cookiebot.com *.googlesyndication.com s.sparmax.no googletagmanager.com *.lipscore.com frankanddick.dev s.kk-resources.com *.criteo.com *.criteo.net *.hotjar.com *.bing.com *.de17a.com *.facebook.net google-analytics.com *.adform.net *.sleeknote.com *.zdassets.com google.com gstatic.com *.trustpilot.com *.klarnaservices.com *.clarity.ms *.klarnacdn.net *.klarna.com *.doubleclick.net *.sparmax.se *.sparmax.dk *.maxkjop.no *.skjaraard.no s.skjargaard.no partner.googleadservices.com www.tryggehandel.no *.zopim.com vjs.zencdn.net player.vimeo.com https://*.svea.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudflare.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget-mediator.zopim.com wss://widget-mediator.zopim.com static.zdassets.com *.klarnauserservices.com *.klarnaservices.com wapi.lipscore.com *.zdassets.com sparmax.zendesk.com *.snapchat.com *.google.com *.google-analytics.com *.googlesyndication.com *.visualwebsiteoptimizer.com *.hotjar.io *.playground.klarnaevt.com www.googletagmanager.com www.google-analytics.com *.cookiebot.com *.criteo.com vars.hotjar.com *.de17a.com *.trustpilot.com dnacdn.net *.getsentry.com s.sparmax.no tryggehandel.no google.com gtm.sparmax.no *.clarity.ms bat.bing.com google-analytics.com google.com/recaptcha *.klarnacdn.net *.doubleclick.net *.klarnaevt.com *.klarna.com s.sparmax.se s.sparmax.dk s.maxkjop.no *.skjaraard.no s.skjargaard.no www.facebook.com/tr *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; font-src https://pim.sparmax.no/ static.lipscore.com x.klarnacdn.net fonts.gstatic.com *.fontawesome.com fonts.gstatic.com/s s.sparmax.no s.sparmax.dk s.sparmax.se s.maxkjop.no s.skjargaard.no *.zopim.com data: *.gstatic.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; style-src https://pim.sparmax.no/ getfirebug.com sparmax.wpcloud.trollweb.no x.klarnacdn.net static.lipscore.com tagmanager.google.com fonts.googleapis.com https://*.sparmax.no *.trollweb.no *.lipscore.com *.klarnacdn.net https://*.sparmax.se https://*.sparmax.dk https://*.maxkjop.no https://*.skjargaard.no unsafe-inline vjs.zencdn.net cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.trustpilot.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; img-src https://pim.sparmax.no/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com camo.githubusercontent.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.clerk.io x.klarnacdn.net sparmax.wpcloud.trollweb.no tr.snapchat.com *.google.com *.google.pl *.google.no cdn.klarna.com *.playground.klarnaevt.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com googleads.g.doubleclick.net www.google.com *.cookiebot.com s.sparmax.no www.tryggehandel.no *.trollweb.no google-analytics.com dev.visualwebsiteoptimizer.com google.com/ads www.facebook.com *.bing.com *.criteo.com *.criteo.net *.zdassets.com *.clarity.ms *.doubleclick.net raw.githubusercontent.com/vippsas *.sparmax.se *.sparmax.dk *.maxkjop.no *.skjaraard.no s.skjargaard.no googleadservices.com v2assets.zopim.io www.google.no/ads www.google.se/ads www.google.dk/ads www.google.fr/ads www.google.co.uk/ads www.google.uk/ads www.google.com/ads www.google.de/ads www.google.pl/ads www.google.lt/ads www.google.es/ads www.google.lv/ads www.google.ee/ads www.google.th/ads www.google.no/pagead www.google.se/pagead www.google.dk/pagead www.google.fr/pagead www.google.co.uk/pagead www.google.uk/pagead www.google.com/pagead www.google.de/pagead www.google.pl/pagead www.google.lt/pagead www.google.es/pagead www.google.lv/pagead www.google.ee/pagead www.google.th/pagead gtm.sparmax.no *.klarnaevt.com https:/at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; 1 default-src https: 'unsafe-inline'; font-src *.itemis.com fonts.gstatic.com cdnjs.cloudflare.com data:; img-src https: data:; script-src https: 'unsafe-inline' 'unsafe-eval'; object-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.crisp.chat static.fulfiller.com drhur8ajhi373.cloudfront.net d39xcqom8pbi81.cloudfront.net recette-static.fulfiller.com applepay.cdn-apple.com *.fonts.googleapis.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com connect.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com connect.facebook.net ucarecdn.com pitchprint.io payment.stancer.com 3ds.iliad78.net image.fulfiller.com api-qa.payplug.com secure-qa.payplug.com *.payplug.com *.addthis.com *.twitter.com js.mollie.com *.pinterest.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com blob: integration.ecom.back2print.fr www.fulfiller.com ucarecdn.com axeptio.imgix.net *.crisp.chat *.doubleclick.net *.google.com *.facebook.com *.facebook.net *.fbcdn.net cdn.filestackcontent.com static.filestackapi.com static.fulfiller.com drhur8ajhi373.cloudfront.net d39xcqom8pbi81.cloudfront.net assets.fulfiller.com *.google.fr image.fulfiller.com *.elfsight.com *.elfsightcdn.com *.googleusercontent.com bat.bing.com *.amazonaws.com pitchprint.io recette-static.fulfiller.com zefiles.fulfiller.com https://secure-magenta.dalenys.com *.addthisedge.com *.twitter.com https://www.mollie.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com analytics.tiktok.com static.cloudflareinsights.com *.googletagmanager.com image.fulfiller.com connect.facebook.net graph.facebook.com js.facebook.com *.facebook.net static.filestackapi.com static.fulfiller.com drhur8ajhi373.cloudfront.net d39xcqom8pbi81.cloudfront.net *.axept.io ucarecdn.com *.crisp.chat *.elfsight.com *.elfsightcdn.com bat.bing.com *.gstatic.com *.paypal.com cdn.payplug.com pitchprint.io cdn.jsdelivr.net recette-static.fulfiller.com *.tiny.cloud *.tinymce.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com https://cdn-qa.payplug.com https://secure-magenta.dalenys.com *.addthis.com *.moatads.com *.addthisedge.com *.twitter.com js.mollie.com *.googleapis.com *.facebook.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.crisp.chat static.filestackapi.com static.fulfiller.com drhur8ajhi373.cloudfront.net d39xcqom8pbi81.cloudfront.net *.gstatic.com cdn.jsdelivr.net recette-static.fulfiller.com unpkg.com *.tiny.cloud https://secure-magenta.dalenys.com *.googleapis.com 'self' 'unsafe-inline'; object-src ucarecdn.com 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com analytics.tiktok.com bat.bing.net blob: *.axept.io *.crisp.chat wss://client.relay.crisp.chat *.doubleclick.net connect.facebook.net filestack-uploads-persist-production.s3.amazonaws.com cloud.filestackapi.com upload.filestackapi.com *.filestackapi.com static.fulfiller.com drhur8ajhi373.cloudfront.net d39xcqom8pbi81.cloudfront.net *.google.fr image.fulfiller.com *.elfsight.com bat.bing.com pitchprint.io api.pitchprint.io recette-static.fulfiller.com reseller-sandbox.fulfiller.com reseller.fulfiller.com *.uploadcare.com https://uploadcare.s3-accelerate.amazonaws.com ucarecdn.com releases.transloadit.com *.cloudflare.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com 'self' 'unsafe-inline'; child-src *.facebook.com connect.facebook.net http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self';connect-src 'self' https://*.hotjar.com https://*.google-analytics.com https://*.linkedin.com https://*.facebook.com https://*.twitter.com;default-src 'self';form-action 'self' https://*.facebook.com;img-src * data:;media-src 'self';object-src 'none';script-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.googletagmanager.com https://*.google-analytics.com https://*.hotjar.com https://*.facebook.net https://*.twitter.com https://instant.page;style-src 'self' 'unsafe-inline' https://*.googleapis.com;frame-src https://*.googletagmanager.com https://*.hotjar.com https://*.facebook.com https://*.twitter.com https://cdn.yoshki.com;font-src 'self' data: https://*.gstatic.com https://*.googleapis.com 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.avada.io player.vimeo.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net https://widgets.trustedshops.com integrations.etrusted.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://seo.mageplaza.com www.facebook.com *.copernica.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com https://www.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://*.dpdconnect.nl *.dpdconnect.nl service2.loyaltyinabox.com *.pinterest.com www.facebook.com www.youtube.com view.publitas.com www.google.com www.google.nl www.google.de *.google.com maps.google.com chat.babypark.nl *.doubleclick.net td.doubleclick.net googleads.g.doubleclick.net widget.trustpilot.com *.cookiebot.com *.cookiebot.eu chatwidget-prod.web.app www.googletagmanager.com sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl folders.baby-dump.nl platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.klevu.com *.ksearchnet.com www.babypark.nl www.babypark.de www.babydeals.be dehoevebuitenleven.nl m2.babypark.mavendev.com m2.babypark-de.mavendev.com www.ikenik.nl m2.ikenik.mavendev.com m2.babydump.mavendev.com m2.babydump-de.mavendev.com www.google.com www.google.nl www.google.de www.google.com.ua www.facebook.com ct.pinterest.com www.googletagmanager.com www.zenaps.com www.awin1.com static.zdassets.com *.bing.com *.bing.net www.thuiswinkel.org i.ytimg.com img.youtube.com blob: lantern.roeye.com *.clarity.ms *.cookiebot.com *.cookiebot.eu integrations.etrusted.com stats.g.doubleclick.net sst.babypark.nl sst.babypark.de sst.babydeals.be sst.baby-dump.nl pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: maps.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://*.dpdconnect.nl js.klevu.com *.ksearchnet.com *.avada.io www.googletagmanager.com checkout.buckaroo.nl *.clarity.ms lantern.roeyecdn.com widgets.trustedshops.com web-sdk.smartlook.com www.dwin1.com s.pinimg.com connect.facebook.net static.buckaroo.nl view.publitas.com api.360productviewer.com googleads.g.doubleclick.net bat.bing.com bat.bing.net static.zdassets.com js-agent.newrelic.com *.livechatinc.com bam.eu01.nr-data.net chat.babypark.nl widget.trustpilot.com *.pinterest.com *.hotjar.com *.hotjar.io *.cookiebot.com *.cookiebot.eu integrations.etrusted.com chatwidget-prod.web.app twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com *.gstatic.com maps.googleapis.com https://widgets.trustedshops.com *.yotpo.com sst.babydeals.be https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.typekit.net checkout.buckaroo.nl integrations.etrusted.com chatwidget-css.web.app maxcdn.bootstrapcdn.com unsafe-inline *.googleapis.com *.gstatic.com https://widgets.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com integrations.etrusted.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.clarity.ms *.pinterest.com *.doubleclick.net stats.g.doubleclick.net googleads.g.doubleclick.net manager.eu.smartlook.cloud ekr.zdassets.com wss://widget-mediator.zopim.com api.360productviewer.com www.facebook.com livechat.fabulor.eu bam.eu01.nr-data.net region1.analytics.google.com *.google.com *.hotjar.com *.hotjar.io analytics.google.com bat.bing.com bat.bing.net *.cookiebot.com *.cookiebot.eu *.copernica.com integrations.etrusted.com api.ipify.org www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.yotpo.com sst.babydeals.be https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' https://connect.facebook.net http://116389.tctm.co https://td.doubleclick.net https://cdn.userway.org https://cdn.userway.org https://api.userway.org https://www.google.co.il https://www.google.com https://analytics.google.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://fonts.gstatic.com https://stats.g.doubleclick.net https://client.crisp.chat wss://client.relay.crisp.chat https://googleads.g.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://connect.facebook.net http://116389.tctm.co https://ajax.googleapis.com https://www.toyota-europe.com https://cdn.jsdelivr.net https://code.jquery.com https://cdn.userway.org https://cdn.userway.org https://api.userway.org https://www.google.co.il https://www.google.com https://analytics.google.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://fonts.gstatic.com https://stats.g.doubleclick.net https://client.crisp.chat wss://client.relay.crisp.chat https://googleads.g.doubleclick.net; style-src 'self' 'unsafe-inline' https://client.crisp.chat https://cdn.userway.org https://cdn.jsdelivr.net https://cdn.jsdelivr.net; img-src 'self' data: https://www.facebook.com https://www.googletagmanager.com https://www.google.com https://www.google.co.il https://yos17.blob.core.windows.net https://cdn.userway.org https://haifaac.localtimeline.com https://maps.gstatic.com; report-uri /csp-report 1 default-src 'none'; frame-src 'self'; img-src 'self' https://storage.googleapis.com/ https://assets.cantook.net/ https://assets.entrepotnumerique.com/ https://assets.edenlivres.fr/ https://assets-libr.cantook.net/ https://assets-edgt.cantook.net/; script-src 'self' https://cdn.jsdelivr.net/npm/intl-tel-input@25.12.4/build/js/utils.js; style-src 'self' 'unsafe-inline'; connect-src 'self' https://storage.googleapis.com/ https://o37564.ingest.sentry.io; report-uri https://o37564.ingest.sentry.io/api/84541/security/?sentry_key=0b6a319c2af64d94839478210ee88f6c&sentry_environment=prod-northamerica 1 default-src 'self'; base-uri 'none'; connect-src https: wss:; font-src https: data:; form-action 'self'; frame-ancestors 'self'; frame-src https:; img-src https: data:; media-src 'self' https://widget.molin.ai; object-src 'none'; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; report-uri https://kosik.bauhaus.sk/csp_report; report-to bauhaus-csp; 1 font-src *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com applepay.cdn-apple.com 'self' data: fonts.gstatic.com use.fontawesome.com maxcdn.bootstrapcdn.com motorsport-tools.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.securetrading.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com motorsport-tools.com 'self' 'unsafe-inline'; frame-ancestors motorsport-tools.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.rvvuptech.com *.rvvup.com *.afterpay.com *.clearpay.co.uk *.sandbox.paypal.com cdn.eu.trustpayments.com *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com thm.visa.com *.mastercard.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com motorsport-tools.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ *.trackedlink.net validate.fishpig.co.uk *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.afterpay.com assets.dev.rvvuptech.com assets.rvvup.com *.sandbox.paypal.com *.stats.paypal.com *.gstatic.com *.vims.visa.com *.secure.checkout.visa.com *.mastercard.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com motorsport-tools.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com landofcoder.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.google.com *.gstatic.com *.afterpay.com *.sandbox.paypal.com checkout.dev.rvvuptech.com checkout.rvvup.com cdn.eu.trustpayments.com *.securetrading.net *.secure.checkout.visa.com *.cardinalcommerce.com *.mastercard.com applepay.cdn-apple.com *.googletagmanager.com tagmanager.google.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com motorsport-tools.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ *.squarecdn.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net unsafe-inline assets.braintreegateway.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com checkout.dev.rvvuptech.com checkout.rvvup.com fonts.googleapis.com tagmanager.google.com fonts.google.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com motorsport-tools.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com motorsport-tools.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static.afterpay.com static.sandbox.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.clearpay.co.uk *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com landofcoder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.afterpay.com *.sandbox.paypal.com *.sentry.io *.dev.rvvuptech.com *.rvvup.com www.apple.com apple.com browser-intake-datadoghq.com browser-intake-datadoghq.eu t.elasticsuite.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com motorsport-tools.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com motorsport-tools.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com motorsport-tools.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com sgtm.goodfellow.com consentcdn.cookiebot.com app-eu1.hubspot.com *.hs-sites-eu1.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.goodfellow.local *.goodfellow.com mcprod.goodfellow.com mcstaging.goodfellow.com *.feefo.com *.hubspot.com *.linkedin.com *.socialintents.com *.vimeo.com *.cookiebot.com *.bing.com *.businessintuition247.com *.clarity.ms *.google.co.uk *.google.com *.doubleclick.net *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.iweb.co.uk *.mida.so *.hsforms.com goodfellow.com openfpcdn.io *.hubapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.goodfellow.local *.feefo.com *.hubspot.com *.linkedin.com *.socialintents.com *.vimeo.com *.cookiebot.com *.bing.com *.businessintuition247.com *.clarity.ms *.google.co.uk *.doubleclick.net *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.iweb.co.uk *.mida.so *.hsforms.com *.goodfellow.com goodfellow.com openfpcdn.io *.hubapi.com bam.nr-data.net js-eu1.usemessages.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.goodfellow.local *.feefo.com *.hubspot.com *.linkedin.com *.socialintents.com *.vimeo.com *.cookiebot.com *.bing.com *.businessintuition247.com *.clarity.ms *.google.co.uk *.doubleclick.net *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.iweb.co.uk *.mida.so *.hsforms.com *.goodfellow.com goodfellow.com openfpcdn.io *.hubapi.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.goodfellow.local *.feefo.com *.hubspot.com *.linkedin.com *.socialintents.com *.vimeo.com *.cookiebot.com *.bing.com *.businessintuition247.com *.clarity.ms *.google.co.uk *.google-analytics.com *.doubleclick.net *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com *.hs-scripts.com *.licdn.com *.iweb.co.uk *.mida.so *.hsforms.com *.goodfellow.com goodfellow.com openfpcdn.io *.hubapi.com static.hsappstatic.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.goodfellow.com/csp-report; report-to report-endpoint; 1 https://maps.googleapis.com/ https://maps.google.com/ https://youtube.com/ https://*.youtube.com/ https://www.recaptcha.net/ https://www.gstatic.com/ https://www.google.com/ https://connect.facebook.net/ 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self' 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com bid.g.doubleclick.net www.google.com *.google.com *.doubleclick.net *.facebook.com js.mollie.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com magefan.com cm.magefan.com https://www.mollie.com www.google.com.ua data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com js.mollie.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src *; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'self'; report-to /csp-report-endpoint; report-uri /csp-report-endpoint; 1 script-src-elem js.braintreegateway.com *.paypal.com www.paypalobjects.com protection-widget.route.com protect-quote-q.route.com unpkg.com protect-lightning-bolt-widget.route.com bat.bing.com emotivecdn.io static.hotjar.com loader.wisepops.com www.googletagmanager.com chimpstatic.com wisepops.net *.yotpo.com *.criteo.com *.reviews.co.uk script.hotjar.com goal.us14.list-manage.com googleads.g.doubleclick.net www.clarity.ms connect.facebook.net *.affirm.com maps.googleapis.com www.google.com www.gstatic.com payments-sdk.live.commerce-payment-services.com www.googleadservices.com *.termly.io services-connector-ui.magento-ds.com https://data-management-external.magento-ds.com static.cloudflareinsights.com https://search-admin-ui.magento-ds.com *.adobe.io *.adobedtm.com https://static.cloudflareinsights.com *.aptrinsic.com *.magento-ds.com https://commerce.adobedtm.com https://rum.hlx.page dynamic.criteo.com sslwidget.criteo.com widget.reviews.io www.youtube.com sc-static.net ff.kis.v2.scr.kaspersky-labs.com form-assets.mailchimp.com app.certcapture.com cdn.id5-sync.com scripts.clarity.ms cdn.jsdelivr.net js-agent.newrelic.com commerce.adobedtm.com www.ssa.gov ajax.googleapis.com app.pageproofer.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem fonts.googleapis.com *.yotpo.com www.googletagmanager.com https://data-management-external.magento-ds.com www.gstatic.com cdn.honey.io ff.kis.v2.scr.kaspersky-labs.com cdn.jsdelivr.net www.ssa.gov 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.yotpo.com https://fonts.gstatic.com https://*.gstatic.com www.paypalobjects.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.affirm.com *.affirm.ca *.certcapture.com https://plumrocket.com https://www.google.com *.weltpixel.com *.yotpo.com *.googletagmanager.com *.doubleclick.net www.googletagmanager.com *.demdex.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.affirm.com *.affirm.ca *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.bing.com *.facebook.com *.reddit.com *.yotpo.com ads.stickyadstv.com x.bidswitch.net gum.criteo.com cm.adgrx.com *.criteo.com www.google.co.in c.clarity.ms public-prod-dspcookiematching.dmxleo.com um.simpli.fi *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://images.unsplash.com form-assets.mailchimp.com https://*.google.co.in https://*.clarity.ms blob:https://hspdiesel.com *.hspdiesel.com *.everesttech.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.google.co.ve www.google.ca www.google.de bat.bing.net www.google.com.mx www.google.com.au csm.da.us.criteo.net csm.us5.us.criteo.net www.google.com.br www.google.co.uk www.google.dk www.google.com.sg s3-us-west-2.amazonaws.com yt3.ggpht.com www.google.com.do www.google.com.bz cdn.honey.io www.google.md www.google.com.kw lh3.google.com ppepower.com lh3.googleusercontent.com www.google.it www.google.se www.google.sk www.google.com.ec jadserve.postrelease.com partner.mediawallahscript.com criteo-partners.tremorhub.com ad.tpmn.co.kr trends.revcontent.com tapestry.tapad.com exchange.mediavine.com ad.tpmn.io staging.hspdiesel.com www.google.com.co www.google.es www.google.nl www.google.co.th www.google.la www.google.com.ar www.google.com.bh www.google.com.bo www.google.pl i.liadm.com thrtle.com ups.analytics.yahoo.com cms.analytics.yahoo.com sync.crwdcntrl.net obgpm76tt0a0sgogzhdfe.redinuid.imrworldwide.com www.google.ad id5-sync.com ad.yieldlab.net d.turn.com www.google.at cdn.ivaws.com www.google.al client-side-metrics.us5.us.criteo.net www.google.com.hk www.google.no client-side-metrics.da.us.criteo.net us-u.openx.net www.google.fi www.google.com.pk i.ebayimg.com mcprod.hspdiesel.com prodhvya.hspdiesel.com www.google.com.pr local.hspcloud-staging.com www.google.com.gh www.google.com.tr connect.facebook.net www.google.ge www.google.gr www.google.com.cy www.google.co.za www.google.bg www.google.co.id www.google.com.eg www.ssa.gov www.google.com.ng www.google.ae www.google.hn www.google.ru www.google.ch data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.yotpo.com https://apis.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.googletagmanager.com *.googleadservices.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.doubleclick.net unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.adobe.io *.magento-datasolutions.com https://maps.googleapis.com form-assets.mailchimp.com https://*.bing.com http://*.bing.com https://emotivecdn.io https://*.hotjar.com http://*.wisepops.com https://*.clarity.ms https://wisepops.net https://data-management-external.magento-ds.com https://recommendations-admin-ui.adobe.io *.braintreegateway.com *.braintree-api.com https://payments-sdk.live.commerce-payment-services.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com https://js-agent.newrelic.com https://rum.hlx.page static.hotjar.com emotivecdn.io loader.wisepops.com dynamic.criteo.com bat.bing.com wisepops.net script.hotjar.com sslwidget.criteo.com www.clarity.ms app.termly.io widget.us.criteo.com cdn.id5-sync.com cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.certcapture.com downloads.mailchimp.com *.googleapis.com *.yotpo.com *.tagmanager.google.com *.googletagmanager.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com https://*.googleapis.com https://data-management-external.magento-ds.com *.braintreegateway.com *.braintree-api.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com cdn.jsdelivr.net cdn.honey.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.affirm.com *.affirm.ca *.certcapture.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.yotpo.com flag.lab.amplitude.com api.lab.amplitude.com www.emotiveapp.co x.clarity.ms api2.amplitude.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.snplow.net commerce.adobedc.net api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://*.emotiveapp.co https://*.clarity.ms https://*.hotjar.io *.braintreegateway.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io bat.bing.com k.clarity.ms e.clarity.ms b.clarity.ms z.clarity.ms r.clarity.ms p.clarity.ms a.clarity.ms s.clarity.ms q.clarity.ms u.clarity.ms j.clarity.ms t.clarity.ms l.clarity.ms w.clarity.ms d.clarity.ms n.clarity.ms h.clarity.ms v.clarity.ms m.clarity.ms f.clarity.ms bat.bing.net o.clarity.ms www.google.com.au i.clarity.ms www.google.ca www.google.com.kw popup.wisepops.com activity.wisepops.com eventcollector.mcf-prod.a.intuit.com 9kvu81ddh3.execute-api.us-east-2.amazonaws.com y.clarity.ms www.google.com c.ba.contentsquare.net www.google.se stats.g.doubleclick.net www.google.co.in www.facebook.com subwayblaze.com rum.hlx.page api.geoedge.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://hspdiesel.com/rest/all/V1/cspmanager/frontend_report; report-to report-endpoint; 1 script-src 'strict-dynamic' 'nonce-pyEVkE6IWBiLE+fNMzVYxw==' 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com https://www.google.com https://vars.hotjar.com landofcoder.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com http://www.googleadservices.com http://www.alteroemer.de https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://script.hotjar.com https://static.hotjar.com landofcoder.com *.avada.io *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://cdn.jsdelivr.net https://use.fontawesome.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com https://in.hotjar.com https://www.google-analytics.com landofcoder.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://fonts.googleapis.com/ https://consent.cookiefirst.com https://edge.cookiefirst.com https://api.cookiefirst.com https://cdn.voiceflow.com fonts.gstatic.com https://fonts.bunny.net *.googleapis.com *.gstatic.com https://geowidget.easypack24.net maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com sandbox.przelewy24.pl secure.przelewy24.pl addtoany.com bam.eu01.nr-data.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.youtube.com https://www.instagram.com https://google.com https://www.googletagmanager.com/ pay.google.com https://geowidget-app.inpost.pl/ *.addtoany.com bam.eu01.nr-data.net https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com https://www.facebook.com https://www.google.de https://www.google.en https://www.google.pl https://www.google.com.ua https://www.google.com https://maps.gstatic.com https://cdn.voiceflow.com *.amazonaws.com static.przelewy24.pl www.gstatic.com gstatic.com https://firebasestorage.googleapis.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.addtoany.com bam.eu01.nr-data.net https://meetanshi.com/media/logo.png data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleservices.com https://v2.zopim.com https://consent.cookiefirst.com https://edge.cookiefirst.com https://api.cookiefirst.com https://connect.facebook.net https://region1.google-analytics.com https://analytics.google.com https://www.instagram.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://cdn.voiceflow.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com https://ipinfo.io *.avada.io *.fontawesome.com *.googleapis.com *.gstatic.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.addtoany.com bam.eu01.nr-data.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://consent.cookiefirst.com https://www.google.com https://www.gstatic.com https://fast.fonts.net https://secure.przelewy24.pl https://edge.cookiefirst.com https://api.cookiefirst.com https://cdn.voiceflow.com fonts.googleapis.com https://fonts.bunny.net *.googleapis.com *.addtoany.com https://geowidget.easypack24.net https://geowidget.inpost.pl maxcdn.bootstrapcdn.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com https://widget-mediator.zopim.com https://consent.cookiefirst.com https://edge.cookiefirst.com https://api.cookiefirst.com https://www.facebook.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://analytics.google.com https://maps.gstatic.com https://pagead2.googlesyndication.com https://region1.analytics.google.com https://maps.googleapis.com https://google.com https://www.google.com https://analytics.tiktok.com https://general-runtime.voiceflow.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.addtoany.com bam.eu01.nr-data.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://www.google.com https://www.gstatic.com; frame-src 'self' https://www.google.com; connect-src 'self' https://www.google-analytics.com; frame-ancestors 'self'; 1 child-src ; connect-src 'self' analytics.google.com analytics.tiktok.com app.gleen.ai *.bellhop.com *.bellhops.dev api.omappapi.com api.segment.io api-js.mixpanel.com api-us-east-1.graphcms.com bat.bing.com bellhop.extole.io *.clarity.ms *.fullstory.com cdn.segment.com ct.pinterest.com *.growthbook.io *.ingest.sentry.io *.intercom.io nexus-websocket-a.intercom.io maps.googleapis.com pnapi.invoca.net *.shop.pe stats.g.doubleclick.net www.google-analytics.com *.taboola.com *.zdassets.com bellhop.zendesk.com; default-src ; font-src 'self' fonts.gstatic.com js.intercomcdn.com; form-action ct.pinterest.com www.facebook.com; frame-src bid.g.doubleclick.net td.doubleclick.net ct.pinterest.com js.stripe.com www.facebook.com; img-src 'self' ag.innovid.com analytics.twitter.com apolloprogram.io b1sync.zemanta.com bat.bing.com c.us1.dyntrk.com cm.adgrx.com cm.eyereturn.com cmi.netseer.com ct.pinterest.com d.adroll.com flask.nextdoor.com googleads.g.doubleclick.net ib.adnxs.com idsync.rlcdn.com js.intercomcdn.com *.loggly.com load.instinctiveads.com media.graphassets.com media.graphcms.com origin.xtlo.net p.truefitcorp.com pippio.com secure.insightexpressai.com segments.company-target.com static.intercomassets.com su.addthis.com sync.smartadserver.com t.co track2.securedvisit.com ups.analytics.yahoo.com us-u.openx.net vop.sundaysky.com wam.solution.weborama.fr www.facebook.com www.google.com www.google-analytics.com www.googleadservices.com www.googletagmanager.com www.storygize.net x.bidswitch.net x.skimresources.com; manifest-src 'self'; media-src app.gleen.ai; script-src 'unsafe-eval' 'unsafe-inline'; script-src-attr ; script-src-elem 'self' 'unsafe-inline' a.omappapi.com *.adroll.com addshoppers.s3.amazonaws.com ads.nextdoor.com analytics.tiktok.com app.gleen.ai bat.bing.com bellhop.extole.io cdn.segment.com connect.facebook.net d.impactradius-event.com edge.fullstory.com googleads.g.doubleclick.net js.intercomcdn.com js.stripe.com maps.googleapis.com pnapi.invoca.net s.pinimg.com shop.pe *.shop.pe solutions.invocacdn.com static.ads-twitter.com *.taboola.com widget.intercom.io www.clarity.ms www.google-analytics.com www.googleadservices.com www.googletagmanager.com *.zdassets.com; style-src ; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' a.omappapi.com fonts.googleapis.com origin.xtlo.net; worker-src ; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' matomo.siinergy.net themes.googleusercontent.com *.typekit.net www.googletagmanager.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net tagmanager.google.com www.google.com linkedin.com px.ads.linkedin.com snap.licdn.com https://api.mapbox.com https://api.tiles.mapbox.com https://cdnjs.cloudflare.com https://js.hsforms.net; worker-src blob:; report-uri https://sii-group.com/fr-FR/report-uri/reportOnly 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.intercomcdn.com https://widget.intercom.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://api-iam.intercom.io wss://nexus-websocket-a.intercom.io; frame-src 'self' https://www.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; report-uri https://rootbg.report-uri.com/r/d/csp/reportOnly 1 default-src 'self'; font-src *;img-src * data:; script-src *; style-src * 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cdn.bladeville.pl cdn.bladeville.com *.facebook.com *.facebook.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * apm.przelewy24.pl secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com static.payu.com cdn.bladeville.pl cdn.bladeville.com bladeville.dev.aur.ac bladevilleen.dev.aur.ac *.facebook.com *.facebook.net blob: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl secure.payu.com secure.snd.payu.com cdn.bladeville.pl cdn.bladeville.com bladeville.dev.aur.ac bladevilleen.dev.aur.ac *.facebook.com *.facebook.net https://furgonetka.pl *.jsdelivr.net api.mapbox.com https://unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com cdn.bladeville.pl cdn.bladeville.com bladeville.dev.aur.ac bladevilleen.dev.aur.ac *.facebook.com *.facebook.net api.mapbox.com *.jsdelivr.net https://unpkg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com secure.payu.com merch-prod.snd.payu.com cdn.bladeville.pl cdn.bladeville.com bladeville.dev.aur.ac bladevilleen.dev.aur.ac *.facebook.com *.facebook.net *.furgonetka.pl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com *.sooqr.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://z.moatads.com https://cdn.jsdelivr.net *.avada.io *.sooqr.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.sooqr.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://www.googletagmanager.com https://teamease.app https://assets.elementor.com https://lh3.googleusercontent.com https://storage.googleapis.com https://teamease.eu https://really-simple-ssl.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.iubenda.com https://www.googletagmanager.com https://cs.iubenda.com https://cdnjs.cloudflare.com https://www.iubenda.com data: https://www.gstatic.com blob: https://www.google.com https://beacon-v2.helpscout.net https://teamease.eu https://cdn.jsdelivr.net 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://cdn.iubenda.com https://www.googletagmanager.com https://cs.iubenda.com https://cdnjs.cloudflare.com https://www.iubenda.com data: https://www.gstatic.com blob: https://www.google.com https://beacon-v2.helpscout.net https://teamease.eu https://cdn.jsdelivr.net ; style-src 'self' 'unsafe-inline' https://use.fontawesome.com https://fonts.googleapis.com https://www.iubenda.com https://www.gstatic.com https://teamease.eu ; style-src-elem 'self' 'unsafe-inline' https://use.fontawesome.com https://fonts.googleapis.com https://www.iubenda.com https://www.gstatic.com https://teamease.eu ; font-src 'self' https://use.fontawesome.com https://teamease.app https://fonts.gstatic.com https://teamease.eu data:; frame-src 'self' https://cdn.iubenda.com https://www.iubenda.com https://www.google.com https://www.youtube.com https://kanerika.com https://www.sugarandsoul.co blob:; connect-src 'self' https://yoast.com https://idb.iubenda.com https://region1.google-analytics.com https://cpl.iubenda.com https://www.google-analytics.com https://d3hb14vkzrxvla.cloudfront.net https://www.google.com https://teamease.eu; media-src 'self' https://teamease.app https://teamease.eu; worker-src 'self' blob:; report-uri https://teamease.eu/wp-json/really-simple-security/v1/csp?rsssl_apitoken=295984221; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com landofcoder.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googleadservices.com/ https://marketingplatform.google.com/ https://www.gstatic.com/ *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' https://engine.styla.com https://fast.fonts.net https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://delivery-assets.squarelovin.com https://fonts.googleapis.com https://cdn.parcellab.com https://www.gstatic.com; connect-src 'self' https://*.windsor.de https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.kameleoon.io https://*.kameleoon.eu https://blackbit-styla.s3.eu-central-1.amazonaws.com https://*.styla.com https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://tracking-api.squarelovin.com https://www.paypal.com https://*.adyen.com https://*.clarity.ms https://ad.doubleclick.net https://*.bing.com https://*.bing.net https://ct.pinterest.com https://px.ads.linkedin.com https://ib.adnxs.com/pixie/up https://www.facebook.com https://connect.facebook.net https://*.hotjar.io wss://ws.hotjar.com https://analytics.tiktok.com https://google.com https://*.google.com https://*.analytics.google.com https://*.googleapis.com https://api.parcellab.com https://bt.fraud0.com https://recommender.scarabresearch.com https://in.hotjar.com; base-uri 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; object-src 'none'; worker-src 'self' https://windsor.de https://*.windsor.de blob:; frame-src 'self' https://windsor.de https://*.windsor.de https://app.usercentrics.eu https://web.cmp.usercentrics.eu https://player.vimeo.com https://www.google.com https://td.doubleclick.net https://*.fls.doubleclick.net https://pay.google.com https://www.paypal.com https://*.adyen.com https://*.global-e.com https://www.facebook.com https://bat.bing.com; media-src 'self' https://windsor.de https://*.windsor.de data: https://styla-prod-us.imgix.net https://cdn.kameleoon.com https://cdn-vid.squarelovin.com; frame-ancestors 'self' https://windsor.de https://*.windsor.de; img-src 'self' https://windsor.de https://*.windsor.de blob: data: https://www.googletagmanager.com https://*.analytics.google.com https://*.google.com https://www.google.ch https://www.google.de https://www.google.fr https://www.google.at https://www.google.pt https://www.google.hu https://www.google.it https://www.google.ee https://www.google.pl https://www.google.lt https://www.google.hr https://www.google.co.uk https://www.google.nl https://www.google.be https://stats.g.doubleclick.net https://www.googleadservices.com https://*.usercentrics.eu https://*.service.usercentrics.eu https://*.api.service.cmp.usercentrics.eu https://styla-prod-us.imgix.net https://s3.global-e.com https://squarelovin-main-app.s3.eu-central-1.amazonaws.com https://cdn.squarelovin.com https://cdn-vid.squarelovin.com https://*.adyen.com https://*.cdn.adyen.com https://*.clarity.ms https://*.hotjar.com https://www.paypalobjects.com https://icons.parcellab.com https://www.gstatic.com https://fast.fonts.net https://*.bing.com https://*.bing.net https://ad.doubleclick.net https://googleads.g.doubleclick.net https://*.google-analytics.com https://*.vimeocdn.com https://www.facebook.com https://ib.adnxs.com https://px.ads.linkedin.com https://secure.adnxs.com https://lantern.roeye.com https://static.kameleoon.com https://icons.parcellab.com https://bt.fraud0.com https://analytics.tiktok.com https://*.ads.linkedin.com; default-src 'self' https://windsor.de https://*.windsor.de; font-src 'self' data: https://blackbit-styla-demo.s3.eu-central-1.amazonaws.com https://fast.fonts.net https://fonts.gstatic.com https://s3.global-e.com https://script.hotjar.com https://assets.faircado.com; report-uri https://windsor.de/csp/report; report-to csp-endpoint; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.de https://*.etracker.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com cdn.privacy-mgmt.com consent.bauer-plus.de 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com www.bauer-plus.de stats.g.doubleclick.net https://*.etracker.de https://*.google.de *.captcha.eu *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com useruploads.vwo.io chart.googleapis.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com int.bauer-plus.de *.facebook.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.etracker.de https://*.etracker.com www.dwin1.com cdn.privacy-mgmt.com consent.bauer-plus.de i.ytimg.com *.gstatic.com/recaptcha *.captcha.eu jquery.sellxed.com *.avada.io static.zdassets.com static.zdassets.com/ekr/snippet.js static.zdassets.com/web_widget/classic/latest/web-widget-main-4a143a0.js static.zdassets.com/web_widget/classic/latest/web-widget-locales/classic/de-de-json-4a143a0.js static.zdassets.com/web_widget/classic/latest/web-widget-chat-sdk-4a143a0.js *.visualwebsiteoptimizer.com app.vwo.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io www.google.com bid.g.doubleclick.net cdn.pushcrew.com useruploads.vwo.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com chimpstatic.com *.list-manage.com app.letsconnect.at/embed.js connect.facebook.net https://www.captcha.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com wss://widget-mediator.zopim.com cdn.privacy-mgmt.com stats.g.doubleclick.net *.visualwebsiteoptimizer.com app.vwo.com *.vimeo.com ekr.zdassets.com con-dermedienvertrieb.zendesk.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net cdn.pushcrew.com useruploads.vwo.io chart.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.captcha.eu www.sandbox.paypal.com pilot-payflowlink.paypal.com https://w19.captcha.at https://at.captcha.at https://get.geojs.i https://*.etracker.de https://*.etracker.com https://*.google-analytics.com consent.bauer-plus.de europe-west1-pathadvice-app.cloudfunctions.net pagead2.googlesyndication.com *.facebook.com https://www.captcha.eu https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.bauer-plus.de/general/csp/; report-to report-endpoint; 1 default-src 'none'; form-action 'Self' https://*.macmap.org https://export.highcharts.com https://mas-admintools.intracen.org; child-src 'Self' https://*.intracen.org https://platform.twitter.com https://syndication.twitter.com https://www.youtube.com https://div.show; frame-src 'Self' https://www.youtube.com https://*.intracen.org https://www.youtube.com https://platform.twitter.com https://syndication.twitter.com http://auth.iws-hybrid.trendmicro.com https://auth.iws-hybrid.trendmicro.com https://auth.vemic.com https://block.opendns.com https://blocked.syd-1.linewize.net https://gateway.id.swg.umbrella.com https://gateway.zscaler.net https://gateway.zscalertwo.net https://gateway.zscloud.net https://notify.bluecoat.com https://pwm-image.trendmicro.com https://safe.menlosecurity.com https://www.securly.com https://web-notification.capgemini.com; frame-ancestors 'Self' https://*.macmap.org https://www.trade.gov.in https://www.macmap.org; img-src 'Self' data: blob: https://www.googletagmanager.com https://fonts.gstatic.com https://translate.google.com https://cdn.honey.io:443 https://pos.baidu.com https://www.gstatic.com https://www.macmap.org https://yastatic.net https://cdn.shopimgs.com https://yastatic.net https://macmap.org; style-src 'Self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; style-src-attr 'Self' 'report-sample' 'unsafe-inline'; style-src-elem 'Self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://*.kaspersky-labs.com https://www.gstatic.com https://cdn.honey.io:443 https://fonts.googleapis.com https://pwm-image.trendmicro.com https://www.gstatic.com https://www.gstatic.com:443 https://www.l-sou.com https://www.macmap.org; script-src 'Self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://maxcdn.bootstrapcdn.com https://code.jquery.com https://platform.twitter.com https://www.googletagmanager.com https://*.macmap.org https://code.jquery.com; script-src-attr 'Self' 'unsafe-inline'; script-src-elem 'Self' 'report-sample' 'unsafe-inline' blob: https://www.googletagmanager.com https://platform.twitter.com https://code.jquery.com https://maxcdn.bootstrapcdn.com https://ajax.googleapis.com https://ajax.googleapis.com:443 https://cdn.bootcdn.net https://code.jquery.com https://connect.facebook.net:443 https://ff.kis.v2.scr.kaspersky-labs.com https://gc.kis.v2.scr.kaspersky-labs.com https://infird.com https://me.kis.v2.scr.kaspersky-labs.com https://platform.twitter.com https://translate.google.com https://translate.googleapis.com https://www.googletagmanager.com https://www.l-sou.com https://www.macmap.org; connect-src 'Self' blob: data: https://region1.google-analytics.com https://www.google-analytics.com https://api.adsfight.com https://cdn.shopimgs.com https://fonts.googleapis.com https://fonts.googleapis.com:443 https://fonts.gstatic.com https://fonts.gstatic.com:443 https://gateway.oyealva.com https://infragrid.v.network https://local.adblock360.com https://l-sou.com https://overbridgenet.com https://polyfilljs.org https://translate.googleapis.com https://translate.googleapis.com:443 https://translate-pa.googleapis.com https://translate-pa.googleapis.com:443 https://www.google-analytics.com https://www.googletagmanager.com https://www.macmap.org https://overbridgenet.com https://www.google-analytics.com https://cdn.shopimgs.com; font-src 'Self' data: https://fonts.gstatic.com https://account.affilitizer.com https://at.alicdn.com https://cdn.fastdic.com https://cdn.jsdelivr.net https://cdn.megabonus.com https://cdn.scite.ai https://cdn-uicons.flaticon.com https://migaku-public-data.migaku.com https://r2cdn.perplexity.ai https://use.typekit.net; media-src blob: data: https://ssl.gstatic.com; worker-src blob:; manifest-src 'Self' https://www.macmap.org; object-src 'Self' https://www.macmap.org; report-uri https://fawedsitereporting.azurewebsites.net/api/csp-report?; report-to default 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' kontur.ru *.kontur.ru *.kontur.host *.skbkontur.ru data: https://mc.yandex.ru https://mc.yandex.az https://mc.yandex.by https://mc.yandex.co.il https://mc.yandex.com https://mc.yandex.com.am https://mc.yandex.com.ge https://mc.yandex.com.tr https://mc.yandex.ee https://mc.yandex.fr https://mc.yandex.kg https://mc.yandex.kz https://mc.yandex.lt https://mc.yandex.lv https://mc.yandex.md https://mc.yandex.tj https://mc.yandex.tm https://mc.yandex.ua https://mc.yandex.uz https://mc.webvisor.com https://mc.webvisor.org https://yastatic.net https://www.googletagmanager.com https://fonts.googleapis.com https://ssl.gstatic.com https://www.gstatic.com https://tagmanager.google.com *.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net; connect-src 'self' kontur.ru *.kontur.ru *.kontur.host *.skbkontur.ru wss://*.kontur.ru https://mc.yandex.ru https://mc.yandex.az https://mc.yandex.by https://mc.yandex.co.il https://mc.yandex.com https://mc.yandex.com.am https://mc.yandex.com.ge https://mc.yandex.com.tr https://mc.yandex.ee https://mc.yandex.fr https://mc.yandex.kg https://mc.yandex.kz https://mc.yandex.lt https://mc.yandex.lv https://mc.yandex.md https://mc.yandex.tj https://mc.yandex.tm https://mc.yandex.ua https://mc.yandex.uz https://mc.webvisor.com https://mc.webvisor.org https://yastatic.net *.google-analytics.com *.analytics.google.com https://analytics.google.com https://www.google-analytics.com; report-uri https://frontreport-relay.kontur.host/csp/ 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-sHb8rZrfskk-ZrQakHqMzPw6vcs2qAcH'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-d9dmCHauRvVeQydnA8P1jTgjUjVTv1L6'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.lampadadiretta.it data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.lampadadiretta.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.lampadadiretta.it 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b428c232-f415-4fb2-b456-fef23ba335ec.sansec.watch/; report-to report-endpoint; 1 default-src 'self' litium.revolutionrace.pl fbcdn.revolutionrace.pl wss://fbcdn.revolutionrace.pl *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.pl *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.userway.org api.userway.org 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com cdn.userway.org api.userway.org cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com cdn.userway.org api.userway.org player.vimeo.com cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.userway.org api.userway.org cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn.userway.org api.userway.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com cdn.userway.org api.userway.org cdn.jsdelivr.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self'; report-to csp-endpoint; 1 default-src 'self' https://eraluvat.fi https://www.eraluvat.fi https://*.eraluvat.fi; script-src 'nonce-574pfMNz3SDxNQuq+MI8pWxOLv1Yd2vW' 'unsafe-eval' 'strict-dynamic' https: http: 'self' blob: https://*.askem.com https://*.cookiebot.com https://*.snoobi.eu; style-src 'self' 'unsafe-inline' https://*.gstatic.com; img-src 'self' data: blob: https://*.amazonaws.com https://*.paytrail.com https://*.cookiebot.com https://*.google.com https://*.gstatic.com; font-src 'self' data:; frame-src 'self' https://*.youtube.com https://*.retkikartta.fi https://retkikartta.fi https://*.cookiebot.com https://*.powerappsportals.com https://*.cloudflare.com https://*.powerbi.com; connect-src https://*.eraluvat.fi https://eraluvat.fi https://www.eraluvat.fi https://*.production.elegantelmbranch.com 'self' https://*.sentry.io https://*.askem.com https://*.nsvcs.net https://*.cookiebot.com; object-src 'none'; base-uri 'self'; form-action 'self' https://*.eraluvat.fi https://*.nordea.fi https://*.danskebank.fi https://*.paytrail.com https://*.paymenthighway.com; report-uri https://o4508380741828608.ingest.de.sentry.io/api/4508381875798096/security/?sentry_key=36be02ca7164eaa9aabe5db910c6c7e1&sentry_environment=production 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://flex.cybersource.com https://testflex.cybersource.com https://unpkg.com https://vjs.zencdn.net; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://unpkg.com https://vjs.zencdn.net; style-src-attr 'self'; frame-ancestors 'self' 1 connect-src https://cdp.customer.io https://firebase.googleapis.com https://consumer.cloud.gist.build https://realtime.cloud.gist.build wss://nexus-websocket-a.intercom.io https://px.ads.linkedin.com; default-src 'self'; font-src https://fonts.gstatic.com; frame-ancestors 'none'; img-src https://www.google.co.il/ads/ga-audiences https://px.ads.linkedin.com; object-src 'none'; script-src https://cdp.customer.io/v1/analytics-js/inAppPlugin.js https://cdp.customer.io/v1/analytics-js/ajs-destination.js https://cdp.customer.io/v1/analytics-js/646.js https://cdp.customer.io/v1/analytics-js/snippet/5295770effba49705388/analytics.min.js https://cdp.customer.io/v1/analytics-js/snipp; style-src https://fonts.googleapis.com/css; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=PCWiWYhgHAs06uguxK859_InBM5M5p_zxnCvsOW8py4-1765933249-1.0.1.1-ah0b3wWa0ZTLxuAtVyKWVzpLm9GsmiMLw6XpSdYppBF.lql5ANV1xyPlTyBUHl1APs3Wi_i1gw9Ehp_jisE.7TEPHQqsLp0xWB7CjYzl0YOEolLRd835YukE426jk9iapdSxMdil_oOdjBQTBGsRwLgjjbHR1O1p_IpIFRhtws47aFebJlxLaJIqo1ZcXi3bKsGR3TMaTFoDeQwnGIIDiQ; report-to cf-xjsyiycpeojupbag 1 object-src 'none'; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com https://www.googleadservices.com https://www.googleoptimize.com https://www.google-analytics.com https://cookie-cdn.cookiepro.com https://munchkin.marketo.net https://script.crazyegg.com https://snap.licdn.com https://static.addtoany.com; script-src-attr 'self'; script-src-elem 'self' https://www.googletagmanager.com https://www.googleadservices.com https://www.googleoptimize.com https://www.google-analytics.com https://cookie-cdn.cookiepro.com https://munchkin.marketo.net https://view.ceros.com https://player.vimeo.com https://script.crazyegg.com https://snap.licdn.com 'sha256-3/mNUpqF9X/gMYE+bOG6g8d6I32wdYdWwWuAk90mPCM=' 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' https://m.addthis.com https://z.moatads.com https://v1.addthisedge.com https://bam.nr-data.net https://js-agent.newrelic.com 'sha256-De2mpaFLR0YDSf4Kwof2qARuqqxurfOvrVuX1nl4SGc=' https://static.addtoany.com; style-src 'self' 'unsafe-inline' https://app-lon05.marketo.com https://cookie-cdn.cookiepro.com https://www.googletagmanager.com https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; worker-src 'self' blob:; frame-ancestors 'self' 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.eu https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-ekTZAsyqhCQ_SxUbWivLUg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-1xZGEcxUUsojoaytXYyP6w' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-mt1uxiMBJNaD3HJ_3sbOEg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' 'unsafe-inline'; font-src 'self' *.cloudflare.com *.gstatic.com *.isecurenet.in; frame-src 'self' *.google.com; img-src 'self' *.isecurenet.in; script-src-elem 'self' *.isecurenet.in; style-src-attr 'self' 'unsafe-inline' *.cloudflare.com *.googleapis.com *.isecurenet.in; report-uri https://csp.isecurenet.in/_csp 1 frame-src 'self' www.google.com www.youtube.com js.stripe.com widget.userlist.com; style-src 'self' ajax.googleapis.com fonts.googleapis.com *.gstatic.com js.stripe.com 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com client.crisp.chat editor.unlayer.com; img-src * data:; script-src 'self' ajax.googleapis.com *.googleanalytics.com *.googletagmanager.com storage.googleapis.com *.google-analytics.com *.segment.com *.smartlook.com *.stripe.com *.stripe.com 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net cdnjs.cloudflare.com unpkg.com *.posthog.com *.google.com *.googleapis.com *.gstatic.com client.crisp.chat editor.unlayer.com js.userlist.com sentry.spotipo.dev browser.sentry-cdn.com js.hs-scripts.com js.hs-banner.com js.hscollectedforms.net; font-src 'self' themes.googleusercontent.com *.gstatic.com client.crisp.chat; report-uri https://app.spotipo.com/csp_report/ 1 default-src 'self'; script-src 'self' https://stock.limz.com/ https://limz.org 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://stock.limz.com/ https://limz.org 'unsafe-inline'; img-src 'self' https://stock.limz.com/ https://limz.org data: blob:; font-src 'self' https://stock.limz.com/ https://limz.org data:; frame-src 'self' https://stock.limz.com/ https://limz.org ; connect-src 'self' https://stock.limz.com/ https://limz.org wss:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; object-src 'none'; report-uri /en/limz-core-cspReport 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googleapis.com *.google-analytics.com *.googletagmanager.com *.salesforceliveagent.com *.pendo.io; object-src 'none'; style-src 'self' 'unsafe-inline' *.googleapis.com; img-src 'self' *.google.com *.google.nl *.pendo.io *.googletagmanager.com; connect-src 'self' *.google-analytics.com *.doubleclick.net; font-src 'self' *.gstatic.com 1 font-src *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.awin1.com *.zenaps.com *.doubleclick.net *.googletagmanager.com *.google.co.uk account.fetchify.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.awin1.com *.zenaps.com *.wepowerconnections.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com 'self' data: *.google.co.uk *.bing.com https://firebasestorage.googleapis.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.bing.com *.civiccomputing.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://chimpstatic.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com cc-cdn.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.google.com *.civiccomputing.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://portal.envisagedigital.co.uk/api/website/gvvx36u0tq/report-uri; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.affirm.com *.affirm.ca *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.affirm.com *.affirm.ca *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.bing.com maps.gstatic.com guarantee-cdn.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com apis.google.com *.affirm.com *.affirm.ca *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.ruggedmade.com *.googleapis.com maps.googleapis.com *.cloudflare.com guarantee-cdn.com https://www.googletagmanager.com tagmanager.google.com unpkg.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://static.klaviyo.com assets.braintreegateway.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.affirm.com *.affirm.ca *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com analytics.google.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; connect-src 'self' https://adservice.google.com https://www.google.com https://*.doubleclick.net https://www.google-analytics.com https://*.appcues.com https://*.appcues.net wss://*.appcues.net wss://*.appcues.com statsnzprod.azure-api.net https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://www.google.co.nz https://www.google.com.au https://www.google.com.vn https://export.highcharts.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.livechatinc.com https://app.optimalworkshop.com performance.typekit.net; default-src 'self'; form-action 'self' https://export.highcharts.com govt.us9.list-manage.com; img-src 'self' https: https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com *.ytimg.com https://*.appcues.com https://*.appcues.net res.cloudinary.com cdn.jsdelivr.net https://*.googletagmanager.com https://*.google-analytics.com *.hotjar.com *.hotjar.io *.livechatinc.com shielded.co.nz staticcdn.co.nz p.typekit.net; media-src 'self' *.livechatinc.com; object-src 'self' *.livechatinc.com; font-src 'self' https://fonts.gstatic.com data: use.fontawesome.com *.hotjar.com *.hotjar.io staticcdn.co.nz data://* use.typekit.net; upgrade-insecure-requests; frame-src https://*.doubleclick.net https://stats.g.doubleclick.net https://www.googletagmanager.com https://bid.g.doubleclick.net player.vimeo.com *.youtube.com 'self' https://*.appcues.com *.hotjar.com *.hotjar.io *.livechatinc.com staticcdn.co.nz helpline.homecaremedical.co.nz *.office.com *.shinyapps.io statsnz.maps.arcgis.com statsmaps.cloud.eaglegis.co.nz; script-src https://www.googletagmanager.com 'unsafe-eval' https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net player.vimeo.com www.youtube.com s.ytimg.com 'self' https://*.appcues.com https://*.appcues.net https://*.googletagmanager.com *.hotjar.com *.hotjar.io 'unsafe-inline' *.livechatinc.com s3.amazonaws.com staticcdn.co.nz helpline.homecaremedical.co.nz use.typekit.net cdnjs.cloudflare.com; style-src https://tagmanager.google.com https://fonts.googleapis.com 'self' https://*.appcues.com https://*.appcues.net https://fonts.google.com 'unsafe-inline' stackpath.bootstrapcdn.com use.fontawesome.com *.livechatinc.com cdn-images.mailchimp.com use.typekit.net; child-src player.vimeo.com 'self' *.livechatinc.com; script-src-elem https://*.googletagmanager.com https://*.google-analytics.com *.hotjar.com *.hotjar.io 'self' 'unsafe-inline' 'unsafe-eval' *.livechatinc.com staticcdn.co.nz helpline.homecaremedical.co.nz use.typekit.net cdnjs.cloudflare.com; manifest-src 'self'; report-uri https://report-to-api.raygun.com/reports-csp?apikey=fUCNIUtmo6N5JyZrZmL9g 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' https://bat.bing.com https://www.google-analytics.com https://www.googletagmanager.com https://*.healthroundprince.com https://cdn.privacy-mgmt.com https://cdn.ablyft.com https://static.cloudflareinsights.com https://connect.facebook.net https://service.force.com https://googleads.g.doubleclick.net https://d.la1-core1.sfdc-yzvdd4.salesforceliveagent.com; frame-ancestors 'none'; report-uri https://oapi.oskar.de/api/v3/tenant/1/language/1/shared/log/csp-violation; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.twitter.com https://*.fbcdn.net https://*.google.com https://*.ingenious.ai https://*.googleapis.com https://*.facebook.net https://siteimproveanalytics.com https://js.createsend1.com https://www.googletagmanager.com https://fburl.com https://theta360.com https://ecommunications.wyndham.vic.gov.au https://www.createsend.com https://soundcloud.com https://wyndham.vudoo.io https://*.eventbrite.com.au https://cdn.jsdelivr.net https://unpkg.com https://*.ingest.sentry.io https://*.buzzsprout.com https://www.gstatic.com https://api.smooch.io https://www.pagespeed-mod.com https://*.google-analytics.com https://*.cloudflare.com https://conoret.com https://*.hotjar.com ; object-src 'self'; style-src 'self' 'unsafe-inline' blob: https://*.fbcdn.net https://*.ingenious.ai https://*.googleapis.com https://www.gstatic.com tagmanager.google.com https://theta360.com https://ecommunications.wyndham.vic.gov.au https://www.createsend.com https://soundcloud.com https://wyndham.vudoo.io https://*.eventbrite.com.au https://cdn.jsdelivr.net https://unpkg.com https://*.ingest.sentry.io https://*.buzzsprout.com https://*.cloudflare.com https://*.opoint.no https://*.trendmicro.com; img-src 'self' 'unsafe-inline' data: blob: https://*.ingenious.ai https://*.fbcdn.net *.google-analytics.com https://*.twimg.com https://*.gstatic.com https://*.siteimproveanalytics.io https://*.twitter.com https://*.eventbrite.com.au https://cdn.jsdelivr.net https://unpkg.com https://*.ingest.sentry.io https://*.buzzsprout.com https://*.googletagmanager.com https://*.google.com https://*.ytimg.com https://theta360.com https://*.cloudfront.net https://*.googleapis.com https://digital.wyndham.vic.gov.au https://*.smooch.io https://*.facebook.com https://*.g.doubleclick.net https://*.google.com.au; media-src 'self' data: https://web-messenger-v5.ingenious.ai https://*.gstatic.com; frame-src 'self' data: https://youtu.be https://www.youtube.com *.google.com https://*.twitter.com https://js.createsend1.com https://w.soundcloud.com https://wyndham.vudoo.io https://*.eventbrite.com.au https://cdn.jsdelivr.net https://unpkg.com https://*.buzzsprout.com https://wyndham.civicclerk.com.au https://*.facebook.com https://block.localnetwork.zone https://theta360.com https://*.wyndham.vic.gov.au https://*.zscalertwo.net https://*.trendmicro.com https://*.vimeo.com https://*.zscloud.net https://td.doubleclick.net https://au.api.ingenious.ai https://cloud.enrolnow.com.au ; frame-ancestors 'self'; child-src 'self' https://youtu.be https://www.youtube.com; font-src 'self' data: https://fonts.gstatic.com https://web-messenger-v5.ingenious.ai https://at.alicdn.com https://shopping.qantas.com https://cdn.jsdelivr.net https://script.hotjar.com; connect-src 'self' data: https://*.googleapis.com https://web-messenger-v5.ingenious.ai *.smooch.io https://*.google-analytics.com wss://api.smooch.io https://createsend.com https://*.doubleclick.net https://*.facebook.com https://*.google.com https://*.global-cache.online https://*.ytlogs.ru https://meetlookup.com https://zone1-services-cdn.com https://*.cdn77.org https://ecmacore.com https://zone1-services-cdn.com https://*.hotjar.io wss://ws.hotjar.com https://*.google.com.au https://fonts.gstatic.com https://connect.facebook.net https://www.google.com.bn https://www.google.com.np https://c.ba.contentsquare.net https://web-messenger-v5.ingenious.ai https://www.googletagmanager.com https://stats.g.doubleclick.net https://widget-config.au.ingenious.ai; report-uri /report-csp-violation; upgrade-insecure-requests 1 base-uri 'self'; child-src 'self' https://www.google.com https://consentcdn.cookiebot.com; connect-src 'self' https://maps.googleapis.com https://consentcdn.cookiebot.com https://region1.google-analytics.com; font-src 'self' data: blob: ; form-action 'self'; frame-ancestors 'self'; frame-src https://www.google.com https://consentcdn.cookiebot.com; img-src 'self' data: https://maps.googleapis.com https://s3.eu-west-1.amazonaws.com https://log.pinterest.com https://imgsct.cookiebot.com https://www.googletagmanager.com; media-src 'self'; object-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google.com https://maps.googleapis.com https://assets.pinterest.com https://www.gstatic.com https://consent.cookiebot.com https://www.google-analytics.com https://consentcdn.cookiebot.com https://js.createsend1.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; style-src-attr 'unsafe-inline'; worker-src 'self'; report-uri https://csp.tools.acato.nl/api/v1/report 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.facebook.com https://track.hubspot.com https://c.clarity.ms https://c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.hotjar.com https://d10lpsik1i8c69.cloudfront.net https://js.hs-scripts.com https://www.clarity.ms https://js.hs-analytics.net https://js.hs-banner.com https://settings.luckyorange.net https://connect.facebook.net https://scripts.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://settings.luckyorange.net https://j.clarity.ms https://js.hs-banner.com https://a.clarity.ms https://www.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.e-worksmedia.com data:; connect-src 'self' *.e-worksmedia.com http://*.twitter.com https://*.twitter.com; font-src 'self' *.e-worksmedia.com http://*.gstatic.com https://*.gstatic.com http://*.googleapis.com https://*.googleapis.com data:; child-src 'self' *.e-worksmedia.com http://*.facebook.com https://*.facebook.com http://*.twitter.com https://*.twitter.com http://*.google.com https://*.google.com http://*.pinterest.com https://*.pinterest.com javascript:; frame-src 'self' *.e-worksmedia.com http://*.facebook.com https://*.facebook.com http://*.twitter.com https://*.twitter.com http://*.google.com https://*.google.com http://*.pinterest.com https://*.pinterest.com javascript:; img-src 'self' *.e-worksmedia.com https://*.doubleclick.net http://*.pinterest.com https://*.pinterest.com http://*.pinimg.com https://*.pinimg.com https://*.twitter.com https://*.facebook.com http://*.gstatic.com https://*.pinimg.com http://*.googleapis.com https://*.googleapis.com http://*.google-analytics.com https://*.google-analytics.com data:; media-src 'self' *.e-worksmedia.com; object-src 'self' *.e-worksmedia.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'nonce-3895f36fa3acd7437bd980e0ebc37b78626f44a6' 'nonce-62636e112f349cebf666fa585b453a45749f8829' 'nonce-8cf848db8c63b78fca87a182aa49e6e03e02deef' *.e-worksmedia.com data: https://*.braintreegateway.com http://*.github.com https://*.github.com http://*.google-analytics.com https://*.google-analytics.com https://*.doubleclick.net http://*.facebook.com https://*.facebook.com http://*.facebook.net https://*.facebook.net http://*.twitter.com https://*.twitter.com http://*.google.com https://*.google.com http://*.gstatic.com https://*.gstatic.com http://*.googleapis.com https://*.googleapis.com http://*.pinterest.com https://*.pinterest.com; style-src 'unsafe-inline' 'self' *.e-worksmedia.com http://*.gstatic.com https://*.gstatic.com http://*.googleapis.com https://*.googleapis.com; report-uri /csp 1 style-src-elem https://*.mindbox.ru *.yclients.com *.googleapis.com 'unsafe-inline' 'self'; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.salonsecret.ru/ https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://*.salonsecret.ru/ https://*.matrix.ru https://matrix.ru 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.salonsecret.ru/ https://kerastaseru.push.world https://*.google.com https://*.doubleclick.net/ https://*.googletagmanager.com https://www.facebook.com/ *.doubleclick.net/ https://helpdeskeddy.loreal.com.ru https://loreal.helpdeskeddy.com https://beautyid.pro https://*.weborama.fr https://e-academie.ru https://vk.com https://ru.spotscan.com https://loreal-webconsultation.modiface.com https://*.criteo.com https://*.criteo.net https://*.yclients.com https://*.yandex.ru/ https://*.yandex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.salonsecret.ru/ https://wf-ru-frontend.weborama-tech.ru https://wcm.weborama-tech.ru https://cstatic-ru-cv.weborama-tech.ru https://vk.com https://api-maps.yandex.ru https://www.google.com https://www.google.ru https://www.google.by https://cdn.retailrocket.net w1.yclients.com https://*.maps.yandex.net http://ad.doubleclick.net https://adservice.google.com https://www.facebook.com https://*.mail.ru https://*.flocktory.com https://*.mindbox.ru https://*.leadplan.ru/ https://adservice.google.ru/ https://storage.cloud.croc.ru/ https://*.yandex.ru/ https://*.yandex.com *.doubleclick.net/ https://*.weborama.fr www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com http://www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.salonsecret.ru/ https://cstatic.weborama-tech.ru https://cstatic.weborama.fr https://vk.com https://api-maps.yandex.ru https://yastatic.net http://cdn.retailrocket.ru https://www.google.com https://www.gstatic.com https://www.artfut.com https://cstatic-ru-cv.weborama-tech.ru http://*.yandex.ru https://*.facebook.net https://*.mindbox.ru https://loreal-luxe-services.directcrm.ru https://aprtx.com https://aprtn.com https://*.mail.ru https://*.lenmit.com https://top-fwz1.mail.ru http://*.lenmit.com https://*.flocktory.com https://kerastaseru.push.world https://cdn.leadplan.ru/ https://cdn.helpdeskeddy.com https://*.weborama.fr https://*.nr-data.net https://www.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.salonsecret.ru/ https://fonts.googleapis.com https://cdn.retailrocket.net https://w1.yclients.com https://*.mindbox.ru assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://analytics.google.com/ www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.salonsecret.ru/ https://mc.yandex.md https://tracking.retailrocket.net https://cdn.retailrocket.net https://api.retailrocket.net https://stats.g.doubleclick.net https://google-analytics.com https://geocode-maps.yandex.ru https://e-academie.ru https://mc.yandex.ru https://*.mindbox.ru https://*.mail.ru https://aprtx.com https://app.leadplan.ru/ https://www.google-analytics.com https://*.analytics.google.com/ https://*.nr-data.net https://suggestions.dadata.ru https://*.yandex.ru https://*.yandex.com *.doubleclick.net/ https://*.weborama.fr api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.matrix.ru/csp/collect; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-bDowFgVd2IupV6oy6DCamg=='; report-uri https://send.hsbrowserreports.com/csp/report 1 script-src 'self' https://www.paypal.com/sdk/js 1 default-src 'self'; script-src 'self'; img-src 'self' 1 font-src *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://app2.salesmanago.com 'self' www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.glami.pl *.pixel.wp.pl *.imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.googletagmanager.com *.opineo.pl *.consent.cookiebot.com *.consentcdn.cookiebot.com www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://*.ingest.sentry.io *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.vc-service.saleago.com ws: *.consent.cookiebot.com *.consentcdn.cookiebot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.klaviyo.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.iubenda.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.google.it *.exacttarget.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.iubenda.com s7.addthis.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com cdn.evgnet.com *.clerk.io *.vimeo.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.fontawesome.com *.google.com unsafe-inline https://fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.iubenda.com ekr.zdassets.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com pagead2.googlesyndication.com vimeo.com *.vimeo.com *.evergage.com *.googleapis.com *.google.com *.doubleclick.net *.klaviyo.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com *.cloudflare.com *.twitter.com *.x.com *.google.com *.google.co.in *.facebook.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.bootstrapcdn.com data: *.tawk.to maxcdn.bootstrapcdn.com *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net fonts.googleapis.com 'self' data: https://cdnjs.cloudflare.com https://widgets.trustedshops.com *.yotpo.com *.googleapis.com *.bing.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.x.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.twitter.com *.x.com www.google.com www.google.co.in www.facebook.com *.trustpilot.com td.doubleclick.net *.g.doubleclick.net www.kiyoh.com consentcdn.cookiebot.com tagmanager.google.com *.googletagmanager.com *.multisafepay.com https://pay.google.com www.gstatic.com apis.google.com js.mollie.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com *.bing.com 'self'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.cloudflare.com static.pay.nl *.gstatic.com *.google.com *.google.nl *.google.co.in www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.x.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net *.g.doubleclick.net d.adroll.com pixel.advertising.com pixel.rubiconproject.com simage2.pubmatic.com dsum-sec.casalemedia.com ads.yahoo.com eb2.3lift.com sync.outbrain.com trc.taboola.com x.bidswitch.net/sync ib.adnxs.com idsync.rlcdn.com us-u.openx.net ups.analytics.yahoo.com segments.company-target.com sync.tidaltv.com *.pay.nl *.tawk.to tawk.link *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.bing.net *.etrusted.com *.multisafepay.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com quickchart.io img.youtube.com https://www.mollie.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com *.bing.com *.clarity.ms *.kaltura.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.cloudflare.com *.twitter.com *.x.com *.google.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.googlesyndication.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.paypal.com *.googletagmanager.com s.adroll.com d.adroll.com d.adroll.mgr.consensu.org *.bootstrapcdn.com *.trustpilot.com *.g.doubleclick.net *.tawk.to consentcdn.cookiebot.com tagmanager.google.com script.hotjar.com static.hotjar.com *.cloudfront.net cloudfront.net cdn.cookiecode.nl *.multisafepay.com https://pay.google.com *.googleapis.com *.avada.io *.shopify.com player.vimeo.com js.mollie.com https://player.vimeo.com https://www.youtube.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.yotpo.com *.clarity.ms integrations.etrusted.com bat.bing.com *.kaltura.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com downloads.mailchimp.com *.cloudflare.com *.googleapis.com *.twitter.com *.x.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.tawk.to tagmanager.google.com *.googletagmanager.com *.etrusted.com maxcdn.bootstrapcdn.com *.multisafepay.com https://fonts.bunny.net fonts.gstatic.com https://fonts.googleapis.com http://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.g.doubleclick.net *.cloudflare.com *.twitter.com *.x.com *.paypal.com *.twimg.com *.google.com *.google.co.in *.facebook.com translations.piggy.eu maps.googleapis.com *.tawk.to wss://*.tawk.to consentcdn.cookiebot.com *.analytics.google.com script.hotjar.com static.hotjar.com core.helloretail.com cdn.cookiecode.nl api.cookiecode.nl *.bing.net *.multisafepay.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src i.cdn-typekit.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.fitness-seller.nl/; report-to report-endpoint; 1 default-src https:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; img-src https: data: blob:; media-src https: data: blob:; child-src https:; font-src https: data:; connect-src https: wss:; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com js.mollie.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com *.facebook.com *.clarity.ms *.hotjar.com *.kleeneproducties.nl kleeneproducties.nl issuu.com *.issuu.com adobe.com *.pinterest.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.mollie.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.doubleclick.net *.facebook.com *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.nl *.guapatest.nl *.homecenter.nl *.kapenga.nl *.stoelenconcurrent.nl *.pinterest.com *.clarity.ms *.bing.com *.linkedin.com *.travyk.nl *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net https://ipinfo.io js.mollie.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.clickcease.com *.facebook.net *.googletagmanager.com *.googleoptimize.com *.googleanalytics.com *.google-analytics.com *.gstatic.com *.hotjar.com *.clarity.ms chimpstatic.com mylivechat.com *.mylivechat.com issuu.com *.issuu.com adobe.com ipinfo.io *.ipinfo.io *.pinimg.com *.licdn.com *.homecenter.nl *.kapenga.nl *.cloudfront.net *.pinterest.com *.travyk.nl *.googlesyndication.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net *.multisafepay.com assets.braintreegateway.com *.trustpilot.com *.google.com *.googleapis.com *.homecenter.nl *.mailchimp.com *.mylivechat.com kleeneproducties.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ekr.zdassets.com/ *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.doubleclick.net *.google-analytics.com *.homecenter.nl *.hypernode.io *.clarity.ms *.hotjar.com *.hotjar.io wss://*.hotjar.com/ *.hotjar.com/ *.pinterest.com *.googlesyndication.com *.demdex.net *.linkedin.com *.kapenga.nl *.travyk.nl *.amazonaws.com *.kleeneproducties.nl kleeneproducties.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.zohocdn.com *.cloudflare.com *.bootstrapcdn.com gtm.mintt.com mintt.com *.fs1inc.com *.sitejabber.com maxcdn.bootstrapcdn.com fonts.googleapis.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com gtm.mintt.com mintt.com *.fs1inc.com *.sitejabber.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com 512435.stats.ryzeo.com secure.livechatinc.com js.stripe.com embedsocial.com gtm.mintt.com mintt.com *.fs1inc.com *.sitejabber.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.zohocdn.com *.zohopublic.com *.disqus.com *.cloudflare.com *.googleadservices.com *.googletagmanager.com *.google.com.co *.facebook.com pop1.screenpopper.com bat.bing.com cdn.livechatinc.com googletagmanager.com d2ldlvi1yef00y.cloudfront.net d69o642psi61v.cloudfront.net gtm.mintt.com mintt.com *.fs1inc.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.sitejabber.com quickchart.io img.youtube.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.fs1inc.com *.zoho.com *.zohocdn.com *.disqus.com *.cloudflare.com *.twitter.com *.fontawesome.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.clickcease.com *.livechatinc.com *.doubleclick.net cdn.statstrk01.com bat.bing.com connect.facebook.net stats.ryzeo.com js.stripe.com embedsocial.com pop1.screenpopper.com screenpopper.com gtm.mintt.com mintt.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.sitejabber.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.zohocdn.com *.zohopublic.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com embedsocial.com screenpopper.com gtm.mintt.com mintt.com *.fs1inc.com *.sitejabber.com maxcdn.bootstrapcdn.com fonts.gstatic.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zohocdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.zohocdn.com *.zohopublic.com *.zoho.com *.cloudflare.com *.googleadservices.com *.facebook.com stats.g.doubleclick.net analytics.google.com api.livechatinc.com facebook.com gtm.mintt.com mintt.com *.fs1inc.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.sitejabber.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.acsbapp.com https://*.ads-twitter.com https://*.bing.com https://*.convertexperiments.com https://*.cookiebot.com https://*.facebook.net https://*.google.com https://*.google.co.uk https://*.google.com.au https://*.google.ca https://*.google.de https://*.google.fr https://*.google.com.ph https://*.google.co.in https://*.google.com.br https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://*.hotjar.com https://*.licdn.com https://*.openx.net https://*.simpli.fi https://*.zekelman.com https://acsbapp.com https://app-cf.bc0a.com https://cdn.amplitude.com https://cdn.amcharts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsforms.net https://js.hs-scripts.com https://js.hscollectedforms.net https://tags.srv.stackadapt.com https://*.hubspotusercontent-na1.net https://static.hsappstatic.net; script-src-elem 'self' 'unsafe-inline' https://*.acsbapp.com https://*.ads-twitter.com https://*.bing.com https://*.convertexperiments.com https://*.cookiebot.com https://*.facebook.net https://*.google.com https://*.google.co.uk https://*.google.com.au https://*.google.ca https://*.google.de https://*.google.fr https://*.google.com.ph https://*.google.co.in https://*.google.com.br https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://*.hotjar.com https://*.licdn.com https://*.openx.net https://*.simpli.fi https://*.zekelman.com https://acsbapp.com https://app-cf.bc0a.com https://cdn.amplitude.com https://cdn.amcharts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hsforms.net https://js.hs-scripts.com https://js.hscollectedforms.net https://tags.srv.stackadapt.com https://*.hubspotusercontent-na1.net https://static.hsappstatic.net; style-src 'self' 'unsafe-inline' https://*.typography.com https://*.zekelman.com https://maxcdn.bootstrapcdn.com https://tags.srv.stackadapt.com; style-src-elem 'self' 'unsafe-inline' https://*.typography.com https://*.zekelman.com https://maxcdn.bootstrapcdn.com https://tags.srv.stackadapt.com; font-src 'self' 'unsafe-inline' data: https://*.gstatic.com https://cloud.typography.com https://www.zekelman.com https://maxcdn.bootstrapcdn.com; img-src 'self' data: https://*.1rx.io https://*.3lift.com https://*.accessnewswire.com https://*.adnxs.com https://*.adnxs.net https://*.ads-twitter.com https://*.adsrvr.org https://*.agkn.com https://*.amazon-adsystem.com https://*.bfmio.com https://*.bing.com https://*.bing.net https://*.casalemedia.com https://*.cootlogix.com https://*.crwdcntrl.net https://*.doubleclick.net https://*.exelator.com https://*.eyeota.com https://*.eyeota.net https://*.facebook.com https://*.facebook.net https://*.fwmrm.net https://*.google.ca https://*.google.co.in https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.infolinks.com https://*.intentiq.com https://*.lijit.com https://*.linkedin.com https://*.lkqd.net https://*.mgid.com https://*.openx.net https://*.pgammedia.com https://*.pippio.com https://*.pro-market.net https://*.pubmatic.com https://*.rlcdn.com https://*.rubiconproject.com https://*.simpli.fi https://*.smaato.net https://*.tapad.com https://*.temu.com https://*.tremorhub.com https://*.twitter.com https://*.yahoo.com https://*.zekelman.com https://forms.hsforms.com https://imgsct.cookiebot.com https://s.w.org https://pippio.com https://secure.gravatar.com https://forms-na1.hsforms.com https://*.hsforms.com https://t.co https://tags.srv.stackadapt.com https://test-zekelmancom.pantheonsite.io https://track.hubspot.com; connect-src 'self' https://*.1rx.io https://*.3lift.com https://*.acsbapp.com https://*.adnxs.com https://*.adnxs.net https://*.ads-twitter.com https://*.adsrvr.org https://*.agkn.com https://*.amazon-adsystem.com https://*.bfmio.com https://*.bing.com https://*.bing.net https://*.casalemedia.com https://*.cootlogix.com https://*.cookiebot.com https://*.crwdcntrl.net https://*.doubleclick.net https://*.exelator.com https://*.eyeota.com https://*.eyeota.net https://*.facebook.com https://*.facebook.net https://*.fwmrm.net https://*.google.ca https://*.google.com https://*.google.co.in https://*.google.co.uk https://*.google.com.au https://*.google.de https://*.google.fr https://*.google.com.ph https://*.google.co.in https://*.google.com.br https://*.google-analytics.com https://*.googletagmanager.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.infolinks.com https://*.intentiq.com https://*.lijit.com https://*.linkedin.com https://*.lkqd.net https://*.mgid.com https://*.openx.net https://*.pgammedia.com https://*.pippio.com https://*.pro-market.net https://*.pubmatic.com https://*.rlcdn.com https://*.rubiconproject.com https://*.simpli.fi https://*.smaato.net https://*.tapad.com https://*.temu.com https://*.tremorhub.com https://*.typography.com https://*.yahoo.com https://*.zekelman.com https://acsbapp.com https://api2.amplitude.com https://app-cdn.bc0a.com https://app-cf.bc0a.com https://forms.hscollectedforms.net https://pippio.com https://tags.srv.stackadapt.com; frame-src 'self' https://*.facebook.com https://*.google.com https://*.google.co.uk https://*.google.com.au https://*.google.ca https://*.google.de https://*.google.fr https://*.google.com.ph https://*.google.co.in https://*.google.com.br https://*.googletagmanager.com https://*.youtube.com https://*.youtube-nocookie.com https://consentcdn.cookiebot.com https://rive.app https://forms.hsforms.com https://*.hsforms.com; worker-src 'self' blob:; report-uri https://www.zekelman.com/csp-report/; 1 default-src https: 'self'; base-uri 'self'; block-all-mixed-content; child-src 'self' *.bluekai.com *.doubleclick.net *.facebook.com *.pay.jp *.pa-mieruka.net platform.twitter.com; connect-src 'self' wss: http://*.milltalk.jp https://*.milltalk.jp *.juicer.cc *.facebook.com *.nr-data.net *.o2u.jp *.optimizely.com *.google-analytics.com *.analytics.google.com stats.g.doubleclick.net; font-src 'self' data:; form-action 'self' http://*.milltalk.jp https://*.milltalk.jp *.facebook.com questant.jp; frame-ancestors 'self' http://*.milltalk.jp https://*.milltalk.jp; img-src 'self' data: *.milltalk.jp s3-ap-northeast-1.amazonaws.com *.s3-ap-northeast-1.amazonaws.com *.s3.ap-northeast-1.amazonaws.com *.adsrvr.org *.adsymptotic.com *.audiencedata.net *.bluekai.com *.eyeota.net *.doubleclick.net *.google.com *.google.co.jp *.google-analytics.com *.analytics.google.com *.facebook.com *.interactive-circle.jp *.tapad.com *.logly.co.jp *.macromill.com *.mookie1.com *.o2u.jp *.rfihub.com *.socdm.com *.treasuredata.com *.amazon-adsystem.com *.ec-concier.com *.id.amgdgt.com a.ddli.jp idsync.rlcdn.com secure.adnxs.com r.turn.com www.googletagmanager.com; media-src 'self'; object-src 'self'; plugin-types application/x-shockwave-flash; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.audiencedata.net *.bkrtx.com *.bluekai.com *.doubleclick.net *.ec-concier *.facebook.net *.google.com *.google.co.jp *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.im-apps.net *.iogous.com *.juicer.cc *.logly.co.jp *.newrelic.com *.nr-data.net *.o2u.jp *.optimizely.com *.pay.jp *.st-hatena.com *.treasuredata.com *.twitter.com *.yahoo.co.jp ec-concier.com; style-src 'self' 'unsafe-inline' http://*.milltalk.jp https://*.milltalk.jp 1 base-uri 'self'; child-src 'self' https://*.youtube.com; connect-src 'self' wss://proxy.qubeshub.org wss://vncproxy.qubeshub.org wss://qubeshub.org https://qubeshub.org/api/members/tools/diskusage https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net https://www.dropbox.com https://api.scite.ai https://maps.googleapis.com https://docs.google.com https://monorail-edge.shopifysvc.com/v1/ https://simiode.myshopify.com/api/2021-07/ https://region1.google-analytics.com/g/ https://sagecell.sagemath.org wss://sagecell.sagemath.org/sockjs/; default-src 'self' https://*.qubeshub.org; font-src about: chrome-extension: data: https://fonts.gstatic.com safari-extension: 'self' https://use.typekit.net https://storage.googleapis.com/speechify-website-assets/fonts/ https://cdn.scite.ai/assets/fonts/scite-icons/ https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://cdn.scite.ai/assets/fonts/scite-icons/ https://use.fontawesome.com/releases/v4.7.0/ https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.11.2/webfonts/ https://at.alicdn.com/t/ https://fonts.cdnfonts.com/css/dejavu-serif https://sagecell.sagemath.org/static/ https://cdn.jsdelivr.net/npm/mathjax@3/es5/ https://fonts.cdnfonts.com/s/109/; form-action 'self' https://platform.twitter.com https://syndication.twitter.com https://www.paypal.com/donate https://www.paypal.com/cgi-bin/webscr; frame-ancestors 'self' https://qubeshub.org/; frame-src 'self' https://*.qubeshub.org https://content.googleapis.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://youtube.com https://player.vimeo.com https://calendar.google.com https://www.youtube.com https://vimeo.com https://docs.google.com https://accounts.google.com https://recaptcha.net https://admin.google.com https://syndication.twitter.com https://platform.twitter.com https://app.genial.ly/ https://app.involve.me/qubes/ https://cdnapisec.kaltura.com https://community.gep.wustl.edu https://creativecommons.org https://docs.google.com https://etherpad.opendev.org https://etherpad.openstack.org https://fortress.maptive.com https://giphy.com https://gvsu.hosted.panopto.com https://open.spotify.com https://padlet.com/ https://rpubs.com https://shorts.flipgrid.com https://w.soundcloud.com/ https://www.educreations.com https://www.geogebra.org https://www.google.com/ https://www.mentimeter.com https://www.rpubs.com https://www.youtube.com https://embed.bsky.app; img-src * data: image: file: blob:; media-src 'self' data:; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com/analytics.js https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com/gtag/js https://www.google.com/jsapi https://www.gstatic.com/charts/ https://cdnjs.cloudflare.com/ajax/libs/gsap/1.20.3/TweenMax.min.js https://cdnjs.cloudflare.com/ajax/libs/ScrollMagic/2.0.5/ScrollMagic.js https://cdnjs.cloudflare.com/ajax/libs/ScrollMagic/2.0.5/plugins/ https://apis.google.com/js/client:plusone.js https://apis.google.com/_/scs/apps-static/_/js/ https://platform.twitter.com/widgets.js https://abs.twimg.com/responsive-web/client-web/ https://platform.twitter.com/js/ https://cdn.syndication.twimg.com/timeline/ https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://cdn.mathjax.org/mathjax/contrib/a11y/ https://code.jquery.com https://embedr.flickr.com/assets/ https://releases.flowplayer.org/ https://sdks.shopifycdn.com/ https://secure.givelively.org https://use.fontawesome.com/88cd5351e6.js https://widgets.flickr.com/embedr/ https://www.geogebra.org https://sagecell.sagemath.org/static/embedded_sagecell.js https://cdn.jsdelivr.net/npm/mathjax@3/es5/ https://pretextbook.org/js/ https://cdnjs.cloudflare.com/ajax/libs/lunr.js/ https://ssl.google-analytics.com/ga.js https://embed.bsky.app/static/embed.js; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://www.google.com https://code.jquery.com https://cdnjs.cloudflare.com https://www.gstatic.com https://p.typekit.net https://use.typekit.net https://platform.twitter.com/css/ https://ton.twimg.com/tfw/css/ https://use.fontawesome.com/88cd5351e6.css https://use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.css https://releases.flowplayer.org/ https://pretextbook.org/css/ https://fonts.cdnfonts.com/css/dejavu-serif.css https://fonts.cdnfonts.com/css/dejavu-serif; worker-src blob:; report-uri https://csp.hubzero.org/csp-cms.php 1 default-src 'self' https: wss: *.binotel.com *.webpushs.com *.pushdata.sendpulse.com; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' *.binotel.com *.webpushs.com *.pushdata.sendpulse.com https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; report-uri /csp-violation-report-endpoint 1 font-src *.squarecdn.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.yotpo.com *.googleapis.com *.gstatic.com cdn.icomoon.io *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.reviews.io *.reviews.co.uk *.paymentexpress.com *.windcave.com *.yotpo.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com https://accounts.google.com *.reviews.io *.reviews.co.uk *.weltpixel.com *.paymentexpress.com *.windcave.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com www.xtento.com *.yotpo.com *.laybuy.com www.facebook.com *.hotjar.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.trackedlink.net *.alothemes.com *.magepow.com *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk t.zip.co static.zipmoney.com.au www.xtento.com cdn.xtento.com *.yotpo.com *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net *.laybuy.com www.facebook.com *.google.com *.google.co.nz *.google.com.au *.paypalobjects.com *.clarity.ms *.bing.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io https://rum.hlx.page https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net polyfill.io *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com s7.addthis.com *.avada.io *.alothemes.com *.magepow.com *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://accounts.google.com https://www.gstatic.com *.reviews.io *.reviews.co.uk *.maxmind.com static.zipmoney.com.au zip.co www.xtento.com cdn.xtento.com *.yotpo.com *.authorize.net *.googleapis.com *.vimeo.com *.googletagmanager.com *.google-analytics.com *.cardinalcommerce.com *.addressfinder.io *.polyfill.io *.addthis.com *.tawk.to cdn.jsdelivr.net *.google.com *.gstatic.com js-agent.newrelic.com bam.nr-data.net *.facebook.net *.laybuy.com *.hotjar.com *.doubleclick.net *.googleadservices.com *.clarity.ms *.3wisemen.co.nz *.zip.co *.afterpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://api.addressfinder.io static.afterpay.com/ *.squarecdn.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to unsafe-inline assets.braintreegateway.com https://accounts.google.com https://www.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.yotpo.com *.googleapis.com cdn.icomoon.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.algolia.net *.algolia.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://accounts.google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.mmapiws.com *.yotpo.com *.facebook.net *.algolianet.com ekr.zdassets.com *.googleapis.com *.tawk.to bam.nr-data.net *.google-analytics.com *.laybuy.com *.doubleclick.net t.labs.au.edge.zip.co in.hotjar.com *.hotjar.io *.clarity.ms *.addressfinder.io *.googlesyndication.com sst.3wisemen.co.nz 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src www.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://*.hotjar.com/ *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.maksekeskus.ee *.test.maksekeskus.ee https://www.google.ee/ https://*.hotjar.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: https://www.google.com/ https://*.hotjar.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.hotjar.com/ unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee https://*.google-analytics.com/ https://www.google.ee/ https://*.hotjar.com/ https://*.hotjar.io/ wss://*.hotjar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com; script-src-attr 'self'; style-src 'self' cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * payment.preprod.direct.worldline-solutions.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.disqus.com *.facebook.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://browser.sentry-cdn.com *.disqus.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com cdn.cookielaw.org payment.preprod.direct.worldline-solutions.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://*.ingest.sentry.io *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site cdn.cookielaw.org payment.preprod.direct.worldline-solutions.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: fonts.googleapis.com fonts.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com cdn.checkout.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.facebook.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com *.twitter.com *.google.com *.trustpilot.com *.checkout.com *.demdex.net *.consensu.org *.hotjar.com *.facebook.com *.eurolandir.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.google.com *.google.co.uk *.google.co.in *.google.nl *.zopim.com *.doubleclick.net d23yuld0pofhhw.cloudfront.net *.googletagmanager.com *.cdninstagram.com *.facebook.net *.facebook.com *.demdex.net *.omtrdc.net *.everesttech.net *.adroll.com *.rubiconproject.com *.yahoo.com *.3lift.com *.bidswitch.net *.adnxs.com *.openx.net *.advertising.com *.outbrain.com *.pubmatic.com *.taboola.com *.wynnstay.co.uk *.casalemedia.com *.rlcdn.com *.reson8.com *.pippio.com *.omnithrottle.com *.mathtag.com *.adsrvr.org *.adsystem.com *.w55c.net *.apxlv.com *.cogocast.net *.adadvisor.net *.agkn.com *.crwdcntrl.net *.sitescout.com *.target.com *.tapad.com *.mxptint.net *.survata.com *.adentifi.com *.stackadapt.com *.bing.com *.bidr.io *.linksynergy.com *.addthis.com *.tidaltv.com *.cardlytics.com *.entitytag.co.uk *.avocet.io *.avct.cloud *.360yield.com *.owneriq.net *.krxd.net *.bluekai.com *.criteo.com *.exelator.com *.scorecardresearch.com *.turn.com *.amgdgt.com *.walmart.com *.simpli.fi *.ipredictive.com *.bttrack.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.googletagmanager.com *.googlecommerce.com *.doubleclick.net *.trustpilot.com *.zopim.com *.zdassets.com *.payments-amazon.com *.amazon.com *.local.com *.checkout.com chimpstatic.com *.facebook.net *.facebook.com *.adroll.com *.dotdigital-pages.com *.civiccomputing.com *.consensu.org *.newrelic.com *.nr-data.net *.disqus.com *.trackedweb.net *.hotjar.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.fontawesome.com *.checkout.com *.adroll.com https://static.klaviyo.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.zopim.com *.amazon.com 'self' wss: *.checkout.com *.google-analytics.com *.googleapis.com *.demdex.net *.civiccomputing.com *.nr-data.net *.adroll.com *.doubleclick.net *.hotjar.com *.alphavantage.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://www.gstatic.com https://fonts.gstatic.com static.zip.co *.afterpay.com *.yotpo.com *.googleapis.com *.cloudflare.com *.font.im *.optimonk.com *.nikon.co.in *.slant.co *.alicdn.com *.loli.net *.migaku.com *.ziplyne.com *.googleusercontent.com *.nikon.com.au *.hsappstatic.net *.nikon.com.sg *.fontshare.com smc.org.in *.nikon-asia.com *.nikon-mea.com unpkg.com *.nikon.co.th *.crisp.chat *.githack.com yastatic.net *.cdn-apple.com *.jsdelivr.net *.zohocdn.com *.tiktok.com *.vixverify.com *.gstatic.cn use.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com https://secure-test.worldpay.com/shopper/3ds/ddc.html swellrewards.com *.swellrewards.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com *.googletagmanager.com https://pay.google.com https://secure-test.worldpay.com swellrewards.com *.swellrewards.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.files-text.com *.livechatinc.com *.livechat-files.com *.livechat-static.com https://*.googleapis.com https://*.googleusercontent.com https://maps.gstatic.com zip.co static.zip.co bpi.zip.co *.google.com.au *.linkedin.com *.yahoo.com *.adroll.com *.afterpay.com *.yotpo.com *.bazaarvoice.com *.nikon-mea.com *.nikon.com.hk *.solone.net vumbnail.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.tl www.google.tn www.google.to www.google.tt www.google.vu www.google.ws yastatic.net *.google.com *.mynikonlife.com.au *.nikon.co.in *.nikon.com.au www.google.ad www.google.as www.google.cf www.google.co.ck www.google.com.bz www.google.com.cu www.google.com.gi www.google.com.tj www.google.cv www.google.dj www.google.fm www.google.ga www.google.gl www.google.gy www.google.je www.google.ki www.google.ml www.google.ne www.google.sr www.google.st www.google.td www.google.tg www.google.tm *.baidu.com *.giphy.com *.ibb.co *.riskified.com *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com www.google.cn *.nikon.com.sg *.optimonk.com *.crwdcntrl.net *.ctnsnet.com *.ggpht.com *.nikon-asia.com *.nikon.co.th www.google.com.au *.tiktok.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.sm bitly.com dakotaram.com s3.amazonaws.com www.google.nu *.3lift.com *.adnxs.com *.adsrvr.org *.amazon-adsystem.com *.bidswitch.net *.bing.com *.bluekai.com *.casalemedia.com *.googleadservices.com *.openx.net *.outbrain.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com *.scorecardresearch.com *.taboola.com *.tapad.com google.com www.google.nr nikon-asia.com *.ytimg.com *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.livechatinc.com *.livechat-static.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://maps.googleapis.com snapwidget.com *.zip.co d35p4vvdul393k.cloudfront.net *.yotpo.com *.optimonk.com *.tiktok.com *.crazyegg.com *.adroll.com snap.licdn.com consentag.eu ctnsnet.com *.newrelic.com *.bazaarvoice.com *.disqus.com *.tailwindcss.com *.truecreatorstudio.com *.vimeo.com unpkg.com *.googleapis.com *.nikon.co.in *.alicdn.com *.riskified.com *.stackadapt.com *.qvdt3feo.com translate.google.com.hk *.googleadservices.com *.33across.com *.ctnsnet.com *.instagram.com *.cloudflare.com *.nikon.com.au d16i99j5zwwv51.cloudfront.net *.nikon.com.sg *.nikon-asia.com dakotaram.com *.cfjump.com *.nikon-mea.com *.ucweb.com *.nikon.co.th *.crisp.chat googletagmanager.com yastatic.net *.adobe.net *.adobedtm.com *.cdn-apple.com *.google-analytics.com *.jsdelivr.net *.licdn.com *.mynikonlife.com.au *.netcoresmartech.com localhost *.vixverify.com npmcdn.com *.gstatic.cn https://*.riskified.com https://www.google.com/recaptcha/api.js https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js swellrewards.com *.swellrewards.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com display.ugc.bazaarvoice.com *.livechatinc.com https://fonts.googleapis.com zip.co bpi.zip.co *.afterpay.com *.yotpo.com *.bazaarvoice.com *.optimonk.com *.nikon.co.in *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com *.nikon.com.au *.nikon.com.sg *.nikon-asia.com *.nikon-mea.com *.nikon.co.th *.mynikonlife.com.au *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.livechatinc.com 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com *.livechat-static.com *.vimeocdn.com *.gstatic.com nikon-asia.com *.google.com *.nikon.com.au 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.livechatinc.com *.text.com api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://maps.googleapis.com *.zipmoney.com.au *.zip.co *.afterpay.com *.optimonk.com *.crazyegg.com *.linkedin.com *.tiktok.com ctnsnet.com *.nr-data.net *.googletagmanager.com *.google.com *.googleadservices.com *.yotpo.com *.bazaarvoice.com *.crwdcntrl.net *.doubleclick.net *.truecreatorstudio.com localhost truecreatorstudio.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bs www.google.bt www.google.by www.google.ca www.google.cg www.google.ch www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.tn www.google.to www.google.vu *.nikon.co.in www.google.bj www.google.cd www.google.ci www.google.cm www.google.com.cu www.google.com.ly www.google.com.ni www.google.com.pr www.google.com.sl www.google.com.sv www.google.com.tj www.google.dj www.google.ga www.google.im www.google.je www.google.ml www.google.ne www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tt www.google.ws *.baidu.com *.riskified.com *.stackadapt.com *.qvdt3feo.com www.google.com.na www.google.com.uy www.google.gg *.ctnsnet.com www.google.com.sb www.google.bi lottie.host *.nikon.com.au www.google.ad www.google.com.do *.nikon.com.sg www.google.com.ag www.google.gl *.nikon-asia.com www.google.co.ls www.google.ki www.google.com.bz *.nikon-mea.com www.google.cf *.ucweb.com *.nikon.co.th www.google.tm www.google.st www.google.co.ck *.netcoresmartech.com *.openfpcdn.io *.samsung.com google.com kg668dbov0.execute-api.us-east-1.amazonaws.com www.google.nr www.google.cn www.google.com.gi www.google.cv www.google.gy www.google.sm *.conversionsapigateway.com mpc-prod-1-1053047382554.us-central1.run.app mpc-prod-2-1053047382554.us-central1.run.app mpc-prod-18-s6uit34pua-uc.a.run.app www.google.com.vc www.google.li *.vixverify.com *.alicdn.com mpc-prod-14-s6uit34pua-ue.a.run.app test-drive-20-1053047382554.us-central1.run.app swellrewards.com *.swellrewards.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.livechatinc.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.crazyegg.com *.optimonk.com *.facebook.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.riskified.com 'self' 'unsafe-inline'; report-uri https://7c4e2960-bb15-40d6-acb7-9e6842d5f617.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com assets-uk1-cloud.deskpro.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com esecure.sia.eu geoissuer.cardinalcommerce.com *.cardinalcommerce.com *.arcot.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.demdex.net *.adyen.com www.google.com *.google.com *.doubleclick.net *.facebook.com js.stripe.com *.hotjar.com *.paypalobjects.com esecure.sia.eu geoissuer.cardinalcommerce.com *.cardinalcommerce.com *.arcot.com *.wdscomponents.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com www.xtento.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com c.bing.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk https://assets-uk1-cloud.deskpro.com via.placeholder.com *.wdscomponents.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com c.clarity.ms assets-uk1-cloud.deskpro.com attachments-uk1-cloud-deskpro-com.s3.amazonaws.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * assets.adobedtm.com *.magento-ds.com *.adyen.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.newrelic.com *.nr-data.net *.pcapredict.com *.hotjar.com *.trustpilot.com *.canddi.com *.wdscomponents.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com c.bing.com c.clarity.ms assets-uk1-cloud.deskpro.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com services.postcodeanywhere.co.uk *.typekit.net assets-uk1-cloud.deskpro.com *.wdscomponents.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com https://cdnjs.cloudflare.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net assets-uk1-cloud.deskpro.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com assets-uk1-cloud.deskpro.com *.zdassets.com ws: *.newrelic.com *.nr-data.net *.doubleclick.net *.hotjar.com *.wdscomponents.com wdsmedia.wdscomponents.com wdscomponents.deskpro.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com *.fontawesome.com *.googleapis.com *.gstatic.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ * magento-cloudflare.jetrails.com *.klarna.com *.trustpilot.com *.hotjar.com https://*.google.com/recaptcha/ *.zendesk.com *.zdassets.com *.zopim.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com * *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.ytimg.com *.klarna.com *.klarnaevt.com *.googleadservices.com *.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.se *.paypal.com *.paypalobjects.com https://www.facebook.com https://mcusercontent.com https://js.klevu.com https://*.mgr.consensu.org https://cdn.consentmanager.net https://cx.atdmt.com *.zendesk.com *.zdassets.com *.zopim.com https://bat.bing.com/ https://*.cookiefirst.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.fontawesome.com *.googleapis.com *.gstatic.com *.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://maps.googleapis.com *.google.com https://connect.facebook.net/ *.trustpilot.com *.klarnacdn.net https://js.klevu.com https://downloads.mailchimp.com *.hotjar.com *.hotjar.io *.gtm.adt313.net https://checkoutshopper-test.adyen.com https://*.mgr.consensu.org https://*.cloudflareinsights.com *.zendesk.com *.zdassets.com *.zopim.com https://bat.bing.com/ *.clarity.ms https://consent.cookiefirst.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.cash.app downloads.mailchimp.com *.fontawesome.com *.fonts.googleapis.com *.googleapis.com *.gstatic.com https://downloads.mailchimp.com https://js.klevu.com https://*.mgr.consensu.org *.zendesk.com *.zdassets.com *.zopim.com https://consent.cookiefirst.com/ unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com * *.klarnaevt.com *.paypal.com *.cardinalcommerce.com *.stripe.com *.klarna.com *.klarnacdn.net *.google-analytics.com *.addwish.com *.doubleclick.net *.facebook.com *.hotjar.com https://*.mgr.consensu.org *.zendesk.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com *.clarity.ms/ https://bat.bing.com/ https://*.cookiefirst.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.agechecker.net https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trustpilot.com consentcdn.cookiebot.com consentcdn.cookiebot.eu js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io img.agechecker.net https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://info.dibs.se c.bing.com c.clarity.ms imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.agechecker.net https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com https://*.dibspayment.eu www.clarity.ms *.trustpilot.com consent.cookiebot.com consent.cookiebot.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.hotjar.com js.klevu.com *.ksearchnet.com *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com https://*.dibspayment.eu *.trustpilot.com downloads.mailchimp.com https://static.klaviyo.com https://test.checkout.dibspayment.eu https://checkout.dibspayment.eu *.google.com snusdaddy.test *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.agechecker.net https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://*.dibspayment.eu o.clarity.ms *.clarity.ms consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://test.checkout.dibspayment.eu https://checkout.dibspayment.eu *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.datadoghq-browser-agent.com https://assets.juicer.io; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.datadoghq-browser-agent.com https://assets.juicer.io; style-src 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net https://assets.juicer.io https://cdn.jsdelivr.net; font-src 'self' https://use.typekit.net https://p.typekit.net; img-src * 'self' data:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://*.moneris.com/ www.googletagmanager.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.moneris.com https://www.youtube.com https://c.paypal.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.moneris.com/ *.avada.io connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.moneris.com *.webeyez.com paypal.com *.fontawesome.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com downloads.mailchimp.com https://*.moneris.com/ *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com paypal.com paypalobjects.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' ; base-uri 'self' ; object-src 'none' ; style-src 'self' 'unsafe-inline' cdn.plyr.io https://fonts.googleapis.com https://devcomapbotpilot-test.azurewebsites.net/ https://chatbotapp-stage.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ ; script-src 'strict-dynamic' 'nonce-vwYVI7608pdpK1hwqMP61Pywjndn5lAA' 'self' 'unsafe-inline' 'unsafe-eval' https://js.monitor.azure.com https://admin.dev.comap-control.bluehosting.cz https://chatbotapp-stage.azurewebsites.net/ https://devcomapbotpilot-test.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ ; font-src 'self' https://fonts.gstatic.com/ ; connect-src 'self' https://*.logic.azure.com/ https://devcomapbotpilot-test.azurewebsites.net https://chatbotapp-stage.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ https://devcomapcognitiveservices-test.azurewebsites.net https://intelisearch-stage.azurewebsites.net https://intelisearch.azurewebsites.net https://directline.botframework.com wss://directline.botframework.com https://*.in.applicationinsights.azure.com/ wss://localhost:44377 ws://localhost:50602 noembed.com cdn.plyr.io ; img-src * 'self' data: ; media-src 'self' *.comap-control.com/ https://comapkenticouat6527.blob.core.windows.net ; frame-src https://www.thinglink.com youtube-nocookie.com www.youtube-nocookie.com youtube.com www.youtube.com vimeo.com www.vimeo.com https://www.google.com/ ; frame-ancestors https://admin.dev.comap-control.bluehosting.cz/ 1 font-src *.googleapis.com *.gstatic.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hipay-tpp.com *.hipay.com *.googleapis.com *.klarna.com www.googletagmanager.com gum.criteo.com widget.trustpilot.com ct.pinterest.com fledge.eu.criteo.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com https://cdn.clerk.io cdn.doofinder.com *.hipay.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.amazonaws.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io cdn.doofinder.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.klarna.com *.klarnacdn.net *.klarnaservices.com tps.trovaprezzi.it cdn.iubenda.com cs.iubenda.com widget.trustpilot.com s.kk-resources.com eu1-config.doofinder.com dynamic.criteo.com s.pinimg.com cdn.clerk.io api.clerk.io ct.pinterest.com sslwidget.criteo.com *.avada.io *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.sendcloud.sc *.jsdelivr.net tm.tradetracker.net tracking.trovaprezzi.it www.trovaprezzi.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.doofinder.com *.hipay.com *.googleapis.com *.klarnacdn.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com cdn.doofinder.com cdn.iubenda.com *.fontawesome.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.doofinder.com wss://*.doofinder.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com stats.g.doubleclick.net region1.analytics.google.com eu1-api.doofinder.com mug.criteo.com ct.pinterest.com idb.iubenda.com widget.trustpilot.com measurement-api.criteo.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src stats.g.doubleclick.net www.google.it www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.gabrielny.com *.cloudflare.com https://acsbapp.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.affirm.com *.affirm.ca *.timedelay.com *.gabrielny.com *.doubleclick.net *.paypal.com *.firebaseio.com *.authorize.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.affirm.com *.affirm.ca *.chekkit.io *.cloudfront.net *.gemfind.net *.gabrielny.com *.paypal.com *.googletagmanager.com *.ashidiamonds.com *.locker2.com *.acsbapp.com *.facebook.com *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.facebook.net *.hotjar.com https://pageimprove.io/ https://insiderdata360online.com/ *.chekkit.io *.gabrielny.com *.googletagmanager.com *.doubleclick.net *.google.com *.paypal.com *.causalfunnel.com *.firebaseio.com https://acsbapp.com/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gabrielny.com *.cloudflare.com *.googleapis.com downloads.mailchimp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.overnightmountings.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.affirm.com *.affirm.ca http://insiderdata360online.com/ *.doubleclick.net https://pageimprove.io/ *.chekkit.io *.gabrielny.com *.gabrielny.com:8080 *.braintree-api.com *.paypal.com *.google-analytics.com *.google.com *.gstatic.com *.firebaseio.com wss://s-usc1f-nss-2501.firebaseio.com/ *.acsbapp.com *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 https://www.calyxsoftware.com; static.hsappstatic.net, *.hubspotusercontent-*.net, *.hubspot.net, *.hs-scripts.com; script-src 'strict-dynamic' 'nonce-5CGWodUpgrDwR442d7LSgA==' 1 font-src fonts.gstatic.com use.typekit.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.slant.co *.flaticon.com unpkg.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.xtento.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.addthis.com http://*.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com www.xtento.com cdn.xtento.com https://static.afterpay.com https://site-assets.afterpay.com/ *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bt www.google.by www.google.ca www.google.ch www.google.cl www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mk www.google.mn www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.tn https://eb2.3lift.com https://ib.adnxs.com https://*.adroll.com http://*.adroll.com https://*.bidswitch.net https://dsum-sec.casalemedia.com https://www.google.com https://www.google.com.au https://www.google.com.vn https://idsync.rlcdn.com https://pixel.rubiconproject.com https://us-u.openx.net https://sync.outbrain.com https://image2.pubmatic.com https://sync.taboola.com https://ups.analytics.yahoo.com https://prf.hn *.tiktok.com *.windsorsmithoutlet.com.au www.google.bj www.google.cd www.google.cg www.google.co.ug www.google.com.bn www.google.com.py www.google.com.sb www.google.la www.google.ps www.google.to *.cdninstagram.com foursixty.com *.foursixty.com www.google.bf www.google.bs www.google.ci www.google.cm www.google.co.ao www.google.co.ck www.google.co.ls www.google.co.zw www.google.com.af www.google.com.bh www.google.com.kw www.google.com.na www.google.com.pa www.google.dj www.google.gy www.google.hn www.google.ht www.google.kg www.google.mg www.google.mu www.google.rw www.google.sr www.google.tl www.google.tt www.google.vu www.google.ws *.afterpay.com *.googleapis.com *.trackedweb.net google.com www.google.co.vi www.google.com.ly www.google.cv www.google.gg www.google.im www.google.sh www.google.so www.google.tg *.googleadservices.com *.kxcdn.com www.google.dm www.google.gm www.google.nr www.google.sc *.tumblr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.afterpay.com https://static.afterpay.com *.squarecdn.com *.cash.app polyfill.io *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com www.xtento.com cdn.xtento.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.addthis.com http://*.addthis.com https://v1.addthisedge.com https://*.adroll.com http://*.adroll.com https://t.cfjump.com https://*.newrelic.com https://z.moatads.com https://widgets.pinterest.com http://widgets.pinterest.com https://analytics.tiktok.com https://cfjump.windsorsmith.com.au https://static.zdassets.com https://v2.zopim.com *.hotjar.com *.tiktok.com *.personyze.com foursixty.com *.foursixty.com *.adobe.net *.ahrefs.com *.cfjump.com *.googleapis.com *.zopim.com unpkg.com *.adobedtm.com *.googleadservices.com googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com/ static.afterpay.com/ *.squarecdn.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://s.adroll.com foursixty.com *.foursixty.com *.bootstrapcdn.com *.google-analytics.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.bolt.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afterpay.com *.afterpay-beta.com static.afterpay.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com static.sandbox.afterpay.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.clearpay.co.uk *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com https://*.addthis.com http://*.addthis.com https://*.adroll.com http://*.adroll.com *.hotjar.com *.hotjar.io localhost https://analytics.tiktok.com https://*.zdassets.com https://windsorsmith.zendesk.com https://bam.nr-data.net https://*.afterpay.com www.google.ae www.google.al www.google.be www.google.bg www.google.by www.google.ca www.google.ch www.google.cl www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.za www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.et www.google.com.fj www.google.com.hk www.google.com.kh www.google.com.lb www.google.com.mx www.google.com.my www.google.com.np www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.de www.google.dk www.google.es www.google.fr www.google.ge www.google.gr www.google.it www.google.lt www.google.lv www.google.md www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.si www.google.sk www.google.sm www.google.at www.google.az www.google.bt www.google.co.bw www.google.co.cr www.google.co.kr www.google.co.ma www.google.com.do www.google.com.eg www.google.com.gh www.google.com.gt www.google.com.jm www.google.com.mt www.google.com.ng www.google.com.pr www.google.com.qa www.google.com.sa www.google.cz www.google.ee www.google.fi www.google.hr www.google.hu www.google.ie www.google.kz www.google.lk www.google.lu www.google.mk www.google.rs www.google.se www.google.tn foursixty.com *.foursixty.com *.cdninstagram.com *.tiktok.com www.google.am www.google.ba www.google.bs www.google.ci www.google.co.ao www.google.co.ls www.google.co.tz www.google.co.uz www.google.co.zm www.google.co.zw www.google.com.bo www.google.com.gi www.google.com.kw www.google.com.ni www.google.com.pa www.google.com.sb www.google.com.sv www.google.com.uy www.google.dz www.google.gy www.google.hn www.google.iq www.google.is www.google.jo www.google.kg www.google.li www.google.mg www.google.mn www.google.mu www.google.mw www.google.ps www.google.ru www.google.sr www.google.tt www.google.vu *.ahrefs.com *.contentsquare.net *.googleapis.com *.zdassets-backup.com www.google.co.mz www.google.com.ly www.google.com.mm www.google.com.na www.google.com.om www.google.ga www.google.gg www.google.me www.google.mv www.google.sh www.google.so www.google.tl *.googleadservices.com www.google.ad www.google.cm www.google.co.ck www.google.co.ug www.google.com.bz www.google.gm www.google.nr www.google.rw www.google.ws *.bootstrapcdn.com www.google.bf 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://988f5f2a-8122-4a5c-b667-a92f322522d6.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://images.unsplash.com *.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.googletagmanager.com *.facebook.net *.avada.io js.mollie.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.typekit.net *.klarnacdn.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.gstatic.com *.googleapis.com imgsct.cookiebot.com imgsct.cookiebot.eu *.trackedlink.net https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ consent.cookiebot.com consent.cookiebot.eu *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.googleapis.com *.typekit.net *.klarnacdn.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com *.amazon.com *.cloudflare.com *.twitter.com *.twimg.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://233a377d-1420-456f-9376-009a10f60e15.sansec.watch/; report-to report-endpoint; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com cdn.ampproject.org www.gstatic.com connect.facebook.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com www.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdn.ampproject.org www.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.at ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.at *.spreadshirt.at ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.at ; font-src 'self' https: data: *.spreadshirt.at ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.at ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.at ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com *.gstatic.com https://script.hotjar.com *.landbot.io cash-f.squarecdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es api.paycomet.com *.ogone.com *.v-psp.com https://www.facebook.com *.redsys.es * 'self' 'unsafe-inline'; frame-ancestors *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.adobe.com https://bid.g.doubleclick.net https://www.linkbux.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.dotdigital-pages.com *.dotdigital.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com api.paycomet.com *.doubleclick.net pay.google.com service.force.com hal9000.redintelligence.net https://pikolinrecommend.botslovers.com https://*.soreto.com https://ams.creativecdn.com/ https://www.facebook.com/ https://www.awin1.com/ *.redsys.es https://www.googletagmanager.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com *.trackedlink.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.gstatic.com *.adotmob.com *.facebook.com *.facebook.net *.google.com *.google.es *.googleapis.com *.omtrdc.net https://*.g.doubleclick.net/ *.doubleclick.net https://*.googletagmanager.com *.google-analytics.com *.analytics.google.com *.media-amazon.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://ade.googlesyndication.com https://lantern.roeyecdn.com https://lantern.roeye.com https://pikolinrecommend.botslovers.com https://*.tagmanager.google.com https://pikolin.botslovers.com https://cdn.botslovers.com https://t.teads.tv/ https://c.clarity.ms/ https://*.bing.com/ https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com https://rt.udmserve.net/ https://pixel.rubiconproject.com https://www.awin1.com/ https://eb2.3lift.com/ https://secure.adnxs.com/ https://ih.adscale.de/ https://sync.outbrain.com/ https://ssp-csync.smartadserver.com/ https://ads.stickyadstv.com https://ads.yieldmo.com/ https://api.soreto.com/ https://cdn.doofinder.com/ https://ib.adnxs.com/ eu1-doofinderuser.s3.amazonaws.com https://*.collect.igodigital.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com https://maps.googleapis.com *.gstatic.com *.zdassets.com js-agent.newrelic.com *.serving-sys.com *.facebook.net *.doubleclick.net *.zopim.com *.cstatic.weborama.fr https://cdn.cookielaw.org https://pikolin.botslovers.com.co https://pikolin.botslovers.com https://pikolinrecommend.botslovers.com https://cdn.landbot.io *.payments-amazon.com pay.google.com https://service.force.com https://cdn.doofinder.com *.clarity.ms *.hotjar.com https://www.dwin1.com https://www.wepowerconnections.com https://lantern.roeyecdn.com https://espadesa.my.salesforce.com/ https://*.googletagmanager.com https://*.tagmanager.google.com https://*.google-analytics.com https://www.googleadservices.com https://p.teads.tv/ https://*.soreto.com https://cdn.frizbit.com/ https://js.cookieless-data.com/ https://*.adform.net/ https://js.sddan.com/ https://tags.creativecdn.com/ https://*.bing.com https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://*.datnova.com/ https://static.lightning.force.com https://espadesa.secure.force.com https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/ https://d.la2-c1-cdg.salesforceliveagent.com/ *.redsys.es https://sslwidget.criteo.com/ https://dynamic.criteo.com/ https://*.collect.igodigital.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com/ *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com service.force.com *.clarity.ms https://cdn.doofinder.com https://*.googletagmanager.com https://*.tagmanager.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.frizbit.com/ https://espadesa.secure.force.com/ *.cash.app *.trustpilot.com 'self' 'unsafe-inline'; object-src *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.pikolin.com/es *.pikolin.com/pt pikolin.tt.omtrdc.net *.magentosite.cloud *.beds.es *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.serving-sys.com *.google-analytics.com *.analytics.analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.demdex.net *.paypal.com *.doubleclick.net https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://maps.googleapis.com https://google.com https://www.google.es https://www.google.com https://pagead2.googlesyndication.com pay.google.com https://payments-eu.amazon.com *.amazon.com eu1-layer.doofinder.com wss://eu1-layer.doofinder.com/ *.clarity.ms https://*.hotjar.io https://*.hotjar.com wss://*.hotjar.com https://pikolinrecommend.botslovers.com *.tt.omtrdc.net https://pikolin.botslovers.com https://cdn.botslovers.com/ https://www.facebook.com/ https://cm.teads.tv/ https://t.teads.tv/ https://www.wepowerconnections.com https://*.soreto.com https://*.frizbit.com/ https://ams.creativecdn.com/ https://the.sciencebehindecommerce.com/ https://geolocation.onetrust.com https://privacyportal.onetrust.com https://privacyportal-eu.onetrust.com https://*.bing.com/ https://espadesa.secure.force.com/ *.googleapis.com *.landbot.io * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com https://*.trustpilot.com/ 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es https://*.soreto.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; report-uri https://pikolin.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 connect-src 'self' *.hubspot.com *.google.com *.bing.com *.hotjar.com *.hotjar.io *.linkedin.com *.licdn.com *.reddit.com *.facebook.com *.stackadapt.com *.doubleclick.net *.googlesyndication.com *.google.com.mx *.google.co.uk *.google.com.br *.google.co.in *.google.de *.google.com.tr *.google.co.il *.google.ca *.google.ro *.google.nl *.google.fr *.google.es *.google.ie *.google.com.pr *.google.it *.google.com.au *.google.com.ec *.google.com.ph *.google.com.sg *.google.com.pk *.google.at *.google.no *.google.cl *.google.co.kr *.google.se *.google.co.jp *.google.com.pe *.google.com.my *.google.co.th *.google.co.za *.google.com.ua *.google.sk *.google.com.ng *.google.pl *.google.be *.google.fi *.google.ae *.google.com.co *.google.co.id *.google.co.ve *.google.com.hk *.google.com.eg *.google.com.uy *.google.com.ar *.google.ch *.google.ru *.google.co.ke *.google.pt *.google.mu *.google.com.sa *.google.com.vn *.google.com.tw *.google.gr *.google.com.bd *.google.dk *.google.com.py *.google.ee *.google.co.nz *.google.co.ma *.google.cz *.google.lk *.google.bg *.google.rs *.google.com.do *.google.hu *.google.iq *.google.co.cr *.google.al *.google.jo *.google.hr *.google.com.pa *.google.com.cy *.google.com.gh *.google.lt *.google.kz *.google.com.np *.google.by *.google.dz *.google.com.sv *.google.hn *.google.com.kw *.google.com.et *.google.mk *.google.ge *.google.cn *.google.com.jm *.google.si *.google.co.ug *.google.lv *.google.md *.google.co.mz *.google.lu *.google.am *.api.osano.com api.hubapi.com connect.facebook.net cdn.acsbapp.com forms.hscollectedforms.net forms.hsforms.com fonts.gstatic.com fonts.googleapis.com js.zi-scripts.com js.hs-scripts.com js.hs-analytics.net js.hsadspixel.net js.hubspotfeedback.com js.hs-banner.com js.hsleadflows.net js.usemessages.com monitor.clickcease.com www.googletagservices.com www.google-analytics.com www.redditstatic.com ws.zoominfo.com www.googletagmanager.com cdn.cookie-script.com *.nr-data.net t.contentsquare.net wss://ws.hotjar.com https://tracker-shield.funnelytics.workers.dev https://track-v3.funnelytics.io https://consent.cookie-script.com/; default-src 'self'; font-src 'self' data: *.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com script.hotjar.com; frame-src 'self' data: *.hubspot.com *.facebook.com *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net forms.hsforms.com js.usemessages.com js.hscollectedforms.net js.hsadspixel.net sdx.microsoft.com vars.hotjar.com www.linkedin.com www.googletagmanager.com x.adroll.com; img-src 'self' data: blob: *.hubspot.com *.bing.com *.microsoft.com *.linkedin.com *.licdn.com *.facebook.com *.facebook.net *.fbcdn.net *.stackadapt.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.google.com.mx *.google.co.uk *.google.com.br *.google.co.in *.google.de *.google.com.tr *.google.co.il *.google.ca *.google.ro *.google.nl *.google.fr *.google.es *.google.ie *.google.com.pr *.google.it *.google.com.au *.google.com.ec *.google.com.ph *.google.com.sg *.google.com.pk *.google.at *.google.no *.google.cl *.google.co.kr *.google.se *.google.co.jp *.google.com.pe *.google.com.my *.google.co.th *.google.co.za *.google.com.ua *.google.sk *.google.com.ng *.google.pl *.google.be *.google.fi *.google.ae *.google.com.co *.google.co.id *.google.co.ve *.google.com.hk *.google.com.eg *.google.com.uy *.google.com.ar *.google.ch *.google.ru *.google.co.ke *.google.pt *.google.mu *.google.com.sa *.google.com.vn *.google.com.tw *.google.gr *.google.com.bd *.google.dk *.google.com.py *.google.ee *.google.co.nz *.google.co.ma *.google.cz *.google.lk *.google.bg *.google.rs *.google.com.do *.google.hu *.google.iq *.google.co.cr *.google.al *.google.jo *.google.hr *.google.com.pa *.google.com.cy *.google.com.gh *.google.lt *.google.kz *.google.com.np *.google.by *.google.dz *.google.com.sv *.google.hn *.google.com.kw *.google.com.et *.google.mk *.google.ge *.google.cn *.google.com.jm *.google.si *.google.co.ug *.google.lv *.google.md *.google.co.mz *.google.lu *.google.am alb.reddit.com cdn2.hubspot.net d.adroll.com forms.hsforms.com fonts.gstatic.com p.adsymptotic.com script.hotjar.com tr-rc.lfeeder.com www.googleadservices.com www.redditstatic.com www.googletagmanager.com match.adsrvr.org pixel.tapad.com; media-src 'self' dai.google.com media.licdn.com; object-src *.googlesyndication.com; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' data: blob: https://*.google.com https://*.imp.stackadapt.com https://*.srv.stackadapt.com https://*.googletagservices.com https://*.googlesyndication.com https://*.googleadservices.com https://*.doubleclick.net https://*.srv.stackadapt.com https://acsbapp.com https://bat.bing.com https://connect.facebook.net https://content.linkedin.com https://cdn.calltrk.com https://cmp.osano.com https://d.adroll.com https://forms.hsforms.com https://googleads.g.doubleclick.net https://google-analytics.com https://graph.facebook.com https://googletagmanager.com https://js.facebook.com https://js.zi-scripts.com https://js.hsforms.net https://js.hscollectedforms.net https://js.hs-analytics.net https://js.usemessages.com https://js.hubspotfeedback.com https://js.hsadspixel.net https://js.hs-banner.com https://js.hsleadflows.net https://js-na1.hs-scripts.com https://js.hs-scripts.com https://lftracker.leadfeeder.com https://maxcdn.bootstrapcdn.com https://netdna.bootstrapcdn.com https://platform.linkedin.com https://r.bing.com https://ssl.google-analytics.com https://static-exp1.licdn.com https://snap.licdn.com https://script.hotjar.com https://static.hotjar.com https://s.adroll.com https://stackpath.bootstrapcdn.com https://tagmanager.google.com https://www.google-analytics.com https://www.clickcease.com https://www.redditstatic.com https://www.googletagmanager.com https://pi.pardot.com/ https://js-agent.newrelic.com/ https://code.jquery.com https://cdn.cookie-script.com https://t.contentsquare.net https://qvdt3feo.com https://geo.cookie-script.com/ https://cdn.funnelytics.io/; style-src 'self' 'report-sample' 'unsafe-inline' *.bootstrapcdn.com *.google.com *.bing.com *.licdn.com *.srv.stackadapt.com fonts.googleapis.com www.googletagmanager.com; 1 font-src *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com *.gstatic.com *.checkout.vficloud.net *.vficloud.net *.amazonaws.com *.checkout.verifone.cloud *.verifone.cloud data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.revolut.com *.google.com *.cdn-apple.com google.com *.gstatic.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.revolut.com *.google.com *.cdn-apple.com google.com *.gstatic.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io http://dpm.demdex.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com *.checkout.vficloud.net *.vficloud.net *.checkout.verifone.cloud *.verifone.cloud 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pge.phreesia.net;script-src 'nonce-c7dc7a1528c0459d96b582ebd55ac725' https://www.tannermychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.tannermychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src https: 'unsafe-inline' 'unsafe-eval'; connect-src https: wss:; img-src https: 'unsafe-inline' 'unsafe-eval' data: 1 worker-src blob:; font-src *.squarecdn.com fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com widgets.sandbox.afterpay.com *.cash.app facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.cash.app scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.cdninstagram.com *.fbcdn.net t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com s7.addthis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.afterpay.com/ *.squarecdn.com *.cash.app *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com ekr.zdassets.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 script-src 'self' blob: https://prod-bk-web.mx.rbi.tools/en/static/js/vendor.0101545a.js https://prod-bk-web.mx.rbi.tools/en/static/js/main.af2a5e86.js https://prod-bk-web.mx.rbi.tools/en/static/js/runtime.1e5c2b6c.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.mx.rbi.tools/en/static/js/vendor.988de8a5.js https://prod-bk-web.mx.rbi.tools/en/static/js/main.b665fdd9.js https://prod-bk-web.mx.rbi.tools/en/static/js/runtime.85a2feb7.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com *.klarna.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com.ua https://www.googleadservices.com https://bat.bing.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cc-cdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widget.reviews.co.uk https://porjs.com https://cdn-cookieyes.com https://log.cookieyes.com https://www.google.com.ua newrelic.com nr-data.net https://bat.bing.com https://www.clarity.ms https://static.addtoany.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com cc-cdn.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://k.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com *.amazon.com *.google-analytics.com *.doubleclick.net https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net blog.farmaciasvivo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.redsys.es sis-t.redsys.es:25443 blog.farmaciasvivo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com blog.farmaciasvivo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.doubleclick.net cl.avis-verifies.com tagging.farmaciasvivo.com tagging-preview.farmaciasvivo.com https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com blog.farmaciasvivo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io farmaciasvivo.com www.farmaciasvivo.com cdn.farmaciasvivo.com blog.farmaciasvivo.com cl.avis-verifies.com *.google.es *.google.com *.facebook.com *.sharethis.com *.doofinder.com *.aemps.es eu1-doofinderuser.s3.amazonaws.com cdn.connectif.cloud http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.googleapis.com https://firebasestorage.googleapis.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com localhost:35729 *.doofinder.com connect.facebook.net *.plerdy.com *.sharethis.com cdn.connectif.cloud analytics.tiktok.com tagging.farmaciasvivo.com tagging-preview.farmaciasvivo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com blog.farmaciasvivo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.googletagmanager.com cdn.connectif.cloud *.fontawesome.com https://fonts.bunny.net *.multisafepay.com blog.farmaciasvivo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ blog.farmaciasvivo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com ws://localhost:35729 *.doofinder.com wss://eu1-layer.doofinder.com *.doubleclick.net *.google.es *.analytics.google.com *.google-analytics.com *.facebook.com *.sharethis.com *.plerdy.com wss://d.plerdy.com eu8-api.connectif.cloud cdn.connectif.cloud cdn.farmaciasvivo.com analytics.tiktok.com tagging.farmaciasvivo.com tagging-preview.farmaciasvivo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.googleapis.com *.gstatic.com data: https://get.geojs.io *.avada.io *.multisafepay.com blog.farmaciasvivo.com 'self' 'unsafe-inline'; child-src blog.farmaciasvivo.com http: https: blob: 'self' 'unsafe-inline'; default-src blog.farmaciasvivo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'report-sample'; style-src 'self' 'report-sample' fonts.googleapis.com https://fonts.googleapis.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com https://t.pepperjamnetwork.com *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://shareasale.com/sale.cfm https://track.linksynergy.com https://www.bizrate.com https://www.awin1.com https://*.zenaps.com https://track.webgains.com https://prf.hn https://track.flexlinks.com https://scripts.affiliatefuture.com https://t.powerreviews.com https://match.sharethrough.com https://cm.g.doubleclick.net https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://jadserve.postrelease.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://ps.eyeota.net https://public-prod-dspcookiematching.dmxleo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com stackpath.bootstrapcdn.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.dwin1.com https://intljs.rmtag.com https://cdn.avmws.com https://images.bizrate.com https://www.awin1.com https://*.zenaps.com https://swrap.tradedoubler.com https://analytics.optimalpeople.fr https://www.linkconnector.com https://d3v27wwd40f0xu.cloudfront.net https://static.criteo.net https://sslwidget.criteo.com https://*.affiliatefuture.com https://static.powerreviews.com https://analytics.webgains.io *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com stackpath.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://shareasale.com/sale.cfm https://analytics.optimalpeople.fr https://measurement-api.criteo.com https://api.webgains.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://h.online-metrix.net https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ cdn.mundipagg.com api.pagar.me *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.mundipagg.com api.pagar.me t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.gstatic.com data: *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.certcapture.com https://maps.google.com/ ipinfo.io *.stripe.com https://js.stripe.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.certcapture.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com ipinfo.io *.stripe.com https://js.stripe.com/v2/ https://js.stripe.com/v3/ *.google.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com 'sha256-g/qbQ8sW5eJ9JO8sQzRJ1OvARbUyKpJXFeof9SLw1eI=' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src ipinfo.io landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.ipinfo.io *.certcapture.com ipinfo.io *.stripe.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.fontawesome.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com https://seo.mageplaza.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.youtube.com/ challenges.cloudflare.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.alothemes.com *.magepow.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.alothemes.com *.magepow.com challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addtoany.com *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org http://dpm.demdex.net *.alothemes.com *.magepow.com *.gstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src 'self' static.artforum.sk use.typekit.net data:; style-src 'self' 'unsafe-inline' static.artforum.sk *.typekit.net cdn.luigisbox.com tools.luckyorange.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' static.artforum.sk cdn.luigisbox.com scripts.luigisbox.com cdnjs.cloudflare.com www.googletagmanager.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com pagead2.googlesyndication.com googleads.g.doubleclick.net www.google.com www.google.sk www.google.cz connect.facebook.net login.dognet.sk browser.sentry-cdn.com js.sentry-cdn.com *.sentry.io sibautomation.com widget.packeta.com tools.luckyorange.com static.posta.sk scripts.clarity.ms www.clarity.ms bat.bing.com; img-src * data:; worker-src 'self'; form-action 'self' www.facebook.com connect.facebook.net; frame-src 'self' www.facebook.com staticxx.facebook.com connect.facebook.net *.doubleclick.net www.google.com www.googletagmanager.com player.vimeo.com www.youtube-nocookie.com www.podbean.com w.soundcloud.com www.scribd.com online.fliphtml5.com www.mixcloud.com www.soundtier.com sibautomation.com widget.packeta.com static.posta.sk; object-src 'none'; default-src 'self' blob:; media-src static.artforum.sk; connect-src * 'unsafe-eval' 'unsafe-inline' 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.yotpo.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.twitter.com *.typekit.net *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.syfpos.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.yotpo.com *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com syf.demdex.net *.syfpos.com *.syf.com *.twitter.com *.google.com *.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.gstatic.com *.googleusercontent.com data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.affirm.com *.affirm.ca *.facebook.com *.yotpo.com https://scontent.cdninstagram.com *.meetanshi.com https://meetanshi.com/media/logo.png www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js apis.google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.yotpo.com s7.addthis.com *.meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com m.addthis.com z.moatads.com *.addthisedge.com graph.facebook.com widgets.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com maxcdn.bootstrapcdn.com *.yotpo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.syfpos.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.yotpo.com ekr.zdassets.com/ https://graph.instagram.com *.meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net *.cloudflare.com *.twitter.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.moesif.com; script-src 'self' 'unsafe-inline' *.moesif.com *.unpkg.com *.jsdelivr.net *.auth0.com *.datadoghq.com *.amplitude.com *.unlayer.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.facebook.net *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hubspot.com *.hsappstatic.net *.apollo.io; script-src-elem 'self' 'unsafe-inline' *.moesif.com *.auth0.com *.hscollectedform.net *.hubspot.com *.hs-scripts.com *.facebook.net *.clarity.ms *.googletagmanager.com *.unpkg.com *.jsdelivr.net; script-src-attr 'unsafe-inline'; style-src 'self' *.moesif.com 'unsafe-inline' *.unlayer.com *.googletagmanager.com; style-src-elem 'self' 'unsafe-inline' *.moesif.com *.jsdelivr.net unpkg.com; style-src-attr 'unsafe-inline'; img-src 'self' data: *.moesif.com *.auth0.com blob: *.datadoghq.com *.amplitude.com *.wp.com *.unlayer.com *.gravatar.com *.mapbox.com *.google-analytics.com *.googleusercontent.com *.googletagmanager.com *.googleleadservices.com *.hsappstatic.net *.hs-banner.com *.hsforms.com *.facebook.net *.hubspot.com *.doubleclick.net; connect-src 'self' *.moesif.net *.moesif.com *.auth0.com *.datadoghq.com *.amplitude.com browser-intake-datadoghq.com *.unlayer.com *.clarity.com *.clarity.ms *.google-analytics.com *.google.com *.googletagmanager.com *.googleleadservices.com *.google.ca *.doubleclick.net *.aplo-evnt.com aplo-evnt.com *.facebook.net *.facebook.com *.hubspot.com *.hscollectedforms.net *.hs-banner.com *.statuspage.io; font-src 'self' data: *.moesif.com moz-extension: *.unlayer.com *.googleapis.com *.gstatic.com; frame-src 'self' *.moesif.com *.doubleclick.net *.hubspot.com *.facebook.com *.auth0.com *.unlayer.com *.googletagmanager.com; media-src 'self' data: *.moesif.com; worker-src 'self' blob: *.moesif.com *.unlayer.com; object-src 'none'; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub5216f5ae0690200e71eff84be3b1303a&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aprod 1 font-src *.gstatic.com 'self' data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: cenuklubs.lv data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.cookie-script.com *.gstatic.com *.googleapis.com *.google.com data: *.jquery.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com t.elasticsuite.io *.google-analytics.com *.cookie-script.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; frame-src https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.adobe.com *.googleapis.com data: *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com *.adobedtm.com hcaptcha.com *.hcaptcha.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.weltpixel.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com *.google.com https://www.google.co.in *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com https://script.crazyegg.com https://bat.bing.com https://www.facebook.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.magento-datasolutions.com *.magento-ds.com *.typekit.net google.com *.google.com http://www.googleadservices.com http://www.google-analytics.com *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://static.hotjar.com https://script.crazyegg.com http://script.crazyegg.com/ hcaptcha.com *.hcaptcha.com js.hcaptcha.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.google.com *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com https://script.crazyegg.com hcaptcha.com *.hcaptcha.com https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.google.com *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com https://script.crazyegg.com https://static.zdassets.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.paypal.com google.com *.google.com wss://widget-mediator.zopim.com https://metrics.hotjar.io/ *.klaviyo.com https://embedsocial.com *.zdassets.com *.bing.com *.cloudfront.net *.orthomed.ca *.hotjar.com *.crazyegg.com *.zendesk.com *.zopim.com https://script.crazyegg.com wss://ws.hotjar.com https://content.hotjar.io *.adobe.com hcaptcha.com *.hcaptcha.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' googletagmanager.com google-analytics.com googletagservices.com adservice.google.nl adservice.google.com www.googletagservices.com securepubads.g.doubleclick.net tpc.googlesyndication.com static.hotjar.com script.hotjar.com stats.nhg.org stats.henw.org stats.thuisarts.nl connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; object-src 'self'; style-src 'self' 'unsafe-inline' p.typekit.net use.typekit.com fonts.googleapis.com fast.fonts.net; img-src * data:; media-src 'self' *.nhg.org; frame-src 'self' 'unsafe-inline' googleads.g.doubleclick.net adservice.google.nl *.safeframe.googlesyndication.com tpc.googlesyndication.com google.com app.springcast.fm securepubads.g.doubleclick.net https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptch; frame-ancestors 'self' *.prescriptor.nl; child-src 'self'; font-src 'self' use.typekit.com fonts.googleapis.com fonts.gstatic.com fast.fonts.net; connect-src 'self' securepubads.g.doubleclick.net pagead2.googlesyndication.com google-analytics.com stats.g.doubleclick.net stats.henw.org stats.nhg.org stats.thuisarts.nl *.hotjar.io fast.fonts.net; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src https: data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src https: wss:; report-uri https://almexx.report-uri.io/r/default/csp/reportOnly 1 base-uri 'self'; default-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://plausible.io; connect-src 'self' https://plausible.io https://statuspal.io; frame-src 'self' https://iframe.mediadelivery.net https://www.youtube.com; form-action 'self' https://www.activityinfo.org; report-uri /app/csp-violation; 1 default-src 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.consentmanager.net https://delivery.consentmanager.net https://*.cookiebot.com https://*.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.be https://*.google.nl https://*.google.ch https://*.googletagmanager.com https://*.gstatic.com https://www.youtube.com https://*.youtube.com https://*.lndo.site https://*.mobiel.de mobielfrontend.projektserver.org https://*.westfalenfahrplan.de https://*.stadtwerke-bielefeld.de https://*.bielefeld.de https://hcaptcha.com https://www.google-analytics.com https://www.googleadservices.com https://connect.facebook.net https://www.facebook.com ; img-src 'self' data: https://*.analytics.google.com https://*.consentmanager.net https://*.cookiebot.com https://*.doubleclick.net https://*.google-analytics.com https://google.com https://*.google.com https://*.google.de https://*.google.be https://*.google.nl https://*.google.ch https://*.googleapis.com https://*.googletagmanager.com https://*.gstatic.com https://*.youtube.com https://*.mobiel.de mobielfrontend.projektserver.org https://*.westfalenfahrplan.de https://*.stadtwerke-bielefeld.de https://*.bielefeld.de https://*.tile.openstreetmap.org https://www.googleadservices.com https://*.ytimg.com https://www.facebook.com ; connect-src 'self' https://*.analytics.google.com https://*.consentmanager.net https://*.cookiebot.com https://*.doubleclick.net https://*.google-analytics.com https://google.com https://*.google.com https://*.google.de https://*.google.be https://*.google.nl https://*.google.ch https://*.googletagmanager.com https://*.mobiel.de mobielfrontend.projektserver.org https://*.westfalenfahrplan.de https://*.stadtwerke-bielefeld.de https://*.bielefeld.de https://www.googleadservices.com https://connect.facebook.net https://www.facebook.com ; frame-src 'self' https://*.cookiebot.com https://*.consentmanager.net https://*.doubleclick.net https://*.youtube.com https://player.vimeo.com https://*.youtube-nocookie.com https://google.com https://*.google.com https://*.google.de https://*.google.be https://*.google.nl https://*.google.ch https://*.googletagmanager.com https://*.mobiel.de https://westfalenfahrplan.de https://*.westfalenfahrplan.de https://*.bielefeld.de https://germany.nextbike.net https://connect.facebook.net https://www.facebook.com ; style-src 'unsafe-inline' https:; font-src 'self' data:; report-uri /_cspreports 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com https://*.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.googleapis.com maps.gstatic.com https://images.unsplash.com *.googleapis.com https://belco-prod.s3-eu-central-1.amazonaws.com *.google.nl *.disposablediscounter.nl *.bing.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com disposablediscounter.nl *.cookiebot.com imagedelivery.net *.belco.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.belco.io *.belco.io *.bing.com *.cloudfront.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com *.avada.io *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.convertexperiments.com *.hotjar.com *.sgmntfy.com *.cookiebot.com *.cookiebot.co *.segmentify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.googleapis.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com *.multisafepay.com assets.braintreegateway.com *.segmentify.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com wss://chat.belco.io https://cdn.belco.io *.belco.io *.klaviyo.com *.bing.com *.cloudfront.net *.doubleclick.net *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.hotjar.io gandalf-eu.segmentify.com *.convertexperiments.com *.hotjar.com wss://ws.hotjar.com *.google-analytics.com *.cookiebot.com *.google.nl *.disposablediscounter.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://climate.stripe.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://sales-live-chat.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com https://y4pfttj91h-1.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-2.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-3.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-dsn.algolia.net/1/indexes/mkt_partners/query https://tax-connectors.stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://climate.stripe.com https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://checkout.stripe.dev https://support-conversations.stripe.com https://b.stripecdn.com https://checkout.stripe.com https://crypto-js.stripe.com https://js.stripe.com https://sales-live-chat.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com https://stripe-camo.global.ssl.fastly.net 'self'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; script-src https://b.stripecdn.com https://crypto-js.stripe.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src 'none'; report-uri https://q.stripe.com/csp-violation?q=FiKcpJOK7ksKyNyIDAC6KBYSKE3VIzSeTdRIK560pm2wNPAZEKm1WsktkUvSWL4%3D 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.in/api/csp-report; report-to csp-endpoint 1 report-uri /csp-violation-report;default-src 'self';base-uri 'self';script-src 'self' 'unsafe-eval' https://assets.ymshub.com https://www.datadoghq-browser-agent.com https://cdn.jsdelivr.net https://cdn.datatables.net https://kit.fontawesome.com https://cdnjs.cloudflare.com https://canvasjs.com https://cdn.canvasjs.com https://www.googletagmanager.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob: 'nonce-XlqAu2aKDAx9prDsPJehTIdEdms6AGzsjkrNoQSd';style-src 'self' 'unsafe-inline' https://assets.ymshub.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdn.datatables.net https://ka-p.fontawesome.com https://fonts.bunny.net;font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net https://*.fontawesome.com https://fonts.bunny.net data:;img-src 'self' https://assets.ymshub.com https://yms-client-storage-production.s3.us-east-2.amazonaws.com https://yms-client-storage-production.s3.us-west-2.amazonaws.com https://yms-client-storage-production.s3.amazonaws.com https://yms-client-storage-production-us-east-2.s3.us-east-2.amazonaws.com https://*.googleapis.com https://*.gstatic.com *.google.com blob: data: https://ymshub-assets.s3.amazonaws.com;connect-src 'self' wss://ws.ymshub.com:443 https://cdn.jsdelivr.net https://browser-intake-datadoghq.com https://ka-p.fontawesome.com https://*.googleapis.com *.google.com https://*.gstatic.com https://*.google-analytics.com data: blob:;frame-src 'self' https://www.googletagmanager.com *.google.com;form-action 'self';object-src 'none';media-src 'self';manifest-src 'self';worker-src 'self' blob: 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://consent.ory.com https://fast.wistia.com https://fast.wistia.net https://distillery.wistia.com https://js.hsforms.net; script-src-elem blob: 'self' 'unsafe-inline' https://vercel.live https://fast.wistia.com https://fast.wistia.net https://js.hsforms.net https://static.hsappstatic.net https://js-eu1.hs-banner.com https://js-eu1.hs-analytics.net https://js-eu1.hsadspixel.net https://js-eu1.usemessages.com https://googleads.g.doubleclick.net https://js.zi-scripts.com https://*.hs-scripts.com https://script.crazyegg.com https://www.googletagmanager.com https://sqa-web.ory.com https://static.reo.dev https://s.ory.com https://consent.ory.com https://www.redditstatic.com https://core.sanity-cdn.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fast.wistia.com https://fast.wistia.net https://js.hsforms.net https://static.hsappstatic.net https://cdn.jsdelivr.net; img-src 'self' data: blob: https:; connect-src 'self' https://stats.g.doubleclick.net https://ws.zoominfo.com https://*.hubapi.com https://*.hubspot.com https://static.hsappstatic.net https://analytics.google.com https://js.zi-scripts.com https://script.crazyegg.com https://conversions-config.reddit.com https://www.redditstatic.com https://pixel-config.reddit.com https://www.google.com https://api.reo.dev https://project.console.ory.sh https://api.console.ory.sh https://sqa-web.ory.com https://consent.ory.com https://fast.wistia.net https://fast.wistia.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://forms-eu1.hsforms.com https://33xluxe1.api.sanity.io https://33xluxe1.apicdn.sanity.io https://cdn.sanity.io https://cdn.jsdelivr.net wss://33xluxe1.api.sanity.io https://pipedream.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io https://raw.githubusercontent.com https://api.github.com https://www.googleadservices.com; font-src 'self' data: https://fast.wistia.net https://cdn.jsdelivr.net; worker-src blob: 'self'; media-src 'self' https://embed-ssl.wistia.com blob:; frame-src 'self' https://*.hubspot.com https://vercel.live https://app-eu1.hubspot.com https://www.googletagmanager.com https://consent.ory.com https://sqa-web.ory.com https://fast.wistia.com https://fast.wistia.net https://embed-ssl.wistia.com https://www.youtube.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://app-eu1.hubspot.com https://www.googletagmanager.com; upgrade-insecure-requests; report-uri https://o481709.ingest.us.sentry.io/api/4510205854482432/security/?sentry_key=62382f4c47aefd04c9afd518f417b97a; report-to csp-endpoint; 1 font-src *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.sandbox.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.iubenda.com *.google.com/ https://www.youtube.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.magezon.com *.iubenda.com https://meetanshi.com/media/logo.png https://api.mapbox.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.iubenda.com *.avada.io *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.iubenda.com https://get.geojs.io *.avada.io autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.ragingstallion.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.ragingstallion.com join.gammasecure.com; script-src 'self' *.ragingstallion.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.ragingstallion.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: *.oct8ne.com https://oct8necdneu.azureedge.net https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors localhost:* *.motive.co 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cdn.ealyx.tech https://player.vimeo.com https://www.youtube-nocookie.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://consentcdn.cookiebot.com https://www.salesmanago.pl https://app3.salesmanago.pl https://www.salesmanago.com https://backoffice-eu.oct8ne.com https://sandbox.sequrapi.com https://live.sequrapi.com https://eu1-search.doofinder.com https://eu1-layer.doofinder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://cdn.ealyx.tech https://maps.gstatic.com https://maps.googleapis.com https://images.unsplash.com blob: https://firebasestorage.googleapis.com *.motive.co *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://www.google.com https://www.google.es https://oct8necdneu.azureedge.net https://www.bazarelregalo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com self https://cdn.ealyx.tech https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/ *.avada.io *.motive.co https://player.vimeo.com https://www.youtube.com *.oct8ne.com *.omniwallet.cloud sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com http://media.flixfacts.com https://prod.flixgvid.flix360.io http://media.flixcar.com https://cdn.doofinder.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://static-eu.oct8ne.com https://sandbox.sequrapi.com https://live.sequrapi.com https://eu1-search.doofinder.com https://app3.salesmanago.pl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.ealyx.tech *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com http://media.flixcar.com https://cdn.doofinder.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://api.ealyx.tech https://cdn.ealyx.tech https://maps.googleapis.com https://get.geojs.io *.avada.io *.motive.co https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.oct8ne.com *.omniwallet.cloud sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.youtube.com https://youtu.be https://frontal-eu.oct8ne.com https://js-agent.newrelic.com https://bam.nr-data.net https://eu1-layer.doofinder.com wss://eu1-layer.doofinder.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self'; frame-ancestors 'self'; report-uri https://account-subdomain.uriports.com/reports/report; report-to default 1 frame-ancestors 'self' http://pudtoday http://prointnet; frame-src 'self' *.chelanpud.org chelanpud.jotform.com; form-action 'self'; default-src 'self' fonts.googleapis.com fonts.gstatic.com ajax.googleapis.com www.google-analytics.com *.google.com; img-src 'self' data: *.facebook.com *.google.com *.doubleclick.net; style-src 'self' *.mailerlite.com fonts.googleapis.com 'unsafe-inline'; script-src 'self' form.chelanpud.org connect.facebook.net siteimproveanalytics.com *.mailerlite.com *.google.com ajax.googleapis.com www.googletagmanager.com js.adsrvr.org 'unsafe-inline' 'unsafe-eval'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-hashes' 'strict-dynamic' 'report-sample' https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://static.addtoany.com https://use.fontawesome.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' 'report-sample' https://www.googletagmanager.com https://www.google-analytics.com https://script.crazyegg.com https://snap.licdn.com https://static.hotjar.com https://googleads.g.doubleclick.net https://browser-update.org https://rtp-static.marketo.com https://sjrtp3.marketo.com https://script.hotjar.com https://sjrtp3-cdn.marketo.com https://vidassets.terminus.services https://munchkin.marketo.net https://extend.vimeocdn.com https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://static.addtoany.com https://use.fontawesome.com platform.instagram.com platform.twitter.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' 'report-sample' https://fonts.googleapis.com cdnjs.cloudflare.com https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline' 'unsafe-hashes' 'report-sample'; style-src-elem 'self' 'unsafe-inline' 'report-sample' https://fonts.googleapis.com https://use.fontawesome.com https://rtp-static.marketo.com cdnjs.cloudflare.com https://cdnjs.cloudflare.com; frame-ancestors 'self' 1 default-src 'self'; child-src blob: https://*; connect-src 'self' blob: https://d8ejoa1fys2rk.cloudfront.net https://static.bynder.cloud https://sentry10.bynder.cloud https://api2.amplitude.com https://*.google-analytics.com https://stats.g.doubleclick.net https://*.amazonaws.com https://fast.appcues.com https://api.appcues.com https://api.appcues.net wss://api.appcues.net https://*.courier.com wss://*.courier.com https://apiv2.webdamdb.com/oauth2/token https://cmp.osano.com https://consent.api.osano.com https://tattle.api.osano.com https://disclosure.api.osano.com https://api.eu1.honeycomb.io https://heapanalytics.com https://*.heapanalytics.com https://*.heap-api.com; font-src https://* data: ; img-src https://* data: blob:; media-src https://*; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://d8ejoa1fys2rk.cloudfront.net https://static.bynder.cloud https://www.googletagmanager.com https://www.google-analytics.com https://js.hs-analytics.net https://fast.appcues.com https://browser.sentry-cdn.com https://bynder-static.s3.amazonaws.com https://cmp.osano.com https://consent.api.osano.com https://tattle.api.osano.com https://disclosure.api.osano.com https://heapanalytics.com https://*.heapanalytics.com https://*.heap-api.com; style-src 'self' 'unsafe-inline' https://d8ejoa1fys2rk.cloudfront.net https://static.bynder.cloud https://fonts.googleapis.com https://bynder-static.s3.amazonaws.com https://fast.appcues.com https://cmp.osano.com https://consent.api.osano.com https://tattle.api.osano.com https://disclosure.api.osano.com https://heapanalytics.com https://*.heapanalytics.com https://*.heap-api.com; worker-src 'self' blob:; report-uri https://sentry10.bynder.cloud/api/1817/security/?sentry_key=638cfd1ab10c78c179140416b9893c0e 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.sirv.com fonts.gstatic.com *.typekit.net hobgoblin.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com/tr/ *.googlesyndication.com *.tiktok.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com hobgoblin.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com hobgoblin.com 'self'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com www.google.com/recaptcha/ www.googletagmanager.com *.trustpilot.com www.xtento.com hobgoblin.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.googleadservices.com www.google-analytics.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://firebasestorage.googleapis.com *.sirv.com *.youtube.com *.cookieyes.com https://dashboard.feedbucket.app stats.g.doubleclick.net www.google.com www.google.co.uk www.googletagmanager.com maps.gstatic.com/mapfiles/ https://s.ytimg.com bat.bing.com www.instagram.com cdn-cookieyes.com *.googleapis.com widget.trustpilot.com www.xtento.com cdn.xtento.com hobgoblin.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googleadservices.com www.google-analytics.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com *.avada.io *.sirv.com player.vimeo.com *.cookieyes.com cdn.feedbucket.app www.googletagmanager.com googleads.g.doubleclick.net/pagead/viewthroughconversion/ google.com/pagead/ maps.googleapis.com/maps/ maps.googleapis.com/maps-api-v3/ *.usersnap.com mc.us7.list-manage.com assets.pinterest.com bat.bing.com www.youtube.com polyfill.io *.algolia.net *.algolianet.com cdn-cookieyes.com log.cookieyes.com directory.cookieyes.com *.klarna.net *.googleapis.com *.trustpilot.com www.xtento.com cdn.xtento.com hobgoblin.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.sirv.com https://cdn.feedbucket.app fonts.googleapis.com *.typekit.net *.trustpilot.com hobgoblin.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.sirv.com blob: hobgoblin.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.google-analytics.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com www.facebook.com/tr/ *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com api.addressy.com https://get.geojs.io *.avada.io *.sirv.com vimeo.com *.youtube.com blob: *.cookieyes.com cdn-cookieyes.com dashboard.feedbucket.app cdn.feedbucket.app stats.g.doubleclick.net maps.googleapis.com/maps/ maps.googleapis.com/maps-api-v3/ www.instagram.com *.klarna.net *.googleapis.com widget.trustpilot.com hobgoblin.com 'self' 'unsafe-inline'; child-src hobgoblin.com http: https: blob: 'self' 'unsafe-inline'; default-src hobgoblin.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.multivlaai.nl data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.multivlaai.nl 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com https://www.paypal.com *.multivlaai.nl https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.googleapis.com *.google-analytics.com *.google.com *.google.nl *.google.be *.multivlaai.nl https://api.taggrs.io/ https://stats.g.doubleclick.net https://www.facebook.com https://bat.bing.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com *.gstatic.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.multivlaai.nl *.cookie-script.com bat.bing.com *.facebook.net *.clarity.ms http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.fluxmill.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.googleapis.com *.multivlaai.nl *.cookie-script.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com *.multivlaai.nl *.google.nl https://stats.g.doubleclick.net *.googlesyndication.com *.google-analytics.com https://bat.bing.net https://bat.bing.com *.clarity.ms https://consent.cookie-script.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/; report-to report-endpoint; 1 font-src maxcdn.bootstrapcdn.com *.hotjar.com *.hotjar.io *.gstatic.com *.facebook.com *.giosg.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com paytrail.com *.facebook.com *.giosg.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.hotjar.com *.hotjar.io www.facebook.com *.giosg.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.paytrail.com *.placeholder.com *.adnxs.com www.facebook.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.gstatic.com *.giosg.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn2.hubspot.net resources.paytrail.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.gstatic.com *.googletagmanager.com *.ccdc02.com *.hotjar.com *.hotjar.io www.facebook.com *.facebook.net *.giosg.com *.custobar.com connect.facebook.net graph.facebook.com business.facebook.com www.termsfeed.com https://api.unifaun.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.googleapis.com tagmanager.google.com *.facebook.com *.giosg.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.authorize.net *.hotjar.com *.hotjar.io wss://*.hotjar.com *.google-analytics.com stats.g.doubleclick.net www.facebook.com *.giosg.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.paytrail.com *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.bunny.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ https://www.youtube.com js.mollie.com https://www.googletagmanager.com https://www.paypal.com https://vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com https://www.mollie.com https://www.gstatic.com https://*.trustedshops.com https://zigarre-de.alterspruefung365.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.amazonaws.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com *.google.com/ js.mollie.com https://static-eu.payments-amazon.com https://*.braintreegateway.com https://integrations.etrusted.com https://www.google-analytics.com https://pay.google.com https://www.google.com/recaptcha https://www.googletagmanager.com https://cdn.klarna.com https://*.paypal.com https://widgets.trustedshops.com https://zigarre-de.alterspruefung365.de js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.sendcloud.sc *.jsdelivr.net https://widgets-qa.trustedshops.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com https://*.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://*.klaviyo.com https://*.trustedshops.com https://zigarre-de.alterspruefung365.de unsafe-inline assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io https://payments-eu.amazon.com https://payments.amazon.de https://*.braintreegateway.com https://integrations.etrusted.com https://cdn.klarna.com https://*.klaviyo.com https://d.ratepay.com https://secure.pay1.de https://zigarre-de.alterspruefung365.de api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-to https://c27a0dbdb777b25e6be808015953fd29.report-uri.com/r/d/csp/wizard 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com https://bat.bing.com https://www.redditstatic.com https://origin.acuityplatform.com https://e.acuityplatform.com https://secure.adnxs.com https://www.googleadservices.com https://js-agent.newrelic.com https://bam.nr-data.net https://pixel.mathtag.com https://ums.acuityplatform.com https://connect.facebook.net https://tpc.googlesyndication.com https://tr.contextweb.com https://bh.contextweb.com https://epidiolex-medinfo-c.uat.v3.chat.conversationhealth.com https://epidiolex-medinfo-c.prod.v3.chat.conversationhealth.com https://trc.lhmos.com https://match.deepintent.com https://cdn.cookielaw.org https://eq5trck.com https://cai.conversationhealth.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://moderate.cleantalk.org https://polyfill.io https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com https://bat.bing.com https://www.redditstatic.com https://origin.acuityplatform.com https://e.acuityplatform.com https://secure.adnxs.com https://www.googleadservices.com https://js-agent.newrelic.com https://bam.nr-data.net https://pixel.mathtag.com https://ums.acuityplatform.com https://connect.facebook.net https://tpc.googlesyndication.com https://tr.contextweb.com https://bh.contextweb.com https://epidiolex-medinfo-c.uat.v3.chat.conversationhealth.com https://epidiolex-medinfo-c.prod.v3.chat.conversationhealth.com https://trc.lhmos.com https://match.deepintent.com https://cdn.cookielaw.org https://eq5trck.com https://cai.conversationhealth.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://moderate.cleantalk.org https://polyfill.io https://unpkg.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net http://hello.myfonts.net https://www.googletagmanager.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net http://hello.myfonts.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; frame-ancestors 'self' 1 font-src *.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com landofcoder.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com https://js.klevu.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ maxcdn.bootstrapcdn.com api.mapy.cz data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com https://www.google.com/recaptcha/ https://*.doubleclick.net https://ehub.cz https://*.gls-czech.cz https://*.packeta.com/ https://*.heureka.cz/ https://*.heureka.sk/ https://tm.vitalpoint.cz https://*.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com https://firebasestorage.googleapis.com https://*.ppl.cz https://*.seznam.cz https://im9.cz https://*.google.cz https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.facebook.com https://*.g.doubleclick.net https://*.mailkit.eu https://ehub.cz https://*.heureka.cz/ https://*.heureka.sk/ https://*.zbozi.cz https://*.bing.com https://*.clarity.ms/ https://tm.vitalpoint.cz https://bat.bing.net https://bat.bing.com https://*.analytics.google.com flagpedia.net www.ppl.cz api.mapy.cz data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.avada.io https://*.googletagmanager.com https://*.smartlook.com https://*.smartlook.cloud https://*.smartform.cz https://*.heureka.cz https://*.mailkit.eu https://*.google.cz/ https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.seznam.cz https://*.dognet.sk https://ehub.cz https://*.facebook.net https://*.googleadservices.com https://*.google-analytics.com https://*.googleapis.com https://*.packeta.com/ https://*.zbozi.cz/ https://im9.cz/ https://*.clarity.ms/ https://bat.bing.com/ https://bat.bing.net/ https://cdn.heureka.group/ https://*.heureka.sk/ https://tm.vitalpoint.cz https://*.googlesyndication.com *.gstatic.com maps.googleapis.com www.ppl.cz api.mapy.cz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ https://client.smartform.cz/ https://im9.cz maxcdn.bootstrapcdn.com *.gstatic.com api.mapy.cz 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io https://*.ppl.cz https://*.smartlook.com https://*.smartlook.cloud https://*.mailkit.eu https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google.com https://*.g.doubleclick.net https://ehub.cz https://widget.packeta.com https://*.clarity.ms https://*.heureka.group https://bat.bing.net https://tm.vitalpoint.cz https://*.seznam.cz https://*.googlesyndication.com https://bat.bing.com www.gstatic.com maps.googleapis.com api.mapy.cz api.dhl.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.gstatic.com fonts.gstatic.com https://cdnjs.cloudflare.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com api.payplug.com secure.payplug.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net maps.googleapis.com www.gstatic.com www.google.com https://cdnjs.cloudflare.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com api.payplug.com *.hsforms.net *.hsforms.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.addtoany.com fonts.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://www.google-analytics.com ekr.zdassets.com/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com http://dpm.demdex.net maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https: web106.reachmee.com www.skuld.com; frame-ancestors 'self' https: www.skuld.com skuld.com; 1 frame-src 'self'; report-uri https://secure.acsevents.org/site/XFrameViolation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.flixcar.com *.flixfacts.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addthis.com *.sandbox.paypal.com *.yotpo.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.flixcar.com *.flix360.io *.flix360.com *.etrustmark.rs https://www.mollie.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.drtechno.rs/static/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addthis.com *.sandbox.paypal.com *.yotpo.com *.loadbee.com *.flixfacts.com *.cnetcontent.com *.flixcar.com *.etrustmark.rs *.safesigned.com js.mollie.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com https://fonts.googleapis.com *.drtechno.rs/static/ *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.flixcar.com *.flixfacts.com *.safesigned.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.flixcar.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.portaldepagosholcim.sdd.com.ar *.portaldepagosholcim.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.salesmanago.pl *.salesmanago.es *.salesmanago.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://testcheckout.redserfinsa.com:8087/ https://www.serfinsacheckout.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://testcheckout.redserfinsa.com:8087/ https://www.serfinsacheckout.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src smct.co *.smct.co smct.io *.smct.io *.amazonaws.com maxcdn.bootstrapcdn.com 'unsafe-inline' data: *.bootstrapcdn.com https://widgets.trustedshops.com fonts.gstatic.com *.gstatic.com 'self' data: https://*.sovendus.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com/ *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de smct.co *.smct.co smct.io *.smct.io *.amazonaws.com d2d7do8qaecbru.cloudfront.net *.google.com *.adcell.com *.mollie.com www.xtento.com js.mollie.com *.weltpixel.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.bing.com *.usercentrics.eu *.trustedshops.com *.etrusted.com *.google.com *.google.at *.google.de *.static-eu.payments-amazon.com static-eu.payments-amazon.com *.googletagmanager.com *.adcell.com *.ad4m.at *.doubleclick.net x.bidswitch.net dsum-sec.casalemedia.com csync.loopme.me r.adserver01.de *.adition.com secure.adnxs.com rtb-csync.smartadserver.com usync.vrtcal.com s.ad.smaato.net inv-nets.admixer.net *.adform.net pixel.rubiconproject.com us-u.openx.net s.pubmine.com ad.yieldlab.net sync-eu.connectad.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com https://www.mollie.com 'self' data: https://*.sovendus.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de smct.co *.smct.co smct.io *.smct.io *.amazonaws.com pix.hyj.mobi *.bing.com *.usercentrics.eu *.amazon.com *.trustedshops.com *.braintreegateway.com *.gstatic.com *.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.adcell.com *.ad-srv.net *.ad4m.at ad4m.at https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com js.mollie.com https://*.sovendus.com https://www.sovopt.com https://static.sovopt.com https://www.getback.ch https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com *.etrusted.com *.cloudflare.com *.fontawesome.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googleapis.com *.gstatic.com https://static.getback.ch https://*.sovendus.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.bing.com *.ad4m.at *.usercentrics.eu *.doubleclick.net *.google-analytics.com *.google.com *.google.at *.adcell.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-jCfkIN5iXcCKphRsq4_toQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.clarity.ms c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com.co *.google.com *.googletagmanager.com https://maps.googleapis.com https://maps.gstatic.com https://www.googletagmanager.com https://*.clarity.ms *.bam.nr-data.net https://bam.nr-data.net https://h.online-metrix.net/ *.online-metrix.net https://js-agent.newrelic.com/ https://maps.googleapis.com/ https://stats.g.doubleclick.net/ *.pingdom.net widgets.pau.zone www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.rum-static.pingdom.net https://www.google-analytics.com/ *.google.com *.googletagmanager.com *.googleadservices.com *.connect.facebook.net *.stats.g.doubleclick.net *.rum-collector-2.pingdom.net *.amazonaws.com https://maps.googleapis.com https://www.googletagmanager.com www.clarity.ms https://www.clarity.ms https://*.clarity.ms *.js-agent.newrelic.com *.bam.nr-data.net https://bam.nr-data.net *.onesignal.com https://onesignal.com/ https://h.online-metrix.net/ *.online-metrix.net https://js-agent.newrelic.com/ https://bam.nr-data.net/ https://*.cardinalcommerce.com/ *.pingdom.net widgets.pau.zone js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.fontawesome.com *.cloudflare.com https://fonts.googleapis.com https://*.clarity.ms unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.rum-static.pingdom.net *.google-analytics.com *.google.com *.static.klaviyo.com *.stats.g.doubleclick.net *.connect.facebook.net *.rum-collector-2.pingdom.net https://www.googletagmanager.com www.clarity.ms https://*.clarity.ms *.bam.nr-data.net https://bam.nr-data.net https://h.online-metrix.net/ *.online-metrix.net https://js-agent.newrelic.com/ https://maps.googleapis.com/ https://stats.g.doubleclick.net/ *.pingdom.net *.smallshi.com:1442/ *.smallshi.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src https://*.clarity.ms assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.rum-static.pingdom.net *.connect.facebook.net *.stats.g.doubleclick.net *.rum-collector-2.pingdom.net https://*.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://*.clarity.ms 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.usercentrics.eu 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://www.loewen.de https://maps.gstatic.com https://maps.google.com https://maps.googleapis.com https://www.youtube.com https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://www.facebook.com https://*.usercentrics.eu https://medien.loewen.de https://medien.loewen-kundenportal.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://vimeo.com https://www.googletagmanager.com https://*.usercentrics.eu; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.usercentrics.eu 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org https://maps.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.usercentrics.eu; font-src 'self' https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' 'report-sample'; script-src-elem 'self' 'sha256-kmB83Qlmak1+ekHFk+S5GfHhbvJrD6n2YITJgFDEWWQ=' https://maps.google.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://www.facebook.com https://*.usercentrics.eu 'report-sample'; report-uri https://www.loewen.de/gruppe/@http-reporting?csp=report&requestTime=1765942837042406&requestHash=d7de5b7c9b447d012eda4835d055d509ba5793dd 1 font-src *.klarnacdn.net *.fontawesome.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.klarnaevt.com *.google.de *.klarna.com *.doubleclick.net secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net *.google.de *.alothemes.com *.magepow.com https://api.mapbox.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.klarnaevt.com *.klarnacdn.net *.klarnaservices.com *.google.de *.doubleclick.net *.alothemes.com *.magepow.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.fontawesome.com *.alothemes.com *.magepow.com d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.doubleclick.net *.google.de *.google.com *.google-analytics.com *.alothemes.com *.magepow.com payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com mysticlabsd8.com maxcdn.bootstrapcdn.com data *.fontawesome.com https://cdnjs.cloudflare.com *.cloudflare.com *.popt.in *.amazonaws.com *.on.aws *.cloudfront.net use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net https://plumrocket.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com whitepages.site x.adroll.com ad.ipredictive.com tags.crwdcntrl.net www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net https://plumrocket.com www.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.sharethis.com mysticlabsd8.com alb.reddit.com www.facebook.com d.adroll.com image2.pubmatic.com pixel.rubiconproject.com x.bidswitch.net eb2.3lift.com dsum-sec.casalemedia.com ml314.com pixel.tapad.com us-u.openx.net x.adroll.com sync.taboola.com sync.outbrain.com ib.adnxs.com pixel.sitescout.com segment.prod.bidr.io idsync.reson8.com p.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://meetanshi.com *.popt.in *.cloudfront.net www.sourceknowledge.com upx.provenpixel.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.sharethis.com unsafe-inline unsafe-eval mysticlabsd8.com static.klaviyo.com static-tracking.klaviyo.com cdn.popt.in s.adroll.com amplify.outbrain.com ruler.nyltx.com assets.mantisadnetwork.com edge.fullstory.com sc-static.net www.redditstatic.com unpkg.com cdnjs.cloudflare.com acsbapp.com www.clarity.ms wave.outbrain.com aggle.net analytics.nyltx.com d.adroll.com js.ipredictive.com connect.facebook.net rs.fullstory.com cdn.aggle.net tags.crwdcntrl.net upx.provenpixel.com www.google.com www.gstatic.com cdn-widgetsrepository.yotpo.com js.authorize.net jstest.authorize.net static-forms.klaviyo.com fast.a.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com www.facebook.com graph.facebook.com business.facebook.com code.jquery.com *.authorize.net *.popt.in *.cloudflare.com *.jsdelivr.net sandbox-assets.secure.checkout.visa.com www.sourceknowledge.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com unsafe-inline mysticlabsd8.com maxcdn.bootstrapcdn.com static.klaviyo.com https://static.klaviyo.com cdnjs.cloudflare.com *.popt.in *.cloudflare.com *.jsdelivr.net *.on.aws *.amazonaws.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com static-forms.klaviyo.com fast.a.klaviyo.com a.klaviyo.com amplify.outbrain.com edge.fullstory.com pixel-config.reddit.com www.redditstatic.com mysticlabsd8.com paid.outbrain.com cdn.acsbapp.com rs.fullstory.com analytics.mantis.marketing d.adroll.com display.popt.in i.clarity.ms x.adroll.com herb.aggle.net bcp.crwdcntrl.net js.authorize.net jstest.authorize.net telemetrics.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com https://www.google-analytics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cloudfront.net *.cloudflare.com *.popt.in yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src analytics.nyltx.com mysticlabsd8.com i.clarity.ms rs.fullstory.com tr6.snapchat.com commerce.adobedc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors https://istobal--partial.sandbox.my.site.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://istobal--partial.sandbox.my.site.com https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://istobal.com https://l.sharethis.com https://ws.sharethis.com https://imgsct.cookiebot.com https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://istobal.com https://go.istobal.com https://ws.sharethis.com https://l.sharethis.com https://ipinfo.io https://istobal--partial.sandbox.my.salesforce-scrt.com https://istobal--partial.sandbox.my.site.com https://istobal.my.site.com https://consent.cookiebot.com https://consentcdn.cookiebot.com *.avada.io https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://go.istobal.com https://static.fliphtml5.com https://ws.sharethis.com https://istobal--partial.sandbox.my.salesforce-scrt.com https://istobal--partial.sandbox.my.site.com/ https://istobal.my.site.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://l.sharethis.com https://online.fliphtml5.com https://istobal--partial.sandbox.my.salesforce-scrt.com https://istobal--partial.sandbox.my.site.com https://istobal.my.salesforce-scrt.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.vivapayments.com *.cardlink.gr *.eurocommerce.gr *.iris.dias.com.gr *.test-iris.dias.com.gr *.piraeusbank.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.vivapayments.com *.disqus.com *.avada.io *.shopify.com https://cdnjs.cloudflare.com maps.googleapis.com *.piraeusbank.gr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com https://www.googletagmanager.com/ *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net fonts.googleapis.com downloads.mailchimp.com maxcdn.bootstrapcdn.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.vimeocdn.com s.ytimg.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net cdn-scripts.signifyd.com www.youtube.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.avada.io *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://accounts.google.com https://*.google.com https://*.hotjar.com https://vars.hotjar.com https://www.facebook.com https://*.criteo.com https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com public.montonio.com https://www.google.com https://www.google.ee https://www.google-analytics.com rx.sudameapteek.ee data: http: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com https://connect.facebook.net graph.facebook.com business.facebook.com public.montonio.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com rx.sudameapteek.ee http: https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com rx.sudameapteek.ee http: https: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://stats.g.doubleclick.net rx.sudameapteek.ee http: https: wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' boutiquedassi.com.br *.boutiquedassi.com.br wake-components.fbitsstatic.net boutiquedassi.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.mercadopago.com api.mercadopago.com secure.mlstatic.com *.mlstatic.com *.mercadolibre.com gstatic.com *.gstatic.com *.boutiquedassi.com.br *.google.com googleads.g.doubleclick.net *.googleadservices.com *.fbits.net *.moip.com.br *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.amazonaws.com *.g.doubleclick.net signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.facebook.net *.facebook.com connect.facebook.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.egoi.site cdn-te.e-goi.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.mailbiz.one *.jsdelivr.net *.cloudfront.net d3eq1zq78ux3cv.cloudfront.net *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.google.com.br *.googleapis.com google.com.py google.it google.co.uk google.cl *.google.pt *.com.mx *.co.jp *.bonifiq.com.br widget.bonifiq.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.pagaleve.io *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.conectiva.io *.sunset.systems *.cartstack.com.br *.cartstack.com *.performa.ai *.cupom.social *.conectiva.app conectiva.io app.conectiva.io vm.conectiva.io conectiva.app api.performa.ai valid.performa.ai cartstack.com.br app.cartstack.com.br api.cartstack.com.br sunset.systems api.sunset.systems cupom.social app.cupom.social cdn.performa.ai *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.boutiquedassi.com.br boutiquedassi.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.fonts.bunny.net maxcdn.bootstrapcdn.com *.use.typekit.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.googletagmanager.com *.googletagmanager.com connect.facebook.net *.connect.facebook.net www.facebook.com *.facebook.com *.doubleclick.net/ recostream.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.pl *.google.pl *.google-analytics.com *.analytics.google.com *.ekomiapps.de *.amazonaws.com www.facebook.com *.facebook.com imgsct.cookiebot.com *.clarity.ms data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com snrcdn.net *.snrbox.com *.ekomiapps.de *.snrcdn.net connect.facebook.net *.connect.facebook.net www.facebook.com *.facebook.com clarity.ms *.clarity.ms *.cookiebot.com *.openwidget.com web-integration.recombee.com *.web-integration.recombee.com cdn.jsdelivr.net *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com recostream.com/ trustmate.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.snrcdn.net *.snrbox.com *.ekomiapps.de *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com snrcdn.net *.snrcdn.net *.snrbox.com *.ekomiapps.de *.google-analytics.com *.analytics.google.com connect.facebook.net *.connect.facebook.net www.facebook.com *.facebook.com doubleclick.net *.doubleclick.net tiktok.com *.tiktok.com clarity.ms *.clarity.ms *.googlesyndication.com *.cookiebot.com *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com api01.carpeto.pl api01.mazovia.de ws: recostream.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googletagmanager.com *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.newrelic.com *.nr-data.net fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com *.fontawesome.com 'self' data: *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.usercentrics.eu *.bing.com *.zdassets.com *.google.com *.google.gr *.clarity.ms/ *.haritidis.gr *.klarnacdn.net https://fonts.bunny.net *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.vivapayments.com *.zdassets.com *.facebook.com *.contactpigeon.com *.google.gr *.skroutz.gr >https://skroutza.skroutz.gr *.zopim.com *.moosend.com *.cloudflare.com td.doubleclick.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ widget-v3.boxnow.gr/ widget-v5.boxnow.cy *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com *.skroutz.gr >https://skroutza.skroutz.gr *.contactpigeon.com *.hotjar.com td.doubleclick.net widget-v3.boxnow.gr *.clarity.ms/ *.bing.com *.google.com/ *.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.zdassets.com https://trustmark.gr *.tiktok.com *.contactpigeon.com *.googleapis.com *.gstatic.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.skroutz.gr >https://skroutza.skroutz.gr *.moosend.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.io td.doubleclick.net *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.clarity.ms/ *.youtube.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com https://www.magezon.com *.designer-images.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.vivapayments.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: *.tiktok.com *.googletagmanager.com *.googleapis.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com *.newrelic.com *.nr-data.net *.paypal.com *.google.com/ *.hotjar.com *.fontawesome.com *.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.youtube.com *.skroutz.gr >https://skroutza.skroutz.gr *.cloudflare.com *.google.gr https://trustmark.gr/badge/dist/index.js https://static.adman.gr/adman.js https://greca.adman.gr cdn.omnicliq.com/ss.js *.clarity.ms/ *.bing.com *.debugbear.com *.haritidis.gr *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.stat-track.com polyfill.io *.moosend.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googletagmanager.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com *.newrelic.com *.nr-data.net *.fontawesome.com *.trustpilot.com cdn.jsdelivr.net *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.bing.com *.hotjar.com *.clarity.ms/ *.haritidis.gr *.klarnacdn.net https://fonts.bunny.net fonts.googleapis.com *.moosend.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' data: *.google.gr *.zopim.com *.skroutz.gr >https://skroutza.skroutz.gr *.moosend.com *.cloudflare.com *.youtube.com *.haritidis.gr 'self' 'unsafe-inline'; manifest-src *.haritidis.gr 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.haritidis.gr *.skroutz.gr >https://skroutza.skroutz.gr *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.tiktok.com *.contactpigeon.com *.paypal.com stats.g.doubleclick.net https://googleads.g.doubleclick.net/ *.zdassets.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.cloudflare.com https://pagead2.googlesyndication.com *.bing.com *.clarity.ms/ *.debugbear.com td.doubleclick.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=l3BVlrfvw2FBd3cJ4RkoS71BlUjHz3WTvorpc8EqE9E-1765934677-1.0.1.1-w7H0ZFQvzpZTmj9RwpIr2CGP1fUddgcX6VuzGzaAzERx4VoKfyrRG17yQ74KynVZcA4gnNvnFdDKqx8y3Rabvnd9L4PuWROQXb_QggAUFrFmKQdn1j7kBGmfjYHFlUafx0LlEXqa8S.x_MVnyixHG4vvxspBas76qDaoZvaymAWQPFknJtMATHsaiRQezhF5ict9mzAE1gbMk9eFFLSEtQ; report-to cf-ljyxdzidrafojdit 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' normatel.com.br *.normatel.com.br wake-components.fbitsstatic.net normatel.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br traycorp.paymee.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com googleadservices.com stats.g.doubleclick.net *.hotjar.com *.googleadservices.com *.g.doubleclick.net *.googletagmanager.com *.google-analytics.com *.googlesyndication.com google-analytics.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.smarthint.co *.sandbox.3dsecure.io *.3dsecure.io wake-commerce-scripts.omni.chat *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.normatel.com.br normatel.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 connect-src 'self' *.google-analytics.com ws: http://localhost:* https://localhost:*; default-src 'self'; font-src 'self'; frame-ancestors 'none'; img-src 'self' www.googletagmanager.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' www.googletagmanager.com *.google-analytics.com ajax.googleapis.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; 1 default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://analytics.tiktok.com https://*.in.applicationinsights.azure.com https://cdn-ukwest.onetrust.com https://*.googletagmanager.com https://*.google-analytics.com https://js.monitor.azure.com https://static.hotjar.com https://connect.facebook.net https://tracker.marinsm.com https://bat.bing.com https://tt.mbww.com https://www.tradedoubler.com https://secure.adnxs.com https://ade.googlesyndication.com https://jaishroff-org-help.freshchat.com https://script.hotjar.com https://googleads.g.doubleclick.net https://*.smct.io https://smct.co https://swrap.tradedoubler.com https://collect.bannercrowd.net https://*.bannercrowd.net https://*.marinsoftware.com https://*.tangoo.it; style-src 'self' 'unsafe-inline' 'self' 'unsafe-inline' https://fonts.googleapis.com https://jaishroff-org-help.freshchat.com https://cdn-ukwest.onetrust.com https://cdn.honey.io; object-src 'none'; base-uri 'self'; connect-src 'self' 'self' https://analytics.tiktok.com https://analytics.google.com https://bat.bing.net https://*.analytics.google.com https://*.in.applicationinsights.azure.com https://cdn-ukwest.onetrust.com https://*.googletagmanager.com https://*.google-analytics.com https://js.monitor.azure.com https://*.hotjar.com https://*.hotjar.io https://connect.facebook.net https://tracker.marinsm.com https://bat.bing.com https://tt.mbww.com https://www.tradedoubler.com https://secure.adnxs.com https://www.facebook.com https://stats.g.doubleclick.net https://*.smct.io https://firehose.eu-west-1.amazonaws.com https://cognito-identity.eu-west-1.amazonaws.com https://*.doubleclick.net https://*.google.com https://*.facebook.com https://analytics-ipv6.tiktokw.us wss://*.hotjar.com https://*.tiktokw.us https://api.bannercrowd.net; font-src 'self' data: 'self' https://fonts.gstatic.com https://cdn-ukwest.onetrust.com; frame-src 'self' 'self' https://open.spotify.com https://analytics.tiktok.com https://*.googletagmanager.com https://jaishroff-org-help.freshchat.com https://connect.facebook.net https://*.doubleclick.net https://*.smct.io https://d2d7do8qaecbru.cloudfront.net https://*.tangooserver.com; img-src 'self' 'self' https://ade.googlesyndication.com https://analytics.tiktok.com https://uksouth-1.in.applicationinsights.azure.com https://cdn-ukwest.onetrust.com https://*.googletagmanager.com https://*.google-analytics.com https://static.hotjar.com https://bat.bing.com https://secure.adnxs.com https://*.google.com https://*.google.co.uk https://*.google.com.it https://ad.doubleclick.net https://bat.bing.net https://*.facebook.com https://cdn.smct.io https://*.smct.co data: https://*.google.com.et; manifest-src 'self'; media-src 'self'; worker-src 'self'; report-uri /csp-violation-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://js.checkout.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net gateway.apaylater.com gateway.atome.sg *.cdninstagram.com *.igodigital.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com reddotpayment.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com gateway.apaylater.com gateway.atome.sg https://cdn.checkout.com *.klarnacdn.net *.instagram.com *.igodigital.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com gateway.apaylater.com gateway.atome.sg https://cdn.checkout.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://js.checkout.com *.klarnaevt.com *.instagram.com *.igodigital.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.hipay-tpp.com *.hipay.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hipay.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://www.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com https://www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.sharethis.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.googleapis.com https://www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.googletagmanager.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * consentcdn.cookiebot.com consent.cookiebot.com www.facebook.com geowidget-app.inpost.pl mapa.ecommerce.poczta-polska.pl pudofinder.dpd.com.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com *.hsforms.net *.hsforms.com 'self' data: ts.tradetracker.net www.magmodules.eu consentcdn.cookiebot.com imgsct.cookiebot.com trustmate.io www.facebook.com maps.gstatic.com google.com www.google.pl *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com cdn.jsdelivr.net maps.googleapis.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl ruch-osm.sysadvisors.pl mapa.ecommerce.poczta-polska.pl *.hsforms.net *.hsforms.com *.gstatic.com tm.tradetracker.net consentcdn.cookiebot.com consent.cookiebot.com *.googleapis.com www.google.com www.google.pl cdn.ampproject.org connect.facebook.net googletagmanager.com trustmate.io geowidget.inpost.pl api.inpost.pl *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com ruch-osm.sysadvisors.pl trustmate.io google.com geowidget.inpost.pl tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com consentcdn.cookiebot.com consent.cookiebot.com *.googleapis.com stats.g.doubleclick.net region1.google-analytics.com region1.analytics.google.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; connect-src 'self' https://www.paynearme.com https://s.yimg.com https://www.google-analytics.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://www.gstatic.com https://bat.bing.com google.com.pr *.google.com.pr hotjar.io *.hotjar.io *.google.com wss://ws.hotjar.com www.googleadservices.com https://api.rollbar.com https://content.hotjar.io https://www.commissionsoup.com https://metrics.hotjar.io https://*.google.com ninjafetch.com *.ninjafetch.com neuro-id.com *.neuro-id.com neuroid.cloud *.neuroid.cloud; default-src 'self'; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; form-action 'self' https://*.yodlee.com; frame-src 'self' https://www.paynearme.com https://td.doubleclick.net https://www.googletagmanager.com bat.bing.com https://widget.sophtron.com https://*.edgescore.com https://*.yodlee.com https://www.commissionsoup.com; img-src 'self' data: https://sp.analytics.yahoo.com https://static.ads-twitter.com https://t.co analytics.twitter.com https://*.googletagmanager.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.google.com totalcardinc.com *.totalcardinc.com bing.com *.bing.com bat.bing.net www.google.com.mx www.google.com.ng www.googleadservices.com www.google.com.ph https://edge-public-assets.s3.us-east-2.amazonaws.com https://www.commissionsoup.com https://images.totalcardinc.com https://www.google.co.in www.google.com.pr https://bat.bing.com https://www.google.com.pr; object-src 'none'; script-src https://www.paynearme.com https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com 'self' static.ads-twitter.com *.static.ads-twitter.com yimg.com *.yimg.com bat.bing.com *.bat.bing.com hotjar.com *.hotjar.com engagement.technology *.engagement.technology g.doubleclick.net *.g.doubleclick.net googleadservices.com *.googleadservices.com ninjafetch.com *.ninjafetch.com yodlee.com *.yodlee.com neuro-id.com *.neuro-id.com 'unsafe-inline'; style-src 'self' https://www.paynearme.com https://unpkg.com/swiper@7/swiper-bundle.min.css https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.css 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' https://ninjafetch.com https://www.paynearme-sandbox.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=ItYlsoV_mSKoXrIbK6CogTx7UmDXwYnae08LWIU.oK8-1765938183.1158812-1.0.1.1-G9o_kuZKrQC69cL5YJMKJiEk74NzAirg365VRy.UVR7rZ9iLiVl5WlpoJBzZVefBz_21PC6uKTWZz.JkgQJcAKRTjfyT57L9fiptZ8F9K1T..0c.EarAIOCiDzYUZykWjye2x56fwkBAXLgLefTPfpkOhTXxbmyqwRnMj_E3xCPY.9LTVu07LfPnizANWCBraSaMyiPtTCfEK.6Xlnr7Hw; report-to cf-xwjepgspurwiugfe 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://extend.vimeocdn.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://snap.licdn.com https://player.vimeo.com https://*.pardot.com blob:; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://*.pardot.com; img-src 'self' https://www.googletagmanager.com https://i.vimeocdn.com https://*.google.com https://*.gstatic.com https://cdn.cookielaw.org https://*.ads.linkedin.com https://www.linkedin.com https://*.pardot.com data:; font-src 'self' https://cdn.cookielaw.org https://*.pardot.com; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://stats.g.doubleclick.net https://extend.vimeocdn.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://*.ads.linkedin.com https://www.linkedin.com https://*.pardot.com; frame-src 'self' https://www.google.com https://www.recaptcha.net https://player.vimeo.com https://cdn.cookielaw.org https://go.genedata.com https://*.pardot.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https://go.genedata.com https://*.pardot.com; upgrade-insecure-requests 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-R8YvQ3Jielk5hhYkikKmWg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://maxcdn.bootstrapcdn.com/ *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trackedlink.net https://www.google.co.in/ https://www.facebook.com/ https://www.magecomp.com/ https://raw.githubusercontent.com/ magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://connect.facebook.net https://cookie-script.com/ https://cdn.cookie-script.com/ https://secure.paytmpayments.com/ https://staticpg.paytmpayments.com/ https://accounts.paytm.com/ *.disqus.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://maxcdn.bootstrapcdn.com/ https://staticpg.paytmpayments.com/ *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://secure.paytmpayments.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com lumberjack.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com https://www.google.com https://maps.google.com https://maps.googleapis.com https://stats.g.doubleclick.net https://www.google-analytics.com https://www.loterie.lu https://loterie.lu https://195.46.247.200 https://10.8.215.223 https://region1.analytics.google.com https://consent.cookiebot.com; font-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com data: https://stats.g.doubleclick.net https://www.loterie.lu https://loterie.lu https://consent.cookiebot.com https://195.46.247.200 https://10.8.215.223 https://fonts.gstatic.com https://region1.analytics.google.com 'unsafe-inline' 'unsafe-eval'; script-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com https://maps.google.com https://maps.googleapis.com https://www.google.com https://stats.g.doubleclick.net https://www.google-analytics.com https://www.googletagmanager.com https://www.loterie.lu https://loterie.lu https://consent.cookiebot.com https://195.46.247.200 https://10.8.215.223 https://region1.analytics.google.com 'unsafe-inline' 'unsafe-eval'; style-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com 'unsafe-inline' https://maps.google.com https://maps.googleapis.com http://fonts.googleapis.com https://stats.g.doubleclick.net https://www.loterie.lu https://loterie.lu https://consent.cookiebot.com https://195.46.247.200 https://region1.analytics.google.com https://10.8.215.223; object-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com https://maps.google.com https://maps.googleapis.com https://stats.g.doubleclick.net https://www.loterie.lu https://loterie.lu https://consent.cookiebot.com https://195.46.247.200 https://region1.analytics.google.com https://10.8.215.223; img-src https://maps.googleapis.com https://www.google.com https://www.google.pl https://maps.gstatic.com https://stats.g.doubleclick.net https://www.loterie.lu https://loterie.lu https://consent.cookiebot.com https://195.46.247.200 https://10.8.215.223 https://region1.analytics.google.com https://www.google-analytics.com data:; frame-src https://analytics.google.com https://forms.sbc30.net https://consentcdn.cookiebot.com https://www.saferpay.com https://maps.google.com https://maps.googleapis.com https://consent.cookiebot.com https://www.loterie.lu https://region1.analytics.google.com https://loterie.lu; upgrade-insecure-requests; 1 default-src https: 'unsafe-inline' 'unsafe-eval' data: about:; report-uri /_resources/php/csp-report.php 1 font-src fonts.gstatic.com *.google.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com udraw-app.racadtech.com udraw-app.b-cdn.net www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com *.badb5refl.com *.doubleclick.net *.hellobar.com *.liadm.com *.hotjar.com idcband.com *.idcband.com *.intercomcdn.com data: www.idcband.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.searchserverapi.com *.hsforms.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi1.com *.twitter.com www.idcband.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.stripe.com stripe.com *.link.com *.amazon.com www.idcband.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com www.googletagmanager.com https://*.hubspot.com https://*.usemessages.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com landofcoder.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * udraw-app.racadtech.com *.gosendex.com udraw-app.b-cdn.net mailto: tel: www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com *.weltpixel.com *.badb5refl.com *.cookiebot.com *.doubleclick.net *.google.co.uk *.gstatic.com *.hellobar.com *.liadm.com *.hotjar.com idcband.com *.idcband.com *.sandbox.paypal.com https://js.playground.klarna.com data: *.sharethis.com *.vimeo.com *.paypalobjects.com *.kaptcha.com *.braintreegateway.com www.idcband.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.analytics.google.com *.bing.com blob: *.facebook.com *.google.co.uk *.google-analystics.com *.hsforms.com *.hubspot.com *.ads.linkedin.com https://*.hubspotusercontent*.net https://*.hubspot.com *.trackedlink.net validate.fishpig.co.uk http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com udraw-app.racadtech.com udraw-app.b-cdn.net *.wikimedia.org *.twitter.com *.twimg.com www.google.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com maps.googleapis.com *.badb5refl.com *.callrail.com *.certcapture.com *.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.hellobar.com *.liadm.com *.hotjar.com idcband.com *.idcband.com *.intercom.io *.intercomassets.com *.intercomcdn.com wss://nexus-websocket-a.intercom.io *.klarnacdn.net *.sandbox.paypal.com *.postcodeanywhere.co.uk *.trustpilot.com *.vimeo.com *.sharethis.com *.idcband.dev *.clarity.ms *.racadtech.com www.idcband.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com cdn.ampproject.org raw.githubusercontent.com *.air360tracker.net *.bing.com *.callrail.com googleads.g.doubleclick.net *.enzuzo.com *.facebook.net *.google.com *.hellobar.com *.hotjar.com *.hsadspixel.net *.hsforms.net *.hscollectedforms.net *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hubspot.com *.licdn.com https://*.osano.com *.usemessages.com *.zoominfo.com https://js.hs-scripts.com https://js.usemessages.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com udraw-app.racadtech.com *.gosendex.com cdnjs.cloudflare.com udraw-app.b-cdn.net searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com *.trustpilot.com https://cdn.ingest-lr.com https://cdn.lr-ingest.com https://cdn.lr-in-prod.com https://cdn.lr-in.com https://cdn.lr-ingest.io https://cdn.logrocket.io https://cdn.lrkt-in.com https://cdn.lrkt-in.com/LogRocket.min.js https://cdn.lrkt-in.com/logger-1.min.js pay.activa-card.com *.amplitude.com *.arcot.com *.badb5refl.com *.braintreegateway.com 3ds-secure.cardcomplete.com *.cardinalcommerce.com *.certcapture.com *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.cookiebot.com data: *.demdex.net cdn.dnky.co *.dotdigital.com *.doubleclick.net *.fetchify.com *.githubusercontent.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.gstatic.com/recaptcha idcband.com *.idcband.com *.intercom.io *.intercomcdn.com *.ip-api.com *.jquery.com *.liadm.com *.lijit.com *.lloydstsb.com *.monzo.com *.paypalobjects.com idand11112.pcapredict.com *.postcodeanywhere.co.uk *.racadtech.com rsa3dsauth.com www.securesuite.co.uk *.sharethis.com acs.sia.eu *.touchtechpayments.com *.wirecard.com *.wlp-acs.com *.ytimg.com www.idcband.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.google.co.uk *.fontawesome.com webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com udraw-app.racadtech.com *.vultrcdn.com udraw-app.b-cdn.net www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com *.badb5refl.com *.callrail.com *.certcapture.com *.doubleclick.net *.google-analystics.com *.google-analytics.com *.googletagmanager.com *.hellobar.com *.liadm.com *.hotjar.com idcband.com *.idcband.com *.intercom.io *.intercomassets.com *.intercomcdn.com wss://nexus-websocket-a.intercom.io *.klarnacdn.net *.paypal.com *.sandbox.paypal.com *.postcodeanywhere.co.uk https://searchserverapi.com data: *.vimeo.com *.sharethis.com www.idcband.com 'self' 'unsafe-inline'; object-src landofcoder.com *.trustpilot.com 'self' 'unsafe-inline'; media-src *.adobe.com *.google.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.badb5refl.com *.doubleclick.net *.hellobar.com *.liadm.com *.hotjar.com idcband.com *.idcband.com *.intercomcdn.com *.youtube-nocookie.com *.vimeo.com *.sharethis.com www.idcband.com 'self' 'unsafe-inline'; manifest-src *.google.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org *.air360tracker.net *.air360.io *.bing.com *.enzuzo.com *.google.com *.googlesyndication.com region1.google-analytics.com *.hsforms.com *.hscollectedforms.net *.hubapi.com *.hubspot.com idcband.com *.idcgo.es *.idcgo.fr *.ads.linkedin.com https://*.osano.com *.merchant-center-analytics.goog *.searchserverapi1.com *.ip-api.com *.trustpilot.com *.zoominfo.com https://api.usemessages.com https://*.hubspot.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk landofcoder.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com udraw-app.racadtech.com pricematrix.racadtech.com udraw-app.b-cdn.net api.amplitude.com stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com places.googleapis.com *.badb5refl.com *.callrail.com *.certcapture.com *.cookiebot.com *.doubleclick.net *.google-analytics.com *.google-analystics.com *.hellobar.com *.liadm.com *.hotjar.com *.idcband.com *.intercom.io *.intercomcdn.com wss://nexus-websocket-a.intercom.io *.sandbox.paypal.com *.postcodeanywhere.co.uk *.sharethis.com *.clarity.ms https://*.logrocket.io https://*.lr-ingest.io https://*.logrocket.com https://*.lr-in.com https://*.lr-in-prod.com https://*.lr-ingest.com https://*.ingest-lr.com https://r.lrkt-in.com www.idcband.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.idcband.com http: https: blob: 'self' 'unsafe-inline'; default-src udraw-app.racadtech.com udraw-app.b-cdn.net www.idcband.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' https://metroselskabet.euwest01.umbraco.io/ https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net https://ssl.gstatic.com https://www.gstatic.com https://www.facebook.com blob: data:; media-src 'self' https://metroselskabet.euwest01.umbraco.io/ blob: data:; font-src 'self' https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self'; form-action 'self' https://metroselskabet.euwest01.umbraco.io/; frame-ancestors 'none'; upgrade-insecure-requests; connect-src 'self' https://metroselskabet.euwest01.umbraco.io/ https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; frame-src 'self' https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://* data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.disqus.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src custom.intucdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/CSIRESOURCES/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CSIRESOURCES/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/CSIRESOURCES/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CSIRESOURCES/ https://higherlogicdownload.s3.amazonaws.com/CSIRESOURCES/ https://higherlogiclongterm.s3.amazonaws.com/CSIRESOURCES/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/CSIRESOURCES/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CSIRESOURCES/ 'self' https://higherlogiclongterm.s3.amazonaws.com/CSIRESOURCES/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/CSIRESOURCES/ https://higherlogicdownload.s3.amazonaws.com/CSIRESOURCES/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CSIRESOURCES/ https://higherlogicstream.s3.amazonaws.com/CSIRESOURCES/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/CSIRESOURCES/ https://higherlogicdownload.s3.amazonaws.com/CSIRESOURCES/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CSIRESOURCES/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.addressy.com *.google-analytics.com https://get.geojs.io *.avada.io *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.analytics.google.com 'self' *.fullstory.com *.doubleclick.net *.googleapis.com *.googlesyndication.com *.facebook.com *.loyaltylion.net *.loyaltylion.com *.elfsight.com forms-eu1.hscollectedforms.net *.livechatinc.com *.sjv.io *.ojrq.net *.loggly.com s.yimg.com *.paypal.cn *.paypalobjects.com browser-intake-us5-datadoghq.com *.qualtrics.com *.acsbapp.com *.storepoint.co localhost www.google.ca www.google.co.in www.google.de www.google.ie www.google.pt *.8x8.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.paypalobjects.com *.paypal.com *.googletagmanager.com *.trustpilot.com *.google-analytics.com *.nosto.com *.livechatinc.com cdn.cookie-script.com googleads.g.doubleclick.net sdk-static.loyaltylion.net sdk.loyaltylion.net unpkg.com commerce.adobedtm.com r1-t.trackedlink.net cdn.jsdelivr.net www.google.com livesearch-metrics.magento-ds.com connect.facebook.net edge.fullstory.com js-eu1.hs-scripts.com email-motocaddy.com *.newrelic.com magento-recs-sdk.adobe.net utt.impactcdn.com fonts.googleapis.com fonts.gstatic.com *.google.co.uk *.gstatic.com www.gstatic.com *.adyen.com *.8x8.com static.trackedweb.net pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9e50c508-95d2-4a1a-ad83-23f368938734.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com https://www.google.com rivieramaisonnl.api.useinsider.com td.doubleclick.net ct.pinterest.com https://rivieramaisonnlacc.api.useinsider.com https://www.sovendus-connect.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://portal.payconiq.com https://static.buckaroo.nl https://www.magezon.com log.api.useinsider.com www.google.nl www.facebook.com bat.bing.com www.gstatic.com widgets.trustedshops.com https://rivieramaison.com https://acc-rivieramaison.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net unpkg.com commerce.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.google.com splitwise.clickvalue.nl consent.cookiefirst.com c.zmags.com widgets.trustedshops.com d5yoctgpv4cpx.cloudfront.net static.hotjar.com rivieramaisonnl.api.useinsider.com osm.klarnaservices.com script.hotjar.com na-library.klarnaservices.com www.youtube.com eitri.api.useinsider.com www.google.com bat.bing.com s.pinimg.com cdn.mxpnl.com connect.facebook.net www.gstatic.com cas.zma.gs static.buckaroo.nl checkout.buckaroo.nl widget.intercom.io ct.pinterest.com js.intercomcdn.com https://rivieramaisonnlacc.api.useinsider.com https://integrations.etrusted.com https://www.clarity.ms https://l.clarity.ms https://gtmadapter-node-cbjg5cz5hq-ew.a.run.app https://region1.google-analytics.com https://api.sovendus.com https://www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl c.zmags.com consent.cookiefirst.com assets.api.useinsider.com www.gstatic.com checkout.buckaroo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net commerce.adobedtm.com commerce.adobedc.net vimeo.com api.magento.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://na.klarnaevt.com https://*.clarity.ms region1.analytics.google.com consent.cookiefirst.com na-library.klarnaservices.com edge.cookiefirst.com content.hotjar.io hit.api.useinsider.com rivieramaisonnl.api.useinsider.com region1.google-analytics.com ct.pinterest.com api-iam.intercom.io https://www.google.com https://identification-api.sovendus.com https://press-tracking-api.sovendus.com https://ct.pinterest.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com ws.hotjar.com www.google.com metrics.hotjar.io nexus-websocket-a.intercom.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.zohocdn.com *.zohopublic.com *.alothemes.com *.magepow.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.ampproject.net https://www.youtube.com https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.logoscorp.com *.zohopublic.com *.zohocdn.com *.preprod.sambilonline.com *.sambilonline.com *.google.co.ve *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://i.ytimg.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.zohocdn.com *.zoho.com *.zohopublic.com *.googletagmanager.com *.doubleclick.net s7.addthis.com *.avada.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.ampproject.org *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.zohocdn.com *.zohopublic.com *.alothemes.com *.magepow.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net https://w.clarity.ms/collect *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.cloudflare.com *.twitter.com *.twimg.com *.zohocdn.com *.zoho.com *.zohopublic.com ws://vts.zohopublic.com *.doubleclick.net ekr.zdassets.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.ampproject.org *.ampproject.net https://connect.facebook.net https://www.google-analytics.com https://www.facebook.com/tr *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.sambilonline.com/; report-to report-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/publicsector_google 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net https://static.addtoany.com mdbootstrap.com 'unsafe-inline' https://matomo.gpseo.fr.stratis.pro/; script-src-attr 'self'; script-src-elem 'self' cdn.jsdelivr.net https://static.addtoany.com mdbootstrap.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com *.bootstrapcdn.com celebrosnlp.com *.livechatinc.com https://static.zipmoney.com.au *.zipmoney.com.au *.zip.co *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com sandbox.zip.co 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://magento2.avada.io/ my.reviewr.com.au https://reviewr.app/ https://www.reviewr.app/ https://vars.hotjar.com/ https://secure.livechatinc.com/ *.google.com https://bid.g.doubleclick.net/ *.mouseflow.com https://cdn.mouseflow.com https://secure.ewaypayments.com *.ewaypayments.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cloudflare.com *.google-analytics.com static.reviewmgr.com *.google.com *.google.co.in https://static.zipmoney.com.au *.livechatinc.com https://img.icons8.com/ https://bpi.zip.co *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com assets.adobedtm.com *.magento-ds.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.cloudflare.com *.twitter.com *.fontawesome.com *.googletagmanager.com *.google-analytics.com *.smartlook.com https://static.zipmoney.com.au *.reviewmgr.com *.cdn.livechatinc.com *.static.hotjar.com *.g.doubleclick.net *.my.reviewr.com.au *.livechatinc.com https://script.hotjar.com/ https://static.hotjar.com/ *.api.livechatinc.com *.mouseflow.com https://cdn.mouseflow.com https://secure.ewaypayments.com *.ewaypayments.com https://data.stats.tools *.clickcease.com https://www.clickcease.com https://js-agent.newrelic.com *.newrelic.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com downloads.mailchimp.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com https://bpi.zip.co maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.adobe.io performance.typekit.net *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com https://stats.g.doubleclick.net/ *.hotjar.com https://manager.eu.smartlook.cloud https://api.zipmoney.com.au/ *.zip.co *.livechatinc.com https://bam.nr-data.net/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src d1b5rpvosb5ex9.cloudfront.net da4ehj3jkwbbp.cloudfront.net *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://sis-t.redsys.es:25443 https://sis.redsys.es *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.cookiebot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d1b5rpvosb5ex9.cloudfront.net da4ehj3jkwbbp.cloudfront.net lupa.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cookiebot.com d1b5rpvosb5ex9.cloudfront.net da4ehj3jkwbbp.cloudfront.net *.avada.io *.shopify.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com d1b5rpvosb5ex9.cloudfront.net da4ehj3jkwbbp.cloudfront.net *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cookiebot.com d1b5rpvosb5ex9.cloudfront.net da4ehj3jkwbbp.cloudfront.net *.lupa.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-wqF16t0oBLe52XYAMwk1jzqTR69EnAdA'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 font-src maxcdn.bootstrapcdn.com *.oct8ne.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com *.storyblok.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com *.multisafepay.com https://pay.google.com *.oct8ne.com *.hotjar.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com cdn.flbx.io *.cloudfront.net *.equalweb.com https://images.unsplash.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.multisafepay.com *.oct8ne.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.doofinder.com *.getflowbox.com *.equalweb.com https://maps.googleapis.com connect.facebook.net twitter.com platform.twitter.com *.multisafepay.com https://pay.google.com *.oct8ne.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.doofinder.com maxcdn.bootstrapcdn.com *.multisafepay.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com *.getflowbox.com *.equalweb.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=41475e7c-4079-42f8-90f5-1e8cf296ba8a; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.boxnow.gr *.boxnow.cy *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.z-mall.gr *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com www.facebook.com *.bestprice.gr *.pstatic.gr *.z-mall.gr *.twitter.com *.piraeusbank.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com *.boxnow.gr *.boxnow.cy connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.cleverpoint.gr *.cookiebot.com *.boxnow.gr/ *.bestprice.gr *.pstatic.gr *.googletagmanager.com *.klarnaservices.com *.z-mall.gr *.twitter.com *.skroutz.gr www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://cube.commercebox.io *.boxnow.gr *.boxnow.cy connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.google.gr *.cookiebot.com *.google-analytics.com maps.gstatic.com *.bestprice.gr *.pstatic.gr *.z-mall.gr *.googleapis.com *.klarnaservices.com *.cloudflare.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.skroutz.gr www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://cdn.jsdelivr.net/gh/CommerceBox-io/ *.boxnow.gr *.boxnow.cy connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.cleverpoint.gr 'self' data: *.cookiebot.com *.googleadservices.com *.bestprice.gr *.pstatic.gr *.linkwi.se *.octocom.ai octocomstorage.blob.core.windows.net *.hotjar.com *.scanandpay.gr *.hotjar.io *.z-mall.gr *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.piraeusbank.gr *.skroutz.gr www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.bestprice.gr *.pstatic.gr *.octocom.ai octocomstorage.blob.core.windows.net *.jsdelivr.net *.z-mall.gr *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://torus.commercebox.io https://cube.commercebox.io *.boxnow.gr *.boxnow.cy connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io maps.googleapis.com stats.g.doubleclick.net *.cookiebot.com *.bestprice.gr *.pstatic.gr *.scanandpay.gr *.octocom.ai *.hotjar.com *.hotjar.io eu.klarnaevt.com *.ipify.org *.z-mall.gr *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klevu.com *.ksearchnet.com *.fontawesome.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.stripe.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' *.google.co.uk *.postcodeanywhere.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.stripe.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.tradecentric.com https://storage.googleapis.com https://fcm.googleapis.com https://fcmregistrations.googleapis.com https://js.klevu.com https://chimpstatic.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.stripe.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klevu.com *.ksearchnet.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.tradecentric.com https://js.klevu.com *.postcodeanywhere.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.bolt.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.stripe.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klevu.com *.ksearchnet.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://storage.googleapis.com https://fcm.googleapis.com https://fcmregistrations.googleapis.com 'self' *.postcodeanywhere.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' data: *.pcapredict.com *.postcodeanywhere.co.uk *.googletagmanager.com cdn.jsdelivr.net *.commerce.adobedtm.com *.google.com *.paypalobjects.com *.paypal.com connect.punchout2go.com https://chimpstatic.com https://livesearch-metrics.magento-ds.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://unpkg.com https://commerce.adobedtm.com https://www.gstatic.com https://js-agent.newrelic.com https://live.opayo.eu.elavon.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5bdbaad3-6a97-4252-89b1-8c6a100dc1b0.sansec.watch/; report-to report-endpoint; 1 report-uri https://cspevents.azurewebsites.net/api/collect;default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.scope.ne.jp *.pay.jp stscopestatics001.blob.core.windows.net scope-files.s3.amazonaws.com *.rakuten.co.jp ui.customsearch.ai hosteduxprod.z13.web.core.windows.net cdnjs.cloudflare.com www.googletagmanager.com www.google-analytics.com analytics.google.com *.analytics.google.com www.google.co.jp www.google.com www.gstatic.com func-bbs-scope-stage-japaneast.azurewebsites.net func-bbs-scope-prod-japaneast.azurewebsites.net *.youtube.com yt.ggpht.com *.gstatic.com i.ytimg.com static.doubleclick.net stats.g.doubleclick.net www.facebook.com connect.facebook.net player.vimeo.com td.doubleclick.net js-agent.newrelic.com bam.nr-data.net 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://ct.pinterest.com https://consentcdn.cookiebot.com *.google.com/ https://plumrocket.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com https://scontent.cdninstagram.com *.cloudfront.net *.helloretail.com *.pinterest.com *.google.com *.google.dk https://info.dibs.se ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com www.google.com.ua maps.googleapis.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://gtm.bittekairand.com https://magento.com https://foursixty.com https://static.bambora.com https://cdn.jsdelivr.net https://connect.facebook.net https://*.doubleclick.net https://*.hotjar.com https://*.mouseflow.com https://*.pinimg.com *.cookiebot.com https://*.dibspayment.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.gstatic.com *.fontawesome.com *.avada.io *.shopify.com *.google.com/ maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://foursixty.com https://cdn.jsdelivr.net https://*.dibspayment.eu downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com https://foursixty.com *.pinterest.com https://gtm.bittekairand.com *.doubleclick.net *.cookiebot.com https://*.dibspayment.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io maps.googleapis.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://www.gstatic.com *.zopim.com data: *.trustedshops.com widgets.trustedshops.com *.googleapis.com https://fonts.gstatic.com *.gstatic.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.cookiebot.com *.facebook.com *.hotjar.com *.mijnmhs.nl *.criteo.com *.criteo.net *.bookerz.nl *.doubleclick.net *.googletagmanager.com *.addthis.com https://hcaptcha.com https://*.google.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com imgsct.cookiebot.com *.trackedlink.net *.datatrics.com *.multisafepay.com *.google.nl *.googletagmanager.com *.bing.com *.ledlampenkopen.nu *.trustedshops.com *.pubmatic.com *.openx.net *.adform.net *.media.net *.adnxs.com *.teads.tv *.casalemedia.com *.smaato.net *.taboola.com *.yahoo.com *.360yield.com *.smartadserver.com *.doubleclick.net *.outbrain.com *.3lift.com *.rubiconproject.com *.zopim.io *.g.doubleclick.net *.addthis.com *.squeezely.tech squeezely.tech x.bidswitch.net match.sharethrough.com ads.stickyadstv.com cdn.stickyadstv.com exchange.mediavine.com pixel.advertising.com i.liadm.com i6.liadm.com *.liadm.com cm.mgid.com sync-criteo.ads.yieldmo.com gum.criteo.com dis.criteo.com partner.mediawallahscript.com idsync.ricdn.com pixel.tapad.com ad.tpmn.co.kr crb.kargo.com an.yandex.ru ad.as.amanad.adtdp.com trends.revcontent.com *.sooqr.com static.sooqr.com c.clarity.ms *.cloudfront.net *.ledskaufen.de *.facebook.com *.cookiebot.com *.googleusercontent.com *.clarity.ms https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://meetanshi.com/media/logo.png 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com consent.cookiebot.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://polyfill-fastly.io https://browser.sentry-cdn.com s7.addthis.com *.google-analytics.com *.bing.com *.profitmetrics.io *.cookiebot.com *.google.com *.google.nl *.datatrics.com *.criteo.net *.criteo.com *.cloudflare.com *.trustedshops.com *.wappy.chat *.zopim.com *.zdassets.com *.googleadservices.com *.hotjar.com static.hotjar.com *.sooqr.com static.sooqr.com clarity.ms *.clarity.ms *.ledlampenkopen.nu ledskaufen.de *.ledskaufen.de *.luckyorange.com *.cookiecode.nl *.facebook.net *.cloudfront.net *.googleapis.com *.addthis.com *.sentry.io *.googletagmanager.com *.doubleclick.net https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.moatads.com *.addthisedge.com *.pinterest.com *.multisafepay.com https://pay.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com fonts.googleapis.com *.trustedshops.com *.gstatic.com *.sooqr.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com *.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.sentry.io ekr.zdassets.com/ *.bing.com *.datatrics.com *.criteo.com *.trustedshops.com *.etrusted.com *.wappy.chat *.zdassets.com *.zopim.com wss: *.hotjar.com in.hotjar.com *.hotjar.io cognito-identity.eu-central-1.amazonaws.com *.ledlampenkopen.nu ledskaufen.de *.ledskaufen.de *.luckyorange.com *.cookiecode.nl *.google.com *.zendesk.com *.googlesyndication.com *.amazonaws.com *.clarity.ms *.cookiebot.com https://*.google.com *.googletagmanager.com *.doubleclick.net *.addthis.com https://hcaptcha.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://*.hcaptcha.com *.multisafepay.com t.elasticsuite.io *.google-analytics.com https://integrations.etrusted.site *.analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' *.ledlampenkopen.nu *.trustedshops.com zmkmhs.ledlampenkopen.nu *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://purina.do; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://unpkg.com https://static.addtoany.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://cdns.us1.gigya.com https://cdn.cookielaw.org https://cdn.az.ciam.nestle.com https://cdn.gbqofs.com https://zn4iy6orojcrswicb-nestleglobalmktg.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://brand-ecommerce-assets.fusepump.com https://cdn.adimo.co https://w.usabilla.com https://connect.facebook.net https://maps.googleapis.com https://googleads.g.doubleclick.net https://api.usabilla.com https://shared.az.ciam.nestle.com https://www.google.com https://www.recaptcha.net https://www.gstatic.com https://www.youtube.com https://www.google-analytics.com data-sa.purina.com.do; object-src 'none'; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://fonts.googleapis.com https://d6tizftlrpuof.cloudfront.net; img-src 'self' data: https://www.googletagmanager.com https://cdn.cookielaw.org https://ad.doubleclick.net https://www.google.com.ar https://d6tizftlrpuof.cloudfront.net https://fra1.qualtrics.com https://www.facebook.com https://www.googleadservices.com https://maps.gstatic.com https://siteintercept.qualtrics.com https://www.google.com https://maps.googleapis.com https://w.usabilla.com https://googleads.g.doubleclick.net https://cdns.us1.gigya.com https://stats.g.doubleclick.net; media-src *; frame-src 'self' https://www.google-analytics.com https://static.addtoany.com https://cdns.us1.gigya.com https://www.googletagmanager.com https://10002872.fls.doubleclick.net https://campaigns-api.adimo.co https://campaigns.adimo.co https://www.youtube-nocookie.com https://nestleglobalmktg.qualtrics.com https://nestlmexiconew.qualifioapp.com https://nestlemexico.qualifioapp.com https://www.youtube.com https://www.google.com https://9918513.fls.doubleclick.net; frame-ancestors 'self'; child-src 'self' blob:;; font-src 'self' https://cdn.jsdelivr.net https://fonts.gstatic.com data:;; connect-src 'self' https://cdn.jsdelivr.net https://pagead2.googlesyndication.com https://cdnjs.cloudflare.com https://cdns.us1.gigya.com https://www.google-analytics.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://www.google.com https://ad.doubleclick.net https://www.google.com https://analytics.google.com https://siteintercept.qualtrics.com https://4dvq37jqcg.execute-api.eu-west-1.amazonaws.com https://dynamic-cta.adimo.co https://cdn.adimo.co https://report.nestle.gbqofs.io https://report.nestle.gbqofs.io https://www.facebook.com https://maps.googleapis.com https://www.googleadservices.com https://am1.device-api.indigitall.com https://googleads.g.doubleclick.net https://accounts.us1.gigya.com https://stats.g.doubleclick.net https://privacyportal-ch.onetrust.com data-sa.purina.com.do; report-uri https://www.svelty.com.mx/report-csp-violation 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bing.com *.google-analytics.com *.googleadservices.com *.google.co.uk *.googletagmanager.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.feefo.com *.adobedtm.com *.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.ometria.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.bing.com *.google-analytics.com *.googletagmanager.com googleadservices.com *.googleapis.com expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.noibu.com https://www.noibu.com https://cdn.noibu.com *.facebook.net https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.dixa.io x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://api.ometria.com *.ometria.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.bing.com *.bing.net *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com maps.googleapis.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.advancedcommerce.services https://cdn.noibu.com wss://input.noibu.com https://input.noibu.com *.noibu.com https://cdn.jsdelivr.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.dixa.io x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://api.ometria.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://*.intimatemerger.com https://*.im-apps.net; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.webwinkelkeur.nl *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.google.nl *.webwinkelkeur.nl *.usercentrics.eu img.sct.eu1.usercentrics.eu bat.bing.net bat.bing.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.demdex.net id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.1rx.io sync.targeting.unrulymedia.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.dhlecommerce.nl *.cookiebot.eu *.cookiebot.com *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.calendly.com *.beslist.nl *.pinimg.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.pinterest.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com widget.tagembed.com api.taggbox.com cdn.tagbox.com static.dhlecommerce.nl https://static.klaviyo.com *.fontawesome.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.pinterest.com *.criteo.com *.beslist.nl widget.tagembed.com api.taggbox.com cdn.tagbox.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.multisafepay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.es https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; script-src 'self' googleads.g.doubleclick.net stats.g.doubleclick.net ws-na.assoc-amazon.com www.amazon.com rcm.amazon.com www.google.com apis.google.com cse.google.com www.google-analytics.com www.googletagmanager.com partner.googleadservices.com pagead2.googlesyndication.com www.googleadservices.com tpc.googlesyndication.com; frame-src googleads.g.doubleclick.net stats.g.doubleclick.net ws-na.assoc-amazon.com www.amazon.com rcm.amazon.com www.google.com apis.google.com cse.google.com www.google-analytics.com www.googletagmanager.com partner.googleadservices.com pagead2.googlesyndication.com www.googleadservices.com tpc.googlesyndication.com; object-src 'self'; form-action 'none'; frame-ancestors 'none'; report-uri https://c408453ef55b803114646d679c50ef77.report-uri.com/r/d/csp/reportOnly; 1 upgrade-insecure-requests ; default-src 'self' bongiornowork.com *.ads.linkedin.com stats.g.doubleclick.net www.google.com www.paypal.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' widget.feedaty.com cdnjs.cloudflare.com ajax.googleapis.com scripts.clarity.ms www.google-analytics.com kit.fontawesome.com *.pinimg.com snap.licdn.com custom.clerk.io use.fontawesome.com api.clerk.io *.api.clerk.io connect.facebook.net gdpr.point2point.it sibautomation.com static-eu.oct8ne.com www.bongiornowork.com www.clarity.ms www.googletagmanager.com www.paypal.com ; connect-src 'self' widget.feedaty.com ads.linkedin.com *.ads.linkedin.com *.clarity.ms backoffice-eu.oct8ne.com ct.pinterest.com frontal-eu.oct8ne.com gdpr.point2point.it in-automate.brevo.com *.fontawesome.com oct8neeucatalogservice.azurewebsites.net *.analytics.google.com stats.g.doubleclick.net www.google-analytics.com www.google.com www.googleadservices.com www.paypal.com; img-src 'self' data: www.bongiornowork.com c.bing.com clarity.ms *.clarity.ms ecommerce.nexi.it api.prestashop-project.org widget.feedaty.com *.ads.linkedin.com backoffice-eu.oct8ne.com googleads.g.doubleclick.net static-eu.oct8ne.com www.google.com www.google.it www.paypalobjects.com www.googletagmanager.com; media-src 'self' static-eu.oct8ne.com; style-src 'self' 'unsafe-inline' widget.feedaty.com stackpath.bootstrapcdn.com use.fontawesome.com fonts.googleapis.com backoffice-eu.oct8ne.com static-eu.oct8ne.com; font-src 'self' data: use.fontawesome.com stackpath.bootstrapcdn.com *.fonts.gstatic.com fonts.gstatic.com; frame-src 'self' backoffice-eu.oct8ne.com ct.pinterest.com www.googletagmanager.com www.paypal.com; object-src 'none'; frame-ancestors 'none'; report-to csp-endpoint; report-uri https://stage.bongiornowork.com/headers/csp-report-uri.php; 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr *.gstatic.com *.stape.io *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.youtube.com https://form.typeform.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://ipdev-kj11847-1841.fast-mage.com/ https://instantprecieux.fr/ https://www.google.fr/ https://www.facebook.com/ https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.paypalobjects.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://static.cloudflareinsights.com/ https://connect.facebook.net/ https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com widget.freshworks.com m2epro.freshdesk.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.jsdelivr.net *.google-analytics.com *.googleadservices.com *.colissimo.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://static.cloudflareinsights.com/ https://region1.google-analytics.com https://mpc2-prod-1-is5qnl632q-uc.a.run.app https://ws.colissimo.fr https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ 'self' https://*.oppwa.com; font-src cash-f.squarecdn.com https://*.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.klaviyo.com https://prilla.com *.googleapis.com *.bootstrapcdn.com https://*.nshiftportal.com https://*.typekit.net https://img-statics.com https://*.kustom.co https://*.klarna.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com https://widgets.trustedshops.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://www.facebook.com https://*.epayment.nets.eu https://*.nets.eu https://cembrapay.ch https://*.techlab-cdn.com pago.qit.nu https://*.qliro.com https://*.vipps.no https://*.trustly.com https://*.ideal.nl https://*.apple.com https://*.unzer.com https://*.heidelpay.com https://*.kustom.co https://*.klarna.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.google.com https://*.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ * *.adyen.com https://*.klarna.com 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.cookiebot.eu https://*.google.com https://policy.app.cookieinformation.com https://*.online-metrix.net https://www.facebook.com page.qit.nu https://*.qliro.com https://*.g.doubleclick.net https://*.tradedoubler.com https://*.techlab-cdn.com/ https://*.gstatic.com https://*.nshiftportal.com https://*.kustom.co www.xtento.com www.facebook.com platform.twitter.com *.google.com *.addthis.com *.pinterest.com *.trustpilot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net https://*.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io * https://*.gstatic.com *.adyen.com cembrapay.ch https://info.dibs.se https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://*.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.agechecked.com https://firebasestorage.googleapis.com 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.creative-serving.com https://*.creative-serving.org https://id5-sync.com https://*.sharethis.com https://*.justpremium.com https://*.ad.smaato.net https://*.videowalldirect.com *.google.com *.google.co.in *.googleadservices.com *.google-analytics.com *.lightemporium.com *.usercentrics.eu https://stats.g.doubleclick.net https://d.adroll.com https://*.advertising.com https://*.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net *.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com https://*.online-metrix.net https://byjuno.ch https://www.facebook.com https://ads.stickyadstv.com https://sync.search.spotxchange.com https://ad.sxp.smartclip.net https://cm.adform.net https://wt.rqtrk.eu https://ad.360yield.com https://cm.g.doubleclick.net https://match.adsrvr.org https://match.adsby.bidtheatre.com https://1f2e7.v.fwmrm.net https://pr-bh.ybp.yahoo.com https://meetanshi.com/media/logo.png https://www.google.se https://rtb-csync.smartadserver.com https://synchroscript.deliveryengine.adswizz.com https://match.prod.bidr.io https://c1.adform.net https://pm.w55c.net https://pixel.onaudience.com https://sync.crwdcntrl.net/ https://ps.eyeota.net https://*.tradedoubler.com https://*.adform.net https://*.img-statics.com https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://googleads.g.doubleclick.net https://*.doubleclick.net https://*.googlesyndication.com https://*.zeotap.com https://imgstatic.eu https://*.paypalobjects.com https://cms.analytics.yahoo.com https://bidberry.net https://cembrapay.ch https://*.trustpilot.com https://*.snapengage.com https://*.kargo.com https://*.amazon-adsystem.com https://*.mgid.com https://*.scorecardresearch.com https://*.simpli.fi https://*.ck-ie.com https://*.tapad.com https://*.thrtle.com https://*.clickagy.com https://*.agkn.com https://*.hotjar.io https://*.inkclub.com:9000 https://sync.srv.stackadapt.com https://*.w55c.net https://*.pubmatic.com https://*.insightexpressai.com https://*.dotomi.com https://*.imgstatics.com https://pippio.com https://tags.rd.linksynergy.com https://*.rfihub.com https://*.techlab-cdn.com/ https://*.nshiftportal.com https://*.m1314.com https://*.typekit.net https://*.kustom.co https://ml314.com www.xtento.com cdn.xtento.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.cloudflare.com https://cdn.klarna.com *.vimeocdn.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com https://*.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://*.dibspayment.eu https://maps.googleapis.com *.disqus.com https://*.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.agechecked.com https://cdn.jsdelivr.net *.avada.io *.shopify.com 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.adnxs.com https://*.pingdom.net https://*.cookiebot.eu https://*.clarity.ms https://*.creative-serving.com https://*.creative-serving.org https://*.googleadservices.com https://*.google-analytics.com https://*.googletagmanager.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.adobedtm.com *.magento.com https://*.adobedtm.com *.ccdc02.com https://*.googleoptimize.com https://googleads.g.doubleclick.net https://*.nr-data.net https://policy.app.cookieinformation.com https://*.online-metrix.net https://*.bidtheatre.com https://*.qit.nu https://connect.facebook.net https://*.snapengage.com https://*.qliro.com https://*.tradedoubler.com https://*.adform.net https://img-statics.com https://eu-test.oppwa.com https://*.techlab-cdn.com https://*.newrelic.com *.trustpilot.com https://*.klaviyo.com https://*.kargo.com https://*.amazon-adsystem.com https://*.hotjar.com https://*.hotjar.io https://*.inkclub.com:9000 https://*.rfihub.com https://*.google.com https://*.gstatic.com https://*.nshiftportal.com https://*.kustom.co https://*.cembrapay.ch https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js www.xtento.com cdn.xtento.com connect.facebook.net twitter.com platform.twitter.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://consent.cookiebot.com https://p11.techlab-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://fonts.googleapis.com/ https://*.dibspayment.eu *.klarnacdn.net https://static.klaviyo.com *.agechecked.com *.fontawesome.com https://cdn.jsdelivr.net https://fonts.bunny.net 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ *.bootstrapcdn.com https://*.googletagmanager.com https://*.google.com https://*.googleapis.com https://*.nshiftportal.com https://*.typekit.net https://*.kustom.co https://*.klaviyo.com https://*.klarna.com maxcdn.bootstrapcdn.com *.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.snapengage.com https://*.qit.nu https://cembrapay.ch https://*.inkclub.com:9000 https://*.nshiftportal.com https://*.kustom.co https://*.klarna.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.adyen.com https://*.dibspayment.eu https://maps.googleapis.com https://player.vimeo.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://*.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io 'self' https://*.snushof.ch/ https://*.snusexpress.se/ https://*.snusexpress.com/ https://*.snusexpress.ch/ https://*.snusexpress.no/ https://*.snus.de/ https://*.snus.at/ https://*.snus.ch/ https://*.snus.no/ https://*.mysnus.com/ https://*.snuscentral.com/ https://*.nicobags.com/ https://*.buysnus.com/ https://*.snusdirect.com/ https://*.snusdirect.no/ https://*.clarity.ms https://*.pingdom.net https://*.cookiebot.eu https://id5-sync.com *.adobedtm.com *.magento.com https://*.adobedtm.com *.adobe.com *.ccdc02.com *.google-analytics.com https://*.googleapis.com https://*.googleadservices.com https://*.googleoptimize.com https://*.gstaic.com *.usercentrics.eu https://*.nr-data.net https://policy.app.cookieinformation.com https://*.online-metrix.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.techlab-cdn.com/ https://*.qliro.com *.demdex.net *.amcglobal.sc.omtrdc.net https://*.trustpilot.com https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://*.inkclub.com:9000 https://*.imgstatics.com https://*.zeotap.com https://img-statics.com https://*.rfihub.com https://*.gstatic.com https://*.nshiftportal.com https://*.m1314.com https://*.kustom.co *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.snushof.ch/; report-to report-endpoint; 1 frame-ancestors 'self'; default-src 'self' https:; script-src 'report-sample' 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'report-sample' 'self' https: 'unsafe-inline'; font-src 'self' https: 'unsafe-inline' data:; img-src 'self' https: data:; report-uri https://5eb1e20184090c563b06661b.endpoint.csper.io; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: *.retailcrm.tech https://geowidget.easypack24.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de magento-cloudflare.jetrails.com www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com secure.payu.com merch-prod.snd.payu.com *.twitter.com *.googletagmanager.com *.facebook.com *.aquamonkey.pl.local *.aquamonkey.pl *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.ytimg.com *.facebook.com quickchart.io img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com aquapolis.ua *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.google.com.ua *.paypal.com *.twitter.com *.twimg.com *.lightemporium.com *.usercentrics.eu *.fontawesome.com *.retailcrm.tech https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://polyfill-fastly.io https://browser.sentry-cdn.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com secure.payu.com secure.snd.payu.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.unpkg.com *.retailcrm.tech *.googletagmanager.com *.facebook.net *.facebook.com *.newrelic.com *.nr-data.net *.cdn-apple.com *.stripe.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://static.payu.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com unsafe-inline *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: *.retailcrm.tech *.easypack24.net https://geowidget.easypack24.net *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src aquapolis.ua https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://*.ingest.sentry.io www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com secure.payu.com merch-prod.snd.payu.com *.cloudflare.com *.google-analytics.com *.doubleclick.net *.google.com *.twitter.com *.paypal.com *.twimg.com *.retailcrm.tech *.googletagmanager.com *.facebook.com *.newrelic.com *.nr-data.net *.stripe.com *.easypack24.net *.inpost.pl *.openstreetmap.org klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://www.gstatic.com https://fonts.gstatic.com static.zip.co *.afterpay.com *.yotpo.com *.googleapis.com *.cloudflare.com *.font.im *.optimonk.com *.nikon.co.in *.slant.co *.alicdn.com *.loli.net *.migaku.com *.ziplyne.com *.googleusercontent.com *.nikon.com.au *.hsappstatic.net *.nikon.com.sg *.fontshare.com smc.org.in *.nikon-asia.com *.nikon-mea.com unpkg.com *.nikon.co.th *.crisp.chat *.githack.com yastatic.net *.cdn-apple.com *.jsdelivr.net *.zohocdn.com *.tiktok.com *.vixverify.com *.gstatic.cn use.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com https://secure-test.worldpay.com/shopper/3ds/ddc.html swellrewards.com *.swellrewards.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com *.googletagmanager.com https://pay.google.com https://secure-test.worldpay.com swellrewards.com *.swellrewards.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.files-text.com *.livechatinc.com *.livechat-files.com *.livechat-static.com https://*.googleapis.com https://*.googleusercontent.com https://maps.gstatic.com zip.co static.zip.co bpi.zip.co *.google.com.au *.linkedin.com *.yahoo.com *.adroll.com *.afterpay.com *.yotpo.com *.bazaarvoice.com *.nikon-mea.com *.nikon.com.hk *.solone.net vumbnail.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.tl www.google.tn www.google.to www.google.tt www.google.vu www.google.ws yastatic.net *.google.com *.mynikonlife.com.au *.nikon.co.in *.nikon.com.au www.google.ad www.google.as www.google.cf www.google.co.ck www.google.com.bz www.google.com.cu www.google.com.gi www.google.com.tj www.google.cv www.google.dj www.google.fm www.google.ga www.google.gl www.google.gy www.google.je www.google.ki www.google.ml www.google.ne www.google.sr www.google.st www.google.td www.google.tg www.google.tm *.baidu.com *.giphy.com *.ibb.co *.riskified.com *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com www.google.cn *.nikon.com.sg *.optimonk.com *.crwdcntrl.net *.ctnsnet.com *.ggpht.com *.nikon-asia.com *.nikon.co.th www.google.com.au *.tiktok.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.sm bitly.com dakotaram.com s3.amazonaws.com www.google.nu *.3lift.com *.adnxs.com *.adsrvr.org *.amazon-adsystem.com *.bidswitch.net *.bing.com *.bluekai.com *.casalemedia.com *.googleadservices.com *.openx.net *.outbrain.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com *.scorecardresearch.com *.taboola.com *.tapad.com google.com www.google.nr nikon-asia.com *.ytimg.com *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.livechatinc.com *.livechat-static.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://maps.googleapis.com snapwidget.com *.zip.co d35p4vvdul393k.cloudfront.net *.yotpo.com *.optimonk.com *.tiktok.com *.crazyegg.com *.adroll.com snap.licdn.com consentag.eu ctnsnet.com *.newrelic.com *.bazaarvoice.com *.disqus.com *.tailwindcss.com *.truecreatorstudio.com *.vimeo.com unpkg.com *.googleapis.com *.nikon.co.in *.alicdn.com *.riskified.com *.stackadapt.com *.qvdt3feo.com translate.google.com.hk *.googleadservices.com *.33across.com *.ctnsnet.com *.instagram.com *.cloudflare.com *.nikon.com.au d16i99j5zwwv51.cloudfront.net *.nikon.com.sg *.nikon-asia.com dakotaram.com *.cfjump.com *.nikon-mea.com *.ucweb.com *.nikon.co.th *.crisp.chat googletagmanager.com yastatic.net *.adobe.net *.adobedtm.com *.cdn-apple.com *.google-analytics.com *.jsdelivr.net *.licdn.com *.mynikonlife.com.au *.netcoresmartech.com localhost *.vixverify.com npmcdn.com *.gstatic.cn https://*.riskified.com https://www.google.com/recaptcha/api.js https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js swellrewards.com *.swellrewards.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com display.ugc.bazaarvoice.com *.livechatinc.com https://fonts.googleapis.com zip.co bpi.zip.co *.afterpay.com *.yotpo.com *.bazaarvoice.com *.optimonk.com *.nikon.co.in *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com *.nikon.com.au *.nikon.com.sg *.nikon-asia.com *.nikon-mea.com *.nikon.co.th *.mynikonlife.com.au *.vixverify.com *.cloudflare.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.livechatinc.com 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com *.livechat-static.com *.vimeocdn.com *.gstatic.com nikon-asia.com *.google.com *.nikon.com.au 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.livechatinc.com *.text.com api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://maps.googleapis.com *.zipmoney.com.au *.zip.co *.afterpay.com *.optimonk.com *.crazyegg.com *.linkedin.com *.tiktok.com ctnsnet.com *.nr-data.net *.googletagmanager.com *.google.com *.googleadservices.com *.yotpo.com *.bazaarvoice.com *.crwdcntrl.net *.doubleclick.net *.truecreatorstudio.com localhost truecreatorstudio.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bs www.google.bt www.google.by www.google.ca www.google.cg www.google.ch www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.tn www.google.to www.google.vu *.nikon.co.in www.google.bj www.google.cd www.google.ci www.google.cm www.google.com.cu www.google.com.ly www.google.com.ni www.google.com.pr www.google.com.sl www.google.com.sv www.google.com.tj www.google.dj www.google.ga www.google.im www.google.je www.google.ml www.google.ne www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tt www.google.ws *.baidu.com *.riskified.com *.stackadapt.com *.qvdt3feo.com www.google.com.na www.google.com.uy www.google.gg *.ctnsnet.com www.google.com.sb www.google.bi lottie.host *.nikon.com.au www.google.ad www.google.com.do *.nikon.com.sg www.google.com.ag www.google.gl *.nikon-asia.com www.google.co.ls www.google.ki www.google.com.bz *.nikon-mea.com www.google.cf *.ucweb.com *.nikon.co.th www.google.tm www.google.st www.google.co.ck *.netcoresmartech.com *.openfpcdn.io *.samsung.com google.com kg668dbov0.execute-api.us-east-1.amazonaws.com www.google.nr www.google.cn www.google.com.gi www.google.cv www.google.gy www.google.sm *.conversionsapigateway.com mpc-prod-1-1053047382554.us-central1.run.app mpc-prod-2-1053047382554.us-central1.run.app mpc-prod-18-s6uit34pua-uc.a.run.app www.google.com.vc www.google.li *.vixverify.com *.alicdn.com mpc-prod-14-s6uit34pua-ue.a.run.app test-drive-20-1053047382554.us-central1.run.app swellrewards.com *.swellrewards.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.livechatinc.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.crazyegg.com *.optimonk.com *.facebook.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.riskified.com 'self' 'unsafe-inline'; report-uri https://0dadbbe9-c882-40e2-9362-7a9071a0b3ac.sansec.watch/; report-to report-endpoint; 1 font-src www.paypalobjects.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://applepay.cdn-apple.com fonts.gstatic.com tibiona.it tibiona.eu data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.payplug.com *.dalenys.com https://applepay.cdn-apple.com consentcdn.cookiebot.com sibautomation.com td.doubleclick.net www.googletagmanager.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.feedaty.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://secure-magenta.dalenys.com tibiona.it tibiona.eu www.facebook.com imgsct.cookiebot.com www.google.it www.google.com.vn cdn.doofinder.com support-pre.tiledesk.com widget.tiledesk.com m.media-amazon.com tibiona.b-cdn.net imagedelivery.net *.facebook.com *.reddit.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com js.stripe.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com *.feedaty.com *.avada.io *.shopify.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com static.cloudflareinsights.com tibiona.it tibiona.eu consent.cookiebot.com sibautomation.com unpkg.com cdn.doofinder.com connect.facebook.net consentcdn.cookiebot.com widget.tiledesk.com applepay.cdn-apple.com static-eu.payments-amazon.com www.google.com www.google.it https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com assets.braintreegateway.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.feedaty.com *.fontawesome.com https://fonts.bunny.net https://secure-magenta.dalenys.com tibiona.it tibiona.eu cdn.doofinder.com widget.tiledesk.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com widget.tiledesk.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com *.feedaty.com https://get.geojs.io *.avada.io eu1-layer.doofinder.com in-automate.brevo.com tibiona.it tibiona.eu consentcdn.cookiebot.com api.tiledesk.com eu.rtmv3.tiledesk.com wss://eu1-layer.doofinder.com wss://eu.rtmv3.tiledesk.com payments-eu.amazon.com pagead2.googlesyndication.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src tibiona.it tibiona.eu www.google.com eu1-layer.doofinder.com eu.rtmv3.tiledesk.com www.googletagmanager.com payments-eu.amazon.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri widget.tiledesk.com 'self' 'unsafe-inline'; 1 default-src 'self'; object-src 'none'; font-src data: https:; frame-ancestors 'none'; form-action 'self'; script-src 'unsafe-eval' 'unsafe-inline' https:; img-src https: data:; style-src https: 'unsafe-inline'; connect-src https:; media-src https:; frame-src https:; worker-src blob:; upgrade-insecure-requests; block-all-mixed-content; 1 frame-ancestors https://sdccd.instructure.com/ https://sdmiramar.edu http://sdmiramar.edu https://dev.loc http://dev.loc; report-uri /report-csp-violation 1 frame-ancestors *.storyblok.com 'self'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; object-src www.google.com www.gstatic.com 'self' 'unsafe-inline'; connect-src quirumed.azure-api.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.doofinder.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; form-action https://sis.redsys.es/ pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; media-src widget-v2.smartsuppcdn.com c.clarity.ms *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; frame-src www.google.com vars.hotjar.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; script-src www.googletagmanager.com www.google.com www.gstatic.com www.smartsuppchat.com static.hotjar.com cdn.segmentify.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com maxcdn.bootstrapcdn.com *.photoslurp.com *.nosto.com *.doofinder.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com maxcdn.bootstrapcdn.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: 'self' data: *.doubleclick.net *.fontawesome.com maxcdn.bootstrapcdn.com applepay.cdn-apple.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.google.com *.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.iubenda.com api.payplug.com secure.payplug.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net cdn.doofinder.com *.iubenda.com https://www.magezon.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.google.com *.googletagmanager.com *.facebook.net *.doubleclick.net cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.iubenda.com api.payplug.com applepay.cdn-apple.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doubleclick.net *.doofinder.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.google-analytics.com *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.iubenda.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.gstatic.com *.cdn.userway.org; font-src 'self' fonts.gstatic.com; img-src 'self' cdn.userway.org data:; connect-src 'self' api.userway.org; script-src 'self' cdn.userway.org ajax.googleapis.com maxcdn.bootstrapcdn.com 'unsafe-eval' 'unsafe-inline' 'sha256-DA5u3f4yP+a9Q14vkm9t+LDdJOUnmWzlAHP81359zY0=' 'sha256-ccElp1F3PwWbFIK1pWZLQ+fAhCc777pDA16/ImcnLt4='; 1 default-src 'self'; form-action 'self' https://request.qlar.com; base-uri 'none'; frame-ancestors 'none'; object-src 'none'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://ad.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.es https://*.google.co.in https://*.google.co.jp https://*.google.co.uk https://*.ads.linkedin.com https://t.visitorqueue.com; frame-src 'self' https://request.qlar.com https://td.doubleclick.net https://*.googletagmanager.com https://www.youtube.com https://www.youtube-nocookie.com https://www.recaptcha.net; script-src 'strict-dynamic' 'nonce-pEOlJnS6dBMy49WYdHYflJKFiADPLQvgvcpUVkjO' 'self' https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://*.googletagmanager.com https://snap.licdn.com https://t.visitorqueue.com https://online.flippingbook.com https://d33i2vgywgme2s.cloudfront.net https://request.qlar.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.es https://*.google.co.in https://*.google.co.jp https://*.google.co.uk https://*.ads.linkedin.com https://t.visitorqueue.com; report-uri https://www.qlar.com/api/report/csp; report-to csp-endpoint; upgrade-insecure-requests; block-all-mixed-content 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.trbo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net www.mainadv.com opt.kuponacdn.de ad4m.at *.redintelligence.net *.doubleclick.net *.ad-srv.net d.c.cdnsrv.de ban.tangooserver.com *.trbo.com https://www.googletagmanager.com/ www.xtento.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.jeans-fritz.de www.facebook.com lantern.roeye.com insight.adsrvr.org adservice.google.com as.ad4m.at imagesrv.adition.com track.adform.net secure.adnxs.com t.uimserv.net widgets.trustedshops.com dsum-sec.casalemedia.com maps.gstatic.com www.google.de rtb-csync.smartadserver.com *.adfarm1.adition.com *.doubleclick.net *.twiago.com *.pubmatic.com *.adscale.de *.trbo.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.xtento.com cdn.xtento.com https://www.mollie.com data: 'self' 'unsafe-inline';, script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com www.jeans-fritz.de www.dwin1.com s.uicdn.com retrack-kupona.kuponacdn.de cdn.taboola.com amplify.outbrain.com widgets.trustedshops.com *.cloudfront.net connect.facebook.net opt.kuponacdn.de ad4m.at *.gsitrix.com *.ad-srv.net analytics.fatmedia.io trc.taboola.com *.adfarm1.adition.com analytics.tiktok.com *.adform.net pixel.mathtag.com mastertag.kpcustomer.de d.c.cdnsrv.de maps.googleapis.com ban.solocpm.com cdn.tangooserver.com eu-assets.i.posthog.com *.trbo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ www.xtento.com cdn.xtento.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.trbo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline';, connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com payments-eu.amazon.com https://maps.googleapis.com https://player.vimeo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com psb.taboola.com www.jeans-fritz.de *.gsitrix.com analytics.fatmedia.io trc-events.taboola.com retrack-kupona.kuponacdn.de maps.googleapis.com eu.i.posthog.com analytics.tiktok.com *.trbo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.friendlycaptcha.com eu-api.friendlycaptcha.eu 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.jeans-fritz.de www.google.com analytics.tiktok.com commerce.adobedc.net www.wepowerconnections.com *.posthog.com *.trbo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9f59f850-840a-442b-b604-22d85b9ebc07.sansec.watch/; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.clerk.io https://cdn.consentmanager.net https://c.delivery.consentmanager.net https://www.google.de https://x.bidswitch.net https://r.adserver01.de https://ad11.adfarm1.adition.com https://as.ad4m.at https://imagesrv.adition.com https://secure.adnxs.com https://ih.adscale.de https://rtb-csync.smartadserver.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://a.twiago.com https://c.clarity.ms https://c.bing.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.consensu.org www.google.com.ua https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io https://c.delivery.consentmanager.net https://cdn.consentmanager.net https://custom.clerk.io https://t.adcell.com https://s.pinimg.com https://ct.pinterest.com https://www.clarity.ms https://conversations-widget.brevo.com https://tm.ad-srv.net https://ad4m.at https://pix.hyj.mobi https://ad.ad-srv.net https://*.ad-srv.net https://cdn.brevo.com https://sibautomation.com https://conversations-widget.sendinblue.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.consensu.org data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com a.massive-naturmoebel.de https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io unsafe-inline assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.consensu.org https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://t.adcell.com https://as.ad4m.at https://ct.pinterest.com https://googleads.g.doubleclick.net https://*.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.consensu.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site a.massive-naturmoebel.de https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'nonce-14kOWYZ26PeJbps0lEHp9A==' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:; base-uri 'none'; report-uri https://sentry.io/api/1258985/security/?sentry_key=1891ca9ff5bc416bbb0349a074c3b41f 1 font-src fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.canadapost.ca https://sso.epost.ca *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://firebasestorage.googleapis.com mageside.com *.canadapost.ca *.canadapost-postescanada.ca *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.googleapis.com cdn.ampproject.org raw.githubusercontent.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com cdn.ampproject.org *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' *.xyplanningnetwork.com *.google.com *.gstatic.com *.googletagmanager.com *.googleapis.com googleapis.com *.cloudfront.net cloudfront.net *.cloudflare.com *.clarity.ms c.bing.com *.facebook.net *.facebook.com *.jsdelivr.net *.hubspot.com *.libsyn.com *.wistia.com browser.sentry-cdn.com *.doubleclick.net *.hsappstatic.net *.hubspotusercontent20.net *.hubspotusercontent-na1.net *.hscollectedforms.net *.usemessages.com *.hsleadflows.net *.hs-scripts.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hs-banner.net *.hsforms.net *.hsforms.com *.hubspotvideo.com *.hubspotfeedback.com *.hubapi.com *.unpkg.com *.whova.com https://whova.com *.google-analytics.com; img-src 'self' data: *.xyplanningnetwork.com *.gstatic.com *.google-analytics.com *.s3.us-west-2.amazonaws.com *.wistia.com *.hsforms.net *.googleapis.com *.googletagmanager.com *.rogerdooley.com *.bing.com *.clarity.ms *.hubspot.com *.hubspot.net *.googleusercontent.com *.hs-forms.com *.hsforms.com *.hubspotusercontent00.net *.hubspotusercontent-na1.net *.w3.org *.whova.com whova.com *.facebook.com *.clarity.ms c.bing.com www.google.com perf-na1.hsforms.com static.hsappstatic.net; frame-src 'self' xyplanningnetwork.com *.xyplanningnetwork.com *.hs-sites.com *.facebook.com *.hsforms.com *.google.com *.doubleclick.net *.googletagmanager.com *.hubspot.com *.hubspotvideo.com *.hubspot.net *.youtube.com *.libsyn.com https://whova.com whova.com *.whova.com; style-src 'self' 'unsafe-inline' *.xyplanningnetwork.com *.cloudflare.com *.fs1.hubspotusercontent-na1.net *.fontawesome.com *.hubspot.net *.googeapis.com *.googletagmanager.com *.hsappstatic.net *.gstatic.com fonts.googleapis.com; connect-src 'self' *.zapier.com *.hsappstatic.net *.xyplanningnetwork.com *.cloudflare.com *.googleapis.com *.googlesyndication.com aeo-evaluator-production.up.railway.app googleadservices.com *.googleadservices.com *.googletagmanager.com hubspot-forms-static-embed.s3.amazonaws.com *.facebook.com *.clarity.ms *.bing.com google.com *.google.com *.wistia.com *.google-analytics.com *.hubspot.com *.doubleclick.net *.hubspot.net *.hubapi.com *.rippling.com *.hsforms.net *.hsforms.com *.hs-banner.com *.hsappstatic.net *.hscollectedforms.net; frame-ancestors 'self' https://*.xyplanningnetwork.com; block-all-mixed-content; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://api.eu1.exponea.com https://static.me-talk.ru https://connect.facebook.net https://www.clarity.ms https://mc.yandex.ru https://www.gstatic.com; style-src 'self' 'unsafe-inline' https:; font-src 'self' data:; img-src 'self' data: blob: https:; connect-src 'self' https://api.country.is https://www.google-analytics.com https://stats.g.doubleclick.net https://api.eu1.exponea.com https://static.me-talk.ru https://www.facebook.com https://y.clarity.ms https://mc.yandex.ru https://www.googletagmanager.com https://www.gstatic.com https://www.google.com https://api.stage.unamoliya.uz https://faro-stage.robocash.global; media-src 'self' blob:; worker-src 'self' blob:; frame-src 'self' https://www.googletagmanager.com https://www.facebook.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors none; 1 script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://dap.digitalgov.gov https://static.cloudflareinsights.com https://script.crazyegg.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com; 1 default-src 'self' https://*.mipulse.co https://*.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; script-src 'self' 'nonce-qbqEqjD166DA5piHFoRNYg==' 'unsafe-eval' https://maps.googleapis.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://cdn.cookielaw.org https://connect.facebook.net https://*.krxd.net https://cstatic.weborama.fr https://cdn.livechatinc.com https://api.livechatinc.com https://pureinfluencer.idrove.it https://assets.adobedtm.com https://www.youtube.com/ 'sha256-IXwUgYQlz6whdqY9fAsuWm5tF3a/48gpSOx/RrJVM2M=' 'sha256-ZmOqvxu/SYXtKMZjkegWCZv0fNWqYPMIAbkDSAFd9HQ=' 'sha256-rwMOiOeVICH7/Cjy5SkreID3OOi5HTrit357k22hUDQ=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-mIJsOQOBL5URHW6ppIPLOp054yHEgxgh+tumu3VW4uY=' 'sha256-L6GTuf9tzJT4M/eRPyT9q18L0UnaWdBIpW2kYl6Fkwk=' 'sha256-IdzrL+27mccklOzBWVvXNgfZ8D6HIFjn7Y46BiYZxTY=' 'sha256-5Cz4ZsI1P9g7z/hqtco8MVFsPeuN1kkADoDE9KE5Nzw=' 'sha256-gJR8nYIj9BIisULplpuG6AU6/3PMeA+ZN5sISuG7Roc=' 'sha256-73tOv4V0QRBLpWjCPRThujEhdW5bB4Hx1uA8jBszxUQ=' 'sha256-zCzIA5Bv5v0Y/u686kOREhia31pT64lCSWPLez72SsI=' 'sha256-2sDhctfJAd53/P/qWSTE71aWvnK2vYVrDmF3P2a5yC0=' 'sha256-g6+9PI/TlodFbDrCPHRXzigoOKGKtu3pJ7F2bPLWRQ0=' 'sha256-7PyrcA0NOMOO1UolfxOEr0a+ClC2NRZZopOV0aDnqTc=' 'sha256-7sUD0rKPq7QkPTkJQIxh29ga8KBXgV/+rXHtn0jzPRg=' 'sha256-ULRvWsXdAu0tZgP5Lm/YcdG09i5xDrD0FTeK0+8+LDY=' 'sha256-ykJUQ34Vs5aGtiZ8/Y/3jk7xHgXHFFdobPe/XpUPwbU=' 'sha256-z8P9D8SlqjFhTbJlsocGwGVQPS1kjtDPFseU75brggM=' 'sha256-V685dp7Jpv93B7VcKE2er/ZlyPI5HIRWk2E6qllmjeY=' 'sha256-U7/M8TKZhT8DWAhD2RL1hr60w7H1i+GRfNYe7iOJMfE=' 'sha256-nOc3LegX/8ADmYdGC1d7ig0o995pVq2rfz34uz28tTo=' 'sha256-/XghktC/jSbJ/rP3BqRv6WKIGjlfgmVSGsI6nJAo5qw=' 'sha256-ae9Y2uLK/1m5oiL4aIDKOSYBXCHA/9LjsjAQ5a+qjd4='; img-src 'self' data: https://*.krxd.net https://www.facebook.com https://*.adsrvr.org https://maps.googleapis.com https://www.google.com https://www.google.co.in https://www.google.ca https://ups.analytics.yahoo.com https://cm.g.doubleclick.net https://*.mipulse.co https://maps.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com http://report.mitsubishicars.com https://cdn.cookielaw.org; frame-src 'self' data: https://www.facebook.com https://8715429.fls.doubleclick.net https://bid.g.doubleclick.net https://aax-eu.amazon-adsystem.com https://mitsubishi1.solution.weborama.fr https://*.krxd.net https://td.doubleclick.net https://*.mipulse.co https://secure.livechatinc.com; connect-src 'self' https://cdn.cookielaw.org https://stats.g.doubleclick.net https://*.onetrust.com https://analytics.google.com https://pagead2.googlesyndication.com https://*.mipulse.co https://maps.googleapis.com/ https://www.google-analytics.com https://api.livechatinc.com https://pureinfluencer-api.idrove.it https://pro.ip-api.com https://rts-api.idrove.it; media-src 'self' data: https://*.mipulse.co https://cdn.livechatinc.com; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 manifest-src 'self' 'unsafe-inline' https://*.sata.com https://sata.com; img-src 'self' blob: data: data: 'unsafe-inline' https://gundesigner.s3.eu-central-1.amazonaws.com https://hm.baidu.com *.facebook.com *.ggpht.com ssl.google-analytics.com www.google-analytics.com *.google.com analytics.google.com maps.google.com translate.google.com https://translate.google.com www.google.com www.googleadservices.com *.googleapis.com translate.googleapis.com *.googlesyndication.com www.googletagmanager.com https://gstatic.com maps.gstatic.com www.gstatic.com https://www.gstatic.com www.gstatic.com/recaptcha *.paypal.com www.paypalobjects.com https://*.sata.com https://sata.com https://i.vimeocdn.com *.youtube.com *.ytimg.com https://i.ytimg.com *.doubleclick.net *.facebook.net *.fbcdn.net https://cdn.cookielaw.org https://www.google.de userlike-cdn-operators.s3-eu-west-1.amazonaws.com d3upe020n1uosc.cloudfront.net www.userlike.com userlike-store-media-files.s3.amazonaws.com i.ytimg.com https://tr.lfeeder.com/ https://sc.lfeeder.com/ *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug https://www.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://www.saferpay.com https://www.facebook.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io test.saferpay.com www.saferpay.com saferpay.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://js.fraugster.com/v1/fraugster.js https://www.gstatic.cn/recaptcha/ https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://graph.facebook.com https://js.facebook.com https://google-analytics.com https://ssl.google-analytics.com https://www.google-analytics.com https://*.google.com maps.google.com https://tagmanager.google.com https://translate.google.com https://www.google.com https://www.google.com/recaptcha/ https://*.googleadservices.com maps.googleapis.com https://translate.googleapis.com https://*.googlesyndication.com https://googletagmanager.com https://www.googletagmanager.com https://*.googletagservices.com https://www.gstatic.com https://www.gstatic.com/recaptcha/ https://js-agent.newrelic.com https://www.paypal.com https://www.paypalobjects.com https://*.sata.com https://sata.com https://api.userlike.com https://m.youtube.com https://www.youtube.com https://d3dc1lgancj6l0.cloudfront.net https://*.doubleclick.net https://connect.facebook.net https://bam.eu01.nr-data.net https://recaptcha.net https://www.recaptcha.net https://cdn.cookielaw.org api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net https://userlike-cdn-umm.b-cdn.net/ https://sc.lfeeder.com/ googleads.g.doubleclick.net https://www.sata.com https://stats.sata.com/ assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com test.saferpay.com www.saferpay.com saferpay.com js.fraugster.com *.google.com *.gstatic.com https://cdn.cookie-script.com; style-src 'self' 'unsafe-inline' *.google.com tagmanager.google.com https://fonts.googleapis.com translate.googleapis.com www.googletagmanager.com https://fonts.gstatic.com https://*.sata.com https://sata.com *.adobe.com maxcdn.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.gstatic.com; frame-ancestors 'self' https://*.sata.com https://sata.com; frame-src 'self' 'unsafe-inline' *.facebook.com *.google.com maps.google.com https://recaptcha.google.com https://www.google.com/recaptcha/ maps.googleapis.com *.googlesyndication.com www.googletagmanager.com *.paypal.com www.paypalobjects.com https://www.saferpay.com https://*.sata.com https://sata.com https://player.vimeo.com www.youtube-nocookie.com *.youtube.com *.doubleclick.net connect.facebook.net recaptcha.net *.recaptcha.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net www.youtube.com player.vimeo.com fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com test.saferpay.com www.saferpay.com saferpay.com; media-src 'self' 'unsafe-inline' *.adobe.com dai.google.com https://*.sata.com https://sata.com d3dc1lgancj6l0.cloudfront.net userlike-store-media-files.s3.amazonaws.com www.userlike.com blob:; object-src 'self' 'unsafe-inline' *.googlesyndication.com https://*.sata.com https://sata.com; font-src 'self' data: data: 'unsafe-inline' https://fonts.gstatic.com https://*.sata.com https://sata.com maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com; form-action 'self' 'unsafe-inline' *.facebook.com *.google.com https://*.sata.com https://sata.com connect.facebook.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com test.saferpay.com www.saferpay.com saferpay.com ; worker-src 'self' blob: https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com www.google.com https://*.sata.com https://sata.com www.recaptcha.net; connect-src 'self' 'unsafe-eval' 'unsafe-inline' about: data: https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://hm.baidu.com *.facebook.com www.google-analytics.com *.google.com ampcid.google.com analytics.google.com maps.google.com translate.google.com https://maps.googleapis.com translate.googleapis.com *.googlesyndication.com www.googletagmanager.com www.googletagservices.com www.gstatic.com https://privacyportal-fr.onetrust.com *.paypal.com www.paypalobjects.com https://*.sata.com https://sata.com https://eu-api.friendlycaptcha.eu/api/ *.doubleclick.net stats.g.doubleclick.net connect.facebook.net https://bam.eu01.nr-data.net/ https://cdn.cookielaw.org https://dvkmaxr3fb.execute-api.eu-west-1.amazonaws.com https://u4irfd30ti.execute-api.eu-west-1.amazonaws.com https://api.userlike.com/api/um/chat/button/check/ wss://umd.userlike.com umd.userlike.com api.userlike.com d3upe020n1uosc.cloudfront.net www.userlike.com https://geolocation.onetrust.com/ ssl.google-analytics.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com test.saferpay.com www.saferpay.com saferpay.com t.elasticsuite.io *.google-analytics.com https://consent.cookie-script.com/collect; child-src 'self' blob: http: https: 'unsafe-inline' *.facebook.com *.google.com *.googlesyndication.com www.googletagmanager.com *.paypal.com www.paypalobjects.com https://sata.com https://*.sata.com www.youtube.com *.doubleclick.net connect.facebook.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net; default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://www.facebook.com https://*.sata.com https://sata.com https://player.vimeo.com https://stats.sata.com test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com; base-uri 'self' 'unsafe-inline'; report-uri https://sentry.imi.de/api/15/security/?sentry_key=74dec59931c24572bd888c406dc88cc4 1 script-src-elem *.livechatinc.com *.payments-amazon.com https://*.helloextend.com *.route.com *.routeapp.io bam.nr-data.net tpc.googlesyndication.com www.full-race.com www.google-analytics.com *.affirm.com connect.facebook.net visualsponline.azurewebsites.net gc.kis.v2.scr.kaspersky-labs.com ssl.google-analytics.com www.pagespeed-mod.com *.klaviyo.com www.gstatic.com *.google.com js.braintreegateway.com c.paypal.com ajax.cloudflare.com www.paypal.com www.paypalobjects.com www.googleadservices.com localhost:49506 me.kis.v2.scr.kaspersky-labs.com data1.ilplet.com z.moatads.com browser.sentry-cdn.com js.sentry-cdn.com gc.kes.v2.scr.kaspersky-labs.com cdn.ghostaio.com milkpload.net hublosk.com jullyambery.net ads.creative-serving.com payperclickadz.com floatingplayer.com ucads-cdn.ucweb.com cloudjs.netlify.com appslinker.net ss1.js.images.static.jqurey.vip www.googletagmanager.com rialto-gms.s3.amazonaws.com pilaff-up.ru *.googleapis.com *.doubleclick.net *.verifypass.com https://www.google.com/_/scs/shopping-verified-reviews-static/* *.yotpo.com d18eg7dreypte5.cloudfront.net *.revenuehunt.com contact.gorgias.help 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem www.full-race.com cdn1.affirm.com use.fontawesome.com static.klaviyo.com gc.kis.v2.scr.kaspersky-labs.com me.kis.v2.scr.kaspersky-labs.com cdn.honey.io *.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; font-src *.gstatic.com *.googleapis.com *.yotpo.com https://d1cwup7r903a1d.cloudfront.net www.full-race.com www.affirm.com themes.googleusercontent.com static3.avast.com www.slant.co assets.quadpay.com cdn.megabonus.com cdn.honey.io www.clearplay.com at.alicdn.com use.typekit.net gateway.zscalerone.net pouch-global-font-assets.s3.eu-central-1.amazonaws.com maxcdn.bootstrapcdn.com fonts.googleapis.com *.livechatinc.com static.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.facebook.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com www.full-race.com 'self' 'unsafe-inline'; frame-ancestors www.full-race.com 'self'; frame-src fast.amc.demdex.net *.adobe.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.amazon.com *.payments-amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.affirm.com *.livechatinc.com *.facebook.com bid.g.doubleclick.net *.youtube-nocookie.com * *.yotpo.com googleads.g.doubleclick.net tpc.googlesyndication.com mediazilla.com *.google.com ssl.kaptcha.com www.googletagmanager.com www.paypalobjects.com web.archive.org div.show static.klaviyo.com www.google.com.jm www.google.ca www.google.cl www.google.com.sg floatingplayer.com mozbar.moz.com www.google.iq *.securly.com t.windows7home.com t.032168.com www.google.com.tr 192.168.148.132:15871 www.google.com.mx utp.ucweb.com ss1.js.images.static.jqurey.vip www.google.com.pr www.google.it gateway.zscalerthree.net acestream.me mini.bijiatu.com 'self' 'unsafe-inline'; img-src data: *.yotpo.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ *.avada.io assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.affirm.com *.payments-amazon.com *.livechatinc.com https://*.helloextend.com *.klaviyo.com googleads.g.doubleclick.net www.googletagmanager.com *.nr-data.net *.youtube.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.yotpo.com *.route.com *.routeapp.io bam.nr-data.net connect.facebook.net tpc.googlesyndication.com z.moatads.com js.sentry-cdn.com browser.sentry-cdn.com polyfill.io gateway.zscalerone.net ucads-cdn.ucweb.com *.google.com *.doubleclick.net *.verifypass.com www.google.com/_/scs/shopping-verified-reviews-static/* *.revenuehunt.com contact.gorgias.help 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.klaviyo.com assets.braintreegateway.com *.yotpo.com cdn1.affirm.com *.googleapis.com cdn.honey.io gateway.zscalerone.net 'self' 'unsafe-inline'; object-src noop.style 'self' 'unsafe-inline'; media-src *.adobe.com app.tealhq.com tts.baidu.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com mws.amazonservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.affirm.com https://*.helloextend.com *.klaviyo.com www.googleadservices.com www.googletagmanager.com *.nr-data.net vimeo.com pilot-payflowlink.paypal.com *.googleapis.com *.google.com *.yotpo.com api.paypal.com *.route.com bam.nr-data.net *.doubleclick.net www.full-race.com localhost:49506 api.rollbar.com hm.baidu.com o19233.ingest.sentry.io plugin.ucads.ucweb.com gjtrack.ucweb.com h7s9xishng.execute-api.us-east-1.amazonaws.com floatingplayer.com uc.gre track.uc.cn ss1.js.images.static.jqurey.vip translate.googleapis.com *.facebook.com *.lab.amplitude.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://shopline.itau.com.br *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://www.magezon.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.pagar.me *.avada.io *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.pagar.me https://viacep.com.br https://www.viacep.com.br https://get.geojs.io *.avada.io http://api.itaushopline.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net maxcdn.bootstrapcdn.com fonts.gstatic.com designpanels.de data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com designpanels.de 'self' 'unsafe-inline'; frame-ancestors designpanels.de 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.klarna.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com www.xtento.com designpanels.de 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com 'self' data: validate.fishpig.co.uk *.klarna.com *.klarnaevt.com *.klarnacdn.net maps.googleapis.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com designpanels.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com player.vimeo.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com sc-static.net *.snapchat.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com www.xtento.com cdn.xtento.com designpanels.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com assets.braintreegateway.com fonts.googleapis.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com designpanels.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' data: designpanels.de 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com sc-static.net *.snapchat.com *.doubleclick.net *.run.app *.typeform.com designpanels.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com designpanels.de http: https: blob: 'self' 'unsafe-inline'; default-src designpanels.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com fonts.googleapis.com 'self' data: *.alkar.es *.alkar-autospiegel.de data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.cloudfront.net www.google.es www.google-analytics.com stats.g.doubleclick.net *.onetrust.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.alkar.es *.alkar-autospiegel.de alkar.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.gstatic.com sl.google-analytics.com js-agent.newrelic.com bam.nr-data.net *.onetrust.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.alkar.es *.alkar-autospiegel.de https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com fonts.gstatic.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.alkar.es *.alkar-autospiegel.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com www.google-analytics.com stats.g.doubleclick.net bam.nr-data.net *.onetrust.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.alkar.es *.alkar-autospiegel.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.alkar.es *.alkar-autospiegel.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.v.me https://*.visa.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.visa.com https://*.v.me;img-src 'self' https://*.v.me https://*.visa.com https://*.unica.com https://ad.doubleclick.net;style-src 'self' 'unsafe-inline' https://*.visa.com;object-src https://*.v.me https://*.visa.com data:;report-uri /logging/logCSPReport; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com *.stape.io https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.consentmanager.net *.kameleoon.io *.linkedin.com *.kellerfahnen.ch *.etrusted.com *.bing.com *.bing.net *.facebook.net *.licdn.com *.google.de *.googletagmanager.com kellerfahnenbalancer.ch.trendhosting.cloud https://files.zakeke.com https://images.unsplash.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net magefan.com cm.magefan.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.stape.io https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.consentmanager.net *.kameleoon.io *.linkedin.com *.kellerfahnen.ch *.etrusted.com *.bing.com *.bing.net *.facebook.net *.licdn.com *.google.de *.googletagmanager.com kellerfahnenbalancer.ch.trendhosting.cloud *.maatoo.io https://maps.googleapis.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.stape.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.consentmanager.net *.kameleoon.io *.linkedin.com *.kellerfahnen.ch *.etrusted.com *.bing.com *.bing.net *.facebook.net *.licdn.com *.google.de *.googletagmanager.com kellerfahnenbalancer.ch.trendhosting.cloud *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.stape.io unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.consentmanager.net *.kameleoon.io *.linkedin.com *.kellerfahnen.ch *.etrusted.com *.bing.com *.bing.net *.facebook.net *.licdn.com *.google.de *.googletagmanager.com kellerfahnenbalancer.ch.trendhosting.cloud *.maatoo.io https://maps.googleapis.com https://player.vimeo.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com pay.google.com places.googleapis.com *.trustedshops.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 base-uri 'none'; style-src 'report-sample' 'self' 'unsafe-inline' ; object-src 'none'; img-src 'self' *.regenwald.org data: ; connect-src 'self' ; block-all-mixed-content; report-uri /csp-violation-report/a206a119-350 1 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: https://static-content.vnforapps.com https://cdn.chattigo.com https://media.chattigo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com www.facebook.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com https://maps.googleapis.com *.gstatic.com https://static-content.vnforapps.com https://m.vnforapps.com https://h.online-metrix.net https://components.chattigo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io maps.googleapis.com api.comapi.com bam.nr-data.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com https://config-global.chattigo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://vervoe.com https://www.facebook.com https://secure.gravatar.com https://perf-na1.hsforms.com https://7663936.fs1.hubspotusercontent-na1.net https://www.googletagmanager.com https://bat.bing.com https://www.google.co.id https://i.ytimg.com https://b.sf-syn.com https://no-cache.hubspot.com https://forms-na1.hsforms.com https://www.google.co.in https://www.google.ca https://lh3.googleusercontent.com https://i.vimeocdn.com https://www.google.com.ph blob: https://lh4.googleusercontent.com https://lh7-rt.googleusercontent.com https://websitedemos.net https://account.crocoblock.com https://img.youtube.com https://lh5.googleusercontent.com https://www.google.com.pk https://www.linkedin.com https://www.google.com.ng https://www.google.co.nz https://www.google.co.za https://lh7-us.googleusercontent.com https://www2.deloitte.com https://www.google.co.ls https://www.google.jo https://www.google.com.hk https://www.google.co.uk https://www.google.com.eg https://www.google.co.zw https://www.google.com.my https://perf.hsforms.com https://ad.doubleclick.net https://www.google.mw https://www.google.tt https://www.google.com.et https://fonts.gstatic.com https://translate.google.com https://www.google.lk https://pos.baidu.com https://www.google.com.pr https://www.google.com.tr https://www.google.com.vn https://www.google.com.ar https://www.google.kz https://www.google.com.na https://res.cloudinary.com https://www.google.co.ke https://www.google.com.qa https://cdn.honey.io https://www.google.com.co https://www.google.com.ec https://www.google.co.ug https://www.google.com.pg https://www.google.com.ua https://www.google.co.tz https://www.google.co.ma https://www.google.ae https://yastatic.net https://www.google.com.sg https://googleads.g.doubleclick.net https://www.google.tn https://exceptions.hs-embed-reporting.com https://www.google.ru https://www.google.co.th https://www.google.com.bd https://www.google.mn https://f.hubspotusercontent30.net https://www.google.com.lb https://www.google.com.kh https://www.google.co.mz https://www.google.com.br https://www.google.cm https://www.google.cl https://www.google.com.mm https://www.google.so https://www.google.com.np https://www.google.ci https://www.google.com.sa https://www.google.com.mx https://www.google.com.gh https://www.google.co.uz https://www.google.com.gt https://zapier-images.imgix.net https://www.google.am https://www.gstatic.com https://www.google.iq https://www.google.com.bh https://www.google.mv https://www.google.com.bn https://lh3.google.com https://www.google.com.fj https://storage.googleapis.com https://www.google.rs https://www.google.com.af https://bat.bing.net https://www.google.bt https://www.google.la https://message-cdn.getvero.com https://www.google.com.om https://www.google.com.jm https://www.google.co.il https://www.google.com.sv https://www.google.co.jp https://www.google.rw https://www.google.dz https://www.google.com.tw https://www.google.com.uy https://ps.w.org https://px4.ads.linkedin.com https://www.google.cd https://www.google.mu https://www.google.com.sl https://www.google.com.ly https://www.google.az https://www.google.com.ni https://www.google.co.kr https://heapanalytics.com https://www.google.com.pe https://s.w.org https://www.google.ch https://www.google.co.cr https://files.atlas.so https://www.google.no https://www.google.com.bz https://www.google.fr https://www.google.pl https://www.google.be https://www.google.it https://www.google.nl https://www.google.ie https://www.google.ro https://www.google.ws https://www.google.sk https://www.google.de https://www.google.ee https://www.google.es https://www.google.se https://www.google.com.kw https://www.google.mk https://www.google.hr https://cdn.jsdelivr.net https://www.google.com.cy https://www.google.at https://stats.g.doubleclick.net https://www.google.co.bw https://www.google.cz https://really-simple-ssl.com ; default-src 'self'; script-src 'self' 'unsafe-inline' https://vervoe.com https://cdn.segment.com https://www.googleoptimize.com https://tag.clearbitscripts.com https://js.hubspot.com https://x.clearbitjs.com https://cdn.firstpromoter.com https://b.sf-syn.com https://reveal.clearbit.com https://bat.bing.com https://js-na1.hs-scripts.com https://js.hsforms.net https://snap.licdn.com blob: https://js.hscollectedforms.net https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://www.googletagmanager.com https://hubspot.clearbit.com https://infirc.com https://js.hs-banner.com https://js.hsleadflows.net https://cdnjs.cloudflare.com https://js.hs-analytics.net https://d10lpsik1i8c69.cloudfront.net https://www.youtube.com https://zapier.com https://ajax.googleapis.com https://tracking.g2crowd.com https://gc.kes.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://www.google-analytics.com https://js.convertflow.co https://ssl.luckyorange.com https://app.convertflow.co https://cdn.zapier.com https://cdn.amplitude.com https://connect.facebook.net https://player.vimeo.com https://www.google.com https://js.hs-scripts.com https://googleads.g.doubleclick.net https://3001.scriptcdn.net https://cta-service-cms2.hubspot.com https://translate.googleapis.com https://translate.google.com https://translate-pa.googleapis.com https://mstat.acestream.net https://www.printfriendly.com https://infird.com https://ritrag.com https://localhost https://cdn.toolszen.com https://get663.com https://fast.wistia.com https://maps.googleapis.com https://secured-pixel.com https://mainf.global-cache.online https://me.kes.v2.scr.kaspersky-labs.com https://sslwidget.criteo.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://vervoe.com https://cdn.segment.com https://www.googleoptimize.com https://tag.clearbitscripts.com https://js.hubspot.com https://x.clearbitjs.com https://cdn.firstpromoter.com https://b.sf-syn.com https://reveal.clearbit.com https://bat.bing.com https://js-na1.hs-scripts.com https://js.hsforms.net blob: https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://hubspot.clearbit.com https://infirc.com https://cdnjs.cloudflare.com https://www.youtube.com https://zapier.com https://ajax.googleapis.com https://gc.kes.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://js.convertflow.co https://app.convertflow.co https://cdn.zapier.com https://player.vimeo.com https://www.google.com https://3001.scriptcdn.net https://cta-service-cms2.hubspot.com https://translate.googleapis.com https://translate.google.com https://translate-pa.googleapis.com https://mstat.acestream.net https://www.printfriendly.com https://infird.com https://ritrag.com https://localhost https://cdn.toolszen.com https://get663.com https://fast.wistia.com https://maps.googleapis.com https://secured-pixel.com https://mainf.global-cache.online https://me.kes.v2.scr.kaspersky-labs.com https://sslwidget.criteo.com ; style-src 'self' 'unsafe-inline' https://vervoe.com https://fonts.googleapis.com https://adblockers.opera-mini.net https://gc.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com https://ff.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://cdn.honey.io https://pwm-image.trendmicro.com https://cdn.zapier.com https://dw0d7wrju75izszv1lk.mentionusercontent.net https://builder-assets.unbounce.com https://use.fontawesome.com ; style-src-elem 'self' 'unsafe-inline' https://vervoe.com https://fonts.googleapis.com https://adblockers.opera-mini.net https://gc.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com https://ff.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://cdn.honey.io https://pwm-image.trendmicro.com https://cdn.zapier.com https://dw0d7wrju75izszv1lk.mentionusercontent.net https://builder-assets.unbounce.com https://use.fontawesome.com ; connect-src 'self' https://api.segment.io https://cdn.segment.com https://bat.bing.com https://www.google-analytics.com https://www.facebook.com https://geoip.cookieyes.com https://px.ads.linkedin.com https://cta-service-cms2.hubspot.com wss://in.visitors.live https://region1.google-analytics.com wss://visitors.live https://forms.hscollectedforms.net https://tracking.g2crowd.com https://adservice.google.com https://api-preview.luckyorange.com https://bs.nakanohito.jp https://z.clarity.ms https://forms.hsforms.com https://pubsub.googleapis.com https://vervoe.com https://r.clarity.ms https://gtm.miinto.de https://perf-na1.hsforms.com https://q.clarity.ms https://t.clarity.ms https://x.clarity.ms https://lexicon.33across.com https://lm.serving-sys.com https://overbridgenet.com https://api.solarflareenergy.net https://translate.googleapis.com https://clientstream.launchdarkly.com http://ad.doubleclick.net https://api.software-downloading.com https://forms-na1.hubspot.com https://api.datacloudstat.com https://api.vid-adblocker.com https://lh7-rt.googleusercontent.com https://apis.google.com https://analytics.google.com https://polyfilljs.org https://hubspot-forms-static-embed.s3.amazonaws.com https://translate-pa.googleapis.com https://zapier.com https://api.solarspireconsulting.com data: https://infragrid.v.network https://api.amcreativemedia.com https://yandex.ru https://n.emojikeyboardforchrome.com https://n.wistiaextension.com https://api.zapier.com https://api.highdataanalytics.com http://localhost https://api.fbanalytics.org https://www.googleadservices.com https://sdmextension.com https://api.solaranalyticscorp.com https://n.noadsadblocker.com https://retcode-us-west-1.arms.aliyuncs.com https://pk.api4load.net https://api.mkmediaworks.com https://api.killadsapi.com properties https://api.global-data-lab.com https://cdnml.global-cache.online https://bat.bing.net https://api.aituria.com ws://localhost https://metrics-dre.dt.dbankcloud.cn https://ff.kis.v2.scr.kaspersky-labs.com https://www.googletagmanager.com wss://ff.kis.v2.scr.kaspersky-labs.com https://metrics-dra.dt.dbankcloud.cn https://gc.kis.v2.scr.kaspersky-labs.com https://api.socialsolutionapp.com https://api.ginger-analytics.com https://www.gstatic.com https://api.video-adblock.com https://tracking-api.production.g2.com https://app.atlas.so wss://app.atlas.so https://cdn.fs.atlas.so https://i.ytimg.com https://gjtrack.ucweb.com https://me.kes.v2.scr.kaspersky-labs.com wss://127.0.0.1 https://me.kis.v2.scr.kaspersky-labs.com https://tracking-api.g2.com https://service5.gstatic-cache.com https://visitors.live https://in.visitors.live https://rum.browser-intake-us5-datadoghq.com https://gc.kes.v2.scr.kaspersky-labs.com https://ipgeolocation.abstractapi.com wss://gc.kis.v2.scr.kaspersky-labs.com https://code.jquery.com https://www.google.com.au https://region1.analytics.google.com https://www.google.com.mx https://www.google.com.pk https://www.google.ae https://www.google.com.ua https://www.google.co.za https://www.google.ca https://www.google.de https://www.google.no https://www.google.co.uk https://www.google.it https://www.google.com.ng https://www.google.co.in https://www.google.ci https://www.google.com.hk https://www.google.com.ar https://www.google.com.ph https://www.google.com.vn https://www.google.fr https://www.google.com.mm https://www.google.co.jp https://www.google.nl https://www.google.pl https://www.google.com.et https://www.google.com.br https://www.google.co.th https://www.google.pt https://www.google.com.pr https://www.google.lv https://www.google.com.gt https://www.google.co.id https://www.google.ch https://www.google.co.nz https://www.google.com.sg https://www.google.co.ke https://www.google.co.uz https://www.google.be https://www.google.ru https://www.google.rs https://www.google.es https://www.google.dz https://www.google.co.zw https://www.google.hr https://www.google.com.my https://www.google.se https://www.google.hu https://www.google.com.bd https://www.google.com.kh https://www.google.co.ug https://www.google.co.il https://www.google.lk https://www.google.com.co https://www.google.bs https://www.google.com.af https://www.google.cz https://www.google.mw https://www.google.com.pe https://www.google.co.tz https://www.google.ie https://www.google.com.tr https://www.google.so; frame-src 'self' https://app.hubspot.com https://player.vimeo.com https://www.youtube.com https://td.doubleclick.net https://mozbar.moz.com https://forms.hsforms.com https://www.figma.com https://w.soundcloud.com https://gateway.zscloud.net https://cdn.segment.com https://div.show https://res.dugouthub.com https://gateway.zscalertwo.net https://block.opendns.com https://support.google.com https://zapier.com https://www.googletagmanager.com https://trust.holisticai.com http://player.vimeo.com.x.4d7e1d6303ff00467108281053e323e3d100.43d7524b.id.opendns.com http://td.doubleclick.net.x.2db9d6b90e4a504d080b2ef0b5c07014005b.92708534.id.opendns.com null http://td.doubleclick.net.x.b191ff890e5ca04c370b22303993b550882e.43d7532d.id.opendns.com https://ext.rdplinks.com http://td.doubleclick.net.x.3c95fef70c68304875082ad0c26fbddc0cb3.d045247e.id.opendns.com https://wp-rocket.me https://www.linkedin.com https://www.holisticai.com http://td.doubleclick.net.x.31e78aaa0948b04b5b08ff6066e5b1aaa1a0.43d75326.id.opendns.com https://bat.bing.com blob: http://127.0.0.1; font-src 'self' https://vervoe.com https://fonts.gstatic.com https://use.typekit.net moz-extension https://cdn.scite.ai https://ray.st ms-browser-extension https://cdn.userlove.io chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Regular.woff chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Medium.woff2 https://static.hsappstatic.net http://themes.googleusercontent.com https://frontdoorcdn.mindverse.ai chrome-extension://05C29A66-3002-46DE-B4FC-6BFF211D2428/fonts/Inter-Variable.ttf chrome-extension://05C29A66-3002-46DE-B4FC-6BFF211D2428/fonts/Recoleta-Variable.otf chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Bold.woff https://at.alicdn.com https://migaku-public-data.migaku.com chrome-extension://extension_id__/fonts/Inter-Variable.ttf chrome-extension://extension_id__/fonts/Recoleta-Variable.otf chrome-extension://extension_id__/fonts/SFProText-Variable.otf https://vervoe.temp513.kinsta.cloud; object-src 'self' https://trust.holisticai.com https://rules.cityofnewyork.us; manifest-src 'self' https://vervoe.com; worker-src 'self' blob: data:; media-src 'self' data: https://ssl.gstatic.com; child-src 'self' blob:; report-uri https://vervoe.com/wp-json/rsssl/v1/csp?rsssl_apitoken=1646020246; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-edb55fb5d376cef7b355a314926c8335' 'strict-dynamic' https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/tag/js/gpt.js https://static.hotjar.com/ https://cdn.cookielaw.org/ https://imasdk.googleapis.com/ https://*.hotjar.io/ https://connect.facebook.net/ https://*.facebook.com/ https://*.facebook.net/ https://analytics.tiktok.com/ https://galt.hit.gemius.pl/ ; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org/ https://fonts.googleapis.com/ https://www.biathlonworld.com/embedded-player.css https://www.atletiek.nl/build/css/css-ebu.build.css; img-src 'self' data: https://imageservice.evsports.opentv.com/images/v1/image/Sport/ https://cabi.evsports.sports.opentv.com/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://static.hotjar.com/ https://cdn.cookielaw.org/logos/ https://www.google.com/ https://www.google.co.uk/ https://www.facebook.com/ https://*.g.doubleclick.net/ https://ep1.adtrafficquality.google/pagead/ https://*.googlesyndication.com/ https://www.ebu.ch/files/live/sites/ebu/files/images/ https://*.cloudfront.net/EBU/; font-src 'self' data: https://fonts.gstatic.com/; connect-src 'self' https://cdn.cookielaw.org/ https://api.evsports.opentv.com/metadata/delivery/ https://www.google.com/pagead/form-data/ https://www.google.com/ccm/form-data/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://*.googlesyndication.com/ https://ep1.adtrafficquality.google/getconfig/sodar https://securepubads.g.doubleclick.net/pagead/ https://securepubads.g.doubleclick.net/gampad/ https://analytics.tiktok.com/ https://www.facebook.com/ https://*.tiktokw.us/ https://*.hotjar.com/ https://galt.hit.gemius.pl/ https://firebase.googleapis.com/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://*.facebook.com/ https://*.fbcdn.net/ https://*.facebook.net/ https://*.google-analytics.com/ https://*.onetrust.com/ https://*.hotjar.io/ wss://ws.hotjar.com/ https://*.akamaized.net/ https://*.anycast.nagra.com/ https://evs-dtvsports-vod-secure2.akamaized.net/ https://*.ampproject.org/ https://api.evsports.opentv.com/ https://api.evsports.opentv.com/useractivityvault/v1/useractivity/; frame-src https://files.eurovisionsport.com/ https://www.google.com/ https://ep2.adtrafficquality.google/ https://www.googletagmanager.com/ https://*.g.doubleclick.net/ https://*.safeframe.googlesyndication.com/ http://imasdk.googleapis.com/ http://console.googletagservices.com/ https://www.ebu.ch/ https://eurovisionsport.com/; media-src 'self' blob: https://*.akamaized.net/ https://*.anycast.nagra.com/ https://*.sports.opentv.com/; script-src-elem 'self' 'nonce-edb55fb5d376cef7b355a314926c8335' https://cdn.ampproject.org/ https://*.hotjar.com/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://cdn.cookielaw.org/ https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/ https://imasdk.googleapis.com/js/sdkloader/ima3.js https://*.hotjar.io/; object-src 'none'; base-uri 'self'; form-action 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.google-analytics.com *.facebook.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.sooqr.com *.amazonaws.com *.geojs.io *.paypal.com *.paypalobjects.com *.magezon.com *.channable.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.sooqr.com *.amazonaws.com *.geojs.io *.paypalobjects.com *.magezon.com *.channable.com *.googletagmanager.com *.facebook.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com *.google-analytics.com *.sooqr.com *.amazonaws.com *.geojs.io *.paypalobjects.com *.magezon.com *.bootstrapcdn.com *.channable.com *.googletagmanager.com *.google.com/ https://www.googletagmanager.com/ *.facebook.com *.facebook.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com *.sooqr.com *.amazonaws.com *.geojs.io *.paypalobjects.com *.magezon.com *.bootstrapcdn.com *.channable.com *.googletagmanager.com https://images.unsplash.com imgsct.cookiebot.com https://www.magezon.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.facebook.com *.facebook.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.sooqr.com *.amazonaws.com *.geojs.io *.magezon.com *.doubleclick.net *.channable.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js consent.cookiebot.com *.google.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.facebook.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google-analytics.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.sooqr.com *.amazonaws.com *.geojs.io *.paypal.com *.paypalobjects.com *.magezon.com *.channable.com *.googletagmanager.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.google-analytics.com *.facebook.com *.sooqr.com *.amazonaws.com https://get.geojs.io *.paypalobjects.com *.magezon.com *.bootstrapcdn.com *.channable.com *.googletagmanager.com https://www.sandbox.paypal.com https://www.paypal.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.facebook.net *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.schilderijenshop.com/; report-to report-endpoint; 1 worker-src ; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.shopify.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com cdn.ampproject.org connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.feedbackcompany.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.sirv.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.feedbackcompany.com *.cloudflare.com *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.googleapis.com *.googletagmanager.com *.chimpstatic.com *.adobetm.com *.adobe.com polyfill.io *.doubleclick.net *.cookiebot.eu *.bing.com *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu *.sentry-cdn.com *.trustedshops.com *.helloretail.com *.google.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.cloudflare.com *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.googleapis.com *.googletagmanager.com *.chimpstatic.com *.adobetm.com polyfill.io *.cookiebot.eu *.cookiebot.com *.bing.com *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu *.sentry-cdn.com *.trustedshops.com *.helloretail.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.feedbackcompany.com *.cloudflare.com *.multisafepay.com *.amazonaws.com *.sirv.com *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.chimpstatic.com *.adobetm.com polyfill.io *.cookiebot.eu *.cookiebot.com *.bing.com *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu *.sentry-cdn.com *.trustedshops.com *.helloretail.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.feedbackcompany.com https://polyfill-fastly.io https://browser.sentry-cdn.com *.cloudflare.com *.twitter.com *.fontawesome.com s7.addthis.com player.vimeo.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.sirv.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.chimpstatic.com *.adobetm.com polyfill.io *.cookiebot.eu *.bing.com *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu *.sentry-cdn.com *.trustedshops.com *.helloretail.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io *.clarity.ms maillist-manage.eu *.maillist-manage.eu *.getqonfi.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com *.multisafepay.com *.sendcloud.sc *.jsdelivr.net *.sirv.com *.twitter.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.chimpstatic.com *.adobetm.com polyfill.io *.cookiebot.eu *.bing.com *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu *.sentry-cdn.com *.trustedshops.com *.helloretail.com *.google.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.sirv.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.feedbackcompany.com *.sentry-cdn.com *.cloudflare.com ekr.zdassets.com/ *.multisafepay.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.sirv.com *.youtube.com blob: *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.googletagmanager.com *.chimpstatic.com *.adobetm.com *.adobe.com polyfill.io *.cookiebot.eu *.bing.com *.bing.net *.chatbase.co *.zoho.eu *.zohocdn.com *.zohopublic.eu wss://vts.zohopublic.eu *.trustedshops.com *.helloretail.com *.fietsonline.com fietsonlinedev.hypernode.io *.fietsbandonline.nl *.fietszitjesonline.nl *.fahrrad-reifen-online.de *.fahrradteile-outlet.de *.fahrrad-reifen-online.at *.fahrradteile-outlet.at *.flaggel.com *.pagesense.io *.clarity.ms *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://flaggel.com/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.boxnow.gr *.boxnow.cy applepay.cdn-apple.com *.klarnacdn.net *.bootstrapcdn.com https://assets.egalaxy.gr data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.boxnow.gr *.boxnow.cy int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.klarna.com https://widget-v5.boxnow.gr https://tbibank.gr https://www.googletagmanager.com https://www.facebook.com https://td.doubleclick.net https://youtu.be https://skroutza.skroutz.gr 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io calc.tbibank.gr *.boxnow.gr *.boxnow.cy *.findbar.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com *.designer-images.net https://new.egalaxy.gr https://assets.egalaxy.gr https://www.facebook.com https://www.google.gr https://maps.googleapis.com https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net calc.tbibank.gr *.boxnow.gr *.boxnow.cy *.findbar.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.stat-track.com polyfill.io *.moosend.com https://assets.egalaxy.gr https://360.bestprice.gr https://scripts.bestprice.gr https://connect.facebook.net https://www.facebook.com https://analytics.tiktok.com https://www.gstatic.com https://skroutza.skroutz.gr https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.findbar.io *.klarnacdn.net *.moosend.com *.bootstrapcdn.com https://assets.egalaxy.gr https://use.typekit.net https://p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.findbar.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io calc.tbibank.gr *.boxnow.gr *.boxnow.cy *.findbar.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.stat-track.com *.m-pages.com *.m-operations.com https://assets.egalaxy.gr https://region1.google-analytics.com https://region1.analytics.google.com https://www.google.com https://analytics.tiktok.com https://stats.g.doubleclick.net https://www.google.gr https://www.facebook.com https://pagead2.googlesyndication.com https://maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://pmjsulxvuv1wvuwvesziy6jt.httpschecker.net/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.stripe.com google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com *.revolut.com *.google.com *.cdn-apple.com pay.google.com www.awardmedals.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ipg-online.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * www.awardmedals.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com www.awardmedals.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * *.cdn-apple.com *.gstatic.com www.awardmedals.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.stripe.com google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.revolut.com *.google.com *.cdn-apple.com pay.google.com www.awardmedals.com www.google.com.cy www.google.co.id www.google.com.qa *.googletagmanager.com www.google.com.co www.google.com.bh houseofnames.com www.google.com.tw www.google.com.om www.google.cv www.google.tt www.google.com.sg *.facebook.com www.google.nl www.google.co.in www.google.gg www.google.ge www.google.lk www.google.gl www.google.com.lb *.bing.net www.google.at www.google.al www.google.ro *.googleusercontent.com www.google.no www.google.rs www.google.ie www.google.co.ke cdn-cookieyes.com www.google.hr www.google.cd www.google.mw www.google.com.pa www.google.co.ve www.google.ae www.google.com.pg www.google.pl www.google.com.fj www.google.com.tr www.google.dk www.google.com.np www.google.com.uy www.google.se www.google.pt www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn www.google.ru www.google.com.bn www.google.jo www.google.com.sb www.google.it www.google.ch www.google.com.et www.google.ee *.elfsightcdn.com *.facebook.net www.google.hu www.google.ml www.google.com.pr www.google.iq www.google.ca www.google.com.mm www.google.md www.google.co.jp www.google.am www.google.de www.google.cl www.google.com.vc *.doubleclick.net www.google.im www.google.es www.google.co.za www.google.td www.google.lt www.google.is www.google.sc www.google.com.bo www.google.co.nz www.google.lu www.google.co.uk www.google.com.eg www.google.com.gt www.google.co.ma www.google.com.br www.google.com.jm www.google.com.bd www.google.fi www.google.sk www.google.kz www.google.co.ug www.google.com.ph www.google.je www.google.com.au www.google.si www.google.mn www.google.bs www.google.lv www.google.com.ec www.google.com.mt www.google.ba www.google.mk www.google.st www.google.com.sa www.google.so www.google.cz www.google.co.th www.google.co.kr www.google.dz *.bing.com www.google.mv www.google.com.vn www.google.com.hk www.google.sh www.google.co.vi www.google.com.ua www.google.com.af www.google.co.mz www.google.com.ar www.google.com.gh www.google.az www.google.rw www.google.com.ly www.google.bg www.google.co.uz www.google.com.my www.google.com.pk www.google.gr www.google.com.gi www.google.fr www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.stripe.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.revolut.com www.awardmedals.com https://chimpstatic.com hallofnames.com cdn-cookieyes.com *.optmnstr.com *.addthis.com *.doubleclick.net *.google-analytics.com *.elfsight.com *.omappapi.com *.bing.com *.googleoptimize.com *.elfsightcdn.com *.googletagmanager.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.stripe.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com www.awardmedals.com *.omappapi.com *.googletagmanager.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.awardmedals.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.revolut.com *.cdn-apple.com pay.google.com *.gstatic.com www.awardmedals.com www.google.cz www.google.com.pr www.google.com.bd www.google.ee www.google.lv www.google.com.gt www.google.ae www.google.gr www.google.mn www.google.ro www.google.es www.google.com.np www.google.lu www.google.com.lb www.google.at www.google.com.jm *.bing.com www.google.cv www.google.com.pk www.google.bs www.google.gl cdn-cookieyes.com www.google.ge www.google.se www.google.pl www.google.so *.google-analytics.com www.google.com.hk *.facebook.com www.google.ie www.google.com.vn www.google.de www.google.mu www.google.lk www.google.co.za www.google.co.kr www.google.fi www.google.kz www.google.com.ly *.bing.net www.google.cl www.google.be www.google.im www.google.com.bn www.google.dz www.google.co.ke www.google.com.uy *.doubleclick.net www.google.ba www.google.co.nz *.omappapi.com www.google.com.pg www.google.nl www.google.ch www.google.az www.google.bg www.google.gg www.google.com.gi www.google.pt www.google.rs *.elfsight.com www.google.hu www.google.com.mx www.google.com.ua www.google.co.il www.google.co.uk www.google.fr www.google.co.in www.google.cd www.google.co.mz www.google.mv www.google.iq www.google.co.jp www.google.com.br www.google.no www.google.com.tw www.google.st www.google.je www.google.lt www.google.dk www.google.com.tr www.google.hr www.google.com.au www.google.ru www.google.com.et www.google.ml www.google.sk www.google.com.sa www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.com.sb www.google.it www.google.al www.google.com.af www.google.com.bh www.google.is hallofnames.com www.google.co.th www.google.com.ng www.google.com.ph www.google.co.ma www.google.com.cy www.google.com.co www.google.com.mt www.google.com.my 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.awardmedals.com http: https: blob: 'self' 'unsafe-inline'; default-src www.awardmedals.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://c1747441-744a-4795-a738-1e451acf02a3.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com d1w350bl4wlonm.cloudfront.net d8mmzo4dbge7k.cloudfront.net drevs12goudzk.cloudfront.net d2zjb5saaoidg0.cloudfront.net d1bj2pk3s4epo2.cloudfront.net d12kmzq5k6k6i9.cloudfront.net d3o0jgwii26u89.cloudfront.net nuk.de applepay.cdn-apple.com cdnjs.cloudflare.com/ 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com oppwa.com *.oppwa.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://www.googletagmanager.com/ configurator.nuk.de pay.google.com applepay.cdn-apple.com cmp.osano.com match.adsrvr.org hal9000.redintelligence.net insight.adsrvr.org ad.ad-srv.net d.c.cdnsrv.de surveymonkey.com www.surveymonkey.com secure.novalnet.de customers.barzahlen.de customers-sandbox.barzahlen.de oppwa.com *.oppwa.com data:text 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.gstatic.com *.awin1.com *.zenaps.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com d1w350bl4wlonm.cloudfront.net d8mmzo4dbge7k.cloudfront.net drevs12goudzk.cloudfront.net d2zjb5saaoidg0.cloudfront.net d1bj2pk3s4epo2.cloudfront.net d12kmzq5k6k6i9.cloudfront.net d3o0jgwii26u89.cloudfront.net display-stg.ugc.bazaarvoice.com network-eu-stg-a.bazaarvoice.com network-eu-a.bazaarvoice.com nuk.de cdn.pixabay.com maps.googleapis.com ad.doubleclick.net t.uimserv.net maps.gstatic.com lantern.roeye.com pagead2.googlesyndication.com https://api.mapbox.com oppwa.com *.oppwa.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ d1w350bl4wlonm.cloudfront.net d8mmzo4dbge7k.cloudfront.net drevs12goudzk.cloudfront.net d2zjb5saaoidg0.cloudfront.net d1bj2pk3s4epo2.cloudfront.net d12kmzq5k6k6i 9.cloudfront.net d3o0jgwii26u89.cloudfront.net mapagmbh.germany-2.evergage.com cdn.evgnet.com/ network-eu-stg-a.bazaarvoice.com network-eu-a.bazaarvoice.com facebook.net facebook.com etracker.com etracker.de nuk.de maps.googleapis.com cmp.osano.com newell.piwik.pro tm.ad-srv.net s.uicdn.com connect.facebook.net cdn.mookie1.com acdn.adnxs.com js.adsrvr.org r.df-srv.de d.c.cdnsrv.de widget.surveymonkey.com ajax.googleapis.com lantern.roeye.com cdn.novalnet.de cdn.barzahlen.de applepay.cdn-apple.com *.oppwa.com oppwa.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com display.ugc.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com d1w350bl4wlonm.cloudfront.net d8mmzo4dbge7k.cloudfront.net drevs12goudzk.cloudfront.net d2zjb5saaoidg0.cloudfront.net d1bj2pk3s4epo2.cloudfront.net d12kmzq5k6k6i9.cloudfront.net d3o0jgwii26u89.cloudfront.net nuk.de cdnjs.cloudflare.com/ oppwa.com *.oppwa.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://the.sciencebehindecommerce.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ d1w350bl4wlonm.cloudfront.net d8mmzo4dbge7k.cloudfront.net drevs12goudzk.cloudfront.net d2zjb5saaoidg0.cloudfront.net d1bj2pk3s4epo2.cloudfront.net d12kmzq5k6k6i9.cloudfront.net d3o0jgwii26u89.cloudfront.net nuk.de secure.novalnet.de maps.googleapis.com newell.piwik.pro www.google.com googleads.g.doubleclick.net mapagmbh.germany-2.evergage.com www.wepowerconnections.com cmp.osano.com bat.bing.com/ lantern.roeye.com pagead2.googlesyndication.com payport.novalnet.de oppwa.com *.oppwa.com autocomplete2.postdirekt.de *.google-analytics.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; style-src data: 'unsafe-inline' https:; img-src data: https: blob:; font-src data: https:; connect-src https: wss:; media-src https: blob:; object-src https:; child-src https: data: blob:; form-action https:; report-uri https://csp.db.no/csp 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.cloudflare.com *.bootstrapcdn.com unpkg.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.lpsnmedia.net *.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com *.cloudflare.com media.granquartz.com *.granquartz.com *.facebook.com *.google.com *.google.com.vn forms.hsforms.com *.hubspot.com *.s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.twitter.com *.fontawesome.com *.facebook.net *.hotjar.com *.liveperson.net *.lpsnmedia.net *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.hs-analytics.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com unpkg.com *.fonts.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleapis.com *.cloudflare.com *.hotjar.com *.hubspot.com *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'nonce-vhCfnPzfjpWKsK3yVXhcJJ1roWY+K5to6MaR+fiKcLY=' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net; style-src 'self' 'nonce-vhCfnPzfjpWKsK3yVXhcJJ1roWY+K5to6MaR+fiKcLY=' https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com ; img-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.gstatic.com https://*.google.com https://googleads.g.doubleclick.net data:; font-src 'self' https://fonts.gstatic.com data:; frame-src https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://bid.g.doubleclick.net; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.googleapis.com; report-uri /csp-report ;report-to cspendpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src secure.authorize.net test.authorize.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com js.mollie.com payment.preprod.direct.worldline-solutions.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com *.vimeocdn.com i.ytimg.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.mollie.com payment.preprod.direct.worldline-solutions.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com payment.preprod.direct.worldline-solutions.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com https://www.facebook.com/tr/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://www.facebook.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com https://www.facebook.com *.taggrs.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googleapis.com *.gstatic.com *.croapp.net https://unpkg.com landofcoder.com *.taggrs.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.googleapis.com https://analytics.ringostat.net https://region1.analytics.google.com https://sst.kuz.ua landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.hotjar.com *.klevu.com *.typekit.net maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.hotjar.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ *.hotjar.com *.youtube.com *.addthis.com account.fetchify.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.doubleclick.net *.linkedin.com *.google.com *.cookiebot.com https://images.unsplash.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.youtube.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.gstatic.com *.googletagmanager.com *.hotjar.com *.zdassets.com *.trackedlink.net *.addthis.com *.klevu.com *.trustpilot.com *.moatads.com *.addthisedge.com *.licdn.com *.cookiebot.com cc-cdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.myfonts.net *.klevu.com *.typekit.net *.googleapis.com cc-cdn.com maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.hotjar.com wss://ws42.hotjar.com *.hotjar.io *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com *.doubleclick.net *.google-analytics.com *.zendesk.com *.cookiebot.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com *.amazon.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * www.google.com www.youtube.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.saint-louis.com *.ytimg.com *.google.fr *.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com polyfill-fastly.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googleapis.com www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cookielaw.org *.facebook.net sibautomation.com *.pinimg.com *.clarity.ms *.brevo.com *.pinterest.com https://cdnjs.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com *.google.fr payments-eu.amazon.com *.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com *.googleapis.com *.cookielaw.org *.onetrust.com *.db-ip.com *.google-analytics.com in-automate.brevo.com ct.pinterest.com i.clarity.ms www.merchant-center-analytics.goog https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.tyba.com.co *.gstatic.com *.googleapis.com www.googletagmanager.com www.google.com *.hotjar.com *.licdn.com *.googletapmanager.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.facebook.net *.doubleclick.net *.ads-twitter.com *.segment.com *.leadgenios.net *.appsflyer.com *.clarity.ms *.criteo.com *.google-analytics.com *.tiktok.com *.hs-scripts.com *.leadgenios.net *.g2afse.com leadgenios.net cdnjs.cloudflare.com js.hubspot.com js.hsforms.net *.hsappstatic.net *.onesignal.com *.cdn.onesignal.com onesignal.com i2.wp.com *.quantumcloud.com *.qcld.com *.qcld-wpbot.com *.qchatbox.com 1 font-src *.sagepay.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sagepay.com acs.3ds-pit.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ js.stripe.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afterpay.com *.clearpay.co.uk *.paypal.com *.sagepay.com ebizmarts-website.s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.stripe.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com maxcdn.bootstrapcdn.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.paypal.com *.sagepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.accelasearch.io *.cloudflare.com *.gstatic.com *.typekit.net *.twimg.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.fonts.gstatic.com *.accelasearch.net *.oct8ne.com applepay.cdn-apple.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.iubenda.com *.nexi.it www.google.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * api-qa.payplug.com secure-qa.payplug.com *.payplug.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.weltpixel.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.accelasearch.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.iubenda.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu pm7.it https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.ecommerce.nexi.it *.amcglobal.sc.omtrdc.net action-wear.com maps.gstatic.com *.accelasearch.net *.action-wear.com cdn.action-wear.fr cdn.actionwear.es cdn.actionwear.fr cdn.wear4you.net cdn.wear4u.it *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://secure-magenta.dalenys.com *.hsforms.net *.hsforms.com *.gstatic.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.accelasearch.io chimpstatic.com downloads.mailchimp.com *.list-manage.com int-ecommerce.nexi.it ecommerce.nexi.it www.google.com www.gstatic.com *.iubenda.com *.cloudflare.com *.google-analytics.com *.twimg.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.legalblink.it *.avada.io *.alothemes.com *.magepow.com *.cdnjs.cloudflare.com *.scriptcdn.net *.google.com maps.googleapis.com *.nexi.it *.accelasearch.net *.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com https://cdn-qa.payplug.com https://secure-magenta.dalenys.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.accelasearch.io downloads.mailchimp.com *.cloudflare.com *.googleapis.com *.twimg.com *.gstatic.com *.typekit.net *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.fonts.googleapis.com *.jsdelivr.net *.iubenda.com media.action-wear.com *.accelasearch.net cdn.action-wear.com cdn.action-wear.fr cdn.actionwear.es cdn.actionwear.fr cdn.wear4you.net cdn.wear4u.it unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com tagmanager.google.com 'self' 'unsafe-inline'; object-src *.youtube.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.accelasearch.io int-ecommerce.nexi.it ecommerce.nexi.it *.iubenda.com *.cloudflare.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.legalblink.it https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.nexi.it maps.googleapis.com prezzi2.crmcag.it *.accelasearch.net *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/camac/endpoint; report-to report-endpoint; 1 frame-ancestors www.youtube.com; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.youtube-nocookie.com https://youtu.be *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.bootstrapcdn.com *.doubleclick.net *.nr-data.net *.bobcatparts.com *.fontawesome.com *.googleadservices.com *.google.com *.facebook.net *.facebook.com *.paypal.com *.paypalobjects.com *.google.com.ua *.livechatinc.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com *.affirm.com *.klaviyo.com *.inspectlet.com *.braintree-api.com *.bobcat.com *.okta.com *.facebook.com *.mouseflow.com *.dmctools.com *.mcstaging.dmctools.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com *.olark.com *.google-analytics.com *.affirm.com *.doubleclick.net *.newrelic.com *.nr-data.net *.bobcatparts.com *.fontawesome.com *.googleadservices.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.com.ua *.klaviyo.com *.inspectlet.com *.braintree-api.com *.kaptcha.com *.mouseflow.com *.iwdagency.com *.dmctools.com *.mcstaging.dmctools.com *.livechatinc.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.certcapture.com *.magentocommerce.com *.ytimg.com data: *.google.com *.bootstrapcdn.com *.doubleclick.net *.newrelic.com *.nr-data.net *.bobcatparts.com *.fontawesome.com *.googleadservices.com *.google-analytics.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.com.ua *.klaviyo.com *.google.com *.google.co.in *.google.nl *.inspectlet.com *.yotpo.com *.mouseflow.com *.reddit.com *.linkedin.com *.hsforms.net *.hsforms.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.google.com.ua *.google-analytics.com *.affirm.com *.doubleclick.net *.fontawesome.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.facebook.com *.paypal.com *.paypalobjects.com *.instagram.com *.klaviyo.com *.inspectlet.com *.braintree-api.com *.mouseflow.com *.cloudflare.com *.igodigital.com *.pingdom.net *.dmctools.com *.mcstaging.dmctools.com *.amazonaws.com *.livechatinc.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com *.hsforms.net *.hsforms.com *.sdiapi.com *.licdn.com rum.hlx.page *.adobe.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.bootstrapcdn.com *.googleapis.com *.google.com.ua *.doubleclick.net *.newrelic.com *.nr-data.net *.bobcatparts.com *.typekit.net *.fontawesome.com *.googleadservices.com *.facebook.net *.facebook.com *.paypal.com *.paypalobjects.com *.klaviyo.com *.cloudflare.com *.googletagmanager.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com https://static.klaviyo.com assets.braintreegateway.com *.tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.bobcat.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.certcapture.com *.cardinalcommerce.com *.google-analytics.com *.olark.com *.affirm.com *.groupbycloud.com *.doubleclick.net *.bobcatparts.com *.fontawesome.com *.googleadservices.com *.facebook.net *.facebook.com *.paypalobjects.com *.google.co.in *.google.com.ua *.klaviyo.com inspectlet.com *.inspectlet.com *.yotpo.com *.mouseflow.com *.iwdagency.com *.pingdom.net *.dmctools.com *.mcstaging.dmctools.com *.livechatinc.com *.hsforms.net *.hsforms.com *.sdiapi.com *.linkedin.com *.bridgepaynetsecuretest.com *.bridgepaynetsecuretx.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.klarnacdn.net *.charlesbentley.com *.bam.nr-data.net *.cloudflare.com *.twitter.com *.bootstrapcdn.com *.trustpilot.com *.paypal.com *.xtento.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.reviews.io *.reviews.co.uk *.charlesbentley.com *.bam.nr-data.net *.webchat.dotdigital.com *.facebook.com *.trustpilot.com *.xtento.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.instagram.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.charlesbentley.com *.bam.nr-data.net *.adyen.com *.sandbox.paypal.com api.sandbox.braintreegateway.com *.klarna.com *.g.doubleclick.net/ *.amazon.com *.trustpilot.com *.addthis.com *.sharethis.com *.demdex.net *.facebook.com *.pinterest.com *.clarity.ms *.hotjar.com *.xtento.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.cdninstagram.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.charlesbentley.com *.bam.nr-data.net *.quora.com *.bing.com *.reddit.com *.linkedin.com *.facebook.com t.co *.quantserve.com *.google.com *.google.co.in *.google.co.uk *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.postcodeanywhere.co.uk *.pcapredict.com *.sharethis.com *.cookiepro.com *.amazonaws.com *.pinterest.com *.trustpilot.com *.clarity.ms www.xtento.com *.pallex.com *.prfct.co *.adnxs.com *.rubiconproject.com *.openx.net *.doubleclick.net *.addthis.com *.yahoo.com *.omtrdc.net cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.instagram.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.charlesbentley.com *.bam.nr-data.net *.windows.net *.jquery.com *.klarnaservices.com *.klarnacdn.net *.sandbox.paypal.com *.postcodeanywhere.co.uk *.pcapredict.com *.sharethis.com *.cloudfront.net porjs.com *.chat.freshdesk.com *.trustpilot.com *.cookiepro.com xtento.com *.bing.com *.hotjar.com *.pinimg.com *.facebook.net *.perk0mean.com *.clarity.ms *.aptrinsic.com *.paypalobjects.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.google-analytics.com *.googleadservices.com *.cdn.salesfire.co.uk *.addtoany.com *.freshworks.com *.marketingautomation.services *.perfectaudience.com *.prfct.co *.pinterest.com *.tumblr.com *.facebook.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.typekit.net tagmanager.google.com *.charlesbentley.com *.bam.nr-data.net *.klarnacdn.net *.trustpilot.com *.yotpo.com *.twitter.com *.bootstrapcdn.com *.gstatic.com *.postcodeanywhere.co.uk *.pcapredict.com *.chat.freshdesk.com *.cookiepro.com *.paypal.com *.xtento.com *.widget.freshworks.com *.freshworks.com *.aptrinsic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.smartmetrics.co.uk www.googleapis.com https://www.google-analytics.com *.charlesbentley.com *.bam.nr-data.net *.klarnaservices.com *.klarnaevt.com *.sandbox.paypal.com *.google-analytics.com *.g.doubleclick.net/ *.facebook.com *.postcodeanywhere.co.uk *.cookiepro.com *.sharethis.com *.chat.freshdesk.com *.trustpilot.com geolocation.onetrust.com *.pinterest.com *.clarity.ms *.hotjar.com *.aptrinsic.com *.xtento.com *.widget.freshworks.com *.freshworks.com *.googletagmanager.com *.googleadservices.com *.dpm.demdex.net *.live.smartmetrics.co.uk *.hit.salesfire.co.uk *.stbuttons.click *.gstatic.com *.addtoany.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net staticw2.yotpo.com cdn-widgetsrepository.yotpo.com *.yotpo.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.perplexity.ai *.slant.co *.ivaws.com *.googleusercontent.com unpkg.com *.rakuten.com *.cloudflare.com *.tql.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com gum.criteo.com td.doubleclick.net fledge.criteo.com www.google.com fledge.us.criteo.com insight.adsrvr.org match.adsrvr.org tags.rd.linksynergy.com static.criteo.net imgs.signifyd.com h.online-metrix.net *.weltpixel.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com *.googletagmanager.com *.doubleclick.net www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.magezon.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.trackedlink.net idsync.rlcdn.com bat.bing.com www.google.com.br criteo-partners.tremorhub.com sync.outbrain.com c.bing.com sync-t1.taboola.com criteo-sync.teads.tv pixel.rubiconproject.com simage2.pubmatic.com eb2.3lift.com ad.360yield.com tapestry.tapad.com exchange.mediavine.com x.bidswitch.net jadserve.postrelease.com contextual.media.net r.casalemedia.com dis.criteo.com ade.clmbtech.com rtb-csync.smartadserver.com ad.tpmn.io aa.agkn.com ib.adnxs.com thrtle.com sync.targeting.unrulymedia.com ads.stickyadstv.com ut.rd.linksynergy.com tags.rd.linksynergy.com insight.adsrvr.cn p.yotpo.com login.dotomi.com ce.lijit.com pippio.com imgs.signifyd.com h.online-metrix.net viewer.new.sayduck.com viewer.legacy.sayduck.com maps.googleapis.com maps.gstatic.com gstatic.com cdn.sayduck.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com store.paradoxlabs.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net www.google.co.id www.google.com.qa *.online-metrix.net www.google.com.co www.google.com.bh www.google.com.tw www.google.tn www.google.com.sg www.google.co.in www.google.gg www.google.by www.google.lk www.google.gl *.imrworldwide.com www.google.at www.google.ad www.google.al www.google.vu *.revcontent.com *.stackadapt.com www.google.rs www.google.ie www.google.co.ke www.google.hr www.google.cm www.google.mw www.google.com.pa www.google.ae www.google.com.pg *.linksynergy.com google.com www.google.pl www.google.com.fj www.google.com.kw www.google.com.np www.google.pt www.google.com.pe www.google.be www.google.co.il *.tpmn.co.kr www.google.com.mx www.google.mu *.yahoo.com www.google.jo www.google.co.cr *.rakuten.com www.google.it www.google.co.zm www.google.ch www.google.com.et id5-sync.com www.google.ee www.google.com.py www.google.hu *.rfihub.com www.google.com.pr www.google.iq www.google.ca www.google.li www.google.gy www.google.md www.google.co.jp www.google.sr www.google.am *.adform.net www.google.de www.google.im *.mathtag.com www.google.es www.google.lt www.google.is www.google.com.bo www.google.lu www.google.as www.google.com.do www.google.co.zw www.google.co.ma *.criteo.com *.signifyd.com www.google.fi www.google.sk www.google.co.ls www.google.co.ug *.liadm.com www.google.com.ph www.google.co.tz *.kaltura.com www.google.si www.google.mn www.google.lv *.adsrvr.org www.google.com.ec *.rlcdn.com www.google.ba *.criteo.net www.google.me www.google.com.kh www.google.com.sa www.google.bj *.mediawallahscript.com www.google.co.th www.google.dz *.bing.com *.turn.com www.google.ci www.google.com.vn www.google.ps www.google.com.hk www.google.co.vi www.google.com.ua www.google.com.ar www.google.com.gh www.google.rw www.google.co.uz www.google.com.my *.lijit.com www.google.fr www.google.com.ng www.google.com.cy www.google.com.om www.google.cv *.pubmatic.com www.google.tt www.google.nl www.google.ge www.google.com.lb *.bing.net www.google.ro *.googleusercontent.com *.breadfinancial.com www.google.no www.google.com.sv www.google.cd www.google.co.ve www.google.com.tr www.google.dk www.google.com.uy www.google.se www.google.mg www.google.hn www.google.com.bn www.google.ru www.google.tl www.google.ml www.google.co.ao www.google.sm *.fwmrm.net *.ivaws.com *.rezync.com www.google.com.cu www.google.com.na www.google.sn www.google.com.mm www.google.cl www.google.com.vc www.google.com.ni www.google.co.za *.cookiepro.com www.google.com.ag d1z0mfyqx7ypd2.cloudfront.net *.adnxs.com www.google.sc www.google.co.nz www.google.com.bz www.google.co.uk www.google.com.eg www.google.com.gt www.google.la www.google.com.jm www.google.cg www.google.com.bd www.google.tm *.googleadservices.com www.google.ht whonhow.com www.google.kz www.google.je www.google.com.au www.google.bs *.crwdcntrl.net *.nxcli.io www.google.com.mt *.1rx.io www.google.mk *.bidr.io www.google.kg *.cloudflare.com www.google.so cartera-cdn.freetls.fastly.net www.google.cz *.dmxleo.com www.google.bf www.google.co.kr www.google.mv www.google.co.bw www.google.com.af www.google.co.mz www.google.com.tj www.google.az www.google.com.ly www.google.bg www.google.com.pk www.google.gr www.google.com.gi data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cookie-cdn.cookiepro.com tag.rmp.rakuten.com connect.breadpayments.com dynamic.criteo.com js.adsrvr.org cdn-widgetsrepository.yotpo.com bat.bing.com fledge.criteo.com ut.rd.linksynergy.com cdn.mouseflow.com unpkg.com d18eg7dreypte5.cloudfront.net r2-t.trackedlink.net fledge.us.criteo.com www.google.com www.gstatic.com sslwidget.criteo.com js-agent.newrelic.com tags.rd.linksynergy.com staticw2.yotpo.com viewer.sayduck.com viewer.new.sayduck.com viewer.legacy.sayduck.com cdn.sayduck.io cdn-scripts.signifyd.com imgs.signifyd.com h64.online-metrix.net static-na.payments-amazon.com gstatic.com ipinfo.io *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com *.googleapis.com *.google.com *.gstatic.com *.authorize.net maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com *.criteo.com *.linksynergy.com *.rmtag.com *.adobe.net *.sayduck.com *.online-metrix.net *.id5-sync.com *.cloudflare.com *.signifyd.com *.adsrvr.org *.kaltura.com *.mouseflow.com *.google-analytics.com *.bing.com *.cookiepro.com *.rakuten.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.gstatic.com staticw2.yotpo.com cdn-widgetsrepository.yotpo.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com *.fontawesome.com *.google.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com *.bwe.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bing.com *.kaltura.com *.rakuten.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com cookie-cdn.cookiepro.com geolocation.onetrust.com mug.criteo.com measurement-api.criteo.com bam.nr-data.net privacyportal.cookiepro.com connect.breadpayments.com staticw2.yotpo.com api.pp-prod-ads.ue2.breadgateway.net api-cdn.yotpo.com imgs.signifyd.com api.sayduck.io maps.googleapis.com api.sp-pv-ads.ue2.breadgateway.net viewer.sayduck.com www.gstatic.com cdn.sayduck.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.authorize.net *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://imgs.signifyd.com www.google.com.bd www.google.ee www.google.com.gt www.google.co.zw *.criteo.com www.google.ae www.google.com.py www.google.mn www.google.com.ni www.google.co.tz www.google.es *.shopimgs.com www.google.ge www.google.sr www.google.se www.google.pl www.google.so www.google.ie www.google.com.vn www.google.de www.google.co.ve www.google.co.za www.google.co.kr www.google.com.ly *.bing.net www.google.cl *.nr-data.net www.google.be www.google.com.bn www.google.com.ec www.google.dz id5-sync.com www.google.co.cr www.google.co.ke www.google.tn www.google.co.nz d2rol5dpdbtxxu.cloudfront.net www.google.com.vc www.google.nl www.google.ch *.googleadservices.com www.google.bg www.google.hn www.google.com.gi www.google.rs www.google.com.mx www.google.com.ua d1r22q6sxlmkhx.cloudfront.net www.google.co.il www.google.fr www.google.co.in www.google.gy www.google.am www.google.co.bw www.google.no www.google.com.tw www.google.com.pe www.google.lt www.google.dk www.google.com.tr www.google.hr www.google.la www.google.ru www.google.co.zm www.google.sk www.google.by www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.me www.google.co.ls www.google.it www.google.al www.google.sm www.google.com.bh www.google.co.vi www.google.com.do www.google.co.th www.google.rw www.google.ad www.google.com.ph www.google.com.na www.google.co.ma www.google.ht www.google.com.my www.google.mk www.google.cz www.google.com.pr www.google.co.ao www.google.lv www.google.tt www.google.com.gh www.google.com.ar www.google.co.uz www.google.mw www.google.gr www.google.ro www.google.com.np www.google.lu www.google.com.lb www.google.at www.google.com.jm *.bing.com www.google.com.pk www.google.bs *.mouseflow.com www.google.cm www.google.com.ag www.google.md www.google.com.hk *.facebook.com www.google.mu www.google.lk www.google.kz www.google.fi www.google.tl www.google.com.sv www.google.com.pa www.google.ba www.google.jo www.google.com.pg www.google.az www.google.bj *.breadgateway.net www.google.pt www.google.hu www.google.com.kh www.google.co.uk www.google.cd www.google.mv www.google.iq www.google.co.jp www.google.com.br www.google.kg www.google.com.om www.google.je www.google.com.kw *.signifyd.com www.google.co.ug *.adobedc.net www.google.com.au *.adsrvr.org www.google.li www.google.com.sa *.gstatic.com www.google.co.id www.google.com.af www.google.mg www.google.is www.google.com.mm www.google.com.ng www.google.com.cy www.google.com.co www.google.com.mt www.google.si 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com imgs.signifyd.com bam.nr-data.net bat.bing.com www.google.com commerce.adobedc.net csm.us5.us.criteo.net connect.breadpayments.com p.yotpo.com shopjura.com www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://01b7bbb5-d792-48c7-a108-0d87ef3a3ea7.sansec.watch/; report-to report-endpoint; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action *.twitter.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com/ bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.paytabs.com *.paytabs.sa * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.vimeocdn.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.facebook.net *.googletagmanager.com *.google.com *.jsdelivr.net www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.equiti.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net cdn.almapay.com *.googleapis.com *.gstatic.com 'self' data: *.fontawesome.com fonts.gstatic.com ws.colissimo.fr *.speed1.fr *.quadyland.com *.quadyland.ovh cdn.amcharts.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com tpeweb.e-transactions.fr tpeweb.paybox.com tpeweb1.paybox.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.speed1.fr *.quadyland.com *.quadyland.ovh 'self' data: quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self'; frame-src fast.amc.demdex.net bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com www.google.com *.facebook.com www.youtube.com *.speed1.fr *.quadyland.com *.quadyland.ovh 'self' data: youtu.be tpc.googlesyndication.com www.quadyland.com www.googletagmanager.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google.nl stats.g.doubleclick.net *.googletagmanager.com *.facebook.com *.datatrics.com maps.googleapis.com maps.gstatic.com ws.colissimo.fr *.tile.openstreetmap.fr *.google.fr c.clarity.ms c.bing.com cdn.almapay.com *.speed1.fr *.quadyland.com *.quadyland.ovh cdn.amcharts.com www.google.be www.google.pt www.google.ca www.google.co.ma www.google.dz www.google.lu www.google.tn www.google.co.uk www.google.es www.google.de sb-img-fr.s3.amazonaws.com www.google.fr www.google.ch www.google.sn www.quadyland.com pagead2.googlesyndication.com cdn.doofinder.com tpc.googlesyndication.com media.speed1.fr bat.bing.com eu1-doofinderuser.s3.amazonaws.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.youtube.com www.gstatic.com/recaptcha/ www.google.com/recaptcha/ cdn.jsdelivr.net *.almapay.com static.addtoany.com/ cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com apis.google.com *.paypal.com *.google.com *.googletagmanager.com *.googleadservices.com snap.licdn.com *.fontawesome.com *.facebook.net *.google-analytics.com *.googleoptimize.com *.clarity.ms maps.googleapis.com www.google.com www.gstatic.com ws.colissimo.fr api.mapbox.com *.typeform.com *.doofinder.com *.quadyland.com *.quadyland.ovh cdn.amcharts.com cdn.doofinder.com bat.bing.com pagead2.googlesyndication.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.jsdelivr.net *.almapay.com fonts.googleapis.com *.googleapis.com checkout.buckaroo.nl *.fontawesome.com ws.colissimo.fr api.mapbox.com *.typeform.com *.doofinder.com cdn.almapay.com *.speed1.fr *.quadyland.com *.quadyland.ovh cdn.amcharts.com cdn.doofinder.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; object-src *.doubleclick.net *.speed1.fr *.quadyland.com *.quadyland.ovh 'self' data: www.quadyland.com blob quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; media-src *.speed1.fr *.quadyland.com *.quadyland.ovh quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; manifest-src quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com stats.addtoany.com/menu cdn.ampproject.org *.googleapis.com www.facebook.com *.facebook.com graph.facebook.com business.facebook.com *.paypal.com stats.g.doubleclick.net *.clarity.ms nominatim.openstreetmap.org *.doofinder.com google.com google.fr google.be googleads.g.doubleclick.net *.quadyland.com *.quadyland.ovh *.analytics.google.com adservice.google.com www.google.com maps.googleapis.com eu1-layer.doofinder.com pagead2.googlesyndication.com bat.bing.com quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; child-src quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri quadyland.com spyder.quadyland.com scooter.quadyland.com media.quadyland.com speed1.fr 125-vintage.fr scooterelec.fr concession.quadyland.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; 1 frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action *.facebook.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; img-src *.hubspot.com *.facebook.com *.bing.com *.googletagmanager.com *.google.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.hsforms.net googleadservices.com google-analytics.com paypalobjects.com *.braintreegateway.com www.paypal.com *.cardinalcommerce.com *.paypal.com *.vimeo.com *.youtube.com *.hsforms.com google-analytics.com cdn-cookieyes.com *.doubleclick.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.sharethis.com https://devdocs.magento.com https://magento.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; connect-src *.hubapi.com *.hubspot.com *.hscollectedforms.net *.googletagmanager.com *.google.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.hsforms.net googleadservices.com google-analytics.com paypalobjects.com *.braintreegateway.com www.paypal.com *.cardinalcommerce.com *.paypal.com *.vimeo.com *.youtube.com *.hsforms.com google-analytics.com *.doubleclick.net *.cookieyes.com cdn-cookieyes.com google.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com https://devdocs.magento.com https://magento.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.net *.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; style-src *.zencdn.net *.adobe.com *.sharethis.com fonts.googleapis.com https://devdocs.magento.com https://magento.com *.google.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.googletagmanager.com *.doubleclick.net *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.net *.facebook.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; font-src data: *.googleapis.com *.gstatic.com https://devdocs.magento.com https://magento.com *.google.com *.google.ca *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.net *.facebook.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; script-src *.facebook.net *.clickcease.com *.bing.com *.doubleclick.net googletagmanager.com *.googletagmanager.com *.hs-analytics.net *.hscollectedforms.net *.hsadspixel.net *.hsleadflows.net *.hs-banner.com *.hs-scripts.com *.googletagmanager.com *.google.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.hsforms.net googleadservices.com google-analytics.com paypalobjects.com *.braintreegateway.com www.paypal.com *.cardinalcommerce.com *.paypal.com *.vimeo.com *.youtube.com *.hsforms.com google-analytics.com cdn-cookieyes.com *.hotjar.com *.hubspot.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com https://devdocs.magento.com https://magento.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.com *.googleadservices.com *.adobedtm.com js.adsrvr.org *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; frame-src *.facebook.com *.fls.doubleclick.net *.googletagmanager.com *.google.com *.gstatic.com *.google.ca *.google-analytics.com *.googleapis.com *.hsforms.net googleadservices.com google-analytics.com paypalobjects.com *.braintreegateway.com www.paypal.com *.cardinalcommerce.com *.paypal.com *.vimeo.com *.youtube.com *.hsforms.com google-analytics.com youtube.com *.doubleclick.net fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://devdocs.magento.com https://magento.com *.bootstrapcdn.com *.postescanada-canadapost.ca *.tiktok.com *.facebook.net insight.adsrvr.org c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; 1 font-src https://cdn.livechatinc.com https://dev.click2mail.com/ https://stage.click2mail.com/ https://www.click2mail.com/ https://click2mail.com/ https://fonts.gstatic.com https://click2mail.cloudflareaccess.com/ data: https://staticw2.yotpo.com/ *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://*.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://v3mdvz78qnm1.statuspage.io/ https://td.doubleclick.net/ https://industry-templates.click2mail.com/ https://templates.click2mail.com/ https://stage-industry-templates.click2mail.com/ https://stage-templates.click2mail.com/ https://dev-industry-templates.click2mail.com/ https://dev-templates.click2mail.com/ https://click2mail.kayako.com/ https://amc.demdex.net/ https://forms.helpdesk.com/ https://click2mail.kb.help/ https://dev.click2mail.com/ https://stage.click2mail.com/ https://www.click2mail.com/ https://click2mail.com/ https://secure.livechatinc.com https://s7.addthis.com https://imgs.signifyd.com/ https://h.online-metrix.net/ https://www.paypal.com https://www.sandbox.paypal.com https://pilot-payflowlink.paypal.com https://player.vimeo.com https://industry-templates.click2mail.com https://click2mail.kayako.com https://imgs.signifyd.com https://h.online-metrix.net https://www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com https://compliancy-group.com/ https://notify.bugsnag.com/ https://google.com/ https://www.google.com/ https://www.google.co.in/ https://click2mail.kayako.com/ https://assets.kayako.com/ https://templates.click2mail.com https://stage-templates.click2mail.com/ https://dev-templates.click2mail.com/ https://img.youtube.com/ https://zapier-images.imgix.net https://zapier.com https://seal-dc-easternpa.bbb.org https://i0.wp.com https://click2mail.wpcomstaging.com/ https://i0.wp.com/click2mail.wpcomstaging.com/ https://industry-templates.click2mail.com/ https://dev.click2mail.com/ https://stage.click2mail.com/ https://click2mail.com/ https://click2mail.cloudflareaccess.com/ https://www.click2mail.com/ https://data.pendo.io https://blog.click2mail.com https://dev-blog.click2mail.com/ https://stage-blog.click2mail.com/ https://p.yotpo.com/ https://cdn-yotpo-images-production.yotpo.com/ https://yotpo-editor-production.s3.amazonaws.com/ https://maps.gstatic.com/ https://maps.googleapis.com/ https://amcglobal.sc.omtrdc.net https://imgs.signifyd.com/ https://cdn.klarna.com/ https://store.paradoxlabs.com/ https://sealserver.trustwave.com/ https://w2txo5aane2loy5fxwduxmtkesjvfskqugiqazyy7eb55235936d6b30am1.e.aa.online-metrix.net/ store.paradoxlabs.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://googleads.g.doubleclick.net/ https://google.com/ https://click2mail.kayakocdn.com/ https://assets.kayako.com/ https://d2wy8f7a9ursnm.cloudfront.net/ https://click2mail.kayako.com/ wss://kre.kayako.net/ https://api-public.addthis.com/ https://cdn.calltrk.com/ https://js.calltrk.com/ https://zapier.com/ https://cdn.zapier.com/ https://code.jquery.com/ https://cdnjs.cloudflare.com/ https://www.gstatic.com https://ekr.zendesk.com/ http://cdn.livechatinc.com/ https://dev.click2mail.com/ https://stage.click2mail.com/ https://www.click2mail.com/ https://click2mail.com/ https://maps.googleapis.com/ https://www.google.com https://api.livechatinc.com https://cdn.livechatinc.com https://cdn4.mxpnl.com/ https://static.zdassets.com/ https://www.googletagmanager.com/ https://imgs.signifyd.com/ https://secure.livechatinc.com https://cdn.pendo.io https://data.pendo.io https://ajax.cloudflare.com/ https://staticw2.yotpo.com https://s7.addthis.com https://z.moatads.com https://static.cloudflareinsights.com/ https://v1.addthisedge.com https://m.addthis.com https://apis.google.com *.cardinalcommerce.com https://sealserver.trustwave.com/ https://click2mail.cloudflareaccess.com/ https://www.googletagmanager.com https://bid.g.doubleclick.net https://api.zapier.com/ https://staticw2.yotpo.com/ https://get.geojs.io chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.zapier.com/ https://fonts.googleapis.com/ https://click2mail.cloudflareaccess.com/ https://staticw2.yotpo.com/ https://dev.click2mail.com/ https://stage.click2mail.com/ https://www.click2mail.com/ https://click2mail.com/ *.fontawesome.com downloads.mailchimp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://click2mail.kayakocdn.com/ https://google.com/ https://www.google.com https://dev-industry-templates.click2mail.com/ https://assets.kayako.com/ https://js.calltrk.com/ https://d2wy8f7a9ursnm.cloudfront.net/ https://click2mail.kayako.com/ wss://kre.kayako.net/ https://api-public.addthis.com/ https://stats.g.doubleclick.net/ https://analytics.google.com/ https://ekr.zendesk.com/ https://zendesk-eu.my.sentry.io/ https://zapier.com/ https://api.zapier.com/ https://dev.click2mail.com/ https://data.pendo.io/ https://stage.click2mail.com/ https://www.click2mail.com/ https://click2mail.com/ https://m.addthis.com/live/ https://jstest.authorize.net https://staticw2.yotpo.com/ https://maps.googleapis.com/ https://api.livechatinc.com https://amcglobal.sc.omtrdc.net https://ekr.zdassets.com/ https://click2mail.zendesk.com/ https://imgs.signifyd.com/ https://www.google-analytics.com/ https://cdn4.mxpnl.com/ https://www.google-analytics.com https://*.payments-amazon.com https://*.amazon.com https://*.amazon.co.uk https://*.amazon.co.jp https://*.amazon.it https://*.amazon.fr https://*.amazon.es https://*.amazon.de https://mws.amazonservices.com https://mws.amazonservices.co.uk https://mws.amazonservices.co.jp https://mws.amazonservices.it https://mws.amazonservices.fr https://mws.amazonservices.es https://mws.amazonservices.de https://get.geojs.io *.avada.io *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; child-src 'none'; object-src 'none'; script-src http: https: 'nonce-DPux7D/nhFaMbVorSq/eETWgkdDonTkVGij5oun4bH4='; connect-src 'self' https://*.google-analytics.com https://*.google.com; worker-src blob:; style-src 'self' 'unsafe-inline'; img-src 'self' https:; font-src 'self'; base-uri 'self'; 1 font-src *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net https://firebasestorage.googleapis.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js chimpstatic.com downloads.mailchimp.com *.list-manage.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io https://api.unifaun.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-Bh-vA7Xp0JMqk7r_zJEaBQ'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-Bh-vA7Xp0JMqk7r_zJEaBQ'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self'; report-uri https://uk3hg0f8.uriports.com/reports/report 1 font-src *.fontawesome.com https://fonts.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com landofcoder.com *.mercadolibre.com https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br https://www.google.com/ https://www.youtube.com/ https://www.facebook.com/ *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br https://stc.pagseguro.uol.com.br https://sandbox.stc.pagseguro.uol.com.br https://www.google.com/ https://d335luupugsy2.cloudfront.net https://www.google.com.br https://www.googletagmanager.com *.gstatic.com *.facebook.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com landofcoder.com *.avada.io *.mlstatic.com *.mercadopago.com http://viacep.com.br https://stc.pagseguro.uol.com.br https://stc.sandbox.pagseguro.uol.com.br https://d335luupugsy2.cloudfront.net https://static.zdassets.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.google.com/ *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com https://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com landofcoder.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolibre.com https://ekr.zdassets.com https://sacsitiodamata.zendesk.com https://popups.rdstation.com.br https://pageview-notify.rdstation.com.br wss://widget-mediator.zopim.com https://google.com/ *.google-analytics.com analytics.google.com *.facebook.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.kueskipay.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.mipc.com.mx *.icecat.biz *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.googletagmanager.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com mipc.com.mx 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com www.facebook.com *.google.com *.sharethis.com *.doubleclick.net *.livechatinc.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.kueskipay.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.hsforms.net *.hsforms.com 'self' data: *.mipc.com.mx www.google.com.mx *.icecat.biz *.sharethis.com *.mercadopago.com.mx device.clearsale.com.br h.online-metrix.net seal.godaddy.com *.clarity.ms *.omappapi.com *.bing.com img.mlstatic.com *.elfsightcdn.com *.facebook.com *.gstatic.com storage.getbutton.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.kueskipay.com *.mxpnl.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com cdn.ampproject.org www.gstatic.com *.mipc.com.mx cdn.mouseflow.com cdn.bitrix24.es kit.fontawesome.com *.omappapi.com *.app-us1.com trackcmp.net io.clickguard.com *.mipcapps.mx *.icecat.biz cdn.jsdelivr.net mipc.bitrix24.es *.doubleclick.net *.sharethis.com *.clarity.ms seal.godaddy.com device.clearsale.com.br h.online-metrix.net *.bing.com *.firecheckout.com cdn.clickydata.com dash.callbell.eu polyfill.io static.getbutton.io js.stripe.com *.googleapis.com *.elfsight.com *.cloudflare.com *.livechatinc.com *.hotjar.com *.callbell.eu studio.icecat.biz live-html.icecat.biz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com www.gstatic.com *.mipc.com.mx *.omappapi.com *.icecat.biz cdn.jsdelivr.net mipc.bitrix24.es dash.callbell.eu polyfill.io *.livechatinc.com *.callbell.eu studio.icecat.biz live-html.icecat.biz 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.icecat.biz *.callbell.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.kueskipay.com *.doubleclick.net https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com t.elasticsuite.io *.hsforms.net *.hsforms.com cdn.ampproject.org www.googleapis.com *.mipc.com.mx io.clickguard.com *.omappapi.com *.fontawesome.com *.icecat.biz *.google.com *.mipcapps.mx *.sharethis.com *.clarity.ms *.mixpanel.com dash.callbell.eu widget.getbutton.io *.googleapis.com *.bing.com *.elfsight.com https://www.googletagmanager.com/debug/badge.css google.com facebook.com api.livechatinc.com bcp.crwdcntrl.net *.callbell.eu wss://centrifugo.callbell.eu studio.icecat.biz live-html.icecat.biz 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.mipc.com.mx *.mipcapps.mx 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maps.googleapis.com www.google.com www.gstatic.com maps.gstatic.com fonts.googleapis.com fonts.gstatic.com www.w3.org *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.addthis.com *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.addtoany.com *.pinterest.com *.google.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com www.gstatic.com maps.gstatic.com fonts.googleapis.com www.w3.org blob: *.gstatic.com *.pinterest.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com www.google.com www.gstatic.com maps.gstatic.com fonts.googleapis.com www.w3.org *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.addtoany.com *.facebook.com *.pinterest.com *.tumblr.com *.google.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maps.googleapis.com www.google.com www.gstatic.com maps.gstatic.com fonts.googleapis.com www.w3.org *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.addthis.com/ *.moatads.com *.addthisedge.com m.addthis.com api-public.addthis.com *.cloudfront.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com *.paypal.com *.addtoany.com *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com www.xtento.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com x.klarnacdn.net *.klarnaservices.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com x.klarnacdn.net *.klarnaservices.com api.addressy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com fonts.gstatic.com https://cdn.jsdelivr.net components-bnpl-pe-bbva-production.moprestamo.com sole.com.pe mcstaging.sole.com.pe https://components-bnpl-pe-bbva-moprestamo-com.s3.amazonaws.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://sole.qualtrics.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.payment.pagoefectivo.pe td.doubleclick.net https://h.online-metrix.net https://static-content-qas.vnforapps.com https://m.vnforapps.com https://sole.qualtrics.com https://www.facebook.com *.moprestamo.com *.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.maps.googleapis.com mldp.mercadopago.com www.mercadolibre.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com mcstaging.sole.com.pe https://mcprod.sole.com.pe www.facebook.com www.google.cl www.google.com.ar www.google.com.pe www.sole.com.pe sole.com.pe *.apurata.com sandbox.pulsedive.com *.vnforapps.com *.clarity.ms *.bing.com static.apurata.com https://www.google.com.co https://app.apurata.com https://static-content.vnforapps.com https://m.vnforapps.com https://*.online-metrix.net https://siteintercept.qualtrics.com *.moprestamo.com https://firebasestorage.googleapis.com mageside.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br imgmp.mlstatic.com a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com gateway.payulatam.com sandbox.api.payulatam.com maf.pagosonline.net devicefingerprinting.fraudvault.com admin.revenuehunt.com connect.facebook.net components-bnpl-pe-bbva-production.moprestamo.com widgets-static.embluemail.com *.clarity.ms cdnjs.cloudflare.com zn3fnfkjfbzjxoun4-sole.siteintercept.qualtrics.com siteintercept.qualtrics.com *.vnforapps.com *.newrelic.com *.moprestamo.com https://*.inferencelabs9.com mcstaging.sole.com.pe sole.com.pe components-bnpl-pe-bbva-green.moprestamo.com www.clarity.ms js-agent.newrelic.com static-content-qas.vnforapps.com www.google.com www.gstatic.com https://m.vnforapps.com https://*.online-metrix.net *.avada.io *.mlstatic.com *.mercadopago.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.maps.googleapis.com http2.mlstatic.com secure.mlstatic.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net components-bnpl-pe-bbva-production.moprestamo.com sole.com.pe mcstaging.sole.com.pe *.moprestamo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com maf.pagosonline.net devicefingerprinting.fraudvault.com siteintercept.qualtrics.com apurata.com *.powerpay.pe *.clarity.ms *.nr-data.net *.moprestamo.com https://*.inferencelabs9.com https://www.google.com sole.com.pe mcstaging.sole.com.pe bam.nr-data.net a.clarity.ms https://stats.g.doubleclick.net https://mo-services-bbva-bnpl-pe-green.moprestamo.com https://maps.googleapis.com https://apurata.com https://h.online-metrix.net https://m.vnforapps.com https://www.google.com.co https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolibre.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.maps.googleapis.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com bam.nr-data.net mcstaging.sole.com.pe a.clarity.ms www.google.com.co sole.com.pe *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.globalpay.com https://fonts.gstatic.com *.klarnacdn.net maxcdn.bootstrapcdn.com www.skopes.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com www.skopes.co.uk 'self' 'unsafe-inline'; frame-ancestors www.skopes.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.klarna.com *.trustpilot.com www.youtube.com www.xtento.com www.skopes.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.globalpay.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.adobedtm.com www.xtento.com cdn.xtento.com www.skopes.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.trustpilot.com www.youtube.com player.vimeo.com www.xtento.com cdn.xtento.com www.skopes.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://fonts.googleapis.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.trustpilot.com www.skopes.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com www.skopes.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com cdn.plyr.io noembed.com www.skopes.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.skopes.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.skopes.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' *.unitek.com *.nitrocdn.com *.googleapis.com *.cloudflare.com; script-src-elem mc.yandex.ru *.gtranslate.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.unitek.com *.doubleclick.net *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.google.com *.googleadservices.com *.nitrocdn.com *.bing.com cdn.calltrk.com snap.licdn.com *.clickcease.com *.clarity.ms rdata.mpio.io js.callrail.com cdn.jsdelivr.net nexus.ensighten.com *.mxradon.com cdata.modernpostcard.com *.cloudflareinsights.com *.cloudflare.com *.facebook.net aa.agkn.com mc.yandex.ru embed.typeform.com blob: data:; connect-src 'self' *.google-analytics.com *.googleapis.com *.gstatic.com api.ipify.org js.callrail.com *.clarity.ms *.nitrocdn.com *.getnitropack.com *.google.com *.doubleclick.net www.facebook.com *.bing.com *.unitek.com monitor.clickcease.com *.gtranslate.net data:; font-src 'self' *.nitrocdn.com *.gstatic.com *.cloudflare.com zip.co data:; media-src 'self' data:; img-src * data:; frame-src 'self' insight.adsrvr.org *.cloudfront.net *.doubleclick.net *.facebook.com *.google.com *.vimeo.com *.youtube.com data:; worker-src blob:; child-src blob:; report-uri https://dreamwire.uriports.com/reports/report; report-to default 1 font-src cash-f.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.sharethis.com www.xtento.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * *.sharethis.com https://cdn.clerk.io *.openstreetmap.org https://maps.googleapis.com *.cloudfront.net *.facebook.com www.google.it *.clarity.ms *.bing.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com www.google.com.ua data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com https://api.clerk.io https://cdn.clerk.io cdnjs.cloudflare.com *.clerk.io *.clarity.ms connect.facebook.net *.cloudfront.net *.bing.com www.xtento.com cdn.xtento.com *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com network.oliunid.es https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.openstreetmap.org https://maps.googleapis.com stats.g.doubleclick.net *.clarity.ms *.facebook.com *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com network.oliunid.es https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.google.ca https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com cdn.cookielaw.org https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com ma.protected.ca cdn.cookielaw.org js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ekr.zdassets.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ma.protected.ca cdn.cookielaw.org geolocation.onetrust.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com; script-src-attr 'self'; style-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com; style-src-attr 'self'; style-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com; frame-ancestors 'self' 1 default-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagservices.com https://*.googlesyndication.com https://*.googleadservices.com https://*.doubleclick.net https://*.google.com https://bat.bing.com https://connect.facebook.net https://graph.facebook.com https://*.google-analytics.com https://*.googletagmanager.com https://js.facebook.com https://js-cdn.dynatrace.com https://r.bing.com https://unpkg.com https://sec.windcave.com https://js-agent.newrelic.com https://www.clarity.ms https://*.clarity.ms https://gateway.zscaler.net; object-src *.googlesyndication.com; style-src 'self' 'unsafe-inline' *.google.com *.bing.com unpkg.com https://www.googletagmanager.com https://www.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://*.google.com https://*.google.com.au https://*.google.com.jp https://*.google.com.sg https://*.google.com.vn https://*.google.co.uk https://*.google.co.nz https://*.google.com.pg https://www.google-analytics.com https://*.google-analytics.com https://*.bing.com https://www.facebook.com https://*.analytics.yahoo.com https://ad.doubleclick.net https://gateway.zscaler.net https://*.clarity.ms https://*.g.doubleclick.net https://*.googletagmanager.com https://*.googleusercontent.com https://*.intentiq.com https://*.star.com.au; media-src data:; frame-src 'self' *.doubleclick.net *.pinterest.com *.googleadservices.com *.google.com *.googletagmanager.com *.windcave.com *.facebook.com *.bing.com https://gateway.zscaler.net; frame-ancestors 'self';; child-src 'self' blob: *.facebook.com *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net *.googletagmanager.com; font-src 'self' data:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleadservices.com *.dynatrace.com *.star.com.au *.doubleclick.net *.bing.com bam.nr-data.net https://www.facebook.com *.google.com *.google.com.au *.google.com.hk *.google.co.nz *.google.co.kr *.google.com.tr *.google.com.tw *.google.ae *.google.com.hk *.google.com.sg https://bf63062ypw.bf.dynatrace.com https://www.gstatic.com https://translate.googleapis.com https://*.clarity.ms https://*.intentiq.com; report-uri /report-csp-violation 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.vimeo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.youtube.com *.vimeo.com *.vimeocdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.microsoftonline.com www.google-analytics.com *.aristotle.com *.visapac.com visapac.com *.visa.com cdn.jsdelivr.net; img-src data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com www.google-analytics.com; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net; form-action 'self' *.microsoftonline.com *.aristotle.com *.visapac.com visapac.com *.visa.com; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; 1 default-src 'self' https: https://backend.abuauf.com https://abuauf-stg.cloudhosta.com https://abuauf.com;script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' https://static.cloudflareinsights.com https://analytics.google.com https://api-gateway-uat.ngenius-payments.com https://paypage.sandbox.ngenius-payments.com https://paypage.ngenius-payments.com https://*.ngenius-payments.com https://www.googletagmanager.com https://backend.abuauf.com https://abuauf-stg.cloudhosta.com https://abuauf.com https://script.hotjar.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.googletagmanager.com;img-src 'self' blob: data: https://c.bing.com/ https://c.clarity.ms/c.gif https://scripts.clarity.ms/ https://*.googleapis.com https://backend.abuauf.com https://abuauf-stg.cloudhosta.com https://abuauf.com https://www.facebook.com https://maps.gstatic.com https://www.google.com https://www.google.com https://www.google.com.eg https://www.googletagmanager.com https://www.google.ru https://*.abuauf.com https://googleads.g.doubleclick.net https://i.ytimg.com https://www.google-analytics.com https://fonts.gstatic.com;media-src 'self' blob: https://backend.abuauf.com https://abuauf-stg.cloudhosta.com https://abuauf.com ;font-src 'self' 'unsafe-eval' blob: data: webpack: https://fonts.gstatic.com;base-uri 'self';connect-src 'self' https://cloudflareinsights.com https://ipapi.co https://static.cloudflareinsights.com https://analytics.tiktok.com https://analytics.google.com https://api-gateway-uat.ngenius-payments.com https://paypage.sandbox.ngenius-payments.com https://paypage.ngenius-payments.com https://*.ngenius-payments.com https://www.googleleadservices.com https://www.googleadservices.com https://www.google-analytics.com https://backend.abuauf.com https://backendstg.abuauf.com/ https://www.googleapis.com https://www.facebook.com https://graph.facebook.com https://google.com https://vc.hotjar.io https://metrics.hotjar.io https://www.google.com https://www.google.com.eg https://stats.g.doubleclick.net https://www.clarity.ms https://*.clarity.ms;script-src-elem 'self' 'unsafe-inline' https://scripts.clarity.ms/ https://static.cloudflareinsights.com https://analytics.tiktok.com https://analytics.google.com https://paypage.sandbox.ngenius-payments.com https://paypage.ngenius-payments.com https://*.ngenius-payments.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://static.hotjar.com https://connect.facebook.net https://js.createsend1.com https://*.googleapis.com https://*.google.com https://googleads.g.doubleclick.net https://script.hotjar.com https://ap-gateway.mastercard.com https://www.googleadservices.com https://www.youtube.com https://waffarad.com https://www.clarity.ms;form-action 'self' https://analytics.google.com https://api-gateway-uat.ngenius-payments.com https://authentication.cardinalcommerce.com https://www.facebook.com https://secure-acs2ui-b1-indmum-mumrdc.wibmo.com https://ap.gateway.mastercard.com https://*.wibmo.com;frame-src 'self' https://analytics.google.com https://api-gateway.sandbox.ngenius-payments.com https://api-gateway-uat.ngenius-payments.com https://paypage.sandbox.ngenius-payments.com https://paypage.ngenius-payments.com https://*.ngenius-payments.com https://authentication.cardinalcommerce.com https://www.googletagmanager.com https://www.facebook.com https://backend.abuauf.com https://backendstg.abuauf.com/ https://abuauf.com https://www.youtube.com https://td.doubleclick.net https://ap-gateway.mastercard.com https://secure-acs2ui-b1-indmum-mumrdc.wibmo.com https://ap.gateway.mastercard.com https://*.wibmo.com;object-src 'self' blob: data:;worker-src 'self' blob:;report-to default; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.clarity.ms *.stripe.com *.stripe.network *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors https://widget.reviews.co.uk *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.clarity.ms *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' *.clarity.ms https://c.bing.com https://www.google.co.in *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.clarity.ms *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com data: *.clarity.ms https://fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.clarity.ms 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.sandbox.paypal.com https://www.paypal.com *.clarity.ms *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com fonts.gstatic.com *.cloudflare.com *.googleapis.com *.zopim.com *.gstatic.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.google.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.gstatic.com *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.polyfill.io https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com *.avada.io *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.klevu.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klevu.com *.ksearchnet.com *.fontawesome.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.google.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.paypal.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net cort.demdex.net ct.pinterest.com www.youtube.com *.opendns.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net smetrics.cortevents.com smetrics.cortpartyrental.com *.linkedin.com *.cookielaw.org *.amazonaws.com cdn.cort.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com acsbapp.com *.acsbapp.com *.usabilla.com *.cookielaw.org *.licdn.com *.appdynamics.com *.gbqofs.com consent.trustarc.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com acsbapp.com *.acsbapp.com *.cookielaw.org optanon.blob.core.windows.net *.linkedin.oribi.io *.doubleclick.net *.eum-appdynamics.com smetrics.cortevents.com smetrics.cortpartyrental.com *.ads.linkedin.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.cloudfront.net 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';object-src 'none';script-src 'self' 'nonce-ODlGRTlERDlCN0E4MkJEQTRGRENFNUI0MkU1RTZBQUQ' https://cdn.jsdelivr.net https://www.google-analytics.com https://siteimproveanalytics.com;style-src 'self' 'nonce-ODlGRTlERDlCN0E4MkJEQTRGRENFNUI0MkU1RTZBQUQ';img-src 'self' data: https://cdn.jsdelivr.net;font-src 'self' https://cdn.jsdelivr.net;connect-src 'self' https://www.youtube.com https://informatiemodel.istandaarden.nl;worker-src 'self' blob:;media-src 'self' data:;frame-src https://www.youtube.com https://informatiemodel.istandaarden.nl;frame-ancestors 'self' https://informatiemodel.istandaarden.nl https://cms-o.kiesbeter.nl https://cms-ts.kiesbeter.nl https://cms-ac.kiesbeter.nl https://cms.kiesbeter.nl;form-action 'self';upgrade-insecure-requests; report-uri /services/cspreport; 1 report-uri /api/report-csp;base-uri 'self';connect-src 'self' dl2dg4vx8rw69.cloudfront.net *.googletagmanager.com www.google-analytics.com *.analytics.google.com adservice.google.com analytics.google.com google.com stats.g.doubleclick.net translate.googleapis.com www.google.ca www.google.com www.googleadservices.com *.braintree-api.com *.paypal.com analytics.braintreegateway.com analytics.sandbox.braintreegateway.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com www.facebook.com bat.bing.com;default-src 'self';font-src dl2dg4vx8rw69.cloudfront.net 'self' data: fonts.gstatic.com;form-action 'self' www.facebook.com;img-src dl2dg4vx8rw69.cloudfront.net d1oy5biuu9v5f4.cloudfront.net s3.ca-central-1.amazonaws.com data: 'self' ssl.gstatic.com www.gstatic.com *.analytics.google.com *.g.doubleclick.net *.google-analytics.com *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com *.google.com.af *.google.com.ag *.google.com.ai *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.ms *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vg *.google.vu *.google.ws *.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net www.google.com google.com www.googleadservices.com i.ytimg.com assets.braintreegateway.com *.paypal.com www.paypalobjects.com www.facebook.com bat.bing.com;media-src 'self';object-src 'none';script-src dl2dg4vx8rw69.cloudfront.net 'self' 'unsafe-eval' 'nonce-lW4kpvGJqC4zcL7KmmsWfpXfSjZjOvnc' tagmanager.google.com *.googletagmanager.com ssl.google-analytics.com www.google-analytics.com www.google.com www.googleadservices.com googleads.g.doubleclick.net www.youtube.com api.braintreegateway.com api.sandbox.braintreegateway.com assets.braintreegateway.com *.paypal.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com js.braintreegateway.com www.paypalobjects.com connect.facebook.net bat.bing.com;style-src dl2dg4vx8rw69.cloudfront.net 'self' 'unsafe-inline' fonts.googleapis.com tagmanager.google.com www.gstatic.com;frame-src *.googletagmanager.com bid.g.doubleclick.net www.google.com td.doubleclick.net tpc.googlesyndication.com www.youtube.com *.cardinalcommerce.com assets.braintreegateway.com *.paypal.com www.paypalobjects.com m.facebook.com www.facebook.com bat.bing.com;child-src assets.braintreegateway.com c.paypal.com 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; font-src 'self' *.gstatic.com; img-src 'self' *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com data: *.onetrust.com cm.everesttech.net *.googleapis.com; connect-src 'self' *.go-mpulse.net cdn-ukwest.onetrust.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com; script-src 'self'; frame-src 'self' googletagmanager.com doubleclick.net google-analytics.com; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src 'self'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com; script-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-to https://costa.report-uri.com/r/t/csp/reportOnly 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.cdninstagram.com *.smarthint.co challenges.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.addthis.com *.sharethis.com *.pinterest.com *.twitter.com *.cdninstagram.com *.smarthint.co *.hotjar.io *.hotjar.com *.sunset.systems challenges.cloudflare.com mymetric.com.br jcdecor-server.ue.r.appspot.com 'self' https://bid.g.doubleclick.net https://www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.pagaleve.io *.pagaleve.com.br *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.klarna.com *.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.sharethis.com *.pinterest.com *.cdninstagram.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.mercadolibre.com *.mercadolivre.com *.facebook.com *.googletagmanager.com *.arrowhitech.net *.mercadopago.com *.mercadopago.com.br *.yourviews.com.br *.yviews.com.br *.jcdecor.com.br *.google.com.br *.googleusercontent.com *.amazonaws.com *.smarthint.co *.doubleclick.net *.conectiva.io https://conectiva.io *.jivosite.com *.clarity.ms *.bing.com *.imgur.com *.widde.io challenges.cloudflare.com *.mercadolibre.com.br https://mercadopago.com.br *.mlstatic.com *.pagaleve.com.br *.pagseguro.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com *.addthis.com *.sharethis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googleadservices.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.vimeo.com *.paypal.com *.paypalobjects.com *.cdninstagram.com *.facebook.net *.google.com *.yourviews.com.br *.yviews.com.br *.hotjar.io *.hotjar.com *.google.com.br *.smarthint.co *.jivosite.com *.jquery.com *.cartstack.com.br *.conectiva.io https://conectiva.io *.doubleclick.net *.clarity.ms *.widde.io *.zdassets.com *.zopim.com challenges.cloudflare.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.openpix.com.br *.openpix.dev *.sentry.io *.ingest.sentry.io https://plugin.openpix.dev/v1/openpix-dev.js https://api.openpix.dev https://graphql.openpix.dev/openpix/graphql https://graphql.openpix.dev/shopper/graphql https://plugin.openpix.com.br/v1/openpix.js https://api.openpix.com.br/openpix/graphql https://api.openpix.com.br/shopper/graphql *.pagaleve.com.br *.pagseguro.com.br https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.cdninstagram.com *.yourviews.com.br *.yviews.com.br *.smarthint.co *.googletagmanager.com *.jivosite.com *.jquery.com challenges.cloudflare.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.jivosite.com *.widde.io challenges.cloudflare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.sharethis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com *.twitter.com *.twimg.com *.cdninstagram.com *.facebook.net *.mercadolibre.com *.yourviews.com.br *.doubleclick.net *.hotjar.io wss://ws14.hotjar.com/* *.hotjar.com *.facebook.com *.openpix.com.br *.performa.ai *.conectiva.io *.zendesk.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com https://conectiva.io *.jivosite.com wss://vi-ya-4.jivosite.com *.google.com *.cartstack.com.br *.clarity.ms *.smarthint.co *.googlesyndication.com https://x.clarity.ms/collect *.widde.io jcdecor-server.ue.r.appspot.com challenges.cloudflare.com mymetric.com.br api.ip2location.io https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri *.jcdecor.com.br/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' www.facebook.com https://unpkg.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com 'self' tagmanager.google.com analytics.ahrefs.com connect.facebook.net *.alpinejs.dev maps.googleapis.com cdn.moyasar.com polyfill.io https://unpkg.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' 'unsafe-inline' tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com 'self' www.google-analytics.com analytics.ahrefs.com connect.facebook.net www.facebook.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=49c36148-bf64-4b19-8c45-87b5b6f61004; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-hYOHVrTGioZmG4Sdwk/rHu5RLzE=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self';script-src 'self' 'strict-dynamic' https://www.trade-schools.net https://api.trustedform.com https://visitor2.constantcontact.com/ https://*.googletagmanager.com https://tagmanager.google.com https://s.pinimg.com/ https://ct.pinterest.com/ 'nonce-koLpyURiRYbKhUnqfc/Rw1khfEvJfg+RRPZomzn0fkY='; style-src 'self' 'unsafe-inline' https://static.ctctcdn.com/ https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' https://beeline-tsnetapi-prod.azurewebsites.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ca https://ssl.gstatic.com https://www.gstatic.com https://usage.trackjs.com https://*.trustedform.com/ https://cdn.matomo.cloud https://log.pinterest.com; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://beeline-tsnetapi-prod.azurewebsites.net https://api.zip-codes.com https://apilayer.net https://static.ctctcdn.com https://visitor2.constantcontact.com https://tradeschools.matomo.cloud https://create.leadid.com https://api.trustedform.com/; frame-src 'self' https://www.youtube.com/ https://embed.ted.com/ https://player.vimeo.com https://platform.twitter.com/ https://td.doubleclick.net/;object-src 'none';base-uri 'self' 1 font-src *.gstatic.com www.beo-car.rs beo-car.rs fonts.gstatic.com use.typekit.net *.typekit.net https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com portal.bulkgate.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action www.facebook.com www.beo-car.rs beo-car.rs bib.eway2pay.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * portal.bulkgate.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.facebook.com www.beo-car.rs beo-car.rs *.yandex.ru *.yandex.com *.doubleclick.net *.cookiebot.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * portal.bulkgate.com 'self' 'unsafe-inline'; img-src *.googleapis.com *.gstatic.com stats.g.doubleclick.net www.google.com www.google.rs www.facebook.com www.googletagmanager.com *.b-cdn.net beocar.b-cdn.net www.beo-car.rs beo-car.rs *.yandex.ru *.yandex.com *.iconfinder.com *.yads.tech *.sharethis.com *.ymmobi.com *.opera.com *.doubleclick.net yandex.ru *.cookiebot.com eu.asas.yango.com yandex.com *.yandex.md *.yango.com cm.g.doubleclick.net t.adx.opera.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net bid.g.doubleclick.net analytics.google.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com portal.bulkgate.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.googleapis.com *.gstatic.com *.googletagmanager.com www.google-analytics.com connect.facebook.net googleads.g.doubleclick.net stats.g.doubleclick.net www.beo-car.rs beo-car.rs *.hotjar.com *.yandex.ru *.yandex.com *.cookiebot.com static.addtoany.com yandex.com *.yandex.md yandex.ru *.yads.tech *.yango.com cm.g.doubleclick.net t.adx.opera.com assets.adobedtm.com *.adobe.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com portal.bulkgate.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com www.beo-car.rs beo-car.rs *.yandex.ru *.yandex.com *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com portal.bulkgate.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.addtoany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.b-cdn.net beocar.b-cdn.net www.beo-car.rs beo-car.rs *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.googleapis.com www.google-analytics.com connect.facebook.net stats.g.doubleclick.net www.beo-car.rs beo-car.rs *.hotjar.io *.yandex.ru *.yandex.com yandex.com *.hotjar.com ws.hotjar.com *.googlesyndication.com *.google.com google.com *.doubleclick.net *.yandex.md yandex.ru *.yads.tech *.yango.com cm.g.doubleclick.net t.adx.opera.com dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com portal.bulkgate.com *.gstatic.com https://get.geojs.io *.avada.io http://dpm.demdex.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' ; frame-src 'self' *.google.com *.youtube.com *.doubleclick.net ; connect-src 'self' *.axept.io *.doubleclick.net *.googlesyndication.com *.google-analytics.com *.google.com *.google.fr *.googleadservices.com *.googleapis.com *.mapbox.com *.matomo.cloud *.pointvision.com *.pointvision.fr yoast.com *.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.axept.io *.clarity.ms *.clickcease.com *.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.matomo.cloud *.s4mdsp.com tarteaucitron.io *.youtube.com ; font-src 'self' data: *.gstatic.com ; style-src 'self' 'unsafe-inline' *.mapbox.com *.googleapis.com *.gstatic.com *.youtube.com ; img-src 'self' data: *.pointvision.com *.clarity.ms *.ggpht.com *.google-analytics.com *.google.com *.google.fr *.googletagmanager.com *.gravatar.com *.gstatic.com *.imgix.net *.pointvision.fr *.youtube.com *.ytimg.com 1 script-src 'report-sample' https://hcaptcha.com https://*.hcaptcha.com; img-src 'self' https://staticfiles.new.smart.pr/; style-src 'self' 'unsafe-inline' https://staticfiles.new.smart.pr/ https://fonts.googleapis.com; object-src 'none'; font-src 'self' https://staticfiles.new.smart.pr/ https://fonts.gstatic.com; connect-src 'self' https://hcaptcha.com https://*.hcaptcha.com; frame-src 'self' https://hcaptcha.com https://*.hcaptcha.com; default-src 'self'; base-uri 'none'; upgrade-insecure-requests; report-uri https://o4509259652202496.ingest.de.sentry.io/api/4509259661246544/security/?sentry_key=909be8f68697b70e64601a6917e60993&sentry_environment=production 1 font-src *.klarnacdn.net *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.klarna.com js.mollie.com *.sendcloud.sc *.jsdelivr.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://www.mollie.com *.amazonaws.com https://widgets.trustedshops.com https://integrations.etrusted.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.magmodules.eu *.squeezely.tech https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.klarna.com *.klarnacdn.net *.klarnaservices.com js.mollie.com *.sendcloud.sc *.jsdelivr.net https://www.googletagmanager.com https://widgets.trustedshops.com https://integrations.etrusted.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com squeezely.tech www.squeezely.tech *.squeezely.tech polyfill.io cdn.cookie-script.com gallery.cevoid.com inc.fotobehang.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.klarnacdn.net *.fontawesome.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://integrations.etrusted.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' *.facebook.net *.js.stripe.com *.typekit.net analytics.twitter.com az416426.vo.msecnd.net bam.eu01.nr-data.net blob: cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com d2oh4tlt9mrke9.cloudfront.net googleads.g.doubleclick.net ipinfo.io js.stripe.com js-agent.newrelic.com maps.googleapis.com maxcdn.bootstrapcdn.com s3.amazonaws.com script.hotjar.com static.ads-twitter.com static.hotjar.com stats.g.doubleclick.net unpkg.com widget.trustpilot.com ws.sessioncam.com www.google-analytics.com www.googletagmanager.com www.instagram.com;style-src 'self' 'unsafe-inline' *.typekit.net cdn.jsdelivr.net code.jquery.com fonts.googleapis.com www.instagram.com;img-src 'self' *.akamaihd.net *.facebook.com *.google.com *.googleapis.com *.googleusercontent.com *.gstatic.com *.typekit.net analytics.twitter.com d2oh4tlt9mrke9.cloudfront.net data: s3-eu-west-1.amazonaws.com t.co ws.sessioncam.com www.google.co.uk www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.instagram.com www.laywheeler.com;connect-src 'self' *.google.com *.googleapis.com *.gstatic.com *.nr-data.net *.typekit.net api.stripe.com blob: d2oh4tlt9mrke9.cloudfront.net data: googleads.g.doubleclick.net ipinfo.io maps.googleapis.com pay.realexpayments.com region1.google-analytics.com stats.g.doubleclick.net widget.trustpilot.com ws.sessioncam.com www.google-analytics.com www.googletagmanager.com www.instagram.com;font-src 'self' *.typekit.net analytics.twitter.com fonts.gstatic.com;frame-src 'self' *.facebook.com *.google.com *.js.stripe.com hooks.stripe.com js.stripe.com td.doubleclick.net widget.trustpilot.com www.googletagmanager.com www.instagram.com;worker-src 'self' blob:;block-all-mixed-content; 1 default-src 'self' *.relay42.com 6162542.fls.doubleclick.net;script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.averoachmea.nl *.doubleclick.net *.facebook.net *.google.com *.googlesyndication.com *.hs-scripts.com *.linkedin.com *.r42tag.com *.relay42.com *.svtrd.com *.usabilla.com achmeadpm.achmea.nl:9999 ajax.googleapis.com api.usabilla.com app.contentsquare.com bat.bing.com cba.nmrc.nl cdn.ampproject.org cdn.harvest.graindata.com d6tizftlrpuof.cloudfront.net googleads.g.doubleclick.net https://www.googleoptimize.com https://www.googletagmanager.com js.hs-analytics.net js.hs-banner.com js.hsadspixel.net js.hsleadflows.net js.monitor.azure.com js.usemessages.com maps.googleapis.com player.quadia.net r.bing.com snap.licdn.com static.cloud.coveo.com surfly.com t.contentsquare.net tags.nmrc.nl www.dwin1.com www.google-analytics.com www.googleadservices.com www.youtube.com www.zenaps.com www.awin1.com https://api-engage-eu.sitecorecloud.io https://d35vb5cccm4xzp.cloudfront.net https://d1mj578wat5n4o.cloudfront.net;script-src-elem 'unsafe-inline' https:;style-src 'self' 'unsafe-inline' fonts.googleapis.com d6tizftlrpuof.cloudfront.net www.google.com static.cloud.coveo.com acc.cdn.verzuim.averoachmea.nl cdn.verzuim.averoachmea.nl;img-src 'self' data: *.averoachmea.nl img.youtube.com t.svtrd.com www.google-analytics.com www.facebook.com stats.g.doubleclick.net www.google.nl www.google.com *.usabilla.com cm.g.doubleclick.net a.svtrd.com n01d05.cumulus-cloud.com tdn.r42tag.com admin.relay42.com bat.bing.com www.googleapis.com clients1.google.com avr.imgix.net px.ads.linkedin.com track.hubspot.com forms.hubspot.com d6tizftlrpuof.cloudfront.net https://googleads.g.doubleclick.net *.ads.linkedin.com https://i.ytimg.com *.google-analytics.com *.analytics-google.com https://www.advieskeuze.nl https://maps.googleapis.com https://maps.gstatic.com https://www.googletagmanager.com acc.cdn.verzuim.averoachmea.nl cdn.verzuim.averoachmea.nl *.googlesyndication.com acc.cdn.dgv.aov.achmea.nl cdn.dgv.aov.achmea.nl *.contentsquare.net *.contentsquare.com;font-src 'self' fonts.gstatic.com acc.cdn.verzuim.averoachmea.nl cdn.verzuim.averoachmea.nl acc.cdn.dgv.aov.achmea.nl cdn.dgv.aov.achmea.nl fonts.googleapis.com data:;connect-src 'self' *.org.coveo.com fonts.googleapis.com maps.googleapis.com *.averoachmea.nl wss://*.hotjar.com https://*.hotjar.com https://*.hotjar.io *.hubapi.com api.hubspot.com forms.hubspot.com vc.hotjar.io cm.g.doubleclick.net connect.facebook.net googleads.g.doubleclick.net stats.g.doubleclick.net *.ave01.pre.connectis.io https://www.google-analytics.com https://surfly.com https://sentry.io *.hsforms.com *.averoachmea.nl *.collectie.centraalbeheer.nl https://controle.achmea.consentmonitor.nl https://collectie.centraalbeheer.nl dc.services.visualstudio.com *.google-analytics.com *.analytics-google.com *.advieskeuze.nl https://px.ads.linkedin.com https://td.doubleclick.net *.googlesyndication.com https://api.usabilla.com acc.cdn.dgv.aov.achmea.nl cdn.dgv.aov.achmea.nl https://api-engage-eu.sitecorecloud.io *.contentsquare.net *.contentsquare.com;media-src 'self';object-src 'self';child-src 'self' blob: www.googletagmanager.com youtube.com *.doubleclick.net t.svtrd.com *.hotjar.com cba.nmrc.nl www.youtube-nocookie.com youtube-nocookie.com d6tizftlrpuof.cloudfront.net *.surfly.com surfly.com app.hubspot.com forms.hsforms.com https://td.doubleclick.net https://formulier.averoachmea.nl https://formulier.centraalbeheer.nl;frame-ancestors 'self' youtube.com www.youtube-nocookie.com youtube-nocookie.com;form-action * 'self' t.svtrd.com *.averoachmeaonline.nl *.hsforms.com *.achmea.nl;manifest-src 'self';report-uri https://avero.ams.report-uri.com/r/t/csp/enforce; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.arcelik.com.tr https://www.google.com https://cdn.cookielaw.org https://www.clarity.ms https://d2ztbiegtp19vn.cloudfront.net https://cdn.evgnet.com https://configs.glov.ai https://c.la1-c2-cdg.salesforceliveagent.com https://w.usabilla.com https://www.googletagmanager.com https://scripts.clarity.ms https://cdn.jsdelivr.net https://scripts.agilone.com https://maps.googleapis.com https://ui.swogo.net https://platform.poltio.com https://googleads.g.doubleclick.net https://bat.bing.com https://d6tizftlrpuof.cloudfront.net https://s.go-mpulse.net https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com https://cdn.taboola.com https://s.pinimg.com https://sslwidget.criteo.com https://analytics.tiktok.com https://connect.facebook.net https://*.useinsider.com https://trc.taboola.com https://dynamic.criteo.com https://platform.twitter.com https://poltio.arcelik.com.tr https://d.la1-c2-fra.salesforceliveagent.com https://ct.pinterest.com https://s2.adform.net https://track.adform.net https://tags.creativecdn.com https://*.mathrics.com https://www.google-analytics.com https://go.assistbox.io https://service.force.com https://www.gstatic.com https://d.la1-core1.sfdc-cehfhs.salesforceliveagent.com https://static.ads-twitter.com 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.kxcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://consent.cookiefirst.com https://static.cookiefirst.com *.weglot.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com *.weglot.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://secure.pay1.de https://d.ratepay.com https://www.jsctool.com https://consent.cookiefirst.com https://static.cookiefirst.com *.doubleclick.net *.salesmanago.pl *.clarity.ms *.weglot.com *.googletagmanager.com *.trustpilot.com *.mondu.ai/ *.mondu.local localhost:*/ connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://i.ytimg.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.cdninstagram.com *.fbcdn.net https://mageside.com https://consent.cookiefirst.com https://static.cookiefirst.com *.facebook.com *.facebook.net *.google.de *.google.at *.google.ch *.google.nl *.google.ie *.google.pl *.google.dk *.google.no *.google.se *.google.fi https://cx.atdmt.com https://img.idealo.com https://www.googletagmanager.com https://widgets.trustedshops.com *.doubleclick.net *.shopvote.de *.bing.com *.clarity.ms *.amazonaws.com *.meetanshi.com *.weglot.com blob: *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.avada.io https://secure.pay1.de https://d.ratepay.com https://consent.cookiefirst.com https://static.cookiefirst.com data: *.shopvote.de *.doubleclick.net *.s24.com *.bing.com *.clarity.ms *.weglot.com *.trustpilot.com matomo.baushop-express.com *.mondu.ai/widget.js *.mondu.local/widget.js localhost:*/dist/widget.js www.facebook.com graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.stripe.network *.stripecdn.com https://consent.cookiefirst.com https://static.cookiefirst.com *.shopvote.de *.weglot.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://www.baushop-express.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://secure.pay1.de https://d.ratepay.com https://analytics.google.com https://consent.cookiefirst.com *.cookiefirst.com https://api.cookiefirst.com https://stats.g.doubleclick.net *.google.de *.google.at *.google.ch *.google.nl *.google.ie *.google.pl *.google.dk *.google.no *.google.se *.google.fi data: *.shopvote.de *.facebook.com *.doubleclick.net https://googleads.g.doubleclick.net *.bing.com *.clarity.ms *.weglot.com *.saleago.com *.google-analytics.com *.googlesyndication.com https://google.com matomo.baushop-express.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /tools/report/index; report-to report-endpoint; 1 img-src 'self' data: https://www.rocketnews.com https://dev.rocketnews.com http://dev.rocketnews.com https://www.googletagmanager.com https://rocketnews.com https://images.unsplash.com blob: https://storage.googleapis.com https://npr.brightspotcdn.com https://i1.wp.com https://i0.wp.com https://images.pexels.com https://i3.wp.com https://i2.wp.com https://media.npr.org https://lh3.googleusercontent.com https://image.cnbcfm.com https://ichef.bbci.co.uk https://www.criminaldefenselawgroup.com https://www.whiteplainscriminallawyers.com https://libankruptcylawyers.com https://www.yaglaw.com https://www.medicaidfraudlawyer.com https://www.travelandtourworld.com https://pos.baidu.com https://www.lawyer.zogby.com https://divorceattorneynyc.com https://lawpetroff.com https://www.schoolmatters.com https://porcelloestatebuyers.com https://static-redesign.cnbcfm.com https://apps.npr.org https://cdn.honey.io https://www.cidrap.umn.edu https://www.news4jax.com https://www.cognitoforms.com https://www.npr.org https://media.istockphoto.com https://etruel.com https://yastatic.net https://injuredonline.com https://az415021.vo.msecnd.net https://nycbankruptcylawyers.com https://wp3869-flywheel.netdna-ssl.com https://graduate.norwich.edu https://www.msainjurylaw.com https://schoolmatters.com https://www.criminallawyer-chicago.com https://www.ignisproducts.com https://pbs.twimg.com https://www.nycdwilawyers.com https://divorcelawyersnyc.org https://www.nycdivorcelawyers.com https://www.instapics.com https://www.protectyourfuture.org https://ci3.googleusercontent.com https://fm.cnbc.com https://www.arrestedtoday.com https://really-simple-ssl.com https://mw4.wsj.net https://duckduckgo.com https://translate.google.com https://fonts.gstatic.com https://static.files.bbci.co.uk https://1v3y281fy9im2ig6ge1zpnrx-wpengine.netdna-ssl.com https://www.freshhealthyvending.com https://www.qumana.com https://mphdegree.usc.edu https://public.flourish.studio https://wp.fifu.app https://www.zayedlawoffices.com https://techcrunch.com http://religionnews.com https://kffhealthnews.org https://maps.googleapis.com https://s.france24.com https://i.abcnewsfe.com https://s.abcnews.com https://msainjurylaw.com https://translate.googleapis.com https://assets.science.nasa.gov https://www.nasa.gov https://science.nasa.gov https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://s3.tradingview.com https://maps.googleapis.com https://rocketnews.com https://ct.captcha-delivery.com https://api.wire.threatspike.com https://cdnjs.cloudflare.com https://platform.twitter.com https://connect.facebook.net https://static.cognitoforms.com https://me.kis.v2.scr.kaspersky-labs.com https://js.stripe.com https://static.userguiding.com https://cdn.toolszen.com https://www.cognitoforms.com https://toolsminati.com https://cdn.datatables.net https://player.ooyala.com https://www.google-analytics.com https://friends.honestpaws.com https://3001.scriptcdn.net https://ritrag.com https://mainf.global-cache.online blob: https://www.paypalobjects.com https://edge.eu1.fullstory.com https://infird.com https://gc.kis.v2.scr.kaspersky-labs.com https://gtmpx.com https://translate.google.com https://static.cloudflareinsights.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://s3.tradingview.com https://maps.googleapis.com https://rocketnews.com https://ct.captcha-delivery.com https://www.cognitoforms.com https://api.wire.threatspike.com https://cdnjs.cloudflare.com https://platform.twitter.com https://connect.facebook.net https://static.cognitoforms.com https://me.kis.v2.scr.kaspersky-labs.com https://js.stripe.com https://static.userguiding.com https://cdn.toolszen.com https://toolsminati.com https://cdn.datatables.net https://player.ooyala.com https://www.google-analytics.com https://friends.honestpaws.com https://3001.scriptcdn.net https://ritrag.com https://mainf.global-cache.online blob: https://www.paypalobjects.com https://edge.eu1.fullstory.com https://infird.com https://gc.kis.v2.scr.kaspersky-labs.com https://gtmpx.com https://translate.google.com https://static.cloudflareinsights.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://rocketnews.com https://www.opoint.no https://cdnjs.cloudflare.com https://cdn.datatables.net https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.honey.io https://www.cognitoforms.com https://07u3wb6wearju75if9pcvik.mentionusercontent.net https://07u3wb6wearju75rcbzlnek.mentionusercontent.net https://adblockers.opera-mini.net https://07u3wb6wearju75izsssgpk.mentionusercontent.net https://ff.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com https://07u3wb6wearju75rqd5m3xk.mentionusercontent.net https://07u3wb6wearju75ibfdt6gk.mentionusercontent.net https://07u3wb6wearju75raui1ysk.mentionusercontent.net https://07u3wb6wearju75r41hbj1k.mentionusercontent.net https://07u3wb6wearju75ihr0mruk.mentionusercontent.net ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://rocketnews.com https://www.opoint.no https://cdnjs.cloudflare.com https://cdn.datatables.net https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.honey.io https://www.cognitoforms.com https://07u3wb6wearju75if9pcvik.mentionusercontent.net https://07u3wb6wearju75rcbzlnek.mentionusercontent.net https://adblockers.opera-mini.net https://07u3wb6wearju75izsssgpk.mentionusercontent.net https://ff.kis.v2.scr.kaspersky-labs.com https://www.gstatic.com https://07u3wb6wearju75rqd5m3xk.mentionusercontent.net https://07u3wb6wearju75ibfdt6gk.mentionusercontent.net https://07u3wb6wearju75raui1ysk.mentionusercontent.net https://07u3wb6wearju75r41hbj1k.mentionusercontent.net https://07u3wb6wearju75ihr0mruk.mentionusercontent.net ; font-src 'self' https://fonts.gstatic.com https://rocketnews.com https://www.slant.co https://www.cognitoforms.com https://static.cognitoforms.com https://fonts.cdnfonts.com https://cdn.scite.ai https://account.affilitizer.com https://migaku-public-data.migaku.com http://rocketnews.com https://at.alicdn.com https://r2cdn.perplexity.ai https://use.typekit.net data:; frame-src 'self' https://s.tradingview.com https://www.tradingview-widget.com https://www.youtube.com https://mozbar.moz.com https://player.vimeo.com https://platform.twitter.com https://www.healthiq.com https://js.stripe.com https://www.googletagmanager.com https://pwm-image.trendmicro.com https://www.nbcnews.com https://www.nasa.gov blob:; connect-src 'self' https://yoast.com https://www.google-analytics.com https://maps.googleapis.com https://ai.elegantthemes.com https://region1.google-analytics.com https://rocketnews.com https://o622089.ingest.us.sentry.io https://www.cognitoforms.com https://infragrid.v.network https://fonts.gstatic.com data: https://me.kis.v2.scr.kaspersky-labs.com https://www.googletagmanager.com https://i0.wp.com https://overbridgenet.com https://detector.scamsniffer.io https://production.checkitt.news https://translate.googleapis.com https://d1lkfzu2puirk6.cloudfront.net https://sdk.userguiding.com blob: https://cdn.shopimgs.com https://user.userguiding.com https://translate-pa.googleapis.com https://localhost https://www.google.com https://www.rocketnews.com https://dev-apigw.inquirer.com; media-src 'self' https://media3.giphy.com https://media0.giphy.com https://media1.giphy.com https://media2.giphy.com data: https://media4.giphy.com https://images.outbrainimg.com; worker-src 'self' blob:; report-uri https://rocketnews.com/wp-json/rsssl/v1/csp?rsssl_apitoken=187879785; 1 font-src fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.facebook.com *.facebook.net *.google.com *.addthis.com *.pinterest.com www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com *.facebook.net https://www.magezon.com ozow-live-cdn.s3.eu-west-1.amazonaws.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://polyfill-fastly.io https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com s7.addthis.com *.facebook.com *.facebook.net *.avada.io *.google.com/ *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com www.youtube.com player.vimeo.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com ekr.zdassets.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; connect-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=txLH4S18JkcXLZ_KgNcROiB498xJoezdIHRnyEtWWaE-1765936453-1.0.1.1-s11gOJt683mFWBw02rfAc.Oxjp6Syy73ODPSS7ecnMz6U17btMZbvwQWisW2N0XAxK1zhsocbn3_7rhmelXiXlosaL46AnBA_wfyabWMX.0w83xFRp.9EkEkCkzVFTVAq_su.yQUVEclJLdT_FJnzE4nNZOgJ2kFVRbDNHAlu2U70GEk5us4gzN3uLl1BUZk; report-to cf-csp-endpoint 1 report-to self; font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com 'self' data: widgets.trustedshops.com https://widgets.trustedshops.com d2jyby6zfixqwe.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com https://www.googletagmanager.com/ *.facebook.com js.mollie.com td.doubleclick.net d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.trackedlink.net *.ddlnk.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.hsforms.net *.hsforms.com *.cdninstagram.com flagpedia.net https://www.mollie.com 'self' data: *.cloudfront.net *.usercentrics.eu integrations.etrusted.com *.content.lego.com www.google.pl www.google.de www.google.en blob: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com maps.gstatic.com d2jyby6zfixqwe.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.hsforms.net *.hsforms.com player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.gstatic.com maps.googleapis.com js.mollie.com *.usercentrics.eu *.content.lego.com *.hotjar.com toysforfun.matomo.cloud https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://d2jyby6zfixqwe.cloudfront.net d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com integrations.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; object-src d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.content.lego.com d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com www.gstatic.com maps.googleapis.com *.usercentrics.eu api.legogroup.io *.content.lego.com region1.analytics.google.com googleads.g.doubleclick.net pagead2.googlesyndication.com www.google.pl www.google.de www.google.en wss://ws.hotjar.com content.hotjar.com content.hotjar.io metrics.hotjar.io toysforfun.matomo.cloud *.trustedshops.com *.etrusted.com https://integrations.etrusted.site d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d2jyby6zfixqwe.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.cloudfront.net 'self' 'unsafe-inline'; 1 default-src https: 'self'; style-src https: 'self' 'sha256-uxelkF613AGxref1/rP3ZHZE+P7Ug0CyXVLR1rLSakU=' 'sha256-P+2NeKq71oAxK8zY6cOiSwpf3Aa/xXHbkXu4DioxsRQ=' 'sha256-vv9IoKo7BSLbWcUHr3tNmfNVmm5L/9Cfn2H6LMk7/ow=' 'sha256-QiN3HnNUibKmvNsuNF2t2ZEEAvhvIG0Po8FCMXDUuvo=' 'sha256-PDv7PK7p4vec7tI/1XbvDMwahytuLYN1Ul7CMcw1gHY=' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-E9oHpuvJ6jOR3P7K7KizBmPB/3U+maUP840PXFjEq+A=' 'sha256-u6jtHZ4a6N0kmQve7cxZ0+3oAelZx+CiMr0HwTbRoxA=' 'sha256-2EA12+9d+s6rrc0rkdIjfmjbh6p2o0ZSXs4wbZuk/tA=' 'sha256-Lpt5CFCrGLrsjxO/wBhoSm4Lc1o5pxDZuW5/UU9ANhE='; script-src https: 'self' 'sha256-WN0hqek1jEauhlhWVVXeQPa5BD3f0rsMdmwSZtw1Cys=' 'sha256-eIXWvAmxkr251LJZkjniEK5LcPF3NkapbJepohwYRIc=' 'sha256-Jz4XDAN4f076pEj8cOt8mEdISulquB3CBdxFvEpSSyc=' https://www.googletagmanager.com https://www.clarity.m 'sha256-xJVBbz8FBogVbgagro0nHcjfwOz3sqjCtGSjihUh2m0=' 'sha256-SsAnEE7qERD9tzeNelDfWgW7Ej6bXCyaaggwM/cg0+M=' 'sha256-1ileVmLABVmb2IIWyUuP5uxf3JiJDAJhDAzM8BwWvO4=' 'sha256-gPjlli1HEdLlR0AZTY971/wQVOdSkl9mEinLnxrPpJw='; 1 default-src 'self' https://*.wistia.com https://*.wistia.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.mxpnl.com js.arcgis.com maps.googleapis.com www.google.com/jsapi www.google-analytics.com https://*.wistia.com https://*.wistia.net http://js.sentry-cdn.com https://src.litix.io static.theorgwiki.com/v1327781/ 'nonce-_Xx_F_pT4C5xgZFPhBA1zOD7kNaOp43c' 'strict-dynamic'; connect-src 'self' maps.googleapis.com api-js.mixpanel.com arcgis.com www.arcgis.com js.arcgis.com www.js.arcgis.com cdn.arcgis.com static.arcgis.com basemaps.arcgis.com basemaps-api.arcgis.com www.google-analytics.com stats.g.doubleclick.net https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net https://*.litix.io wss:; font-src 'self' data: fonts.gstatic.com js.arcgis.com https://*.wistia.com static.theorgwiki.com/v1327781/; frame-src 'self' https://fast.wistia.com https://fast.wistia.net; style-src 'self' 'unsafe-inline' blob: fonts.googleapis.com js.arcgis.com fast.wistia.com static.theorgwiki.com/v1327781/; worker-src 'self' blob:; media-src 'self' blob data: orgwiki-app-files-prod.s3.amazonaws.com https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net https://orgwiki-app-files-prod.s3.amazonaws.com/pronunciations/; img-src 'self' data: blob: cdn.arcgis.com www.arcgis.com *.licdn.com *.googleusercontent.com maps.gstatic.com *.twimg.com/profile_images/ www.google-analytics.com https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net https://orgwiki-app-files-prod.s3.amazonaws.com static.theorgwiki.com/v1327781/; report-uri /csp-report; object-src 'none'; base-uri 'none'; 1 font-src fonts.gstatic.com use.typekit.net https://www.googletagmanager.com *.googleapis.com *.gstatic.com 'self' data: https://userlike-cdn-umm.b-cdn.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ secure.novalnet.de seamless.novalnet.de customers.barzahlen.de customers-sandbox.barzahlen.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://userlike-cdn-operators.userlike.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net https://app.usercentrics.eu https://www.google.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://rum.hlx.page tagmanager.google.com https://www.googletagmanager.com cdn.novalnet.de cdn.barzahlen.de js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://ajax.googleapis.com https://userlike-cdn-umm.b-cdn.net https://app.usercentrics.eu https://connect.facebook.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://sgtm.agrar-direct.de *.usercentrics.eu *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com unsafe-inline assets.braintreegateway.com *.gstatic.com https://integrations.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.userlike.com https://edge.adobedc.net https://api.usercentrics.eu https://sgtm.agrar-direct.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.usercentrics.eu 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ landofcoder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.g.doubleclick.net *.googlesyndication.com *.facebook.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.facebook.com *.googlesyndication.com *.google.com.bd *.clarity.ms *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ landofcoder.com s7.addthis.com *.addtoany.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.facebook.net *.facebook.com *.googlesyndication.com *.googleadservices.com *.google.com.bd *.localhost *.clarity.ms *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.facebook.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com landofcoder.com ekr.zdassets.com/ http://dpm.demdex.net *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.facebook.com *.googlesyndication.com ap.stape.info *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.example.com/; report-to report-endpoint; 1 font-src *.fontawesome.com *.gstatic.com *.fonts.googleapis.com data: *.cloudflare.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es https://seo.mageplaza.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.google.com *.addthis.com *.pinterest.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es cdn.doofinder.com data: *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es cdn.doofinder.com *.avada.io maps.googleapis.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.doofinder.com *.googleapis.com tagmanager.google.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.doofinder.com wss://*.doofinder.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com https://www.google-analytics.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.vimeo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com s7.addthis.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.ideal-postcodes.co.uk ekr.zdassets.com/ *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.youtube.com *.vimeo.com *.vimeocdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com *.youtube-nocookie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://firebasestorage.googleapis.com *.multisafepay.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://browser.sentry-cdn.com *.avada.io *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io *.multisafepay.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://*.cloudfront.net https://www.googletagmanager.com https://connect.facebook.net/ https://s7.addthis.com https://s.adroll.com blob:; font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com https://netdna.bootstrapcdn.com https://www.gstatic.com; media-src https:; style-src 'self' https://fonts.googleapis.com https://netdna.bootstrapcdn.com https://www.gstatic.com 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob: 'self'; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data:; connect-src 'self' https://*.googleapis.com *.google.com https://*.gstatic.com https://*.google-analytics.com https://script.crazyegg.com https://d2dq2ahtl5zl1z.cloudfront.net data: blob:; frame-src 'self' *.google.com; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-fb453f355389481c847f62a2fe142972' https://minsundhedsplatform.dk 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://minsundhedsplatform.dk 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action 'self';media-src https://* 'self' blob:; 1 default-src 'self'; img-src 'self' data: https:; media-src 'self' https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; connect-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/datacenters_google 1 image-src https://www.facebook.com; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com static.kimidori.es data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.addthis.com *.facebook.com *.twitter.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.addthisedge.com *.twitter.com *.googleapis.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com media.kimidori.es static.kimidori.es cdn.kimidori.es *.google.es *.amazonaws.com imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.disqus.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com maps.googleapis.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net static.kimidori.es static.zdassets.com widget-mediator.zopim.com s.pinimg.com ct.pinterest.com *.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.gstatic.com *.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com static.kimidori.es 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com maps.googleapis.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app kimidorihelp.zendesk.com static.kimidori.es media.kimidori.es widget-mediator.zopim.com stats.g.doubleclick.net ct.pinterest.com vc-service.saleago.com *.google.es wss://widget-mediator.zopim.com *.cookiebot.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.windows.net *.powerbi.com *.gstatic.com *.googleapis.com *.visualstudio.com content.powerapps.com stats.g.doubleclick.net www.google-analytics.com www.google.com www.googletagmanager.com *.pendo.io; style-src 'self' 'unsafe-inline' www.gstatic.com content.powerapps.com fonts.googleapis.com *.pendo.io; img-src 'self' data: blob: file *.windows.net *.1bc.app *.powerapps.com www.google-analytics.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.pendo.io; frame-src 'self' *.google.com app.pendo.io; frame-ancestors 'self' app.pendo.io; worker-src blob:; report-uri https://1breadcrumb.report-uri.com/r/d/csp/reportOnly 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com https://*.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.333obra.com.br *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' data: *.demdex.net *.online-metrix.net *.doubleclick.net *.braintreegateway.com *.googletagmanager.com *.facebook.com https://*.useinsider.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.online-metrix.net *.d.aa.online-metrix.net https://firebasestorage.googleapis.com quickchart.io img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com maps.gstatic.com *.google.com *.google.com.br *.facebook.com assets-shorts.mimo.com.br assets.mimo.com.br ad.doubleclick.net https://*.cloudfront.net https://cdn.cookielaw.org https://*.hotjar.com https://*.nr-data.net https://*.adobe.com https://*.adobedtm.com https://*.demdex.net https://cimentobomdemais.com.br *.333obra.com.br *.clarity.ms *.bing.com https://s3.amazonaws.com https://dev.visualwebsiteoptimizer.com https://s3.amazonaws.com/raichu-beta/ra-verified/assets/images/verified.svg https://s3.amazonaws.com/raichu-beta/ra-verified/assets/images/ra-logo.svg https://votorantimcimentoshelp1697804564.zendesk.com https://*.votorantimcimentoshelp.zendesk.com https://static.zdassets.com/web_widget/latest/default_avatar.png https://*.useinsider.com https://img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://h.online-metrix.net *.cardinalcommerce.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com connect.facebook.net js-agent.newrelic.com analytics.tiktok.com bat.bing.com h64.online-metrix.net https://cdn.cookielaw.org https://*.cloudfront.net https://cdnjs.cloudflare.com/ajax/libs/select2/3.5.2/select2.min.js https://bam.nr-data.net https://*.hotjar.com 'unsafe-inline' https://cdn.jsdelivr.net/npm/choices.js@4/public/assets/scripts/choices.min.js https://cdn.popconvert.com.br/widget/popconvert.js https://cdn.popconvert.com.br/widget/dist/js/app.js https://cdn.pn.vg https://www.clarity.ms https://bat.bing.com/bat.js https://*.sentry-cdn.com https://*.zendesk.com https://static.zdassets.com https://*.s3.amazonaws.com https://dev.visualwebsiteoptimizer.com https://s3.amazonaws.com/raichu-beta/ra-verified/bundle.js https://sdk.crmback.io/connect.js https://plugins.crmback.io/helpers/tresobra.js shorts.mimo.com.br https://*.useinsider.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com https://cdnjs.cloudflare.com/ajax/libs/select2/3.5.2/select2.min.css https://*.hotjar.com 'unsafe-inline' https://s3.amazonaws.com https://s3.amazonaws.com/raichu-beta/ra-verified/styles.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com assets-shorts.mimo.com.br 'self' 'unsafe-inline'; manifest-src 'self' data: 'unsafe-inline' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://viacep.com.br maps.googleapis.com *.google-analytics.com stats.g.doubleclick.net analytics.tiktok.com bat.bing.com h64.online-metrix.net https://api.reclameaqui.com.br *.cookielaw.org https://privacyportal-br.onetrust.com https://geolocation.onetrust.com https://*.cloudfront.net *.rdstation.com.br https://bam.nr-data.net https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.adobe.com *.adobedtm.com *.demdex.net *.magentocommerce.com *.doubleclick.net *.googleadservices.com *.vimeocdn.com *.vimeo.com *.youtube.com *.omtrdc.net *.googletagmanager.com *.adobedc.net *.magento.com *.adobe.io *.adobe.net *.magedevteam.com *.metrix.net *.geojs.io *.braintreegateway.com wa.me web.whatsapp.com *.snplow.net performance.typekit.net paypal.com paypalobjects.com *.online-metrix.net viacep.com.br 'self' data: 'unsafe-inline' gyruss.rdops.systems/v2/conversions osp-assets.pn.vg *.clarity.ms https://*.ingest.sentry.io/api https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net https://dev.visualwebsiteoptimizer.com https://*.zendesk.com https://*.s3.amazonaws.com https://static.zdassets.com https://ekr.zdassets.com https://iosite.reclameaqui.com.br wss://pod-27.zendesk.com https://s3.amazonaws.com/raichu-beta/ra-verified/bundle.js https://onsite.crmback.io/collect https://x.cbstatus.net/check https://www.333obra.com.br/share_cart/action/link/ pip.mimo.com.br assets-shorts.mimo.com.br assets.mimo.com.br cms.mimo.com.br https://api.shorts.mimo.com.br https://gtw.mimo.com.br analytics.mimo.com.br fonts.gstatic.com *.firebaseio.com player.live-video.net *.us-east-1.playback.live-video.net https://*.useinsider.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.bootstrapcdn.com *.gstatic.com 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net consentcdn.cookiebot.com www.googletagmanager.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com www.a4h-tech.com maps.gstatic.com www.facebook.com bat.bing.com bat.bing.net https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com * https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.googletagmanager.com tagmanager.google.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.bootstrapcdn.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl downloads.mailchimp.com https://static.klaviyo.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.googleapis.com *.zendesk.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com pagead2.googlesyndication.com sentry.io bat.bing.net *.cookiebot.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.googletagmanager.com https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' agrosolo.com.br *.agrosolo.com.br wake-components.fbitsstatic.net agrosolo.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.intelipost.com.br *.g.doubleclick.net *.googleadservices.com *.onesignal.com *.lahar.com.br *.googlesyndication.com *.smarthint.co dzpxyxks1bfmb.cloudfront.net imgs.ebit.com.br *.fabricadeaplicativos.com.br *.fabapp.com *.app.vc *.applink.com.br galeria.fabricadeaplicativos.com.br pwa.app.vc pages.agrosolo.com.br *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.facebook.net *.google.com.br connect.facebook.net gstatic.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com special.api.mandae.com.br mandae.com.br *.azurewebsites.net *.blob.core.windows.net *.avalio.eu avalio.eu *.jsdelivr.net *.mailbiz.one *.fbits.store *.adyen.com *.conectiva.io *.sunset.systems *.cartstack.com.br *.cartstack.com *.performa.ai *.cupom.social *.conectiva.app app.conectiva.io vm.conectiva.io conectiva.app api.performa.ai valid.performa.ai cartstack.com.br app.cartstack.com.br api.cartstack.com.br sunset.systems api.sunset.systems cupom.social app.cupom.social cdn.performa.ai *app.cartstack.com *.clarity.ms conectiva.io *.goadopt.io *.pagar.me *.mundipagg.com *.getnet.com.br *.utmify.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.stapecdn.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.maxipago.net stapecdn.com *.cloudflare.com *.trlution.com trlution.com tracking.leadspark.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.tioliveira.com cdn.jsdelivr.net ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.agrosolo.com.br agrosolo.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self'; script-src 'self' 'nonce-e-tbmzD9XcamatRUeGAvlw6-GkHykI1ar1Oky2jPLRjLB5xDfMlIKQ' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com; report-uri https://www.asterdmhealthcare.in/@http-reporting?csp=report&requestTime=1765933888372388 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://polyfill-fastly.io https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.oppwa.com oppwa.com *.peachpayments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com oppwa.com *.oppwa.com *.peachpayments.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net *.adobe.com https://fonts.googleapis.com *.fontawesome.com *.oct8ne.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vimeo.com *.afip.gob.ar *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net *.mercadolibre.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://live.decidir.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vimeo.com *.afip.gob.ar *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afip.gob.ar *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net https://apis.google.com *.avada.io *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.mlstatic.com *.mercadopago.com *.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com https://developers.decidir.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afip.gob.ar *.fitit.ai https://cdn.fitit.ai https://us-central1-fitit-a5bde.cloudfunctions.net https://get.geojs.io *.avada.io *.google-analytics.com https://www.google-analytics.com *.mercadopago.com *.mercadolibre.com *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://live.decidir.com https://developers.decidir.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'unsafe-inline' data: *.kxcdn.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.eglobal.com.mx *.newrelic.com *.hotjar.com *.facebook.net *.online-metrix.net *.ecommercebbva.com *.openpay.mx *.cardinalcommerce.com *.verifiedbyvisa.com *.arcot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.fbcdn.net blob: cdn.doofinder.com *.disqus.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.google.com.mx *.cloudflare.com *.googletagmanager.com *.hotjar.com *.facebook.net *.newrelic.com *.cardinalcommerce.com *.online-metrix.net *.fraudlabspro.com *.magecomp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com cdn.doofinder.com *.disqus.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.comodo.com *.list-manage.com *.googletagmanager.com polyfill.io *.hotjar.com *.facebook.net *.fraudlabspro.com *.twitter.com *.fontawesome.com *.cardinalcommerce.com *.online-metrix.net *.algolianet.com *.arcot.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.doofinder.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cloudflare.com *.bootstrapcdn.com *.newrelic.com *.cardinalcommerce.com *.online-metrix.net *.arcot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.doofinder.com wss://*.doofinder.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.cloudflare.com *.fraudlabspro.com *.hotjar.com *.facebook.net *.doubleclick.net *.cardinalcommerce.com *.online-metrix.net *.algolia.net chimpstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com 'self' data: *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.innoship.ro https://www.googletagmanager.com/ *.wesupply.xyz https://wesupplylabs.com s.pinimg.com ct.pinterest.com consentcdn.cookiebot.com *.weltpixel.com *.tawk.to https://b2d.springfarma.com/ https://consentcdn.cookiebot.eu/ *.creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tbicp.com *.tile.openstreetmap.org *.openstreetmap.org http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ t.themarketer.com cdn1.themarketer.com *.hsforms.net *.hsforms.com 'self' data: www.google.ro/ads www.facebook.com/tr analytics.tiktok.com *.google-analytics.com *.analytics.google.com s.pinimg.com ct.pinterest.com www.google.com.ua *.tawk.to cdn.jsdelivr.net *.facebook.com *.omnitagjs.com *.google.ro https://b2d.springfarma.com *.adnxs.com *.mktr2.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tbicp.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io t.themarketer.com cdn1.themarketer.com *.hsforms.net *.hsforms.com www.google.ro attr-2p.com cdnjs.cloudflare.com retargeting.newsmanapp.com analytics.tiktok.com https://connect.facebook.net s.pinimg.com ct.pinterest.com consent.cookiebot.com *.tawk.to cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.cloudflareinsights.com *.clarity.ms *.newrelic.com *.cookiebot.eu *.creativecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com t.themarketer.com cdn1.themarketer.com *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.mktr2.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com c1api.themarketer.com c2api.themarketer.com c3api.themarketer.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://connect.facebook.net analytics.tiktok.com *.analytics.google.com s.pinimg.com ct.pinterest.com *.tawk.to wss://*.tawk.to *.facebook.net https://www.google.com https://ams.creativecdn.com https://bam.eu01.nr-data.net *.nr-data.net *.cookiebot.eu *.clarity.ms *.googlesyndication.com *.tiktokw.us 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.feedbackcompany.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.fonts.googleapis.com data: *.cloudflare.com https://dashboard.webwinkelkeur.nlfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.doubleclick.net *.googlesyndication.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://*.dpdconnect.nl *.addthis.com *.pinterest.com *.cookiebot.com *.googletagmanager.com *.webwinkelkeur.nl https://dashboard.webwinkelkeur.nl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com imgsct.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.feedbackcompany.com https://firebasestorage.googleapis.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com *.google.co.in *.cookiebot.com *.bing.com mcusercontent.com *.google.nl *.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io consent.cookiebot.com https://*.dpdconnect.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.feedbackcompany.com *.avada.io *.shopify.com player.vimeo.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.cookiebot.com *.varify.io *.bing.com unpkg.com *.bing.net https://www.googletagmanager.com https://www.google-analytics.com *.cookie-script.com *.pinimg.com https://dashboard.webwinkelkeur.nl/sidebar.js https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net *.doubleclick.net *.googlesyndication.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.feedbackcompany.com https://get.geojs.io *.avada.io *.cloudflare.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.cookiebot.com *.bing.com *.varify.io *.bing.net *.pinterest.com *.cookie-script.com *.pinimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com x.klarnacdn.net cdn.elev.io maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl *.avile.dk policy.app.cookieinformation.com ct.pinterest.com td.doubleclick.net tr.snapchat.com tr6.snapchat.com messenger-edge.dixa.io messenger.dixa.io www.googletagmanager.com facebook.com *.facebook.com *.klarna.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com *.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.google.dk *.facebook.com bat.bing.com bat.bing.net stats.g.doubleclick.net *.sleeknote.com parametre.online *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.at *.ditur.co.uk *.ditur.ie *.ditur.be *.ditur.nl *.ditur.is *.ditur.it *.ditur.es *.ditur.pt *.klockia.se *.klockia.dk *.klockia.no *.avile.dk ditur.dk ditur.no ditur.se ditur.de ditur.fi ditur.com ditur.fr ditur.at ditur.co.uk ditur.ie ditur.be ditur.nl ditur.is ditur.it ditur.es ditur.pt klockia.se klockia.dk klockia.no avile.dk tr.snapchat.com tr6.snapchat.com *.etrusted.com *.trustedshops.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://redchamps.com *.klarna.com *.klarnaevt.com *.klarnacdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com *.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.reaktion.com policy.app.cookieinformation.com policy.cookieinformation.com *.facebook.net script.parametre.online ct.pinterest.com s.pinimg.com bat.bing.com *.tiktok.com *.sleeknote.com *.getdrip.com *.cloudfront.net *.kameleoon.eu *.kameleoon.io *.fontawesome.com *.ditur.dk *.ditur.se *.ditur.no *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl messenger.dixa.io sc-static.net tr.snapchat.com cdn.elev.io *.clarity.ms checkout.reepay.com static.cloudflareinsights.com *.trustedshops.com *.etrusted.com *.getzowie.com *.heylink.com *.posthog.com *.tangiblee.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.klarnacdn.net *.klarna.com *.profitmetrics.io *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.products.kameleoon.com x.klarnacdn.net fonts.googleapis.com *.etrusted.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.reaktion.com *.cookieinformation.com google.com *.google.com googleads.g.doubleclick.net *.pinterest.com *.tiktok.com *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl *.avile.dk api.products.kameleoon.com *.kameleoon.eu data.kameleoon.io *.fontawesome.com bat.bing.com bat.bing.net invitejs.trustpilot.com tr.snapchat.com tr6.snapchat.com messenger-edge.dixa.io region1.google-analytics.com cdn.elev.io ipa.elev.io events.elev.io *.clarity.ms pagead2.googlesyndication.com *.etrusted.com *.getzowie.com analytics.sleeknote.com/ *.posthog.com *.tangiblee.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.klarnacdn.net *.klarna.com *.klarnaevt.com *.profitmetrics.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.boxnow.gr *.boxnow.cy *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com *.auglio.com cdnjs.cloudflare.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.piraeusbank.gr *.vivapayments.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.boxnow.gr *.boxnow.cy x.grxchange.gr iframe.auglio.com *.twitter.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.boxnow.gr *.boxnow.cy https://firebasestorage.googleapis.com *.designer-images.net trustmark.gr greca-obj.adman.gr *.dustandcream.gr www.google.gr l.sharethis.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.boxnow.gr *.boxnow.cy *.avada.io *.stat-track.com polyfill.io *.moosend.com static.adman.gr trustmark.gr go.linkwi.se mirror.virtooal.com greca.adman.gr tryon.auglio.com static.cloudflareinsights.com auglio.pages.dev cdn.stat-track.com platform-api.sharethis.com buttons-config.sharethis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.piraeusbank.gr *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.moosend.com *.bootstrapcdn.com cdnjs.cloudflare.com use.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.dustandcream.gr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.boxnow.gr *.boxnow.cy https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com greca.adman.gr static.adman.gr www.virtooal.com iframe.auglio.com t.stat-track.com forms.m-pages.com l.sharethis.com tryon.auglio.com *.cloudflare.com *.twitter.com *.twimg.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src iframe.auglio.com greca.adman.gr auglio.pages.dev 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.farmakeio101.gr assets.farmakeio101.gr *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com *.vivapayments.com *.cardlink.gr *.eurocommerce.gr *.iris.dias.com.gr *.test-iris.dias.com.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.google.com *.google.com *.skroutz.gr *.hotjar.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.google.com *.google.gr *.stage-farmakeio101.artserver.gr *.farmakeio101.gr farmakeio101.gr *.zevioo.com *.trustmark.gr *.skroutz.gr *.sharethis.com *.bsscommerce.com *.magecomp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.facebook.com *.designer-images.net https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.g.doubleclick.net *.googletagmanager.com *.stage-farmakeio101.artserver.gr *.farmakeio101.gr farmakeio101.gr *.zevioo.com *.adman.gr *.hotjar.com *.trustmark.gr *.skroutz.gr *.sharethis.com *.facebook.net *.vivapayments.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.avada.io *.stat-track.com polyfill.io *.moosend.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com *.googleapis.com *.stage-farmakeio101.artserver.gr *.farmakeio101.gr farmakeio101.gr *.zevioo.com *.findbar.io *.fontawesome.com maxcdn.bootstrapcdn.com *.moosend.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.findbar.io 'self' 'unsafe-inline'; manifest-src *.stage-farmakeio101.artserver.gr *.farmakeio101.gr farmakeio101.gr 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.analytics.google.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.googleapis.com artserver.gr *.sharethis.com *.facebook.net *.facebook.com *.g.doubleclick.net *.farmakeio101.gr assets.farmakeio101.gr www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.google-analytics.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://*.amazonaws.com/static.khipu.com/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.google.cl prod-cencosudchile.omni.pro stats.g.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net region1-google-analytics.com stats.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app region1-google-analytics.com stats.g.doubleclick.net googleads.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.feedbackcompany.com *.googleapis.com maxcdn.bootstrapcdn.com https://*.hotjar.com https://*.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.feedbackcompany.com https://*.tawk.to https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ https://*.tawk.to https://*.doubleclick.net https://www.facebook.com https://assets.pinterest.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://stellar.givingeurope.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.feedbackcompany.com 'self' data: https://*.sirv.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://*.analytics.google.com https://*.clarity.ms https://*.google-analytics.com https://*.googletagmanager.com https://*.hotjar.com https://*.linkedin.com https://*.tawk.to https://bat.bing.com https://c.bing.com https://cdn.jsdelivr.net https://exch.vanheijster.nl https://exch.vanhelden.nl https://exch.vanhelden.be https://exch.eurogifts.be https://exch.eurogifts.fr https://googleads.g.doubleclick.net https://tawk.link https://www.google.nl https://www.facebook.com https://i.pinimg.com https://log.pinterest.com https://imgsct.cookiebot.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://ade.googlesyndication.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com d2a6mddvzruxpc.cloudfront.net https://stellar.givingeurope.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://maps.googleapis.com *.feedbackcompany.com bam.nr-data.net bam-cell.nr-data.net js-agent.newrelic.com https://*.sirv.com https://portal.zakeke.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://*.convertexperiments.com https://*.googletagmanager.com https://*.hotjar.com https://*.tawk.to https://bat.bing.com https://connect.facebook.net https://cdn.jsdelivr.net https://googleads.g.doubleclick.net https://snap.licdn.com https://script.adcalls.nl https://www.clarity.ms https://www.google.com https://www.googleadservices.com https://www.googleoptimize.com https://assets.pinterest.com https://widgets.pinterest.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://ct.pinterest.com https://s.pinimg.com https://ct.beslist.nl https://cdn.optimizely.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://stellar.givingeurope.com https://components.givingeurope.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com maxcdn.bootstrapcdn.com https://*.sirv.com https://*.hotjar.com https://*.tawk.to https://cdn.jsdelivr.net https://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.tawk.to https://v.pinimg.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.feedbackcompany.com bam.nr-data.net bam-cell.nr-data.net https://*.sirv.com https://api.zakeke.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.analytics.google.com https://*.clarity.ms https://*.google-analytics.com https://*.googletagmanager.com https://*.hotjar.com https://*.hotjar.io https://*.tawk.to https://api.adcalls.nl https://bat.bing.com https://cdn.linkedin.oribi.io https://fonts.gstatic.com https://www.facebook.com wss://*.hotjar.com wss://*.tawk.to https://consentcdn.cookiebot.com https://exch.vanheijster.nl https://exch.vanhelden.nl https://exch.vanhelden.be https://exch.eurogifts.be https://exch.eurogifts.fr https://ct.pinterest.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://*.googlesyndication.com https://*.metrics.convertexperiments.com https://logs.convertexperiments.com https://*.convertexperiments.com https://ct.beslist.nl https://ad.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://stellar.givingeurope.com https://components.givingeurope.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://www.googletagmanager.com *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com fastcalc.dialux.com *.isoled.shop *.list-manage.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.isoled.info *.isoled.hu *.isoled.ch 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://youtube.com fastcalc.dialux.com *.isoled.shop *.googletagmanager.com *.doubleclick.net *.isoled.info youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io camo.githubusercontent.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com maps.gstatic.com widgets.trustedshops.com/ *.facebook.com fastcalc.dialux.com *.google.at *.visableleads.com *.kununu.com *.linkedin.com *.bing.com *.isoled.shop isoled.shop blob: img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com youtube.com https://cdnjs.cloudflare.com maps.googleapis.com *.googleadservices.com *.usercentrics.eu widgets.trustedshops.com/ fastcalc.dialux.com *.visableleads.com *.isoled.shop *.isoled.info sst.dev.isoled.shop *.chimpstatic.com *.clarity.ms *.licdn.com *.bing.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com static-app.connect-qa.trustedshops.com fastcalc.dialux.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com maps.googleapis.com *.googletagmanager.com *.analytics.google.com *.amazon.com *.amazon.de fastcalc.dialux.com *.doubleclick.net *.isoled.shop *.isoled.info region1.google-analytics.com *.linkedin.com *.clarity.ms *.bing.com *.googlesyndication.com *.usercentrics.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' liderdamatilha.com.br *.liderdamatilha.com.br wake-components.fbitsstatic.net LiderdaMatilha.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com googleadservices.com cloudflare.com alphassl.com doubleclick.net hertzen.com moip.com.br ebit.com.br *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.alphassl.com *.cloudflare.com *.googleadservices.com *.doubleclick.net *.ebit.com.br *.hertzen.com *.moip.com.br wss://signalr.fbits.net *.gstatic.com *.hotjar.com k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.hotjar.io vc.hotjar.io secure.mlstatic.com *.mercadopago.com mercadopago.com *.clearsale.com.br wss://ws4.hotjar.com *.hotjar hotjar.com hotjar script.hotjar.com wss://ws14.hotjar.com wss://ws2.hotjar.com *.bootstrapcdn.com wss://*.hotjar.com dzpxyxks1bfmb.cloudfront.net *.mercadolibre.com *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net samuraiexpertsstorage.blob.core.windows.net *.azurewebsites.net *.analytics.tiktok.com *.liderdamatilha.com.br *.tiktok.com *.pinimg.com *.avis-verifies.com *.bing.com cl.avis-verifies.com s.pinimg.com bat.bing.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.clarity.ms *.pinterest.com *.blob.core.windows.net analytics.tiktok.com *.fbits.store *.adyen.com *.mimo.com.br *.shorts.mimo.com.br *.konfidency.com.br *.google.com.br google.com.br translate.googleapis.com *.googleapis.com *.com.ph *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.lightwidget.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.pagaleve.com.br wake.koin.com.br *.bonifiq.com.br bq-scripts.s3.amazonaws.com paypal-wake.s3.us-east-1.amazonaws.com cdn.jsdelivr.net *.jsdelivr.net *.mailbiz.one collector.mailbiz.one *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.liderdamatilha.com.br liderdamatilha.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://h.online-metrix.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://h.online-metrix.net *.cardinalcommerce.com *.pagaleve.io *.pagaleve.com.br *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://h.online-metrix.net *.d.aa.online-metrix.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.pagaleve.com.br https://cdn.mundipagg.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://h.online-metrix.net *.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.pagaleve.com.br *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com downloads.mailchimp.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://api.mundipagg.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src 'self' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com data:;style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com assets.mxapis.com *.cloudfront.net www.gstatic.com;style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com fonts.soundestlink.com www.gstatic.com assets.mxapis.com *.cloudfront.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.hotjar.com *.cloudflare.com *.doubleclick.net static.cloudflareinsights.com *.clarity.ms *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net *.googleapis.com;script-src-elem 'self' 'unsafe-inline' cdn.datatables.net static.cloudflareinsights.com *.clarity.ms *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.cloudflare.com *.doubleclick.net www.youtube.com pagead2.googlesyndication.com *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net;connect-src 'self' https://api.moonmart.lt *.nordcode.io *.google-analytics.com *.doubleclick.net *.google.com *.cookiebot.com *.bing.com *.googlesyndication.com *.clarity.ms *.facebook.com adservice.google.com graph.facebook.com www.googleadservices.com www.google.com www.google.lt www.google.lv googleadservices.com google.com google.lt google.lv pagead2.googlesyndication.com *.nosto.com *.sentry.io *.googleapis.com *.equalweb.com *.soundestlink.com *.dot.vu ams.creativecdn.com analytics.tiktok.com *.e-menessaptieka.lv *.moonmart.lt *.mxapis.com *.tiktokw.us;frame-src 'self' *.cookiebot.com *.doubleclick.net *.youtube.com accounts.google.com *.ladesk.com live.dot.vu ams.creativecdn.com cdn.mxapis.com;img-src 'self' data: https://api.moonmart.lt https://images.moonmart.lt *.klix.app *.cookiebot.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.googletagmanager.com *.google.com *.google.lt *.google.lv *.cloudflare.com *.tawk.to tawk.link *.hotjar.com *.soundestlink.com *.googleapis.com *.gstatic.com *.facebook.com *.youtube.com *.doubleclick.net *.dmxleo.com *.hotjar.com *.bing.com *.adform.net *.criteo.com *.clarity.ms *.demdex.net x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com googleads.g.doubleclick.net omnisnippet1.com csm.fr3.eu.criteo.net id5-sync.com ade.googlesyndication.com *.nosto.com *.appspot.com serve.mxapis.com *.e-menessaptieka.lv *.moonmart.lt www.googleadservices.com *.creativecdn.com static.salidzini.lv ema.ladesk.com;default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://api.moonmart.lt https://images.moonmart.lt;report-uri https://api.moonmart.lt/csp/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://js.klevu.com *.ccbagroup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://static.whatsapp.net *.ccbagroup.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://js-agent.newrelic.com https://apps.mypurecloud.ie *.ccbagroup.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com https://cdnjs.cloudflare.com *.ccbagroup.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://edge.adobedc.net https://bam.nr-data.net https://api-cdn.mypurecloud.ie *.ccbagroup.com https://adobedc.demdex.net/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://c4b562ef207d9ca89618f9d5f5a9d1d9.report-uri.com/r/d/csp/reportOnly; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.dotdigital-pages.com *.dotdigital.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.ewaypayments.com https://*.sandbox.ewaypayments.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com *.trackedlink.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com t.zip.co static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://*.ewaypayments.com https://*.sandbox.ewaypayments.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net static.zip.co zip.co https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.cloudfront.net *.trustpilot.com *.cloudflare.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com pay.google.com js.stripe.com *.stripecdn.com newassets.hcaptcha.com *.stripe.network *.trustpilot.com youtu.be *.vimeo.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * https://plumrocket.com https://www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.gstatic.com *.googleapis.com *.cloudfront.net bat.bing.com www.google.bg www.google.com.ua www.google.co.uk *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu blob: *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudfront.net apis.google.com *.trustpilot.com bat.bing.com js.stripe.com *.stripecdn.com pay.google.com hcaptcha.com newassets.hcaptcha.com *.stripe.network *.zdassets.com region1.analytics.google.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.googleadservices.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com https://apis.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://load.cofs.partscentre.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudfront.net js.stripe.com *.stripecdn.com *.trustpilot.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.stripe.network *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://ipinfo.io *.cloudfront.net bat.bing.com *.zdassets.com partsretailgroup.zendesk.com region1.analytics.google.com js.stripe.com *.stripe.com pay.google.com *.hcaptcha.com *.trustpilot.com widget-mediator.zopim.com *.cloudflare.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://load.cofs.partscentre.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.goftino.com; font-src 'self' https://fonts.gstatic.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; connect-src *; frame-src * 1 font-src maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.swagger.io *.scene7.com static.klaviyo.com mcstaging.polarenlinea.com mcprod.polarenlinea.com *.facebook.com *.doubleclick.net p.typekit.net *.gstatic.com *.googleapis.com *.google.com *.google-analytics.com *.googleadservices.com *.braintreegateway.com *.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.marketo.net 233-mju-939.mktoresp.com smetrics.polarenlinea.com *.facebook.com *.facebook.net *.connect.facebook.net *.cardinalcommerce.com unpkg.com cdn.jsdelivr.net *.magento-datasolutions.com *.googleadservices.com *.google-analytics.com *.google.com *.googletagmanager.com *.paypal.com *.paypalobjects.com *.bolt.com *.commerce-quick-checkout.com *.magento-ds.com amcglobal.sc.omtrdc.net use.typekit.net *.googleapis.com *.gstatic.com *.online-metrix.net *.cybersource.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com fonts.gstatic.com static.klaviyo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.demdex.net 233-mju-939.mktoresp.com *.cardinalcommerce.com *.snplow.net *.facebook.com *.paypal.com *.pingdom.net *.woorank.com *.adobe.io *.adobedc.net *.youtube.com *.google.com *.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com *.bolt.com *.magento-ds.com performance.typekit.net *.sentry.io *.braintreegateway.com *.braintree-api.com smetrics.polarenlinea.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' litium.revolutionrace.dk fbcdn.revolutionrace.dk wss://fbcdn.revolutionrace.dk *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.dk *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 default-src 'self' litium.revolutionrace.fi fbcdn.revolutionrace.fi wss://fbcdn.revolutionrace.fi *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.fi *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 default-src 'self'; script-src 'self'; script-src-elem 'self' ajax.googleapis.com *.westpac.com.au api.payway.com.au cdn.impel.io maps.googleapis.com www.google.com www.gstatic.com apis.google.com rum-static.pingdom.net www.googletagmanager.com js-agent.newrelic.com www.google-analytics.com *.hotjar.com snap.licdn.com trkcall.com *.doubleclick.net www.googleadservices.com *.nr-data.net connect.facebook.net tags.srv.stackadapt.com static.cloudflareinsights.com cdnjs.cloudflare.com 'sha256-/F/mq+WLzVf3FEiOMnr2La2iRHAQNBsHWuOAm7j4Se8=' 'sha256-7MH6kRlp+lID8UEmfqu2Jm1PAkBem+q56oJaMqh6E/o=' 'sha256-zEF/ALwwDYV2nZ+rdYGh2XpjU1lbO3oZ2osZayOlmpw=' 'sha256-nLnCNpJbSw3otcW8NkBseYzmHzlTHdZbaPGtRs3+Hrs=' 'sha256-FQnwEr51/dvILYpXGzPt0xHtru/wgNyzR5sPaD1vEW8=' 'sha256-bCZAA1uPxVFldSMgHf5/pBNKmqTA59mkFD3OfxXi5pE=' 'sha256-RhD734aJ6iBEq9vAIsknBvuRlX1AEVJptGJhXDz5NC8='; connect-src 'self' *.googleapis.com *.facebook.com api.payway.com.au www.google.com www.google-analytics.com analytics.google.com *.pingdom.net *.doubleclick.net *.linkedin.com *.trkcall.com *.nr-data.net tags.srv.stackadapt.com *.hotjar.io *.hotjar.com s3-ap-southeast-2.amazonaws.com wss://slatteryauction-api.herokuapp.com https://slatteryauction-api.herokuapp.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com tags.srv.stackadapt.com; media-src 'self' *.amazonaws.com *.slatteryauctions.com.au; img-src data: http: https:; font-src 'self' fonts.gstatic.com; frame-src slatteryauctions.com.au *.slatteryauctions.com.au https://spins.spincar.com td.doubleclick.net *.google.com www.googletagmanager.com api.payway.com.au; object-src 'self'; frame-ancestors 'self' *.slatteryauctions.com.au slatteryauctions.com.au *.salesforce.com slattery.lightning.force.com slattery.my.salesforce.com *.sandbox.lightning.force.com; worker-src blob: 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 'self' 'unsafe-inline'; frame-ancestors https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.google.com/ https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' data: 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://gum.criteo.com/ https://ct.pinterest.com/ https://server.souqstore.com.br *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://stats.g.doubleclick.net https://staticfiles.yviews.com.br https://service.yourviews.com.br https://api.pagar.me https://cdn.mundipagg.com https://img.youtube.com https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://c.clarity.ms https://newimgebit-a.akamaihd.net https://c.bing.com/ https://helpsouq.zendesk.com/ https://bat.bing.com/ https://oaz.sc.omtrdc.net/ https://www.souqstore.com.br/ https://server.souqstore.com.br cdn.mundipagg.com api.pagar.me data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com *.google.com/ http://viacep.com.br https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://www.googleoptimize.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net https://commerce.adobedtm.com https://js-agent.newrelic.com/ https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://www.clarity.ms/ https://imgs.ebit.com.br/ https://onsite.optimonk.com/ https://cdn-asset.optimonk.com/ https://gs-cdn.optimonk.com/ 'self' https://sslwidget.criteo.com/ https://pip.mimo.com.br/ https://ct.pinterest.com/ https://static.zdassets.com/ https://dynamic.criteo.com/ https://reviews.konfidency.com.br/ https://bat.bing.com/ https://s.pinimg.com/ https://www.dwin1.com/ https://flipnet-assets.s3.sa-east-1.amazonaws.com/ https://tag.goadopt.io/ 3ds2.pagar.me 3ds2-sdx.pagar.me https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br *.googleapis.com *.google.com tagmanager.google.com 'self' 'unsafe-inline'; object-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ widget.freshworks.com m2epro.freshdesk.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br https://newimgebit-a.akamaihd.net/ https://w.clarity.ms/ https://j.clarity.ms/ https://front.optimonk.com/ https://cdn-account.optimonk.com/ https://cdn-limit.optimonk.com/ https://jfapiprod.optimonk.com/ https://ekr.zdassets.com/ https://api.mimolivesales.com.br/ https://ct.pinterest.com/ https://helpsouq.zendesk.com/ https://idacomvoce.zendesk.com/ https://reviews-api.konfidency.com.br/ https://i.konduto.com/ https://oaz.tt.omtrdc.net/ https://server.souqstore.com.br api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br pay.sandbox.google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' data: 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://td.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://commerce.adobedc.net https://commerce.adobedtm.com https://*.gstatic.com https://*.google.com https://*.google.com.br https://*.googleadservices.com https://google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.g.doubleclick.net https://td.doubleclick.net https://*.facebook.com https://*.facebook.com.br https://*.facebook.net https://gstatic.com https://google.com https://google.com.br https://googleadservices.com https://*.google-analytics.com https://googletagmanager.com https://googleapis.com https://g.doubleclick.net https://facebook.com https://facebook.com.br https://facebook.net 'self' 'unsafe-inline' https://consent.cookiefirst.com/ *.yourviews.com.br *.yviews.com.br 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.weltpixel.com gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com https://*.clic2buy.com https://*.doubleclick.net https://ehub.cz https://*.gls-czech.cz https://*.packeta.com/ https://*.heureka.cz/ https://*.heureka.sk/ https://*.googletagmanager.com https://*.facebook.com widget.packeta.com backup.packeta.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://firebasestorage.googleapis.com https://*.cdninstagram.com https://*.ppl.cz https://*.seznam.cz https://im9.cz https://*.google.cz https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.facebook.com https://*.g.doubleclick.net https://*.mailkit.eu https://ehub.cz https://*.heureka.cz/ https://*.heureka.sk/ https://*.zbozi.cz https://*.bing.com https://*.clarity.ms/ https://bat.bing.net https://bat.bing.com https://*.analytics.google.com flagpedia.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com https://*.clic2buy.com https://*.googletagmanager.com https://*.smartlook.com https://*.smartlook.cloud https://*.smartform.cz https://*.heureka.cz https://*.mailkit.eu https://*.google.cz/ https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.seznam.cz https://*.dognet.sk https://ehub.cz https://*.facebook.net https://*.googleadservices.com https://*.google-analytics.com https://*.googleapis.com https://*.packeta.com/ https://*.zbozi.cz/ https://im9.cz/ https://*.clarity.ms/ https://bat.bing.com/ https://bat.bing.net/ https://cdn.heureka.group/ https://*.heureka.sk/ https://*.googlesyndication.com https://*.cdn-apple.com https://*.cloudfront.net widget.packeta.com backup.packeta.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ https://client.smartform.cz/ maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com https://maps.googleapis.com https://player.vimeo.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io https://*.ppl.cz https://*.smartlook.com https://*.smartlook.cloud https://*.mailkit.eu https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google.com https://*.facebook.com https://*.g.doubleclick.net https://ehub.cz https://widget.packeta.com https://*.clarity.ms https://*.heureka.group https://bat.bing.net https://*.seznam.cz https://*.googlesyndication.com https://bat.bing.com https://*.stape.at *.homecredit.cz *.homecredit.sk widget.packeta.com backup.packeta.com www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; report-to default; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; connect-src 'self'; img-src 'self' ; style-src 'self' 'unsafe-inline'; base-uri 'self'; font-src 'self';form-action 'self' https://intelligence.wdp.envestnet.com/; frame-src https://www.google.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.trustedshops.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com youtu.be *.vimeo.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.quotes.stockinthechannel.co.uk *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu blob: *.magebig.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com media.stockinthechannel.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com objects.icecat.biz 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.googleapis.com https://ipinfo.io *.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self';font-src 'self' fonts.gstatic.com;img-src 'self' secure.gravatar.com;style-src 'self' fonts.googleapis.com;frame-ancestors 'self'; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: bstore.be bstore.nl webprice.eu btienda.es fr.bstore.be 1 default-src 'self'; script-src 'self' 'nonce-8z97DuUYKLDIm3ZYdErQEAJuqJzrV2hrhOxYPY_KOTEFaHzBJfvBng' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com; report-uri https://www.landkreis-ludwigsburg.de/@http-reporting?csp=report&requestTime=1765938359423445&requestHash=59c9532739afd22aa664a303f26db4f228f0d8a9 1 object-src 'none'; script-src 'self' 'report-sample' https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://unpkg.com https://use.fontawesome.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.quadpay.com https://*.zip.co maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.lewandmassager.com *.bvibe.com use.fontawesome.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://bid.g.doubleclick.net *.lewandmassager.com *.bvibe.com https://www.googletagmanager.com/ *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.quadpay.com https://*.zip.co www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com shareasale.com *.bvibe.com *.lewandmassager.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://*.quadpay.com https://*.zip.co *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.google.com https://cdnjs.cloudflare.com *.lewandmassager.com *.bvibe.com *.impactcdn.com https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com maxcdn.bootstrapcdn.com assets.braintreegateway.com https://fonts.gstatic.com https://fonts.googleapis.com *.lewandmassager.com *.bvibe.com *.yotpo.com swellrewards.com *.swellrewards.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://*.quadpay.com https://*.zip.co api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://bvibe.pxf.io/ https://lewand-massager.sjv.io/ *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.fonts.googleapis.com data: *.cloudflare.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://plumrocket.com *.google.com *.addthis.com *.pinterest.com *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.attr-2p.com www.google.co.in 'self' data: blob: 'unsafe-inline' data: *.facebook.com quickchart.io img.youtube.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com static.cloudflareinsights.com attr-2p.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com s7.addthis.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.addthis.com *.graph.instagram.com *.google-analytics.com ekr.zdassets.com/ *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src www.paypalobjects.com; connect-src 'self' 'report-sample' s3.amazonaws.com/cv3.customfiles mpcart.commercev3.com *.listrakbi.com *.listrak.com www.google-analytics.com ssl.google-analytics.com ui.powerreviews.com stats.g.doubleclick.net analytics.google.com bat.bing.com www.paypal.com *.smartystreets.com ct.pinterest.com/user/ *.google-analytics.com *.analytics.google.com *.clarity.ms www.facebook.com *.klaviyo.com sandbox.affirm.com widget.sezzle.com media.sezzle.com tracker.affirm.com www.googletagmanager.com measurement-api.criteo.com www.google.com/pay *.pay.google.com www.google.com www.google.co.in pay.google.com; default-src 'self' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com 'unsafe-eval' ajax.googleapis.com analytics.google.com bat.bing.com c.bing.com code.jquery.com connect.facebook.net fonts.googleapis.com fonts.gstatic.com t.paypal.com www.facebook.com www.google-analytics.com www.googletagmanager.com www.paypal.com www.paypalobjects.com *.bootstrapcdn.com fonts.cdnfonts.com; font-src 'self' cdnprd.commercev3.net mpcart.commercev3.com s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com fonts.gstatic.com *.bootstrapcdn.com use.fontawesome.com data: fonts.cdnfonts.com; form-action 'self' www.facebook.com www.paypal.com checkout.sezzle.com; frame-src 'self' *.doubleclick.net www.paypalobjects.com www.paypal.com www.facebook.com www.pinterest.com www.google.com gum.criteo.com sandbox.affirm.com static.criteo.net player.vimeo.com www.youtube.com fledge.criteo.com pay.google.com fledge.us.criteo.com www.googletagmanager.com pay.google.com; frame-ancestors 'self' ; img-src 'self' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com ssl.google-analytics.com www.google.com/pagead/1p-user-list/ www.google.com/ads/ga-audiences ct.pinterest.com/v3/ stats.g.doubleclick.net bat.bing.com c.bing.com t.paypal.com www.facebook.com www.google-analytics.com www.googletagmanager.com *.listrakbi.com www.trustlogo.com data: code.jquery.com/ui/ *.google-analytics.com *.analytics.google.com *.clarity.ms www.paypal.com www.paypalobjects.com secure.trust-provider.com gum.criteo.com eb2.3lift.com tapestry.tapad.com s.ad.smaato.net trends.revcontent.com jadserve.postrelease.com idsync.rlcdn.com ads.stickyadstv.com matching.ivitrack.com tg.socdm.com visitor.omnitagjs.com ad.yieldlab.net ups.analytics.yahoo.com criteo-sync.teads.tv sync-t1.taboola.com rtb-csync.smartadserver.com match.sharethrough.com pixel.rubiconproject.com simage2.pubmatic.com contextual.media.net sync.outbrain.com exchange.mediavine.com ad.360yield.com r.casalemedia.com ih.adscale.de googleads.g.doubleclick.net media.sezzle.com ib.adnxs.com cm.g.doubleclick.net partner.mediawallahscript.com x.bidswitch.net sync-criteo.ads.yieldmo.com ad.tpmn.co.kr ade.clmbtech.com criteo-partners.tremorhub.com cotads.adscale.de dis.criteo.com mvezin.modernperformance.com www.googleadservices.com www.gstatic.com/images/ i.vimeocdn.com/video www.google.co.in; script-src 'self' 'report-sample' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com 'unsafe-inline' 'unsafe-eval' ssl.google-analytics.com ui.powerreviews.com bat.bing.com code.jquery.com connect.facebook.net *.bootstrapcdn.com www.google-analytics.com www.googletagmanager.com www.paypal.com www.paypalobjects.com *.listrakbi.com *.smartystreets.com api.livechatinc.com cdn.livechatinc.com ajax.googleapis.com googleads.g.doubleclick.net www.gstatic.com www.trustlogo.com www.googleadservices.com d79i1fxsrar4t.cloudfront.net/jquery.liveaddress/ s.pinimg.com/ct/ www.google.com www.clarity.ms static.klaviyo.com static-tracking.klaviyo.com secure.trust-provider.com sslwidget.criteo.com static.criteo.net widget.sezzle.com cdn1-sandbox.affirm.com widget.us.criteo.com www.google.com; script-src-elem 'self' 'report-sample' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com 'unsafe-inline' 'unsafe-eval' ssl.google-analytics.com ui.powerreviews.com bat.bing.com code.jquery.com connect.facebook.net *.bootstrapcdn.com www.google-analytics.com www.googletagmanager.com www.paypal.com www.paypalobjects.com *.listrakbi.com *.smartystreets.com api.livechatinc.com cdn.livechatinc.com ajax.googleapis.com googleads.g.doubleclick.net www.gstatic.com www.trustlogo.com www.googleadservices.com d79i1fxsrar4t.cloudfront.net/jquery.liveaddress/ s.pinimg.com/ct/ www.google.com www.clarity.ms static.klaviyo.com static-tracking.klaviyo.com secure.trust-provider.com sslwidget.criteo.com static.criteo.net widget.sezzle.com cdn1-sandbox.affirm.com widget.us.criteo.com www.google.com; style-src 'self' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com 'unsafe-inline' 'unsafe-eval' ui.powerreviews.com use.fontawesome.com code.jquery.com fonts.googleapis.com *.bootstrapcdn.com cdn.listrakbi.com/css/ hello.myfonts.net media.sezzle.com fonts.cdnfonts.com; style-src-elem 'self' cdnprd.commercev3.net s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com 'unsafe-inline' 'unsafe-eval' ui.powerreviews.com use.fontawesome.com code.jquery.com fonts.googleapis.com *.bootstrapcdn.com cdn.listrakbi.com/css/ hello.myfonts.net media.sezzle.com fonts.cdnfonts.com; style-src-attr 'unsafe-inline'; media-src 'self' mpcart.commercev3.com s3.amazonaws.com/cdn.modernperformance.com/ cdn.commercev3.net/cdn.modernperformance.com/ cdn.modernperformance.com www.bing.com; 1 default-src https: 'unsafe-inline' 'unsafe-eval'; report-uri https://b3ceba9babf02086c0dca962bbbd1cda.report-uri.io/r/default/csp/reportOnly 1 font-src data: cdn.jsdelivr.net *.googleapis.com *.gstatic.com *.tawk.to https://webchat.saysimple.io/ fonts.googleapis.com fonts.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://player.vimeo.com/ *.google.com https://googleads.g.doubleclick.net/ https://www.google.nl/ https://ct.pinterest.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.doubleclick.net 'self' data: *.googleapis.com *.gstatic.com cdn.jsdelivr.net *.tawk.to tawk.link *.facebook.com *.gravatar.com https://www.google.nl/ https://imgsct.cookiebot.com/1.gif https://ct.pinterest.com/v3/* https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.google.com *.google.bg *.facebook.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com *.jsdelivr.net *.tawk.to player.vimeo.com http://player.vimeo.com/api/player.js chimpstatic.com https://connect.facebook.net/ https://webchat.saysimple.io/ *.smooch.io https://s.pinimg.com/ https://ct.pinterest.com/ consent.cookiebot.com consent.cookiebot.eu https://s.pinimg.com/ct/lib/main.742e9fad.js https://s.pinimg.com/ct/core.js https://ct.pinterest.com/static/ct/token_create.js https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com *.list-manage.com *.multisafepay.com https://pay.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com cdn.jsdelivr.net *.tawk.to https://webchat.saysimple.io/ fonts.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com maxcdn.bootstrapcdn.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com/api/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com 'self' data: *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com/ *.paypal.com *.tawk.to 'self' ws: *.doubleclick.net https://webchat.saysimple.io/ *.smooch.io *.gravatar.com https://ct.pinterest.com/ consent.cookiebot.com consent.cookiebot.eu https://ct.pinterest.com/* https://ct.pinterest.com/v3/* https://ct.pinterest.com/user/* https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.facebook.com *.facebook.net *.google.com *.googlesyndication.com *.tiktok.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com 'self' data: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com www.googletagmanager.com *.adyen.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com platform.cloud-iq.com.au *.facebook.com *.doubleclick.net *.bedbathntable.com.au *.criteo.com *.pinterest.com *.dotdigital-pages.com *.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.adyen.com https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com *.googleapis.com *.gstatic.com dev.visualwebsiteoptimizer.com *.google.com *.facebook.com *.cloud-iq.com.au *.afterpay.com *.linksynergy.com *.google.com.au *.bedbathntable.com.au bbnt-m2-image-library.s3-ap-southeast-2.amazonaws.com *.cdninstagram.com *.google.lk *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.socdm.com *.criteo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.media.net *.bing.com *.yieldmo.com *.aralego.com *.3lift.com *.clmbtech.com *.teads.tv *.smaato.net *.rubiconproject.com *.pubmatic.com *.outbrain.com *.aralego.net *.1rx.io *.bluekai.com *.contextweb.com *.unrulymedia.com *.trackedlink.net *.ddlnk.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com *.google.com www.googletagmanager.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.googleapis.com applepay.cdn-apple.com dev.visualwebsiteoptimizer.com *.afterpay.com *.newrelic.com cdnjs.cloudflare.com bam-cell.nr-data.net platform.cloud-iq.com.au *.crazyegg.com *.facebook.net *.facebook.com *.rakuten.com googleads.g.doubleclick.net cdn.lr-ingest.io *.foursixty.com *.bedbathntable.com.au *.tiktok.com *.pinimg.com *.criteo.com *.pinterest.com *.freshworks.net *.freshworks.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zipmoney.com.au zip.co https://www.bedbathntable.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com unpkg.com *.foursixty.com *.bedbathntable.com.au *.cloud-iq.com.au *.use.typekit.net *.p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.crazyegg.com googleads.g.doubleclick.net bam-cell.nr-data.net *.lr-ingest.io *.foursixty.com *.google-analytics.com *.doubleclick.net *.bedbathntable.com.au *.nr-data.net foursixty.com *.pinterest.com *.pangle-ads.com *.tiktok.com *.criteo.com *.google.com *.freshworks.net *.freshworks.com *.attraqt.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com https://accounts.google.com/ *.googletagmanager.com *.google-analytics.com https://www.google.com/ https://www.google.com.br/ https://www.mercadopago.com.br/ *.clarity.ms https://analytics.google.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.youtube.com/ https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ ecommerce.live.gobots.com.br qa-plugin-stg.gobots.com.br qa.gobots.com.br https://analytics.tiktok.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://www.youtube.com/iframe_api https://accounts.google.com/ https://www.google.com/ https://www.google.com.br/ https://www.mercadopago.com.br/ https://mcprod.bfcasa.com.br/ https://*.newrelic.com/ https://stape.bfcasa.com.br/ *.clarity.ms *.google-analytics.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com qa.gobots.com.br https://viacep.com.br https://www.viacep.com.br https://analytics.tiktok.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://stape.bfcasa.com.br/ *.clarity.ms https://bam.nr-data.net *.googletagmanager.com *.google-analytics.com https://analytics.google.com *.analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://get.geojs.io *.avada.io *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob:; script-src 'self' 'nonce-{{ request.nonce }}' https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-scripts.com https://*.hscollectedforms.net https://*.hs-banner.com https://*.hubspotusercontent.com https://*.hubspotusercontent-eu1.net https://js.hs-analytics.net https://js.hsforms.net https://api.hsforms.com https://api.hubapi.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hs-web-analytics.net https://static.hsappstatic.net https://cdn2.hubspot.net https://cdn.hubspot.com https://*.cloudfront.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://stats.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org https://www.youtube.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https: data:; connect-src 'self' https: wss:; media-src 'self' https: data: blob:; worker-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self' https://*.hubspot.com; 1 default-src 'self' 'unsafe-inline' fonts.gstatic.com fonts.googleapis.com; img-src 'self' data: https: http: ; frame-src 'self' http: https: *.google.com; script-src 'self' 'unsafe-inline' https: ; object-src 'self' 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com *.cloudflare.com *.cloudfront.net *.bootstrapcdn.com *.werksraeder24.de data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.werksraeder24.de *.werksraeder24.com *.originelevelgen24.nl 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ secure.novalnet.de customers.barzahlen.de customers-sandbox.barzahlen.de *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.freshchat.com *.facebook.com optimize.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.trustedshops.com *.cloudflare.com *.cloudfront.net *.facebook.com *.google.de *.werksraeder24.de *.bing.com *.clarity.ms *.doubleclick.net *.billiger.de *.ytimage.com *.googleoptimize.com *.google-analytics.com *.googletagmanager.com optimize.google.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ cdn.novalnet.de cdn.barzahlen.de js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.cloudflare.com *.cloudfront.net *.twitter.com *.fontawesome.com *.userlike.com *.amazonaws.com *.trustedshops.com *.facebook.net *.facebook.com *.werksraeder24.de *.freshchat.com *.bing.com *.clarity.ms *.googleoptimize.com optimize.google.com *.googleanalytics.com *.google-analytics.com *.smarketer.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com maxcdn.bootstrapcdn.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.cloudfront.net *.bootstrapcdn.com *.trustedshops.com *.werksraeder24.de *.freshchat.com *.googleoptimize.com optimize.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.cloudfront.net *.facebook.com *.amazonaws.com *.werksraeder24.de *.googlesyndication.com *.doubleclick.net *.bing.com *.clarity.ms *.trustedshops.com *.etrusted.com *.trustbadge.com *.google-analytics.com ws://127.0.0.1:35729/livereload *.googleoptimize.com *.smarketer.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.werksraeder24.de *.werksraeder24.com *.originelevelgen24.nl *.freshchat.com *.freshworksapi.com *.smarketer.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'nonce-d1byY2KW7y1BBsqwwXsNDA==' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' 'sha256-f9ms/4u9WrRYV3p93xXv88VDowcvTVxabxYcmCxoxBE=' https://connect.facebook.net https://accounts.google.com https://www.googletagmanager.com https://cdn.jifo.co https://s.infogram.com https://www.youtube.com https://www.google.com https://www.google.com.au https://www.googleadservices.com https://www.google.co.in https://www.gstatic.com https://securepubads.g.doubleclick.net https://bat.bing.com https://www.clarity.ms https://play.google.com https://can.canstar.com.au https://graph.canstar.com.au https://jnn-pa.googleapis.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://sdk-02.moengage.com https://metrics.hotjar.io https://siteintercept.qualtrics.com https://collector-px58c3a4zy.perimeterx.net https://platform.twitter.com https://syndication.twitter.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://gfonts.jifo.co https://cdn.jifo.co https://themes.jifo.co https://accounts.google.com https://graph.canstar.com.au https://platform.twitter.com; style-src-attr 'self' 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline' https://cns-angular-content-uat-2.freetls.fastly.net https://cns-angular-content-prod-1.freetls.fastly.net https://cns-angular-content-prod-2.freetls.fastly.net; img-src 'self' data: blob: https://graph.canstar.com.au https://snapshots.uat.canstar.com.au https://snapshots.canstar.com.au https://www.youtube.com https://i.ytimg.com https://yt3.ggpht.com https://images.jifo.co https://www.google.com https://www.google.com.au https://www.google.co.in https://www.gstatic.com https://www.googletagmanager.com https://securepubads.g.doubleclick.net https://bat.bing.com https://www.clarity.ms https://play.google.com https://can.canstar.com.au https://graph.canstar.com.au https://jnn-pa.googleapis.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://sdk-02.moengage.com https://fonts.gstatic.com https://themes.jifo.co https://gfonts.jifo.co https://cdn.jifo.co https://www.facebook.com https://connect.facebook.net https://analytics.tiktok.com https://www.canstarblue.com.au https://www.canstar.com.au https://secure.gravatar.com https://ep1.adtrafficquality.google https://adtrafficquality.google; font-src 'self' https://fonts.gstatic.com https://themes.jifo.co https://gfonts.jifo.co https://cdn.jifo.co https://script.hotjar.com; frame-src 'self' https://www.youtube.com https://accounts.google.com https://e.infogram.com https://www.googletagmanager.com http://www.googletagmanager.com https://10445216.fls.doubleclick.net https://10420344.fls.doubleclick.net https://can.canstar.com.au https://can.canstarblue.com.au https://securepubads.g.doubleclick.net https://platform.twitter.com https://syndication.twitter.com https://a25480140109.cdn.optimizely.com; connect-src 'self' https://graph.canstar.com.au https://can.canstar.com.au https://can.canstarblue.com.au https://jnn-pa.googleapis.com https://www.google-analytics.com https://bat.bing.com https://www.clarity.ms https://sdk-02.moengage.com https://connect.facebook.net https://www.facebook.com https://accounts.google.com https://www.googletagmanager.com https://cdn.jifo.co https://s.infogram.com https://www.youtube.com https://www.google.com https://www.google.com.au https://www.googleadservices.com https://www.google.co.in https://www.gstatic.com https://securepubads.g.doubleclick.net https://stats.g.doubleclick.net https://play.google.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://clerk.canstar.com.au https://vital-wasp-63.clerk.accounts.dev https://faithful-gannet-95.clerk.accounts.dev https://clerk-telemetry.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://metrics.hotjar.io https://surveystats.hotjar.io https://siteintercept.qualtrics.com https://collector-px58c3a4zy.perimeterx.net https://ep1.adtrafficquality.google https://adtrafficquality.google https://cns-angular-content-uat-2.freetls.fastly.net https://cns-angular-content-prod-1.freetls.fastly.net https://cns-angular-content-prod-2.freetls.fastly.net; worker-src 'self' blob:; base-uri 'self'; form-action 'self'; report-uri https://graph.canstar.com.au/csp-report; 1 base-uri 'self'; default-src 'self' app.usercentrics.eu api.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu uct.service.usercentrics.eu www.youtube-nocookie.com www.youtube.com region1.analytics.google.com stats.g.doubleclick.net; font-src 'self' maps.gstatic.com fonts.gstatic.com data:; img-src 'self' *.sdk.de app.usercentrics.eu api.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu uct.service.usercentrics.eu privacy-proxy-server.usercentrics.eu i.ytimg.com yt3.ggpht.com www.youtube-nocookie.com maps.googleapis.com www.google.com www.google.de www.googletagmanager.com www.googleadservices.com maps.gstatic.com px.ads.linkedin.com px4.ads.linkedin.com www.facebook.com connect.facebook.net lh3.googleusercontent.com cdn.eye-able.com stats.g.doubleclick.net googleads.g.doubleclick.net data: blob:; script-src 'self' *.sdk.de app.usercentrics.eu api.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu uct.service.usercentrics.eu www.youtube-nocookie.com maps.googleapis.com www.google.com www.googletagmanager.com www.googleadservices.com cdn.eye-able.com snap.licdn.com connect.facebook.net 'unsafe-inline' 'unsafe-eval' 'report-sample'; worker-src * blob: 'report-sample'; script-src-elem 'self' *.sdk.de app.usercentrics.eu api.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu plugins.flockler.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com cdn.eye-able.com snap.licdn.com connect.facebook.net 'unsafe-inline' blob: 'report-sample'; connect-src 'self' *.sdk.de app.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu uct.service.usercentrics.eu aggregator.service.usercentrics.eu www.googlesyndication.com www.googletagmanager.com stats.g.doubleclick.net www.google.de www.facebook.com maps.googleapis.com www.google.com www.googleadservices.com px.ads.linkedin.com cdn.eye-able.com api.flockler.app stats-api.flockler.app region1.analytics.google.com region1.google-analytics.com pagead2.googlesyndication.com analytics.google.com; object-src 'none'; style-src 'self' *.sdk.de www.youtube-nocookie.com www.googletagmanager.com maps.googleapis.com www.google.com www.google.de cdn.eye-able.com 'unsafe-inline' 'report-sample'; frame-src 'self' *.sdk.de app.usercentrics.eu api.usercentrics.eu consent-api.service.consent.usercentrics.eu privacy-proxy.usercentrics.eu uct.service.usercentrics.eu www.youtube-nocookie.com www.youtube.com www.google.com kundenportal.sdk-neva.de www.googletagmanager.com form.virtualq.tech blob:; frame-ancestors 'self' *.sdk.de; media-src 'self' data:; form-action 'self' adfs.sdk.de; manifest-src 'self'; report-uri https://www.sdk.de/@http-reporting?csp=report&requestTime=1765935949414973&requestHash=a9d477644b40bee0dd0a35a26ab5bccc71302096 1 default-src 'self';script-src 'self' 'nonce-2GaWjUhDQsDi7XKOyYHpuA' 'strict-dynamic' 'unsafe-inline' 'unsafe-hashes' 'sha256-84VEGGZ3d0BGWTTS9iD8PjP2hIz1iIUHrU9PK25GvBg=' 'sha256-ImOhpd9lZ7yGbvUIoO7EnTtcP+hRIrzesfIVrZmrCPQ=' 'sha256-+KQ22X773lXs7ERwqSTqkq1coxIpHSpgU3YrmV/EwdQ=' 'sha256-SDANlNAm5lFOdhEO8A2N6qlBW5GqloicdUrRpJTQWfs=' 'sha256-JXGej4mPACbE/fP5kuunldJEyMk62sNjNe85DtAcMoU=' 'sha256-Zo6yt7iHKSKyTZ73PcCwMGGBa64g83rX80b1tFgKnME=' https://*.facebook.net https://*.googlesyndication.com https://*.cookiebot.eu https://*.usercentrics.eu https://*.googletagmanager.com https://*.cookiebot.com https://*.jsdelivr.net https://*.googleadservices.com https://*.doubleclick.net https://*.tiktok.com;script-src-elem 'self' 'nonce-2GaWjUhDQsDi7XKOyYHpuA' 'strict-dynamic' 'unsafe-inline' 'sha256-84VEGGZ3d0BGWTTS9iD8PjP2hIz1iIUHrU9PK25GvBg=' 'sha256-ImOhpd9lZ7yGbvUIoO7EnTtcP+hRIrzesfIVrZmrCPQ=' 'sha256-+KQ22X773lXs7ERwqSTqkq1coxIpHSpgU3YrmV/EwdQ=' 'sha256-SDANlNAm5lFOdhEO8A2N6qlBW5GqloicdUrRpJTQWfs=' 'sha256-JXGej4mPACbE/fP5kuunldJEyMk62sNjNe85DtAcMoU=' 'sha256-Zo6yt7iHKSKyTZ73PcCwMGGBa64g83rX80b1tFgKnME=' https://*.cookiebot.eu https://*.googlesyndication.com https://*.usercentrics.eu https://*.googletagmanager.com https://*.cookiebot.com https://*.jsdelivr.net https://*.tiktok.com https://*.twitter.com https://*.ads-twitter.com https://*.google-analytics.com;style-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.googleapis.com;img-src 'self' blob: data: https://*.ytimg.com https://*.gstatic.com https://*.googleadservices.com https://*.googlesyndication.com https://*.usercentrics.eu https://*.cookiebot.com https://*.googletagmanager.com https://*.facebook.com https://*.doubleclick.net https://*.google.com https://*.google.com.mt https://*.google.pl https://*.google.nl https://*.google.gr https://*.google.ca https://*.facebook.net https://*.twitter.com https://*.google.co.jp https://*.google.com.kh https://*.google.de https://*.google.co.uk https://*.google.ru https://*.google.com.sg https://*.uniperks.pl https://uniperks.pl;connect-src 'self' https://*.posthog.com https://*.googlesyndication.com https://*.cookiebot.eu https://*.google.com https://*.google.pl https://*.cookiebot.com https://*.tiktok.com https://*.tiktokw.us https://*.facebook.com https://*.google-analytics.com https://*.analytics.google.com https://*.googleadservices.com https://*.doubleclick.net https://*.uniperks.pl;frame-src 'self' https://*.youtube.com https://*.googletagmanager.com https://*.cookiebot.eu https://*.cookiebot.com https://*.doubleclick.net https://*.uniperks.pl https://keycloak.localhost.pl/;object-src 'none';frame-ancestors 'self';base-uri 'self';script-src-attr 'unsafe-hashes' 'report-sample' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'sha256-63KPA7slAzdpCGFnEKbG4Hi4byhxXk6q7iUYzHvMEjI=';font-src 'self' data: https://*.googleapis.com https://*.gstatic.com https://*.affilitizer.com;report-uri https://api.uniperks.pl/student/v1/reporting/report-uri;form-action 'self';upgrade-insecure-requests 1 default-src 'self' https://*.amf.se;connect-src 'self' https://*.amf.se https://amf.piwik.pro https://*.ace.teliacompany.com https://*.ace.teliacompany.net;form-action 'self' https://*.amf.se https://*.minpension.se;frame-src 'self' https://*.amf.se https://amf.fondlista.se https://dreambroker.com https://*.infogram.com https://infogram.com https://*.jobylon.com https://*.ace.teliacompany.com https://*.ace.teliacompany.net https://*.youtube-nocookie.com;img-src 'self' data: https://*.amf.se https://amf.piwik.pro https://*.ace.teliacompany.com https://*.ace.teliacompany.net https://*.ytimg.com;media-src 'self' https://*.amf.se https://*.ace.teliacompany.com https://*.ace.teliacompany.net;script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://amf.piwik.pro https://*.infogram.com https://infogram.com https://*.ace.teliacompany.com https://*.ace.teliacompany.net https://*.youtube.com;style-src 'self' data: 'unsafe-inline' https://*.ace.teliacompany.com https://*.ace.teliacompany.net;report-uri /_csp_uri;report-to csp; 1 default-src 'self' media1.jpc.de lesen.de; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; script-src 'self' media1.jpc.de lesen.de 'nonce-FHazFgjAeoen7MytZ3sbT1sgHwwlNzsKg4Xl1xqdMFeflYKqRF4JcZ2Ey7O4CGqsclAtJ1GmqUqfL8/5xPLjbg==' 'report-sample'; style-src 'self' media1.jpc.de lesen.de 'report-sample' 'unsafe-inline'; font-src 'self' media1.jpc.de lesen.de; img-src 'self' media1.jpc.de lesen.de data:; connect-src 'self' media1.jpc.de lesen.de https://use.jpc.de; report-uri /csp/; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.bootstrapcdn.com data: *.3dcloud.io *.fontawesome.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cloudinary.com *.facebook.com *.cybersource.com *.bazaarvoice.com *.salsify.com *.3dcloud.io *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.affirm.com *.affirm.ca *.certcapture.com cloudinary.com res.cloudinary.com *.pinterest.com *.facebook.com *.doubleclick.net *.cybersource.com *.trkn.us *.paypal.com *.bazaarvoice.com *.google.com *.salsify.com *.hotjar.com *.hon.com *.3dcloud.io *.kmail-lists.com/ *.braintreegateway.com *.kaptcha.com *.addtoany.com *.paystand.com *.paystand.co *.google.com/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.hon.com *.allsteeloffice.com *.honbasyx.com honbasyx.com cloudinary.com res.cloudinary.com *.addtoany.com *.bing.com *.facebook.com *.pinterest.com *.google.com *.google.co.in *.cybersource.com *.bazaarvoice.com *.salsify.com meetanshi.com *.3dcloud.io *.paypal.com https://www.magezon.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com cloudinary.com *.addtoany.com *.bootstrapcdn.com *.googletagmanager.com *.doubleclick.net *.trkn.us *.pinimg.com *.facebook.net *.bing.com *.pinterest.com *.cybersource.com *.online-metrix.net *.hotjar.com *.hotjar.io *.google.com *.google.co.in *.google.in *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.vimeo.com *.cdn-scripts.com *.braintreegateway.com *.signifyd.com *.bazaarvoice.com *.salsify.com bam.nr-data.net *.crazyegg.com mczbf.com *.mczbf.com *.3dcloud.io *.chimpstatic.com *.paypal.com *.paystand.com *.paystand.co widget.freshworks.com m2epro.freshdesk.com *.google.com/ *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com downloads.mailchimp.com cloudinary.com *.addtoany.com *.googleapis.com *.bootstrapcdn.com *.cybersource.com *.bazaarvoice.com *.salsify.com *.3dcloud.io *.fontawesome.com *.datatables.net *.typekit.net *.paystand.com *.paystand.co widget.freshworks.com m2epro.freshdesk.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.hon.com *.allsteeloffice.com *.honbasyx.com honbasyx.com cloudinary.com res.cloudinary.com *.cybersource.com *.bazaarvoice.com *.salsify.com data: *.3dcloud.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com *.addtoany.com *.facebook.com *.cybersource.com *.pinterest.com *.salsify.com *.google-analytics.com bam.nr-data.net *.hotjar.com *.hotjar.io *.crazyegg.com *.doubleclick.net mczbf.com *.mczbf.com sjwoe.com *.sjwoe.com *.3dcloud.io *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com *.addthis.com *.pinterest.com *.weltpixel.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.facebook.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io *.googletagmanager.com *.google-analytics.com *.facebook.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.googleapis.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.google-analytics.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 secure-frame-src *.idtheftscanner.f-secure.com; font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.idtheftscanner.f-secure.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.cloudfront.net https://electric-house.com https://static.addtoany.com https://www.google-analytics.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.idtheftscanner.f-secure.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.idtheftscanner.f-secure.com landofcoder.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cookiefirst.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.idtheftscanner.f-secure.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.idtheftscanner.f-secure.com *.cookiefirst.com landofcoder.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https: http: *.tiktok.com; connect-src 'self' https: http: *.tiktok.com 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.co.il https://www.myheritage.co.il 'unsafe-eval' 'nonce-c615d159826f75775d769b3837fe0766' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.co.il;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.transbank.cl https://webpay3gint.transbank.cl/webpayserver/initTransaction https://webpay3g.transbank.cl/webpayserver/initTransaction 'self' 'unsafe-inline'; frame-ancestors *.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.weltpixel.com *.doubleclick.net *.basis.net https://webpay3gint.transbank.cl https://webpay3g.transbank.cl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.google.co.in *.basis.net *.hsforms.net *.hsforms.com 'self' data: *.transbank.cl https://webpay3gint.transbank.cl/webpayserver/initTransaction https://webpay3g.transbank.cl/webpayserver/initTransaction https://www.novasalud.cl/ https://www.facebook.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com ajax.googleapis.com *.googletagmanager.com *.googleapis.com *.bing.com *.facebook.net unsafe-inline *.hsforms.net *.hsforms.com *.gstatic.com *.transbank.cl https://webpay3gint.transbank.cl/webpayserver/initTransaction https://webpay3g.transbank.cl/webpayserver/initTransaction https://www.novasalud.cl/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.transbank.cl https://webpay3gint.transbank.cl/webpayserver/initTransaction https://webpay3g.transbank.cl/webpayserver/initTransaction unsafe-inline https://www.novasalud.cl/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://www.novasalud.cl/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.transbank.cl https://webpay3gint.transbank.cl/webpayserver/initTransaction https://webpay3g.transbank.cl/webpayserver/initTransaction https://www.novasalud.cl/ https://stats.g.doubleclick.net/ 'self' 'unsafe-inline'; child-src https://www.novasalud.cl/ http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com https://www.novasalud.cl/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.novasalud.cl/ 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://client.crisp.chat data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://image.crisp.chat www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com cdn.ampproject.org raw.githubusercontent.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://client.crisp.chat js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://client.crisp.chat assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com cdn.ampproject.org https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.facebook.net *.facebook.com *.cloudflare.com *.gstatic.com *.crisp.chat *.tawk.to *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.net *.facebook.com *.twitter.com https://seo.mageplaza.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.bka.sh *.bkash.com *.facebook.net *.facebook.com *.addtoany.com optimize.google.com *.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bdtronics.com *.facebook.net *.facebook.com *.amazonaws.com *.cloudfront.net *.crisp.chat *.tawk.to tawk.link *.jsdelivr.net *.googletagmanager.com *.google.com.bd *.google.com *.inspectlet.com *.shofity.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.bka.sh *.facebook.net *.facebook.com https://cdn.jsdelivr.net *.onebark.org *.addtoany.com *.smartlook.com *.inspectlet.com *.sentry-cdn.com *.googletagmanager.com *.datadome.co *.crisp.chat *.tawk.to *.doubleclick.net *.klaviyo.com *.openreplay.com *.hs-scripts.com *.hs-analytics.net *.hs-banner.com *.usemessages.com *.hscollectedforms.net *.clare.ai cdnjs.cloudflare.com https://maps.googleapis.com https://player.vimeo.com unpkg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.facebook.net *.facebook.com *.cloudflare.com *.googleapis.com *.crisp.chat *.tawk.to unpkg.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.facebook.net *.facebook.com *.googleapis.com *.google.com *.smartlook.cloud *.inspectlet.com wss://ws.inspectlet.com *.sentry.io *.datadome.co wss://client.relay.crisp.chat *.crisp.chat *.tawk.to wss://*.tawk.to *.diligent-infotech.com insights.algolia.io *.doubleclick.net https://maps.googleapis.com https://player.vimeo.com *.bdtronics.com:8108 *.bdtronics.com:2053 https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.stripe.com www.googletagmanager.com td.doubleclick.net *.trbo.com app.usercentrics.eu *.cloudflarestream.com accounts.google.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com cdn.newsha.com productimages.newsha.com productimages.newsha.de www.google.de perf-eu1.hsforms.com app.usercentrics.eu uct.service.usercentrics.eu track-eu1.hubspot.com widgets.trustedshops.com maps.gstatic.com collect.trbo.com maps.google.com maps.googleapis.com https://meetanshi.com/media/logo.png magefan.com cm.magefan.com *.facebook.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net https://www.mollie.com https://prf.hn https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com js.stripe.com app.usercentrics.eu pzapi-nb.com widgets.trustedshops.com js-eu1.hs-scripts.com analytics.tiktok.com js-eu1.hs-analytics.net js-eu1.hubspot.com js-eu1.hsadspixel.net js-eu1.hs-banner.com maps.google.com api-v4.trbo.com www.clarity.ms t.clarity.ms static.trbo.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io accounts.google.com *.gstatic.com maps.googleapis.com js.mollie.com https://prf.hn https://pzapi-nb.com https://pzapi-kg.com https://pzapi-ij.com/ https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net accounts.google.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com region1.google-analytics.com region1.analytics.google.com api.usercentrics.eu cta-eu1.hubspot.com api-eu1.hubapi.com maps.googleapis.com www.clarity.ms t.clarity.ms analytics.tiktok.com *.google-analytics.com https://get.geojs.io *.avada.io accounts.google.com www.gstatic.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: www.gstatic.com https://challenges.cloudflare.com 'nonce-V2u+9rp8eXyTNfg/0Yt/NQ=='; style-src 'self' https:; report-uri https://craftcourses.report-uri.com/r/d/csp/enforce 1 font-src https://www.gstatic.com https://fonts.gstatic.com fonts.gstatic.com fonts.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: https://code.tidio.co/widget-v4/fonts/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cloudfront.s-a-g.fr/ https://www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.googletagmanager.com/ https://www.societe-des-avis-garantis.fr/wp-content/plugins/ag-core/widgets/iframe/2/h/ https://r.adserver01.de/r/797151516356679.html https://td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.google.fr https://ad3.adserver01.de/www/delivery/fc.php https://action.metaffiliation.com http://www.googleadservices.com http://www.google-analytics.com http://www.google.com https://ad3.adserver01.de https://v2assets.zopim.io https://axeptio.imgix.net https://cloudfront.s-a-g.fr/static/product-widget/img/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cloudfront.s-a-g.fr/ *.google.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io maps.googleapis.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://lqb.leroidelafenetre.fr https://static.axept.io https://static.zdassets.com https://profiling.socialperf.com https://r.adserver01.de https://tag.beyable.com https://tag.beyable.com/api/beYableJSv2.js https://soc.socialperf.com/profiling/perform.php https://front.activation.beyable.com/api/v2/displays https://assets.adobedtm.com https://www.googleadservices.com/ https://www.google-analytics.com https://googleads.g.doubleclick.net/ https://analytics.google.com https://www.googletagmanager.com http://www.googleadservices.com http://www.googletagmanager.com https://www.google.com https://soc.socialperf.com https://code.tidio.co https://widget-v4.tidiochat.com https://embed.tawk.to 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com http://www.googleapis.com https://cloudfront.s-a-g.fr/static/product-widget/css/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://static.zdassets.com https://widget-v4.tidiochat.com https://code.tidio.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://api.axept.io https://leroidelafenetre.zendesk.com https://lqb.leroidelafenetre.fr https://region1.analytics.google.com https://widget-mediator.zopim.com https://www.google.com https://ekr.zdassets.com https://googleads.g.doubleclick.net https://client.axept.io https://widget-mediator.zopim.com/s/W/ws/W05234pNQ9BT-RBK/c/1712579529421 https://widget-mediator.zopim.com/s/W/ws/FSus75S4Yg5FU2AJ/c/1712579533925 https://www.google-analytics.com https://www.googleadservices.com https://analytics.google.com https://www.googletagmanager.com http://www.googletagmanager.com http://www.google-analytics.com http://www.googleadservices.com wss://widget-mediator.zopim.com wss://socket.tidio.co https://va.tawk.to https://cloudfront.s-a-g.fr/dynamic/10007/productWidget/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://leroidelafenetre-fr.report.centralcsp.com/; report-to report-endpoint; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.trustpilot.com *.demdex.net *.clarity.ms *.nr-data.net *.bing.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com *.nr-data.net *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com *.twitter.com *.addthis.com *.trustpilot.com *.google.com *.doubleclick.net *.paypal.com *.braintreegateway.com *.consentmanager.net *.googletagmanager.com *.aptrinsic.com *.demdex.net *.clarity.ms *.nr-data.net *.bing.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.trustpilot.com *.cloudfront.net *.consensu.org *.consentmanager.net *.google.com *.google.co.in *.gstatic.com *.aptrinsic.com *.demdex.net *.everesttech.net *.clarity.ms *.adobedtm.com *.magentocommerce.com *.nr-data.net *.bing.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addthis.com *.moatads.com *.addthisedge.com *.newrelic.com *.nr-data.net *.omtrdc.net *.trustpilot.com *.luckyorange.com *.consensu.org *.consentmanager.net *.doubleclick.net *.paypal.com *.aptrinsic.com *.demdex.net *.clarity.ms *.bing.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.omtrdc.net *.trustpilot.com *.consensu.org *.aptrinsic.com *.demdex.net *.clarity.ms *.nr-data.net *.bing.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.addthis.com *.nr-data.net *.trustpilot.com *.sc.omtrdc.net *.luckyorange.com *.braintree-api.com *.braintreegateway.com *.aptrinsic.com *.demdex.net *.clarity.ms *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' *;frame-src 'self' *;img-src 'self' * data:;connect-src 'self' *;style-src 'self' 'unsafe-inline' *;object-src 'none';upgrade-insecure-requests;base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';script-src-attr 'none' 1 default-src 'self' *.veone.io *.googleapis.com *.gstatic.com; img-src 'self' data: blob: *.veone.io; style-src 'self' *.googleapis.com *.gstatic.com 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.veone.io; connect-src 'self' blob: *.veone.io; 1 default-src 'self' loccioni.com *.loccioni.com; img-src * data:; frame-src *.youtube.com *.loccioni.com *.loccioni.com:9300 serviceloccioni.b2clogin.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com; script-src 'self' loccioni.com *.loccioni.com 'unsafe-eval' 'nonce-ZvVn_4uTdJNbTTGSIgW7yAAAAJs' 'nonce-aUImPFr35Zs5aQFgufdUDwAAAAQ'; script-src-elem 'self' loccioni.com *.loccioni.com cdn-cookieyes.com *.googletagmanager.com *.google-analytics.com *.googleapis.com 'unsafe-inline' 'nonce-ZvVn_4uTdJNbTTGSIgW7yAAAAJs' 'nonce-aUImPFr35Zs5aQFgufdUDwAAAAQ'; connect-src 'self' wss: loccioni.com *.loccioni.com cdn-cookieyes.com *.cookieyes.com *.google-analytics.com analytics.google.com *.analytics.google.com stats.g.doubleclick.net *.google.it *.googleapis.com serviceloccioni.b2clogin.com; report-uri https://sentry.loccioni.com//api/33/security/?sentry_key=c407f8937e802b8c2db6b48b4b6346c4; report-to csp-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.inpost.pl *.fontawesome.com https://fonts.bunny.net https://geowidget.easypack24.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com *.inpost.pl landofcoder.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com *.inpost.pl magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com *.inpost.pl landofcoder.com *.disqus.com *.avada.io *.shopify.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org maps.googleapis.com www.gstatic.com connect.facebook.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.inpost.pl *.fontawesome.com https://fonts.bunny.net https://geowidget.easypack24.net https://geowidget.inpost.pl www.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com *.inpost.pl https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com *.inpost.pl landofcoder.com https://get.geojs.io *.avada.io *.easypack24.net *.openstreetmap.org places.googleapis.com www.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com/ *.bootstrapcdn.com/ https://analytics.google.com/ https://www.googletagmanager.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com/ *.gstatic.com/ https://analytics.google.com/ https://www.googletagmanager.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://maps.gstatic.com/ *.googleapis.com/ *.w3.org/ https://analytics.google.com/ *.cdn.place1seo.com/ https://cdn.beedash.com/ https://www.google.com/ https://www.googletagmanager.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.googleapis.com/ https://analytics.google.com/ https://googleads.g.doubleclick.net/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com/ https://analytics.google.com/ *.bootstrapcdn.com/ https://www.googletagmanager.com/ unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io https://analytics.google.com/ https://googleads.g.doubleclick.net/ https://stats.g.doubleclick.net/ https://www.googletagmanager.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; img-src 'self' data: blob: https:; media-src 'self' https: blob: data:; font-src 'self' https://fonts.gstatic.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.elfsight.com https://*.elfsightcdn.com; script-src 'self' https://*.elfsight.com https://*.elfsightcdn.com https://embed.bsky.app https://www.googletagmanager.com https://www.google-analytics.com https://ajax.googleapis.com; connect-src 'self' https://*.elfsight.com https://*.elfsightcdn.com https://www.google-analytics.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://embed.bsky.app https://api.bsky.app https://*.bsky.app https://bsky.social; frame-src 'self' https://*.elfsight.com https://*.elfsightcdn.com https://embed.bsky.app https://www.youtube.com https://player.vimeo.com; 1 font-src *.gstatic.com data: *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.versapay.com *.paynup.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com *.versapay.com *.paynup.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com cld.bz *.versapay.com *.twitter.com *.paynup.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com pages.cld.bz d1lx47257n5xt.cloudfront.net *.versapay.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.paynup.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cld.bz *.versapay.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.paynup.com *.datadoghq.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.versapay.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.paynup.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/magento_os/; report-to report-endpoint; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://translate.googleapis.com https://www.gstatic.com/_/translate_http/ https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/dist/css/bootstrap.min.css; connect-src 'self' ws://localhost:3000 https://shop-api.kfm-motorraeder.de https://webhook.kfm-motorraeder.de https://translate.googleapis.com https://shops-si.trustedshops.com https://api.trustedshops.com https://widgets.trustedshops.com https://trustbadge.api.etrusted.com https://api.trustbadge.etrusted.com https://payments-eu.amazon.com https://payments.amazon.de https://*.kaspersky-labs.com wss://*.kaspersky-labs.com; script-src 'self' 'self' 'unsafe-inline' 'unsafe-eval' https://widgets.trustedshops.com https://static-eu.payments-amazon.com; img-src 'self' data: https://www.kfm-motorraeder.de https://img.kfm-motorraeder.de https://widgets.trustedshops.com https://translate.google.com https://translate.googleapis.com https://fonts.gstatic.com/s/i/ https://www.gstatic.com/images/ https://yastatic.net https://m.media-amazon.com/images/ https://static-eu.payments-amazon.com/assets/; font-src 'self' data: https://fonts.gstatic.com https://github.com/google/fonts/; object-src 'none'; report-uri https://webhook.kfm-motorraeder.de/csp 1 font-src *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.iubenda.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.iubenda.com *.alothemes.com *.magepow.com https://www.mollie.com maps.gstatic.com maps.google.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.iubenda.com s7.addthis.com *.alothemes.com *.magepow.com js.mollie.com *.googleapis.com maps.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.iubenda.com ekr.zdassets.com/ *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; manifest-src 'self' *.airwaysim.com *.airlinemanagementsim.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.airwaysim.com *.airlinemanagementsim.com js.braintreegateway.com assets.braintreegateway.com www.paypalobjects.com *.paypal.com pay.google.com songbird.cardinalcommerce.com static.client.cardinaltrusted.com *.cdn-apple.com www.google.com www.gstatic.com connect.facebook.net www.googletagmanager.com *.doubleclick.net; style-src 'self' data: blob: 'unsafe-inline' *.airwaysim.com *.airlinemanagementsim.com assets.braintreegateway.com cdnjs.cloudflare.com fonts.googleapis.com; font-src 'self' data: cdnjs.cloudflare.com fonts.gstatic.com; connect-src 'self' data: https: stats.airwaysim.com api.braintreegateway.com client-analytics.braintreegateway.com *.braintree-api.com *.paypal.com pay.google.com *.cardinalcommerce.com *.cardinaltrusted.com www.google.com google.com www.gstatic.com www.facebook.com; frame-src 'self' https: assets.braintreegateway.com *.paypal.com www.google.com recaptcha.google.com www.facebook.com; form-action 'self' https:; img-src * data: blob:; object-src 'none'; report-uri /errors/cspreport 1 font-src cash-f.squarecdn.com https://cdn.riverty.design/ *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * uc8.tv *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * uc8.tv https://documents.riverty.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com *.addthis.com js.mollie.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.klarnaservices.com *.hotjar.com *.googlesyndication.com *.doubleclick.net *.cookiebot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://cdn.clerk.io imgsct.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.facebook.com https://www.mollie.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.cloudflare.com *.clerk.io *.slimminglabs.com *.klarnaservices.com *.bralex.nl *.doubleclick.net *.bing.com *.hotjar.com *.google.com *.google.ch *.google.de *.google.dk *.google.es *.google.fi *.google.fr *.google.co.uk *.google.ie *.google.it *.google.nl *.google.no *.google.pl *.google.pt *.google.se *.google.ad *.google.cz *.google.gr *.google.hr *.google.sk *.google.com.tr *.google.be *.google.com.co *.google.hu *.google.lu *.google.at *.google.si *.google.ro *.cookiebot.com *.billink.nl *.gyazo.com whm.asip.cloud paywithmybank.com blob: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ https://maps.googleapis.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://api.clerk.io https://cdn.clerk.io consent.cookiebot.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net *.klarnaservices.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.googletagmanager.com *.facebook.net js.mollie.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.cloudflare.com *.clerk.io *.bralex.nl *.doubleclick.net *.bing.com *.googleoptimize.com *.hotjar.com *.fontawesome.com *.newrelic.com *.cookiebot.com *.mida.so whm.asip.cloud *.profitmetrics.io *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com https://static.klaviyo.com *.klarnacdn.net https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.hotjar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.google-analytics.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.klarnauserservices.com *.doubleclick.net *.hotjar.io *.hotjar.com wss://*.hotjar.com *.bing.com *.bing.net *.google.ch *.google.de *.google.dk *.google.es *.google.fi *.google.fr *.google.co.uk *.google.ie *.google.it *.google.nl *.google.no *.google.pl *.google.pt *.google.se *.google.ad *.google.cz *.google.gr *.google.hr *.google.sk *.google.com.tr *.google.be *.google.com.co *.google.hu *.google.lu *.google.at *.google.si *.google.ro *.googlesyndication.com *.nr-data.net *.mida.so *.cookiebot.com whm.asip.cloud 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.slimminglabs.com/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net data: blob: *.americanframe.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.filestackapi.com https://acsbapp.com *.acsbapp.com *.acsbap.com acsbap.com acsbapp.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com data: blob: *.americanframe.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.braintree-api.com *.braintreegateway.com *.hubspot.com *.hsforms.net *.hsforms.com *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ data: blob: *.americanframe.com *.googletagmanager.com *.paypal.com *.paypalobjects.com *.cybersource.com *.braintree-api.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.google.com *.googlesyndication.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.doubleclick.net *.hubspot.com *.kaptcha.com *.accessibe.com *.hsforms.com *.hsforms.net outlook.office365.com *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com *.certcapture.com https://acsbapp.com *.acsbapp.com *.acsbap.com acsbap.com acsbapp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net blob: *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.s3.amazonaws.com s3.amazonaws.com *.paypal.com *.paypalobjects.com *.braintree-api.com *.braintreegateway.com *.magentocommerce.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.gstatic.com *.google.com *.google.de *.google.es *.google.fr *.google.gr *.google.ie *.google.it *.google.jo *.google.ik *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.se *.google.sk *.google.com.ar *.google.com.au *.google.com.br *.google.com.ec *.google.com.eg *.google.com.gh *.google.com.my *.google.com.ng *.google.com.pk *.google.com.pr *.google.com.sa *.google.com.sg *.google.com.tw *.google.com.ua *.google.com.vn *.google.ae *.google.ca *.google.cn *.google.co.in *.google.co.il *.google.co.kr *.google.co.nz *.google.co.th *.google.co.uk *.google.co.za *.google.co.ma *.googleusercontent.com *.doubleclick.net *.hsforms.com *.hsforms.net *.hubspot.com *.adelixir.com *.bing.com *.acsbapp.com www.facebook.com *.certcapture.com *.nr-data.net *.clarity.ms meetanshi.com *.hubspotusercontent-na1.net *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com https://fonts.googleapis.com https://*.filestackapi.com https://cdn.filestackcontent.com *.acsbap.com acsbap.com acsbapp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com data: blob: *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.paypal.com *.paypalobjects.com *.google.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.hotjar.io *.hotjar.com *.doubleclick.net *.cybersource.com *.hs-scripts.com *.hsforms.com *.hsforms.net *.hscollectedforms.net *.hs-banner.com *.hs-analytics.net *.hsadspixel.net *.bing.com *.adelixir.com *.braintree-api.com *.braintreegateway.com *.usemessages.com *.facebook.net *.certcapture.com *.hsleadflows.net *.polyfill.io *.clarity.ms *.hubspot.com *.aptrinsic.com *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com https://*.filestackapi.com https://acsbapp.com *.acsbapp.com *.acsbap.com acsbap.com acsbapp.com https://www.googletagmanager.com tagmanager.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com data: blob: *.getfirebug.com *.myfonts.net *.googleapis.com *.certcapture.com *.hubspot.com *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com https://*.filestackapi.com https://fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com data: blob: 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io data: blob: *.magento.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.s3.amazonaws.com *.google-analytics.com *.googleadservices.com *.google.com *.doubleclick.net *.hubspot.com *.acsbapp.com *.braintree-api.com *.braintreegateway.com *.bing.com *.paypal.com *.certcapture.com *.facebook.net *.hsforms.com *.hubapi.com *.clarity.ms *.demdex.net *.hscollectedforms.net *.hotjar.io *.hotjar.com *.ws.hotjar.com wss://ws.hotjar.com *.gorgias.chat *.gorgias.help *.gorgias.io *.klaviyo.com https://fonts.googleapis.com https://filestack-uploads-persist-production.s3.amazonaws.com https://cdn.filestackcontent.com https://*.filestackapi.com https://cdn.acsbapp.com *.acsbap.com acsbap.com acsbapp.com https://www.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src data: blob: *.americanframe.com *.cybersource.com *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com *.americanframe.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://humanelement.report-uri.com/r/d/csp/enforce; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' *.pepperjam.com https://www.googletagmanager.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.doubleclick.net *.facebook.com 'self' *.pepperjam.com https://www.googletagmanager.com/ webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bing.com *.google.com.ph *.google.com.sg *.google.com.au *.google.com.ca https://static-na.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.bg https://www.googletagmanager.com/ *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' *.pepperjam.com *.upscope.io *.freshchat.com *.xsellco.com *.bing.com *.hotjar.com *.cloudfront.net *.shop.pe https://shop.pe *.clarity.ms *.s3.amazonaws.com *.dnky.co *.dotdigital.com https://api.comapi.com *.zoovu.com 'self' 'unsafe-inline' *.googleapis.com https://polyfill.io webchat.dotdigital.com webchat.staging.dotdigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.freshchat.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.facebook.com *.facebook.net *.doubleclick.net wss://*.hotjar.com *.hotjar.io *.clarity.ms *.shop.pe wss://*.upscope.io *.xsellco.com *.comapi.com *.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.luckyorange.com *.visualwebsiteoptimizer.com *.googletagmanager.com *.google.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://images.unsplash.com https://*.gstatic.com *.adyen.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com dev.visualwebsiteoptimizer.com *.luckyorange.com *.googletagmanager.com *.google-analytics.com *.ksearchnet.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.feedoptimise.com cdn.feedoptimise.com *.klevu.com magefan.com cm.magefan.com *.mageside.com mageside.com https://www.magezon.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gtm.bamford.com *.googletagmanager.com *.google-analytics.com dev.visualwebsiteoptimizer.com tools.luckyorange.com loader.usehero.com cdn.usehero.com *.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.feedoptimise.com cdn.feedoptimise.com *.klevu.com *.ksearchnet.com *.google.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com tagmanager.google.com https://js.klevu.com https://www.bamford.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ tools.luckyorange.com dev.visualwebsiteoptimizer.com *.ksearchnet.com tagmanager.google.com *.adyen.com https://static.klaviyo.com *.klevu.com assets.braintreegateway.com fonts.google.com https://statsjs.klevu.com https://js.klevu.com https://www.bamford.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://maps.googleapis.com https://player.vimeo.com *.adyen.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googletagmanager.com *.google-analytics.com *.luckyorange.com dev.visualwebsiteoptimizer.com api.usehero.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.reviews.io maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de videos.sproutvideo.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.reviews.io *.sproutvideo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dwin1.com https://chimpstatic.com *.reviews.io *.sproutvideo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.reviews.io *.sproutvideo.com cdn.dnky.co webchat.dotdigital.com maxcdn.bootstrapcdn.com unsafe-inline tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com cdn.ampproject.org *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.reviews.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.reviews.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.acmewhistles.co.uk *.salesfire.co.uk *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://www.magezon.com *.commoninja.com *.acmewhistles.co.uk *.google.co.uk *.ytimg.com *.ggpht.com *.stripe.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.commoninja.com *.acmewhistles.co.uk sos-de-fra-1.exo.io *.salesfire.co.uk *.feefo.com *.g.doubleclick.net *.stripe.com *.sagepay.com *.opayo.eu.elavon.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.acmewhistles.co.uk *.salesfire.co.uk *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.commoninja.com *.feefo.com *.acmewhistles.co.uk *.analytics.google.com *.googleapis.com *.googlevideo.com *.smartmetrics.co.uk *.salesfire.co.uk *.stripe.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.acmewhistles.co.uk *.smartmetrics.co.uk *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.googleapis.com data: *.formstack.com hscoilusa.com *.hscoilusa.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com *.geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com *.modinjapan.com cdn-btsg.com/ *.cdn-btsg.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.payfabric.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.affirm.com *.affirm.ca *.certcapture.com *.formstack.com *.paypalobjects.com paypalobjects.com *.payfabric.com *.kaptcha.com kaptcha.com *.geniustoolsusa.com *.modinjapan.com affirm.com hscoilusa.com *.hscoilusa.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com cdn-btsg.com/ *.cdn-btsg.com trustpilot.com/ *.trustpilot.com https://www.googletagmanager.com/ https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.affirm.com *.affirm.ca *.certcapture.com *.cloudflare.com *.google.com *.elfsightcdn.com *.facebook.com facebook.com *.geniustoolsusa.com gstatic.com *.googleapis.com googleapis.com paypal.com affirm.com hscoilusa.com *.hscoilusa.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com *.modinjapan.com cdn-btsg.com/ *.cdn-btsg.com userway.org/ *.userway.org https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.payfabric.com maps.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.certcapture.com *.cloudflare.com *.twitter.com *.fontawesome.com unpkg.com *.trustpilot.com *.elfsight.com *.gstatic.com gstatic.com *.googleapis.com googleapis.com *.facebook.net facebook.net *.payfabric.com *.jsdelivr.net *.formstack.com ipinfo.io affirm.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com *.geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com *.modinjapan.com hscoilusa.com *.hscoilusa.com cdn-btsg.com/ *.cdn-btsg.com userway.org/ *.userway.org widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com maps.googleapis.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com unpkg.com *.googleapis.com data: *.jsdelivr.net *.formstack.com hscoilusa.com *.hscoilusa.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com *.geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com *.modinjapan.com cdn-btsg.com/ *.cdn-btsg.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.affirm.com *.affirm.ca *.certcapture.com *.cloudflare.com *.elfsight.com *.google-analytics.com *.doubleclick.net *.payfabric.com googleapis.com *.googleapis.com affirm.com hscoilusa.com *.hscoilusa.com stackpathcdn.com *.stackpathcdn.com geniustoolsusa.com *.geniustoolsusa.com duratiredirect.com *.duratiredirect.com otrprodirect.com *.otrprodirect.com modinjapan.com *.modinjapan.com cdn-btsg.com/ *.cdn-btsg.com userway.org/ *.userway.org widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com www.apptrian.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com *.fontawesome.com *.addtoany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com www.apptrian.com http://dpm.demdex.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://n5mcn64l2tp5piztj1c2b0wj.httpschecker.net/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.monetico-services.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.monetico-services.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.gstatic.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com *.monetico-services.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.mercadolibre.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.affirm.com *.affirm.ca magento-cloudflare.jetrails.com www.youtube.com *.twitter.com *.authorize.net *.cardinalcommerce.com *.mercadolibre.com *.facebook.com *.doubleclick.net *.soundcloud.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.affirm.com *.affirm.ca *.bird.eu *.ytimg.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.mercadopago.com *.mercadolibre.com *.mercadolibre.com.mx *.mercadolibre.com.br *.mercadolibre.com.ar *.paypalobject.com *.mercadolivre.com.br *.mlstatic.com *.olark.com *.newrelic.com *.nr-data.net *.googletagmanager.com *.bing.com *.facebook.net *.ads-twitter.com *.yimg.com *.alexametrics.com *.optimonk.com *.inspectlet.com *.doubleclick.net *.facebook.com maps.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.mlstatic.com https://maps.googleapis.com *.olark.com *.newrelic.com *.nr-data.net *.paypal.com *.googletagmanager.com *.bing.com *.facebook.net *.ads-twitter.com *.yimg.com *.alexametrics.com *.optimonk.com *.inspectlet.com *.doubleclick.net *.hotjar.com *.gorgias.chat *.soundcloud.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com *.newrelic.com *.nr-data.net *.paypal.com *.google-analytics.com *.googletagmanager.com *.bing.com *.facebook.net *.ads-twitter.com *.yimg.com *.alexametrics.com *.optimonk.com *.inspectlet.com *.doubleclick.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.affirm.com *.affirm.ca *.cloudflare.com *.twitter.com *.twimg.com *.cardinalcommerce.com *.mercadopago.com https://maps.googleapis.com *.olark.com *.newrelic.com *.nr-data.net *.google-analytics.com *.googletagmanager.com *.bing.com *.facebook.net *.ads-twitter.com *.yimg.com *.alexametrics.com *.optimonk.com *.inspectlet.com *.doubleclick.net *.gorgias.chat analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src https://www.sakestore.nl https://dev.sakestore.nl blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.riverty.design/ 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net https://www.sakestore.nl https://use.typekit.net https://fonts.googleapis.com https://fonts.gstatic.com https://script.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com uc8.tv *.facebook.com *.googlesyndication.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com uc8.tv https://documents.riverty.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.sakestore.nl https://vars.hotjar.com https://nl.pinterest.com https://www.pinterest.com https://ct.pinterest.com https://www.youtube.com https://documents.riverty.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.faslet.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.sakestore.nl https://www.google.com https://www.google.nl https://www.googletagmanager.com https://script.hotjar.com https://ct.pinterest.com https://dev.visualwebsiteoptimizer.com https://cdn.myafterpay.com https://log.pinterest.com https://www.facebook.com https://scontent-ams4-1.cdninstagram.com https://scontent-amt2-1.cdninstagram.com https://img.sct.eu1.usercentrics.eu https://c.bing.com *.clarity.ms maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ https://maps.googleapis.com https://player.vimeo.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.faslet.net *.disqus.com https://cdn.jsdelivr.net *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.sakestore.nl https://www.googletagmanager.com https://static.hotjar.com http://static.hotjar.com https://script.hotjar.com https://s.pinimg.com https://dev.visualwebsiteoptimizer.com https://www.smartsuppchat.com https://rec.smartlook.com https://widget-v2.smartsuppcdn.com https://widget-v3.smartsuppcdn.com https://js-agent.newrelic.com https://bam.eu01.nr-data.net https://assets.pinterest.com https://chimpstatic.com https://connect.facebook.net https://cdn.matomo.cloud https://sakestore.matomo.cloud https://consentcdn.cookiebot.eu https://ct.pinterest.com *.clarity.ms https://matomojs.trackify.info http://172.17.0.2:15729 http://172.17.0.2:35729 http://127.0.0.1:35729 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.multisafepay.com assets.braintreegateway.com https://www.sakestore.nl https://use.typekit.net https://p.typekit.net https://fonts.googleapis.com https://widget-v3.smartsuppcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://stats.g.doubleclick.net *.googlesyndication.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.faslet.net https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.sakestore.nl https://www.google-analytics.com https://in.hotjar.com https://surveystats.hotjar.com https://surveystats.hotjar.io https://ct.pinterest.com https://bootstrap.smartsuppchat.com https://translations.smartsuppcdn.com https://widget-v2.smartsuppcdn.com https://widget-v3.smartsuppcdn.com wss://websocket-visitors.smartsupp.com https://websocket-visitors.smartsupp.com smartsupp.com *.smartsupp.com https://manager.smartlook.com https://web-writer.eu.smartlook.cloud https://bam.eu01.nr-data.net https://analytics.google.com https://graph.instagram.com https://sakestore.matomo.cloud https://googleads.g.doubleclick.net https://kleding.sakestore.nl *.clarity.ms http://172.17.0.2:35729 ws://172.17.0.2:35729 ws://127.0.0.1:35729 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com https://www.sakestore.nl https://dev.sakestore.nl http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com *.gstatic.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.dotdigital-pages.com *.dotdigital.com auth.fisheye.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' data: *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com unpkg.com *.reviews.io *.reviews.co.uk *.avada.io https://getaddress.io *.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.cloudfront.net *.reviews.io *.reviews.co.uk *.fontawesome.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://get.geojs.io *.avada.io https://api.getaddress.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com maxcdn.bootstrapcdn.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.mollie.com https://my.sendinblue.com https://www.facebook.com https://platform.twitter.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.facebook.com quickchart.io img.youtube.com https://www.mollie.com https://api.mapbox.com https://app.usercentrics.eu *.usercentrics.eu https://www.google.de https://syndication.twitter.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.googletagmanager.com *.facebook.net www.termsfeed.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.mollie.com https://app.usercentrics.eu *.usercentrics.eu https://platform.twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com autocomplete2.postdirekt.de https://api.usercentrics.eu https://aggregator.service.usercentrics.eu *.usercentrics.eu https://region1.analytics.google.com https://stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io b.stats.paypal.com dub.stats.paypal.com paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com madefor.github.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' www.clarity.ms fonts.gstatic.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.clarity.ms *.usercentrics.eu *.impactcdn.com *.pxf.io www.googletagmanager.com www.google-analytics.com login-ds.dotomi.com www.google.com *.gstatic.com data:; connect-src 'self' *.usercentrics.eu *.impactcdn.com *.pxf.io *.google-analytics.com api-js.mixpanel.com *.azurewebsites.net; img-src 'self' *.service.usercentrics.eu app.usercentrics.eu www.google-analytics.com *.cloudfront.net data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com googletagmanager.com *.google-analytics.com;base-uri 'self';form-action 'self' 1 script-src 'self' cdnjs.cloudflare.com https://unpkg.com stackpath.bootstrapcdn.com; script-src-attr 'self'; style-src 'self' https://pro.fontawesome.com https://use.fontawesome.com stackpath.bootstrapcdn.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self' 'unsafe-inline' *.asahiglassplaza.net cdn.jsdelivr.net fonts.gstatic.com code.jquery.com cdnjs.cloudflare.com www.googletagmanager.com www.google-analytics.com www.youtube.com webto.salesforce.com *.googleapis.com agc-gp.sitesearch.jp chromestatus.com; report-uri /csp_reports/ 1 font-src *.fontawesome.com https://fonts.gstatic.com/ fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://maps.gstatic.com https://maps.googleapis.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://maps.googleapis.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.gstatic.com *.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cookiebot.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.cookiebot.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.cookiebot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.globalpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cookiebot.com *.typekit.net *.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://google.com/pay https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.googleapis.com *.cookiebot.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.efpa.es api.locize.app maxcdn.bootstrapcdn.com ka-f.fontawesome.com; img-src efpa.es *.efpa.es 'self' data: 'self'; font-src 'self' 'unsafe-inline' 'unsafe-eval' fonts.gstatic.com *.fontawesome.com fonts.googleapis.com data: 'self'; style-src 'self' 'unsafe-inline' 'unsafe-eval' fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.fontawesome.com; object-src 'self'; 1 font-src https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com s7.addthis.com *.google.com *.fontawesome.com *.avada.io * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com ekr.zdassets.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.roche.com *.roche.net *.gene.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.roche.com *.roche.net *.gene.com snap.licdn.com cdn.walkme.com apis.google.com tpc.googlesyndication.com api.html5media.info workdevapp.com cdn-js.net gdata.youtube.com twitter.com geolocation.onetrust.com api.flickr.com graph.facebook.com sharecdn.social9.com maps.googleapis.com use.typekit.com use.typekit.net munchkin.marketo.net img.en25.com w.likebtn.com cdn.mathjax.org sadmin.brightcove.com cdnjs.cloudflare.com releases.flowplayer.org script.crazyegg.com wi.likebtn.com pepperglobal.com analytics.twitter.com cdn.blueconic.net connect.facebook.net fullstory.com script.hotjar.com gnntch.blueconic.net rules.quantcount.com secure.quantserve.com static.hotjar.com www.youtube.com www.googletagmanager.com www.google-analytics.com google-analytics.com *.gstatic.com static.ads-twitter.com sjs.bizographics.com *.linkedin.com www.google.com w.soundcloud.com s.ytimg.com *.cloudflareaccess.com *.salesforceliveagent.com https://*.roche.com:8080 https://cdnjs.org https://service.force.com/* cdn.cookielaw.org static.cloudflareinsights.com googleads.g.doubleclick.net 7232514.collect.igodigital.com; style-src * 'self' 'unsafe-inline'; img-src * 'self' data:; font-src * 'self' data:; connect-src * 'self'; media-src * 'self' data:; object-src 'self'; child-src 'self' *.roche.com *.roche.net *.gene.com *.facebook.net qpcr.probefinder.com *.force.com *.hotjar.com www.facebook.com www.google.com www.googletagmanager.com www.youtube.com; frame-src 'self' *.roche.com *.roche.net *.gene.com www.youtube.com sites.google.com *.googleapis.com *.cloudfront.net *.facebook.net *.arcot.com live.sagepay.com player.vimeo.com tpc.googlesyndication.com players.brightcove.net qpcr.probefinder.com *.eloqua.com *.hotjar.com *.soundcloud.com *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.mendeley.com *.force.com https://cdn.walkme.com/*; worker-src 'self' *.roche.com *.roche.net *.gene.com; frame-ancestors 'self' *.roche.com *.roche.net *.gene.com datastudio.google.com sites.google.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com *.cloudflareworkers.com; form-action 'self' *.roche.com *.roche.net *.gene.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com; base-uri 'self' *.roche.com *.roche.net *.gene.com *.secure.roche.com; report-uri https://ayba8dhs.uriports.com/reports/report; report-to default 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' google-analytics.com use.fontawesome.com fonts.googleapis.com fonts.gstatic.com cdn.jsdelivr.net *.google-analytics.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://consent.cookiebot.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: https:; frame-src 'self' https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.googletagmanager.com https://td.doubleclick.net; connect-src 'self' https://pocanaliticafapp.azurewebsites.net; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://6caa61e4788c4099a36ed2f1ff44942f.js.ubembed.com https://assets.ubembed.com https://www.gstatic.com https://cdn-cookieyes.com https://*.cloudflare.com https://googleads.g.doubleclick.net https://js.hs-scripts.com https://js.hsforms.net https://play.vidyard.com https://script.crazyegg.com https://snap.licdn.com https://www.google.com https://www.googletagmanager.com https://js.hsleadflows.net https://js.hs-analytics.net https://js.hsadspixel.net https://js.hs-banner.com https://builder-assets.unbounce.com https://js.hubspot.com https://js-na1.hs-scripts.com https://connect.facebook.net https://fonts.ub-assets.com https://ajax.googleapis.com https://apis.google.com https://shieldshealthsolutions.com https://cdn-cookieyes.com/*; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://6caa61e4788c4099a36ed2f1ff44942f.js.ubembed.com https://assets.ubembed.com https://www.gstatic.com https://cdn-cookieyes.com https://*.cloudflare.com https://googleads.g.doubleclick.net https://js.hs-scripts.com https://js.hsforms.net https://play.vidyard.com https://script.crazyegg.com https://snap.licdn.com https://www.google.com https://www.googletagmanager.com https://js.hsleadflows.net https://js.hs-analytics.net https://js.hsadspixel.net https://js.hs-banner.com https://builder-assets.unbounce.com https://connect.facebook.net; style-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://fonts.googleapis.com https://builder-assets.unbounce.com https://fonts.ub-assets.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://api.hubapi.com https://cdn-cookieyes.com https://forms.hubspot.com https://log.cookieyes.com https://px.ads.linkedin.com https://*.hsforms.com https://stats.g.doubleclick.net https://hubspot-forms-static-embed.s3.amazonaws.com https://adservice.google.com/pagead https://play.vidyard.com https://directory.cookieyes.com https://overbridgenet.com https://static.hsappstatic.net https://cdnjs.cloudflare.com https://bat.bing.com https://yoast.com https://www.googletagmanager.com/* https://www.google.com/* https://www.google.com/ccm/collect; font-src 'self' 'unsafe-inline' https://fonts.gstatic.com https://fonts.ub-assets.com https://use.typekit.net https://www.globalization-partners.com; frame-src 'self' https://www.google.com https://app.hubspot.com https://play.vidyard.com https://www.googletagmanager.com https://td.doubleclick.net https://safe.menlosecurity.com https://go.shieldshealthsolutions.com https://cn186503-7rx10900.ibosscloud.com https://gateway.zscloud.net https://feedback-pa.clients6.google.com; img-src 'self' https://shieldshealthsolutions.com https://*.vidyard.com https://cdn-cookieyes.com https://forms-na1.hsforms.com https://px.ads.linkedin.com https://track.hubspot.com https://www.googletagmanager.com/* https://www.googletagmanager.com/td https://d9hhrg4mnvzow.cloudfront.net https://stats.g.doubleclick.net https://secure.gravatar.com https://cdn.honey.io https://s.w.org https://translate.google.com https://fonts.gstatic.com; manifest-src 'self'; media-src 'self'; report-uri https://csp-checker.fahlgrendigital.com/api/csp-report; worker-src 'self' https://shieldshealthsolutions.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://interprojekt.pl https://use.typekit.net https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.mageplaza.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.google.com/ apm.przelewy24.pl https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ www.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://pos.baidu.com https://maps.gstatic.com https://maps.googleapis.com https://i.ytimg.com https://i.vimeocdn.com https://www.paypal.com https://p.typekit.net https://*.gstatic.com https://*.openstreetmap.org https://*.inpost.pl https://*.easypack24.net https://static.przelewy24.pl https://*.behance.net https://*.ftcdn.net https://validator.swagger.io magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://www.magezon.com static.przelewy24.pl www.gstatic.com gstatic.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.hotjar.com https://script.hotjar.com https://maps.googleapis.com https://maps.gstatic.com https://connect.facebook.net https://www.youtube.com https://player.vimeo.com https://www.paypal.com https://static.przelewy24.pl *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.google.com/ sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org cdn.ampproject.org www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com assets.braintreegateway.com https://interprojekt.pl https://use.typekit.net *.googleapis.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://geowidget.inpost.pl www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://region1.google-analytics.com https://api.example.com https://vc.hotjar.io https://content.hotjar.io wss://ws.hotjar.com https://maps.googleapis.com https://maps.gstatic.com https://connect.facebook.net https://www.paypal.com https://secure.przelewy24.pl *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com *.easypack24.net *.inpost.pl *.openstreetmap.org cdn.ampproject.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.hotjar.com https://static.ads-twitter.com https://3ieinternational.my.salesforce-sites.com https://www.googletagmanager.com https://snap.licdn.com https://www.google-analytics.com https://static.ads-twitter.com/uwt.js https://script.hotjar.com https://s7.addthis.com https://www.google.com https://t.sharethis.com https://platform-api.sharethis.com https://e.infogram.com https://www.clarity.ms https://s3.amazonaws.com https://px.ads.linkedin.com https://3ieimpact.us2.list-manage.com/subscribe/post-json cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://d1bxh8uas1mnw7.cloudfront.net https://d3js.org https://kendo.cdn.telerik.com https://static.addtoany.com https://unpkg.com https://ws.sharethis.com https://www.gstatic.com mdbootstrap.com platform.instagram.com platform.twitter.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://static.hotjar.com https://static.ads-twitter.com https://3ieinternational.my.salesforce-sites.com https://www.googletagmanager.com https://snap.licdn.com https://www.google-analytics.com https://static.ads-twitter.com/uwt.js https://script.hotjar.com https://s7.addthis.com https://www.google.com https://t.sharethis.com https://platform-api.sharethis.com https://e.infogram.com https://www.clarity.ms https://s3.amazonaws.com https://px.ads.linkedin.com https://3ieimpact.us2.list-manage.com/subscribe/post-json cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://d1bxh8uas1mnw7.cloudfront.net https://d3js.org https://kendo.cdn.telerik.com https://static.addtoany.com https://unpkg.com https://ws.sharethis.com https://www.gstatic.com mdbootstrap.com platform.instagram.com platform.twitter.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://ws.sharethis.com https://cdn-images.mailchimp.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://kendo.cdn.telerik.com https://maxcdn.bootstrapcdn.com https://www.google.com mdbootstrap.com use.fontawesome.com; style-src-elem 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://ws.sharethis.com https://cdn-images.mailchimp.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://kendo.cdn.telerik.com https://maxcdn.bootstrapcdn.com https://www.google.com mdbootstrap.com use.fontawesome.com; form-action 'self' https://3ieimpact.us2.list-manage.com/subscribe/post-json; frame-ancestors 'self' 1 default-src 'self'; upgrade-insecure-requests; require-trusted-types-for 'script'; block-all-mixed-content; report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.bootstrapcdn.com *.kleecks-cdn.com https://blogborgione.blog *.fontawesome.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com https://blogborgione.blog 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.criteo.com *.salesmanago.pl landofcoder.com https://blogborgione.blog *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.googleads/ *.amazonaws.com *.kleecks-cdn.com *.feedaty.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://blogborgione.blog *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.google.de *.googleads/ *.zdassets.com *.adobe.net *.authorize.net *.unpkg.net *.omtrdc.net *.paypal.com *.ytimg.com *.cardinalcommerce.com *.ccdc02.com polyfill.io *.payments-amazon.com *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.iubenda.com *.hotjar.com *.magnewsemail.com *.criteo.com *.criteo.net *.zoorate.com *.kleecks-cdn.com *.kleecks-stats.com *.feedaty.com landofcoder.com https://blogborgione.blog widget.freshworks.com m2epro.freshdesk.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com www.google.com www.gstatic.com pay.google.com beacon.riskified.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.feedaty.com *.iubenda.com *.kleecks-cdn.com https://blogborgione.blog widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.trustpilot.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.zdassets.com *.zendesk.com *.magento.com *.adobedtm.com *.adobedc.io *.typekit.net *.magedevteam.com *.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.amazon.com *.amazon.co.uk *.payments-amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de *.iubenda.com *.magnewsemail.com *.kleecks-cdn.com *.kleecks-stats.com *.feedaty.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com landofcoder.com https://blogborgione.blog widget.freshworks.com m2epro.freshdesk.com www.google.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.googleapis.com *.google.com.au *.googletagmanager.com *.google-analytics.com *.afterpay.com *.tryzens-analytics.com *.bazaarvoice.com *.paypal.com *.facebook.com *.zip.co zip.co; script-src 'self' 'strict-dynamic' 'nonce-4a889de3' *.scarabresearch.com *.googletagmanager.com *.google-analytics.com *.googleapis.com *.googleadservices.co *.youtube.com *.bazaarvoice.com *.useinsider.com *.paypal.com *.paypalobjects.com *.afterpay.com *.braintreegateway.com *.tryzens-analytics.com *.facebook.net *.vimeo.com *.recaptcha.net *.gstatic.com *.autopro.com.au *.facebook.com *.zip.co zip.co; img-src 'self' data: *.useinsider.com *.ctfassets.net *.autopro.com.au *.bazaarvoice.com *.gstatic.com *.paypal.com *.afterpay.com *.google.com.au *.googletagmanager.com *.facebook.com *.zip.co zip.co *.paypalobjects.com; object-src 'none'; frame-ancestors 'self' *.contentful.com; frame-src 'self' *.youtube.com *.vimeo.com *.contentful.com bapcor.formcrafts.com *.useinsider.com *.googletagmanager.com *.paypal.com *.braintreegateway.com *.cardinalcommerce.com *.recaptcha.net zip.co *.zip.co; style-src 'self' 'unsafe-inline' *.bazaarvoice.com *.braintreegateway.com *.googleapis.com *.useinsider.com *.zip.co; font-src 'self' data: *.bazaarvoice.com *.googleapis.com *.zip.co *.paypalobjects.com fonts.gstatic.com *.fonts.gstatic.com; connect-src 'self' *.algolia.io *.googleapis.com *.googletagmanager.com *.google-analytics.com *.afterpay.com *.useinsider.com *.bazaarvoice.com *.paypal.com *.scarabresearch.com *.tryzens-analytics.com *.braintree-api.com *.braintreegateway.com *.paypalobjects.com *.recaptcha.net *.eservice.emarsys.net *.facebook.com *.zip.co zip.co zipmoney.com.au *.zipmoney.com.au; worker-src 'self' blob:; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/bapcor-cspdata 1 default-src 'self' https://cdn.cookielaw.org; base-uri 'self'; script-src 'self' 'nonce-6eWODTmMVgDdz4cO+DJihQ==' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' https://stats.wp.com https://cdn.cookielaw.org https://rs.fullstory.com ; font-src 'self' data: fonts.gstatic.com; style-src 'self' 'nonce-6eWODTmMVgDdz4cO+DJihQ==' fonts.googleapis.com https://googletagmanager.com https://tagmanager.google.com; frame-src https://*.googletagmanager.com 1 script-src 'self' 'nonce-jq7wYqtvDelWzPX2HSZvWx8yoVzpD3qCn4Qt+qz/+Zo=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 object-src 'none'; script-src 'self' 'report-sample' cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill.io https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' cdn.jsdelivr.net fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.klarna.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.google.com *.youtube.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.tawk.to *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.gstatic.com *.googleapis.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.google.co.in bat.bing.com accounts.google.com *.facebook.com *.sharethis.com *.proav.co.uk *.blogger.com maps.gstatic.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sharethis.com bat.bing.com *.hotjar.com *.cookiebot.com komito.net connect.facebook.net js.klarna.com *.klarna.com maps.googleapis.com *.tawk.to cdn.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com unsafe-inline assets.braintreegateway.com x.klarnacdn.net *.tawk.to cdn.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com embed.tawk.to 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.bolt.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.sharethis.com *.cookiebot.com bcp.crwdcntrl.net *.doubleclick.net vc.hotjar.io *.facebook.com js.klarna.com eu.klarnaevt.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://proav.co.uk/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.firstdata.com https://cdnjs.cloudflare.com www.londonstone.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.firstdata.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.londonstone.co.uk 'self' 'unsafe-inline'; frame-ancestors www.londonstone.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.firstdata.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.londonstone.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.afd.co.uk *.firstdata.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.londonstone.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com *.afd.co.uk *.firstdata.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.londonstone.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.firstdata.com https://static.klaviyo.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com www.londonstone.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.londonstone.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.afd.co.uk *.firstdata.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com www.londonstone.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.londonstone.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.londonstone.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.websenso.com; script-src 'self' 'unsafe-inline' https://*.websenso.com https://*.marches-publics.info https://*.comarquage.fr https://www.notre-commune.fr https://*.typekit.net data:; style-src 'self' 'unsafe-inline' https://*.websenso.com https://www.notre-commune.fr https://*.typekit.net; img-src 'self' data: https://*.websenso.com https://images.weserv.nl https://wsrv.nl https://*.tile.openstreetmap.org https://tile.openstreetmap.org https://www.notre-commune.fr https://*.cantal.fr; font-src 'self' https://*.typekit.net data:; frame-src blob: https://www.openstreetmap.org https://www.youtube.com/ https://www.youtube-nocookie.com https://*.marches-publics.info https://*.comarquage.fr https://*.notre-commune.fr; media-src 'self' https://www.youtube.com/ https://www.youtube-nocookie.com https://youtu.be; connect-src 'self' https://*.websenso.com https://*.comarquage.fr https://www.notre-commune.fr; report-uri https://csp-report.appsenso.eu/report.php; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com https://eadn-wc01-5645730.nxedge.io *.maxaccess.io *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.authorize.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.consensu.org *.sharethis.com https://eadn-wc01-5645730.nxedge.io *.maxaccess.io *.authorize.net https://plumrocket.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.google.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.authorize.net https://eadn-wc01-5645730.nxedge.io *.maxaccess.io store.paradoxlabs.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.facebook.net *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.google.com *.sharethis.com https://eadn-wc01-5645730.nxedge.io *.maxaccess.io *.googleapis.com *.avada.io *.authorize.net https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://eadn-wc01-5645730.nxedge.io *.maxaccess.io *.google.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.sharethis.com *.maxaccess.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.authorize.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com https://www.magezon.com quickchart.io img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ landofcoder.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://www.sandbox.paypal.com https://www.paypal.com landofcoder.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com papi.hobex.at ors.custhelp.com ors--tst1.custhelp.com ors.widget.custhelp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com simplitv.docker https://simplitv.docker integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud https://integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud www3.simplitv.at https://www3.simplitv.at www.simplitv.at https://www.simplitv.at *.google.com/ papi.hobex.at js.mollie.com orfdigital.thelounge.net digital.orf.at viveum.test.v-psp.com viveum.v-psp.com insight.adsrvr.org 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.googleapis.com maps.gstatic.com https://images.unsplash.com https://www.magezon.com papi.hobex.at magefan.com cm.magefan.com https://www.mollie.com www.rnengage.com www.simplitv.at www3.simplitv.at www.google.ro *.clarity.ms *.bing.com *.simplitv.at data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com https://player.vimeo.com simplitv.docker https://simplitv.docker integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud https://integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud www3.simplitv.at https://www3.simplitv.at www.simplitv.at https://www.simplitv.at *.google.com/ papi.hobex.at js.mollie.com ors.custhelp.com ors--tst1.custhelp.com www.rnengage.com js-agent.newrelic.com bam.nr-data.net imagesrv.adition.com *.bing.com connect.facebook.net js.adsrvr.org *.adform.net *.doubleclick.net *.clarity.ms ors.widget.custhelp.com www.googleoptimize.com *.simplitv.at https://io.fusedeck.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com papi.hobex.at ors.custhelp.com *.datatables.net ors--tst1.custhelp.com ors.widget.custhelp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com simplitv.docker https://simplitv.docker integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud https://integration-5ojmyuq-ltroc5ehej66o.eu-3.magentosite.cloud www3.simplitv.at https://www3.simplitv.at www.simplitv.at https://www.simplitv.at papi.hobex.at ors.custhelp.com ors--tst1.custhelp.com ors.widget.custhelp.com ors--tst1.widget.custhelp.com bam.nr-data.net google-analytics.com *.google-analytics.com *.doubleclick.net *.clarity.ms maps.googleapis.com www.google.com *.simplitv.at wss://io.fusedeck.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.kxcdn.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de www.googletagmanager.com *.paypal.com https://www.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://www.magezon.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com 'self' assets.braintreegateway.com *.paypal.com *.vimeo.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com https://www.google.com/ *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.googleadservices.com *.google-analytics.com twitter.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com *.cardinalcommerce.com songbirdstag.cardinalcommerce.com *.cloudflare.com pay.google.com c.paypal.com *.paypal.com *.typekit.net bat.bing.com static.zdassets.com maps.googleapis.com *.aptrinsic.com 'self' https://t.profitshare.ro https://profitshare.ro/tgt/js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com ekr.zdassets.com/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net 'self' api.braintreegateway.com *.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self'; script-src 'report-sample' 'unsafe-inline' 'self' https://bat.bing.com/p/insights/s/0.8.1 https://cdn-cookieyes.com/client_data/3163df0a6f39249079c92eb3/script.js https://cdn.taboola.com/libtrc/unip/1655489/tfa.js https://connect.facebook.net/en_US/fbevents.js; style-src 'report-sample' 'unsafe-inline' 'self' https://fonts.googleapis.com https://x.klarnacdn.net; object-src 'none'; base-uri 'self'; connect-src 'self' https://api2.amplitude.com https://bat.bing.com https://bat.bing.net https://cdn-cookieyes.com https://edge.eu1.fullstory.com https://eu.klarnaevt.com https://js.klarna.com https://log.cookieyes.com https://o24547.ingest.sentry.io; font-src 'self' data: https://fonts.gstatic.com https://x.klarnacdn.net; frame-src 'self' https://hpp.worldpay.com https://js.klarna.com https://td.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://www.recaptcha.net; img-src 'self' https://cdn-cookieyes.com https://googleads.g.doubleclick.net https://lantern.roeye.com https://secure.gravatar.com https://www.facebook.com https://www.google-analytics.com https://www.google.co.uk https://www.google.com; manifest-src 'self'; media-src 'self'; worker-src 'self'; report-to csp-endpoint; 1 default-src https: 'unsafe-eval' 'unsafe-inline'; report-uri https://support.stnhost.com/csp/record-bad-https.php 1 upgrade-insecure-requests ; 1 report-uri https://csp.withgoogle.com/csp/forms/prod;frame-ancestors 'none' 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.mageplaza.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de js.stripe.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.google.ee *.facebook.com public.montonio.com self: *.nosto.com *.nos.to data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.googletagmanaget.com *.google-analytics.com *.googleadservices.com *.adobedtm.com *.hotjar.com *.stripe.com *.facebook.net *.addthis.com d1cocw0250tpxv.cloudfront.net public.montonio.com js.stripe.com *.nosto.com *.nos.to 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.googletagmanaget.com *.googleadservices.com *.adobedtm.com *.hotjar.com *.stripe.com *.facebook.net *.facebook.com metrics.hotjar.io api.sandbox-card-payments.montonio.com api.card-payments.montonio.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.hotjar.com *.trustami.com *.confmetrix.com *.metrix-demo.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com *.yotpo.com *.googleapis.com www.auronia.de data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com https://www.sandbox.paypal.com *.yotpo.com www.auronia.de 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.auronia.de 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.hotjar.com *.pinterest.com *.klarna.com *.imajize.com https://plumrocket.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com *.yotpo.com www.auronia.de 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.bing.com *.pinterest.com *.klarnacdn.net *.usercentrics.eu *.confmetrix.com *.metrix-demo.com validate.fishpig.co.uk https://a.klaviyo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com www.auronia.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.pinterest.com *.klaviyo.com *.bing.com *.hotjar.com *.zdassets.com *.zendesk.com *.zopim.com *.pinimg.com *.confmetrix.com *.metrix-demo.com *.klarnacdn.net *.trustami.com https://unpkg.com/vimeo-froogaloop2@0.1.0/javascript/froogaloop.min.js *.usercentrics.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com https://static.klaviyo.com https://fast.a.klaviyo.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com *.yotpo.com www.auronia.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.trustami.com *.confmetrix.com *.metrix-demo.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com *.yotpo.com www.auronia.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.pinterest.com *.zdassets.com www.auronia.de 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.pinterest.com *.zdassets.com *.doubleclick.net *.zendesk.com *.zopim.com *.confmetrix.com *.metrix-demo.com *.hotjar.com *.klaviyo.com wss://widget-mediator.zopim.com/ *.klarnaevt.com/ *.trustpilot.com/ https://bat.bing.com/ *.usercentrics.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://static.klaviyo.com https://fast.a.klaviyo.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com www.auronia.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com www.auronia.de http: https: blob: 'self' 'unsafe-inline'; default-src www.auronia.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 default-src 'self' https://*.google.com https://*.google.ca https://*.googletagmanager.com https://*.doubleclick.net https://*.google-analytics.com https://*.pickatime.com https://*.pnwsoft.com https://*.fontawesome.com https://www.youtube.com; connect-src 'self' wss: https://*.google.com https://*.google.ca https://*.googletagmanager.com https://*.doubleclick.net https://*.google-analytics.com https://*.pickatime.com https://*.pnwsoft.com https://*.fontawesome.com https://*.google-analytics.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.youtube.com https://*.gstatic.com https://*.pickatime.com https://*.paypal.com https://*.google.com https://*.googletagmanager.com https://*.pnwsoft.com https://browser.sentry-cdn.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.youtube.com https://*.gstatic.com https://*.pickatime.com https://*.paypal.com https://*.google.com https://*.googletagmanager.com https://*.pnwsoft.com https://browser.sentry-cdn.com; script-src-attr 'unsafe-inline' 'unsafe-eval' https://*.pickatime.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.youtube.com https://*.fontawesome.com https://*.google.com https://*.gstatic.com https://fonts.googleapis.com https://*.pnwsoft.com https://*.pickatime.com; style-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://www.youtube.com https://*.fontawesome.com https://*.google.com https://*.gstatic.com https://fonts.googleapis.com https://*.pnwsoft.com https://*.pickatime.com; style-src-attr 'unsafe-inline' 'unsafe-eval' https://*.pickatime.com; img-src 'self' data: blob: https://*.google.com https://*.google.ca https://*.googletagmanager.com https://*.doubleclick.net https://*.google-analytics.com https://*.gstatic.com https://*.pickatime.com https://*.pnwsoft.com https://*.fontawesome; media-src 'self' data: ; font-src 'self' data: blob: https://fonts.gstatic.com https://*.fontawesome.com https://*.fontshare.com https://*.bootstrapcdn.com https://*.google.com https://*.pickatime.com; frame-src 'self' https://*.google.com https://www.youtube.com https://*.paypal.com; report-uri https://pickatime.com/home/receivecspreport; report-to csp-endpoint 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.twitter.com *.addthis.com *.cookiebot.com js.mollie.com *.sendcloud.sc *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io maps.gstatic.com maps.googleapis.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.facebook.com *.google.com *.google.be *.googletagmanager.com *.doubleclick.net *.googlesyndication.com https://www.mollie.com www.google.com www.google.com.ua *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com maps.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.be *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.zendesk.com *.cookiebot.com *.zdassets.com *.facebook.net *.doubleclick.net *.googleapis.com *.googlesyndication.com *.createsend1.com *.avada.io js.mollie.com *.sendcloud.sc *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com gtm.dandoy-sports.eu https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.cloudflare.com *.twitter.com *.facebook.com *.paypal.com wss://*.zopim.com *.doubleclick.net *.zendesk.com *.cookiebot.com *.zdassets.com *.googlesyndication.com *.google-analytics.com https://www.google-analytics.com gtm.dandoy-sports.eu https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: 'unsafe-inline' https://www.paypalobjects.com/;connect-src https://combined-demo.apm.eu-west-1.aws.cloud.es.io/;frame-src 'self' https://www.youtube.com/; report-uri https://reports.webperf.tools/qrexplore; report-to default 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://* data: blob: https://challenges.cloudflare.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com https://* blob: data:; frame-src 'self' *.google.com https://* data: blob: https://challenges.cloudflare.com; connect-src 'self' * https://*.googleapis.com *.google.com https://*.gstatic.com wss://* https://* data: blob:; font-src 'self' https://fonts.gstatic.com https://* data: blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://* data: blob:; worker-src 'self' https://* data: blob:; report-to browser-intake-datadoghq; frame-ancestors 'self' 1 font-src https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://accounts.google.com https://*.google.com https://*.hotjar.com https://vars.hotjar.com https://www.facebook.com https://*.criteo.com https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com public.montonio.com https://www.facebook.com https://www.google.com https://www.google.ee https://www.google-analytics.com rx.apotheka.lv data: http: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com public.montonio.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://www.gstatic.com rx.apotheka.lv http: https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com rx.apotheka.lv http: https: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://www.google-analytics.com https://stats.g.doubleclick.net rx.apotheka.lv http: https: wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' upload.bazar.at asset.bazar.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; connect-src 'self' upload.bazar.at asset.bazar.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; base-uri 'self'; form-action 'self'; img-src 'self' data: upload.bazar.at asset.bazar.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; script-src 'self' 'unsafe-inline' upload.bazar.at asset.bazar.at static.kurier.at *.googletagservices.com *.googletagmanager.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.gstatic.com *.google.com *.google.at *.google.de *.google.sk *.privacy-center.org *.hotjar.com *.doubleclick.net *.openstreetmap.fr *.addthis.com cdn.ampproject.org; 1 default-src 'self'; script-src 'self' https://js.cobrowse.io/CobrowseIO.js https://*.agentiq.co frame-src 'self' https://cobrowse.io connect-src 'self' https://*.agentiq.co wss://*.agentiq.co https://api.cobrowse.io wss://*.cobrowse.io https://cobrowse.io frame-ancestors 'self' https://*.agentiq.co style-src 'self' https://*.agentiq.co 1 default-src 'self' https://www.google.com https://apikeys.civiccomputing.com; font-src 'self' https://fonts.gstatic.com https://script.hotjar.com; img-src 'self' data: https://www.hostellingscotland.org.uk https://hostellingscotland.org.uk https://static.hotjar.com https://maps.gstatic.com https://maps.googleapis.com https://developers.google.com https://ssl.google-analytics.com https://stats.g.doubleclick.net https://www.google.co.uk https://www.facebook.com https://t.co https://analytics.twitter.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://hostelbookings.net https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://maps.googleapis.com https://www.google-analytics.com https://ssl.google-analytics.com https://cc.cdn.civiccomputing.com https://static.ctctcdn.com https://www.youtube.com https://e.issuu.com https://cdnjs.cloudflare.com https://script.crazyegg.com https://static.hotjar.com https://script.hotjar.com https://connect.facebook.net https://static.ads-twitter.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://static.ctctcdn.com; connect-src 'self' https://listgrowth.ctctcdn.com https://script.crazyegg.com https://in.hotjar.com https://stats.g.doubleclick.net https://apikeys.civiccomputing.com https://surveystats.hotjar.io; object-src 'none'; frame-ancestors 'self'; frame-src https://www.youtube.com https://e.issuu.com https://www.google.com https://www.gstatic.com; 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com js.mollie.com *.cookiebot.com *.kiyoh.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://www.mollie.com *.zendesk.com *.zdassets.com *.cookiebot.com *.facebook.com *.google.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://browser.sentry-cdn.com js.mollie.com *.zendesk.com *.zdassets.com *.cookiebot.com *.dwin1.com *.hotjar.com *.facebook.net *.roeyecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://*.ingest.sentry.io *.zendesk.com *.zdassets.com *.cookiebot.com *.doubleclick.net *.analytics.google.com *.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://shop.dejongmarinelife.nl/; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' thugnine.com.br *.thugnine.com.br wake-components.fbitsstatic.net thugnine.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.g.doubleclick.net *.googleadservices.com *.yourviews.com.br *.criteo.com *.yviews.com.br *.criteo.net *.clearsale.com.br *.pinimg.com *.pinterest.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net d3bo67muzbfgtl.cloudfront.net api.edrone.me *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gstatic.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.edrone.me *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.pagaleve.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.thugnine.com.br thugnine.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com geowidget.easypack24.net https://fonts.gstatic.com https://cdnjs.cloudflare.com https://geowidget.easypack24.net https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com https://td.doubleclick.net secure.payu.com merch-prod.snd.payu.com pay.google.com apm.przelewy24.pl https://static.addtoany.com https://pudofinder.dpd.com.pl *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://ct.pinterest.com https://consentcdn.cookiebot.com/ https://consent.cookiebot.com https://smart-widget-assets.ekomiapps.de c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.awin1.com *.zenaps.com *.wepowerconnections.com *.hsforms.net *.hsforms.com static.payu.com magefan.com cm.magefan.com osm.inpost.pl geowidget.easypack24.net *.tile.openstreetmap.org *.disqus.com static.przelewy24.pl www.gstatic.com gstatic.com https://widget-v2.smartsuppcdn.com https://files.smartsuppcdn.com https://files.smartsupp.com https://twemoji.maxcdn.com https://www.google.com https://www.google.pl https://googleads.g.doubleclick.net https://ruch-osm.sysadvisors.pl https://geowidget.easypack24.net https://osm.inpost.pl https://c.clarity.ms https://pixel.wp.pl https://lantern.roeye.com https://smart-widget-assets.ekomiapps.de https://sw-assets.ekomiapps.de https://ekomi-srr.s3.eu-central-1.amazonaws.com https://zaufane.pl https://imgsct.cookiebot.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.hsforms.net *.hsforms.com secure.payu.com secure.snd.payu.com *.disqus.com cdn.jsdelivr.net sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl https://www.smartsuppchat.com https://widget-v2.smartsuppcdn.com https://www.rzetelnyregulamin.pl https://googleads.g.doubleclick.net https://static.addtoany.com https://www.orlenpaczka.pl https://ruch-osm.sysadvisors.pl https://geowidget.easypack24.net https://www.clarity.ms https://pixel.wp.pl https://smart-widget-assets.ekomiapps.de https://lantern.roeyecdn.com https://s.pinimg.com https://ct.pinterest.com https://consentcdn.cookiebot.com https://sw-assets.ekomiapps.de https://consent.cookiebot.com analytics.tiktok.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com geowidget.easypack24.net *.googleapis.com *.addtoany.com cdn.jsdelivr.net https://www.rzetelnyregulamin.pl https://cdnjs.cloudflare.com https://ruch-osm.sysadvisors.pl https://geowidget.easypack24.net https://sw-assets.ekomiapps.de https://smart-widget-assets.ekomiapps.de https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.typekit.net *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.wepowerconnections.com https://the.sciencebehindecommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com secure.payu.com merch-prod.snd.payu.com api-pl-points.easypack24.net api-fr-points.easypack24.net api-uk-points.easypack24.net api-ca-points.easypack24.net api-it-points.easypack24.net http://dpm.demdex.net sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com https://bootstrap.smartsuppchat.com https://widget-v2.smartsuppcdn.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://ruch-osm.sysadvisors.pl https://api-pl-points.easypack24.net https://o.clarity.ms https://pixel.wp.pl https://vc-service.saleago.com https://ct.pinterest.com https://smart-widget-assets.ekomiapps.de https://consentcdn.cookiebot.com https://sentry.advox.pl/api sw-assets.ekomiapps.de pagead2.googlesyndication.com analytics.tiktok.com server-side-tagging-ggil7flztq-uc.a.run.app *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com ws: 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com platform.twitter.com *.nosto.com *.nos.to landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.google-analytics.com *.google.co.uk *.google.com *.google.co.in *.googletagmanager.com www.gstatic.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.nosto.com *.nos.to https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cloudflareinsights.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.gstatic.com s7.addthis.com connect.facebook.net twitter.com platform.twitter.com *.nosto.com *.nos.to landofcoder.com *.googleapis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.googleapis.com *.google.com https://fonts.bunny.net assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflareinsights.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.gstatic.com ekr.zdassets.com/ *.nosto.com *.nos.to landofcoder.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'unsafe-inline' 'self'; script-src 'unsafe-eval' 'unsafe-inline' 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://osozre.kamsoft.local https://unpkg.com https://ad.osoz.pl; script-src-elem 'unsafe-eval' 'unsafe-inline' 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://osozre.kamsoft.local https://ad.osoz.pl https://unpkg.com https://osozre.kamsoft.local https://ajax.googleapis.com https://cdnjs.cloudflare.com https://code.jquery.com; style-src 'unsafe-inline' 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://fonts.googleapis.com https://unpkg.com https://osozre.kamsoft.local https://ad.osoz.pl; style-src-elem 'unsafe-inline' 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://fonts.googleapis.com https://unpkg.com https://osozre.kamsoft.local https://ad.osoz.pl https://re.osoz.pl; font-src 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://fonts.gstatic.com; img-src 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://re.osoz.pl https://api.kamsoft.pl https://ad.osoz.pl http://ws4.pharmindex.pl https://ws3.pharmindex.pl https://pljasien.pl blob: data:; child-src 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl; object-src https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl blob: data:; connect-src 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://fonts.gstatic.com https://dc.services.visualstudio.com https://ad.osoz.pl https://osozre.kamsoft.local; frame-src 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl https://repoedm-dev.azure-api.net https://edm-suite.kamsoft.pl https://api.kamsoft.pl https://api.pharmindex.pl blob: data:; frame-ancestors 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl; media-src 'unsafe-eval' 'unsafe-inline' 'self' https://static.serum.com.pl https://serum.com.pl https://s1.serum.com.pl data: blob:; report-uri https://s1.serum.com.pl/cspreps1; report-to csp-endpoint 1 default-src 'self'; base-uri 'self'; object-src 'none'; img-src 'self' https://www.feistyduck.com https://queue.simpleanalyticscdn.com; connect-src 'self' https://*.ingest.de.sentry.io https://queue.simpleanalyticscdn.com; font-src 'self' data: https://assets.gumroad.com; script-src 'nonce-ed701ccbc1c9840ae102f6cb147d5cc5' 'strict-dynamic' 'report-sample' 'unsafe-inline' https: http:; style-src 'report-sample' 'self' 'unsafe-inline' https://www.feistyduck.com https://assets.gumroad.com; upgrade-insecure-requests; frame-src 'none'; frame-ancestors 'none'; report-uri https://o4510000335486976.ingest.de.sentry.io/api/4510028218630224/security/?sentry_key=f18f1ce40d04e3436aa406dafaf65736 1 img-src https://higherlogicdownload.s3.amazonaws.com/POPULATIONASSOCIATION/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/POPULATIONASSOCIATION/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/POPULATIONASSOCIATION/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogicdownload.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogiclongterm.s3.amazonaws.com/POPULATIONASSOCIATION/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/POPULATIONASSOCIATION/ 'self' https://higherlogiclongterm.s3.amazonaws.com/POPULATIONASSOCIATION/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogicdownload.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogicstream.s3.amazonaws.com/POPULATIONASSOCIATION/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/POPULATIONASSOCIATION/ https://higherlogicdownload.s3.amazonaws.com/POPULATIONASSOCIATION/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/POPULATIONASSOCIATION/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src 'self' https://cdn.wolterskluwer.io/ https://www.googletagmanager.com/ https://analytics.sleeknote.com/ https://dc.services.visualstudio.com/v2/track https://www.google-analytics.com/ https://region1.google-analytics.com/ https://vimeo.com/ https://pagead2.googlesyndication.com/ https://cmtt.nl/ https://ep1.adtrafficquality.google/ https://securepubads.g.doubleclick.net/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.userdatatrust.com/ https://securepubads.g.doubleclick.net/ https://pagead2.googlesyndication.com/ https://ep2.adtrafficquality.google/ https://www.googletagmanager.com/ https://eu2.cdn.thunderhead.com/one/rt/js/one-tag.js?siteKey=ONE-JHGTRIWT14-2067 http://sleeknotecustomerscripts.sleeknote.com/23807.js http://img.en25.com/i/elqCfg.min.js https://az416426.vo.msecnd.net/scripts/a/ai.0.js http://sleeknotestaticcontent.sleeknote.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1069938057/ https://www.google-analytics.com/analytics.js https://www.googletagservices.com/ https://connect.facebook.net/ http://cdn.feedbackify.com/ http://dev.visualwebsiteoptimizer.com/ https://certify-js.alexametrics.com/ http://ajax.googleapis.com/; style-src 'self' 'unsafe-inline' https://cdn.wolterskluwer.io/; img-src 'self' https://cdn.wolterskluwer.io/wk-logos/1.0.x/ https://s1364398973.t.eloqua.com/visitor/v200/svrGP data: https://www.google.com/ https://www.google.it/ https://www.google-analytics.com/ https://i.vimeocdn.com/ https://www.taxvisions.nl/ https://acc.taxvisions.nl/ https://ep1.adtrafficquality.google/ https://ep2.adtrafficquality.google/ https://tpc.googlesyndication.com/ https://pagead2.googlesyndication.com/ https://www.googletagmanager.com/ http://cdn.feedbackify.com/ https://dev.visualwebsiteoptimizer.com/; font-src 'self' https://cdn.wolterskluwer.io/; frame-src 'self' https://player.vimeo.com/ *.safeframe.googlesyndication.com/ https://ep2.adtrafficquality.google/; frame-ancestors 'self'; 1 report-uri https://report-uri.io/report/corburn/reportOnly 1 img-src *.force.com https://omt.honda.com https://owners.honda.com https://ahfc.techsee.me slack-imgs-mil-dev.com https://honda.demdex.net 'self' https://www.acura.com https://stats.g.doubleclick.net https://usa690.sfdc-lywfpd.salesforce.com/icons/ https://img.youtube.com https://media-ahfc.cdn-us.techsee.me https://payments.salesforce.com/icons/ https://cdn.cookielaw.org https://login.salesforce.com/icons/ http://code.jquery.com https://ahfc-api.techsee.me https://somt.honda.com https://ahfc--webproj1.my.salesforce.com https://www.gstatic.com *.slack-edge-gov.com https://self1.techsee.me *.my-salesforce.com https://assets.adobedtm.com *.cloudinary.com https://www.google.com https://analytics.google.com https://rec1.techsee.me https://dpm.demdex.net https://techsee.me *.amazonaws.com blob: https://survey2.sendyouropinions.com *.gstatic.com https://ahfc.my.salesforce.com https://eshopping.americanhondafinance.com *.facebook.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.youtube.com https://ssl.gstatic.com *.twimg.com *.youtube-nocookie.com *.slack.com https://www.paypal.com https://imagebaseurl.techsee.me https://ahfc.file.force.com https://cm.everesttech.net *.slack-imgs.com slack-imgs-gov.com https://uat2.sendyouropinions.com https://prod-us.techsee.me https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://prod-eu.techsee.me *.salesforce-experience.com https://sdk-us.techsee.me https://maps.a.forceusercontent.com https://consent-api.onetrust.com slack-imgs-gov-dev.com *.slack-edge.com https://self.techsee.me https://ahfc.sf-na.techsee.me https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://fonts.googleapis.com https://rec.techsee.me slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://geolocation.onetrust.com https://privacyportal-ae.onetrust.com https://td.doubleclick.net https://automobiles.honda.com https://powersports.honda.com https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://i.vimeocdn.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://ahfc.sf-na.desktop.show https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://ahfc.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Dj0000001oPqD&networkId=0DM5b000000wk5s&type=communities 1 font-src *.typekit.net *.gstatic.com cdnjs.cloudflare.com fonts.gstatic.com *.googleapis.com 'unsafe-inline' data: *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com magento.buildify.shop oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.hana.ondemand.com 'self'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com s3.amazonaws.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://widgets.payflex.co.za oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; style-src cdnjs.cloudflare.com fonts.googleapis.com magento.buildify.shop https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src widget-v4.tidiochat.com *.zdassets.com 'self' 'unsafe-inline'; connect-src wss://socket.tidio.co telemetrics.klaviyo.com magento.buildify.shop www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; frame-src magento.buildify.shop bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com platform.twitter.com www.google.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; script-src www.instagram.com code.tidio.co widget-v4.tidiochat.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com platform.twitter.com platform.instagram.com apis.google.com magento.buildify.shop *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.avada.io *.shopify.com https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self'; script-src https://mc.yandex.ru 'unsafe-eval' 'unsafe-inline' 'report-sample' 'self' https://cdn.gpeople.online https://www.google.com/ https://www.gstatic.com; style-src 'unsafe-inline' 'report-sample' 'self' https://cdn.gpeople.online; object-src 'none'; connect-src https://mc.yandex.ru 'self' https://cdn.gpeople.online https://okr.sbdv.ru wss://vps.gpeople.online https://web-telemetry.gpeople.online https://sentry-api.gpeople.online; font-src 'self' data: https://cdn.gpeople.online; frame-src https://mc.yandex.ru 'self' blob: https://www.google.com/; img-src https://mc.yandex.ru 'self' data: https://cdn.gpeople.online https://s-dt2.cloud.edgecore.ru; manifest-src 'self' https://cdn.gpeople.online; media-src 'self'; frame-ancestors http://*.webvisor.com http://webvisor.com https://*.webvisor.com https://webvisor.com https://metrika.yandex.ru 'self' https://www.speechpro.ru; worker-src 'none'; child-src https://mc.yandex.ru 'self' blob:; base-uri 'self'; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=18168&v=v1.0&payload=OmAZ91Za5TPbhRNpMd-KaiiZEyJJp5TKtczGBrr8Z4osz8b3uSUuTT6hGTdHyzoXjBqpY73JWwGAlynjVfza6UEXQ9cM6eELxiqQ1qPWIn1TpS5CNSJ2sIvURWLUN_0nd0a6W7meS8knu6dACDk97f2XBzGmvkPcES9dOEgmAJrhgbt0pWQEvBpfZ2dA1sJdAxo5sxbb9oQtTSev9C-67g==; 1 script-src 'unsafe-inline' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com *.googletagmanager.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com mageside.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.google.com *.afip.gob.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com self https://*.googletagmanager.com tagmanager.google.com https://*.google-analytics.com https://*.google.com https://*.google.com.ar https://*.gstatic.com https://*.googleapis.com https://*.googleadservices.com https://*.cloudflareinsights.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: fonts.googleapis.com *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magento-cloudflare.jetrails.com www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ytimg.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.genderxfilms.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.genderxfilms.com join.gammasecure.com; script-src 'self' *.genderxfilms.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.genderxfilms.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com acs.3ds-pit.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com account.fetchify.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com acs.3ds-pit.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarna.com *.klarnaevt.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com *.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com acs.3ds-pit.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com cc-cdn.com https://*.googleapis.com *.typekit.net unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com acs.3ds-pit.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/PTG/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/PTG/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/PTG/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/PTG/ https://higherlogicdownload.s3.amazonaws.com/PTG/ https://higherlogiclongterm.s3.amazonaws.com/PTG/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/PTG/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/PTG/ 'self' https://higherlogiclongterm.s3.amazonaws.com/PTG/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/PTG/ https://higherlogicdownload.s3.amazonaws.com/PTG/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/PTG/ https://higherlogicstream.s3.amazonaws.com/PTG/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/PTG/ https://higherlogicdownload.s3.amazonaws.com/PTG/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/PTG/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; frame-ancestors 'self' *.intuit.com intuit.com *.quickbooks.com quickbooks.com *.square.com square.com *.squareupstaging.com squareupstaging.com *.squareup.com squareup.com *.bambee.com bambee.com *.gusto.com gusto.com *.netsuite.com netsuite.com *.remote.com remote.com *.niceremote.com niceremote.com toasttab.com *.toasttab.com patriotsoftware.com *.patriotsoftware.com *.7shifts.com 7shifts.com *.aioapp.com aioapp.com *.belfrysoftware.com belfrysoftware.com *.blinkpayroll.com blinkpayroll.com *.buddypunch.com buddypunch.com *.central.inc central.inc *.checkhq.com checkhq.com *.concordmaterials.com concordmaterials.com *.dripos.com dripos.com *.eddy.com eddy.com *.encompassfi.com encompassfi.com *.getthera.com getthera.com *.gogateway.ai gogateway.ai *.gosteelhead.com gosteelhead.com *.housecallpro.com housecallpro.com *.joinhomebase.com joinhomebase.com *.joinmoxie.com joinmoxie.com *.joinwarp.com joinwarp.com *.keka.com *.kekad.com *.kekauat.com *.kekastage.com *.kekademo.com *.lumberfi.com lumberfi.com *.masonworkforce.com masonworkforce.com *.miter.com miter.com *.monograph.com monograph.com *.mymaterial.co mymaterial.co *.plane.com plane.com *.runtrayd.com runtrayd.com *.tryplayground.com tryplayground.com *.zenoti.com zenoti.com *.zoho.com zoho.com *.collective.com collective.com *.myhrfh.com myhrfh.com *.studiodesigner.com studiodesigner.com; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri https://simplyinsured.report-uri.com/r/d/csp/reportOnly 1 object-src 'none'; worker-src 'self'; base-uri 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com account.fetchify.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://s3bucketagri.s3.eu-west-2.amazonaws.com https://www.facebook.com https://hn.inspectlet.com https://www.google.co.uk magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io https://www.gstatic.com https://static.hotjar.com https://cdn.inspectlet.com https://wisepops.net https://script.hotjar.com https://js-agent.newrelic.com *.disqus.com *.avada.io *.shopify.com *.google.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.what3words.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://hn.inspectlet.com wss://ws.inspectlet.com https://wisepops.net https://activity.wisepops.com https://bam.nr-data.net https://www.google.co.uk https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.what3words.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://www.youtube.com https://crmware-previsora.comware.com.co https://www.google.com https://www.isoatprevisora.transfiriendo.com https://osbasahpublisher-ac-uswest1.lfr.cloud https://www.google-analytics.com https://cloudapps.emtelco.co https://*.yahooapis.com https://*.gstatic.com https://*.fontawesome.com; script-src 'self' 'nonce-qHhAplPey1Wb/KjG8GLzkw==' 'unsafe-eval' https://api-backend-service.comware.com.co:3023 https://www.gstatic.com https://www.google.com https://*.liferay.com https://www.googletagmanager.com https://www.google-analytics.com https://www.previsora.gov.co https://cloudapps.emtelco.co https://*.fontawesome.com https://*.cloudflare.com https://unpkg.com https://*.jsdelivr.net; style-src 'self' 'nonce-qHhAplPey1Wb/KjG8GLzkw==' https://*.googleapis.com https://unpkg.com https://*.jsdelivr.net; style-src-elem 'self' 'nonce-qHhAplPey1Wb/KjG8GLzkw==' https://cloudapps.emtelco.co https://*.googleapis.com https://*.fontawesome.com https://unpkg.com https://*.jsdelivr.net; img-src 'self' data: https://api-backend-service.comware.com.co:3023 https://www.google-analytics.com https://cloudapps.emtelco.co; font-src 'self' data: https://cloudapps.emtelco.co https://*.gstatic.com https://*.fontawesome.com; frame-ancestors 'self' https://www.previsora.gov.co; 1 default-src 'self' https://assetspwa.fabletics.mx; script-src 'self' https://assetspwa.fabletics.mx; script-src 'self' https://assetspwa.fabletics.mx* 'unsafe-inline'; font-src 'self' https://assetspwa.fabletics.mx; script-src https://assetspwa.fabletics.mx; style-src 'self' https://assetspwa.fabletics.mx 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' eletrorastro.com.br *.eletrorastro.com.br wake-components.fbitsstatic.net eletrorastro.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com criteo.com trustvox.com.br shopback.net shopconvert.com.br cloudflare.com criteo.net linximpulse.net shoptarget.com.br googleadservices.com retargeter.com.br doubleclick.net hertzen.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.googleadservices.com *.criteo.net *.linximpulse.net *.shoptarget.com.br *.retargeter.com.br *.criteo.com *.trustvox.com.br *.shopback.net *.shopconvert.com.br *.cloudflare.com *.hertzen.com *.doubleclick.net wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.chaordicsystems.com *.itau.com *.itau.com.br *.itaushopline.com *.itaushopline.com.br *.hotjar.com *.navdmp.com *.clearsale.com.br *.goadopt.io *.shoppush.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.google.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.rdstation.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.tiktok.com analytics.tiktok.com d335luupugsy2.cloudfront.net *.cloudfront.net *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io wake-commerce-scripts.omni.chat *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.eletrorastro.com.br eletrorastro.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vivapayments.com *.twitter.com *.google.com *.cardlink.gr *.eurocommerce.gr *.iris.dias.com.gr *.test-iris.dias.com.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.youtube.com/ https://scontent-ams4-1.cdninstagram.com *.contactpigeon.com https://www.googletagmanager.com/ *.weltpixel.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://platform-api.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com https://clauem2.arrowtheme.com https://scontent.cdninstagram.com/ https://scontent-ams4-1.cdninstagram.com *.contactpigeon.com https://firebasestorage.googleapis.com https://www.magezon.com https://cdn-cookieyes.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vivapayments.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.maps.googleapis.com *.trackedlink.net *.maps.gstatic.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com https://buttons-config.sharethis.com/ https://connect.facebook.net https://sharethis.com/ https://scontent-ams4-1.cdninstagram.com *.contactpigeon.com *.avada.io *.shopify.com https://www.googletagmanager.com/ https://*.cookieyes.com https://cdn-cookieyes.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com https://platform-api.sharethis.com https://fonts.bunny.net tagmanager.google.com https://*.cookieyes.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://scontent-ams4-1.cdninstagram.com *.contactpigeon.com https://get.geojs.io *.avada.io https://www.google-analytics.com https://cdn-cookieyes.com 'self' 'unsafe-inline'; child-src *.contactpigeon.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com platform.twitter.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com twitter.com platform.twitter.com *.gstatic.com maps.googleapis.com *.nosto.com *.nos.to https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.nosto.com *.nos.to https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com *.dotdigital-pages.com *.dotdigital.com *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com *.gstatic.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klarnacdn.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com services.postcodeanywhere.co.uk *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com api.addressy.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: 'unsafe-inline' 'unsafe-eval' 'self' data: www.google-analytics.com ajax.googleapis.com downloads.mailchimp.com *.pushengage.com; object-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.inkifi.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: magento-cloudflare.jetrails.com *.klarna.com https://designer.mediacliphub.com https://*.azureedge.net *.weltpixel.com https://plumrocket.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com *.doubleclick.net *.typeform.com *.cloudflareinsights.com *.mediacliphub.com *.facebook.com *.laybuy.com *.azureedge.net zenaps.com *.zenaps.com *.pinterest.com *.pinterest.ca *.pinterest.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.ytimg.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://render.mediacliphub.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com blob: *.adobedtm.com *.stripe.com dev.visualwebsiteoptimizer.com *.wistia.com *.cloudfront.net inkifi.com *.nxcli.net *.sweetanalytics.com *.google.ru *.google.co.uk *.zopim.com *.zopim.io *.mediacliphub.com awin1.com *.awin1.com zenaps.com *.zenaps.com *.googleadservices.com *.sciencebehindecommerce.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://static.mediacliphub.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com *.adobedtm.com *.gorgias.chat self *.hcaptcha.com unsafe-inline unsafe-eval unsafe-hashes *.visualwebsiteoptimizer.com *.googleoptimize.com player.vimeo.com *.wistia.com *.sweetanalytics.com *.mediacliphub.com *.dwin1.com *.cloudflare.com *.twitter.com *.fontawesome.com *.google-analytics.com *.twimg.com *.gstatic.com *.authorize.net *.googleapis.com *.demdex.net *.amcglobal.sc.omtrdc.net *.cardinalcommerce.com *.paypal.com *.paypalobjects.com *.zdassets.com *.pinterest.co.uk *.pinterest.ca *.facebook.com *.apptrian.com *.zopim.com *.sciencebehindecommerce.com zenaps.com *.zenaps.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.klaviyo.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.zdassets.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://api.mediacliphub.com https://dc.services.visualstudio.com maps.googleapis.com *.stripe.com klarna.com *.link.com *.amazon.com https://www.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.gorgias.chat *.googleapis.com *.datadome.co *.google.uk *.google.ru js.monitor.azure.com *.litix.io *.wistia.com *.nxcli.net *.sweetanalytics.com *.cloudflare.com *.demdex.net *.amcglobal.sc.omtrdc.net *.cardinalcommerce.com *.paypalobjects.com *.zdassets.com *.pinterest.co.uk *.pinterest.ca *.facebook.com *.apptrian.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.mediacliphub.com *.services.visualstudio.com *.sciencebehindecommerce.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-3kI24Z9J-0dbs11X00-iH7WAV5oatPWd'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com static.klaviyo.com *.bootstrapcdn.com *.cdnfonts.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: https://use.fontawesome.com https://d1cwup7r903a1d.cloudfront.net *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com blob: *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com www.facebook.com platform.twitter.com https://player.vimeo.com https://www.youtube-nocookie.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.tawk.to https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.amazonaws.com *.cloudinary.com *.google.com www.google.com.co.uk blob: *.cloudfront.net stats.g.doubleclick.net *.s3-us-west-2.amazonaws.com magefan.com cm.magefan.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.sezzle.com *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.amazonaws.com *.jst.ai *.cloudflare.com *.klaviyo.com static.klaviyo.com fast.a.klaviyo.com a.klaviyo.com *.typeform.com *.liadm.com *.retention.com *.execute-api.us-west-2.amazonaws.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net connect.facebook.net twitter.com platform.twitter.com https://player.vimeo.com https://www.youtube.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.routeapp.io https//fonts.googleapis.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.tawk.to cdn.jsdelivr.net https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.klaviyo.com *.fontawesome.com *.bootstrapcdn.com assets.braintreegateway.com *.typekit.net *.typeform.com *.cdnfonts.com *.googleapis.com *.googletagmanager.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com https://use.fontawesome.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net fonts.cdnfonts.com *.tawk.to cdn.jsdelivr.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src blob: 'self' 'unsafe-inline'; media-src *.adobe.com blob: *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com stats.g.doubleclick.net *.typeform.com *.liadm.com *.retention.com *.klaviyo.com fast.a.klaviyo.com a.klaviyo.com *.execute-api.us-west-2.amazonaws.com aly.jst.ai *.sezzle.com 'self' 'unsafe-inline' *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.route.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com *.tawk.to wss://*.tawk.to https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.bootstrapcdn.com *.dhlparcel.nl https://static.dhlecommerce.nl https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.google.com www.google.com *.doubleclick.net www.facebook.com *.addthis.com *.hotjar.com *.cookiebot.com consentcdn.cookiebot.eu js.mollie.com *.trustpilot.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.googleapis.com *.gstatic.com *.google.nl *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com forza-refurbished.nl *.forza-refurbished.nl *.bluebirdday.io *.amazonaws.com *.google.com *.bing.com *.trustpilot.com *.trustpilot.net *.clarity.ms magefan.com cm.magefan.com https://maps.googleapis.com https://maps.gstatic.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com https://img.youtube.com https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com *.hsforms.net *.hsforms.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.vimeocdn.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.trengo.eu *.addthis.com *.addthisedge.com *.moatads.com chimpstatic.com *.cookiebot.com *.dhlparcel.nl *.bing.com *.hotjar.com *.trustpilot.com *.clarity.ms consent.cookiebot.eu consentcdn.cookiebot.eu https://static.dhlecommerce.nl https://maps.googleapis.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com *.trustpilot.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.addthis.com *.trengo.eu *.bing.com *.hotjar.com *.doubleclick.net *.trustpilot.com *.clarity.ms *.cookiebot.com consent.cookiebot.eu consentcdn.cookiebot.eu https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.bootstrapcdn.com 'self' data: *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.zdassets.com *.userway.org 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.paytrace.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.demo.convergepay.com api.convergepay.com gstatic.com *.googletagmanager.com *.twitter.com *.facebook.com https://www.traceparts.com https://player.vimeo.com/ https://vars.hotjar.com/ *.userway.org *.doubleclick.net https://calculator.exair.com/cabinetcooler/calculator/index.php 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.alothemes.com *.magepow.com https://meetanshi.com/media/logo.png www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://bat.bing.com http://t.co/ https://px.ads.linkedin.com http://www.trustlogo.com/ https://ssl.comodo.com https://camo.githubusercontent.com/ https://p.adsymptotic.com/ https://secure.trust-provider.com/ https://c.clarity.ms/c.gif cdn.userway.org *.facebook.net *.facebook.com *.google.com *.google.co.in *.bing.com *.linkedin.com *.google.ca *.twitter.com *.simpli.fi *.doubleclick.net *.tremorhub.com *.3lift.com *.tapad.com *.agkn.com *.intentiq.com *.pubmatic.com *.exelator.com *.yahoo.com *.bfmio.com *.bluekai.com *.crwdcntrl.net *.lijit.com *.rlcdn.com *.spotxchange.com *.adnxs.com *.rubiconproject.com *.openx.net *.pro-market.net *.comodoca.com *.pippio.com *.sectigo.com https://d3k81ch9hvuctc.cloudfront.net/company/XxTZBJ/images/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.alothemes.com *.magepow.com *.paytrace.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com api.demo.convergepay.com api.convergepay.com gstatic.com 'self' data: *.googletagmanager.com tagmanager.google.com https://chimpstatic.com http://bat.bing.com/bat.js https://bat.bing.com/p/action/16008447.js static.ads-twitter.com *.twimg.com https://snap.licdn.com/li.lms-analytics/insight.min.js *.trustlogo.com *.google-analytics.com *.zdassets.com *.ekr.zdassets.com https://analytics.twitter.com exairhelp.zendesk.com https://widget-mediator.zopim.com wss://widget-mediator.zopim.com https://secure.trust-provider.com https://libs.fraud.elavongateway.com/sdk-web-js/0.13.8/3ds2-web-sdk.min.js https://www.convergepay.com/hosted-payments/Checkout.js https://demo.convergepay.com/hosted-payments/Checkout.js *.clarity.ms https://static.hotjar.com/c/hotjar-2555992.js https://script.hotjar.com *.hotjar.com https://edge.fullstory.com/s/fs.js *.fullstory.com *.userway.org *.facebook.net *.doubleclick.net *.bing.com *.linkedin.com https://snap.licdn.com/li.lms-analytics/insight.old.min.js https://static.zdassets.com/web_widget* https://static.zdassets.com/ekr/snippet.js/* *.simpli.fi *.cloudflare.com https://snap.licdn.com/li.lms-analytics/insight.beta.min.js *.truevaultcdn.com *.dcatalog.com *.jquery.com *.termsfeedtag.com https://recruitingbypaycor.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com fonts.google.com *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.googletagmanager.com *.userway.org *.klaviyo.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com *.zdassets.com *.ekr.zdassets.com https://static.zdassets.com/web_widget/latest/fda6cd35495c75f83508d9d2e77ee33d.mp3 *.static.zdassets.com https://static.zdassets.com/web_widget* 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.demo.convergepay.com api.convergepay.com gstatic.com 'unsafe-inline' data: 'unsafe-inline' blob: *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com *.facebook.net *.zdassets.com *.ekr.zdassets.com https://analytics.twitter.com exairhelp.zendesk.com https://widget-mediator.zopim.com wss://widget-mediator.zopim.com https://www.convergepay.com/hosted-payments/service/payment/hpe/process https://demo.convergepay.com/hosted-payments/service/payment/hpe/process https://clarity.microsoft.com/ *.clarity.ms *.hotjar.com *.bing.com *.fullstory.com *.userway.org *.doubleclick.net *.linkedin.com https://static.zdassets.com/web_widget* *.oribi.io *.googlesyndication.com *.truevaultcdn.com *.termsfeedtag.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de player.vimeo.com *.facebook.com *.youtube.com *.youtube-nocookie.com 'self' 'unsafe-inline'; img-src d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cdninstagram.com *.hsforms.net *.hsforms.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com connect.facebook.net *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.klarnacdn.net https://static.klaviyo.com tagmanager.google.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ vimeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com analytics.google.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com *.facebook.net *.facebook.com maxcdn.bootstrapcdn.com *.onlineafspraken.nl *.googletagmanager.com *.feedbackcompany.com issuu.com e.issuu.com *.quantserve.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.addthis.com *.pinimg.com *.hs-scripts.com *.doubleclick.net *.pinterest.com *.facebook.com *.googleapis.com *.googletagmanager.com *.feedbackcompany.com issuu.com e.issuu.com *.quantserve.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.twitter.com *.demdex.net *.google.com www.youtube.com youtu.be *.vimeo.com *.weltpixel.com js.mollie.com *.addthis.com *.pinimg.com *.hs-scripts.com *.doubleclick.net *.pinterest.com *.facebook.com *.googleapis.com *.googletagmanager.com *.feedbackcompany.com issuu.com e.issuu.com *.quantserve.com *.sibautomation.com *.sleak.chat 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.cloudflare.com *.cdninstagram.com *.klarna.com *.demdex.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com youtu.be *.lightemporium.com *.usercentrics.eu *.trustedshops.com *.google.nl *.google.com *.zopim.com *.bing.com c.clarity.ms *.facebook.net *.facebook.com *.vimeo.com https://www.mollie.com *.addthis.com *.pinimg.com *.hs-scripts.com *.doubleclick.net *.pinterest.com *.feedbackcompany.com issuu.com e.issuu.com *.quantserve.com *.sleak.chat *.supabase.co *.webflow.com *.getqonfi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.cloudflare.com *.twitter.com *.sentry-cdn.com *.google-analytics.com *.googleadservices.com *.paypalobject.com *.google.com *.google.nl youtu.be *.googletagmanager.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.amazonaws.com *.zdassets.com *.dassets.com *.diffuse.tools *.yotpo.com *.twimg.com chimpstatic.com *.zopim.com *.newrelic.com *.facebook.net *.facebook.com js.mollie.com *.addthis.com *.pinimg.com *.hs-scripts.com *.doubleclick.net *.pinterest.com *.onlineafspraken.nl *.feedbackcompany.com *.moatads.com *.addthisedge.com issuu.com e.issuu.com *.quantserve.com sibautomation.com *.sibautomation.com *.sleak.chat *.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com *.getqonfi.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com *.addthis.com *.pinimg.com *.hs-scripts.com *.doubleclick.net *.pinterest.com *.facebook.com *.onlineafspraken.nl *.googletagmanager.com *.feedbackcompany.com *.moatads.com *.addthisedge.com issuu.com e.issuu.com *.quantserve.com *.sleak.chat tagmanager.google.com *.getqonfi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.instagram.com *.doubleclick.net *.demdex.net *.cloudflare.com *.twitter.com *.amazonaws.com *.zdassets.com *.paypal.com *.twimg.com *.zopim.com *.sentry.io wss://widget-mediator.zopim.com client.diffuse.tools *.facebook.net *.facebook.com youtu.be *.vimeo.com *.addthis.com *.pinimg.com *.hs-scripts.com *.pinterest.com *.onlineafspraken.nl *.jquery.com *.jsdelivr.net *.googletagmanager.com *.feedbackcompany.com *.moatads.com *.addthisedge.com issuu.com e.issuu.com *.quantserve.com *.brevo.com *.google.com *.sleak.chat https://www.google-analytics.com *.getqonfi.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.onlineafspraken.nl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com *.gstatic.com data: *.oney.io *.staging.oney.io https://fonts.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.hipay-tpp.com *.hipay.com *.paypal.com *.googleapis.com *.weltpixel.com https://thinglink.com/ https://app.usercentrics.eu/ www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.hipay.com *.oney.io *.staging.oney.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://maps.gstatic.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://widgets.trustedshops.com/ https://integrations.etrusted.com/ https://app.usercentrics.eu/ *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.oney.io *.staging.oney.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdnjs.cloudflare.com https://maps.googleapis.com https://widgets.trustedshops.com/ https://integrations.etrusted.com/ https://cdn.thinglink.me/ https://app.usercentrics.eu/ https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.hipay.com *.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://integrations.etrusted.com/ tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.oney.io *.staging.oney.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://nominatim.openstreetmap.org https://integrations.etrusted.com/ https://app.usercentrics.eu/ https://api.usercentrics.eu/ *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; script-src 'self' 'nonce-{RANDOM}' 'strict-dynamic' https://www.googletagmanager.com https://www.google-analytics.com https://js.hubspot.com https://*.hubspot.com https://*.hubspotusercontent-na1.net 'nonce-LXT8QS3tcBlkwKmB15hXoA=='; connect-src 'self' https://*.google-analytics.com https://region1.analytics.google.com https://*.googletagmanager.com https://*.hubspot.com https://*.hubspotusercontent-na1.net; style-src 'self' 'unsafe-inline' https://*.hubspotusercontent-na1.net; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com https://*.hubspot.com https://*.hubspotusercontent-na1.net; font-src 'self' https://*.hubspotusercontent-na1.net; frame-src https://*.hubspot.com https://*.googletagmanager.com; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests 1 default-src 'none'; script-src 'self' 'unsafe-eval'; report-uri https://rycor.report-uri.com/r/t/csp/wizard; connect-src 'self' www.google.com translate.googleapis.com; form-action 'self'; img-src 'self' fonts.gstatic.com www.gstatic.com; style-src-elem 'self' 'unsafe-inline' use.fontawesome.com www.gstatic.com code.jquery.com; frame-src pay.rycor.net www.google.com; script-src-attr 'unsafe-inline'; script-src-elem 'unsafe-inline' www.google.com translate-pa.googleapis.com translate.google.com translate.googleapis.com www.gstatic.com 'self'; style-src-attr 'unsafe-inline'; font-src fonts.gstatic.com use.fontawesome.com 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://www.google.com https://www.gstatic.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://www.google.com https://www.gstatic.com https://libs.na.bambora.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com google.com gstatic.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://cdn.na.bambora.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://www.google-analytics.com https://www.googletagmanager.com https://www.gstatic.com https://www.google.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com google.com gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com google.com gstatic.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trackedlink.net *.klevu.com *.ksearchnet.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://api.addressfinder.io tagmanager.google.com https://www.googletagmanager.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.addressfinder.io https://www.googletagmanager.com tagmanager.google.com *.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://api.addressfinder.io https://www.google-analytics.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; style-src 'self' 'unsafe-inline' *.liveperson.net *.addressy.com *.freshchat.com *.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleconnerce.com *.liveperson.net *.googletagmanager.com *.facebook.net *.googleapis.com bat.bing.com *.google.com connect.facebook.com *.freshchat.com *.google-analytics.com *.googleadservices.com schwaab.oro-cloud.com *.doubleclick.net *.bootstrapcdn.com *.googlecommerce.com *.addressy.com *.lpsnmedia.net; font-src 'self' fonts.gstatic.com; report-uri https://www.stampxpress.com/report.aspx 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com www.apptrian.com scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.cdninstagram.com *.fbcdn.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com https://www.glensoutdoors.com/ https://*.google.com https://*.google.ca https://*.google.ro https://rootways.com https://localhost.glensoutdoors.com https://test.glensarmynavystore.com https://www.googletagmanager.com https://static.garmincdn.com blob: *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.avada.io *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://www.glensoutdoors.com https://test.glensarmynavystore.com https://bit.ly/3NogJdr https://resource.kenect.com/api/v1/widget/client-data/QYmSooOPToIH4X94g03SkG https://*.google.com https://*.google.ro https://*.google.ca https://seal.verisign.com https://rootways.com https://ajax.cloudflare.com https://www.googletagmanager.com https://localhost.glensoutdoors.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://chimpstatic.com 'self' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com www.apptrian.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://get.geojs.io *.avada.io *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com https://www.glensoutdoors.com/ https://www.facebook.com https://localhost.glensoutdoors.com https://www.googletagmanager.com https://www.localhost.glensoutdoors.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.glensoutdoors.com/glens-api/report-csp.php; report-to report-endpoint; 1 default-src 'self' ingest.sentry.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' www.facebook.com www.google.co.uk www.google.com *.googletagmanager.com googleads.g.doubleclick.net *.google-analytics.com maps.googleapis.com widget.trustpilot.com js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.hs-scripts.com js-eu1.hs-analytics.net track-eu1.hubspot.com app-eu1.hubspot.com snap.licdn.com prismic.io px.ads.linkedin.com connect.facebook.net o2.mouseflow.com cdn.mouseflow.com static.cdn.prismic.io adservice.google.com www.google-analytics.com www.googleadservices.com *.amplifyapp.com/ localhost:* sentry.io; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' googleads.g.doubleclick.net snap.licdn.com maps.googleapis.com widget.trustpilot.com www.googletagmanager.com connect.facebook.net js-eu1.hs-analytics.net eu.posthog.com eu-assets.i.posthog.com www.facebook.com www.google.co.uk www.google.com *.googletagmanager.com googleads.g.doubleclick.net *.google-analytics.com maps.googleapis.com widget.trustpilot.com js-eu1.hs-banner.com js-eu1.hscollectedforms.net js-eu1.hs-scripts.com js-eu1.hs-analytics.net track-eu1.hubspot.com app-eu1.hubspot.com snap.licdn.com prismic.io px.ads.linkedin.com connect.facebook.net o2.mouseflow.com cdn.mouseflow.com static.cdn.prismic.io adservice.google.com www.google-analytics.com www.googleadservices.com *.amplifyapp.com/ localhost:* sentry.io; frame-src 'self' app-eu1.hubspot.com sunsave-website.prismic.io td.doubleclick.net widget.trustpilot.com cdn.mouseflow.com flo.uri.sh www.facebook.com www.youtube.com meetings-eu1.hubspot.com sunsave-energy.cal.com; connect-src 'self' *.analytics.google.com *.google-analytics.com *.googletagmanager.com cognito-idp.eu-west-2.amazonaws.com px.ads.linkedin.com forms-eu1.hscollectedforms.net widget.trustpilot.com o2.mouseflow.com connect.facebook.net www.facebook.com o1211967.ingest.sentry.io account-api.sunsave.energy account-api.staging.sunsave.energy join-api.sunsave.energy join-api.staging.sunsave.energy js-eu1.hs-banner.com maps.googleapis.com www.googleadservices.com adservice.google.com www.google.com static.hsappstatic.net prismic.io *.prismic.io ad.doubleclick.net *.amplifyapp.com/ localhost:* internal-e.posthog.com internal-t.posthog.com eu.posthog.com eu.i.posthog.com; img-src 'self' blob: data: *; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.amplifyapp.com/ localhost:* app-static.eu.posthog.com ; frame-ancestors 'self' https://sunsave-website.prismic.io; font-src 'self' data: fonts.gstatic.com cdn.mouseflow.com *.amplifyapp.com/ localhost:*; object-src 'self'; worker-src blob:; base-uri 'self'; form-action 'self' www.facebook.com *.amplifyapp.com/ localhost:*; media-src 'self' https://sunsave-website.cdn.prismic.io; 1 default-src 'self' f24.com *.f24.com; block-all-mixed-content; report-uri https://0ze76053.uriports.com/reports/report; report-to csp-endpoint; manifest-src 'none'; script-src https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com 'self' f24.com *.f24.com 'unsafe-inline'; style-src https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com 'self' f24.com *.f24.com 'unsafe-inline'; img-src www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com 'self' f24.com *.f24.com; font-src https://fonts.gstatic.com data: 'self' f24.com *.f24.com; connect-src www.googletagmanager.com www.google.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com cdn.cookielaw.org 'self' f24.com *.f24.com; frame-ancestors 'none'; 1 default-src 'self'; script-src 'self' https: 'unsafe-inline' 'report-sample'; style-src 'self' https: 'unsafe-inline' 'report-sample'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests 1 default-src https:; connect-src *; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; 1 font-src www.paypalobjects.com *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.googleapis.com *.gstatic.com *.mlstatic.com *.mercadopago.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.mercadopago.com *.mercadolibre.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com js.stripe.com *.awin1.com *.zenaps.com *.fls.doubleclick.net facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sendcloud.sc *.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.awin1.com *.zenaps.com *.wepowerconnections.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net maps.gstatic.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.scalapay.com *.sendcloud.sc *.jsdelivr.net tracking.trovaprezzi.it www.trovaprezzi.it *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com *.feedbackcompany.com *.googleapis.com https://www.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.feedbackcompany.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.feedbackcompany.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com https://www.google.nl https://imgsct.cookiebot.com https://benem.nl https://bat.bing.com https://bat.bing.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.feedbackcompany.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.shopify.com https://consentcdn.cookiebot.com https://consent.cookiebot.com https://www.smartsuppchat.com https://widget-v3.smartsuppcdn.com https://bat.bing.com https://www.clarity.ms js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com downloads.mailchimp.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net https://widget-v3.smartsuppcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com https://stats.g.doubleclick.net *.googlesyndication.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.feedbackcompany.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io https://www.postcode-checkout.nl https://consent.cookiebot.com https://googleads.g.doubleclick.net https://consentcdn.cookiebot.com https://smartsuppcdn.com https://bootstrap.smartsuppchat.com https://widget-v3.smartsuppcdn.com https://translations.smartsuppcdn.com/ wss://websocket-visitors.smartsupp.com https://q.clarity.ms https://bat.bing.net https://o.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://ipgtest.monri.com/ https://ipg.monri.com/ https://formtest.wspay.biz/ https://form.wspay.biz/ *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://ipgtest.monri.com/ https://ipg.monri.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://www.facebook.com/ https://connect.facebook.net/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.shopify.com https://ipgtest.monri.com/ https://ipg.monri.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://static.elfsight.com/ https://connect.facebook.net/ https://www.facebook.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://ipgtest.monri.com/ https://ipg.monri.com/ assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com places.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com https://core.service.elfsight.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.fontawesome.com *.cloudflare.com *.matcha.wine *.avis-verifies.com *.doofinder.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.avis-verifies.com *.cookiebot.com *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.doofinder.com *.mainadv.com *.redintelligence.net *.pinterest.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com www.googletagmanager.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org cdn.doofinder.com *.cloudflare.com *.matcha.wine *.avis-verifies.com bat.bing.com lantern.roeye.com imgsct.cookiebot.com www.zenaps.com www.awin1.com trc.taboola.com *.doofinder.com *.google.fr *.googlesyndication.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com *.cloudflare.com *.matcha.wine *.avis-verifies.com *.cookiebot.com *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.doofinder.com *.bing.com *.roeyecdn.com *.advcredirect.com *.clarity.ms *.pinimg.com *.pinterest.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.fontawesome.com *.cloudflare.com *.matcha.wine *.avis-verifies.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com *.doofinder.com wss://*.doofinder.com *.cloudflare.com *.matcha.wine *.avis-verifies.com *.cookiebot.com *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com psb.taboola.com pips.taboola.com cds.taboola.com bat.bing.com lantern.roeye.com lantern.roeyecdn.com mainadv.com widget.trustpilot.com region1.analytics.google.com sb.advcredirect.com *.redintelligence.net mpc-prod-18-s6uit34pua-uc.a.run.app demo-1.conversionsapigateway.com www.google.com www.google.fr *.clarity.ms *.googlesyndication.com *.pinterest.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ science.cem.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com 'self' *.s3.amazonaws.com *.svc.dynamics.com *.clarity.ms *.bing.com cem.com *.cem.com 'unsafe-inline' https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com 'self' *.clarity.ms www.clarity.ms *.marketo.net bid.g.doubleclick.net www.google.com *.avada.io *.shopify.com mktdplp102cdn.azureedge.net 'unsafe-eval' 'unsafe-hashes' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.googleapis.com 'self' *.mktoresp.com *.google.com googleads.g.doubleclick.net *.googlesyndication.com *.avada.io *.shopify.com mktdplp102cdn.azureedge.net https://get.geojs.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.cem.com/; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ioteams.com https://hm.baidu.com https://assets.growingio.com https://res.wx.qq.com; report-uri https://m.sre.videoteams.cn:8043/monitor/csp-report.htm 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com maps.googleapis.com *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-uri https://e4beab92-39ea-454f-9ce8-34b635081f44.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com www.searchanise.com *.searchserverapi.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.facebook.net *.canadapost.ca https://sso.epost.ca www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com *.facebook.com *.facebook.net www.searchanise.com *.searchserverapi.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com www.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.jivosite.com *.convertcart.com *.naturalpigments.com yotpo-editor-production.s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.facebook.com *.facebook.net https://img.youtube.com mageside.com *.canadapost.ca *.canadapost-postescanada.ca www.facebook.com https://meetanshi.com/media/logo.png *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.attn.tv events.attentivemobile.com *.klaviyo.com *.jivosite.com *.convertcart.com *.jsdelivr.net *.googleadservices.com *.google-analytics.com *.assets.adobedtm.com *.doubleclick.net *.googletagmanager.com *.cardinalcommerce.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.facebook.com *.facebook.net *.avada.io connect.facebook.net searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.instagram.com maps.googleapis.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.jivosite.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com *.jivosite.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.attn.tv events.attentivemobile.com *.jivosite.com *.convertcart.com wss://vi-ya-5.jivosite.com *.naturalpigments.com *.naturalpigments.eu *.naturalpigments.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io api.amplitude.com stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.doubleclick.net https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com https://*.gstatic.com data: https://*.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.typekit.net *.klarnacdn.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.doubleclick.net https://*.braintreegateway.com https://*.paypal.com https://*.trustpilot.com https://*.salesfire.co.uk https://*.google.com https://*.hotjar.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.paypal.com https://*.salesfire.co.uk https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.reviews.io *.reviews.co.uk *.salesfire.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com https://www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.cloudfront.net https://*.google-analytics.com https://*.doubleclick.net https://*.paypal.com https://*.trustpilot.com https://*.salesfire.co.uk https://*.smartmetrics.co.uk https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://secure.leadforensics.com https://*.googleapis.com *.klevu.com *.ksearchnet.com *.avada.io *.shopify.com *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://js.klevu.com https://www.heamar.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://*.cloudfront.net https://*.googleapis.com https://*.salesfire.co.uk https://*.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com https://www.heamar.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://dashboard.cwarmer.io/api/matrix https://*.freshdesk.com https://*.hotjar.com wss://*.hotjar.com https://*.googleapis.com api.addressy.com https://*.adobedc.net https://*.nr-data.net *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.smartmetrics.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: logger.scot.nhs.uk *.fontawesome.com use.typekit.net *.google.com *.google.co.uk *.googleapis.com themes.googleusercontent.com *.gstatic.com code.jquery.com yui.yahooapis.com *.bootstrapcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com www.youtube-nocookie.com player.vimeo.com i.vimeocdn.com cdn.jwplayer.com content.jwplatform.com prd.jwpltx.com *.jwpcdn.com *.jwpsrv.com *.civiccomputing.com cc.cdn.civiccomputing.com secure.gravatar.com public.tableau.com www.openstreetmap.org browser-update.org s.w.org www.geoplugin.net *.wp.com hcaptcha.com *.hcaptcha.com www.careopinion.org.uk www.patientopinion.org.uk assets.nhs.uk www.travelinescotland.com www.travelinescotland.com www.nhsgrampian.com www.nhsgrampian.co.uk nhsgrampian.org *.nhsgrampian.org walkit.com nhs.attendanywhere.com; worker-src 'self' www.google.com; frame-ancestors 'self'; base-uri 'self'; report-to csp-endpoint; report-uri https://web-reports.scot.nhs.uk/api/v1/csp-report 1 font-src http://maxcdn.bootstrapcdn.com/font-awesome/ https://widgets.trustedshops.com/ https://fonts.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://widgets.trustedshops.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.facebook.com/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://www.google.com/recaptcha/ https://www.facebook.com/ https://bid.g.doubleclick.net/ https://www.youtube.com/ https://gum.criteo.com/ https://static.criteo.net/ https://config1.veinteractive.com/ *.google.com/ https://www.youtube.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://widgets.trustedshops.com/ https://www.facebook.com/ https://connect.facebook.net/ https://www.google.com/pagead/ https://www.google.de/pagead/ https://www.google.com/ads/ https://www.google.de/ads/ https://googleads.g.doubleclick.net/ https://stats.g.doubleclick.net/ https://www.gstatic.com/ https://ssl.gstatic.com/ https://www.google-analytics.com/ https://www.google.com/ https://bat.bing.com/ https://files.newsletter2go.com/ https://ad.mail.ru/ https://ads.yieldmo.com/ https://sync-criteo.ads.yieldmo.com/ https://ad.sxp.smartclip.net/ https://pixel.rubiconproject.com/ https://gum.criteo.com/ https://sp.analytics.yahoo.com/ https://s.ad.smaato.net/ https://i.liadm.com/ https://i6.liadm.com/ https://sync.outbrain.com/ https://sync.e-planning.net/ https://sync-t1.taboola.com/ https://ib.adnxs.com/ https://simage2.pubmatic.com/ https://visitor.omnitagjs.com/ https://cm.adform.net/ https://beacon.krxd.net/ https://dis.criteo.com/ https://cm.g.doubleclick.net/ https://criteo-sync.teads.tv/ https://secure.adnxs.com/ https://ad.360yield.com/ https://match.sharethrough.com/ https://rtb-csync.smartadserver.com/ https://r.casalemedia.com/ https://ads.yahoo.com/ https://ups.analytics.yahoo.com/ https://pixel.advertising.com/ https://us-u.openx.net/ https://eb2.3lift.com/ https://contextual.media.net/ https://cotads.adscale.de/ https://ih.adscale.de/ https://tg.socdm.com/ https://x.bidswitch.net/ https://ad.yieldlab.net https://ads.stickyadstv.com/ https://cdn.stickyadstv.com/ https://idsync.rlcdn.com/ https://jadserve.postrelease.com/ https://criteo-partners.tremorhub.com/ https://pixel.tapad.com/ https://s.thebrighttag.com/ https://www.magezon.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.google.com/ https://www.gstatic.com/recaptcha/ https://connect.facebook.net https://www.googletagmanager.com/ https://tagmanager.google.com/ http://widgets.trustedshops.com/ https://googleads.g.doubleclick.net/ https://www.google-analytics.com/ https://ssl.google-analytics.com/ https://www.google.com/ https://www.googleadservices.com/ https://bat.bing.com/ https://secure.pay1.de/ https://static.newsletter2go.com/ https://sslwidget.criteo.com/ https://top-fwz1.mail.ru/ https://static.criteo.net/ https://config1.veinteractive.com/ https://autocomplete2.postdirekt.de/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com http://maxcdn.bootstrapcdn.com/font-awesome/ https://tagmanager.google.com/ https://fonts.googleapis.com/ *.fontawesome.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://api.newsletter2go.com/ https://top-fwz1.mail.ru/ https://www.paypal.com/ https://www.facebook.com/ https://autocomplete2.postdirekt.de/ autocomplete2.postdirekt.de *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src *.force.com slack-imgs-mil-dev.com 'self' https://stats.g.doubleclick.net https://img.youtube.com https://payments.salesforce.com/icons/ https://clients.smartsecure.tsys.co.uk:443 https://login.salesforce.com/icons/ https://*.springcm.com https://acs.apata.io https://3ds-a.live.ext.prod.enfuce.com https://www.gstatic.com *.slack-edge-gov.com *.my-salesforce.com https://danskebank-3ds-vdm.wlp-acs.com *.cloudinary.com https://mycardsecure.com https://api.ipify.org https://sccb--c.um5.visual.force.com *.amazonaws.com https://www.rsa3dsauth.co.uk blob: https://sccb--llc-bi.um5.visual.force.com https://santander.freightos.cn https://cdn-ukwest.onetrust.com slack-imgs.com slack-gov-dev.com https://verify.monzo.com *.sfdcstatic.com https://*.arcot.com *.twimg.com https://acs.revolut.com https://sccb.file.force.com https://*.docusign.net https://api.mixpanel.com *.slack.com https://www.paypal.com *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://www.securesuite.co.uk https://*.clm.docusign.mil https://channel-cards-html.lloydsbankinggroup.com https://eu51.salesforce.com/icons/ slack-imgs-gov-dev.com *.slack-edge.com https://santander.freightos.com https://3ds-b.live.ext.prod.enfuce.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://geolocation.onetrust.com https://sccb.my.salesforce.com https://live.sagepay.com https://*.mpts.modirum.com https://www.santandernavigator.co.uk https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://sccb--c.documentforce.com https://*.clmfed.docusign.com https://i.vimeocdn.com https://vimeo.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://acs.airplus.com https://*.rsa3dsauth.co.uk https://authentication.cardinalcommerce.com https://*.adyen.com slack-imgs.mil https://authentication-acs.marqeta.com data:; report-to sfdc-csp-ep; report-uri https://sccb.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D0Y000000YCdJ&networkId=0DM4J0000008nyc&type=communities 1 default-src 'self'; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.hsforms.net/forms/ https://*.hsforms.com/embed/ https://sdk.privacy-center.org https://www.clarity.ms https://www.google-analytics.com/analytics.js https://cdn.amplitude.com https://*.google-analytics.com https://*.hsadspixel.net https://*.hscollectedforms.net https://*.hs-banner.com https://*.hs-analytics.net https://*.hs-scripts.com https://*.clarity.ms https://www.youtube.com/ https://ws.zoominfo.com https://snap.licdn.com https://connect.facebook.net https://static.ads-twitter.com https://platform.twitter.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://cdn.amplitude.com https://code.jquery.com https://www.google.com https://www.googletagmanager.com https://j.6sc.co https://s.adroll.com https://d.adroll.com https://cdn.cookielaw.org https://www.workable.com https://apply.workable.com https://dcvxs6ggqztsa.cloudfront.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com; img-src 'self' https://cybelangel.com https://*.cybelangel.com https://d.adroll.com https://b.6sc.co https://eb2.3lift.com https://*.3lift.com https://image2.pubmatic.com https://*.pubmatic.com https://sync.taboola.com https://*.taboola.com https://pixel.rubiconproject.com https://*.rubiconproject.com https://dsum-sec.casalemedia.com https://*.casalemedia.com https://pixel.tapad.com https://*.tapad.com https://ml314.com https://*.ml314.com https://www.google.com https://www.google.fr https://*.hsforms.com/embed/ https://secure.gravatar.com https://www.googletagmanager.com https://track-eu1.hubspot.com https://forms-eu1.hsforms.com https://forms-eu1.hscollectedforms.net https://px.ads.linkedin.com https://px4.ads.linkedin.com https://www.facebook.com https://t.co https://analytics.twitter.com https://syndication.twitter.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://login.dotomi.com https://i.ytimg.com https://i.imgur.com https://media.discordapp.net https://cdn.discordapp.com https://ssl.gstatic.com https://translate.google.com data: blob:; font-src 'self' https://fonts.gstatic.com https://use.typekit.net https://cdn.fontshare.com https://cdn.megabonus.com https://static.zohocdn.com https://cdn.scite.ai https://cdn.faceworks.nl https://assets.faircado.com https://migaku-public-data.migaku.com https://unpkg.com data: chrome-extension: moz-extension:; connect-src 'self' https://*.hsforms.com/embed/ https://*.clarity.ms/ https://www.google-analytics.com https://region1.google-analytics.com https://js-eu1.hscollectedforms.net https://forms-eu1.hscollectedforms.net https://api2.amplitude.com https://ws.zoominfo.com https://px.ads.linkedin.com https://www.facebook.com https://pagead2.googlesyndication.com https://fonts.gstatic.com https://fonts.googleapis.com https://code.jquery.com https://www.google.com https://translate.google.com https://www.googletagmanager.com https://www.googleadservices.com https://www.google.fr https://ipv6.6sc.co https://d.adroll.com/ https://c.6sc.co https://api.privacy-center.org https://cdn.cookielaw.org data: sentry.beapi.fr; media-src 'self' https://ssl.gstatic.com data:; frame-src 'self' https://www.youtube.com https://www.google.com/recaptcha/ https://www.linkedin.com https://platform.twitter.com https://www.googletagmanager.com chrome-error:; worker-src 'self' blob:; manifest-src 'self'; object-src 'self'; base-uri 'self'; frame-ancestors 'self'; report-to csp-endpoint; report-uri https://sentry.beapi.fr/api/7/security/?sentry_key=a138dbe1a2fb42d0e8c2f51ebaa59f74&sentry_environment=production; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *; img-src https://*.earthdata.nasa.gov https://*.vis.earthdata.nasa.gov https://tile.openstreetmap.org/; script-src-elem https://cdn.jsdelivr.net/npm/ol@v7.2.2/dist/ol.js; style-src-elem https://cdn.jsdelivr.net/npm/ol@v7.2.2/ol.css 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net https://static.klaviyo.com *.watson.appdomain.cloud data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com *.googletagmanager.com *.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.bing.com *.pinterest.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cookielaw.org *.bing.com *.facebook.net *.pinimg.com *.hotjar.com *.pinterest.com cdn.jsdelivr.net *.watson.appdomain.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://static.klaviyo.com https://static-tracking.klaviyo.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cookielaw.org *.pinterest.com *.googlesyndication.com *.bing.com *.google-analytics.com *.hotjar.com *.hotjar.io *.watson.appdomain.cloud 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://www.googletagmanager.com https://imgsct.cookiebot.com https://www.facebook.com https://www.google.es https://www.google-analytics.com https://t.co https://analytics.twitter.com https://www.google.co.nz https://www.google.co.ve https://adservice.google.com https://region1.google-analytics.com https://www.google.co.uk https://www.google.com.pe https://i.liadm.com https://www.google.no https://i.ytimg.com https://www.google.com.ph https://www.google.com.ar https://www.google.com.co https://www.google.fr https://www.google.com.bo https://www.google.com.cu https://www.google.hn https://www.fcarreras.org https://www.google.com.mx https://www.google.com.eg https://www.google.pl https://www.google.ch https://www.google.cl https://www.google.com.sv https://www.google.co.kr https://www.google.com.ec https://www.google.de https://sync.intentiq.com https://www.google.com.pa https://www.google.com.do https://www.google.pt https://www.google.com.au https://www.google.com.ni https://trc.taboola.com https://www.google.com.tr https://analytics.google.com https://stats.g.doubleclick.net https://translate.google.com blob: https://www.google.com.pr https://googleads.g.doubleclick.net https://www.google.co.za https://www.google.co.id https://www.google.com.py https://fcarreras.org https://www.google.at https://fonts.gstatic.com https://www.google.nl https://www.google.ad https://www.google.co.cr https://www.google.com.uy https://www.google.ca https://www.google.com.hk https://www.google.co.ma https://www.google.com.gt https://www.google.com.my https://www.google.ru https://ad.doubleclick.net https://www.google.al https://www.google.com.br https://www.google.ie https://www.google.it https://analytics.pangle-ads.com https://analytics.tiktok.com https://www.google.co.in https://www.google.lu https://www.google.dk https://www.google.co.zm https://www.google.co.ao https://www.google.com.ua https://live.primis.tech https://www.google.gr https://www.google.ro https://www.google.com.fj https://www.google.com.kh https://www.google.com.lb https://www.google.lv https://www.google.com.ng https://www.google.ge https://www.google.co.il https://www.google.se android-webview https://www.google.com.et https://www.google.cz https://www.google.com.kw https://www.google.sn https://www.google.co.th https://www.google.com.gh https://www.google.hu https://www.google.ae https://www.google.co.jp https://www.google.mk https://www.google.be https://region1.analytics.google.com https://www.google.com.sg https://www.google.ml https://www.google.com.pk https://www.google.co.zw https://www.google.co.ug https://www.google.lk https://www.google.co.ke https://www.google.by https://www.google.tl https://www.google.rs https://www.google.com.vc https://www.google.tn https://www.google.cm https://www.google.com.qa https://www.google.cv https://www.google.co.tz https://www.googleadservices.com https://www.google.com.na https://connect.facebook.net https://www.google.ee https://www.google.com.vn https://tr.outbrain.com https://cdn.honey.io https://www.google.com.sa https://www.google.bg https://www.google.jo https://www.google.ci https://www.google.iq https://www.google.com.ly https://s01.europapress.net https://www.google.ga https://mc.yandex.ru https://sync1.intentiq.com https://www.google.az https://www.google.com.gi https://tpcs.payu.in https://www.google.is https://www.google.co.uz https://www.google.cn https://www.google.com.bd https://www.google.cf https://www.google.so https://www.google.mu https://www.google.dz https://www.google.com.np https://www.google.ps https://www.google.com.sl https://pos.baidu.com https://www.google.com.jm https://www.google.com.cy https://www.rtve.es https://www.google.com.bz https://www.google.com.bh https://www.google.bs https://www.google.bj https://www.google.kz https://www.google.li https://www.google.co.mz https://www.google.sk https://www.google.sc https://adminmenueditor.com https://www.gstatic.com https://www.google.com.tw https://www.google.bf https://updates.themepunch-ext-c.tools https://cdn.leanlibrary.app https://www.google.mv https://www.google.si https://www.google.cd https://www.google.rw https://www.google.tt https://www.google.com.mt https://www.google.md https://www.reprintsdesk.com https://www.researchsolutions.com https://s3.amazonaws.com https://www.google.gg https://www.google.gm https://www.google.me https://test.fcarreras.org https://blocks.jupiterx.com https://www.google.hr https://keepupnews.org https://www.google.ba https://www.google.je https://storage.googleapis.com https://www.descubrir.com https://library.elementor.com https://ce.lijit.com https://u.openx.net https://ad.360yield.com https://surfe.be https://px.ads.linkedin.com https://c.clarity.ms https://tr.line.me https://tr.charleskeith.co.th https://i6.liadm.com https://pixel.quantserve.com https://stamp.wma.comb.es https://www.google.lt https://www.google.mn https://www.google.com.ag https://static.gamezop.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://consent.cookiebot.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://llamamegratis.es https://www.google-analytics.com https://analytics.tiktok.com https://cdn.taboola.com https://static.addtoany.com https://wave.outbrain.com https://trc.taboola.com https://tr.outbrain.com https://connect.facebook.net https://googleads.g.doubleclick.net https://static.ads-twitter.com https://static.hotjar.com https://amplify.outbrain.com https://script.hotjar.com https://www.youtube.com https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://apis.google.com https://www.googleadservices.com https://me.kis.v2.scr.kaspersky-labs.com https://data1.vulapo.com https://data1.thetto.com https://data1.griloup.com https://negbar.ad-blocker.org https://data1.hatolep.com https://www.pagespeed-mod.com https://ssl.google-analytics.com https://savingsslider-a.akamaihd.net https://ff.kis.v2.scr.kaspersky-labs.com https://www.google.com https://data1.muarrf.com https://gc.kes.v2.scr.kaspersky-labs.com https://data1.app-fast.com http://amplify.outbrain.com https://conoret.com https://mstat.acestream.net https://data1.gestona.com https://fcarreras.org https://ytskip.b-cdn.net https://ams.wpml.org https://data1.phistouquet.com https://cdn.reskyt.com https://data1.limclir.com https://editor-static-bucket.elementor.com https://accounts.google.com https://translate.google.com https://translate.googleapis.com https://lazyload.org https://player.vimeo.com https://s3.amazonaws.com https://s.pinimg.com https://ct.pinterest.com https://data1.blicot.com data: https://data1.imc-peso.com blob: https://infimv.com https://pagead2.googlesyndication.com https://sc-static.net https://farmatodo.api.useinsider.com https://js.appboycdn.com https://dynamic.criteo.com https://apps.bazaarvoice.com https://snap.licdn.com https://tr.charleskeith.co.th https://www.clarity.ms https://d.line-scdn.net https://charleskeithth.api.useinsider.com https://atag.adgile.media https://websdk.appsflyer.com https://static.zdassets.com https://pixel.mathtag.com https://s.zzcdn.me https://secure.quantserve.com https://tags.creativecdn.com https://static.usizy.es https://p2s.boyner.com.tr https://vsh.visilabs.net https://rules.quantcount.com https://belcorpbrand.api.useinsider.com https://cdn.treasuredata.com https://tag.goadopt.io https://cdn.logr-ingest.com https://app.varify.io https://survey.survicate.com https://assets-cdn.woowup.com https://cdn.embluemail.com https://surveys-static.survicate.com https://ipmeta.io https://bat.bing.com https://init.blackcrow.ai https://www.artfut.com https://s.yimg.com https://static.criteo.net https://analytics.webgains.io https://infirc.com https://secure-cdn.mplxtms.com https://cdn.cookielaw.org 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.gstatic.com/recaptcha/ https://consent.cookiebot.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://llamamegratis.es https://www.google-analytics.com https://analytics.tiktok.com https://cdn.taboola.com https://static.addtoany.com https://wave.outbrain.com https://trc.taboola.com https://tr.outbrain.com https://connect.facebook.net https://googleads.g.doubleclick.net https://static.ads-twitter.com https://static.hotjar.com https://amplify.outbrain.com https://script.hotjar.com https://www.youtube.com https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://apis.google.com https://www.googleadservices.com https://me.kis.v2.scr.kaspersky-labs.com https://data1.vulapo.com https://data1.thetto.com https://data1.griloup.com https://negbar.ad-blocker.org https://data1.hatolep.com https://www.pagespeed-mod.com https://ssl.google-analytics.com https://savingsslider-a.akamaihd.net https://ff.kis.v2.scr.kaspersky-labs.com https://www.google.com https://data1.muarrf.com https://gc.kes.v2.scr.kaspersky-labs.com https://data1.app-fast.com http://amplify.outbrain.com https://conoret.com https://mstat.acestream.net https://data1.gestona.com https://fcarreras.org https://ytskip.b-cdn.net https://ams.wpml.org https://data1.phistouquet.com https://cdn.reskyt.com https://data1.limclir.com https://editor-static-bucket.elementor.com https://accounts.google.com https://translate.google.com https://translate.googleapis.com https://lazyload.org https://player.vimeo.com https://s3.amazonaws.com https://s.pinimg.com https://ct.pinterest.com https://data1.blicot.com data: https://data1.imc-peso.com blob: https://infimv.com https://pagead2.googlesyndication.com https://sc-static.net https://farmatodo.api.useinsider.com https://js.appboycdn.com https://dynamic.criteo.com https://apps.bazaarvoice.com https://snap.licdn.com https://tr.charleskeith.co.th https://www.clarity.ms https://d.line-scdn.net https://charleskeithth.api.useinsider.com https://atag.adgile.media https://websdk.appsflyer.com https://static.zdassets.com https://pixel.mathtag.com https://s.zzcdn.me https://secure.quantserve.com https://tags.creativecdn.com https://static.usizy.es https://p2s.boyner.com.tr https://vsh.visilabs.net https://rules.quantcount.com https://belcorpbrand.api.useinsider.com https://cdn.treasuredata.com https://tag.goadopt.io https://cdn.logr-ingest.com https://app.varify.io https://survey.survicate.com https://assets-cdn.woowup.com https://cdn.embluemail.com https://surveys-static.survicate.com https://ipmeta.io https://bat.bing.com https://init.blackcrow.ai https://www.artfut.com https://s.yimg.com https://static.criteo.net https://analytics.webgains.io https://infirc.com https://secure-cdn.mplxtms.com https://cdn.cookielaw.org ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://llamamegratis.es https://me.kis.v2.scr.kaspersky-labs.com https://gc.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com http://fonts.googleapis.com https://fcarreras.org https://www.gstatic.com https://cdn.honey.io https://ams.wpml.org https://www.googletagmanager.com https://cdn.jsdelivr.net https://surveys-static.survicate.com ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://llamamegratis.es https://me.kis.v2.scr.kaspersky-labs.com https://gc.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com http://fonts.googleapis.com https://fcarreras.org https://www.gstatic.com https://ams.wpml.org https://www.googletagmanager.com https://cdn.jsdelivr.net https://surveys-static.survicate.com ; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com https://cdnjs.cloudflare.com https://cdn.goin.cloud https://cdn-uicons.flaticon.com https://cdn.blerp.com https://cdn.scite.ai moz-extension https://static.zohocdn.com chrome-extension https://fcarreras.org https://www.slant.co https://app.escribelo.ai https://aceify.ai http://themes.googleusercontent.com https://cdn.megabonus.com data:; frame-src 'self' https://consentcdn.cookiebot.com https://td.doubleclick.net https://static.addtoany.com https://tsdtocl.com https://cdn.taboola.com https://www.youtube.com https://cdn.knightlab.com https://maps.google.com https://www.google.com https://www.googletagmanager.com https://e.issuu.com https://cdncache-a.akamaihd.net http://notify.bluecoat.com https://assistance.quantumadblocker.com https://block.opendns.com https://www.ciuvo.com https://global.acs.prismaaccess.com https://llamamegratis.es https://santjosepobrer.imtlazarus.com https://www.facebook.com https://mozbar.moz.com https://myaccount.google.com https://www.carrerasresearch.org https://gateway.zscloud.net https://translate.googleapis.com https://r.zozezop.com https://emet.news https://emet.live https://acestream.tv https://ct.pinterest.com https://aldapeta.imtlazarus.com https://feedback-pa.clients6.google.com https://sanignacio.imtlazarus.com mailto https://gateway.zscalertwo.net https://td.doubleclick.net.fvhs2nchnr2gm4lzgzfte4tfnbudamtj.redirect.b1tdc.infoblox.com https://sase.merck.com gsa://onpageload https://charleskeithth.api.useinsider.com https://gum.criteo.com https://farmatodo.api.useinsider.com http://192.168.128.141 http://www.youtube.com.x.987f63ec0f4dc04bf40a5500eff7ec16bc93.ccc2ef7d.id.opendns.com blob:; connect-src 'self' https://analytics.tiktok.com https://pips.taboola.com https://region1.analytics.google.com https://consentcdn.cookiebot.com https://www.google.com https://stats.g.doubleclick.net https://www.facebook.com https://region1.google-analytics.com https://cds.taboola.com https://tr.outbrain.com https://www.google-analytics.com https://analytics.pangle-ads.com https://trc-events.taboola.com https://analytics.google.com https://vc.hotjar.io https://adservice.google.com https://googleads.g.doubleclick.net https://api.mkmediaworks.com https://skincareadvertsking.com https://assistance.quantumadblocker.com https://metrics.hotjar.io properties https://yoast.com https://translate.googleapis.com https://api.intentiq.com https://api.verdevisionresearch.com https://stats.addtoany.com https://pagead2.googlesyndication.com https://overbridgenet.com http://uc.gre http://pluginx.uc.local https://psb.taboola.com https://savingsslider-a.akamaihd.net https://ajax.googleapis.com https://api.solarspireconsulting.com https://api.ultimateaderaser.com https://stickyid-a.akamaihd.net https://api.blocksly.org https://api.amcreativemedia.com https://www.googleadservices.com https://api.ciuvo.com https://metrics-dra.dt.dbankcloud.cn https://api.redirects-4.com https://translate-pa.googleapis.com data: https://api.global-data-lab.com https://ams.wpml.org https://api.freevideoguard.org https://rktstats.reskyt.com https://api.fbanalytics.org https://infragrid.v.network https://metrics-dre.dt.dbankcloud.cn https://api.adblocking247.com https://api.solaranalyticscorp.com https://api.range-offer.com https://ct.pinterest.com https://www.googletagmanager.com https://use.fontawesome.com https://amplify.outbrain.com https://analytics.twitter.com https://t.co https://api.aituria.com https://fonts.googleapis.com https://llamamegratis.es http://ad.doubleclick.net https://static.addtoany.com https://get663.com http://148.153.18.0 https://px.ads.linkedin.com https://atag.adgile.media https://ekr.zdassets.com https://charleskeithth.zendesk.com https://q.clarity.ms https://zendesk-eu.my.sentry.io https://x.clarity.ms https://p.clarity.ms https://wa.onelink.me https://sdk.iad-06.braze.com https://wa.appsflyer.com https://v.clarity.ms https://t.clarity.ms https://api.finemob.com https://myip.duoduodev.com https://api.vid-adblocker.com https://ams.creativecdn.com https://usizy.com https://u.clarity.ms https://b.clarity.ms https://api.bigdatacloud.net https://cdp.in.treasuredata.com https://disclaimer-api.goadopt.io https://api.socialsolutionapp.com https://lb.eu-1-id5-sync.com https://fonts.gstatic.com https://aiqua-sdk.c.appier.net https://analyticsgroupcom.bnpparibas.com https://id5-sync.com https://rp.liadm.com https://tr.snapchat.com https://s.clarity.ms; worker-src 'self' blob: data:; media-src 'self' data: https://updates.themepunch-ext-c.tools; object-src 'self' https://static.issuu.com https://www.tv3.cat http://www.irtve.es; report-uri https://fcarreras.org/en/wp-json/rsssl/v1/csp?rsssl_apitoken=844942300; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.certcapture.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.com *.listrakbi.com *.sharethis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.listrakbi.com *.sharethis.com https://www.google.com https://maps.googleapis.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com assets.braintreegateway.com https://fonts.googleapis.com https://cdn.listrakbi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.certcapture.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com *.sharethis.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e642b22f-d607-4621-92e1-03494fa44c2a.sansec.watch/; report-to report-endpoint; 1 default-src https: ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test processing.psmock.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.two.inc *.sandbox.two.inc *.demo.two.inc *.staging.two.inc *.release.two.inc *.experimental.two.inc *.perf.two.inc *.cyber.two.inc *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.buildingmaterials.co.uk paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test *.trustpilot.com processing.psmock.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://images.unsplash.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bing.com *.bing.net *.google.co.uk *.roeye.com cdn-cookieyes.com *.dynamicyield.com *.dynamicyield.eu paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test www.feedoptimise.com cdn.feedoptimise.com services.postcodeanywhere.co.uk processing.psmock.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://gtm.buildingmaterials.co.uk data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.bing.com *.bing.net *.mediahawk.co.uk *.noibu.com *.roeyecdn.com *.hotjar.com cdn-cookieyes.com *.dynamicyield.com *.dynamicyield.eu https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/* cdnjs.cloudflare.co m/ajax/libs/clipboard.js/* paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test www.feedoptimise.com cdn.feedoptimise.com api.addressy.com *.trustpilot.com processing.psmock.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://gtm.buildingmaterials.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.dynamicyield.com *.dynamicyield.eu https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/* paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test api.addressy.com processing.psmock.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.bing.com *.bing.net *.mediahawk.co.uk *.buildingmaterials.co.uk *.googlesyndication.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.dynamicyield.com *.dynamicyield.eu *.dy-api.com *.dy-api.eu paymentpage.ecommpay.com paymentpage.westresscode.net pp.terminal.test api.addressy.com processing.psmock.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.two.inc *.sandbox.two.inc *.demo.two.inc *.staging.two.inc *.release.two.inc *.experimental.two.inc *.perf.two.inc *.cyber.two.inc *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://gtm.buildingmaterials.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.two.inc *.sandbox.two.inc *.demo.two.inc *.staging.two.inc *.release.two.inc *.experimental.two.inc *.perf.two.inc *.cyber.two.inc 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://*.gstatic.com https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://*.googleapis.com https://*.googleusercontent.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com test.transafe.com post.live.transafe.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://player.vimeo.com https://www.youtube-nocookie.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://player.vimeo.com https://www.youtube.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com downloads.mailchimp.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.creditvidya.com *.prefr.com *.google-analytics.com google-analytics.com google-analytics.com/collect google-analytics.com/analytics.js; frame-src 'self' *.creditvidya.com *.prefr.com google-analytics.com google-analytics.com/collect google-analytics.com/analytics.js; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.creditvidya.com *.prefr.com *.googletagmanager.com googletagmanager.com *.google-analytics.com google-analytics.com/collect google-analytics.com/analytics.js ajax.googleapis.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.creditvidya.com *.prefr.com *.googletagmanager.com googletagmanager.com *.google-analytics.com google-analytics.com/collect google-analytics.com/analytics.js ajax.googleapis.com; img-src 'self' *.creditvidya.com *.prefr.com *.google-analytics.com data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.creditvidya.com *.prefr.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com *.creditvidya.com *.prefr.com; font-src 'self' fonts.gstatic.com *.creditvidya.com *.prefr.com data:; report-to /_/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.multisafepay.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com https://www.correios.com.br 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com *.mercadolibre.com www.facebook.com www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com www.youtube.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.mlstatic.com *.mercadopago.com *.pagseguro.com.br maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.mercadopago.com *.mercadolibre.com https://ws.correios.com.br cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://cdn.coaster-count.com; base-uri 'self'; frame-ancestors 'self'; frame-src 'self' https://www.google.com https://maps.google.com https://maps.google.de https://rcdb.com https://www.rcdb.com https://*.rcdb.com https://www.paypal.com; child-src 'self' https://www.google.com https://maps.google.com https://maps.google.de https://rcdb.com https://www.rcdb.com https://*.rcdb.com https://www.paypal.com; img-src 'self' https://cdn.coaster-count.com data: https:; font-src 'self' https://cdn.coaster-count.com https://fonts.gstatic.com https://www.paypalobjects.com data:; style-src 'self' https://cdn.coaster-count.com https://fonts.googleapis.com 'unsafe-inline'; script-src 'self' https://cdn.coaster-count.com https://maps.googleapis.com https://www.paypalobjects.com 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https://cdn.coaster-count.com https://maps.googleapis.com https://www.paypal.com; report-uri /csp-report 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://challenges.cloudflare.com https://kit.fontawesome.com; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://www.google.com https://www.gstatic.com https://www.facebook.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://ka-f.fontawesome.com; font-src 'self' data: https://fonts.gstatic.com https://ka-f.fontawesome.com; img-src 'self' data: blob: https:; media-src 'self' blob: https:; worker-src 'self' blob:; frame-src 'self' https://www.googletagmanager.com https://www.google.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://challenges.cloudflare.com https://www.facebook.com; form-action 'self' https://www.facebook.com; manifest-src 'self'; 1 default-src 'self'; connect-src 'self' https://translate.googleapis.com https://koop.piwik.pro; font-src 'self' https://themes.googleusercontent.com https://koop.piwik.pro; img-src 'self' data: https://validator.swagger.io https://fonts.gstatic.com https://www.gstatic.com https://koop.piwik.pro; script-src 'self' https://translate-pa.googleapis.com https://translate.google.com https://koop.piwik.pro 'nonce-462bda38068df184290c14daa5eb70849df12d92afde3003651512d272231619'; style-src 'self' 'unsafe-inline' https://www.gstatic.com https://koop.piwik.pro 1 default-src 'self' static.addtoany.com secure.gravatar.com fonts.gstatic.com fonts.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com ssl.google-analytics.com script.addtoany.com static.addtoany.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src 'self' data: jigsaw.w3.org www.w3.org www.google-analytics.com ssl.google-analytics.com www.linkedin.com static.addtoany.com s.w.org secure.gravatar.com; font-src 'self' data: fonts.gstatic.com; frame-src 'self' static.addtoany.com; report-uri https://bishnet.report-uri.io/r/default/csp/reportOnly; 1 default-src 'none'; connect-src 'self' https://svanalytics.containers.piwik.pro/ https://predict.rekai.se/ https://view.rekai.se/view https://svanalytics.piwik.pro/; media-src 'self'; font-src 'self'; img-src 'self' data:; script-src 'self' 'nonce-eccf56b1-daf1-11f0-9220-733b17241ec6' https://svanalytics.containers.piwik.pro/ https://static.rekai.se/ 'unsafe-eval'; style-src 'self' 'nonce-eccf56b1-daf1-11f0-9220-733b17241ec6'; frame-ancestors 'self'; frame-src 'self'; 1 default-src data: blob: 'self' http://www.itkruze.com http://*.www.itkruze.com:* https://www.itkruze.com https://*.www.itkruze.com:* https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.youtube.com http://*.youtube.com https://*.doubleclick.net https://*.googletagmanager.com 'unsafe-inline' 'self' http://www.itkruze.com http://*.www.itkruze.com:* https://www.itkruze.com https://*.www.itkruze.com:* https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.youtube.com http://*.youtube.com https://*.doubleclick.net https://*.googletagmanager.com 'unsafe-eval' 'self' http://www.itkruze.com http://*.www.itkruze.com:* https://www.itkruze.com https://*.www.itkruze.com:* https://fonts.gstatic.com/ https://fonts.googleapis.com https://*.youtube.com http://*.youtube.com https://*.doubleclick.net https://*.googletagmanager.com;report-uri https://www.itkruze.com/index-reporting.html?minimize=0; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.google.co.uk *.googletagmanager.com *.google-analytics.com cdn.polyfill.io *.brightcove.net munchkin.market.net your.fitchratings.com *.evidon.com cdn2.funnelenvy.com script.crazyegg.com snap.licdn.com *.idio.co chart-studio.plotly.com public.flourish.studio app.fitchconnect-stg.com *.fitchconnect.com *.fitch.group *.jotjar.com *.zencdn.net *.mktorest.com *.ads-twitter.com *.googleadservices.com googleads.g.doubleclick.net *.linkedin.com *.ads.linkedin.com *.amazonaws.com *.google-analytics.com *.analytics.google.com *.twitter.com *.facebook.com *.youtube.com *.googleapis.com *.facebook.net *.evidon.com *.crwdcntrl.net *.addtoany.com cdn.jsdelivr.net *.bing.com *.licdn.com *.baidu.com *.ads-twitteer.com *.crazyegg.com *.hotjar.com *.marketo.net *.funnelenvy.com *.ctnsnet.com *.typekit.net *.woopra.com consentag.eu *.adobedtm.com demdex.net *.adobedc.net *.gstatic.com *.googlesyndication.com *.google.com.hk global.ketchcdn.com cdn.ketchjs.com; object-src 'self'; style-src 'self' 'unsafe-inline' https: blob: *.amazonaws.com *.googleapis.com *.googletagmanager.com your.fitchratings.com fonts.googleapis.com *.fitch.group *.hotjar.com consentag.eu assets.adobedtm.com demdex.net edge.adobedc.net; img-src 'self' 'unsafe-inline' https: blob: data: *.amazonaws.com *.doubleclick.net *.google-analytics.com *.google.com *.google.co.in *.google.de *.google.co.jp *.google.co.uk *.google.fr *.google.com.br *.google.it *.google.es *.google.com.mx *.google.ca *.google.com.au *.google.com.tr *.google.nl *.google.pl *.google.co.id *.google.com.ar *.google.com.sa *.google.com.eg *.google.co.th *.google.com.my *.google.co.za *.google.com.sg *.google.com.tw *.google.be *.google.com.ua *.google.se *.google.ch *.google.at *.google.com.co *.google.pt *.google.dk *.google.fi *.google.no *.google.gr *.google.hu *.google.cz *.google.ro consentag.eu assets.adobedtm.com demdex.net edge.adobedc.net global.ketchcdn.com cdn.ketchjs.com; media-src 'self' *.youtube.com consentag.eu assets.adobedtm.com demdex.net edge.adobedc.net; frame-src 'self' 'unsafe-inline' *.brightcove.net *.doubleclick.net vars.hotjar.com *.addtoany.com *.facebook.com bid.g.doubleclick.net *.fls.doubleclick.net *.fitchratings.com *.evidon.com *.infogram.com infogram-download-eu.s3.eu-west-1.amazonaws.com infogram-download-us2.s3.eu-west-1.amazonaws.com your.fitch.group flo.uri.sh plotly.com chart-studio.plotly.com fitchgroup.eu.qualtrics.com indd.adobe.com *.hotjar.com bid.g.doubleclick.net *.fls.doubleclick.net td.doubleclick.net i.ctnsnet.com tags.crwdcntrl.net px.ads.linkedin.com *.gtm.js i.ctnsnet.com *.googletagmanager.com *.flashtalking.com *.lpsnmedia.net consentag.eu assets.adobedtm.com demdex.net edge.adobedc.net *.gstatic.com *.google.com.hk *.googlesyndication.com *.google.com; frame-ancestors 'self'; child-src 'self'; font-src 'self' 'unsafe-inline' https: data: *.fitchratings.com fonts.gstatic.com *.hotjar.com consentag.eu assets.adobedtm.com demdex.net edge.adobedc.net; connect-src 'self' https: blob: wss: *.funnelenvy.com *.hotjar.com *.mktoresp.com *.bing.com *.ipinfo.io *.google-analytics.com *.bugsnag.com a.clarity.ms *.linkedin.oribi.io *.googletagmanager.com *.fitchratings.com *.brightcove.com *.brightcove.net 732-ckh-767.mktoresp.com fx.fitchgroup.co *.boltdns.net *.akamaihd.net *.crazyegg.com *.idio.co *.brightcovecdn.com *.marketo.net *.fitch.group *.evidon.com *.google.com *.google.co.uk *.twitter.com *.googleapis.com snap.licdn.com *.ctfassets.net *.gstatic.com stats.g.doubleclick.net api.sjpf.io api.fpjs.io *.analytics.google.com *.mktorest.com td.doubleclick.net i.ctnsnet.com tags.crwdcntrl.net px.ads.linkedin.com *.gtm.js i.ctnsnet.com *.google.co.in *.google.de *.google.co.jp *.google.fr *.google.com.br *.google.it *.google.es *.google.com.mx *.google.ca *.google.com.au *.google.com.tr *.google.nl *.google.pl *.google.co.id *.google.com.ar *.google.com.sa *.google.com.eg consentag.eu *.adobedtm.com demdex.net *.adobedc.net global.ketchcdn.com cdn.ketchjs.com; report-uri /report-csp-violation 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://cloud.typography.com https://*.googleapis.com https://*.typekit.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.youtube.com https://www.google-analytics.com https://snap.licdn.com https://static.ads-twitter.com https://connect.facebook.net https://*.hotjar.com https://*.hotjar.io https://*.googleapis.com https://*.twitter.com https://use.typekit.net; img-src * data: blob:; frame-src *; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net; connect-src 'self' https://stats.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://www.facebook.com https://*.hotjar.com https://*.hotjar.io https://performance.typekit.net https://translate.googleapis.com; 1 default-src 'self'; script-src 'unsafe-inline' https://pagead2.googlesyndication.com https://adservice.google.com https://www.googletagmanager.com *.google-analytics.com https://fundingchoicesmessages.google.com https://widget.spreaker.com *.doubleclick.net https://sync.search.spotxchange.com/; style-src 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://i.ytimg.com https://www.google-analytics.com https://www.spreaker.com/ https://www.facebook.com/ *.adtrafficquality.google *.doubleclick.net https://sync.search.spotxchange.com/; frame-src 'self' https://www.google.com https://www.youtube.com https://www.spreaker.com/ https://www.facebook.com/ https://*.googlesyndication.com https://tpc.googlesyndication.com https://fundingchoicesmessages.google.com https://widget.spreaker.com https://*.adtrafficquality.google https://googleads.g.doubleclick.net https://sync.search.spotxchange.com/ https://www.googleadservices.com; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://*.google-analytics.com https://www.shinystat.com/ https://www.facebook.com/ https://www.postpickr.com/ https://*.googlesyndication.com https://adservice.google.com https://fundingchoicesmessages.google.com https://*.adtrafficquality.google https://*.doubleclick.net https://googleads.g.doubleclick.net https://sync.search.spotxchange.com/ https://www.google.com https://www.googleadservices.com; frame-ancestors 'self' 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.com *.cookielaw.org *.facebook.net *.gmlinteractive.com *.taboola.com *.fullstory.com *.adform.net *.geocomply.com *.tostarsbuilding.com *.googletagmanager.com *.kameleoon.io *.creativecdn.com *.kameleoon.eu *.cloudflareinsights.com *.sportradarserving.com *.sportradar.com *.greencolumnart.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=h.WpTMgTRTcsG.ggMcn.mXCCN3xiX2VR_7fHAT0aOZ0-1765942266-1.0.1.1-BbKUpudNTXY0Hpd0p7IT_CLF7ToI4KW636Tj8yQ3Sk9SUVd3eVzvfh3kjms2fD40TFwQn.vJhPsVczQr4aMzNsC2cWXwCVEBHSwhAiw.dqJMXKQ.XMAkzZPb5BDbrYAIvf90JDo5fZ2dWz7rdrebwarbROTsHXBjiZc1y2nfKysI8Gn899TrUvqGuuJr4cI6aPx5vDz0BDveii9h1_VPVQ; report-to cf-bulbpsabebruxrpb 1 default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' *.bugherd.com d2iiunr5ws5ch1.cloudfront.net bugherd-attachments.s3.amazonaws.com data:; script-src 'self' *.pusher.com *.bugherd.com digistats.de 'nonce-oteIj0PKcGxmNegul3BbeOVZ'; connect-src 'self' wss: *.pusher.com sessions.bugsnag.com *.bugherd.com digistats.de; frame-src *.bugherd.com; report-uri https://ospa-csp.uriports.com/reports/report; report-to default; media-src 'self' https://www.ospa-schwimmbadtechnik.de/files/media/global/video/ospa-vorteile.mp4 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-taFf05lGZnLhaLik9cNKJg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; report-uri https://api.aipei.tw/csp_report; 1 font-src *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.atlassian.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.atlassian.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com *.avada.io *.atlassian.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.atlassian.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=WsDjTMdzDwhX8_OSRPLF1fN54IdbohDDwRnjxU1Y3Y0-1765936959-1.0.1.1-O9tbiSQiARN6UAPQzAM_d.qNqw1Q2vOjTBPnhmJPFIY7VTuJB15X9oR7IqXdB_L5_3VMIyCDEfjwJ5ILKC.cDRhpYBc5jYQyPMatkXz1yQykk0FRaxJgg5c.8TVT7qERwLdQXyTuHxG14hnGRYeigfOZ86YpzHuBEO655JBlXA1jGeK7nSILjNqwCegBcKCJ; report-to cf-csp-endpoint 1 font-src *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.avada.io *.shopify.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com api.addressy.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'unsafe-eval' 'nonce-79a53b3f869d3c203080272544c63c031bc466ddd50db14a' 'strict-dynamic'; style-src 'self' data: 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://instantcms.ru; font-src 'self' data: https://fonts.gstatic.com; report-uri https://valekse.ru/csp/report; report-to icms-csp-ep 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv50.20dsa-19b2a1f6471-0x702#pd 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de js.mollie.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://www.mollie.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de js.mollie.com https://maps.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com *.typekit.net *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com https://cdn.clerk.io *.ducksuite.com *.cdninstagram.com *.fbcdn.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.sizebay.technology cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com https://api.clerk.io https://cdn.clerk.io *.ducksuite.com *.jsdelivr.net polyfill.io chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com applepay.cdn-apple.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com https://api.clerk.io https://cdn.clerk.io *.ducksuite.com *.typekit.net downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com applepay.cdn-apple.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.ducksuite.com *.cdninstagram.com *.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com cdn.remainbirgerchristensen.com cdn.rotatebirgerchristensen.com *.ducksuite.com *.keen.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' *.google.com *.googleapis.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.google.ad *.google.ae *.google.al *.google.at *.google.be *.google.bg *.google.ca *.google.ch *.google.co.id *.google.co.il *.google.co.in *.google.co.kr *.google.co.ma *.google.co.nz *.google.co.th *.google.co.uk *.google.co.za *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.hk *.google.com.lb *.google.com.mt *.google.com.mx *.google.com.my *.google.com.ph *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vn *.google.cz *.google.de *.google.dk *.google.ee *.google.es *.google.fr *.google.ge *.google.gr *.google.hr *.google.hu *.google.ie *.google.it *.google.li *.google.lt *.google.lu *.google.lv *.google.md *.google.mg *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.se *.google.si *.google.sk *.google.sr *.google.tn api.leadinfo.com collector.leadinfo.net consentcdn.cookiebot.com ct.pinterest.com api.expertise.ai *.hotjar.io wss://ws.hotjar.com www.rensonevents.com renson-public.azure-api.net adservice.google.com bat.bing.com googleads.g.doubleclick.net px.ads.linkedin.com stats.g.doubleclick.net *.facebook.com *.wisepops.net *.wisepops.com *wisepops.net *.visualwebsiteoptimizer.com app.getwisp.co *.cookieinformation.com; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com www.renson.eu *.bootstrapcdn.com; frame-src 'self' ct.pinterest.com e.issuu.com consentcdn.cookiebot.com *.youtube.com www.facebook.com www.google.com www.googletagmanager.com *.calendly.com td.doubleclick.net td.doubleclick.net.x.09600de704fdb043ff099c40aabe2d8e7198.d0452329.id.opendns.com td.doubleclick.net.x.0bd2460605b4e04bf409574056f2418fd810.d0452329.id.opendns.com td.doubleclick.net.x.11f3929f0711204179088e1076d27c30fcfc.d0452329.id.opendns.com td.doubleclick.net.x.12062b6606f6804057080e602e654f342153.d045232a.id.opendns.com td.doubleclick.net.x.166dd5d20db1b04cb00bb5b0884c6cf94d6f.d0452329.id.opendns.com td.doubleclick.net.x.2c7492b00bb7a04b350a6900ac977ec52030.d0452329.id.opendns.com td.doubleclick.net.x.31c642540514d04bc80b949092146ba26358.d0452329.id.opendns.com td.doubleclick.net.x.35cc51200e4c704c3f08a430eb59507708ab.d0452329.id.opendns.com td.doubleclick.net.x.3b58afbe0ea5d04ae60988b023ea5ea2359b.d045232a.id.opendns.com td.doubleclick.net.x.3e6a328505e2804f81088350914b066f49a0.d0452329.id.opendns.com td.doubleclick.net.x.429955f002718049410bd6200e42c267599c.d0452329.id.opendns.com td.doubleclick.net.x.4648cb5e0e5a404b490b9a105477214446b6.d0452329.id.opendns.com td.doubleclick.net.x.489bb32f0a15404673098cb0c1351dd70222.d0452329.id.opendns.com td.doubleclick.net.x.51fda7e1067db0405f0b2dd05608976fe2dd.d045232a.id.opendns.com td.doubleclick.net.x.5a63bf430171304e730a84f0d9f52c4187dc.d0452329.id.opendns.com td.doubleclick.net.x.6f93b53a0470d04633080d8024491a677636.d0452329.id.opendns.com td.doubleclick.net.x.71f8a2360890f0488d09ea60691fad4265f6.d045232a.id.opendns.com td.doubleclick.net.x.79e545d800555042160869703a3fb53d3d9d.d0452329.id.opendns.com td.doubleclick.net.x.7c948fc00baef042bb0a8100764725ee9678.d045232a.id.opendns.com td.doubleclick.net.x.7d7b73560e1e5044c80bba00ab620978d940.d0452329.id.opendns.com td.doubleclick.net.x.7f206e2a0a44504d250b7100616d2172708b.d0452329.id.opendns.com td.doubleclick.net.x.85acb37104bbe04e470af500fa5abc2a85c4.d0452329.id.opendns.com td.doubleclick.net.x.8a5cdd200b65104e1e08e780ff4e6c9c2009.d0452329.id.opendns.com td.doubleclick.net.x.8ae9da7f07c8a044fd09adb07b13a044244a.d0452329.id.opendns.com td.doubleclick.net.x.9f4ee3e10e549048800b3d90307f47a07fb2.d0452329.id.opendns.com td.doubleclick.net.x.ab2cb5e605336048a30b0df0f39973dacd76.d0452329.id.opendns.com td.doubleclick.net.x.ac1ca9c20dc3e04c950a5fe0d8a1ffe32d5b.d045232a.id.opendns.com td.doubleclick.net.x.b1b51f290464f04f5108e4201f4de2e7b690.d0452329.id.opendns.com td.doubleclick.net.x.b46b14ab04c0a047b608ef905b8f1143837d.d0452329.id.opendns.com td.doubleclick.net.x.ce9226f40c1f904c84090b6046a863167757.d0452329.id.opendns.com td.doubleclick.net.x.d44cb5620a41404e4c091d00c62a34fdffd7.d0452329.id.opendns.com td.doubleclick.net.x.e2bde31a00424041b60902f07e8b96739702.d0452329.id.opendns.com td.doubleclick.net.x.e60e8ce80796004348081da00bb4f6cc1035.d0452329.id.opendns.com td.doubleclick.net.x.ee2110460af800460008d110a9de7bf33df3.d0452329.id.opendns.com td.doubleclick.net.x.fc22e2bb098ff047ed092f807e0a5b7a130a.d0452329.id.opendns.com *.wisepops.com wisepops.net *.visualwebsiteoptimizer.com *.cookieinformation.com; img-src 'self' data: renson-co-renson-kentico-dev-cdn-wa-ep.azureedge.net renson-co-stg-kentico-website-live-cdnep.azureedge.net renson-co-prd-kentico-website-live-cdnep.azureedge.net *.renson.eu *.renson.net *.bynder.com imgsct.cookiebot.com *.googleapis.com *.google-analytics.com *.google.com www.googletagmanager.com *.gstatic.com img.youtube.com i.ytimg.com cdnjs.cloudflare.com chatsimple-widget.s3.us-east-2.amazonaws.com connect.facebook.net www.facebook.com *.doubleclick.net googleads.g.doubleclick.net i.vimeocdn.com log.pinterest.com *.linkedin.com *.google.ad *.google.ae *.google.al *.google.at *.google.be *.google.bg *.google.ca *.google.ch *.google.co.id *.google.co.il *.google.co.in *.google.co.kr *.google.co.ma *.google.co.nz *.google.co.th *.google.co.uk *.google.co.za *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.hk *.google.com.lb *.google.com.mt *.google.com.mx *.google.com.my *.google.com.ph *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vn *.google.cz *.google.de *.google.dk *.google.ee *.google.es *.google.fr *.google.ge *.google.gr *.google.hr *.google.hu *.google.ie *.google.it *.google.li *.google.lt *.google.lu *.google.lv *.google.md *.google.mg *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.se *.google.si *.google.sk *.google.sr *.google.tn *.wisepops.net *.wisepops.com *.visualwebsiteoptimizer.com dx4nr741tfc02.cloudfront.net wisp-production-storage.s3.amazonaws.com ct.pinterest.com; manifest-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' www.gstatic.com *.google.com *.googleapis.com *.googlesyndication.com *.google-analytics.com *.googleadservices.com www.googletagmanager.com *.youtube.com cdn.chatsimple.ai *.wisepops.com *.visualwebsiteoptimizer.com chatsimple-widget.s3.us-east-2.amazonaws.com code.jquery.com *.cookiebot.com cdn.leadinfo.net *.hotjar.com connect.facebook.net *.cookieinformation.com cdnjs.cloudflare.com *.facebook.net *.pinterest.com googleads.g.doubleclick.net https://cdnjs.cloudflare.com/ajax/libs/jquery/ https://cdnjs.cloudflare.com/ajax/libs/tooltipster/ https://cdnjs.cloudflare.com/ajax/libs/fotorama/4.6.4/fotorama.min.js; script-src 'nonce-NOvWaum6VnCEtAd8ZQOFoQ==' 'self' code.jquery.com cdn.leadinfo.net connect.facebook.net *.cookiebot.com *.googlesyndication.com *.google.com www.google-analytics.com *.googletagmanager.com www.gstatic.com maps.googleapis.com www.googleadservices.com *.cloudflare.com *.wisepops.net *.wisepops.com *wisepops.net *.visualwebsiteoptimizer.com app.getwisp.co googleads.g.doubleclick.net *.youtube.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.calendly.com cdn.chatsimple.ai cdnjs.cloudflare.com fonts.googleapis.com stackpath.bootstrapcdn.com; report-uri https://440648cc39180e293ac22cb81bfa4281.report-uri.com/r/d/csp/reportOnly 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/startup_google_com 1 default-src 'self'; script-src 'report-sample' 'self' https://idm-dev-din.insuranceclaimcheck.com https://idm-model-mex.insuranceclaimcheck.com https://idm-icc.insuranceclaimcheck.com https://dev-assurant.oktapreview.com https://assurant.oktapreview.com https://assurant.okta.com https://sdk.asapp.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'report-sample' 'self' https://fonts.googleapis.com https://sdk.asapp.com; object-src 'none';base-uri 'self'; connect-src 'self' https://idm-dev-din.insuranceclaimcheck.com https://idm-model-mex.insuranceclaimcheck.com https://idm-icc.insuranceclaimcheck.com https://dev-assurant.oktapreview.com https://assurant.oktapreview.com https://assurant.okta.com https://assuranthousing-demo01.test.asapp.com https://assuranthousing.asapp.com https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://idm-dev-din.insuranceclaimcheck.com https://idm-model-mex.insuranceclaimcheck.com https://idm-icc.insuranceclaimcheck.com https://dev-assurant.oktapreview.com https://assurant.oktapreview.com https://assurant.okta.com https://player.vimeo.com https://sandbox.esignlive.com https://apps.esignlive.com https://sdk.asapp.com https://www.google.com; img-src 'self' https://i.vimeocdn.com https://www.google-analytics.com; manifest-src 'self'; media-src 'self'; report-uri sso/cspreport; worker-src 'none'; 1 font-src www.paypalobjects.com fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.feedbackcompany.com cdnjs.cloudflare.com cdn.jsdelivr.net static.widget.trengo.eu fonts.bunny.net *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com chatwidget-prod.web.app www.googletagmanager.com sst.jimmyatwork.nl sst.georgeatwork.com js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.feedbackcompany.com *.jimmyatwork.nl *.amazonaws.com *.google.nl *.keurmerk.info integrations.etrusted.com magefan.com cm.magefan.com https://www.mollie.com *.multisafepay.com ssl.gstatic.com www.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.facebook.com *.facebook.net *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.feedbackcompany.com *.trengo.eu *.cookiefirst.com *.clarity.ms *.clickcease.com static.cloudflareinsights.com cdnjs.cloudflare.com assets.adobetm.com app.aiden.cx *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com integrations.etrusted.com chatwidget-prod.web.app js.mollie.com *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://tagging.jimmyatwork.nl https://form-assets.mailchimp.com https://*.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com cdnjs.cloudflare.com fonts.bunny.net consent.cookiefirst.com integrations.etrusted.com *.fontawesome.com maxcdn.bootstrapcdn.com https://pay.multisafepay.com tagmanager.google.com fonts.google.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.feedbackcompany.com *.trengo.eu *.cookiefirst.com *.clarity.ms *.openfpcdn.io sst.jimmyatwork.at sst.jimmyatwork.de sst.jimmyatwork.nl sst.jimmyatwork.be sst.georgeatwork.at sst.georgeatwork.de sst.georgeatwork.nl sst.georgeatwork.com sst.georgeatwork.ch sst.georgeatwork.co.uk sst.georgeatwork.fr sst.georgeatwork.it sst.georgeatwork.eu *.multisafepay.com *.googletagmanager.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://tagging.jimmyatwork.nl https://form-assets.mailchimp.com https://eventcollector.mcf-prod.a.intuit.com https://9kvu81ddh3.execute-api.us-east-2.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.hubspot.com https://*.hsappstatic.net https://js.hsforms.net https://*.hsforms.com https://js.hs-analytics.net https://js.hs-banner.com https://*.hubspotusercontent-na1.net https://connect.facebook.net https://platform.twitter.com https://snap.licdn.com https://script.hotjar.com https://static.hotjar.com https://d.adroll.com https://s.adroll.com https://bat.bing.com https://geotargetly-api-2.com https://unpkg.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://protechtgroup.my.salesforce.com https://service.force.com https://*.salesforceliveagent.com https://community.protechtgroup.com https://b.static.lightning.force.com https://www.google.com https://www.gstatic.com https://tracking.g2crowd.com https://googleads.g.doubleclick.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; connect-src 'self' https://*.hubspot.com https://*.hubapi.com https://js.hsforms.net https://*.hsforms.com https://*.googletagmanager.com https://analytics.google.com https://www.google-analytics.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://ka-p.fontawesome.com https://bat.bing.com https://vc.hotjar.io wss://ws.hotjar.com https://px.ads.linkedin.com https://tracking-api.g2.com https://protechtgroup.my.salesforce.com https://service.force.com https://*.salesforceliveagent.com https://community.protechtgroup.com https://b.static.lightning.force.com https://www.google.com/recaptcha/; img-src 'self' data: https://www.protechtgroup.com https://*.hubspot.com https://*.hubspot.net https://*.hubspotusercontent-na1.net https://no-cache.hubspot.com https://static.hsappstatic.net https://js.hscta.net https://js-eu1.hscta.net https://*.hsforms.com https://*.hsforms.net https://forms-na1.hsforms.com https://perf.hsforms.com https://perf-na1.hsforms.com https://www.google-analytics.com https://stats.g.doubleclick.net https://bat.bing.com https://px.ads.linkedin.com https://connect.facebook.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://static.hsappstatic.net https://cdnjs.cloudflare.com https://*.hubspot.net https://*.hubspotusercontent-na1.net https://service.force.com https://community.protechtgroup.com; font-src 'self' data: https://ka-p.fontawesome.com https://cdnjs.cloudflare.com https://*.hubspotusercontent-na1.net; frame-src 'self' https://*.hubspot.com https://*.hsforms.net https://*.hsforms.com https://*.hs-sites.com https://*.hs-sites-eu1.com https://*.hubspot.net https://play.hubspotvideo.com https://play-eu1.hubspotvideo.com https://service.force.com https://platform.twitter.com https://www.googletagmanager.com https://www.facebook.com https://www.youtube.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; form-action 'self' https://*.hubspot.com https://*.hsforms.com; worker-src 'self' blob:; manifest-src 'self'; upgrade-insecure-requests; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com *.certcapture.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.certcapture.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://cdn.eleczo.com blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://cdn.eleczo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' escutaoveio.com *.escutaoveio.com wake-components.fbitsstatic.net escutaoveio.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.escutaoveio.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.googleadservices.com *.g.doubleclick.net *.tiktok.com *.google.com.br *.google.com *.googleapis.com *.googletagmanager.com *.co.ao *.google-analytics.com google.com google.pt connect.facebook.net google.com.br analytics.tiktok.com *.com.ph *.facebook.net *.smarthint.co *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br service.smarthint.co *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com gstatic.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io flipnet-assets.s3.sa-east-1.amazonaws.com *.flip.net.br wake-commerce-scripts.omni.chat *.fbitsstatic.net api-admin.widde.io cdn.widde.io videos.widde.io sdk.widde.io *.widde.io *.google.it *.visa.com *.escutaoveio.com.br *.wake.tech *.appmax.com.br *.tunagateway.com *.plataformasocial.com.br *.dito.com.br events.plataformasocial.com.br login.plataformasocial.com.br storage.googleapis.com js.dito.com.br ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.escutaoveio.com escutaoveio.com; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.facebook.net *.yotpo.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.youtube.com *.paypal.com *.yotpo.com *.creditguard.co.il *.vimeo.com *.googletagmanager.com *.google.com *.xtento.com *.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com *.googleadservices.com *.facebook.com *.yotpo.com *.cdninstagram.com *.google-analytics.com *.google.com *.google.com.vn *.google.co.il https://www.google *.magentocommerce.com *.paypal.com *.paypalobjects.com *.ytimg.com *.web-view.net *.googleapis.com *.nagich.co.il *.vimeo.com www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com *.vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google-analytics.com *.googleapis.com *.google.com *.fontawesome.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.doubleclick.net *.analytics.com *.rawgit.com *.nagich.co.il *.luckyorange.com *.youtube.com *.xtento.com *.paypal.com *.paypalobjects.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com cdn.dnky.co webchat.dotdigital.com tagmanager.google.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.analytics.com *.facebook.com *.google-analytics.com *.nagich.co.il vimeo.com player.vimeo.com *.luckyorange.com *.googleapis.com wss://realtime.luckyorange.com wss://in.visitors.live/socket.io wss://in.visitors.live/socket.io/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://www.google-analytics.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.cuckoldsessions.com *.dfxtra.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.cuckoldsessions.com *.dfxtra.com join.gammasecure.com; script-src 'self' *.cuckoldsessions.com *.dfxtra.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.cuckoldsessions.com *.dfxtra.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 worker-src blob:; form-action *.cardinalcommerce.com *.paypal.com www.sandbox.paypal.com *.amazon.com *.facebook.com *.googlesyndication.com connect.facebook.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.googletagmanager.com *.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.braintreegateway.com google.com js.stripe.com *.amazon.com *.payments-amazon.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com connect.facebook.net www.commercepartnerhub.com assets.braintreegateway.com plumrocket.com *.authorize.net www.googleadservices.com *.artifi.net assets.pinterest.com ct.pinterest.com www.paypalobjects.com i.liadm.com 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net *.google.com *.newrelic.com *.nr-data.net *.authorize.net *.commerce-payment-services.com *.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klaviyo.com fast.a.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.shopify.com *.sandbox.braintreegateway.com celebrosnlp.com *.celebros-analytics.com maps.googleapis.com www.googletagservices.com cdn.gladly.qa cdn.gladly.com *.cloudflare.com *.artifi.net *.monetate.net cdn.popt.in *.visualwebsiteoptimizer.com *.cloudfront.net s.pinimg.com bat.bing.com tag.rmp.rakuten.com ut.rd.linksynergy.com *.pinterest.com cdn.noibu.com *.hotjar.com b-code.liadm.com secure.merchantadvantage.com assets.finestationery.com finestat-ac.celebros.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://www.finestationery.com/pr-csp/report/add/; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com public.montonio.com https://omnisnippet1.com https://wt.soundestlink.com https://maps.omnivasiunta.lt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com s7.addthis.com *.avada.io public.montonio.com https://omnisnippet1.com https://forms.soundestlink.com https://unpkg.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com ekr.zdassets.com/ https://get.geojs.io *.avada.io https://geocode.arcgis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; report-uri https://ff14b95b6f497a1a52882af1be64557d.report-uri.com/r/t/csp/wizard 1 font-src *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.weltpixel.com *.klarna.com *.google.com/ js.mollie.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://api.mapbox.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.magezon.com https://www.mollie.com *.google.de *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com cdn.doofinder.com *.chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com *.google.com/ js.mollie.com *.magento.com *.doofinder.com *.shoplytics.de *.dagmarfischermode.de *.googleadservices.com *.googletagmanager.com *.adobedtm.com *.pinimg.com *.clarity.ms https://freegeoip.app ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com downloads.mailchimp.com maxcdn.bootstrapcdn.com *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.doofinder.com wss://*.doofinder.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io *.developer.adobe.com *.google.com *.doubleclick.net *.pinterest.com autocomplete2.postdirekt.de https://freegeoip.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src-attr 'self'; frame-ancestors 'self' 1 font-src *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://*.gstatic.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com script.hotjar.com fonts.googleapis.com fonts.gstatic.com *.inside-graph.com integration-cdn.toshi.co acsbapp.com shopping.qantas.com appdown.pstatic.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.cardinalcommerce.com www.facebook.com *.kaptcha.com bid.g.doubleclick.net ct.pinterest.com www.rsa3dsauth.co.uk www.securesuite.co.uk *.americanexpress.com 3dsecure-vrp.de 'self' 'unsafe-inline'; frame-ancestors *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com au-tracker.inside-graph.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.bglobale.com *.global-e.com *.google.com *.doubleclick.net *.facebook.com *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.pinterest.com *.sharethis.com *.hotjar.co vimeo.com acsbapp.com *.kaptcha.com player.smartzer.com www.google.com www.facebook.com accounts.accessibe.com dashboard.accessibe.com cestream.me 3ds.sia.eu acs2.3dsecure.no www.houzz.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://*.gstatic.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com adservice.google.com script.hotjar.com www.google.sa www.google.ca *.bing.com *.clarity.ms data:* web1.acsbapp.com integration-sandbox-cdn.toshi.co www.google.bg www.google.be www.google.co.uk www.google.nl www.gstatic.com translate.google.com idsync.rlcdn.com consent.linksynergy.com au-live.inside-graph.com bam-cell.nr-data.net integration-cdn.toshi.co bat.bing.com www.google.com.au google.com.au *.searchspring.io *.media.tumblr.com s.ytimg.com maps.googleapis.com maps.gstatic.com au-cdn.inside-graph.com www.google.co.in d3cgm8py10hi0z.cloudfront.net track.linksynergy.com *.sharethis.com *.micpn.com *.pinterest.com zimmermann.com www.google.tn www.google.com.hk www.google.com.et www.google.com.eg www.google.co.tz www.google.ci www.google.co.ke www.google.cm www.google.lk www.google.com.ng www.google.ne www.google.com.mm www.google.co.mz www.google.co.id www.google.bi www.google.com.kh www.google.co.ve www.google.cd www.google.com.gh www.google.so www.google.com.af www.google.ht www.google.com.ni www.google.la www.google.cg www.google.bf www.google.sn www.google.com.ly www.google.mg www.google.com.sb www.google.com.pg www.google.com.np sync.sharethis.com www.google.com.py www.google.ml www.google.com.sl www.google.co.ls www.google.to www.google.gm www.google.rw www.google.com.vn www.google.com.sv www.google.co.kr www.google.com.bo www.google.com.sg www.google.mw www.google.si www.google.tl www.google.sc www.google.co.zm www.google.tg www.google.com.pk 4mrr1kwk.micpn.com www.google.ge www.google.com.fj www.google.com.na www.google.td www.google.ee www.google.mk www.google.bj www.google.mn www.google.bt www.google.co.bw www.google.fi www.google.com.uy www.google.co.th www.google.com.pe www.google.cv www.google.co.zw www.google.ga www.google.by www.google.iq www.google.com.ec www.google.co.jp www.google.com.pa www.google.dz www.google.ws analytics.tiktok.com www.google.gy www.google.de sdk.privacy-center.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com https://cdn.searchspring.net/intellisuggest/is.min.js *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com analytics.tiktok.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com *.searchspring.net *.acsbapp.com au-tracker.inside-graph.com cdn.scarabresearch.com intljs.rmtag.com *.inside-graph.co js-agent.newrelic.com *.inside-graph.com acsbapp.com tag.lexer.io *.toshi.co *.bugsnag.com *.sharethis.com script.crazyegg.com *.clarity.ms www.fullstory.com songbirdstag.cardinalcommerce.com www.gstatic.com vimeocdn.com youtube.com googletagmanager.com maps.googleapis.com fullstory.com bat.bing.com 4mrr1kwk.micpn.com s.pinimg.com tag.rmp.rakuten.com *.hotjar.com ut.rd.linksynergy.com ct.pinterest.com unsafe-inline sdk.privacy-center.org www.onelink-edge.com 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.bglobale.com *.global-e.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://fonts.googleapis.com/ *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.inside-graph.com *.searchspring.net webchat.dotdigital.com cdn.honey.io *.aptrinsic.com 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com au-cdn.inside-graph.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://beacon.searchspring.io/beacon *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com analytics.tiktok.com data.stbuttons.click www.google.com.au translate.googleapis.com *.searchspring.io *.acsbapp.co cdn.acsbapp.com au-live.inside-graph.com bam.nr-data.net uat.tryzens-analytics.com:12280 *.scarabresearch.com wss://au-live.inside-graph.com *.bugsnag.com *.postcodeanywhere.co.uk *.sharethis.com script.crazyegg.com stats.g.doubleclick.net *.pinterest.com track.lexer.io www.tryzens-analytics.com:12280 www.google.co.ke www.google.bi pagestates-tracking.crazyegg.com www.google.com.sl www.google.co.ao www.google.cm www.google.com.np www.google.cd www.google.co.ve www.google.lk www.google.co.tz www.google.com.ng www.google.so www.google.ne www.google.co.id www.google.co.ls www.google.tn assets-tracking.crazyegg.com www.google.ht www.google.co.mz acsbapp.com www.google.com.co cp.crwdcntrl.net www.google.ci tracking.crazyegg.com www.google.co.za www.google.tl www.google.com.pk www.google.com.sv www.google.com.ly www.google.mg www.google.tg www.google.gm www.google.com.eg www.google.co.kr www.google.bf www.google.sn www.google.ga www.google.bj ad.doubleclick.net www.google.cg www.google.com.ar www.google.co.ma www.google.com.et www.google.fr www.google.com.na www.google.co.uk www.google.nl www.google.ml www.google.rw www.google.com.uy www.google.com.bo www.google.com.ni www.google.ki www.google.ee www.google.com.gt www.google.com.py www.google.com.gh www.google.com.kh www.google.com.vn www.google.ru www.google.cv www.google.com.mm www.google.co.zm www.google.vu www.google.com.ec www.google.es www.google.at bat.bing.com vc.hotjar.io www.google.de ws.hotjar.com content.hotjar.io metrics.hotjar.io www.google.ca www.tryzens-analytics.com ct.pinterest.com www.google.com.pe www.google.co.in www.google.ge googleads.g.doubleclick.net fresnel.vimeocdn.com api.privacy-center.org pagead2.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/zmn-cspdata; report-to report-endpoint; 1 style-src-elem *.petitceller.com *.etrusted.com; font-src cl.avis-verifies.com *.criteo.net *.criteo.com *.adsrvr.org *.googlesyndication.com *.petitceller.com *.payments-amazon.com *.fontawesome.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.redsys.es *.facebook.com *.amazon.es *.petitceller.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.amazon.es *.petitceller.com *.avis-verifies.com *.googlesyndication.com c.avis-verifies.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.redsys.es *.facebook.com consentcdn.cookiebot.com *.amazon.com *.amazon.es *.criteo.com *.criteo.net *.avis-verifies.com c.avis-verifies.com *.adsrvr.org *.googlesyndication.com *.petitceller.com *.etrusted.com *.trustedshops.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.collect.igodigital.com *.cloudfront.net cl.avis-verifies.com *.google.com *.google.es *.facebook.com *.adsrvr.org *.clarity.ms *.rfihub.com *.doubleclick.net *.casalemedia.com *.adnxs.com *.bidswitch.net *.tremorhub.com *.netreviews.eu *.agkn.com *.rubiconproject.com *.yahoo.com *.bing.com *.taboola.com *.spotxchange.com *.gstatic.com *.advertising.com *.liadm.com *.smaato.net *.criteo.com *.criteo.net *.outbrain.com *.kargo.com *.addthis.com *.tapad.com *.smartadserver.com *.360yield.com *.pubmatic.com *.postrelease.com *.3lift.com *.adform.net *.media.net *.teads.tv *.rambler.ru *.aralego.com *.mail.ru *.yieldmo.com *.sharethrough.com *.yieldlab.net *.omnitagjs.com *.stickyadstv.com *.ivitrack.com *.mgid.com *.mediavine.com *.adotmob.com *.e-planning.net *.openx.net *.adscale.de *.rlcdn.com *.avis-verifies.com/ *.magentocommerce.com/ *.googlesyndication.com *.dmxleo.com *.petitceller.com *.etrusted.com *.trustedshops.com imgsct.cookiebot.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.collect.igodigital.com consent.cookiebot.com consentcdn.cookiebot.com *.googletagmanager.com cl.avis-verifies.com *.svn.avis-verifies.com *.avis-verifies.com *.bucket.cdnwebcloud.com *.facebook.com *.facebook.net *.google-analytics.com *.webgains.io *.clarity.ms *.googleapis.com *.googleadservices.com *.cdnwebcloud.com *.taboola.com *.criteo.com *.criteo.net *.adsrvr.org *.googlesyndication.com *.petitceller.com *.etrusted.com *.trustedshops.com *.trustedshops-static.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.petitceller.com *.etrusted.com *.trustedshops.com *.trustedshops-static.com *.fontawesome.com assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.collect.igodigital.com *.taboola.com *.google-analytics.com *.google.com *.doubleclick.net *.clarity.ms *.netreviews.eu *.cdnwebcloud.com *.avis-verifies.com c.avis-verifies.com *.cookiebot.com *.paypal.com *.webgains.io *.facebook.com *.youtube.com *.adsrvr.org *.googlesyndication.com *.petitceller.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.sandbox.my.site.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.google.com *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://*.pricespider.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.force.com *.my.salesforce.com *.salesforceliveagent.com *.my.salesforce-sites.com https://sbmlifescience--partial.sandbox.my.site.com https://www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.salesforce.com *.force.com *.sandbox.my.site.com *.pricespider.com *.my.salesforce-sites.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.facebook.com *.facebook.net *.salesforce-scrt.com *.bazaarvoice.com *.pricespider.com *.my.salesforce-sites.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * api.razorpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.cdninstagram.com *.fbcdn.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.google.co.in www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.googleapis.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com *.youtube.com static.cloudflareinsights.com *.disqus.com *.avada.io *.doubleclick.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com https://get.geojs.io *.avada.io https://widget.tagembed.com https://api.taggbox.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 worker-src blob: *.paypal.com *.braintreegateway.com; font-src *.googleapis.com *.gstatic.com data: fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com https://static.addtoany.com/ *.certcapture.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.certcapture.com store.paradoxlabs.com scontent.cdninstagram.com *.kxcdn.com *.twitter.com google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com https://img.youtube.com *.facebook.com https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.barefootbooks.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com s7.addthis.com *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.clarity.ms *.doubleclick.net www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.googleapis.com google.com *.kxcdn.com *.gstatic.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.googleapis.com *.certcapture.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com ekr.zdassets.com/ *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.clarity.ms *.doubleclick.net 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self' lifepointhealth.okta.com www.lifepointone.net *.oktacdn.com; connect-src 'self' lifepointhealth.okta.com lifepointhealth-admin.okta.com www.lifepointone.net *.oktacdn.com *.mixpanel.com *.mapbox.com lifepointhealth.kerberos.okta.com lifepointhealth.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'nonce--fW7lu8FI7V2B2b2ux9Prg' 'unsafe-eval' 'self' 'report-sample' lifepointhealth.okta.com www.lifepointone.net *.oktacdn.com; style-src 'unsafe-inline' 'nonce--fW7lu8FI7V2B2b2ux9Prg' 'self' 'report-sample' lifepointhealth.okta.com www.lifepointone.net *.oktacdn.com; frame-src 'self' lifepointhealth.okta.com lifepointhealth-admin.okta.com www.lifepointone.net login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' lifepointhealth.okta.com www.lifepointone.net *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' lifepointhealth.okta.com www.lifepointone.net data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 script-src 'nonce-EWrQZxdp+MtIlQVxKm+4Qg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=727ec40f-68f6-4d7c-8665-3a8666efe981; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src *.opayo.eu.elavon.com https://fonts.bunny.net/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.dotdigital-pages.com *.dotdigital.com *.opayo.eu.elavon.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.ngenius-payments.com/ https://cdn.moengage.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.paypal.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.exponea.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.opayo.eu.elavon.com *.ngenius-payments.com/ *.newrelic.com/ *.nr-data.net/ https://cdn.logrocket.io https://cdn.logr-ingest.com https://cdn.lr-ingest.io https://cdn.lr-in.com https://cdn.lr-in-prod.com https://cdn.lr-ingest.com https://cdn.ingest-lr.com https://cdn.lr-intake.com https://cdn.intake-lr.com https://cdn.moengage.com/ https://app-cdn.moengage.com/ https://moe-email-campaigns.s3.amazonaws.com/ https://image.moengage.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.opayo.eu.elavon.com *.myfonts.net/count/3bd9db https://cdn.moengage.com/ https://app-cdn.moengage.com/ https://fonts.bunny.net/ unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.adyen.com *.exponea.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.paypal.com *.opayo.eu.elavon.com *.nr-data.net/ *.google-analytics.com/ https://*.logrocket.io https://*.lr-ingest.io https://*.logrocket.com https://*.lr-in.com https://*.lr-in-prod.com https://*.lr-ingest.com https://*.ingest-lr.com https://*.lr-intake.com https://*.intake-lr.com https://*.logr-ingest.com https://sdk-01.moengage.com/ https://sdk-02.moengage.com/ https://sdk-03.moengage.com/ https://sdk-04.moengage.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com *.typekit.net *.adabra.com *.adbr.io *.fontawesome.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com lightwidget.com *.adabra.com *.adbr.io *.addthis.com *.hotjar.com *.cookiebot.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.adabra.com *.adbr.io *.google.it fonts.gstatic.com *.zemanta.com *.clarity.ms *.bing.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.lightwidget.com code.jquery.com lightwidget.com *.adabra.com *.adbr.io cdn.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.hotjar.com *.fullstory.com fullstory.com *.clarity.ms *.cookiebot.com connect.facebook.net twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cdn.dnky.co webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.typekit.net *.adabra.com *.adbr.io *.fontawesome.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.adabra.com *.adbr.io *.addthis.com *.g.doubleclick.net *.clarity.ms *.hotjar.com *.cookiebot.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self'; script-src 'self'; report-uri https://www.kcrent.jp/csp-report/; 1 default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; report-uri /csp-violation-report 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com/ js.mollie.com *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ flagpedia.net https://www.mollie.com *.multisafepay.com https://redchamps.com 'self' data: ts.tradetracker.net www.magmodules.eu https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.disqus.com https://polyfill-fastly.io https://browser.sentry-cdn.com *.google.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ maps.googleapis.com js.mollie.com *.multisafepay.com https://pay.google.com tm.tradetracker.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.multisafepay.com *.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.gstatic.com maps.googleapis.com *.multisafepay.com t.elasticsuite.io *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.fontawesome.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.punchout2go.com *.tradecentric.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.usg.edu * 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.punchout2go.com *.tradecentric.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.klevu.com *.ksearchnet.com *.disqus.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.clarity.ms *.punchout2go.com *.tradecentric.com *.klevu.com *.ksearchnet.com *.disqus.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.fontawesome.com *.punchout2go.com *.tradecentric.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com https://www.pocketnurse.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.clarity.ms *.klevu.com *.ksearchnet.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.anyday.io *.fontawesome.com *.klarnacdn.net *.typekit.net https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.anyday.io *.klarna.com *.addthis.com *.facebook.com *.twitter.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.anyday.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net *.addthisedge.com *.twitter.com cdn.barlife.dk https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.anyday.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net *.klarnaservices.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com policy.app.cookieinformation.com cookieinformation.com ct.pinterest.com pinterest.com checkout.reepay.com load.ss.barlife.dk ss.barlife.dk ss.barlife.no barlifese.bar-life.se ss.barliife.de bat.bing.com s.pinimg.com widget.trustpilot.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.cloudflare.com ajax.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.anyday.io *.fontawesome.com https://static.klaviyo.com *.klarnacdn.net *.typekit.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.anyday.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com ekr.zdassets.com/ ws: *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com compucram.us11.list-manage.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.google.com *.addthis.com *.talkable.com *.compucram.com *.doubleclick.net nytrng.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.compucram.com *.purechat.com *.visualwebsiteoptimizer.com *.quantserve.com bat.bing.com www.facebook.com secure.gravatar.com i0.wp.com *.shop.pe cdn.cookielaw.org *.hsforms.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.omappapi.com *.purechat.com *.purechatcdn.com *.crazyegg.com *.cloudfront.net *.hotjar.com s3.amazonaws.com *.visualwebsiteoptimizer.com *.quantserve.com *.quantcount.com bat.bing.com connect.facebook.net shop.pe *.shop.pe *.bam.nr-data.net cdn.cookielaw.org geolocation.onetrust.com privacyportal.onetrust.com js-agent.newrelic.com matomo.colibrilearning.xyz cdn.optimizely.com js.hsforms.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.omappapi.com cdn.cookielaw.org unsafe-inline assets.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.omappapi.com *.purechat.com *.crazyegg.com *.doubleclick.net www.facebook.com *.shop.pe cdn.cookielaw.org geolocation.onetrust.com privacyportal.onetrust.com bam.nr-data.net logx.optimizely.com forms.hsforms.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: use.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.gstatic.com maps.googleapis.com *.disqus.com *.cloudfront.net https://www.mollie.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js maps.googleapis.com *.disqus.com https://cdn.polyfill.io https://browser.sentry-cdn.com js.mollie.com *.sendcloud.sc *.jsdelivr.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@v3.0.0/dist/cookieconsent.umd.js *.trustpilot.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@v3.0.0/dist/cookieconsent.css use.fontawesome.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ingest.sentry.io *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://media.ltsecurityinc.com https://static.ltsecurityinc.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://player.vimeo.com https://www.youtube-nocookie.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://media.ltsecurityinc.com https://static.ltsecurityinc.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://media.ltsecurityinc.com https://static.ltsecurityinc.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com s7.addthis.com *.avada.io https://player.vimeo.com https://www.youtube.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://media.ltsecurityinc.com https://static.ltsecurityinc.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ekr.zdassets.com/ https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://plumrocket.com app.chatterspot.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net nrastore.com *.cloudfront.net *.certcapture.com www.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com nrastore.com *.cloudfront.net cdn.nextopia.net *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.typekit.net *.cloudfront.net cdn.nextopia.net *.certcapture.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudfront.net persona.nextopia.net *.certcapture.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://*.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self' https://*.stripe.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' https://player.vimeo.com https://*.youtube.com https://bid.g.doubleclick.net https://td.doubleclick.net https://*.doubleclick.net https://www.paypal.com https://www.sandbox.paypal.com https://pilot-payflowlink.paypal.com https://*.stripe.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaevt.com https://www.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://firebasestorage.googleapis.com maps.gstatic.com 'self' https://www.paypal.com https://www.sandbox.paypal.com https://googleads.g.doubleclick.net https://www.google.com https://www.googletagmanager.com https://*.google.de data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com 'self' https://esd.equipment https://*.google-analytics.com https://*.googletagmanager.com https://*.paypal.com https://*.stripe.com https://*.klarna.com https://cdn.ampproject.org https://*.newrelic.com https://*.nr-data.net https://s.ytimg.com https://*.doubleclick.net https://static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://*.google-analytics.com https://*.googletagmanager.com https://*.paypal.com https://*.stripe.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaevt.com https://*.google.com https://*.analytics.google.com https://*.newrelic.com https://*.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com *.typekit.net *.cloudflare.net 'self' data: cdnjs.cloudflare.com cdn.jsdelivr.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com calendly.com *.google.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.webdamdb.com *.rectorseal.com rectorseal.com *.img-us3.com *.amazon.com *.amazonaws.com *.cloudfront.net *.linkedin.com *.google.com 'self' data: *.hs-banner.com *.hs-analytics.net *.hscollectedforms.net *.hsforms.com *.hubspot.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.calendly.com *.cloudfront.net *.licdn.com *.jsdelivr.com *.cloudflare.net *.hs-banner.com *.hs-analytics.net *.hscollectedforms.net *.hsforms.com *.hubspot.com *.hotjar.com *.pardot.com *.hs-scripts.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com *.typekit.net *.cloudflare.net cdnjs.cloudflare.com cdn.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.doubleclick.net *.hs-banner.com *.hs-analytics.net *.hscollectedforms.net *.hsforms.com *.hubspot.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.xempire.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.xempire.com join.gammasecure.com; script-src 'self' *.xempire.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.xempire.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self'; font-src 'self' data:; img-src 'self' data:; object-src 'none'; script-src 'self'; style-src 'self'; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.avada.io *.shopify.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://browser.sentry-cdn.com *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com *.oppwa.com oppwa.com *.peachpayments.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com https://js.klevu.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.unpkg.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.packeta.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.unpkg.com https://firebasestorage.googleapis.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.unpkg.com *.avada.io *.shopify.com *.packeta.com *.mailchimp.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.unpkg.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.unpkg.com https://get.geojs.io *.avada.io *.packeta.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com *.cloudfront.net *.reviews.io *.reviews.co.uk fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io widgets.automizely.com widgets.automizely.io https://images.unsplash.com www.feedoptimise.com cdn.feedoptimise.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io www.feedoptimise.com cdn.feedoptimise.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk maps.googleapis.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.automizely.com api.automizely.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-MHSG/ocv6sqhWKIDIfA65g=='; report-uri https://send.hsbrowserreports.com/csp/report 1 font-src *.gstatic.com 'self' data: *.googleapis.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.hotjar.com *.typekit.net cdn.curator.io static.klaviyo.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.youtube-nocookie.com www.google.com *.chatra.io *.hotjar.com *.facebook.com *.trustpilot.com *.kiyoh.com *.pinterest.com *.criteo.com *.cookiefirst.com www.googletagmanager.com *.weltpixel.com *.multisafepay.com https://pay.google.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com * scontent.fzty3-2.fna.fbcdn.net alb.reddit.com p.typekit.net www.facebook.com curator-assets.b-cdn.net *.multisafepay.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.gstatic.com *.chimpstatic.com downloads.mailchimp.com *.list-manage.com use.typekit.net *.cloudflare.com *.twitter.com *.fontawesome.com *.elfsight.com *.chatra.io *.jsdelivr.net chimpstatic.com *.facebook.com *.doubleclick.net *.trustpilot.com s.pinimg.com *.zdassets.com *.google-analytics.com *.feedbackcompany.com *.facebook.net *.hotjar.com *.mailchimp.com *.curator.io *.typekit.net *.clarity.ms *.leadinfo.net *.criteo.com www.googletagmanager.com *.googleadservices.com consent.cookiefirst.com *.cookiefirst.com www.datadoghq-browser-agent.com bat.bing.com *.tidio.co *.tidiochat.com *.iubenda.com js-agent.newrelic.com cdn.curator.io sleeknotecustomerscripts.sleeknote.com www.redditstatic.com embed.sendcloud.sc cdn.jsdelivr.net *.multisafepay.com https://pay.google.com www.google.com *.googletagmanager.com *.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.klaviyo.com unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net *.googleapis.com 'unsafe-inline' data: *.curator.io *.cookiefirst.com maxcdn.bootstrapcdn.com pay.multisafepay.com cdn.jsdelivr.net *.multisafepay.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src curatorio.s3.amazonaws.com curator-assets.b-cdn.net video-lga3-2.cdninstagram.com video-iad3-1.xx.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.googleapis.com *.cloudflare.com *.elfsight.com *.instacloud.io *.google-analytics.com *.google.com *.doubleclick.net *.hotjar.com *.hotjar.io ct.pinterest.com *.paypal.com *.zdassets.com *.zendesk.com *.feedbackcompany.com *.curator.io *.clarity.ms *.leadinfo.net *.cookiefirst.com gtm-mm85h6s-nzi2m.uc.r.appspot.com www.google-analytics.com www.google.com maps.googleapis.com *.livechatinc.com dev.visualwebsiteoptimizer.com www.googletagmanager.com pagead2.googlesyndication.com region1.analytics.google.com consent.cookiefirst.com www.redditstatic.com pixel-config.reddit.com edge.cookiefirst.com sendcloud-checkout-static-data.sendcloud.sc *.multisafepay.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com k.clarity.ms analytics.sleeknote.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src i.icomoon.io use.typekit.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.googletagmanager.com *.sendcloud.sc *.jsdelivr.net *.doubleclick.net *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.amazonaws.com www.google.be www.google.co.uk www.facebook.com maps.gstatic.com maps.googleapis.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sendcloud.sc *.jsdelivr.net *.facebook.net maps.googleapis.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sendcloud.sc *.jsdelivr.net *.icomoon.io *.typekit.net fonts.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com stats.g.doubleclick.net *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com maps.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.cdninstagram.com *.fbcdn.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com s7.addthis.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.unbxdapi.com *.unbxd.io *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.productreview.com.au *.bootstrapcdn.com *.clickcease.com *.clarity.ms *.bing.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.unbxdapi.com *.unbxd.io *.coupahost.com app.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.clickcease.com *.clarity.ms *.productreview.com.au *.bing.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.ariba.com *.t1cloud.com https://seo.mageplaza.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.ariba.com *.coupahost.com *.t1cloud.com app.instapunchout.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.unbxdapi.com *.unbxd.io *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.clickcease.com *.clarity.ms *.productreview.com.au *.bing.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * hcaptcha.com *.hcaptcha.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.unbxdapi.com *.unbxd.io *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.bing.com *.googleadservices.com *.google-analytics.com *.google.com *.googletagmanager.com *.magezon.com *.productreview.com.au *.paypalobjects.com *.google.co.in *.googleapis.com *.clickcease.com *.clarity.ms www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com *.disqus.com instant-imgs.s3.ap-southeast-2.amazonaws.com southland.com.au *.southland.com.au https://firebasestorage.googleapis.com *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://api.addressfinder.io *.unbxdapi.com *.unbxd.io *.klevu.com *.googleapis.com *.cloudfront.net *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.clickcease.com *.clarity.ms *.productreview.com.au *.bing.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com *.instant.one *.instant-dpryor.ngrok.dev instant-dpryor.ngrok.dev *.instant-tschipke.ngrok.dev instant-tschipke.ngrok.dev hcaptcha.com *.hcaptcha.com *.avada.io connect.facebook.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.tawk.to cdn.jsdelivr.net landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io *.fontawesome.com *.unbxdapi.com *.unbxd.io *.klevu.com *.googleapis.com *.fontawsome.com *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.bootstrapcdn.com *.clickcease.com *.clarity.ms *.productreview.com.au *.bing.com assets.braintreegateway.com hcaptcha.com *.hcaptcha.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.unbxdapi.com *.unbxd.io *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.clickcease.com *.clarity.ms *.productreview.com.au *.bing.com *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com api.magento.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io *.unbxdapi.com *.unbxd.io *.coupahost.com *.instapunchout.com *.microsoftazuread-sso.com *.microsoftonline.com *.clarity.ms *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.paypalobjects.com https://get.geojs.io *.tawk.to *.productreview.com.au *.clickcease.com *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.api.instant.one *.instant.one instant-imgs.s3.ap-southeast-2.amazonaws.com unbxd-console-platform.s3.amazonaws.com hcaptcha.com *.hcaptcha.com *.avada.io *.analytics.google.com stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com wss://*.tawk.to landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com https://*.fontawesome.com *.fontawesome.com *.googleapis.com https://*.gstatic.com *.alothemes.com *.magepow.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline' https://embed.tawk.to https://*.googleapis.com data: https://fonts.gstatic.com https://fonts.googleapis.com https://i.ytimg.com https://yt3.ggpht.com https://assets.reviews.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net magefan.com cm.magefan.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.hsforms.net *.hsforms.com 'self' data: 'self' https://tawk.link data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.googleapis.com *.gstatic.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.hsforms.net *.hsforms.com https://www.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' https://www.googleadservices.com https://cdn.evgnet.com https://t.elasticsuite.io https://www.google-analytics.com https://www.googletagmanager.com https://cc.cdn.civiccomputing.com https://embed.tawk.to https://apikeys.civiccomputing.com https://va.tawk.to https://js.stripe.com https://connect.facebook.net https://snap.licdn.com https://px.ads.linkedin.com https://assets.reviews.io https://widget.reviews.io https://www.clarity.ms https://c.clarity.ms https://l.clarity.ms https://b.clarity.ms https://settings.luckyorange.com https://tools.luckyorange.com https://sg-production.wcdpreview.uk https://apple-pay-gateway.apple.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.alothemes.com *.magepow.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' https://embed.tawk.to https://*.dotdigital-pages.com https://assets.reviews.io 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://t.elasticsuite.io *.hsforms.net *.hsforms.com https://analytics.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' https://apikeys.civiccomputing.com https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://www.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://pilot-payflowlink.paypal.com https://*.paypal.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://*.trackedlink.net https://*.trackedweb.net https://*.dotdigital-pages.com https://webchat.dotdigital.com https://webchat.staging.dotdigital.com https://*.klarna.com https://klarna.com https://*.klarnacdn.net https://*.klarnaevt.com https://*.stripe.com https://r.stripe.com https://apple-pay-gateway.apple.com https://*.avada.io https://*.alothemes.com https://*.magepow.com https://*.hsforms.net https://*.hsforms.com https://va.tawk.to https://embed.tawk.to wss://*.tawk.to https://cdn.evgnet.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://bat.bing.com https://c.clarity.ms https://l.clarity.ms https://b.clarity.ms https://www.clarity.ms https://connect.facebook.net https://px.ads.linkedin.com https://snap.licdn.com https://api.reviews.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googletagmanager.com *.google-analytics.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.googletagmanager.com *.google-analytics.com *.stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; report-uri https://seopanamahosting.com?gdsih-csp-report; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://edge.marker.io/latest/shim.js https://www.googletagmanager.com/gtm.js https://w19.captcha.at/sdk.js https://edge.marker.io/latest/2.v2.15.0.f2fdbd0e05d6efcac7d3.js https://edge.marker.io/latest/3.v2.15.0.d94e68f6b8a22e3b32c2.js https://edge.marker.io https://www.baufi-lead.de https://www.youtube.com/iframe_api https://www.googletagmanager.com https://unpkg.com/micromodal@0.4.10/dist/micromodal.min.js https://cdn.jsdelivr.net/npm/air-datepicker@3.3.5/air-datepicker.min.js https://js-eu1.hs-analytics.net/analytics/ https://js-eu1.hs-banner.com/v2/25186610/banner.js https://js-eu1.hsleadflows.net/leadflows.js https://js-eu1.hubspot.com/web-interactives-embed.js https://js-eu1.hs-scripts.com/25186610.js https://www.youtube.com/s/player/c9dd45ed/www-widgetapi.vflset/www-widgetapi.js https://www.baufi-lead.de/baufilead/partner/9JkejpCHJ5aDn4bP2WYVb65WPDAXXj/imports.js https://www.youtube.com/s/player/ https://developer.ogulo.com/js/ https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/2756326424442993 https://googleads.g.doubleclick.net/ https://www.ksk-immobilien.de/wp-content/plugins/wp-sentry-integration/public/wp-sentry-init.js https://energieausweis.de/scripts/dist/reseller.min.js https://www.googleadservices.com https://www.google.com https://cdn.consentmanager.net https://c.delivery.consentmanager.net www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: https://cdn.consentmanager.net https://c.delivery.consentmanager.net www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://images.ksk-immobilien.de/www.ksk-immobilien.de/uploads/immobilie-kaufen-startseite.jpg https://images.ksk-immobilien.de https://www.captcha.eu/logo-small40.png https://www.captcha.eu https://cdn.consentmanager.net/delivery/recall/recall_shield.svg https://cdn.consentmanager.net https://c.delivery.consentmanager.net https://amazonaws.com https://track-eu1.hubspot.com https://www.facebook.com https://www.google.com/pagead/1p-user-list/755947047/ https://perf-eu1.hsforms.com/embed/v3/counters.gif https://www.google.de/pagead/1p-user-list/755947047/ https://googleleads.g.doubleclick.net https://www.google.com https://google.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com data: www.googletagmanager.com; connect-src 'self' https://connect.facebook.net https://connect.facebook.net/en_US/fbevents.js https://o149539.ingest.sentry.io/api/5793876/envelope/ https://www.google.com/ https://analytics.ksk-immobilien.de/ https://region1.analytics.google.com/ https://stats.g.doubleclick.net/ https://js-eu1.hs-banner.com/ https://cta-eu1.hubspot.com/ https://forms-eu1.hubspot.com/ https://googleads.g.doubleclick.net/ https://api.marker.io/widget/ping https://www.baufi-lead.de www.googletagmanager.com; font-src 'self' data: https://cdn.consentmanager.net https://c.delivery.consentmanager.net data:; object-src * ; media-src 'self' https://cdn.consentmanager.net https://c.delivery.consentmanager.net; frame-src 'self' https://td.doubleclick.net/ https://tour.ogulo.com/ https://app.kyl.immo https://energieausweis.de/energieausweis2/bedarfsausweis-wohngebaeude/ https://www.ksk-immobilien.de/energieausweis2/bedarfsausweis-wohngebaeude/ www.googletagmanager.com; manifest-src 'none' ; child-src 'self' www.googletagmanager.com; worker-src 'self' https://www.ksk-immobilien.de; base-uri 'none' ; form-action 'self' ; frame-ancestors 'none' ; 1 default-src 'self'; script-src 'report-sample' 'self' https://app.whoisvisiting.com/who.js https://connect.facebook.net/en_US/fbevents.js https://lc.iadvize.com/iadvize.js https://script.hotjar.com/modules.1e98293c16a88afdf1b7.js https://sibautomation.com/sa.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.hotjar.com/c/hotjar-900238.js https://unpkg.com/swiper/swiper-bundle.js https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/NZrMWHVy58-S9gVvad9HVGxk/recaptcha__fr.js; style-src 'report-sample' 'self' https://unpkg.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://content.hotjar.io https://in-automate.sendinblue.com https://in.hotjar.com https://lc.iadvize.com wss://wsp21.hotjar.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://sibautomation.com https://widget.trustpilot.com https://www.google.com; img-src 'self' https://dashboard.whoisvisiting.com https://px.ads.linkedin.com https://www.facebook.com; manifest-src 'self'; media-src 'self'; report-uri https://642c042d622ceaeaddd42e78.endpoint.csper.io/?v=0; worker-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com moroso.us14.list-manage.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.weltpixel.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com *.googleapis.com *.clarity.ms *.bing.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net developers.google.com acsbapp.com *.acsbapp.com *.addthis.com *.clarity.ms chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com downloads.mailchimp.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com *.gstatic.com *.googleapis.com bam.nr-data.net bam-cell.nr-data.net developers.google.com acsbapp.com *.acsbapp.com *.addthis.com *.clarity.ms form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /_csp/report; report-to report-endpoint; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.authorize.net *.brevo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com magefan.com cm.magefan.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ s7.addthis.com *.authorize.net *.brevo.com *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com ekr.zdassets.com/ *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://683a17cb-2730-43d7-9160-6b8b43e52cd9.sansec.watch/; report-to report-endpoint; 1 font-src api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.google.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.stape.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://ps1.ncrsecurepay.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://ps1.ncrsecurepay.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://ps1.ncrsecurepay.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.stape.io unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://ps1.ncrsecurepay.com *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' monashuni.okta.com *.oktacdn.com; connect-src 'self' monashuni.okta.com monashuni-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com monashuni.kerberos.okta.com monashuni.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-_eLwybYF8IjfmIyuntta2w' 'unsafe-eval' 'self' 'report-sample' monashuni.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-_eLwybYF8IjfmIyuntta2w' 'self' 'report-sample' monashuni.okta.com *.oktacdn.com; frame-src 'self' monashuni.okta.com monashuni-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' monashuni.okta.com *.oktacdn.com https://ok8static.oktacdn.com/fs/bcg/4/gfs4cm0e9zTmZn4WU3l7 *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' monashuni.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://my.monash.apps.monash.edu 1 default-src 'self'; script-src 'self' 'wasm-unsafe-eval' https://*.google.com https://www.gstatic.com https://www.googletagmanager.com https://*.segment.com https://*.sentry.io https://*.hotjar.com https://*.checkout.com https://*.iesnare.com https://*.zdassets.com https://*.smooch.io https://*.twilio.com; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob: https://*.frasers.plus https://*.tymit.com https://*.fgfs.services https://*.checkout.com https://www.googletagmanager.com https://*.zdassets.com https://*.zdusercontent.com https://*.zendesk.com; connect-src 'self' https://*.tymit.io https://*.tymit.com https://*.fgfs.services https://*.segment.io https://*.segment.com https://*.segmentapis.com https://*.sentry.io https://*.hotjar.io https://*.hotjar.com https://*.firebase.google.com https://*.googleapis.com https://*.google-analytics.com https://www.google.com https://www.googletagmanager.com https://*.checkout.com https://*.iesnare.com https://*.zdassets.com https://*.zendesk.com wss://*.iesnare.com wss://*.hotjar.com wss://api.smooch.io wss://*.zendesk.com https://*.twilio.com; frame-src 'self' https://*.google.com https://*.checkout.com; media-src 'self' https://static.zdassets.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; report-uri https://o1286768.ingest.us.sentry.io/api/6691512/security/?sentry_key=07a6d722bc084e008b023ebf73aa0513; report-to csp-endpoint 1 script-src 'nonce-5YCtsK-aT1U5K58r1n0vlg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klaviyo.com *.heyflow.cloud *.prd.heyflow.com *.reviews.io *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ test.saferpay.com www.saferpay.com saferpay.com js.mollie.com www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com bat.bing.com bat.bing.net *.storyblok.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ test.saferpay.com www.saferpay.com saferpay.com https://*.usercentrics.eu https://userlike-cdn-operators.userlike.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com https://js-eu1.hsforms.net/forms/embed/v2.js bat.bing.com bat.bing.net cdn.mouseflow.com *.cloudfront.net *.prd.heyflow.com *.reviews.io *.clarity.ms *.abtasty.com *.storyblok.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ test.saferpay.com www.saferpay.com saferpay.com https://*.usercentrics.eu https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net https://api.userlike.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com www.youtube.com player.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.typekit.net *.heyflow.cloud *.prd.heyflow.com *.reviews.io *.storyblok.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.storyblok.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.amazonaws.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com https://player.vimeo.com bat.bing.com bat.bing.net *.execute-api.eu-central-1.amazonaws.com *.clarity.ms *.abtasty.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ test.saferpay.com www.saferpay.com saferpay.com https://*.usercentrics.eu https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.userlike.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://4b389dcc-7b01-4225-801a-74fac70c5da1.sansec.watch/; report-to report-endpoint; 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-dJ9FQk33T1ljA8yJK-Unmw'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-dJ9FQk33T1ljA8yJK-Unmw'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self'; report-uri https://uk3hg0f8.uriports.com/reports/report 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://css.zohocdn.com https://fonts.gstatic.com https://unpkg.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://js.stripe.com/ *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com https://*.supplychimp.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com validator.swagger.io www.apptrian.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com s7.addthis.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://salesiq.zoho.com https://js.zohocdn.com https://cdn.pagesense.io https://js.stripe.com/ https://js-agent.newrelic.com/ https://bam-cell.nr-data.net/ https://bam.nr-data.net/ *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com *.fontawesome.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com https://salesiq.zoho.com https://css.zohocdn.com http://fonts.googleapis.com https://fonts.googleapis.com https://unpkg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com ekr.zdassets.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://*.zoho.com https://*.zohopublic.com ws://vts.zohopublic.com https://bam.nr-data.net/ *.mmapiws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.asc-stage-magento.com asc-stage-magento.com *.channels.magento.com channels.magento.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klevu.com *.ksearchnet.com fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://maps.gstatic.com https://maps.googleapis.com https://images.unsplash.com blob: flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/ *.avada.io maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.google.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://maps.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' .clubedomalte.com.br *..clubedomalte.com.br wake-components.fbitsstatic.net ClubeDoMalte.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com cnt.my retargeter.com.br shopconvert.com.br tawk.to getblue.io hospedagemweb.net hotjar.io hotjar.com adschoom.com cloudflare.com linximpulse.net viptarget.com.br googleadservices.com smarthint.co bing.com ebit.com.br shoptarget.com.br googleapis.com doubleclick.net shopback.net citydsp.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.citydsp.com *.bing.com *.ebit.com.br *.shoptarget.com.br *.doubleclick.net *.shopback.net *.googleapis.com *.adschoom.com *.cloudflare.com *.linximpulse.net *.hotjar.com *.viptarget.com.br *.googleadservices.com *.smarthint.co *.hotjar.io *.getblue.io *.hospedagemweb.net *.tawk.to *.cnt.my *.retargeter.com.br *.shopconvert.com.br wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.picpay.com *.lomadee.com *.rakuten.com *.linksynergy.com *.nxtck.com *.xg4ken.com *.mybeerclass.com.br mybeerclass.com.br *.criteotilt.com *.criteo.net *.criteo.com aprtn.com *.aprtn.com *.g.doubleclick.net *.google.com *.plataformasocial.com.br *.dataroyal.com.br *.acstat.com *.advcakebr.com *.clearsale.com.br app.picpay.com *.googleoptimize.com *.amazonaws.com *.execute-api.sa-east-1.amazonaws.com vfourc5jd2.execute-api.sa-east-1.amazonaws.com dzpxyxks1bfmb.cloudfront.net *.duminio.com *.nacaocervejeira.com.br nacaocervejeira.com.br *.enviou.com.br *.gstatic.com *.google.com.br *.fbits.net *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.content-security-policy.com *.l2.io l2.io gstatic.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.com.pe *.netdeal.com.br checkout.clubedomalte.com.br signalrcore.fbits.net *.afilio.com.br wss://signalrcore.fbits.net *.g2afse.com *.analytics.tiktok *.netdeal.com *.cloudfront.net netdeal.com.br *.fontawesome.com *.rtb123.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.tps: tps: *.adnxs.com *.tiktok.com pub-csp.fbits.net google-analytics.com *.viacep.com.br *.clubedomalte.com.br *.localhost:5501 localhost:5501 *.fbitsstatic.net recursos.clubedomalte.com.br *.preciso.net d3u0jcwe5p7qrc.cloudfront.net d2rp1k1dldbai6.cloudfront.net cybba-bucket.s3.amazonaws.com *.cybba.solutions *.cybba.us storage.googleapis.com c.amazon-adsystem.com *.stackadapt.com *.adsrvr.org *.facebook.net *.cybbaview.com *.fbits.store *.adyen.com *.safrapay.com.br *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io td.doubleclick.net googleads.g.doubleclick.net *.us-central1.run.app *.stapecdn.com test-drive-20-1053047382554.us-central1.run.app *.pinimg.com stapecdn.com *.belvo.io *.cloudfront.net d335luupugsy2.cloudfront.net *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.a.run.app mpc-prod-14-s6uit34pua-ue.a.run.app demo-1.conversionsapigateway.com *.conversionsapigateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *..clubedomalte.com.br .clubedomalte.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.mercadolibre.com *.cookiebot.com *.googletagmanager.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io https://docs.google.com https://www.googletagmanager.com/ challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.facebook.com *.googleadservices.com *.google-analytics.com *.google.com.br *.mercadopago.com.br *.beltnutrition.com.br cdn.mundipagg.com api.pagar.me http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com http://www.vimeo.com/ www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.mlstatic.com *.mercadopago.com https://www.googleoptimize.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://consent.cookiebot.com/ http://www.google-analytics.com/ http://www.googleadservices.com/ http://www.paypal.com/ http://www.facebook.com/ https://js-agent.newrelic.com/ https://vfr-v3-production.sizebay.technology/ https://maps.google.com/ https://www.google.com/ *.cloudfront.net *.facebook.net *.sdk.mercadopago.com *.googletagmanager.com https://viacep.com.br/ *.avada.io 3ds2.pagar.me 3ds2-sdx.pagar.me challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com *.fontawesome.com *.jsdelivr.net/ *.cloudflare.com/ *.googleapis.com *.cloudfront.net *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.mercadopago.com *.mercadolibre.com https://www.google-analytics.com/ *.facebook.com https://viacep.com.br https://get.geojs.io *.avada.io api.mundipagg.com api.pagar.me *.gstatic.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.viacep.com.br 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self' https://d6tizftlrpuof.cloudfront.net/live/;connect-src 'self' https://api.just.nl https://app.talkjs.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://czgroep.piwik.pro https://dev.visualwebsiteoptimizer.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com;font-src 'self' data:;frame-src 'self' https://consentcdn.cookiebot.com;frame-ancestors 'self';img-src 'self' https://6005850.global.siteimproveanalytics.io https://d6tizftlrpuof.cloudfront.net https://dev.visualwebsiteoptimizer.com https://imgsct.cookiebot.com;manifest-src 'self';media-src 'self' https://cdn.talkjs.com;object-src 'self';script-src 'self' https://cdn.talkjs.com https://cdstatic-sc.cz.nl https://consent.cookiebot.com https://consentcdn.cookiebot.com/consentconfig/ https://czgroep.containers.piwik.pro/ppms.js https://dev.visualwebsiteoptimizer.com https://inzicht.cz.nl/containers/ https://siteimproveanalytics.com/js/ https://w.usabilla.com https://www.googletagmanager.com 'unsafe-inline' 'unsafe-eval';style-src 'self' https://cdstatic-sc.cz.nl 'unsafe-inline';worker-src 'self' blob:; 1 font-src fonts.googleapis.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google.com h.online-metrix.net eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com c.sharethis.mgr.consensu.org *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com maps.googleapis.com maps.gstatic.com platform-api.sharethis.com platform-cdn.sharethis.com l.sharethis.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com cdn.conekta.io conektaapi.s3.amazonaws.com h.online-metrix.net eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com static.zdassets.com buttons-config.sharethis.com platform-cdn.sharethis.com platform-api.sharethis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.conekta.io ekr.zdassets.com l.sharethis.com *.zendesk.com wss://widget-mediator.zopim.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.bird.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com fmgaggi.com images.simpletire.com rs.fullstory.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com static.hotjar.com fmgaggi.com simpletire.com edge.fullstory.com rs.fullstory.com cdn.rudderlabs.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com simpletire.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.addressy.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com fmgaggi.com static.hotjar.com simpletire.com affiliate.simpletire.com edge.fullstory.com rs.fullstory.com api.rudderstack.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src http: wss:; script-src http: 'unsafe-inline'; style-src http: 'unsafe-inline'; img-src http: data:; font-src http: data:; report-uri /csp-report 1 font-src *.fontawesome.com *.cloudflare.com cdnjs.cloudflare.com cdn.jsdelivr.net cookiechimp.com www.cookiechimp.com *.cookiechimp.com *.frogbikes.com frogbikes.com static.klaviyo.com fonts.gstatic.com *.gstatic.com self data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com *.extforms.netsuite.com self 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.sharethis.com *.dotdigital-pages.com *.dotdigital.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.frogbikes.com *.usercentrics.eu www.xtento.com widget.trustpilot.com *.userway.org www.google.com *.gstatic.com app.usercentrics.eu *.doubleclick.net cookiechimp.com www.cookiechimp.com *.cookiechimp.com frogbikes.com *.extforms.netsuite.com self 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.frogbikes.com *.usercentrics.eu www.xtento.com cdn.xtento.com *.userway.org *.cloudfront.net cookiechimp.com www.cookiechimp.com *.cookiechimp.com www.facebook.com www.googletagmanager.com *.gstatic.com frogbikes.com alb.reddit.com bat.bing.com c.clarity.ms c.bing.com *.jsdelivr.net self data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.usercentrics.eu *.jquery.com *.frogbikes.com *.newrelic.com *.lr-in-prod.com www.xtento.com cdn.xtento.com widget.trustpilot.com *.userway.org *.jsdelivr.net app.termly.io js.klarna.com js-agent.newrelic.com code.jquery.com *.klaviyo.com connect.facebook.net bat.bing.com www.clarity.ms cdn.storerocket.io cookiechimp.com www.cookiechimp.com *.cookiechimp.com frogbikes.com www.redditstatic.com maps.googleapis.com *.gstatic.com cdnjs.cloudflare.com *.cloudflare.com *.extforms.netsuite.com self 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com cc-cdn.com https://static.klaviyo.com *.fontawesome.com unsafe-inline *.frogbikes.com *.cloudflare.com fonts.googleapis.com *.gstatic.com *.userway.org *.jsdelivr.net static.klaviyo.com cookiechimp.com www.cookiechimp.com *.cookiechimp.com frogbikes.com cdnjs.cloudflare.com self 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com bam.nr-data.net *.usercentrics.eu *.google-analytics.com *.lr-in-prod.com *.analytics.google.com maps.googleapis.com *.gstatic.com *.userway.org app.termly.io widget.trustpilot.com storerocket.io *.klaviyo.com a.clarity.ms cookiechimp.com www.cookiechimp.com *.cookiechimp.com *.reddit.com www.redditstatic.com *.frogbikes.com frogbikes.com bat.bing.com bat.bing.net www.google.com *.extforms.netsuite.com self 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' data: stats.g.doubleclick.net googleads.g.doubleclick.net static.doubleclick.net static.addtoany.com addtoany.com www.googletagmanager.com www.youtube.com *.fontawesome.com www.google-analytics.com *.googleapis.com fonts.gstatic.com *.gstatic.com; script-src 'self' 'unsafe-inline' data: stats.g.doubleclick.net googleads.g.doubleclick.net static.doubleclick.net static.addtoany.com addtoany.com www.googletagmanager.com www.youtube.com *.fontawesome.com www.google-analytics.com *.googleapis.com fonts.gstatic.com *.gstatic.com; report-uri /report-csp-violation 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.datatrics.com https://fonts.gstatic.com https://searchserverapi.com maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://*.facebook.com https://*.googleapis.com https://searchserverapi.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com https://*.dialogflow.com https://*.doubleclick.net https://*.facebook.com https://*.hotjar.com https://searchserverapi.com https://*.sharethis.com https://*.snapchat.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com *.tiktok.com https://*.cookiebot.com https://*.datatrics.com https://*.examenoverzicht.nl https://*.facebook.com https://*.facebook.net https://*.google.com https://*.google.nl https://*.g.doubleclick.net https://*.privacysandbox.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.pay.nl https://*.reddit.com https://*.sharethis.com https://searchserverapi.com https://*.snapchat.com https://*.squeezely.tech https://*.visualwebsiteoptimizer.com https://www.magezon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.tiktok.com https://cdn.amplitude.com https://*.aptrinsic.com https://*.calendly.com https://*.cloudflareinsights.com https://*.cookiebot.com https://*.datatrics.com https://*.facebook.com https://*.facebook.net https://*.google.com https://*.google.nl https://*.googleadservices.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.googleapis.com https://sc-static.net https://*.googlesyndication.com https://*.googletagmanager.com https://*.gstatic.com https://*.hotjar.com https://*.jsdelivr.net https://*.redditstatic.com https://searchserverapi.com https://*.sharethis.com https://*.snapchat.com https://squeezely.tech https://*.tiktok.com https://*.visualwebsiteoptimizer.com https://*.youtube.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com https://*.datatrics.com https://*.googleapis.com https://searchserverapi.com https://*.sharethis.com https://*.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.tiktok.com https://*.cookiebot.com https://*.datatrics.com https://*.examenoverzicht.nl https://*.exovdev.nl https://*.exovtest.nl connect.facebook.net https://*.feedbackcompany.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.googleapis.com https://*.google.com https://*.googlesyndication.com https://*.hotjar.com https://*.hotjar.io https://*.pangle-ads.com https://*.sharethis.com https://*.snapchat.com https://*.tiktok.com https://*.tiktokw.us https://*.visualwebsiteoptimizer.com wss://*.hotjar.com www.facebook.com graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.amplitude.com stats.g.doubleclick.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.cleverreach.com https://www.gstatic.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cleverreach.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.cleverreach.com newassets.hcaptcha.com landofcoder.com https://www.google.com https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudfront.net www.gstatic.com *.trackedlink.net *.googleapis.com *.fbcdn.net *.google.de *.google.com *.facebook.com *.cdninstagram.com *.instagram.com *.paypal.com *.crl.eu *.smartsuppcdn.com *.ytimg.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.google.com *.googleapis.com *.gstatic.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.instagram.com *.facebook.com *.facebook.net *.googletagmanager.com cdnjs.cloudflare.com paypalobjects.com *.smartsuppchat.com *.smartsuppcdn.com *.qualtrics.com hcaptcha.com landofcoder.com https://www.google.com https://www.gstatic.com *.avada.io https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com *.google.com *.gstatic.com *.smartsuppcdn.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.smartsuppcdn.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.paypal.com *.google.com *.gstatic.com *.smartsuppcdn.com *.smartsupp.com *.smartsuppchat.com *.google-analytics.com *.doubleclick.net *.qualtrics.com wss://websocket-visitors.smartsupp.com *.hcaptcha.com landofcoder.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src hcaptcha.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com maxcdn.bootstrapcdn.com *.googleapis.com *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.dpdconnect.nl landofcoder.com maps.googleapis.com chart.googleapis.com www.facebook.com platform.twitter.com *.facebook.com *.hotjar.com https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://belco-prod.s3-eu-central-1.amazonaws.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://www.kippenhuis.nl https://www.plukmachine.nl https://stats.g.doubleclick.net *.google.com *.google.nl https://dev.visualwebsiteoptimizer.com http://www.w3.org 'self' data: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com flagpedia.net *.multisafepay.com https://c.clarity.ms https://c.bing.com https://cdn1.avada.io data: 'self'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.belco.io *.belco.io https://*.dpdconnect.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com landofcoder.com maps.googleapis.com chart.googleapis.com s7.addthis.com connect.facebook.net twitter.com platform.twitter.com *.chimpstatic.com *.googleapis.com bam.nr-data.net bam.eu01.nr-data.net https://maps.google.com *.hotjar.com https://polyfill.io *.pinterest.com *.facebook.net *.facebook.com https://googleads.g.doubleclick.net *.googletagmanager.com http://dev.visualwebsiteoptimizer.com *.gstatic.com *.salesfeed.com *.leadinfo.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.multisafepay.com https://pay.google.com https://www.clarity.ms https://consent.cookiefirst.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.googleapis.com downloads.mailchimp.com *.bootstrapcdn.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.multisafepay.com https://consent.cookiefirst.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com cdn.belco.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com wss://chat.belco.io https://cdn.belco.io *.belco.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com landofcoder.com maps.googleapis.com chart.googleapis.com ekr.zdassets.com/ *.google-analytics.com *.g.doubleclick.net *.facebook.com https://region1.analytics.google.com *.hotjar.com *.cloudflare.com *.bootstrapcdn.com *.yotpo.com *.addthis.com *.salesfeed.com *.leadinfo.net *.leadinfo.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io www.gstatic.com *.multisafepay.com https://t.clarity.ms https://consent.cookiefirst.com https://edge.cookiefirst.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.mommysgirl.com *.girlsway.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.mommysgirl.com *.girlsway.com join.gammasecure.com; script-src 'self' *.mommysgirl.com *.girlsway.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.mommysgirl.com *.girlsway.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src * data: blob: 'unsafe-inline'; script-src * 'unsafe-inline'; script-src-elem * 'unsafe-inline'; style-src * 'unsafe-inline'; font-src * data:; img-src * data: blob:; connect-src * wss:; frame-src *; object-src 'none'; frame-ancestors *; report-uri /csp-report-endpoint.php 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.innoship.ro www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.cdninstagram.com *.fbcdn.net *.tile.openstreetmap.org *.openstreetmap.org *.disqus.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com cdn.ampproject.org googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com *.disqus.com *.avada.io www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.google.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-T2Y2ba5IpPSwevcvY9cUBGMZVaQ=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' frame-ancestors 'self'; connect-src 'self' https://api.newsletter2go.com https://consent.cookiefirst.com https://edge.cookiefirst.com; script-src 'self' 'unsafe-inline' https://static.newsletter2go.com/utils.js https://consent.cookiefirst.com; font-src 'self'; style-src 'self' https://consent.cookiefirst.com 'unsafe-inline'; img-src 'self' data: https://api.newsletter2go.com https://files.newsletter2go.com; frame-src 'self' https://report.sayway.com/s/pj8vbA https://3d-tour.linsenspektrum.de/tour/ https://www.youtube-nocookie.com/embed/; worker-src 'self'; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' www.ewebcart.com www.google-analytics.com www.googletagmanager.com secure.leadforensics.com bat.bing.com cdn.cookie-script.com snap.licdn.com/li.lms-analytics/insight.min.js *.googleapis.com cdn.livechatinc.com api.livechatinc.com ldynamicspublicapi.leadforensics.com embedr.flickr.com www.youtube.com widgets.flickr.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src 'self' ldynamicspublicapi.leadforensics.com www.google.com www.google.co.uk bat.bing.com *.linkedin.com cdn.livechatinc.com www.google-analytics.com live.staticflickr.com; font-src *; connect-src 'self' www.google-analytics.com bat.bing.com stats.g.doubleclick.net www.google.com ldynamicspublicapi.leadforensics.com api.livechatinc.com; media-src userlike-cdn-widgets.s3-eu-west-1.amazonaws.com; frame-src userlike-cdn-widgets.s3-eu-west-1.amazonaws.com www.youtube-nocookie.com www.youtube.com www.google.com; prefetch-src fonts.googleapis.com; 1 default-src 'self'; frame-ancestors 'self'; 1 font-src *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com api-maps.yandex.ru yastatic.net *.maps.yandex.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.retailrocket.ru *.disqus.com *.avada.io *.shopify.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com api-maps.yandex.ru yastatic.net *.maps.yandex.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.retailrocket.ru https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; frame-src https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; img-src 'self' https: data:; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; manifest-src 'self' https:; media-src 'self' https:; connect-src 'self' https: 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' cafdonate.cafonline.org assets.calendly.com *.googletagmanager.com *.google-analytics.com https://unpkg.com/htmx.org@1.7.0/dist/htmx.js https://unpkg.com/htmx.org@1.7.0/dist/htmx.min.js cdnjs.cloudflare.com/ajax/libs/gsap/3.10.2/gsap.min.js https://cdnjs.cloudflare.com/ https://www.eventbrite.co.uk/static/widgets/eb_widgets.js cdn.datatables.net; style-src 'self' 'unsafe-inline'; frame-src 'nonce-c2h5enRyYmhpeXN4d2pnc3J4emtjYWVoZGJpcnNzcW5neW5k' *.youtube.com *.calendly.com *.cafonline.org *.eventbrite.co.uk; 1 script-src-attr *.tesup.com; script-src-elem *.tesup.com; font-src *.gstatic.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net https://firebasestorage.googleapis.com https://www.mollie.com *.designer-images.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.mollie.com *.stat-track.com polyfill.io *.moosend.com *.zendesk.com *.zdassets.com *.tesup.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com *.moosend.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com ipinfo.io *.zendesk.com wss://widget-mediator.zopim.com *.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://plumrocket.com https://www.youtube.com https://form.typeform.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.googletagmanager.com 'self' matomo.thewetailers.fr analytics.ecpad.fr https://matomo.thewetailers.fr https://analytics.ecpad.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maps.googleapis.com https://matomo.thewetailers.fr https://analytics.ecpad.fr 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' minhacasasolar.com.br *.minhacasasolar.com.br wake-components.fbitsstatic.net minhacasasolar.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net *.minhacasasolar.com.br *.ecommercegateway.com.br *.itau.com *.itau.com.br *.itaushopline.com.br *.itaushopline.com *.clearsale.com.br *.criteo.net *.shoptarget.com.br app.shoptarget.com.br *.onesignal.com *.trustvox.com.br *.ip.sb *.alphassl.com *.ecommercemail.com.br rawgit.com *.jivosite.com *.criteo.com *.googleadservices.com *.masterpass.com *.amazonaws.com *.gstatic.com *.dc.linximpulse.net *.g.doubleclick.net cdnjs.cloudflare.com checkout.minhacasasolar.com.br masterpass.com apis.google.com cdn.onesignal.com rate.trustvox.com.br sslwidget.criteo.com integration-healthy.dc.linximpulse.net *.mundipaggone.com *.linximpulse.net *.fbits.net poscompra.shopconvert.com.br *.shopconvert.com.br static.shopback.net *.ckies.net *.shopback.net cdn.jsdelivr.net ajax.googleapis.com *.retargeter.com.br trustvox.com.br events.chaordicsystems.com *.chaordicsystems.com click.retargeter.com.br onesignal.com wss://chat-ca.jivosite.com ckies.net google.com *.google.com *.facebook.net certificate.trustvox.com.br api-ads.percycle.com wss://node224.jivosite.com *.googlesyndication.com *.google-analytics.com connect.facebook.net recursos.minhacasasolar.com.br recursos.ecommercegateway.com.br k-analytix.com *.k-analytix.com i.konduto.com ssl.google-analytics.com *.facebook.com facebook.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net cdn.bitrix24.com *.bitrix24.com googletagmanager.com *.googletagmanager.com gm.fbits.net suite.linximpulse.net collect.chaordicsystems.com api.shopback.net gum.criteo.com wss://rtc-v2-us1.bitrix24.com google-analytics.com static.trustvox.com.br *.sun21.com.br *.mundipagg.com *.smarthint.co *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.shoppush.com.br *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.bitrix24.site signalrcore.fbits.net wss://signalrcore.fbits.net .crazyegg.com *.crazyegg.com *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com gstatic.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.pagaleve.com.br *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.minhacasasolar.com.br minhacasasolar.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.typekit.net *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com maps.googleapis.com chart.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.afterpay.com https://site-assets.afterpay.com/ https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com *.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com maps.googleapis.com chart.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com https://*.googleapis.com *.typekit.net *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com maps.googleapis.com chart.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ariba.com app.instapunchout.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.ariba.com app.instapunchout.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.youtube.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr flagpedia.net https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn2.hubspot.net resources.paytrail.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com applepay.cdn-apple.com http://www.sinelli.fi 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com applepay.cdn-apple.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://nominatim.openstreetmap.org www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.paytrail.com autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com fonts.googleapis.com *.oney.io *.staging.oney.io *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com p.monetico-services.com/ *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hipay-tpp.com *.hipay.com *.googleapis.com cl.avis-verifies.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.hipay.com www.google.fr *.oney.io *.staging.oney.io t4.my-probance.one/ t4.my-probance.one https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com *.googleapis.com *.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.oney.io *.staging.oney.io static.cloudflareinsights.com ajax.cloudflare.com/ t4.my-probance.one/ t4.my-probance.one *.avada.io *.shopify.com js.mollie.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.hipay.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com maps.googleapis.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.oney.io *.staging.oney.io region1.analytics.google.com https://get.geojs.io *.avada.io https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src t4.my-probance.one/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' data: https://www.motonet.se https://graphql.datocms.com https://*.doubleclick.net https://www.instagram.com https://*.broman.group https://*.litix.io https://vimeo.com https://*.klarna.com https://*.klarnaevt.com/v1/ https://*.adyen.com/checkoutanalytics/ https://*.adyen.com/checkoutshopper/ https://api.postmarkapp.com https://www.youtube.com https://api.videoly.co https://js.testfreaks.com https://api.testfreaks.com https://reviews.testfreaks.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://api.custobar.com/js/v1/custobar.js https://*.google-analytics.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://*.googlesyndication.com https://*.adform.net https://*.creativecdn.com https://connect.facebook.net https://browser-intake-datadoghq.eu https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.se https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com/ https://src.freshmarketer.eu/mas; img-src 'self' data: https://www.datocms-assets.com https://i.ytimg.com https://image.mux.com https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.se; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://js.playground.kustom.co https://osm.klarnaservices.com/ https://*.adyen.com/ https://*.vimeo.com https://app.ecoonline.com https://www.maston.fi https://websds.volvo.com https://policy.app.cookieinformation.com/ https://*.criteo.com https://*.adform.net https://*.creativecdn.com https://www.facebook.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.broman.group https://maps.googleapis.com https://js.playground.kustom.co https://js.klarna.com https://js.klarna.com/web-sdk/ https://api.videoly.co/1/quchbox/0/5257/quch.js https://www.paypal.com/sdk/js https://dapi.videoly.co https://www.youtube.com https://*.vimeo.com https://policy.app.cookieinformation.com https://api.custobar.com/js/v1/custobar.js https://*.criteo.net https://*.criteo.com https://*.adform.net https://connect.facebook.net https://tags.creativecdn.com https://dev.visualwebsiteoptimizer.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; object-src data:; worker-src 'self' blob:; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://h.online-metrix.net *.cardinalcommerce.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://h.online-metrix.net *.d.aa.online-metrix.net *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://h.online-metrix.net *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.gstatic.com *.fontawesome.com *.newrelic.com *.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br *.cloudflare.com *.twitter.com *.paypal.com *.newrelic.com *.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce--zQYdBzaqMe2qMhoqlNvuolRpInTRZGD'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 default-src 'self'; connect-src 'self' *.kerebro.com *.google-analytics.com *.google.com *.facebook.com *.livechatinc.com store.gsscloud.com opencompany.azurewebsites.net in.hotjar.com kerebro.com stats.g.doubleclick.net vc.hotjar.io www.gsscloud.com ka-p.fontawesome.com b.clarity.ms; font-src 'self' data: fonts.gstatic.com www.gsscloud.com uwillx.com cdn.livechatinc.com; frame-src 'self' *.doubleclick.net secure.livechatinc.com www.facebook.com vars.hotjar.com www.youtube.com tpc.googlesyndication.com www.googletagmanager.com cdn.videgree.com bizform.vitalyun.com; img-src 'self' data: *.gsscloud.com *.google-analytics.com *.n0.cdn.getcloudapp.com *.g.doubleclick.net *.gstatic.com cdn.files-text.com www.facebook.com i.ytimg.com www.google.com www.google.com.tw gssweb.gss.com.tw www.gss.com.tw cl.ly connect.facebook.net uwillx.com www.googletagmanager.com widgets.magentocommerce.com s3.amazonaws.com lh3.googleusercontent.com lh4.ggpht.com member.kerebro.com www.googleadservices.com jolly-beach-08300eb00.6.azurestaticapps.net; media-src cdn.livechatinc.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.livechatinc.com *.hotjar.com *.google-analytics.com *.google.com connect.facebook.net googleads.g.doubleclick.net kerebro.com store.gsscloud.com www.googleadservices.com www.googletagmanager.com www.youtube.com www.linkedin.com uwillx.com tpc.googlesyndication.com unpkg.com kit.fontawesome.com cdnjs.cloudflare.com www.clarity.ms; script-src-elem 'self' 'unsafe-inline' data: store.gsscloud.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.livechatinc.com api.livechatinc.com unpkg.com www.clarity.ms kit.fontawesome.com www.googletagmanager.com kerebro.com www.youtube.com www.google-analytics.com ssl.google-analytics.com connect.facebook.net googleads.g.doubleclick.net; style-src 'self' 'unsafe-eval' 'unsafe-inline' fonts.googleapis.com store.gsscloud.com uwillx.com kerebro.com kerebro.com unpkg.com cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com unpkg.com; report-uri https://gsscloud.report-uri.com/r/d/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.highcharts.com *.braintreegateway.com *.cardinalcommerce.com *.tawk.to *.zopim.com *.usersnap.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.twitter.com *.banorte.com *.tawk.to *.zopim.com *.usersnap.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.twitter.com *.consensu.org *.sharethis.com *.banorte.com *.highcharts.com *.braintreegateway.com *.tawk.to *.zopim.com *.usersnap.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.highcharts.com *.braintreegateway.com *.adobetm.com *.cardinalcommerce.com *.gstatic.com *.googleapis.com *.google.com *.tawk.to cdn.jsdelivr.net *.zopim.com *.usersnap.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.google.com *.sharethis.com s7.addthis.com player.vimeo.com *.youtube.com *.banorte.com *.highcharts.com *.braintreegateway.com *.adobetm.com *.cardinalcommerce.com *.googleapis.com *.tawk.to cdn.jsdelivr.net *.zopim.com *.usersnap.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com *.banorte.com *.highcharts.com *.braintreegateway.com *.adobetm.com *.cardinalcommerce.com *.tawk.to cdn.jsdelivr.net *.zopim.com *.usersnap.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com commerce.adobe.net qa-api.magedevteam.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com ekr.zdassets.com/ *.banorte.com *.highcharts.com *.braintreegateway.com *.adobe.com *.adobetm.com *.cardinalcommerce.com *.googleapis.com *.tawk.to wss://*.tawk.to *.zopim.com *.usersnap.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://www.googletagmanager.com *.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com https://*.every-pay.com/ https://*.every-pay.eu/ https://*.lhv.ee/ https://pay.google.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://connect.facebook.net https://static.axept.io https://omnisnippet1.com *.instagram.com https://*.every-pay.com/ https://*.every-pay.eu/ https://*.lhv.ee/ https://pay.google.com/ https://maps.googleapis.com https://unpkg.com tagmanager.google.com https://www.googletagmanager.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://unpkg.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.googletagmanager.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://connect.facebook.net https://www.facebook.com https://api.axept.io https://maps.googleapis.com https://player.vimeo.com https://www.terminalmappingjs.com https://geocode.arcgis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://api.lupasearch.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; img-src https://picfit.cdstyle.lt/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.facebook.com https://payment.ecommerce.sebgroup.com https://wt.omnisendlink.com https://www.google.lt *.cdninstagram.com https://*.every-pay.com/ https://*.every-pay.eu/ https://*.lhv.ee/ https://images.unsplash.com https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt https://cdn.lupasearch.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; 1 font-src https://static.sizebay.technology/ *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.twitter.com *.ads-twitter.com *.pinterest.com *.facebook.com connect.facebook.net https://www.correios.com.br 'self' 'unsafe-inline'; frame-ancestors ; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com https://api.sunset.systems/ https://td.doubleclick.net/ *.twitter.com *.addthis.com *.youtube.com *.sharethis.com *.consensu.org *.youtube.com/ https://youtube.com *.google.com *.sunset.systems *.doubleclick.net *.ads-twitter.com *.facebook.com *.pinterest.com connect.facebook.net *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.conectiva.io/XEngine/ https://conectiva.io/XEngine/ https://static.sizebay.technology/icons/Hanger.svg https://static.sizebay.technology/icons/tabela-medidas.svg *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.paperview.com.br *.sharethis.com *.googletagmanager.com *.facebook.com *.conectiva.io https://conectiva.io *.google.com *.google.com.br *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net www.youtube.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com https://static.sizebay.technology/ https://vfr-v3-production.sizebay.technology/ *.sizebay.technology/ https://app.cartstack.com.br https://static.hotjar.com https://script.hotjar.com/ *.hotjar.com/ https://conectiva.io/XEngine/ *.cloudflare.com *.twitter.com *.doubleclick.net *.jivosite.com *.google-analytics.com *.googleadservices.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.vimeo.com *.youtube.com *.addthis.com *.paypal.com *.paypalobjects.com *.addthisedge.com *.moatads.com *.facebook.com *.google.com *.cloudfront.net *.facebook.net *.sharethis.com *.googletagmanager.com *.cartstack.com.br https://conectiva.io https://whebi.com.br https://cdn.leadster.com.br https://static.cloudflareinsights.com *.googleapis.com analytics.tiktok.com *.app.cartstack.com *.performa.ai *.cupom.social unpkg.com http://viacep.com.br https://www.googletagmanager.com tagmanager.google.com analytics.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://static.sizebay.technology/ https://vfr-v3-production.sizebay.technology/V4/implantation/index.css *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googletagmanager.com *.jivosite.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com https://conectiva.io/ https://api.performa.ai/ https://vfr-v3-production.sizebay.technology/ https://api2.cartstack.com.br/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.addthis.com *.rdstation.com.br *.sharethis.com *.googletagmanager.com *.performa.ai conectiva.io *.leadster.com.br *.google-analytics.com *.doubleclick.net *.jivosite.com *.googleapis.com analytics.tiktok.com *.cartstack.com.br https://app.cartstack.com *.cupom.social *.conectiva.app *.navdmp.com *.azurewebsites.net *.conectiva.io https://conectiva.io/* app.snapbot.com.br https://ws.correios.com.br analytics.google.com *.facebook.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src https://api.itau.com.br/ https://api.itau.com.br:443/ https://sts.itau.com.br/ https://sts.itau.com.br:443/ https://secure.api.itau/ https://secure.api.itau:443/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://*.paperview.com.br/; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'report-sample' js.adsrvr.org connect.facebook.net js-agent.newrelic.com app.pendo.io cdn.pendo.io c.amazon-adsystem.com data.pendo.io pendo-static-5713592751095808.storage.googleapis.com apps.cac1.pure.cloud tarion.breezy.hr www.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net https://www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net/npm cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com 'nonce-KnclCg5ZJwmoEkwZKdwvqA'; script-src-elem 'self' 'report-sample' js.adsrvr.org connect.facebook.net js-agent.newrelic.com app.pendo.io cdn.pendo.io c.amazon-adsystem.com data.pendo.io pendo-static-5713592751095808.storage.googleapis.com apps.cac1.pure.cloud tarion.breezy.hr www.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net https://www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net/npm cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com 'nonce-KnclCg5ZJwmoEkwZKdwvqA'; style-src 'self' fonts.googleapis.com www.googletagmanager.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdnjs.cloudflare.com; base-uri 'self'; frame-ancestors 'self'; report-uri https://app.csplog.com/api/v1/report/tarion-com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://media.laspepas.com.ar https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com www.facebook.com *.trackedlink.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com http://www.afip.gob.ar https://notifications-icommkt.website https://media.laspepas.com.ar *.postimg.cc *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com https://www.googletagmanager.com/ *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com https://maps.google.com https://www.google.com/pagead/conversion_async.js https://googleads.g.doubleclick.net *.cloudfront.net/ *.jsdelivr.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com business.facebook.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net https://media.laspepas.com.ar https://fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io https://maps.googleapis.com/ https://track-icommkt.com/ https://notifications-icommkt.com https://www.mailing.laspepas.com.ar *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com 'self' data: *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://secure.networkmerchants.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.yotpo.com *.openwidget.com *.chatbot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com 'self' data: *.iubenda.com *.facebook.net *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.yotpo.com *.openwidget.com *.chatbot.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://secure.networkmerchants.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com *.iubenda.com *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.yotpo.com *.openwidget.com *.chatbot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://secure.networkmerchants.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.googleapis.com *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.yotpo.com *.openwidget.com *.chatbot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tidiochat.com *.yotpo.com *.openwidget.com *.chatbot.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://secure.networkmerchants.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.googlesyndication.com *.iubenda.com *.tidio.co wss://socket.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.yotpo.com *.openwidget.com *.chatbot.com *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; report-to asperion.nl; report-uri asperion.nl; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.google.com/ *.multisafepay.com https://pay.google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.weltpixel.com *.trustpilot.com *.googletagmanager.com *.doubleclick.net *.freshchat.com https://consentcdn.cookiebot.com *.issuu.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com *.sharethis.com *.googleapis.com https://www.magezon.com imgsct.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.multisafepay.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://cdn.flbx.io https://redchamps.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.cookiebot.com trello-attachments.s3.amazonaws.com *.mailplus.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.sharethis.com *.googleapis.com *.gstatic.com consent.cookiebot.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.postcode-checkout.nl/api/international/v1/autocomplete/* *.google.com/ *.multisafepay.com https://pay.google.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.freshchat.com *.cookiebot.com https://www.google-analytics.com https://your-custom-script-source.com https://assets.calendly.com https://polyfill.io *.mailplus.nl *.omappapi.com *.hotjar.com bat.bing.com *.issuu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.sharethis.com downloads.mailchimp.com *.fontawesome.com https://static.klaviyo.com *.googleapis.com *.multisafepay.com *.trustpilot.com tagmanager.google.com *.tagmanager.google.com *.googletagmanager.com https://fonts.googleapis.com https://assets.calendly.com *.freshchat.com *.omappapi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com *.sharethis.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.postcode-checkout.nl/api/international/v1/autocomplete/* *.multisafepay.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com https://www.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.cookiebot.com *.omappapi.com googleads.g.doubleclick.net *.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://static.lyra.com/static/ *.fontawesome.com 'self' data: *.cloudfront.net *.wistia.com *.hotjar.com *.hotjar.io snippet.maze.co data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ http://info.soprema.fr info.soprema.fr *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com app.sarooma.de *.sopremauvalue.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ *.bynder.com my.assets-library.com app.ideta.io checkout.sandbox.dev.clover.com checkout.clover.com copilotstudio.microsoft.com sopremap.wpenginepowered.com app.sarooma.de *.sopremauvalue.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com s7.addthis.com *.hotjar.com *.hotjar.io fast.wistia.com fast.wistia.net fortress.maptive.com widget.getcody.ai ausschreiben.de *.calameo.com uvalue.nettt.nl websiteintegration.source.thenbs.com bimobject.com tel: *.soprema-cms.awstudio.website 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com maps.googleapis.com *.googleapis.com magefan.com cm.magefan.com https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ *.disqus.com https://img.youtube.com 'self' data: *.bynder.com my.assets-library.com *.cloudfront.net *.cloudinary.com checkout.sandbox.dev.clover.com checkout.clover.com *.soprema.fr *.soprema-eu.test *.soprema-na.test *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com *.google.com *.google.fr *.google.ca *.googletagmanager.com *.g.doubleclick.net *.hotjar.com *.hotjar.io *.pardot.com *.linkedin.com *.facebook.com bat.bing.com *.wistia.com *.wistia.net embedwistia-a.akamaihd.net *.clarity.ms pagead2.googlesyndication.com *.teads.tv tags.srv.stackadapt.com snippet.maze.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com developers.google.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.disqus.com d8ejoa1fys2rk.cloudfront.net ucv.bynder.com checkout.sandbox.dev.clover.com checkout.clover.com www.ingenuityinsightful-52.com info.soprema.fr *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com bam.nr-data.net js-agent.newrelic.com z.moatads.com v1.addthisedge.com m.addthis.com *.hotjar.com *.hotjar.io *.googletagmanager.com cdn.leadinfo.net cdn.jsdelivr.net *.pardot.com connect.facebook.net snap.licdn.com bat.bing.com *.wistia.com *.wistia.net src.litix.io secure.leadforensics.com *.clarity.ms *.teads.tv *.bugherd.com tags.srv.stackadapt.com srv.stackadapt.com east.srv.stackadapt.com uw.srv.stackadapt.com eu.srv.stackadapt.com qvdt3feo.com/ *.soprema-cms.awstudio.website snippet.maze.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.lyra.com/static/ *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudfront.net cdn-images.mailchimp.com *.hotjar.com *.hotjar.io *.typekit.net fast.wistia.com *.googletagmanager.com tags.srv.stackadapt.com snippet.maze.co 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com *.wistia.com *.wistia.net embedwistia-a.akamaihd.net blob: my.assets-library.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ t.elasticsuite.io *.cloudfront.net *.bynder.com my.assets-library.com scl-sandbox.dev.clover.com scl.clover.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com lotus.soprema.fr bat.bing.com app.sarooma.de *.sopremauvalue.com bam-cell.nr-data.net m.addthis.com bam.nr-data.net *.googletagmanager.com pagead2.googlesyndication.com *.leadinfo.net api.leadinfo.com *.g.doubleclick.net *.hotjar.com wss://*.hotjar.com *.hotjar.io wss://*.hotjar.io *.pardot.com *.linkedin.com *.facebook.com *.wistia.com *.litix.io embedwistia-a.akamaihd.net *.clarity.ms *.teads.tv tags.srv.stackadapt.com *.soprema-cms.awstudio.website api.maze.co prompts.maze.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' https://cdn.weglot.com https://static.b-ite.com https://cs-assets.b-ite.com https://chat-app.neurabot.neuraflow.de https://prod-chat-app.neurabot.neuraflow.de/ cdn.jsdelivr.net cdn1.readspeaker.com code.etracker.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com platform.instagram.com platform.twitter.com www.etracker.de; script-src-elem 'self' 'unsafe-inline' https://cdn.weglot.com https://static.b-ite.com https://cs-assets.b-ite.com https://chat-app.neurabot.neuraflow.de https://prod-chat-app.neurabot.neuraflow.de/ cdn.jsdelivr.net cdn1.readspeaker.com code.etracker.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com platform.instagram.com platform.twitter.com www.etracker.de; style-src 'self' 'unsafe-inline' https://cdn.weglot.com https://cs-assets.b-ite.com https://chat-app.neurabot.neuraflow.de https://prod-chat-app.neurabot.neuraflow.de/ https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com cdn1.readspeaker.com; style-src-elem 'self' 'unsafe-inline' https://cdn.weglot.com https://cs-assets.b-ite.com https://chat-app.neurabot.neuraflow.de https://prod-chat-app.neurabot.neuraflow.de/ https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com cdn1.readspeaker.com 1 frame-src *.force.com https://player.vimeo.com 'self' https://*.123formbuilder.com *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://1millioncups--uat.livepreview.salesforce-communities.com https://checkoutshopper-test.adyen.com/ https://www.facebook.com https://pal-test.adyen.com *.cybersource.com *.youtube.es https://1millioncups--c.visualforce.com *.adis.ws https://www.gstatic.com https://www.youtube-nocookie.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://www.google.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video https://*.vimeo.com *.youtube.fr https://beta22.1millioncups.com https://*.a.forceusercontent.com https://player.cloudinary.com https://usa634.sfdc-lywfpd.salesforce.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws https://salesforce.123formbuilder.com *.forceusercontent.com *.youtube.com *.brightcove.net *.youtube.nl https://service.force.com/embeddedservice/ https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com *.youtube.com.br *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net *.youtube.ca https://location.force.com *.vidyard.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://*.a.forceusercontent.com/lightningmaps/ https://www.googletagmanager.com *.wistia.net https://storage101.iad3.clouddrive.com https://www.google-analytics.com *.salesforce.com *.youtube.pl https://1millioncups.file.force.com maps.a.forceusercontent.com; report-to sfdc-csp-ep; report-uri https://1millioncups.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4W000006kWdP&networkId=0DM4W0000000Z5o&type=communities 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com www.militarytour.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.militarytour.com 'self' 'unsafe-inline'; frame-ancestors www.militarytour.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.militarytour.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.militarytour.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.militarytour.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com maxcdn.bootstrapcdn.com www.militarytour.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.militarytour.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.militarytour.com 'self' 'unsafe-inline'; child-src www.militarytour.com http: https: blob: 'self' 'unsafe-inline'; default-src www.militarytour.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-ZmZlMDIzYjMtZWQ0Yy00NmM5LThiMzEtMjA2MDc5MTM2Y2I1' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 worker-src blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.gstatic.com *.zopim.com *.zopim.io *.s3.amazonaws.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com fonts.googleapis.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com https://plumrocket.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.s3.amazonaws.com www.googletagmanager.com https://plumrocket.com *.ampproject.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io widgets.automizely.com widgets.automizely.io *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.s3.amazonaws.com *.googletagmanager.com quickchart.io img.youtube.com https://i.ytimg.com https://redchamps.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.s3.amazonaws.com *.googleapis.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.ampproject.org *.reviews.io *.reviews.co.uk maps.googleapis.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com *.s3.amazonaws.com *.google.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.cloudfront.net *.reviews.io *.reviews.co.uk www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io *.s3.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.automizely.com api.automizely.io fcmregistrations.googleapis.com firebaseinstallations.googleapis.com www.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://stats.g.doubleclick.net *.s3.amazonaws.com https://ipinfo.io/json http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.googletagmanager.com stats.g.doubleclick.net *.ampproject.org *.ampproject.net https://connect.facebook.net https://www.google-analytics.com https://www.facebook.com/tr *.cloudfront.net *.reviews.io *.reviews.co.uk places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com *.gstatic.com *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.hotjar.com *.jsdelivr.net *.feedaty.com *.doofinder.com *.google.it *.google.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com www.googletagmanager.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bird.eu *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.googletagmanager.com *.google.it *.google.com *.googleadservices.it *.googleadservices.com *.google-analytics.it *.google-analytics.com *.mailchimp.com *.addtoany.com *.leadchampion.com *.klaviyo.com *.doofinder.com *.feedaty.com *.iubenda.com *.facebook.net *.upsellit.com *.scalapay.com *.etrusted.com *.hotjar.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.leadchampion.com *.addtoany.com *.klaviyo.com *.doofinder.com *.googletagmanager.com *.google.it *.feedaty.com *.jsdelivr.net *.dwin1.com *.iubenda.com *.facebook.net *.roeyecdn.com *.preciso.net *.bounce-commerce.de *.brandswap.com *.iintf.co *.envolvetech.com *.smct.co *.upsellit.com *.soreto.com *.tyviso.com *.smct.io *.ad4m.at *.contester.net *.cloudfront.net *.recova.ai *.etagdigital.com *.doubleclick.net *.scalapay.com *.etrusted.com *.cloudflareinsights.com *.jquery.com 'unsafe-eval' *.thecustomproductbuilder.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.googleadservices.com *.google-analytics.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.jsdelivr.net *.feedaty.com *.doofinder.com *.google.it *.google.com downloads.mailchimp.com *.klarnacdn.net *.fontawesome.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.googletagmanager.com *.google.it *.google.com *.mailchimp.com *.addtoany.com *.doubleclick.net *.2trk.info *.wepowerconnections.com *.lcmark.net *.leadchampion.com *.klaviyo.com *.doofinder.com *.feedaty.com *.jsdelivr.net *.dwin1.com *.iubenda.com *.facebook.net *.facebook.com *.roeyecdn.com *.preciso.net *.bounce-commerce.de *.brandswap.com *.iintf.co *.envolvetech.com *.smct.co *.upsellit.com *.soreto.com *.tyviso.com *.ad4m.at *.contester.net *.cloudfront.net *.recova.ai *.etagdigital.com *.scalapay.com *.etrusted.com *.cloudflareinsights.com *.jquery.com *.apptrian.com 'self' 'unsafe-inline' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doofinder.com wss://*.doofinder.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://dpm.demdex.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.multisafepay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.mamanetsophie.com *.mamanetsophie.it mamanetsophie.com mamanetsophie.it dev.mamanetsophie.com dev.mamanetsophie.it *.doubleclick.net *.2trk.info *.wepowerconnections.com *.lcmark.net *.google.it *.google.com 'self' 'unsafe-eval' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://cdn.riverty.design/ *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.fonts.googleapis.com data: *.cloudflare.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com uc8.tv https://documents.riverty.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.addthis.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https:/at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.sooqr.com *.spotlersearch.com *.multisafepay.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com ts.tradetracker.net www.magmodules.eu *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com tm.tradetracker.net www.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cdn.dnky.co webchat.dotdigital.com https://static.klaviyo.com *.fontawesome.com *.sooqr.com *.spotlersearch.com *.multisafepay.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.sooqr.com *.spotlersearch.com *.multisafepay.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net code.ionicframework.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google-analytics.com www.google.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com code.ionicframework.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' * data: blob:; style-src 'self' 'unsafe-inline' *; img-src 'self' data: *; font-src 'self' * data:; connect-src 'self' *; frame-src 'self' *; frame-ancestors 'self'; report-uri https://unwomen.de 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' 'unsafe-eval'; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.onesignal.com https://cdnjs.cloudflare.com https://unpkg.com https://vjs.zencdn.net https://www.google.com platform.instagram.com platform.twitter.com unpkg.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://use.fontawesome.com https://vjs.zencdn.net unpkg.com 'unsafe-inline'; style-src-attr 'self'; frame-ancestors 'self' 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.klarna.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com *.klarnacdn.net fast.fonts.net *.fontawesome.com *.google.com *.gstatic.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://accounts.google.com https://www.facebook.com https://login.live.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.google.com *.google.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com https://www.magezon.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io cdn.doofinder.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.google.co.uk *.amazonaws.com app.usercentrics.eu uct.service.usercentrics.eu *.doofinder.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.doofinder.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.googletagmanager.com *.doubleclick.net *.doofinder.com eu1-config.doofinder.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.cloudflare.com cdn.doofinder.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.doubleclick.net cdn.doofinder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.weltpixel.com *.google.com/ js.mollie.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.ad-srv.net www.usemaxserver.de *.redintelligence.net www.pinterest.com www.pinterest.de www.facebook.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net https://www.mollie.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com maps.gstatic.com *.gstatic.com *.cdninstagram.com *.fbcdn.net www.google.de *.facebook.com *.pinterest.com www.usemaxserver.de *.awin1.com *.googleadservices.com *.doubleclick.net widgets.trustedshops.com https://as.ad4m.at https://ad11.adfarm1.adition.com https://imagesrv.adition.com adservice.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.shopify.com *.google.com/ *.gstatic.com maps.googleapis.com js.mollie.com ajax.googleapis.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://freegeoip.app https://www.googletagmanager.com tagmanager.google.com *.instagram.com analytics.gourvita.com www.gstatic.com *.ratepay.com www.dwin1.com www.usemaxserver.de *.ad-srv.net *.doubleclick.net connect.facebook.net *.pinimg.com widgets.trustedshops.com *.googletagmanager.com https://lantern.roeyecdn.com https://ad4m.at 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com fonts.googleapis.com d.ratepay.com d.payla.io dr.payla.io tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com https://freegeoip.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com analytics.gourvita.com *.ratepay.com *.pinterest.com *.google.com *.merchant-center-analytics.goog *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-z7wNDLEI/tRuAlA0iSnW59hx97U=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.webvisor.com epharm.bg *.yandex.ru *.yastatic.net *.googleadservices.com *.bootstrapcdn.com *.google.com *.ymetrica1.com *.google-analytics.com *.googletagmanager.com *.google.bg cdn.epharm.bg static.cloudflareinsights.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.twitter.com *.google.com *.addthis.com *.webvisor.com *.google.bg *.doubleclick.com epharm.bg cdn.epharm.bg static.cloudflareinsights.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.facebook.com https://firebasestorage.googleapis.com *.webvisor.com epharm.bg *.yandex.ru *.yastatic.net *.googleadservices.com *.bootstrapcdn.com *.google.com *.ymetrica1.com *.google-analytics.com *.googletagmanager.com *.google.bg cdn.epharm.bg static.cloudflareinsights.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com *.webvisor.com epharm.bg *.yandex.ru *.yastatic.net *.googleadservices.com *.bootstrapcdn.com *.google.com *.ymetrica1.com *.google-analytics.com *.google.bg cdn.epharm.bg static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.webvisor.com epharm.bg *.yandex.ru *.yastatic.net *.googleadservices.com *.bootstrapcdn.com *.google.com *.ymetrica1.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.google.bg cdn.epharm.bg static.cloudflareinsights.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com https://get.geojs.io *.avada.io *.webvisor.com epharm.bg *.yandex.ru *.yastatic.net *.googleadservices.com *.bootstrapcdn.com *.google.com ymetrica1.com *.ymetrica1.com *.googletagmanager.com *.gstatic.com *.google.bg *.doubleclick.com stats.g.doubleclick.net cdn.epharm.bg static.cloudflareinsights.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com https://static.addtoany.com/ *.instagram.com www.google.com js.stripe.com https://www.googletagmanager.com https://td.doubleclick.net *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com *.cdninstagram.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://wheelioapp.azureedge.net https://p.veritone-ce.com https://www.lightboxcdn.com magefan.com cm.magefan.com https://redchamps.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.vimeo.com js.stripe.com *.matomo.cloud https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://wheelioapp.azureedge.net https://dashboard.wheelio-app.com https://cdnjs.cloudflare.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://shopstarship.matomo.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com https://wheelioapp.azureedge.net https://www.lightboxcdn.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://stats.addtoany.com/menu *.googleapis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.matomo.cloud https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google.com https://analytics.google.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.xtento.com https://plumrocket.com https://*.sameday.ro *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com https://redchamps.com *.hsforms.net *.hsforms.com maps.gstatic.com https://cdn.tbibank.support data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.avada.io www.xtento.com cdn.xtento.com https://*.sameday.ro *.hsforms.net *.hsforms.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://*.sameday.ro 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com https://ro.tbibank.support 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.maxcdn.bootstrapcdn.com/ *.fontawesome.com data: *.cloudfront.net *.reviews.io *.reviews.co.uk *.fonts.googleapis.com *.cloudflare.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com www.google.com *.stripe.com *.braintreepayments.com https://www.facebook.com/ *.google-analytics.com *.braintree-api.com *.googleadservices.com *.googleapis.com *.sandbox.paypal.com *.stripecdn.com *.reviews.co.uk *.klarna.com *.amazon.com *.luckyorange.net *.flashtalking.com *.google.com.ua *.google.co.uk *.reviews.io *.addthis.com *.pinterest.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.twitter.com *.imagekit.io *.meetanshi.com https://www.google.co.in/ads/ga-audiences https://bat.bing.com/action/0 www.sandbox.paypal.com https://c.clarity.ms/c.gif *.pushalert.co *.facebook.com *.google.com *.google.com.ua *.google.co.uk *.doubleclick.net moogento.com *.moogento.com https://redchamps.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.stripe.com widget.freshworks.com m2epro.freshdesk.com *.googleadservices.com *.googletagmanager.com *.clarity.ms *.facebook.com *.google-analytics.com *.paypal.com *.paypalobjects.com *.stripecdn.com *.reviews.co.uk *.klarna.com *.amazon.com *.luckyorange.net *.bing.com *.pushalert.co *.cloudfront.net *.adsrvr.org *.flashtalking.com *.conversitor.com *.google.com.ua *.google.co.uk *.gstatic.com *.doubleclick.net l2.moogento.com *.reviews.io *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.stripe.network klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com https://r.clarity.ms/collect *.google-analytics.com *.googleadservices.com *.googleapis.com *.sandbox.paypal.com *.stripecdn.com *.reviews.co.uk *.stripe.com *.klarna.com *.amazon.com *.luckyorange.net *.cloudfront.net *.reviews.io *.cloudflare.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.facebook.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.cleverreach.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.iwv-plugins.de js.mollie.com *.trustpilot.com *.hotjar.com *.twitter.com 'self' 'unsafe-inline'; img-src 'self' data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.cloudfront.net magefan.com cm.magefan.com https://www.mollie.com https://api.mapbox.com www.gartenwelt.de *.cloudflare.com *.linkedin.com *.adsymptotic.com *.google.nl *.cookiebot.com https://widgets.trustedshops.com https://integrations.etrusted.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com js.mollie.com *.cloudflare.com *.twitter.com *.fontawesome.com *.pingdom.net *.trustpilot.com *.hotjar.com *.licdn.com *.convertexperiments.com *.cookiebot.com *.clarity.ms https://widgets.trustedshops.com https://integrations.etrusted.com *.twimg.com *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com autocomplete2.postdirekt.de *.cloudflare.com *.pingdom.net *.hotjar.com *.usercentrics.eu *.demdex.net *.convertexperiments.com *.visualwebsiteoptimizer.com gartenwelt.nl *.cookiebot.com *.trustedshops.com *.etrusted.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' 'strict-dynamic' https://myfavoritequiltstore.com https://www.clarity.ms *.clarity.ms https://static-tracking.klaviyo.com https://stats.g.doubleclick.net https://analytics.tiktok.com https://googleads.g.doubleclick.net https://connect.facebook.net https://sc-static.net https://static.klaviyo.com https://www.redditstatic.com https://analytics.twitter.com https://static.ads-twitter.com https://bat.bing.com https://s.pinimg.com https://analytics.tiktok.com https://www.googleadservices.com https://connect.facebook.net https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube.com https://apis.google.com https://dev.visualwebsiteoptimizer.com https://www.gstatic.com https://www.google.com https://assets.gorgias.chat https://config.gorgias.chat https://js.smile.io https://polyfill.io https://shopify-gtm-suite.getelevar.com https://www.googleoptimize.com https://api.getemails.com 'sha256-oafQL/+rENnojosA/XKcZ29LdGUyZUYnxLDmeg6qeTM=' 'sha256-YTWugyxLMwaGvKFv4VtjsYWq24gIWht2ZRa8pdlgbnk='; style-src 'report-sample' 'self' 'unsafe-inline' https://static.klaviyo.com https://fonts.googleapis.com https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://insights.algolia.io https://gwywm8uj54.algolia.net https://bat.bing.com https://*.clarity.ms https://stats.g.doubleclick.net https://www.facebook.com https://apis.google.com https://www.google-analytics.com wss://*.gorgias.chat https://*.gorgias.chat https://*.klaviyo.com https://myfavoritequiltstore.com https://*.myfavoritequiltstore.com https://ct.pinterest.com https://*.smile.io https://tr.snapchat.com https://api.segment.io https://o1146830.ingest.sentry.io https://analytics.tiktok.com https://analytics.twitter.com https://dev.visualwebsiteoptimizer.com; font-src 'self' https://assets.gorgias.chat https://js.smile.io https://fonts.googleapis.com https://fonts.gstatic.com; frame-src 'self' https://www.youtube.com https://accounts.google.com https://www.google.com https://tr.snapchat.com https://tr6.snapchat.com https://www.facebook.com https://analytics.tiktok.com https://ct.pinterest.com https://a.klaviyo.com https://fast.a.klaviyo.com https://static-forms.klaviyo.com https://d.clarity.ms https://bid.g.doubleclick.net; frame-ancestors 'self' https://www.youtube.com; img-src 'self' https://analytics.tiktok.com https://c.bing.com *.clarity.ms https://ct.pinterest.com https://www.google.com https://www.facebook.com https://t.co https://bat.bing.com https://alb.reddit.com https://www.google-analytics.com https://www.googletagmanager.com https://cdn.shopify.com https://fonts.gstatic.com https://csi.gstatic.com https://cdn.sweettooth.io https://*.myfavoritequiltstore.com https://dev.visualwebsiteoptimizer.com data: https://i.ytimg.com https://googleads.g.doubleclick.net https://analytics.twitter.com; manifest-src 'self'; media-src 'self' https://www.youtube.com https://cdn.shopify.com https://assets.gorgias.chat; report-uri /api/csp-violation-report/; worker-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://use.typekit.net fonts.googleapis.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://consentcdn.cookiebot.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://static.hotjar.com https://script.hotjar.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com *.disqus.com *.avada.io *.shopify.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://use.typekit.net https://p.typekit.net *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net/ https://pagead2.googlesyndication.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9c7eaa4e-11d4-4b74-af4e-1758420c0a75.sansec.watch/; report-to report-endpoint; 1 default-src 'none'; script-src 'self' https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com https://maps.googleapis.com https://*.pendo.io https://pendo-io-static.storage.googleapis.com https://stats.pusher.com https://cdn.datatables.net https://cdnjs.cloudflare.com; script-src-elem 'self' https://*.pendo.io https://pendo-static-5749076184662016.storage.googleapis.com https://pendo-io-static.storage.googleapis.com https://www.web.edrnet.com https://*.edrnet.com https://ws.edrnet.com https://www.google-analytics.com https://www.googletagmanager.com https://maps.googleapis.com https://www.datadoghq-browser-agent.com https://*.collateral360.com; style-src 'self' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.datatables.net; img-src 'self' data: https://www.google-analytics.com https://www.google.com https://maps.gstatic.com https://*.googleapis.com https://www.googletagmanager.com https://*.collateral360.com https://*.pendo.io https://pendo-static-5749076184662016.storage.googleapis.com https://*.s3.amazonaws.com https://*.edrnet.com https://www.web.edrnet.com https://developers.google.com/maps/documentation/javascript/examples/markerclusterer/m1.png; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://*.collateral360.com; connect-src 'self' https://*.collateral360.com https://*.google-analytics.com https://analytics.google.com https://*.browser-intake-datadoghq.com https://*.googleapis.com https://stats.g.doubleclick.net wss://ws-us2.pusher.com https://sockjs-us2.pusher.com https://data.pendo.io https://maps.googleapis.com https://*.browser-intake-datadoghq.com; worker-src blob:; frame-src 'self'; form-action 'self'; manifest-src 'self'; report-to csp 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.google.com http://fonts.gstatic.com/ https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://www.magezon.com cdn.mundipagg.com api.pagar.me https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com 3ds2.pagar.me 3ds2-sdx.pagar.me *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.smarthint.co maps.googleapis.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.googleapis.com *.google.com http://fonts.googleapis.com/ https://fonts.bunny.net assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io *.adobedc.net *.demdex.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com https://viacep.com.br https://www.viacep.com.br api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br pay.sandbox.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.ingest.sentry.io *.acsbapp.com *.tiqcdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: images.ctfassets.net otbnet.d3.sc.omtrdc.net; media-src 'self' blob: data: dacastmmod-mmd-cust.lldns.net; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests; connect-src 'self' *.ingest.sentry.io *.acsbapp.com *.tiqcdn.com dacastmmod-mmd-cust.lldns.net otbnet.d3.sc.omtrdc.net; 1 default-src https://*.deutschlandsim.de; object-src 'none'; script-src 'self' data: 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.deutschlandsim.de https://visitor-service.tealiumiq.com/drillisch/main/ https://visitor-service-eu-central-1.tealiumiq.com/drillisch/main/ https://tags.tiqcdn.com/utag/drillisch/deutschlandsim.de/prod/ https://tags.tiqcdn.com/utag/tiqapp/ https://cdn2.spatialbuzz.com/cust/D7FF6FE4/ https://cdn2.spatialbuzz.com/cust/DCCB7552/; style-src 'self' data: 'report-sample' 'unsafe-inline' https://*.deutschlandsim.de; img-src https: data:; font-src https: data:; connect-src 'self' https://*.deutschlandsim.de wss://*.deutschlandsim.de https://dpm.demdex.net https://collect.tealiumiq.com/event https://collect-eu-central-1.tealiumiq.com/drillisch/main/ https://visitor-service.tealiumiq.com/drillisch/main/ https://visitor-service-eu-central-1.tealiumiq.com/drillisch/main/ https://cdn.spatialbuzz.com https://cdn2.spatialbuzz.com https://cdn2.spatialbuzz.com/api/maintenance_mode; frame-src 'self' https://*.deutschlandsim.de https://cdn2.spatialbuzz.com https://1and1internetag.demdex.net https://netmap.vodafone.de/cokart-client/index.html; child-src 'self' https://cdn2.spatialbuzz.com; upgrade-insecure-requests; block-all-mixed-content; report-uri https://www.drillisch-online.de/csp-reports 1 font-src https://*.gstatic.com *.fontawesome.com fonts.googleapis.com www.leonpaul.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de www.leonpaul.com 'self' 'unsafe-inline'; frame-ancestors www.leonpaul.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.adyen.com pay.google.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com https://www.googletagmanager.com/ *.weltpixel.com www.leonpaul.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com *.trackedlink.net validate.fishpig.co.uk http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ maps.gstatic.com www.leonpaul.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com polyfill.io *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal http://www.googletagmanager.com/ https://www.googletagmanager.com/ maps.googleapis.com www.leonpaul.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ *.fontawesome.com www.leonpaul.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.leonpaul.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.leonpaul.com 'self' 'unsafe-inline'; child-src www.leonpaul.com http: https: blob: 'self' 'unsafe-inline'; default-src www.leonpaul.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-YmM2YTMwOTQtYmRlYS00ZjNhLWE3OWMtNjI1MmZmMjc5MzM3' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src https://fonts.gstatic.com https://www.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com preeziestaticcontent.blob.core.windows.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com *.nosto.com *.nos.to static.addtoany.com lpcdn.lpsnmedia.net *.webeyez.com vars.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com *.yotpo.com https://oc-cdn-public-oce.azureedge.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://img.youtube.com *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com *.nosto.com *.nos.to lpcdn.lpsnmedia.net *.google.com *.google.com.ua *.google.com.au usage.trackjs.com magento-staging.signet.net.au magento-staging.insignia.com.au signet.net.au insignia.com.au *.bing.com c.clarity.ms px.ads.linkedin.com p.adsymptotic.com preeziestaticcontent.blob.core.windows.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io https://rum.hlx.page polyfill.io *.googleapis.com https://www.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com s7.addthis.com *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com *.nosto.com *.nos.to static.addtoany.com lptag.liveperson.net cdn.trackjs.com sy.v.liveperson.net accdn.lpsnmedia.net lpcdn.lpsnmedia.net newrelic.com nr-data.net magento-staging.signet.net.au magento-staging.insignia.com.au signet.net.au insignia.com.au *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com snap.licdn.com bat.bing.com *.hotjar.com *.clarity.ms *.azureedge.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.google.com *.yotpo.com https://oc-cdn-public-oce.azureedge.net/livechatwidget/scripts/LiveChatBootstrapper.js https://oc-cdn-public-oce.azureedge.net/livechatwidget/v2scripts/LiveChatBootstrapper.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to magento-staging.signet.net.au magento-staging.insignia.com.au signet.net.au insignia.com.au unsafe-inline assets.braintreegateway.com *.yotpo.com https://oc-cdn-public-oce.azureedge.net/livechatwidget/v2public/styles/LiveChatWidgetFrame.css *.azureedge.net 'self' 'unsafe-inline'; object-src *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.algolia.net *.algolia.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ekr.zdassets.com/ http://dpm.demdex.net *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com *.nosto.com *.nos.to bam.nr-data.net *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com stats.g.doubleclick.net *.hotjar.com k.clarity.ms *.azurewebsites.net *.azureedge.net prod-eh-v1-analytics.servicebus.windows.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com https://s.clarity.ms/collect 'self' 'unsafe-inline'; child-src *.merchantwarrior.com https://base.merchantwarrior.com *.mycardsecure.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.adyen.com *.instagram.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com *.googleapis.com *.cdninstagram.com www.apptrian.com www.facebook.com *.trackedlink.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page *.googleapis.com *.gstatic.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk cdn.jsdelivr.net js-agent.newrelic.com bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com www.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.adyen.com *.googleapis.com www.apptrian.com connect.facebook.net graph.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.s3.magento.com s3.magento.com *.cloudfront.net cloudfront.net *.doubleclick.net doubleclick.net *.s3.amazonaws.com s3.amazonaws.com *.pixriot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googletagmanager.com googletagmanager.com gstatic.com *.cloudfront.net cloudfront.net *.mailchimp.com mailchimp.com cdn-images.mailchimp.com *.list-manage.com list-manage.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com *.s3.magento.com s3.magento.com *.cloudfront.net cloudfront.net downloads.mailchimp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.s3.magento.com s3.magento.com *.cloudfront.net cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.luckyorange.net luckyorange.net *.visitors.live visitors.live auth.axiomaudio.com *.pixriot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blob: http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.acousticalsolutions.com *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.google.com *.doubleclick.net *.facebook.com js.mollie.com niko-productguide.solyd.be *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.mollie.com *.koongo.com *.google.pt *.google.be *.google.com.tr *.bing.com maps.googleapis.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com maps.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://cdn.polyfill.io https://browser.sentry-cdn.com s7.addthis.com js.mollie.com static.hotjar.com *.bing.com gtmadapter-node-cbjg5cz5hq-ew.a.run.app *.cookie-script.com *.trustpilot.com tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://*.ingest.sentry.io ekr.zdassets.com/ *.koongo.com stats.g.doubleclick.net maps.googleapis.com gtmadapter-node-cbjg5cz5hq-ew.a.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.googleapis.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem https://cdn-cookieyes.com; font-src *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com https://*.typekit.net/ *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.safecharge.com https://cdn-cookieyes.com https://ade.googlesyndication.com https://cdn-int.safecharge.com https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://secure.safecharge.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.fontawesome.com/ https://*.typekit.net/ https://*.googleapis.com/ https://*.chatra.io/ https://*.facebook.net/ https://*.safecharge.com https://play.google.com https://magento.com https://cdn-cookieyes.com https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://cdn-int.safecharge.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.facebook.net www.termsfeed.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ https://*.safecharge.com/ https://*.typekit.net/ https://cdn.safecharge.com https://devmobile.sccdev-qa.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.safecharge.com https://*.nuvei.com/ https://play.google.com https://cdn-cookieyes.com https://log.cookieyes.com https://directory.cookieyes.com https://pagead2.googlesyndication.com https://sdkmon.safecharge.com https://ppp-test.safecharge.com https://ppp-test.nuvei.com https://secure.safecharge.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-sri-for script; report-uri https://mandarb.report-uri.com/r/default/csp/reportOnly ; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.ch ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.ch *.spreadshirt.ch ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.ch ; font-src 'self' https: data: *.spreadshirt.ch ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.ch ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.ch ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://cdn.cardknox.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net min-js.co t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.clarity.ms *.bing.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net min-js.co geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.cardknox.com/ifields/2.15.2405.1601/ifields.min.js *.googleapis.com *.gstatic.com https://clarity.ms https://www.clarity.ms https://player.vimeo.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.clarity.ms https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.nigunmusic.com/; report-to report-endpoint; 1 default-src 'self' data:; script-src 'self'; script-src-elem 'self' 'unsafe-inline' www.googletagmanager.com *.google-analytics.com cdnjs.cloudflare.com googleads.g.doubleclick.net ajax.googleapis.com *.mouseflow.com platform.illow.io unpkg.com cdn.jsdelivr.net *.google.co.in ; style-src 'self'; style-src-elem 'self' fonts.googleapis.com use.fontawesome.com cdnjs.cloudflare.com platform.illow.io; style-src-attr 'unsafe-inline'; img-src 'self' www.google.com www.googleadservices.com *.google-analytics.com pagead2.googlesyndication.com; font-src * 'self'; connect-src betaclientapi.nextbee.io firestore.googleapis.com www.google-analytics.com www.googleapis.com ipgeolocation.abstractapi.com platform.illow.io *.mouseflow.com; media-src 'self'; object-src 'self'; frame-src 'self' *.googletagmanager.com player.vimeo.com *.doubleclick.net *.olark.com; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; report-uri https://nbsetupcsp.report-uri.com/r/d/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.klaviyo.com *.hubspot.com *.logrocket.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.google.com/ https://cdn.logrocket.io *.hubspot.com *.hsforms.net c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com *.hubspot.com https://*.instantsearchplus.com *.logrocket.com *.lr-in-prod.com *.hsforms.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com 'unsafe-inline' 'unsafe-eval' *.klaviyo.com https://*.instantsearchplus.com https://*.fastsimon.com https://fastsimon-grid.akamaized.net https://*.akamaized.net https://js.usemessages.com *.logrocket.com *.lr-in-prod.com *.lr-ingest.com *.hsforms.net *.hs-scripts.com *.hs-analytics.net *.hsappstatic.net *.google-analytics.com *.googletagmanager.com *.gstatic.com *.doubleclick.net *.paypal.com *.paypalobjects.com *.braintree-api.com *.axept.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.klaviyo.com *.fastsimon.com fonts.bunny.net *.logrocket.com *.hubspot.com *.hsforms.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com thm.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.klaviyo.com *.fastsimon.com https://fastsimon.akamaized.net https://*.akamaized.net *.logrocket.com *.lr-in-prod.com *.lr-ingest.com *.hsforms.net *.hsforms.com *.hs-analytics.net *.hsappstatic.net *.google-analytics.com *.googletagmanager.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' construmarques.com.br *.construmarques.com.br wake-components.fbitsstatic.net construmarques.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.egoi.site egoi.site *.e-goi.com *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.azurewebsites.net *.blob.core.windows.net *.boletoflex.com samuraiexpertsstorage.blob.core.windows.net boletoflexhom.azurewebsites.net boletoflex.azurewebsites.net *.bflx.com.br *.google.com analytics.google.com *.g.doubleclick.net *.googleadservices.com *.com.au service.smarthint.co *.google.com.br *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.facebook.net *.googleapis.com *.google.de *.googletagmanager.com *.google.pt *.google-analytics.com *.google.fr *.com.py *.co.jp *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br azurewebsites.net static.hotjar.com static.fbits.net koin-custom-conector-gateway.fbits.net payments.koin.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.mailbiz.one *.jsdelivr.net *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.pagseguro.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.construmarques.com.br construmarques.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.ccavenue.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.ccavenue.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.ccavenue.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.ccavenue.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.ccavenue.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.clarity.ms https://c.bing.com 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'nonce-1746633616965' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://*.clarity.ms https://www.youtube.com https://www.googleadservices.com https://ad.doubleclick.net https://googleads.g.doubleclick.net https://lett.2buycdn.com; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://*.clarity.ms https://www.youtube.com https://www.googleadservices.com https://ad.doubleclick.net https://googleads.g.doubleclick.net https://lett.2buycdn.com; style-src 'self' 'unsafe-inline' 'nonce-1746633616965' https://use.typekit.net https://p.typekit.net; style-src-elem 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net; style-src-attr 'unsafe-inline'; font-src 'self' https://use.typekit.net https://p.typekit.net; img-src 'self' data: blob: https://www.google-analytics.com https://www.facebook.com https://ad.doubleclick.net https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://www.google.com.br https://*.clarity.ms; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://www.google.com https://www.google.com.br https://ad.doubleclick.net https://stats.g.doubleclick.net https://www.googleadservices.com https://connect.facebook.net https://www.facebook.com https://*.clarity.ms; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com https://www.google.com https://6689030.fls.doubleclick.net https://td.doubleclick.net; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-uri https://www.claybom.com.br/server/csp-report.php 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojanetlab.com.br *.lojanetlab.com.br wake-components.fbitsstatic.net lojanetlab.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com api.fbits.net *.fbits.net *.eficazmarketing.com *.fbits.store *.reclameaqui.com.br s3.amazonaws.com cdn.jsdelivr.net eficazmarketing.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.ucarecdn.com *.uploadcare.com *.yviews.com.br *.yourviews.com.br service2.yourviews.com.br *.lojaconfiavel.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br viacep.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br cdn02.jotfor.ms *.jotfor.ms clarity.ms *.clarity.ms tag.goadopt.io *.goadopt.io stats.g.doubleclick.net *.g.doubleclick.net googleads.g.doubleclick.net disclaimer-api.goadopt.io td.doubleclick.net *.doubleclick.net *.google.be *.google.com.br *.googleadservices.com *.google.com *.fbitsstatic.net *.com.ar *.youtube.com *.googletagmanager.com *.pachane.com.br *.fpcs-monitor.com.br *.localhost:5500 *.grasow.com *.com.py *.chrome-extension *.com.ec *.co.uk *.google.ca *.googleapis.com adservice.google.com *.facebook.net google.co.jp *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br googletagmanager.com *.google-analytics.com securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.google.it *.google.pt *.instagram.com *.mylabor.com.br mylabor.com.br instagram.fvix1-1.fna.fbcdn.net *.fvix1-1.fna.fbcdn.net scontent.cdninstagram.com *.cdninstagram.com *.fldb1-1.fna.fbcdn.net *.cupom.social wake.koin.com.br bat.bing.com *.bing.com *.google.es paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com plugins.soclminer.com.br *.soclminer.com.br graph.instagram.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.lojanetlab.com lojanetlab.com *.3dsecure.io *.conectiva.io:1:0 *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojanetlab.com.br lojanetlab.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojaslivia.com.br *.lojaslivia.com.br wake-components.fbitsstatic.net lojaslivia.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com hotjar.com cloudflare.com zopim.com googleadservices.com hertzen.com smarthint.co doubleclick.net zdassets.com googleapis.com hotjar.io *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.zdassets.com *.googleapis.com *.hotjar.io *.hotjar.com *.cloudflare.com *.googleadservices.com *.hertzen.com *.smarthint.co *.doubleclick.net *.zopim.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.ebit.com.br *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.traycheckout.com.br *.yapay.com.br *.clearsale.com.br wss://widget-mediator.zopim.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.mailbiz.one cdn.jsdelivr.net *.jsdelivr.net *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.facebook.net *.facebook.com *.pinterest.com google.com.br *.google.com.br *.gstatic.com blog.lojaslivia.com.br lojaslivia.com.br d3bo67muzbfgtl.cloudfront.net api.edrone.me *.visa.com lojaslivia-br.mais.social *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojaslivia.com.br lojaslivia.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src maxcdn.bootstrapcdn.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.gstatic.com 'self' data: v2.zopim.com *.zopim.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.facebook.com *.hotjar.com *.doubleclick.net https://e.issuu.com v2assets.zopim.io *.pinterest.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.storyblok.com *.hsforms.net *.hsforms.com 'self' data: *.monsoonconsulting.dev *.cloudwaysapps.com *.facebook.com api.feefo.com *.google.com *.google.ie *.google.pt *.google.fr *.google.com.br *.zopim.com *.zopim.io *.pinterest.com *.cookiepro.com *.getamigo.io *.goodgrowth.tech *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.autoaddress.ie *.storyblok.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.cloudwaysapps.com *.hotjar.com connect.facebook.net api.feefo.com register.feefo.com v2.zopim.com *.klaviyo.com widget-mediator.zopim.com browser-update.org static.zdassets.com *.doubleclick.net *.googletagmanager.com *.cookiepro.com *.avada.io *.pinimg.com *.pinterest.com *.getamigo.io *.goodgrowth.tech *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.fontawesome.com https://static.klaviyo.com *.storyblok.com *.googleapis.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.autoaddress.ie *.googleapis.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com *.feefo.com ekr.zdassets.com wss://widget-mediator.zopim.com/ *.doubleclick.net *.klaviyo.com *.cookiepro.com *.google.com *.getamigo.io *.cloudwaysapps.com *.hotjar.io *.facebook.com *.zopim.com *.paypal.com *.pinterest.com *.goodgrowth.tech https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://use.typekit.net *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.svea.com https://*.vipps.no https://*.trustly.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.trustpilot.com www.paypalobjects.com google-analytics.com vimeo.com *.yotpo.com *.googleapis.com https://use.typekit.net/* *.cookiebot.com/ *.fontawesome.com htps://fonts.gstatic.com https://*.svea.com *.weltpixel.com checkoutapistage.svea.com *.swiipe.com *.paymentiq.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://cdn.clerk.io *.google.com cdn.valuesportal.com log.adtraction.fail https://www.unifaunonline.se https://*.tile.openstreetmap.org/ imgsct.cookiebot.com *.bing.com *.clarity.ms *.swiipe.com maps.gstatic.com *.disqus.com https://img.youtube.com https://meetanshi.com/media/logo.png flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com/ *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.clerk.io https://cdn.clerk.io *.api.unifaun.com cdn.clerk.io api.clerk.io custom.clerk.io widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js v2.zopim.com *.gstatic.com chimpstatic.com static.zdassets.com bam.eu01.nr-data.net *.cookiebot.com/ addrevenue.io/ valuesportal.com cdn.adt393.com gtm.adt313.net pin.gymkompaniet.se cdn1.profitmetrics.io t.adii.se https://*.svea.com https://api.unifaun.com consent.cookiebot.com checkoutapistage.svea.com *.bing.com *.clarity.ms *.swiipe.com maps.googleapis.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://cdn1.profitmetrics.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io *.googleapis.com *.yotpo.com https://use.typekit.net cdn.dnky.com https://p.typekit.net *.fontawesome.com *.swiipe.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src *.swiipe.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com my.profitmetrics.io gymkompaniet.zendesk.com https://ekr.zdassets.com widget-mediator.zopim.com https://googleads.g.doubleclick.net https://static.doubleclick.net https://stats.g.doubleclick.net www.youtube.com bam.eu01.nr-data.net api.adtraction.net pin.gymkompaniet.se log.adtraction.fail consentcdn.cookiebot.com *.clarity.ms *.bing.com *.swiipe.com maps.googleapis.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src http: https: data:; font-src https: data:; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.iglusport.si www.iglusport.rs iglusport.magento.dev.optiweb.si www.google.com cdn.flipsnack.com consentcdn.cookiebot.com td.doubleclick.net www.facebook.com www.googletagmanager.com kuula.co c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.iglusport.si *.iglusport.rs iglusport.magento.dev.optiweb.si *.cookiebot.com *.google.si *.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.cookiebot.com static.kuula.io kuula.co c.bing.com *.clarity.ms pagead2.googlesyndication.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.iglusport.si *.iglusport.rs iglusport.magento.dev.optiweb.si unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io pagead2.googlesyndication.com *.google-analytics.com maps.googleapis.com *.iglusport.si *.iglusport.rs capig.stape.tech *.cookiebot.com *.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src capig.stape.tech 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; script-src 'self' cdn.globalpay.com.co cdnjs.cloudflare.com https://cdn.ampproject.org https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com https://www.google.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.icomoon.io i.icomoon.io fonts.googleapis.com *.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors self *.worldpay.com https://www.google.com https://www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com self consentcdn.cookiebot.com *.worldpay.com *.livechatinc.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.reviews.io *.reviews.co.uk *.weltpixel.com try.access.worldpay.com access.worldpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io mageside.com self maps.googleapis.com *.clarity.ms *.google.com *.google.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.google.com.ua *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.mageside.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com self *.googleapis.com cdn.icomoon.io consent.cookiebot.com *.cardinalcommerce.com youtube.com jquery.sellxed.com *.trackedlink.net ddlnk.net dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com *.gstatic.com *.trustpilot.com cdn.jsdelivr.net *.bugherd.com *.hotjar.com *.livechatinc.com *.myriadpayments.com *.clarity.ms *.klaviyo.com *.worldpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net *.avada.io *.reviews.io *.reviews.co.uk https://www.googletagmanager.com tagmanager.google.com try.access.worldpay.com access.worldpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com self cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cdn.icomoon.io i.icomoon.io use.typekit.net p.typekit.net *.cloudfront.net *.googleapis.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.reviews.io *.reviews.co.uk tagmanager.google.com data: *.myriadpayments.com *.klaviyo.com https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com www.google.co.uk region1.google-analytics.com *.clarity.ms *.klaviyo.com *.livechatinc.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io *.cloudfront.net *.reviews.io *.reviews.co.uk https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src self cdn.icomoon.io unpkg.com fonts.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' blob: https://prod-bk-web.nz.rbi.tools/en/static/js/vendor.a6eaa405.js https://prod-bk-web.nz.rbi.tools/en/static/js/main.dca8508c.js https://prod-bk-web.nz.rbi.tools/en/static/js/runtime.f1bcba12.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.nz.rbi.tools/en/static/js/vendor.e07adce7.js https://prod-bk-web.nz.rbi.tools/en/static/js/main.a88adef4.js https://prod-bk-web.nz.rbi.tools/en/static/js/runtime.eeea76eb.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.com.pt https://www.myheritage.com.pt 'unsafe-eval' 'nonce-8b4b522c56f9033fae0817be0f205c07' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.com.pt;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src self; font-src self; img-src self; script-src self; style-src self 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; script-src 'nonce-429649053bdb4bc781d58b5de44d6d2f' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; style-src 'self' 'nonce-429649053bdb4bc781d58b5de44d6d2f' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=145-0340557-5581622:rid=4CD70B9B498B484FBDD1:sn=www.amazongamestudios.com 1 font-src *.fontawesome.com *.typekit.net *.cloudflare.com *.twitter.com *.gstatic.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com consentcdn.cookiebot.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io js.mollie.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googletagmanager.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com cdn.conveythis.com www.gstatic.com recaptcha.org *.js.mollie.com *.assets.braintreegateway.com *.api.braintreegateway.com *.googleapis.com *.cookiebot.com consent.cookiebot.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline *.typekit.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com ws: *.cloudflare.com *.twitter.com *.twimg.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com ws: *.cloudflare.com api-proxy.conveythis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://shop.website.it/; report-to report-endpoint; 1 font-src https://*.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.klaviyo.com *.typekit.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://tr.snapchat.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.googletagmanager.com *.doubleclick.net *.redintelligence.net *.trustpilot.com *.googlesyndication.com *.dwin1.com https://widget.trustpilot.com https://tr.snapchat.com https://ad4mat.net https://ad4m.at https://s7.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://*.gstatic.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ad4m.at *.bidswitch.net *.sync.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com blob: *.google.com *.google.co.uk *.gstatic.com *.googlesyndication.com *.bing.com *.bing.net *.cloudflare.com *.cloudfront.net *.roeye.com *.freshchat.com *.clarity.ms *.wisepops.com wisepops.net *.soreto.com https://scontent.cdninstagram.com https://tr.outbrain.com https://bat.bing.com https://x.klarnacdn.net https://www.zenaps.com https://www.awin1.com https://lh4.googleusercontent.com https://r.adserver01.de https://secure.adnxs.com https://adservice.google.co.uk https://ads.creative-serving.com https://aa.agkn.com https://adadvisor.net https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleoptimize.com *.disqus.com *.avada.io *.shopify.com *.google.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.tiktok.com *.taboola.com *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.withcubed.com *.roeyecdn.com *.klaviyo.com *.trustpilot.com *.visualwebsiteoptimizer.com *.payments-amazon.com fw-cdn.com cdn-sitegainer.com *.ip-api.com *.cloudflare.com *.cloudfront.net *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.ytimg.com *.googleapis.com *.vimeo.com *.freshchat.com *.outbrain.com *.sciencebehindecommerce.com *.cloudflareinsights.com https://amplify.outbrain.com https://tr.outbrain.com https://static.zdassets.com https://widget.trustpilot.com https://bat.bing.com https://www.dwin1.com https://sc-static.net https://ad4m.at https://z.moatads.com https://s7.addthis.com https://v1.addthisedge.com https://m.addthis.com https://bam.eu01.nr-data.net *.hsforms.net *.hsforms.com https://snippets.freshchat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ cc-cdn.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com data: *.googleapis.com *.googlesyndication.com *.typekit.net *.seersco.com *.klaviyo.com *.freshchat.com https://fonts.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googlesyndication.com *.doubleclick.net *.bing.com *.bing.net *.taboola.com *.tiktok.com *.tiktokw.us *.seersco.com *.soreto.com *.clarity.ms *.wisepops.com wisepops.net *.awinblackfriday.com *.freshchat.com *.amazonaws.com *.googletagmanager.com *.dwin1.com *.trustpilot.com *.zopim.com wss://widget-mediator.zopim.com https://makemyblinds.zendesk.com https://ekr.zdassets.com *.algolianet.com https://telemetrics.klaviyo.com https://bat.bing.com https://m.addthis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://js.playground.klarna.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com static.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.powerboard.commbank.com.au *.paydock.com mtf.gateway.mastercard.com/ *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.powerboard.commbank.com.au *.paydock.com mtf.gateway.mastercard.com/ auth.sandbox.zip.co/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.bolt.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.dotdigital-pages.com *.dotdigital.com *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com *.paydock.com *.powerboard.commbank.com.au pay.google.com mtf.gateway.mastercard.com/ *.afterpay.com *.zip.co *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://static.afterpay.com site-assets.afterpay.com *.trackedlink.net *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.zip.co static.zipmoney.com.au *.zip.co d3k1w8lx8mqizo.cloudfront.net static.sandbox.afterpay.com *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://api.addressfinder.io https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.gstatic.com *.avada.io *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.authorize.net test.authorize.net js.braintreegateway.com maps.googleapis.com fonts.googleapis.com *.nosto.com *.nos.to assets.braintreegateway.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com static.zipmoney.com.au zip.co widget.paydock.com *.powerboard.commbank.com.au static.zip.co bpi.zip.co *.squarecdn.com portal.sandbox.afterpay.com applepay.cdn-apple.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com static.zip.co tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net *.bolt.com qa-api.magedevteam.com *.sentry.io https://api.addressfinder.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paydock.com *.powerboard.commbank.com.au static.zipmoney.com.au *.afterpay-beta.com *.cloudfront.net trx.zip.co *.zip.co *.google.com/pay *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem *.lursoft.lv cookiehub.net *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.hotjar.com *.cloudflareinsights.com *.doubleclick.net *.facebook.net *.mxapis.com *.klaviyo.com *.unpkg.com/* *.googlesyndication.com *.creativecdn.com *.videoly.co *.youtube.com *.maksekeskus.ee 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem *.cookiehub.net *.cookiehub.eu cookiehub.net *.googleapis.com assets.mxapis.com *.klaviyo.com 'self' 'unsafe-inline'; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.typekit.net *.trustedshops.com *.fontawesome.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.twitter.com *.twimg.com *.googleapis.com data: *.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com *.youtube.com youtu.be *.vimeo.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee *.twitter.com *.youtube-nocookie.com *.hotjar.com forms.office.com *.creativecdn.com *.googlesyndication.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klarna.com *.paypal.com *.ytimg.com *.usercentrics.eu *.maksekeskus.ee *.test.maksekeskus.ee https://maps.omnivasiunta.lt *.googleadservices.com *.google.lv *.googleapis.com *.twitter.com *.twimg.com *.lightemporium.com *.every-pay.com *.prof.lv *.omnivasiunta.lt *.klix.app *.googletagmanager.com api.mapbox.com *.cartocdn.com *.magecomp.com *.kevin.eu *.gstatic.com *.cloudfront.net *.videoly.co https://redchamps.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.google-analytics.com www.google.com www.gstatic.com *.trustedshops.com *.usercentrics.eu *.avada.io 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: https://unpkg.com *.twitter.com *.googleapis.com *.twimg.com *.gstatic.com *.fontawesome.com *.cloudflareinsights.com gatete.luminorgroup.com *.newrelic.com *.nr-data.net *.lursoft.lv cookiehub.net *.yandex.ru *.hotjar.com *.klaviyo.com *.unpkg.com/* 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doubleclick.net *.facebook.com https://static.klaviyo.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.twitter.com *.twimg.com *.gstatic.com *.bootstrapcdn.com cookiehub.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.paypal.com *.googleapis.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee https://geocode.arcgis.com *.twitter.com *.twimg.com *.fontawesome.com *.nr-data.net *.arcgis.com stats.g.doubleclick.net *.lursoft.lv *.yandex.ru *.hotjar.com *.hotjar.io *.google.com *.klaviyo.com *.creativecdn.com 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.cloudflare.com *.cloudwaysapps.com *.amazonaws.com *.googleadservices.com *.facebook.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com *.cloudwaysapps.com www.google.com www.gstatic.com *.bootstrapcdn.com *.facebook.net *.googletagmanager.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.network *.stripecdn.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com *.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://cuatro.sim-cdn.nl; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-M2M5ODMxMmQtMjgwYi00MWExLTg2OTgtZmM4Y2ZlNjA4ZDNi' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.hotjar.com *.hotjar.io *.cloudflare.com *.gstatic.com *.peterprint.nl *.frontapp.com *.sentry-cdn.com *.facebook.com *.facebook.net *.doubleclick.net *.clarity.ms peterprint.wufoo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://www.googletagmanager.com/ *.klarna.com www.xtento.com *.multisafepay.com https://pay.google.com *.cloudflare.com *.google.com *.hotjar.com *.hotjar.io *.frontapp.com *.sentry-cdn.com *.peterprint.nl *.facebook.com *.facebook.net *.doubleclick.net peterprint.wufoo.com *.pinterest.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.sharethis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com *.multisafepay.com cdn-cookieyes.com *.placeholder.com *.peterprint.nl *.cloudflare.com *.google.nl *.bing.com *.googleapis.com *.gstatic.com *.sentry-cdn.com *.cookieyes.com *.facebook.com *.clarity.ms *.doubleclick.net *.frontapp.com *.visualwebsiteoptimizer.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.sharethis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com www.xtento.com cdn.xtento.com *.multisafepay.com https://pay.google.com cdn-cookieyes.com *.cookieyes.com *.google.com *.gstatic.com *.google-analytics.com *.hotjar.com *.hotjar.io *.fontawesome.com *.cloudflare.com *.mouseflow.com *.peterprint.nl *.bing.com *.doubleclick.net unpkg.com *.googleapis.com *.googleoptimize.com *.frontapp.com *.sentry-cdn.com *.facebook.com *.facebook.net *.clarity.ms peterprint.wufoo.com *.pinterest.com *.pinimg.com *.visualwebsiteoptimizer.com *.sendcloud.sc *.jsdelivr.net https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.multisafepay.com *.googleapis.com *.peterprint.nl *.sentry-cdn.com *.cookieyes.com *.facebook.com *.facebook.net *.doubleclick.net *.clarity.ms peterprint.wufoo.com *.frontapp.com *.cloudflare.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.sharethis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io *.multisafepay.com cdn-cookieyes.com *.cookieyes.com *.google.com *.gstatic.com *.google-analytics.com *.fontawesome.com *.hotjar.com *.hotjar.io *.cloudflare.com *.peterprint.nl *.googleapis.com https://chat-assets.frontapp.com/ *.sentry-cdn.com *.facebook.com *.facebook.net *.doubleclick.net *.clarity.ms peterprint.wufoo.com *.pinterest.com https://sessions.bugsnag.com wss://front-eu-realtime.ably.io *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'sha256-Ik2zJXrghvpFggM0aGJJcKJXb9RZV2yAzAD7+mXLIvY=' 'self' 'self' https://collect.impressiondigital.com https://bat.bing.com https://ads-twitter.com https://static.ads-twitter.com https://doubleclick.net https://cdn-cookieyes.com https://connect.facebook.net https://posthog.com https://eu.posthog.com https://eu-assets.i.posthog.com https://www.youtube-nocookie.com https://clarity.ms https://y.clarity.ms https://snap.licdn.com https://hsforms.net https://hs-analytics.net https://hs-banner.com https://js-eu1.hs-banner.com https://hs-scripts.com https://js-eu1.hs-scripts.com https://js-eu1.hubspot.com https://usemessages.com https://js-eu1.hs-analytics.net https://js-eu1.hsforms.net https://o377590.ingest.sentry.io https://forms-eu1.hsforms.com https://www.googleadservices.com https://www.google.co.uk https://px.ads.linkedin.com https://*.typekit.net https://t.co https://www.facebook.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googletagmanager.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net; script-src-elem 'self' https://www.youtube.com https://*.clarity.ms https://gateway.impressiondigital.com https://collect.impressiondigital.com https://www.gstatic.com https://js-eu1.hs-banner.com https://cdn-cookieyes.com https://js-eu1.hs-scripts.com https://bat.bing.com https://snap.licdn.com https://static.ads-twitter.com https://eu.posthog.com https://eu-assets.i.posthog.com https://js-eu1.hsforms.net https://js-eu1.hubspot.com https://js-eu1.hs-analytics.net; style-src 'self' https://cdn-cookieyes.com https://fonts.googleapis.com https://*.typekit.net https://www.gstatic.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' https://bat.bing.com https://ads-twitter.com https://doubleclick.net https://ad.doubleclick.net https://connect.facebook.net https://posthog.com https://clarity.ms https://*.clarity.ms https://snap.licdn.com https://px.ads.linkedin.com https://t.co https://www.facebook.com https://images.impression.co.uk https://track-eu1.hubspot.com https://perf-eu1.hsforms.com https://forms-eu1.hsforms.com https://www.glassdoor.co.uk https://adservice.google.com https://cdn-cookieyes.com https://analytics.twitter.com https://px4.ads.linkedin.com https://region1.analytics.google.com https://i.ytimg.com https://stape.io https://collect.impressiondigital.com https://cdn.impression.co.uk https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://google.com https://gateway.impressiondigital.com https://px.ads.linkedin.com; connect-src 'self' https://o377590.ingest.sentry.io https://www.google-analytics.com https://www.google.co.uk https://clarity.ms https://posthog.com https://eu.posthog.com https://hs-analytics.net https://js-eu1.hs-analytics.net https://usemessages.com https://collect.impressiondigital.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://www.youtube.com https://accounts.google.com https://cta-eu1.hubspot.com https://forms-eu1.hsforms.com https://pagead2.googlesyndication.com https://staging.admin.impressiondigital.com https://admin.impressiondigital.com https://api.teamtailor.com https://eu.i.posthog.com https://log.cookieyes.com https://directory.cookieyes.com https://cdn-cookieyes.com https://px.ads.linkedin.com https://www.googleadservices.com https://bat.bing.com https://bat.bing.net https://sitemap-tool.impression.co.uk https://gateway.impressiondigital.com https://*.clarity.ms https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk https://pagead2.googlesyndication.com https://google.com https://eu-assets.i.posthog.com; font-src 'self' https://fonts.gstatic.com https://*.typekit.net; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://forms-eu1.hsforms.com https://hsforms.net https://collect.impressiondigital.com https://www.googletagmanager.com https://consent.cookieyes.com; media-src 'self' https://www.youtube.com https://www.youtube-nocookie.com; object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests ; require-trusted-types-for 'script'; report-uri https://report.centralcsp.com/68b831ea648355d9060a0089 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: *.gstatic.com *.bootstrapcdn.com *.zopim.com https://widgets.trustedshops.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net player.vimeo.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.googletagmanager.com/ *.vimeo.com *.hotjar.com *.google.com *.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: *.vimeocdn.com s.ytimg.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de imgsct.cookiebot.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ flagpedia.net *.koongo.com *.retailrocket.net *.google.com *.google.nl *.bing.com *.facebook.com *.trustedshops.com *.facebook.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.google.fr *.google.ie 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com polyfill.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de consent.cookiebot.com *.retailrocket.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.gstatic.com maps.googleapis.com *.cloudflare.com chimpstatic.com *.google.com *.trustedshops.com *.google-analytics.com *.googleadservices.com browser-update.org *.bing.com *.facebook.com *.doubleclick.net *.hotjar.com *.facebook.net *.zopim.com *.newrelic.com *.nr-data.net *.zdassets.com *.googletagmanager.com *.cookiebot.com *.clarity.ms https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.google.fr *.google.ie googleads.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.sooqr.com *.spotlersearch.com maxcdn.bootstrapcdn.com *.gstatic.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css *.retailrocket.net *.bootstrapcdn.com *.googleapis.com *.cloudflare.com *.googletagmanager.com *.cookiebot.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.algolia.net *.algolia.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.retailrocket.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.gstatic.com maps.googleapis.com *.koongo.com *.doubleclick.net *.hotjar.io *.hotjar.com *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com *.nr-data.net *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem www.googletagmanager.com ajax.googleapis.com consent.cookiebot.com consentcdn.cookiebot.com embed.sendcloud.sc cdn.jsdelivr.net gc.kis.v2.scr.kaspersky-labs.com ff.kis.v2.scr.kaspersky-labs.com infirc.com ritrag.com me.kis.v2.scr.kaspersky-labs.com connect.facebook.net infird.com kproxyservers.site gc.kes.v2.scr.kaspersky-labs.com cdn.toolszen.com ff.kes.v2.scr.kaspersky-labs.com mstat.acestream.net cdnjs.cloudflare.com data1.pletar.com apis.google.com translate.google.com translate.googleapis.com c.chuyueshop.com gc.kis.scr.kaspersky-labs.com me.kes.v2.scr.kaspersky-labs.com dakotaram.com jullyambery.net hublosk.com wistiaextension.com utq.vvipquan.com secured-pixel.com 3001.scriptcdn.net api.wire.threatspike.com extensionscontrol.com cdn.cookie-script.com www.oilonline.store sc-static.net 4ddons.com cdn.sleak.chat static.ads-twitter.com rialto-gms.s3.amazonaws.com vk-online.xyz pro-sw.ru mainf.global-cache.online www.pagespeed-mod.com www.google-analytics.com images.uc.cn g.alicdn.com vtesting.yoganc.fun dmp.im-apps.net static.hotjar.com www.clickcease.com script.hotjar.com assets.adobedtm.com pagead2.googlesyndication.com conversations-widget.sendinblue.com cdn.by.wonderpush.com bokezu.tijapixuno.com static.cloudflareinsights.com www.google.com www.gstatic.com mediashower.com www.youtube.com youwanoss.oss-cn-shanghai.aliyuncs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem maxcdn.bootstrapcdn.com fonts.googleapis.com cdn.jsdelivr.net gc.kis.v2.scr.kaspersky-labs.com ff.kis.v2.scr.kaspersky-labs.com www.gstatic.com pwm-image.trendmicro.com me.kis.v2.scr.kaspersky-labs.com www.oilonline.store cdn.honey.io use.fontawesome.com cdn.sleak.chat adblockers.opera-mini.net mediashower.com 'self' 'unsafe-inline'; font-src maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com at.alicdn.com cdn.megabonus.com use.typekit.net static.hsappstatic.net themes.googleusercontent.com chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia static3.avast.com use.fontawesome.com aceify.ai cdn.scite.ai cdn.fontshare.com www.slant.co appdown.pstatic.net app.escribelo.ai qncdn.aoscdn.com cdn.faceworks.nl www.oilonline.store assets.alicdn.com cdnjs.cloudflare.com images.simplycodes.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com r2cdn.perplexity.ai www.vinci.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com www.oilonline.store translate.googleapis.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.oilonline.store 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.sendcloud.sc *.jsdelivr.net *.weltpixel.com www.xtento.com *.googletagmanager.com *.doubleclick.net consentcdn.cookiebot.com www.googletagmanager.com pwm-image.trendmicro.com gateway.zscloud.net gateway.zscalerthree.net menrealitycalc.com safe.menlosecurity.com gateway.zscaler.net acestream.tv emet.live emet.news gateway.zscalertwo.net feedback-pa.clients6.google.com c.safen110.com div.show global.acs.prismaaccess.com 172.16.1.240:9123 noop.style portal.farsons.com 10.33.141.1 wm-livechat-2-prod-dot-watermelonmessenger.appspot.com translate.googleapis.com widget.sleak.chat lordfilm-crew.net remove.video block.opendns.com www.youtube.com.x.11d761ca0d21704a6c0b3510df542b18da88.d045213f.id.opendns.com www.oelonline.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io quickchart.io img.youtube.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com *.gstatic.com *.facebook.com maps.googleapis.com www.xtento.com cdn.xtento.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://www.magezon.com flagpedia.net imgsct.cookiebot.com www.olieonline.nl www.olieonline.co.uk www.oelonline.com translate.google.com log-papago.naver.com pos.baidu.com www.oilonline.store cdn.honey.io mc.yandex.ru translate.googleapis.com dakotaram.com yastatic.net staging.oilonline.store sygpwnluwwetrkmwilea.supabase.co uploads-ssl.webflow.com t.co analytics.twitter.com my.productfruits.com gateway.zscalertwo.net cdn.sleak.chat actimg.heytapimg.com stagingcw.olieonline.co.uk www.bing.com img.alicdn.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.sendcloud.sc *.jsdelivr.net ajax.googleapis.com *.google.com *.facebook.net unpkg.com maps.googleapis.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.gstatic.com consent.cookiebot.com consentcdn.cookiebot.com greasyfork.org update.greasyfork.org cdn.cookie-script.com cdn.sleak.chat static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com unsafe-inline *.sendcloud.sc *.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com *.gstatic.com www.gstatic.com cdn.sleak.chat 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com ssl.gstatic.com sygpwnluwwetrkmwilea.supabase.co cdn.sleak.chat 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.gstatic.com maps.googleapis.com consentcdn.cookiebot.com translate.googleapis.com translate-pa.googleapis.com overbridgenet.com api.global-data-lab.com api.mkmediaworks.com wss://ny1.xmrminingproxy.com consent.cookiebot.com www.oilonline.store gjtrack.ucweb.com api.amcreativemedia.com api.fbanalytics.org yandex.ru www.google.com s3.ap-east-1.amazonaws.com o0rmue7xt0.execute-api.il-central-1.amazonaws.com wss://127.0.0.1:2020 wss://127.0.0.1:2023 wss://127.0.0.1:2024 wss://127.0.0.1:2021 wss://127.0.0.1:2025 wss://127.0.0.1:2027 wss://127.0.0.1:2022 wss://127.0.0.1:2026 wss://127.0.0.1:2029 wss://127.0.0.1:2028 localhost:8036 api.trongrid.io n.wistiaextension.com region1.google-analytics.com ajax.googleapis.com baidustatics.net infragrid.v.network adtonus.com code.jquery.com rktds.net d1lkfzu2puirk6.cloudfront.net consent.cookie-script.com editor.api.clonable.net clientstream.launchdarkly.com fonts.googleapis.com fonts.gstatic.com local.adblock360.com cdn.sleak.chat widget.sleak.chat sygpwnluwwetrkmwilea.supabase.co my.productfruits.com api.video-adblock.com gateway.zscalertwo.net api.privacy-protector-adblocker.com ws://127.0.0.1:35729 tl.ytlogs.ru service.gstatic-cache.com cdnmmh.global-cache.online aegis.qq.com api.vid-adblocker.com localhost:4443 detector.scamsniffer.io px.wpk.quark.cn vtesting.yoganc.fun www.facebook.com api.freevideoguard.org www.olieonline.co.uk junklip.com ad-ninja.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.amazon.de www.exxonmobil.com www.mobil.com www.oelonline.com 7gtronic.pl 'self' 'unsafe-inline'; report-uri https://www.olieonline.co.uk/rest/all/V1/cspmanager/frontend_report; 1 default-src 'self' data:; report-uri /csp.cfm; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.typekit.net; font-src 'self' data: https:; frame-ancestors 'self'; frame-src 'self' player.vimeo.com *.youtube.com www.google.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' ajax.googleapis.com www.google-analytics.com www.googletagmanager.com maps.googleapis.com; img-src 'self' data: www.google-analytics.com maps.googleapis.com maps.gstatic.com www.googletagmanager.com; connect-src 'self' *.google-analytics.com 1 font-src i.icomoon.io fonts.gstatic.com *.typekit.net *.gstatic.com 'self' data: https://dashboard.trustprofile.comfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.becom.digital *.facebook.com *.google.com *.salesmanago.pl *.trustprofile.com *.youtube-nocookie.com becom.digital www.googletagmanager.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net https://dashboard.trustprofile.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.doubleclick.net *.facebook.com *.facebook.net *.googleadservices.com *.googlesyndication.com *.gstatic.com *.newstat.net *.salesmanago.pl *.trustprofile.com blogger.googleusercontent.com www.google.be *.salesmanago.es *.salesmanago.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.multisafepay.com *.koongo.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com *.cookie-script.com *.facebook.net *.salesmanago.com *.salesmanago.pl *.salesmanago.es *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js *.sendcloud.sc *.jsdelivr.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://dashboard.trustprofile.com/sidebar.js *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googletagmanager.com i.icomoon.io fonts.googleapis.com *.typekit.net *.multisafepay.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.cookie-script.com *.facebook.com *.google.com *.googleadservices.com *.googlesyndication.com google.com pay.google.com www.google.be www.google.com stats.g.doubleclick.net *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.multisafepay.com *.koongo.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5a66314f-575a-41a8-9234-232d774a014f.sansec.watch/; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ lh-dottie.dcatalog.com *.dotdigital-pages.com *.dotdigital.com www.google.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com/ *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.trackedlink.net https://www.magezon.com maps.gstatic.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ html5.dcatalog.com cdnjs.cloudflare.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com/ https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdnjs.cloudflare.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com bam.nr-data.net maps.googleapis.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' data: blob: 'nonce-de30cead84fcd960e991ab1808ba32fc-argus' 'strict-dynamic' 'unsafe-inline' https:; connect-src 'self' *.idouyinvod.com:* *.volcsiriusbd.com:* *.volcsirius.com:* *.tt.x.bsgslb.cn:* *.dy.zzcdnx.com:* *.qc.bsccdn.net:* *.smtcdns.com:* *.ugslb.com:* *.livehwc3.cn:* *.smtcdns.net:* *.bytefcdnrd.com:* *.ksyungslb.com:* *.ksyungslb2.com:* *.ourdvsss.com:* *.tbcache.com:* *.jomodns.com:* *.douyincdn.com:* *.ixigua.com:* *.bdxigualive.com:* *.pstatp.com:* *.douyinliving.com:* *.picovr.com:* *.huoshanlive.com:* *.ihuoshanlive.com:* *.volccdn.com:* *.bestv.com.cn:* *.bytefcdn.com:* *.douyinvod.com:* *.qnqcdn.net:* *.weilayun.com:* *.saxysec.com:* *.saxyit.com:* *.saxydc.com:* *.sjxysec.com:* *.sjxydc.com:* *.hiecheimaetu.com:* *.ppio.cloud:* *.vegslb.com:* *.xsj.wasu.tv:* *.zebracdn.com:* *.volctranscdn.com:* *.hizhecheng.com:* *.sealaly.net:* *.souajki.net:* *.souajki.com:* *.souajki.cn:* *.siomxity.cn:* *.siomxity.com:* *.siomxity.net:* *.uochly.cn:* *.smogfly.cloud:* *.smogfly.club:* *.iquaveizeeru.com:* *.ietheivaicai.com:* *.bytescm.com *.bytetos.com *.ibytedapm.com *.zijieapi.com *.snssdk.com *.bytedance.com *.bytedance.net *.pstatp.com *.bytednsdoc.com *.bytegoofy.com *.byted-static.com *.yhgfb-cn-static.com *.usergrowth.com.cn:* *.toutiao.com:* *.fqnovel.com:* *.google-analytics.com:* *.fqnovelstatic.com:*; frame-ancestors 'self'; upgrade-insecure-requests ; report-to slardar-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://*.googleapis.com https://*.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://*.cookiebot.com https://*.cloudflareinsights.com https://trackcmp.net https://*.hotjar.com https://script.hotjar.com https://cdn.mxpnl.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data: https: blob:; connect-src 'self' https://*.thethirdwave.co https://*.googleapis.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com https://*.cookiebot.com https://*.hotjar.com https://*.mixpanel.com https://*.facebook.com https://connect.facebook.net; frame-src 'self' https://www.google.com https://www.youtube.com https://*.cookiebot.com https://*.hotjar.com https://*.facebook.com; object-src 'none'; base-uri 'self'; form-action 'self'; 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://d1pna5l3xsntoj.cloudfront.net www.apptrian.com x.klarnacdn.net cdn.klarna.com/1.0/shared/image www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net www.apptrian.com *.googleapis.com *.google.com *.gstatic.com bankauswahl.giropay.de www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com bankauswahl.giropay.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://core.helloretail.com www.apptrian.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com bankauswahl.giropay.de bankauswahl.girocheckout.de 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://accounts.google.com https://www.facebook.com https://login.live.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy https://js.tuna.uy *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy https://js.tuna.uy *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.hsforms.net *.hsforms.com *.gstatic.com https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy https://js.tuna.uy *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy https://js.tuna.uy *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com *.google.fr *.google.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.jsdelivr.net *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.gstatic.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.ewaypayments.com https://*.sandbox.ewaypayments.com *.ewaypayments.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://*.ewaypayments.com https://*.sandbox.ewaypayments.com js-agent.newrelic.com bam.nr-data.net *.ewaypayments.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com bam.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://cdn.goftino.com https://fonts.gstatic.com https://translate.google.com https://www.googletagmanager.com https://www.mayoclinic.org https://lh3.googleusercontent.com https://s3.goftino.com https://images.rxlist.com https://www.google-analytics.com https://elmobadan.ir blob: https://images.medicinenet.com https://really-simple-ssl.com https://s2.goftino.com https://encrypted-tbn0.gstatic.com https://api.themeisle.com https://www.google.com https://woocommerce.com https://torob.com https://cdn.zhaket.com https://pos.baidu.com https://api.wpclever.net https://www.gstatic.com https://pd.w.org https://notificationx.com https://duckduckgo.com https://drdarousaz.ir https://images.profileengine.com http://www.stackoverflow.com https://www.stackoverflow.com https://mc.yandex.ru https://embed-ssl.wistia.com https://cdn.yektanet.com https://tasvir-t.yektanet.com https://tasvir-r.yektanet.com https://tasvir.yektanet.com https://dkstatics-public.digikala.com https://cdn.lfunl.com https://static.cdn.asset.filimo.com https://tasvir-s.yektanet.com https://t.cdn.sfstr.com https://cdn.plnst.ir https://plus.sabavision.com https://ua.yektanet.com https://perfmatters.io http://drdarousaz.ir https://woodmart.xtemos.com https://assets.elementor.com https://bahmankhah.com https://addtrolly.com https://media.rtlcdn.com https://files.rtl-theme.com https://drsoleimanifar.com https://lingo4030.com https://content-marketing.rtlcdn.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' blob: data: https://cdn.goftino.com https://www.goftino.com https://drdarousaz.ir https://www.googletagmanager.com https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://www.pagespeed-mod.com https://www.google-analytics.com https://ff.kis.v2.scr.kaspersky-labs.com https://cdn.immereeako.info https://s3.scriptcdn.net https://connect.facebook.net https://infimv.com https://apis.google.com https://translate.google.com https://translate.googleapis.com https://translate-pa.googleapis.com https://gc.kes.v2.scr.kaspersky-labs.com https://3001.scriptcdn.net asset https://infirc.com https://fvpvpnextension.com https://unpkg.com https://cdnjs.cloudflare.com https://cdn.datatables.net https://www.google.com https://infird.com https://s3.amazonaws.com https://mstat.acestream.net https://cct.google https://fast.wistia.com https://beacon-v2.helpscout.net https://api.nimblecapture.com https://cdn.yektanet.com https://native-scripts.yektanet.com https://cdn.ravenjs.com https://emojikeyboardforchrome.com https://cdn.alsgp0.fds.api.mi-img.com https://s.skimresources.com https://com.lge.browser https://www.gstatic.com https://ajax.googleapis.com https://maps.google.com https://ff.kes.v2.scr.kaspersky-labs.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' blob: data: https://cdn.goftino.com https://www.goftino.com https://drdarousaz.ir https://www.googletagmanager.com https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://www.pagespeed-mod.com https://www.google-analytics.com https://ff.kis.v2.scr.kaspersky-labs.com https://cdn.immereeako.info https://s3.scriptcdn.net https://connect.facebook.net https://infimv.com https://apis.google.com https://translate.google.com https://translate.googleapis.com https://translate-pa.googleapis.com https://gc.kes.v2.scr.kaspersky-labs.com https://3001.scriptcdn.net asset https://infirc.com https://fvpvpnextension.com https://unpkg.com https://cdnjs.cloudflare.com https://cdn.datatables.net https://www.google.com https://infird.com https://s3.amazonaws.com https://mstat.acestream.net https://cct.google https://fast.wistia.com https://beacon-v2.helpscout.net https://api.nimblecapture.com https://cdn.yektanet.com https://native-scripts.yektanet.com https://cdn.ravenjs.com https://emojikeyboardforchrome.com https://cdn.alsgp0.fds.api.mi-img.com https://s.skimresources.com https://www.gstatic.com https://ajax.googleapis.com https://maps.google.com https://ff.kes.v2.scr.kaspersky-labs.com ; style-src 'self' 'unsafe-inline' https://cdn.goftino.com https://www.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com https://adblockers.opera-mini.net https://me.kis.v2.scr.kaspersky-labs.com data: https://gc.kis.v2.scr.kaspersky-labs.com https://cdnjs.cloudflare.com https://ff.kis.v2.scr.kaspersky-labs.com https://ajax.googleapis.com https://fonts.bunny.net https://drdarousaz.ir https://addtrolly.com ; style-src-elem 'self' 'unsafe-inline' https://cdn.goftino.com https://www.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com https://adblockers.opera-mini.net https://me.kis.v2.scr.kaspersky-labs.com data: https://gc.kis.v2.scr.kaspersky-labs.com https://cdnjs.cloudflare.com https://ff.kis.v2.scr.kaspersky-labs.com https://ajax.googleapis.com https://fonts.bunny.net https://drdarousaz.ir https://addtrolly.com ; font-src 'self' https://cdn.goftino.com https://fonts.gstatic.com https://cdn.scite.ai https://cdnjs.cloudflare.com https://qncdn.aoscdn.com moz-extension https://at.alicdn.com chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Regular.woff2 chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Medium.woff2 chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Medium.woff chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia/Inter-Bold.woff2 https://fonts.bunny.net chrome-extension://extension_id__/fonts/SFProText-Variable.otf chrome-extension://extension_id__/fonts/Inter-Variable.ttf chrome-extension://extension_id__/fonts/Recoleta-Variable.otf https://cdn-uicons.flaticon.com chrome-extension://294E33BD-64CB-420D-B37A-4B101C408C80/fonts/Inter-Variable.ttf https://pouch-global-font-assets.s3.eu-central-1.amazonaws.com https://cdn.fastdic.com https://pro.fontawesome.com https://www.slant.co https://pz.ihiof.ir data:; frame-src 'self' https://m.youtube.com https://www.googletagmanager.com https://mozbar.moz.com https://td.doubleclick.net https://www.ciuvo.com https://run.wemanage.app https://translate.googleapis.com https://www.youtube.com https://div.show https://surfe.be https://loader.media https://cosmicnootropic.com https://noop.style gsa://onpageload https://emet.news https://acestream.tv https://emet.live https://api.wp-rocket.me https://ua.yektanet.com https://www.google.com https://aiven-rest-aiven-public.database.cloud.ovh.net https://balad.ir blob:; connect-src 'self' https://www.google-analytics.com wss://ws11.goftino.com https://translate.googleapis.com https://region1.google-analytics.com https://www.goftino.com https://gjtrack.ucweb.com https://api.rankmath.com https://metrics-dre.dt.dbankcloud.cn https://metrics-dra.dt.dbankcloud.cn https://api.trongrid.io https://cdnml.global-cache.online https://tl.ytlogs.ru https://s3.goftino.com https://translate-pa.googleapis.com https://searchaggr-dra.dt.dbankcloud.com https://infragrid.v.network https://stats.g.doubleclick.net https://analytics.google.com https://detector.scamsniffer.io https://www.googleapis.com https://woocommerce.com https://www.googletagmanager.com https://overbridgenet.com https://cr-input.mxpnl.net wss://chaboktar.ir https://api.downloader-software.com https://adtonus.com https://code.jquery.com https://rktds.net https://api.software-downloading.com https://api.redirects-4.com https://publickeyservice.keys.adm-services.goog https://api.killadsapi.com http://127.0.0.1 https://api.browsekeeper.com https://api.freedomsair.com https://api.fbanalytics.org https://api.adblock360.net https://api.mkmediaworks.com https://api.amcreativemedia.com data: https://api.solaranalyticscorp.com https://api.privacy-protector-adblocker.com https://api.srv247app.com https://api.brs.intl.miui.com https://d3hb14vkzrxvla.cloudfront.net https://pipedream.wistia.com https://fast.wistia.com https://audience.yektanet.com https://ua.yektanet.com https://native-removal.triboon.net https://nfetch.yektanet.com https://event.yektanet.com https://ck.yektanet.com https://meetlookup.com https://wwwm https://searchaggr-dre.dt.dbankcloud.com wss://localhost https://apm-rum-sgp.inf.miui.com https://sentry.yektanet.tech wss://gc.kis.v2.scr.kaspersky-labs.com https://wpmudev.com https://app.formbricks.com https://cdnjs.cloudflare.com https://evmos-evm.publicnode.com https://maps.googleapis.com http://drdarousaz.ir https://addtrolly.com https://eon-rpc.horizenlabs.io; media-src 'self' https://cdn.goftino.com https://s2.goftino.com data: https://notificationx.com https://woodmart.xtemos.com; worker-src 'self' blob:; report-uri https://drdarousaz.ir/wp-json/rsssl/v1/csp?rsssl_apitoken=890740830; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com fonts.googleapis.com *.hotjar.com *.zopim.com data: app.probefahrtenbutler.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com finanzieren.consorsfinanz.de https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.googletagmanager.com td.doubleclick.net secure.pay1.de *.klarna.com *.klarnaservices.com/ www.xtento.com cdn.dnky.co www.youtube.com *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com inoa.de www.jsctool.com *.awin1.com payments.amazon.de jsctool.com js.playground.klarna.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://api.mapbox.com lantern.roeye.com widgets.trustedshops.com bat.bing.com www.gstatic.com maps.gstatic.com maps.googleapis.com www.google.com.vn *.klarna.com *.klarnaevt.com *.klarnacdn.net m.media-amazon.com https://widgets.trustedshops.com https://integrations.etrusted.com *.pixriot.com *.storeimaging.com www.xtento.com cdn.xtento.com *.nova-motors.de www.google.de www.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com www.linkedin.com linkedin.com googletagmanager.com gallery.mailchimp.com *.trustedshops.com www.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.ytimg.com *.awin1.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com widgets.trustedshops.com www.dwin1.com static.cloudflareinsights.com lantern.roeyecdn.com bat.bing.com cdn.jsdelivr.net www.google.com www.gstatic.com secure.pay1.de static-eu.payments-amazon.com *.tiktok.com https://widgets.trustedshops.com https://integrations.etrusted.com www.xtento.com cdn.xtento.com google.com gstatic.com *.googleapis.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.trustpilot.com *.newrelic.com *.nr-data.net www.googleoptimize.com www.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com www.dwin1.com/ *.awin1.com the.sciencebehindecommerce.com d.ratepay.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.googleapis.com www.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net maps.googleapis.com www.google.com.vn www.google.com secure.pay1.de payments-eu.amazon.com *.tiktok.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.awinblackfriday.com bat.bing.com *.tiktokw.us *.trustedshops.com *.etrusted.com *.pixriot.com *.storeimaging.com commerce.adobedc.net api.comapi.com www.google-analytics.com *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.nr-data.net www.clarity.ms *.facebook.com *.datatrics.com the.sciencebehindecommerce.com *.trustpilot.com payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com www.google.com payments-eu.amazon.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.tawk.to data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src https://secure.asxgw.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.tawk.to 'self' 'unsafe-inline'; img-src https://api.allsecpay.xyz https://i.postimg.cc assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com.ua *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ data: 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.facebook.net https://asxgw.com https://asxgw.paymentsandbox.cloud https://secure.asxgw.com https://asxgw.com/ assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src https://asxgw.paymentsandbox.cloud/ https://asxgw.com/ dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://fonts.gstatic.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.bootstrapcdn.com https://static.olark.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.certcapture.com www.facebook.com platform.twitter.com https://static.olark.com https://www.google.com https://bid.g.doubleclick.net https://www.equipmentleasing.org https://pay.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.certcapture.com *.hsforms.com *.hubspot.com *.searchspring.io *.searchspring.net d3cgm8py10hi0z.cloudfront.net magefan.com cm.magefan.com https://redchamps.com https://firebasestorage.googleapis.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://log.olark.com https://www.google.com https://marketing.labdepotinc.com https://www.google.com.ph https://www.googletagmanager.com https://www.gstatic.com https://stats.g.doubleclick.net https://bat.bing.com *.inspectlet.com https://analytics.sleeknote.com *.nextopia.net *.securitymetrics.com *.bing.com *.clarity.ms *.labdepotinc.com maps.gstatic.com *.facebook.com https://www.labdepotinc.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.bugherd.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hscollectedforms.net *.hs-scripts.com *.hubspot.com https://static.olark.com https://cdn.searchspring.net/intellisuggest/is.min.js s7.addthis.com *.avada.io connect.facebook.net twitter.com platform.twitter.com *.cloudflare.com *.google-analytics.com *.bootstrapcdn.com *.nextopia.net https://ac.nextopiasoftware.com https://connect.facebook.net https://nrpc.olark.com https://www.googletagmanager.com https://marketing.labdepotinc.com https://googleads.g.doubleclick.net https://www.google.com https://pay.google.com https://static.cloudflareinsights.com https://api.olark.com https://bat.bing.com https://apis.google.com https://assets.olark.com *.inspectlet.com https://labdepotinc-com.ecomm-nav.com *.clarity.ms js.hs-scripts.com *.newrelic.com *.pardot.com *.pinimg.com *.searchspring.io maps.googleapis.com cdn.ampproject.org www.gstatic.com tagmanager.google.com *.facebook.net unpkg.com https://d.clarity.ms https://www.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.certcapture.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com *.bootstrapcdn.com https://cdn.nextopia.net https://static.olark.com https://a.omappapi.com www.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.certcapture.com *.hscollectedforms.net *.hubapi.com *.hubspot.com *.hs-scripts.com *.searchspring.io *.bugherd.com a.omappapi.com https://beacon.searchspring.io/beacon ekr.zdassets.com/ https://get.geojs.io *.avada.io *.cloudflare.com *.bootstrapcdn.com https://nrpc.olark.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com https://stats.g.doubleclick.net *.inspectlet.com wss://ws.inspectlet.com https://bat.bing.com *.braintreegateway.com *.clarity.ms bam.nr-data.net *.facebook.com *.pinimg.com *.pinterest.com maps.googleapis.com cdn.ampproject.org *.google-analytics.com *.facebook.net https://a.omappapi.com https://api.omappapi.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cadencedev.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src *.fontawesome.com https://fonts.gstatic.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com https://plumrocket.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.google.com *.addthis.com *.pinterest.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com *.avada.io searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.fontawesome.com https://fonts.googleapis.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com api.addressy.com https://get.geojs.io *.avada.io api.amplitude.com stats.g.doubleclick.net *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://mackshop.com/pr-csp/report/add/; report-to report-endpoint; 1 default-src 'none'; base-uri 'self'; child-src 'self' platform.twitter.com syndication.twitter.com *.youtube.com; connect-src 'self' https://webpush.ii.nl/; font-src 'self'; form-action 'self' syndication.twitter.com; frame-ancestors 'self'; frame-src 'self' platform.twitter.com syndication.twitter.com *.youtube.com; img-src 'self' data: *.ii.nl blob: abs.twimg.com pbs.twimg.com ton.twimg.com platform.twitter.com syndication.twitter.com; manifest-src 'self'; media-src 'none'; object-src 'none'; report-uri /csp-report; script-src 'self' platform.twitter.com; style-src 'unsafe-inline' 'self' platform.twitter.com ton.twimg.com 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.googleapis.com *.fontawesome.com *.bootstrapcdn.com data: *.claspo.io *.googletagmanager.com *.razorpay.com *.cardinalcommerce.com *.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com blob: 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.addthis.com *.doubleclick.net *.flexiquiz.com/ *.hotjar.com *.claspo.io *.googletagmanager.com *.razorpay.com *.cardinalcommerce.com *.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com blob: 'self' https://www.google.com/ https://api.razorpay.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io https://images.unsplash.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.co.in *.google.com *.ccavenue.com *.doubleclick.net *.hotjar.com *.magentocommerce.com *.magecomp.com *.claspo.io *.googletagmanager.com *.razorpay.com *.cardinalcommerce.com *.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com blob: 'self' *.clarity.ms https://stats.g.doubleclick.net/ https://cdn.razorpay.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.cloudflare.com *.twitter.com *.google-analytics.com *.sandbox.paypal.com *.twimg.com *.gstatic.com *.fontawesome.com *.googletagmanager.com *.googleadservices.com *.razorpay.com *.cloudflareinsights.com *.cloudfront.net *.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com cdn.tailwindcss.com blob: 'self' *.clarity.ms *.paypalobjects.com https://plausible.io https://a.opmnstr.com https://rum-static.pingdom.net https://checkout.razorpay.com *.mgt.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.fontawesome.com *.google.com *.claspo.io *.googletagmanager.com *.razorpay.com *.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com cdn.tailwindcss.com cdnjs.cloudflare.com blob: 'self' assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com *.indiacakes.com *.cloudflare.com *.twitter.com *.twimg.com *.doubleclick.net *.hotjar.com *.claspo.io *.googletagmanager.com *.razorpay.com *.cardinalcommerce.com wss://vts.zohopublic.com *.gallabox.com *.zoho.com *.embedsocial.com *.zohocdn.com *.zohostatic.com wss://nexus-websocket-a.intercom.io blob: 'self' https://salesiq.zohopublic.com https://plausible.io *.clarity.ms https://api.razorpay.com https://lumberjack.razorpay.com https://lumberjack-metrics.razorpay.com https://get.geojs.io *.mgt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data: https://www.gravatar.com/avatar/ https://*.google-analytics.com https://*.googletagmanager.com blob:; script-src 'self' https://*.googletagmanager.com 'nonce-ef9d4839bb0ea1fe3bb7263602597036' https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com blob:; style-src 'self' 'nonce-ef9d4839bb0ea1fe3bb7263602597036' https://fonts.googleapis.com; worker-src 'self' blob:; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com data: blob:; frame-ancestors 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.iubenda.com https://player.flipsnack.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://scontent.cdninstagram.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.iubenda.com *.avada.io *.shopify.com *.fontawesome.com https://kite.wildix.com https://siliconsrl.matomo.cloud 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://kite.wildix.com https://cdn.iubenda.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://siliconsrl.matomo.cloud 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-IiVvqy78BG7-dDWvsXLIFg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com *.fontawesome.com 'self' data: *.moosend.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.bing.com *.zdassets.com *.google.com *.google.gr *.googletagmanager.com *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.newrelic.com *.nr-data.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.google.gr *.facebook.com *.zopim.com *.moosend.com *.cloudflare.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ widget-v3.boxnow.gr/ widget-v5.boxnow.cy *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn.dnky.co *.hotjar.com *.google.com/ *.trustpilot.com *.criteo.com *.zopim.com *.moosend.com *.cloudflare.com *.google.gr *.sandbox.paypal.com *.twitter.com *.googletagmanager.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.gr *.google.com *.google.nl *.google.co.in connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.skroutz.gr *.moosend.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.io *.doubleclick.net *.soundestlink.com *.mastercard.com https://trustmark.gr *.tiktok.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com https://www.magezon.com https://omnisnippet1.com https://wt.soundestlink.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paypal.com *.google.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytic.com *.trustpilot.com *.newrelic.com *.nr-data.net cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com *.youtube.com cdn.mouseflow.com *.skroutz.gr *.moosend.com *.adobedtm.com *.cloudflare.com *.google.gr *.vimeo.com 'self' data: *.tiktok.com *.doubleclick.net *.google-analytics.com *.google.com/ int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com *.avada.io https://omnisnippet1.com https://forms.soundestlink.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net *.skroutz.gr *.zopim.com *.moosend.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.googletagmanager.com www.googleadservices.com www.google-analytics.com vimeo.com *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.newrelic.com *.nr-data.net *.hotjar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.toms.gr *.google.gr *.zopim.com *.moosend.com *.cloudflare.com 'self' data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.gr *.paypal.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net https://stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.nr-data.net *.clarity.ms *.datatrics.com *.moosend.com *.cloudflare.com *.soundestlink.com *.omnisendlink.com *.googleadservices.com *.googleapis.com *.gstatic.com *.mastercard.com *.google.com *.googletagmanager.com *.tiktok.com https://googleads.g.doubleclick.net/ https://pagead2.googlesyndication.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-to default-src; report-uri default-src; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net www.searchanise.com *.searchserverapi.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com https://downloads.mailchimp.com https://livehc.alcdashley.net *.gorgias.chat *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://sandbox.payfast.co.za https://www.payfast.co.za/eng/process www.searchanise.com *.searchserverapi.com *.twitter.com https://downloads.mailchimp.com https://www.facebook.com/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors http://downloads.mailchimp.com https://devdocs.magento.com https://www.facebook.com/ *.gorgias.chat 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.bootstrapcdn.com https://downloads.mailchimp.com https://www.facebook.com/ https://googleads.g.doubleclick.net/ https://web.facebook.com/ *.gorgias.chat *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.bootstrapcdn.com https://www.facebook.com/ https://connect.facebook.net/ https://www.google.com https://www.google.co.in https://downloads.mailchimp.com https://livehc.alcdashley.net https://www.scanpan.co.za https://gallery.mailchimp.com/ https://www.google.co.za/ *.gorgias.chat *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.goaffpro.com https://static.goaffpro.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com https://chimpstatic.com https://connect.facebook.net https://downloads.mailchimp.com https://mc.us15.list-manage.com https://livehc.alcdashley.net https://www.facebook.com/ https://apis.google.com/ *.gorgias.chat https://www.googletagmanager.com tagmanager.google.com unpkg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.cloudflare.com *.googleapis.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://downloads.mailchimp.com *.bootstrapcdn.com https://livehc.alcdashley.net *.gorgias.chat tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gorgias.chat 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.goaffpro.com https://static.goaffpro.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com api.amplitude.com stats.g.doubleclick.net *.cloudflare.com *.google-analytics.com *.twitter.com *.twimg.com *.bootstrapcdn.com https://stats.g.doubleclick.net/ https://downloads.mailchimp.com https://livehc.alcdashley.net https://www.facebook.com/ *.gorgias.chat https://api.segment.io/ https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.oct8ne.com instantcredit.net test.instantcredit.net https://oct8necdneu.azureedge.net https://static-eu.oct8ne.com https://cl.avis-verifies.com https://media.flixfacts.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com https://consentcdn.cookiebot.com https://www.salesmanago.pl https://app3.salesmanago.pl https://www.salesmanago.com https://backoffice-eu.oct8ne.com https://cl.avis-verifies.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://www.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://firebasestorage.googleapis.com *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com https://www.google.es https://oct8necdneu.azureedge.net https://static-eu.oct8ne.com https://integrations.etrusted.com https://imgsct.cookiebot.com https://cl.avis-verifies.com https://media.flixcar.com https://media.flixfacts.com *.connectif.cloud *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net https://www.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.avada.io *.shopify.com *.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com https://cdn.doofinder.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js-agent.newrelic.com https://bam.nr-data.net http://media.flixfacts.com https://prod.flixgvid.flix360.io http://media.flixcar.com https://cdn.loadbee.com http://widgets.trustedshops.com https://sandbox.sequrapi.com https://live.sequrapi.com https://cl.avis-verifies.com *.connectif.cloud *.hotjar.com *.freshdesk.com *.cloudfront.net tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com instantcredit.net test.instantcredit.net https://integrations.etrusted.com https://cl.avis-verifies.com https://media.flixcar.com *.freshdesk.com *.cloudfront.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com instantcredit.net *.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com https://consentcdn.cookiebot.com https://www.youtube.com https://youtu.be https://js-agent.newrelic.com https://bam.nr-data.net https://availability.loadbee.com https://frontal-eu.oct8ne.com https://media.flixcar.com https://vc-service.saleago.com https://cl.avis-verifies.com *.connectif.cloud *.freshdesk.com *.hotjar.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cdnfonts.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.bing.com *.clarity.ms *.cookiebot.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.cloudflare.com *.cloudflareinsights.com *.ladesk.com *.clarity.ms *.sentry-cdn.com *.cookiebot.com elastic-cdn.magentobox.pl *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.cloudflare.com *.typekit.net *.cdnfonts.com *.ladesk.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.clarity.ms *.cookiebot.com *.google-analytics.com elastic-apm.magentobox.pl https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://*.msignia.com https://*.cardinalcommerce.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ esqa.moneris.com www3.moneris.com pay.google.com www.google.com https://*.msignia.com https://*.cardinalcommerce.com www.xtento.com *.cantook.net *.issuu.com *.facebook.com *.livechatinc.com google.com *.google.com *.doubleclick.net *.flipsnack.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.gstatic.com *.googleapis.com ws1.postescanada-canadapost.ca https://*.privacy-center.org t.ofsys.com 'self' data: www.xtento.com cdn.xtento.com www.google.com.ng www.google.com.cy www.google.co.id www.google.com.qa www.google.com.bh www.google.com.co www.google.com.tw www.google.com.om www.google.cv www.google.tn www.google.tt www.google.com.sg *.facebook.com www.google.nl www.google.co.in www.google.ge *.ggpht.com www.google.by www.google.lk www.google.com.lb www.google.at www.google.al www.google.ro www.google.no www.google.rs www.google.com.sv www.google.ie www.google.co.ke www.google.cd www.google.hr www.google.cm www.google.com.pa www.google.co.ve www.google.ae www.google.pl www.google.com.fj www.google.com.tr www.google.com.kw www.google.dk www.google.bt www.google.com.uy www.google.com.np www.google.pt www.google.se www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn www.google.ru www.google.jo www.google.ne www.google.co.cr www.google.it www.google.co.zm www.google.com.et www.google.ch www.google.ee www.google.com.py *.facebook.net www.google.hu www.google.ml www.google.co.ao *.google.com www.google.com.pr www.google.iq www.google.ca www.google.com.cu www.google.com.na www.google.gy www.google.sn www.google.md www.google.co.jp www.google.sr www.google.am www.google.de www.google.cl www.google.com.vc *.doubleclick.net www.google.com.ni www.google.es www.google.co.za www.google.td www.google.com.ag www.google.lt www.google.is www.google.sc www.google.com.bo www.google.co.nz www.google.com.bz www.google.lu www.google.bi www.google.co.uk www.google.as www.google.com.do www.google.co.zw www.google.com.eg www.google.com.gt www.google.co.ma www.google.la www.google.com.br www.google.cg www.google.com.jm www.google.com.bd *.googleadservices.com www.google.ht www.google.fi www.google.cf www.google.sk www.google.dm www.google.co.ls www.google.kz www.google.co.ug www.google.com.ph www.google.co.tz www.google.com.au www.google.ga www.google.si www.google.tg www.google.lv www.google.com.ec www.google.com.mt www.google.ba www.google.mk www.google.com.kh www.google.com.sa www.google.so www.google.bj www.google.cz www.google.bf www.google.co.th *.livechat-static.com www.google.co.kr www.google.dz www.google.ci www.google.mv www.google.com.vn www.google.com.hk www.google.co.bw *.files-text.com www.google.com.ua www.google.com.af www.google.com.ar www.google.com.gh www.google.az www.google.rw www.google.com.ly www.google.bg www.google.co.uz www.google.com.pk www.google.com.my www.google.gr www.google.fr data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net esqa.moneris.com www3.moneris.com applepay.cdn-apple.com pay.google.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ ws1.postescanada-canadapost.ca ajax.cloudflare.com https://*.privacy-center.org t.ofsys.com *.google.com www.xtento.com cdn.xtento.com *.livechatinc.com *.privacy-center.org *.licdn.com *.doubleclick.net *.issuu.com *.facebook.net *.googletagmanager.com *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com ws1.postescanada-canadapost.ca *.googleapis.com *.gstatic.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io pay.google.com https://google.com/pay *.googleapis.com ws1.postescanada-canadapost.ca www.google.com https://*.privacy-center.org t.ofsys.com t.elasticsuite.io www.google.si www.google.cz www.google.com.pr www.google.com.bd www.google.ee www.google.co.ao www.google.td www.google.lv www.google.com.gt www.google.tt www.google.com.gh www.google.com.ar www.google.co.zw www.google.ae www.google.gr www.google.com.py www.google.ro www.google.com.ni www.google.ci www.google.co.tz www.google.es www.google.com.lb www.google.com.jm www.google.at www.google.cv www.google.com.pk www.google.cm google.com www.google.ge www.google.sr www.google.bf www.google.se www.google.pl www.google.md www.google.so www.google.com.hk www.google.ie *.facebook.com www.google.com.vn www.google.de www.google.mu www.google.co.ve www.google.cf www.google.sn www.google.co.za www.google.co.kr www.google.kz www.google.fi www.google.com.sv www.google.cg www.google.cl www.google.com.pa www.google.be www.google.com.ec www.google.dz www.google.co.cr www.google.co.ke *.googlesyndication.com www.google.tn www.google.com.uy *.issuu.com *.doubleclick.net www.google.com.fj www.google.co.nz www.google.tg www.google.nl www.google.ch www.google.com.bz *.googleadservices.com www.google.az www.google.com.cu *.livechatinc.com www.google.bg www.google.hn www.google.bj www.google.pt www.google.rs www.google.hu www.google.com.mx www.google.com.ua www.google.com.kh www.google.co.il www.google.co.uk www.google.fr www.google.co.in www.google.gy www.google.cd www.google.mv www.google.iq www.google.co.jp www.google.com.br www.google.no www.google.com.om www.google.com.tw www.google.ne *.google.com www.google.com.pe www.google.lt www.google.com.kw www.google.dk www.google.com.tr www.google.hr www.google.co.ug www.google.com.au www.google.ru www.google.com.et www.google.co.zm www.google.ml www.google.sk www.google.by www.google.com.sa www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.it www.google.al www.google.mg www.google.bi www.google.is www.google.com.do www.google.co.th www.google.rw www.google.com.ng www.google.sc www.google.com.ph www.google.com.bo www.google.com.na www.google.co.ma www.google.com.cy *.facebook.net www.google.com.co www.google.com.mt www.google.com.my 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://77cedd63-a272-453b-875f-e0b7f4add1ad.sansec.watch/; report-to report-endpoint; 1 font-src https://fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.facebook.com *.googlesyndication.com *.tiktok.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com *.tbicp.com t.themarketer.com cdn1.themarketer.com https://redchamps.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com www.apptrian.com *.tbicp.com t.themarketer.com cdn1.themarketer.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.google.com maxcdn.bootstrapcdn.com t.themarketer.com cdn1.themarketer.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com t.themarketer.com cdn1.themarketer.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; connect-src 'self'; default-src 'none'; font-src 'self'; form-action 'self'; frame-ancestors 'none'; frame-src 'self'; img-src 'self' data: https:; media-src 'self'; object-src 'none'; script-src 'self'; style-src 'self'; upgrade-insecure-requests; report-uri https://richardlouv.com/?ACT=56 1 default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com 'unsafe-inline' data: *.fontawesome.com *.gstatic.com 'self' data: *.superpayments.com *.stripe.com *.cloudflare.com *.clarity.ms static.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.superpayments.com *.stripe.com *.facebook.com *.mdoq.io 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.superpayments.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.superpayments.com *.stripe.com widget.trustpilot.com lpcdn.lpsnmedia.net *.paypalobjects.com www.facebook.com *.clarity.ms 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com https://images.unsplash.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.superpayments.com *.stripe.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.cloudflare.com *.mdoq.io *.ibottles.co.uk *.google.com *.google.co.uk www.worldofpower.co.uk media.worldofpower.co.uk media.worldofbbqs.co.uk media.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk bat.bing.com *.clarity.ms c.bing.com media2.giphy.com www.facebook.com image.providesupport.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.superpayments.com *.stripe.com segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.liveperson.net *.lpsnmedia.net bat.bing.com world11215.pcapredict.com www.googlecommerce.com connect.facebook.net image.providesupport.com *.clarity.ms static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk https://cdn.superpayments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.superpayments.com *.stripe.com tagmanager.google.com fonts.google.com *.cloudflare.com *.bootstrapcdn.com *.clarity.ms static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.ideal-postcodes.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.superpayments.com *.stripe.com stripe.com cognito-idp.eu-west-2.amazonaws.com segment.com *.segment.com *.segmentapis.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws cdn.seondf.com *.seondnsresolve.com *.seondfresolver.com *.deviceinfresolver.com *.seonintelligence.com *.trustpilot.com *.analytics.google.com *.googletagmanager.com *.cloudflare.com stats.g.doubleclick.net *.clarity.ms www.facebook.com static.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk static-forms.klaviyo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://zero1.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://fast.wistia.net https://fast.wistia.com https://cdn.jsdelivr.net https://www.gstatic.com https://ajax.googleapis.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://static.addtoany.com https://js.hsforms.net https://js.hs-analytics.net https://js.hs-scripts.com https://js-na1.hs-scripts.com https://js.hs-banner.com https://js.hscollectedforms.net https://js.hubspot.com https://js.hsadspixel.net https://tracking.g2crowd.com https://ws.zoominfo.com https://connect.facebook.net https://bat.bing.com https://snap.licdn.com https://www.redditstatic.com https://analytics.tiktok.com https://js.adsrvr.org https://tags.clickagy.com https://b-code.liadm.com https://acsbapp.com https://s3-us-west-2.amazonaws.com https://widget.intercom.io https://js.intercomcdn.com https://d-code.liadm.com https://opps-widget.getwarmly.com https://browser.sentry-cdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net https://ajax.googleapis.com https://cdnjs.cloudflare.com; img-src 'self' data: https://www.google-analytics.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://www.google.com https://www.facebook.com https://connect.facebook.net https://*.ads.linkedin.com https://alb.reddit.com https://bat.bing.com https://*.hubspot.com https://*.hsforms.com https://*.wistia.com https://*.wistia.net https://aorta.clickagy.com https://cdn.jsdelivr.net https://busybusydev.wpenginepowered.com https://assets-global.website-files.com https://secure.gravatar.com https://idsync.rlcdn.com https://us-u.openx.net; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://busybusydev.wpenginepowered.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net https://www.google.com https://www.facebook.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://bat.bing.com https://px.ads.linkedin.com https://tracking-api.g2.com https://tracking.g2crowd.com https://api.nelioabtesting.com https://js.hs-banner.com https://forms.hscollectedforms.net https://perf-na1.hsforms.com https://*.hubspot.com https://api.hubapi.com https://fast.wistia.com https://embed.wistia.com https://*.wistia.com https://*.wistia.net https://cdn.acsbapp.com https://aorta.clickagy.com https://hemsync.clickagy.com https://a.usbrowserspeed.com https://alocdn.com https://idx.liadm.com https://rp.liadm.com https://rp4.liadm.com https://pro.ip-api.com https://insight.adsrvr.org https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://api-iam.intercom.io https://widget.intercom.io wss://nexus-websocket-a.intercom.io https://pixel-config.reddit.com https://9xgnrndqve.execute-api.us-west-2.amazonaws.com https://sessions.bugsnag.com https://opps-api.getwarmly.com wss://opps-api.getwarmly.com; frame-src 'self' https://www.googletagmanager.com https://static.addtoany.com https://fast.wistia.net https://embed.wistia.com https://forms.hsforms.com https://js.hsforms.net https://insight.adsrvr.org https://match.adsrvr.org; media-src 'self' https://*.wistia.com https://*.wistia.net; form-action 'self' https:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.intercomcdn.com/ https://be.gamemania.com/ *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.bunny.net fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.facebook.com platform.twitter.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io https://www.youtube.com https://www.youtube-nocookie.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://flagcdn.com/ https://be.gamemania.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://firebasestorage.googleapis.com *.facebook.com https://i.ytimg.com quickchart.io img.youtube.com flagpedia.net https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://cdn.tailwindcss.com/ https://js.intercomcdn.com/ https://widget.intercom.io/ https://be.gamemania.com/ connect.facebook.net twitter.com platform.twitter.com static.addtoany.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.avada.io *.shopify.com *.googletagmanager.com *.facebook.net www.termsfeed.com https://www.youtube.com https://s.ytimg.com *.gstatic.com maps.googleapis.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://be.gamemania.com/ *.fontawesome.com maxcdn.bootstrapcdn.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://fonts.bunny.net fonts.gstatic.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://www.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://nexus-websocket-b.intercom.io/ https://api-iam.intercom.io/ https://api.apicheck.nl https://be.gamemania.com/ wss://nexus-websocket-a.intercom.io stats.addtoany.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv27.amvn3-19b2a2e362a-0x1704#pd 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.ampproject.org www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.at https://www.myheritage.de 'unsafe-eval' 'nonce-670453a2432805bbdbc07328c4d31118' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.at;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-HccU6eX2C7g5DkMyFfgMnw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.ap-gateway.mastercard.com *.mastercard.com www.googletagmanager.com googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com 'self' data: blob: 'unsafe-inline' data: *.ap-gateway.mastercard.com *.mastercard.com *.clarity.ms c.bing.com www.google.co.in data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.ap-gateway.mastercard.com ap-gateway.mastercard.com *.mastercard.com *.clarity.ms www.clarity.ms c.bing.com *.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.clarity.ms www.clarity.ms c.bing.com *.cloudflareinsights.com www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src *.force.com slack-imgs-mil-dev.com 'self' *.slack.com https://www.paypal.com https://img.youtube.com https://childcareportals.my.site.com https://payments.salesforce.com/icons/ https://usa9014.sfdc-pu91w7.salesforce.com/icons/ https://login.salesforce.com/icons/ *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://www.gstatic.com *.slack-edge-gov.com *.my-salesforce.com slack-imgs-gov-dev.com *.slack-edge.com *.cloudinary.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://www.google.com slack-mil-dev.com https://www.gstatic.com/recaptcha/ *.amazonaws.com blob: https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://mdccs.my.salesforce.com https://i.vimeocdn.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.salesforce.com *.twimg.com https://mdccs.file.force.com https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://mdccs.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D8z0000008aLS&networkId=0DM8z00000000TE&type=communities 1 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' https://developers.google.com https://www.googletagmanager.com https://maps.googleapis.com https://consent.cookiebot.com https://d2qh0sy46xxq25.cloudfront.net https://sgtm.euro-sportring.com https://googleads.g.doubleclick.net https://bat.bing.com https://connect.facebook.net https://static.hotjar.com https://www.clarity.ms https://consentcdn.cookiebot.com https://scripts.clarity.ms https://script.hotjar.com https://www.facebook.com https://www.recaptcha.net https://www.gstatic.com https://oo8yvqo6jl.execute-api.eu-central-1.amazonaws.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://developers.google.com https://www.googletagmanager.com https://maps.googleapis.com https://consent.cookiebot.com https://d2qh0sy46xxq25.cloudfront.net https://sgtm.euro-sportring.com https://googleads.g.doubleclick.net https://bat.bing.com https://connect.facebook.net https://static.hotjar.com https://www.clarity.ms https://consentcdn.cookiebot.com https://scripts.clarity.ms https://script.hotjar.com https://www.facebook.com https://www.recaptcha.net https://www.gstatic.com https://oo8yvqo6jl.execute-api.eu-central-1.amazonaws.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com; style-src 'self' 'report-sample' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://unpkg.com mdbootstrap.com use.fontawesome.com; webrtc 'allow'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://plumrocket.com *.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src https://hummingbirdbakery.com *.adobe.com 'self' 'unsafe-inline'; font-src *.klaviyo.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.hummingbirdbakery.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; style-src *.typekit.net *.klaviyo.com *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.gstatic.com *.googleapis.com *.fontawesome.com https://cdn.jsdelivr.net https://fonts.bunny.net assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; connect-src *.zendesk.com wss://widget-mediator.zopim.com *.instagram.com https://mgibtoec.eul.stape.io *.cookiebot.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com https://api.smooch.io wss://api.smooch.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com ekr.zdassets.com/ *.ideal-postcodes.co.uk https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src *.cdninstagram.com *.hummingbirdbakery.com https://hummingbirdbakery.com *.cookiebot.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.googleapis.com maps.gstatic.com https://www.facebook.com https://hummingbirdbakery.zendesk.com https://www.googleadservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.zdassets.com https://mgibtoec.eul.stape.io *.cookiebot.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://static.hotjar.com https://script.hotjar.com connect.facebook.net https://api.smooch.io https://www.googleadservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io www.facebook.com graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 frame-ancestors 'none'; font-src 'self' www.mozilla.org; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io js.stripe.com s.ytimg.com tagmanager.google.com transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org www.youtube.com; base-uri 'none'; connect-src 'self' cdn.transcend.io https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org/submit/bedrock/; img-src 'self' blog.mozilla.org data: images.ctfassets.net www.google-analytics.com www.googletagmanager.com www.mozilla.org; object-src 'none'; style-src 'self' cdn.transcend.io transcend-cdn.com www.mozilla.org; upgrade-insecure-requests; frame-src 'self' accounts.firefox.com js.stripe.com www.google-analytics.com www.googletagmanager.com www.youtube.com; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.mozilla.org; default-src 'self' *.mozilla.org 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cleverreach.com 'self' 'unsafe-inline'; frame-ancestors https://datastudio.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com https://www.youtube-nocookie.com/ https://datastudio.google.com/ https://rest.cleverreach.com/ https://3dswissmedia.com/ https://old.3dswissmedia.com/ https://cdn7.3dswissmedia.com/ https://td.doubleclick.net/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudfront.net https://images.unsplash.com blob: https://img.youtube.com/ https://maps.googleapis.com/maps/ https://maps.gstatic.com/mapfiles/ https://www.google-analytics.com/ https://pagead2.googlesyndication.com/ https://www.google.ch/ads/ https://www.google.li/ads/ https://www.google.be/ads/ https://www.google.sk/ads/ https://www.facebook.com/ https://widgets.trustedshops.com/ https://chart.googleapis.com/ https://bat.bing.com/ https://*.usercentrics.eu/ https://googleads.g.doubleclick.net/ https://www.hajk.ch/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google.com/ www.googletagmanager.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.googleapis.com *.gstatic.com jquery.sellxed.com https://www.youtube.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://ssl.google-analytics.com/ https://matomo.cs2.ch/ https://matomo.jajuma.de/ https://instant.page/ https://connect.facebook.net/ https://widgets.trustedshops.com/ https://bat.bing.com/ https://bat.bing-int.com/ https://script.crazyegg.com/ https://*.usercentrics.eu/ https://www.googletagmanager.com/ https://googleads.g.doubleclick.net/ https://analytics.tiktok.com/ https://*.elfsight.com/ https://universe-static.elfsightcdn.com/ http://www.googletagmanager.com/ *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com/ https://www.google-analytics.com/ https://region1.analytics.google.com/ https://pagead2.googlesyndication.com/ https://www.google.com/ https://google.com/ https://googleads.g.doubleclick.net/ https://stats.g.doubleclick.net/ https://matomo.cs2.ch/ https://matomo.jajuma.de/ https://www.facebook.com/ https://api.trustedshops.com/ https://shops-si.trustedshops.com/ https://trustbadge.api.etrusted.com/ https://logging.trustbadge.com/ https://api.trustbadge.etrusted.com/ https://script.crazyegg.com/ https://bat.bing.com/ https://bat.bing-int.com/ https://*.usercentrics.eu/ https://analytics.tiktok.com/ https://www.googletagmanager.com/ https://*.elfsight.com/ https://universe-static.elfsightcdn.com/ http://stats.g.doubleclick.net/ http://www.google-analytics.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.hajk.ch/csp.php; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.google.com *.google.com.br *.googleapis.com *.doubleclick.net *.googletagmanager.com *.googleadservices.com *.facebook.net *.facebook.com *.youtube.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br data: *.akamaized.net https://vimeo.com *.vimeocdn.com amcglobal.sc.omtrdc.net *.tiktok.com *.pinterest.com *.pinimg.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.doubleclick.net *.googletagmanager.com *.youtube.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.tiktok.com *.pinterest.com *.pinimg.com https://accounts.google.com https://www.facebook.com https://login.live.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://h.online-metrix.net *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.google.com.br *.doubleclick.net *.gstatic.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.facebook.com *.ytimg.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br data: *.akamaized.net https://vimeo.com *.vimeocdn.com *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.googleadservices.com *.google-analytics.com *.google.com *.google.com.br *.googleapis.com *.doubleclick.net *.googletagmanager.com *.facebook.net *.facebook.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.akamaized.net https://vimeo.com *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com www.google.com.ua www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://unpkg.com *.disqus.com *.avada.io *.cristaisaquarius.com.br *.magento.local https://cristaisaquarius.com.br https://cristais.magento.local *.google.com.br *.google-analytics.com *.gstatic.com *.googleapis.com *.doubleclick.net *.googletagmanager.com *.googleadservices.com *.facebook.net *.facebook.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.akamaized.net *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com *.pagseguro.com.br *.pagseguro.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com server.cristaisaquarius.com.br https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.googleapis.com *.doubleclick.net *.google.com *.google.com.br *.gstatic.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com https://connect.facebook.net *.facebook.com *.youtube.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.akamaized.net https://vimeo.com *.vimeocdn.com amcglobal.sc.omtrdc.net *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.google.com.br *.googleapis.com *.doubleclick.net *.gstatic.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.facebook.com *.youtube.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.mercadopago.com *.mercadolibre.com *.akamaized.net *.vimeocdn.com *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com *.pagseguro.com.br *.pagseguro.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com server.cristaisaquarius.com.br https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.cristaisaquarius.com.br *.cristaisaquarius.local https://cristaisaquarius.com.br https://cristais.magento.local *.google.com *.google.com.br *.google-analytics.com *.gstatic.com *.doubleclick.net *.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.facebook.com *.youtube.com *.ytimg.com *.youtube-nocookie.com *.googlevideo.com *.criteo.com *.criteo.net https://d335luupugsy2.cloudfront.net *.rdstation.com.br *.akamaized.net https://vimeo.com *.vimeocdn.com *.adobetm.com *.tiktok.com *.pinterest.com *.pinimg.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.googleapis.com *.cdn.leadmanagerfx.com 'self' data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.cdninstagram.com *.googleapis.com 'self' blob: ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.instagram.com *.gstatic.com *.googleapis.com *.googletagmanager.com google.com/recaptcha cdn.leadmanagerfx.com chimpstatic.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net *.marketingcloudfx.com *.leadmanagerfx.com *.pinterest.com *.pinimg.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.gstatic.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.gstatic.com *.googleapis.com bam.nr-data.net bam-cell.nr-data.net *.marketingcloudfx.com *.leadmanagerfx.com *.pinterest.com *.pinimg.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.mayflowerdistributing.com/; report-to report-endpoint; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; script-src 'nonce-404f8a8b3aa34f6cafea6008255ed2ce' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; style-src 'self' 'nonce-404f8a8b3aa34f6cafea6008255ed2ce' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=134-9399579-8441616:rid=74078F0692634D90BDDA:sn=www.amazongamestudios.com 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.xtento.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://scontent.cdninstagram.com www.xtento.com cdn.xtento.com *.tiktok.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.xtento.com cdn.xtento.com *.tiktok.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://graph.instagram.com *.tiktok.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.addressy.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://5nk3ky.pixum.at https://wl9nnvm0c8.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://5nk3ky.pixum.at https://wl9nnvm0c8.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 img-src https://higherlogicdownload.s3.amazonaws.com/ILTANET/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ILTANET/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/ILTANET/ blob: https://d132x6oi8ychic.cloudfront.net 'self' https://aws.predictiveresponse.net https://aws.predictiveresponse.net https://px.ads.linkedin.com https://aws.predictiveresponse.net https://px.ads.linkedin.com https://cdn.userway.org https://aws.predictiveresponse.net https://px.ads.linkedin.com https://cdn.userway.org https://d3uf7shreuzboy.cloudfront.net/ https://cdnjs.cloudflare.com https://px4.ads.linkedin.com; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ILTANET/ https://higherlogicdownload.s3.amazonaws.com/ILTANET/ https://higherlogiclongterm.s3.amazonaws.com/ILTANET/ 'self' https://cdnjs.cloudflare.com; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/ILTANET/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ILTANET/ 'self' https://higherlogiclongterm.s3.amazonaws.com/ILTANET/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data: https://ka-f.fontawesome.com/ https://ka-f.fontawesome.com/ https://ilta.legaltechnologyhub.com/ https://cdn.userway.org/; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline' https://ilta.legaltechnologyhub.com/ https://cdn.userway.org/ d214eakhb4e2xn.cloudfront.net https://d214eakhb4e2xn.cloudfront.net; media-src https://higherlogiclongterm.s3.amazonaws.com/ILTANET/ https://higherlogicdownload.s3.amazonaws.com/ILTANET/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ILTANET/ https://higherlogicstream.s3.amazonaws.com/ILTANET/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/ILTANET/ https://higherlogicdownload.s3.amazonaws.com/ILTANET/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ILTANET/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://ilta.legaltechnologyhub.com/ https://cdn.userway.org/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob: https://px.ads.linkedin.com/ https://aws.predictiveresponse.net/ https://ilta.legaltechnologyhub.com/ https://api.userway.org/; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; style-src-elem https://d2x5ku95bkycr3.cloudfront.net/ https://maxcdn.bootstrapcdn.com/ https://cdn.userway.org/ https://d2x5ku95bkycr3.cloudfront.net/ https://maxcdn.bootstrapcdn.com/ https://cdn.userway.org/ sha256-Rab7AJLFualVC4CUBBV53un9yiys/tCLSbaVZsjd1vs= https://d2x5ku95bkycr3.cloudfront.net/ https://maxcdn.bootstrapcdn.com/ https://cdn.userway.org/ sha256-Rab7AJLFualVC4CUBBV53un9yiys/tCLSbaVZsjd1vs= sha256-2gCt3a4f6dxlUfEwTCIts7vls6yRLGu6Dc6LrwMwYhE=; 1 default-src 'self' 'unsafe-inline' https: *.google.com *.gstatic.com *.youtube-nocookie.com *.livechatinc.com; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com eadn-wc04-11639733.nxedge.io *.tawk.to *.bootstrapcdn.com *.fonts.googleapis.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.addthis.com *.pinterest.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com eadn-wc04-11639733.nxedge.io www.facebook.com *.tawk.to tawk.link *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com *.googleusercontent.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com eadn-wc04-11639733.nxedge.io *.facebook.com *.tawk.to *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.instagram.com *.optimonk.com *.elfsight.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com eadn-wc04-11639733.nxedge.io *.tawk.to *.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com eadn-wc04-11639733.nxedge.io *.tawk.to *.elfsight.com *.service-reviews-ultimate.elfsight.com *.optimonk.com *.cloudflare.com *.addthis.com *.graph.instagram.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.facebook.com *.reddit.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.disqus.com https://cdn.jsdelivr.net *.googletagmanager.com maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com tagmanager.google.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.doubleclick.net *.google-analytics.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.typekit.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.disqus.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googletagmanager.com app.promotron.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.typekit.net *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com ws: *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; font-src 'self' assets.cardly.net cdn1.cardly.net fonts.gstatic.com v2.zopim.com; form-action 'self' www.facebook.com; frame-ancestors 'none'; frame-src www.facebook.com www.googletagmanager.com *.js.stripe.com js.stripe.com hooks.stripe.com www.youtube.com zapier.com; img-src 'self' data: https: cdn1.cardly.net assets.cardly.net i.ytimg.com www.facebook.com px.ads.linkedin.com v2.zopim.com www.google.com googleads.g.doubleclick.net *.google-analytics.com googletagmanager.com *.googletagmanager.com pagead2.googlesyndication.com ssl.gstatic.com www.googleadservices.com www.gstatic.com google.com; object-src 'none'; report-uri https://report.centralcsp.com/68fd9dbd3bf8b7a78b68636b; report-to csp-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-9rVotlilZ6pp6Dzt3SBG5g4PKig=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' *.geerly.com o1169527.ingest.sentry.io flwic8ipog-dsn.algolia.net *.algolianet.com formspree.io quantcast.mgr.consensu.org *.quantserve.com *.hotjar.com *.facebook.com *.google-analytics.com; connect-src 'self' geerly.com geerly.graphcdn.app *.geerly.com vercel.live *.google.com *.doubleclick.net *.google-analytics.com *.algolianet.com *.algolia.net *.sentry.io *.hotjar.com wss://*.hotjar.com *.hotjar.io *.quantcast.mgr.consensu.org; script-src-elem 'self' vercel.live quantcast.mgr.consensu.org rules.quantcount.com *.hotjar.com *.googletagmanager.com *.google-analytics.com connect.facebook.net *.quantserve.com; font-src 'self' fonts.gstatic.com script.hotjar.com vercel.live; img-src 'self' i.ytimg.com *.cloudfront.net cdn.geerly.com res.cloudinary.com w3.org data: *.google.co.uk *.google-analytics.com *.facebook.com *.quantcast.com pixel.quantserve.com; script-src 'self'; style-src 'self' 'unsafe-inline'; 1 default-src 'self' www.google-analytics.com cdnjs.cloudflare.com 'unsafe-inline' bam.nr-data.net; script-src 'self' bam.nr-data.net www.googletagmanager.com 'unsafe-inline' ajax.googleapis.com www.google-analytics.com cdn.jsdelivr.net js-agent.newrelic.com static.addtoany.com unpkg.com cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' www.google-analytics.com fonts.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com use.fontawesome.com www.google-analytics.com img.youtube netdna.bootstrapcdn.com; img-src 'self' data: https: img.youtube.com google-analytics.com; frame-src 'self' static.addtoany.com www.youtube.com; font-src 'self' use.fontawesome.com cdnjs.cloudflare.com cdn.jsdelivr.net fonts.gstatic.com netdna.bootstrapcdn.com; report-uri /report-csp-violation 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://connect.facebook.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.chatbase.co https://cdn.bitrix24.es https://isteeducacion.bitrix24.es https://maps.googleapis.com https://maps.gstatic.com https://online.iste.edu.ec https://www.youtube.com https://mozilla.github.io; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://isteeducacion.bitrix24.es https://online.iste.edu.ec; img-src 'self' data: https://api.myskillcamp.com https://static.myskillcamp.com https://mscprod.blob.core.windows.net https://cdn.bitrix24.es https://isteeducacion.bitrix24.es https://maps.googleapis.com https://maps.gstatic.com https://www.google.com https://www.google.com.ec https://www.google.com.sg https://www.google.nl https://www.facebook.com https://www.googletagmanager.com https://connect.facebook.net https://s.w.org https://secure.gravatar.com; font-src 'self' data: https://fonts.gstatic.com https://static.myskillcamp.com https://online.iste.edu.ec; connect-src 'self' https://api.myskillcamp.com https://maps.googleapis.com https://www.google.com https://www.google.com.ec https://www.google.com.sg https://www.googletagmanager.com https://analytics.google.com https://region1.analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://n8n.etech-solutions-llc.com https://o479680.ingest.sentry.io https://isteeducacion.bitrix24.es; frame-src 'self' https://maps.google.com https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://online.iste.edu.ec; report-to csp; report-uri https://iste.edu.ec/csp-report.php; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com bid.g.doubleclick.net js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com www.hyva.io magefan.com cm.magefan.com https://www.magezon.com https://www.mollie.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com js.mollie.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://77656ea2-9f80-4a74-ba7d-9d4c3bc7b1bd.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; connect-src 'self'; font-src 'self' data:; form-action 'self' https://*.infotip-rts.com https://*.infotip-rts-dev.com https://*.infotip-rts-local.com https://*.infotip-rts.de https://infotip-dev-login.auth.eu-central-1.amazoncognito.com/oauth2/authorize; frame-ancestors 'self'; frame-src 'self'; img-src 'self' images.philips.com data: blob:; media-src 'self'; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; report-to csp_endpoint;aux-data 'eyJVcmxQcmciOiJodHRwOlwvXC9pbmZvdGlwLXJ0cy5jb21cLyIsIlVybFBhZ2UiOiJIb21lLnhodG1sIiwiTG9naW5OYW1lIjoiOlJUUy1Qb3J0YWwiLCJVc2VyUm9sZSI6IjkwIiwiaW5BY3Rpb24iOiJIT01FIiwiaW5Qb3J0YWxJZCI6IjpSVFMtUG9ydGFsIiwiaW5PcmRlcklkIjoiIiwiU3lzdGVtIjoiTGl2ZSJ9' 1 font-src cash-f.squarecdn.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com data: *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com * *.hotjar.com *.google.com *.doubleclick.net https://www.googletagmanager.com/ cdn.dnky.co *.facebook.com *.trustpilot.com *.criteo.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://maps.gstatic.com *.google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.googleadservices.com *.g.doubleclick.net *.doubleclick.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.gstatic.com *.linkedin.com amcglobal.sc.omtrdc.net cm.everesttech.net *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com chimpstatic.com *.hotjar.com *.gstatic.com *.google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net downloads.mailchimp.com *.list-manage.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com *.googleapis.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com checkout.buckaroo.nl *.zopim.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com cdn.prooffactor.com cdn.one.store https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app *.cookiehub.net *.googletagmanager.com fonts.googleapis.com fonts.gstatic.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.zopim.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.hotjar.com *.google.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.googleadservices.com *.doubleclick.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.paypal.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.io *.zopim.com wss://*.zopim.com dpm.demdex.net *.feedbackcompany.com amcglobal.sc.omtrdc.net *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com *.one.store 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.perfumist.net *.perfumist.fr *.ccm19.de *.barrierefreie-web.de parfuemerie.b-cdn.net https://widgets.trustedshops.com *.klarnacdn.net *.fontawesome.com *.alothemes.com *.magepow.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.cookiebot.com www.xtento.com https://www.googletagmanager.com/ *.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.perfumist.net *.perfumist.fr https://consenttool.haendlerbund.de *.haendlerbund.de *.cookiebot.com *.ccm19.de *.vgz.fr *.barrierefreie-web.de flagcdn.com *.casalemedia.com *.bidswitch.net ad11.adfarm1.adition.com imagesrv.adition.com *.google.de ad.adnet.de parfuemerie.b-cdn.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.plugins.emarsys.net *.scarabresearch.com *.perfumist.net *.perfumist.fr https://consenttool.haendlerbund.de *.facebook.net *.cookiebot.com *.ccm19.de *.barrierefreie-web.de *.adcell.com pix.hyj.mobi tm.ad-srv.ne *.ad-srv.net ad4m.at *.bounce-commerce.de img.adnet.de *.pinterest.com sibautomation.com *.pinimg.com parfuemerie.b-cdn.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.sovendus.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://maps.googleapis.com/ *.alothemes.com *.magepow.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.perfumist.net *.perfumist.fr https://consenttool.haendlerbund.de *.cookiebot.com *.ccm19.de *.barrierefreie-web.de parfuemerie.b-cdn.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.klarnacdn.net *.fontawesome.com *.alothemes.com *.magepow.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.scarabresearch.com *.eservice.emarsys.net *.perfumist.net *.perfumist.fr https://consenttool.haendlerbund.de *.cookiebot.com *.googleapis.com *.doubleclick.net *.ccm19.de *.barrierefreie-web.de *.adcell.com *.ad4m.at *.bounce-commerce.de *.pinterest.com *.brevo.com parfuemerie.b-cdn.net *.trustedshops.com *.etrusted.com https://integrations.etrusted.site http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.sovendus.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://maps.googleapis.com/ *.alothemes.com *.magepow.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.getbutton.io *.baidu.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com *.paypal.com fonts.googleapis.com fonts.gstatic.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.getbutton.io *.baidu.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.getbutton.io *.baidu.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com *.twitter.com *.google.com maps.googleapis.com lightwidget.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.getbutton.io *.google.com *.baidu.com *.fontawesome.com *.bootstrapcdn.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com maps.googleapis.com maps.gstatic.com https://maps.gstatic.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com maps.googleapis.com *.getbutton.io *.baidu.com *.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com maps.gstatic.com fonts.googleapis.com *.avada.io https://maps.googleapis.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.facebook.net cdn.lightwidget.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.getbutton.io *.baidu.com *.google.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com *.paypal.com fonts.googleapis.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com maps.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.getbutton.io *.baidu.com *.google.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.ionicframework.com *.google-analytics.com *.doubleclick.net ipinfo.io *.islash.io *.facebook.com *.google.com.hk *.googletagmanager.com *.paypalobjects.com https://get.geojs.io *.avada.io https://maps.googleapis.com *.twitter.com *.twimg.com *.youtube.com maps.googleapis.com facebook.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com *.google.com.ua *.google.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.google.com *.google.com.ua *.google.co.uk *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.instagram.com stats.g.doubleclick.net apple.com *.apple.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com stats.g.doubleclick.net apple.com *.apple.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com www.googletagmanager.com consentcdn.cookiebot.com td.doubleclick.net www.google.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://static.buckaroo.nl imgsct.cookiebot.com *.google.nl *.googleapis.com px.ads.linkedin.com api.taggrs.io analytics.portofoonweb.nl www.google.com.ua cart2quote.zendesk.com region1.google-analytics.com assets.myparcel.nl *.openstreetmap.fr *.openstreetmap.org bat.bing.com www.google.nl www.gstatic.com region1.analytics.google.com www.google.com.ly https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://images.unsplash.com *.disqus.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl consent.cookiebot.com snap.licdn.com *.hotjar.com *.bing.com static.klaviyo.com static-tracking.klaviyo.com translate.googleapis.com translate-pa.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com www.gstatic.com bat.bing.com www.google.com dpm.demdex.net consentcdn.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.jsdelivr.net www.gstatic.com https://static.klaviyo.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net https://cdn.jsdelivr.net *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.facebook.net *.google.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.hotjar.com *.doubleclick.net px.ads.linkedin.com *.klaviyo.com analytics.portofoonweb.nl api.taggrs.io imgsct.cookiebot.com www.google.com.ua translate.googleapis.com translate-pa.googleapis.com region1.google-analytics.com api.myparcel.nl cdn.jsdelivr.net consent.cookiebot.com consentcdn.cookiebot.com a.klaviyo.com bat.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.dotdigital-pages.com *.dotdigital.com https://www.facebook.com https://tpc.googlesyndication.com https://consentcdn.cookiebot.com https://assets.braintreegateway.com https://*.paypal.com https://interfaces.zapier.com https://*.zapier.app https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.trackedlink.net *.ddlnk.net https://www.google.fi https://maps.gstatic.com https://maps.googleapis.com https://log.pinterest.com https://eckerolinechatbottest.blob.core.windows.net https://fonts.gstatic.com https://assets.braintreegateway.com https://*.paypal.com https://imgsct.cookiebot.com https://px.ads.linkedin.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://ajax.cloudflare.com https://js-agent.newrelic.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://assets.pinterest.com https://maps.googleapis.com https://eckerolinechatbottest.blob.core.windows.net https://api.videoly.co https://www.google.fi https://www.googleadservices.com https://tpc.googlesyndication.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js.braintreegateway.com https://assets.braintreegateway.com https://www.paypalobjects.com https://*.paypal.com https://snap.licdn.com https://interfaces.zapier.com https://dapi.videoly.co https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.eckeroline.ee 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://fast.fonts.net https://eckerolinechatbottest.blob.core.windows.net https://use.typekit.net https://p.typekit.net https://assets.braintreegateway.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://maps.googleapis.com https://fonts.gstatic.com https://vimeo.com https://consentcdn.cookiebot.com https://api.sandbox.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://api.braintreegateway.com https://client-analytics.braintreegateway.com https://*.paypal.com https://px.ads.linkedin.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src https://assets.braintreegateway.com https://*.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.houseofwine.gr *.fontawesome.com https://fonts.bunny.net *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.vivapayments.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.contactpigeon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.skroutz.gr *.tawk.to *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.houseofwine.gr *.google.gr *.googleadservices.com *.g.doubleclick.net *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.contactpigeon.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.skroutz.gr *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.vivapayments.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.houseofwine.gr https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.contactpigeon.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.skroutz.gr *.tawk.to cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.findbar.io *.houseofwine.gr https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.findbar.io *.houseofwine.gr *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.houseofwine.gr https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.contactpigeon.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.tawk.to wss://*.tawk.to https://www.google-analytics.com 'self' 'unsafe-inline'; child-src *.contactpigeon.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com staticw2.yotpo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ js.mollie.com www.youtube.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://www.magezon.com ifs-ccm.de fonts.gstatic.com www.gstatic.com p.yotpo.com cfvod.kaltura.com bat.bing.com www.google.de magefan.com cm.magefan.com https://www.mollie.com *.adobedtm.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de ifs-ccm.de cdn-widgetsrepository.yotpo.com translate.google.com translate.googleapis.com translate-pa.googleapis.com d18eg7dreypte5.cloudfront.net staticw2.yotpo.com static-na.payments-amazon.com connect.facebook.net bat.bing.com cdnapisec.kaltura.com *.google.com/ js.mollie.com www.youtube.com player.vimeo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com ifs-ccm.de www.gstatic.com cdn-widgetsrepository.yotpo.com cdn-widget-assets.yotpo.com staticw2.yotpo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de ifs-ccm.de api-cdn.yotpo.com staticw2.yotpo.com bat.bing.com cdn.plyr.io noembed.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src ifs-ccm.de translate.googleapis.com bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com www.google-analytics.com *.googlesyndication.com *.g.doubleclick.net www.youtube.com *.clarity.ms *.moengage.com connect.facebook.net analytics.tiktok.com ct.pinterest.com s.pinimg.com tracker.metricool.com *.goadopt.io *.growthbook.io *.varify.io; style-src 'self' 'unsafe-inline' fonts.googleapis.com www.googletagmanager.com cdn.moengage.com app-cdn.moengage.com *.moengage.com www.gstatic.com *.growthbook.io *.varify.io; img-src 'self' data: blob: https: secure.gravatar.com; font-src 'self' data: use.typekit.net fonts.gstatic.com fonts.bunny.net fonts.googleapis.com *.moengage.com *.growthbook.io *.varify.io; connect-src 'self' *.google.com *.google.com.br *.google-analytics.com *.googleadservices.com *.g.doubleclick.net *.googlesyndication.com googleads.g.doubleclick.net demo-1.conversionsapigateway.com www.googletagmanager.com www.facebook.com https://www.facebook.com/privacy_sandbox/topics/registration/ www.facebook.com/privacy_sandbox/topics/registration/ *.facebook.com ct.pinterest.com analytics.tiktok.com *.moengage.com *.clarity.ms *.goadopt.io analytics-ipv6.tiktokw.us mpc-prod-16-s6uit34pua-uk.a.run.app viacep.com.br *.growthbook.io *.varify.io; media-src *.moengage.com *.varify.io; frame-src 'self' www.googletagmanager.com www.facebook.com td.doubleclick.net youtube.com www.youtube.com m.youtube.com *.youtube.com youtube-nocookie.com www.youtube-nocookie.com *.moengage.com ct.pinterest.com trk.bdmkweb.com slides.com *.slides.com *.growthbook.io *.varify.io; report-to csp-endpoint; report-uri https://o4508988206219264.ingest.us.sentry.io/api/4509368646696960/security/?sentry_key=a427738ce4078a2e8f17c5570095c27c&sentry_environment=production 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://appleid.cdn-apple.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://appleid.apple.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://pms.dwatson.pk https://cdn.jsdelivr.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com cdn.jsdelivr.net https://accounts.google.com https://play.google.com https://code.jquery.com https://cdnjs.cloudflare.com https://appleid.cdn-apple.com https://appleid.apple.com https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com *.alothemes.com *.magepow.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net https://accounts.google.com https://appleid.cdn-apple.com https://cdn.jsdelivr.net https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://appleid.apple.com https://appleid.cdn-apple.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com https://tracking.retailrocket.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io https://tracking.retailrocket.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.hotjar.com *.zopim.com *.fontawesome.com *.cloudflare.com maxcdn.bootstrapcdn.com 'self' data: www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.google.com cdn.dnky.co *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com *.weltpixel.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com *.addthis.com *.googleapis.com *.cookieyes.com *.addtoany.com *.resengo.com *.storescan.eu *.doubleclick.net *.joyfotografie.nl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.linkedin.com *.googletagmanager.com gallery.mailchimp.com amcglobal.sc.omtrdc.net cm.everesttech.net *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' data: *.onesignal.com onesignal.com *.hsforms.net *.hsforms.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com *.cdninstagram.com *.cookieyes.com cdn-cookieyes.com *.google-analytics.com *.google.de data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.paypal.com *.google.com *.googletagmanager.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com onesignal.com https://www.googletagmanager.com tagmanager.google.com unpkg.com s7.addthis.com *.avada.io *.hsforms.net *.hsforms.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com *.marker.io *.addthis.com *.cookieyes.com cdn-cookieyes.com *.addtoany.com *.resengo.com *.cloudflare.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net https://static.klaviyo.com *.cloudflare.com *.onesignal.com onesignal.com tagmanager.google.com maxcdn.bootstrapcdn.com *.gstatic.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com *.klaviyo.com *.cookieyes.com 'self' 'unsafe-inline'; object-src www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; media-src *.zopim.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; manifest-src www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.paypal.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com dpm.demdex.net *.feedbackcompany.com amcglobal.sc.omtrdc.net *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com onesignal.com *.facebook.net ekr.zdassets.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com *.addthis.com ws.hotjar.com *.marker.io *.google.com *.stape.org *.instagram.com *.cookieyes.com cdn-cookieyes.com *.google.nl *.googlesyndication.com *.klaviyo.com 'self' 'unsafe-inline'; child-src www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.gartencenterleurs.de www.leurs.nl www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.mattca.ro *.tawk.to embed.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com/ connect.facebook.net graph.facebook.com business.facebook.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.innoship.ro c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.mattca.ro *.google.com/ads/ *.google.ro *.google.ro/ads/ *.trusted.ro/ trusted.ro/ *.profitshare.ro *.omtrdc.net *.salofarm.ro maps.googleapis.com maps.gstatic.com *.stormers.ro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jivosite.com *.profitshare.ro profitshare.ro *.7w.ro *.aptrinsic.com *.mattca.ro maps.googleapis.com widget.trusted.ro *.tawk.to embed.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.aptrinsic.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.jivosite.com *.mattca.ro *.salofarm.ro *.stormers.ro *.tawk.to embed.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.jivosite.com *.mattca.ro 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://stats.g.doubleclick.net/ *.jivosite.com *.7w.ro *.aptrinsic.com maps.googleapis.com socialplugin.facebook.net salofarm.ro wss://chat-eu1-4.jivosite.com *.mattca.ro va.tawk.to vsa86.tawk.to vsa83.tawk.to vsa98.tawk.to *.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src data: blob: 'unsafe-eval' 'unsafe-inline' px-client.net px-cdn.net pxchk.net perimeterx.net px-cloud.net https: 'self'; script-src 7299633.collect.igodigital.com ajax.cloudflare.com *.bazaarvoice.com bs.serving-sys.com cdn.evgnet.com/beacon/liderdomicilio/pruebas/scripts/evergage.min.js connect.facebook.net deploy.mopinion.com googleads.g.doubleclick.net *.lider.cl media.richrelevance.com recs.richrelevance.com s3.amazonaws.com/mapcity-assets/leaflet-0.7.3/leaflet.js secure-ds.serving-sys.com services.mapcity.com static.cloudflareinsights.com www.google-analytics.com www.google.com www.googletagmanager.com *.googleapis.com static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js *.googleadservices.com *.gstatic.com cdn-widgets.chattigo.com media.flixfacts.com media.flixcar.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'none'; report-uri https://csp.walmart.com/c/r/liders 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.flashyapp.com api.flashy.app *.flashy.dev *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.flashyapp.com api.flashy.app *.flashy.dev *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * gateway21.pelecard.biz 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com magefan.com cm.magefan.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.disqus.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com gateway21.pelecard.biz data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.flashyapp.com api.flashy.app *.flashy.dev *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com *.disqus.com cdn.jsdelivr.net maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.clarity.ms gateway21.pelecard.biz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.flashyapp.com api.flashy.app *.flashy.dev *.cloudflare.com *.twitter.com *.twimg.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net cdn.doofinder.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com maps.googleapis.com *.gstatic.com *.google.ch *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com maps.googleapis.com *.cloudflare.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.doofinder.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com commerce.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://deploy.mopinion.com https://static.hotjar.com https://script.hotjar.com https://tdn.r42tag.com https://www.google-analytics.com https://collect.mopinion.com https://www.googletagmanager.com https://www.googleoptimize.com https://static.cloud.coveo.com https://data1.ralasis.com https://optimize.google.com https://translate.googleapis.com https://translate.google.com https://dev.visualwebsiteoptimizer.com https://admin.relay42.com https://static.hotjar.com https://www.google-analytics.com https://app.vwo.com https://cdn.harvest.graindata.com https://a.omappapi.com https://api-engage-eu.sitecorecloud.io https://*.cloudfront.net https://apps.mypurecloud.ie https://snap.licdn.com https://ingest.promptwatch.com;style-src 'self' 'unsafe-inline' https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://collect.mopinion.com https://fonts.mopinion.com https://static.cloud.coveo.com https://fonts.googleapis.com https://translate.googleapis.com https://optimize.google.com https://admin.relay42.com https://app.vwo.com https://a.omappapi.com;img-src 'self' data: https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://www.google-analytics.com https://www.gstatic.com https://i.ytimg.com https://translate.google.com https://translate.googleapis.com https://admin.relay42.com https://tdn.r42tag.com https://t.svtrd.com https://fonts.gstatic.com https://region1.google-analytics.com https://dev.visualwebsiteoptimizer.com https://www.googletagmanager.com https://a.omappapi.com https://px.ads.linkedin.com;font-src 'self' data: https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://fonts.mopinion.com https://gstatic.mopinion.com https://fonts.gstatic.com https://static.cloud.coveo.com https://staticdev.cloud.coveo.com;connect-src * https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl wss://*.hotjar.com https://*.hotjar.com;media-src 'self' https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl;object-src 'none';child-src https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://t.svtrd.com/ https://vars.hotjar.com https://www.youtube-nocookie.com https://www.google.com https://www.youtube-nocookie.com https://www.google.com https://optimize.google.com https://m.youtube.com https://app.vwo.com https://apps.mypurecloud.ie;frame-ancestors https://www.youtube-nocookie.com https://www.google.com https://optimize.google.com https://m.youtube.com https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://app.vwo.com;form-action 'self' https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl https://t.svtrd.com/structure-collection https://broker.nxtid.nl;base-uri https://*.achmearechtsbijstand.nl https://www.achmearechtsbijstand.nl https://achmearechtsbijstand.nl;report-uri https://bcd8a826da9dc721f317d24ae6b9e320.ams.report-uri.com/r/t/csp/reportOnly;report-to endpoint-csp-violation-report-only; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-uD5pBkKlawQQ5U4RLGKC2RmyZN4=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net data: *.hotjar.com github.com cdn.honey.io *.photoslurp.com * data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.redsys.es facebook.com *.adyen.com *.redsys.com *.pinterest.com sas.redsys.es *.facebook.com sas.redsys.com checkoutshopper-live.adyen.com checkoutshopper-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.google.com *.addthis.com *.kampyle.com facebook.com docs.google.com *.facebook.com *.pinterest.es *.pinterest.com service.force.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com blob: *.w3.org *.bing.com c.bing.com *.hotjar.com *.paypal.com bat.bing.com *.clarity.ms *.google.fr facebook.com *.kampyle.com *.gstatic.com *.ladybird.nl *.google.com *.fbcdn.net *.cookiepro.com *.pinterest.com *.pronovias.com *.facebook.com *.google.es *.photoslurp.com *.googleapis.com *.sanpatrick.com *.nicolemilano.com *.cdninstagram.com instagram.com *.verawangbride.com *.whiteonebridal.com *.googletagmanager.com scontent.fmad7-1.fna.fbcdn.net click.s50.exacttarget.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com unpkg.com *.force.com bat.bing.com *.adyen.com *.pinimg.com *.google.com *.hotjar.com *.tiktok.com dropbox.com gstatic.com *.clarity.ms *.moatads.com *.addthis.com *.kampyle.com *.gstatic.com *.dropbox.com *.cookiepro.com *.facebook.net *.facebook.com facebook.net *.photoslurp.com *.googleapis.com *.salesforce.com *.addthisedge.com *.secure.force.com http://polyfill.io service.force.com bam.eu01.nr-data.net *.nicolemilano.com *.empathybroker.com x.empathy.co x.staging.empathy.co *.lightning.force.com analytics.tiktok.com *.googletagmanager.com googletagmanager.com *.salesforceliveagent.com static.lightning.force.com *.la3-c1cs-fra.salesforceliveagent.com d.la3-c1cs-fra.salesforceliveagent.com pronoviasgroup.my.salesforce.com *.pinterest.com player.vimeo.com * 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.honey.io *.kampyle.com *.force.com *.photoslurp.com service.force.com *.nicolemilano.com gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net *.photoslurp.com player.vimeo.com vod-progressive.akamaized.net * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io wss: bat.bing.com *.force.com *.tiktok.com *.google.com *.hotjar.io *.clarity.ms *.vimeo.com d.clarity.ms h.clarity.ms *.kampyle.com *.hotjar.com google.com vc.hotjar.io ws7.hotjar.com *.instagram.com *.cookiepro.com *.pinterest.com *.amazonaws.com client.rum.us-east-1.amazonaws.com sts.eu-west-1.amazonaws.com ws16.hotjar.com ws20.hotjar.com ws22.hotjar.com ws23.hotjar.com ws33.hotjar.com ws34.hotjar.com *.facebook.com *.googleapis.com *.photoslurp.com *.secure.force.com bam.eu01.nr-data.net *.empathybroker.com x.empathy.co x.staging.empathy.co stats.g.doubleclick.net *.google-analytics.com api.empathybroker.com api.empathy.co api.staging.empathy.co *.cardinalcommerce.com api-staging.empathybroker.com pronoviasgroupcti.secure.force.com analytics.pangle-ads.com properties * 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com https://static.klaviyo.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-3y1dkpKJRpHMeyWNfQjcw+NT6Ms=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.core.windows.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com https://www.paypal.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com magefan.com cm.magefan.com *.core.windows.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com widget.freshworks.com m2epro.freshdesk.com *.core.windows.net *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl widget.freshworks.com m2epro.freshdesk.com *.core.windows.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.core.windows.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com widget.freshworks.com m2epro.freshdesk.com *.core.windows.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e30f6215-74d1-4da1-8d7d-134f535ab5ab.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com *.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://pcls1.craftyclicks.co.uk *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.weltpixel.com *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://www.magezon.com https://meetanshi.com/media/logo.png *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.avada.io *.google.com/ *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com https://get.geojs.io *.avada.io *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://fonts.gstatic.com data: *.hotjar.com *.hotjar.io *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://bid.g.doubleclick.net https://www.pinterest.com https://consentcdn.cookiebot.com *.hotjar.com *.hotjar.io *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com media.thatsarte.com *.gstatic.com https://ssl.gstatic.com https://www.gstatic.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.it *.googleadservices.com https://s.pinimg.com https://ct.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.googletagmanager.com tagmanager.google.com https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://s.pinimg.com https://ct.pinterest.com https://unpkg.com https://ajax.googleapis.com *.cookiebot.com *.hotjar.com *.hotjar.io *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.fontawesome.com tagmanager.google.com https://tagmanager.google.com https://fonts.googleapis.com https://unpkg.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com https://s.pinimg.com https://ct.pinterest.com https://consentcdn.cookiebot.com *.hotjar.com *.hotjar.io wss://ws31.hotjar.com wss://ws31.hotjar.io https://stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob:; connect-src 'self' https: wss://ws.hotjar.com; img-src 'self' https: data:; style-src 'self' https: 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com https://cdn1.stamped.io https://cdn-bhcke.nitrocdn.com https://s0.wp.com data:; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://js.stripe.com https://pay.google.com https://www.google.com https://www.googletagmanager.com https://td.doubleclick.net https://www.facebook.com https://dashboard.exampapersplus.co.uk; worker-src 'self' blob:; report-uri /csp-report-endpoint.php 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: https://fonts.gstatic.com *.stape.io *.fontawesome.com cdn.green-it.shop *.loopingo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io js.mollie.com js.klarna.com td.doubleclick.net gtm.green-it.shop https://*.billiger.de https://billiger.de *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.stape.io https://www.mollie.com *.haendlerbund.de *.shopauskunft.de *.tradetracker.net *.loopingo.com tree-nation.com cdn.green-it.shop https://*.billiger.de https://billiger.de www.google.cl www.google.com.cy www.google.co.id *.googlesyndication.com www.google.es www.google.com.co www.google.co.za www.google.com.tw www.google.lt www.google.tn www.google.com.sg www.google.is www.google.sc www.google.co.in www.google.com.bo www.google.co.nz www.google.lu www.google.ge www.google.lk www.google.com.do www.google.by www.google.gl www.google.com.eg www.google.at www.google.al www.google.co.ma www.google.com.br www.google.ro www.google.com.jm www.google.com.bd www.google.no www.google.rs www.google.com.sv www.google.fi www.google.ie www.google.sk www.google.co.ke www.google.co.ug www.google.com.ph www.google.hr www.google.ae www.google.co.tz www.google.com.au google.com www.google.pl www.google.si www.google.com.tr www.google.dk www.google.se www.google.lv www.google.pt www.google.mg www.google.co.il www.google.com.mx www.google.mu www.google.com.mt www.google.ba www.google.ru www.google.jo www.google.mk www.google.me www.google.it www.google.com.sa www.google.ch www.google.com.et www.google.cz www.google.ee www.google.co.th www.google.co.kr www.google.dz www.google.ci www.google.mv www.google.com.vn www.google.com.hk www.google.hu www.google.co.ao www.google.com.ar www.google.com.gh www.google.az www.google.iq www.google.bg www.google.ca www.google.co.uz www.google.com.cu www.google.li www.google.com.na www.google.md www.google.co.jp www.google.com.pk www.google.com.my www.google.gr www.google.fr www.google.am www.google.de data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net *.stape.io js.mollie.com https://analytics.ahrefs.com integration.loopingo.com awmonitor.com tm.tradetracker.net ts.tradetracker.net tree-nation.com *.shopauskunft.de https://cdn.green-it.shop gtm.green-it.shop *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com cdn.green-it.shop *.loopingo.com *.shopauskunft.de 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src data: 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com widget.freshworks.com m2epro.freshdesk.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://analytics.ahrefs.com core.loopingo.com *.userwerk.com eu.klarnaevt.com tree-nation.com stats.g.doubleclick.net gtm.green-it.shop https://cmodul.solutenetwork.com www.google.cz www.google.nl www.google.ch www.google.com.bd www.google.ee www.google.co.ao www.google.bg www.google.pt www.google.hu www.google.com.mx www.google.com.gh www.google.com.ar www.google.com.ua www.google.co.uz www.google.co.uk www.google.fr www.google.ae www.google.co.in www.google.gr www.google.ro www.google.ci www.google.es www.google.lu www.google.com.br www.google.at www.google.com.tw www.google.com.pk www.google.lt www.google.dk www.google.hr www.google.co.ug www.google.com.au www.google.se www.google.pl www.google.com.hk www.google.ie *.shopauskunft.de www.google.de www.google.lk www.google.co.id www.google.it www.google.al www.google.be www.google.co.ke www.google.co.th www.google.ba www.google.co.ma www.google.com.mt www.google.com.my 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9656870a-0f24-4a24-848b-91facff41950.sansec.watch/; report-to report-endpoint; 1 worker-src paypal.com *.braintreegateway.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.searchanise.com *.searchserverapi.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.searchanise.com *.searchserverapi.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube-nocookie.com www.searchanise.com *.searchserverapi.com *.twitter.com ct.pinterest.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://firebasestorage.googleapis.com *.sharethis.com forms.hsforms.com ct.pinterest.com *.facebook.com *.bing.com *.hubspot.com google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io *.sharethis.com searchserverapi.com connect.facebook.net js.hs-banner.com js.hscollectedforms.net js.hs-analytics.net js.hs-scripts.com s.pinimg.com *.clarity.ms ct.pinterest.com shopbagsy.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com vimeo.com api.amplitude.com stats.g.doubleclick.net https://get.geojs.io *.avada.io *.sharethis.com forms.hscollectedforms.net ct.pinterest.com *.clarity.ms bcp.crwdcntrl.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.clickhelp.com *.gravatar.com *.googleapis.com *.gstatic.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.fontawesome.com mc.yandex.ru cdnjs.cloudflare.com cdn.jsdelivr.net integration.graphcomment.com *.youtube.com *.vimeo.com canny.io *.canny.io *.calendly.com d3h3meckw07nf.cloudfront.net *.scalar.com; frame-ancestors 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'unsafe-inline' data: *.paypal.com *.yotpo.com eventstable.com *.eventstable.com *.atlaschairs.com *.globaleventsupply.com *.braintreegateway.com *.signifyd.com *.trustspot.io trustspot.io s3.amazonaws.com trustspot-app-assets.s3.amazonaws.com use.fontawesome.com *.klaviyo.com stackpath.bootstrapcdn.com *.accessibly.app *.accessiblyapp.com *.octocom.ai data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'unsafe-inline' data: *.eventstable.com eventstable.com *.atlaschairs.com *.globaleventsupply.com *.braintreegateway.com *.signifyd.com *.trustspot.io *.klaviyo.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'unsafe-inline' data: *.online-metrix.net *.signifyd.com www.google.com *.doubleclick.net *.eventstable.com eventstable.com *.atlaschairs.com *.globaleventsupply.com www.youtube.com *.vimeo.com *.demdex.net *.trustspot.io *.klaviyo.com www.socialintents.com *.octocom.ai www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com https://plumrocket.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.omtrdc.net *.yotpo.com *.bing.com *.signifyd.com *.online-metrix.net *.google.com p.adsymptotic.com *.linkedin.com *.atdmt.com *.eventstable.com eventstable.com *.atlaschairs.com *.globaleventsupply.com *.bbb.org *.scanalert.com *.cloudfront.net *.demdex.net *.klaviyo.com *.creditkey.com creditkey-assets.s3-us-west-2.amazonaws.com *.shopperapproved.com *.braintreegateway.com *.ravecapture.com ravecapture-app-assets.s3.amazonaws.com trustspot-logos.imgix.net trustspot-product-photos.imgix.net productphotos.trustspot.io *.roundprincemusic.com *.searchspring.io *.accessibly.app *.accessiblyapp.com *.octocom.ai *.hubspot.com *.hsforms.com *.clarity.ms www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.facebook.com *.reddit.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'unsafe-eval' data: www.google.com maps.googleapis.com www.gstatic.com *.klaviyo.com *.signifyd.com static-na.payments-amazon.com a.optmnstr.com snap.licdn.com *.yotpo.com *.pushalert.co bat.bing.com www.socialintents.com www.clickcease.com *.paypal.com eventstable.com *.eventstable.com *.atlaschairs.com *.globaleventsupply.com bam.nr-data.net *.shopperapproved.com *.ravecapture.com trustspot.io cdn.jsdelivr.net *.adobetm.com *.roundprincemusic.com *.hotjar.com *.mouseflow.com *.online-metrix.net analytics.tiktok.com *.accessibly.app *.accessiblyapp.com rum.hlx.page *.octocom.ai *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.usemessages.com *.hs-banner.com *.clarity.ms https://cdn.mida.so unpkg.com www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'unsafe-inline' data: *.yotpo.com www.socialintents.com *.paypal.com eventstable.com *.eventstable.com *.atlaschairs.com *.globaleventsupply.com *.klaviyo.com *.braintreegateway.com *.signifyd.com *.ravecapture.com trustspot.io s3.amazonaws.com use.fontawesome.com www.shopperapproved.com stackpath.bootstrapcdn.com unpkg.com *.octocom.ai *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.usemessages.com *.hs-banner.com https://static.klaviyo.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'unsafe-inline' data: *.demdex.net *.yotpo.com api.omappapi.com *.klaviyo.com payments.amazon.com *.signifyd.com *.cardinalcommerce.com *.doubleclick.net eventstable.com *.eventstable.com *.atlaschairs.com *.globaleventsupply.com *.pushalert.co bam.nr-data.net www.creditkey.com *.ravecapture.com static-forms.klaviyo.com telemetrics.klaviyo.com https://px.ads.linkedin.com *.hotjar.io *.vimeocdn.com analytics.tiktok.com *.accessibly.app *.accessiblyapp.com *.octocom.ai *.hubspot.com *.hscollectedforms.net *.hubapi.com *.hsappstatic.net https://bat.bing.com *.clarity.ms https://cdn.mida.so https://api.mida.so https://api-us.mida.so https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com fonts.googleapis.com use.fontawesome.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-//hdWGh73WgsJonY7E4qC+n1aFY=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.feedbackcompany.com *.googleapis.com maxcdn.bootstrapcdn.com https://*.hotjar.com https://*.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.feedbackcompany.com https://*.tawk.to https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ https://*.tawk.to https://*.doubleclick.net https://www.facebook.com https://assets.pinterest.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://stellar.vanhelden.nl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.feedbackcompany.com 'self' data: https://*.sirv.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://*.analytics.google.com https://*.clarity.ms https://*.google-analytics.com https://*.googletagmanager.com https://*.hotjar.com https://*.linkedin.com https://*.tawk.to https://bat.bing.com https://c.bing.com https://cdn.jsdelivr.net https://exch.vanheijster.nl https://exch.vanhelden.nl https://exch.vanhelden.be https://exch.eurogifts.be https://exch.eurogifts.fr https://googleads.g.doubleclick.net https://tawk.link https://www.google.nl https://www.facebook.com https://i.pinimg.com https://log.pinterest.com https://imgsct.cookiebot.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://ade.googlesyndication.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com d2a6mddvzruxpc.cloudfront.net https://stellar.vanhelden.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://maps.googleapis.com *.feedbackcompany.com bam.nr-data.net bam-cell.nr-data.net js-agent.newrelic.com https://*.sirv.com https://portal.zakeke.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://*.convertexperiments.com https://*.googletagmanager.com https://*.hotjar.com https://*.tawk.to https://bat.bing.com https://connect.facebook.net https://cdn.jsdelivr.net https://googleads.g.doubleclick.net https://snap.licdn.com https://script.adcalls.nl https://www.clarity.ms https://www.google.com https://www.googleadservices.com https://www.googleoptimize.com https://assets.pinterest.com https://widgets.pinterest.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://ct.pinterest.com https://s.pinimg.com https://ct.beslist.nl https://cdn.optimizely.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://stellar.vanhelden.nl https://components.vanhelden.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com maxcdn.bootstrapcdn.com https://*.sirv.com https://*.hotjar.com https://*.tawk.to https://cdn.jsdelivr.net https://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.tawk.to https://v.pinimg.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.feedbackcompany.com bam.nr-data.net bam-cell.nr-data.net https://*.sirv.com https://api.zakeke.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.analytics.google.com https://*.clarity.ms https://*.google-analytics.com https://*.googletagmanager.com https://*.hotjar.com https://*.hotjar.io https://*.tawk.to https://api.adcalls.nl https://bat.bing.com https://cdn.linkedin.oribi.io https://fonts.gstatic.com https://www.facebook.com wss://*.hotjar.com wss://*.tawk.to https://consentcdn.cookiebot.com https://exch.vanheijster.nl https://exch.vanhelden.nl https://exch.vanhelden.be https://exch.eurogifts.be https://exch.eurogifts.fr https://ct.pinterest.com https://px.ads.linkedin.com https://googleads.g.doubleclick.net https://*.googlesyndication.com https://*.metrics.convertexperiments.com https://logs.convertexperiments.com https://*.convertexperiments.com https://ct.beslist.nl https://ad.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://stellar.vanhelden.nl https://components.vanhelden.nl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'nonce-kh6mIk/Cgd1kMSddkhz8Q05rUTlnFRqNMt7th96GxLo=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 upgrade-insecure-requests; object-src 'none'; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.plyr.io https://cdnjs.cloudflare.com https://code.jquery.com https://go.everstream.ai https://munchkin.marketo.net https://static.addtoany.com https://tag.demandbase.com https://fonts.googleapis.com https://ws-assets.zoominfo.com https://www.googletagmanager.com https://assets.codepen.io https://443-ezw-095.mktoweb.com https://cdn-cookieyes.com https://unpkg.com https://static.hotjar.com https://script.hotjar.com https://boards.greenhouse.io https://snap.licdn.com https://*.googleusercontent.com http://*.googleusercontent.com https://www.youtube.com https://cdn.bizible.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://fast.wistia.com; connect-src 'self' https://boards-api.greenhouse.io https://443-ezw-095.mktorest.com https://munchkin.marketo.net https://tag.demandbase.com https://ws-assets.zoominfo.com https://www.googletagmanager.com https://go.everstream.ai https://log.cookieyes.com https://cdn-cookieyes.com https://directory.cookieyes.com https://yoast.com https://ams.wpml.org https://noembed.com https://cdn.plyr.io https://px.ads.linkedin.com https://content.hotjar.io wss://ws.hotjar.com https://api.company-target.com https://analytics.google.com https://region1.google-analytics.com https://www.google-analytics.com https://tag-logger.demandbase.com https://pagead2.googlesyndication.com https://www.google.com https://stats.g.doubleclick.net https://metrics.hotjar.io https://www.google.ca; frame-src 'self' https://player.vimeo.com https://443-ezw-095.mktoweb.com https://static.addtoany.com https://job-boards.greenhouse.io https://www.youtube.com https://*.googleusercontent.com http://*.googleusercontent.com https://s.company-target.com https://td.doubleclick.net; style-src 'self' 'unsafe-inline' https://cdn.plyr.io https://cdnjs.cloudflare.com https://fonts.googleapis.com https://assets.codepen.io https://cdn-cookieyes.com https://unpkg.com https://443-ezw-095.mktoweb.com https://ams.wpml.org; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com data:; img-src 'self' data: https://cdn.plyr.io https://cdnjs.cloudflare.com https://go.everstream.ai https://munchkin.marketo.net https://static.addtoany.com https://tag.demandbase.com https://ws-assets.zoominfo.com https://www.googletagmanager.com https://assets.codepen.io https://cdn-cookieyes.com https://secure.gravatar.com https://*.ytimg.com https://i.ytimg.com https://px.ads.linkedin.com https://cdn.bizible.com https://id.rlcdn.com https://www.google.ca https://www.google.be; worker-src 'self' blob:; report-uri https://o82685.ingest.us.sentry.io/api/4509293955907584/security/?sentry_key=d0bac385543dfe367058e2015e42c128; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'nonce-GQtDzQXlwj0jPdWUjzpcCA=='; style-src 'self' https: 'unsafe-inline' 'nonce-GQtDzQXlwj0jPdWUjzpcCA=='; connect-src 'self' https: wss://localhost:8181 wss://localhost:8282 wss://localhost:8383 wss://localhost:8484 wss://127.0.0.1:8181 wss://127.0.0.1:8282 wss://127.0.0.1:8383 wss://127.0.0.1:8484 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' airtools-loomis.prod-mid-euw3.investis.com captcha.loomis.com cdn.cookielaw.org cdnjs.cloudflare.com code.jquery.com irs.tools.investis.com www.googletagmanager.com; script-src 'self' 'nonce-zpmAiHNacmm5KQhvC6Jslg12s/4=' 'sha384-11cX+Naw18bPoIYxEkQI+DltxbxL5/5L0krcoW8ObmMGsC3OiLBkmZjXSWPrrjYh' captcha.loomis.com *.googleapis.com cdn.cookielaw.org cdnjs.cloudflare.com code.jquery.com loomis.jobbase.io loomis.onlyfy.jobs www.googletagmanager.com www.google.com www.gstatic.com googleads.g.doubleclick.net pagead2.googlesyndication.com connect.facebook.net snippet.capybara.lmc.cz www.googleadservices.com loomis-dk.containers.piwik.pro; style-src 'self' 'unsafe-inline' captcha.loomis.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googleapis.com snippet.capybara.lmc.cz; img-src 'self' data: captcha.loomis.com cdn.cookielaw.org cdn-endpoint-sitecorecdn-es-01.azureedge.net px.ads.linkedin.com www.facebook.com www.googleadservices.com www.googletagmanager.com img.icons8.com media.licdn.com 1.bp.blogspot.com cdn.theorg.com googleads.g.doubleclick.net maps.gstatic.com *.googleapis.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; connect-src 'self' 'unsafe-inline' data: airtools-loomis.prod-mid-euw3.investis.com *.google.com google.com px.ads.linkedin.com *.google-analytics.com captcha.loomis.com cdn.cookielaw.org privacyportal-de.onetrust.com geolocation.onetrust.com api.capybara.lmc.cz www.googleadservices.com www.google.se www.facebook.com *.googleapis.com; font-src 'self' 'unsafe-inline' fonts.gstatic.com snippet.capybara.lmc.cz; frame-src 'self' airtools-loomis.prod-mid-euw3.investis.com irs.tools.investis.com loomis.onlyfy.jobs td.doubleclick.net www.youtube.com www.youtube-nocookie.com otp.investis.com otp.tools.investis.com view.genially.com *.google.com *.googletagmanager.com google.com googletagmanager.com publish.ne.cision.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com use.fontawesome.com/releases/v5.6.0/webfonts 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.imseuro.co.uk www.imseuro.eu 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.xtento.com consentcdn.cookiebot.com consentcdn.cookiebot.eu account.fetchify.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.xtento.com cdn.xtento.com imgsct.cookiebot.com imgsct.cookiebot.eu *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ g10696554090.co chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.xtento.com cdn.xtento.com consent.cookiebot.com consent.cookiebot.eu *.hsforms.net *.hsforms.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com cc-cdn.com use.fontawesome.com/releases/v5.6.0/css *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu api.craftyclicks.co.uk pcls1.craftyclicks.co.uk t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdn-custom.optimonk.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.magerocket.com *.gocuotas.com https://event.getblue.io https://www.googletagmanager.com *.mercadolibre.com https://mobbex.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io www.apptrian.com www.facebook.com *.magerocket.com *.gocuotas.com https://firebasestorage.googleapis.com https://wbg.menze.la https://res.sugaway.io https://media.wanamakids.com https://www.google.com.co *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.mobbex.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com *.avada.io https://onsite.optimonk.com https://cdn-account.optimonk.com https://cdn-limit.optimonk.com https://ekr.zdassets.com https://jfapiprod.optimonk.com https://front.optimonk.com https://d3v-menze.zendesk.com https://cdn-asset.optimonk.com https://player.vimeo.com https://gs-cdn.optimonk.com https://static.zdassets.com https://assets-cdn.woowup.com https://cdn.jsdelivr.net https://res.sugaway.io *.mlstatic.com *.mercadopago.com *.mobbex.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdn.jsdelivr.net https://media.wanamakids.com https://cdn-asset.optimonk.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io www.apptrian.com connect.facebook.net graph.facebook.com *.magerocket.com *.gocuotas.com https://get.geojs.io *.avada.io https://front.optimonk.com https://cdn-account.optimonk.com https://cdn-limit.optimonk.com https://ekr.zdassets.com https://jfapiprod.optimonk.com https://d3v-menze.zendesk.com https://cdn-asset.optimonk.com https://player.vimeo.com https://gs-cdn.optimonk.com https://static.zdassets.com https://assets-cdn.woowup.com https://cdn.jsdelivr.net https://j.clarity.ms *.mercadopago.com *.mercadolibre.com *.mobbex.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.vivapayments.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com www.googletagmanager.com www.google.com www.google.com/recaptcha vimeo.com www.youtube-nocookie.com leafstag.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com *.weltpixel.com *.google.com widget-v5.boxnow.gr td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com *.paypal.com c.paypal.com checkout.paypal.com www.sandbox.paypal.com vimeo.com player.vimeo.com www.youtube.com gallery.mailchimp.com downloads.mailchimp.com form-assets.mailchimp.com chimpstatic.com *.list-manage.com ebizmarts-website.s3.amazonaws.com magefan.com cm.magefan.com *.disqus.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com www.facebook.com bat.bing.net *.vivapayments.com www.clarity.ms https://ss.butlers.gr https://osm.klarnaservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net business.facebook.com connect.facebook.net graph.facebook.com sandbox.braintree-api.com *.weltpixel.com www.google.gr www.gstatic.com *.googlesyndication.com pagead2.googlesyndication.com adservice.google.com adservice.google.gr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com player.vimeo.com www.youtube.com maps.googleapis.com *.paypal.com c.paypal.com checkout.paypal.com leafstag.cardinalcommerce.com centinelapi.cardinalcommerce.com songbirdstag.cardinalcommerce.com *.behance.net *.ftcdn.net *.gstatic.com assets.braintreegateway.com api.braintreegateway.com api.sandbox.braintreegateway.com js.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.stat-track.com *.avada.io *.vivapayments.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com pay.google.com analytics.braintreegateway.com sandbox.braintree-api.com bat.bing.com www.clarity.ms *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com region1.google-analytics.com *.googlesyndication.com pagead2.googlesyndication.com adservice.google.com adservice.google.gr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com cm.everesttech.net maps.googleapis.com www.googleapis.com *.paypal.com assets.braintreegateway.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.stat-track.com *.avada.io google.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.cardinalcommerce.com *.google.com analytics.braintreegateway.com sandbox.braintree-api.com bat.bing.com www.clarity.ms *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com region1.google-analytics.com *.googlesyndication.com pagead2.googlesyndication.com adservice.google.com adservice.google.gr stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://js.hs-scripts.com https://js.hscollectedforms.net https://js.hsforms.net https://www.google-analytics.com https://ssl.google-analytics.com https://www.googletagmanager.com https://ajax.googleapis.com https://code.jquery.com https://cdn.jsdelivr.net https://cdn2.hubspot.net https://js.hs-analytics.net https://js.hubspot.com https://js.hsadspixel.net https://js.hs-banner.com https://cdnjs.cloudflare.com https://js.zi-scripts.com https://googleads.g.doubleclick.net https://www.googleadservices.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://7052064.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://7052064.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com; font-src 'self' https://fonts.gstatic.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' data: https://cdn2.hubspot.net https://www.google-analytics.com https://23990167.fs1.hubspotusercontent-na1.net https://forms.hsforms.com https://no-cache.hubspot.com https://perf-na1.hsforms.com https://track.hubspot.com https://cta-service-cms2.hubspot.com; connect-src 'self' https://forms.hubspot.com https://api.hubapi.com https://forms.hscollectedforms.net https://cta-service-cms2.hubspot.com https://js.hs-banner.com https://js.zi-scripts.com; frame-src https://*.hubspot.com https://*.hsforms.com https://23990167.hs-sites.com https://www.googletagmanager.com https://td.doubleclick.net; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com business.facebook.com www.commercepartnerhub.com *.openpay.mx *.openpay.co *.opencontrol.mx *.kaptcha.com *.openpay.pe *.paynet.com.mx c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sandbox.paypal.com *.paypalobjects.com cdn.dnky.co amc.demdex.net www.google.com youtube.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com business.facebook.com *.postimg.cc *.openpay.mx www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com 'self' data: maps.gstatic.com maps.googleapis.com accounts.google.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com business.facebook.com *.s3.amazonaws.com *.openpay.co *.openpay.pe *.google-analytics.com *.google.com/recaptcha/ *.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com https://www.google.com *.gstatic.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com https://maps.googleapis.com *.tawk.to cdn.jsdelivr.net *.convertexperiments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com cdn.dnky.co *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com business.facebook.com *.openpay.mx *.openpay.co *.openpay.pe api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sandbox.paypal.com *.paypalobjects.com *.google-analytics.com api.comapi.com bam.nr-data.net *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors app.cux.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com play.google.com *.autopay.eu c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com www.youtube.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com pixel.wp.pl trustmate.io facebook.com *.cookiebot.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com www.google.pl www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.dwin1.com dc.cux.io connect.facebook.net *.livechatinc.com *.luigisbox.com pixel.wp.pl *.comfino.pl trustmate.io *.cookiebot.com *.hotjar.com *.adform.net unpkg.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com static.clickonometrics.pl www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.autopay.eu *.googleapis.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com unpkg.com *.comfino.pl trustmate.io *.cloudflare.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com *.track.cux.io pixel.wp.pl *.comfino.pl *.cookiebot.com *.hotjar.com *.adform.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com stats.g.doubleclick.net ws: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com https://h.online-metrix.net/ https://static-content.vnforapps.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net cm.everesttech.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com https://www.google.com https://maps.googleapis.com https://sibautomation.com/sa.js https://share.hsforms.com/1u5aYKB4eS7in1XkiXplEuAr2a3r https://script.crazyegg.com/pages/scripts/0019/6089.js https://static.hotjar.com/ https://h.online-metrix.net/fp/tags.js https://static-content.vnforapps.com/v2/js/checkout.js https://static-content.vnforapps.com/v2/js/prd_dfp.js https://rum.hlx.page/.rum/@adobe/ https://script.hotjar.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.googletagmanager.com *.cookielaw.org *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org https://in-automate.brevo.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.prosto.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.clarity.ms *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: *.amazonaws.com *.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ pay.google.com play.google.com *.autopay.eu *.prosto.com *.twitter.com *.pay.google.com *.cards-accept.bm.pl *.googletagmanager.com *.savecart.pl pixel.wp.pl *.hotjar.com *.facebook.net *.google.com *.clarity.ms *.pinterest.com *.packeta.com secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu *.prosto.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.googletagmanager.com *.savecart.pl pixel.wp.pl *.hotjar.com *.facebook.net *.facebook.com *.clarity.ms *.wp.pl *.gdpsystem.eu *.pinimg.com *.tiktok.com *.segmentify.com *.google.pl static.payu.com *.amazonaws.com *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com *.pay.google.com *.cards-accept.bm.pl google.com paypal.com *.prosto.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.savecart.pl pixel.wp.pl *.hotjar.com *.facebook.net *.clarity.ms *.wp.pl *.gdpsystem.eu *.pinimg.com *.tiktok.com *.segmentify.com *.google.pl *.inis360.com *.avada.io *.packeta.com secure.payu.com secure.snd.payu.com *.google.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.autopay.eu *.googleapis.com *.prosto.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.wp.pl *.gdpsystem.eu *.pinimg.com *.tiktok.com *.segmentify.com *.google.pl maxcdn.bootstrapcdn.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.gstatic.com *.prosto.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.savecart.pl *.pinterest.com *.hotjar.com *.clarity.ms *.wp.pl *.gdpsystem.eu *.pinimg.com *.tiktok.com *.segmentify.com *.google.pl *.google.com https://get.geojs.io *.avada.io *.packeta.com secure.payu.com merch-prod.snd.payu.com t.elasticsuite.io *.amazonaws.com *.cloudfront.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://prosto.com/; report-to report-endpoint; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.google.com *.addthis.com api.razorpay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com 'self' data: https://www.magezon.com cdn.razorpay.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.apptrian.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.avada.io checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com *.cloudflare.com *.twitter.com *.paypal.com https://get.geojs.io *.avada.io lumberjack.razorpay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.kundanrefinery.com/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com id.dokobit.com id-sandbox.dokobit.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://app.usercentrics.eu 'self' *.maksekeskus.ee *.test.maksekeskus.ee www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.dokobit.com *.google.lv *.openstreetmap.org https://maps.omnivasiunta.lt ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com https://app.usercentrics.eu *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com *.maksekeskus.ee *.test.maksekeskus.ee www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.dokobit.com *.usercentrics.eu *.hotjar.com https://unpkg.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://www.googletagmanager.com https://polyfill.io https://api.usercentrics.eu https://id-sandbox.dokobit.com *.disqus.com *.avada.io *.shopify.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com downloads.mailchimp.com id.dokobit.com id-sandbox.dokobit.com *.googleapis.com https://fonts.bunny.net *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.dokobit.com *.doubleclick.net https://geocode.arcgis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://api.usercentrics.eu https://id-sandbox.dokobit.com https://get.geojs.io *.avada.io 'self' *.maksekeskus.ee *.test.maksekeskus.ee www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors *.facebook.com https://www.facebook.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.google.com/ *.facebook.net *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net https://www.gstatic.com https://translate.googleapis.com https://fonts.gstatic.com http://translate.google.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com https://translate.googleapis.com http://translate.google.com https://translate-pa.googleapis.com s7.addthis.com *.avada.io *.google.com/ *.facebook.net *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com www.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com https://translate.googleapis.com ekr.zdassets.com/ https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.weltpixel.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com www.googletagmanager.com consentcdn.cookiebot.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com maps.gstatic.com maps.googleapis.com *.mageside.com mageside.com *.multisafepay.com www.facebook.com imgsct.cookiebot.com sst.amode.be www.google.be *.cdninstagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com maps.googleapis.com https://maps.googleapis.com *.multisafepay.com https://pay.google.com ajax.googleapis.com connect.facebook.net *.cloudfront.net core.helloretail.com consentcdn.cookiebot.com consent.cookiebot.com sst.amode.be *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.multisafepay.com cdn-images.mailchimp.com *.cloudfront.net pay.multisafepay.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://maps.googleapis.com *.multisafepay.com region1.analytics.google.com core.helloretail.com maps.googleapis.com consentcdn.cookiebot.com sst.amode.be https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com core.helloretail.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.google.com https://cdn.cardknox.com/ checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ media.sezzle.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdn.cardknox.com/ifields/2.15.2405.1601/ifields.min.js *.googleapis.com *.google.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com https://www.googletagmanager.com tagmanager.google.com *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline *.googleapis.com *.google.com *.gstatic.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.cdnfonts.com fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com https://www.google-analytics.com *.mmapiws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-to csp-endpoint;default-src 'self';script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://*.clarity.ms https://api.livechatinc.com https://cdn.livechatinc.com https://connect.facebook.com https://connect.facebook.net ; connect-src 'self' ws://localhost:12387 https://connect.facebook.net https://adservice.google.com https://adservice.google.com:443 https://*.google.com https://*.google.com:443 https://*.google.com.mt https://www.google.com.mt https://www.google.com www.google-analytics.com https://*.clarity.ms https://*.analytics.google.com https://api.livechatinc.com https://cdn.livechatinc.com https://stats.g.doubleclick.net https://www.facebook.com; img-src 'self' https://online.welbees.mt https://welbees.mt https://c.bing.com https://c.clarity.ms https://www.facebook.com https://www.googletagmanager.com https://*.google https://*.google.com.mt https://*.doubleclick.net https://www.googletagmanager.com:443 https://googleads.g.doubleclick.net:443; style-src 'self' 'unsafe-inline';frame-src 'self' https://secure.livechatinc.com https://www.googletagmanager.com https://www.facebook.com https://psp.transactium.com https://* 1 script-src 'unsafe-inline' 'unsafe-eval' 'report-sample' https: www.googletagmanager.com www.google-analytics.com; script-src-elem 'unsafe-inline' 'unsafe-eval' 'report-sample' https: www.googletagmanager.com www.google-analytics.com; form-action 'self' https://*.planetrentalcars.com; object-src 'none'; media-src 'none'; report-uri /csp/report; worker-src 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' boitempoeditorial.com.br *.boitempoeditorial.com.br wake-components.fbitsstatic.net boitempoeditorial.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.boitempoeditorial.com.br boitempoeditorial.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com https://premier.trustcommerce.com;script-src 'nonce-faaff85903f24a5b8683cbb06c54d219' https://www.ccmychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://us-api.experian.com/decisionanalytics/crosscore/npc3zwbc5v26/services/v0/applications/3;style-src https://www.ccmychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.se https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src 'self' *.b2clogin.com https://www.youtube.com https://www.google.com https://services.gastronovi.com www.recaptcha.net *.loadbee.com *.youtube.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com js-agent.newrelic.com www.youtube.com www.google-analytics.com bam.nr-data.net static.dvinci-easy.com maps.googleapis.com bat.bing.com www.gstatic.com connect.facebook.net widget.msgp.pl services.gastronovi.com www.gastronavi.de www.googleadservices.com googleads.g.doubleclick.net blob: cdnjs.cloudflare.com https://cdn.kiprotect.com https://cdnjs.cloudflare.com unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' www.googletagmanager.com static.dvinci-easy.com unpkg.com js-agent.newrelic.com www.google-analytics.com maps.googleapis.com bam.nr-data.net connect.facebook.net bat.bing.com www.gstatic.com www.youtube.com widget.msgp.pl services.gastronovi.com www.gastronavi.de www.googleadservices.com googleads.g.doubleclick.net www.google.com www.recaptcha.net content.syndigo.com js.monitor.azure.com *.dvinci-easy.com www.clarity.ms *.clarity.ms *.loadbee.com cdnjs.cloudflare.com https://cdn.kiprotect.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' static.dvinci-easy.com fonts.googleapis.com cdnjs.cloudflare.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; base-uri 'self'; frame-ancestors 'self' 1 frame-ancestors 'self' *.shopee.com *.shopeepay.com *.monee.com 1 default-src 'self'; img-src 'self' data: 'unsafe-eval' https://cdn.rand.com https://s1749.t.eloqua.com https://cihost.uberflip.com https://dpm.demdex.net https://idsync.rlcdn.com https://sync.crwdcntrl.net https://match.adsrvr.org https://ps.eyeota.net https://px.ads.linkedin.com https://b.6sc.co https://ml314.com https://chatserver12.comm100.io https://www.google.com https://www.google.ca https://www.google-analytics.com https://insights.sitesearch360.com https://content.cdntwrk.com https://i.ytimg.com https://app.cdntwrk.com https://blogs.rand.com https://vue.comm100.com https://www.googletagmanager.com https://bat.bing.com https://tags.bluekai.com https://cm.g.doubleclick.net https://ws.rqtrk.eu https://pippio.com https://pixel.tapad.com https://dmp.adform.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://bat.bing.com https://googleads.g.doubleclick.net https://ajax.aspnetcdn.com https://img.en25.com/i/elqCfg.min.js https://img.en25.com/i/elqCfg.min.js https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://cdnjs.cloudflare.com https://cdn.sitesearch360.com/ https://j.6sc.co/6si.min.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://vue.comm100.com https://ml314.com https://415621.tctm.xyz/t.js; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://content.cdntwrk.com; connect-src 'self' https://www.google-analytics.com https://c.6sc.co https://ipv6.6sc.co https://stats.g.doubleclick.net https://chatserver12.comm100.io https://cdn.linkedin.oribi.io https://analytics.google.com https://epsilon.6sense.com https://insights.sitesearch360.com ; font-src 'self' data: https://fonts.gstatic.com https://vue.comm100.com; frame-src 'self' https://www.youtube-nocookie.com https://www.google.com; 1 font-src *.bootstrapcdn.com *.googleapis.com *.gstatic.com js.klevu.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca www.google.com/ googleads.g.doubleclick.net google.com google.com/ affirm.com affirm.com/ *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.google.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca https://googleads.g.doubleclick.net/ *.klevu.com *.trackedlink.net *.ksearchnet.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com *.gstatic.com *.facebook.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca www.google.com/recaptcha/ www.gstatic.com/recaptcha/ affirm.com js.klevu.com *.googlesyndication.com *.googlecommerce.com *.googletagservices.com googletagmanager.com *.bing.com *.google.com *.intercom.io *.intercomcdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.ksearchnet.com connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.bootstrapcdn.com js.klevu.com *.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.affirm.com *.affirm.ca pagead2.googlesyndication.com *.intercom.io affirm.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com https://fonts.gstatic.com/ https://staticw2.yotpo.com/ *.typekit.net *.trustedshops.com *.fontawesome.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://klear.com https://s7.addthis.com/ https://www.google.com/ https://player.vimeo.com/ https://bid.g.doubleclick.net/ https://8985111.fls.doubleclick.net/ https://td.doubleclick.net/ https://www.youtube.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://*.googletagmanager.com https://*.teads.tv/ www.facebook.com *.klaviyo.com *.cloudfront.net *.cloudflare.com https://cdn.klarna.com *.paypal.com https://www.janmarini.com https://p.yotpo.com/ https://cdn-yotpo-images-production.yotpo.com/ blob: https://www.google.com *.doubleclick.net *.cdninstagram.com https://s.ytimg.com *.usercentrics.eu img.icons8.com cfvod.kaltura.com staticw2.yotpo.com maps.googleapis.com maps.gstatic.com meetanshi.com *.kickfire.com https://www.rumiview.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.clarity.ms *.google-analytics.com *.googletagmanager.com *.google.com *.fbcdn.net *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com https://f.vimeocdn.com/ www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://mariniskinsolutions.com/ https://plugins-media.makeupar.com/ https://script.hotjar.com/ https://static.hotjar.com/ https://c.amazon-adsystem.com/ https://kit.fontawesome.com https://klear.com https://*.tiktok.com/ *.cloudflare.com *.demandbase.com *.kickfire.com *.klaviyo.com https://*.googletagmanager.com https://googleads.g.doubleclick.net/ https://www.google.com/ https://www.gstatic.com/ maps.googleapis.com https://www.googleapis.com/ www.facebook.com https://cmp.osano.com/ https://cdn.jsdelivr.net/ https://stackpath.bootstrapcdn.com/ https://staticw2.yotpo.com/ *.trustedshops.com *.usercentrics.eu https://s7.addthis.com/ https://z.moatads.com/ https://v1.addthisedge.com/ https://m.addthis.com/ https://code.jquery.com/ https://vimeo.com/ https://cdnapisec.kaltura.com/ https://assets.adobedtm.com/ https://www.rumiview.com/ https://i.simpli.fi/ https://tag.simpli.fi/ https://www.dialogtech.com/ https://*.teads.tv/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.authorize.net jstest.authorize.net ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klaviyo.com *.cloudflare.com *.typekit.net https://fonts.googleapis.com/ https://staticw2.yotpo.com/ *.trustedshops.com *.usercentrics.eu https://code.jquery.com/ https://cdn.jsdelivr.net/ https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://plugins-media.makeupar.com/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://s.amazon-adsystem.com/ https://ara.paa-reporting-advertising.amazon/ https://*.tiktok.com/ https://klear.com https://*.teads.tv/ https://*.rumiview.com/ *.klaviyo.com *.doubleclick.net *.cloudflare.com https://w2.yotpo.com https://staticw2.yotpo.com/ https://*.instagram.com/ https://tattle.api.osano.com/ *.paypal.com https://app.proofo.io/ https://api.yotpo.com/ https://dpm.demdex.net/ https://www.google-analytics.com/ https://analytics.google.com/ https://pagead2.googlesyndication.com/ https://bt.signifyd.com:11103/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com apitest.authorize.net jstest.authorize.net *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.clarity.ms *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-WJCEE58wS9xEnG1cdUcPrEVC' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.reviews.io *.reviews.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://my.ukfast.co.uk https://images.ukfast.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://firebasestorage.googleapis.com *.reviews.io *.reviews.co.uk *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://my.ukfast.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.what3words.com *.avada.io *.shopify.com player.vimeo.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.reviews.io *.reviews.co.uk https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com assets.braintreegateway.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.cloudflare.com *.twitter.com *.twimg.com https://cmtgroup.3cx.co.uk https://stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.what3words.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.intercomcdn.com *.bootstrapcdn.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.mobilpay.ro *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com dacia-ro.os.tc *.facebook.com *.doubleclick.net *.cookiebot.com *.pinterest.com *.dotdigital-pages.com *.dotdigital.com *.addthis.com *.twitter.com *.creativecdn.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.google.ro *.googleapis.com *.googletagmanager.com *.ibb.co contactrenaultgroup.secure.force.com *.salesforceliveagent.com *.intercomcdn.com *.facebook.com trusted.ro *.analytics.yahoo.com *.pinterest.com *.kafune.ro *.trackedlink.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.addthisedge.com *.twitter.com lafantana.ro *.lafantana.ro *.smartsuppcdn.com *.linkedin.com *.docomo.ne.jp *.e-planning.net *.media.net *.smaato.net *.rakuten.com *.gumgum.com *.opera.com *.cookiebot.com *.disqus.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.googleoptimize.com *.googletagmanager.com onesignal.com *.onesignal.com *.intercom.io *.intercomcdn.com *.salesforceliveagent.com *.googleapis.com *.gstatic.com *.facebook.net *.yimg.com *.retargeting.biz *.retargeting.app *.cookiebot.com *.mczbf.com *.pinimg.com *.smartsuppchat.com *.smartsuppcdn.com *.smartsupp.com *.creativecdn.com *.pinterest.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.avada.io *.shopify.com *.addthis.com *.moatads.com *.addthisedge.com *.twitter.com *.smartlook.com *.licdn.com webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://lafantana.ro 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.smartsuppcdn.com webchat.dotdigital.com webchat.staging.dotdigital.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.intercomcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.intercom.io wss://nexus-websocket-a.intercom.io wss://ah-pusher.gd.ro *.webrci.ro *.yimg.com cdn.cookielaw.org *.retargeting.app *.smartsuppchat.com *.pinterest.com *.googleapis.com *.smartsuppcdn.com *.smartsupp.com wss://websocket-visitors.smartsupp.com *.creativecdn.com *.sjwoe.com *.mczbf.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://get.geojs.io *.avada.io *.google.ro *.smartlook.cloud *.cookiebot.com *.tiktok.com webchat.dotdigital.com webchat.staging.dotdigital.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://forms.bigpixelstudio.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.bigpixelstudio.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.instagram.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de forms.bigpixelstudio.com *.paypalobjects.com *.paypal.com sandbox.paypal.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com magento-cloudflare.jetrails.com www.youtube.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.google.com *.addthis.com *.pinterest.com *.bigpixelstudio.com https://forms.bigpixelstudio.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://forms.bigpixelstudio.com www.sandbox.paypal.com *.ytimg.com https://firebasestorage.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.bigpixelstudio.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.instagram.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.shopify.com cdn.jsdelivr.net connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.bigpixelstudio.com https://forms.bigpixelstudio.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://forms.bigpixelstudio.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com unsafe-inline *.bigpixelstudio.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://forms.bigpixelstudio.com *.googleadservices.com https://get.geojs.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.bigpixelstudio.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors *.hana.ondemand.com 'self'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src live-agrinet-m2.vaimo.net *.zdassets.com 'self' 'unsafe-inline'; font-src live-agrinet-m2.vaimo.net https://static.klaviyo.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com https://fonts.gstatic.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; style-src live-agrinet-m2.vaimo.net fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; connect-src static-forms.klaviyo.com live-agrinet-m2.vaimo.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; form-action live-agrinet-m2.vaimo.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-src live-agrinet-m2.vaimo.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src live-agrinet-m2.vaimo.net widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src www.youtube.com live-agrinet-m2.vaimo.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com https://www.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network 'self' 'unsafe-inline' 'unsafe-eval'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.gstatic.com *.oct8ne.com fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google.com chart.googleapis.com *.addthis.com *.addthisedge.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.bird.eu cdn.doofinder.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net *.hsforms.com *.gumlet.io placehold.co *.google.it *.hubspot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl www.google.com www.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com cdn.jsdelivr.net maps.google.com *.addthis.com *.addthisedge.com *.moatads.com unpkg.com cdn.iubenda.com *.hsforms.net *.hotjar.com *.pardot.com *.hs-scripts.com *.hs-banner.com *.hs-analytics.net *.hscollectedforms.net *.usemessages.com/ *.legalblink.it *.fontawesome.com accessibility.tun2u.it *.hubspot.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com cdn.jsdelivr.net *.googleapis.com unpkg.com cdn.iubenda.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.doofinder.com wss://*.doofinder.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com www.google.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com chart.googleapis.com *.addthis.com *.hsforms.com *.google-analytics.com *.doubleclick.net *.hubspot.com *.legalblink.it *.hscollectedforms.net *.gumlet.io accessibility.tun2u.it *.fontawesome.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' maps.gstatic.com maps.googleapis.com *.stripe.com *.linkedin.com *.cookiepro.com www.googletagmanager.com https://*.hotjar.com; script-src 'self' https://oxerambd.activehosted.com https://js.stripe.com https://connect-js.stripe.com https://*.mimecastprotect.com https://diffuser-cdn.app-us1.com https://*.googleapis.com https://*.cookiepro.com https://snap.licdn.com Https://prism.app-us1.com https://trackcmp.net https://www.googletagmanager.com https://*.hotjar.com 'unsafe-inline'; connect-src 'self' *.googleapis.com *.linkedin.com *.cookiepro.com *.google-analytics.com www.googletagmanager.com www.google.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; font-src 'self' https://fonts.gstatic.com https://*.hotjar.com; style-src 'self' https://fonts.googleapis.com https://*.hotjar.com 'unsafe-inline'; frame-src https://connect-js.stripe.com https://js.stripe.com; 1 font-src https://cdnjs.cloudflare.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.addthis.com js.mollie.com *.sendcloud.sc *.jsdelivr.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://www.mollie.com *.amazonaws.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net js.mollie.com *.sendcloud.sc *.jsdelivr.net https://mikabot-staging.studio-mikado.be https://mikabot.studio-mikado.be *.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com https://cdn.jsdelivr.net *.sendcloud.sc *.jsdelivr.net https://mikabot-staging.studio-mikado.be https://mikabot.studio-mikado.be https://cdnjs.cloudflare.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://mikabot-staging.studio-mikado.be https://mikabot.studio-mikado.be *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors https://canonplus.com https://admin.treefortsystems.com; report-uri https://o1003299.ingest.sentry.io/api/5966172/security/?sentry_key=2a13400a30ad4037a8f0cf127af14bff; 1 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com *.twitter.com https://www.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.twitter.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.trackedlink.net *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.mollie.com *.multisafepay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com https://*.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.multisafepay.com https://pay.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'nonce-MTFhOGEwOWYtZDEyMy00YTFlLWE0ZmItYTkyZjc2MjgyYjlm' 'strict-dynamic' ; style-src 'self' 'unsafe-inline' 'nonce-MTFhOGEwOWYtZDEyMy00YTFlLWE0ZmItYTkyZjc2MjgyYjlm' https://fonts.googleapis.com https://myhealthatvanderbilt.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' blob: data: https://*.files.vanderbilthealth.com https://api.krames.com; font-src 'self' https://fonts.gstatic.com; object-src 'self' https://*.files.vanderbilthealth.com; connect-src 'self' https://edge.adobedc.net http://*.mktoresp.com http://*.swiftypecdn.com; frame-src https://myhealthatvanderbilt.com https://play.vidyard.com https://www.youtube-nocookie.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; block-all-mixed-content; upgrade-insecure-requests; report-uri /api/v1/csp-report; report-to csp-endpoint; 1 default-src 'self' 'unsafe-eval'; script-src 'unsafe-eval' 'nonce-dpMyTkLpLidcud-v7pgz8TB8uwTQDxhKndIi2VoZG7JhVUe7PB6YuQ' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org; base-uri 'self'; frame-src https://display.contentfry.com; style-src-elem 'self' 'unsafe-inline' cdn.ckeditor.com 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org; script-src-elem 'self' 'unsafe-inline' data: https://platform.contentfry.com https://cdn.ckeditor.com 'report-sample'; frame-ancestors 'self'; script-src-attr 'unsafe-inline' 'report-sample'; report-uri https://www.adlershof.de/@http-reporting?csp=report&requestTime=1765935721703617&requestHash=64e167bf1dcc275f48149a0c4abfed65bc230f1f 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: www.saschina.org *.fontawesome.com *.googleapis.com *.googletagmanager.com *.plyr.io unpkg.com fonts.gstatic.com youtube.com *.google-analytics.com *.cloudflare.com www.youtube.com snap.licdn.com static.ads-twitter.com px.ads.linkedin.com stats.g.doubleclick.net analytics.google.com noembed.com *.saschina.org data: *.jsdelivr.net *.facebook.net *.saschina.org *.polyv.net flbook.com.cn live-hls.snsports.cn *.cloudvdn.com pili-live-rtmp.banmabang.cn *.videocc.net; img-src data: blob: 'self' *.saschina.org *.docksal.site *.jsdelivr.net *.tugboatqa.com i.ytimg.com www.facebook.com player.polyv.net *.videocc.net; frame-src 'self' www.saschina.org *.saschina.org flbook.com.cn blob: *.saschina.org; child-src 'self' www.saschina.org *.saschina.org flbook.com.cn blob: *.saschina.org; report-uri /report-csp-violation 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://futbolbase.services.answerbase.com https://*.googletagmanager.com https://*.googletagservices.com https://*.googlesyndication.com https://fundingchoicesmessages.google.com https://*.gstatic.com https://*.adtrafficquality.google https://*.googleapis.com https://*.ampproject.org https://*.ezojs.com https://*.ezoic.net https://*.ezodn.com https://*.gatekeeperconsent.com https://cdn.id5-sync.com https://cdn.jsdelivr.net https://www.humix.com https://*.humix.com https://*.doubleclick.net https://*.rubiconproject.com https://*.quantserve.com https://*.quantcount.com https://*.criteo.net https://open.video https://*.open.video https://*.ccgateway.net https://*.2mdn.net https://*.zencdn.net https://*.facebook.net https://*.bing.com https://*.bing.net https://*.clarity.ms https://*.yahoo.com https://*.33across.com https://*.crwdcntrl.net https://*.openxcdn.net https://*.pubmatic.com https://*.creativecdn.com https://*.optable.co https://*.doubleverify.com https://www.google.com https://*.google.com https://*.truste.com https://*.trustarc.com https://*.adsafeprotected.com https://*.flashtalking.com https://*.adsrvr.org https://*.amazon-adsystem.com https://*.globalwarm.io https://*.script.ac https://*.yieldmo.com https://*.liadm.com https://secured-pixel.com https://*.secured-pixel.com https://extensionscontrol.com https://*.extensionscontrol.com https://*.hadronid.net https://*.fastclick.net https://*.adform.net https://*.taptapnetworks.com https://*.sharethrough.com https://*.createjs.com https://*.ftstatic.com https://*.jwplayer.com https://*.jwpcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://futbolbase.services.answerbase.com https://*.ezodn.com https://*.ezoic.net https://*.2mdn.net https://*.answerbase.com; font-src 'self' data: https://fonts.gstatic.com https://*.cloudflare.com https://*.goin.cloud https://*.googlesyndication.com; img-src 'self' data: https:; connect-src 'self' data: wss://localhost:* wss://*.imtlazarus.com:* https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.google.com https://*.google.es https://*.google.fr https://*.google.pt https://*.google.de https://*.google.co.uk https://*.google.nl https://*.google.com.br https://*.google.pl https://*.google.co.kr https://*.google.ch https://*.google.ad https://*.google.co.il https://*.google.co.ma https://*.google.co.jp https://*.google.com.qa https://*.google.com.pe https://*.google.si https://*.googleadservices.com https://adservice.google.com https://*.googletagmanager.com https://*.doubleclick.net https://fundingchoicesmessages.google.com https://*.googlesyndication.com https://*.adtrafficquality.google https://*.gstatic.com https://*.googleapis.com https://futbolbase.services.answerbase.com https://*.gatekeeperconsent.com https://*.ezoic.net https://*.ezoic.com https://id5-sync.com https://*.id5-sync.com https://*.eu-1-id5-sync.com https://*.eu-3-id5-sync.com https://*.eu-4-id5-sync.com https://*.us-1-id5-sync.com https://*.ap-1-id5-sync.com https://*.hadron.ad.gt https://*.ad.gt https://*.a-mx.com https://*.yahoo.com https://*.criteo.com https://*.criteo.net https://*.crwdcntrl.net https://*.adsrvr.org https://cdn.jsdelivr.net https://*.rubiconproject.com https://*.onetag-sys.com https://*.yieldmo.com https://*.a-mo.net https://*.ezodn.com https://*.sharethrough.com https://*.quantserve.com https://*.quantcount.com https://*.sonobi.com https://*.ccgateway.net https://*.open.video https://*.rlcdn.com https://*.dotomi.com https://*.bing.com https://*.bing.net https://*.clarity.ms https://*.ampproject.org https://*.pubmatic.com https://dnacdn.net https://*.dnacdn.net https://*.rtbhouse.com https://*.facebook.com https://*.optable.co https://*.33across.com https://*.openx.net https://*.ltmsphrcl.net https://*.adnxs.com https://*.doubleverify.com https://*.icu https://*.flashtalking.com https://*.globalwarm.io https://*.amazon-adsystem.com https://*.a2z.com https://*.liadm.com https://cgkthn.com https://*.cgkthn.com https://*.publisher-services.amazon.dev https://*.clean.gg https://*.omnitagjs.com https://*.adform.net https://*.imganalytics.com; frame-src 'self' https://fundingchoicesmessages.google.com https://*.doubleclick.net https://*.googlesyndication.com https://*.googletagmanager.com https://adservice.google.com https://*.adtrafficquality.google https://*.google.com https://*.googleapis.com https://*.googleadservices.com https://*.pubmatic.com https://onetag-sys.com https://*.onetag-sys.com https://*.openx.net https://*.ezodn.com https://*.ezoic.net https://*.criteo.com https://*.creativecdn.com https://*.2mdn.net https://*.yieldmo.com https://*.rubiconproject.com https://*.a-mo.net https://*.sonobi.com https://*.bannerflow.net https://*.omnitagjs.com https://*.connextra.com https://*.facebook.com https://*.liadm.com https://*.adsrvr.org; media-src 'self' data: blob: https:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; report-uri /api/CspReport 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.googleapis.com maps.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=cc827c65-ab7c-4dbd-abc1-89f697f8da59; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 default-src https:; connect-src https: wss:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' *.google.com fonts.googleapis.com static.pazaruvaj.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net maxcdn.bootstrapcdn.com ssl.ceneo.pl s.kk-resources.com elnino.daktela.com www.wiarygodneopinie.pl ts.tradetracker.net cdn.foxentry.cz www.parfemy-elnino.cz geowidget.inpost.pl www.googletagmanager.com smartsuppcdn.com static.compari.ro *.demandware.net; object-src 'self'; img-src 'self' https: data:; font-src https: data:; frame-ancestors 'self' *.creativecdn.com *.hotjar.com *.googletagmanager.com; report-uri https://elnino.report-uri.com/r/d/csp/enforce 1 font-src *.gstatic.com cdn.jsdelivr.net fonts.gstatic.com *.fontawesome.com 'self' data: *.jsdelivr.net *.almapay.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com https://www.youtube.com https://vimeo.com https://www.dailymotion.com https://www.google.com http://www.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.com *.gstatic.com *.doubleclick.net *.imgix.net 'self' data: https://a.tile.openstreetmap.fr https://a.tile.openstreetmap.org https://b.tile.openstreetmap.fr https://b.tile.openstreetmap.org https://c.tile.openstreetmap.fr https://c.tile.openstreetmap.org https://www.google.fr https://fonts.gstatic.com https://www.googletagmanager.com *.etrusted.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.net *.facebook.com *.imgix.net *.axept.io https://www.googletagmanager.com https://www.google.com https://www.gstatic.com *.doubleclick.net cdn.jsdelivr.net jquery.sellxed.com *.avada.io *.google.com *.gstatic.com https://api.instagram.com https://analytics.1789.fr https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com cdn.jsdelivr.net fonts.googleapis.com *.fontawesome.com *.gstatic.com *.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.axept.io *.google-analytics.com *.google.com *.doubleclick.net *.getalma.eu https://get.geojs.io *.avada.io t.elasticsuite.io https://nominatim.openstreetmap.org https://analytics.1789.fr *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' yale.com.br *.yale.com.br wake-components.fbitsstatic.net yale.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.googleadservices.com *.g.doubleclick.net googleadservices.com *.google-analytics.com *.googletagmanager.com *.cloudfront.net *.hotjar.com *.facebook.net *.fbits.store *.adyen.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com *.posclick.dinamize.com *.emkt.dinamize.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io gstatic.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.yale.com.br yale.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 script-src 'nonce-Q1NQXzY5NDIxMzJkMGY4OGI0LjM5MTA0OTEx' 'strict-dynamic' https: 'unsafe-inline'; object-src 'none'; base-uri 'none'; report-uri https://www.zenstore.it/csp/report.php 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com *.magento-ds.com www.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com getfirebug.com *.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://apisandbox.cieloecommerce.cielo.com.br/ https://apiquerysandbox.cieloecommerce.cielo.com.br/ https://api.cieloecommerce.cielo.com.br/ https://apiquery.cieloecommerce.cielo.com.br/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob: *.google.com *.stripe.com; font-src maxcdn.bootstrapcdn.com *.gstatic.com pro.fontawesome.com maxcdb.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://api.systempay.fr/static/ https://fonts.bunny.net https://cdnjs.cloudflare.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.facebook.net 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://vars.hotjar.com *.weltpixel.com *.cookiebot.com *.stripe.com *.google.com *.parcelsapp.com facebook.com www.facebook.com youtube.com www.youtube.com platform.twitter.com google.com https://player.vimeo.com *.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ *.facebook.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.google.com https://www.google.fr https://cl.avis-verifies.com https://axeptio.imgix.net *.bing.com blob: *.gstatic.com *.google.com *.stripe.com scontent.cdninstagram.com *.twitter.com *.googleapis.com google.com www.facebook.com ssl.google-analytics.com *.paypal.com cl.avis-verifies.com *.netreviews.eu *.openstreetmap.org *.facebook.com cdn.doofinder.com maps.googleapis.com maps.gstatic.com https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ magefan.com cm.magefan.com *.facebook.net https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.googleoptimize.com https://googleads.g.doubleclick.net https://unpkg.com *.axept.io https://static.hotjar.com https://script.hotjar.com *.cookiebot.com *.bing.com *.clarity.ms *.skeepers.io *.google.com *.stripe.com https://magento.com *.googleapis.com google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com platform.twitter.com *.fontawesome.com cdn.jsdelivr.net f.vimeocdn.com *.paypal.com cl.avis-verifies.com *.openstreetmap.org tagmanager.google.com *.facebook.net unpkg.com cdn.doofinder.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ s7.addthis.com *.facebook.com *.avada.io *.shopify.com www.facebook.com graph.facebook.com business.facebook.com js.mollie.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com *.adobe.com https://unpkg.com *.googleapis.com google.com *.gstatic.com *.fontawesome.com www.google-analytics.com cdn.jsdelivr.net maxcdb.bootstrapcdn.com tagmanager.google.com *.doofinder.com fonts.googleapis.com https://api.systempay.fr/static/ https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://stats.g.doubleclick.net *.axept.io *.googlesyndication.com *.google.com *.stripe.com *.bing.com https://www.paypal.com/xoplatform/logger/api/logger *.paypal.com *.braintree-api.com cdn.ampproject.org insights.algolia.io *.analytics.google.com *.doubleclick.net *.clarity.ms *.brevo.com *.bat.bing.com *.google-analytics.com *.facebook.net *.doofinder.com wss://*.doofinder.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ ekr.zdassets.com/ *.facebook.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://pay.digitalfemsa.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net cdn.conekta.io conektaapi.s3.amazonaws.com pay.digitalfemsa.io https://devinfra24.devg4a.net/ *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io api.conekta.io api.digitalfemsa.io *.paypal.com *.sandbox.paypal.com *.paypalobjects.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com https://*.qliro.com https://*.vipps.no https://*.trustly.com https://*.ideal.nl https://*.apple.com https://*.unzer.com https://*.heidelpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com https://*.qliro.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com https://*.qliro.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.bootstrapcdn.com *.cloudflare.com *.gstatic.com *.googleusercontent.com *.slant.co unpkg.com *.jsdelivr.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.arcot.com *.cardinalcommerce.com *.americanexpress.com *.uobgroup.com *.citibank.com *.inicis.com *.2c2p.com *.dnp-cdms.jp *.ipay88.com.my *.unionpay.com *.ctbcbank.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.weltpixel.com *.afterpay.com *.arcot.com *.ctbcbank.com *.cardinalcommerce.com *.americanexpress.com *.uobgroup.com *.google.com *.citibank.com *.unionpay.com *.inicis.com *.dnp-cdms.jp 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://static.afterpay.com https://site-assets.afterpay.com/ k.kakaocdn.net *.inicis.com www.google.co.id www.google.es www.google.com.co *.googletagmanager.com www.google.co.za www.google.com.tw www.google.com.sg www.google.nl www.google.co.in www.google.co.uk *.hstatic.net *.google-analytics.com *.google.com www.google.at www.google.ad *.thecompanystore.com.sg *.gstatic.com *.googleusercontent.com www.google.com.bd *.googleapis.com www.google.ie *.afterpay.com www.google.com.ph www.google.com.au www.google.dk www.google.se www.google.com.mt www.google.it www.google.co.th www.google.co.kr www.google.com.vn www.google.com.hk *.naver.com *.doubleclick.net *.elcompanies.com www.google.co.jp www.google.com.my www.google.fr www.google.de data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.addressfinder.io *.adyen.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com maps.googleapis.com developers.kakao.com *.kakaocdn.net *.avada.io *.inicis.com *.afterpay.com *.newrelic.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.fontawesome.com *.inicis.com *.jsdelivr.net *.gstatic.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self'; media-src *.adobe.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://api.addressfinder.io *.adyen.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com kauth.kakao.com https://get.geojs.io *.avada.io *.inicis.com www.google.nl www.google.com.bd *.newrelic.com *.afterpay.com www.google.fr www.google.co.in www.google.es www.google.co.jp www.google.at www.google.com.tw *.google.com www.google.dk www.google.com.au *.google-analytics.com www.google.com.hk www.google.ie www.google.com.vn www.google.de www.google.com.sg www.google.co.id www.google.co.za www.google.it www.google.co.kr *.nr-data.net *.googleapis.com www.google.co.th *.doubleclick.net www.google.ad www.google.com.ph www.google.com.mt *.googletagmanager.com www.google.com.my 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self'; default-src 'self'; base-uri 'self'; report-uri https://32b97dac-2dc9-426f-bbe7-fbeb1b35a245.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-N2YyN2JiZGUtNTIwMC00NTE5LTkwNWYtYjM4NTg5NmY2ZDY1' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src *.fontawesome.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ *.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ *.google.com *.gstatic.com *.google-analytics.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.canadapost.ca https://sso.epost.ca *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * gstatic.com *.twitter.com *.doubleclick.net *.hotjar.com *.livechatinc.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ mageside.com *.canadapost.ca *.canadapost-postescanada.ca www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.google.ca *.doubleclick.net *.cdninstagram.com *.googlesyndication.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://static.addtoany.com/ cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com gstatic.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.doubleclick.net *.googletagmanager.com trackcmp.net *.facebook.net *.hotjar.com *.bootstrapcdn.com *.livechatinc.com *.gorgias.chat *.klaviyo.com *.privacy-center.org *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.bootstrapcdn.com *.privacy-center.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://stats.addtoany.com/menu cdn.ampproject.org *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.hotjar.com *.hotjar.io *.instagram.com *.klaviyo.com *.gorgias.chat *.doubleclick.net *.privacy-center.org *.googlesyndication.com *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.example.com/; report-to report-endpoint; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-ce80062042af499daa65720a2a1e2c6d' https://mybeaumontchart.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mybeaumontchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.medline.eu *.cookiebot.com *.vo.msecnd.net *.google-analytics.com *.linkedin.oribi.io *.algolia.net *.algolianet.com *.mouseflow.com *.gstatic.com *.g.doubleclick.net *.google.com *.ads.linkedin.com *.linkedin.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.medline.eu polyfill.io *.licdn.com *.cookiebot.com *.googletagmanager.com *.google-analytics.com *.jsdelivr.net *.youtube.com *.algolia.net *.mouseflow.com *.cloudflareinsights.com *.clickdimensions.com *.cloudflare.com *.blob.core.windows.net/webtracking/WebTracking/WebTracking.bundle.js; style-src 'self' 'unsafe-inline' *.medline.eu *.googletagmanager.com *.googleapis.com; img-src 'self' *.medline.eu *.assets.medline.eu *.ads.linkedin.com *.linkedin.com *.cookiebot.com *.googletagmanager.com *.gstatic.com *.google.com *.google.co.in *.google-analytics.com *.ytimg.com data:; frame-src 'self' *.cookiebot.com *.youtube.com *.clickdimensions.com *.vimeo.com *.blob.core.windows.net; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com https://fonts.gstatic.com/ *.fontawesome.com https://fonts.bunny.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com account.fetchify.com https://maps.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com google.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://cdnjs.cloudflare.com/ s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com google.com *.kxcdn.com *.gstatic.com downloads.mailchimp.com cc-cdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com/ *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com https://cdn.jsdelivr.net *.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.hotjar.com *.cloudfront.net *.paysera.com *.every-pay.com *.googletagmanager.com *.packeta.com https://*.every-pay.com/ https://pay.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io maps.google.com maps.googleapis.com maps.gstatic.com https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com *.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://map.plugins.itella.com *.hotjar.com *.cloudfront.net *.paysera.com *.every-pay.com *.google.lt https://bank.paysera.com https://maps.omnivasiunta.lt https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt https://*.every-pay.com/ https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net maps.google.com maps.googleapis.com https://static.addtoany.com/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://unpkg.com https://browser.sentry-cdn.com *.hotjar.com *.cloudfront.net *.paysera.com *.every-pay.com *.clarity.ms *.cloudflareinsights.com *.lupasearch.com *.packeta.com https://*.every-pay.com/ https://pay.google.com/ *.avada.io cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com https://unpkg.com *.fontawesome.com https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io maps.googleapis.com https://stats.addtoany.com/menu https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.ingest.sentry.io *.hotjar.com *.cloudfront.net *.paysera.com *.every-pay.com *.clarity.ms *.google.com *.lupasearch.com https://geocode.arcgis.com *.packeta.com https://www.terminalmappingjs.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.fontawesome.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com fast.fonts.net embed.tawk.to acsbapp.com *.acsbapp.com static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.twitter.com *.authorize.net *.syfpos.com *.syf.com *.syfpayments.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.twitter.com *.addthis.com *.addtoany.com *.authorize.net syf.demdex.net *.syfpos.com *.syf.com platform.twitter.com *.pinterest.com servedby.flashtalking.com *.hotjar.com amc.demdex.net *.syfpayments.com *.mysynchrony.com calendly.com *.googletagmanager.com view360.io *.cloudfront.net insight.adsrvr.org 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com 'self' data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net *.mysynchrony.com *.pinterest.com embed.tawk.to tawk.link syndication.twitter.com scontent.cdninstagram.com scontent-ort2-1.cdninstagram.com img.youtube.com *.cloudfront.net *.google.co.in *.cdninstagram.com *.acsbapp.com secure.media6degrees.com *.synchrony.com *.syfpayments.com ssynchronyfinancial.d1.sc.omtrdc.net *.mdhv.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ 'self' data: https://ajax.googleapis.com/ *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.jsdelivr.net *.addtoany.com *.authorize.net *.syfpos.com analytics.synchrony.com *.mysynchrony.com *.syf.com *.tiqcdn.com tags.srv.stackadapt.com acsbap.com cdn.jsdelivr.net embed.tawk.to acsbapp.com platform.twitter.com static-tracking.klaviyo.com bam.nr-data.net *.datadome.co static.cloudflareinsights.com action.media6degrees.com *.hotjar.com *.cloudfront.net static.wywy.com action.dstillery.com s.pinimg.com emma-content-aggregates-prd.s3.amazonaws.com qvdt3feo.com cdn.noibu.com *.synchrony.com *.syfpayments.com tags.tiqcdn.com nexus.ensighten.com *.clarity.ms js.adsrvr.org 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.bootstrapcdn.com maxcdn.bootstrapcdn.com *.syfpos.com fast.fonts.net tags.srv.stackadapt.com embed.tawk.to *.syf.com *.klaviyo.com *.syfpayments.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com embed.tawk.to *.acsbapp.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'unsafe-inline' data: 'unsafe-inline' blob: *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.facebook.com *.facebook.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.g.doubleclick.net *.addthis.com *.pinterest.com *.addtoany.com *.authorize.net *.syfpos.com *.syf.com *.d1.sc.omtrdc.net *.acsbapp.com tags.srv.stackadapt.com *.tawk.to wss://*.tawk.to *.klaviyo.com bam.nr-data.net *.datadome.co *.hotjar.com *.doubleclick.net acsbapp.com *.hotjar.io acsbap.com wss://ws.hotjar.com ssynchronyfinancial.d1.sc.omtrdc.net *.syfpayments.com pagead2.googlesyndication.com *.google.com *.clarity.ms *.adsrvr.org *.mdhv.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.tawk.to *.onglesdor.com onglesdor.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.facebook.net *.tawk.to *.onglesdor.com onglesdor.com 'self' 'unsafe-inline'; frame-ancestors https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ landofcoder.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com https://*.moneris.com/ *.addthis.com *.tawk.to *.sezzle.com *.doubleclick.net checkout.sezzle.com sandbox.checkout.sezzle.com checkout.eu.sezzle.com sandbox.checkout.eu.sezzle.com tracking.sezzle.com tracking.eu.sezzle.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com camo.githubusercontent.com https://www.magezon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com *.onglesdor.com onglesdor.com cdn.jsdelivr.net *.google.ca *.sezzle.com *.cloudfront.net media.sezzle.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net https://*.moneris.com/ *.avada.io *.shopify.com 'unsafe-inline' *.tawk.to *.agilecrm.com *.tiktok.com *.sezzle.com *.amazonaws.com chimpstatic.com cdn.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.onglesdor.com onglesdor.com *.instagram.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com checkout-sdk.eu.sezzle.com sandbox.checkout-sdk.eu.sezzle.com widget.sezzle.com widget.eu.sezzle.com widget.sezzle.in maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.googleapis.com *.googletagmanager.com https://*.moneris.com/ *.fontawesome.com https://fonts.bunny.net cdn.jsdelivr.net *.sezzle.com *.tawk.to *.onglesdor.com onglesdor.com *.cloudfront.net 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com *.facebook.com *.facebook.net *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io *.tawk.to wss://*.tawk.to *.addthis.com *.tiktok.com *.sezzle.com *.onglesdor.com onglesdor.com places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.tawk.to 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'self' *.youtube.com; default-src * 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com data:; frame-src 'self' https://challenges.cloudflare.com *.plaid.com js.stripe.com *.youtube.com https://www.googletagmanager.com https://*.doubleclick.net https://www.facebook.com/ https://tpc.googlesyndication.com https://intercom-sheets.com/ https://calendly.com https://*.calendly.com https://capture.navattic.com https://guideline.navattic.com https://insight.adsrvr.org https://iframe.cloudflarestream.com/ https://customer-x5mykgv2c1zv0440.cloudflarestream.com/ https://match.adsrvr.org; img-src 'self' *.guideline.io https://cms-assets.guideline.com https://imagedelivery.net https://*.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.google.com https://*.google-analytics.com https://pagead2.googlesyndication.com https://www.facebook.com ads-twitter.com *.bing.com *.microsoft.com https://*.adsymptotic.com https://t.co https://*.linkedin.com https://analytics.twitter.com https://cdn.cookielaw.org https://trkn.us https://www.gravatar.com https://*.googleadservices.com https://alb.reddit.com https://*.intercomcdn.com https://*.intercomassets.com https://*.intercomusercontent.com data:; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' https://challenges.cloudflare.com https://cdn-assets-prod.s3.amazonaws.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://tracking-api.g2.com https://cdn.prod.uidapi.com https://*.googletagmanager.com https://tagmanager.google.com 'unsafe-eval' 'nonce-bfb67fcc7b27136d5b267383739e0a75' 'strict-dynamic'; worker-src 'self' *.youtube.com; base-uri 'self'; frame-ancestors 'self' https://*.squareup.com https://squareup.com https://*.squareupstaging.com https://squareupstaging.com https://*.checkhq.com https://*.eddy.com https://eddy.com https://app.belfrysoftware.com https://*.joinwarp.com https://*.monograph.com https://*.enkempass.com https://*.central.inc https://*.keka.com https://*.lumberfi.com https://*.workstream.us https://pro.housecallpro.com https://*.tryplayground.com https://*.7shifts.com https://app.getthera.com https://dashboard.miter.com https://*.zenoti.com https://*.prod.aioapp.com https://app.gosteelhead.com https://*.encompassfi.com https://*.joinhomebase.com; report-uri https://sentry2.guideline.com/api/6/security/?sentry_key=f678b7ad3eade55e6da26393e869e420; 1 font-src maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com *.facebook.net js.mollie.com *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.facebook.com *.facebook.net https://firebasestorage.googleapis.com https://www.mollie.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net *.avada.io *.shopify.com js.mollie.com *.reviews.io *.reviews.co.uk *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io *.cloudfront.net *.reviews.io *.reviews.co.uk t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com www.promessedefleurs.ie data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com www.promessedefleurs.ie 'self' 'unsafe-inline'; frame-ancestors www.promessedefleurs.ie 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.promessedefleurs.ie 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure-magenta.dalenys.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie www.promessedefleurs.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com cl.avis-verifies.com bat.bing.com s.pinimg.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://unpkg.com/pwacompat www.promessedefleurs.ie 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com unpkg.com www.promessedefleurs.ie 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.promessedefleurs.ie 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net www.promessedefleurs.ie 'self' 'unsafe-inline'; child-src www.promessedefleurs.ie http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com www.promessedefleurs.ie 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://netdna.bootstrapcdn.com *.klarnacdn.net fonts.googleapis.com www.yorkshirecaravans.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.sagepay.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.yorkshirecaravans.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.yorkshirecaravans.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://my.matterport.com https://secure-img3.caravanfinder.co.uk www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com landofcoder.com maps.googleapis.com chart.googleapis.com *.sagepay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com www.yorkshirecaravans.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://secure-img.webpurchaseimages.co.uk https://secure-render2.caravanfinder.co.uk https://secure.caravanfinder.co.uk https://maps.gstatic.com https://maps.googleapis.com https://secure-render1.caravanfinder.co.uk www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://lh3.googleusercontent.com https://*.gstatic.com https://googleads.g.doubleclick.net * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.yorkshirecaravans.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://*.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://use.fontawesome.com https://assets.adobedtm.com https://secure.authorize.net https://test.authorize.net https://www.googleadservices.com https://js.braintreegateway.com https://maps.google.com https://connect.facebook.net https://secure-render2.caravanfinder.co.uk https://static.cloudflareinsights.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.sagepay.com https://maps.googleapis.com https://www.gstatic.com * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.yorkshirecaravans.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://secure-render2.caravanfinder.co.uk https://secure-render1.caravanfinder.co.uk *.klarnacdn.net https://static.klaviyo.com assets.braintreegateway.com www.yorkshirecaravans.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com www.yorkshirecaravans.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.sagepay.com https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com www.yorkshirecaravans.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.yorkshirecaravans.com http: https: blob: 'self' 'unsafe-inline'; default-src www.yorkshirecaravans.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com https://www.gstatic.com https://fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com fonts.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de challenges.cloudflare.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.hotjar.com consentcdn.cookiebot.com *.facebook.com *.pinterest.com *.pinterest.de *.usercentrics.eu *.googletagmanager.com *.weltpixel.com js.mollie.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.facebook.com *.google.com *.google.de *.google.at *.google.ro *.google.us *.pinterest.com *.pinterest.de *.manga-mafia.de *.manga-mafia.com *.merchindice.com *.cosplay-shop.de *.mage-world.de *.googletagmanager.com *.mailchimp.com *.usercentrics.eu *.amazonaws.com *.trustedshops.com cdn.klarna.com x.klarnacdn.net https://www.mollie.com *.gstatic.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de challenges.cloudflare.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.gstatic.com cdnjs.cloudflare.com *.google-analytics.com *.hotjar.com consent.cookiebot.com connect.facebook.net *.pinimg.com *.googleadservices.com *.clerk.io *.googletagmanager.com *.usercentrics.eu *.trustedshops.com *.adcell.com *.3cx.com js.mollie.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.trustedshops.com *.tagmanager.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.paypal.com *.pinterest.com *.pinterest.de *.usercentrics.eu *.klarnacdn.net *.on3cx.de:5001 *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * https: data: blob: 'unsafe-inline' 'unsafe-hashes'; object-src 'self'; base-uri 'self' 1 default-src 'self'; script-src https://a.bff.fm https://platform.twitter.com https://www.google-analytics.com; object-src 'none'; style-src data: https://a.bff.fm; img-src data: https://a.bff.fm https://www.google-analytics.com; connect-src 'self' https://www.google-analytics.com; font-src data:; media-src https://*.bff.fm; frame-src *; block-all-mixed-content; upgrade-insecure-requests; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: script.hotjar.com *.trustedshops.com maxcdn.bootstrapcdn.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.googletagmanager.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com kantkonfigurator.feld-eitorf.de *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com consentcdn.cookiebot.com consent.cookiefirst.com google.com/recaptcha/api2 www.gstatic.com/recaptcha/ *.doubleclick.net *.clarity.ms *.visualwebsiteoptimizer.com app.vwo.com *.klarna.com *.facebook.com www.googletagmanager.com *.pinterest.com kantkonfigurator.feld-eitorf.de *.weltpixel.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.gstatic.com *.googleapis.com https://images.unsplash.com www.google.de *.g.doubleclick.net *.facebook.net *.facebook.com *.clarity.ms chart.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com *.trustedshops.com bat.bing.com *.bing.net *.cookiefirst.com *.doubleclick.net *.storyblok.com www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.co.ao www.google.co.in www.google.co.ke www.google.co.th www.google.co.uk www.google.com.co www.google.com.do www.google.com.eg www.google.com.tr www.google.com.tw www.google.com.ua www.google.cz www.google.dk www.google.ee www.google.es www.google.fr www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.li www.google.lk www.google.lu www.google.mk www.google.nl www.google.no www.google.pl www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk bat.bing.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com js-agent.newrelic.com bam.nr-data.net google-analytics.com googletagmanager.com consentcdn.cookiebot.com consent.cookiebot.com h.online-metrix.net gstatic.com www.gstatic.com www.google.com *.bing.com *.hotjar.com *.g.doubleclick.net *.clarity.ms commerce-chat.com *.visualwebsiteoptimizer.com app.vwo.com *.trustedshops.com *.cookiefirst.com 'unsafe-inline' data: 'self' data: connect.facebook.net *.analytics.google.com *.doubleclick.net *.facebook.net *.googletagmanager.com *.pinimg.com *.pinterest.com *.scriptcdn.net *.storyblok.com https://www.googletagmanager.com tagmanager.google.com unpkg.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.hsforms.net *.hsforms.com *.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 127.0.0.1:35729 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com *.cookiefirst.com *.trustedshops.com *.storyblok.com tagmanager.google.com maxcdn.bootstrapcdn.com assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com https://maps.googleapis.com https://player.vimeo.com bat.bing.com *.hotjar.com *.aiaibot.com *.g.doubleclick.net bam.nr-data.net bam.nr-data.net/events/ consent.cookiebot.com www.facebook.com *.google-analytics.com *.visualwebsiteoptimizer.com app.vwo.com *.klarnaevt.com *.klarnacdn.com *.klarnacdn.net *.klarna.com *.cookiefirst.com *.google.com *.analytics.google.com *.clarity.ms *.hotjar.io wss://ws.hotjar.com api.trustedshops.com shops-si.trustedshops.com api.trustbadge.etrusted.com trustbadge.api.etrusted.com *.google.de *.bing.net *.doubleclick.net *.facebook.com *.pinterest.com *.trustedshops.com www.google.at www.google.be www.google.bg www.google.ca www.google.ch www.google.co.in www.google.co.uk www.google.com.co www.google.com.do www.google.com.tr www.google.com.ua www.google.cz www.google.dk www.google.es www.google.fr www.google.ge www.google.hr www.google.hu www.google.it www.google.lk www.google.lu www.google.nl www.google.no www.google.pl www.google.ro www.google.ru www.google.si bat.bing.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.etrusted.com https://integrations.etrusted.site 127.0.0.1:35729 ws://127.0.0.1:35729 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://906d42bb-492d-4824-b48a-f928e7d30432.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://maps.omnivasiunta.lt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io https://unpkg.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io https://geocode.arcgis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com t.elasticsuite.io *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https: wss:; report-uri https://csp.prod.devops.forlagshuset.no/csp/report-only; report-to csp-endpoint 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com *.consensu.org *.sharethis.com secure.payu.com merch-prod.snd.payu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com static.payu.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.google.com *.sharethis.com maps.googleapis.com *.avada.io secure.payu.com secure.snd.payu.com *.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.sharethis.com maps.googleapis.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com *.googleapis.com *.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-Mq0b8/QZBCnHOKveDFR5HJJ+D18=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com *.googleapis.com cdn-cookieyes.com *.cookieyes.com *.facebook.net *.facebook.com *.google.pt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com *.googleapis.com *.gstatic.com cdn-cookieyes.com *.cookieyes.com *.facebook.net *.facebook.com *.google.pt js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://maps.googleapis.com https://player.vimeo.com *.googleapis.com cdn-cookieyes.com *.cookieyes.com *.facebook.net *.facebook.com *.google.pt api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.cloudfront.net data: *.typekit.net data: 'self' 'unsafe-inline'; form-action *.facebook.com *.cleverreach.com https://seu2.cleverreach.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com secure.pay1.de payments.amazon.de www.jsctool.com https://consentcdn.cookiebot.com *.hotjar.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com cdn.pay1.de www.paypal.com www.paypalobjects.com x.klarnacdn.net *.cloudfront.net *.trustedshops.com *.sleeknote.com *.cookiebot.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com www.jsctool.com *.googleapis.com https://consent.cookiebot.com https://consentcdn.cookiebot.com *.paypalobjects.com *.paypal.com *.trustedshops.com *.sleeknote.com *.amazonaws.com *.pay1.de *.klarna.com *.authorize.net *.braintreegateway.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com d.ratepay.com *.typekit.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com payments.amazon.de d.ratepay.com www.jsctool.com *.fact-finder.de *.fact-finder.com *.fact-finder.co.uk *.fact-finder.fr *.fact-finder.pl *.fact-finder.it *.fact-finder.at *.fact-finder.ch *.fact-finder.cloud *.googletagmanager.com *.hotjar.com https://consentcdn.cookiebot.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.bootstrapcdn.com *.gstatic.com *.googleapis.com 'self' data: *.hotjar.com *.typekit.net cdn.curator.io static.klaviyo.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.chatra.io *.hotjar.com *.facebook.com *.trustpilot.com *.kiyoh.com *.pinterest.com *.criteo.com *.cookiefirst.com www.googletagmanager.com *.weltpixel.com *.multisafepay.com https://pay.google.com www.google.com *.sendcloud.sc *.jsdelivr.net www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com * scontent.fzty3-2.fna.fbcdn.net alb.reddit.com p.typekit.net www.facebook.com curator-assets.b-cdn.net *.gstatic.com *.multisafepay.com *.amazonaws.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ use.typekit.net *.cloudflare.com *.twitter.com *.fontawesome.com *.elfsight.com *.chimpstatic.com *.chatra.io *.jsdelivr.net chimpstatic.com *.facebook.com *.doubleclick.net *.trustpilot.com s.pinimg.com *.zdassets.com *.google-analytics.com *.feedbackcompany.com *.facebook.net *.hotjar.com *.mailchimp.com *.list-manage.com *.curator.io *.typekit.net *.clarity.ms *.leadinfo.net *.criteo.com www.googletagmanager.com *.googleadservices.com consent.cookiefirst.com *.cookiefirst.com www.datadoghq-browser-agent.com bat.bing.com *.tidio.co *.tidiochat.com *.iubenda.com js-agent.newrelic.com cdn.curator.io sleeknotecustomerscripts.sleeknote.com www.redditstatic.com embed.sendcloud.sc cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com s7.addthis.com *.multisafepay.com https://pay.google.com www.google.com www.gstatic.com *.sendcloud.sc analytics.google.com unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net *.googleapis.com 'unsafe-inline' data: *.curator.io *.cookiefirst.com fonts.googleapis.com maxcdn.bootstrapcdn.com pay.multisafepay.com cdn.jsdelivr.net tagmanager.google.com *.multisafepay.com *.sendcloud.sc 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src curatorio.s3.amazonaws.com curator-assets.b-cdn.net video-lga3-2.cdninstagram.com video-iad3-1.xx.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.cloudflare.com *.elfsight.com *.instacloud.io *.google-analytics.com *.google.com *.doubleclick.net *.hotjar.com *.hotjar.io ct.pinterest.com *.paypal.com *.zdassets.com *.zendesk.com *.feedbackcompany.com *.curator.io *.clarity.ms *.leadinfo.net *.cookiefirst.com gtm-mm85h6s-nzi2m.uc.r.appspot.com www.google-analytics.com www.google.com maps.googleapis.com *.livechatinc.com dev.visualwebsiteoptimizer.com www.googletagmanager.com pagead2.googlesyndication.com region1.analytics.google.com consent.cookiefirst.com www.redditstatic.com pixel-config.reddit.com edge.cookiefirst.com sendcloud-checkout-static-data.sendcloud.sc https://www.google-analytics.com ekr.zdassets.com/ *.multisafepay.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com k.clarity.ms analytics.sleeknote.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' casabergan.com.br *.casabergan.com.br wake-components.fbitsstatic.net casabergan.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.g.doubleclick.net *.googleadservices.com *.google.com.br stats.g.doubleclick.net a.omappapi.com clarity.ms api.omappapi.com service.yourviews.com.br *.googletagmanager.com *.google-analytics.com googleads.g.doubleclick.net facebook.com connect.facebook.net staticfiles.yviews.com.br *.yourviews.com.br *.yviews.com.br google-analytics.com googletagmanager.com *.lightwidget.com cdn.lightwidget.com *.clarity.ms td.doubleclick.net *.doubleclick.net casabergan.fbitsstatic.net youtube.com *.fbitsstatic.net *.fbits.net pub-gateway.fbits.net *.ucarecdn.com *.comupload.uploadcare.com *.uploadcare.com *.lojaconfiavel.com service2.yourviews.com.br service.yviews.com.br upload.uploadcare.com properties z.omappapi.com *.fbits.store *.jivosite.com server-side-tagging-wvnqi32bba-uc.a.run.app bq-scripts.s3.amazonaws.com *.a.run.app *.vimeo.com *.goadopt.io *.bonifiq.com.br *.adyen.com *.hotjar.com *.mailclick.me *.youtube.com *.properties *.google.ca translate.googleapis.com *.googleapis.com *.google.no google.no google.ca google.com.py *.com.py google.com.au google.be google.bs google.pt google.ro google.com.uy google.ci google.de google.com.ar *.google.be translate-pa.googleapis.com google.com.br googleadservices.com google.com *.google.bs *.pagar.me *.mundipagg.com *.casabergan.com.br vimeo.com *.facebook.net *.facebook.com *.getnet.com.br tagmanager.events tag.goadopt.io *.konfidency.com.br reviews.konfidency.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.lomadee.com secure.lomadee.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net *.googlesyndication.com bt-wake-connector.com.br pagead2.googlesyndication.com *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com localhost:12387 gstatic.com static.fbits.net scripts.fbits.net code.jquery.com wss://vi-ya-8.jivosite.com wss://node-ya-9.jivosite.com wake.koin.com.br *.streamshop.com.br assets.streamshop.com.br *.liveshop.com.br *.hj.contentsquare.net *.contentsquare.net t.contentsquare.net casabergan.liveshop.com.br s3.amazonaws.com api.reclameaqui.com.br paypal-wake.s3.us-east-1.amazonaws.com api.edrone.me d3bo67muzbfgtl.cloudfront.net *.cardinalcommerce.com *.secureacs.com *.edrone.me *.cloudfront.net api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.widde.io cdn.widde.io api-admin.widde.io videos.widde.io *.3dsecure.io *.mailbiz.one *.jsdelivr.net *.ingest.us.sentry.io casabergan.app.n8n.cloud *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.casabergan.com.br casabergan.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ consentcdn.cookiebot.com consentcdn.cookiebot.eu www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://id5-sync.com/ https://bat.bing.com/ https://ad.360yield.com/ https://matching.ivitrack.com/ https://exchange.mediavine.com/ https://jadserve.postrelease.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://trends.revcontent.com/ https://match.sharethrough.com/ https://criteo-partners.tremorhub.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://cm.g.doubleclick.net https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://cm.adform.net/ https://visitor.omnitagjs.com/ https://dis.criteo.com/ https://beacon.krxd.net/ https://gum.criteo.com/ https://s.thebrighttag.com/ https://imgsct.cookiebot.com/ https://assets.adobedtm.com/ https://www.google.pl/ https://hb.yahoo.net/ https://r.casalemedia.com/ https://c1.adform.net/ *.clarity.ms *.bing.com https://pixel.wp.pl/ *.adobedtm.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://embedsocial.com/ https://dynamic.criteo.com/ https://sslwidget.criteo.com/ https://bat.bing.com/ https://tp.convertiser.com/ https://www.clarity.ms/ consent.cookiebot.com consent.cookiebot.eu consentcdn.cookiebot.com pagead2.googlesyndication.com https://pixel.wp.pl/ https://analytics.tiktok.com/ *.mapbox.com https://cdn.jsdelivr.net *.adobedtm.com https://www.googleadservices.com/ https://www.google-analytics.com https://googleads.g.doubleclick.net/ https://analytics.google.com/ https://t.elasticsuite.io/ https://furgonetka.pl https://unpkg.com furgonetka.pl webetech.pl webep1.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.snrcdn.net *.snrbox.com *.ekomiapps.de *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://embedsocial.com/ *.mapbox.com *.jsdelivr.net https://unpkg.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.clarity.ms consentcdn.cookiebot.com consentcdn.cookiebot.eu https://www.google.com https://googleads.g.doubleclick.net/ *.criteo.com/ https://analytics.tiktok.com/ https://pixel.wp.pl/ https://api.furgonetka.pl/ https://c.furgonetka.pl/ https://unpkg.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' OculosMeninaFlor.com.br *.OculosMeninaFlor.com.br wake-components.fbitsstatic.net lotusoculos.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com konduto.com googleadservices.com hotjar.io criteo.net online-metrix.net reduza.com.br criteo.com traycheckout.com.br hertzen.com k-analytix.com hotjar.com clearsale.com.br doubleclick.net yapay.com.br cloudflare.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.googleadservices.com *.konduto.com *.hotjar.io *.criteo.net *.online-metrix.net *.reduza.com.br *.criteo.com *.traycheckout.com.br *.hertzen.com *.k-analytix.com *.cloudflare.com *.clearsale.com.br *.doubleclick.net *.yapay.com.br *.hotjar.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.yourviews.com.br *.clearsale.com.br *.compreconfie.com.br *.voxus.com.br *.voxus.tv *.ipify.org *.loggly.com *.targeting.voxus.com.br dzpxyxks1bfmb.cloudfront.net *.getblue.io *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com gstatic.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io cdn.widde.io *.widde.io api-admin.widde.io storage.googleapis.com *.googleapis.com videos.widde.io recursos.oculosmeninaflor.com.br *.oculosmeninaflor.com.br lotusoculos.fbitsstatic.net *.fbitsstatic.net *.fbits.net static.fbits.net static.criteo.net *.visa.com player.vimeo.com *.vimeo.com o4509708062818304.ingest.us.sentry.io *.ingest.us.sentry.io *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.OculosMeninaFlor.com.br OculosMeninaFlor.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.gstatic.com apis.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com https://chatbot.oteroindustrial.cl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://aheadworks.com maps.gstatic.com maps.googleapis.com cdn.rawgit.com/googlemaps/ cdn.jsdelivr.net/gh/googlemaps/ *.facebook.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.alothemes.com *.magepow.com https://chatbot.oteroindustrial.cl *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net maps.googleapis.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.alothemes.com *.magepow.com https://chatbot.oteroindustrial.cl *.hsforms.net *.hsforms.com https://www.googletagmanager.com tagmanager.google.com *.redditstatic.com *.reddit.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net assets.braintreegateway.com *.alothemes.com *.magepow.com https://chatbot.oteroindustrial.cl tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io maps.googleapis.com *.google-analytics.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.alothemes.com *.magepow.com https://chatbot.oteroindustrial.cl t.elasticsuite.io *.hsforms.net *.hsforms.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' ValordoConhecimento.com.br *.ValordoConhecimento.com.br wake-components.fbitsstatic.net valordoconhecimento.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net *.valordoconhecimento.com.br *.ecommercegateway.com.br *.opolen.com.br *.addthis.com *.yapay.com.br k-analytix.com *.k-analytix.com i.konduto.com *.traycheckout.com.br *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.ValordoConhecimento.com.br ValordoConhecimento.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' data: 'unsafe-inline' https://maxcdn.bootstrapcdn.com https://www.google-analytics.com https://stats.g.doubleclick.net https://dc.services.visualstudio.com; script-src 'self' 'unsafe-inline' https://maxcdn.bootstrapcdn.com https://www.google-analytics.com https://www.googletagmanager.com https://ajax.googleapis.com https://*.msecnd.net; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; sandbox allow-forms allow-same-origin allow-scripts; 1 font-src www.paypalobjects.com fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net cdn2.booqable.com embed.tawk.to data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.addthis.com www.youtube.com js.mollie.com *.sendcloud.sc *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com cdn.usefathom.com www.google.nl www.google.be www.google.pl www.google.se www.google.es www.google.ro www.google.md www.google.co.uk doubleclick.net stats.g.doubleclick.net cdn3.booqable.com cdn2.booqable.com metrics.masta.nl yt3.ggpht.com www.youtube.com www.huren.nl region1.analytics.google.com https://www.mollie.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io *.shopify.com cdn.jsdelivr.net cdn.cookie-script.com cdn.usefathom.com embed.tawk.to static.cloudflareinsights.com metrics.masta.nl 277ac9cf-07c8-40a2-9abc-40d0ce12c492.assets.booqable.com cdn2.booqable.com www.youtube.com static.doubleclick.net www.google.com www.gstatic.com js.mollie.com *.sendcloud.sc *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net cdn2.booqable.com www.youtube.com embed.tawk.to tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://get.geojs.io *.avada.io va.tawk.to embed.tawk.to wss://*.tawk.to bat.bing.com metrics.masta.nl 277ac9cf-07c8-40a2-9abc-40d0ce12c492.booqable.store googleads.g.doubleclick.net jnn-pa.googleapis.com www.youtube.com rr2---sn-5hnekn7s.googlevideo.com play.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://masta.report-uri.com/a/d/g; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://connect.facebook.net https://*.stripe.com https://*.braintreegateway.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.youtube.com https://s.ytimg.com https://*.weeecdn.com https://*.weeecdn.net https://*.tiktok.com https://*.clarity.ms https://*.cloudfront.net https://*.awswaf.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.weeecdn.com https://*.weeecdn.net; img-src 'self' data: blob: https://*.weeecdn.com https://*.weeecdn.net https://weee.pics https://*.masgusto.net https://*.google-analytics.com https://*.doubleclick.net https://*.facebook.com https://*.stripe.com https://*.youtube.com https://*.ytimg.com https://cdn.cookielaw.org https://*.anycart.com https://*.masgusto.com https://*.masgusto.net https://static.weeecdn.com https://static.weeecdn.net; font-src 'self' data: https://fonts.gstatic.com https://*.weeecdn.com https://*.weeecdn.net; connect-src 'self' wss://*.sayweee.com https://*.sayweee.com wss://*.sayweee.net https://*.sayweee.net wss://*.masgusto.com https://*.masgusto.com wss://*.masgusto.net https://*.masgusto.net https://*.google-analytics.com https://*.google.com https://region1.google-analytics.com https://*.facebook.com https://*.stripe.com https://*.braintreegateway.com https://*.onetrust.com https://*.googleapis.com https://*.gstatic.com https://*.tiktok.com https://*.weeecdn.com https://*.weeecdn.net https://cdn.cookielaw.org https://*.cloudflare.com https://*.awswaf.com https://*.clarity.ms https://*.masgusto.com https://*.masgusto.net https://www.masgusto.com https://click.masgusto.com; media-src 'self' https://*.sayweeecdn.com https://*.youtube.com https://*.tiktok.com; object-src 'none'; frame-src https://*.stripe.com https://hooks.stripe.com https://assets.braintreegateway.com https://*.youtube.com https://*.google.com https://*.facebook.com https://*.tiktok.com https://cdn.cookielaw.org; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; worker-src 'self' blob:; manifest-src 'self'; upgrade-insecure-requests; report-uri https://api.masgusto.net/ec/bff/report/csp-violation; report-to csp-endpoint 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.iris.dias.com.gr *.test-iris.dias.com.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.addthis.com *.intuit.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.calc.tbibank.gr *.google.gr ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.gstatic.com https://translate.googleapis.com https://fonts.gstatic.com http://translate.google.com *.adobe.com *.disqus.com https://firebasestorage.googleapis.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.calc.tbibank.gr *.addthis.com *.addthisedge.com *.moatads.com s3.amazonaws.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://translate.googleapis.com http://translate.google.com www.googletagmanager.com https://translate-pa.googleapis.com *.disqus.com *.avada.io https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com www.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.addthis.com *.google.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://translate.googleapis.com *.googleapis.com *.googleadservices.com *.googletagmanager.com *.sandbox.paypal.com *.paypalobjects.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.addthis.com *.facebook.com *.twitter.com www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.addthisedge.com *.twitter.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com int-ecommerce.nexi.it ecommerce.nexi.it www.google.com www.gstatic.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com maps.googleapis.com cdn.ampproject.org connect.facebook.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com downloads.mailchimp.com maxcdn.bootstrapcdn.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com int-ecommerce.nexi.it ecommerce.nexi.it places.googleapis.com cdn.ampproject.org 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; connect-src https: wss:; report-uri /csp-report 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-Mw/hCYVWiU/L6q0WN6HVCPFfsYs=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' *.sitepen.com; base-uri 'self'; child-src *; connect-src 'self' stats.g.doubleclick.net www.google-analytics.com region1.google-analytics.com; font-src 'self' fonts.gstatic.com use.typekit.net; form-action 'self'; frame-ancestors 'self'; frame-src *; img-src *; media-src *; object-src 'self'; report-to default; report-uri https://sitepen.report-uri.com/r/d/csp/reportOnly; script-src 'self' 'unsafe-inline' www.google-analytics.com player.vimeo.com; script-src-elem 'self' 'unsafe-inline' www.google-analytics.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com; worker-src 'self' 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.gstatic.com https://*.cloudflare.com/ https://conoret.com/ https://*.facebook.net/ https://*.sentry-cdn.com/ https://*.cookielaw.org/ https://*.mouseflow.com/ https://chimpstatic.com/ https://*.chimpstatic.com/ https://*.mailchimp.com/ https://*.myfonts.net/ https://*.fontawesome.com/ https://*.list-manage.com/ https://*.paytrace.com/ https://*.getsitecontrol.com/ https://*.google-analytics.com/ https://*.googletagmanager.com/; style-src 'report-sample' 'self' 'unsafe-inline' data: https://*.gstatic.com https://*.mailchimp.com/ https://*.googleapis.com/; object-src 'self'; base-uri 'self'; connect-src 'self' https://dt.spinneybeck.com https://*.googleapis.com https://updates.expressionengine.com https://*.getsitecontrol.com/ https://*.scamsniffer.io/ https://*.onetrust.com/ https://*.cookielaw.org/ https://*.fontawesome.com/ https://*.sentry.io/ https://*.doubleclick.net/ https://*.google-analytics.com/ https://*.amcreativemedia.com/; font-src 'self' data: https://*.flaticon.com https://*.designmanager.com/ https://*.gstatic.com/ https://*.cookielaw.org/ https://*.fontawesome.com/ https://*.getsitecontrol.com/ https://*.typekit.net/; frame-src 'self' https://filzfelt.us6.list-manage.com https://*.vimeo.com/ https://*.paytrace.com/; img-src 'self' data: blob: https://cdn.cookielaw.org https://mcusercontent.com/ https://*.mailchimp.com/ https://*.google.com/ https://*.gstatic.com/ https://*.pinterest.com/ https://*.fontawesome.com/ https://*.getsitecontrol.com/ https://*.google-analytics.com/ https://*.googletagmanager.com/ https://*.eeharbor.com/ https://*.vimeocdn.com/; manifest-src 'self'; media-src 'self'; worker-src blob:; report-uri https://o236859.ingest.sentry.io/api/4506139720548352/security/?sentry_key=76260eda922e4376c52c41c8eb5341c8 1 default-src 'self' *.googleapis.com *.gstatic.com www.openstreetmap.org secure.ogone.com *.youtube.com player.vimeo.com *.vimeocdn.com *.tolkie.nl; report-uri /cspreport; script-src 'self' 'unsafe-inline' 'unsafe-eval' code.jquery.com ajax.aspnetcdn.com *.google-analytics.com translate.google.com *.readspeaker.com *.googleapis.com www.openlayers.org openlayers.org *.openstreetmap.org *.typekit.net www.googletagmanager.com matomoembraceklantportaal.azurewebsites.net matomoembracewin.azurewebsites.net *.matomo.cloud *.cookiebot.com *.tolkie.nl cdnjs.cloudflare.com embed.email-provider cdn.cookie-script; connect-src 'self' *.typekit.net *.google-analytics.com *.stats.g.doubleclick.net *.umbraco.org *.openstreetmap.org *.googleapis.com *.analytics.google.com ws://lefier.nl matomoembraceklantportaal.azurewebsites.net matomoembracewin.azurewebsites.net *.matomo.cloud consent.cookiebot.com *.tolkie.nl cdnjs.cloudflare.com embed.email-provider analytics.google.com; img-src 'self' data: *.umbraco.org umbraco.tv www.gravatar.com pbs.twimg.com cdn.jsdelivr.net *.typekit.net *.google-analytics.com placehold.it *.gstatic.com www.google.com translate.googleapis.com *.googleapis.com *.openstreetmap.org www.openlayers.org openlayers.org api.maptiler.com umbracowebportalsnonprod.azureedge.net *.analytics.google.com www.googletagmanager.com umbracowebportalsprod.azureedge.net umbracowebportalsprod.blob.core.windows.net *.cookiebot.com *.tolkie.nl; media-src 'self' ; font-src 'self' data: *.typekit.net *.gstatic.com *.tolkie.nl cdnjs.cloudflare.com cdn.faceworks.nl ; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com www.openlayers.org openlayers.org www.gstatic.com *.readspeaker.com *.cloudflare.com *.tolkie.nl; frame-ancestors 'self' ; 1 connect-src 'self' https://www.google.com/recaptcha/ https://cdn-ukwest.onetrust.com/ https://geolocation.onetrust.com/ https://www.googleadservices.com https://googleads.g.doubleclick.net https://google.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://www.google.co.uk/ads/ga-audiences https://pagead2.googlesyndication.com https://privacyportal-uk.onetrust.com https://px.ads.linkedin.com https://bat.bing.com https://bat.bing.net https://www.facebook.com/privacy_sandbox/topics/registration/; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://www.googletagmanager.com/ https://go.arbuthnotlatham.co.uk/ https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://charts3.equitystory.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://tagmanager.google.com https://bat.bing.com https://cdn-ukwest.onetrust.com https://connect.facebook.net https://snap.licdn.com https://use.typekit.net https://p.typekit.net https://go.arbuthnotlatham.co.uk https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.googletagmanager.com https://www.youtube.com https://player.vimeo.com https://ajax.googleapis.com https://pi.pardot.com/analytics cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://use.typekit.net https://p.typekit.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.arbuthnotlatham.co.uk/log-report-uri/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com maxcdn.bootstrapcdn.com *.googleapis.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.google.com *.weltpixel.com https://plumrocket.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com *.analytics.google.com *.equiline.it *.google-analytics.com *.google.it ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.googleapis.com *.iubenda.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google-analytics.com *.hotjar.com unsafe-inline chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.iubenda.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app unsafe-inline downloads.mailchimp.com maxcdn.bootstrapcdn.com *.googleapis.com https://fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com * https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.googlesyndication.com *.equiline.it form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem https://jkb-1.stage-ecombox.com https://bat.bing.com https://www.clarity.ms https://app.jkb.test https://jkb-1.test-ecombox.com https://jkb-pl.test-ecombox.com https://jkb-en.test-ecombox.com https://jkb-fr.test-ecombox.com https://jkb-de.test-ecombox.com https://jkb-it.test-ecombox.com https://jkb-pl.stage-ecombox.com https://jkb-en.stage-ecombox.com https://jkb-fr.stage-ecombox.com https://jkb-de.stage-ecombox.com https://jkb-it.stage-ecombox.com https://fairytrees.pl https://fairytrees.eu https://fairytrees.fr https://fairytrees.de https://fairytrees.it https://widget.trustpilot.com https://js.stripe.com https://invitejs.trustpilot.com https://www.googletagmanager.com https://www.salesmanago.pl https://www.google.com https://www.gstatic.com https://static.hotjar.com https://connect.facebook.net https://script.hotjar.com https://app.avada.io https://googleads.g.doubleclick.net https://integrations.etrusted.com 'unsafe-inline' https://elfsightcdn.com https://widgets.trustedshops.com https://scripts.clarity.ms; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.googletagmanager.com secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://www.google.pl https://bat.bing.com https://c.clarity.ms https://c.bing.com https://app.jkb.test https://jkb-1.test-ecombox.com https://jkb-pl.test-ecombox.com https://jkb-en.test-ecombox.com https://jkb-fr.test-ecombox.com https://jkb-de.test-ecombox.com https://jkb-it.test-ecombox.com https://jkb-pl.stage-ecombox.com https://jkb-en.stage-ecombox.com https://jkb-fr.stage-ecombox.com https://jkb-de.stage-ecombox.com https://jkb-it.stage-ecombox.com https://fairytrees.pl https://fairytrees.eu https://fairytrees.fr https://fairytrees.de http://magento.jkb-group.com https://magento.jkb-group.com https://phosphor.utils.elfsightcdn.com https://widgets.trustedshops.com static.payu.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com mageside.com *.hsforms.net *.hsforms.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com www.gstatic.com/recaptcha/ www.google.com/recaptcha/ *.googletagmanager.com *.hotjar.com secure.payu.com secure.snd.payu.com *.disqus.com *.avada.io *.hsforms.net *.hsforms.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-eval' *.etrusted.com integrations.etrusted.com magento.jkb-group.com vc.hotjar.io *.elfsightcdn.com *.trustedshops.com scripts.clarity.ms *.shopify.com *.amazon.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://p.clarity.ms https://widget.trustpilot.com https://invitejs.trustpilot.com https://content.hotjar.io wss://ws.hotjar.com https://e.clarity.ms https://google.com https://vc.hotjar.io https://bat.bing.com https://k.clarity.ms https://core.service.elfsight.com https://widget-data.service.elfsight.com secure.payu.com merch-prod.snd.payu.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://abgtr7ca.uriports.com/reports/report; report-to default; connect-src 'self' https://vz-865b183f-ef4.b-cdn.net https://analytics.weddybird.com https://www.googletagmanager.com https://pagead2.googlesyndication.com https://www.googleadservices.com https://www.google.com https://google.com https://*.google-analytics.com https://*.analytics.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://consentcdn.cookiebot.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://consent.cookiebot.eu https://beaconapi.helpscout.net https://chatapi.helpscout.net https://d3hb14vkzrxvla.cloudfront.net wss://*.pusher.com https://s.pinimg.com https://ct.pinterest.com https://analytics.tiktok.com https://bat.bing.com https://www.facebook.com https://www.facebook.net https://connect.facebook.net https://api.refiner.io https://api.rollbar.com https://*.paypal.com https://*.paypalobjects.com https://*.venmo.com; font-src 'self' https://cdn.wbsrv.de https://fonts.bunny.net data: https://fonts.gstatic.com https://beacon-v2.helpscout.net; frame-src 'self' https://preview.weddybird.com/ https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com https://td.doubleclick.net https://www.facebook.com https://www.facebook.net https://connect.facebook.net https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu https://beacon-v2.helpscout.net https://s.pinimg.com https://ct.pinterest.com https://js.refiner.io https://*.paypal.com https://*.paypalobjects.com https://*.venmo.com https://sibforms.com/ https://*.sibforms.com/; manifest-src 'self'; media-src 'self' blob: https://vz-865b183f-ef4.b-cdn.net https://beacon-v2.helpscout.net; style-src 'self' 'unsafe-inline' https://cdn.wbsrv.de https://fonts.bunny.net https://www.googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://beacon-v2.helpscout.net https://js.refiner.io https://storage.refiner.io https://*.paypal.com https://*.paypalobjects.com https://*.venmo.com; form-action 'self' https://www.facebook.com https://www.mollie.com 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ; base-uri 'self' ; style-src 'self' 'unsafe-inline' https://www.gstatic.com https://*.googleapis.com https://maxcdn.bootstrapcdn.com ; font-src 'self' data: https://*.googleapis.com https://*.gstatic.com https://maxcdn.bootstrapcdn.com ; img-src 'self' data: https://www.imvrs.com https://data.pendo.io https://fonts.gstatic.com https://translate.google.com https://verify.authorize.net ; frame-ancestors 'self' ; frame-src 'self' https://www.googletagmanager.com https://static.novacredit.com https://app.verifast.com https://sandbox.verifast.com https://www.youtube.com https://data.pendo.cio https://*.storage.googleapis.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.rhris.com https://www.rhrtest.com https://www.googletagmanager.com https://seal.godaddy.com https://ajax.googleapis.com https://cdn.pendo.io https://static.novacredit.com https://verify.authorize.net https://*.storage.googleapis.com ; connect-src 'self' https://data.pendo.io https://*.storage.googleapis.com https://*.googleapis.com https://www.google-analytics.com ; report-uri https://www.rhrtest.com/test/csp-violation-report-endpoint.cfm ; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.gstatic.com data: *.kxcdn.com *.stape.io https://use.typekit.net https://*.fontawesome.com script.hotjar.com sf-static-content.s3.us-east-1.amazonaws.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io consentcdn.cookiebot.com browser-intake-us3-datadoghq.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://maps.gstatic.com *.googleapis.com scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.google.com *.cdninstagram.com *.fbcdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.stape.io https://p.typekit.net https://maps.googleapis.com www.statlab.com marketing.statlab.com app.usercentrics.eu uct.service.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sce.toogoerp.net sce.toogo.io *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net *.stape.io https://devdocs.magento.com https://magento.com https://maps.googleapis.com https://www.youtube.com https://*.ctctcdn.com consentcdn.cookiebot.com static.hotjar.com 359532.tctm.co d1stxfv94hrhia.cloudfront.net consent.cookiebot.com script.hotjar.com waves.retentionscience.com wss://ws.hotjar.com browser-intake-us3-datadoghq.com assets.adobetm.com web.cmp.usercentrics.eu www.datadoghq-browser-agent.com marketing.statlab.com td.doubleclick.net form-element-use1-prod.salesfusion.com static.zdassets.com www.statlab.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com assets.braintreegateway.com *.googletagmanager.com *.stape.io https://devdocs.magento.com https://*.typekit.net https://fonts.googleapis.com https://*.ctctcdn.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://api-public.addthis.com https://maps.googleapis.com https://graphql.usercentrics.eu https://*.ctctcdn.com googleads.g.doubleclick.net stats.g.doubleclick.net consentcdn.cookiebot.com content.hotjar.io ws.hotjar.com metrics.hotjar.io browser-intake-us3-datadoghq.com v1.api.service.cmp.usercentrics.eu graphql.usercentrics.eu wss://ws.hotjar.com ekr.zdassets.com pages-backend.msgapp.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.fontawesome.com https://widgets.trustedshops.com https://static.unzer.com https://applepay.cdn-apple.com fonts.gstatic.com https://fonts.gstatic.com https://fonts.googleapis.com static.klaviyo.com https://cdnjs.cloudflare.com/ https://d362h7pxdteoyk.cloudfront.net/ https://cdn.popt.in/ https://s3.us-west-2.amazonaws.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com *.sendcloud.sc *.jsdelivr.net https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.ad-srv.net https://r.adserver01.de https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.amazonaws.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://www.geschenkefuerfreunde.de *.usercentrics.eu https://www.google.com https://www.google.com.ua https://integrations.etrusted.com https://app.popt.in/ https://d3lopmpcew67el.cloudfront.net/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net *.googletagmanager.com tagmanager.google.com *.adcell.com *.usercentrics.eu *.ad-srv.net *.online-metrix.net https://cdn.popt.in/pixel.js https://cdnjs.cloudflare.com/ https://cdn.brevo.com/ https://sibautomation.com/sa.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com tagmanager.google.com fonts.google.com https://fonts.googleapis.com https://integrations.etrusted.com https://fonts.popt.in https://tctguyhimcwcyexxgullu3seem0fkhrh.lambda-url.us-west-2.on.aws/ https://cdn.popt.in/ https://cdnjs.cloudflare.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.usercentrics.eu *.adcell.com https://stats.g.doubleclick.net *.googlesyndication.com wss://127.0.0.1 https://display.popt.in/ https://d3lopmpcew67el.cloudfront.net/ https://in-automate.brevo.com https://www.google.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://assets.adobedtm.com https://customer.cludo.com https://ds-aksb-a.akamaihd.net https://s.ytimg.com https://www.youtube.com https://e.issuu.com https://irs.tools.investis.com https://otp.tools.investis.com https://c.evidon.com https://www.googletagmanager.com https://t.contentsquare.net https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://www.gstatic.com https://fonts.googleapis.com https://otp.tools.investis.com; img-src 'self' data: https: ; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://otp.tools.investis.com; connect-src 'self' https://clydesdalebank.tt.omtrdc.net https://clydesdalebank.d3.sc.omtrdc.net https://dpm.demdex.net https://ds-aksb-a.akamaihd.net https://api-eu1.cludo.com https://api.cludo.com https://www.google.com https://irs.tools.investis.com https://c.evidon.com https://l.evidon.com https://dgcollector.evidon.com https://optoutapi.evidon.com https://dgvendorhostapi.evidon.com; media-src 'self'; object-src 'self'; worker-src 'self' blob:; frame-src 'self' https://clydesdalebankplc.demdex.net https://secure.flife.de https://otp.tools.investis.com https://irs.tools.investis.com https://clydesdale-bank.production.investis.com https://www.youtube.com https://e.issuu.com https://player.vimeo.com https://embeds.audioboom.com; frame-ancestors 'self' *.virginmoney.com; report-uri https://cyburi.report-uri.com/r/t/csp/reportOnly; 1 font-src *.cloudflare.com *.bootstrapcdn.com *.gstatic.com *.googleapis.com 'unsafe-inline' data: https://widgets.trustedshops.com https://integrations.etrusted.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com https://*.dpdconnect.nl *.demdex.net *.googletagmanager.com *.doubleclick.net/ *.weltpixel.com *.multisafepay.com https://pay.google.com *.pinterest.com *.cookiebot.com *.google.com *.adobe.com *.paypal.com *.dpdconnect.nl *.cardinalcommerce.com *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trustedshops.com *.clarity.ms *.roeye.com *.multisafepay.com https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com *.bing.com www.google.be *.pinterest.com *.google-analytics.com *.googleadservices.com *.paypal.com *.google.com *.google.be *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://*.dpdconnect.nl *.cloudflare.com *.twitter.com *.fontawesome.com *.trustedshops.com chimpstatic.com *.google.com *.gstatic.com *.clarity.ms *.hotjar.com *.multisafepay.com https://pay.google.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com tagmanager.google.com *.cookiebot.com www.dwin1.com *.pinimg.com *.facebook.net *.bing.com *.tiktok.com *.googleadservices.com *.google-analytics.com *.paypal.com *.googleapis.com *.dpdconnect.nl *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net 'unsafe-inline' data: *.googletagmanager.com *.multisafepay.com https://widgets.trustedshops.com https://integrations.etrusted.com tagmanager.google.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.cloudflare.com *.demdex.net *.clarity.ms *.multisafepay.com *.trustedshops.com *.etrusted.com https://www.google-analytics.com www.google.com *.doubleclick.net *.pinterest.com *.bing.com *.tiktok.com *.cookiebot.com *.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-br47OGlWGT4a51DlLBxCk8VzKJM=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src sundberguat-m2-cdn.azureedge.net sundbergprd-m2-cdn.azureedge.net *.gstatic.com *.fonts.gstatic.com *.hawksearch.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com batchgeo.com https://spins0.arqspin.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.trackedlink.net *.ddlnk.net sundberguat-m2-cdn.azureedge.net sundbergprd-m2-cdn.azureedge.net *.repairclinic.com *.www.stageimages.repairclinic.com https://spins0.arqspin.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com sundberguat-m2-cdn.azureedge.net sundbergprd-m2-cdn.azureedge.net *.googleapis.com *.ajax.googleapis.com *.hawksearch.net https://www.sundbergamerica.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com sundberguat-m2-cdn.azureedge.net sundbergprd-m2-cdn.azureedge.net manage.hawksearch.com *.googleapis.com *.fonts.googleapis.com *.hawksearch.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com https://www.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.googleapis.com https://firebasestorage.googleapis.com https://www.mollie.com *.google.co.uk *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.shopify.com js.mollie.com https://static.cloudflareinsights.com https://www.google.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-MGY0NThhOTktMzZhNy00YmFmLWJkY2EtNWUwMDgyNTIzZjky' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 default-src 'self'; script-src 'self' https://analytics.tiktok.com https://bat.bing.com https://cdn-3.convertexperiments.com https://cdn-4.convertexperiments.com https://cdn.cookielaw.org https://cdn.debugbear.com https://cdn.ometria.com https://script.hotjar.com https://code.jquery.com https://connect.facebook.net https://googleads.g.doubleclick.net https://p.teads.tv https://s.pinimg.com https://script.hotjar.com https://static.hotjar.com https://unpkg.com https://widget.trustpilot.com https://www.bing.com https://js.klarna.com https://payments.worldpay.com https://rum-static.pingdom.net https://www.awin1.com https://www.dwin1.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://app.convert.com https://ct.pinterest.com https://no-cdn.convertexperiments.com https://r.bing.com https://apis.google.com https://js.playground.klarna.com https://translate-pa.googleapis.com https://translate.google.com https://translate.googleapis.com https://www.google-analytics.com https://pagead2.googlesyndication.com https://*.ssl.ak.dynamic.tiles.virtualearth.net https://www.flyingflowers.co.uk https://www.interflora.ie https://www.interflora.co.uk https://www.paypal.com https://static.zdassets.com 'report-sample'; script-src-attr 'self'; script-src-elem 'self' https://cdn-4.convertexperiments.com https://www.paypal.com https://atlas.microsoft.com https://static.zdassets.com https://www.googletagmanager.com https://www.dwin1.com https://widget.trustpilot.com https://unpkg.com https://static.hotjar.com https://script.hotjar.com https://s.pinimg.com https://rum-static.pingdom.net https://js.klarna.com https://googleads.g.doubleclick.net https://ct.pinterest.com https://connect.facebook.net https://cdn.ometria.com https://cdn.debugbear.com https://cdn.cookielaw.org https://bat.bing.com https://analytics.tiktok.com https://payments.worldpay.com; connect-src 'self' https://hpp.worldpay.com https://*.metrics.convertexperiments.com https://ekr.zdassets.com https://ad.doubleclick.net https://analytics.tiktok.com https://ask.hotjar.io https://bat.bing.com https://cdn-3.convertexperiments.com https://cdn.cookielaw.org https://cdn.debugbear.com https://cm.teads.tv https://content.hotjar.io https://ct.pinterest.com https://data.debugbear.com https://googleads.g.doubleclick.net https://in.hotjar.com https://insights.algolia.io https://l.teads.tv https://logs.convertexperiments.com https://metrics.hotjar.io https://msn7pvpzhu-1.algolianet.com https://msn7pvpzhu-2.algolianet.com https://msn7pvpzhu-3.algolianet.com https://msn7pvpzhu-dsn.algolia.net https://stats.g.doubleclick.net https://surveystats.hotjar.io https://t.teads.tv https://trk.ometria.com https://unpkg.com https://vc.hotjar.io https://widget.trustpilot.com wss://ws.hotjar.com https://www.bing.com https://www.facebook.com https://media.interflora.co.uk https://apis.google.com https://cdn.ometria.com https://geolocation.onetrust.com https://payments.worldpay.com https://privacyportal-eu.onetrust.com https://rum-collector-2.pingdom.net https://rum-static.pingdom.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://uksouth-0.in.applicationinsights.azure.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://o4506853695881216.ingest.us.sentry.io https://*.playground.klarnaevt.com https://adservice.google.com https://cdn-4.convertexperiments.com https://connect.facebook.net https://js.klarna.com https://js.playground.klarna.com https://oc.klarnaevt.com https://eu.klarnaevt.com https://region1.analytics.google.com https://analytics.google.com https://api.edq.com https://bat.bing.net https://dev.virtualearth.net https://translate.googleapis.com https://translate-pa.googleapis.com https://www.google.co.uk https://na.klarnaevt.com https://atlas.microsoft.com https://na.klarnaevt.com https://www.interflora.ie https://www.flyingflowers.co.uk https://dc.services.visualstudio.com https://www.awin1.com https://www.googleadservices.com https://wepowerconnections.com https://fonts.gstatic.com https://google.com https://www.paypal.com https://analytics-ipv6.tiktokw.us https://www.sandbox.paypal.com https://cdn.media.amplience.net https://o24547.ingest.sentry.io; style-src 'self' 'unsafe-inline'; frame-src 'self' https://*.fls.doubleclick.net https://match.adsrvr.org https://ct.pinterest.com https://hpp.worldpay.com https://js.klarna.com https://payments.worldpay.com https://td.doubleclick.net https://widget.trustpilot.com https://www.awin1.com https://www.facebook.com https://js.klarna.com https://pay.klarna.com https://www.paypal.com https://www.googletagmanager.com https://www.sandbox.paypal.com; img-src 'self' data: https://www.interflora.co.uk https://media.interflora.co.uk https://ad.doubleclick.net https://analytics.tiktok.com https://bat.bing.com https://cdn.cookielaw.org https://cm.teads.tv https://connect.facebook.net https://googleads.g.doubleclick.net https://l.teads.tv https://stats.g.doubleclick.net https://t.teads.tv https://trk.ometria.com https://www.awin1.com https://www.bing.com https://www.facebook.com https://logs.convertexperiments.com https://adservice.google.com https://media.flyingflowers.co.uk https://translate.google.com https://www.flyingflowers.co.uk https://www.googletagmanager.com https://t.ssl.ak.dynamic.tiles.virtualearth.net https://interflora.a.bigcontent.io https://ade.googlesyndication.com https://www.wepowerconnections.com https://eu.fareye.co https://cdn.media.amplience.net https://media.interflora.ie https://www.interflora.ie https://fonts.gstatic.com https://www.google.co.uk https://www.google.com https://pagead2.googlesyndication.com https://bat.bing.net https://analytics-ipv6.tiktokw.us https://google.com https://www.googleadservices.com; form-action 'self' https://payments.worldpay.com; worker-src 'self'; report-uri https://flyingflowers.report-uri.com/r/t/csp/reportOnly; 1 default-src 'self'; report-uri /csp-violations 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://cdn-cookieyes.com https://cdn.weglot.com https://script.hotjar.com https://static.hotjar.com https://a3.mylivechat.com https://mylivechat.com https://ws.zoominfo.com https://tags.clickagy.com https://cm.g.doubleclick.net https://td.doubleclick.net https://d-code.liadm.com https://rp.liadm.com https://idx.liadm.com https://i.liadm.com https://hemsync.clickagy.com https://dpm.demdex.net https://idsync.rlcdn.com https://js.zi-scripts.com https://snap.licdn.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://bat.bing.com https://www.google.com https://www.gstatic.com https://code.tidio.co https://api.livechatinc.com https://cdn.livechatinc.com https://wordpress.livechat.com https://analytics.ahrefs.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' data: https://fonts.gstatic.com https://code.tidio.co https://openit.com; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://browser.pipe.aria.microsoft.com https://www.google.com https://stats.g.doubleclick.net https://px.ads.linkedin.com https://vc.hotjar.io https://metrics.hotjar.io https://www.facebook.com https://js.zi-scripts.com https://ws.zoominfo.com https://aorta.clickagy.com https://hemsync.clickagy.com https://idx.liadm.com https://rp.liadm.com https://log.cookieyes.com https://cdn-cookieyes.com https://analytics.ahrefs.com wss://socket.tidio.co; img-src 'self' data: blob: https://openit.com https://www.openit.com https://www.google-analytics.com https://px.ads.linkedin.com https://i.liadm.com https://www.google.com https://www.google.com.ph https://cdn.weglot.com https://www.facebook.com https://bat.bing.com https://cdnjs.cloudflare.com https://staging.analyzer4a.com https://www.googletagmanager.com https://cdn-cookieyes.com https://aorta.clickagy.com https://idsync.rlcdn.com https://us-u.openx.net https://pixel-sync.sitescout.com https://aa.agkn.com; frame-src 'self' https://talentit.openit.com https://www.youtube.com https://www.facebook.com https://td.doubleclick.net https://www.googletagmanager.com https://i.liadm.com https://www.google.com; media-src 'self' https://code.tidio.co; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; 1 font-src *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.ca-dev.co *.chargeafter.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca https://cdn-sandbox.ca-dev.co https://cdn.chargeafter.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca https://cdn-sandbox.ca-dev.co https://cdn.chargeafter.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.authorize.net test.authorize.net js.authorize.net jstest.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.ca-dev.co *.chargeafter.com http://dpm.demdex.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com apitest.authorize.net jstest.authorize.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; default-src 'none'; child-src; connect-src 'self' https://rec.smartlook.com http://rec.smartlook.com rec.smartlook.com https://forms.hsforms.com; font-src 'self' https://fonts.gstatic.com http://fonts.gstatic.com fonts.gstatic.com https://use.typekit.net http://use.typekit.net use.typekit.net data:; form-action 'self' https://*.twitter.com http://*.twitter.com *.twitter.com https://forms.hsforms.com; frame-ancestors 'none'; frame-src https://iframe.videodelivery.net https://youtube.com https://www.youtube.com https://forms.hsforms.com https://*.twitter.com http://*.twitter.com *.twitter.com https://*.doubleclick.net http://*.doubleclick.net *.doubleclick.net; img-src 'self' https://www.google-analytics.com http://www.google-analytics.com www.google-analytics.com https://www.google.com http://www.google.com www.google.com https://www.google.co.uk http://www.google.co.uk www.google.co.uk https://*.hsforms.com blob: data:; media-src https://youtube.com http://youtube.com youtube.com https://www.youtube.com http://www.youtube.com www.youtube.com; object-src 'none'; manifest-src 'self'; script-src 'self' https://www.googletagmanager.com http://www.googletagmanager.com www.googletagmanager.com https://www.google-analytics.com http://www.google-analytics.com www.google-analytics.com https://www.googleadservices.com http://www.googleadservices.com www.googleadservices.com https://*.googleapis.com http://*.googleapis.com *.googleapis.com https://*.doubleclick.net http://*.doubleclick.net *.doubleclick.net https://oss.sheetjs.com http://oss.sheetjs.com oss.sheetjs.com https://js.hsforms.net 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.typekit.net http://*.typekit.net *.typekit.net https://*.googleapis.com http://*.googleapis.com *.googleapis.com 'unsafe-inline' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; worker-src 'self' blob:; font-src 'self'; connect-src 'self'; report-uri https://dcc-cspreport.enovation.ie/csp-report-hlane.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.payfabric.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.trustedsite.com *.payfabric.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com acsbapp.com acsbap.com *.acsbapp.com *.acsbap.com https://cdn.ywxi.net https://meetanshi.com/media/logo.png *.payfabric.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.magento-datasolutions.com *.magento-ds.com *.typekit.net google.com *.google.com tagmanager.google.com https://www.googletagmanager.com chimpstatic.com downloads.mailchimp.com *.list-manage.com acsbapp.com acsbap.com *.acsbapp.com *.acsbap.com *.googleapis.com https://cdn.ywxi.net https://www.trustedsite.com *.payfabric.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com acsbapp.com acsbap.com *.acsbapp.com *.acsbap.com *.wikipedia.org *.googleapis.com https://s3-us-west-2.amazonaws.com/mfesecure-public/ https://www.trustedsite.com *.payfabric.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://www.google.com/ https://www.facebook.com/ ; script-src 'self' 'unsafe-inline' http://platform.twitter.com/ https://smarticon.geotrust.com/; child-src 'self' https://www.google.com/; style-src 'self' 'unsafe-inline'; font-src 'self' ; block-all-mixed-content; img-src * data:; object-src 'self' ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com use.typekit.net static.zip.co *.choosewine.com.au *.winedirect.com.au *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.omappapi.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.com bat.bing.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com pos.baidu.com *.baidu.com *.instant.one *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com widgets.sandbox.afterpay.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com use.typekit.net *.typekit.net *.winedirect.com.au *.choosewine.com.au cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com *.instant.one c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.yotpo.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com use.typekit.net *.choosewine.com.au *.adobedtm.com *.winedirect.com.au *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in *.google.co.in *.sc.omtrdc.net cm.everesttech.net *.magentocommerce.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com *.paypalobjects.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ytimg.com static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.sandbox.paypal.com *.swagger.io *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.app bat.bing.com *.adobe.net *.site.com dev-54ta5gq-6zoeclprllyye.ap-3.magentosite.cloud 'self' *.google.bg *.facebook.net *.doubleclick.net *.googlesyndication.com *.instant.one rec.smartlook.com t.cfjump.com img.youtube.com maps.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net t.zip.co cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com static.zip.co data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com *.ytimg.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com use.typekit.net typekit.net choosewine.com.au winedirect.com.au *.winedirect.com.au adobedtm.com adobe.com z.clarity.ms clarity.ms rec.smartlook.com smartlook.com t.cfjump.com cfjump.com zip.co static.zipmoney.com.au zipmoney.com.au tagmanager.google.com www.google.co.in adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com bidswitch.net doubleclick.net casalemedia.com openx.net taboola.com outbrain.com pubmatic.com google-analytics.com 3lift.com rubiconproject.com google.co.in sc.omtrdc.net demdex.net dpm.demdex.net cm.everesttech.net everesttech.net magentocommerce.com widgets.magentocommerce.com googleadservices.com paypalobjects.com t.paypal.com paypal.com ftcdn.net behance.net p.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io gstatic.com sandbox.paypal.com swagger.io afterpay.com facebook.com glopal.com glopalservice.com braintreegateway.com d.adroll.com c.bing.com bing.com googletagmanager.com ib.adnxs.com adnxs.com s3-us-west-2.amazonaws.com amazonaws.com js-agent.newrelic.com newrelic.com sandbox.my.site.com hello.zonos.com zonos.com front.optimonk.co optimonk.co qa.clevertar.app *.clevertar.com bat.bing.com cardinalcommerce.com optimonk.com a.omappapi.com googleapis.com unpkg.com magento-datasolutions.com omtrdc.net vimeocdn.com youtube.com magento-ds.com google.bg facebook.net googlesyndication.com trackedlink.net trackedweb.net ddlnk.net dotdigital-pages.com dhv2ziothpgrr.cloudfront.net yotpo.com yahoo.com instant.one addthis.com dnky.co dotdigital.internal pages.com adobe.net ccdc02.com downloads.mailchimp.com commerce.adobe.net www.gstatic.com/recaptcha/ www.google.com/recaptcha/ portal.sandbox.clearpay.co.uk portal.clearpay.co.uk portal.sandbox.afterpay.com portal.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.dnky.co s7.addthis.com *.instant.one *.choosewine.com.au *.z.clarity.ms *.clarity.ms *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co *.zipmoney.com.au *.adroll.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.googleadservices.com *.paypalobjects.com *.paypal.com *.ftcdn.net *.behance.net *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.stamped.io *.bing.com *.adnxs.com *.amazonaws.com *.sandbox.my.site.com *.zonos.com *.optimonk.co *.clevertar.app *.cardinalcommerce.com *.optimonk.com *.googleapis.com *.unpkg.com *.omtrdc.net *.dhv2ziothpgrr.cloudfront.net *.yotpo.com *.yahoo.com *.addthis.com *.dnky.co *.dotdigital.internal *.pages.com *.vimeo.com *.adobe.net *.ccdc02.com js.braintreegateway.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com pos.baidu.com *.baidu.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ static.zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com webchat.dotdigital.com webchat.staging.dotdigital.com static.zip.co *.winedirect.com.au *.a.omappapi.com *.clevertar.app *.choosewine.com.au *.cardinalcommerce.com *.googleapis.com *.googlesyndication.com *.dnky.co *.instant.one a.omappapi.com static.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com cdn.dnky.co *.yotpo.com unsafe-inline assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com pos.baidu.com *.baidu.com use.typekit.net *.typekit.net *.choosewine.com.au *.winedirect.com.au *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com dpe0djwch8671.cloudfront.net a.omappapi.com js.monitor.azure.com *.js.monitor.azure.com jfapiprod.optimonk.com cdn-limit.optimonk.com use.typekit.net *.typekit.net bam.nr-data.net mcstaging.winedirect.com.au because it violates the following Content Security Policy directive: "connect-src static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com ekr.zdassets.com/ *.instant.one *.choosewine.com.au *.winedirect.com.au *.z.clarity.ms *.clarity.ms stats.g.doubleclick.net *.g.doubleclick.net manager.eu.smartlook.cloud *.smartlook.com www.google.co.in *.adobedtm.com *.adobe.com rec.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.co.in *.sc.omtrdc.net *.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com *.googleadservices.com *.analytics.yahoo.com *.paypalobjects.com t.paypal.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io site-assets.afterpay.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com cdn1.stamped.io checkout.paypal.com stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.glopal.com *.glopalservice.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com front.optimonk.co *.optimonk.co qa.clevertar.app *.clevertar.app bat.bing.com api.omappapi.com front.optimonk.com australiaeast-1.in.applicationinsights.azure.com cdn-account.optimonk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.aptrinsic.com cdn.livechatinc.com *.livechatinc.com api.livechatinc.com clevertar.azureedge.net *.azureedge.net dc.services.visualstudio.com *.visualstudio.com my.clevertar.com *.clevertar.com pos.baidu.com *.baidu.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.instant.one 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://a.klaviyo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://static.klaviyo.com https://fast.a.klaviyo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://static.klaviyo.com https://fast.a.klaviyo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: blob: ; object-src https: data: 'unsafe-inline'; style-src https: data: 'unsafe-inline' ; script-src https: data: 'unsafe-inline' 'unsafe-eval' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-H8HJw1oiG2XB/F/E49nDL0SIPnY=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.hydroflask.com.co *.gstatic.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net js.authorize.net jstest.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com cdn-scripts.signifyd.com www.youtube.com *.magerocket.com *.gocuotas.com s7.addthis.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.magerocket.com *.gocuotas.com ekr.zdassets.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.mommysboy.com *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.mommysboy.com *.adulttime.com join.gammasecure.com; script-src 'self' *.mommysboy.com *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.mommysboy.com *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.ie https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/about 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' *.googletagmanager.com *.google-analytics.com *.google.com *.gstatic.com *.cookiebot.com consentcdn.cookiebot.com *.hubspot.com *.hs-scripts.com js.hs-analytics.net cdnjs.cloudflare.com code.jquery.com *.hsappstatic.net *.hubspotusercontent-eu1.net *.licdn.com *.sumo.com *.facebook.net *.trustpilot.com *.doubleclick.net *.sumome.com *.hsadspixel.net *.hs-analytics.net js.hscta.net js-eu1.hscta.net static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hubspotfeedback.com feedback.hubapi.com feedback-eu1.hubapi.com; style-src 'self' 'unsafe-inline' *.cookiebot.com *.hubspot.com fonts.googleapis.com cdnjs.cloudflare.com code.jquery.com *.hsappstatic.net *.hubspotusercontent-eu1.net cdn2.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net; img-src 'self' data: *.google-analytics.com *.google.com *.google.nl *.gstatic.com *.cookiebot.com *.hubspot.com *.hs-analytics.net *.facebook.com *.ads.linkedin.com *.googletagmanager.com ade.googlesyndication.com perf-eu1.hsforms.com static.hsappstatic.net *unpkg.com *.hsforms.com *.hubspotusercontent-eu1.net no-cache.hubspot.com js.hscta.net js-eu1.hscta.net *.hubspot.net cdn2.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net; font-src 'self' fonts.googleapis.com fonts.gstatic.com *.hubspot.com *.hsappstatic.net *.hubspotusercontent-eu1.net; connect-src 'self' *.google-analytics.com *lottie.host *.cookiebot.com *.hubspot.com api.hubapi.com *.hsforms.net *.hsforms.com forms-eu1.hscollectedforms.net pagead2.googlesyndication.com wss://*.hubspot.com js.hscta.net js-eu1.hscta.net *.hs-banner.com *.hscollectedforms.net; frame-src 'self' *.cookiebot.com *.hubspot.com *.hsforms.net *.hsforms.com *.google.com https://www.google.com www.googletagmanager.com *.doubleclick.net *.hs-sites.com *.hs-sites-eu1.com *.hubspot.net play.hubspotvideo.com play-eu1.hubspotvideo.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self' *.hsforms.net *.hsforms.com; object-src 'none'; 1 default-src 'self'; script-src https://mc.yandex.ru 'unsafe-eval' 'unsafe-inline' 'report-sample' 'self' https://cdn.gtalk.pro https://cdn.gring.pro https://www.google.com/ https://www.gstatic.com; style-src 'unsafe-inline' 'report-sample' 'self' https://cdn.gtalk.pro https://cdn.gring.pro; object-src 'none'; connect-src https://mc.yandex.ru 'self' https://cdn.gtalk.pro https://cdn.gring.pro https://okr.sbdv.ru wss://vps.gtalk.pro wss://vps.gring.pro https://web-telemetry.gtalk.pro https://web-telemetry.gring.pro https://sentry-api.gtalk.pro https://sentry-api.gring.pro; font-src 'self' data: https://cdn.gtalk.pro https://cdn.gring.pro; frame-src https://mc.yandex.ru 'self' blob: https://www.google.com/; img-src https://mc.yandex.ru 'self' data: https://cdn.gtalk.pro https://cdn.gring.pro https://s-dt2.cloud.edgecore.ru; manifest-src 'self' https://cdn.gtalk.pro https://cdn.gring.pro; media-src 'self'; frame-ancestors http://*.webvisor.com http://webvisor.com https://*.webvisor.com https://webvisor.com https://metrika.yandex.ru 'self' https://www.speechpro.ru; worker-src 'none'; child-src https://mc.yandex.ru 'self' blob:; base-uri 'self'; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com/ https://www.youtube.com js.authorize.net jstest.authorize.net accept.authorize.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net adservice.adswg.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.magezon.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com d1vqnh1hf9z1x2.cloudfront.net www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.google.com/ js.authorize.net jstest.authorize.net sandbox-assets.secure.checkout.visa.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://www.sandbox.paypal.com https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io js.authorize.net jstest.authorize.net api.authorize.net apitest.authorize.net accept.authorize.net test.authorize.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com https://ct.pinterest.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net *.despegar.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com *.online-metrix.net https://www.google.com/pagead/ https://www.google.com.br/pagead/ https://apps.mypurecloud.com https://td.doubleclick.net https://event.getblue.io https://app-indecx.com https://ct.pinterest.com/ https://web-modules-de-na1.niceincontact.com/ https://h.online-metrix.net/* *.despegar.com/ *.braintreepayments.com assets.braintreegateway.com *.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://h.online-metrix.net *.d.aa.online-metrix.net https://cdnjs.cloudflare.com https://res.cloudinary.com https://vlibras.gov.br https://lumisfera.com.br https://cdn.cookielaw.org https://cdn.jsdelivr.net https://p.afilio.com.br https://bat.bing.com https://www.facebook.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ *.adobedtm.com *.googleadservices.com *.google.com *.googletagmanager.com facebook.com.br/* https://connect.facebook.net/en_US/fbevents.js https://c.bing.com/ *.clarity.ms/ www.google.com/* www.google.com.br/* ct.pinterest.com/* *.despegar.com/ *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://h.online-metrix.net *.cardinalcommerce.com *.online-metrix.net https://cdn.cookielaw.org https://cdn.jsdelivr.net https://vlibras.gov.br *.mypurecloud.com https://surveydynamix.com https://cdn.mouseflow.com https://bat.bing.com https://analytics.tiktok.com https://event.getblue.io https://widget.getblue.io https://www.clarity.ms https://js.braintreegateway.com https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ https://viacep.com.br/* https://*.sc.omtrdc.net/ https://*.facebook.net/ facebook.com.br/* https://*.adobedtm.com/ www.googleadservices.com.br *.google.com *.google.com.br https://www.google.com/pagead/ https://www.google.com.br/pagead/ https://connect.facebook.net/en_US/fbevents.js https://s.pinimg.com https://ct.pinterest.com/* https://web-modules-de-na1.niceincontact.com https://cdnjs.cloudflare.com/ https://h.online-metrix.net/* *.despegar.com/ *.paypal.com *.pagseguro.com.br *.pagseguro.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdnjs.cloudflare.com https://cdn-prod.securiti.ai https://cdn.cookielaw.org/* https://web-modules-de-na1.niceincontact.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://dev.visualwebsiteoptimizer.com https://cdn.cookielaw.org https://api-cdn.mypurecloud.com https://content.hotjar.io https://analytics.tiktok.com https://t.clarity.ms https://indecx.com https://geolocation.onetrust.com *.cardinalcommerce.com www.googleadservices.com.br *.google.com *.google.com.br www.googletagmanager.com.br *.adobedc.net wss://*.hotjar.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ facebook.com.br/* https://connect.facebook.net/en_US/fbevents.js https://viacep.com.br https://stats.g.doubleclick.net/g/* *.clarity.ms/ https://ct.pinterest.com/* stats.g.doubleclick.net ct.pinterest.com *.despegar.com/ *.braintree-api.com *.pagseguro.com.br *.pagseguro.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://fonts.bunny.net *.klarnacdn.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com *.braintreegateway.com *.paypal.com google.com * *.adyen.com *.klarna.com *.google.de *.doubleclick.net *.googlesyndication.com *.googletagservices.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com * https://images.unsplash.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.adyen.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.google.de *.googletagmanager.com *.doubleclick.net *.google.com *.googlesyndication.com *.googletagservices.com *.googleadservices.com www.artplants.de bat.bing.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com widget.freshworks.com m2epro.freshdesk.com https://maps.googleapis.com *.avada.io *.shopify.com *.gstatic.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://www.google-analytics.com https://stats.artplants.de https://cdn.artplants.de https://bat.bing.com www.google.de *.googletagmanager.com *.doubleclick.net *.googlesyndication.com *.googletagservices.com *.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.klarnacdn.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * widget.freshworks.com m2epro.freshdesk.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io *.google-analytics.com *.adyen.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.doubleclick.net *.googlesyndication.com *.googletagservices.com stats.artplants.de bat.bing.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com *.sirv.com *.olark.com *.contivio.com *.avalara.com sbx.certcapture.com app.certcapture.com https://img.en25.com/i/elqCfg.min.js https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/ https://x.adroll.com/ https://ipv4.d.adroll.com/ *.visualvisitor.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com *.sirv.com www.xtento.com cdn.xtento.com *.olark.com https://img.en25.com/i/elqCfg.min.js *.artifi.net *.monetate.net www.magecomp.com *.contivio.com *.avalara.com sbx.certcapture.com app.certcapture.com https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/ https://x.adroll.com/ https://ipv4.d.adroll.com/ *.visualvisitor.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com *.sirv.com player.vimeo.com www.xtento.com cdn.xtento.com *.olark.com *.monetate.net img03.en25.com *.coveo.com *.newrelic.com *.artifi.net https://img.en25.com/i/elqCfg.min.js *.contivio.com *.avalara.com sbx.certcapture.com app.certcapture.com https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/ https://x.adroll.com/ https://ipv4.d.adroll.com/ *.visualvisitor.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com *.sirv.com *.olark.com *.contivio.com *.avalara.com sbx.certcapture.com app.certcapture.com https://img.en25.com/i/elqCfg.min.js https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/ https://x.adroll.com/ https://ipv4.d.adroll.com/ *.visualvisitor.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.sirv.com *.olark.com blob: *.avalara.com sbx.certcapture.com app.certcapture.com https://img.en25.com/i/elqCfg.min.js https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/consent/ https://x.adroll.com/attribution/trigger https://ipv4.d.adroll.com/ *.visualvisitor.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com thm.visa.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com *.sirv.com *.youtube.com blob: *.olark.com *.cloud.coveo.com bam.nr-data.net *.artifi.net *.contivio.com *.avalara.com sbx.certcapture.com app.certcapture.com https://img.en25.com/i/elqCfg.min.js https://trk.barcoproducts.com/ *.invocacdn.com *.crazyegg.com https://bat.bing.com/ https://s.adroll.com/ https://d.adroll.com/consent/ https://x.adroll.com/attribution/trigger https://ipv4.d.adroll.com/ *.visualvisitor.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://*.icomoon.io https://fonts.gstatic.com https://*.google.com https://cdnjs.cloudflare.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://*.googletagmanager.com https://*.cookiebot.com https://*.facebook.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.weltpixel.com www.xtento.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://connect.facebook.net https://*.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.multisafepay.com *.amazonaws.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com https://*.sportimex.com https://developer.adobe.com https://magento.com https://*.cookiebot.com https://static.dhlecommerce.nl https://*.bootstrapcdn.com https://*.jsdelivr.net https://*.google.com https://connect.facebook.net chimpstatic.com downloads.mailchimp.com *.list-manage.com *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com ajax.googleapis.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.sportimex.com https://*.icomoon.io https://*.cloudfront.net https://static.dhlecommerce.nl https://*.cookiebot.com https://*.jsdelivr.net https://*.google.com https://cdnjs.cloudflare.com downloads.mailchimp.com *.multisafepay.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://*.sportimex.com https://developer.adobe.com https://*.google.com *.multisafepay.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com places.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://zhklrkwwz3qjjxbsljqmqe2b.httpschecker.net/report 1 font-src *.klarnacdn.net maxcdn.bootstrapcdn.com fonts.gstatic.com widget-v4.tidiochat.com x.klarnacdn.net code.tidio.co data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.klarna.com www.googletagmanager.com td.doubleclick.net *.doubleclick.net pagead2.googlesyndication.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com https://resources.paytrail.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net *.googleusercontent.com cdnjs.cloudflare.com google.se *.google.fi avatars.tidiochat.com resources.paytrail.com pagead2.googlesyndication.com google.com maps.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com maps.googleapis.com code.tidio.co widget-v4.tidiochat.com pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net maxcdn.bootstrapcdn.com *.gstatic.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com widget-v4.tidiochat.com code.tidio.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com sentry-new.tidio.co wss://socket.tidio.co api-v2.tidio.co google.com www.google.com googleads.g.doubleclick.net pagead2.googlesyndication.com *.google.com www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.gstatic.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.addthis.com *.multisafepay.com https://pay.google.com *.cookiebot.com *.cookiebot.eu *.googletagmanager.com *.doubleclick.net *.facebook.com *.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.disqus.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.orbitvu.co *.facebook.com *.google.nl google.nl *.cookiebot.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://browser.sentry-cdn.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.cookiebot.com *.cookiebot.eu *.facebook.net *.pinimg.com *.pinterest.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net *.fontawesome.com *.multisafepay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.googlesyndication.com *.pinterest.com *.cookiebot.eu *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.googletagmanager.com tagmanager.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src tagmanager.google.com fonts.google.com downloads.mailchimp.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googletagmanager.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.bing.com *.doubleclick.net *.facebook.com *.usercentrics.eu *.discountlight.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.wwlholding.com *.bing.com *.clarity.ms *.facebook.net *.googleapis.com *.hotjar.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.videoly.co *.beslist.nl *.discountlight.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com tagmanager.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.wwlholding.com *.bing.com *.doubleclick.net *.googlesyndication.com *.leadinfo.com *.leadinfo.net *.mopinion.com *.usercentrics.eu *.googleapis.com *.addressy.com *.beslist.nl *.hotjar.com *.hotjar.io *.discountlight.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://www.magezon.com https://img.youtube.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com https://cdn.jsdelivr.net *.google.com/ *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.fontawesome.com cdn.jsdelivr.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://content.quantcount.com https://code.jquery.com https://cdn.datatables.net https://fonts.googleapis.com https://*.bootstrapcdn.com https://cdn.jsdelivr.net https://*.googleapis.com https://*.cloudflare.com https://www.gstatic.com https://trello.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://assets.adobedtm.com https://fordeu.d3.sc.omtrdc.net https://*.ampproject.org https://*.adnxs-simple.com https://*.comcar.co.uk https://*.adnxs.com https://*.googlesyndication.com https://*.googletagservices.com https://adservice.google.co.uk https://adservice.google.com https://cdn.jsdelivr.net https://use.typekit.net https://*.quantcount.com https://*.quantserve.com https://*.consensu.org https://datacygnal.io https://*.doubleclick.net https://*.googletagmanager.com https://*.opel.com https://*.vauxhall.co.uk https://*.googleadservices.com https://*.bing.com https://netmng.com https://*.hotjar.com https://*.cloudfront.net https://*.netmng.com https://cbvc.agilecrm.com https://*.cloudflare.com https://*.google-analytics.com https://*.amazonaws.com https://cdn.datatables.net https://use.fontawesome.com https://www.google.com https://stackpath.bootstrapcdn.com unpkg.com https://browser.sentry-cdn.com https://www.google.com/jsapi https://www.gstatic.com https://code.jquery.com https://*.googleapis.com https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://trello.com; font-src 'self' data: https://use.typekit.net https://cdn.jsdelivr.net https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://secure.carmendata.co.uk https://fonts.googleapis.com; img-src 'self' data: https://p.typekit.net https://*.google-analytics.com https://*.quantcount.com https://*.quantserve.com https://*.googlesyndication.com https://*.pubmatic.com https://*.google.com https://*.google.co.uk https://*.omtrdc.net https://*.bing.com https://*.adnxs.com https://*.doubleclick.net https://ssl.caranddriving.com https://secura.cloud https://s3-eu-west-1.amazonaws.com https://*.googleapis.com https://res.cloudinary.com; frame-ancestors 'self' https://kia.com https://www.kia.com https://www.seat.co.uk https://www.cupraofficial.co.uk https://www.ethosfinance.co.uk https://www.skoda.co.uk https://daysfleet.com https://www.mg.co.uk https://www.sgfleet.com https://www.fleetalliance.co.uk https://www.vanarama.com https://www.fleetnews.co.uk https://www.businesscar.co.uk https://www.whatvan.co.uk https://www.wessexfleet.co.uk; frame-src 'self' https://*.pubmatic.com https://*.comcar.co.uk https://*.adnxs.com https://*.googlesyndication.com https://*.hotjar.com https://*.doubleclick.net https://ssl.caranddriving.com https://www.google.com; connect-src 'self' https://*.googlesyndication.com https://*.amazonaws.com wss://*.hotjar.com https://*.consensu.org https://*.doubleclick.net https://*.pubmatic.com https://*.teads.tv https://*.adnxs.com https://*.hotjar.com https://*.hotjar.io https://*.google-analytics.com https://*.googleapis.com https://*.comcar.co.uk https://*.sentry.io https://sentry.io; 1 font-src *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.vivapayments.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.googletagmanager.com www.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.findbar.io magefan.com cm.magefan.com *.disqus.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.pharm24.gr www.gstatic.com https://zachospharmacy.gr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.vivapayments.com *.findbar.io *.disqus.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com stage.zachospharmacy.gr app.findbar.io www.google.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.findbar.io *.fontawesome.com unsafe-inline assets.braintreegateway.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.findbar.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.findbar.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com region1.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src stage.zachospharmacy.gr www.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com ByramBaby.pxf.io https://www.ojrq.net https://logs-01.loggly.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.certcapture.com https://utt.impactcdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com ByramBaby.pxf.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /-/csp_report?report_only=true&source=webapp-no-object-src; script-src 'nonce-ugix9r0cb0tye7nmv8677ucbb' 'nonce-rvhhfk2oq2dv1prnse45ygy2g' 'self' https: 'strict-dynamic' 'report-sample' 'wasm-unsafe-eval' 'unsafe-inline' https://ssl.gstatic.com https://apis.google.com https://accounts.google.com/gsi/client https://d3ki9tyy5l5ruj.cloudfront.net https://d1gwm4cf8hecp4.cloudfront.net https://d1a3usp4brejtz.cloudfront.net https://d3u0af8znnrzzj.cloudfront.net https://d1dg3ns82tdjz3.cloudfront.net https://d2y3xhxlqzgfzh.cloudfront.net https://oauth.googleusercontent.com https://app.box.com https://platform.twitter.com https://connect.facebook.net https://platform.harvestapp.com https://www.google.com https://docs.google.com https://www.gstatic.com https://www.dropbox.com https://www.paypal.com/sdk/js https://recordwidget.vimeocdn.com https://api.stripe.com https://hooks.stripe.com https://js.stripe.com https://m.stripe.com https://m.stripe.network https://q.stripe.com https://prod-eu1.app.asana.com https://prod-au1.app.asana.com https://prod-jp1.app.asana.com https://prod-me1.app.asana.com https://cdn.cookielaw.org https://861-iiv-735.mktoweb.com https://resources.asana.com https://ccwizard.vertexsmb.com; frame-ancestors 'self' https://teams.integrations.asana.plus https://teams-beta.integrations.asana.plus https://teams-uat.integrations.asana.plus https://teams.microsoft.com https://teams.cloud.microsoft; frame-src 'self' blob: https://www.figma.com https://*.invisionapp.com https://invis.io https://miro.com https://whimsical.com https://www.loom.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.com https://www.canva.com https://xd.adobe.com https://*.looker.com https://lucid.app https://*.okta.com https://*.sharepoint.com https://*.dovetail.com https://*.tableau.com https://airtable.com https://*.mural.co https://help.asana.com https://accounts.google.com https://accounts.google.com/gsi/ https://content.googleapis.com https://www.google.com https://docs.google.com https://fast.wistia.net https://www.dropbox.com https://platform.harvestapp.com https://forms.asana.plus https://forms-server.asana.plus https://local.asana.com https://asana.com https://apisandbox.zuora.com https://test.zuora.com https://www.zuora.com https://www.sandbox.paypal.com https://www.paypal.com https://recordwidget.vimeocdn.com https://api.stripe.com https://hooks.stripe.com https://js.stripe.com https://m.stripe.com https://m.stripe.network https://q.stripe.com https://pixel.asana.com https://d3ki9tyy5l5ruj.cloudfront.net https://prod-eu1.app.asana.com https://prod-au1.app.asana.com https://prod-jp1.app.asana.com https://prod-me1.app.asana.com https://cdn.cookielaw.org https://form.asana.com https://form.asana-gov.com https://form-beta.asana.com https://form-stag.luna-s.org https://localhost.asana.com:3000 https://861-iiv-735.mktoweb.com https://resources.asana.com https://ccwizard.vertexsmb.com https://*.qualtrics.com; worker-src 'self' blob: https://d3ki9tyy5l5ruj.cloudfront.net; child-src 'self' blob: https://d3ki9tyy5l5ruj.cloudfront.net; object-src 'none'; base-uri 'none' 1 default-src 'self'; report-to csp-endpoint 1 script-src 'strict-dynamic' 'nonce-878d9feb87e161ae0a1db49ac8946086' 'unsafe-inline' 'unsafe-eval' https: ; frame-ancestors 'self' ; base-uri 'self'; object-src 'none'; report-uri https://csp.phenompeople.com/violations; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.bunny.net *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * challenges.cloudflare.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.vimeo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com *.avada.io *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com challenges.cloudflare.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.bunny.net *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com assets.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.youtube.com *.vimeo.com *.vimeocdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.globalpay.com https://fonts.gstatic.com *.acsbapp.com acsbapp.com *.queue-it.net https://js.globalpay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com pay.sandbox.realexpayments.com https://pay.realexpayments.com https://apis.sandbox.globalpay.com https://apis.globalpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com account.fetchify.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com pay.sandbox.realexpayments.com https://pay.realexpayments.com https://apis.sandbox.globalpay.com https://apis.globalpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.globalpay.com *.acsbapp.com acsbapp.com *.queue-it.net services.postcodeanywhere.co.uk google.com google.co.za www.google.co.za https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://js.globalpay.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cc-cdn.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com *.acsbapp.com acsbapp.com *.queue-it.net services.postcodeanywhere.co.uk js-agent.newrelic.com bam.nr-data.net https://js.globalpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cc-cdn.com https://fonts.googleapis.com *.acsbapp.com acsbapp.com *.queue-it.net services.postcodeanywhere.co.uk https://www.gstatic.com/recaptcha/ https://js.globalpay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://google.com/pay *.acsbapp.com acsbapp.com *.queue-it.net js-agent.newrelic.com bam.nr-data.net *.postcodeanywhere.co.uk stats.g.doubleclick.net https://edge.adobedc.net https://apis.sandbox.globalpay.com https://apis.globalpay.com https://js.globalpay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://data.expivi.net https://admin.expivi.net *.fontawesome.com https://dashboard.webwinkelkeur.nlfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net https://dashboard.webwinkelkeur.nl *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://expivi.net https://data.expivi.net https://assets.expivi.net https://cache.expivi.net https://admin.expivi.net https://www.gstatic.com magefan.com cm.magefan.com *.multisafepay.com *.amazonaws.com *.facebook.com *.reddit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com consent.cookiebot.com consent.cookiebot.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://expivi.net https://data.expivi.net https://assets.expivi.net https://cache.expivi.net https://admin.expivi.net *.multisafepay.com https://pay.google.com https://www.postcode-checkout.nl/api/v2/ *.sendcloud.sc *.jsdelivr.net https://dashboard.webwinkelkeur.nl/sidebar.js https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com *.multisafepay.com *.sendcloud.sc *.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://expivi.net https://data.expivi.net https://assets.expivi.net https://cache.expivi.net https://admin.expivi.net https://www.gstatic.com *.multisafepay.com https://www.postcode-checkout.nl/api/v2/ *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com data: dianochedesigns.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * dianochedesigns.com 'self' 'unsafe-inline'; frame-ancestors dianochedesigns.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co *.hotjar.com *.facebook.com *.trustpilot.com *.criteo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * dianochedesigns.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.pinterest.com *.google.com.au *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.googleapis.com *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com dianochedesigns.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cloudflare.com *.ctctcdn.com *.pinterest.com stylifyhub.com *.adroll.com *.paypal.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com dianochedesigns.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.ctctcdn.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net assets.braintreegateway.com dianochedesigns.com 'self' 'unsafe-inline'; object-src dianochedesigns.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com dianochedesigns.com 'self' 'unsafe-inline'; manifest-src dianochedesigns.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.ctctcdn.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com dianochedesigns.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com dianochedesigns.com http: https: blob: 'self' 'unsafe-inline'; default-src dianochedesigns.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri dianochedesigns.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com apis.google.com www.googleapis.com *.googleapis.com *.googleadservices.com www.googletagmanager.com js.mollie.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://www.mollie.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com apis.google.com www.googleapis.com *.googleapis.com *.googleadservices.com connect.facebook.net *.googletagmanager.com *.google-analytics.com js.mollie.com https://cdnjs.cloudflare.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src apis.google.com www.googleapis.com *.googleapis.com *.googleadservices.com landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com apis.google.com www.googleapis.com *.googleapis.com *.googleadservices.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com https://fonts.googleapis.com https://fonts.gstatic.com 'unsafe-eval' https://ajax.googleapis.com cdn.mxpnl.com api-js.mixpanel.com www.google-analytics.com docs.google.com calendar.google.com www.googletagmanager.com 'sha256-NA873dC45BPUIltw0jU+n0ruk2+jONPmJcyl4SBo3g4=' 'sha256-lNcex84UyBcPsRtxOC9W/OGR64xdMRuNcUOAlerAFVs=' 'sha256-y6pA5FCRcyc+97gtaC7vBcHyKxmI+J0dyfCUfauaxGc=' 'sha256-+d5SsXB+CcN7crzReEewJ4ivzmwyjeydRhi4QRBEG1I=' 'sha256-E8FbddONPGbyUqvXE7X2FE3aW37wjEFutXHxUf/qNlU=' 'sha256-JT4a2/oQ9RezHv8G/Q5UNBv8bu14p+tzmNz4n1AelgI=' 'sha256-1EDHfB5zrroZFaWqKs7b+J3UW4RArR6wluB7eyn+KiA=' 'sha256-nhF+jfQINrkwabT9O/YDt+80aTJ+E2+q4apH1Ec+AbA=' 'report-sample'; report-uri /csp-violation-report-endpoint/; script-src https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com https://fonts.googleapis.com https://fonts.gstatic.com 'unsafe-eval' https://ajax.googleapis.com cdn.mxpnl.com api-js.mixpanel.com www.google-analytics.com docs.google.com calendar.google.com www.googletagmanager.com 'sha256-NA873dC45BPUIltw0jU+n0ruk2+jONPmJcyl4SBo3g4=' 'sha256-lNcex84UyBcPsRtxOC9W/OGR64xdMRuNcUOAlerAFVs=' 'sha256-y6pA5FCRcyc+97gtaC7vBcHyKxmI+J0dyfCUfauaxGc=' 'sha256-+d5SsXB+CcN7crzReEewJ4ivzmwyjeydRhi4QRBEG1I=' 'sha256-E8FbddONPGbyUqvXE7X2FE3aW37wjEFutXHxUf/qNlU=' 'sha256-JT4a2/oQ9RezHv8G/Q5UNBv8bu14p+tzmNz4n1AelgI=' 'sha256-1EDHfB5zrroZFaWqKs7b+J3UW4RArR6wluB7eyn+KiA=' 'sha256-nhF+jfQINrkwabT9O/YDt+80aTJ+E2+q4apH1Ec+AbA=' 'report-sample'; style-src 'unsafe-inline' https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com https://fonts.googleapis.com https://fonts.gstatic.com 'unsafe-eval' https://ajax.googleapis.com cdn.mxpnl.com api-js.mixpanel.com www.google-analytics.com docs.google.com calendar.google.com www.googletagmanager.com ; frame-ancestors https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com 'self'; media-src https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com blob:; worker-src https://www.veevashare.com/ https://www.veevashare.com/ https://www.veevashare.com/ https://fonts.googleapis.com v1233915-channel-prod.services.veevashare.com wss://v1233915-channel-prod.services.veevashare.com https://cdn2.veevashare.com/v1233915/ vlshare-files-prod.s3.amazonaws.com blob:; img-src *; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com business.facebook.com *.addthis.com *.vudoo.io *.doubleclick.net *.adroll.com *.recaptcha.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.adyen.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://prf.hn *.google.com *.unbxd.io *.unbxdapi.com *.adroll.com *.bing.com *.bidswitch.net *.casalemedia.com *.rubiconproject.com *.openx.net *.outbrain.com *.pubmatic.com *.yahoo.com *.taboola.com *.adnxs.com *.3lift.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com https://prf.hn https://pzapi-nb.com https://pzapi-kg.com https://pzapi-ij.com/ *.unbxd.io *.unbxdapi.com *.hotjar.com *.adroll.com *.vudoo.io *.tiktok.com *.bing.com *.optimonk.com acsbapp.com *.acsbapp.com *.cloudfront.net *.lexer.io *.pdst.fm *.recaptcha.net *.zdassets.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app display.ugc.bazaarvoice.com https://static.klaviyo.com *.fontawesome.com *.unbxd.io *.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.addthis.com *.unbxd.io *.unbxdapi.com acsbapp.com *.acsbapp.com *.adroll.com *.spotify.com *.optimonk.com *.tiktok.com *.amazonaws.com *.zendesk.com places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com swisse.com.au searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com places.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: accounts.google.com *.clearpay.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.afterpay.com *.clearpay.co.uk *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com accounts.google.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com https://cdn.jsdelivr.net *.avada.io *.shopify.com *.alothemes.com *.magepow.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com accounts.google.com *.afterpay.com/ *.squarecdn.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com accounts.google.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com use.fontawesome.com fonts.gstatic.com stackpath.bootstrapcdn.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br *.wesupply.xyz https://wesupplylabs.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io getscw.com forms.hsforms.com www.getscw.com forms-na1.hsforms.com 'self' 'unsafe-inline' *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br https://stc.pagseguro.uol.com.br https://sandbox.stc.pagseguro.uol.com.br yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com https://www.google.ge/ https://px.ads.linkedin.com/ https://perf-na1.hsforms.com/ https://cta-service-cms2.hubspot.com/ https://static.hubspot.com/ https://static.hsappstatic.net/ https://track.hubspot.com/ bat.bing.com cdn2.hubspot.net bat.bing.net px4.ads.linkedin.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.hsforms.net stc.pagseguro.uol.com.br https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com *.avada.io *.shopify.com *.gstatic.com maps.googleapis.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://stc.pagseguro.uol.com.br https://stc.sandbox.pagseguro.uol.com.br *.cloudflare.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com https://static.hotjar.com/ https://snap.licdn.com/ https://www.statcounter.com/ https://js.hs-scripts.com/ https://cdn.callrail.com/ https://script.hotjar.com/ https://js.hs-banner.com/ https://js.hubspot.com/ https://js.usemessages.com/ https://js.hscollectedforms.net/ https://js.hsadspixel.net/ https://js.hs-analytics.net/ js.callrail.com https://bat.bing.com/bat.js https://bat.bing.com/p/action/26018725.js js.usemessages.com js.hs-banner.com js.hubspot.com browser.sentry-cdn.com birdeye.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://stackpath.bootstrapcdn.com 'self' 'unsafe-inline' *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com player.vimeo.com download-video.akamaized.net vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://forms.hsforms.com/ api.security.pagseguro.uol.com 'self' 'unsafe-inline' https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com https://eu2.make.com/ https://stats.g.doubleclick.net/ https://c.statcounter.com/ https://px.ads.linkedin.com/ https://js.callrail.com/ https://api.hubspot.com/ https://api.hubapi.com/ https://cta-service-cms2.hubspot.com/ https://forms.hscollectedforms.net/ https://google.com/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://metrics.hotjar.io/ o4508131567534080.ingest.us.sentry.io api.hubspot.com api.hubapi.com cta-service-cms2.hubspot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.googletagmanager.com/ *.google.com https://www.youtube.com *.addthis.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.vimeocdn.com s.ytimg.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com maps.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.google.com/ player.vimeo.com *.youtube.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://core.helloretail.com https://helloretailcdn.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.oktacdn.com; connect-src 'self' *.oktacdn.com *.mixpanel.com *.mapbox.com https://oinmanager.clouditude.com data:; script-src 'unsafe-inline' 'nonce-XDWHo4k64D2ggLIOof1HKA' 'unsafe-eval' 'self' 'report-sample' *.oktacdn.com; style-src 'unsafe-inline' 'nonce-XDWHo4k64D2ggLIOof1HKA' 'self' 'report-sample' *.oktacdn.com; frame-src 'self' login.clouditude.com https://login.clouditude.com *.vidyard.com; img-src 'self' *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 default-src data: https: 'unsafe-inline' 'unsafe-eval'; report-uri https://kontur.ru/csp 1 img-src https://higherlogicdownload.s3.amazonaws.com/AWB/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AWB/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/AWB/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AWB/ https://higherlogicdownload.s3.amazonaws.com/AWB/ https://higherlogiclongterm.s3.amazonaws.com/AWB/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/AWB/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AWB/ 'self' https://higherlogiclongterm.s3.amazonaws.com/AWB/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/AWB/ https://higherlogicdownload.s3.amazonaws.com/AWB/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AWB/ https://higherlogicstream.s3.amazonaws.com/AWB/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/AWB/ https://higherlogicdownload.s3.amazonaws.com/AWB/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AWB/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com/ data:; style-src 'self' 'unsafe-inline'; style-src-elem 'self' https://api.tiles.mapbox.com/ https://fonts.googleapis.com/ https://wchat.eu.freshchat.com/ https://app.getbeamer.com/ 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'sha256-cjeHmUT8tPYJL6GbVRyK0g+jkI57j4xwcA0JNZvyH7s=' blob: https://*.usercentrics.eu; script-src-elem 'self' 'unsafe-inline' blob: https://app.usercentrics.eu https://maps.googleapis.com https://images.sabscorp.com https://*.usercentrics.eu https://unpkg.com https://api.tiles.mapbox.com/ https://cdn.jsdelivr.net/ https://www.google-analytics.com/ https://app.getbeamer.com/ https://wchat.eu.freshchat.com https://*.eu.pendo.io/ ; img-src 'self' data: https://template.rdg-bat-vt-acc.cloud.sqills.com https://*.sabre.com https://images.sabscorp.com https://media.iceportal.com https://secure.holidayextras.co.uk https://d1xcii4rs5n6co.cloudfront.net https://i.travelapi.com https://*.usercentrics.eu https://hotelbookerssl.sabre.com https://ssl.conferma.com https://static4.holidayextras.com https://scoutfroneasset.blob.core.windows.net https://app.getbeamer.com/ https://www.google.com https://www.google.co.uk https://www.google-analytics.com https://*.eu.pendo.io/ https://*.groundspan.com https://maps.gstatic.com https://maps.googleapis.com https://upamedia.atpco.net ; connect-src 'self' data: https://d1xcii4rs5n6co.cloudfront.net https://secure.holidayextras.co.uk https://*.sabre.com https://unpkg.com/@googlemaps/ https://images.sabscorp.com https://test.trips.uk.com/ https://maps.gstatic.com/ https://fonts.googleapis.com https://app.getbeamer.com https://maps.googleapis.com https://scout-eu-nlu-dev.azurewebsites.net https://scout-advertisement-server.azurewebsites.net https://scout-global-app.azurewebsites.net https://approve-test.ctmportal.co.uk https://*.auth0.com https://www.google-analytics.com/ https://backend.getbeamer.com/ https://stats.g.doubleclick.net https://*.usercentrics.eu https://hotelbookerssl.sabre.com https://ssl.conferma.com https://media.iceportal.com https://i.travelapi.com https://investor.travelctm.com.au https://fonts.gstatic.com https://*.eu.pendo.io/ ; frame-src 'self' https://*.usercentrics.eu https://*.auth0.com https://wchat.eu.freshchat.com/ https://*.eu.webpush.freshchat.com https://app.getbeamer.com/ ; media-src https://scoutfroneasset.blob.core.windows.net; report-uri https://test.trips.uk.com/CorpAdmin/report-uri-Logging.pl; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.newrelic.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.multisafepay.com assets.myparcel.nl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com www.google.com.na www.google.sn www.google.md www.google.co.jp treasurejuwelier.nl www.google.sr www.google.com.pk www.google.com.my *.openstreetmap.fr www.google.gr www.google.fr www.google.am www.google.de *.cookiebot.com www.google.cl *.treasurejuwelier.nl www.google.im www.google.com.cy www.google.com.qa www.google.es www.google.com.co www.google.co.za www.google.com.tw www.google.com.om www.google.cv www.google.com.ag www.google.lt www.google.tn www.google.com.sg www.google.nl www.google.is www.google.gm www.google.co.in *.taggrs.io www.google.co.nz www.google.com.bz www.google.lu www.google.co.uk www.google.by www.google.com.do www.google.lk *.google.com www.google.com.lb *.bing.net www.google.com.eg www.google.at www.google.ad www.google.com.gt www.google.co.ma www.google.ro www.google.com.br www.google.com.jm s3.amazonaws.com www.google.no www.google.com.bd www.google.rs *.googleadservices.com www.google.fi www.google.ie www.google.sk www.google.co.ke www.google.co.ug www.google.cd www.google.com.ph www.google.hr www.google.cm www.google.com.pa www.google.je www.google.co.ve www.google.ae www.google.co.tz www.google.com.au www.google.pl www.google.si www.google.com.tr www.google.com.kw www.google.dk www.google.com.uy www.google.se www.google.pt www.google.lv www.google.mg www.google.com.pe www.google.be www.google.com.mx www.google.mu www.google.com.mt www.google.com.ec www.google.ba www.google.ru www.google.jo *.bing.com www.google.mk www.google.me *.clarity.ms www.google.co.cr www.google.com.kh www.google.it www.google.com.sa www.google.kg www.google.co.zm www.google.com.et www.google.ch www.google.cz www.google.co.th www.google.ee www.google.co.kr www.google.mv www.google.com.vn www.google.ps www.google.com.hk www.google.hu www.google.co.vi www.google.com.ua www.google.com.ar *.google-analytics.com www.google.com.gh www.google.az www.google.rw www.google.com.ly www.google.ca data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://chimpstatic.com *.clarity.ms *.hotjar.com *.bing.com *.cookiebot.com *.newrelic.com *.fullstory.com *.marker.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com *.fontawesome.com *.multisafepay.com cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com *.multisafepay.com api.myparcel.nl api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.marker.io *.clarity.ms *.contentsquare.net *.hotjar.com www.google.nl *.googleadservices.com s3.eu-west-1.amazonaws.com *.bing.com *.cookiebot.com *.hotjar.io *.samsung.com *.bing.net *.nr-data.net *.treasurejuwelier.nl 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a717a566-b317-4973-bbbe-bb61b5876afa.sansec.watch/; report-to report-endpoint; 1 font-src *.googleapis.com *.gstatic.com use.typekit.net *.fontawesome.com *.klarnacdn.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.sagepay.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.klarna.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://plumrocket.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com media.craftandhobby.uk.com media.fashionfriendly.uk.com media.gardenability.uk.com media.healthylivingdirect.com media.housewaresdirect.uk.com www.google.pl ad.doubleclick.net register.feefo.com api.feefo.com sp.analytics.yahoo.com live.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.apptrian.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com register.feefo.com api.feefo.com s.yimg.com player.vimeo.com www.google.pl r1-t.trackedlink.net static.hotjar.com live.opayo.eu.elavon.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com p.typekit.net use.typekit.net register.feefo.com live.opayo.eu.elavon.com *.fontawesome.com *.klarnacdn.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com api.feefo.com collect.feefo.com s.yimg.com region1.google-analytics.com stats.g.doubleclick.net live.opayo.eu.elavon.com eventcollector.mcf-prod.a.intuit.com 9kvu81ddh3.execute-api.us-east-2.amazonaws.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.sagepay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.addthis.com js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://www.mollie.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net js.mollie.com *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://cdn.jsdelivr.net *.fontawesome.com *.multisafepay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.fontawesome.com *.googleapis.com *.gstatic.com *.google.com/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarnaevt.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.flashyapp.com api.flashy.app *.flashy.dev *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com *.cash.app www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.flashyapp.com api.flashy.app *.flashy.dev *.facebook.com platform.twitter.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.afterpay.com/ *.cash.app www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.disqus.com https://img.youtube.com *.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.gstatic.com api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il maps.gstatic.com *.cloudfront.net dhv2ziothpgrr.cloudfront.net www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.flashyapp.com api.flashy.app *.flashy.dev *.disqus.com *.facebook.net *.facebook.com twitter.com platform.twitter.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.clarity.ms api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il *.googleapis.com *.cloudfront.net dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.cash.app *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com dhv2ziothpgrr.cloudfront.net *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.flashyapp.com api.flashy.app *.flashy.dev *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com pay.google.com *.clarity.ms *.doubleclick.net dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.darkx.com *.xempire.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.darkx.com *.xempire.com join.gammasecure.com; script-src 'self' *.darkx.com *.xempire.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.darkx.com *.xempire.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' 'unsafe-inline'; connect-src *; font-src *; img-src * data:; media-src *; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net maps.stamen.com stats.sciencespo-lyon.fr; worker-src 'self' blob; frame-ancestors 'self'; report-to csp-endpoint 1 default-src 'self' ; base-uri 'self' ; object-src 'none' ; script-src 'self' 'unsafe-eval' 'nonce-yOnytD5dcc2gDqXr8dUx5Q==' *.googleapis.com *.baidu.com *.zohocdn.com *.cloudfront.net *.googletagmanager.com *.cdn.pagesense.io *.youtube.com; connect-src 'self' *.googleapis.com *.google-analytics.com *.nimbuspop.com ws: data: ; font-src 'self' *.gstatic.com *.zohowebstatic.com *.zohostatic.com *.zohocdn.com data: ; style-src 'self' 'unsafe-inline' *.zoho.com *.zohocdn.com; frame-src 'self' * ; img-src 'self' *.ytimg.com *.zohoexternal.com *.zohocdn.com data: blob: *.nimbuspop.com *.zohopublic.com 1 font-src *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.buyabattery.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com www.buyabattery.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com www.buyabattery.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.xtento.com www.buyabattery.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com www.buyabattery.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.xtento.com cdn.xtento.com www.buyabattery.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com unsafe-inline www.buyabattery.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.buyabattery.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.buyabattery.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.buyabattery.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.buyabattery.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com v2.zopim.com *.tawk.to *.adobe.com *.zopim.com *.gstatic.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.facebook.com *.hotjar.com https://e.issuu.com v2assets.zopim.io *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com https://cdn.flbx.io https://firebasestorage.googleapis.com *.storyblok.com *.mullanlighting.com api.feefo.com *.ytimg.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.zopim.com *.zopim.io *.cloudfront.net blob: *.rudderlabs.com *.rudderstack.com cdn-cookieyes.com cookieyes.com *.jsdelivr.net *.tawk.to tawk.link www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com *.avada.io *.storyblok.com *.hotjar.com api.feefo.com register.feefo.com v2.zopim.com widget-mediator.zopim.com browser-update.org static.zdassets.com *.jsdelivr.net *.tawk.to *.rudderlabs.com *.rudderstack.com cdn-cookieyes.com *.cookieyes.com *.googlesyndication.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.storyblok.com maxcdn.bootstrapcdn.com *.jsdelivr.net *.tawk.to unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com https://get.geojs.io *.avada.io *.feefo.com ekr.zdassets.com wss://widget-mediator.zopim.com/ *.doubleclick.net *.getflowbox.com *.zendesk.com *.google.es *.tawk.to *.rudderlabs.com *.rudderstack.com cdn-cookieyes.com *.cookieyes.com *.googlesyndication.com *.hotjar.com *.zopim.com *.facebook.com wss://*.tawk.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es cdn.dnky.co webchat.dotdigital.com www.facebook.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.gstatic.com *.googleapis.com data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es maps.gstatic.com *.facebook.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com www.gstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com cdn.ampproject.org www.googleapis.com *.google-analytics.com analytics.google.com *.facebook.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-75e35e8b8425469fa392310352c50b51' https://mychart-p.well-net.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart-p.well-net.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=3g1tNKV7ABbdZDWA6Xi5smgN8eAUwJevKrl6T7URrG0-1765935559-1.0.1.1-wyoWLt2rirnkGPwge01MgDln.vrFw0JGzVay7L2v5Iy82_3KwmDi0biYtRiyj.AlSndRuuXThbfHnW6PmfGEMEanKIWnLc51mMFmaDVZ82LifIpU460kwp66rvQ_waz2HckTxz7aZ9JsuHUOXBm37c_XyP6S9DqEvyt44DGdj2N5aKYcfkZagQtYl6mhGMNK; report-to cf-csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; require-trusted-types-for 'script'; style-src * 'unsafe-inline' 'unsafe-eval' data: blob:; style-src-attr * 'unsafe-inline' data: blob:; style-src-elem * 'unsafe-inline' data: blob:; font-src * data: blob:; img-src 'self' https://cdn.cigdigital.net https://www.google.com https://www.google.co.uk https://securepubads.g.doubleclick.net https://ad.doubleclick.net https://tpc.googlesyndication.com https://ep1.adtrafficquality.google https://ade.googlesyndication.com https://s0.2mdn.net https://googleads.g.doubleclick.net https://ads.adventive.com https://assets.adventivecdn.com https://up.clickiocdn.com https://clickiocmp.com https://px.ads.linkedin.com/ https://www.facebook.com/ data: blob:; connect-src *; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'; report-to csp-endpoint; report-uri /csp-report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-rMNh6-QFFU_gHwfLibiAWg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'self' 'nonce-qyaismhGpmYXLRZP14MGViAeQKRfNnFiKJmFclz1N8MfeYnLEZPykw' https://*.google.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.d21y75miwcfqoq.cloudfront.net *.mapsresources-pa.googleapis.com *.pagead2.googlesyndication.com *.googleapis.com *.gstatic.com *.googlesyndication.com *.google.ch *.google.es *.cloudfront.net *.linkedin.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.www.googletagmanager.com *.googletagmanager.com; style-src-elem 'self' 'nonce-qyaismhGpmYXLRZP14MGViAeQKRfNnFiKJmFclz1N8MfeYnLEZPykw' https://fonts.gstatic.com https://fonts.googleapis.com *.googleapis.com *.gstatic.com 'report-sample'; script-src-elem 'self' 'nonce-qyaismhGpmYXLRZP14MGViAeQKRfNnFiKJmFclz1N8MfeYnLEZPykw' 'strict-dynamic' https: 'unsafe-eval' blob: https://www.googletagmanager.com *.googletagmanager.com 'report-sample'; connect-src 'self' *.google.com https://*.googleapis.com https://*.gstatic.com blob: data: *.mapsresources-pa.googleapis.com *.pagead2.googlesyndication.com *.mirabaud.matomo.cloud *.cdn.cookielaw.org *.googleapis.com *.gstatic.com *.googlesyndication.com *.googleadservices.com *.matomo.cloud *.cookielaw.org *.onetrust.com; font-src 'self' https://fonts.gstatic.com; worker-src 'self' 'nonce-qyaismhGpmYXLRZP14MGViAeQKRfNnFiKJmFclz1N8MfeYnLEZPykw' blob:; report-uri https://www.mirabaud.com/en/@http-reporting?csp=report&requestTime=1765938125019253&requestHash=4be953a6e8a6f26ae41dfb2935933e97d82f072a 1 font-src fonts.gstatic.com https://fonts.gstatic.com *.gstatic.com data: cdn.jsdelivr.net *.fontawesome.com https://www.google.com https://www.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.gstatic.com *.googleapis.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.google.fr *.google.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net *.googleapis.com *.gstatic.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com s7.addthis.com *.google.com https://cdnjs.cloudflare.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.getalma.eu *.googleapis.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ekr.zdassets.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ccavenue.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.ccavenue.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ccavenue.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.ccavenue.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.ccavenue.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://ggj3qf05xeualpl0weo7xdrg.httpschecker.net/report 1 default-src 'self' https://*.weerplaza.nl https://*.windguru.cz https://*.buienradar.nl https://*.knmi.nl; base-uri 'self'; frame-src 'self' https://*.windguru.cz; frame-ancestors 'self'; form-action 'self'; 1 worker-src blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.kxcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.holest.com d3hqo5epsodxzz.cloudfront.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.addthis.com *.holest.com d3hqo5epsodxzz.cloudfront.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.cdninstagram.com *.fbcdn.net *.holest.com d3hqo5epsodxzz.cloudfront.net magefan.com cm.magefan.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com 'unsafe-inline' *.addthis.com *.addthisedge.com *.moatads.com static.cloudflareinsights.com *.holest.com d3hqo5epsodxzz.cloudfront.net s7.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com *.googletagmanager.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.holest.com d3hqo5epsodxzz.cloudfront.net ekr.zdassets.com/ *.doubleclick.net *.googlesyndication.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.addthis.com *.google.com/ *.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://images.unsplash.com https://www.magezon.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net s7.addthis.com *.google.com/ *.mlstatic.com *.mercadopago.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.jsdelivr.net *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com ekr.zdassets.com/ *.mercadopago.com *.mercadolibre.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' 'unsafe-inline'; font-src 'self'; form-action 'self; base-uri 'self';default-src 'self' 1 connect-src * ;default-src 'self' 'nonce-wpIlvO3/lCWbhRJQJ2H2Be83RIg=';font-src * ;frame-ancestors 'self' www.googletagmanager.com *.google.com *.gstatic.com ;frame-src 'self' www.googletagmanager.com *.google.com *.gstatic.com *.stripe.com ;img-src * ;media-src * ;object-src * ;script-src 'self' *.addthis.com *.addthisedge.com *.google-analytics.com ajax.googleapis.com *.azure.com www.googletagmanager.com *.google.com *.gstatic.com *.mikmak.ai code.jquery.com cdnjs.cloudflare.com cdn.jsdelivr.net *.facebook.com *.facebook.net *.swaven.com *.stripe.com 'unsafe-eval' 'nonce-wpIlvO3/lCWbhRJQJ2H2Be83RIg=';style-src 'self' 'unsafe-inline' ; 1 font-src fonts.googleapis.com fonts.gstatic.com v2.zopim.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com identity.bluebirdday.io accounts.google.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.google.com www.youtube.com www.facebook.com v2.zopim.com https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com www.google.nl www.facebook.com widgets.trustedshops.com v2assets.zopim.com v2assets.zopim.io v2.zopim.com v2.zopim.io *.fs1.hubspotusercontent-na1.net maps.googleapis.com maps.gstatic.com perf-na1.hsforms.com ct.pinterest.com perf.hsforms.com track.hubspot.com no-cache.hubspot.com f.hubspotusercontent10.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com maps.googleapis.com widgets.trustedshops.com www.dwin1.com v2.zopim.com connect.facebook.net static.zdassets.com ekr.zdassets.com www.facebook.com checkout.buckaroo.nl js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hsleadflows.net js.hubspot.com s.pinimg.com js.hscta.net cta-service-cms2.hubspot.com ct.pinterest.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com checkout.buckaroo.nl maps.googleapis.com fonts.googleapis.com *.fontawesome.com *.multisafepay.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com v2.zopim.com stats.g.doubleclick.net region1.google-analytics.com ekr.zdassets.com widget-mediator.zopim.com wss://widget-mediator.zopim.com v2assets.zopim.io api.hubapi.com *.hubspot.com maps.googleapis.com *.googletagmanager.com js.hs-banner.com ct.pinterest.com ipinfo.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'strict-dynamic' 'nonce-neJD09RHWdX5ZFUQSbf+jw==' 'sha256-/JqT3SQfawRcv/BIHPThkBvs0OEvtFFmqPF/lYI/Cxo=' 'sha384-RuyvpeZCxMJCqVUGFI0Do1mQrods/hhxYlcVfGPOfQtPJh0JCw12tUAZ/Mv10S7D' 'sha384-I7E8VVD/ismYTF4hNIPjVp/Zjvgyol6VFvRkX/vR+Vc4jQkC+hVqc2pM8ODewa9r' 'sha256-AlTido85uXPlSyyaZNsjJXeCs07eSv3r43kyCVc8ChI=' 'sha256-5kTP1GtVzERrwf+MJaNPcX7idt6AAoXDzcgeL9RbcGQ=' https: http:; style-src 'self' https://fonts.googleapis.com https://ajax.googleapis.com 'nonce-neJD09RHWdX5ZFUQSbf+jw==' https://ka-p.fontawesome.com; style-src-elem 'self' https://p.typekit.net https://use.typekit.net https://ajax.googleapis.com https://fonts.googleapis.com 'nonce-neJD09RHWdX5ZFUQSbf+jw==' 'sha256-5kTP1GtVzERrwf+MJaNPcX7idt6AAoXDzcgeL9RbcGQ='; font-src 'self' https://fonts.gstatic.com https://use.typekit.net https://ka-p.fontawesome.com; img-src 'self' data: https://www.google-analytics.com; connect-src 'self' https://www.google-analytics.com https://ka-p.fontawesome.com; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com/; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; require-trusted-types-for 'script'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-VaellHY+qWGhBIY1CMuwBShzLJI=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 block-all-mixed-content; frame-ancestors 'self'; upgrade-insecure-requests 1 base-uri 'none'; child-src 'none'; connect-src 'self' 'unsafe-inline' https://esp.aptrinsic.com https://esp-m.aptrinsic.com https://assets.adobedtm.com https://bat.bing.com https://cdn-ukwest.onetrust.com *.google-analytics.com *.google.com https://*.googletagmanager.com *.doubleclick.net https://bam.nr-data.net https://geolocation.onetrust.com https://services.postcodeanywhere.co.uk https://invitejs.trustpilot.com api.hcaptcha.com api2.hcaptcha.com https://*.stripe.com *.acsbapp.com https://backend.acsbapp.com/ https://cdn.acsbapp.com *.google.co.uk https://pagead2.googlesyndication.com https://o2.mouseflow.com ws://localhost:12387 https://privacyportal-uk.onetrust.com https://*.hotjar.io wss://*.hotjar.com https://*.hotjar.com https://cdn.livechatinc.com https://api.livechatinc.com/ https://www.wepowerconnections.com https://www.awinblackfriday.com/ https://cdn.cookielaw.org wss://api-fra.livechatinc.com https://eu01.rec.mouseflow.com https://acsbapp.com https://cta-eu1.hubspot.com https://api-eu1.hubspot.com https://api-eu1.hubapi.com https://forms-eu1.hsforms.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://www.googleadservices.com; default-src 'self'; font-src 'self' *.stripe.com *.stripecdn.com https://script.hotjar.com https://fonts.gstatic.com/*; form-action 'self'; frame-src 'self' https://td.doubleclick.net b.stripecdn.com *.stripe.com m.stripe.network newassets.hcaptcha.com https://www.googletagmanager.com https://secure-fra.livechatinc.com https://*.hs-sites-eu1.com https://app-eu1.hubspot.com https://www.youtube.com; frame-ancestors 'self' *.stripe.com https://stripe.com; img-src 'self' https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://cdn-ukwest.onetrust.com https://bat.bing.com https://www.facebook.com https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com https://*.google.co.uk https://lantern.roeye.com/track.php https://apetito.co.uk https://services.postcodeanywhere.co.uk/ https://c5.adalyser.com https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://www.awin1.com/sread.php https://www.awin1.com/sread.img https://track-eu1.hubspot.com/* https://www.facebook.com/* https://perf-eu1.hsforms.com/* https://px.ads.linkedin.com/* https://www.googleadservices.com/* https://wiltshirefarmfoods.com/media/* https://www.wiltshirefarmfoods.com/media/* https://analytics.twitter.com https://t.co/* https://i.ytimg.com/*; manifest-src 'none'; media-src 'self'; script-src 'self' 'unsafe-inline' googleads.g.doubleclick.net googletagmanager.com *.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net www.google-analytics.com connect.facebook.net https://acsbapp.com/apps/app/dist/js/loader.js https://acsbapp.com/apps/app/dist/js/app.js assets.adobedtm.com web-sdk.aptrinsic.com bat.bing.com https://app.leadsrx.com/visitor.js api.livechatinc.com js-agent.newrelic.com js.stripe.com *.stripecdn.com invitejs.trustpilot.com merchant-ui-api.stripe.com hcaptcha.com newassets.hcaptcha.com https://acsbapp.com/apps/* https://*.google.co.uk 'unsafe-eval' https://script.hotjar.com https://www.awin1.com/sread.js https://www.dwin1.com/2536.js https://lantern.roeyecdn.com/lantern_global_2536.min.js https://c5.adalyser.com/adalyser.js https://cdn.cookielaw.org/scripttemplates/otSDKStub.js https://cdn.mouseflow.com *.static.hotjar.com https://static.hotjar.com/ https://widget.trustpilot.com https://cdn-ukwest.onetrust.com https://api-fra.livechatinc.com cdn.livechatinc.com https://unpkg.com/web-vitals@4.2.4/* https://unpkg.com/web-vitals/* https://unpkg.com/web-vitals/dist/web-vitals.iife.js https://145747460.fs1.hubspotusercontent-na1.net/* https://145747460.fs2.hubspotusercontent-na1.net/* https://145747460.fs1.hubspotusercontent-eu1.net/* https://145747460.fs2.hubspotusercontent-eu1.net/* https://js-eu1.hubspot.com/* https://js-eu1.hsadspixel.net/* https://js-eu1.hs-analytics.net/* https://static.hsappstatic.net/* https://js-eu1.usemessages.com/* https://js-eu1.hs-banner.com/* https://js-eu1.hs-scripts.com/* https://static.cloudflareinsights.com/* https://www.youtube.com/* https://assets.ubembed.com/universalscript/* https://performance.radar.cloudflare.com/* https://snap.licdn.com/li.lms-analytics/* https://www.gstatic.com/* https://script.infinity-tracking.com/* https://apeti11122.pcapredict.com/* https://static.ads-twitter.com/*; style-src 'self' 'unsafe-inline' *.stripecdn.com *.stripe.network https://static.hotjar.com https://script.hotjar.com https://fonts.googleapis.com/*; worker-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=TGZCDSa_kxpiZSrqmqQNlpyWODmC2yQO4_cuoAZCcAQ-1765938779.1206677-1.0.1.1-919ayLyr3C.aaIArf1pP8J08v1gHt0WEYXZez_nbYMFMiqkExoxGkDmABl65ZsePhErQmeRooXV5jbCpvgjbmax582QaSmNVzEbZCxIZKMDZxycpJAx.s7nwKIjovsX9XPc7C49RTIlzCkDrEw6rOgxuU.f1prR2CDZDc0puDyvKyzrF6L3wFmDqDYuX8t6cRi95yOYJ2I51WM6ooGwK8A; report-to cf-lklfqbjeccthhekx 1 default-src https: 'unsafe-eval' 'unsafe-inline' 1 img-src https://higherlogicdownload.s3.amazonaws.com/THEACA/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/THEACA/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/THEACA/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/THEACA/ https://higherlogicdownload.s3.amazonaws.com/THEACA/ https://higherlogiclongterm.s3.amazonaws.com/THEACA/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/THEACA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/THEACA/ 'self' https://higherlogiclongterm.s3.amazonaws.com/THEACA/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/THEACA/ https://higherlogicdownload.s3.amazonaws.com/THEACA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/THEACA/ https://higherlogicstream.s3.amazonaws.com/THEACA/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/THEACA/ https://higherlogicdownload.s3.amazonaws.com/THEACA/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/THEACA/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com https://plumrocket.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com/ web.e.test.connect.paymentsense.cloud web.e.connect.paymentsense.cloud *.paymentsensegateway.com:4430 https://plumrocket.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://www.magezon.com www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.google.com/ web.e.test.connect.paymentsense.cloud web.e.connect.paymentsense.cloud www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com maxcdn.bootstrapcdn.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es thm.visa.com www.paypal.com www.sandbox.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com fonts.googleapis.com *.remote-ag.dojo.tech yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com www.promessedefleurs.es data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com www.promessedefleurs.es 'self' 'unsafe-inline'; frame-ancestors www.promessedefleurs.es 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.promessedefleurs.es 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure-magenta.dalenys.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie www.promessedefleurs.es data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com cl.avis-verifies.com bat.bing.com s.pinimg.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://unpkg.com/pwacompat www.promessedefleurs.es 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com unpkg.com www.promessedefleurs.es 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.promessedefleurs.es 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net www.promessedefleurs.es 'self' 'unsafe-inline'; child-src www.promessedefleurs.es http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com www.promessedefleurs.es 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://*.ipay88.com.ph https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.net *.facebook.com https://*.ipay88.com.ph https://plumrocket.com amc.demdex.net www.facebook.com web.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.googleapis.com maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.gstatic.com *.facebook.net connect.facebook.net https://*.ipay88.com.ph www.google.com www.gstatic.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://*.ipay88.com.ph www.facebook.com maps.googleapis.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.doubleclick.net *.gstatic.com *.googleapis.com; font-src data: *.bootstrapcdn.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.cookielaw.org *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webpaypaymentgatewaystage.svea.com webpaypaymentgateway.svea.com cardtest.svea.com card.svea.com checkout.trustly.com *.twitter.com *.cookielaw.org *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com checkoutapistage.svea.com checkoutapi.svea.com js.playground.klarna.com www.js.playground.klarna.com *.twitter.com js.klarna.com *.consensu.org *.sharethis.com youtube.com www.youtube.com linkedin.com www.linkedin.com *.google.com *.vimeo.com widget.trustpilot.com ecommscript-integrationapp.trustpilot.com *.cookielaw.org *.googletagmanager.com td.doubleclick.net *.clarity.ms *.doubleclick.net *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.vimeocdn.com s.ytimg.com data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com eu.playground.klarnaevt.com www.eu.playground.klarnaevt.com *.cloudfront.net *.cloudflare.com eu.klarnaevt.com *.google.com *.google.se *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.lightemporium.com *.usercentrics.eu *.sharethis.com api.unifaun.com *.googletagmanager.com *.cookielaw.org *.googleusercontent.com *.bing.com *.clarity.ms *.doubleclick.net www.google.com.ua *.google.pl *.gstatic.com *.analytics.google.com app.cookieyes.com dashboard.feedbucket.app *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com *.google-analytics.com secure.authorize.net test.authorize.net s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net cdn-scripts.signifyd.com www.youtube.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com googleads.g.doubleclick.net checkoutapistage.svea.com checkoutapi.svea.com connect.getflowbox.com www.connect.getflowbox.com js.playground.klarna.com www.js.playground.klarna.com cdn.addwish.com www.cdn.addwish.com addwish.com www.addwish.com *.cloudfront.net js.klarna.com chimpstatic.com www.chimpstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.google.com *.sharethis.com platform.linkedin.com www.platform.linkedin.com www.linkedin.com www.ehandelscertifiering.se static.zdassets.com www.static.zdassets.com widget.trustpilot.com www.widget.trustpilot.com invitejs.trustpilot.com www.invitejs.trustpilot.com www.googletagmanager.com widget-mediator.zopim.com www.googleanalytics.com www.googleoptimize.com ecommplugins-trustboxpreview.trustpilot.com *.googleapis.com *.cookielaw.org *.clerk.io core.helloretail.com www.core.helloretail.com *.bing.com *.clarity.ms *.adobedtm.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net app.cookieyes.com cdn.feedbucket.app *.avada.io https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.bootstrapcdn.com *.cloudfront.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com addwish.com www.addwish.com optimize.google.com *.cookielaw.org *.googletagmanager.com app.cookieyes.com cdn.feedbucket.app maxcdn.bootstrapcdn.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com static.zdassets.com *.cookielaw.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com eu.playground.klarnaevt.com www.eu.playground.klarnaevt.com addwish.com www.addwish.com core.helloretail.com www.core.helloretail.com eu.klarnaevt.com www.eu.klarnaevt.com *.doubleclick.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com cicptqmkej.execute-api.eu-west-1.amazonaws.com app.getsentry.com terrang.zendesk.com www.terrang.zendesk.com ekr.zdassets.com www.ekr.zdassets.com 9mn3sm7015.execute-api.eu-west-1.amazonaws.com wss://widget-mediator.zopim.com/ *.cookielaw.org europe-west1-bold-sorter-288913.cloudfunctions.net dpm.demdex.net *.clarity.ms *.google.com *.bing.com google.com *.googlesyndication.com *.googletagmanager.com *.analytics.google.com region1.google-analytics.com dashboard.feedbucket.app cdn.feedbucket.app https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src custom.intucdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.bunny.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.google.com *.doubleclick.net *.facebook.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.adyen.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.clerk.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.adyen.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io *.googleapis.com google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://cdnjs.cloudflare.com cdnjs.cloudflare.com *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io google.com *.kxcdn.com downloads.mailchimp.com https://cdnjs.cloudflare.com cdnjs.cloudflare.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://core.helloretail.com https://helloretailcdn.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.productreview.com.au data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.google.com *.google.com.vn *.productreview.com.au pliable.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.cloudflare.com *.productreview.com.au *.afterpay.com portal.sandbox.afterpay.com *.vertexsmb.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.productreview.com.au *.afterpay.com portal.sandbox.afterpay.com pliable.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.facebook.com *.dotdigital-pages.com *.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.weltpixel.com 'self' 'unsafe-inline'; img-src https://assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.facebook.com https://www.google.co.in https://cdn.hoolah.co https://scontent.cdninstagram.com/ https://d27eqfoeueoniv.cloudfront.net https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://scontent-sin6-1.cdninstagram.com https://scontent-sin6-2.cdninstagram.com/ https://scontent-sin6-3.cdninstagram.com https://scontent-sin6-4.cdninstagram.com *.clarity.ms *.bing.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.dycdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://connect.facebook.net *.tiktok.com *.cloudfront.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com *.google.com www.facebook.com https://merchant.cdn.hoolah.co https://merchant.cdn.hoolah.co.net *.trackedweb.net *.hit-pay.com *.clarity.ms https://hit-pay.com/hitpay.js https://am.freshrelevance.com/ *.assets.adobedtm.com *.trackedlink.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net am.freshrelevance.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://merchant.cdn.hoolah.co https://cdn.hoolah.co https://cdnjs.cloudflare.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.doubleclick.net *.facebook.net *.facebook.com https://web.facebook.com *.demdex.net *.omtrdc.net *.tiktok.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.paypalobjects.com *.trackedweb.net https://melissa.com.sg/fbe/Pixel/ProductInfoForAddToCart *.clarity.ms wss://am.freshrelevance.com/ https://am.freshrelevance.com *.dycdn.net *.trackedlink.net *.dotdigital-pages.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com am.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.analytics.google.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' matchgroup.okta.com *.oktacdn.com; connect-src 'self' matchgroup.okta.com matchgroup-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com matchgroup.kerberos.okta.com matchgroup.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; script-src 'unsafe-inline' 'nonce-edSCyKBkvhWfbRcNc9I_wg' 'unsafe-eval' 'self' 'report-sample' matchgroup.okta.com *.oktacdn.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'unsafe-inline' 'self' 'report-sample' matchgroup.okta.com *.oktacdn.com; frame-src 'self' matchgroup.okta.com matchgroup-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; img-src 'self' matchgroup.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' matchgroup.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://docs.matchgroupcentral.net 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.cloudflare.com https://*.pinterest.com https://*.google-analytics.com https://*.googletagmanager.com https://*.youtube.com https://*.vimeocdn.com https://*.vimeo.com https://*.hotjar.com https://*.visualwebsiteoptimizer.com https://*.klarna.com https://*.facebook.net https://*.bing.com https://*.pinimg.com https://*.google.com https://*.getflowbox.com https://*.sprell-no.getadigital.cloud https://*.sprell.no https://*.adsrvr.org https://*.googleadservices.com https://*.clarity.ms https://*.cookieinformation.com https://*.itxuc.com https://*.doubleclick.net https://*.cognitionhub.no https://*.z03.azurefd.net https://*.pingdom.com https://*.vipps.no; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.mapbox.com https://*.typekit.net https://*.googletagmanager.com https://*.sprell-no.getadigital.cloud https://*.sprell.no https://*.itxuc.com; img-src 'self' data: blob: https://*.google.no https://*.clarity.ms https://*.ytimg.com https://*.vimeocdn.com https://*.googleadservices.com https://*.google-analytics.com https://*.sanity.io https://*.visualwebsiteoptimizer.com https://*.klarnaevt.com https://*.pinterest.com https://*.bing.com https://*.facebook.com https://*.facebook.net https://*.adyen.com https://*.gstatic.com https://d2rfa446ja7yzb.cloudfront.net https://*.googletagmanager.com https://*.sprell-no.getadigital.cloud https://*.sprell.no https://*.google.no https://*.google.com https://*.adsrvr.org https://*.doubleclick.net https://stsprellomnium.blob.core.windows.net https://*.sprell.no https://*.google.rs https://*.googleapis.com; font-src 'self' data: https://*.gstatic.com https://*.typekit.net https://*.sprell-no.getadigital.cloud https://*.sprell.no; connect-src 'self' https://*.clarity.ms https://*.visualwebsiteoptimizer.com https://*.bing.com https://*.google-analytics.com https://vimeo.com https://*.mapbox.com https://*.sanity.io https://*.klarnaevt.com https://*.adyen.com https://*.pinterest.com https://*.getflowbox.com https://*.google.com https://google.com https://*.analytics.google.com https://*.sprell-no.getadigital.cloud https://*.sprell.no https://*.doubleclick.net https://*.googlesyndication.com https://*.cookieinformation.com https://*.facebook.com https://*.cognitionhub.no https://*.pingdom.com https://*.omnium.no https://*.adsrvr.org; base-uri 'self'; frame-ancestors 'self' https://sprell-no.sanity.studio https://sprell-no.getadigital.cloud https://*.sprell.no; frame-src 'self' https://*.youtube.com https://*.vimeo.com https://*.hotjar.com https://*.klarna.com https://*.facebook.com https://*.googletagmanager.com https://*.pinterest.com https://*.adyen.com https://*.google.com https://google.com https://*.adsrvr.org https://*.cookieinformation.com https://*.itxuc.com https://*.doubleclick.net https://*.sebkort.com https://*.3dsecure.no https://*.americanexpress.com https://*.google.com https://*.edb.com https://*.danskebank.com https://*.nordea.com; form-action 'self' https://*.facebook.com https://*.googletagmanager.com https://*.adyen.com https://*.sebkort.com https://*.3dsecure.no https://*.americanexpress.com https://*.google.com https://*.edb.com https://*.danskebank.com https://*.nordea.com; manifest-src 'self'; media-src 'self' data: https://*.flbx.io; object-src 'self'; child-src 'self'; worker-src 'self' blob:; report-to csp; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarnaevt.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'unsafe-eval' 'unsafe-inline' analytics.twitter.com www.googleadservices.com c.la2-c1-ph2.salesforceliveagent.com d.la3-c1-ph2.salesforceliveagent.com bat.bing.com c.paypal.com teechip.com d18p8z0ptb8qab.cloudfront.net fast.appcues.com cdn.freshmarketer.com edge.fullstory.com fullstory.com api.scalablelicensing.com cdn.32pt.com dbcpu9gznkryx.cloudfront.net js.stripe.com www.google.com www.paypal.com www.paypalobjects.com www.gstatic.com www.google-analytics.com static.ads-twitter.com s.pinimg.com googleads.g.doubleclick.net www.googletagmanager.com connect.facebook.net;style-src 'unsafe-inline' cdn.32pt.com teechip.com fast.appcues.com translate.googleapis.com inkp-production.32pt.com fonts.googleapis.com p.typekit.net use.typekit.net;font-src inkp-production.32pt.com cdn.32pt.com data: fonts.gstatic.com teechip.com use.typekit.net;img-src * data: blob:;frame-src checkout.stripe.com fbrpc: www.facebook.com www.google.com bid.g.doubleclick.net assets.braintreegateway.com js.stripe.com www.googletagmanager.com www.paypalobjects.com;object-src 'none';connect-src dbcpu9gznkryx.cloudfront.net translate.googleapis.com checkout.stripe.com bat.bing.com api.appcues.net fast.appcues.com www.google.com graph.facebook.com z-m-graph.facebook.com launcher.teechip.com rs.fullstory.com client-analytics.braintreegateway.com www.facebook.com app.getsentry.com api.braintreegateway.com stats.g.doubleclick.net teechip.com wss://api.appcues.net www.paypal.com api.scalablelicensing.com scalable-licensing.s3.amazonaws.com www.google-analytics.com ct.pinterest.com src.freshmarketer.com sentry.io t.getletterpress.com m.stripe.com scalablepress.com; report-uri /__csp-reports; 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.usercentrics.eu 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://www.loewen.de https://maps.gstatic.com https://maps.google.com https://maps.googleapis.com https://www.youtube.com https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.usercentrics.eu https://medien.loewen.de https://medien.loewen-kundenportal.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://vimeo.com https://www.googletagmanager.com https://*.usercentrics.eu; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.usercentrics.eu 'report-sample'; connect-src 'self' data: https://*.openstreetmap.org https://maps.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com https://*.analytics.google.com https://*.usercentrics.eu; font-src 'self' https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' 'report-sample'; script-src-elem 'self' 'sha256-kmB83Qlmak1+ekHFk+S5GfHhbvJrD6n2YITJgFDEWWQ=' https://maps.google.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://*.usercentrics.eu 'report-sample'; report-uri https://www.loewen.de/@http-reporting?csp=report&requestTime=1765933999489953&requestHash=73e38d37e9f7384bb46aecec2c213f06034a4705 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.magneticnaildesign.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://instant.page *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.myfonts.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: https://maxcdn.bootstrapcdn.com *.livehelpnow.net *.hotjar.com *.fontawesome.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.canadapost.ca https://sso.epost.ca *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.gstatic.com *.google.com roundme.com *.facebook.com www.xtento.com *.authorize.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com *.livehelpnow.net https://www.facebook.com *.fbcdn.net *.google.com *.google.ca *.authorize.net *.bing.com *.beachcomberhottubs.com *.cdninstagram.com www.xtento.com cdn.xtento.com mageside.com *.canadapost.ca maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://connect.facebook.net *.newrelic.com *.nr-data.net *.hotjar.com *.bing.com *.polyfill.io *.jquery.com *.jsdelivr.net *.cloudflare.com *.livehelpnow.net *.google.com www.xtento.com cdn.xtento.com *.authorize.net maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.livehelpnow.net *.fontawesome.com *.jsdelivr.net *.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com data: *.livehelpnow.net *.doubleclick.net *.nr-data.net wss://app.livehelpnow.net/ *.hotjar.com wss://wsp25.hotjar.com/ *.google.ca *.authorize.net *.bing.com *.polyfill.io *.beachcomberhottubs.com *.hotjar.io wss://wsp37.hotjar.com/ *.clickdimensions.com *.instagram.com *.paypal.com maps.googleapis.com https://www.google-analytics.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce-tUAfyw53pqUBHabC9AMb' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 img-src 'self' data: https://googleads.g.doubleclick.net https://www.googletagmanager.com https://pixel.wp.com https://aws-obg-image-lb-5.tcl.com https://b.tile.openstreetmap.org https://cdn.razorpay.com https://a.tile.openstreetmap.org https://www.google.co.in https://www.apple.com https://nandilathgmart.com https://translate.google.com https://fonts.gstatic.com https://cdn.anscommerce.com https://c.tile.openstreetmap.org https://apps.apple.com https://aws-obg-image-lb-4.tcl.com https://aws-obg-image-lb-2.tcl.com https://cdn.honey.io https://static-obg.tcl.com https://aws-obg-image-lb-3.tcl.com https://aws-obg-image-lb-1.tcl.com https://www.google.ae https://i.ytimg.com blob: https://woodmart.xtemos.com https://assets.elementor.com https://www.google.com.bd https://www.nandilathgmart.com https://l.facebook.com https://woocommerce.com https://www.google.com.au https://www.gstatic.com https://pagead2.googlesyndication.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://script.hotjar.com https://static.hotjar.com https://cdn.razorpay.com https://checkout.razorpay.com https://stats.wp.com https://pagead2.googlesyndication.com https://www.youtube.com https://connect.facebook.net https://ff.kis.v2.scr.kaspersky-labs.com https://nandilathgmart.com https://yoast.com https://gc.kis.v2.scr.kaspersky-labs.com blob: https://infird.com https://maps.google.com https://gc.kis.scr.kaspersky-labs.com https://cdnjs.cloudflare.com https://secured-pixel.com https://gc.kes.v2.scr.kaspersky-labs.com http://nandilathgmart.com https://me.kis.v2.scr.kaspersky-labs.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://script.hotjar.com https://static.hotjar.com https://cdn.razorpay.com https://checkout.razorpay.com https://stats.wp.com https://pagead2.googlesyndication.com https://www.youtube.com https://connect.facebook.net https://ff.kis.v2.scr.kaspersky-labs.com https://nandilathgmart.com https://yoast.com https://gc.kis.v2.scr.kaspersky-labs.com blob: https://infird.com https://maps.google.com https://gc.kis.scr.kaspersky-labs.com https://cdnjs.cloudflare.com https://secured-pixel.com https://gc.kes.v2.scr.kaspersky-labs.com http://nandilathgmart.com https://me.kis.v2.scr.kaspersky-labs.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://nandilathgmart.com https://ff.kis.v2.scr.kaspersky-labs.com https://adblockers.opera-mini.net https://cdn.honey.io data: https://www.gstatic.com https://gc.kis.v2.scr.kaspersky-labs.com http://nandilathgmart.com ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://nandilathgmart.com https://ff.kis.v2.scr.kaspersky-labs.com https://adblockers.opera-mini.net https://cdn.honey.io data: https://www.gstatic.com https://gc.kis.v2.scr.kaspersky-labs.com http://nandilathgmart.com ; font-src 'self' https://fonts.gstatic.com https://s0.wp.com https://nandilathgmart.com https://r2cdn.perplexity.ai https://www.slant.co https://cdn.scite.ai https://use.typekit.net data:; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://cdn.razorpay.com https://maps.google.com https://www.youtube.com https://api.razorpay.com https://div.show https://app.stylar.com blob:; connect-src 'self' https://www.google-analytics.com https://www.googleadservices.com https://yoast.com https://vc.hotjar.io https://www.google.com https://lumberjack.razorpay.com https://content.hotjar.io https://metrics.hotjar.io https://region1.google-analytics.com https://www.googletagmanager.com https://translate.googleapis.com https://nandilathgmart.com https://my.yoast.com https://www.google.co.in https://overbridgenet.com https://gjtrack.ucweb.com data: https://googleads.g.doubleclick.net https://metrics-dra.dt.dbankcloud.cn https://translate-pa.googleapis.com https://infragrid.v.network https://pagead2.googlesyndication.com https://maps.googleapis.com https://localhost; media-src 'self' data: https://d4qgj78fzsl5j.cloudfront.net; worker-src 'self' blob:; report-uri https://nandilathgmart.com/wp-json/rsssl/v1/csp?rsssl_apitoken=244797718; 1 font-src 'self' https://fonts.gstatic.com; frame-src 'self'; img-src 'self' data: https:; media-src 'self'; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net https://cdn.brevo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://ws.sharethis.com https://www.gstatic.com https://www.recaptcha.net; script-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js https://js-agent.newrelic.com cdn.jsdelivr.net https://cdn.brevo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://ws.sharethis.com https://www.gstatic.com https://www.recaptcha.net; style-src 'self' 'report-sample' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; worker-src 'self'; base-uri 'self' 1 font-src *.googleapis.com *.gstatic.com *.cloudflare.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.vimeo.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.youtube.com magefan.com cm.magefan.com *.cloudflare.com *.doofinder.com *.doofinder *.ytimg.com *.doubleclick.net *.casmarglobal.com *.google-analytics.com *.connectif.cloud akeneo.casmarglobal.com:8000 *.eu1-layer.doofinder.com www.vimeo.com imgsct.cookiebot.com cdn.doofinder.com storage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.clarity.ms *.bing.com *.google.es *.google.com.ar www.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.fontawesome.com *.cloudflare.com *.google-analytics.com *.connectif.cloud *.doofinder.com *.analytics.google.com *.casmarglobal.com pro.casmarglobal.com consent.cookiebot.com consentcdn.cookiebot.com cdn.doofinder.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cookiebot.com *.consent.cookiebot.com *.region1.analytics.google.com *.www.google.es *.clarity.ms *.licdn.com *.google.com consentcdn.cookiebot.com/sdk/bc-v4.min.html *.usercentrics.com *.usercentrics.eu *.consent.cookiebot.eu *.cdn.connectif.cloud *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.doofinder.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.google-analytics.com *.casmarglobal.com *.cookiebot.com *.connectif.cloud *.doofinder.com wss://*.doofinder.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.clarity.ms *.doubleclick.net *.usercentrics.com *.usercentrics.eu *.consent.cookiebot.eu cdn.connectif.cloud eu4-api.connectif.cloud *.consent.cookiebot.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; child-src 'self'; connect-src 'self' sicoob.com.br *.sicoob.com.br google.com *.google.com google-analytics.com *.google-analytics.com googleadservices.com *.googleadservices.com clarity.ms *.clarity.ms; default-src 'self' sicoob.com.br *.sicoob.com.br; font-src 'self'; frame-src 'self'; media-src 'self'; script-src 'self' sicoob.com.br *.sicoob.com.br google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com gstatic.com *.gstatic.com google.com *.google.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=GWMZx7GCouaJDPAJrEqKr3NJ6SzbnOnPg8UPOHP.Fc4-1765940312-1.0.1.1-qWzefUi7IV2qKkzdXAc7J4WUAougVTapU_EGzTVRCQFP0MAvB9onZ1HON3Hlq5IIRCnfil5OkJDj8wYhHBogURjWWcD.Lxbt4rTxJHm_Q.R5IUrcJH_w5hej5UaPyBaEq6Q2KCe3xpxM648InGsJKwwp0jIbXQ8A_LTf2IH6q8e0AOQ47DtZm7tvY02ijvynDJC8GE3zznmO6LOkKQUPOA; report-to cf-dtjlyblqlwfiryzw 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com *.klarnacdn.net 'self' data: *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.cloudflare.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: www.google.com.cy www.google.co.id www.google.com.qa *.googletagmanager.com www.google.com.co www.google.com.bh www.google.com.tw www.google.com.om *.wiska.com www.google.cv www.google.tn www.google.tt www.google.com.sg *.facebook.com www.google.nl www.google.co.in www.google.gg www.google.ge www.google.lk www.google.by www.google.ws www.google.com.lb www.google.at www.google.ad www.google.al www.google.ro www.google.no www.google.rs www.google.com.sv www.google.ie www.google.co.ke www.google.cd www.google.hr www.google.mw www.google.com.pa www.google.co.ve www.google.ae www.google.com.pg www.google.pl www.google.com.fj www.google.com.tr www.google.com.kw www.google.dk www.google.com.np www.google.com.uy www.google.pt www.google.se www.google.mg www.google.com.pe www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.hn www.google.com.bn www.google.ru www.google.jo www.google.co.cr www.google.it www.google.co.zm www.google.ch www.google.com.et *.i-sells.co.uk www.google.ee www.google.com.py www.google.hu www.google.co.ao *.bigcommerce.com www.google.sm www.google.com.pr www.google.iq www.google.ca www.google.com.cu www.google.li www.google.gy www.google.sn www.google.md www.google.com.mm www.google.co.jp www.google.am www.google.de www.google.cl www.google.com.vc *.doubleclick.net www.google.im www.google.es *.googlesyndication.com www.google.co.za www.google.com.ag www.google.lt www.google.is www.google.gm www.google.sc www.google.com.bo www.google.co.nz www.google.lu www.google.co.uk www.google.com.do www.google.co.zw www.google.com.eg www.google.com.gt www.google.co.ma www.google.la www.google.com.br www.google.com.jm www.google.cg www.google.com.bd www.google.tm www.google.fi www.google.sk www.google.dm www.google.co.ls www.google.kz www.google.co.ug www.google.com.ph www.google.je www.google.co.tz www.google.com.au www.google.ga www.google.si www.google.mn www.google.bs www.google.lv www.google.com.ec www.google.com.mt www.google.ba www.google.mk www.google.me www.google.st www.google.com.kh www.google.com.sa www.google.kg www.google.so www.google.bj *.wiska.co.uk www.google.cz www.google.dj www.google.bf www.google.co.th www.google.co.kr www.google.dz www.google.ci www.google.mv www.google.com.vn www.google.ps www.google.com.hk www.google.sh www.google.co.vi www.google.co.bw *.ytimg.com www.google.com.ua www.google.co.mz www.google.com.ar www.google.com.gh www.google.az www.google.rw www.google.com.ly www.google.bg www.google.co.uz www.google.com.pk www.google.com.my www.google.gr www.google.com.gi www.google.fr *.esellerpro.com www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.link.com *.trustpilot.com *.formilla.com *.buttonizer.io *.googletagmanager.com *.facebook.net *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.stripe.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.klarnacdn.net unsafe-inline assets.braintreegateway.com *.gstatic.com *.stripe.network *.stripecdn.com *.trustpilot.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src *.youtube.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.google.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com klarna.com *.link.com www.google.cz www.google.com.bd www.google.ee *.trustpilot.com www.google.co.ao www.google.lv www.google.com.gt www.google.tt www.google.com.gh www.google.com.ar www.google.co.uz www.google.co.zw www.google.ae www.google.gr www.google.mn www.google.ro *.buttonizer.io www.google.co.tz www.google.es www.google.com.np www.google.lu www.google.com.lb www.google.at www.google.com.pk www.google.bs www.google.ge www.google.com.ag www.google.bf www.google.se www.google.pl www.google.md www.google.so www.google.com.hk *.facebook.com www.google.ie www.google.com.vn www.google.de www.google.mu www.google.lk www.google.co.za www.google.co.kr www.google.fi www.google.com.ly www.google.cl www.google.com.pa www.google.be www.google.im www.google.com.bn www.google.com.ec www.google.dz www.google.co.cr www.google.co.ke *.googlesyndication.com www.google.tn www.google.com.uy *.doubleclick.net www.google.co.nz www.google.dj www.google.jo www.google.com.vc www.google.nl www.google.ch *.formilla.com www.google.az www.google.gg www.google.bg www.google.hn www.google.bj www.google.com.gi www.google.pt www.google.rs www.google.hu www.google.com.mx www.google.com.kh www.google.com.ua www.google.co.il www.google.co.uk www.google.fr www.google.co.in www.google.cd www.google.am www.google.mv www.google.iq www.google.co.jp www.google.co.bw www.google.com.br www.google.no www.google.com.om www.google.com.tw www.google.je www.google.com.pe www.google.lt www.google.com.kw www.google.dk www.google.com.tr www.google.hr www.google.co.ug www.google.com.au www.google.ru www.google.com.et www.google.co.zm www.google.li www.google.sk www.google.by www.google.com.sa www.google.ca www.google.com.qa www.google.com.sg www.google.com.eg www.google.co.id www.google.co.ls www.google.it www.google.al www.google.com.bh www.google.co.vi www.google.is www.google.com.do www.google.co.th www.google.rw www.google.com.ng www.google.sc www.google.com.ph www.google.com.bo www.google.co.ma www.google.com.cy www.google.com.co www.google.com.mt www.google.com.my www.google.mk www.google.si 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://fe01bf3e-e83e-4500-af8b-4766d0d3c786.sansec.watch/; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sendcloud.sc *.jsdelivr.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src *; script-src 'self' 'unsafe-inline' 'strict-dynamic' http: https: 'nonce-gr8p0p4rd1n1'; style-src 'self' 'unsafe-inline' http: https: data:; img-src 'self' 'unsafe-inline' http: https: data:; connect-src *; font-src 'self' 'unsafe-inline' http: https: data:; media-src *; report-uri *; child-src *; form-action *; frame-ancestors 'self'; object-src 'none'; frame-src *; worker-src *; manifest-src *; prefetch-src *; base-uri 'self' 'strict-dynamic' 1 style-src-elem https://*.googleapis.com https://*.gstatic.com https://*.feefo.com https://*.prommt.com https://product-locator.near.st https://*.salesfire.co.uk https://static.klaviyo.com cookiehub.net cdn.cookiehub.eu https://*.cookiebot.eu 'unsafe-inline' 'self'; script-src-elem https://connect.facebook.net https://*.facebook.com https://bat.bing.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.feefo.com https://*.algolia.net https://*.algolianet.com https://*.zdassets.com https://*.salesfire.co.uk https://*.klaviyo.com https://*.clarity.ms https://*.whizeo.com https://cdn.cookiehub.eu https://*.sweetanalytics.com https://secure.informationcreativeinnovative.com https://app.prommt.com https://product-locator.near.st https://*.cookiebot.eu 'unsafe-inline' 'unsafe-eval' 'self' *.cookiebot.com *.cookiebot.eu; font-src fonts.gstatic.com use.typekit.net https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com 'self' https://*.paypalobjects.com https://static.klaviyo.com https://script.hotjar.com *.fontawesome.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com https://safekeyacs.americanexpress.com https://www.facebook.com https://www.rsa3dsauth.co.uk https://www.securesuite.co.uk https://*.arcot.com https://*.monzo.com https://clients.smartsecure.tsys.co.uk https://authentication-acs.marqeta.com https://acs.apata.io https://*.modirum.com https://mycardsecure.com https://acs.touch.tech 'self' 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://safekeyacs.americanexpress.com https://acs.touch.tech https://mycardsecure.com https://*.doubleclick.net https://www.facebook.com https://tst.kaptcha.com https://*.google.com https://google.com https://www.googletagmanager.com https://www.gstatic.com/ https://*.youtube.com https://acs.revolut.com https://tpc.googlesyndication.com https://www.rsa3dsauth.co.uk https://*.arcot.com https://*.lloydsbankinggroup.com https://*.securesuite.co.uk https://*.ipg-online.com https://*.monzo.com https://clients.smartsecure.tsys.co.uk https://authentication-acs.marqeta.com https://acs.apata.io https://*.modirum.com https://register.feefo.com/ https://*.prommt.com https://product-locator.near.st https://*.starlingbank.com https://tourmkr.com *.cookiebot.com *.cookiebot.eu *.salesfire.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com *.gstatic.com maps.gstatic.com * 'self' https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.salesfire.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com polyfill.io tagmanager.google.com https://www.googletagmanager.com *.googleapis.com https://connect.facebook.net https://*.facebook.com https://bat.bing.com https://maps.googleapis.com https://*.doubleclick.net https://*.feefo.com https://*.jquery.com https://*.google.com https://www.gstatic.com https://*.algolia.net https://*.algolianet.com https://*.googlesyndication.com https://*.google-analytics.com https://*.zdassets.com https://*.sweetanalytics.com https://*.hotjar.com https://*.klaviyo.com *.prommt.com https://*.clarity.ms https://cdn.jsdelivr.net https://product-locator.near.st https://*.inspiration-insight.com https://secure.informationcreativeinnovative.com https://*.amazonaws.com https://*.whizeo.com https://*.whizeoapi.com cookiehub.net cdn.cookiehub.eu 'unsafe-inline' 'self' *.cookiebot.com *.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.salesfire.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://*.googleapis.com https://*.feefo.com https://*.gstatic.com https://*.prommt.com https://product-locator.near.st https://*.klaviyo.com cookiehub.net cdn.cookiehub.eu https://app.prommt.com 'unsafe-inline' 'self' *.fontawesome.com https://static.klaviyo.com *.salesfire.co.uk *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://www.google-analytics.com *.googleapis.com https://*.feefo.com https://bat.bing.com https://www.paypal.com https://www.facebook.com https://*.google-analytics.com https://*.doubleclick.net https://*.googleapis.com https://*.google.com https://google.com https://www.googletagmanager.com https://*.zdassets.com https://*.zendesk.com wss://*.zopim.com https://*.sweetanalytics.com https://*.clarity.ms https://*.klaviyo.com https://fast.a.klaviyo.com https://static-forms.klaviyo.com https://*.googlesyndication.com https://*.algolia.io https://*.hotjar.io wss://*.hotjar.com https://bat.bing.net https://product-locator.near.st ds.cookiehub.net consent.cookiehub.net region-eu.cookiehub.net consent-eu.cookiehub.net cookiehub.net cdn.cookiehub.eu https://api.whizeo.com https://test-drive-20-1053047382554.us-central1.run.app 'self' *.cookiebot.com *.cookiebot.eu *.ideal-postcodes.co.uk https://static.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.salesfire.co.uk *.smartmetrics.co.uk 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: *.zip.co *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ blob: *.fmicassets.com *.facebook.com *.google.co.in *.zip.co zip.co *.bing.com *.google.com.pk moogento.com *.moogento.com *.zipmoney.com.au *.kxcdn.com *.prf.hn *.aaronknightdev.com https://redchamps.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://api.addressfinder.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net *.hotjar.com *.jsdelivr.net *.clarity.ms *.bing.com *.cloudflareinsights.com l2.moogento.com *.zipmoney.com.au *.zip.co *.addthis.com *.studio19.com.au *.zdassets.com *.cloudflare.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.addressfinder.io assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com *.typekit.net *.zip.co https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://api.addressfinder.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.hotjar.io *.hotjar.com *.facebook.com *.doubleclick.net *.clarity.ms wss://ws.hotjar.com *.zipmoney.com.au *.zip.co *.zendesk.com *.zdassets.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.iconify.design https://fonts.gstatic.com *.gstatic.com *.fontawesome.com cdnjs.cloudflare.com *.facebook.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com https://www.google.com https://www.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cloudflare.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.twitter.com www.googletagmanager.com www.paypalobjects.com *.facebook.com *.facebook.net connect.facebook.net www.facebook.com firebasestorage.googleapis.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.facebook.com www.googletagmanager.com td.doubleclick.net *.google.com *.google.com.co *.youtube.com/ https://scontent-ams4-1.cdninstagram.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io nguillers.com *.nguillers.com *.cloudflare.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.amazonaws.com seeklogo.com *.seeklogo.com www.facebook.com *.usercentrics.eu maps.googleapis.com maps.gstatic.com *.facebook.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com checkout.paypal.com c.paypal.com *.twimg.com *.twitter.com stats.g.doubleclick.net facebook.com *.doubleclick.net files.stripe.com statics.addi.com s3.amazonaws.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.ytimg.com *.lightemporium.com *.google.com *.maps.gstatic.com https://clauem2.arrowtheme.com https://scontent-ams4-1.cdninstagram.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.jsdelivr.net *.credinet.co player.vimeo.com *.facebook.com *.facebook.net connect.facebook.net www.facebook.com d335luupugsy2.cloudfront.net *.google-analytics.com firebasestorage.googleapis.com stats.g.doubleclick.net demdex.net amcglobal.sc.omtrdc.net flowlink.paypal.com *.hsforms.net *.hsforms.com facebook.com checkout.paypal.com js.stripe.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.maps.googleapis.com *.trackedlink.net *.google.com *.maps.gstatic.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com https://scontent-ams4-1.cdninstagram.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.jsdelivr.net *.facebook.com stats.g.doubleclick.net www.google-analytics.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com fonts.googleapis.com *.google-analytics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.iconify.design *.googleapis.com *.gstatic.com *.fontawesome.com *.credinet.co *.paypal.com *.paypalobjects.com *.facebook.com *.facebook.net connect.facebook.net www.facebook.com firebasestorage.googleapis.com *.seeklogo.com flowlink.paypal.com analyticsuite.io *.hsforms.net *.hsforms.com facebook.com api.stripe.com api.paypal.com www.merchant-center-analytics.goog stats.g.doubleclick.net *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.trackedlink.net *.ampproject.org *.google.com *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://scontent-ams4-1.cdninstagram.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self'; script-src 'self' https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https:; img-src 'self' data: https:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com fonts.googleapis.com 'self' data: *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardlink.gr *.alphaecommerce.gr *.eurocommerce.gr *.qcb.gov.qa *.snapchat.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.infobip.com *.snapchat.com *.klarna.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io calc.tbibank.gr https://www.magezon.com *.facebook.net *.facebook.com *.twitter.com t.co *.google.gr *.cookiefirst.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com calc.tbibank.gr *.facebook.net *.facebook.com *.infobip.com *.cloudflareinsights.com *.google.gr *.googlesyndication.com *.twitter.com *.ads-twitter.com sc-static.net *.doubleclick.net *.iconify.design scripts.bestprice.gr skroutza.skroutz.gr analytics.skroutz.gr 360.bestprice.gr *.clarity.ms *.cookiefirst.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.cookiefirst.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com calc.tbibank.gr *.infobip.com *.facebook.com *.snapchat.com *.doubleclick.net *.clarity.ms *.cookiefirst.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' 'nonce-XL0vmFQDYPaPFxNvsRilKw==' 1 object-src 'none'; script-src 'nonce-PD52tUjU0GZyWv0XDlJXNxlNs0U=' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample'; base-uri 'self'; frame-ancestors 'self'; report-uri https://elementsuite.report-uri.com/r/t/csp/reportOnly 1 base-uri 'self'; default-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-src 'self' https://td.doubleclick.net; connect-src 'self' https://swile-privacy.my.onetrust.com https://cdn.cookielaw.org https://swile.containers.piwik.pro https://swile.piwik.pro/ https://adservice.google.com https://googleads.g.doubleclick.net https://www.google.com; img-src 'self' blob: data: https://cdn.cookielaw.org https://www.google.fr https://www.googletagmanager.com https://fonts.gstatic.com; manifest-src 'self'; object-src 'none'; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub1f7041eb55ec9a12eea50b161be3d8c0&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to csp; script-src 'nonce-YmQwZmEwOTctYzFiNS00OGYxLWI1NzMtZDhjYWExNTkzMjhl' 'strict-dynamic'; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://fonts.googleapis.com 1 default-src 'self'; img-src 'self' data:; script-src 'self' 'unsafe-eval';style-src 'self' 'unsafe-inline';object-src 'none'; base-uri 'none'; connect-src 'self' *.zorgdoc.nl; report-uri https://sentry.zorgdoc.nl/api/11/security/?sentry_key=710eec7163c34959bcfe36be5404c07a 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'nonce-rxpTxqm8Ev6j+0PnDH390w=='; style-src 'self' https: 'unsafe-inline' 'nonce-rxpTxqm8Ev6j+0PnDH390w=='; connect-src 'self' https: wss://localhost:8181 wss://localhost:8282 wss://localhost:8383 wss://localhost:8484 wss://127.0.0.1:8181 wss://127.0.0.1:8282 wss://127.0.0.1:8383 wss://127.0.0.1:8484 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.googleapis.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com www.gstatic.com *.trackedlink.net *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com https://www.gardenersedge.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/publicpolicy_google 1 font-src cdn.livechatinc.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.codeweavers.net *.feefo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.codeweavers.net *.feefo.com *.livechatinc.com *.doubleclick.net *.trustpilot.com *.gstatic.com *.google.com optimize.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.codeweavers.net *.feefo.com *.linkedin.com *.bing.com *.google.com *.doubleclick.net *.googletagmanager.com *.mercedes-benzsouthwest.co.uk.cfstack.com *.gravatar.com *.tangelo.co.uk *.google.co.uk *.google.co.in *.hsforms.com *.hubspot.com *.facebook.com *.mercedes-benzsouthwest.co.uk https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.codeweavers.net *.feefo.com *.licdn.com *.livechatinc.com *.bing.com *.trustpilot.com *.doubleclick.net *.msgapp.com *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.facebook.net *.hsleadflows.net *.newrelic.com *.hsforms.com googleoptimize.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com optimize.google.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.codeweavers.net *.feefo.com wss://ws-eu.pusher.com/ *.doubleclick.net *.livechatinc.com *.hubapi.com *.hubspot.com *.facebook.com *.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://vmtawsjkbhlls5jckka33h0c.httpschecker.net/report 1 object-src 'none'; connect-src 'self' *.tabooheat.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.tabooheat.com join.gammasecure.com; script-src 'self' *.tabooheat.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.tabooheat.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' cabralmotor.com.br *.cabralmotor.com.br wake-components.fbitsstatic.net cabralmotor.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br gstatic.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.googleapis.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com *.cabralmotor.com.br api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.google.com.br *.g.doubleclick.net *.clarity.ms *.leadster.com.br *.google-analytics.com *.fbits.net *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.cabralmotor.com.br cabralmotor.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=b0ad3a7f-e709-416c-9455-c63982bdaa49; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com searchserverapi.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.google.com searchserverapi.com *.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.youtube.com/ https://scontent-ams4-1.cdninstagram.com *.multisafepay.com https://pay.google.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com https://clauem2.arrowtheme.com https://scontent-ams4-1.cdninstagram.com widgets.trustedshops.com *.etrusted.com searchserverapi.com *.facebook.com *.google.nl *.bing.com *.clarity.ms imgsct.cookiebot.com *.klaviyo.com *.multisafepay.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.maps.googleapis.com *.trackedlink.net *.maps.gstatic.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com https://scontent-ams4-1.cdninstagram.com widgets.trustedshops.com searchserverapi.com cdn.amplitude.com google.nl *.facebook.net *.bing.com *.clarity.ms consent.cookiebot.com s.pinimg.com *.clerk.io *.klaviyo.com sst.kayori.nl *.avada.io *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com widgets.trustedshops.com *.etrusted.com searchserverapi.com *.klaviyo.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://scontent-ams4-1.cdninstagram.com searchserverapi.com *.doubleclick.net *.googlesyndication.com *.facebook.com *.clarity.ms ct.pinterest.com *.klaviyo.com https://get.geojs.io *.avada.io *.multisafepay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none'; base-uri 'none'; report-uri https://o225139.ingest.us.sentry.io/api/4508413968973824/security/?sentry_key=d470f887ca7cad3517dfc80c0b6dd0cc&sentry_environment=PRODUCTION; script-src 'unsafe-eval' 'strict-dynamic' 'report-sample' 'unsafe-hashes' 'sha256-lo7ZdP6kFds+wf1WMWvn7MhcFVFJV44kAXODRevzRZ8=' 'sha256-rRMdkshZyJlCmDX27XnL7g3zXaxv7ei6Sg+yt4R3svU=' 'sha256-kbHtQyYDQKz4SWMQ8OHVol3EC0t3tHEJFPCSwNG9NxQ=' 'nonce-EOj77KR5CJMSXZtfVmkUww==' 1 child-src blob:;default-src 'none';img-src 'self' https://images.ctfassets.net/t0p2cqcl8cn8/ *.googleapis.com *.gstatic.com www.facebook.com ad.doubleclick.net www.googletagmanager.com *.contentsquare.net data: blob: ade.googlesyndication.com adservice.google.com www.googleadservices.com https://bat.bing.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.fr https://sdk.privacy-center.org https://assets.funecap.org *.kameleoon.io;font-src 'self' https://fonts.gstatic.com;connect-src 'self' roc-eclerc.com *.roc-eclerc.com https://*.google-analytics.com *.googleapis.com *.gstatic.com *.google.com google.com metrics.roc-eclerc.com *.realytics.io *.pa-cd.com *.doubleclick.net *.contentsquare.net https://login.microsoftonline.com https://graph.microsoft.com https://www.facebook.com https://pagead2.googlesyndication.com https://affdjz.go2cloud.org/ https://www.googleadservices.com/ https://tpmtrk.com https://graph.facebook.com/ https://bat.bing.com https://sdk.privacy-center.org https://api.privacy-center.org *.kameleoon.io;script-src 'self' 'unsafe-inline' *.googleapis.com www.googletagmanager.com *.contentsquare.net app.contentsquare.com https://tag.aticdn.net https://connect.facebook.net *.realytics.io *.realytics.net https://www.googleadservices.com https://bat.bing.com *.doubleclick.net https://www.google.com https://www.google.fr https://sdk.privacy-center.org https://api.privacy-center.org https://tag.imagino.com 'unsafe-eval' *.kameleoon.io ;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/css;media-src 'self' https://videos.ctfassets.net/t0p2cqcl8cn8/;frame-src 'self' https://www.youtube.com https://youtube.com *.doubleclick.net https://www.facebook.com https://tbl.tradedoubler.com/;frame-ancestors roc-eclerc.com *.roc-eclerc.com https://app.contentful.com;report-uri https://9jnmnwzx.uriports.com/reports;report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.tufano.store *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.tufano.store *.icecat.biz *.xrex.it www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.tufano.store *.jsdelivr.net www.google.com www.gstatic.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.tufano.store *.jsdelivr.net *.fontawesome.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.tufano.store *.google-analytics.com *.googletagmanager.com *.xrex.it www.google.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://www.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.cleverreach.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.weltpixel.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com https://www.google.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.cloudfront.net cdn.pay1.de x.klarnacdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://www.gstatic.com *.google.com *.gstatic.com *.avada.io secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://www.google.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com https://get.geojs.io *.avada.io payments.amazon.de d.ratepay.com jsctool.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com x.klarnacdn.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardlink.gr *.alphaecommerce.gr *.eurocommerce.gr *.vivapayments.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com static.addtoany.com www.google.com widget-v5.boxnow.gr consentcdn.cookiebot.com www.googletagmanager.com *.contactpigeon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://www.crocs.gr https://crocs.gr widget-v5.boxnow.gr tile.openstreetmap.org www.google.gr https://www.facebook.com https://connect.facebook.net https://imgsct.cookiebot.com *.contactpigeon.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com *.vivapayments.com static.addtoany.com www.google.com www.gstatic.com widget-v5.boxnow.gr cdnjs.cloudflare.com unpkg.com ajax.googleapis.com api.ipstack.com crocs.overguess.com js.klarna.com *.cookiebot.com *.googlesyndication.com *.google-analytics.com *.googletagmanager.com https://connect.facebook.net *.contactpigeon.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com www.gstatic.com widget-v5.boxnow.gr cdnjs.cloudflare.com unpkg.com crocs.overguess.com x.klarnacdn.net https://ping.contactpigeon.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com boxlockersloadfiles.blob.core.windows.net widgettranslations.blob.core.windows.net region1.analytics.google.com widget-v5.boxnow.gr crocs.overguess.com *.googlesyndication.com https://consentcdn.cookiebot.com *.contactpigeon.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src *.contactpigeon.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src stats.g.doubleclick.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com 'self' 'unsafe-inline'; 1 font-src www.mygossip.in data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' data: *.payu.in https://plumrocket.com www.mygossip.in 'self' 'unsafe-inline'; frame-ancestors 'self' data: *.payu.in *.facebook.com *.flydubai.com *.myshopify.com www.mygossip.in 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' data: *.payu.in *.facebook.com *.flydubai.com *.myshopify.com https://plumrocket.com api.razorpay.com *.weltpixel.com www.mygossip.in 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn.razorpay.com www.mygossip.in data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.mgt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.payu.in checkout.razorpay.com www.mygossip.in 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline www.mygossip.in 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.mygossip.in 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.mgt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.payu.in lumberjack.razorpay.com lumberjack-metrics.razorpay.com www.mygossip.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.mygossip.in http: https: blob: 'self' 'unsafe-inline'; default-src www.mygossip.in 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-5GQ7dFOEwF9ezCkkISsDA3fN' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://cdn.jsdelivr.net https://ajax.googleapis.com https://code.jquery.com https://cdnjs.cloudflare.com https://static.zdassets.com https://ekr.zdassets.com https://*.cloudflare.com https://stackpath.bootstrapcdn.com https://*.sectigo.com https://secure.trust-provider.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com; img-src 'self' data: https://www.google-analytics.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://secure.trust-provider.com https://www.sectigo.com; font-src 'self' https://fonts.gstatic.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net; connect-src 'self' https://*.zdassets.com https://www.google-analytics.com https://www.googletagmanager.com https://*.sectigo.com https://secure.trust-provider.com https://region1.google-analytics.com https://e-tutungerie.zendesk.com wss://widget-mediator.zopim.com; media-src 'self' https://static.zdassets.com; frame-src 'self' https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com cdn.livehelpnow.net static.klaviyo.com eadn-wc04-195113.nxedge.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.trackedlink.net developer.livehelpnow.net eadn-wc04-195113.nxedge.io www.facebook.com cdn.mouseflow.com google.com www.livehelpnow.net q.clarity.ms c.clarity.ms c.bing.com bat.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com cdn.mouseflow.com developer.livehelpnow.net cdn.livehelpnow.net eadn-wc04-195113.nxedge.io connect.facebook.net q.clarity.ms clarity.ms bat.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com webchat.dotdigital.com webchat.staging.dotdigital.com developer.livehelpnow.net eadn-wc04-195113.nxedge.io static-tracking.klaviyo.com https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com developer.livehelpnow.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com developer.livehelpnow.net stats.g.doubleclick.net wss://app.livehelpnow.net us01.rec.mouseflow.com eadn-wc04-195113.nxedge.io q.clarity.ms https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri eadn-wc04-195113.nxedge.io 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com *.gstatic.com 'self' data: https://dashboard.webwinkelkeur.nlfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com js.mollie.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com imgsct.cookiebot.com magefan.com cm.magefan.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: https://www.myhairshop.nl https://www.google.com https://www.google.com.ua https://www.google.nl https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://maps.googleapis.com consent.cookiebot.com js.mollie.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://dashboard.webwinkelkeur.nl/sidebar.js https://d5yoctgpv4cpx.cloudfront.net https://cdn1.profitmetrics.io https://pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net vimeo.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://www.google.com https://google.com https://www.google.com.ua https://www.google.nl https://www.google.pl https://my.profitmetrics.io https://stats.g.doubleclick.net https://pagead2.googlesyndication.com https://p2iqhncxyh.execute-api.eu-central-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data:; connect-src 'self' https: https://*.browser-intake-datadoghq.com https://apc.mdlogix.com https://*.appcues.com https://*.appcues.net wss://apc.mdlogix.com wss://*.appcues.net wss://*.appcues.com https://forms.bhworks.io; font-src 'self' https: data: https://fonts.gstatic.com; frame-src 'self' https://*.statuspage.io https://apc.mdlogix.com https://*.appcues.com; img-src 'self' https: data: https://apc.mdlogix.com https://*.appcues.com https://*.appcues.net res.cloudinary.com cdn.jsdelivr.net; object-src 'none'; script-src 'self' 'unsafe-inline' api-standard.opentok.com https://*.statuspage.io https://*.freshworks.com www.datadoghq-browser-agent.com https://apc.mdlogix.com https://*.appcues.com https://*.appcues.net https://forms.bhworks.io 'nonce-yIP1dDim8UdwTZEYe4dgmA=='; style-src 'self' https: 'unsafe-inline' https://apc.mdlogix.com https://*.appcues.com https://*.appcues.net https://fonts.googleapis.com https://fonts.google.com https://forms.bhworks.io unsafe-inline; worker-src blob: 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.gr/api/csp-report; report-to csp-endpoint 1 connect-src *.chromalox.com *.onetrust.com *.onetrust.io *.google-analytics.com *.hotjar.com *.hotjar.io *.qualtrics.com wss://*.hotjar.com maps.googleapis.com 'self' *.clarity.ms maps.googleapis.com *.cookieyes.com vimeo.com px.ads.linkedin.com front.optimonk.com cdn-account.optimonk.com jfapiprod.optimonk.com cdn-renderer.optimonk.com pagead2.googlesyndication.com cdn-cookieyes.com googleads.g.doubleclick.net places.googleapis.com analytics.google.com region1.analytics.google.com www.google-analytics.com www.googletagmanager.com www.googleadservices.com ad.doubleclick.net stats.g.doubleclick.net 680-ryi-639.mktoresp.com forms.hubspot.com forms.hsforms.com cdn.linkedin.oribi.io adservice.google.com www.google.com www.google.co.uk www.google.ae www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bs www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.hu www.google.co.id www.google.co.il www.google.co.im www.google.co.in www.google.co.je www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.nf www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.uz www.google.com.vc www.google.com.vn www.google.cn www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.gg www.google.gl www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mn www.google.ms www.google.mu www.google.mw www.google.net www.google.nl www.google.no www.google.nr www.google.nu www.google.pl www.google.pn www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sm www.google.sn www.google.tm www.google.tn www.google.to www.google.tp www.google.tt www.google.tv www.google.uz www.google.vg www.google.vu www.google.ws www.google.co.zw www.google.dz/ads/ga-audiences www.google.al/ads/ga-audiences www.google.bf/ads/ga-audiences ttps://www.google.by/ads/ga-audiences www.google.cm/ads/ga-audiences www.google.co.ao/ads/ga-audiences ttps://www.google.co.mz/ads/ga-audiences www.google.co.tz/ads/ga-audiences www.google.com.bn/ads/ga-audiences ttps://www.google.com.gh/ads/ga-audiences www.google.com.kh/ads/ga-audiences www.google.com.lb/ads/ga-audiences ttps://www.google.com.mm/ads/ga-audiences www.google.com.ng/ads/ga-audiences www.google.com.pg/ads/ga-audiences ttps://www.google.dz/ads/ga-audiences www.google.ge/ads/ga-audiences www.google.iq/ads/ga-audiences www.google.sr/ads/ga-audiences 680-ryi-639.mktoutil.com wss://lo.msg.liveperson.net bat.bing.com; font-src *.onetrust.com 'self' fonts.gstatic.com use.typekit.net data:; img-src *.qualtrics.com optimize.google.com www.google-analytics.com www.googletagmanager.com 'self' data: *; manifest-src 'self'; script-src *.onetrust.com *.scr.kaspersky-labs.com *.qualtrics.com www.googleanalytics.com www.googleoptimize.com optimize.google.com static.ads-twitter.com 'self' 'nonce-MGFiMDY2YjQtZDljMC00NTlhLWFhODQtZmMxZDIzZDZmZjAw' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'sha256-NiPpcuG5iPK1KPR3YIEEEz98KT0W7243V6u7FeP7hdE=' 'sha256-gRuNVLzs+xy+3p6+I1CnZb8pDmnXUWSlO9ejbnSR/lQ=' 'sha256-ibqfaR/CmFL3wQZAxIuZ0V4RMm9txqHSln46Z5WyeVA=' 'sha256-30EB3olZggJZ3OT2ahL22VzuYSIEPTzmMb+L3StxKgI=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-bkXrlHTrWu78qnQooXw+JqlG1rZijbuVZIkNBzTfagM=' 'sha256-vbs/XR7vkC12NXdDH8FEaUASiJdg/16cqF/0T3ze1ks=' 'sha256-4nxBwvGtrokGNkqD2OxOt8Y07P7caJHk00sGwjNYF5I=' 'sha256-/Fu0G2rh4wmpTYIDt4lb/x5WJp6zusqpavun8dZ8Yns=' 'sha256-yqVa7ver8F3o3KAsmdt2r10wQlIPCHuaBhkxEMbFQKE=' 'sha256-pZ/qdkaCfUhJbPDW6dxGk6IT/oRRR/mlpXeonIs9iew=' 'sha256-tYXM2mIrtKnuv7Rvj326AzVweHLHgtfBqDHsiYM5xg8=' 'sha256-kcSZExtSK6wGWjH32NFqA7z0v/0DUB7/EuCavQ6V0Nc=' 'sha256-/amMNPylJzZhxuDqWJaOB1tblrNn/VTGmyo1F6Jydsc=' 'sha256-nMZuForFzEBU+4yE21DCTnFwd73xR2dj4cDRSkbEfhA=' 'sha256-s3czzyz3eEMkekPOnj13dd1TYxC0uLYtFJPalu7jVtg=' 'sha256-FL2ompMo2e6GBcy6brKSOH0L/JUlb+gXWURUoorBwLI=' ssl.google-analytics.com connect.facebook.net www.facebook.net www.google-analytics.com www.googletagmanager.com www.gstatic.com www.youtube.com platform.twitter.com cdn.syndication.twimg.com www.google.com accdn.lpsnmedia.net googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsforms.net js.hsleadflows.net lo.v.liveperson.net lpcdn.lpsnmedia.net lptag.liveperson.net munchkin.marketo.net script.hotjar.com snap.licdn.com static.hotjar.com www.googleadservices.com www.clarity.ms ajax.googleapis.com platform.linkedin.com; style-src-elem *.onetrust.com 'self' fonts.googleapis.com p.typekit.net use.typekit.net platform.twitter.com ton.twimg.com optimize.google.com www.googletagmanager.com 'unsafe-inline'; frame-src *.chromalox.com *svc.dynamics.com *.doubleclick.net *.qualtrics.com optimize.google.com vars.hotjar.com www.youtube.com lpcdn.lpsnmedia.net *.liveperson.net sseacademy.csod.com www.googletagmanager.com www.facebook.com www.google.com www.youtube.com m.youtube.com share.hsforms.com platform.twitter.com syndication.twitter.com player.vimeo.com calendly.com www.linkedin.com; media-src 'self' *.chromalox.com *.gestra.com *.spiraxsarco.com lpcdn.lpsnmedia.net www.facebook.com; form-action 'self'; style-src-attr 'unsafe-inline'; object-src 'none'; base-uri 'self'; style-src optimize.google.com fonts.googleapis.com 'unsafe-inline'; report-uri https://steam.report-uri.com/r/d/csp/enforce 1 default-src *; script-src * https://cdn-cookieyes.com; style-src *; img-src *; connect-src *; font-src *; media-src *; report-uri *; child-src *; form-action *; frame-ancestors *; object-src *; frame-src *; worker-src *; manifest-src *; navigate-to *; prefetch-src *; base-uri * 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com api.payme.hsbc.com.hk *.twitter.com sandbox.api.payme.hsbc.com.hk *.gateway.mastercard.com https: 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com api.payme.hsbc.com.hk *.twitter.com * data: blob: sandbox.api.payme.hsbc.com.hk qr.payme.hsbc.com.hk payme-cashout-secure.hsbc.com.hk *.google.com/ www.googletagmanager.com td.doubleclick.net *.adsrvr.org applepay.cdn-apple.com pay.google.com gateway-japa.americanexpress.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.appspot.com *.appier.net *.yahoo.com *.clarity.ms *.bing.com *.yimg.com *.analytics.yahoo.com *.facebook.com *.facebook.net *.google.com.hk *.gstatic.com https://firebasestorage.googleapis.com https://www.magezon.com ad.doubleclick.net ade.googlesyndication.com adservice.google.com https://tags.srv.stackadapt.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com api.payme.hsbc.com.hk *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com/ *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.authorize.net *.cardinalcommerce.com *.appspot.com *.appier.net *.yahoo.com *.bing.com *.yimg.com *.googleapis.com *.facebook.com *.facebook.net *.clarity.ms sandbox.api.payme.hsbc.com.hk qr.payme.hsbc.com.hk payme-cashout-secure.hsbc.com.hk *.avada.io *.taboola.com *.adsrvr.org applepay.cdn-apple.com pay.google.com gateway-japa.americanexpress.com *.qgr.ph *.qgraph.io *.aiqua.io *.rollbar.com *.quantumgraph.com *.gocm.c.appier.net https://tags.srv.stackadapt.com https://srv.stackadapt.com https://ap.srv.stackadapt.com/ https://east.srv.stackadapt.com https://uw.srv.stackadapt.com https://eu.srv.stackadapt.com https://qvdt3feo.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.appspot.com *.appier.net *.yahoo.com https://fonts.bunny.net https://tags.srv.stackadapt.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.demdex.net *.cloudflare.com *.twitter.com *.twimg.com *.google-analytics.com *.google.com google.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.authorize.net *.clarity.ms *.yimg.com *.googleapis.com *.appier.net https://get.geojs.io *.avada.io pagead2.googlesyndication.com *.taboola.com https://tags.srv.stackadapt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://dis.genki.com:8700/; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.aspnetcdn.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://front.optimonk.com https://onsite.optimonk.com https://cdn-asset.optimonk.com https://knockoutjs.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: https://dr8bsncg67mqz.cloudfront.net/; font-src 'self' data: https://fonts.gstatic.com/; frame-src 'self' https://www.googletagmanager.com/; worker-src 'self'; form-action 'self'; frame-ancestors 'self'; base-uri 'self'; 1 default-src 'self' blob: wss: data: https: 'report-sample'; block-all-mixed-content; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: https: 'report-sample'; style-src 'self' 'unsafe-inline' data: https: 'report-sample'; report-uri /nelmio/csp/report 1 base-uri 'self'; child-src 'self' lakedistrictgivaways.co.uk *.websiteni.com blob:; connect-src 'self' lottie.host *.googleapis.com *.facebook.net *.pay.com api.staging.pay.com api.pay.com metacapi.blaagiveaways.com *.google-analytics.com blaagiveaways.com *.cloudflare.com *.jsdelivr.net *.typekit.net matomo.mckinneycompetitions.com unpkg.com; default-src 'self'; font-src 'self' fonts.gstatic.com fonts.googleapis.com *.jsdelivr.net *.cloudflare.com data: *.typekit.net *.cdn-apple.com; form-action 'self' www.facebook.com; frame-ancestors 'self'; frame-src 'self' *.trustpilot.com *.pay.com universal.staging.pay.com universal.pay.com *.cardinalcommerce.com *.youtube.com; img-src 'self' imagedelivery.net maps.gstatic.com maps.googleapis.com data: *.google.com *.facebook.com *.facebook.net blaagiveaways.com *.googletagmanager.com; media-src 'self'; object-src 'self'; script-src 'self' unpkg.com widget.trustpilot.com lottie.host fonts.googleapis.com maps.googleapis.com *.jquery.com *.cloudflare.com *.jsdelivr.net 'unsafe-inline' *.datatables.net 'unsafe-eval' *.facebook.net *.pay.com js.staging.pay.com www.googletagmanager.com *.cdn-apple.com *.checkout.com matomo.mckinneycompetitions.com; style-src 'self' *.cloudflare.com *.jsdelivr.net fonts.googleapis.com widget.trustpilot.com lottie.host 'unsafe-inline' *.datatables.net maps.googleapis.com *.typekit.net unpkg.com; manifest-src 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn.ampproject.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; default-src 'none'; object-src 'self'; media-src 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src https://www.youtube.com; img-src 'self' data: https://www.google-analytics.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'nonce-df66df636bd528fbd5c52038dd6917a7a8b1f805' 'sha256-NeueIEO8rwnaeJW0jYHRwrarPP+KzGzhk6xBJ06ntlw=' https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://maps.googleapis.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.magezon.com *.multisafepay.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.fontawesome.com *.googleapis.com *.gstatic.com *.google.com/ *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.multisafepay.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com tagmanager.google.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.multisafepay.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.google-analytics.com *.doubleclick.net *.pay.nl 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.ronaldadventureshop.nl/paynl/csp/report; report-to report-endpoint; 1 default-src 'self' pxlfsn.co www.google-analytics.com maps.googleapis.com ajax.googleapis.com www.google.com google.com gstatic.com www.gstatic.com connect.facebook.net facebook.com www.moshtix.com.au; 1 script-src 'nonce-62f596d7-7ad3-44a5-8c8c-b0ea6482aaec' 'strict-dynamic' 'report-sample'; report-uri /csp/report?metadata=form%3a387ec81f-5bca-49bc-bd6d-1297e819c3c7; report-to csp-endpoint 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-+wbYvV+SW+YRRrWT0S5kKvzKolU=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-9kK8i2naa0EXVZH9H3+NS8A2bYM=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-LxsxkUKXfwfJmDM+sna7MLMxP8I=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 frame-src *.force.com https://player.vimeo.com 'self' *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es *.adis.ws *.youtube.ie https://www.youtube.com *.cloudinary.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr https://citizenstpo.file.force.com https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net https://usa776.sfdc-8tgtt5.salesforce.com *.youtube.nl https://service.force.com/embeddedservice/ https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com *.youtube.com.br *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net *.youtube.ca https://location.force.com https://stackpath.bootstrapcdn.com *.vidyard.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://*.a.forceusercontent.com/lightningmaps/ *.wistia.net *.salesforce.com *.youtube.pl; report-to sfdc-csp-ep; report-uri https://citizenstpo.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D4x0000050SLu&networkId=0DM4x000000d3Mi&type=communities 1 script-src 'unsafe-eval' blob: 'self' 'unsafe-inline' www.dmlive.wiki; default-src 'self' data: blob: www.dmlive.wiki; style-src 'self' data: blob: www.dmlive.wiki 'unsafe-inline'; img-src * data: blob:; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.maksekeskus.ee *.test.maksekeskus.ee www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.ceno.lv *.salidzini.lv *.kurpirkt.lv 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ player.vimeo.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com cdn.jsdelivr.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'unsafe-inline' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com fonts.gstatic.com *.libreka.de *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com *.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.google.com js.stripe.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.libreka.de www.sovendus-connect.com www.sovendus-benefits.com *.cookiebot.com *.pinterest.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.googleapis.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com cdn.cookielaw.org qm.magazinabo.com qm.bergweltenabo.ch qm.getredbulletin.ch *.libreka.de https://firebasestorage.googleapis.com *.cookiefirst.com *.cookiebot.com *.elfsight.com *.facebook.com *.google.de *.linkedin.com *.pinterest.com *.redbull.com *.usd.de *.usercentrics.eu *.scnem2.com cdn.consentmanager.net cloud.ccm19.de *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.googletagmanager.com tagmanager.google.com cdn.cookielaw.org qm.magazinabo.com qm.bergweltenabo.ch qm.getredbulletin.ch *.libreka.de api.sovendus.com https://polyfill-fastly.io https://browser.sentry-cdn.com *.avada.io *.shopify.com *.cloudfront.net *.cookiefirst.com *.cookiebot.com *.elfsight.com *.facebook.net *.google.com *.google-analytics.com *.haymarketstat.de *.licdn.com *.linkedin.com *.logopaletti.de *.redbull.com *.trustedshops.com *.pinimg.com *.usercentrics.eu *.scnem2.com *.s7.addthis.com cdn.consentmanager.net d.delivery.consentmanager.net cloud.ccm19.de *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com d.ratepay.com d.payla.io dr.payla.io tagmanager.google.com fonts.google.com *.libreka.de *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.cookiefirst.com *.google.com *.trustedshops.com cdn.consentmanager.net cloud.ccm19.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.libreka.de *.cloudfront.net *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.googleapis.com payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com privacyportal-de.onetrust.com pagead2.googlesyndication.com qm.magazinabo.com qm.getredbulletin.ch *.libreka.de identification-api.sovendus.com press-tracking-api.sovendus.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io *.cookiefirst.com *.cookiebot.com *.cookielaw.org *.doubleclick.net *.elfsight.com *.google.de *.haymarketstat.de *.logopaletti.de *.usercentrics.eu *.pinterest.com cloud.ccm19.de t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' dc.services.visualstudio.com www.google-analytics.com stats.g.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' az416426.vo.msecnd.net www.googletagmanager.com www.google-analytics.com www.google.com www.gstatic.com; style-src 'self' 'unsafe-inline'; frame-src 'self' www.google.com ; img-src 'self' googletagmanager.com data: 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.gstatic.com *.googleapis.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com https://cdnjs.cloudflare.com https://maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com *.googleapis.com https://nominatim.openstreetmap.org https://maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem maps.gstatic.com maps.googleapis.com fonts.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx; font-src fonts.gstatic.com use.typekit.net *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com *.gstatic.com data: https://fonts.bunny.net https://www.google.com https://www.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com 'self' *.doubleclick.net *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.google.com *.examedi.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com *.facebook.com *.sharethis.com *.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://firebasestorage.googleapis.com *.mitec.com.mx *.bird.eu *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.avada.io *.mitec.com.mx www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.jscrambler.com *.examedi.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.bunny.net *.googleapis.com *.addtoany.com *.mitec.com.mx *.google.com https://accesosalud.com.mx 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.mitec.com.mx https://www.google.com https://www.gstatic.com *.jscrambler.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com http://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://cdnjs.cloudflare.com https://js-agent.newrelic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com api.razorpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com testourcode.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googleadservices.com *.paypalobjects.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com cdn.razorpay.com magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com assets.snapmint.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com checkout.razorpay.com *.googleapis.com *.google.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com api.snapmint.com assets.snapmint.com sandboxapi.snapmint.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws http://fonts.googleapis.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; form-action https:; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.aerogligli.fr; script-src-elem 'self' 'unsafe-inline' https://www.aerogligli.fr; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://www.gstatic.com https://www.aerogligli.fr; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://www.gstatic.com https://www.aerogligli.fr; img-src 'self' data: blob: https:; font-src 'self' https://fonts.gstatic.com https://www.aerogligli.fr data:; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com; connect-src 'self' data:; media-src 'self' data: blob:; upgrade-insecure-requests; report-uri /csp-violation-endpoint 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=3_HQ2ySTL3lRxJx5fhDJJQt5E3hlCugDNDuopl8ujC8-1765935208.7561684-1.0.1.1-P0wMhSNDmRRQnC_Xvg_48M3HBmtPCpaegbIsVvYSxtLNFePsHK40peP.ZkW.7r9TdNuM.T1UkbEFWiX1qKHp71G6tO3sFMipvMOoNpUyrySF34UHAgB8XLJMuGSwhiNQUq1YQ9LaRFD89T_0OEyGJzHCiqAzPGpG8fUeDNIVCJ9xU8zeq5vnA.a0Y3qZ6mxM; report-to cf-csp-endpoint 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://firebasestorage.googleapis.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com s7.addthis.com *.avada.io *.google.com unpkg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com unpkg.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com *.oct8ne.com https://static.oct8ne.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vimeo.com *.afip.gob.ar *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com *.oct8ne.com https://static.oct8ne.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://live.decidir.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.vimeo.com *.afip.gob.ar *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.oct8ne.com https://static.oct8ne.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afip.gob.ar *.avada.io *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.oct8ne.com https://static.oct8ne.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com https://developers.decidir.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.afip.gob.ar https://get.geojs.io *.avada.io *.google-analytics.com https://www.google-analytics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.oct8ne.com https://static.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://live.decidir.com https://developers.decidir.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.tiendaforastero.cl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com mageside.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://static.klaviyo.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' anjuss.com.br *.anjuss.com.br wake-components.fbitsstatic.net anjuss.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.ytimg.com *.anjuss.com.br *.hotjar.io *.hotjar.com *.shoptarget.com.br *.g.doubleclick.net *.google.com *.google.com.br *.lomadee.com *.pagar.me *.mundipagg.com *.yourviews.com.br *.getnet.com.br *.braintree-api.com *.braintreegateway.com checkout.anjuss.com.br *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.g2afse.com *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.azurewebsites.net static.hotjar.com static.fbits.net koin-custom-conector-gateway.fbits.net payments.koin.com.br *.fbits.net *.koin.com.br *.bithome-brasil.com.br plac.bithome-brasil.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com gstatic.com *.cardinalcommerce.com *.secureacs.com *.cloudfront.net *.s3.amazonaws.com *.cybba.solutions *.rtb123.com *.cybba.us *.amazon-adsystem.com *.adnxs.com *.stackadapt.com *.adsrvr.org *.facebook.net *.licdn.com *.cloudfront.ne *.ads.linkedin.com *.cybbaview.com *.googletagmanager.com *.smct.io *.pinimg.com *.amazonaws.com *.pinterest.com *.dsspn.com *.doubleclick.net *.reclameaqui.com.br d2rp1k1dldbai6.cloudfront.net cybba-bucket.s3.amazonaws.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.anjuss.com.br anjuss.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src *.google-analytics.com *.paypal.com *.googleadservices.com *.youtube.com *.vimeocdn.com *.cloudfront.net www.facebook.com www.google.rs *.facebook.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com i.ytimg.com p.typekit.net *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.google-analytics.com *.googletagmanager.com *.paypal.com *.klaviyo.com *.vimeocdn.com *.youtube.com *.newrelic.com *.nr-data.net connect.facebook.net assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src static-tracking.klaviyo.com *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src stats.g.doubleclick.net *.facebook.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://app-pay.jp https://api.veritrans.co.jp https://api3.veritrans.co.jp https://o983003.ingest.sentry.io https://cognito-idp.ap-northeast-1.amazonaws.com https://cognito-identity.ap-northeast-1.amazonaws.com https://analytics.google.com 'unsafe-inline'; connect-src https://app-pay.jp https://analytics.google.com https://api.veritrans.co.jp https://api3.veritrans.co.jp https://o983003.ingest.sentry.io https://cognito-idp.ap-northeast-1.amazonaws.com https://cognito-identity.ap-northeast-1.amazonaws.com https://stats.g.doubleclick.net https://55altsx9ie.execute-api.ap-northeast-1.amazonaws.com; img-src https:; font-src https:; script-src https://app-pay.jp https://api.veritrans.co.jp https://api3.veritrans.co.jp https://o983003.ingest.sentry.io 'unsafe-inline' https://www.googletagmanager.com; report-uri https://55altsx9ie.execute-api.ap-northeast-1.amazonaws.com/dev/securityReport; report-to https://55altsx9ie.execute-api.ap-northeast-1.amazonaws.com/dev/securityReport 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://firebasestorage.googleapis.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.pagseguro.com.br *.pagseguro.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io *.pagseguro.com.br *.pagseguro.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src https://use.typekit.net/byt4ecx.css https://p.typekit.net/ https://*.smartsuppcdn.com/ 'self' 'unsafe-inline' https://cdn.luigisbox.com/ https://fonts.googleapis.com/ https://tagmanager.google.com/ https://www.googletagmanager.com/; font-src https://use.typekit.net/ https://*.smartsuppcdn.com/ 'nonce-NCq6KNFIh6ALVSsMO7YcSQ==' 'self' http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://fonts.gstatic.com/ data:; script-src 'unsafe-eval' 'nonce-NCq6KNFIh6ALVSsMO7YcSQ==' 'strict-dynamic' 'unsafe-inline' https: http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io 'unsafe-inline' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://cdn.luigisbox.com/ https://scripts.luigisbox.com/ https://tagmanager.google.com/; connect-src https://ares.gov.cz/ https://maps.googleapis.com/ https://google.com/ https://*.google.com/ https://*.google.cz/ https://*.leady.com/ https://bat.bing.net/ https://bat.bing.com/ https://*.amazonaws.com/ https://*.smartsuppchat.com/ https://*.smartsuppcdn.com/ wss://*.smartsuppcdn.com/ wss://*.smartsupp.com/ https://*.clarity.ms/ https://*.seznam.cz/ https://*.googlesyndication.com/ https://www.facebook.com/ https://artisan.ecomailapp.cz/ 'self' http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com https://www.google-analytics.com/ https://www.googletagmanager.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.openstreetmap.org/ https://*.cpost.cz/ https://*.mapy.cz/ https://api.luigisbox.com/ https://live.luigisbox.com/ https://stats.g.doubleclick.net/ https://www.google.com/pagead/ https://analytics.google.com/ https://*.analytics.google.com/ https://*.google-analytics.com/ https://www.google.sk/ https://googleads.g.doubleclick.net/ https://www.googletagmanager.com/ https://www.google-analytics.com/; frame-src https://assets.pinterest.com/ https://*.doubleclick.net/ https://*.zbozi.cz/ 'self' https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.facebook.com/ https://www.youtube.com/ https://www.instagram.com/ https://www.facebook.com/ https://twitter.com/ https://twitframe.com/ https://www.google.com/ https://www.google.sk/ https://www.google.cz/ https://www.googletagmanager.com/ https://apis.google.com/ https://gate.gopay.cz/ https://gate.gopay.com/ https://gw.sandbox.gopay.com/; img-src https://maps.gstatic.com/ https://*.seznam.cz/ https://*.zbozi.cz/ https://bat.bing.net/ https://*.bing.com/ https://*.smartsuppcdn.com/ https://*.clarity.ms/ https://*.googleadservices.com/ https://googleads.g.doubleclick.net/ https://*.googlesyndication.com/ https://*.amazonaws.com/ https://*.cloudfront.net/ https://*.facebook.net/ https://*.artisan.cz/ https://artisan.cz/ 'nonce-NCq6KNFIh6ALVSsMO7YcSQ==' 'self' data: http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.facebook.com/ https://www.google.cz/ blob: https://maps.googleapis.com/ https://*.openstreetmap.org/ https://*.mapy.cz/ https://www.google.com/ https://www.google.sk/ https://www.google.cz/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://www.googletagmanager.com/ https://c.imedia.cz/ https://ssl.gstatic.com/ https://www.gstatic.com/ https://fonts.gstatic.com/; media-src https://*.smartsuppcdn.com 'self' https://www.youtube.com/ https://www.instagram.com/ https://www.facebook.com/ https://twitter.com/ https://twitframe.com/; default-src 'none'; script-src-elem 'nonce-NCq6KNFIh6ALVSsMO7YcSQ==' 'strict-dynamic' 'unsafe-inline' https: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ 'self' 'nonce-NCq6KNFIh6ALVSsMO7YcSQ==' https://scripts.luigisbox.com/ https://www.googletagmanager.com/ https://gate.gopay.cz/ https://gate.gopay.com/ https://gw.sandbox.gopay.com/; frame-ancestors 'self'; object-src 'self'; form-action 'self' https://www.facebook.com/ https://gate.gopay.cz/ https://gate.gopay.com/ https://gw.sandbox.gopay.com/; manifest-src 'self'; base-uri 'self'; report-uri https://csp.webovy-servis.cz/api/798f42ab59b3cfd1a86143904fd02dd4; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.termsfeed.com *.adobe.com *.adobedtm.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.facebook.com *.facebook.net *.atcb2b.gr *.cloudflare.com *.typekit.net *.trustedshops.com *.fontawesome.com fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com youtu.be *.vimeo.com *.addthis.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.com/ 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.termsfeed.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.facebook.com *.facebook.net *.atcb2b.gr ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cloudflare.com https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu blob: *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://www.magezon.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.termsfeed.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.facebook.com *.facebook.net *.atcb2b.gr chimpstatic.com downloads.mailchimp.com *.list-manage.com *.cloudflare.com *.google-analytics.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com s7.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.termsfeed.com *.adobedtm.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.facebook.com *.facebook.net *.atcb2b.gr downloads.mailchimp.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu fonts.googleapis.com *.googletagmanager.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.termsfeed.com *.adobe.com *.adobedtm.com *.googleadservices.com *.googleapis.com *.gstatic.com *.google.com *.facebook.com *.facebook.net *.atcb2b.gr *.cloudflare.com *.paypal.com ekr.zdassets.com/ *.google-analytics.com *.doubleclick.net *.googlesyndication.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://staging.atcb2b.gr/; report-to report-endpoint; 1 script-src 'self' 'strict-dynamic' 'report-sample' 'nonce-007a34aef6398d8b' https://maps.googleapis.com https://maps.gstatic.com https://www.googletagmanager.com https://connect.facebook.net https://snap.licdn.com https://embed.tawk.to https://cdn.jsdelivr.net https://cdn.lrkt-in.com; script-src-attr 'none' 'report-sample'; worker-src 'self' blob:; report-to csp-endpoint; report-uri https://notify.oasgo.com/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://accounts.google.com https://www.google.com https://www.gstatic.com https://cookie-cdn.cookiepro.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io content.holmbank.ee www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.com https://www.google.ee https://www.google-analytics.com https://www.facebook.com https://cookie-cdn.cookiepro.com https://*.cookiepro.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.google.com https://www.gstatic.com https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cookie-cdn.cookiepro.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://stats.g.doubleclick.net https://privacyportal.cookiepro.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com fonts.googleapis.com *.googleapis.com https://www.google.com https://www.gstatic.com *.gstatic.com https://fonts.gstatic.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com try.access.worldpay.com access.worldpay.com https://player.vimeo.com https://www.youtube-nocookie.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.hsforms.net *.hsforms.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com *.google.com try.access.worldpay.com access.worldpay.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.gstatic.com *.fontawesome.com https://player.vimeo.com https://www.youtube.com *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.googleapis.com http://fonts.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com widget.freshworks.com m2epro.freshdesk.com api.addressy.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src https: 'self' data:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdnjs.com https://cdnjs.cloudflare.com https://polyfill.io https://unpkg.com https://dev.visualwebsiteoptimizer.com https://www.googletagmanager.com https://ideo.containers.piwik.pro https://connect.facebook.net https://js-agent.newrelic.com https://cdn.jsdelivr.net;style-src 'self' 'unsafe-inline' https://unpkg.com https://fonts.googleapis.com https://www.gstatic.com;font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com;frame-src 'self' https://*.scorecastbusiness.com https://scorecastbusiness.com https://*.amazonaws.com https://*.playable.com https://playable-agency.leadfamly.com https://player.vimeo.com;frame-ancestors 'self' https://*.scorecastbusiness.com https://scorecastbusiness.com;img-src 'self' 'unsafe-inline' data: blob: https://dev.visualwebsiteoptimizer.com https://cdn.amcharts.com https://translate.google.com https://fonts.gstatic.com https://www.google.bg https://www.googletagmanager.com https://katalog.motivationdirect.pl https://www.google.nl https://stats.g.doubleclick.net https://www.google.no https://www.google.de https://www.google.be https://www.google.ci https://www.google.hr https://www.google.at https://www.google.ba https://www.google.fi https://www.google.it;worker-src 'self' blob:;report-uri https://bat2you.com/PublicApi/ContentSecurityPolicy/Report 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.youtube.com https://www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.facebook.com https://www.googletagmanager.com https://i.ytimg.com https://www.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google.com https://www.gstatic.com https://js.nagich.co.il https://js-agent.newrelic.com https://bam.nr-data.net s7.addthis.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.fontawesome.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.nagich.co.il https://bam.nr-data.net ekr.zdassets.com/ https://get.geojs.io *.avada.io www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://emdev1.greenboardnow.com/csp-report/CspLog/; report-to report-endpoint; 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.despegar.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com *.despegar.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.despegar.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.despegar.com/ s7.addthis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com cdpj.partners.bancointer.com.br cdpj-sandbox.partners.uatinter.co *.despegar.com/ ekr.zdassets.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.mercadolibre.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.avada.io *.mlstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.mercadopago.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com https://*.typekit.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.facebook.com https://*.youtube.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://*.googleapis.com https://*.google.com https://*.google.nl https://*.facebook.com https://*.bing.com https://*.pinterest.com https://*.clarity.ms https://*.paypal.com https://*.paypalobjects.com https://*.vimeo.com https://*.vimeocdn.com https://*.gstatic.com https://*.adobe.com https://*.adobedtm.com https://*.youtube.com https://*.cloudflare.com https://*.ytimg.com https://*.cardinalcommerce.com https://*.googleads.g.doubleclick.net https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://cm.everesttech.net https://*.magentocommerce.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.googletagmanager.com https://*.feedbackcompany.com https://googleads.g.doubleclick.net https://connect.facebook.net https://*.pinimg.com https://*.bing.com https://*.google-analytics.com https://*.googleadservices.com https://*.googleapis.com https://*.google.com https://*.paypal.com https://*.paypalobjects.com https://*.vimeo.com https://*.vimeocdn.com https://*.gstatic.com https://*.adobe.com https://*.adobedtm.com https://*.youtube.com https://*.cloudflare.com https://*.ytimg.com https://*.cardinalcommerce.com https://prism.app-us1.com https://trackcmp.net https://diffuser-cdn.app-us1.com https://js-agent.newrelic.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com https://*.typekit.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.google-analytics.com https://stats.g.doubleclick.net https://*.feedbackcompany.com https://*.pinterest.com https://*.clarity.ms https://bam.nr-data.net https://*.nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; form-action www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.cloudfront.net https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com s7.addthis.com *.hsforms.net *.hsforms.com www.google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com maps.googleapis.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.cloudflare.com getfirebug.com *.yotpo.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com ekr.zdassets.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com *.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://unpkg.com https://cdn.onesignal.com https://onesignal.com https://*.onesignal.com https://connect.facebook.net https://www.clarity.ms https://static.clarity.ms https://*.clarity.ms https://www.tiktok.com https://analytics.tiktok.com https://*.tiktok.com https://www.google.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://*.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.googleoptimize.com https://*.doubleclick.net https://*.g.doubleclick.net https://ad.doubleclick.net https://tpc.googlesyndication.com https://*.googlesyndication.com https://*.googleadservices.com https://*.googleadservicesasia.com https://*.adtrafficquality.google https://ep2.adtrafficquality.google; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://fonts.googleapis.com https://onesignal.com https://cdn.onesignal.com https://*.onesignal.com; img-src 'self' data: https: http:; font-src 'self' data: https://fonts.gstatic.com https://cdn.jsdelivr.net; frame-src 'self' https://www.google.com https://*.google.com https://*.doubleclick.net https://*.g.doubleclick.net https://ad.doubleclick.net https://tpc.googlesyndication.com https://*.googlesyndication.com https://*.googleadservices.com https://ep2.adtrafficquality.google https://*.adtrafficquality.google https://www.googletagmanager.com https://*.googletagmanager.com https://www.facebook.com https://*.facebook.com; frame-ancestors 'self'; connect-src 'self' https://prod.biogrenci.com https://sandbox.biogrenci.com https://biogrenci.com https://state.biogrenci.com https://api.netgsm.com.tr https://cdn.onesignal.com https://onesignal.com https://*.onesignal.com https://connect.facebook.net https://www.clarity.ms https://static.clarity.ms https://*.clarity.ms https://q.clarity.ms https://www.tiktok.com https://analytics.tiktok.com https://*.tiktok.com https://region1.google-analytics.com https://ep2.adtrafficquality.google https://www.google.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://*.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.googleoptimize.com https://*.doubleclick.net https://*.g.doubleclick.net https://ad.doubleclick.net https://tpc.googlesyndication.com https://*.googlesyndication.com https://*.googleadservices.com https://*.googleadservicesasia.com https://*.adtrafficquality.google ws://127.0.0.1:* 1 default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https: blob:; object-src 'none'; base-uri 'self'; manifest-src 'self' https:; media-src 'self'; form-action 'self' https:; frame-src 'self' https:; frame-ancestors 'self'; worker-src 'self' blob:; report-uri https://www.biohof.at/ajaxgateway/csp/; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.awin1.com *.zenaps.com *.wepowerconnections.com https://*.etracker.com https://*.etracker.de https://images.unsplash.com https://www.mollie.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://*.etracker.com https://*.etracker.de https://maps.googleapis.com js.mollie.com https://app.uptain.de *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://*.etracker.de https://maps.googleapis.com https://player.vimeo.com https://app.uptain.de *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src static.zdassets.com *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; img-src https://ad.doubleclick.net/ https://www.google.bg/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; connect-src https://ekr.zdassets.com/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://brannik.zendesk.com/ wss://widget-mediator.zopim.com/ https://q.clarity.ms/ measurement-api.criteo.com google.bg vc.hotjar.io dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; script-src https://v2.zopim.com/ https://static.hotjar.com/ https://www.clarity.ms/ https://static.zdassets.com/ https://script.hotjar.com/ dynamic.criteo.com sslwidget.criteo.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; 1 script-src 'self' https: *.brokerapp.com.br *.google.com *.cloudflare.com *.mapbox.com *.googleapis.com *.cloudflare.com *.jqueryscript.net *.iporto.com.br *.brokercrm.com.br *.googlesyndication.com *.googletagmanager.com *.facebook.com *.facebook.net 'unsafe-inline' 'unsafe-eval'; img-src * data: blob:; connect-src 'self' https: *.googlesyndication.com *.facebook.com *.facebook.net 'unsafe-inline' 'unsafe-eval' blob: data:; worker-src data: 'unsafe-eval' 'unsafe-inline' blob: 1 script-src 'self' 'unsafe-eval' blob: https://prod-bk-web.pt.rbi.tools/en/static/js/vendor.9d78d548.js https://prod-bk-web.pt.rbi.tools/en/static/js/main.220249bf.js https://prod-bk-web.pt.rbi.tools/en/static/js/runtime.2d47df47.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.pt.rbi.tools/en/static/js/vendor.dd25e709.js https://prod-bk-web.pt.rbi.tools/en/static/js/main.9c805a81.js https://prod-bk-web.pt.rbi.tools/en/static/js/runtime.7c8ab0d4.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.hsforms.net *.hsforms.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.google.com *.google.fr *.google.ie www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://unpkg.com *.avada.io maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.hsforms.net *.hsforms.com *.google.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com https://ajax.googleapis.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://www.google-analytics.com; font-src 'self'; frame-ancestors 'none'; base-uri 'self'; object-src 'none'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' camys.com.br *.camys.com.br wake-components.fbitsstatic.net camys.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.frenet.com.br *.gstatic.com *.paypalobject.com *.paypal.com *.paypalobjects.com gtm-t7r37nv-m2m3o.uc.r.appspot.com clarity.ms *.clarity.ms *.googleadservices.com googleads.g.doubleclick.net app.cartstack.com.br static.hotjar.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.mercadolibre.com *.mercadopago.com *.mlstatic.com *.cloudfront.net s3.amazonaws.com *.amazonaws.com api.etagdigital.com.br *.etagdigital.com.br bossanova.etagdigital.com.br *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.usebeon.io c.usebeon.io *.adyen.com *.etagdigital.com *.pagar.me *.mundipagg.com *.getnet.com.br *.hotjar.io content.hotjar.io wss://ws.hotjar.com *.hotjar.com *.vendavalida.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br wss://api.coretava.com *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.*.voxus *.targeting.voxus.com.br *.voxus.com.br *.voxus.tv wake.koin.com.br secure.adnxs.com *.loggly.com logs-01.loggly.com *.ipify.org api.ipify.org cdn.targeting.voxus.com.br targeting.voxus.com.br targeting.voxus.tv api.voxus.tv *.secure.adnxs.com *.sizebay.technology paypal-wake.s3.us-east-1.amazonaws.com *.doubleclick.net *.yandex.ru *.sibautomation.com *.cardinalcommerce.com *.secureacs.com *.yandex.com *.yango.com *.webvisor.com *.webvisor.org *.yastatic.net hotjar.io hotjar.com insights.hotjar.com vars.hotjar.com script.hotjar.com csmetrics.hotjar.com metrics.hotjar.io vc.hotjar.io api.globalgetnet.com *.globalgetnet.com *.widde.io videos.widde.io api-admin.widde.io cdn.widde.io *.sandbox.3dsecure.io ws.hotjar.com *.3dsecure.io contentsquare.net *.contentsquare.net *.visa.com *.wake.tech collect.vendavalida.com.br *.appmax.com.br *.tunagateway.com src.mastercard.com *.mastercard.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.camys.com.br camys.com.br; report-uri https://pub-csp.fbits.net/ec162487-9b63-4322-ab05-69be6a49d74b; report-to https://pub-csp.fbits.net/ec162487-9b63-4322-ab05-69be6a49d74b; worker-src 'self' blob:; 1 font-src *.fontawesome.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.multisafepay.com https://pay.google.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com blueskytechmage.com mageblueskytech.com placehold.jp *.multisafepay.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de s7.addthis.com *.multisafepay.com https://pay.google.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.multisafepay.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de ekr.zdassets.com/ *.multisafepay.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https:; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data: 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https:; frame-src 'self' https://*.vipleiloes.com.br https://*.provedor.space https://streaming01.vplpar.com:5443; media-src 'self' https:; form-action 'self' https:; base-uri 'self'; frame-ancestors 'self' https://*.vipleiloes.com.br https://streaming01.vplpar.com:5443; object-src 'none'; 1 font-src fonts.gstatic.com use.typekit.net https://fonts.googleapis.com/ https://fonts.gstatic.com/ *.livechatinc.com/ fonts.googleapis.com *.fontawesome.com https://applepay.cdn-apple.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com 'self' 'unsafe-inline'; frame-ancestors *.trustpilot.com/ 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.monetico-services.com *.avis-verifies.com/ *.google.com *.googleapis.com/ *.googletagmanager.com/ *.gstatic.com/ *.livechatinc.com/ https://secure-magenta.dalenys.com *.trustpilot.com/ www.xtento.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com https://bat.bing.net/ *.avis-verifies.com/ *.google.com/ *.google.fr/ *.googleapis.com/ *.ggpht.com/ *.gstatic.com/ https://securelinkdigitalks.fr/ a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com www.xtento.com cdn.xtento.com https://secure-magenta.dalenys.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com https://player.vimeo.com *.app-us1.com/ https://bat.bing.com/ https://www.clickcease.com/ https://www.dwin1.com/ *.google.com *.googleapis.com/ *.gstatic.com/ *.livechatinc.com/ https://cdn.payplug.com/ https://lantern.roeyecdn.com/ https://trackcmp.net/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.axept.io/ *.skeepers.io/ *.trustpilot.com/ www.xtento.com cdn.xtento.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.google.com/ *.googleapis.com/ *.gstatic.com/ *.fontawesome.com cdn.jsdelivr.net https://secure-magenta.dalenys.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com *.monetico-services.com https://bat.bing.net/ *.colissimo.fr/ *.doubleclick.net/ *.google.com/ *.googleapis.com/ *.googlesyndication.com/ *.gstatic.com/ *.livechatinc.com/ *.mapbox.com/ *.onyourmap.com/ maps.googleapis.com *.axept.io/ *.skeepers.io/ *.trustpilot.com/ t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.qvalent.com *.westpac.com.au *.pageuppeople.com *.ckeditor.com *.jsdelivr.net *.cloudflare.com *.createsend1.com *.casey.vic.gov.au *.googleapis.com *.fastly.io *.google.com *.mypurecloud.com.au *.hotjar.com *.gtranslate.net *.visualwebsiteoptimizer.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.hotjar.io *.snapsendsolve.com www.youtube.com *.openstreetmap.org unpkg.com *powerbi.com;; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.qvalent.com *.westpac.com.au *.pageuppeople.com *.ckeditor.com *.jsdelivr.net *.cloudflare.com *.createsend1.com *.casey.vic.gov.au *.googleapis.com *.fastly.io *.google.com *.mypurecloud.com.au *.hotjar.com *.gtranslate.net *.visualwebsiteoptimizer.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.snapsendsolve.com connect.facebook.net *.openstreetmap.org unpkg.com *powerbi.com;; object-src 'self' 'unsafe-inline' 'unsafe-eval' *.qvalent.com *.westpac.com.au *.pageuppeople.com *.ckeditor.com *.jsdelivr.net *.cloudflare.com *.createsend1.com *.casey.vic.gov.au *.googleapis.com *.fastly.io *.google.com *.mypurecloud.com.au *.hotjar.com *.gtranslate.net *.visualwebsiteoptimizer.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.snapsendsolve.com *.openstreetmap.org unpkg.com *powerbi.com;; img-src 'self' 'unsafe-inline' 'unsafe-eval' *.qvalent.com *.westpac.com.au *.pageuppeople.com *.ckeditor.com *.jsdelivr.net *.cloudflare.com *.createsend1.com *.casey.vic.gov.au *.googleapis.com *.fastly.io *.google.com *.mypurecloud.com.au *.hotjar.com *.gtranslate.net *.visualwebsiteoptimizer.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.google.com.au *.openstreetmap.org unpkg.com *powerbi.com data:; connect-src 'self' 'unsafe-inline' 'unsafe-eval' *.qvalent.com *.westpac.com.au *.pageuppeople.com *.ckeditor.com *.jsdelivr.net *.cloudflare.com *.createsend1.com *.casey.vic.gov.au *.googleapis.com *.fastly.io *.google.com *.mypurecloud.com.au *.hotjar.com *.gtranslate.net *.visualwebsiteoptimizer.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.hotjar.io wss://ws.hotjar.com *.doubleclick.net *.openstreetmap.org unpkg.com *powerbi.com;; report-uri /report-csp-violation 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.doubleclick.net *.facebook.com *.googlesyndication.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io cdn.doofinder.com https://images.unsplash.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com https://firebasestorage.googleapis.com 'self' data: *.google.com *.google.it *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.feedaty.com *.googlesyndication.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com maps.gstatic.com https://www.cavallimusica.com *.trustedshops.com *.etrusted.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com cdn.doofinder.com https://maps.googleapis.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com *.avada.io *.shopify.com *.google.bg *.google.it *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.feedaty.com *.googleadservices.com *.adform.net *.iubenda.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com maps.googleapis.com *.trustedshops.com *.etrusted.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.feedaty.com *.iubenda.com assets.braintreegateway.com *.trustedshops.com *.etrusted.com *.tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com https://get.geojs.io *.avada.io *.facebook.com *.facebook.net *.feedaty.com *.googlesyndication.com *.doubleclick.net *.iubenda.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.bootstrapcdn.com *.closet22.com closet22.com 'self' data: *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.qcb.gov.qa *.snapchat.com *.twitter.com *.cardinalcommerce.com *.paypal.com *.modirum.com *.eurocommerce.gr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com *.infobip.com *.snapchat.com *.hotjar.com *.skroutz.gr *.twitter.com *.consensu.org *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.net *.facebook.com *.twitter.com t.co *.skroutz.gr *.bestprice.gr *.google.gr *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com *.facebook.net *.facebook.com *.infobip.com *.cloudflareinsights.com *.google.gr *.twitter.com *.ads-twitter.com sc-static.net *.doubleclick.net *.iconify.design *.hotjar.com *.skroutz.gr *.bestprice.gr *.smartlook.com *.chimpstatic.com chimpstatic.com *.linkwi.se *.heatmap.it *.adman.gr *.cloudflare.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.sharethis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com unsafe-inline *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com *.infobip.com *.facebook.com *.facebook.net *.snapchat.com *.doubleclick.net *.hotjar.com *.google.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self' wss://localhost:44378/MDL3MEarPlugSettlementWeb/ wss://localhost:44339/MDL3MEarPlugSettlementWeb/; script-src 'self' https://acsbapp.com/apps/app/dist/js/ https://acsbapp.com/apps/app/dist/js/app.js 'sha256-a/7jwHVk91+ykLC4DFor1xbtOi2RtBOCEsyGRmbQCqg=' 'nonce-c5233efb04f44a73b6f5818400bd6eec' https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ wss://localhost:44378/MDL3MEarPlugSettlementWeb/ wss://localhost:44339/MDL3MEarPlugSettlementWeb/; style-src 'self' 'sha256-PErmU+TYRcPwrRm3MyRLjITnpqDhWmPNUbcKKJvhDEg=' 'sha256-WPlotXzoUAc9dAX9VP8kh67FoVkPmFBGjhwNruaBRm0=' 'sha256-BFU3BnyqbhnU5P4bEBvLn1IgebSFXoYgLIS9f14EELE=' 'sha256-BFU3BnyqbhnU5P4bEBvLn1IgebSFXoYgLIS9f14EELE=' 'sha256-77eiGD30q+meCl4OODdDJ1/zL6eNuQkiJC/BxPPdysY=' 'sha256-O3jpUocZrCjDOxGs4ipG8JIZfKISj9Kkrvnplmz5hJU=' 'sha256-0hJ78+O6zvs01KYuCuy720JiA8yfNHPGBiulC4LrNwQ=' 'sha256-+E1Dmp1R73QDtKFL3SMs9tIOqvXmNn4KDimSASJyJ1I=' 'sha256-tLnIAscSvDCHUgYQpD8+EtdKCQy3SyrAv4pAtxghOEM=' 'sha256-WPlotXzoUAc9dAX9VP8kh67FoVkPmFBGjhwNruaBRm0=' 'sha256-1SGg8DOvFA7Q2JXQR8X+jtINliFVnWOWksxci1/tt6s=' 'sha256-/QEWW84RZVrjuSPK6q6qMeqbc/pCLMknXFFcCck5TAk=' 'sha256-/QEWW84RZVrjuSPK6q6qMeqbc/pCLMknXFFcCck5TAk=' 'sha256-/QEWW84RZVrjuSPK6q6qMeqbc/pCLMknXFFcCck5TAk=' 'sha256-BFU3BnyqbhnU5P4bEBvLn1IgebSFXoYgLIS9f14EELE=' 'sha256-77eiGD30q+meCl4OODdDJ1/zL6eNuQkiJC/BxPPdysY=' 'sha256-WPlotXzoUAc9dAX9VP8kh67FoVkPmFBGjhwNruaBRm0=' 'sha256-QNGhJ7kaK0ptxgUeZLrfpRNLV1vCWe6mNX20jkQHlKM=' 'sha256-z7zcnw/4WalZqx+PrNaRnoeLz/G9WXuFqV1WCJ129sg=' 'sha256-V5GCv7g+0m456JOc8LaCSG/jwgo4y4k5w8iKRPeff0k=' https://fonts.googleapis.com wss://localhost:44378/MDL3MEarPlugSettlementWeb/; font-src 'self' https://fonts.gstatic.com wss://localhost:44378/MDL3MEarPlugSettlementWeb/; img-src 'self' wss://localhost:44378/MDL3MEarPlugSettlementWeb/ http: https: data:; connect-src 'self' wss://localhost:44395/MDL3MEarPlugSettlementWeb/ wss://localhost:44301/MDL3MEarPlugSettlementWeb/ wss://localhost:44362/MDL3MEarPlugSettlementWeb/ wss://localhost:44339/MDL3MEarPlugSettlementWeb/ wss://localhost:44378/MDL3MEarPlugSettlementWeb/ https://cdn.acsbapp.com/cache/app/wildcards.json https://cdn.acsbapp.com/config/ https://acsbapp.com/apps/app/dist/js/; frame-src 'self' https://www.google.com; object-src 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net/npm/mathjax@2.7.8/ https://www.google.com/recaptcha/ https://www.youtube.com https://vimeo.com https://www.instagram.com; connect-src 'self' blob:; script-src-elem 'self' 'unsafe-inline' https://www.youtube.com https://cdn.jsdelivr.net/npm/mathjax@2.7.8/ https://www.google.com/recaptcha/ https://vimeo.com https://www.instagram.com; frame-src 'self' https://www.youtube.com https://view.genial.ly https://www.canva.com https://player.vimeo.com https://www.instagram.com https://es.educaplay.com https://www.educaplay.com https://prezi.com https://h5p.org; media-src 'self' https://www.youtube.com ; style-src * data: blob: 'unsafe-inline'; style-src-attr * data: blob: 'unsafe-inline'; style-src-elem * data: blob: 'unsafe-inline'; font-src * data: blob: about: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; worker-src data: blob: 'unsafe-inline'; report-uri https://www.comfenalcoantioquia.edu.co/local/csp/collector.php?uid=0&cid=1 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.trustpilot.com cdn.jsdelivr.net fonts.googleapis.com https://api-sogecommerce.societegenerale.eu/static/ https://cdnjs.cloudflare.com www.compagnie-bicarbonate.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.facebook.com www.compagnie-bicarbonate.com 'self' 'unsafe-inline'; frame-ancestors www.compagnie-bicarbonate.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.trustpilot.com https://widget.trustpilot.com widget.trustpilot.com www.google.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.compagnie-bicarbonate.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trustpilot.com *.clarity.ms c.bing.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://sogecommerce.societegenerale.eu/static/latest/images/type-carte/ https://api-sogecommerce.societegenerale.eu/static/ https://sogecommerce.societegenerale.eu/vads-payment/ cdn.doofinder.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com www.compagnie-bicarbonate.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.sheetjs.com *.trustpilot.com widget.trustpilot.com *.clarity.ms www.clarity.ms *.bing.com www.google.com www.gstatic.com cdn.jsdelivr.net *.doofinder.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ cdn.doofinder.com https://cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.compagnie-bicarbonate.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.trustpilot.com cdn.jsdelivr.net https://api-sogecommerce.societegenerale.eu/static/ *.doofinder.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.tagmanager.google.com *.googletagmanager.com www.compagnie-bicarbonate.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.compagnie-bicarbonate.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.clarity.ms https://e.clarity.ms c.bing.com *.doofinder.com maps.googleapis.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ wss://*.doofinder.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.compagnie-bicarbonate.com 'self' 'unsafe-inline'; child-src www.compagnie-bicarbonate.com http: https: blob: 'self' 'unsafe-inline'; default-src https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ www.compagnie-bicarbonate.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://i.ytimg.com https://intelimotor-shops.nyc3.cdn.digitaloceanspaces.com; font-src 'self' data: https://fonts.gstatic.com; media-src 'self'; connect-src 'self' blob: data: https://shops-search.intelimotor.com; object-src 'none'; worker-src 'self' blob:; manifest-src 'self'; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; form-action 'self'; base-uri 'self'; frame-ancestors 'none'; report-uri /csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com *.mercadolibre.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * mldp.mercadopago.com www.mercadolibre.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.vnforapps.com *.online-metrix.net imgmp.mlstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net *.vnforapps.com *.online-metrix.net *.mlstatic.com www.facebook.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com http2.mlstatic.com secure.mlstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com api.comapi.com bam.nr-data.net *.vnforapps.com *.online-metrix.net *.mercadopago.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /csp/report/;base-uri 'self';default-src 'self';script-src 'self' 'unsafe-inline' https: 'nonce-byQpCTYmCI33-A' 'strict-dynamic';frame-src 'self' https://subscription-management.paddle.com https://buy.paddle.com;style-src 'self' 'unsafe-inline' https://cdn.paddle.com/;img-src 'self' https://cdn.paddle.com/ blob: data:;object-src 'none';connect-src 'self' https://plausible.io/ wss://deva.guru ws://deva.guru; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' lib.hmcms.nl *.digiplein.com www.googletagmanager.com *.googleapis.com *.google-analytics.com www.gstatic.com https://www.youtube-nocookie.com https://www.youtube.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ *.livechatinc.com; frame-src 'self' *.digiplein.com https://www.googletagmanager.com https://www.youtube-nocookie.com https://www.youtube.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ *.livechatinc.com; object-src 'self' *.digiplein.com *.livechatinc.com; report-uri https://lib.hmcms.nl/api/csp-report-only.json 1 object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; frame-src td.doubleclick.net/ https://lockerplugin.sameday.ro https://www.googletagmanager.com/ fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://plumrocket.com *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; frame-ancestors unsafe-inline www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; connect-src www.google-analytics.com https://stats.g.doubleclick.net/j/ https://www.google.com/ https://googleads.g.doubleclick.net/ https://web.facebook.com/ pagead2.googlesyndication.com/pagead/buyside_topics/set/ region1.analytics.google.com/g/ https://stats.g.doubleclick.net/ dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net 'self' 'unsafe-inline'; img-src data: www.google.bg/pagead/ www.google.com/pagead/ www.facebook.com/tr/ maps.googleapis.com www.google.bg/ads/ga-audiences www.google.com/ads/ga-audiences assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com 'self' data: *.facebook.com data: 'self' 'unsafe-inline'; style-src maxcdn.bootstrapcdn.com fonts.googleapis.com https://cdn.sameday.ro *.adobe.com downloads.mailchimp.com *.fontawesome.com https://fonts.googleapis.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; font-src maxcdn.bootstrapcdn.com fonts.gstatic.com googleapis.com fonts.googleapis.com *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; script-src connect.facebook.com connect.facebook.net facebook.com googleads.g.doubleclick.net www.google-analytics.com www.google.com/pagead/ www.google.bg/pagead/ www.facebook.com/tr/ maps.googleapis.com ajax.cloudflare.com/cdn-cgi/scripts/ ssets.adobedtm.com secure.authorize.net test.authorize.net js.braintreegateway.com bimg.abv.bg/GDPR/GDPR.js dmp.adwise.bg chimpstatic.com cdn.onesignal.com/sdks/OneSignalSDK.js static.zdassets.com/ekr/asset_composer.js v2.zopim.com/ cdn.onesignal.com/ onesignal.com/ https://cdn.sameday.ro http://www.facebook.com/tr/ assets.adobedtm.com *.adobe.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com www.facebook.com graph.facebook.com downloads.mailchimp.com *.list-manage.com *.avada.io *.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; form-action https://3dsgate.borica.bg/cgi-bin/cgi_link geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com *.facebook.com https://firebasestorage.googleapis.com https://www.magezon.com *.leadgenerationsoftware.it *.google.com *.googleapis.com *.tawk.to *.google.it www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.googleapis.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.avada.io *.klaviyo.com *.hotjar.com *.leadgenerationsoftware.it *.google-analytics.com *.tawk.to *.iubenda.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net *.klaviyo.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.google-analytics.com https://get.geojs.io *.avada.io *.googleapis.com *.klaviyo.com *.hotjar.io *.doubleclick.net *.tawk.to *.iubenda.com *.googlesyndication.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem *.googleapis.com assets.adobedtm.com *.cardinalcommerce.com local.dochorse.nl *.hypernode.io; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com data: *.fontawesome.com *.cloudflare.com fonts.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cookiebot.com *.hotjar.com *.criteo.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.sendcloud.sc *.jsdelivr.net js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.placeholder.com *.linkedin.com *.cookiebot.com *.hypernode.io *.google.com *.google.cn *.cloudfront.net https://images.unsplash.com 'self' data: *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.amazonaws.com flagpedia.net https://www.mollie.com *.hsforms.net *.hsforms.com www.magmodules.eu *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.newrelic.com bam-cell.nr-data.net bam.nr-data.net *.cookiebot.com *.googleapis.com widget.thuiswinkel.org *.hotjar.com *.criteo.net *.criteo.com api.widget.trengo.eu static.widget.trengo.eu *.trustpilot.com vanerkel.zendesk.com static.zdassets.com chimpstatic.com *.cardinalcommerce.com *.authorize.net *.bing.com *.doubleclick.net *.hypernode.io https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.sendcloud.sc maps.googleapis.com js.mollie.com *.hsforms.net *.hsforms.com squeezely.tech www.squeezely.tech *.squeezely.tech https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com *.fontawesome.com *.thuiswinkel-cdn.org *.googleapis.com *.hypernode.io *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.sendcloud.sc *.jsdelivr.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com bam-cell.nr-data.net *.cookiebot.com api.widget.trengo.eu *.thuiswinkel-cdn.org *.hotjar.com wss://ws17.hotjar.com *.google-analytics.com vanerkel.zendesk.com *.zdassets.com *.doubleclick.net *.zopim.com wss://widget-mediator.zopim.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.googlesyndication.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com www.gstatic.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com squeezely.tech *.squeezely.tech *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.bluz.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.leanpay.si https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.bluz.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.bluz.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.bluz.com https://maps.googleapis.com *.disqus.com https://cdn.jsdelivr.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bluz.com https://cdn.jsdelivr.net cdn.jsdelivr.net *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.bluz.com https://maps.googleapis.com https://player.vimeo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://www.dovetailhome.com/api/reporting/; report-to csp-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-W43E6jcsFBnMB89s03W8lA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 connect-src 'self' *; 1 frame-src https://celesio.file.force.com *.force.com https://player.vimeo.com https://content.instrumentation.getconga.com https://*.aah.co.uk https://www.linkedin.com 'self' https://stats.g.doubleclick.net *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es https://*.googleapis.com https://gbr122.sfdc-5pakla.salesforce.com *.adis.ws https://www.gstatic.com https://celesio--c.um3.content.force.com https://composer.congamerge.com https://*.onetrust.com https://*.youtube.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://www.google.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video https://region1.google-analytics.com *.youtube.fr https://cdn-ukwest.onetrust.com https://*.salesforce.com https://region1.analytics.google.com https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com https://data.instrumentation.getconga.com *.youtube.com *.brightcove.net https://ssl.gstatic.com https://*.supplier-point.com *.youtube.nl https://service.force.com/embeddedservice/ https://fast.wistia.net *.quip.com *.arkoselabs.com https://*.cookielaw.org *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com https://youtu.be *.youtube.com.br *.salesforce-experience.com https://*.aah-point.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://celesio--4cdevflu--livepreview.cs110.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net https://*.force.com *.youtube.ca https://location.force.com *.vidyard.com https://*.linkedin.com https://*.trustarc.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://*.medecator.co.uk https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://try.abtasty.com https://px.ads.linkedin.com https://*.a.forceusercontent.com/lightningmaps/ https://www.googletagmanager.com *.wistia.net https://www.google-analytics.com *.salesforce.com https://www.google.co.uk *.youtube.pl; report-to sfdc-csp-ep; report-uri https://celesio.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D24000000aWJn&networkId=0DM4H0000005Qv9&type=communities 1 font-src *.gstatic.com data: 'self' data: *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.google.com *.iubenda.com *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.iubenda.com *.meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.google.com *.gstatic.com ws10b.cvetta.io *.iubenda.com s7.addthis.com *.avada.io *.meetanshi.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.google-analytics.com *.googleapis.com *.iubenda.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.meetanshi.com https://www.google-analytics.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' esportelegal.com.br *.esportelegal.com.br wake-components.fbitsstatic.net esportelegal.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com online-metrix.net googlesyndication.com googleadservices.com traycheckout.com.br yapay.com.br clearsale.com.br doubleclick.net ebit.com.br hertzen.com cloudflare.com k-analytix.com hotjar.io cloudfront.net hotjar.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.googlesyndication.com *.online-metrix.net *.googleadservices.com *.traycheckout.com.br *.yapay.com.br *.cloudflare.com *.k-analytix.com *.ebit.com.br *.hertzen.com *.clearsale.com.br *.doubleclick.net *.cloudfront.net *.hotjar.com *.hotjar.io wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.googletagmanager.com *.rdstation.com.br pageview-notify.rdstation.com.br pages.rdstation.com.br googletagmanager.com hits-banner-cloud-function.azurewebsites.net *.azurewebsites.net *.google.com.br *.clearsale.com.br *.g.doubleclick.net *.google-analytics.com google-analytics.com stats.g.doubleclick.net googleads.g.doubleclick.net google.com.br *.criteo.com *.criteo.net bat.bing.com *.directtalk.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com d3bo67muzbfgtl.cloudfront.net api.edrone.me signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.smarthint.co gstatic.com *.fbits.store *.adyen.com d3vhsxl1pwzf0p.cloudfront.net api-s.edrone.me dgk28ckagqims.cloudfront.net d2vfa2a1j2oldr.cloudfront.net *.edrone.me wss://v18dxapjmd.execute-api.eu-west-1.amazonaws.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com checkout.esportelegal.com. connect.facebook.net *.facebook.net *.sandbox.3dsecure.io maps.googleapis.com *.googleapis.com saltcdn2.googleapis.com translate.googleapis.com translate-pa.googleapis.com cdn.lightwidget.com *.lightwidget.com *.esportelegal.com.br esportelegal.com.br fbitsstatic.net *.fbitsstatic.net .googletagmanager.com vindi.com.br *.vindi.com.br *.facebook.com facebook.com fbits.net *.fbits.net youtube.com *.youtube.com *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.esportelegal.com.br esportelegal.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.gstatic.com *.cdn.userway.org; font-src 'self' fonts.gstatic.com; img-src 'self' cdn.userway.org data: sppagebuilder.com; connect-src 'self' cdn77.api.userway.org api.userway.org; script-src 'self' cdn.userway.org ajax.googleapis.com maxcdn.bootstrapcdn.com 'sha256-N/4d8ewez3Wzx5WmnOwGLZfRBddPWJMlVZKikRqRiQo=' 'sha256-fjHH/hDGedQwWCxjrFtTeJTwaWHkUA4R2FtSczrt+nE=' 'sha256-lysybRP1rtnmYhULZgz5WbX8hVhH60eBe6B+Wf6Kfio=' 'sha256-wZIG9cCx5f/yTZaMx2nTU3dg4bIInmA2Y4RaB3cwgbM=' 'sha256-200wrhX/wS06hTi8A0Zb9eqnXkmPo5X3Z/gq2KpwoDI=' https://www.youtube.com; frame-src 'self' http://www.youtube.com; 1 default-src 'none'; child-src 'self' https://*.stockholm.se; connect-src 'self' data: *.rekai.se https://*.mediaflow.com https://*.stockholm.se https://assets.mediaflowpro.com https://consent.app.cookieinformation.com https://familjebostader.containers.piwik.pro https://familjebostader.piwik.pro https://infragrid.v.network https://m.mediaflow.com https://mfstatic.com https://predict.rek.ai https://predict.rekai.se https://translate-pa.googleapis.com https://v1.mediaflow.com https://view.rekai.se https://www.familjebostader.com https://www.google.com https://www.google-analytics.com policy.app.cookieinformation.com; font-src 'self' data: https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/ https://*.stockholm.se https://at.alicdn.com https://cdn.scite.ai https://fonts.gstatic.com https://mfstatic.com; form-action 'self' https://*.stockholm.se; frame-src 'self' https://*.stockholm.se https://aptusportalen.familjebostader.com https://stockholmsstad.varbi.com https://via.tt.se https://www.google.com https://www.youtube.com policy.app.cookieinformation.com; img-src 'self' blob: data: https://*.familjebostader.com https://*.stockholm.se https://assets.mediaflowpro.com https://cdn.honey.io https://fonts.gstatic.com https://jonypractic.net https://maps.googleapis.com https://mfstatic.com https://translate.google.com; media-src 'self' blob: data: https://*.stockholm.se https://m.mediaflow.com https://v4.mediaflow.com; script-src-attr 'self' 'unsafe-inline' https://*.stockholm.se; script-src-elem 'self' 'unsafe-inline' blob: *.rekai.se https://*.stockholm.se https://cdnjs.cloudflare.com https://connect.facebook.net https://familjebostader.containers.piwik.pro https://gc.kis.v2.scr.kaspersky-labs.com https://maxcdn.bootstrapcdn.com https://mfstatic.com https://policy.app.cookieinformation.com https://secured-pixel.com https://static.rekai.se https://via.tt.se https://web-sdk-eu.aptrinsic.com https://www.google.com https://www.gstatic.com policy.app.cookieinformation.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.stockholm.se https://connect.facebook.net https://familjebostader.containers.piwik.pro https://policy.app.cookieinformation.com https://static.rekai.se; style-src-elem 'self' 'unsafe-inline' http://www.familjebostader.com https://*.familjebostader.com https://*.stockholm.se https://fonts.googleapis.com https://gc.kis.v2.scr.kaspersky-labs.com https://maxcdn.bootstrapcdn.com https://mfstatic.com https://web-sdk-eu.aptrinsic.com https://www.familjebostader.com https://www.gstatic.com; style-src-attr 'unsafe-inline' https://*.stockholm.se; style-src 'unsafe-eval' 'unsafe-inline' http://www.familjebostader.com https://*.stockholm.se https://www.familjebostader.com; worker-src blob: https://*.stockholm.se; base-uri https://*.stockholm.se; frame-ancestors https://*.stockholm.se; manifest-src https://*.stockholm.se; object-src https://*.stockholm.se; report-to stott-security-endpoint; 1 font-src *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com assets.adobedtm.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com *.vimeo.com www.youtube.com data: use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com http://10.40.40.65:443 https://www.ecyd.cl https://www.mercadopago.cl pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com https://www.googletagmanager.com analytics.google.com tagmanager.google.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net assets.adobedtm.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com cdnjs.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com *.vimeo.com *.youtube.com data: bid.g.doubleclick.net *.youtube-nocookie.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.paypal.com google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com *.vimeo.com *.youtube.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://firebasestorage.googleapis.com *.facebook.com https://www.googletagmanager.com tagmanager.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.disqueriachilena.cl *.farmaciamapuche.cl https://produccion24.anticipa.cl *.salud5i.cl/ *.salud5i.com.mx *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com vimeo.com *.youtube.com data: googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.nr-data.net *.commerce-payment-services.com www.googleapis.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.cdn-apple.com cdn.ampproject.org raw.githubusercontent.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.retailrocket.net https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src assets.adobedtm.com *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com *.vimeo.com www.youtube.com data: fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net tagmanager.google.com https://www.googletagmanager.com analytics.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com assets.adobedtm.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com vimeo.com www.youtube.com data: analytics.google.com www.googletagmanager.com *.nr-data.net pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com cdn.ampproject.org www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.retailrocket.net https://get.geojs.io *.google-analytics.com *.facebook.net https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.boria.cl *.farmaciaabba.cl *.anticipa.cl *.disqueriachilena.cl *.calstiendavirtual.cl *.farmaciamapuche.cl *.korb.cl *.kxcdn.com *.cloudflare.com www.google-analytics.com www.googleadservices.com fonts.googleapis.com/ *.googleapis.com fonts.gstatic.com *.google.com https://www.gstatic.com www.paypalobjects.com *.payments-amazon.com www.paypal.com www.sandbox.paypal.com t.paypal.com assets.adobedtm.com *.authorize.net *.braintreegateway.com *.mailchimp.com *.list-manage.com *.avada.io *.freshchat.com *.newrelic.com https://bam.nr-data.net s.ytimg.com video.google.com *.vimeo.com www.youtube.com data: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com maps.googleapis.com chart.googleapis.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.avada.io *.shopify.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://static.klaviyo.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.fontawesome.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.google.com assets.sympl.ai 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com flagpedia.net cdn.jsdelivr.net commerceocean.com placehold.jp assets.sympl.ai www.google.com.ua https://vmuupymy.euj.stape.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ apis.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com maps.googleapis.com cdn.jsdelivr.net assets.sympl.ai https://vmuupymy.euj.stape.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com cdn.jsdelivr.net *.googleapis.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://stats.addtoany.com/menu fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.googleapis.com www.gstatic.com maps.googleapis.com cdn.jsdelivr.net ipapi.co *.typekit.net assets.sympl.ai https://vmuupymy.euj.stape.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src 'self' data: https://analytics.clientify.net https://imgsct.cookiebot.com https://files.smartsuppcdn.com https://tracker.metricool.com https://www.google.es https://px.ads.linkedin.com https://www.google.com https://www.googletagmanager.com https://nueva.firmafy.com https://lh3.googleusercontent.com https://www.google.ie https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://www.smartsuppchat.com https://consent.cookiebot.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://tracker.metricool.com data: https://analytics.clientify.net https://snap.licdn.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://widget-v3.smartsuppcdn.com https://api.clientify.net https://app.firmafy.com https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.trustindex.io https://kit.fontawesome.com 'unsafe-eval' https://www.google.com/recaptcha/; script-src-elem 'self' 'unsafe-inline' https://www.smartsuppchat.com https://consent.cookiebot.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://tracker.metricool.com data: https://analytics.clientify.net https://snap.licdn.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://widget-v3.smartsuppcdn.com https://api.clientify.net https://app.firmafy.com https://gc.kis.v2.scr.kaspersky-labs.com https://cdn.trustindex.io https://kit.fontawesome.com https://google.com https://www.google.com https://gstatic.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://widget-v3.smartsuppcdn.com https://www.gstatic.com https://use.fontawesome.com ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://widget-v3.smartsuppcdn.com https://www.gstatic.com https://use.fontawesome.com ; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com data:; frame-src 'self' https://consentcdn.cookiebot.com https://td.doubleclick.net https://www.googletagmanager.com blob: https://google.com https://www.google.com https://gstatic.com https://www.gstatic.com; connect-src 'self' https://region1.analytics.google.com https://consentcdn.cookiebot.com https://px.ads.linkedin.com https://pagead2.googlesyndication.com https://region1.google-analytics.com https://www.google.com https://bootstrap.smartsuppchat.com https://www.google-analytics.com https://widget-v3.smartsuppcdn.com https://stats.g.doubleclick.net https://translations.smartsuppcdn.com wss://websocket-visitors.smartsupp.com https://fonts.googleapis.com https://www.googleadservices.com https://analytics.google.com https://api.smartsuppchat.com https://www.google.es https://google.com https://analytics.clientify.net; report-uri https://firmafy.com/wp-json/rsssl/v1/csp?rsssl_apitoken=768550442; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' fisiostore.com.br *.fisiostore.com.br wake-components.fbitsstatic.net fisiostore.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.mlstatic.com *.g.doubleclick.net *.google.com.br stats.g.doubleclick.net *.voxus.com.br *.googleadservices.com *.clearsale.com.br *.loggly.com *.googlesyndication.com *.yourviews.com.br *.googletagmanager.com api.ipify.org *.ipify.org *.google-analytics.com google.co.ao google.fr *.google.fr googletagmanager.com *.mercadopago.com *.google.pl *.googleapis.com *.zdassets.com static.zdassets.com *.mercadolibre.com fisio.zendesk.com *.zendesk.com *.clarity.ms *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com google-analytics.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net td.doubleclick.net *.doubleclick.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.fbitsstatic.net *.facebook.net *.facebook.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com yviews.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com *.openwidget.com cdn.openwidget.com connect.facebook.net api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.fisiostore.com.br fisiostore.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.authorize.net https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com store.paradoxlabs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.authorize.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.authorize.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: static.nacongaming.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.google.com www.youtube.com amc.demdex.net vars.hotjar.com www.facebook.com static.nacongaming.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com network-eu-stg.bazaarvoice.com network-eu.bazaarvoice.com network-eu-a.bazaarvoice.com media.nacongaming.com scaleflex.ultrafast.io axeptio.imgix.net www.google.fr www.facebook.com static.nacongaming.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com network-eu.bazaarvoice.com network-eu-stg.bazaarvoice.com www.google.com www.gstatic.com script.hotjar.com static.hotjar.com connect.facebook.net anltc-v2.bigben.fr analytics.tiktok.com www.googleoptimize.com static.nacongaming.com static.axept.io anltc.bigben.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com *.fontawesome.com use.typekit.net p.typekit.net static.nacongaming.com 'self' 'unsafe-inline'; object-src static.nacongaming.com 'self' 'unsafe-inline'; media-src *.adobe.com static.nacongaming.com media.nacongaming.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com in.hotjar.com stats.g.doubleclick.net anltc-v2.bigben.fr axeptio.imgix.net static.nacongaming.com client.axept.io api.axept.io anltc.bigben.fr 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src 'self' 'unsafe-inline' 'unsafe-eval'; font-src https: data:; style-src https: 'unsafe-inline'; img-src https: data:; report-uri https://virtualhawking.com/local/csp/collector.php?uid=0&cid=1 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://media.galponderopa.com https://static.galponderopa.com https://media.galponderopa-prod.menze.la https://static.galponderopa-prod.menze.la 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://media.galponderopa.com https://static.galponderopa.com https://media.galponderopa-prod.menze.la https://static.galponderopa-prod.menze.la *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com https://media.galponderopa.com https://static.galponderopa.com https://media.galponderopa-prod.menze.la https://static.galponderopa-prod.menze.la *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://live.decidir.com https://assets-cdn.woowup.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net https://media.galponderopa.com https://static.galponderopa.com https://media.galponderopa-prod.menze.la https://static.galponderopa-prod.menze.la *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io https://media.galponderopa.com https://static.galponderopa.com https://media.galponderopa-prod.menze.la https://static.galponderopa-prod.menze.la *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://developers.decidir.com https://developers-ventasonline.payway.com.ar https://live.decidir.com https://assets-cdn.woowup.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.typography.com fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com www.googletagmanager.com secure.livechatinc.com ct.pinterest.com metrics.gardssallskapet.se forms.helpdesk.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.elfsightcdn.com *.gardssallskapet.se bat.bing.com www.google.com www.google.se www.googletagmanager.com googleads.g.doubleclick.net https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.cookie-script.com www.gstatic.com www.google.com tagmanager.google.com *.stripe.com *.klarna.com *.elfsight.com *.elfsightcdn.com universe-static.elfsightcdn.com www.googletagmanager.com edge.eu1.fullstory.com rs.eu1.fullstory.com bat.bing.com googleads.g.doubleclick.net www.clarity.ms cdn.livechatinc.com api.livechatinc.com ct.pinterest.com s.pinimg.com stapecdn.com *.stapecdn.com klarna.com *.klarnacdn.net *.klarnaevt.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.typography.com cdnjs.cloudflare.com fonts.googleapis.com *.gardssallskapet.se connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.dotdigital-pages.com *.trackedlink.net *.trackedweb.net *.newrelic.com *.nr-data.net *.vimeo.com dpm.demdex.net amcglobal.sc.omtrdc.net https://fonts.bunny.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com region1.google-analytics.com region1.analytics.google.com *.klarna.com *.stripe.com www.google.com google.com edge.eu1.fullstory.com rs.eu1.fullstory.com bat.bing.com https://get.geojs.io core.service.elfsight.com *.elfsight.com stats.g.doubleclick.net https://stats.g.doubleclick.net ct.pinterest.com *.pinterest.com s.pinimg.com https://metrics.gardssallskapet.se metrics.gardssallskapet.se *.gardssallskapet.se *.googleadservices.com klarna.com *.klarnacdn.net *.klarnaevt.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://use.typekit.net https://geowidget.easypack24.net *.fontawesome.com fonts.gstatic.com *.inpost.pl fonts.googleapis.com https://fonts.bunny.net *.gls.com *.szybkapaczka.pl *.gls-poland.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com https://td.doubleclick.net https://cookie.inpost.pl https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ pay.google.com apm.przelewy24.pl *.inpost.pl *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://ekipatonosi.pl https://indeste.pl https://genzie.store https://influcenter.pl https://krakowkings.store https://hi-store.pl https://sklepbazy.pl https://sklepfazy.pl https://static.paynow.pl *.cloudfront.net https://player.vimeo.com https://www.google.pl https://www.facebook.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org static.przelewy24.pl www.gstatic.com gstatic.com https://firebasestorage.googleapis.com https://api.mapbox.com *.szybkapaczka.pl *.gls-poland.com/ *.gls-poland.com.pl/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://ekipatonosi.pl https://indeste.pl https://genzie.store https://influcenter.pl https://krakowkings.store https://hi-store.pl https://sklepbazy.pl https://sklepfazy.pl https://static.paynow.pl https://developer.gls-poland.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.avada.io *.shopify.com *.szybkapaczka.pl *.gls-poland.com/ sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://developer.gls-poland.com https://use.typekit.net https://geowidget.easypack24.net https://geowidget.inpost.pl *.fontawesome.com fonts.googleapis.com *.inpost.pl https://fonts.bunny.net *.szybkapaczka.pl *.gls-poland.com/ sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.easypack24.net *.inpost.pl *.openstreetmap.org sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl google.com www.google.com pay.google.com https://get.geojs.io *.avada.io *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' https://www.googletagmanager.com 'nonce-AURz7ySxV8NXT9GTXP5Ejg=='; object-src 'none'; base-uri 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.trustedshops.com *.googleapis.com *.bootstrapcdn.com *.cloudfront.net *.hotjar.com gerduva.lt https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.facebook.com *.hotjar.com gerduva.lt 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com *.cloudfront.net *.hotjar.com gerduva.lt https://*.every-pay.com/ https://pay.google.com/ www.youtube.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://omnisnippet1.com https://wt.soundestlink.com *.cloudflare.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com https://*.cloudfront.net/ *.paysera.com https://*.paysera.com/ https://*.youtube.com/ *.hotjar.com gerduva.lt https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt https://*.every-pay.com/ *.facebook.com https://firebasestorage.googleapis.com *.googleapis.com https://maps.omnivasiunta.lt *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://omnisnippet1.com https://forms.soundestlink.com *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.cloudfront.net *.hotjar.com *.paysera.com gerduva.lt https://unpkg.com https://*.every-pay.com/ https://pay.google.com/ s7.addthis.com *.facebook.net *.avada.io *.shopify.com *.googleapis.com www.youtube.com player.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com *.bootstrapcdn.com *.cloudfront.net *.hotjar.com gerduva.lt https://unpkg.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com *.hotjar.com *.paysera.com gerduva.lt https://www.terminalmappingjs.com https://geocode.arcgis.com ekr.zdassets.com/ *.google-analytics.com https://get.geojs.io *.avada.io *.googleapis.com *.gstatic.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1:8080/; report-to report-endpoint; 1 font-src *.fontawesome.com *.alothemes.com *.magepow.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.fallodick78-87.sbs/common www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com static.whatsapp.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com *.facebook.net *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com static.whatsapp.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com gratia.com.ar cdn.gratia.com.ar gratia.66ecommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.alothemes.com *.magepow.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube-nocookie.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io camo.githubusercontent.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.vimeo.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.alothemes.com *.magepow.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.googleapis.com *.fontawesome.com *.bootstrapcdn.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.twitter.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es connect.xpayments.com *.xpayments.com *.twitter.com *.google.com *.addthis.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com data: sealserver.trustwave.com widget.tochat.be yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.authorize.net *.cardinalcommerce.com *.avada.io maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' widget.tochat.be www.trustlogo.com chimpstatic.com sealserver.trustwave.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.cloudflare.com *.twitter.com *.paypal.com services.tochat.be www.google-analytics.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://*.mercadolibre.com https://td.doubleclick.net https://*.adobe.com *.mercadolibre.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.google.com https://*.google.com.ar https://www.afip.gob.ar secure.trust-provider.com www.facebook.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://live.decidir.com secure.comodo.com 'unsafe-inline' https://googleads.g.doubleclick.net https://analytics.google.com https://*.mercadopago.com sha256-JjB9AR5B8LsPf/TKvAnbJPZo0gV8TDK3FD5ufwBVVT8= *.avada.io *.mlstatic.com *.mercadopago.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://developers.decidir.com/ https://live.decidir.com https://*.google.com https://*.google.com.ar https://www.afip.gob.ar secure.trust-provider.com www.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolibre.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.googleapis.com *.gstatic.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io player.vimeo.com connect.facebook.net twitter.com platform.twitter.com static.addtoany.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.googleapis.com *.gstatic.com stats.addtoany.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com autocomplete2.postdirekt.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self';connect-src 'self' *.handels.se *.ace.teliacompany.net handels.humany.net *.google-analytics.com *.cookiebot.com dc.services.visualstudio.com *.clarity.ms *.bing.com *.google.com *.rekai.se *.azure.com;default-src 'self';font-src 'self' www.handels.se handels.humany.net;form-action 'self' *.veranet.se *.grandid.com;frame-src 'self' app.kollektivavtalskollen.se player.vimeo.com wds.ace.teliacompany.com *.cookiebot.com *.doubleclick.net *.handels.se;img-src 'self' data: *.handels.se handels.humany.net humany.blob.core.windows.net *.cookiebot.com www.googletagmanager.com *.bing.com *.clarity.ms *.google.se *.google.com *.doubleclick.net;media-src 'self' data:;object-src 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' app.kollektivavtalskollen.se wds.ace.teliacompany.com handels.humany.net www.googletagmanager.com js.monitor.azure.com *.cookiebot.com dc.services.visualstudio.com www.google-analytics.com *.bing.com *.clarity.ms code.jquery.com *.rekai.se *.doubleclick.net;style-src 'self' 'unsafe-inline' 'unsafe-eval' handels.humany.net wds.ace.teliacompany.com;upgrade-insecure-requests; 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: *.fonts.googleapis.com https://fonts.google.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: consentcdn.cookiebot.com consentcdn.cookiebot.eu *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.wesupply.xyz td.doubleclick.net *.yotpo.com https://www.chatbase.co 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.magezon.com *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.google.com.ua *.google.com.kh *.google.me *.doubleclick.net *.linkedin.com *.cookiebot.com https://img.sct.eu1.usercentrics.eu https://www.googletagmanager.com *.gstatic.com *.facebook.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com consent.cookiebot.com consent.cookiebot.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com *.googleapis.com *.google.com *.gstatic.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudflare.com googleads.g.doubleclick.net snap.licdn.com script.hotjar.com static.hotjar.com *.newrelic.com https://consentcdn.cookiebot.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net unpkg.com https://pa.7w.ro http://pa.7w.ro *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.addtoany.com unsafe-inline tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google-analytics.com stats.g.doubleclick.net px.ads.linkedin.com wss://ws.hotjar.com *.hotjar.io https://bam.eu01.nr-data.net googleads.g.doubleclick.net analytics.google.com *.facebook.net https://pa.7w.ro http://pa.7w.ro *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reachout.global pos-kowzef.reachout.global 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.addtoany.com/ *.doubleclick.net/ *.addthis.com *.doubleclick.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.adobedtm.com *.afip.gob.ar *.cloudfront.net https://player.vimeo.com *.clarity.ms *.google.com.co *.bing.com *.kosiuko.com *.facebook.com *.metricool.com *.google.com.ar *.google.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.addtoany.com *.cloudfront.net *.doubleclick.net *.vimeo.com https://f.vimeocdn.com https://player.vimeo.com *.clarity.ms *.tiktok.com *.aptrinsic.com *.facebook.net *.facebook.com *.googleapis.com *.googletagmanager.com track-icommkt.com *.icommarketing.com *.reachout.global *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.vimeo.com https://vimeo.com *.vimeocdn.com https://f.vimeocdn.com *.clarity.ms *.google.com *.tiktok.com *.facebook.net *.facebook.com *.googletagmanager.com track-icommkt.com *.notifications-icommkt.com https://notifications-icommkt.com pos-kowzef.reachout.global *.reachout.global *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.aptrinsic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com accounts.google.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com accounts.google.com https://maps.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com accounts.google.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com services.paytrail.com v1.api.paymenthighway.io maksu.pivo.fi kultaraha.op.fi epmt.nordea.fi verkkopankki.danskebank.fi verkkomaksu.poppankki.fi auth.aktia.fi verkkomaksu.saastopankki.fi verkkomaksu.omasp.fi online.s-pankki.fi online.alandsbanken.fi pay.paytrail.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ www.google.com www.facebook.com js.playground.klarna.com *.klarna.com policy.app.cookieinformation.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.facebook.com www.google.fi pagead2.googlesyndication.com cdn2.hubspot.net static.paytrail.com resources.paytrail.com x.klarnacdn.net www.resursbank.fi ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.cdninstagram.com https://*.fbcdn.net https://scontent-fra3-1.cdninstagram.com https://*.scontent.cdninstagram.com *.klarna.com *.klarnaevt.com *.klarnacdn.net 'self' data: www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ graph.instagram.com static.zdassets.com widget-mediator.zopim.com connect.facebook.net x.klarnacdn.net chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.cdninstagram.com *.klarna.com *.klarnacdn.net *.klarnaservices.com policy.app.cookieinformation.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.klarnacdn.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ static.zdassets.com https://*.cdninstagram.com https://*.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com hevari.zendesk.com wss://widget-mediator.zopim.com zendesk-eu.my.sentry.io www.facebook.com region1.analytics.google.com www.google.fi pagead2.googlesyndication.com eu.playground.klarnaevt.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com policy.app.cookieinformation.com consent.app.cookieinformation.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.kxcdn.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.facebook.com www.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net *.google.pl *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io connect.facebook.net www.googletagmanager.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com secure.przelewy24.pl google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.google-analytics.com stats.g.doubleclick.net www.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.google.com *.instagram.com *.google-analytics.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com ekr.zdassets.com/ https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 prefetch-src 'self' https://chat.justschool.me; script-src 'self' 'unsafe-eval' 'unsafe-inline' ; style-src 'self' 'unsafe-inline' ; connect-src https://*.creatio.com http://*.creatio.com ws://justschool-creatio.com.ua https://*.bpmonline.com wss://*.bpmonline.com:* wss://justschool-creatio.com.ua http://*.bpmonline.com 'self' https://*.facebook.com https://nominatim.openstreetmap.org https://www.googletagmanager.com https://www.facebook.com https://*.google-analytics.com ; font-src https://fonts.gstatic.com data: 'self' ; manifest-src 'self' ; worker-src 'self' blob: ; frame-src http://*.bpmonline.com 'self' http://*.creatio.com https://*.creatio.com https://*.bpmonline.com https://*.facebook.com https://www.facebook.com chat.justschool.me https://chat.justschool.me; frame-ancestors 'self' ; media-src 'self' ; object-src 'none' ; script-src-elem https://nominatim.openstreetmap.org https://connect.facebook.net https://*.google-analytics.com https://www.googletagmanager.com 'self' 'unsafe-inline' ; style-src-elem https://fonts.googleapis.com 'unsafe-inline' 'self' ; form-action 'self' ; style-src-attr 'self' 'unsafe-inline' ; script-src-attr 'unsafe-inline' 'self' ; img-src * data: ; report-uri https://justschool-creatio.com.ua/0/ServiceModel/CspViolationService.svc/SaveCspViolationData; 1 font-src cash-f.squarecdn.com fonts.googleapis.com fonts.gstatic.com zenloop-assets.s3.eu-west-1.amazonaws.com assets.zenloop.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com www.zenaps.com *.fls.doubleclick.net amc.demdex.net *.hotjar.com *.facebook.com *.trustpilot.com *.criteo.com *.criteo.net *.cleverpush.com *.justspices.de *.justspices.es *.justspices.co.uk *.sovendus.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com maps.gstatic.com *.googletagmanager.com *.trustedshops.com *.facebook.com *.justspices.de *.justspices.es *.justspices.co.uk *.justspices.com *.criteo.com a.twiago.com ad.360yield.com ad.sxp.smartclip.net ad.yieldlab.net ads.stickyadstv.com cdn.stickyadstv.com cm.adform.net contextual.media.net criteo-partners.tremorhub.com criteo-sync.teads.tv exchange.mediavine.com i.liadm.com ih.adscale.de cotads.adscale.de match.sharethrough.com matching.ivitrack.com pixel.rubiconproject.com public-prod-dspcookiematching.dmxleo.com s.ad.smaato.net secure.adnxs.com ib.adnxs.com visitor.omnitagjs.com x.bidswitch.net *.analytics.yahoo.com ads.yahoo.com *.doubleclick.net eb2.3lift.com r.casalemedia.com rtb-csync.smartadserver.com simage2.pubmatic.com sync.outbrain.com *.bing.com *.clarity.ms i.geistm.com *.taboola.com *.google.com *.google.de d3k81ch9hvuctc.cloudfront.net www.awin1.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com www.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com s7.addthis.com *.google.com cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.hotjar.com *.trustedshops.com *.facebook.net *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.criteo.net *.criteo.com *.datatables.net *.shopgate.com *.bing.com cdn.cookielaw.org *.onetrust.com *.pinterest.com s.pinimg.com analytics.tiktok.com *.clarity.ms static.cleverpush.com *.taboola.com www.dwin1.com ssl.geoplugin.net sleeknotecustomerscripts.sleeknote.com static.spott.ai *.sovendus.com the.sciencebehindecommerce.com zenloop-website-overlay-production.s3.amazonaws.com website-overlay.zenloop.com *.fullstory.com *.justspices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.googleapis.com *.trustpilot.com cdn.jsdelivr.net *.klaviyo.com *.adyen.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.facebook.com *.justspices.de *.justspices.es *.justspices.co.uk *.justspices.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com ekr.zdassets.com/ maps.googleapis.com maps.gstatic.com *.hotjar.com *.hotjar.io *.zendesk.com *.clarity.ms bat.bing.com cdn.cookielaw.org *.noibu.com wss://input.noibu.com justspices-privacy.my.onetrust.com *.onetrust.com *.criteo.com stats.g.doubleclick.net *.taboola.com *.facebook.com static-forms.klaviyo.com *.cleverpush.com *.sovendus.com *.trustpilot.com *.trustedshops.com *.zenloop.com zenloop-website-overlay-production.s3.amazonaws.com *.sciencebehindecommerce.com trustbadge.api.etrusted.com *.fullstory.com *.justspices.de *.google-analytics.com *.pinterest.com analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.onetrust.com https://s.yimg.jp *.smart-bdash.com *.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com *.googleadservices.com *.google.com https://googleads.g.doubleclick.net *.twitter.com *.facebook.net *.paygent.co.jp; style-src 'self' 'unsafe-inline' https://googletagmanager.com https://tagmanager.google.com *.googleapis.com; img-src 'self' *.onetrust.com https://googletagmanager.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.google.com https://google.com https://googleads.g.doubleclick.net *.facebook.com data:; font-src 'self' *.gstatic.com data:; connect-src 'self' *.onetrust.com *.smart-bdash.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.facebook.com *.paygent.co.jp *.google.com; frame-src 'self' *.twitter.com *.googletagmanager.com; frame-ancestors 'self'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' karcher-center-altex.com.br *.karcher-center-altex.com.br wake-components.fbitsstatic.net karchercenteraltex.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com doubleclick.net addthis.com hertzen.com cartstack.com moatads.com alphassl.com googleadservices.com online-metrix.net cloudflare.com cartstack.com.br ebit.com.br traycheckout.com.br *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.alphassl.com *.googleadservices.com *.online-metrix.net *.cloudflare.com *.addthis.com *.hertzen.com *.doubleclick.net *.cartstack.com *.moatads.com *.cartstack.com.br *.ebit.com.br *.traycheckout.com.br wss://signalr.fbits.net *.yapay.com.br *.clearsale.com.br k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.conectiva.io *.sunset.systems app.cartstack.com.br *.performa.ai *.cupom.social *.conectiva.app conectiva.io *.hotjar.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com samuraiexpertsstorage.blob.core.windows.net boletoflex.azurewebsites.net boletoflex.com *.boletoflex.com *.azurewebsites.net *.blob.core.windows.net signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store google.com.br *.google.com.br translate.googleapis.com *.googleapis.com *.google.com google.com *.adyen.com google.com.co *.com.co google.es *.google.es *.googletagmanager.com googletagmanager.com google.fr *.google.fr *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com plugins.crmback.io sdk.crmback.io crmback.io crmback.com cbstatus.net *.wake.tech *.appmax.com.br *.tunagateway.com webapp-middleware-wake-hero-seguros.azurewebsites.net static.cloudflareinsights.com *.cloudflareinsights.com clarity.ms *.clarity.ms youtube.com *.youtube.com onsite.crmback.io *.crmback.io x.cbstatus.net *.cbstatus.net ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.karcher-center-altex.com.br karcher-center-altex.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://geowidget.easypack24.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ https://sandbox-easy-geowidget-sdk.easypack24.net/ consentcdn.cookiebot.com consentcdn.cookiebot.eu *.doubleclick.net secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://images.unsplash.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org www.facebook.com connect.facebook.net img.sct.eu1.usercentrics.eu imgsct.cookiebot.com *.clarity.ms *.bing.com www.google.pl static.payu.com *.hsforms.net *.hsforms.com 'self' data: https://media.azan-cdn.pl/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org consent.cookiebot.com consent.cookiebot.eu consentcdn.cookiebot.com consentcdn.cookiebot.eu connect.facebook.net www.clarity.ms www.google.pl www.google.com google.com analytics.tiktok.com secure.payu.com secure.snd.payu.com https://www.datadoghq-browser-agent.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://fonts.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://maps.googleapis.com https://player.vimeo.com *.easypack24.net *.inpost.pl *.openstreetmap.org region1.google-analytics.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.clarity.ms www.facebook.com www.google.pl www.google.com google.com stats.g.doubleclick.net analytics.tiktok.com analytics-ie.tiktokw.eu analytics-ttp2.tiktokw.eu analytics-ipv6.tiktokw.us secure.payu.com merch-prod.snd.payu.com https://browser-intake-datadoghq.eu t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline' https: fonts.googleapis.com cdn.jsdelivr.net; font-src 'self' data: https: fonts.gstatic.com cdn.jsdelivr.net; script-src 'self' 'unsafe-inline' https:; connect-src 'self' https:; frame-ancestors 'self'; frame-src 'self' https:; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.google-analytics.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://superkoch.com.br https://mcstaging.superkoch.com.br *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com https://superkoch.com.br https://mcstaging.superkoch.com.br 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com https://superkoch.com.br https://mcstaging.superkoch.com.br https://targeting.voxus.tv/ *.paypal.com *.klarna.com *.trustedshops.com *.usercentrics.eu https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy https://www.googletagmanager.com/ *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net data: https://h.online-metrix.net *.d.aa.online-metrix.net https://superkoch.com.br http://mcstaging.superkoch.com.br https://www.superkoch.com.br/media/wysiwyg/logo-hibrido.svg *.cloudflare.com *.gstatic.com *.google.com *.google.com.br *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.paypalobjects.com *.googletagmanager.com *.bootstrapcdn.com *.mundipagg.com *.hotjar.com *.clearsale.com.br *.amazonaws.com https://standout.com.br https://www.standout.com.br https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com *.croapp.net https://bat.bing.com/bat.js https://cdn.targeting.voxus.com.br https://targeting.voxus.com.br https://superkoch.com.br https://mcstaging.superkoch.com.br *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.bootstrapcdn.com *.mundipagg.com *.hotjar.com *.clearsale.com.br *.mouseflow.com *.cartstack.com.br https://conectiva.io *.getbutton.io *.goadopt.io *.amazonaws.com *.smartlook.com https://standout.com.br https://www.standout.com.br https://targeting.voxus.tv https://api.ipify.org https://api.voxus.tv https://loggly.com http://secure.adnxs.com *.targeting.voxus.com.br *.targeting.voxus.tv *.api.ipify.org *.api.voxus.tv *.loggly.com *.secure.adnxs.com https://cdn.cs.1worldsync.com/jsc/h1ws.js https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://superkoch.com.br https://mcstaging.superkoch.com.br *.cloudflare.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.mundipagg.com maxcdn.bootstrapcdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.snplow.net commerce.adobedc.net *.adobe.io performance.typekit.net *.sentry.io https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://superkoch.com.br https://mcstaging.superkoch.com.br *.cloudflare.com https://www.paypal.com *.klarna.com https://pay.google.com *.trustedshops.com *.usercentrics.eu https://standout.com.br https://www.standout.com.br https://api.ipify.org https://api.voxus.tv https://loggly.com http://secure.adnxs.com *.targeting.voxus.com.br *.targeting.voxus.tv *.api.ipify.org *.api.voxus.tv *.loggly.com *.secure.adnxs.com https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com t.elasticsuite.io *.google-analytics.com https://viacep.com.br *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com https://ajax.cloudflare.com https://twitter.com https://fonts.gstatic.com https://use.typekit.net https://twimg.com https://widgets.trustedshops.com https://fonts.googleapis.com https://devkrauterie.b-cdn.net https://golivekrauterie.b-cdn.net/ https://golive.krauterie.de https://dev.krauterie.de https://www.krauterie.de wp.krauterie.de data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com https://twitter.com https://www.facebook.com/tr/ wp.krauterie.de 'self' 'unsafe-inline'; frame-ancestors wp.krauterie.de 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube-nocookie.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com https://plumrocket.com *.iubenda.com js.mollie.com https://twitter.com https://player.vimeo.com https://secure.pay1.de https://www.jsctool.com/ratepay/ ct.pinterest.com https://www.googletagmanager.com/ https://td.doubleclick.net/ wp.krauterie.de 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.iubenda.com magefan.com cm.magefan.com https://www.mollie.com https://ajax.cloudflare.com https://www.klarna.com https://googleadservices.com https://www.google.de/ads/ https://google-analytics.com https://www.paypal.com https://twitter.com https://pbs.twimg.com https://vimeocdn.com https://ytimg.com https://widgets.trustedshops.com https://lightemporium.com https://app.usercentrics.eu https://cdn.consentmanager.mgr.consensu.org https://consentmanager.mgr.consensu.org https://cdn.consentmanager.net https://delivery.consentmanager.net https://cloud.ccm19.de https://devkrauterie.b-cdn.net https://golivekrauterie.b-cdn.net/ https://golive.krauterie.de https://www.googletagmanager.com/ https://dev.krauterie.de https://www.krauterie.de https://www.google.de/pagead/ https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com wp.krauterie.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com connect.facebook.net twitter.com platform.twitter.com *.iubenda.com js.mollie.com https://ajax.cloudflare.com https://twitter.com https://pbs.twimg.com https://www.google-analytics.com https://fonts.gstatic.com https://www.gstatic.com https://widgets.trustedshops.com https://app.usercentrics.eu https://cdn.consentmanager.mgr.consensu.org https://consentmanager.mgr.consensu.org https://fontawesome.com https://secure.pay1.de https://d.ratepay.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://cloud.ccm19.de https://devkrauterie.b-cdn.net https://golivekrauterie.b-cdn.net/ https://golive.krauterie.de https://www.googletagmanager.com/ https://dev.krauterie.de https://www.krauterie.de https://s3.amazonaws.com/downloads.mailchimp.com/js/ https://s.pinimg.com/ https://ct.pinterest.com https://fast.smarketer.de https://fast-static.smarketer.de https://stats.g.doubleclick.net https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com wp.krauterie.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com https://ajax.cloudflare.com https://fonts.googleapis.com https://twitter.com https://fonts.gstatic.com https://use.typekit.net https://widgets.trustedshops.com https://app.usercentrics.eu https://cdn.consentmanager.mgr.consensu.org https://fontawesome.com https://cloud.ccm19.de https://devkrauterie.b-cdn.net https://golivekrauterie.b-cdn.net/ https://golive.krauterie.de https://www.googletagmanager.com/ https://dev.krauterie.de https://www.krauterie.de https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com wp.krauterie.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com wp.krauterie.de 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.iubenda.com https://ajax.cloudflare.com https://twitter.com https://paypal.com https://www.paypalobjects.com https://twimg.com https://d.ratepay.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://region1.analytics.google.com https://www.google.com/pagead/ https://www.google.de/pagead/ https://cloud.ccm19.de https://devkrauterie.b-cdn.net https://golivekrauterie.b-cdn.net/ https://golive.krauterie.de https://www.googletagmanager.com/ https://dev.krauterie.de https://www.krauterie.de https://region1.google-analytics.com https://ct.pinterest.com https://pagead2.googlesyndication.com/ https://www.google.com/ccm/ https://fast.smarketer.de https://fast-static.smarketer.de https://stats.g.doubleclick.net *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com wp.krauterie.de 'self' 'unsafe-inline'; child-src wp.krauterie.de http: https: blob: 'self' 'unsafe-inline'; default-src wp.krauterie.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.payu.co.za *.spitz.co.za 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.payu.co.za *.spitz.co.za 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.feedaty.com *.zopim.com data: static.criteo.net *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.feedaty.com *.criteo.com *.criteo.net *.hotjar.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://cdn.clerk.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.feedaty.com *.google.com *.google.it *.zopim.com *.clerk.io *.advertising.com *.doubleclick.net *.openx.net *.rubiconproject.com *.yahoo.com *.smaato.net *.yieldmo.com *.tapad.com *.addthis.com *.outbrain.com *.criteo.com *.criteo.net *.adnxs.com *.adtpd.com *.tpmn.co.kr *.socdm.com *.adingo.jp *.revcontent.com *.kargo.com *.3lift.com *.media.net *.rlcdn.com *.turn.com *.smartadserver.com *.mediawallahscript.com *.360yield.com *.pubmatic.com *.casalemedia.com *.taboola.com *.adform.net *.teads.tv *.bidswitch.net *.dable.io *.sharethrough.com *.liadm.com *.postrelease.com *.mgid.com *.nate.com *.yandex.ru *.rambler.ru *.meba.kr *.admixer.co.kr id5-sync.com *.mail.ru *.adscale.de *.aralego.com *.tremorhub.com *.omnitagjs.com trusted.ro *.kvstore.it *.googletagmanager.com *.hotjar.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://api.clerk.io https://cdn.clerk.io *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.feedaty.com *.zoorate.com *.iubenda.com *.soisy.it *.criteo.com static.criteo.net *.doubleclick.net *.hotjar.com *.zopim.com *.zdassets.com *.clerk.io partner-events.favicdn.net *.gstatic.com cdnjs.cloudflare.com *.avada.io *.shopify.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com cdnjs.cloudflare.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com tagmanager.google.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.criteo.net *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.feedaty.com *.soisy.it *.google-analytics.com *.hotjar.com *.hotjar.io/ *.zdassets.com *.zopim.com *.iubenda.com *.doubleclick.net *.criteo.com *.criteo.net wss://*.zopim.com/ wss://*.hotjar.com/ partner-events.favicdn.net partner-events.favi.sk partner-events.favi.cz partner-events.favi.ro *.googlesyndication.com *.zendesk.com cdnjs.cloudflare.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net http://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://consentcdn.cookiebot.com https://www.salesmanago.pl https://app3.salesmanago.pl https://www.salesmanago.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.google.com https://www.google.es https://widgets.sociablekit.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.doofinder.com https://eu1-search.doofinder.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.google.com https://widgets.sociablekit.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com http://fonts.googleapis.com https://widgets.sociablekit.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://eu1-search.doofinder.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.youtube.com https://youtu.be 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.weltpixel.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src scontent-hel3-1.cdninstagram.com/ instagram.com/ *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors unsafe-inline 'self'; connect-src www.google-analytics.com stats.g.doubleclick.net/j/ stats.g.doubleclick.net googleads.g.doubleclick.net/pagead/landing dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; img-src data: www.google.bg/pagead/ www.google.com/pagead/ www.facebook.com/tr/ maps.googleapis.com www.google.bg/ads/ga-audiences www.google.com/ads/ga-audiences wheelioapp.azureedge.net dealioappstorage.blob.core.windows.net static.klaviyo.com d3k81ch9hvuctc.cloudfront.net/ scontent-hel3-1.cdninstagram.com/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; style-src maxcdn.bootstrapcdn.com fonts.googleapis.com wheelioapp.azureedge.net static-tracking.klaviyo.com *.adobe.com https://static.klaviyo.com *.fontawesome.com *.gstatic.com unsafe-inline assets.braintreegateway.com *.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; font-src maxcdn.bootstrapcdn.com fonts.gstatic.com googleapis.com *.fontawesome.com static.klaviyo.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; script-src connect.facebook.com connect.facebook.net facebook.com googleads.g.doubleclick.net www.google-analytics.com www.google.com/pagead/ www.google.bg/pagead/ www.facebook.com/tr/ maps.googleapis.com ajax.cloudflare.com/cdn-cgi/scripts/ ssets.adobedtm.com secure.authorize.net test.authorize.net js.braintreegateway.com static.klaviyo.com static.klaviyo.com/ cdnjs.cloudflare.com/ dashboard.wheelio-app.com/api/wheelioapp/ www.wheelioapp.azureedge.net/app/ www.wheeliofuncstats.azurewebsites.net/api/ www.wheeliofuncstats.azurewebsites.net www.wheeliofuncstats.azurewebsites.net/ wheelioapp.azureedge.net/app/ wheeliofuncstats.azurewebsites.net/api/ scontent-hel3-1.cdninstagram.com/ https://widget-cdn.boxnow.bg/map-widget/client/v4.js https://static.cloudflareinsights.com assets.adobedtm.com *.adobe.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.instagram.com www.apptrian.com www.facebook.com graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.gstatic.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com *.fontawesome.com use.typekit.net github.com *.avis-verifies.com *.skeepers.io https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.wlp-acs.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com * 'self' 'unsafe-inline'; frame-ancestors *.skeepers.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.adyen.com critizr.com asset.easydmp.net creativecdn.com *.doubleclick.net *.wlp-acs.com *.hotjar.com/ *.avis-verifies.com *.skeepers.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.adyenpayments.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com *.bird.eu *.openstreetmap.org axeptio.imgix.net www.facebook.com google.fr *.google.fr *.bing.com *.adnxs.com cl.avis-verifies.com *.metaffiliation.com *.leroidumatelas.fr *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.adyenpayments.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net *.almapay.com *.adyen.com https://cdn.polyfill.io https://browser.sentry-cdn.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.avis-verifies.com static.critizr.com *.axept.io *.bing.com asset.easydmp.net analytics.tiktok.com trk.lgw.io connect.facebook.net *.hotjar.com *.lm-tracking.com *.metaffiliation.com *.leroidumatelas.fr *.googletagmanager.com *.avada.io *.skeepers.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.de-matrassenkoning.be *.leroidumatelas.be *.msecnd.net *.adyenpayments.com unpkg.com *.matomo.cloud *.perfmaker.net *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net *.almapay.com fonts.googleapis.com static.critizr.com *.fontawesome.com *.adyen.com *.metaffiliation.com *.leroidumatelas.fr *.googletagmanager.com *.avis-verifies.com *.skeepers.io https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.adyenpayments.com *.perfmaker.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com *.openstreetmap.org *.adyen.com https://*.ingest.sentry.io https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.axept.io *.analytics.google.com analytics.tiktok.com *.google.fr *.doubleclick.net *.metaffiliation.com *.leroidumatelas.fr *.googletagmanager.com https://get.geojs.io *.avada.io *.avis-verifies.com awsapis3.netreviews.eu *.skeepers.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.de-matrassenkoning.be *.leroidumatelas.be *.msecnd.net *.adyenpayments.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://challenges.cloudflare.com https://www.google-analytics.com https://resources.digital-cloud-west.medallia.com https://api.ocularsolution.com https://content.hotjar.io https://analytics-fe.digital-cloud-west.medallia.com https://www.bci.cl https://cdnjs.cloudflare.com https://widget.ocularsolution.com https://cdn3.bci.cl 1 default-src 'self'; script-src 'self' https://cdn.jsdelivr.net https://www.googletagmanager.com 'unsafe-inline'; style-src 'self' https://cdn.jsdelivr.net https://use.fontawesome.com 'unsafe-inline'; img-src 'self' data: blob: https://www.googletagmanager.com https://www.google-analytics.com; font-src 'self' https://use.fontawesome.com data:; connect-src 'self' https://www.google-analytics.com; frame-src https://www.googletagmanager.com; 1 default-src 'self'; font-src https://themes.googleusercontent.com/ 'self'; frame-src https://s-static.ak.facebook.com http://static.ak.facebook.com https://www.facebook.com; img-src *; object-src 'none'; script-src http://browser-update.org/ https://www.google.com/ https://www.gstatic.com/recaptcha/ http://www.google.com/recaptcha/ 'unsafe-inline' 'unsafe-eval' 'self'; style-src https://www.google.com/ https://ajax.googleapis.com/ 'unsafe-inline' 'self'; report-uri /nelmio/csp/report 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' loja99oculos.com.br *.loja99oculos.com.br wake-components.fbitsstatic.net loja99oculos.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net *.mlstatic.com k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.mercadopago.com *.mercadopago.com.br *.paypal.com *.paypal.com.br *.paypalobjects.com secure.mlstatic.com *.loja99oculos.com.br *.opolen.com.br *.targeting.voxus.com.br *.getblue.io *.voxus.com.br recursos.loja99oculos.com.br *.voxus.tv api.voxus.tv *.loggly.com *.ipify.org api.ipify.org logs-01.loggly.com *.clearsale.com.br cdn.targeting.voxus.com.br targeting.voxus.com.br *.polen.com.br api.polen.com.br static.opolen.com.br *.edrone.me *.cloudfront.net s.pinimg.com *.hotjar.com static.hotjar.com dynamic.criteo.com dzpxyxks1bfmb.cloudfront.net *.criteo.net *.criteo.com *.pinterest.com *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.pagaleve.com.br wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.konfidency.com.br *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.loja99oculos.com.br loja99oculos.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojaprolab.com.br *.lojaprolab.com.br wake-components.fbitsstatic.net prolab.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.googleadservices.com *.g.doubleclick.net dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com sendermail.lojaprolab.com.br *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojaprolab.com.br lojaprolab.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojastemperare.com.br *.lojastemperare.com.br wake-components.fbitsstatic.net lojastemperare.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.enviou.com.br *.smarthint.co *.clearsale.com.br *.mlstatic.com *.mercadopago.com api.mercadopago.com *.paypalobjects.com paypalobjects.com *.paypal.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojastemperare.com.br lojastemperare.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.iris.dias.com.gr *.test-iris.dias.com.gr *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: https://www.googletagmanager.com/ *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.google-analytics.com *.googleadservices.com *.cookiebot.com mcusercontent.com *.lightemporium.com *.usercentrics.eu *.cloudflare.com *.twitter.com *.klarna.com *.ytimg.com *.twimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.instagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googletagmanager.com tagmanager.google.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cookiebot.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com *.googletagmanager.com tagmanager.google.com *.mailchimp.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.google-analytics.com *.googlesyndication.com *.cookiebot.com *.cloudflare.com *.twitter.com *.twimg.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.nosto.com *.nos.to *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com https://sandbox.sequracdn.com https://live.sequracdn.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.shopalike.es *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com https://sandbox.sequracdn.com https://live.sequracdn.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.shopalike.es www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.doofinder.com *.empathybroker.com *.unpkg.com *.empathy.co *.storyblok.com https://sandbox.sequracdn.com https://live.sequracdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://static.klaviyo.com *.nosto.com *.nos.to *.photoslurp.com *.doofinder.com *.klaviyo.com *.typekit.net *.empathy.co *.empathybroker.com *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co https://sandbox.sequracdn.com https://live.sequracdn.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://sis.redsys.es/ pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com *.kueskipay.com data: http://img-longchamp.grupoultra.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.kueskipay.com data: https://www.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com *.kueskipay.com data: https://players.brightcove.net https://bid.g.doubleclick.net https://insight.adsrvr.org https://static.rolex.com https://td.doubleclick.net plausible.io *.wesupply.xyz https://wesupplylabs.com www.youtube.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.kueskipay.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.kreiconceptstore.com https://www.facebook.com https://www.paypal.com https://www.sandbox.paypal.com https://www.google.com https://www.google.com.mx https://googleads.g.doubleclick.net https://img-longchamp.grupoultra.com https://bat.bing.com https://www.kreiconceptstore.com https://insight.adsrvr.org https://www.tiktok.com https://ultrafemme.com https://us4-files.zohopublic.com https://smetrics.rolex.com https://maps.googleapis.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png www.google.com.ua *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ data: https://a.klaviyo.com https://www.facebook.com https://www.paypal.com https://www.sandbox.paypal.com https://static-tracking.klaviyo.com https://script.crazyegg.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://bam.nr-data.net https://bat.bing.com http://bat.bing.com https://j01l4h3n.com https://secure.adnxs.com https://5mcl.fr http://5mcl.fr http://secure.adnxs.com https://js-cdn.dynatrace.com https://js.adsrvr.org https://www.clarity.ms https://assets.adobedtm.com https://maps.googleapis.com *.avada.io *.shopify.com plausible.io *.cloudflare.com www.youtube.com ajax.googleapis.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ assets.braintreegateway.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com https://static.klaviyo.com data: *.fontawesome.com https://fonts.bunny.net *.tagmanager.google.com *.typeform.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: https://img.kreiconceptstore.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com * *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.kueskipay.com *.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ data: https://a.klaviyo.com https://www.paypalobjects.com https://www.google-analytics.com https://www.sandbox.paypal.com https://www.facebook.com https://stats.g.doubleclick.net https://script.crazyegg.com https://pagestates-tracking.crazyegg.com https://assets-tracking.crazyegg.com https://tracking.crazyegg.com https://bam.nr-data.net https://analytics.google.com https://j.clarity.ms https://bf52126kbt.bf.dynatrace.com https://salesiq.zohopublic.com wss://vts.zohopublic.com https://z.clarity.ms https://maps.googleapis.com https://get.geojs.io *.avada.io plausible.io cdn.plyr.io noembed.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.run.app *.typeform.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:;img-src 'self' https:;style-src 'unsafe-inline' https:;script-src 'unsafe-inline' 'unsafe-eval' http:;media-src *;frame-ancestors 'self' https:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://api.systempay.fr/static/ maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ *.typeform.com api.systempay.fr sso.sbx.edenred.io/ sso.eu.edenred.io/ *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ https://www.lf.fr api.systempay.fr www.google.fr *.googleapis.com maps.gstatic.com *.ggpht.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.typeform.com api.systempay.fr *.googleapis.com *.ggpht.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://api.systempay.fr/static/ maxcdn.bootstrapcdn.com api.systempay.fr *.googleapis.com *.ggpht.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ maps.googleapis.com stats.g.doubleclick.net *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com www.apptrian.com facebook.com *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; style-src https://www.googletagmanager.com/ *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com t.themarketer.com cdn1.themarketer.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; default-src https://www.epay.bg https://online.epay.bg *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; media-src https://static.zdassets.com/web_widget/classic/latest/fda6cd35495c75f83508d9d2e77ee33d.mp3 *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; img-src https://www.google.bg/ https://cdn1.mktr2.com/ https://chart.googleapis.com/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com *.tbicp.com t.themarketer.com cdn1.themarketer.com 'self' data: https://cdn.tbibank.support *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; connect-src https://ekr.zdassets.com/ https://dimitarstoichkov.zendesk.com/ wss://widget-mediator.zopim.com/ https://googleads.g.doubleclick.net/ https://c2api.themarketer.com/ https://stats.g.doubleclick.net/ https://www.google.bg/ https://chart.googleapis.com/ dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com facebook.com https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com t.elasticsuite.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://beta.tbibank.support *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; script-src https://v2.zopim.com/ https://static.zdassets.com/ https://www.epay.bg https://online.epay.bg assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com *.tbicp.com *.avada.io t.themarketer.com cdn1.themarketer.com *.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self'; script-src 'self' 'nonce-e92480419c0d1b1803ec66c70eb532188600823bd8bc56eebaa3254548b55761' 'strict-dynamic' 'report-sample' 'sha256-uDlt9ZdSbqVygheSRezUUp1M3TutA6TKZ7TpveFjaw0='; frame-src 'self' *.google.com https://www.youtube.com/ https://www.facebook.com/ https://weatherwidget.io/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com https://*.fontawesome.com https://cdn.ckeditor.com; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com https://*.fontawesome.com https://use.typekit.net https://vlibras.gov.br https://cdn.jsdelivr.net; connect-src 'self' data: blob: https://www.google-analytics.com https://*.googleapis.com *.google.com https://*.gstatic.com https://*.fontawesome.com https://cke4.ckeditor.com https://api.iconify.design https://yoast.com https://api.unisvg.com https://acessos.vlibras.gov.br https://dicionario2.vlibras.gov.br https://vlibras.gov.br https://cdn.jsdelivr.net https://traducao2.vlibras.gov.br; img-src 'self' data: https://vlibras.gov.br https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.tile.osm.org https://cdn.ckeditor.com https://secure.gravatar.com https://api.iconify.design https://api.simplesvg.com https://api.unisvg.com; object-src 'none'; base-uri 'self'; worker-src blob:; frame-ancestors 'none'; report-to default; report-uri /_csp; 1 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://firebasestorage.googleapis.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google.com *.gstatic.com *.avada.io connect.facebook.net twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-babbb5aa0ec240c9ab677b235d30338e' https://MeinLUKS.ch 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://MeinLUKS.ch 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action 'self';media-src https://* 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.doubleclick.net *.facebook.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * customer-jo4fg3675hw5zuyf.cloudflarestream.com gum.criteo.com fledge.eu.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedaty.com cdn.flbx.io *.cloudfront.net *.iubenda.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com customer-jo4fg3675hw5zuyf.cloudflarestream.com www.gstatic.com a.omappapi.com matching.ivitrack.com x.bidswitch.net sync-t1.taboola.com sync.outbrain.com zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it sync.1rx.io ib.adnxs.com rtb.csync.smartserver.com r.casalemedia.com gum.criteo.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com *.dmxleo.com *.smartadserver.com *.omnitagjs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedaty.com *.getflowbox.com *.iubenda.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com static.zdassets.com cdn.clerk.io customer-jo4fg3675hw5zuyf.cloudflarestream.com cdn.iubenda.com api.clerk.io cs.iubenda.com js-agent.newrelic.com embed.cloudflarestream.com www.google.com www.gstatic.com dynamic.criteo.com a.omappapi.com static.hotjar.com sslwidget.criteo.com script.hotjar.com ecomm.sella.it sandbox.gestpay.net pod-29.zendesk.com sgtm.jeannebaret.com sgtm.cmpsport.com mn.cmpsport.com mn.melby.it connect.facebook.net https://cdn.iubenda.com https://static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.feedaty.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com www.gstatic.com a.omappapi.com cdnjs.cloudflare.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.feedaty.com *.getflowbox.com *.iubenda.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com region1.google-analytics.com ekr.zdassets.com customer-jo4fg3675hw5zuyf.cloudflarestream.com api.openweathermap.org cmp.zendesk.com bam.nr-data.net idb.iubenda.com region1.analytics.google.com api.omappapi.com gum.criteo.com measurement-api.criteo.com wss://pod-29.zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it connect.facebook.net *.doubleclick.net mn.cmpsport.com mn.melby.it 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.nr-data.net *.criteo.net *.cloudflarestream.com *.cloudflare.com *.clerk.io *.cmpsport.com *.melby.it *.zdassets.com *.chimpstatic.com *.iubenda.com *.zendesk.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com *.gstatic.com 'self' data: *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com td.doubleclick.net *.fls.doubleclick.net apollo-public.loyal.ink 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' data: *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com *.fls.doubleclick.net ade.googlesyndication.com *.gstatic.com *.hotjar.com *.facebook.net *.google.cl c.clarity.ms c.bing.com www.google.com.ar tracker.metricool.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.google.com *.gstatic.com https://maps.googleapis.com *.googletagmanager.com *.tagmanager.google.com *.googleadservices.com *.google.com *.facebook.net *.clarity.ms tracker.metricool.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.fontawesome.com *.googletagmanager.com *.cookielaw.org *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.gstatic.com *.tagmanager.google.com *.hotjar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.google.com *.hotjar.com *.hotjar.io e.clarity.ms b.clarity.ms google.com l.clarity.ms 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://www.gstatic.com *.fontawesome.com https://www.google.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.google.com www.gstatic.com apis.google.com js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://*.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://www.mollie.com https://api.mapbox.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com usercentrics.eu *.usercentrics.eu google.de *.google.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.gstatic.com js.mollie.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net usercentrics.eu *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com autocomplete2.postdirekt.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app usercentrics.eu *.usercentrics.eu 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.google-analytics.com https://www.googletagmanager.com https://code.jquery.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://tags.tiqcdn.com http://tags.tiqcdn.com https://visitor-service.tealiumiq.com https://cdn.jsdelivr.net https://cdn.decibelinsight.net https://connect.facebook.net https://static.hotjar.com https://script.hotjar.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https://www.google.com https://www.google.com.ar https://googleads.g.doubleclick.net https://cm.everesttech.net https://www.googletagmanager.com https://everesttech.net https://dpm.demdex.net https://www.facebook.com; connect-src 'self' https://www.google.com https://www.googleadservices.com https://akamai.tiqcdn.com https://collect.tealiumiq.com https://dpm.demdex.net https://gsk.demdex.net https://cm.everesttech.net https://collection.decibelinsight.net https://www.facebook.com https://ws.hotjar.com https://content.hotjar.io wss://ws.hotjar.com; frame-src 'self' https://td.doubleclick.net https://www.googletagmanager.com https://gsk.demdex.net 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com tagmanager.google.com https://www.googletagmanager.com *.avada.io *.google.com/ *.freshworks.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com *.freshworks.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com https://get.geojs.io *.avada.io *.freshworks.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src 'self' epichttp:;script-src 'nonce-efb6d4cb5d7e43e1bf4c73bfde01d739' https://mijnolvg.nl 'self';img-src 'self' blob: https://www.mijnolvg.nl https://www.olvg.nl;style-src 'nonce-efb6d4cb5d7e43e1bf4c73bfde01d739' https://mijnolvg.nl 'self';worker-src 'self' blob:;child-src 'self' blob:;form-action 'self';media-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.googleadservices.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.cognitoforms.com maps.google.com js.mollie.com *.net *.facebook.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com *.onetrust.com *.brightcove.com *.net *.elfsight.com *.elfsightcdn.com *.googleapis.com *.ggpht.com https://images.unsplash.com https://www.mollie.com www.google.com.vn *.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com *.onetrust.com *.brightcove.com *.net *.elfsight.com *.elfsightcdn.com script.crazyegg.com *.googleapis.com *.googleadservices.com unpkg.com unsafe-inline unsafe-eval wasm-eval https://maps.googleapis.com js.mollie.com ajax.cloudflare.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.gstatic.com *.googleapis.com *.googleadservices.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com *.onetrust.com *.brightcove.com *.net *.elfsight.com *.elfsightcdn.com script.crazyegg.com *.googleapis.com *.googleadservices.com data: blob: https://maps.googleapis.com https://player.vimeo.com *.crazyegg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' mimeria.com.br *.mimeria.com.br wake-components.fbitsstatic.net mimeria.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.googleadservices.com *.g.doubleclick.net *.googleads.com *.google.com *.ebit.com.br *.googlesyndication.com *.clearsale.com.br stats.g.doubleclick.net imgs.ebit.com.br hits-banner-cloud-function.azurewebsites.net *.googleads.g.doubleclick.net *.tpc.googlesyndication.com signalrcore.fbits.net wss://signalrcore.fbits.net *.smarthint.co *.cloudfront.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com conectiva.io sunset.systems cartstack.com.br *.conectiva.io *.sunset.systems *.cartstack.com.br *app.cartstack.com *.performa.ai *.cupom.social *.conectiva.app app.conectiva.io vm.conectiva.io conectiva.app api.performa.ai valid.performa.ai app.cartstack.com.br api.cartstack.com.br api.sunset.systems cupom.social app.cupom.social cdn.performa.ai *.facebook.net connect.facebook.net facebook.com *.facebook.com google.com.br *.google.com.br *.doubleclick.net td.doubleclick.net translate.googleapis.com *.googleapis.com *.com.py google.com.py google.com google-analytics.com *.google-analytics.com accounts.google.com *.fbits.store *.adyen.com analytics.tiktok.com *.tiktok.com *.posclick.dinamize.com receiver.posclick.dinamize.com *.pagar.me *.mundipagg.com *.emkt.dinamize.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.stapecdn.com *.mimeria.com.br *.hotjar.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.trustvox.com.br trustvox.com.br *.lightwidget.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.crmbonus.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.mimeria.com.br mimeria.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.gstatic.com *.bootstrapcdn.com *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.facebook.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.pelecard.biz *.queue-it.net *.facebook.com *.facebook.net *.vimeo.com vimeo.com *.google.com *.weltpixel.com business.facebook.com *.wesupply.xyz https://wesupplylabs.com *.allyable.com *.glassix.com *.doubleclick.net *.youtube.com *.paypal.com *.yotpo.com *.xtento.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.magentocommerce.com *.entrust.net *.google.com *.google.com.vn *.doubleclick.net *.cloudfront.net *.googleapis.com *.gstatic.com data: *.facebook.com *.facebook.net *.mltp.co.il business.facebook.com *.xtento.com cdn.xtento.com *.allyable.com *.google.co.il *.googleadservices.com *.google-analytics.com https://www.google *.paypal.com *.paypalobjects.com *.ytimg.com *.adscale.com *.outbrain.com *.hotjar.com *.hotjar.io *.web-view.net *.google.com.sg 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com *.vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.adobedtm.com *.authorize.net *.entrust.net *.trackedweb.net *.gstatic.com www.google.com *.adyen.com *.queue-it.net *.googletagmanager.com *.googleapis.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.signifyd.com *.nowdialogue.com *.xtento.com *.facebook.com *.facebook.net *.nagich.co.il *.rawgit.com https://www.googletagmanager.com tagmanager.google.com business.facebook.com *.cloudflare.com www.xtento.com cdn.xtento.com *.fontawesome.com *.allyable.com *.google-analytics.com *.newrelic.com *.meshulam.co.il *.doubleclick.net *.weezmo.com *.glassix.com https://system.user-a.co.il https://meshulam.co.il *.google.com *.analytics.com *.youtube.com *.paypal.com *.paypalobjects.com *.web-view.net *.jquery.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.nowdialogue.com tagmanager.google.com *.bootstrapcdn.com *.fontawesome.com *.adscale.com *.web-view.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.entrust.net *.trackedweb.net *.google-analytics.com *.nowdialogue.com nowdialogue.com *.nagich.co.il *.doubleclick.net *.vimeo.com vimeo.com *.google.com https://www.google-analytics.com *.facebook.com business.facebook.com *.allyable.com *.glassix.com *.analytics.com *.facebook.net *.googleapis.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com *.zopim.io *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com cdn.dnky.co webchat.dotdigital.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.lt *.google.com *.google.co.in *.mastercard.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com https://maps.omnivasiunta.lt 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com *.google.lt r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com cdn.dnky.co webchat.dotdigital.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es www.google-analytics.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.google.com https://get.geojs.io *.avada.io https://geocode.arcgis.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com p01.mul-pay.jp pt01.mul-pay.jp *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.xtento.com https://www.googletagmanager.com/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com www.xtento.com cdn.xtento.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ p01.mul-pay.jp pt01.mul-pay.jp static.mul-pay.jp stg.static.mul-pay.jp www.xtento.com cdn.xtento.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=15379&v=v1.0&payload=LsqRCwGhVLNr-SHL__TULgYbG_wtaFqSHTX9bzX5GjfjV_45G-Srt5bDJNzKAJMxeU3-YFRjc3fuHEw5bWlk04fkovhTNpjWfDty4t8DHzMN8URr0ZWEDqU0R5DQHSl2EAdFp1AkrYVQI8uxCSnjj5tLQOvkv_LQ9idkk2hImlLNxW0MA0qwdovCl2jj-cvVdeNpcqbUvv6rKuXDghu61Q==; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' mpozenato.com.br *.mpozenato.com.br wake-components.fbitsstatic.net MPozenato.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com cloudflare.com doubleclick.net linximpulse.net crazyegg.com retargeter.com.br googleadservices.com mlstatic.com shopconvert.com.br hotjar.com hotjar.io smarthint.co ebit.com.br viptarget.com.br mercadopago.com shoptarget.com.br directtalk.com.br googleapis.com shopback.net montacasa.com.br *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.shopconvert.com.br *.hotjar.com *.hotjar.io *.smarthint.co *.googleadservices.com *.mlstatic.com *.crazyegg.com *.retargeter.com.br *.cloudflare.com *.doubleclick.net *.linximpulse.net *.mercadopago.com *.shoptarget.com.br *.ebit.com.br *.viptarget.com.br *.montacasa.com.br *.directtalk.com.br *.googleapis.com *.shopback.net wss://signalr.fbits.net gstatic.com k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net track.omguk.com *.omguk.com *.lomadee.com *.vendavalida.com.br *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net s.pinimg.com *.pinimg.com receiver.posclick.dinamize.com *.posclick.dinamize.com ct.pinterest.com *.pinterest.com d3u0jcwe5p7qrc.cloudfront.net d2rp1k1dldbai6.cloudfront.net cybba-bucket.s3.amazonaws.com storage.googleapis.com *.amazon-adsystem.com *.s3.amazonaws.com *.cybba.solutions *.rtb123.com *.cybba.us *.adnxs.com *.stackadapt.com *.adsrvr.org *.facebook.net *.enviou.com.br *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net koinprod.azurewebsites.net payments.koin.com.br koinhomolog.azurewebsites.net *.blob.core.windows.net *.g2afse.com rankmediabrasil.g2afse.com *.cloudfront.net samuraiexpertsstorage.blob.core.windows.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com cdn.preciso.net *.preciso.net *.avis-verifies.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br d3bo67muzbfgtl.cloudfront.net api.edrone.me paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.mpozenato.com.br mpozenato.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' msam.com.br *.msam.com.br wake-components.fbitsstatic.net msam.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gstatic.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.elfsightcdn.com *.service.elfsight.com *.elf.site service-reviews-ultimate.elfsight.com static.elfsight.com core.service.elfsight.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.msam.com.br msam.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 base-uri 'none'; default-src 'none'; object-src 'none'; script-src 'self' https://*.js.stripe.com https://js.stripe.com consent.cookiefirst.com https://*.googletagmanager.com https://static.hotjar.com https://script.hotjar.com 'nonce-XTlElcdz15LByI9hXWxbvQ=='; connect-src 'self' https://s3-eu-west-1.amazonaws.com/assets.my.tvha.co.uk/font.css consent.cookiefirst.com edge.cookiefirst.com api.cookiefirst.com www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://api.stripe.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; img-src 'self' data: https://*.stripe.com consent.cookiefirst.com www.googletagmanager.com https://*.google-analytics.com https://*.googletagmanager.com https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com; style-src 'self' consent.cookiefirst.com 'sha256-/TH2J4ADy16MMQkBGTgUHngbsfb+cbhg46NDE9IAUKw=' https://static.hotjar.com https://script.hotjar.com 'nonce-XTlElcdz15LByI9hXWxbvQ=='; font-src 'self' https://*.hotjar.com; frame-ancestors 'self'; frame-src 'self' https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com; form-action 'self'; report-uri https://appsignal-endpoint.net/logs?api_key=ls-22a1f705-5e15-439f-a9bc-a6a53a13198e&group=mtvh-online 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net *.disqus.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy *.mercadolibre.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com cdn.mundipagg.com api.pagar.me www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.croapp.net https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy *.mlstatic.com *.mercadopago.com 3ds2.pagar.me 3ds2-sdx.pagar.me js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.smarthint.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://token.tuna-demo.uy https://token.tunagateway.com https://engine.tunagateway.com/ https://sandbox.tuna-demo.uy *.mercadopago.com *.mercadolibre.com api.mundipagg.com api.pagar.me api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: youtube.com, google.com, s.ytimg.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data: i.ytimg.com; connect-src 'self' https: youtube.com, google.com; font-src 'self' https: data:; form-action 'self' https:; frame-ancestors 'self'; object-src 'none' youtube.com; frame-src 'self' https: hubspot.com; base-uri 'self'; block-all-mixed-content; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com fonts.googleapis.com *.hotjar.com *.fontawesome.com data: https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://dpd.com.pl http://pudofinder.dpd.com.pl cdn.dnky.co *.hotjar.com *.trustpilot.com https://amc.demex.net landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://secure.przelewy24.pl https://tpay.com https://secure.tpay.com https://dpd.com.pl https://pudofinder.dpd.com.pl *.google.nl *.google.pl *.googleapis.com *.linkedin.com *.trustedshops.com https://static.paynow.pl https://static.sandbox.paynow.pl *.credit-agricole.pl *.leaselink.pl https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com maps.gstatic.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://rep.leaselink.pl https://secure.przelewy24.pl https://tpay.com https://secure.tpay.com https://dpd.com.pl https://pudofinder.dpd.com.pl *.googleapis.com *.googleadservices.com *.hotjar.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.feedbackcompany.com https://region1.analytics.google.com *.trustpilot.com *.googleoptimize.com landofcoder.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com maps.googleapis.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://secure.przelewy24.pl https://secure.przelewy24.pl/skrypty/ecommerce_plugin.css.php https://tpay.com https://secure.tpay.com https://dpd.com.pl https://pudofinder.dpd.com.pl *.fontawesome.com *.mailchimp.com *.cloudflare.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://secure.przelewy24.pl https://tpay.com https://secure.tpay.com https://dpd.com.pl https://pudofinder.dpd.com.pl https://region1.analytics.google.com https://stats.g.doubleclick.net https://www.google.pl *.leaselink.pl landofcoder.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.ch https://www.myheritage.de 'unsafe-eval' 'nonce-7981f8ceb95a9ffc8535b5232cfba489' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.ch;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.gr https://www.myheritage.gr 'unsafe-eval' 'nonce-486278449f8d028ca686153d80934631' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.gr;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.sk https://www.myheritage.sk 'unsafe-eval' 'nonce-4dcdbc66e3949e763bd9384501598309' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.sk;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src storage.googleapis.com/rtux-rtux-data-integration-rti/ *.fontawesome.com *.gstatic.com fonts.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action test.saferpay.com www.saferpay.com saferpay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.bugherd.com *.prismic.io *.netmailer.ch *.google.com *.wufoo.com *.doubleclick.net *.googletagmanager.com *.weltpixel.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.prism.app-us1.com *.prismic.io *.gstatic.com *.magentocommerce.com *.bing.com *.google.rs *.google.ch *.trackjs.com *.profity.ch *.clarity.ms test.saferpay.com www.saferpay.com saferpay.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.googletagmanager.com *.doubleclick.net *.google.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com bx-cdn.com/static/bav2.min.js track.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/rti.min.js track.bx-cloud.com/static/rti.min.js bx-cdn.com/static/rti.min.js storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io *.google.com *.hs-scripts.com *.bugherd.com *.convertful.com *.facebook.net *.hs-analytics.com *.hscollectedforms.com *.headspixel.com *.hs-banner.com *.hotjar.com *.googleapis.com *.licdn.com *.googleadservices.com *.g.doubleclick.net *.newrelic.net *.trackjs.com *.cdn.prismic.io *.bing.com *.clarity.ms *.profity.ch *.wufoo.com test.saferpay.com www.saferpay.com saferpay.com *.googletagmanager.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.klaviyo.com unpkg.com *.doubleclick.net https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com *.googleapis.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src storage.googleapis.com/rtux-rtux-data-integration-rti/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com track.bx-cloud.com main.bx-cloud.com track-gw1.bx-cloud.com bx-cloud.com main.wi-platform-cloud.com r-st.bx-cloud.com track.bx-cloud.com/track/v2 storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io *.google.com *.clarity.ms *.bing.com *.trackjs.com test.saferpay.com www.saferpay.com saferpay.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.googleapis.com https://cdnjs.com https://cdn.jsdelivr.net https://cdn.datatables.net https://cdn.jsdelivr.net/npm/chart.js; style-src 'self' 'unsafe-inline' https://cdnjs.com https://cdn.datatables.net https://cdn.jsdelivr.net; img-src 'self' https: data: blob: data:image/svg+xml; font-src 'self' data: https://cdnjs.com https://cdn.jsdelivr.net; connect-src 'self' https:; media-src 'self' data: blob:; object-src 'none'; child-src 'self'; frame-ancestors 'self'; 1 script-src 'unsafe-inline';report-uri https://csp.withgoogle.com/csp/script-inclusions/6b8ce7c01e3dacd3d2c7a8cd322ff979 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.googletagmanager.com *.gstatic.com *.amasty.com www.clarity.ms scripts.clarity.ms cdn.brevo.com sibautomation.com s3.amazonaws.com static.cloudflareinsights.com *.wonderpush.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com s3.amazonaws.com; img-src 'self' data: https:; font-src 'self' fonts.gstatic.com data: res-1.cdn.office.net; connect-src 'self' *.google-analytics.com www.clarity.ms n.clarity.ms *.amasty.com api.reclameaqui.com.br analytics.google.com in-automate.brevo.com *.wonderpush.com measurements-api.wonderpush.com; object-src 'none'; worker-src 'self'; frame-src 'self' www.facebook.com *.wonderpush.com; manifest-src 'self' *.wonderpush.com; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.cloudfront.net https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.hsforms.net *.hsforms.com www.google.com *.gstatic.com maps.googleapis.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.cloudflare.com getfirebug.com *.yotpo.com *.typekit.net *.trustedshops.com *.usercentrics.eu data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.cloudflare.com *.paypal.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com fonts.gstatic.com *.kxcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://secure.asxgw.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.fbcdn.net blob: ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com maps.gstatic.com *.ggpht https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://asxgw.com https://asxgw.paymentsandbox.cloud https://secure.asxgw.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.googleapis.com *.google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com https://cdnjs.cloudflare.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.google.com *.kxcdn.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://asxgw.com https://asxgw.paymentsandbox.cloud https://www.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.google-analytics.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' *.googletagmanager.com *.paypal.com *.redsys.es https://sis-t.redsys.es:25443 sibautomation.com *.facebook.net *.ads-twitter.com *.twitter.com; font-src 'self' *.typekit.net data:; connect-src 'self' *.google-analytics.com analytics.google.com stats.g.doubleclick.net *.paypal.com in-automate.sendinblue.com *.facebook.com; img-src 'self' data: https: http:; style-src 'self' 'unsafe-inline' *.typekit.net; frame-src *.vimeo.com *.paypal.com sibautomation.com *.facebook.com vimeo.com 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' norterefrigeracao.com.br *.norterefrigeracao.com.br wake-components.fbitsstatic.net norterefrigeracao.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com gstatic.com *.pagar.me *.mundipagg.com *.getnet.com.br *.trustvox.com.br checkout.norterefrigeracao.com.br translate.googleapis.com h.online-metrix.net device.clearsale.com.br *.clearsale.com.br *.braintree-api.com *.braintreegateway.com *.benova.com.br *.pagseguro.com.br trustvox.com.br *.pagbank.com *.smarthint.co *.vindi.com.br googleadservices.com *.googleadservices.com googleads.g.doubleclick.net *.g.doubleclick.net google.com.br *.google.com.br *.google.com adservice.google.com *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net service.smarthint.co bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br *.sino3d.app sino3d.app norterefrigeracao.fbitsstatic.net *.fbitsstatic.net paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io wake-commerce-scripts.omni.chat static.hotjar.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.norterefrigeracao.com.br norterefrigeracao.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klaviyo.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com js.mollie.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com nostebarn-hyva-cdn.tinyelephant.no nostebarn-cdn.tinyelephant.no nostebarn.no *.tryggehandel.no *.cookiebot.com * *.bing.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com https://www.mollie.com *.hsforms.net *.hsforms.com https://nostebarn-hyva.tinyelephant.no data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com gtm.adt313.net *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.cookiebot.com *.tryggehandel.no *.bing.com *.hotjar.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com *.hsforms.net *.hsforms.com https://widget.postenlabs.no/ *.bat.bing.com https://bat.bing.com dpm.demdex.net *.dpm.demdex.net *.amcglobal.sc.omtrdc.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.typekit.net *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://widget.postenlabs.no/assets/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.cookiebot.com *.adtraction.fail *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com https://widget.postenlabs.no/ https://widget.bring.services/api/ *.bat.bing.com https://bat.bing.com/ *.dpm.demdex.net *.amcglobal.sc.omtrdc.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.sharethis.com www.xtento.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * *.sharethis.com https://cdn.clerk.io *.openstreetmap.org https://maps.googleapis.com *.cloudfront.net *.facebook.com www.google.it *.clarity.ms *.bing.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com www.google.com.ua data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com https://api.clerk.io https://cdn.clerk.io cdnjs.cloudflare.com *.clerk.io *.clarity.ms connect.facebook.net *.cloudfront.net *.bing.com www.xtento.com cdn.xtento.com *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com network.oliunid.fr https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.openstreetmap.org https://maps.googleapis.com stats.g.doubleclick.net *.clarity.ms *.facebook.com *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com network.oliunid.fr https: 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.youtube.com https://www.youtube-nocookie.com https://use.typekit.net 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://use.typekit.net; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com https://use.typekit.net data:; frame-src https://www.youtube.com https://www.youtube-nocookie.com https://www.google.com; connect-src 'self' https://use.typekit.net https://p.typekit.net; base-uri 'self'; form-action 'self' 1 report-uri https://sentry.jobijoba.net/api/41/security/?sentry_key=28ec7a7f2b9a43cdb02605d055d23542 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.fontawesome.com *.acsbapp.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.acsbapp.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com acsbapp.com *.acsbapp.com hotjar.com *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com acsbapp.com *.acsbapp.com hotjar.com *.hotjar.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://www.pantit.se https://pantit.se;script-src 'self' https://www.pantit.se https://pantit.se 'unsafe-eval' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com maxcdn.bootstrapcdn.com kit.fontawesome.com ajax.googleapis.com www.googletagmanager.com https://*.googletagmanager.com widget.trustpilot.com consent.cookiebot.com connect.facebook.net client.crisp.chat googleads.g.doubleclick.net www.googleadservices.com consentcdn.cookiebot.com https://*.fullstory.com client.britepaymentgroup.com https://client.britepaymentgroup.com;script-src-elem 'self' https://www.pantit.se https://pantit.se 'unsafe-eval' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com maxcdn.bootstrapcdn.com kit.fontawesome.com ajax.googleapis.com www.googletagmanager.com https://*.googletagmanager.com widget.trustpilot.com consent.cookiebot.com connect.facebook.net client.crisp.chat googleads.g.doubleclick.net www.googleadservices.com consentcdn.cookiebot.com https://*.fullstory.com client.britepaymentgroup.com https://client.britepaymentgroup.com;script-src-attr 'self' https://www.pantit.se https://pantit.se 'unsafe-inline';style-src 'self' https://www.pantit.se https://pantit.se 'unsafe-inline' fonts.googleapis.com maxcdn.bootstrapcdn.com ka-f.fontawesome.com client.crisp.chat *.gstatic.com;frame-src 'self' https://www.pantit.se https://pantit.se wss://client.relay.crisp.chat https://*.crisp.chat https://client.crisp.chat https://*.client.crisp.chat *.crisp.chat widget.trustpilot.com consentcdn.cookiebot.com www.googletagmanager.com v1.checkout.bambora.com checkout.test.trustly.com checkout.trustly.com http://localhost:4200 td.doubleclick.net www.facebook.com production.britepaymentgroup.com https://production.britepaymentgroup.com;media-src wss://client.relay.crisp.chat https://*.crisp.chat https://client.crisp.chat https://*.client.crisp.chat *.crisp.chat;font-src 'self' https://www.pantit.se https://pantit.se data: fonts.gstatic.com http://fonts.gstatic.com maxcdn.bootstrapcdn.com ka-f.fontawesome.com client.crisp.chat;img-src 'self' https://www.pantit.se https://pantit.se https://*.google.se https://google.se https://www.google.se *.google.se https://*.google.de https://google.de https://www.google.de *.google.de https://*.google.com https://google.com https://www.google.com *.google.com https://*.google.co.uk https://google.co.uk https://www.google.co.uk *.google.co.uk https://*.google.com.tr https://google.com.tr https://www.google.com.tr *.google.com.tr https://*.google.com.pk https://google.com.pk https://www.google.com.pk *.google.com.pk https://*.google.com.ua https://google.com.ua https://www.google.com.ua *.google.com.ua https://*.google.com.cy https://google.com.cy https://www.google.com.cy *.google.com.cy https://*.google.ch https://google.ch https://www.google.ch *.google.ch https://*.google.dk https://google.dk https://www.google.dk *.google.dk https://*.google.nl https://google.nl https://www.google.nl *.google.nl https://*.google.fr https://google.fr https://www.google.fr *.google.fr https://*.google.ie https://google.ie https://www.google.ie *.google.ie https://*.google.no https://google.no https://www.google.no *.google.no https://*.google.es https://google.es https://www.google.es *.google.es https://*.google.fi https://google.fi https://www.google.fi *.google.fi https://*.google.ge https://google.ge https://www.google.ge *.google.ge https://*.google.rs https://google.rs https://www.google.rs *.google.rs https://*.google.pt https://google.pt https://www.google.pt *.google.pt https://*.google.at https://google.at https://www.google.at *.google.at https://*.google.be https://google.be https://www.google.be *.google.be https://*.google.it https://google.it https://www.google.it *.google.it https://*.google.pl https://google.pl https://www.google.pl *.google.pl https://*.google.ru https://google.ru https://www.google.ru *.google.ru https://*.google.co.jp https://google.co.jp https://www.google.co.jp *.google.co.jp https://*.google.gr https://google.gr https://www.google.gr *.google.gr https://*.google.com.br https://google.com.br https://www.google.com.br *.google.com.br https://*.google.ca https://google.ca https://www.google.ca *.google.ca https://*.google.si https://google.si https://www.google.si *.google.si https://*.google.sk https://google.sk https://www.google.sk *.google.sk https://*.google.ro https://google.ro https://www.google.ro *.google.ro https://*.google.mt https://google.mt https://www.google.mt *.google.mt https://*.google.lu https://google.lu https://www.google.lu *.google.lu https://*.google.lt https://google.lt https://www.google.lt *.google.lt https://*.google.lv https://google.lv https://www.google.lv *.google.lv https://*.google.hu https://google.hu https://www.google.hu *.google.hu https://*.google.hr https://google.hr https://www.google.hr *.google.hr https://*.google.ee https://google.ee https://www.google.ee *.google.ee https://*.google.cz https://google.cz https://www.google.cz *.google.cz https://*.google.bg https://google.bg https://www.google.bg *.google.bg https: data: blob: pantit-images.s3.amazonaws.com pantit-images.s3.eu-west-1.amazonaws.com pantit-receipt.s3.amazonaws.com imgsct.cookiebot.com *.facebook.com *.facebook.net *.googletagmanager.com test-gateway.zignsec.com gateway.zignsec.com *.googleadservices.com consentcdn.cookiebot.com marknad.pantit.se *.crisp.chat *.gstatic.com *.doubleclick.net https://*.doubleclick.net https://googleads.g.doubleclick.net https://stats.g.doubleclick.net *.googlesyndication.com https://pagead2.googlesyndication.com;connect-src 'self' https://www.pantit.se https://pantit.se https: http: ws: wss: https://*.google.se https://google.se https://www.google.se *.google.se https://*.google.de https://google.de https://www.google.de *.google.de https://*.google.com https://google.com https://www.google.com *.google.com https://*.google.co.uk https://google.co.uk https://www.google.co.uk *.google.co.uk https://*.google.com.tr https://google.com.tr https://www.google.com.tr *.google.com.tr https://*.google.com.pk https://google.com.pk https://www.google.com.pk *.google.com.pk https://*.google.com.ua https://google.com.ua https://www.google.com.ua *.google.com.ua https://*.google.com.cy https://google.com.cy https://www.google.com.cy *.google.com.cy https://*.google.ch https://google.ch https://www.google.ch *.google.ch https://*.google.dk https://google.dk https://www.google.dk *.google.dk https://*.google.nl https://google.nl https://www.google.nl *.google.nl https://*.google.fr https://google.fr https://www.google.fr *.google.fr https://*.google.ie https://google.ie https://www.google.ie *.google.ie https://*.google.no https://google.no https://www.google.no *.google.no https://*.google.es https://google.es https://www.google.es *.google.es https://*.google.fi https://google.fi https://www.google.fi *.google.fi https://*.google.ge https://google.ge https://www.google.ge *.google.ge https://*.google.rs https://google.rs https://www.google.rs *.google.rs https://*.google.pt https://google.pt https://www.google.pt *.google.pt https://*.google.at https://google.at https://www.google.at *.google.at https://*.google.be https://google.be https://www.google.be *.google.be https://*.google.it https://google.it https://www.google.it *.google.it https://*.google.pl https://google.pl https://www.google.pl *.google.pl https://*.google.ru https://google.ru https://www.google.ru *.google.ru https://*.google.co.jp https://google.co.jp https://www.google.co.jp *.google.co.jp https://*.google.gr https://google.gr https://www.google.gr *.google.gr https://*.google.com.br https://google.com.br https://www.google.com.br *.google.com.br https://*.google.ca https://google.ca https://www.google.ca *.google.ca https://*.google.si https://google.si https://www.google.si *.google.si https://*.google.sk https://google.sk https://www.google.sk *.google.sk https://*.google.ro https://google.ro https://www.google.ro *.google.ro https://*.google.mt https://google.mt https://www.google.mt *.google.mt https://*.google.lu https://google.lu https://www.google.lu *.google.lu https://*.google.lt https://google.lt https://www.google.lt *.google.lt https://*.google.lv https://google.lv https://www.google.lv *.google.lv https://*.google.hu https://google.hu https://www.google.hu *.google.hu https://*.google.hr https://google.hr https://www.google.hr *.google.hr https://*.google.ee https://google.ee https://www.google.ee *.google.ee https://*.google.cz https://google.cz https://www.google.cz *.google.cz https://*.google.bg https://google.bg https://www.google.bg *.google.bg wss://client.relay.crisp.chat https://*.crisp.chat https://client.crisp.chat https://*.client.crisp.chat *.crisp.chat https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.doubleclick.net https://stats.g.doubleclick.net https://*.googlesyndication.com https://*.googleadservices.com https://consentcdn.cookiebot.com https://pagead2.googlesyndication.com https://*.facebook.com https://connect.facebook.net https://www.facebook.com client.britepaymentgroup.com https://client.britepaymentgroup.com;form-action 'self' https://www.pantit.se https://pantit.se www.facebook.com;worker-src 'self' https://www.pantit.se https://pantit.se blob:;base-uri 'self' https://www.pantit.se https://pantit.se;frame-ancestors 'self' https://www.pantit.se https://pantit.se;object-src 'none';upgrade-insecure-requests;report-uri /callbacks/csp-violation-report-endpoint 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.fontawesome.com data: *.trustedshops.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com https://www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.trustedshops.com *.instagram.com *.fbcdn.net *.via.placeholder.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.polyfill.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://browser.sentry-cdn.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.trustedshops.com *.cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com widget.freshworks.com m2epro.freshdesk.com https://*.ingest.sentry.io *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.instagram.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://s.brightspace.com https://*.ally.ac https://leaplti.desire2learn.com/ https://leaplti-fr.brightspace.com/ https://tryleap.brightspace.com/ https://leaplti-es.desire2learn.com/ https://leaplti-ptbr.desire2learn.com/ https://leaplti-us.brightspace.com/ https://leaplti-apac.brightspace.com/ https://leaplti-emea.brightspace.com/ https://leapqa.net https://leaplti-ap.brightspace.com https://login.microsoftonline.com/ https://login.live.com/ https://cdn.lcs.brightspace.com/ https://leaplti-in.brightspace.com; report-uri https://logger.us-east-1.logging.brightspace.com/log/csp/97MOPTmbJSWZDoPzmweSogAAAZsp3qmd 1 default-src 'self' https://challenges.cloudflare.com; style-src 'self' https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net data: 'unsafe-inline'; script-src 'self' 'sha256-+EejO0ruI2UlGX+0zx67jP3cDUSJqrZ8AAEzt9e62Qw=' https://www.google-analytics.com https://www.googletagmanager.com https://code.jquery.com https://cdn.jsdelivr.net https://kit.fontawesome.com https://challenges.cloudflare.com https://googleads.g.doubleclick.net https://www.googleadservices.com 'unsafe-eval' 'unsafe-inline'; img-src 'self' data: https://*.blob.core.windows.net https://www.googletagmanager.com https://i.postimg.cc https://www.google.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.hn https://www.google.es https://www.google.it https://www.google.cn https://www.google.com.hk https://www.google.com.mx https://www.google.com.pa https://www.google.com.co https://www.google.co.uk https://www.google.co.jp https://www.google.com.sa https://www.google.ae https://www.google.co.il https://www.google.com.qa https://www.google.com.py https://www.google.com.br https://www.google.ca https://www.google.cl; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://sigob.org https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.jsdelivr.net https://i.postimg.cc https://translate.googleapis.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://*.blob.core.windows.net https://www.google.com https://www.google.hn; frame-src 'self' https://challenges.cloudflare.com https://sde.gob.hn https://www.googletagmanager.com https://googleads.g.doubleclick.net; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; manifest-src 'self'; report-uri https://pdihonduras.gob.hn/auth/api/healthcheck/csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com https://www.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.monetico-services.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.sharethis.com https://www.google.com *.doubleclick.net *.facebook.com *.monetico-services.com *.hotjar.com *.cloudfront.net *.vimeo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.sharethis.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://www.magezon.com *.cloudfront.net *.cookielaw.org *.usabilla.com https://admin.pearsonclinical.eu/media/wysiwyg/ce_copy_0.png https://admin.pearsonclinical.eu/media/wysiwyg/iso-27001-certified.png data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.sharethis.com *.googleapis.com https://www.gstatic.com https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.avada.io *.hotjar.com *.usabilla.com optanon.blob.core.windows.net code.jquery.com *.cookielaw.org *.igodigital.com *.cloudfront.net pearson.tfaforms.net bat.bing.com www.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com optanon.blob.core.windows.net *.cookielaw.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.sharethis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.monetico-services.com https://get.geojs.io *.avada.io *.hotjar.com *.hotjar.io *.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.cloudfront.net 'self' 'unsafe-inline'; 1 default-src 'self' https://id-sandbox.dokobit.com/ https://id.dokobit.com/; img-src 'self' blob: https://*.amazonaws.com https://id-sandbox.dokobit.com/ https://id.dokobit.com/ data:; font-src 'self' fonts.googleapis.com fonts.gstatic.com https://id-sandbox.dokobit.com/ https://id.dokobit.com/; media-src 'self' https://*.amazonaws.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://id-sandbox.dokobit.com/ https://id.dokobit.com/; style-src-elem 'self' 'unsafe-inline' https://id-sandbox.dokobit.com/ https://id.dokobit.com/ fonts.googleapis.com; script-src-elem 'self' 'unsafe-inline' https://id-sandbox.dokobit.com/ https://id.dokobit.com/ https://static.zdassets.com/ https://widget-mediator.zopim.com/ https://www.googletagmanager.com blob:; connect-src 'self' https://www.certific.co/ https://ekr.zdassets.com/ https://certific.zendesk.com/ https://widget-mediator.zopim.com/ wss://widget-mediator.zopim.com/ https://region1.google-analytics.com https://www.google-analytics.com/ wss://*.twilio.com https://id-sandbox.dokobit.com/ https://id.dokobit.com/; report-uri /api/log/csp-report; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.avada.io *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://accounts.google.com https://*.google.com https://*.hotjar.com https://vars.hotjar.com https://www.facebook.com https://*.criteo.com https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com public.montonio.com https://www.facebook.com https://www.google.com https://www.google.ee https://www.google-analytics.com chat.petcity.ee data: http: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com public.montonio.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://www.gstatic.com chat.petcity.ee http: https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com chat.petcity.ee http: https: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://www.google-analytics.com https://stats.g.doubleclick.net chat.petcity.ee http: https: wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.cloudflare.com *.petelegante.com.br api.mundipagg.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com api.mundipagg.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.youtube.com *.petelegante.com.br *.doubleclick.net *.googlesyndication.com *.facebook.com *.tiktok.com *.pinimg.com *.pinterest.com www.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://cdn.mundipagg.com *.cloudflare.com *.petelegante.com.br *.facebook.com *.googletagmanager.com api.mundipagg.com google.com *.google.com google.com.br *.google.com.br *.google-analytics.com *.gstatic.com *.googleadservices.com *.tiktok.com *.doubleclick.net *.googlesyndication.com *.pinimg.com *.pinterest.com 'self' blob: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://sandbox.gerencianet.com.br https://api.gerencianet.com.br *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' *.cloudflare.com *.cloudflareinsights.com *.petelegante.com.br *.googletagmanager.com api.mundipagg.com *.doubleclick.net *.googlesyndication.com *.youtube.com *.facebook.com *.google-analytics.com google.com *.google.com *.gstatic.com *.googleadservices.com *.tiktok.com *.pinimg.com *.pinterest.com maps.googleapis.com www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.cloudflare.com *.petelegante.com.br api.mundipagg.com *.facebook.com *.tiktok.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://api.mundipagg.com *.cloudflare.com opencep.com *.petelegante.com.br *.googletagmanager.com *.doubleclick.net *.googlesyndication.com api.mundipagg.com *.facebook.com *.google-analytics.com google.com *.google.com *.gstatic.com *.googleadservices.com *.tiktok.com *.cloudflareinsights.com *.pinimg.com *.pinterest.com http://localhost:12387/ www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com *.granado.com.br *.phebo.com.br *.fontawesome.com *.alothemes.com *.magepow.com *.cloudflare.com *.twitter.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com www.google.com *.granado.com.br *.phebo.com.br *.criteo.com *.criteo.net *.run.app *.doubleclick.net *.getblue.io *.groovinads.com *.googleapis.com *.twitter.com *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com *.googleapis.com *.granado.com.br *.phebo.com.br *.clarity.ms *.bing.com *.bidswitch.net *.doubleclick.net *.adnxs.com *.casalemedia.com *.dmxleo.com *.criteo.com *.stickyadstv.com *.360yield.com *.liadm.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.revcontent.com *.rubiconproject.com *.smartadserver.com *.taboola.com *.teads.tv *.tremorhub.com *.clmbtech.com *.3lift.com *.1rx.io *.agkn.com *.unrulymedia.com *.fwmrm.net *.adsrvr.org *.yahoo.com *.bidr.io *.adform.net *.sitescout.com *.crwdcntrl.net *.springserve.com *.stackadapt.com *.ipredictive.com *.openx.net *.mdhv.io *.w55c.net *.simpli.fi *.turn.com *.sundaysky.com *.contextweb.com *.everesttech.net *.adgrx.com *.a-mo.net *.google.com.br *.dotomi.com *.groovinads.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.alothemes.com *.magepow.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.ytimg.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.net *.klaviyo.com *.googletagmanager.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com polyfill.io *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.granado.com.br *.phebo.com.br *.clarity.ms *.criteo.com *.getblue.io *.dwin1.com *.tiktok.com *.pmweb.com.br *.grow.up.st *.groovinads.com *.goab.io *.roeyecdn.com *.sciencebehindecommerce.com *.awin1.com *.evgnet.com *.alothemes.com *.magepow.com *.cloudflare.com *.twitter.com *.google-analytics.com *.fontawesome.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.ads-twitter.com *.bing.com *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ *.granado.com.br *.phebo.com.br *.fontawesome.com *.alothemes.com *.magepow.com *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.googleapis.com *.granado.com.br *.phebo.com.br *.clarity.ms *.criteo.com *.algolia.io *.run.app *.exct.net *.grow.up.st *.tiktok.com *.pmweb.com.br https://viacep.com.br *.alothemes.com *.magepow.com *.cloudflare.com *.twitter.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.granado.com.br *.phebo.com.br 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=625c0197-5a17-4fda-84a5-1827b6d57dbe; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.easypack24.net *.gdpsystem.eu *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.dpd.com.pl *.easypack24.net *.inpost.pl *.openstreetmap.org *.gdpsystem.eu https://ssl.ceneo.pl pay.google.com apm.przelewy24.pl https://www.googletagmanager.com/ *.packeta.com secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.google.pl *.easypack24.net *.inpost.pl *.openstreetmap.org pieceofcase.pl *.gdpsystem.eu *.googleusercontent.com https://*.elfsightcdn.com https://ssl.ceneo.pl static.przelewy24.pl www.gstatic.com gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com static.payu.com *.hsforms.net *.hsforms.com https://*.bing.com https://us-ms.gr-cdn.com https://bat.bing.net https://*.googlesyndication.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.google.pl *.hotjar.com *.poczta-polska.pl unpkg.com *.mapbox.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.gdpsystem.eu https://static.cloudflareinsights.com https://*.cloudflareinsights.com https://*.elfsight.com https://ssl.ceneo.pl sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl https://cdnjs.cloudflare.com cdnjs.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com *.packeta.com secure.payu.com secure.snd.payu.com *.hsforms.net *.hsforms.com https://an.gr-wcon.com https://bat.bing.com https://us-an.gr-cdn.com https://us-wbe.gr-cdn.com https://*.elfsightcdn.com https://app.responso.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.gdpsystem.eu https://cdnjs.cloudflare.com cdnjs.cloudflare.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.easypack24.net pieceofcase.pl *.gdpsystem.eu http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com *.facebook.net https://googleads.g.doubleclick.net *.googlesyndication.com *.tiktok.com wss://ws.hotjar.com *.hotjar.io *.easypack24.net *.inpost.pl *.openstreetmap.org *.gdpsystem.eu https://*.g.doubleclick.net https://*.elfsight.com sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.packeta.com secure.payu.com merch-prod.snd.payu.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://*.getresponse.com https://ts.getresponse.pl https://bat.bing.net https://*.googlesyndication.com https://app.responso.com https://participant.connect.eu-west-2.amazonaws.com wss://tufsuyburufn.transport.connect.eu-west-2.amazonaws.com bat.bing.com vwe.gr-wcon.com cdn.jsdelivr.net unpkg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; child-src blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https:; font-src https: data:; style-src https: 'unsafe-inline'; img-src https: blob: data:; frame-ancestors 'self'; frame-src 'self' https:; worker-src blob:; object-src 'self'; media-src https: blob: data:; report-uri https://www.plateforme-apis.fr/local/csp/collector.php?uid=0&cid=1 1 font-src maxcdn.bootstrapcdn.com *.cloudfront.net *.zohocdn.com *.amazonaws.com *.gstatic.com; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.google.com *.googleapis.com *.gstatic.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.cloudfront.net *.facebook.com *.zohocdn.com *.zohopublic.in *.google.co.in 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.avada.io *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.cloudfront.net *.cloudflare.com *.fontawesome.com *.zohocdn.com *.zoho.in *.facebook.net *.google.com www.gstatic.com *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com maxcdn.bootstrapcdn.com *.cloudfront.net *.zohocdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.google-analytics.com https://www.google-analytics.com *.cloudfront.net *.paypal.com *.zoho.in *.cardinalcommerce.com *.zohopublic.in wss://vts.zohopublic.in *.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-3I9m/8NkOoBnuyxrGPgKrg==' https://www.googletagmanager.com/ https://www.google.com/ https://www.heureka.sk/ https://www.heureka.cz/ http://www.heureka.cz/ https://cdn.heureka.group/ https://api.foxentry.cz/ https://cdn.foxentry.cz/ https://connect.facebook.net 'unsafe-inline' 'report-sample' 'nonce-3I9m/8NkOoBnuyxrGPgKrg==' 'strict-dynamic' 'unsafe-eval' https://www.pneusvet.sk/ https://pneusvet.venalio.com/ https://pneusvet.bwcdn.net/ https://www.googletagmanager.com/ https://www.google.com/ https://www.heureka.sk/ https://www.heureka.cz/ http://www.heureka.cz/ https://cdn.heureka.group/ https://api.foxentry.cz/ https://cdn.foxentry.cz/ https://connect.facebook.net 'unsafe-inline' 'report-sample'; report-uri https://pneusvet.sk/api/v1/csp/hook; 1 script-src 'self' blob: https://prod-plk-web.es.rbi.tools/en/static/js/vendor.7ec3a292.js https://prod-plk-web.es.rbi.tools/en/static/js/main.d069336f.js https://prod-plk-web.es.rbi.tools/en/static/js/runtime.4f4a1c64.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-plk-web.es.rbi.tools/en/static/js/vendor.40df2a59.js https://prod-plk-web.es.rbi.tools/en/static/js/main.40c6ae07.js https://prod-plk-web.es.rbi.tools/en/static/js/runtime.790f342d.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com * www.magmodules.eu *.datatrics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com * *.datatrics.com www.facebook.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com squeezely.tech www.squeezely.tech *.squeezely.tech 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://p.typekit.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net * *.datatrics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com www.google.com secure.pay1.de *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io legalweb.io magefan.com cm.magefan.com https://www.mollie.com www.facebook.com stats.g.doubleclick.net api.omappapi.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://browser.sentry-cdn.com *.fontawesome.com *.googleapis.com *.gstatic.com js.mollie.com polyfill.io maps.googleapis.com secure.pay1.de cdn.klarna.com connect.facebook.net a.opmnstr.com diffuser-cdn.app-us1.com www.google.com prism.app-us1.com www.gstatic.com ajax.googleapis.com cdnjs.cloudflare.com trackcmp.net *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu sentry.smdm.at api.omappapi.com *.ingest.sentry.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.accelasearch.io *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.accelasearch.io int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com *.iubenda.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.accelasearch.io int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com *.iubenda.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.accelasearch.io *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com https://code.jquery.com/ui/1.12.1/themes/base/jquery-ui.css tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.accelasearch.io int-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com *.iubenda.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data:; connect-src 'self' wss: https:; style-src 'self' 'unsafe-inline' data: https:; frame-src 'self' https://batmaid.prismic.io https://*.trustpilot.com https://vars.hotjar.com https://*.google.com https://www.facebook.com https://*.doubleclick.net https://tpc.googlesyndication.com https://www.youtube.com https://pay.datatrans.com https://3dsec.cardcenter.ch https://acs1.viseca.ch https://acs.touch.tech https://www.instagram.com https://www.googletagmanager.com https://consentcdn.cookiebot.com data:; frame-ancestors 'self'; form-action 'self' https://pay.datatrans.com https://www.facebook.com; object-src 'none'; upgrade-insecure-requests; report-uri /en/api/v1/csp-violation-report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-elK3CUAx7zI7sSOLioyn-w' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 img-src 'self' https://*.autoplus.co.kr data: blob: https://i.ytimg.com ; script-src 'self' 'nonce-VjtFZYpYNajIjs0nBANgaw==' https://dapi.kakao.com https://t1.daumcdn.net ; report-uri /csp/report 1 font-src *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com *.cloudflare.com *.clarity.ms *.bing.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro https://stage-checkout.leanpay.si *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.googleapis.com *.newsmanapp.com *.clarity.ms *.bing.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.doubleclick.net www.googletagmanager.com googletagmanager.com *.clarity.ms *.bing.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tbicp.com *.cloudflare.com s.ytimg.com *.img2run.com *.mailchimp.com *.mcusercontent.com *.google.ro trusted.ro *.whiteimage.biz *.cookiebot.com *.clarity.ms *.bing.com *.googletagmanager.com *.google-analytics.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.tbicp.com *.cloudflare.com *.fontawesome.com *.facebook.net *.attr-2p.com *.2performant.com *.newsmanapp.com attr-2p.com *.mailchimp.com *.list-manage.com *.chimpstatic.com googletagmanager.com *.whiteimage.biz *.cookiebot.com *.criteo.com *.clarity.ms *.bing.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.cloudflare.com *.mailchimp.com *.clarity.ms *.bing.com googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.cloudflare.com *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.google.com *.googletagmanager.com *.clarity.ms *.bing.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.uestra.de https://cloud.ccm19.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://img.youtube.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://cloud.ccm19.de https://elma.gvh.de; base-uri 'self' https://*.uestra.de; frame-src 'self' blob: https://*.youtube.com/ https://gvh.demo.hafas.cloud https://gvh.hafas.de https://abo.gvh.de https://cloud.ccm19.de https://deutschlandticket.gvh.de https://transport.novafind.eu/; media-src 'self' blob:; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://cloud.ccm19.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de https://stats.uestra.de 'report-sample'; font-src 'self' data: https://fonts.gstatic.com https://gvh.demo.hafas.cloud https://gvh.hafas.de https://stats.uestra.de https://elma.gvh.de; connect-src 'self' https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://stats.uestra.de https://elma.gvh.de; object-src 'self' blob: https://*.uestra.de; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://cloud.ccm19.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://*.uestra.de https://relaunch.uestra.de https://*.webit.de https://*.hafas.cloud https://*.hafas.de https://elma.gvh.de 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://www.uestra.de https://relaunch.uestra.de https://stats.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de https://cloud.ccm19.de https://elma.gvh.de 'report-sample'; frame-ancestors 'self' https://*.uestra.de https://gvh.demo.hafas.cloud https://gvh.hafas.de; form-action 'self'; report-uri https://www.uestra.de/@http-reporting?csp=report&requestTime=1765936843943307&requestHash=eac0103a03ebfc3a3031019ee4fefe86161dc8ef 1 frame-src *.force.com https://player.vimeo.com 'self' *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es *.adis.ws https://aus58.sfdc-vwfla6.salesforce.com https://rtbamock.getsandbox.com https://www.gstatic.com *.youtube.ie https://www.youtube.com https://rentalbondsvic.file.force.com *.cloudinary.com https://www.google.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr https://api-m.sandbox.paypal.com https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net *.youtube.nl https://service.force.com/embeddedservice/ https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com *.youtube.com.br *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net *.youtube.ca https://location.force.com *.vidyard.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://*.a.forceusercontent.com/lightningmaps/ *.wistia.net *.salesforce.com *.youtube.pl; report-to sfdc-csp-ep; report-uri https://rentalbondsvic.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D5i000000Hwrq&networkId=0DMMn0000000T0R&type=communities 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe *.weltpixel.com https://www.googletagmanager.com/ business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io business.facebook.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io business.facebook.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://*.sentry.io; img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://resraku-image-files-production.s3.ap-northeast-1.amazonaws.com; object-src 'none'; script-src 'self' 'unsafe-inline' https://browser.sentry-cdn.com https://www.google-analytics.com https://www.googletagmanager.com https://ssl.google-analytics.com https://cdn.jsdelivr.net 'nonce-80b65c0983211d8bacdc0b0ce2d959db'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' 'unsafe-inline' https://fonts.gstatic.com; script-src-attr 'none'; report-uri /csp/report 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.gstatic.com *.googletagmanager.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googletagmanager.com *.google-analytics.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googletagmanager.com *.google-analytics.com *.stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com cardinalcommerce.com epayco.co epayco.com epayco.io geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors cardinalcommerce.com epayco.co epayco.com epayco.io multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com cardinalcommerce.com epayco.co epayco.com epayco.io multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.clarity.ms cardinalcommerce.com epayco.co epayco.com epayco.io multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com rutavity.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.clarity.ms epayco.co epayco.com epayco.io cardinalcommerce.com multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com rutavity.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com www.clarity.ms assets.braintreegateway.com rutavity.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.clarity.ms rutavity.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.clarity.ms rutavity.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com www.clarity.ms cardinalcommerce.com epayco.co epayco.com epayco.io multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com rutavity.com 'self' 'unsafe-inline'; child-src cardinalcommerce.com epayco.co epayco.com epayco.io multimedia.epayco.co geoissuer.cardinalcommerce.com 3ds.seglan.com 3ds.epayco.com emv3dsmethod.secureacs.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com bicicletasmilan.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.clarity.ms rutavity.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.facebook.com https://td.doubleclick.net https://youtu.be 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.designer-images.net https://www.facebook.com https://www.google.gr https://maps.googleapis.com https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com *.stat-track.com polyfill.io *.moosend.com https://connect.facebook.net https://www.facebook.com https://analytics.tiktok.com https://www.gstatic.com https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.moosend.com *.bootstrapcdn.com https://use.typekit.net https://p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.stat-track.com *.m-pages.com *.m-operations.com https://region1.google-analytics.com https://region1.analytics.google.com https://www.google.com https://analytics.tiktok.com https://stats.g.doubleclick.net https://www.google.gr https://www.facebook.com https://pagead2.googlesyndication.com https://maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-cALK_BYptrf4ZUTcfAZcRl5pgMOYvcwu'; base-uri 'none'; report-uri https://data.sanitino.eu/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.flashyapp.com api.flashy.app *.flashy.dev *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.flashyapp.com api.flashy.app *.flashy.dev c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://images.unsplash.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.flashyapp.com api.flashy.app *.flashy.dev maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com api.creditguard.co.il cguat2.creditguard.co.il cgmpiuat.creditguard.co.il ppsuat.creditguard.co.il pps.creditguard.co.il *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.flashyapp.com api.flashy.app *.flashy.dev www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' sbb.com.br *.sbb.com.br wake-components.fbitsstatic.net sbb.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.sbb.com.br sbb.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src *.fontawesome.com https://fonts.gstatic.com *.cloudflare.com *.typekit.net *.trustedshops.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.eewosecure.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://player.vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.addthis.com *.demdex.net *.authorize.net *.paypal.com *.google.com *.facebook.com *.facebook.net *.vimeo.com *.youtube-nocookie.com *.braintreegateway.com *.kaptcha.com *.yotpo.com *.eewosecure.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.paypal.com *.google.com *.youtube.com https://s.ytimg.com *.instagram.com *.cdninstagram.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io https://player.vimeo.com https://www.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.addthis.com *.addthisedge.com *.adobedtm.com *.authorize.net *.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.google.com *.googleadservices.com *.googleapis.com *.google-analytics.com *.gstatic.com *.moatads.com *.paypal.com *.paypalobjects.com *.trustedshops.com *.usercentrics.eu *.instagram.com *.vimeo.com *.yotpo.com youtube.com *.facebook.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline *.cloudflare.com *.typekit.net *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://fonts.googleapis.com https://fonts.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudflare.com *.vimeo.com *.youtube.com *.google.com *.moatads.com *.paypal.com *.braintreegateway.com *.addthis.com *.cardinalcommerce.com *.paypalobjects.com *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.amazonservices.de *.google-analytics.com *.googleapis.com *.gstatic.com *.yotpo.com *.instagram.com *.cdninstagram.com *.facebook.net *.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'nonce-ZXWdJRuDPxYG8MrYgg29YCs9rUDsEdQnvno1juWbwac=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://maps.googleapis.com https://fonts.googleapis.com https://www.posta.hu data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://maps.googleapis.com https://www.posta.hu www.xtento.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.openstreetmap.org blob: https://maps.googleapis.com https://maps.gstatic.com https://www.posta.hu www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com test.saferpay.com www.saferpay.com saferpay.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.googletagmanager.com https://maps.googleapis.com https://www.posta.hu https://posta.hu www.xtento.com cdn.xtento.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://maps.googleapis.com https://fonts.googleapis.com https://maps.gstatic.com https://www.posta.hu assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.doubleclick.net *.google-analytics.com https://maps.googleapis.com https://www.posta.hu https://posta.hu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://www.mollie.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net twitter.com platform.twitter.com js.mollie.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://static.klaviyo.com maxcdn.bootstrapcdn.com *.photoslurp.com *.nosto.com *.doofinder.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.doofinder.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; frame-src https://www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com js.mollie.com *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; media-src 'self'; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net embed.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com js.mollie.com *.googletagmanager.com https://*.sameday.ro challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io github.blog https://images.unsplash.com *.googleapis.com https://firebasestorage.googleapis.com https://www.mollie.com *.googletagmanager.com *.google-analytics.com *.google.ro *.pagead2.googlesyndication.com www.gstatic.com tawk.link embed.tawk.to google.ro cdn.jsdelivr.net ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io *.shopify.com js.mollie.com *.googletagmanager.com *.google-analytics.com connect.facebook.net consent.studio cdn.sameday.ro www.google.com www.gstatic.com analytics.tiktok.com embed.tawk.to cdn.jsdelivr.net https://*.sameday.ro challenges.cloudflare.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net www.gstatic.com embed.tawk.to https://*.sameday.ro tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com https://get.geojs.io *.avada.io *.google-analytics.com *.googletagmanager.com pagead2.googlesyndication.com consent.studio analytics.tiktok.com *.tawk.to wss://*.tawk.to *.tiktokw.us stats.g.doubleclick.net *.analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.shopify.com maps.googleapis.com https://static.addtoany.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io https://static.addtoany.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com *.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net *.flashyapp.com api.flashy.app *.flashy.dev *.yotpo.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com *.pelecard.biz *.queue-it.net *.facebook.com *.facebook.net *.vimeo.com vimeo.com *.adoric.com *.tiktok.com *.glassix.com *.adoric-om.com *.google.com *.flashyapp.com api.flashy.app *.flashy.dev www.xtento.com *.paypal.com *.yotpo.com *.creditguard.co.il *.googletagmanager.com *.xtento.com *.doubleclick.net acsbapp.com *.acsbap.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.magentocommerce.com *.entrust.net *.google.com *.google.com.vn *.doubleclick.net *.cloudfront.net *.googleapis.com *.gstatic.com *.facebook.com *.facebook.net *.mltp.co.il *.adoric.com *.adoric-om.com *.tiktok.com *.giphy.com *.acsbapp.com *.amazonaws.com *.shw.co.il www.xtento.com cdn.xtento.com *.googleadservices.com *.yotpo.com *.cdninstagram.com *.google-analytics.com *.google.co.il https://www.google *.paypal.com *.paypalobjects.com *.vimeo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adscale.com ascl.pro *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.adobedtm.com *.authorize.net *.entrust.net *.gstatic.com www.google.com *.adyen.com *.queue-it.net *.googletagmanager.com *.googleapis.com *.cardinalcommerce.com *.ccdc02.com *.braintreegateway.com *.signifyd.com *.nowdialogue.com *.xtento.com *.facebook.com *.facebook.net *.nagich.co.il *.rawgit.com *.adoric.com *.tiktok.com *.glassix.com *.adoric-om.com *.flashyapp.com api.flashy.app *.flashy.dev www.xtento.com cdn.xtento.com *.google-analytics.com *.google.com *.fontawesome.com *.googleadservices.com *.doubleclick.net *.analytics.com *.youtube.com *.paypal.com *.paypalobjects.com acsbapp.com acsbap.com *.cloudflare.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.adoric.com *.adoric-om.com *.googleapis.com *.nowdialogue.com *.fontawesome.com *.bootstrapcdn.com *.cloudflare.com unsafe-inline tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.entrust.net *.google-analytics.com *.google.com *.nowdialogue.com nowdialogue.com *.nagich.co.il *.doubleclick.net *.vimeo.com vimeo.com *.demdex.com *.adoric.com *.adoric-om.com *.tiktok.com *.glassix.com *.flashyapp.com api.flashy.app *.flashy.dev *.analytics.com *.facebook.com player.vimeo.com *.googleapis.com *.acsbapp.com acsbap.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.easypack24.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.pl *.easypack24.net *.inpost.pl https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.safemage.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.cloudflareinsights.com *.hotjar.com *.easypack24.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com maps.googleapis.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.easypack24.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googlesyndication.com *.hotjar.io *.easypack24.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://www.google-analytics.com *.instagram.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com data: 'self' 'unsafe-inline'; form-action *.payway.com.hr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.polyfill.io *.google.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleapis.com *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.google-analytics.com *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com maxcdn.bootstrapcdn.com *.feedbackcompany.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action *.feedbackcompany.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ consentcdn.cookiebot.com *.googletagmanager.com blob: landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com imgsct.cookiebot.com www.facebook.com www.google.nl cdn.doofinder.com *.feedbackcompany.com 'self' data: magefan.com cm.magefan.com https://img.youtube.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.feedbackcompany.com static.elfsight.com consent.cookiebot.com eu1-config.doofinder.com connect.facebook.net consentcdn.cookiebot.com ct.beslist.nl cdn.doofinder.com *.feedbackcompany.com s7.addthis.com *.avada.io *.alothemes.com *.magepow.com tm.tradetracker.net landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.doofinder.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com region1.google-analytics.com www.feedbackcompany.com core.service.elfsight.com service-reviews-ultimate.elfsight.com pagead2.googlesyndication.com www.youtube.com www.facebook.com connect.facebook.net consentcdn.cookiebot.com ct.beslist.nl www.google.com region1.analytics.google.com stats.g.doubleclick.net *.doofinder.com wss://*.doofinder.com *.feedbackcompany.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com landofcoder.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.stape.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io camo.githubusercontent.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.openstreetmap.org *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.stape.io https://firebasestorage.googleapis.com https://www.magezon.com *.koongo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.sandbox.paypal.com https://www.paypal.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io https://get.geojs.io *.avada.io *.koongo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; frame-src https://challenges.cloudflare.com https://www.youtube.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.safeframe.googlesyndication.com https://*.adtrafficquality.google https://www.google.com https://tpc.googlesyndication.com; script-src-elem 'self' 'unsafe-inline' https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://*.adtrafficquality.google https://www.googletagmanager.com https://www.google-analytics.com https://challenges.cloudflare.com https://www.gstatic.com https://sokcdn.com https://cdn.ampproject.org https://fundingchoicesmessages.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob:; img-src 'self' data: blob: https://*.googleusercontent.com https://*.gstatic.com https://*.doubleclick.net https://sokcdn.com https://*.googlesyndication.com https://*.adtrafficquality.google https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://sokcdn.com; font-src 'self' https://fonts.gstatic.com https://sokcdn.com; connect-src 'self' https://www.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://*.doubleclick.net https://*.adtrafficquality.google https://pagead2.googlesyndication.com https://sokcdn.com https://fundingchoicesmessages.google.com; worker-src 'self' blob:; frame-ancestors 'none'; report-uri https://sokakcio.hu/csp_report.php; 1 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.bootstrapcdn.com *.mopinion.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.newrelic.com https://*.google.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.multisafepay.com *.trackedlink.net bucket-ip-website.s3.eu-central-1.amazonaws.com *.mopinion.com *.sorgente.nl data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com *.multisafepay.com https://pay.google.com *.mopinion.com *.newrelic.com *.marker.io *.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.sharethis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com *.multisafepay.com *.fontawesome.com *.bootstrapcdn.com *.mopinion.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com *.sharethis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com *.multisafepay.com *.hotjar.com *.mopinion.com *.marker.io *.hotjar.io *.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://c31c5428-fe2b-4918-8f94-417118f9c8fa.sansec.watch/; report-to report-endpoint; 1 worker-src blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.ecoflow.no *.ihytta.no *.sparelys.no *.trioweb.net *.trioweb.dev data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.snapchat.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://checkout.dintero.com https://api.vipps.no https://apitest.vipps.no blob: https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.ecoflow.no *.ihytta.no *.sparelys.no *.snapchat.com checkout.dintero.com api.vipps.no apitest.vipps.no *.trustpilot.com apis.google.com *.google.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io magefan.com cm.magefan.com https://checkout.dintero.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.disqus.com flagpedia.net *.hsforms.net *.hsforms.com 'self' data: *.ecoflow.no *.ihytta.no *.sparelys.no *.trioweb.net *.trioweb.dev *.google.no *.google.se *.g.doubleclick.net *.bing.com *.clarity.ms *.snapchat.com *.europa.eu *.victronenergy.com *.kamafritid.no *.google.com checkout.dintero.com *.apple.com apis.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://checkout.dintero.com https://unpkg.com https://api.vipps.no https://apitest.vipps.no unpkg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com *.gstatic.com maps.googleapis.com *.hsforms.net *.hsforms.com *.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.ecoflow.no *.ihytta.no *.sparelys.no *.trioweb.net *.trioweb.dev *.g.doubleclick.net *.bing.com *.clarity.ms sc-static.net checkout.dintero.com api.vipps.no apitest.vipps.no apis.google.com invitejs.trustpilot.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com www.googletagmanager.com *.ecoflow.no *.ihytta.no *.sparelys.no *.trioweb.net *.trioweb.dev 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://checkout.dintero.com https://api.vipps.no https://apitest.vipps.no www.pdf995.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.gstatic.com maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.ecoflow.no *.ihytta.no *.sparelys.no *.trioweb.net *.trioweb.dev www.google-analytics.com *.g.doubleclick.net *.bing.com *.clarity.ms *.snapchat.com checkout.dintero.com api.vipps.no apitest.vipps.no apis.google.com *.google.com report.trioweb.dev 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://dev.sparelys.no/api/1/security/?glitchtip_key=64a87582f77a45308667362dbc2d4347; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://www.paypal.com https://checkout.paystack.com https://polyfill.io https://cdn.jsdelivr.net https://*.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://www.jqueryscript.net https://maxcdn.bootstrapcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://unicons.iconscout.com https://cdnjs.cloudflare.com https://paystack.com https://www.jqueryscript.net https://maxcdn.bootstrapcdn.com https://cdn.jquery.app; img-src 'self' data: blob: https://www.gravatar.com https://www.paypalobjects.com https://www.google-analytics.com https://www.googletagmanager.com https://cdn.jsdelivr.net https://*.cloudflare.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://ipinfo.io https://www.paypal.com; frame-src 'self' https://js.stripe.com https://www.paypal.com https://checkout.paystack.com; object-src 'none'; base-uri 'self'; form-action 'self'; 1 default-src 'self' https:; script-src 'self' https: data: blob:; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data: blob:; connect-src 'self' https:; font-src 'self' https: data:; frame-ancestors 'self' 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.svea.com https://*.vipps.no https://*.trustly.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.svea.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com tagmanager.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com s7.addthis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.svea.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com tagmanager.google.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com ekr.zdassets.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.cookiebot.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://firebasestorage.googleapis.com https://www.magezon.com cdn2.hubspot.net resources.paytrail.com www.shipit.fi cdn.valuesportal.com *.cookiebot.com *.googleapis.com https://api.shipit.ax/images/carrier-logos/home-full-logo-medium.png https://api.shipit.ax/images/carrier-logos/1.1%20Posti%20logo%20Posti%20Orange%20rgb.png https://api.shipit.ax/images/carrier-logos/Matkahuolto_logo_round_DarkBlue_RGB.png https://api.shipit.ax/images/carrier-logos/Logo_DB_Schenker.svg.png https://api.shipit.ax/images/carrier-logos/postnord-logotype-rgb.jpg data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.avada.io *.shopify.com services.paytrail.com cdn.adt393.com static.hotjar.com maps.googleapis.com valuesportal.com *.hotjar.com *.cookiebot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io *.paytrail.com maps.googleapis.com *.adtraction.net vc.hotjar.io *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://therapylog.com https://*.therapylog.com wss://*.firebaseio.com https://cdn.headwayapp.co https://www.google-analytics.com https://www.google.com https://www.recaptcha.net; font-src 'self' https://fonts.gstatic.com data:; form-action 'self' https://therapylog.com https://*.therapylog.com https://*.zoom.us https://therapylog.s3.amazonaws.com https://therapylog-staging.s3.amazonaws.com https://therapylog-demo.s3.amazonaws.com; frame-src 'self' https://*.therapylog.com https://therapylog.com https://*.firebaseio.com https://www.google.com https://www.recaptcha.net https://zentry.io https://*.zentry.io https://therapylog.s3.amazonaws.com https://therapylog-staging.s3.amazonaws.com https://therapylog-demo.s3.amazonaws.com https://*.amazonaws.com https://headway-widget.net zentry:; img-src 'self' therapylog.s3.amazonaws.com therapylog-staging.s3.amazonaws.com therapylog-demo.s3.amazonaws.com data:; media-src 'self' therapylog.s3.amazonaws.com therapylog-staging.s3.amazonaws.com therapylog-demo.s3.amazonaws.com therapylog-video.s3.amazonaws.com; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob: https://cdn.headwayapp.co; script-src-attr 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'; report-uri /csp-violation-report-endpoint 1 default-src *; script-src 'unsafe-inline' https://www.google.com/; style-src 'unsafe-inline' https://www.google.com/; img-src *; font-src *; media-src *; frame-src 'none'; frame-ancestors 'none'; form-action 'none'; report-uri https://thespidershop.report-uri.com/r/d/csp/enforce 1 worker-src https://cdn.connectif.cloud; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.cs.1worldsync.com https://script.hotjar.com https://fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.xtento.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * td.doubleclick.net www.google.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com mcstaging.digitalixcomercio.com mcprod.digitalixcomercio.com rt.flix360.com media.flixcar.com www.google.com.co https://mcprod.digitalixcomercio.com https://cdn.cs.1worldsync.com https://photos-us.bazaarvoice.com https://www.facebook.com https://px.ads.linkedin.com https://www.linkedin.com/px/ https://ad.doubleclick.net https://px4.ads.linkedin.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.xtento.com cdn.xtento.com https://cdn.connectif.cloud js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.cardinalcommerce.com www.google.com www.gstatic.com cdn.cs.1worldsync.com media.flixfacts.com ws.cs.1worldsync.com media.flixcar.com static.queue-it.net assets.queue-it.net static.hotjar.com script.hotjar.com static.zdassets.com js-agent.newrelic.com https://static.zdassets.com https://static.hotjar.com https://static.queue-it.net https://prod.flixgvid.flix360.io https://connect.facebook.net https://snap.licdn.com https://analytics.tiktok.com https://pixels.lemonpi.io https://pagead2.googlesyndication.com https://stapecdn.com https://ix.aqmaster.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com display.ugc.bazaarvoice.com assets.braintreegateway.com tagmanager.google.com https://cdn.cs.1worldsync.com https://fonts.cdnfonts.com/css/satoshi https://www.googletagmanager.com/debug/badge.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com https://cdn.cs.1worldsync.com https://mcprod.shop.epson.com.co/media 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.doubleclick.net media.flixcar.com ekr.zdassets.com *.zendesk.com bam.nr-data.net googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://ekr.zdassets.com wss://widget-mediator.zopim.com https://am1-api.connectif.cloud https://surveystats.hotjar.io https://content.hotjar.io wss://ws.hotjar.com https://vc.hotjar.io https://analytics.tiktok.com https://px.ads.linkedin.com https://www.facebook.com https://ix.aqmaster.com https://cdn.connectif.cloud 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com https: blob: 'self' 'unsafe-inline'; default-src googleads.g.doubleclick.net stats.g.doubleclick.net commerce.adobedc.net widget-mediator.zopim.com https://pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.google.com *.addthis.com *.pinterest.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.cloudflare.com https://cdn.klarna.com data: https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.avada.io *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com *.fontawesome.com *.googleapis.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.fontawesome.com *.fonts.googleapis.com *.cloudflare.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com webpay3g.transbank.cl webpay3gint.transbank.cl *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://app.hubspot.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com *.instagram.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.google.com *.addthis.com *.pinterest.com https://app.hubspot.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com *.googleapis.com *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com https://forms.hsforms.com https://track.hubspot.com https://www.google.com https://www.google.com.bo *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.mlstatic.com *.mercadopago.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com https://js.hs-scripts.com https://js.hs-banner.com https://js.hscollectedforms.net https://js.usemessages.com https://js.hs-analytics.net https://api.hubspot.com https://forms.hubspot.com https://js-agent.newrelic.com https://bam.nr-data.net https://js-na1.hs-scripts.com https://js.hubspotfeedback.com https://js.hsleadflows.net https://js.hsadspixel.net https://js.hs-banner.net https://cdn2.hubspot.net https://static.hsappstatic.net https://feedback.hubapi.com https://hubspot.com https://hubspotusercontentxx.net https://hsforms.net https://hsforms.com https://vidyard.com https://googleads.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com cdn.ampproject.org *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de webchat.dotdigital.com *.mercadopago.com *.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cloudflare.com *.paypal.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com https://api.hubspot.com https://forms.hubspot.com https://bam.nr-data.net https://js-na1.hs-scripts.com https://js.hubspotfeedback.com forms.hscollectedforms.net https://stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.fonts.googleapis.com *.b-cdn.net *.topalovic.rs data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.meetanshi.com meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.addthis.com *.b-cdn.net *.topalovic.rs *.pinterest.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png *.meetanshi.com meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.cdn.klarna.com *.facebook.net *.b-cdn.net *.topalovic.rs *.facebook.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.pinterest.com *.cdninstagram.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com *.meetanshi.com meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.facebook.net *.b-cdn.net *.topalovic.rs *.pinterest.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.b-cdn.net *.topalovic.rs 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io *.meetanshi.com meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.googleapis.com *.addthis.com *.b-cdn.net *.topalovic.rs *.graph.instagram.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com fonts.googleapis.com *.fontawesome.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.getalma.eu *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://www.googletagmanager.com/ *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com maps.googleapis.com maps.gstatic.com tile.openstreetmap.org docs.maptiler.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ 'self' data: *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com cdn.jsdelivr.net maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com *.google.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.jsdelivr.net fonts.googleapis.com unpkg.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.getalma.eu *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=2b14ce6c-9b09-4f1c-8799-6171806c70f2; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' twofeet.com.br *.twofeet.com.br wake-components.fbitsstatic.net twofeet.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.googleadservices.com googleadservices.com td.doubleclick.net *.doubleclick.net *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.twofeet.com.br twofeet.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src staticw2.yotpo.com *.yotpo.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.yotpo.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com www.vismasignforms.com uittokalusto.shard.fi policy.app.cookieinformation.com dapi.videoly.co *.yotpo.com online.avarda.org stage.avarda.org https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com *.cloudfront.net www.google.fi pagead2.googlesyndication.com cdn2.hubspot.net static.paytrail.com resources.paytrail.com p.yotpo.com yotpo-editor-production.s3.amazonaws.com v2assets.zopim.io dapi.videoly.co *.yotpo.com online.avarda.org stage.avarda.org https://cdn.flbx.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com widget-mediator.zopim.com code.tidio.co policy.app.cookieinformation.com t.myvisitors.se static.zdassets.com connect.getflowbox.com staticw2.yotpo.com api.custobar.com script.custobar.com dapi.videoly.co s2.adform.net api.videoly.co *.yotpo.com online.avarda.org stage.avarda.org https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com staticw2.yotpo.com *.yotpo.com *.googleapis.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ cdn.flbx.io static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com www.google.fi www.google.com pagead2.googlesyndication.com zendesk-eu.my.sentry.io wss://widget-mediator.zopim.com scone-pa.clients6.google.com policy.app.cookieinformation.com region1.analytics.google.com ekr.zdassets.com uittokalustohelp.zendesk.com staticw2.yotpo.com gateway.getflowbox.com a.getflowbox.com api.custobar.com *.yotpo.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com consent.app.cookieinformation.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src d2wzl9lnvjz3bh.cloudfront.net d2oarllo6tn86.cloudfront.net inpref.com *.inpref.com fi1.frosmo.com *.fi1.frosmo.com widget-mediator.zopim.com googleads.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es https://store.plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es secure.payu.com merch-prod.snd.payu.com https://store.plumrocket.com api.razorpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es static.payu.com cdn.razorpay.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.avada.io secure.payu.com secure.snd.payu.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es secure.payu.com merch-prod.snd.payu.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com fonts.googleapis.com https://widgets.trustedshops.com applepay.cdn-apple.com *.gstatic.com 'self' data: client.crisp.chat data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com js.mollie.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ js.mollie.com *.payplug.com *.dalenys.com *.googleapis.com game.crisp.chat 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://secure-magenta.dalenys.com *.hsforms.net *.hsforms.com *.googleapis.com *.gstatic.com *.google.com https://www.mollie.com 'self' data: *.crisp.chat integrations.etrusted.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com js.mollie.com https://browser.sentry-cdn.com *.disqus.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.hsforms.net *.hsforms.com *.googleapis.com *.google.com *.gstatic.com smartarget.online client.crisp.chat widgets.trustedshops.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://secure-magenta.dalenys.com *.googleapis.com *.gstatic.com client.crisp.chat integrations.etrusted.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com client.crisp.chat 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com maps.googleapis.com https://maps.googleapis.com https://player.vimeo.com js.mollie.com api-adresse.data.gouv.fr https://*.ingest.sentry.io *.trustedshops.com *.etrusted.com https://integrations.etrusted.site t.elasticsuite.io *.hsforms.net *.hsforms.com *.googleapis.com *.google.com *.google-analytics.com api.smartarget.online *.crisp.chat *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.gstatic.com 'self' data: *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de cdn.doofinder.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.google.com *.google.com.co c.bing.com *.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com s7.addthis.com *.avada.io https://player.vimeo.com https://www.youtube.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.doubleclick.net analytics.google.com cdn.connectif.cloud *.hotjar.com *.clarity.ms connect.facebook.net *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.doofinder.com wss://*.doofinder.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com ekr.zdassets.com/ https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com.co analytics.google.com *.clarity.ms stats.g.doubleclick.net am1-api.connectif.cloud content.hotjar.io *.hotjar.com *.facebook.com *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.fontawesome.com www.googleapis.com www.gstatic.com *.zdassets.com https://static.micuentaweb.pe/static/ *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://secure.micuentaweb.pe/vads-payment/ https://api.micuentaweb.pe/api-payment/ https://static.micuentaweb.pe/static/ https://seo.mageplaza.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.addthis.com www.doubleclick.net www.google.com *.weltpixel.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com api.mercadopago.com events.mercadopago.com https://secure.micuentaweb.pe/vads-payment/ https://static.micuentaweb.pe/static/ *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.uber.com *.ubereats.com www.facebook.com www.facebook.net *.metricool.com www.google.com.ar *.zdassets.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com api.mercadopago.com events.mercadopago.com https://secure.micuentaweb.pe/static/latest/images/type-carte/ https://static.micuentaweb.pe/static/ https://secure.micuentaweb.pe/vads-payment/ *.gstatic.com *.facebook.com *.reddit.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.aptrinsic.com *.metricool.com *.clarity.ms www.facebook.com api.yotpo.com www.facebook.net js-agent.newrelic.com recostream.com *.zdassets.com www.varsovienne.cl unpkg.com *.zendesk.com www.google.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com api.mercadopago.com events.mercadopago.com https://api.micuentaweb.pe/api-payment/ https://static.micuentaweb.pe/static/ https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.googleapis.com www.mailchimp.com *.zdassets.com https://static.micuentaweb.pe/static/ *.fontawesome.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net www.zdassets.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.zendesk.com *.zdassets.com k.clarity.ms api.yotpo.com www.google.com www.facebook.net connect.facebook.net www.googleapis.com unpkg.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com api.mercadopago.com events.mercadopago.com https://secure.micuentaweb.pe/vads-payment/ https://api.micuentaweb.pe/api-payment/ *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net www.aptrinsic.com www.newrelic.com www.demdex.net commerce.adobedc.net www.varsovienne.cl bam.nr-data.net www.google.com https://secure.micuentaweb.pe/vads-payment/ https://api.micuentaweb.pe/api-payment/ https://static.micuentaweb.pe/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://www.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.cookiebot.com *.googletagmamanger.com *.twitter.com https://*.google.com js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com https://*.gstatic.com magefan.com cm.magefan.com *.disqus.com www.magmodules.eu *.squeezely.tech i0.wp.com *.leef.nl *.linkedin.com *.varuvo.nl *.yourskin.nl *.zorghulpdrogist.nl *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://img.youtube.com *.sooqr.com *.spotlersearch.com https://www.mollie.com *.gstatic.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com https://*.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.disqus.com squeezely.tech www.squeezely.tech *.squeezely.tech *.clarity.ms cognito-identity.eu-central-1.amazonaws.com/ *.converterexperiments.com *.cookiebot.com *.corewebvitals.io developer.adobe.com *.facebook.net/ firehose.eu-central-1.amazonaws.com/ http://*.googleadservers.com *.google-analytics.com *.googlesyndication.com *.googletagmamanger.com *.hotjar.com *.licdn.com magento.com *.spotlersearch.com *.spotlersearchanalytics.com *.trustpilot.com *.zdassets.com *.zopim.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com *.sooqr.com spotlersearchanalytics.com js.mollie.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.googleapis.com *.sooqr.com *.spotlersearch.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com squeezely.tech *.squeezely.tech *.clarity.ms cognito-identity.eu-central-1.amazonaws.com firehose.eu-central-1.amazonaws.com *.linkedin.com *.zdassets.com *.zendesk.com *.zopim.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com *.sooqr.com *.spotlersearch.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://3adac9fa-e067-4112-86fb-a8b949bec21a.sansec.watch; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.addthis.com www.googletagmanager.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://static.buckaroo.nl https://meetanshi.com/media/logo.png https:/at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.alothemes.com *.magepow.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.alothemes.com *.magepow.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com downloads.mailchimp.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.addthis.com *.alothemes.com *.magepow.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.svea.com https://*.vipps.no https://*.trustly.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com static.addtoany.com vars.hotjar.com ct.pinterest.com checkoutapi.svea.com connect.facebook.net graph.facebook.com business.facebook.com *.trustpilot.com *.weltpixel.com *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://*.svea.com https://td.doubleclick.net/ td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.google.se merit.soliditet.se maps.gstatic.com maps.googleapis.com ct.pinterest.com s.pinimg.com www.google.co.uk px.ads.linkedin.com cookie-cdn.cookiepro.com *.trustpilot.net *.trustpilot.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com *.google.pl www.google.pl px4.ads.linkedin.com *.klaviyo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com static.addtoany.com maps.googleapis.com cookie-cdn.cookiepro.com static.zdassets.com script.hotjar.com static.hotjar.com snap.licdn.com s.pinimg.com checkoutapi.svea.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com *.trustpilot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.googletagmanager.com tagmanager.google.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://*.svea.com 'self' 'unsafe-inline' 'unsafe-eval' *.pod-29.zendesk.com https://pod-29.zendesk.com/sc/faye *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com *.trustpilot.com https://static.klaviyo.com tagmanager.google.com https://cdn.jsdelivr.net https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com www.facebook.com *.facebook.net stats.g.doubleclick.net pagead2.googlesyndication.com ct.pinterest.com cookie-cdn.cookiepro.com vesaniswedenab.zendesk.com geolocation.onetrust.com *.analytics.google.com connect.facebook.net graph.facebook.com business.facebook.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval' *.pod-29.zendesk.com https://pod-29.zendesk.com/sc/faye *.zendesk.com *.hotjar.io *.klaviyo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' cdnjs.cloudflare.com https://geowidget.easypack24.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com *.addthis.com js.mollie.com pay.google.com apm.przelewy24.pl 'self' https://pudofinder.dpd.com.pl/ *.dpd.com.pl *.user.com www.googletagmanager.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.cdninstagram.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.mollie.com static.przelewy24.pl www.gstatic.com gstatic.com 'self' *.sysadvisors.pl https://cdn-cookieyes.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.instagram.com s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io *.shopify.com js.mollie.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.googletagmanager.com *.snrcdn.net *.snrbox.com *.ekomiapps.de unsafe-inline *.adobedtm.com *.googleadservices.com *.google-analytics.com www.google.com *.easypack24.net *.inpost.pl *.sysadvisors.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com *.ruch-osm.sysadvisors.pl cdnjs.cloudflare.com https://cdn-cookieyes.com *.user.com *.allekurier.pl *.facebook.net https://polyfill-fastly.io https://browser.sentry-cdn.com https://geowidget.easypack24.net tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' *.sysadvisors.pl *.ruch-osm.sysadvisors.pl cdnjs.cloudflare.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com ekr.zdassets.com/ https://get.geojs.io *.avada.io sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com 'self' *.sysadvisors.pl *.user.com wss://vynngroup.user.com https://cdn-cookieyes.com *.cookieyes.com https://*.ingest.sentry.io *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.modo.com.ar data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com *.doubleclick.net mercadopago.com.ar 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.google.com *.google.fr *.google.ie www.google.cl www.google.com.ni www.google.es www.google.com.co www.google.com.tw www.google.com.sg *.facebook.com www.google.nl www.google.co.in *.playdigital.com.ar www.google.com.bo www.google.co.uk www.google.lk www.google.com.do www.google.by www.google.com.eg www.google.com.gt www.google.co.ma www.google.com.br www.google.ro www.google.com.bd www.google.com.sv www.google.fi www.google.com.ph www.google.com.pa www.google.co.ve www.google.ae www.google.com.au www.google.pl www.google.com.tr www.google.dk www.google.com.uy www.google.pt www.google.se www.google.com.pe www.google.com.mx www.google.com.ec www.google.hn www.google.ru www.google.me *.clarity.ms www.google.co.cr www.google.it www.google.ch www.google.dz www.google.com.py www.google.com.vn www.google.co.bw www.google.com.pr *.vitamin-way.com www.google.com.ar *.doubleclick.net www.google.ca www.google.com.cu www.google.co.jp *.modo.com.ar www.google.gr www.google.de data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.clarity.ms *.freshworks.com *.modo.com.ar *.doubleclick.net *.cloudflareinsights.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.freshworks.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com *.google-analytics.com *.doubleclick.net https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ www.google.nl *.freshworks.com www.google.com.bd www.google.ch *.clarity.ms www.google.com.cu www.google.hn www.google.com.gt www.google.pt www.google.hu www.google.com.mx www.google.com.gh www.google.com.ar www.google.co.uk www.google.fr www.google.co.in www.google.com.py www.google.com.ni www.google.ro www.google.es www.google.co.jp www.google.co.bw www.google.com.br www.google.com.tw www.google.com.pe www.google.dk www.google.com.au www.google.ru www.google.pl *.facebook.com www.google.com.vn www.google.ca www.google.de www.google.co.ve www.google.com.sg www.google.com.eg *.playdigital.com.ar www.google.it www.google.com.bh *.amplitude.com www.google.com.sv www.google.cl www.google.com.pa www.google.is www.google.com.ec www.google.co.cr www.google.com.do www.google.com.uy www.google.com.ph www.google.com.bo www.google.com.co 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://fb1042e5-5a1a-4870-abf9-dbe8a3decb09.sansec.watch/; report-to report-endpoint; 1 style-src-elem *.markizeta.info *.doofinder.com doofinder.com *.doubleclick.net *.googleadservices.com 'unsafe-inline' *.s121.mhost.eu *.gr-cdn.com us-an.gr-cdn.com *.consentmanager.net *.gr-wcon.com *.fontawesome.com martom-hurtownia.pl withome.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.facebook.com *.gstatic.com fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl izi.inpost.pl *.trustedshops.com *.it4dev.net.pl *.martom.it4dev.pl https://*.martom.it4dev.pl https://dev.martom.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com www.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.stripe.com integrations.etrusted.com; script-src-elem *.markizeta.info *.doofinder.com doofinder.com *.doubleclick.net *.googleadservices.com *.s121.mhost.eu *.hotjar.com cdnjs.cloudflare.com *.youtube.com withome.pl 'unsafe-inline' *.gr-cdn.com us-an.gr-cdn.com *.consentmanager.net *.gr-wcon.com *.facebook.net *.lightwidget.com *.fontawesome.com martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.facebook.com *.gstatic.com fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl izi.inpost.pl *.trustedshops.com *.it4dev.net.pl *.martom.it4dev.pl https://*.martom.it4dev.pl https://dev.martom.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com www.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.stripe.com integrations.etrusted.com; script-src-attr *.markizeta.info *.s121.mhost.eu *.doubleclick.net *.googleadservices.com withome.pl *.gr-cdn.com us-an.gr-cdn.com 'unsafe-inline' *.fontawesome.com martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.facebook.net *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.lightwidget.com *.gstatic.com *.facebook.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl *.trustedshops.com *.it4dev.net.pl https://dev.martom.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl; font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com withome.pl *.markizeta.info *.fontawesome.com *.adobe.com martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com geowidget.easypack24.net geowidget.inpost.pl widgets.trustedshops.com static-app.connect.trustedshops.com static-app.connect-qa.trustedshops.com *.klarnacdn.net *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.trustedshops.com https://cdnjs.cloudflare.com https://geowidget.easypack24.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.markizeta.info *.googleadservices.com withome.pl markizeta.s121.mhost.eu *.consentmanager.net markizeta.info *.fontawesome.com *.adobedtm.com *.google.pl *.cardinalcommerce.com 'self' assets.adobedtm.com *.it4dev.net.pl *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://geowidget-app.inpost.pl/ https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com cdn.doofinder.com *.markizeta.info *.googleadservices.com withome.pl markizeta.s121.mhost.eu *.consentmanager.net markizeta.info *.fontawesome.com *.google.pl *.cardinalcommerce.com assets.adobedtm.com *.it4dev.net.pl *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com *.trustedshops.com tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com cdn.doofinder.com *.markizeta.info *.googleadservices.com *.s121.mhost.eu withome.pl 'self' *.gr-cdn.com us-an.gr-cdn.com *.fontawesome.com *.cardinalcommerce.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.lightwidget.com *.easypack24.net *.inpost.pl https://widgets.trustedshops.com *.it4dev.net.pl *.martom.it4dev.pl martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com https://dev.martom.it4dev.pl *.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.trustedshops.com mapa.orlenpaczka.pl https://cdnjs.cloudflare.com js.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://geowidget.easypack24.net *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.doofinder.com 'self' *.markizeta.info martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com geowidget.easypack24.net geowidget.inpost.pl widgets.trustedshops.com static-app.connect.trustedshops.com static-app.connect-qa.trustedshops.com *.klarnacdn.net *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline https://geowidget.easypack24.net https://geowidget.inpost.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.doofinder.com wss://*.doofinder.com *.markizeta.info *.googleadservices.com 'self' *.hotjar.com wss://*.hotjar.com b2b.markizeta.info *.hotjar.io *.consentmanager.net *.getresponse.com *.fontawesome.com *.adobe.com martom-hurtownia.pl *.martom-hurtownia.pl martom-shop.com *.martom-shop.com *.adobedtm.com *.cardinalcommerce.com *.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl *.trustedshops.com *.it4dev.net.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl nominatim.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com google.com *.openstreetmap.org t.elasticsuite.io https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; default-src 'self' https://*.motorcar.com https://*.ebizautos.media; img-src *; script-src 'self' 'unsafe-inline' *; font-src *; media-src *; frame-src *; manifest-src 'self'; style-src 'self' 'unsafe-inline' *; connect-src https://*; object-src 'none'; worker-src 'none'; base-uri 'self'; report-uri https://ebizautos.report-uri.com/r/t/csp/reportOnly; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' yoraatacado.com.br *.yoraatacado.com.br wake-components.fbitsstatic.net yoraatacado.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gstatic.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.botmaker.com *.getresponse.com *.production.usebeon.io *.g.doubleclick.net *.clarity.ms *.usebeon.io *.rr.skeepers.io clarity.ms c.usebeon.io *.googleadservices.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com analytics.tiktok.com google.com.br *.gr-cdn-e.com *.gr-cdn.com *.gr-wcon.com *.tiktok.com *.doubleclick.net *.googleapis.com *.fbitsstatic.net wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com *.bwmodas.com.br plugin.bwmodas.com.br api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.yoraatacado.com.br yoraatacado.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.playground.klarna.com cdn.klarna.com www.google.com js.klarna.com youtube.com www.youtube.com *.cookiebot.com *.klarna.com *.kustom.co *.issuu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com *.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.clerk.io *.algolia.net *.algolianet.com polyfill.io cdn.klarna.com x.klarnacdn.net *.playground.klarna.com tagmanager.google.com www.google-analytics.com ssl.google-analytics.com www.google.com www.gstatic.com *.cookiebot.com cdn.clerk.io api.clerk.io vjs.zencdn.net player.vimeo.com js.playground.klarna maps.googleapis.com *.klarna.com *.kustom.co *.hotjar.com *.emailplatform.com *.sleeknote.com *.klarnaservices.com s.zavanna.no bat.bing.com secure.authorize.net test.authorize.net *.googleadservices.com js.braintreegateway.com *.paypal.com 1eafapi.cardinalcommerce.com.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com widget.postenlabs.no cdn.clerk api.clerk *.paypalobjects.com *.snapchat.com sc-static.net *.klarnacdn.net songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.playground.klarnaevt.com *.cookiebot.com *.klarnaevt.com *.klarnauserservices.com *.klarnaservices.com maps.googleapis.com *.klarna.com *.kustom.co s.zavanna.no stats.g.doubleclick.net *.snapchat.com bat.bing.com *.klarnacdn.net x.klarnacdn.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; font-src https://pim.zavanna.no/ fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com x.klarnacdn.net maxcdn.bootstrapcdn.com s.zavanna.no data: *.klarnacdn.net data: 'self' 'unsafe-inline'; style-src https://pim.zavanna.no/ *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io tagmanager.google.com vjs.zencdn.net maxcdn.bootstrapcdn.com x.klarnacdn.net s.zavanna.no *.klarnacdn.net assets.braintreegateway.com 'self' 'unsafe-inline'; img-src https://pim.zavanna.no/ assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.nl *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://cdn.clerk.io *.clerk.io cdn.klarna.com *.playground.klarnaevt.com ssl.gstatic.com www.gstatic.com *.cookiebot.com eu.playground.klarnaevt.com maps.gstatic.com maps.googleapis.com *.klarnaservices.com *.kustom.co s.zavanna.no bat.bing.com *.google.com *.google.pl *.snapchat.com sc-static.net pim.zavanna.no *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; report-uri /csp/report; report-to report-endpoint; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.googletagmanager.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.paypalobjects.com t.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com www.googleadservices.com www.google-analytics.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net www.googleadservices.com www.google-analytics.com connect.facebook.net graph.facebook.com business.facebook.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com www.google-analytics.com connect.facebook.net graph.facebook.com business.facebook.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://maps.googleapis.com https://app.cobrowser.com data: 'self' 'unsafe-inline'; form-action *.paypal.com https://mcheckout.mstart.hr/iCheckOutX/v1/icheckout/confirm.xhtml https://mcheckouttest.mstart.hr:9443/iCheckOutX/v1/icheckout/confirm.xhtml https://form.wspay.biz/authorization.aspx https://formtest.wspay.biz/authorization.aspx googletagmanager.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://widget-cdn.boxnow.hr https://widget-v5.boxnow.hr *.weltpixel.com https://service.force.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://mstart.hr/theme/img/png/logo.png magefan.com cm.magefan.com maps.googleapis.com https://preprod-u1974--preprod.cs173.force.com https://u1974--preprod.my.salesforce.com https://u1974--preprod--c.visualforce.com https://zoocity.secure.force.com https://www.wspay.info/layout/logo.png https://www.facebook.com https://app.cobrowser.com www.google.hr www.facebook.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.g.doubleclick.net *.google.com *.openstreetmap.org *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://widget-cdn.boxnow.hr https://widget-v5.boxnow.hr https://dsp-media.eskimi.com/ maps.googleapis.com https://service.force.com https://*.salesforceliveagent.com https://u1974--preprod.my.salesforce.com https://d.la3-c1cs-cdg.salesforceliveagent.com https://zoocity.my.salesforce.com https://d.la3-c2-fra.salesforceliveagent.com https://static.lightning.force.com https://zoocity.secure.force.com https://d.la1-core1.sfdc-yzvdd4.salesforceliveagent.com https://app.cobrowser.com https://connect.facebook.net *.googletagmanager.com tagmanager.google.com ssl.google-analytics.com dashboard.trustprofile.com https://www.googletagmanager.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://maps.googleapis.com https://service.force.com https://preprod-u1974--preprod.cs173.force.com https://zoocity.secure.force.com https://app.cobrowser.com googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://app.cobrowser.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://mcheckout.mstart.hr/iCheckOutX/v1/icheckout/confirm.xhtml https://mcheckouttest.mstart.hr:9443/iCheckOutX/v1/icheckout/confirm.xhtml maps.googleapis.com https://connect.facebook.net https://preprod-u1974--preprod.cs173.force.com https://zoocity.secure.force.com https://secure.wspay.biz/api/services/processpayment https://test.wspay.biz/api/services/processpayment https://app.cobrowser.com *.googletagmanager.com *.g.doubleclick.net https://www.google-analytics.com map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' data: https://www.google-analytics.com https://stats.g.doubleclick.net; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://www.google-analytics.com https://analytics.google.com; frame-src 'self' https://www.googletagmanager.com https://td.doubleclick.net; worker-src 'self' blob:; 1 font-src *.cloudflare.com *.typekit.net *.trustedshops.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com *.accessibe.com bid.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.cloudflare.com https://cdn.klarna.com *.bing.com *.google.com *.google.co.us *.google.us *.google.co.in *.paypal.com *.blueconic.net https://s.ytimg.com acsbapp.com *.acsbapp.com *.usercentrics.eu googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com store.paradoxlabs.com *.yotpo.com 'self' 'unsafe-inline'; script-src *.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co api.comapi.com webchat.dotdigital.com *.blueconic.net *.newrelic.com *.bing.com *.gstatic.com *.nr-data.net *.cloudflare.com *.paypal.com *.authorize.net *.omtrdc.net www.googleadservices.com acsbapp.com *.acsbapp.com acsbap.com *.acsbap.com *.trustedshops.com *.usercentrics.eu googleads.g.doubleclick.net analytics.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.typekit.net acsbapp.com *.acsbapp.com *.plugins.blueconic.net *.blueconic.net *.trustedshops.com *.usercentrics.eu *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.comapi.com webchat.dotdigital.com infiniteelectronics.blueconic.net *.cloudflare.com *.acsbapp.com *.demdex.net *.cardinalcommerce.com *.comapi.com *.authorize.net *.adobedtm.com *.paypal.com cdn.acsbapp.com www.google-analytics.com www.googleadservices.com www.paypalobjects.com *.google.com *.google.co.us *.google.us *.google.co.in *.doubleclick.net bam.nr-data.net acsbap.com *.acsbap.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.microvision.com; script-src 'self' 'unsafe-inline' *.jobvite.com *.onlyfy.jobs *.googletagmanager.com 'unsafe-eval' https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com *.vimeo.com www.youtube.com; object-src 'none'; font-src 'self' data:; style-src 'self' 'unsafe-inline'; img-src 'self' data: *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.com.br *.google.com.my *.google.com.hk *.google.com.ng *.google.com.pk *.google.com.uk *.google.de *.google.it *.google.fr *.google.at *.google.ch *.google.ca *.google.co.ao *.google.co.nz *.google.co.jp *.google.co.in https://www.google.com https://google.com i.ytimg.com; connect-src 'self' *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.com.br *.google.com.my *.google.com.hk *.google.com.ng *.google.com.pk *.google.com.uk *.google.de *.google.it *.google.fr *.google.at *.google.ch *.google.ca *.google.co.ao *.google.co.nz *.google.co.jp *.google.co.in noembed.com; frame-src 'self' *.jobvite.com *.onlyfy.jobs https://bid.g.doubleclick.net https://td.doubleclick.net *.vimeo.com www.youtube.com www.youtube-nocookie.com; report-uri https://sentry.networkteam.com/api/321/security/?sentry_key=86c8eb4a595a42448a455afac3f49ef6 1 font-src *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.bing.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.google.com *.doubleclick.net *.facebook.com secure.pay1.de payments.amazon.de jsctool.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com cdn.doofinder.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com magefan.com cm.magefan.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net cookie-cdn.cookiepro.com www.google.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com cdn.doofinder.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com *.googleapis.com *.google.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io cookie-cdn.cookiepro.com widgets.trustedshops.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.doofinder.com https://fonts.googleapis.com *.fontawesome.com *.google.com d.ratepay.com d.payla.io dr.payla.io maxcdn.bootstrapcdn.com cookie-cdn.cookiepro.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doofinder.com wss://*.doofinder.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://ipinfo.io https://*.gstatic.com https://*.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com payments.amazon.de d.ratepay.com jsctool.com cookie-cdn.cookiepro.com stats.g.doubleclick.net geolocation.onetrust.com privacyportal.cookiepro.com www.google.com google.de *.google.de *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-+Z9A4rBdoJKPM3x4R75RW5utAq4=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com *.global-e.com *.amazonaws.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.infusionsoft.app *.global-e.com *.addthis.com *.sharethis.com *.hotjar.com www.commercepartnerhub.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.infusionsoft.app https://r.fidelid.com https://pixel.voltn.com *.shopperapproved.com *.google.com wateranywhere.com *.wateranywhere.com *.amazonaws.com *.authorize.net *.bing.com *.clarity.ms *.sharethis.com *.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ flagpedia.net store.paradoxlabs.com assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://container.pepperjam.com https://lz393.infusionsoft.com http://www.upsellit.com http://static.criteo.net https://static.traversedlp.com https://googleads.g.doubleclick.net https://js.adsrvr.org https://www.google.com *.hotjar.com https://script.crazyegg.com https://static.zdassets.com *.shopperapproved.com https://translate.google.com https://translate.googleapis.com *.mailchimp.com *.list-manage.com *.addthis.com *.addthisedge.com *.pinterest.com *.googletagmanager.com *.bglobale.com *.cloudflare.com chimpstatic.com *.global-e.com *.comodo.com *.bing.com *.authorize.net *.clarity.ms *.sharethis.com *.doubleclick.net *.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com http://fonts.googleapis.com https://fonts.googleapis.com https://fonts.gstatic.com *.typekit.net https://translate.google.com https://translate.googleapis.com *.global-e.com *.bglobale.com *.bootstrapcdn.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com wss://widget-mediator.zopim.com https://shopper.shop.pe https://gadgetguard.zendesk.com *.addthis.com *.clarity.ms *.sharethis.com *.hotjar.com *.googleadservices.com *.doubleclick.net *.zdassets.com *.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.gstatic.com maps.googleapis.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src http://fonts.googleapis.com https://fonts.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com; script-src 'self' 'nonce-673dbce4-90b2-46d6-9bbd-e0d733393cbd' 'nonce-a92edb51-a967-4845-95ae-84212c30df23' 'nonce-74d623f7-b0fa-47d7-9417-f15c244bad72' 'nonce-cabd0637-b4b1-49c4-8abd-3fa94a551e1c' 'nonce-d95029a9-6536-41ab-bd21-5eaa4b58a267' 'nonce-6ada93ef-8449-4da6-af33-fe0f9d054d6d' 'nonce-cb1e2492-b160-469b-80e6-310cfcc9d7d9' 'nonce-84e06150-a96d-48f2-a477-50338d992d39' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com *.checkout.visa.com *.fundraiseup.com *.paypal.com *.paypalobjects.com *.plaid.com *.src.mastercard.com *.stripe.com cdn.fundraiseup.com m.stripe.network pay.google.com *.googletagmanager.com api.olark.com cdn-ukwest.onetrust.com knrpc.olark.com s3.amazonaws.com/downloads.mailchimp.com/js/mc-validate.js static.olark.com; script-src-elem 'self' 'unsafe-inline' *.checkout.visa.com *.fundraiseup.com *.paypal.com *.paypalobjects.com *.plaid.com *.src.mastercard.com *.stripe.com cdn.fundraiseup.com m.stripe.network pay.google.com *.googletagmanager.com api.olark.com cdn-ukwest.onetrust.com knrpc.olark.com s3.amazonaws.com/downloads.mailchimp.com/js/mc-validate.js static.olark.com bat.bing.com connect.facebook.net www.google.com googleads.g.doubleclick.net c5.adalyser.com *.gstatic.com cdn-ukwest.onetrust.com; style-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com 'unsafe-inline' careinternational.org.uk careinternationaluk.ams3.cdn.digitaloceanspaces.com https://careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com cdn-images.mailchimp.com cdn-images.mailchimp.com/embedcode/classic-061523.css static.olark.com; style-src-attr 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com 'unsafe-inline' static.olark.com careinternational.org.uk careinternationaluk.ams3.cdn.digitaloceanspaces.com; style-src-elem 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com 'unsafe-inline' careinternational.org.uk careinternationaluk.ams3.cdn.digitaloceanspaces.com https://careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com cdn-images.mailchimp.com static.olark.com; object-src 'none'; base-uri 'self'; connect-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com *.checkout.visa.com *.fundraiseup.com *.mastercard.com *.paypal.com *.paypalobjects.com *.plaid.com *.stripe.com api.addressy.com fndrsp-checkout.net fndrsp.net google.com/pay knrpc.olark.com pay.google.com cdn-ukwest.onetrust.com geolocation.onetrust.com privacyportal-uk.onetrust.com adservice.google.com *.google.co.ug *.google.com *.analytics.google.com *.onetrust.com at.bing.com *.google.com stats.g.doubleclick.net adservice.google.com *.google.co.uk adservice.google.com www.facebook.com; font-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com *.fundraiseup.com *.stripe.com static.olark.com; frame-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com platform.twitter.com player.vimeo.com syndication.twitter.com w.soundcloud.com www.youtube.com www.youtube-nocookie.com/ static.olark.com *.fundraiseup.com *.stripe.com *.src.mastercard.com *.checkout.visa.com *.plaid.com *.paypal.com pay.google.com www.google.com *.doubleclick.net *.paypalobjects.com *.google.com; img-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com 'unsafe-inline' abs.twimg.com pbs.twimg.com platform.twitter.com syndication.twitter.com ton.twimg.com www.facebook.com www.google.co.uk www.google.com data: *.fundraiseup.com ucarecdn.com pay.google.com *.paypalobjects.com log.olark.com t.paypal.com cdn-ukwest.onetrust.com bat.bing.com ad.doubleclick.net c5.adalyser.com *.google.es *.googletagmanager.com *.gstatic.com; manifest-src 'self' ciuk.test ciuk.hactar.work *.careinternational.org.uk https://careinternationaluk.ams3.cdn.digitaloceanspaces.com; media-src 'self'; worker-src 'self'; report-uri /csp/report/; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline' 'unsafe-eval'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' 'unsafe-inline' 'unsafe-eval'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://www.magezon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.heimkinowelt.at www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline' 'unsafe-eval'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com http://www.googleadservices.com https://devdocs.magento.com https://magento.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com/ *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://fonts.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline' 'unsafe-eval'; media-src *.adobe.com 'self' 'unsafe-inline' 'unsafe-eval'; manifest-src 'self' 'unsafe-inline' 'unsafe-eval'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://devdocs.magento.com *.cloudflare.com *.twitter.com *.twimg.com google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; connect-src https: wss:; report-uri /csp-report 1 font-src www.paypalobjects.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.deadgoodundies.com https://fonts.gstatic.com 'self' data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com blog.deadgoodundies.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.deadgoodundies.com www.facebook.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io blog.deadgoodundies.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com blog.deadgoodundies.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.deadgoodundies.com vars.hotjar.com www.google.com https://player.vimeo.com https://www.youtube-nocookie.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.trustpilot.com *.weltpixel.com blog.deadgoodundies.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.deadgoodundies.com www.google.co.uk services.postcodeanywhere.co.uk blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://firebasestorage.googleapis.com blog.deadgoodundies.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.deadgoodundies.com porjs.com static.hotjar.com script.hotjar.com www.google.com www.gstatic.com *.cloudfront.net services.postcodeanywhere.co.uk connect.facebook.net *.onetrust.com *.pcapredict.com https://player.vimeo.com https://www.youtube.com unpkg.com *.unpkg.com cdnjs.cloudflare.com imagekit.io *.imagekit.io *.avada.io *.shopify.com *.trustpilot.com blog.deadgoodundies.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.deadgoodundies.com services.postcodeanywhere.co.uk https://fonts.googleapis.com http://fonts.googleapis.com unpkg.com *.unpkg.com imagekit.io *.imagekit.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.trustpilot.com blog.deadgoodundies.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: blog.deadgoodundies.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.deadgoodundies.com www.google-analytics.com stats.g.doubleclick.net in.hotjar.com services.postcodeanywhere.co.uk webhooks.remarkety.com *.onetrust.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io unpkg.com *.unpkg.com imagekit.io *.imagekit.io https://get.geojs.io *.avada.io blog.deadgoodundies.com 'self' 'unsafe-inline'; child-src blog.deadgoodundies.com http: https: blob: 'self' 'unsafe-inline'; default-src blog.deadgoodundies.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.google.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.youtube.com *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms *.twitter.com *.twimg.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net 'self' data: klarna.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflareinsights.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms *.twitter.com *.consensu.org *.sharethis.com klarna.com *.link.com *.amazon.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.google.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms *.google.rs *.bing.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com https://static.cloudflareinsights.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.sharethis.com *.avada.io *.shopify.com *.hsforms.net *.hsforms.com *.stripe.network klarna.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.google.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.youtube.com *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms downloads.mailchimp.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net *.stripe.network *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.youtube.com *.doubleclick.net *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.twitter.com *.twimg.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.sharethis.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com klarna.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.cloudflareinsights.com *.troentorp.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.feefo.com *.gleamjs.io *.gleam.io *.klaviyo.com *.google.com *.authorize.net *.cloudfront.net *.google-analytics.com *.geissele.com *.rafflecopter.com *.bootstrapcdn.com *.paradoxlabs.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.facebook.net *.twitch.tv *.cenpos.com *.cenpos.net *.youtube.com *.stripe.com *.stripecdn.com *.gtm.js *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.twitter.com nitropack.io *.nitrocdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.thewhoshop.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ipg-online.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com www.thewhoshop.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com www.thewhoshop.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.addthis.com *.trustpilot.com *.twitter.com *.vimeo.com *.doubleclick.net nitropack.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com www.thewhoshop.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com *.google-analytics.com *.twitter.com *.contentsquare.net nitropack.io *.nitrocdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com www.thewhoshop.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.addthis.com *.googleapis.com *.cloudflare.com *.fontawesome.com *.google-analytics.com googletagmanager.com graph.facebook.com *.gstatic.com *.moatads.com *.trustpilot.com widgets.pinterest.com *.contentsquare.com *.contentsquare.net cdn.tailwindcss.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com www.thewhoshop.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.twitter.com cdn.tailwindcss.com nitropack.io cdnjs.cloudflare.com *.nitrocdn.com cdn.jsdelivr.net assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com www.thewhoshop.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.thewhoshop.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.twitter.com *.contentsquare.net *.google-analytics.com *.nitrocdn.com nitropack.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com www.thewhoshop.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.thewhoshop.com http: https: blob: 'self' 'unsafe-inline'; default-src www.thewhoshop.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; report-uri https://csp-reports.security.fastly-edge.com/r?id=wwvCVZD6aUBHQbAAjW8pVn&inv=0 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: *.google.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.google.com/ https://www.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://player.vimeo.com https://www.youtube-nocookie.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com https://www.magezon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com cdn.mundipagg.com api.pagar.me guarantee-cdn.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.avada.io *.shopify.com *.google.com/ player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://player.vimeo.com https://www.youtube.com *.openpix.com.br *.openpix.dev *.sentry.io *.ingest.sentry.io https://plugin.openpix.dev/v1/openpix-dev.js https://api.openpix.dev https://graphql.openpix.dev/openpix/graphql https://graphql.openpix.dev/shopper/graphql https://plugin.openpix.com.br/v1/openpix.js https://api.openpix.com.br/openpix/graphql https://api.openpix.com.br/shopper/graphql *.pagseguro.com.br *.pagseguro.com 3ds2.pagar.me 3ds2-sdx.pagar.me *.google.com *.cloudflare.com guarantee-cdn.com ajax.googleapis.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com *.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src blob: *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://www.google-analytics.com *.googleapis.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.pagseguro.com.br *.pagseguro.com api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br *.google.com google.com pay.sandbox.google.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' metrics.mastercard.com smetrics.mastercard.com assets.adobedtm.com cdn.cookielaw.org www.onetrust.com onetrust.com geolocation.onetrust.com privacyportal.onetrust.com www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com cdn.jsdelivr.net https://asset.forms.mastercard.com https://assets.adobedtm.com https://cdn.cookielaw.org https://play.vidyard.com https://unpkg.com platform.instagram.com platform.twitter.com; script-src-attr 'self' 'unsafe-inline' 'unsafe-hashes'; script-src-elem 'self' 'unsafe-inline' metrics.mastercard.com smetrics.mastercard.com assets.adobedtm.com cdn.cookielaw.org www.onetrust.com onetrust.com geolocation.onetrust.com privacyportal.onetrust.com st.dynamicyield.com go.mastercardservices.com pi.pardot.com snap.licdn.com assets.adobetm.com api-mastercard-dxp.nd.nudatasecurity.com s.go-mpulse.net 6sc.co 6sense.com *.6sc.co *.6sense.com www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com cdn.jsdelivr.net https://asset.forms.mastercard.com https://assets.adobedtm.com https://cdn.cookielaw.org https://play.vidyard.com https://unpkg.com platform.instagram.com platform.twitter.com; style-src 'self' 'unsafe-inline' https://asset.forms.mastercard.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://cdn.dynamicyield.com https://asset.forms.mastercard.com; frame-ancestors 'self' 1 default-src 'self'; base-uri 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' 'report-sample' https://cdn.jsdelivr.net https://cdn.userway.org https://cdnjs.cloudflare.com https://code.jquery.com https://*.hs-scripts.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hubspot.com https://js.usemessages.com https://*.fontawesome.com https://www.googletagmanager.com https://www.solidcomponents.com; style-src 'self' 'unsafe-inline' 'report-sample' https://cdn.userway.org https://fonts.googleapis.com https://use.fontawesome.com https://www.solidcomponents.com; font-src 'self' data: https://fonts.gstatic.com https://ka-p.fontawesome.com https://use.fontawesome.com; connect-src 'self' https://api.hubspot.com https://api.userway.org https://api.weglot.com https://cdn.userway.org https://cta-service-cms2.hubspot.com https://*.fontawesome.com https://*.google-analytics.com https://www.solidcomponents.com; frame-src 'self' https://www.solidcomponents.com https://www.youtube.com https://open.spotify.com; img-src 'self' data: https://kitocrosbyprd.wpenginepowered.com https://cdn.userway.org https://perf-na1.hsforms.com https://track.hubspot.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://69160880d5a1b641687cf3e5.endpoint.csper.io?v=2; 1 default-src 'self' *.sbb.spk-berlin.de *.staatsbibliothek-berlin.de *.sbb.berlin; child-src 'none'; object-src 'none'; script-src http: https: 'nonce-nkWqQMMq3tsLjotF3qFHOdHV3rylKKJtO8PvtA6K5pk='; connect-src 'self' *.sbb.spk-berlin.de *.staatsbibliothek-berlin.de *.sbb.berlin; worker-src blob:; style-src 'self' 'unsafe-inline'; img-src 'self' *.sbb.spk-berlin.de *.staatsbibliothek-berlin.de *.sbb.berlin; font-src 'self'; base-uri 'self'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-SEdGusgFInOfCyq/mifQ9wT2ssw=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src www.paypalobjects.com https://*.gstatic.com *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.addthis.com https://www.sovendus-connect.com *.boxers.nl *.boxers.be *.sokken.nl *.sokken.be *.zwembroeken.nl *.shirts.nl https://www.facebook.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://belco-prod.s3-eu-central-1.amazonaws.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.hsforms.net *.hsforms.com 'self' data: https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://cdn.belco.io https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io sdk.copernica.com https://maps.googleapis.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.boxers.nl *.boxers.be *.sokken.nl *.sokken.be *.zwembroeken.nl *.shirts.nl d5yoctgpv4cpx.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.googleapis.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://cdn.jsdelivr.net *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com wss://chat.belco.io https://cdn.belco.io wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com sdk.copernica.com wss://sdk.copernica.com https://maps.googleapis.com https://player.vimeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://*.execute-api.eu-central-1.amazonaws.com https://www.facebook.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2B1ac1%3Egg%3E0%3B(rbpv5%3F.i~mm7-19b2a60cb10-0x1802#pd 1 frame-ancestors https://www.yamahabicycles.com/ https://www.yamahamotorsports.com/ ; default-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googleapis.com; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' ; connect-src 'self' ; upgrade-insecure-requests; block-all-mixed-content; report-uri https://b3d773270785b0680eb4a1152b5cb1a2.report-uri.io/r/default/csp/reportOnly; 1 font-src *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.payfabric.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com magento-cloudflare.jetrails.com *.payfabric.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com * *.ytimg.com *.payfabric.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com go.alpco.com pi.pardot.com snap.licdn.com *.crazyegg.com *.clarity.ms tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payfabric.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com * https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.payfabric.com *.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data:; frame-ancestors 'self'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com data: *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com https://www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.trustedshops.com *.instagram.com *.fbcdn.net https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.polyfill.io https://browser.sentry-cdn.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.avada.io *.trustedshops.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com https://get.geojs.io *.avada.io *.instagram.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com api.razorpay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com cdn.razorpay.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com lumberjack.razorpay.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.google.com https://*.gstatic.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://googleads.g.doubleclick.net https://ajax.googleapis.com https://platform.twitter.com https://code.jquery.com https://stackpath.bootstrapcdn.com; img-src 'self' 'unsafe-inline' data: https://cdn.jsdelivr.net https://*.googleadservices.com https://*.google.com https://*.google.nl https://*.googletagmanager.com https://*.google-analytics.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://syndication.twitter.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com/ https://fonts.googleapis.com https://stackpath.bootstrapcdn.com https://*.eurocris.org; font-src 'self' 'unsafe-inline' https://fonts.gstatic.com https://themes.googleusercontent.com; object-src 'none'; frame-src 'self' https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://*.twitter.com; connect-src 'self' https://*.google-analytics.com https://stats.g.doubleclick.net; 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com https://fonts.gstatic.com/ *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ariba.com *.coupahost.com *.t1cloud.com app.instapunchout.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.ariba.com *.coupahost.com *.t1cloud.com app.instapunchout.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com https://maps.google.com/ landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net stats.g.doubleclick.net tracker.metricool.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com tracker.metricool.com static.cloudflareinsights.com ssl.google-analytics.com tagmanager.google.com https://cdnjs.cloudflare.com/ landofcoder.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com/ *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com www.google.com stats.g.doubleclick.net www.google.com.tw *.google.com static.cloudflareinsights.com tracker.metricool.com landofcoder.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-0oxDjdubSj+F9euPjxszTgL4kdg=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; script-src 'self' *.salesforce.com 'report-sample'; style-src 'unsafe-inline' 'self' *.file.force.com *.salesforce.com *.visualforce.com:*; img-src *.force.com slack-mil-dev.com slack-imgs-mil-dev.com 'self' *.slack.com *.amazonaws.com blob: *.slack-imgs.com slack-imgs-gov.com *.slack-edge.mil *.salesforce-experience.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.slack-edge-gov.com *.salesforce.com *.twimg.com *.my-salesforce.com slack-imgs-gov-dev.com *.slack-edge.com slack-imgs.mil *.cloudinary.com data:; media-src 'self' *.salesforce.com; frame-src *.force.com *.quip.com *.arkoselabs.com 'self' *.youtube-nocookie.com *.youtube.co.uk *.cybersource.com *.youtube.com.br *.youtube.es *.salesforce-experience.com *.salesforceliveagent.com *.adis.ws *.sfdcfc.net *.youtube.ca *.youtube.ie *.cloudinary.com *.vidyard.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr *.forceusercontent.com *.youtube.com *.brightcove.net *.wistia.net *.salesforce.com *.youtube.nl *.youtube.pl; font-src *.force.com 'self' *.salesforce.com blob: data:; connect-src 'self' *.amazonaws.com *.salesforce.com api.salesforce.com *.api.salesforce.com wss://*.slack.com; report-to sfdc-csp-ep; report-uri https://csp-report.force.com/_/ContentDomainCSPNoAuth?type=mydomain 1 default-src 'none'; connect-src 'self' embedr.flickr.com geo.query.yahoo.com nominatim.openstreetmap.org api.github.com; font-src 'self'; form-action 'self' platform.twitter.com syndication.twitter.com www.paypal.com; frame-ancestors 'self'; frame-src 'self' blob: www.youtube.com w.soundcloud.com twitter.com platform.twitter.com syndication.twitter.com player.vimeo.com www.mixcloud.com www.dailymotion.com media.ccc.de bandcamp.com www.instagram.com; img-src data: blob: *; manifest-src 'self'; media-src https:; script-src 'self' blob: 'unsafe-eval' platform.twitter.com cdn.syndication.twimg.com widgets.flickr.com embedr.flickr.com www.instagram.com 'unsafe-inline' 'nonce-v1hT4CuuZF5iVrNOPPfi5ddu8Qn79bL5scbWCgclpe8='; style-src 'self' 'unsafe-inline' platform.twitter.com *.twimg.com; report-uri https://despora.report-uri.io/r/default/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://stats.g.doubleclick.net https://www.google.com https://www.gstatic.com https://snap.licdn.com https://px.ads.linkedin.com https://www.linkedin.com https://connect.facebook.net https://www.facebook.com https://graph.facebook.com https://static.xx.fbcdn.net https://clientes.konvertti.com https://load.medicion.artexa.com https://js.hs-scripts.com https://js.hs-analytics.net https://track.hubspot.com https://forms.hsforms.com https://forms-na1.hsforms.com https://api.hsforms.com https://api.hsforms.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src 'self' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com 'unsafe-inline';frame-src 'self' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;worker-src 'self' blob: admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;connect-src 'self' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;object-src 'self' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;manifest-src 'self' admin.nuwebgroup.com hub.nuwebgroup.com assets.nuwebgroup.com nextgen-prod-a.s3.eu-west-1.amazonaws.com fw-cdn.com/11211636/ snap.licdn.com/li.lms-analytics/insight.min.js scripts.simpleanalyticscdn.com/latest.js *.getkoala.com s3-us-west-2.amazonaws.com/b2bjsstore/b/ *.vector.co cdn.heapanalytics.com/js/heap-1342847507.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/container_uGM8ZZG6.js onsite.optimonk.com/script.js cdn.matomo.cloud/nuwebgroup.matomo.cloud/matomo.js nuwebgroup.matomo.cloud pro.ip-api.com/json/ *.googleapis.com *.gstatic.com *.google.com google.com *.google-analytics.com *.cloudflareinsights.com cloudflareinsights.com *.cloudflare.com *.googletagmanager.com *.mixpanel.com connect.facebook.net www.facebook.com/tr/ *.fbcdn.net pixel.byspotify.com analytics.tiktok.com static.ads-twitter.com *.birdie.so cdnjs.cloudflare.com/ajax/libs/flag-icon-css/3.1.0/ cdnjs.cloudflare.com/ajax/libs/highlight.js/ cdn.tailwindcss.com goselljslib.b-cdn.net *.tap.company *.oppwa.com oppwa.com *.iovation.com/snare.js *.iesnare.com *.arcot.com *.klarnacdn.net/kp/lib/v1/api.js *.affirm.com/js/v2/affirm.js *.payments-amazon.com/checkout.js *.oney.io/build/loader.min.js *.afterpay.com/afterpay.js *.mastercard.com d.ratepay.com/*/di.js d3rpjm0wf8u2co.cloudfront.net/static/rkfl.js d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js checkout-sdk.sezzle.com/checkout.min.js yookassa.ru/checkout-widget/v1/checkout-widget.js applepay.cdn-apple.com/jsapi/v1.1.0/apple-pay-sdk.js cdn10.ebuckler.com/ebuckler.widget.js stats.ebuckler.com/js/ebuckler.widget.js *.masterpass.com/lightbox/Switch/integration/MasterPass.client.js *.stripe.com *.adyen.com *.authorize.net *.razorpay.com *.netpay.mx *.online-metrix.net *.netpaydev.com *.netpay.com.mx *.cardinalcommerce.com *.ccdc02.com/cardinalcruise/ *.safecharge.com *.onvopay.com *.paypal.com *.braintreegateway.com *.paypalobjects.com *.paytabs.com *.ryftpay.com my.emerchantpay.com *.sumup.com cdn.optimizely.com *.protectgroup.com *.vimeocdn.com *.vimeo.com vimeo.com *.youtube.com *.3ddvapis.com *.clarity.ms *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.bing.net *.zoho.eu *.zohocdn.com *.doubleclick.net www.googleadservices.com *.googlesyndication.com www.google.co.uk/ads www.google.hu/ads www.google.rs/ads www.google.ru/ads www.google.mx/ads *.optimonk.com *.crazyegg.com *.linkedin.com *.licdn.com open.spotify.com;default-src * data: blob: 'unsafe-eval' 'unsafe-inline';report-uri https://nuwebgroup.report-uri.com/r/d/csp/reportOnly; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://d1cwup7r903a1d.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://js.checkout.com *.klarna.com platform.twitter.com *.reviews.io *.reviews.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://meetanshi.com/media/logo.png pinterest.com assets.pinterest.com syndication.twitter.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.checkout.com *.klarnacdn.net *.klarna.com x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ twitter.com platform.twitter.com *.reviews.io *.reviews.co.uk maps.googleapis.com cdn.routeapp.io https//fonts.googleapis.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://js.checkout.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudfront.net *.reviews.io *.reviews.co.uk api.route.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' x.wayin.com www.google.com cdn.jsdelivr.net *.lytics.io *.customer.io www.googletagmanager.com www.googleoptimize.com maps.googleapis.com www.gstatic.com *.hotjar.com *.privacymanager.io *.onetrust.com polyfill.io *.bytedapm.com *.ttwstatic.com www.tiktok.com *.tiktokcdn-us.com *.pricespider.com *.swaven.com *.static-swaven.com edge.marker.io login.dotomi.com sc-static.net; report-uri https://o4504005838045184.ingest.sentry.io/api/4505410929033216/security/?sentry_key=14a5b105c2c7443983e52fe24209ded4 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.typekit.net *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.trustpilot.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com validate.fishpig.co.uk *.dycdn.net https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net https://firebasestorage.googleapis.com *.webtrends-optimize.com https://redchamps.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.stripe.com webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com *.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.avada.io *.shopify.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net *.trustpilot.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.dycdn.net https://*.googleapis.com *.typekit.net *.fontawesome.com https://fonts.bunny.net *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.trustpilot.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com *.dycdn.net *.freshrelevance.com wss://*.freshrelevance.com wss://*.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://get.geojs.io *.avada.io *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' platform.instagram.com www.instagram.com www.googletagservices.com *.googlesyndication.com *.googleadservices.com googleads.g.doubleclick.net adservice.google.com adservice.google.ae adservice.google.al adservice.google.at adservice.google.be adservice.google.bg adservice.google.bs adservice.google.ca adservice.google.ch adservice.google.ci adservice.google.cl adservice.google.co.bw adservice.google.co.cr adservice.google.co.id adservice.google.co.il adservice.google.co.in adservice.google.co.jp adservice.google.co.ke adservice.google.co.kr adservice.google.co.mz adservice.google.co.nz adservice.google.co.th adservice.google.co.tz adservice.google.co.uk adservice.google.co.uz adservice.google.co.ve adservice.google.co.za adservice.google.co.zm adservice.google.co.zw adservice.google.com.ai adservice.google.com.ar adservice.google.com.au adservice.google.com.bd adservice.google.com.bh adservice.google.com.bn adservice.google.com.bo adservice.google.com.br adservice.google.com.co adservice.google.com.cy adservice.google.com.ec adservice.google.com.eg adservice.google.com.et adservice.google.com.fj adservice.google.com.gh adservice.google.com.gi adservice.google.com.gt adservice.google.com.hk adservice.google.com.jm adservice.google.com.kh adservice.google.com.kw adservice.google.com.lb adservice.google.com.mm adservice.google.com.mt adservice.google.com.mx adservice.google.com.my adservice.google.com.ng adservice.google.com.ni adservice.google.com.np adservice.google.com.om adservice.google.com.pa adservice.google.com.pe adservice.google.com.ph adservice.google.com.pk adservice.google.com.pr adservice.google.com.py adservice.google.com.qa adservice.google.com.sa adservice.google.com.sg adservice.google.com.sv adservice.google.com.tr adservice.google.com.tw adservice.google.com.ua adservice.google.com.uy adservice.google.com.vn adservice.google.cz adservice.google.de adservice.google.dk adservice.google.dz adservice.google.ee adservice.google.es adservice.google.fi adservice.google.fr adservice.google.ge adservice.google.gr adservice.google.gy adservice.google.hn adservice.google.hr adservice.google.hu adservice.google.ie adservice.google.im adservice.google.iq adservice.google.is adservice.google.it adservice.google.jo adservice.google.kz adservice.google.li adservice.google.lk adservice.google.lt adservice.google.lu adservice.google.lv adservice.google.md adservice.google.mk adservice.google.mu adservice.google.nl adservice.google.no adservice.google.pl adservice.google.pt adservice.google.ro adservice.google.rs adservice.google.ru adservice.google.se adservice.google.si adservice.google.sk adservice.google.so adservice.google.sr adservice.google.tl adservice.google.tn adservice.google.tt google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com translate.googleapis.com translate.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: fonts.googleapis.com 'unsafe-inline' maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com *.googlesyndication.com stats.g.doubleclick.net data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com translate.googleapis.com translate.google.com i.ytimg.com www.googletagmanager.com; connect-src 'self' *.googlesyndication.com googleads.g.doubleclick.net stats.g.doubleclick.net www.google-analytics.com ampcid.google.com analytics.google.com about: maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; frame-src 'self' www.instagram.com *.googlesyndication.com googleads.g.doubleclick.net maps.googleapis.com maps.google.com www.youtube.com www.googletagmanager.com; child-src 'self' www.youtube.com www.googletagmanager.com; report-uri https://www.tilte.cx?gdsih-csp-report; 1 font-src *.googleapis.com fonts.gstatic.com *.fontawesome.com *.findologic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com www.youtube.com *.google.com *.google.com/ js.mollie.com www.facebook.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://www.magezon.com https://cdn.clerk.io cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com www.facebook.com widgets.trustedshops.com *.google.de *.usercentrics.eu https://firebasestorage.googleapis.com quickchart.io img.youtube.com https://www.mollie.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.googleapis.com *.gstatic.com https://api.clerk.io https://cdn.clerk.io secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io widget.freshworks.com m2epro.freshdesk.com rns.matelso.de *.google.com *.clarity.ms *.findologic.com widgets.trustedshops.com *.adform.net *.googlecommerce.com *.kk-resources.com *.usercentrics.eu *.s24.com *.avada.io *.google.com/ js.mollie.com connect.facebook.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io d.ratepay.com d.payla.io dr.payla.io widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.findologic.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com widget.freshworks.com m2epro.freshdesk.com rns.matelso.de *.clarity.ms *.usercentrics.eu *.demdex.net https://get.geojs.io *.avada.io *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://www.googletagmanager.com *.google-analytics.com *.googleadservices.com *.apptopay.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.globalpay.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.apptopay.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.apptopay.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.apptopay.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com https://player.vimeo.com https://www.youtube-nocookie.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleadservices.com *.apptopay.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.globalpay.com *.klarna.com *.klarnaevt.com *.klarnacdn.net blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google-analytics.com *.googleadservices.com *.apptopay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com player.vimeo.com x.klarnacdn.net *.klarnaservices.com https://player.vimeo.com https://www.youtube.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.google-analytics.com *.googleadservices.com *.apptopay.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://fonts.googleapis.com *.klarnacdn.net http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src *.google-analytics.com *.googleadservices.com *.googleapis.com *.apptopay.com 'self' 'unsafe-inline'; media-src *.adobe.com *.google-analytics.com *.googleadservices.com *.googleapis.com blob: 'self' 'unsafe-inline'; manifest-src *.google-analytics.com *.googleadservices.com *.googleapis.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleadservices.com *.apptopay.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com https://google.com/pay x.klarnacdn.net *.klarnaservices.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.google-analytics.com *.googleadservices.com *.googleapis.com http: https: blob: 'self' 'unsafe-inline'; default-src *.google-analytics.com *.googleadservices.com *.googleapis.com *.apptopay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://*.moneris.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ mageside.com *.designer-images.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.moneris.com/ *.stat-track.com polyfill.io *.moosend.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com https://*.moneris.com/ *.fontawesome.com *.moosend.com *.bootstrapcdn.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.stat-track.com *.m-pages.com *.m-operations.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ account.fetchify.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io cdn.doofinder.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.doofinder.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com/ assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.doofinder.com cc-cdn.com https://static.klaviyo.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.trustpilot.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doofinder.com wss://*.doofinder.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' statistiek.rijksoverheid.nl; script-src 'sha256-8kz5ARm+EueWjOyEtm0gwtTgXhoWcOwXEU0kYGGTVBg=' 'sha256-YOQrIGBQSsAtWodJ1qDZiCtwWVbvXj85Yme1BHNT/z8=' 'sha256-hqgU2e05QSX69TZ3nribEu1fEOT9I09bO9Aa81dAteg=' 'self' 'sha256-3Pejfkj6T0q3nIFwdhJVA0ST+KnF2yIhYlZO1qmTNPU=' statistiek.rijksoverheid.nl 'report-sample' 'sha256-IbtDa5/kbW2Hbn7qGi1538ERW/JuXrjCjK6zuL7QDfE=' 'sha256-/JNc+BuklzUXPWbtNKf7geALzzw4NbuLvyFYGJIRnXc=' 'sha256-CaN42Zi+a+oATitdYvGRVlyS6mCZIxrLFXhTbgp6HCI=' 'nonce-qH3zA576Wx6OHzUk4JkrYw=='; object-src 'self'; style-src 'self' 'sha256-2haq8oHxQM6XYJ1EnNAO37NNVFrJGhmY1jn8sa3S0AU=' 'sha256-7xqMqDOfWqvgvujBp1NXgw9yq9uWja1UZbZbBoSphjU=' 'sha256-mCFjSEfVbMV655L708fbXky77erDrJ8sYVyx+V9Igjg=' 'sha256-5uIP+HBVRu0WW8ep6d6+YVfhgkl0AcIabZrBS5JJAzs=' 'sha256-1VTAHS0X+0lgrfu7iW/2ikIZ/VIANi00phY6Pqavxdg=' 'sha256-p6HyQ9qqQIVvilUDUG0LZmJsmqaueCFxNRdnqp+CQu0=' 'sha256-p3iFO5bVyUOAUUESOH4bv8z4dxbPZZXWh/MQHoshxww='; img-src 'self' statistiek.rijksoverheid.nl *.rovid.nl data:; media-src 'self' rovid.nl *.rovid.nl; frame-src 'self' ; font-src 'self'; report-uri https://sentry.dtnr.nl/api/44/security/?sentry_key=7a6c58c960be4975936f128606931c16&sentry_environment=production 1 default-src 'self' *.googleapis.com *.gstatic.com www.openstreetmap.org secure.ogone.com *.youtube.com player.vimeo.com *.vimeocdn.com *.hotjar.com; report-uri /cspreport; script-src 'self' 'unsafe-inline' 'unsafe-eval' code.jquery.com ajax.aspnetcdn.com *.google-analytics.com translate.google.com *.readspeaker.com *.googleapis.com www.openlayers.org openlayers.org *.openstreetmap.org *.typekit.net www.googletagmanager.com *.googletagmanager.com *.cloudfront.net *.hotjar.com; connect-src 'self' *.typekit.net *.google-analytics.com *.stats.g.doubleclick.net *.umbraco.org *.openstreetmap.org *.googleapis.com *.analytics.google.com ws://woonin.nl *.bugsnag.com *.hotjar.com; img-src 'self' data: *.umbraco.org umbraco.tv www.gravatar.com pbs.twimg.com cdn.jsdelivr.net *.typekit.net *.google-analytics.com placehold.it *.gstatic.com www.google.com translate.googleapis.com *.googleapis.com *.openstreetmap.org www.openlayers.org openlayers.org api.maptiler.com umbracowebportalsnonprod.azureedge.net *.analytics.google.com www.googletagmanager.com umbracowebportalsprod.azureedge.net umbracowebportalsprod.blob.core.windows.net *.cookiebot.com *.tolkie.nl; media-src 'self' ; font-src 'self' data: *.typekit.net *.gstatic.com *.tolkie.nl cdnjs.cloudflare.com cdn.faceworks.nl ; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com www.openlayers.org openlayers.org www.gstatic.com *.typography.com; frame-ancestors 'self' ; 1 font-src *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.nznature.co.nz fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.gstatic.com cdn.nznature.co.nz www.facebook.com www.google.com www.google.co.nz google-analytics.com privymktg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.bing.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.nznature.co.nz connect.facebook.net www.gstatic.com www.google.com widget.privy.com downloads.mailchimp.com chimpstatic.com mc.us16.list-manage.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com cdn.nznature.co.nz fonts.googleapis.com assets.privy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.nznature.co.nz stats.g.doubleclick.net api.privy.com www.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.googleapis.de *.zopim.com *.zopim.io *.unpkg.com unpkg.com *.trustedshops.com trustedshops.com *.cdnfonts.com 'self' data: *.ratepay.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.trustedshops.com *.unpkg.com *.ratepay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.sandbox.paypal.com *.twitter.com *.trustedshops.com trustedshops.com *.unpkg.com unpkg.com *.doubleclick.net www.googletagmanager.com *.jsctool.com *.ratepay.com https://www.roomvo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.twitter.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.de *.google.co.in *.mastercard.com *.trustedshops.com trustedshops.com *.unpkg.com *.etrusted.com magento-dev.habisreutinger.de magento-test.habisreutinger.de habisreutinger.de *.hsforms.net *.hsforms.com *.twimg.com *.lightemporium.com *.usercentrics.eu *.googleapis.com *.ratepay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://www.roomvo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.roomvo.com roomvo.com *.trustedshops.com *.unpkg.com *.doubleclick.net magento-dev.habisreutinger.de magento-test.habisreutinger.de habisreutinger.de *.clarity.ms *.hsforms.net *.hsforms.com *.googleapis.com *.pay1.de *.ratepay.com *.jsctool.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://cdn.roomvo.com/static/scripts/b2b/habisreutingerde.js https://cdn.amplitude.com/libs/amplitude-4.4.0-min.gz.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com d.ratepay.com d.payla.io dr.payla.io *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.unpkg.com https://unpkg.com/ *.googletagmanager.com *.etrusted.com *.cdnfonts.com magento-dev.habisreutinger.de magento-test.habisreutinger.de habisreutinger.de *.usercentrics.eu *.ratepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io *.trustedshops.com trustedshops.com *.unpkg.com unpkg.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com www.google.com www.google.de *.google-analytics.com www.google-analytics.de *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://stats.g.doubleclick.net *.doubleclick.net *.trustedshops.com trustedshops.com *.unpkg.com *.roomvo.com roomvo.com *.googlesyndication.com api.saws.de magento-dev.habisreutinger.de magento-test.habisreutinger.de habisreutinger.de *.clarity.ms t.elasticsuite.io *.hsforms.net *.hsforms.com *.ratepay.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.userway.org sibforms.com *.sendinblue.com *.iubenda.com *.googleapis.com *.bootstrapcdn.com *.cookiebot.com *.teads.tv maxcdn.bootstrapcdn.com *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.google.com *.doubleclick.net *.facebook.com *.userway.org *.googleapis.com *.smooch.io *.pinterest.com *.pinimg.com *.bing.com *.google.it *.google.fr sibautomation.com *.rfihub.net *.amazon-adsystem.com *.cookiebot.com *.teads.tv 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.feedaty.com *.google.it *.fbcdn.net *.zendesk.com *.userway.org sibforms.com *.sendinblue.com *.iubenda.com *.googleapis.com *.smooch.io *.youtube.com *.pinterest.com *.pinimg.com *.bing.com *.google.fr *.teads.tv *.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.feedaty.com *.zdassets.com *.zendesk.com *.userway.org sibforms.com *.sendinblue.com *.iubenda.com *.googleapis.com *.smooch.io *.youtube.com *.pinterest.com *.pinimg.com *.bing.com *.google.it *.google.fr *.hotjar.com sibautomation.com *.rfihub.net *.teads.tv *.cookiebot.com *.avada.io https://www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.feedaty.com *.iubenda.com *.zendesk.com *.userway.org sibforms.com *.sendinblue.com *.smooch.io *.pinterest.com *.pinimg.com *.bing.com *.google.it *.google.fr *.bootstrapcdn.com *.cloudflare.com *.cookiebot.com *.teads.tv maxcdn.bootstrapcdn.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.zendesk.com *.userway.org sibforms.com *.sendinblue.com *.iubenda.com *.googleapis.com *.smooch.io *.youtube.com *.pinterest.com *.pinimg.com *.bing.com *.google.it *.google.fr *.doubleclick.net *.hotjar.com *.brevo.com *.teads.tv *.cookiebot.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: *.dhlparcel.nl *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com identity.bluebirdday.io accounts.google.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.sharethis.com *.cookiebot.com *.facebook.com *.doubleclick.net *.addthis.com *.criteo.com *.kiyoh.com *.robinhq.com *.pinterest.com *.googlesyndication.com *.weltpixel.com maps.googleapis.com chart.googleapis.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.sharethis.com dyka.nl *.dyka.nl *.dyka.bluebirdday.io *.bluebirdday.io *.dhlparcel.nl maps.gstatic.com *.googleapis.com *.ggpht *.google.com *.google.nl *.googletagmanager.com *.googlesyndication.com *.trustedshops.com *.facebook.com *.pinterest.com *.gravatar.com *.percolate-3.hipex.cloud *.bing.com *.windows.net robincontentdesktop.blob.core.windows.net *.doubleclick.net *.google-analytics.com *.clarity.ms *.speedcurve.com *.linkedin.com *.sendtric.com *.cloudfront.net cookiebot.com *.cookiebot.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com dyka.nl *.dyka.nl *.dyka.bluebirdday.io *.bluebirdday.io *.dhlparcel.nl maps.googleapis.com *.google.nl *.gstatic.com *.googleoptimize.com *.googleadservices.com *.pushbird.com chimpstatic.com *.cookiebot.com *.facebook.net *.pinimg.com *.addthisedge.com *.addthis.com *.criteo.net *.criteo.com *.bing.com unpkg.com *.klaviyo.com *.google-analytics.com *.clarity.ms *.robinhq.com robincontentdesktop.blob.core.windows.net surfly.com *.surfly.com *.msecnd.net *.vo.msecnd.net *.googlesyndication.com *.cookie-script.com *.tiktok.com *.licdn.com *.speedcurve.com *.livechatinc.com *.hotjar.com *.hotjar.io downloads.mailchimp.com *.list-manage.com chart.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.avada.io *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.google.com *.klaviyo.com *.dhlparcel.nl downloads.mailchimp.com tagmanager.google.com *.fontawesome.com *.googleapis.com *.gstatic.com *.multisafepay.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.dhlparcel.nl dyka.nl *.dyka.nl *.dyka.bluebirdday.io *.bluebirdday.io *.klaviyo.com *.doubleclick.net *.googleapis.com *.pinterest.com *.bing.com *.google-analytics.com *.analytics.google.com *.clarity.ms surfly.com *.surfly.com *.visualstudio.com *.cookiebot.com *.tiktok.com *.linkedin.com *.googlesyndication.com *.cookie-script.com *.hotjar.com wss://ws.hotjar.com *.hotjar.io wss://ws.hotjar.io maps.googleapis.com chart.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com https://*.tolkie.nl; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl https://*.tolkie.nl; script-src 'nonce-Y2I1ZTY3ZmItYzhkMi00MWZhLTkxNzgtNDM5NDJmODdhMGYw' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: *.fontawesome.com *.fonts.googleapis.com *.gstatic.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.google.com *.addthis.com *.pinterest.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://static.afterpay.com https://site-assets.afterpay.com/ *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com js.authorize.net jstest.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.braintreegateway.com www.youtube.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.avada.io *.googleapis.com *.google.com *.gstatic.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://use.fontawesome.com https://v2.zopim.com *.cloudflare.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com js.mollie.com *.trustpilot.com *.force.com *.cookiebot.com *.sommify.ai *.googletagmanager.com assets.adobedtm.com *.adobedtm.com https://fprnt.com https://s7.addthis.com https://js.mollie.com https://simplicity.trustpilot.com https://googleads.g.doubleclick.net https://www.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://www.mollie.com https://media.jmango360.com https://secure.adnxs.com https://d2dglb1590sxlb.cloudfront.net https://www.google.com https://www.google.ca https://www.google.nl https://www.google.it *.mcusercontent.com *.cookiebot.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.mollie.com *.trustpilot.com https://www.googletagmanager.com https://widget.trustpilot.com/ https://invitejs.trustpilot.com https://v2.zopim.com/ https://www.clickcease.com https://chimpstatic.com https://static.zdassets.com https://pixel.adcrowd.com https://cdn.fraudlabspro.com https://dynamic.adcrowd.com https://s7.addthis.com https://m.addthis.com https://api-public.addthis.com https://z.moatads.com https://v1.addthisedge.com https://js.mollie.com https://service.force.com https://d.la2-c1-cdg.salesforceliveagent.com https://voordeelwijnen.my.salesforce.com *.cookiebot.com *.adobedtm.com *.jquery.com *.cloudflare.com *.conderwines.de *.voordeelwijnen.nl *.zendesk.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com https://use.fontawesome.com https://service.force.com *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://stats.g.doubleclick.net *.sentry.io https://www.google-analytics.com https://ekr.zdassets.com wss://widget-mediator.zopim.com https://s7.addthis.com https://m.addthis.com https://api-public.addthis.com https://monitor.clickcease.com https://invitejs.trustpilot.com https://*.force.com *.zendesk.com *.cookiebot.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-HPvmvcOzWXCgPFWOC3D1eQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com 'self' data: *.cloudflare.com *.bootstrapcdn.com *.hotjar.com *.typekit.net cdn.curator.io static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.google.com *.chatra.io *.hotjar.com *.facebook.com *.trustpilot.com *.kiyoh.com *.pinterest.com *.criteo.com *.cookiefirst.com *.multisafepay.com https://pay.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com * scontent.fzty3-2.fna.fbcdn.net *.multisafepay.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.twitter.com *.fontawesome.com *.elfsight.com *.chimpstatic.com *.chatra.io *.jsdelivr.net chimpstatic.com *.facebook.com *.doubleclick.net *.trustpilot.com s.pinimg.com *.zdassets.com *.google-analytics.com *.feedbackcompany.com *.facebook.net *.hotjar.com *.mailchimp.com *.list-manage.com *.curator.io *.typekit.net *.clarity.ms *.leadinfo.net *.criteo.com *.googleadservices.com *.cookiefirst.com www.datadoghq-browser-agent.com bat.bing.com *.tidio.co *.tidiochat.com *.iubenda.com js-agent.newrelic.com *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net *.googleapis.com *.curator.io *.cookiefirst.com maxcdn.bootstrapcdn.com *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src curatorio.s3.amazonaws.com curator-assets.b-cdn.net video-lga3-2.cdninstagram.com video-iad3-1.xx.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.cloudflare.com *.elfsight.com *.instacloud.io *.google-analytics.com *.google.com *.doubleclick.net *.hotjar.com *.hotjar.io ct.pinterest.com *.paypal.com *.zdassets.com *.zendesk.com *.feedbackcompany.com *.curator.io *.clarity.ms *.leadinfo.net *.cookiefirst.com gtm-mm85h6s-nzi2m.uc.r.appspot.com www.google-analytics.com www.google.com *.livechatinc.com www.paypalobjects.com dev.visualwebsiteoptimizer.com www.googletagmanager.com pagead2.googlesyndication.com googleadservices.com rum.ewings.cloud *.multisafepay.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com *.typekit.net *.hotjar.com www.bugherd.com *.cloudfront.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com maxcdn.bootstrapcdn.com www.betterequipped.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com www.betterequipped.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.betterequipped.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hotjar.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.betterequipped.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com www.google.co.uk stats.g.doubleclick.net bugherd-attachments.s3.amazonaws.com *.cloudfront.net *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net www.betterequipped.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hotjar.com chimpstatic.com *.google.com www.gstatic.com www.bugherd.com *.cloudfront.net *.sagepay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.opayo.eu.elavon.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.betterequipped.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.typekit.net *.cloudfront.net *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com www.betterequipped.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.betterequipped.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.hotjar.com *.hotjar.io www.bugherd.com sessions.bugsnag.com wss://ws.pusherapp.com *.pusher.com www.google.co.uk stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.betterequipped.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.betterequipped.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.betterequipped.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://quadmedepiciframe-pp-prtl.spectrumretailnet.com;script-src 'nonce-a58ebfa2683f491e903013977672064f' https://mychart.myquadmedical.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart.myquadmedical.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:;report-uri https://google.com; 1 font-src *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com airwallex.com *.airwallex.com google.com *.google.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com google.com *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://images.unsplash.com *.googleapis.com *.gstatic.com *.disqus.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.disqus.com https://z.moatads.com https://cdn.jsdelivr.net *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com o11y-demo.airwallex.com o11y.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.googleapis.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net https://static.buckaroo.nl www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.sooqr.com *.spotlersearch.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com *.google-analytics.com *.facebook.com *.facebook.net https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://seo.mageplaza.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com https://payment-webinit.sips-services.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.dpdconnect.nl www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://vars.hotjar.com/ *.weltpixel.com *.code.createjs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com maps.gstatic.com maps.googleapis.com www.google.com.ua https://stats.g.doubleclick.net/ https://www.google.fr/ads/ga-audiences https://www.google.com/ads/ga-audiences https://franceverif.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://*.dpdconnect.nl *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com maps.googleapis.com https://www.gstatic.com/ https://static.hotjar.com/ https://script.hotjar.com/ https://js-agent.newrelic.com/ https://bam.nr-data.net/ https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.google-analytics.com *.googletagmanager.com *.code.createjs.com/ *.cloudflare.com https://widget.franceverif.fr https://www.clickcease.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://in.hotjar.com/api/v2/client/sites/ https://vc.hotjar.io/sessions/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/j/collect *.google-analytics.com *.doubleclick.net https://*.googlesyndication.com https://maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.google.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com unsafe-inline *.typekit.net *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com ws: t.elasticsuite.io *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com fonts.googleapis.com static.hsappstatic.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.certcapture.com e.issuu.com www.youtube.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.certcapture.com store.paradoxlabs.com *.grandstandglass.com *.egrandstand.com *.elfsightcdn.com grandstand-visualizer.s3.us-east-2.amazonaws.com *.analytics.google.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.s3.us-central-1.wasabisys.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ track.hubspot.com *.hsforms.com js.hscollectedforms.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.certcapture.com *.authorize.net polyfill.io cdn.polyfill.io secure.perk0mean.com browser.sentry-cdn.com *.elfsight.com *.elfsightcdn.com fullstory.com *.fullstory.com *.googletagmanager.com *.googleadservices.com *.g.doubleclick.net *.luckyorange.com *.cloudflareinsights.com google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com *.hubspot.com *.hs-scripts.com js.hscollectedforms.net js.hs-analytics.net js.hs-banner.com js.usemessages.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.bc0a.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://cdn.bc0a.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.certcapture.com maxcdn.bootstrapcdn.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src egrandstand.com *.egrandstand.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.net insights.algolia.io *.algolianet.com *.insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.certcapture.com *.authorize.net fullstory.com *.fullstory.com grandstand-visualizer.s3.us-east-2.amazonaws.com *.elfsight.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat pubsub.googleapis.com *.luckyorange.com wss://realtime.luckyorange.com wss://in.visitors.live https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ *.hubspot.com *.hsforms.com forms.hscollectedforms.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com ixfd2-api.bc0a.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://o243388.ingest.sentry.io/api/6139115/security/?sentry_key=1c836c77c72b414e9df244e32c353f5d&sentry_environment=production; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io *.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.zonos.com *.postcodeanywhere.co.uk *.bing.net *.google.rs *.google.com *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://api.clerk.io https://cdn.clerk.io chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://cdn.logrocket.io https://cdn.logr-ingest.com https://cdn.lr-ingest.io https://cdn.lr-in.com https://cdn.lr-in-prod.com https://cdn.lr-ingest.com https://cdn.ingest-lr.com https://cdn.lr-intake.com https://cdn.intake-lr.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.zonos.com *.cloudflareinsights.com *.clerk.io *.pcapredict.com *.postcodeanywhere.co.uk *.bing.com *.clarity.ms *.hotjar.com *.lrkt-in.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com *.postcodeanywhere.co.uk *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://*.logrocket.io https://*.lr-ingest.io https://*.logrocket.com https://*.lr-in.com https://*.lr-in-prod.com https://*.lr-ingest.com https://*.ingest-lr.com https://*.lr-intake.com https://*.intake-lr.com https://*.logr-ingest.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.zonos.com *.cloudflareinsights.com *.pcapredict.com *.postcodeanywhere.co.uk *.bing.com *.clarity.ms *.bing.net *.hotjar.com *.lrkt-in.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com cdn.doofinder.com https://www.mollie.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com cdn.doofinder.com js.mollie.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maps.googleapis.com www.gstatic.com www.google.com https://maps.googleapis.com/ https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.doofinder.com *.fontawesome.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.doofinder.com wss://*.doofinder.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: cdn.mouseflow.com *.mouseflow.com unpkg.com github.com *.googleapis.com *.gstatic.com *.ggpht.com *.googleusercontent.com *.google.com *.google.ch *.google.fr *.google.de google.com *.fontawesome.com *.google-analytics.com *.googletagmanager.com *.cloudflare.com *.facebook.net *.facebook.com www.facebook.com browser-update.org *.adnsxs.com *.adnxs.com *.doubleclick.net *.googleadservices.com googleads.g.doubleclick.net stats.g.doubleclick.net *.googlesyndication.com *.linkedin.com *.licdn.com *.clearbitjs.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.youtube.com *.youtube-nocookie.com *.cookielaw.org *.onetrust.com cdn.ckeditor.com cdn.jsdelivr.net api.fouanalytics.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.ggpht.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.fontawesome.com *.cloudflare.com *.jsdelivr.net unpkg.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net; img-src 'self' data: groupe-e.ch *.groupe-e.ch *.linkedin.com *.licdn.com *.clearbitjs.com *.facebook.net *.facebook.com www.facebook.com *.adnsxs.com *.adnxs.com *.doubleclick.net *.googleadservices.com googleads.g.doubleclick.net stats.g.doubleclick.net *.googlesyndication.com *.google.com *.google.ch *.google.fr *.google.de google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.cookielaw.org *.onetrust.com *.google-analytics.com *.googletagmanager.com i.ytimg.com *.googleapis.com *.gstatic.com *.ggpht.com *.googleusercontent.com; frame-src 'self' data: *.facebook.net *.facebook.com www.facebook.com *.doubleclick.net *.googleadservices.com googleads.g.doubleclick.net stats.g.doubleclick.net *.googlesyndication.com *.google.com *.google.ch *.google.fr *.google.de google.com *.youtube.com *.youtube-nocookie.com *.google-analytics.com *.googletagmanager.com groupe-e.ch *.groupe-e.ch gateway.zscloud.net *.cloudflare.com; font-src 'self' data: *.googleapis.com *.gstatic.com *.ggpht.com *.googleusercontent.com *.fontawesome.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net; connect-src 'self' groupe-e.ch *.groupe-e.ch *.fontawesome.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.googleadservices.com googleads.g.doubleclick.net stats.g.doubleclick.net *.googlesyndication.com *.google.com *.google.ch *.google.fr *.google.de google.com *.oribi.io *.cookielaw.org *.onetrust.com *.linkedin.com *.licdn.com cdn.mouseflow.com *.mouseflow.com *.facebook.net *.facebook.com www.facebook.com api.fouanalytics.com apix.b2c.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-g640BhLNogoAzsYKCgFDJT2pVwE=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' https: data: blob:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' yandex.net *.yandex.net yandex.ru *.yandex.ru yadro.ru *.yadro.ru clarity.ms *.clarity.ms youtube.com *.youtube.com googleusercontent.com *.googleusercontent.com yastatic.net *.yastatic.net google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com *.codepen.io; img-src 'self' data: https: yandex.net *.yandex.net yandex.ru *.yandex.ru youtube.com *.youtube.com googleusercontent.com *.googleusercontent.com yastatic.net *.yastatic.net; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; connect-src 'self' https: yandex.net *.yandex.net yandex.ru *.yandex.ru clarity.ms *.clarity.ms google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com yastatic.net *.yastatic.net; frame-src 'self' https: youtube.com *.youtube.com; frame-ancestors 'self'; report-uri https://www.internet-technologies.ru/csp-report/; 1 default-src 'self' https://*.mensura.be; frame-ancestors https://app.storyblok.com; frame-src 'self' https://www.youtube.com https://player.vimeo.com; connect-src 'self' https://app-pweb-backend-mns-pro.azurewebsites.net https://*.google-analytics.com https://www.googletagmanager.com https://api-eu1.cludo.com https://*.googleapis.com https://www.google.com; img-src 'self' https://*.storyblok.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.google.be data:; font-src 'self' https://use.typekit.net; style-src 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net/; script-src 'self' 'unsafe-inline' https://app.storyblok.com https://customer.cludo.com https://www.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://cdn.cookielaw.org https://*.youtube.com; worker-src 'self' blob:; 1 font-src *.bootstrapcdn.com *.fontawesome.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.hipay-tpp.com *.hipay.com *.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com https://www.googletagmanager.com/ *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io *.hipay.com *.googleapis.com accastillage-diffusion.com accastillage-diffusion.es accastillage-diffusion.it accastillage-diffusion.co.uk d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com *.atinternet-solutions.com *.atinternet.io *.aticdn.net *.xiti.com *.ati-host.net *.atinternet.com *.piano.io *.axept.io *.target2sell.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com https://cdnjs.cloudflare.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.hipay.com *.googleapis.com *.bootstrapcdn.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.atinternet-solutions.com *.atinternet.io *.aticdn.net *.xiti.com *.ati-host.net *.atinternet.com *.piano.io *.axept.io *.target2sell.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.designmanager.com *.gstatic.com *.mustcheck.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com *.weltpixel.com designfiles.co *.doubleclick.net *.fliphtml5.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.gstatic.com *.facebook.com *.doubleclick.net exchjsdata.com *.googleapis.com www.google.ae www.google.am www.google.at www.google.bg www.google.bs www.google.ca www.google.cl www.google.cm www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.kr www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.co www.google.com.do www.google.com.eg www.google.com.hk www.google.com.kw www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zw www.google.cz www.google.de www.google.es www.google.fr www.google.gr www.google.hr www.google.ie www.google.it www.google.mk www.google.nl www.google.pl www.google.ps www.google.rs www.google.ru www.google.se www.google.sk data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.instagram.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://ajax.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://chimpstatic.com designfiles.co *.googleapis.com *.newrelic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com downloads.mailchimp.com tagmanager.google.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.net *.doubleclick.net get663.com *.googleapis.com www.google.be www.google.bs www.google.by www.google.ca www.google.cl www.google.co.id www.google.co.in www.google.co.jp www.google.co.kr www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.do www.google.com.eg www.google.com.hk www.google.com.mx www.google.com.my www.google.com.ng www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.vn www.google.co.th www.google.co.uk www.google.de www.google.fr www.google.gr www.google.hr www.google.nl www.google.ru *.google.com *.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5a06d6ec-c9e3-4020-8ae7-730a01080da3.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; connect-src 'self' https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://pagesense-collect.zoho.com https://stats.g.doubleclick.net https://translate.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://connect.facebook.net https://m.facebook.com https://maps.google.com https://maps.googleapis.com https://mobile.facebook.com https://platform.twitter.com https://static.addtoany.com https://web.facebook.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: blob: https://*.google-analytics.com https://*.analytics.google.com https://fonts.gstatic.com https://pagesense-collect.zoho.com https://*.fbcdn.net https://stats.g.doubleclick.net https://translate.google.com https://translate.googleapis.com https://www.gcis.gov.za https://www.google.com https://www.google.co.za https://www.googletagmanager.com https://www.gov.za https://www.gstatic.com https://www.publicsectormanager.gov.za https://www.sanews.gov.za https://www.vukuzenzele.gov.za https://*.openstreetmap.org https://*.ytimg.com https://www.google-analytics.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://cdn.pagesense.io https://connect.facebook.net https://maps.googleapis.com https://platform.twitter.com https://static.addtoany.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com https://platform.twitter.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.vukuzenzele.gov.za/system/reporting/default; report-to default 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com sis-t.redsys.es sis.redsys.es 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ https://player.vimeo.com https://www.youtube-nocookie.com https://sandbox.sequracdn.com https://live.sequracdn.com spf-es.1000ps.at sparepartsfinder.ktm.com s7.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com https://sandbox.sequracdn.com https://live.sequracdn.com www.google.com www.google.es googleads.g.doubleclick.net new.secomoto.com www.secomoto.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com *.avada.io https://player.vimeo.com https://www.youtube.com https://sandbox.sequracdn.com https://live.sequracdn.com www.googletagmanager.com googleads.g.doubleclick.net pdcc.gdpr.es m.addthis.com v1.addthisedge.com z.moatads.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com pdcc.gdpr.es 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://sandbox.sequracdn.com https://live.sequracdn.com stats.g.doubleclick.net region1.google-analytics.com region1.analytics.google.com s7.addthis.com m.addthis.com www.google.es 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.secomoto.com/; report-to report-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/translate_google 1 default-src 'self'; script-src 'self' 'report-sample' https://apis.google.com/js/client.js https://feeds.trac.jobs/js/v12/EmbeddedJobsBoard.js https://maps.googleapis.com/maps/api/js https://www.browsealoud.com/plus/scripts/3.1.0/ba.js https://www.cqc.org.uk/sites/all/modules/custom/cqc_widget/widget.js https://www.googletagmanager.com/gtm.js; style-src 'self' 'report-sample' https://cdnjs.cloudflare.com https://feeds.trac.jobs https://fonts.googleapis.com https://use.fontawesome.com https://www.cqc.org.uk; img-src 'self' data: https://feeds.trac.jobs https://maps.googleapis.com https://maps.gstatic.com https://static.trac.jobs https://www.cqc.org.uk; font-src 'self' https://cdnjs.cloudflare.com https://fonts.gstatic.com https://use.fontawesome.com; media-src 'self'; object-src 'none'; frame-src 'self' https://my.matterport.com https://player.vimeo.com https://www.youtube-nocookie.com; worker-src 'none'; manifest-src 'self'; base-uri 'self' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-rayoi+NHKzilOF1DPZP9fBvL6rQ=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-MDgzYWQ0ZDYtMGU3Yy00OWVjLWE4OGMtMjhlMDlmMmRhYzEx' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.sitevibes.com sitevibes.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.net *.facebook.com *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.clarity.ms *.doubleclick.net *.acsbapp.com *.googletagmanager.com news.adamshorsesupplies.com *.facebook.net *.facebook.com https://maps.google.com/ magento-cloudflare.jetrails.com *.sitevibes.com sitevibes.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.clarity.ms c.clarity.ms c.bing.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.facebook.net *.facebook.com https://images.unsplash.com *.ytimg.com *.sitevibes.com sitevibes.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.clarity.ms *.acsbapp.com acsbapp.com news.adamshorsesupplies.com *.facebook.net *.facebook.com https://maps.googleapis.com *.sitevibes.com sitevibes.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.sitevibes.com sitevibes.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.clarity.ms *.acsbapp.com acsbapp.com stats.g.doubleclick.net *.facebook.net *.facebook.com https://maps.googleapis.com https://player.vimeo.com *.sitevibes.com sitevibes.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://sales.connectpos.com http://sales.connectpos.com https://www.dijkxhoorn.nl *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self';connect-src 'self' https://www.google-analytics.com https://*.googleapis.com https://api.rudderlabs.com https://hosted.rudderlabs.com https://rudderstack.taskade.cloud https://api.stripe.com https://checkout.stripe.com https://sentry.io wss: https://cn2bi8ujy8.execute-api.us-east-1.amazonaws.com https://taskade-files.s3.us-east-1.amazonaws.com https://files.taskade.com https://vimeo.com https://fast.wistia.com https://*.loom.com https://www2.profitwell.com https://api.canny.io https://companion.taskade.com;default-src 'self';form-action 'self';media-src 'self' https://js.driftqa.com https://files.taskade.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' https://ajax.cloudflare.com https://challenges.cloudflare.com https://js.driftt.com https://widget.drift.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://checkout.stripe.com https://js.stripe.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.com https://r.wdfl.co https://public.profitwell.com https://cdn.firstpromoter.com https://canny.io https://pa.taskade.com https://unicorn.taskade.workers.dev https://static.cloudflareinsights.com;object-src 'none';img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://*.stripe.com https://files.taskade.com https://unpkg.com https://i.ytimg.com https://*.sndcdn.com https://i.vimeocdn.com https://*.wistia.com https://cdn.loom.com https://*.figma.com https://images.typeform.com https://*.whimsical.com https://companion.taskade.com;style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com;font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com;frame-src https://js.driftt.com https://widget.drift.com https://checkout.stripe.com https://hooks.stripe.com https://js.stripe.com https://call.taskade.com https://*.youtube.com https://*.soundcloud.com https://player.vimeo.com https://*.loom.com https://*.figma.com https://*.invisionapp.com https://*.typeform.com https://*.whimsical.com;report-uri /webhooks/csp-report;report-to /webhooks/csp-report;frame-ancestors 'none' 1 connect-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com www.google.com.bd *.klarnaevt.com *.ytimg.com *.clarity.ms *.google.com *.cloudflare.com www.google.com.ni www.google.es s3.eu-west-1.amazonaws.com *.fundelices.be *.hotjar.io *.fundelices.fr www.google.pl www.google.com.vn www.google.de *.media-amazon.com *.google-analytics.com *.klarna.com *.fontawesome.com s3.amazonaws.com www.google.com.ly *.bing.net *.nr-data.net www.google.be *.pinimg.com www.google.com.ec *.googlesyndication.com *.gstatic.com www.google.com.uy *.doubleclick.net *.bing.com d5yoctgpv4cpx.cloudfront.net www.google.nl www.google.ch *.googleadservices.com www.google.com.mx *.marker.io www.google.com.ua www.google.fr www.google.com.tw *.googleapis.com *.freshchat.com *.deleukstetaartenshop.com *.squeezely.tech www.google.dk *.feedbackcompany.com www.google.com.tr p2iqhncxyh.execute-api.eu-central-1.amazonaws.com www.google.ru www.google.com.et *.deleukstetaartenshop.nl www.google.com.qa squeezely.tech www.google.com.sg www.google.com.eg www.google.it *.pinterest.com www.google.com.ph *.cookiefirst.com *.facebook.net *.googletagmanager.com www.google.com.my *.multisafepay.com www.google.cz *.newrelic.com www.google.com.ar *.klarnacdn.net www.google.com.np www.google.com.lb www.google.at www.google.com.pk google.com www.google.com.hk *.facebook.com www.google.com.sv www.google.com.pa vercel.live *.youtube.com www.google.pt www.google.com.kh www.google.co.uk *.deleukstetaartenshop.be *.googleusercontent.com www.google.com.br www.google.com.om www.google.com.kw www.google.com.au www.google.com.sa www.google.com.ng www.google.com.cy www.google.com.co www.google.com.mt noembed.com api.marker.io ssr.marker.io s3.eu-west-1.amazonaws.com/marker.sessions.prod; img-src 'self' 'unsafe-inline' 'unsafe-eval' www.google.com.qa *.googletagmanager.com www.google.com.bh www.google.com.co www.google.com.tw www.google.com.sg *.facebook.com www.google.at www.google.com.pa www.google.pl google.com www.google.com.kw www.google.com.np www.google.pt www.google.com.pe www.google.be www.google.com.mx www.google.it www.google.com.et www.google.ch www.google.com.py *.facebook.net *.google.com www.google.com.pr *.deleukstetaartenshop.nl www.google.de www.google.es www.google.com.bo www.google.com.do *.deleukstetaartenshop.com *.gstatic.com www.google.com.ph *.fundelices.fr www.google.com.ec www.google.com.kh www.google.com.sa *.bing.com www.google.com.vn www.google.com.hk www.google.com.ua www.google.com.ar *.doubleclick.net www.google.com.gh www.google.com.my www.google.fr www.google.com.ng *.ytimg.com www.google.com.cy www.google.com.om www.google.nl *.squeezely.tech *.media-amazon.com www.google.com.lb *.bing.net *.googleusercontent.com s3.amazonaws.com www.google.com.sv *.youtube.com www.google.com.tr www.google.dk www.google.com.uy www.google.com.bn www.google.ru *.klarna.com *.klarnacdn.net www.google.com.na www.google.com.mm www.google.com.ni *.googlesyndication.com www.google.com.ag www.google.co.uk www.google.com.eg www.google.com.gt www.google.com.br *.cookiefirst.com www.google.com.jm www.google.com.bd *.googleadservices.com www.google.com.au *.pinterest.com *.fundelices.be www.google.com.mt www.google.cz *.deleukstetaartenshop.be www.google.com.ly www.google.com.pk blob: data: media.marker.io app.marker.io edge.marker.io; default-src 'self' 'unsafe-inline' 'unsafe-eval' *.clarity.ms *.googlesyndication.com *.hotjar.com *.googletagmanager.com *.pinimg.com *.hotjar.io *.squeezely.tech *.cookiefirst.com *.googleapis.com www.google.fr *.doubleclick.net *.klarnaevt.com noembed.com google.com *.bing.net *.googleadservices.com *.pinterest.com *.google.com *.ytimg.com *.gstatic.com *.facebook.net www.google.be www.google.com.tr www.google.com.au *.klarnacdn.net *.google-analytics.com *.bing.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com www.google.it www.google.de *.youtube.com d5yoctgpv4cpx.cloudfront.net squeezely.tech www.google.cz *.facebook.com *.klarna.com www.google.dk www.google.nl; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.multisafepay.com *.googleapis.com *.hotjar.com *.clarity.ms *.googleadservices.com *.klarnacdn.net *.google.com *.newrelic.com vercel.live *.youtube.com *.freshchat.com *.facebook.net *.gstatic.com *.pinimg.com *.feedbackcompany.com squeezely.tech *.googlesyndication.com *.doubleclick.net *.google-analytics.com *.pinterest.com *.cookiefirst.com *.bing.com d5yoctgpv4cpx.cloudfront.net *.marker.io edge.marker.io app.marker.io; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.fontawesome.com *.multisafepay.com *.deleukstetaartenshop.com *.gstatic.com *.deleukstetaartenshop.be *.freshchat.com *.cookiefirst.com *.googletagmanager.com *.googleapis.com; frame-src 'self' 'unsafe-inline' 'unsafe-eval' *.klarna.com *.klarnaservices.com *.google.com *.googletagmanager.com *.freshchat.com *.doubleclick.net *.bing.com *.pinterest.com *.youtube.com *.facebook.com vercel.live app.marker.io; font-src 'self' 'unsafe-inline' 'unsafe-eval' *.preply.com s3.amazonaws.com *.fontawesome.com *.typekit.net *.deleukstetaartenshop.be *.gstatic.com *.jsdelivr.net *.deleukstetaartenshop.com app.marker.io edge.marker.io; form-action 'self' 'unsafe-inline' 'unsafe-eval' *.facebook.com app.marker.io api.marker.io; child-src 'self' 'unsafe-inline' 'unsafe-eval' app.marker.io; media-src 'self' 'unsafe-inline' 'unsafe-eval' media.marker.io app.marker.io edge.marker.io; report-uri https://fdaba162-4422-4f3a-a4f4-c7768ec87549.sansec.watch/; report-to report-endpoint; 1 default-src 'self' ; style-src 'self' 'unsafe-inline' https://cdn-cookieyes.com ; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://cdn.apple-mapkit.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://cdn-cookieyes.com ; img-src 'self' blob: data: https://snapshot.apple-mapkit.com https://cdn.apple-mapkit.com https://www.googletagmanager.com https://www.google.co.uk https://*.ytimg.com https://img.youtube.com https://secure.gravatar.com https://cdn-cookieyes.com ; font-src 'self' data: https://fonts.gstatic.com ; media-src 'self' data: ; connect-src 'self' https://api.apple-mapkit.com https://cdn.apple-mapkit.com https://gsp10.apple-mapkit.com https://www.google.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://www.googletagmanager.com https://log.cookieyes.com https://cdn-cookieyes.com https://*.cookieyes.com ; frame-src 'self' https://allergens.jdwetherspoon.com https://www.jdwetherspooncareers.com https://www.google.com https://*.youtube-nocookie.com https://*.youtube.com ; frame-ancestors 'self' ; object-src 'none' ; base-uri 'self' ; form-action 'self' ; worker-src 'self' blob: ; upgrade-insecure-requests ; report-uri https://jdwetherspoon.report-uri.com/r/d/csp/reportOnly ; report-to default ; 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-4QzS9zhAl6qhCeNw5tAr0WPiK' 'strict-dynamic'; frame-ancestors 'self'; manifest-src 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com https://www.gstatic.com *.googleapis.com *.zopim.com 'self' data: *.chatchamp.com *.klarnacdn.net https://fonts.gstatic.com https://widgets.trustedshops.com https://webcachex-eu.datareporter.eu https://webcache-eu.datareporter.eu data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.kaptcha.com *.facebook.com *.pinterest.com *.sharethis.com *.chatchamp.com td.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.klarna.com landofcoder.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: blob: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.google.com *.google.de *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.googleadservices.com *.google-analytics.com region1.google-analytics.com *.analytics.google.com *.twitter.com *.twimg.com *.bing.com *.facebook.com *.facebook.net *.pinterest.com *.sleeknote.com *.zopim.com *.dalton-cosmetics.com *.googletagmanager.com *.googleapis.com *.sharethis.com *.newsletter2go.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://analytics.tiktok.com https://*.tiktokcdn.com https://bat.bing.com https://bat.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.google-analytics.com https://*.gstatic.com *.twitter.com *.googletagmanager.com *.googlesyndication.com *.pinimg.com *.bing.com *.facebook.net *.facebook.com *.zopim.com *.googleapis.com *.zdassets.com *.sleeknote.com *.cookielaw.org *.doubleclick.net www.dwin1.com *.paypal.com *.cardinalcommerce.com integrations.etrusted.com *.chatchamp.com *.sharethis.com *.newsletter2go.com 'self' data: js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com landofcoder.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://webcache-eu.datareporter.eu https://webcachex-eu.datareporter.eu https://cdn.brevo.com https://analytics.tiktok.com https://ct.pinterest.com https://sibautomation.com https://trck.linkster.co https://bat.bing.com https://webcache.datareporter.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.chatchamp.com *.sharethis.com 'self' data: assets.braintreegateway.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://webcache-eu.datareporter.eu https://webcachex-eu.datareporter.eu 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://*.google.com *.google-analytics.com *.googleapis.com region1.google-analytics.com *.analytics.google.com *.doubleclick.net *.twitter.com *.cookielaw.org *.pinterest.com *.zopim.com *.zdassets.com *.onetrust.com *.braintree-api.com *.braintreegateway.com *.zendesk.com wss://widget-mediator.zopim.com *.chatchamp.com *.sharethis.com *.newsletter2go.com pagead2.googlesyndication.com *.google.de *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat googleads.g.doubleclick.net *.googleadservices.com *.bing.com *.posthog.com *.sleeknote.com *.crwdcntrl.net *.stbuttons.click api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com landofcoder.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://webcache-eu.datareporter.eu https://swarmcrawler.datareporter.eu https://c.datareporter.eu https://analytics.tiktok.com https://business-api.tiktok.com https://bat.bing.com https://in-automate.brevo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: 'unsafe-inline' fonts.googleapis.com; script-src 'self' 'unsafe-inline' platform.twitter.com maps.googleapis.com *.facebook.net *.google-analytics.com *.googletagmanager.com *.googleapis.com widget2.fanimani.pl cdnjs.cloudflare.com; img-src 'self' secure.gravatar.com s.w.org maps.googleapis.com syndication.twitter.com *.gstatic.com *.google-analytics.com *.facebook.com *.google.com *.google.pl stats.g.doubleclick.net ; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.youtube.com https://widgetbe.com https://*.basis.net https://*.tiktok.com https://*.adnxs.com https://*.jsdelivr.net https://*.omappapi.com https://*.doubleclick.net https://*.facebook.net https://*.opmnstr.com https://cdn.vs12.com https://*.agentimage.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://cdnjs.cloudflare.com https://*.bootstrapcdn.com https://code.jquery.com https://cdn.maptiler.com https://unpkg.com https://static.addtoany.com https://cdn.thedesignpeople.net https://*.hubspot.com https://*.hsforms.net https://*.hotjar.com https://*.idxhome.com https://*.hsappstatic.net https://*.honely.com; style-src 'self' 'unsafe-inline' https://unpkg.com https://*.idxhome.com https://*.omappapi.com https://*.maptiler.com https://cdn.vs12.com https://*.agentimage.com https://*.vimeo.com https://*.googleapis.com https://*.gstatic.com https://cdnjs.cloudflare.com https://*.bootstrapcdn.com https://cdn.thedesignpeople.net; font-src 'self' data: https://*.idxhome.com https://*.googleapis.com https://*.bootstrapcdn.com https://*.gstatic.com https://cdn.vs12.com https://*.agentimage.com https://cdn.thedesignpeople.net; img-src 'self' data: blob: https:; connect-src 'self' https://*.plyr.io https://noembed.com https://*.facebook.com https://*.tiktok.com https://*.tiktokw.us https://*.adnxs.com https://widgetbe.com https://*.omappapi.com https://*.instagram.com https://*.hotjar.io https://cdn.vs12.com https://*.doubleclick.net https://*.agentimage.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.maptiler.com https://cdn.thedesignpeople.net; frame-src 'self' https://www.youtube-nocookie.com https://*.sitescout.com https://*.google.com https://*.googletagmanager.com https://recaptcha.google.com https://www.youtube.com https://*.addtoany.com https://*.youtube.com https://*.vimeo.com; media-src 'self' https://*.akamaized.net https://*.vimeo.com https://*.vimeocdn.com; report-uri /_csp-report/hiltonhyland.com 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com cdnjs.cloudflare.com self unsafe-inline data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com self *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trustpilot.com ecomm.sella.it *.doubleclick.net *.google-analytics.com *.googletagmanager.com www.paypalobjects.com bid.g.doubleclick.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com * ecomm.sella.it *.google.it *.google.com *.doubleclick.net *.google-analytics.com *.googletagmanager.com *.trustpilot.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://api.clerk.io https://cdn.clerk.io chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.fontawesome.com *.googleapis.com *.gstatic.com * *.trustpilot.com ecomm.sella.it *.doubleclick.net *.google-analytics.com *.googletagmanager.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://api.clerk.io https://cdn.clerk.io downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.trustpilot.com cdnjs.cloudflare.com self unsafe-inline tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://core.helloretail.com https://helloretailcdn.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ecomm.sella.it *.doubleclick.net *.google-analytics.com *.googletagmanager.com *.trustpilot.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.amazonaws.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cenpos.net *.cenpos.com *.gstatic.com *.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.cenpos.net *.cenpos.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page chimpstatic.com downloads.mailchimp.com *.list-manage.com https://app.zinrelo.com app.zinrelo.com https://cdn.zinrelo.com/js/all.js *.cenpos.com *.cenpos.net *.gstatic.com *.cardinalcommerce.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.amazonaws.com *.googleapis.com *.hsforms.net *.hsforms.com maps.googleapis.com https://cdn.zinrelo.com/ https://app.zinrelo.com/ https://d395yjvh5spyzw.cloudfront.net/ https://js-agent.newrelic.com/ https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com downloads.mailchimp.com https://fonts.bunny.net assets.braintreegateway.com *.amazonaws.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.amazonaws.com *.googleapis.com *.kodaris.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://cdn.zinrelo.com/ https://app.zinrelo.com/ https://d395yjvh5spyzw.cloudfront.net/ https://js-agent.newrelic.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' segment.okta.com *.oktacdn.com; connect-src 'self' segment.okta.com segment-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com segment.kerberos.okta.com segment.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-jRlyQr_f75oyqNHTXSmPJQ' 'unsafe-eval' 'self' 'report-sample' segment.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-jRlyQr_f75oyqNHTXSmPJQ' 'self' 'report-sample' segment.okta.com *.oktacdn.com; frame-src 'self' segment.okta.com segment-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: api-3bdc2f77.duosecurity.com; img-src 'self' segment.okta.com *.oktacdn.com https://ok4static.oktacdn.com/fs/bcg/4/gfs2pudo8tevoBTe31t7 *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' segment.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://segment.build 1 font-src *.gstatic.com *.tawk.to *.reevoo.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com *.amazonaws.com *.feefo.com *.flix360.io *.flixcar.com *.flixfacts.com *.icomoon.io *.isitetv.com *.livechatinc.com *.mouseflow.com *.paypalobjects.com *.popt.in https://static.isitetv.com https://prod-tiger-themes-runner-s3-webdesigns.s3-eu-west-1.amazonaws.com/custom-dev/assets/fonts/miele/helvetica-neue-bold.woff2 data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.ipg-online.com *.payments.epdq.co.uk https://payments.epdq.co.uk/ncol/prod/orderstandard_utf8.asp https://www.facebook.com/tr/ 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trustpilot.com *.reevoo.com *.facebook.com *.clarity.ms *.hotjar.com *.loadbee.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.chimpstatic.com *.deko.finance *.dekopay.com *.dekopay.org *.epdq.co.uk *.flixcar.com *.globalpay.com *.googleads.g.doubleclick.net *.isitetv.com *.laybuy.com *.livechatinc.com *.mouseflow.com *.pacificawarranty.com *.payments.epdq.co.uk *.paymentsense.cloud *.paypalobjects.com *.pbhomesolutions.co.uk *.quooker.co.uk *.reviews.co.uk *.rlets.com *.vimeo.com *.vimeocdn.com https://pay.deko.finance/ https://www.facebook.com https://www.quooker.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.sharethis.com *.google.com *.google.co.uk *.smartsuppcdn.com *.flix360.com *.tawk.to *.tawk.link *.reevoo.com *.loadbee.com *.flixfacts.com *.flixcar.com *.amazonaws.com *.facebook.com https://gethatch.com *.gstatic.com *.googleapis.com *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://mc.yandex.com *.appliancespares-direct.co.uk *.bing.com *.clarity.ms *.cloudfront.net *.cookiebot.com *.doubleclick.net *.feefo.com *.finance-calculator.co.uk *.flix360.io *.google-analytics.com *.isitetv.com *.jwplayer.com *.jwpsrv.com *.laybuy.com *.livechat-files.com *.livechatinc.com *.matomo.cloud *.media.flixcar.com *.mouseflow.com *.popt.in *.roeye.com *.rvvup.com *.smct.co *.tagserve.com *.yandex.ru *.youreko.com *.zdassets.com *.zdusercontent.com *.zendesk.com https://appluabncespares-direct.co.uk/ https://static.isitetv.com https://tawk.link https://www.beyondtelevision.co.uk https://www.ice-king.co.uk https://cdn-cookieyes.com https://cookerbuilder.lacanche.co.uk https://osm.klarnaservices.com/images/ https://storage.beko.co.uk https://strack.where-to-buy.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.googleapis.com *.googletagmanager.com *.trustpilot.com *.sharethis.com *.reevoo.com *.tawk.to *.smartsuppchat.com *.smartsuppcdn.com *.smartlook.com *.loadbee.com *.flixfacts.com *.flix360.io *.flixcar.com *.jsdelivr.net *.clarity.ms *.hotjar.com chimpstatic.com *.facebook.net *.recapture.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com *.klarnaservices.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://smct.co *.adobedtm.com *.bing.com *.cloudfront.net *.cookiebot.com *.ctctcdn.com *.dekopay.com *.feefo.com *.flix360.com *.freespee.com *.google.co.uk *.googlesyndication.com *.infinity-tracking.com *.isitetv.com *.livechatinc.com *.matomo.cloud *.mouseflow.com *.newrelic.com *.onefeed.co.uk *.popt.in *.rlets.com *.roeyecdn.com *.salesfire.co.uk *.smct.co *.smct.io *.voicestar.com *.webgains.io *.xg4ken.com *.yandex.ru *.youreko.com *.zdassets.com *.zendesk.com https://static.isitetv.com https://widget.reviews.co.uk https://cdn-cookieyes.com https://cookerbuilder.lacanche.co.uk invalidate-https://smct.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.trustpilot.com *.tawk.to *.reevoo.com *.googleapis.com *.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.aws *.ctctcdn.com *.feefo.com *.finance-calculator.co.uk *.flixcar.com *.icomoon.io *.isitetv.com *.popt.in *.smartsuppcdn.com *.youreko.com downloads.mailchimp.com https://static.isitetv.com https://cookerbuilder.lacanche.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.feefo.com *.flixcar.com *.flixfacts.com *.isitetv.com *.jellycathosting.co.uk *.smartsuppcdn.com *.tawk.to *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.sharethis.com *.smartsupp.com wss://websocket-visitors.smartsupp.com *.smartsuppchat.com *.smartsuppcdn.com *.doubleclick.net *.smartlook.com *.smartlook.cloud *.reevoo.com *.tawk.to *.googleapis.com *.loadbee.com *.flixfacts.com *.flixcar.com *.clarity.ms *.hotjar.com *.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com https://google.com https://log.cookieyes.com *.afterpay.com *.amazonaws.com *.analytics.google.com *.barclaycard.co.uk *.bing.com *.capturelogger-prod-usa.localiq.com *.chimpstatic.com *.cloudfront.net *.cloudfunctions.net *.cookieyes.com *.ctctcdn.com *.dekopay.com *.demdex.net *.epdq.co.uk *.facebook.com *.feefo.com *.gannettdigital.com *.google-analytics.com *.googlesyndication.com *.hotjar.io *.infinity-tracking.com *.infinity-tracking.net *.isitetv.com *.livechatinc.com *.matomo.cloud *.mouseflow.com *.nr-data.net *.payments.epdq.co.uk *.popt.in *.reachlocalservices.com *.reviews.co.uk *.rlets.com *.salesfire.co.uk *.smartmetrics.co.uk *.smct.co *.smct.io *.webgains.io *.yandex.com *.yandex.ru *.zdassets.com *.zendesk.com client-event-remote-ag.dojo.tech https://isitetv.com/ https://static.isitetv.com https://www.facebook.com/tr/ https://*.cookiebot.com https://api-abtesting.flix360.io https://cdn-cookieyes.com https://cookerbuilder.lacanche.co.uk wss://*.hotjar.com wss://*.smartsupp.com wss://*.tawk.to wss://*.zendesk.com wss://*.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.mouseflow.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-to https://magento.com/csp-report; font-src *.googleapis.com *.gstatic.com https://*.gstatic.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com unpkg.com js-agent.newrelic.com *.nr-data.net www.google-analytics.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com https://*.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com https://*.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.paypal.com https://*.hotjar.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com https://*.google-analytics.com googleads.g.doubleclick.net analytics.google.com https://*.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.googleapis.com https://*.paypal.com https://*.hotjar.com freegeoip.net http://freegeoip.net/shutdown unpkg.com js-agent.newrelic.com *.nr-data.net www.google-analytics.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://*.google-analytics.com www.googleadservices.com analytics.google.com https://*.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://*.analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.googleapis.com https://*.paypal.com https://*.hotjar.com unpkg.com js-agent.newrelic.com *.nr-data.net www.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://cdn.segment.com https://api.segment.io https://*.hokodo.co www.googleservices.com *.google.com *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.gstatic.com *.onlinewebfonts.com *.onlinebooze.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.net *.facebook.com *.tawk.to *.onlinebooze.co.uk *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.hokodo.co *.tawk.to *.facebook.net *.facebook.com *.google.com *.onlinebooze.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.tawk.to cdn.jsdelivr.net *.cloudflare.com *.cloudflareinsights.com *.google-analytics.com *.onlinebooze.co.uk *.google.com *.google.co.uk *.doubleclick.net *.googletagmanager.com *.facebook.net *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://sibautomation.com https://cdn.segment.com https://*.hokodo.co *.tawk.to cdn.jsdelivr.net *.cloudflare.com *.cloudfront.net *.kissmetrics.com *.cloudflareinsights.com *.facebook.net *.mailchimp.com *.google-analytics.com *.google.com *.doubleclick.net *.gstatic.com *.trustpilot.com *.onlinebooze.co.uk js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net *.mailchimp.com *.onlinebooze.co.uk unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://in-automate.brevo.com https://cdn.segment.com https://api.segment.io https://*.hokodo.co *.tawk.to wss://*.tawk.to *.cloudflare.com *.doubleclick.net *.onlinewebfonts.com *.klaviyo.com *.kissmetrics.com *.onlinebooze.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://acsbapp.com https://snap.licdn.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://static.ads-twitter.com https://analytics.twitter.com https://connect.facebook.net https://cdn.cookielaw.org https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://cdnsecakmi.kaltura.com https://cdnapisec.kaltura.com http://cdnapi.kaltura.com https://cfvod.kaltura.com https://www.google-analytics.com https://cdn.jsdelivr.net https://script.crazyegg.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://bam.nr-data.net https://hm.baidu.com/hm.js https://www.clarity.ms https://www.googleadservices.com blob: https://vjs.zencdn.net/5.0/video.min.js https://analytics.tiktok.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' https: data; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://fonts.googleapis.com https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://script.crazyegg.com https://static.cloudflareinsights.com https://cdnapisec.kaltura.com https://cfvod.kaltura.com https://vjs.zencdn.net/5.0/video-js.min.css https://analytics.tiktok.com; frame-ancestors 'self'; report-uri /jp-ja/report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: https://api.systempay.fr/static/ *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.mapbox.com *.colissimo.fr *.6tematik.fr https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.gstatic.com *.googleapis.com *.mapbox.com *.colissimo.fr *.6tematik.fr https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.mapbox.com *.colissimo.fr *.6tematik.fr https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mapbox.com *.colissimo.fr *.6tematik.fr https://api.systempay.fr/static/ *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.mapbox.com *.colissimo.fr *.6tematik.fr https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.mapbox.com *.colissimo.fr *.6tematik.fr https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://use.typekit.net https://cuatro.sim-cdn.nl https://p.typekit.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl https://use.typekit.net; script-src 'nonce-YjczYTc3MjItZmNjMC00NzkxLThiNzMtMDAwYmRiOTJiY2E5' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 object-src 'none'; connect-src 'self' *.joymii.com *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.joymii.com *.adulttime.com join.gammasecure.com; script-src 'self' *.joymii.com *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.joymii.com *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src static.klaviyo.com use.typekit.net fonts.gstatic.com 'unsafe-inline' data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paymentexpress.com *.windcave.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.paymentexpress.com *.windcave.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.youtube.com https://c.paypal.com/ *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.gstatic.com maps.googleapis.com *.doubleclick.net store.paradoxlabs.com *.smartwaiver.com static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com pixel.locker2.com arttrk.com *.reddit.com um.simpli.fi s.ad.smaato.net sync.1rx.io eb2.3lift.com simplifi.partners.tremorhub.com *.agkn.com pixel.tapad.com sync.inmobi.com sync.targeting.unrulymedia.com sync.intentiq.com *.pubmatic.com ads.stickyadstv.com loadm.exelator.com ib.adnxs.com *.yahoo.com sync.bfmio.com stags.bluekai.com sync-tm.everesttech.net bcp.crwdcntrl.net ce.lijit.com *.pro-market.net pixel.rubiconproject.com idsync.rlcdn.com *.openx.net pippio.com live.primis.tech p.adsymptotic.com x.bidswitch.net bh.contextweb.com ads.betweendigital.com ads.yieldmo.com sync.smartadserver.com *.paymentexpress.com *.windcave.com https://t.co https://analytics.twitter.com https://www.google.com https://c.clarity.ms https://*.cloudfront.net https://c.bing.com https://router.infolinks.com https://match.sharethrough.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.disqus.com https://img.youtube.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com polyfill.io *.bolt.com *.commerce-quick-checkout.com *.smartwaiver.com *.kaptcha.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com tagmanager.google.com *.facebook.net unpkg.com www.redditstatic.com www.clarity.ms *.stackadapt.com *.simpli.fi *.paymentexpress.com *.windcave.com https://sec.webeyez.com https://static.ads-twitter.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.paypal.com songbirdstag.cardinalcommerce.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com https://www.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.smartwaiver.com static.klaviyo.com unsafe-inline assets.braintreegateway.com tagmanager.google.com tags.srv.stackadapt.com *.googleapis.com *.typekit.net https://static-tracking.klaviyo.com https://static.klaviyo.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com *.reddit.com www.redditstatic.com *.stackadapt.com *.clarity.ms *.smartwaiver.com https://send.webeyez.com https://api-js.datadome.co https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.com *.simpli.fi googleads.g.doubleclick.net www.googletagmanager.com cdnjs.cloudflare.com cdn.jsdelivr.net *.fontawesome.com *.rlets.com player.vimeo.com s3-us-west-1.amazonaws.com connect.facebook.net; object-src 'self' ; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com cdn.jsdelivr.net cdn.honey.io; img-src 'self' data: *.simpli.fi *.google.com bat.bing.com pubads.g.doubleclick.net *.googletagmanager.com api.mapbox.com *.googleadservices.com www.google.ie cm.g.doubleclick.net *.rlets.com rtb-csync.smartadserver.com us-u.openx.net bat.bing.com *.fontawesome.com sync.targeting.unrulymedia.com ps.eyeota.net pixel.tapad.com simplifi.partners.tremorhub.com pixel.rubiconproject.com idsync.rlcdn.com bcp.crwdcntrl.net ib.adnxs.com *.googleadservices.com ce.lijit.com fei.pro-market.net sync.intentiq.com s.ad.smaato.net aa.agkn.com eb2.3lift.com sync.bfmio.com loadm.exelator.com ads.stickyadstv.com image2.pubmatic.com sync.1rx.io ups.analytics.yahoo.com loadm.exelator.com idsync.rlcdn.com fei.pro-market.net https: um.simpli.fi; media-src 'self' ; frame-src 'self' *.rlets.com player.vimeo.com *.googletagmanager.com td.doubleclick.net vimeo.com www.youtube.com useast-www.securly.com gateway.zscalerthree.net; frame-ancestors 'self' ; child-src 'self' ; font-src 'self' data: ms-browser-extension; connect-src 'self' *.google-analytics.com *.google.com *.localiq.com bat.bing.com *.rlets.com capture-api.reachlocalservices.com *.googletagmanager.com stats.g.doubleclick.net googleads.g.doubleclick.net *.googleadservices.com google.com api.clockwisemd.com www.google.de www.google.com.sg www.google.co.in 127.0.0.1; report-uri /report-csp-violation; upgrade-insecure-requests 1 font-src *.cloudflare.com *.twitter.com https://*.gstatic.com https://*.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.twitter.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * vars.hotjar.com www.gstatic.com staging.busdepot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://*.doubleclick.net https://*.google.com https://*.google.co.uk https://*.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com https://www.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.hotjar.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com https://*.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://*.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com in.hotjar.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 worker-src blob:; font-src https://*.yotpo.com https://use.typekit.net https://netdna.bootstrapcdn.com 'self' data: *.googleapis.com https://www.gstatic.com *.kodaris.com *.amazonaws.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://forms.hsforms.com https://www.google.com https://www.gstatic.com *.tradecentric.com 'self' data: *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.punchout2go.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://forms.hsforms.com *.google.com *.duosecurity.com *.creditkey.com https://www.socialintents.com *.tradecentric.com *.cenpos.net *.cenpos.com *.gstatic.com *.cardinalcommerce.com *.punchout2go.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com blob: c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' blob: data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com https://*.hsforms.com https://www.google.com https://www.gstatic.com https://*.yotpo.com https://amcglobal.sc.omtrdc.net https://*.punchout2go.com https://hanes.resultspage.com https://empirerigging.resultspage.com https://assets.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://creditkey-assets.s3-us-west-2.amazonaws.com https://*.hanessupply.com https://*.empirerigging.com https://forms.hsforms.com https://track.hubspot.com www.google.de/ads/ga-audiences *.cenpos.net *.cenpos.com *.googleapis.com https://*.gstatic.com *.kodaris.com *.amazonaws.com *.monsido.com bat.bing.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://coc.codes/images/badge/41497493 https://d10lpsik1i8c69.cloudfront.net *.shopperapproved.com https://firebasestorage.googleapis.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com *.reddit.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com https://js.hsforms.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google.com https://ajax.googleapis.com https://www.gstatic.com https://*.yotpo.com https://*.newrelic.com https://*.demdex.net https://*.aptrinsic.com https://*.nr-data.net https://hanes.resultspage.com https://empirerigging.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://unpkg.com https://www.socialintents.com https://*.g.doubleclick.net *.tradecentric.com https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://*.hscollectedforms.net *.cenpos.com *.cenpos.net *.google.com *.gstatic.com *.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.kodaris.com *.amazonaws.com *.monsido.com *.punchout2go.com bat.bing.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://polyfill-fastly.io https://d10lpsik1i8c69.cloudfront.net *.hubspot.com https://cdn-in.pagesense.io/js/innopplitservices/51b88749fcca40fbbdf7fef19d4c664d.js https://static.zohocdn.com *.shopperapproved.com *.avada.io *.shopify.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.cloudflare.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://www.google.com https://www.gstatic.com https://*.yotpo.com https://*.aptrinsic.com https://hanes.resultspage.com https://empirerigging.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://*.typekit.net https://www.socialintents.com https://netdna.bootstrapcdn.com *.tradecentric.com 'self' data: fonts.googleapis.com *.kodaris.com *.gstatic.com *.googleapis.com *.amazonaws.com *.jsdelivr.net *.punchout2go.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://d10lpsik1i8c69.cloudfront.net https://static.zohocdn.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com https://forms.hsforms.com *.amazonaws.com https://*.yotpo.com https://*.demdex.net https://*.aptrinsic.com https://www.google-analytics.com https://*.g.doubleclick.net https://*.punchout2go.com https://maps.googleapis.com https://*.nr-data.net *.tradecentric.com https://forms.hscollectedforms.net *.googleapis.com *.kodaris.com *.monsido.com bat.bing.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://api.luckyorange.com https://settings.luckyorange.net https://pubsub.googleapis.com wss://visitors.live wss://*.visitors.live *.hubspot.com https://*.pagesense.io https://*.zoho.in https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net https://imgs.signifyd.com https://sirius-staging.atwixlabs.tech https://sirius.atwixlabs.tech 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'report-sample' 'nonce-rgfaSsPbNiGbfhUcCa7fsQ' 'unsafe-inline' 'unsafe-eval';object-src 'none';base-uri 'self';worker-src 'self';report-uri /us/_/ThinkWithGoogle/cspreport 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com 'self' data: sw-assets.ekomiapps.de data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.sagepay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * consentcdn.cookiebot.com consentcdn.cookiebot.eu maps.googleapis.com chart.googleapis.com *.sagepay.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.feedoptimise.com cdn.feedoptimise.com 'self' data: www.google.pl sw-assets.ekomiapps.de services.postcodeanywhere.co.uk digitalasset.intuit.com guarantee-cdn.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com consent.cookiebot.com consent.cookiebot.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.feedoptimise.com cdn.feedoptimise.com maps.googleapis.com chart.googleapis.com *.sagepay.com woodh11116.pcapredict.com www.smartsuppchat.com consentcdn.cookiebot.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de services.postcodeanywhere.co.uk *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com *.fontawesome.com *.googleapis.com *.gstatic.com sw-assets.ekomiapps.de services.postcodeanywhere.co.uk *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com maps.googleapis.com chart.googleapis.com *.sagepay.com *.google-analytics.com *.doubleclick.net bootstrap.smartsuppchat.com widgets.ekomi.com smart-widget-assets.ekomiapps.de services.postcodeanywhere.co.uk sw-assets.ekomiapps.de *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com *.typekit.net 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.hsforms.net *.hsforms.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.fontawesome.com *.typekit.net *.typography.com *.nationwideschooluniforms.co.uk *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.ideal-postcodes.co.uk t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.maxcdn.bootstrapcdn.com/ *.klarnacdn.net *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.bootstrapcdn.com embed.tawk.to *.adnxs.com *.omappapi.com *.yotpo.com theflightcasecompany.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com/ *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com theflightcasecompany.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com theflightcasecompany.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.braintreepayments.com https://www.facebook.com/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.yotpo.com theflightcasecompany.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io cdn.doofinder.com *.twitter.com *.imagekit.io *.meetanshi.com https://www.google.co.in/ads/ga-audiences https://bat.bing.com/action/0 www.sandbox.paypal.com https://c.clarity.ms/c.gif *.googleusercontent.com *.elfsightcdn.com *.theflightcasecompany.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.adnxs.com pixel-geo.prfct.co cm.g.doubleclick.net *.doubleclick.net *.cdninstagram.com *.fbcdn.net maps.googleapis.com *.yotpo.com theflightcasecompany.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com tagmanager.google.com https://www.googletagmanager.com cdn.doofinder.com *.googletagmanager.com *.clarity.ms *.elfsight.com *.elfsightcdn.com *.intercomcdn.com *.intercom.io *.theflightcasecompany.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.mgt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com ajax.googleapis.com *.hotjar.com *.omappapi.com embed.tawk.to *.adnxs.com pixel-geo.prfct.co *.jsdelivr.net *.perfectaudience.com *.marketingautomation.services *.instagram.com *.yotpo.com theflightcasecompany.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.doofinder.com *.theflightcasecompany.com downloads.mailchimp.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.typekit.net *.bootstrapcdn.com embed.tawk.to *.adnxs.com *.omappapi.com *.yotpo.com theflightcasecompany.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tawk.to *.cdninstagram.com theflightcasecompany.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com *.doofinder.com wss://*.doofinder.com https://r.clarity.ms/collect *.google-analytics.com *.braintree-api.com *.googleadservices.com *.googleapis.com *.sandbox.paypal.com *.hotjar.io *.elfsight.com *.service.elfsight.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.mgt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.link.com *.amazon.com *.tawk.to *.adnxs.com embed.tawk.to *.omappapi.com wss://vsa49.tawk.to wss://*.tawk.to *.doubleclick.net stats.g.doubleclick.net *.instagram.com *.googleusercontent.com *.yotpo.com theflightcasecompany.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com theflightcasecompany.com http: https: blob: 'self' 'unsafe-inline'; default-src theflightcasecompany.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.googleapis.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com *.dotdigital-pages.com *.dotdigital.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.online-metrix.net/ d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com quickchart.io *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com checkout.airwallex.com h.online-metrix.net/ cdn.ampproject.org raw.githubusercontent.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com cdn.dnky.co api.comapi.com webchat.dotdigital.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com maxcdn.bootstrapcdn.com fonts.gstatic.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com checkout.airwallex.com h.online-metrix.net/ cdn.ampproject.org *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com api.comapi.com webchat.dotdigital.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.fontawesome.com https://fonts.bunny.net *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ https://cdn.cardknox.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.cardknox.com/ifields/2.6.2006.0102/ifields.min.js *.googleapis.com *.google.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.google.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net commerce.adobe.net *.bolt.com qa-api.magedevteam.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net https://www.googletagmanager.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua maps.gstatic.com 1rx.io *.1rx.io 360yield.com *.360yield.com 3lift.com *.3lift.com adnxs.com *.adnxs.com billiger.de *.billiger.de bing.com *.bing.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com google.de *.google.de idealo.com *.idealo.com media.net *.media.net omnitagjs.com *.omnitagjs.com roeye.com *.roeye.com roeyecdn.com *.roeyecdn.com sharethrough.com *.sharethrough.com smartadserver.com *.smartadserver.com taboola.com *.taboola.com teads.tv *.teads.tv tremorhub.com *.tremorhub.com twiago.com *.twiago.com uimserv.net *.uimserv.net usd.de *.usd.de usercentrics.eu *.usercentrics.eu yieldlab.net *.yieldlab.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://a.timeshop24.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com bing.com *.bing.com criteo.com *.criteo.com cdnsrv.de *.cdnsrv.de clickcease.com *.clickcease.com df-srv.de *.df-srv.de fatmedia.io *.fatmedia.io facebook.net *.facebook.net id5-sync.com *.id5-sync.com kuponacdn.de *.kuponacdn.de livechatinc.com *.livechatinc.com pinimg.com *.pinimg.com roeyecdn.com *.roeyecdn.com shopgate.com *.shopgate.com uicdn.com *.uicdn.com usercentrics.eu *.usercentrics.eu googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com www.xtento.com cdn.xtento.com https://www.dwin1.com https://a.timeshop24.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com googletagmanager.com *.googletagmanager.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com criteo.com *.criteo.com doubleclick.net *.doubleclick.net facebook.com *.facebook.com livechatinc.com *.livechatinc.com pinterest.com *.pinterest.com usercentrics.eu *.usercentrics.eu *.wepowerconnections.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://a.timeshop24.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://api.oneworldvirtual.org https://acars.oneworldvirtual.org https://tiles.vasystem.org https://flight-analyses.vasystem.org; font-src 'self'; img-src 'self' https://www.gravatar.com https://images.vasystem.org blob: data:; manifest-src 'self'; script-src 'self'; style-src 'self' https://storage.oneworldvirtual.org 'nonce-3xK+3RDzB96DMwYDgol4cledX6M'; style-src-attr 'unsafe-inline'; report-uri https://oneworldvirtual.org/csp/report 1 script-src-elem https://static.zdassets.com https://widget.trustpilot.com https://www.hifigear.co.uk https://www.googletagmanager.com https://js.stripe.com https://widget-mediator.zopim.com https://www.google-analytics.com https://staticw2.yotpo.com https://js.klarna.com https://code.jquery.com; font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.gstatic.com *.fontawesome.com *.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://widget.trustpilot.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com https://code.jquery.com x.klarnacdn.net *.klarnaservices.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.fontawesome.com *.googleapis.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.klarnacdn.net *.googleapis.com *.googletagmanager.com *.fontawesome.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://ekr.zdassets.com https://hifigear.zendesk.com wss://widget-mediator.zopim.com x.klarnacdn.net *.klarnaservices.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com data: *.cloudflare.com *.googleapis.com *.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.b-cdn.net *.fontawesome.com https://static.payzen.eu/static/ https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.doubleclick.net 'self' userlike-cdn-umm.b-cdn.net www.google.com/recaptcha/ *.google.com secure.payzen.eu/vads-payment/ static.payzen.eu/static/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com www.commercepartnerhub.com *.googletagmanager.com https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.tile.openstreetmap.org maps.googleapis.com maps.gstatic.com blob: *.cloudflare.com *.facebook.com *.google.com *.google.ch *.google-analytics.com *.google.fr *.googleadservices.com *.googleapis.com *.googleusercontent.com *.gstatic.com *.klarna.com *.lightemporium.com https://meetanshi.com/media/logo.png *.ovh.net *.paypal.com *.twimg.com *.usercentrics.eu *.ytimg.com *.userlike.com userlike-cdn-web.b-cdn.net userlike-cdn-operators.s3-eu-west-1.amazonaws.com userlike-store-media-files.s3.amazonaws.com *.clarity.ms *.bing.com *.zendesk.com *.laulhere-france.com *.doubleclick.net https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.beyable.com *.bootstrapcdn.com *.cloudflare.com *.clarity.ms www.facebook.com *.fontawesome.com *.google.com *.google-analytics.com *.googleapis.com *.googleusercontent.com *.gstatic.com *.trustedshops.com *.twimg.com *.usercentrics.eu *.amazonaws.com *.b-cdn.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com userlike-cdn-umm.b-cdn.net *.zdassets.com api.eu-1.smooch.io *.kameleoon.eu *.kameleoon.com *.kameleoon.io *.laulhere-france.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://unpkg.com/aos@2.3.1/dist/aos.css *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.trustedshops.com *.twimg.com *.typekit.net *.usercentrics.eu *.googletagmanager.com https://static.payzen.eu/static/ https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com *.cargo-webproject.com *.cloudflare.com *.doubleclick.net *.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.gstatic.com *.paypal.com *.twimg.com *.twitter.com *.amazonaws.com *.userlike.com wss://umd.userlike.com userlike-cdn-web.b-cdn.net blob: *.zdassets.com *.zendesk.com wss://api.eu-1.smooch.io/faye *.clarity.ms business.facebook.com graph.facebook.com www.commercepartnerhub.com connect.facebook.net *.kameleoon.eu *.kameleoon.com *.kameleoon.io *.laulhere-france.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ www.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://agropur.ddev.site https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://js.zi-scripts.com https://dokumfe7mps0i.cloudfront.net https://builder.lift.acquia.com https://players.brightcove.net https://vjs.zencdn.net https://js-agent.newrelic.com https://www.google.com https://www.gstatic.com https://cdn.cookielaw.org https://acsbapp.com https://snap.licdn.com https://www.clarity.ms https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://polyfill-fastly.io https://unpkg.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; worker-src 'self' https://agropur.ddev.site blob:; frame-ancestors 'self' 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com maps.google.com maps.googleapis.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-A9OJ2hrhpLRH4r7I4n1kcWj2EBs=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 upgrade-insecure-requests; default-src 'none'; object-src 'self'; media-src 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src https://www.youtube.com; img-src 'self' data: https://www.google-analytics.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'nonce-258e87d235b48894ea9e67405b12e2ee6d246772' 'sha256-NeueIEO8rwnaeJW0jYHRwrarPP+KzGzhk6xBJ06ntlw=' https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://maps.googleapis.com; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://v2.zopim.com https://cdn.travel-insides.com https://www.googletagmanager.com https://www.google-analytics.com https://static.zdassets.com; style-src 'self' 'unsafe-inline' https://cdn.travel-insides.com https://fonts.googleapis.com; img-src 'self' data: https://cdn.travel-insides.com https://www.google-analytics.com https://d3plhpfg3500fc.cloudfront.net; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://ekr.zdassets.com https://stream.travel-dev.com https://www.google-analytics.com https://hop2travel.zendesk.com wss://widget-mediator.zopim.com; report-uri /csp-report-endpoint; 1 default-src 'self';script-src 'self' matomo.neanderthal-blog.de;style-src 'self' 'unsafe-inline';img-src 'self' blob: data:;connect-src 'self' matomo.neanderthal-blog.de;object-src 'none';media-serc 'self';font-src 'self';base-uri 'self';form-action 'self';frame-ancestors 'none';block-all-mixed-content;upgrade-insecure-requests;report-uri https://neanderthal.de/csp/report/;report-to default; 1 connect-src 'self' https://*.analytics.google.com https://*.google-analytics.com https://*.googletagmanager.com https://bnp-privacy.my.onetrust.com https://quotes.bnpparibasmarkets.be https://quotes.bnpparibasmarkets.ch https://quotes.produitsdebourse.bnpparibas.fr https://quotes.bnpparibasmarkets.nl https://quotes.varant.bnpparibas.com.tr https://cdn.cookielaw.org https://cib.sc.omtrdc.net https://geolocation.onetrust.com https://in.hotjar.com https://stats.g.doubleclick.net https://vc.hotjar.io https://web-sdk-eu.aptrinsic.com https://www.google-analytics.com https://www.youtube-nocookie.com wss://websockets.bnpparibasmarkets.be wss://websockets.bnpparibasmarkets.ch wss://websockets.produitsdebourse.bnpparibas.fr wss://websockets.bnpparibasmarkets.nl wss://websockets.varant.bnpparibas.com.tr; default-src 'self'; frame-ancestors 'self' https://*.rewardsatwork.be https://www.iex.nl; frame-src 'self' https://forms.klug-newmedia.de https://vars.hotjar.com https://www.youtube.com/iframe_api https://www.youtube-nocookie.com; script-src 'self' https://*.googletagmanager.com https://assets.adobedtm.com https://bnp-privacy.my.onetrust.com https://cdn.cookielaw.org https://cdn.syndication.twimg.com https://cib.sc.omtrdc.net https://script.hotjar.com https://static.hotjar.com https://storage.googleapis.com https://www.youtube.com 'sha256-d26KPbO5JnCveBSpn7HS2ZGhVyD0bECnt3+OlmLV/RY=' 'sha256-hbsKiu0kqNRj+jtfXhSDeqmNwcqBsLKek9UU5mU2Vms=' 'nonce-GPpWz9CjbeUVkQ/x/4lE3BPXY3NNfdJrqPISVYwYPH4='; report-uri https://vicompany.report-uri.com/r/d/csp/reportOnly; 1 font-src https://fonts.gstatic.com/ https://fonts.bunny.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.facebook.com/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ http://cl.avis-verifies.com/ https://cl.avis-verifies.com/ https://www.facebook.com/ https://vars.hotjar.com/ https://ct.pinterest.com/ https://cdn.consentmanager.net https://www.googletagmanager.com/ *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org https://www.google.fr http://maps.gstatic.com/ https://maps.gstatic.com/ https://www.facebook.com/ https://ct.pinterest.com/ https://cdn1.avada.io/ https://c.delivery.consentmanager.net https://cdn.consentmanager.net https://www.gsell.fr http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com maps.googleapis.com maps.gstatic.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://s.pinimg.com/ https://static.hotjar.com/ http://s3.amazonaws.com/ https://s3.amazonaws.com/ https://connect.facebook.net/ https://maps.googleapis.com/ https://embed.sendcloud.sc/ https://servicepoints.sendcloud.sc/ https://chimpstatic.com https://cl.avis-verifies.com https://googleads.g.doubleclick.net https://script.hotjar.com http://cl.avis-verifies.com http://cdn.consentmanager.net https://cdn.consentmanager.net http://delivery.consentmanager.net c.delivery.consentmanager.net https://delivery.consentmanager.net https://ct.pinterest.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io maps.googleapis.com www.gstatic.com www.google.com https://cdn.scalapay.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ https://fonts.bunny.net *.fontawesome.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://analytics.google.com/ http://maps.googleapis.com/ https://maps.googleapis.com/ https://region1.analytics.google.com https://region1.google-analytics.com https://ct.pinterest.com/ https://in.hotjar.com/ https://googleads.g.doubleclick.net https://www.google.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io maps.googleapis.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://buttons-config.sharethis.com/js/68d16b7e6f09a63c8e6f1efb.js https://cdn.mouseflow.com/projects/d085fd17-28ad-4907-af37-b6a3b9b66963.js https://connect.facebook.net/en_US/fbevents.js https://consent.trustarc.com/v2/notice/5eaplw https://count-server.sharethis.com/v2.0/get_counts https://dl.episerver.net/13.5.7/epi-util/find.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/656808352/ https://js.hs-analytics.net/analytics/ https://js.hs-banner.com/v2/5177788/banner.js https://js.hs-scripts.com/5177788.js https://js.hsadspixel.net/fb.js https://js.hsforms.net/forms/v2.js https://js.hsleadflows.net/leadflows.js https://platform-api.sharethis.com/js/sharethis.js https://pregiseu.mpeasylink.com/mpel/mpel.js https://s3.amazonaws.com/beacon.pmmimediagroup.com/prod/script.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.cloudflareinsights.com/beacon.min.js https://t.sharethis.com/1/d/t.dhj https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/enterprise.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/iRvKkcsnpNcOYYwhqaQxPITz/recaptcha__en.js https://www.webtraxs.com/wt.php https://www.youtube.com/s/player/ https://www.googletagmanager.com/gtag/js https://secure.leadforensics.com/js/63143.js http://platform-api.sharethis.com/js/sharethis.js https://secure.leadforensics.com/js/63143.js http://pregiseu.mpeasylink.com/mpel/ https://connect.facebook.net/signals/ https://ssl.google-analytics.com/ga.js https://www.youtube.com/iframe_api http://www.pagespeed-mod.com/v1/ https://static.cloudflareinsights.com/beacon.min.js/v8b253dfea2ab4077af8c6f58422dfbfd1689876627854 https://js.zi-scripts.com https://ws-assets.zoominfo.com https://ws.zoominfo.com https://tags.clickagy.com; style-src 'report-sample' 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com https://pregiseu.mpeasylink.com https://use.fontawesome.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://api.hubapi.com https://consent-reporting.trustarc.com https://consent.trustarc.com https://dc.services.visualstudio.com https://forms.hsforms.com https://forms.hubspot.com https://l.sharethis.com https://prospector.pmmimediagroup.com https://stats.g.doubleclick.net https://www.facebook.com https://www.google-analytics.com https://cdn.linkedin.oribi.io/partner/ https://ws.zoominfo.com https://aorta.clickagy.com https://hemsync.clickagy.com; font-src 'self' data: https://cdnjs.cloudflare.com https://consent.trustarc.com https://fonts.gstatic.com https://use.fontawesome.com; frame-src 'self' https://massinteract.com https://pregiseu.mpeasylink.com https://t.sharethis.com https://www.google.com https://www.youtube.com https://www.facebook.com https://hemsync.clickagy.com; img-src 'self' data: https://analytics.convertlanguage.com https://consent-pref.trustarc.com https://consent.trustarc.com https://forms-na1.hsforms.com https://forms.hsforms.com https://l.sharethis.com https://platform-cdn.sharethis.com https://www.linkedin.com/px/ https://px.ads.linkedin.com https://track.hubspot.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.webtraxs.com https://connect.facebook.net https://5177788.fs1.hubspotusercontent-na1.net/hubfs/5177788/; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 block-all-mixed-content 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-HUM29LeyAmXzJtXy6fJpWtJPR' 'strict-dynamic'; frame-ancestors 'self'; manifest-src 'self' 1 require-trusted-types-for 'script';report-uri /_/Gstore/cspreport 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.tawk.to 'self' data: *.streammarket.co.uk *.bksmotors.com *.cloudflareinsights.com static.cloudflareinsights.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.ccavenue.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.streammarket.co.uk *.bksmotors.com *.cloudflareinsights.com static.cloudflareinsights.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.ccavenue.com landofcoder.com *.google.com.ua *.google.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com *.twitter.com *.addthis.com *.doubleclick.net *.embedly.com *.rvvup.com *.streammarket.co.uk *.bksmotors.com https://accounts.google.com/gsi/ *.cloudflareinsights.com static.cloudflareinsights.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com *.ccavenue.com *.google.com *.google.com.ua *.google.co.uk *.doubleclick.net https://meetanshi.com/media/logo.png www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.co.in *.jsdelivr.net www.logicrays.com www.magecomp.com *.amazonaws.com *.securitymetrics.com *.postcodeanywhere.co.uk *.streammarket.co.uk *.bksmotors.com *.facebook.net *.facebook.com blob: *.cloudflareinsights.com *.cdn.trustindex.io/ *.googleusercontent.com static.cloudflareinsights.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com *.ccavenue.com landofcoder.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu embed.tawk.to cdn.jsdelivr.net *.razorpay.com indep11146.pcapredict.com *.postcodeanywhere.co.uk *.googleapis.com *.feefo.com *.streammarket.co.uk *.bksmotors.com *.facebook.net *.lightwidget.com *.googleadservices.com *.adobedtm.com *.checkout.razorpay.com *.cloudflareinsights.com https://accounts.google.com/gsi/client static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.jsdelivr.net *.google.com *.postcodeanywhere.co.uk *.streammarket.co.uk *.bksmotors.com *.unpkg.com https://unpkg.com/swiper@11.1.14/swiper-bundle.min.css https://unpkg.com/swiper/swiper-bundle.min.css https://accounts.google.com/gsi/style *.cloudflareinsights.com static.cloudflareinsights.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com *.granberg.se 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com *.ccavenue.com landofcoder.com *.google-analytics.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com *.cloudflare.com *.twitter.com *.twimg.com *.tawk.to *.doubleclick.net *.amazonaws.com *.securitymetrics.com *.embedly.com *.rvvup.com *.postcodeanywhere.co.uk *.googleapis.com *.streammarket.co.uk *.bksmotors.com *.facebook.net *.facebook.com https://accounts.google.com/gsi/ *.cloudflareinsights.com static.cloudflareinsights.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.streammarket.co.uk *.bksmotors.com *.facebook.net *.cloudflareinsights.com static.cloudflareinsights.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.google.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://images.unsplash.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com maps.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://*.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com downloads.mailchimp.com assets.braintreegateway.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action 'self' 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; script-src 'self' https://www.googletagmanager.com https://*.google-analytics.com https://openlayers.org https://www.youtube.com https://www.apex-timing.com https://matomo-tracking.fia.com; style-src 'self' 'unsafe-inline' https://openlayers.org https://curator-assets.b-cdn.net https://p.typekit.net https://use.typekit.net; img-src 'self' data: https://*.basemaps.cartocdn.com https://backend.fiakarting.com https://curator-assets.b-cdn.net https://www.google-analytics.com https://www.googletagmanager.com https://openlayers.org https://matomo-tracking.fia.com https://www.youtube.com https://*.ytimg.com; font-src 'self' data: https://use.typekit.net; connect-src 'self' https://backend.fiakarting.com https://*.google-analytics.com https://region1.analytics.google.com https://www.googletagmanager.com https://openlayers.org https://www.apex-timing.com https://matomo-tracking.fia.com; frame-src 'self' https://www.youtube.com https://www.apex-timing.com; 1 script-src-elem 'unsafe-inline' *.brightpearlapp.com *.google.com *.pokerchips.com *.adobedtm.com *.gstatic.com trustspot.io *.livechatinc.com *.designnbuy.us cdn.jsdelivr.net *.googleapis.com *.stripe.com www.googletagmanager.com www.google-analytics.com *.pokerchips.dev *.cloudflare.com www.dropbox.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md *.cometlytrack.com *.klaviyo.com app.ravecapture.com *.newrelic.com *.impactcdn.com *.attn.tv *.emotivecdn.io emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com; font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net trustspot.io s3.amazonaws.com *.stripe.com *.brightpearlapp.com *.demdex.net *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.google.md *.typekit.net fonts.gstatic.com use.typekit.net *.cometlytrack.com *.klaviyo.com trustspot-app-assets.s3.amazonaws.com app.ravecapture.com *.impactcdn.com *.attn.tv *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com *.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md *.impactcdn.com *.attn.tv *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com js.stripe.com magento-cloudflare.jetrails.com trustspot.io *.livechatinc.com *.google.com *.stripe.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md td.doubleclick.net *.impactcdn.com *.attn.tv *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com https://plumrocket.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.google.com s3.amazonaws.com trustspot.io *.stripe.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md *.cometlytrack.com *.klaviyo.com ravecapture-app-assets.s3.amazonaws.com app.ravecapture.com *.impactcdn.com *.attn.tv *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com *.cloudfront.net *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io 'unsafe-inline' trustspot.io *.livechatinc.com *.designnbuy.us cdn.jsdelivr.net *.google.com *.stripe.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md *.cometlytrack.com *.klaviyo.com *.impactcdn.com *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net trustspot.io s3.amazonaws.com *.stripe.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.google.md *.g.doubleclick.net tagmanager.google.com app.ravecapture.com *.cometlytrack.com *.klaviyo.com *.impactcdn.com *.attn.tv *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com *.cloudfront.net 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io stats.g.doubleclick.net trustspot.io *.livechatinc.com *.stripe.com *.brightpearlapp.com *.pokerchips.com *.pokerchips.dev *.cloudflare.com landofcoder.com connect.facebook.net *.facebook.com *.googleadservices.com *.g.doubleclick.net *.google.md *.cometlytrack.com *.klaviyo.com *.impactcdn.com *.emotivecdn.io *.reviews.co.uk *.reviews.io *.googletagmanager.com *.google.com pokerchipscom.sjv.io *.emotiveapp.co *.cloudfront.net *.google-analytics.com *.doubleclick.net *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://pokerchips.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 script-src https://www.googletagmanager.com/gtm.js 'unsafe-inline' 'self' https://payments.salesforce.com/ https://stats.g.doubleclick.net https://autodiag.anap.fr/ https://anap--c.vf.force.com/resource/1673539645000/Favicon https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://youtu.be https://kit.fontawesome.com/e4122e457f.js https://anap.matomo.cloud/ https://anap.fr https://app.fabric.microsoft.com https://checkoutshopper-live.adyen.com/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://static.axept.io/sdk.js https://api.qrserver.com https://cdn.matomo.cloud/anap.matomo.cloud/container_idJebPZk.js https://pay.google.com https://api.ipify.org https://tagmanager.google.com https://it4v7.interactiv-doc.fr https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://teams.microsoft.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://cdn.matomo.cloud/anap.matomo.cloud/matomo.js blob: https://anap.fr/cms/delivery/media/MCZCCUKGVGPZEENGKT5DNFH3Y5TA https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://www.anap.fr/ https://airtable.com/embed/appfTkAvAEjoh https://js.stripe.com/ https://www.anap.fr/s/ https://client.axept.io https://youtube.com https://www.googletagmanager.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval'; report-to sfdc-csp-ep; report-uri https://anap.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D7Q000006HfIy&networkId=0DM7Q000000tJ68&type=communities 1 font-src *.googleapis.com *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 667da16c08c64bfbba4e44bd355bca67.svc.dynamics.com *.svc.dynamics.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com mktdplp102cdn.azureedge.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'nonce-zU52EWtz9xjQFUuVzClpkRFituN8C4T3VnG3ih5fsi8=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-hHbLZFLkTDocqe0hirLlUZLow+o=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.dk/api/csp-report; report-to csp-endpoint 1 connect-src 'self' *.hotjar.com/api/v2/client/ws *.hotjar.io *.trengo.eu https://*.analytics.google.com https://*.chatservice.co/ https://*.cookiepro.com https://*.cookieyes.com https://*.google-analytics.com https://*.google.co.uk https://*.google.com https://*.googletagmanager.com https://*.livechatinc.com https://*.mapbox.com https://*.onetrust.com https://*.reddit.com https://*.redditstatic.com https://*.snapchat.com https://*.tiktok.com https://stats.g.doubleclick.net https://tcs-analytics-tracker.now.sh https://tcs-analytics-tracker.vercel.app https://vitastudent-develop.go-vip.net https://www.facebook.com/tr https://www.google.co.uk wss://ws.hotjar.com/api/v2/client/ws; default-src data: 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' *.cookiepro.com *.doubleclick.net *.facebook.net *.google.com *.googleapis.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.livechatinc.com *.snapchat.com *.tiktok.com *.vitastudent.com *.wp.com https://cht-srvc.net https://r1-t.trackedlink.net/_dmpt.js https://sc-static.net/scevent.min.js https://vita.students; frame-ancestors 'self' https://*.mapbox.com https://www.google.com https://www.youtube.com; img-src data: 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' 'wasm-unsafe-eval' *.cookiepro.com *.gravatar.com *.snapchat.com *.wp.com https://*.bing.com https://*.brandfolder.io https://*.facebook.com https://*.reddit.com https://cdn-cookieyes.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.gstatic.com *.trengo.eu *.vitastudent.com https://*.chatservice.co https://*.hotjar.com https://*.livechatinc.com https://*.snapchat.com https://*.wp.com https://analytics.tiktok.com https://api.mapbox.com/* https://cdn-ukwest.onetrust.com https://connect.facebook.net https://cookie-cdn.cookiepro.com https://cookie-cdn.cookiepro.com/scripttemplates/otSDKStub.js https://dist.chatservice.co/latest/customerService.js https://googleads.g.doubleclick.net https://js.chatservice.co/v0/switch.js https://r1-t.trackedlink.net https://s0.wp.com https://sc-static.net https://ssl.google-analytics.com https://static.ads-twitter.com https://static.srcspot.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.googleoptimize.com https://www.googletagmanager.com https://www.vitastudent.com https://www.youtube.com; script-src-elem 'self' 'unsafe-inline' *.cookiepro.com *.doubleclick.net *.facebook.net *.google.com *.googletagmanager.com *.livechatinc.com *.snapchat.com *.tiktok.com *.trackedlink.net *.wp.com https://*.bing.com https://*.redditstatic.com https://cdn-cookieyes.com https://cht-srvc.net https://sc-static.net https://vita.students; worker-src blob: 'self' 'unsafe-inline' https://vitastudent.com https://www.vitastudent.com 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.feedbackcompany.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.feedbackcompany.com *.nosto.com *.nos.to *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.nosto.com *.nos.to *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com imgsct.cookiebot.com *.feedbackcompany.com magefan.com cm.magefan.com *.nosto.com *.nos.to https://www.unifaunonline.se https://*.tile.openstreetmap.org/ flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn2.hubspot.net resources.paytrail.com https://shareasale.com/sale.cfm https://track.linksynergy.com https://www.bizrate.com https://www.awin1.com https://track.webgains.com https://prf.hn https://track.flexlinks.com https://scripts.affiliatefuture.com https://t.powerreviews.com https://match.sharethrough.com https://cm.g.doubleclick.net https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://jadserve.postrelease.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://ps.eyeota.net https://public-prod-dspcookiematching.dmxleo.com *.getqonfi.com agryghsjho.cloudimg.io *.amazonaws.com www.google.com.ua https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com consent.cookiebot.com *.feedbackcompany.com *.nosto.com *.nos.to s7.addthis.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io https://api.unifaun.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com https://www.dwin1.com https://intljs.rmtag.com https://cdn.avmws.com https://images.bizrate.com https://www.awin1.com https://swrap.tradedoubler.com https://analytics.optimalpeople.fr https://www.linkconnector.com https://d3v27wwd40f0xu.cloudfront.net https://static.criteo.net https://sslwidget.criteo.com https://*.affiliatefuture.com https://static.powerreviews.com *.getqonfi.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://gluehbirnebillig.de https://load.kt1pq.gluehbirnebillig.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.nosto.com *.nos.to https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.feedbackcompany.com *.nosto.com *.nos.to ekr.zdassets.com/ https://get.geojs.io *.avada.io www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.paytrail.com https://shareasale.com/sale.cfm https://analytics.optimalpeople.fr https://measurement-api.criteo.com *.getqonfi.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://load.kt1pq.gluehbirnebillig.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' http://proxyman.debug:3000 http://localhost:3000 https://accounts.google.com https://cdn.cookielaw.org https://*.onetrust.com https://sentry.io https://*.ingest.us.sentry.io https://unpkg.com https://wallpapers.com https://s3.amazonaws.com https://api.mirego.com; default-src 'none'; font-src 'self' fonts.mirego.com fonts.gstatic.com *.typekit.net www.mirego.com; form-action 'self'; frame-src https://mirego-website.scout.mirego.com https://accounts.google.com https://js.stripe.com https://www.youtube.com; img-src 'self' blob: data: https://*.googleusercontent.com https://cdn.cookielaw.org https://wallpapers.com https://s3.amazonaws.com d3gude8cge9lnv.cloudfront.net d72zxqwaon87r.cloudfront.net mirego-website-webapp-qa.dev.mirego.com https://images.mirego.com www.mirego.com; media-src 'self' mirego-website-webapp-qa.dev.mirego.com d3gude8cge9lnv.cloudfront.net d72zxqwaon87r.cloudfront.net https://s3.amazonaws.com www.mirego.com https://images.mirego.com; script-src 'sha256-ZX+ZjgijHT9u5/zwXFM2FqnD4sZoAg4KQ5f2iovVvCo=' 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://accounts.google.com https://cdn.cookielaw.org https://js.stripe.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.youtube.com https://unpkg.com ; script-src-attr 'sha256-ZX+ZjgijHT9u5/zwXFM2FqnD4sZoAg4KQ5f2iovVvCo=' 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://accounts.google.com https://cdn.cookielaw.org https://js.stripe.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.youtube.com https://unpkg.com ; script-src-elem 'sha256-ZX+ZjgijHT9u5/zwXFM2FqnD4sZoAg4KQ5f2iovVvCo=' 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://accounts.google.com https://cdn.cookielaw.org https://js.stripe.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.youtube.com https://unpkg.com ; style-src 'self' 'unsafe-inline' fonts.googleapis.com accounts.google.com www.mirego.com; 1 font-src maxcdn.bootstrapcdn.com *.fontawesome.com fonts.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.awin1.com *.zenaps.com https://images.unsplash.com flagpedia.net https://www.mollie.com www.bunzlaucastle.nl www.bunzlaucastle.com www.bunzlaucastle.de www.bunzlaucastle.fr www.returntosender.nl returntosender.content.clipbv.com bunzlaucastle.content.clipbv.com bat.bing.com googleads.g.doubleclick.net www.google.nl www.google.com b2b.content.clipbv.com b2b.clipbv.com www.thetable.store thetable.content.clipbv.com viavel.content.clipbv.com www.viavel.nl www.facebook.com d15k2d11r6t6rl.cloudfront.net www.googletagmanager.com api.mapbox.com pins.stockist.co stockist.co c.bing.com c.clarity.ms https://widgets.trustedshops.com https://integrations.etrusted.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://maps.googleapis.com *.gstatic.com maps.googleapis.com js.mollie.com bat.bing.com cdn-eu.pagesense.io app.reloadify.com s.pinimg.com connect.facebook.net ct.pinterest.com stockist.co cdnjs.cloudflare.com widget-portal.givacard.nl tagging.bunzlaucastle.nl pagead2.googlesyndication.com tagging.bunzlaucastle.com tagging.bunzlaucastle.de tagging.thetable.store tagging.returntosender.nl https://widgets.trustedshops.com https://integrations.etrusted.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sendcloud.sc *.jsdelivr.net *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com fonts.googleapis.com stockist.co https://widgets.trustedshops.com https://integrations.etrusted.com unsafe-inline assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src b2b.content.clipbv.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://the.sciencebehindecommerce.com https://maps.googleapis.com https://player.vimeo.com www.gstatic.com maps.googleapis.com bat.bing.com app.reloadify.com region1.google-analytics.com ct.pinterest.com www.google.nl stockist.co us-central1-stockist-prod.cloudfunctions.net gap.stockist.workers.dev pro.ip-api.com www.pinterest.com widget-portal.givacard.nl tagging.bunzlaucastle.nl tagging.bunzlaucastle.com tagging.bunzlaucastle.de tagging.thetable.store pagead2.googlesyndication.com tagging.returntosender.nl www.facebook.com *.trustedshops.com *.etrusted.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com assets.reviews.io *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://images.unsplash.com www.google.co.uk assets.reviews.io c.clarity.ms https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://maps.googleapis.com cdn-eu.pagesense.io *.clarity.ms widget.reviews.co.uk seal.digicert.com *.zoho.eu gtm.adt313.net googletagmanager.com static.cloudflareinsights.com self unsafe-inline https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com maxcdn.bootstrapcdn.com assets.reviews.io data: https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://maps.googleapis.com https://player.vimeo.com stats.g.doubleclick.net cnv.adt623.net log.adtraction.fail api.reviews.co.uk pagesense-collect.zoho.eu salesiq.zohopublic.eu googleads.g.doubleclick.net *.zoho.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5138b325-f342-4866-ad48-54385dfcfca7.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com mcstaging.macfarlanepackaging.com https://fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.googletagmanager.com/ js.stripe.com b.stripecdn.com pay.google.com newassets.hcaptcha.com m.stripe.network https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com https://files.zakeke.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klevu.com *.ksearchnet.com 'self' js.klevu.com www.gstatic.com cdn.cookielaw.org public-gbr.mkt.dynamics.com *.azureedge.net macfarlanepackaging.bynder.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.klevu.com *.ksearchnet.com 'self' unpkg.com www.google.com www.gstatic.com js.stripe.com b.stripecdn.com pay.google.com hcaptcha.com m.stripe.network cdn.cookielaw.org *.livechatinc.com *.azureedge.net *.dynamics.com *.scurritrackplus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.klevu.com *.ksearchnet.com 'self' js.klevu.com www.gstatic.com js.stripe.com b.stripecdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.gstatic.com *.googleapis.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klevu.com *.ksearchnet.com 'self' *.stripe.com *.hcaptcha.com *.cardinalcommerce.com *.cookielaw.org *.dynamics.com *.azureedge.net *.googlesyndication.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' commerce.adobedc.net r.stripe.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://2679108e-012b-4aa9-9696-ac7c5fc442e1.sansec.watch/; report-to report-endpoint; 1 img-src https://higherlogicdownload.s3.amazonaws.com/NASBO/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASBO/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/NASBO/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASBO/ https://higherlogicdownload.s3.amazonaws.com/NASBO/ https://higherlogiclongterm.s3.amazonaws.com/NASBO/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/NASBO/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASBO/ 'self' https://higherlogiclongterm.s3.amazonaws.com/NASBO/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/NASBO/ https://higherlogicdownload.s3.amazonaws.com/NASBO/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASBO/ https://higherlogicstream.s3.amazonaws.com/NASBO/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/NASBO/ https://higherlogicdownload.s3.amazonaws.com/NASBO/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/NASBO/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudfront.net *.reviews.io *.reviews.co.uk fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk www.googletagmanager.com td.doubleclick.net widget.reviews.co.uk www.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk lantern.roeye.com bat.bing.com www.google.co.uk www.gstatic.com services.postcodeanywhere.co.uk *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk static.cloudflareinsights.com static.klaviyo.com static-tracking.klaviyo.com lantern.roeyecdn.com cdn.cookie-script.com www.gstatic.com bat.bing.com widget.reviews.co.uk www.clarity.ms www.google.com choco11120.pcapredict.com services.postcodeanywhere.co.uk https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk fonts.googleapis.com widget.reviews.co.uk www.gstatic.com services.postcodeanywhere.co.uk maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://the.sciencebehindecommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk bat.bing.com www.google.co.uk region1.analytics.google.com fast.a.klaviyo.com static-forms.klaviyo.com api.reviews.co.uk a.clarity.ms www.googleapis.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com a.clarity.ms www.google.com player-telemetry.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' fonts.bunny.net; img-src 'self' fraisa.cdn.celum.cloud *.tile.openstreetmap.org px.ads.linkedin.com data:; media-src 'self' 'unsafe-inline'; connect-src 'self' stat.fraisa.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' stat.fraisa.com; script-src-attr 'self' 'unsafe-inline'; worker-src 'self' blob:; report-uri https://fraisa.uriports.com/reports/report; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net js.mollie.com https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.mollie.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net *.disqus.com *.avada.io js.mollie.com https://player.vimeo.com https://www.youtube.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' stats.wp.com static.cloudflareinsights.com www.googletagservices.com *.googlesyndication.com *.googleadservices.com googleads.g.doubleclick.net adservice.google.com adservice.google.ae adservice.google.al adservice.google.at adservice.google.be adservice.google.bg adservice.google.bs adservice.google.ca adservice.google.ch adservice.google.ci adservice.google.cl adservice.google.co.bw adservice.google.co.cr adservice.google.co.id adservice.google.co.il adservice.google.co.in adservice.google.co.jp adservice.google.co.ke adservice.google.co.kr adservice.google.co.mz adservice.google.co.nz adservice.google.co.th adservice.google.co.tz adservice.google.co.uk adservice.google.co.uz adservice.google.co.ve adservice.google.co.za adservice.google.co.zm adservice.google.co.zw adservice.google.com.ai adservice.google.com.ar adservice.google.com.au adservice.google.com.bd adservice.google.com.bh adservice.google.com.bn adservice.google.com.bo adservice.google.com.br adservice.google.com.co adservice.google.com.cy adservice.google.com.ec adservice.google.com.eg adservice.google.com.et adservice.google.com.fj adservice.google.com.gh adservice.google.com.gi adservice.google.com.gt adservice.google.com.hk adservice.google.com.jm adservice.google.com.kh adservice.google.com.kw adservice.google.com.lb adservice.google.com.mm adservice.google.com.mt adservice.google.com.mx adservice.google.com.my adservice.google.com.ng adservice.google.com.ni adservice.google.com.np adservice.google.com.om adservice.google.com.pa adservice.google.com.pe adservice.google.com.ph adservice.google.com.pk adservice.google.com.pr adservice.google.com.py adservice.google.com.qa adservice.google.com.sa adservice.google.com.sg adservice.google.com.sv adservice.google.com.tr adservice.google.com.tw adservice.google.com.ua adservice.google.com.uy adservice.google.com.vn adservice.google.cz adservice.google.de adservice.google.dk adservice.google.dz adservice.google.ee adservice.google.es adservice.google.fi adservice.google.fr adservice.google.ge adservice.google.gr adservice.google.gy adservice.google.hn adservice.google.hr adservice.google.hu adservice.google.ie adservice.google.im adservice.google.iq adservice.google.is adservice.google.it adservice.google.jo adservice.google.kz adservice.google.li adservice.google.lk adservice.google.lt adservice.google.lu adservice.google.lv adservice.google.md adservice.google.mk adservice.google.mu adservice.google.nl adservice.google.no adservice.google.pl adservice.google.pt adservice.google.ro adservice.google.rs adservice.google.ru adservice.google.se adservice.google.si adservice.google.sk adservice.google.so adservice.google.sr adservice.google.tl adservice.google.tn adservice.google.tt google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com translate.googleapis.com translate.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: fonts.googleapis.com 'unsafe-inline' maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: pixel.wp.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com *.googlesyndication.com stats.g.doubleclick.net data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com translate.googleapis.com translate.google.com i.ytimg.com www.googletagmanager.com; connect-src 'self' *.googlesyndication.com googleads.g.doubleclick.net stats.g.doubleclick.net www.google-analytics.com ampcid.google.com analytics.google.com about: maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; frame-src 'self' stripe.com *.googlesyndication.com googleads.g.doubleclick.net maps.googleapis.com maps.google.com www.youtube.com www.googletagmanager.com; child-src 'self' www.youtube.com www.googletagmanager.com; block-all-mixed-content; report-uri https://www.spinal.co.uk?gdsih-csp-report; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com https://*.sameday.ro 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io *.alothemes.com *.magepow.com https://*.sameday.ro 'report-sample' 'self' *.adobedtm.com *.cardinalcommerce.com *.cloudflare.com *.google-analytics.com googletagmanager.com *.googletagmanager.com apis.google.com *.googleadservices.com https://www.gstatic.com/recaptcha https://www.google.com/recaptcha *.google.com/ https://maps.googleapis.com/maps/api/js *.instagram.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.paypalobjects.com sandbox.paypal.com *.sandbox.paypal.com https://js.stripe.com/v3/ *.stripe.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com https://*.sameday.ro 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.gstatic.com https://www.google.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.irclass.org; font-src 'self' https://fonts.gstatic.com https://www.irclass.org; img-src 'self' data: https://www.google-analytics.com https://ssl.google-analytics.com https://maps.gstatic.com https://maps.googleapis.com https://i.ytimg.com; frame-src 'self' https://www.youtube.com https://www.google.com; connect-src 'self' 'unsafe-inline' https://maps.googleapis.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com; object-src 'none'; frame-ancestors 'self' https://staging-new.irclass.net; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com 'self' data: *.tawk.to fonts.gstatic.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.tawk.to *.yotpo.com swellrewards.com *.swellrewards.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.google.com *.addthis.com *.pinterest.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * *.tawk.to *.yotpo.com swellrewards.com *.swellrewards.com https://*.online-metrix.net https://imgs.signifyd.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.tawk.to cdn.jsdelivr.net *.yotpo.com swellrewards.com *.swellrewards.com https://imgs.signifyd.com https://*.online-metrix.net https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com utt.impactcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.tawk.to cdn.jsdelivr.net *.yotpo.com swellrewards.com *.swellrewards.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.tawk.to fonts.googleapis.com cdn.jsdelivr.net *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com thm.visa.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.tawk.to wss://*.tawk.to *.yotpo.com swellrewards.com *.swellrewards.com https://imgs.signifyd.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.reviews.io *.fontawesome.com www.cheerfulsoles.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.cheerfulsoles.co.uk 'self' 'unsafe-inline'; frame-ancestors *.reviews.co.uk 'self' data: 'unsafe-inline' data: 'unsafe-inline' unsafe-inline www.cheerfulsoles.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://widget.reviews.co.uk https://webservices.securetrading.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.cheerfulsoles.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io *.reviews.io *.placeholder.com https://s3-eu-west-1.amazonaws.com/ https://www.facebook.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com validate.fishpig.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.cheerfulsoles.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://widget.reviews.co.uk *.gstatic.com *.page1monk.com chimpstatic.com https://diffuser-cdn.app-us1.com https://prism.app-us1.com https://webservices.securetrading.net https://connect.facebook.net/ downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.cheerfulsoles.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.reviews.io *.googleapis.com *.myfonts.net downloads.mailchimp.com *.fontawesome.com assets.braintreegateway.com www.cheerfulsoles.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.cheerfulsoles.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.reviews.io https://api.reviews.co.uk *.google-analytics.com *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com www.cheerfulsoles.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.cheerfulsoles.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.cheerfulsoles.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com googleapis.com 'self' data: secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; frame-ancestors secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.sharethis.com vimeo.com *.hotjar.com http://insight.adsrvr.org/ *.googletagmanager.com https://d1eoo1tco6rr5e.cloudfront.net/ https://adservices.brandcdn.com/ *.sandbox.paypal.com *.repay.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net *.dotdigital-pages.com *.dotdigital.com newassets.hcaptcha.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com blob: *.googleadservices.com *.googleapis.com *.paypalobjects.com http://insight.adsrvr.org/ *.google.com *.googletagmanager.com *.facebook.com https://match.adsrvr.org/ https://cm.g.doubleclick.net/ https://pixel.rubiconproject.com/ https://hb.yahoo.net/ https://tags.bluekai.com/ https://secure-gl.imrworldwide.com/ https://loadm.exelator.com/ https://mid.rkdms.com/ https://load77.exelator.com/ https://uipglob.semasio.net/ https://eb2.3lift.com/ https://ads.scorecardresearch.com/ https://i.liadm.com/ https://i6.liadm.com/ https://tags.rd.linksynergy.com/ https://match.sharethrough.com/ https://idpix.media6degrees.com/ https://dsum-sec.casalemedia.com/ https://x.bidswitch.net/ https://dmp.truoptik.com/ https://secure.insightexpressai.com/ https://simage2.pubmatic.com/ https://bidagent.xad.com/ *.google.co.in/ https://match.sync.ad.cpe.dotomi.com/ https://onetag-sys.com/ https://avd.innity.com/ *.repay.com addevent.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net *.trackedlink.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.sharethis.com https://connect.facebook.net https://*.hotjar.com 'unsafe-inline' *.googleadservices.com googleapis.com *.paypal.com *.sandbox.paypal.com *.googletagmanager.com *.paypalobjects.com *.googleapis.com *.gstatic.com https://p.typekit.net/ https://use.typekit.net https://*.hotjar.com http://adservices.brandcdn.com/ http://tag.brandcdn.com/ https://kadromm.atlassian.net/ addevent.com https://cdn.addevent.com/ http://localhost:8082 https://*.addevent.com/ https://duplin-winery.disqus.com/ *.repay.com dx.mountain.com *.mountain.com 'self' data: maps.googleapis.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal hcaptcha.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com https://*.hotjar.com https://p.typekit.net/ https://use.typekit.net/ *.repay.com getfirebug.com googleapis.com addevent.com *.gstatic.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; object-src secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; media-src *.adobe.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; manifest-src secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.sandbox.paypal.com *.paypalobjects.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://stats.g.doubleclick.net/ *.repay.com *.mountain.com dx.mountain.com maps.googleapis.com/ secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com 'self' 'unsafe-inline'; child-src secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net hcaptcha.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri secure.apspaymentgateway.com portal.apsclicktopay.com testportal.apsclicktopay.com aps-clicktopay.uat.repay.net aps-clicktopay.repay.net 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-eval' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; style-src 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr https://www.gstatic.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ https://www.youtube.com https://form.typeform.com platform.twitter.com syndication.twitter.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bird.eu https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr www.google.fr *.google.fr syndication.twitter.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill-fastly.io https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com colissimo.fr *.colissimo.fr cloudflare.com *.cloudflare.com data.maisonfl.fr *.jajuma.de platform.twitter.com https://euc-widget.freshworks.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://euc-widget.freshworks.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.stripe.network *.stripecdn.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com ctifl.test ctifl.fr *.ctifl.fr https://euc-widget.freshworks.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io https://nominatim.openstreetmap.org colissimo.fr *.colissimo.fr maps.googleapis.com *.google-analytics.com *.doubleclick.net data.maisonfl.fr *.jajuma.de https://euc-widget.freshworks.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://data.maisonfl.fr 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://mozbar.moz.com https://www.google.com https://stats.g.doubleclick.net https://yoast.com *.vimeo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://pi.pardot.com *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com; style-src 'self' 'unsafe-inline' data: *.vimeocdn.com fonts.googleapis.com 'unsafe-inline' maps.googleapis.com maps.google.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://www.google.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com data: blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com i.ytimg.com www.googletagmanager.com; connect-src 'self' https://yoast.com *.vimeo.com www.google-analytics.com stats.g.doubleclick.net ampcid.google.com analytics.google.com about: maps.googleapis.com maps.google.com www.googletagmanager.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; frame-src 'self' https://cdslegal.com https://mozbar.moz.com https://www.google.com https://pi.pardot.com/pd.js *.vimeo.com *.vimeocdn.com maps.googleapis.com maps.google.com www.youtube.com www.googletagmanager.com; child-src 'self' *.vimeo.com *.vimeocdn.com www.youtube.com www.googletagmanager.com; block-all-mixed-content; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.doubleclick.net https://www.paypal.com https://*.dpdconnect.nl c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://cdn.clerk.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://a.klaviyo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://api.clerk.io https://cdn.clerk.io https://*.dpdconnect.nl chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.klaviyo.com https://fast.a.klaviyo.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tm.tradetracker.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://api.clerk.io https://cdn.clerk.io *.fontawesome.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net *.google.com *.doubleclick.net wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://www.paypal.com https://static.klaviyo.com https://fast.a.klaviyo.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/HITACHI/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/HITACHI/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/HITACHI/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/HITACHI/ https://higherlogicdownload.s3.amazonaws.com/HITACHI/ https://higherlogiclongterm.s3.amazonaws.com/HITACHI/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/HITACHI/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/HITACHI/ 'self' https://higherlogiclongterm.s3.amazonaws.com/HITACHI/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/HITACHI/ https://higherlogicdownload.s3.amazonaws.com/HITACHI/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/HITACHI/ https://higherlogicstream.s3.amazonaws.com/HITACHI/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/HITACHI/ https://higherlogicdownload.s3.amazonaws.com/HITACHI/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/HITACHI/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.mollie.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://*.etracker.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://*.etracker.com https://*.etracker.de https://images.unsplash.com https://firebasestorage.googleapis.com https://www.mollie.com https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.etrusted.com fonts.googleapis.com *.google.de *.google.com *.sleeknote.com *.mollie.com *.consentmanager.net *.linkedin.com 'self' data: *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com jsd-widget.atlassian.com https://*.etracker.com https://*.etracker.de https://maps.googleapis.com https://player.vimeo.com *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.doubleclick.net *.google-analytics.com *.trustedshops.com *.etrusted.com *.etrusted.site *.sleeknote.com *.paypalobjects.com *.googleadservices.com *.mollie.com *.consentmanager.net *.licdn.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.etrusted.com *.cookiefirst.com *.mollie.com *.consensu.org 'self' data: *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com jsd-widget.atlassian.com api-private.atlassian.com https://*.etracker.de https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com autocomplete2.postdirekt.de *.googletagmanager.com *.doubleclick.net *.trustedshops.com *.etrusted.com *.etrusted.site *.youtube.com *.sleeknote.com *.paypalobjects.com *.googleadservices.com *.mollie.com *.linkedin.com fonts.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: maxcdn.bootstrapcdn.com fonts.gstatic.com widget.dixa.io a.omappapi.com static.klaviyo.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com ssl.ditonlinebetalingssystem.dk 'self' 'unsafe-inline'; frame-ancestors viewer.ipaper.io https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: online.adservicemedia.dk consentcdn.cookiebot.com consentcdn.cookiebot.eu adtr.io event-client.viabill.com vars.hotjar.com www.youtube.com www.google.com www.youtube-nocookie.com gum.criteo.com pricetag.viabill.com www.addwish.com display.ipaper.io simplicity.trustpilot.com googleads.g.doubleclick.net cdn.lightwidget.com http://event.getblue.io *.googletagmanager.com *.doubleclick.net/ magento-cloudflare.jetrails.com utt.impactcdn.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com self blob: online.adservicemedia.dk pushcrew.com cdn.pushcrew.com stats.g.doubleclick.net a.klaviyo.com dapi.videoly.co i.ytimg.com dis.criteo.com optin-monster.s3.amazonaws.com maps.googleapis.com maps.gstatic.com a.omappapi.com ssl.gstatic.com www.gstatic.com lh3.googleusercontent.com fonts.gstatic.com *.google.com *.google.pl *.google.no *.google.se *.google.de *.google.co.uk *.google.com.ua d3k81ch9hvuctc.cloudfront.net d1pna5l3xsntoj.cloudfront.net *.ipaper.io *.taboola.com imgsct.cookiebot.com *.bing.com *.bing.net *.pricerunner.dk *.beautycos.dk *.orbitvu.co *.klarna.com img.sct.eu1.usercentrics.eu https://s.kelkoogroup.net https://cdn.clerk.io *.ytimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com flagpedia.net https://widgets.trustedshops.com https://integrations.etrusted.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com unsafe-inline ipinfo.io invitejs.trustpilot.com secure.viabill.com a.opmnstr.com display.ipaper.io widget.dixa.io static.hotjar.com consent.cookiebot.com api.videoly.co cdn.pushcrew.com online.adservicemedia.dk script.hotjar.com pricetag.viabill.com adtr.io cdn.polyfill.io www.google.com www.google.pl www.gstatic.com static.criteo.net *.klaviyo.com cdn.ipaper.io sslwidget.criteo.com d1pna5l3xsntoj.cloudfront.net www.addwish.com ajax.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu cdnjs.cloudflare.com dapi.videoly.co ssl.ditonlinebetalingssystem.dk maps.googleapis.com cdn.adt376.net cdn.adt311.net tagmanager.google.com do.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no a.omappapi.com *.taboola.com s.kk-resources.com *.bing.com *.getblue.io cdn.lightwidget.com cdn.clerk.io ai.trk42.net *.videoly.co *.reepay.com *.cytelligence.io *.youtube.com *.orbitvu.co *.pingdom.net tag.heylink.com api.reaktion.com stapecdn.com files.userlink.ai cdn.mouseflow.com pagead2.googlesyndication.com *.clarity.ms https://s.kk-resources.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.googletagmanager.com *.facebook.net *.avada.io *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com https://www.googletagmanager.com unpkg.com https://www.beautycos.de https://consent.cookiebot.com https://cdn.mida.so 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.pushcrew.com static.klaviyo.com d1pna5l3xsntoj.cloudfront.net tagmanager.google.com cdn.ipaper.io *.omappapi.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com widget.dixa.io *.beautycos.dk api.packship.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com api.omappapi.com z.omappapi.com api.dixa.io wss://sockets.dixa.io stats.g.doubleclick.net fast.a.klaviyo.com sslwidget.criteo.com a.klaviyo.com display.ipaper.io in.hotjar.com vc.hotjar.io telemetrics.klaviyo.com *.beautycos.dk to.beautycos.de do.beautycos.co.uk id.beautycos.se pin.beautycos.no api.packship.eu invitejs.trustpilot.com www.addwish.com core.helloretail.com a.omappapi.com *.taboola.com *.klaviyo.com pagead2.googlesyndication.com *.algolia.io *.bing.com *.google.com *.doubleclick.net ai.trk42.net *.cookiebot.com *.pingdom.net heylinkapi.com bat.bing.net files.userlink.ai backend.userlink.ai files.blueai.dk beautycosaps.sjv.io *.clarity.ms consentcdn.cookiebot.eu https://s.kelkoogroup.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ utt.impactcdn.com *.google-analytics.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com www.google-analytics.com www.google.com ssl.google-analytics.com use.typekit.net use.typekit.com player.vimeo.com vimeo.com i.vimeocdn.com s3.tradingview.com tradingview.com cdn.tradingview.com widget.tradingview.com fxpricing.com cdn.fxpricing.com cashbackforex.com; style-src 'self' 'unsafe-inline' use.typekit.net use.typekit.com player.vimeo.com vimeo.com i.vimeocdn.com s3.tradingview.com cdn.tradingview.com tradingview.com fxpricing.com cdn.fxpricing.com; font-src 'self' use.typekit.net use.typekit.com data: cdn.tradingview.com cdn.fxpricing.com i.vimeocdn.com; img-src 'self' data: www.google-analytics.com www.googletagmanager.com player.vimeo.com vimeo.com i.vimeocdn.com s3.tradingview.com cdn.tradingview.com tradingview.com fxpricing.com cdn.fxpricing.com cashbackforex.com; connect-src 'self' www.google-analytics.com www.googletagmanager.com player.vimeo.com vimeo.com s3.tradingview.com cdn.tradingview.com widget.tradingview.com fxpricing.com cdn.fxpricing.com cashbackforex.com; frame-src 'self' player.vimeo.com vimeo.com s3.tradingview.com tradingview.com fxpricing.com cashbackforex.com; object-src 'none'; base-uri 'self'; form-action 'self'; 1 font-src *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de ekr.zdassets.com/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.bootstrapcdn.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net www.best4balls.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.yotpo.com swellrewards.com *.swellrewards.com www.best4balls.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com www.best4balls.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com www.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com www.best4balls.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com validate.fishpig.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.google.com *.google.co.uk/ *.amazonaws.com *.adroll.com *.facebook.com *.bidswitch.net *.casalemedia.com *.openx.net *.outbrain.com *.pubmatic.com *.analytics.yahoo.com *.taboola.com *.3lift.com *.adnxs.com *.doubleclick.net *.rubiconproject.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net www.best4balls.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.adroll.com *.facebook.net www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www.best4balls.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com unsafe-inline *.bootstrapcdn.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.googleapis.com dhv2ziothpgrr.cloudfront.net www.best4balls.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.best4balls.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.tawk.to *.google-analytics.com *.analytics.google.com *.doubleclick.net *.adroll.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www.best4balls.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.best4balls.com http: https: blob: 'self' 'unsafe-inline'; default-src www.best4balls.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://fbbdcn.pixum.it https://6l5anniv1l.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://fbbdcn.pixum.it https://6l5anniv1l.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 base-uri ai.readabler.com; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google-analytics.com https://staticpg.paytmpayments.com https://merchant-static.paytmpayments.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com https://www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure.paytmpayments.com https://staticpg.paytmpayments.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://staticpg.paytmpayments.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://secure.paytmpayments.com wss://secure.paytmpayments.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: fonts.gstatic.com *.cloudflare.com fonts.googleapis.com 'unsafe-inline' data: *.typekit.net *.cloudfront.net assets.reviews.io media.highwaygardencentre.co.uk static.highwaygardencentre.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com widget.reviews.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com widget.trustpilot.com lpcdn.lpsnmedia.net widget.reviews.co.uk 'self' data: 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.trackedlink.net *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.cloudflare.com *.google.co.uk maps.gstatic.com media.highwaygardencentre.co.uk static.highwaygardencentre.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.googletagmanager.com tagmanager.google.com *.cloudflare.com *.twitter.com *.fontawesome.com *.liveperson.net *.trustpilot.com *.lpsnmedia.net chimpstatic.com widget.reviews.co.uk js-agent.newrelic.com bam.eu01.nr-data.net assets.reviews.io static.highwaygardencentre.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com *.cloudflare.com *.bootstrapcdn.com fonts.googleapis.com *.typekit.net *.cloudfront.net widget.reviews.co.uk assets.reviews.io static.highwaygardencentre.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com media.highwaygardencentre.co.uk static.highwaygardencentre.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.cloudflare.com stats.g.doubleclick.net api.reviews.co.uk api.reviews.io static.highwaygardencentre.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.highwaygardencentre.co.uk/pr-csp/report/add/; report-to report-endpoint; 1 default-src 'self'; form-action 'self' https://request.qlar.com; base-uri 'none'; frame-ancestors 'none'; object-src 'none'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://ad.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.es https://*.google.co.in https://*.google.co.jp https://*.google.co.uk https://*.ads.linkedin.com https://t.visitorqueue.com; frame-src 'self' https://request.qlar.com https://td.doubleclick.net https://*.googletagmanager.com https://www.youtube.com https://www.youtube-nocookie.com https://www.recaptcha.net; script-src 'strict-dynamic' 'nonce-37ioQmUcsIzi7nM50gzvPoIBqyfTcO5gxIbvQfqv' 'self' https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://*.googletagmanager.com https://snap.licdn.com https://t.visitorqueue.com https://online.flippingbook.com https://d33i2vgywgme2s.cloudfront.net https://request.qlar.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.es https://*.google.co.in https://*.google.co.jp https://*.google.co.uk https://*.ads.linkedin.com https://t.visitorqueue.com; report-uri https://www.qlar.com/api/report/csp; report-to csp-endpoint; upgrade-insecure-requests; block-all-mixed-content 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-YXNY7zXMECKhKqSf6wR9NzUElso=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com data: *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com https://seo.mageplaza.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.authorize.net static.addtoany.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net store.paradoxlabs.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.authorize.net static.addtoany.com acsbapp.com apis.google.com *.cloudflare.com cloudflare.com static.cloudflareinsights.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com display.ugc.bazaarvoice.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.authorize.net cdn.acsbapp.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-OGIzMWVmODQtMjhmNC00MmE2LWFkNzMtYTM1NTM3N2E3ZmQ2' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src *.cloudflare.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://mas.astralweb.com.tw ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.omappapi.com/ flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.omappapi.com/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.cloudflare.com *.googleapis.com *.omappapi.com/ *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.omappapi.com/ https://get.geojs.io *.avada.io www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube-nocookie.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.storyblok.com *.klarna.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://images.unsplash.com *.prismic.io *.cdn.prismic.io *.cookiebot.com imgsct.cookiebot.com *.documentforce.com hummuk--c.documentforce.com *.force.com hummuk.file.force.com *.google.com *.google.com.vn bat.bing.com *.linkedin.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com adobedtm.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com static.cdn.prismic.io *.prismic.io cdn.jsdelivr.net *.jsdelivr.net *.cookiebot.com consent.cookiebot.com config.gorgias.chat *.gorgias.chat data: self unsafe-inline *.lr-intake.com bat.bing.com snap.licdn.com s.pinimg.com *.googleoptimize.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com services.postcodeanywhere.co.uk *.klaviyo.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com vimeo.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://maps.googleapis.com https://player.vimeo.com *.doubleclick.net *.fontawesome.com *.youtube.com *.cardinalcommerce.com *.facebook.com config.gorgias.chat *.googlesyndication.com pagead2.googlesyndication.com *.cookiebot.com consent.cookiebot.com *.prismic.io *.algolia.io *.lr-intake.com api.addressy.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a1444c0b-988b-46bf-8bde-a8332665a15c.sansec.watch/; report-to report-endpoint; 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.google.com/recaptcha/api.js https://translate.google.com/translate_a/element.js https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.gstatic.com/_/mss/boq-groups/_/js/k=boq-groups.GroupsFrontendUi.en_US.mjxaaPAOmRE.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /_/GroupsFrontendUi/cspreport/fine-allowlist 1 script-src 'self' https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://www.googletagmanager.com/gtag/js https://region1.google-analytics.com/g/collect https://cdn.cookielaw.org/scripttemplates/ 'unsafe-inline' 'nonce-CGOmRs84onmhaq9oPDIxpw=='; report-uri /nelmio/csp/report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://content-eu-4.content-cms.com *.google.com *.google.co.in *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.avada.io *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.mouseflow.com https://kit.fontawesome.com https://us01.rec.mouseflow.com/ *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com ajax.googleapis.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com https://cdnjs.cloudflare.com https://cdn-images.mailchimp.com/ *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com thm.visa.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://us01.rec.mouseflow.com/ *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.dfxtra.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.dfxtra.com join.gammasecure.com; script-src 'self' *.dfxtra.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.dfxtra.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 script-src sdk.privacy-center.org spir.hit.gemius.pl cnc.daktela.com widget.packeta.com *.google.com *.smartlook.com *.smartsuppcdn.com *.smartsupp.com static.hotjar.com script.hotjar.com *.googletagmanager.com a.opmnstr.com *.google-analytics.com *.googleadservices.com *.smartsuppchat.com googleads.g.doubleclick.net connect.facebook.net 2.adform.net s2.adform.net track.adform.net im9.cz *.im9.cz c.imedia.cz ssl.heureka.cz www.heureka.cz cdn.heureka.group www.zbozi.cz c.seznam.cz 1gr.cz sgtm.signals.cz cdn.cpex.cz *.mapy.cz www.ppl.cz 'self' 'unsafe-inline' 'unsafe-eval';script-src-elem sdk.privacy-center.org spir.hit.gemius.pl cnc.daktela.com widget.packeta.com *.google.com *.smartlook.com *.smartsuppcdn.com *.smartsupp.com static.hotjar.com script.hotjar.com *.googletagmanager.com a.opmnstr.com *.google-analytics.com *.googleadservices.com *.smartsuppchat.com googleads.g.doubleclick.net connect.facebook.net 2.adform.net s2.adform.net track.adform.net im9.cz *.im9.cz c.imedia.cz ssl.heureka.cz www.heureka.cz cdn.heureka.group www.zbozi.cz c.seznam.cz 1gr.cz sgtm.signals.cz cdn.cpex.cz *.mapy.cz www.ppl.cz 'self' 'unsafe-inline' 'unsafe-eval';style-src tagmanager.google.com cdnjs.cloudflare.com maxcdn.bootstrapcdn.com *.smartsuppcdn.com translate.googleapis.com fonts.googleapis.com www.ppl.cz api.mapy.cz 'self' 'unsafe-inline';style-src-elem tagmanager.google.com cdnjs.cloudflare.com maxcdn.bootstrapcdn.com *.smartsuppcdn.com translate.googleapis.com fonts.googleapis.com www.ppl.cz api.mapy.cz 'self' 'unsafe-inline';report-uri /csp 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=28211&v=v1.0&payload=YPdY9WRb5JwJ55hD1-rOWWRMFTotwuhEpaG2NrbPgAA3XxR3jJVhC_d8qPyPTy8u4AgIcuSQyUGxac6L3NavkuHsoPz9gpHnbZMqdEq5VEoBvC4orRMjibCYGjNtyMEwy4VOHB_44eNuv9ZeU4rxlF-nnoUIdPVDLmxKELKxHjlP17uBsUAGT4qkZD3YUBGZ8LzWvojPfHCRaOT4kaFK5A==; 1 font-src *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com maxcdn.bootstrapcdn.com *.fonts.googleapis.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.coinpayments.net/index.php *.canadapost.ca https://sso.epost.ca *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com www.facebook.com platform.twitter.com *.authorize.net *.addthis.com *.pinterest.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.coinpayments.net magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com mageside.com *.canadapost.ca *.canadapost-postescanada.ca *.googleapis.com https://www.magezon.com flagpedia.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.googleapis.com maps.googleapis.com connect.facebook.net twitter.com platform.twitter.com *.authorize.net https://tnsb.postaffiliatepro.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io *.googleapis.com www.gstatic.com maps.googleapis.com *.authorize.net *.cloudflare.com *.paypal.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=887f78f6-69db-4ef1-bf21-87c87e68f49a; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 style-src-elem *.trackjs.com 'self' *.doubleclick.net *.googleadservices.com 'unsafe-inline' *.s121.mhost.eu *.gr-cdn.com us-an.gr-cdn.com *.consentmanager.net *.gr-wcon.com *.fontawesome.com *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.facebook.com *.gstatic.com fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl izi.inpost.pl *.trustedshops.com *.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com www.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.stripe.com integrations.etrusted.com; script-src-elem scripts.luigisbox.com cdn.luigisbox.com *.trackjs.com *.cloudflareinsights.com 'self' *.klarna.com *.bing.com *.braintreegateway.com *.ahrefs.com *.clarity.ms *.przelewy24.pl *.livechatinc.com bing.com *.doubleclick.net *.googleadservices.com *.s121.mhost.eu *.hotjar.com cdnjs.cloudflare.com *.youtube.com 'unsafe-inline' *.gr-cdn.com us-an.gr-cdn.com *.consentmanager.net *.gr-wcon.com *.facebook.net *.lightwidget.com *.fontawesome.com *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.facebook.com *.gstatic.com fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl izi.inpost.pl *.trustedshops.com *.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com www.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.stripe.com integrations.etrusted.com; script-src-attr *.s121.mhost.eu *.doubleclick.net *.googleadservices.com *.gr-cdn.com us-an.gr-cdn.com 'unsafe-inline' *.fontawesome.com *.facebook.net *.adobe.com *.adobedtm.com *.google.com *.cardinalcommerce.com *.googleapis.com *.lightwidget.com *.gstatic.com *.facebook.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.inpost.pl *.trustedshops.com *.it4dev.pl https://dev.martom.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.inpost.pl https://use.fontawesome.com *.adobe.com *.googleapis.com https://fonts.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com geowidget.easypack24.net geowidget.inpost.pl widgets.trustedshops.com static-app.connect.trustedshops.com static-app.connect-qa.trustedshops.com *.klarnacdn.net *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://fonts.bunny.net https://geowidget.easypack24.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.link.com *.amazon.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.inpost.pl *.googleadservices.com *.consentmanager.net *.fontawesome.com *.adobedtm.com *.google.pl www.google.com *.cardinalcommerce.com 'self' assets.adobedtm.com *.it4dev.pl *.klarnaevt.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * apm.przelewy24.pl https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ https://geowidget-app.inpost-group.com/ https://sandbox-global-geowidget.easypack24.net/ *.stripe.com klarna.com *.klarnacdn.net *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src 'self' *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net *.inpost.pl *.trackjs.com *.bing.com bing.com gls-group.com *.clarity.ms *.files-text.com *.questprofile.com questprofile.com questprofile.pl *.googleadservices.com markizeta.s121.mhost.eu *.consentmanager.net markizeta.info *.fontawesome.com *.google.pl *.cardinalcommerce.com assets.adobedtm.com *.it4dev.pl *.klarnaevt.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com *.klarna.com *.klarnacdn.net tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com https://geowidget.easypack24.net *.easypack24.net *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net *.inpost.pl scripts.luigisbox.com cdn.luigisbox.com *.googleadservices.com 'self' 'unsafe-inline' *.gr-cdn.com us-an.gr-cdn.com *.fontawesome.com *.cardinalcommerce.com *.googleapis.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.lightwidget.com *.easypack24.net https://widgets.trustedshops.com *.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com https://dev.martom.it4dev.pl *.paypal.com *.sysadvisors.pl *.dhlparcel.nl *.klarna.com x.klarnacdn.net https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com mapa.orlenpaczka.pl s7.addthis.com *.avada.io *.shopify.com js.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com https://geowidget.easypack24.net *.openstreetmap.org *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.amazon.com *.link.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.inpost.pl 'self' https://use.fontawesome.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com assets.braintreegateway.com geowidget.easypack24.net geowidget.inpost.pl widgets.trustedshops.com static-app.connect.trustedshops.com static-app.connect-qa.trustedshops.com *.klarnacdn.net *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://fonts.bunny.net sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.stripe.network *.stripecdn.com *.amazon.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' *.trackjs.com gls-group.com *.questprofile.com questprofile.com questprofile.pl *.googleadservices.com *.doubleclick.net markizeta.s121.mhost.eu *.consentmanager.net markizeta.info *.fontawesome.com *.facebook.com *.adobe.com *.adobedtm.com *.google.com *.google.pl www.google.com *.cardinalcommerce.com assets.adobedtm.com *.it4dev.pl *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://a.delivery.consentmanager.net https://b.delivery.consentmanager.net https://c.delivery.consentmanager.net https://d.delivery.consentmanager.net *.inpost.pl 'self' *.trackjs.com gls-group.com *.questprofile.com questprofile.com questprofile.pl *.googleadservices.com *.doubleclick.net markizeta.s121.mhost.eu *.consentmanager.net markizeta.info *.fontawesome.com *.facebook.com *.adobedtm.com *.google.com *.google.pl www.google.com *.cardinalcommerce.com assets.adobedtm.com *.it4dev.pl *.klarnaevt.com *.paypal.com *.sysadvisors.pl *.dhlparcel.nl https://dev.martom.it4dev.pl *.etrusted.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.inpost.pl *.trackjs.com *.googleadservices.com *.clarity.ms 'self' *.hotjar.com wss://*.hotjar.com *.hotjar.io *.bing.com *.ahrefs.com *.consentmanager.net *.getresponse.com *.fontawesome.com *.adobe.com *.adobedtm.com *.cardinalcommerce.com *.googleapis.com *.gstatic.com *.googletagmanager.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.easypack24.net *.trustedshops.com *.it4dev.pl *.klarnacdn.net *.klarnaservices.com *.etrusted.com *.klarnaevt.com *.sysadvisors.pl *.dhlparcel.nl x.klarnacdn.net *.klarna.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com nominatim.openstreetmap.org ekr.zdassets.com/ https://get.geojs.io *.avada.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com sandbox.przelewy24.pl secure.przelewy24.pl wss://ws.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com *.openstreetmap.org *.stripe.com klarna.com *.link.com *.amazon.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io houseofmcomics.com www.houseofmcomics.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com widget.freshworks.com m2epro.freshdesk.com *.avada.io *.shopify.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; report-uri https://immuware.com?gdsih-csp-report; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://canadahair-5mufguklkw9.netdna-ssl.com/static/ https://mesrallonges-5mufguklkw9.netdna-ssl.com/static/ *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca https://www.googletagmanager.com/ www.facebook.com platform.twitter.com https://recaptcha.google.com/recaptcha/ checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.google.com *.addthis.com *.pinterest.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com www.facebook.com *.pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net pinterest.com https://canadahair-5mufguklkw9.netdna-ssl.com/media/ https://mesrallonges-5mufguklkw9.netdna-ssl.com/media/ media.sezzle.com *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.cdninstagram.com www.google.com.ua *.yotpo.com https://qqq.canadahair.ca data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.facebook.com twitter.com platform.twitter.com static.addtoany.com *.gstatic.com maps.googleapis.com connect.facebook.net https://gateway.moneris.com https://gatewayt.moneris.com https://googleads.g.doubleclick.net/ https://canadahair-5mufguklkw9.netdna-ssl.com/static/ https://mesrallonges-5mufguklkw9.netdna-ssl.com/static/ checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.instagram.com *.yotpo.com https://qqq.canadahair.ca 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.gstatic.com *.unicorny.hu fonts.googleapis.com fonts.cdnfonts.com *.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ stats.addtoany.com www.gstatic.com maps.googleapis.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com *.yotpo.com https://qqq.canadahair.ca 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: 'unsafe-inline' 'unsafe-eval' data: about: blob:; report-uri /_resources/php/csp-report.php 1 font-src https://v2.zopim.com https://sslzone-brianstoys.netdna-ssl.com data: http://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://sslzone-brianstoys.netdna-ssl.com https://v2assets.zopim.io https://static.zdassets.com https://v2.zopim.com https://stats.g.doubleclick.net https://www.google.com https://bat.bing.com https://quote.brianstoys.com https://www.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://v2.zopim.com https://static.zdassets.com https://bat.bing.com https://connect.facebook.net https://quote.brianstoys.com https://www.googletagmanager.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com http://fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://ekr.zdassets.com wss://*.zopim.com https://brianstoys.zendesk.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://*.klevu.com https://*.gstatic.com https://*.typekit.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.klevu.com *.trackedlink.net https://*.doubleclick.net https://*.google.com https://*.google.co.uk https://*.cloudfront.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.klevu.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.googleapis.com https://*.typekit.net *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ksearchnet.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=f43ebd90-d545-42ca-939e-f99f63c24b41; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 default-src 'self'; img-src 'self' data: https:; media-src 'self' https:; font-src 'self' data: https:; connect-src 'self' https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://ncg5it.pixum.es https://5w824otbi1.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://ncg5it.pixum.es https://5w824otbi1.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 base-uri 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://climate.stripe.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://sales-live-chat.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com https://y4pfttj91h-1.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-2.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-3.algolianet.com/1/indexes/mkt_partners/query https://y4pfttj91h-dsn.algolia.net/1/indexes/mkt_partners/query https://tax-connectors.stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://climate.stripe.com https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://checkout.stripe.dev https://support-conversations.stripe.com https://b.stripecdn.com https://checkout.stripe.com https://crypto-js.stripe.com https://js.stripe.com https://sales-live-chat.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com https://stripe-camo.global.ssl.fastly.net 'self'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; script-src https://b.stripecdn.com https://crypto-js.stripe.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src 'none'; report-uri https://q.stripe.com/csp-violation?q=in4wswXwBsmFglD19957bSHv0BDrA0qvECTDeB6OQQyLeUsmXNJU8bF1RbpZtAs%3D 1 default-src https: data: blob: 'self' 'unsafe-inline' 'unsafe-eval'; img-src data: https:; font-src data: https:; report-uri https://kilian.report-uri.io/r/default/csp/reportOnlyi; connect-src https: data: blob: 'self' 'unsafe-inline' 'unsafe-eval' https://client.crisp.chat https://storage.crisp.chat wss://client.relay.crisp.chat wss://stream.relay.crisp.chat 1 font-src *.fontawesome.com *.sirv.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com www.facebook.com *.hotjar.com *.addthis.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.sirv.com www.xtento.com cdn.xtento.com *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net *.laybuy.com www.facebook.com www.google.com.ua www.google.pl *.cdninstagram.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://rum.hlx.page polyfill.io apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sirv.com player.vimeo.com www.xtento.com cdn.xtento.com secure.authorize.net test.authorize.net www.gstatic.com/recaptcha www.google.com/recaptcha api.addressfinder.io s7.addthis.com *.googleapis.com *.tawk.to cdn.jsdelivr.net www.google.com www.gstatic.com js-agent.newrelic.com bam.nr-data.net *.facebook.net *.laybuy.com *.hotjar.com bam.eu01.nr-data.net *.moatads.com *.addthisedge.com *.addthis.com *.osano.com cdn.pricespider.com locate.pricespider.com *.pricespider.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src display.ugc.bazaarvoice.com https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.sirv.com cdn.pricespider.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.sirv.com stergita.sirv.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sirv.com *.youtube.com blob: *.facebook.net *.algolianet.com ekr.zdassets.com *.googleapis.com *.tawk.to bam.nr-data.net *.laybuy.com *.cloudfront.net stats.g.doubleclick.net t.labs.au.edge.zip.co in.hotjar.com bam.eu01.nr-data.net *.osano.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src www.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com diamondtreats.co.uk 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de diamondtreats.co.uk 'self' 'unsafe-inline'; frame-ancestors diamondtreats.co.uk 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de api.boldcommerce.com api.staging.boldcommerce.com *.paypal.com *.bold.ninja static-eps.secure.boldcommerce.com static-eps.secure.staging.boldcommerce.com *.stripe.com *.klarna.com *.weltpixel.com diamondtreats.co.uk 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com static.boldcommerce.com *.paypal.com www.gstatic.com www.feedoptimise.com cdn.feedoptimise.com validate.fishpig.co.uk *.klarna.com *.klarnaevt.com https://omnisnippet1.com https://wt.soundestlink.com *.gstatic.com diamondtreats.co.uk 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de api.boldcommerce.com api.staging.boldcommerce.com eps.secure.staging.boldcommerce.com cashier.boldcommerce.com *.paypal.com *.paypalobjects.com static-eps.secure.boldcommerce.com static-eps.secure.staging.boldcommerce.com *.bold.ninja *.cdn-apple.com *.stripe.com cdn.safecharge.com www.google.com www.gstatic.com jquery.sellxed.com www.feedoptimise.com cdn.feedoptimise.com *.klarna.com *.googleapis.com *.google.com *.gstatic.com *.avada.io https://omnisnippet1.com https://forms.soundestlink.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com diamondtreats.co.uk 'self' 'unsafe-inline' 'unsafe-eval' 'sha256-7nnKyr+RUZ9a44Hg3lYwjgkUx5VyFQwv2ZUhVw6N7J4='; style-src getfirebug.com *.bold.ninja static-eps.secure.boldcommerce.com static-eps.secure.staging.boldcommerce.com *.googleapis.com *.google.com *.gstatic.com tagmanager.google.com diamondtreats.co.uk 'self' 'unsafe-inline'; object-src api.boldcommerce.com api.staging.boldcommerce.com 'self' 'unsafe-inline'; media-src diamondtreats.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.boldcommerce.com api.staging.boldcommerce.com eps.secure.staging.boldcommerce.com cashier.boldcommerce.com *.sandbox.braintree-api.com *.braintree-api.com *.paypal.com *.braintreegateway.com www.paypalobjects.com eps.secure.boldcommerce.com static-eps.secure.boldcommerce.com static-eps.secure.staging.boldcommerce.com *.bold.ninja *.cdn-apple.com ppp-test.safecharge.com secure.safecharge.com *.klarnaevt.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.google-analytics.com analytics.google.com diamondtreats.co.uk 'self' 'unsafe-inline'; child-src api.boldcommerce.com api.staging.boldcommerce.com diamondtreats.co.uk 'self' 'unsafe-inline'; default-src diamondtreats.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none';script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' cdn.customgpt.ai 'nonce-/nThtyVOOTRauFCnnRjyRsjahRx9H6Wiq7D9Ihl932w=';style-src 'self' cdnjs.cloudflare.com cdn.jsdelivr.net 'report-sample' 'unsafe-inline';connect-src 'self' cdn.customgpt.ai config.customgpt.ai app.customgpt.ai app.planhat.com analytics.planhat.com;font-src 'self' data: cdnjs.cloudflare.com;img-src 'self' data: cdnjs.cloudflare.com martuspublic.blob.core.windows.net cdn.customgpt.ai;frame-src 'self' cdn.customgpt.ai app.customgpt.ai;base-uri 'self' 1 font-src *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net https://www.google.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://td.doubleclick.net/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.consentmanager.net https://delivery.consentmanager.net https://www.google.com/ https://www.google.de/ https://www.trustedshops.de/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.consentmanager.net https://delivery.consentmanager.net http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.gstatic.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.fontawesome.com unsafe-inline 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://payments.amazon.de/ http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ *.google-analytics.com *.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es https://seo.mageplaza.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com api.razorpay.com *.twitter.com *.google.com *.youtube.com *.facebook.com maps.googleapis.com lightwidget.com *.maps.gstatic.com https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com *.wesupply.xyz *.weltpixel.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es cdn.razorpay.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.googleapis.com *.placeholder.com *.maps.gstatic.com https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com *.gstatic.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com checkout.razorpay.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com *.facebook.net cdn.lightwidget.com *.instagram.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.googleapis.com *.placeholder.com *.maps.gstatic.com https://salesiq.zoho.in https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com https://www.googletagmanager.com tagmanager.google.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com *.cdninstagram.com s7.addthis.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.placeholder.com *.maps.gstatic.com tagmanager.google.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com facebook.net *.maps.gstatic.com https://www.google-analytics.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com https://images.unsplash.com *.sooqr.com *.spotlersearch.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.bing.com *.bing.net *.google.nl *.facebook.com *.popupsmart.com *.usercentrics.eu *.etrusted.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com *.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com *.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com https://maps.googleapis.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.bing.com *.cookiebot.eu *.facebook.com *.facebook.net *.popupsmart.com *.hotjar.com *.etrusted.com *.reaktion.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.sooqr.com *.spotlersearch.com assets.braintreegateway.com *.googleapis.com *.etrusted.com *.popupsmart.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com https://maps.googleapis.com https://player.vimeo.com *.sooqr.com *.spotlersearch.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.gstatic.com *.googleapis.com *.bing.com *.bing.net *.cookiebot.eu *.doubleclick.net *.googlesyndication.com *.popupsmart.com *.hotjar.io *.reaktion.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.googletagmanager.com https://mycademy.com/site/ https://cdn.jsdelivr.net/npm/@simplewebauthn/ code.jquery.com cdnjs.cloudflare.com dev.visualwebsiteoptimizer.com www.youtube.com snid.snitcher.com www.clarity.ms cdn.leadinfo.net a.omappapi.com koi-3qna3qmsa0.marketingautomation.services connect.facebook.net snap.licdn.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com https://mycademy.com/site/; img-src 'self' data: https://images.mycademy.com https://mycademy.com/site/ staging-mycademy.kinsta.cloud cdnjs.cloudflare.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com cdnjs.cloudflare.com; connect-src *; media-src 'self'; object-src 'none'; child-src *; frame-src *; worker-src 'self'; frame-ancestors *; form-action *; base-uri 'self'; manifest-src 'self'; report-uri https://mycademy.report-uri.com/r/d/csp/reportOnly; report-to https://mycademy.report-uri.com/r/d/csp/reportOnly; 1 object-src 'none'; connect-src 'self' *.burningangel.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.burningangel.com join.gammasecure.com; script-src 'self' *.burningangel.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.burningangel.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://app.mailjet.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.com *.imgix.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://a.tile.openstreetmap.fr https://scontent-cdt1-1.cdninstagram.com https://scontent-cdg2-1.cdninstagram.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.net *.axept.io *.googletagmanager.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://ajax.googleapis.com https://app.mailjet.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.axept.io https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://nominatim.openstreetmap.org https://graph.instagram.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net ad.doubleclick.net adservice.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com uat-buyer-portal.birlapivot.com t65lc8f1bw-1.algolianet.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com https://cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://commerce-public-bucket.s3.ap-south-1.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src https: *.google-analytics.com www.10life.com https://10life-strapi-media-library-prod.s3.ap-southeast-1.amazonaws.com data:; worker-src 'self' blob: www.10life.com; style-src 'self' 'unsafe-inline' www.10life.com https://fonts.googleapis.com https://www.googletagmanager.com accounts.google.com https://cdn.jsdelivr.net; font-src 'self' data: https://fonts.gstatic.com https://cdn.jsdelivr.net; script-src 'self' 'self' 'unsafe-inline' www.10life.com *.google-analytics.com connect.facebook.net accounts.google.com www.googletagmanager.com s3-ap-southeast-1.amazonaws.com googleads.g.doubleclick.net bat.bing.com static.hotjar.com script.hotjar.com s.yimg.com *.cloudfront.net cse.google.com; connect-src www.10life.com https://strapi-cms.10life.com https://auth.10life.com *.google-analytics.com analytics.google.com stats.g.doubleclick.net s.yimg.com api.tenlife.asia api.10life.com vc.hotjar.io in.hotjar.com *.cloudfront.net *.tenlife.asia *.10lifeconnect.com; frame-src www.10life.com accounts.google.com vars.hotjar.com youtube.com www.youtube.com https://auth.10life.com; media-src youtube.com www.youtube.com; form-action 'self'; frame-ancestors 'none'; object-src 'none'; base-uri www.10life.com 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de https://www.apparelvideos.com https://www.bluegeneration.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.positivessl.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google-analytics.com *.googleadservices.com *.paypal.com *.zonos.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.zonos.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.fls.doubleclick.net *.facebook.com *.googlesyndication.com *.awin1.com *.zenaps.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://images.unsplash.com flagpedia.net ts.tradetracker.net www.magmodules.eu https://widgets.trustedshops.com https://widgets-qa.trustedshops.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io maps.googleapis.com tm.tradetracker.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.wepowerconnections.com https://the.sciencebehindecommerce.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com www.gstatic.com maps.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com static.guirca.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.guirca.com cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com static.guirca.com cdn.cookielaw.org https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com static.guirca.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com static.guirca.com cdn.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' https://stats.g.doubleclick.net https://*.doubleclick.net https://admin-fts.threekit.com https://checkoutshopper-test.adyen.com/ https://*.bing.com https://pal-test.adyen.com https://pi.pardot.com https://px.ads.linkedin.com/ https://prod.accdab.net https://consent.trustarc.com https://*.adsrvr.org https://d.agkn.com https://idsync.rlcdn.com https://mpsnare.iesnare.com https://pay.google.com https://*.agkn.com blob: https://snap.licdn.com https://resources.xg4ken.com 'report-sample' https://service.force.com/embeddedservice/ https://4487060.fls.doubleclick.net 'unsafe-eval' https://*.xg4ken.com 'unsafe-inline' https://payments.salesforce.com/ https://tracker.marinsm.com https://www.googleadservices.com https://ups.analytics.yahoo.com https://insight.adsrvr.org/ https://consent-pref.trustarc.com https://explore.starbuckscardb2b.com https://checkoutshopper-live.adyen.com/ https://*.clarity.ms https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://connect.facebook.net https://tagmanager.google.com https://beacon.lynx.cognitivlabs.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev wss://mpsnare.iesnare.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://bat.bing.com https://js.stripe.com/ https://www.googletagmanager.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js https://www.google.com/; report-to sfdc-csp-ep; report-uri https://d00000000hhupeay.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D00000000hhUP&networkId=0DM1G0000000Cwc&type=communities 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-hmTq0zA8aZY570wkvyVdkjtPoW4=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 style-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://widgets.binotel.com https://maxcdn.bootstrapcdn.com https://fonts.googleapis.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com.ua https://cdn.pulse.is https://ringostat.com https://widgets.binotel.com; font-src maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com *.fontawesome.com fonts.gstatic.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.google.com.ua https://my.binotel.ua https://widgets.binotel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com *.yotpo.com quickchart.io img.youtube.com https://redchamps.com https://yotpo-editor-production.s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval' www.facebook.com https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com.ua https://cdn.pulse.is https://ringostat.com https://widgets.binotel.com maps.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.yotpo.com https://js-agent.newrelic.com https://bam.eu01.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com 'unsafe-inline' maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.fontawesome.com fonts.gstatic.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' https://widgets.binotel.com https://my.binotel.ua 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' https://www.googleadservices.com https://stats.g.doubleclick.net https://widgets.binotel.com https://s3.eu-central-1.amazonaws.com wss://wschat1.binotel.com:9015 https://callback.ringostat.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.ingest.sentry.io *.yotpo.com https://bam.eu01.nr-data.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/AEDWEB/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AEDWEB/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/AEDWEB/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AEDWEB/ https://higherlogicdownload.s3.amazonaws.com/AEDWEB/ https://higherlogiclongterm.s3.amazonaws.com/AEDWEB/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/AEDWEB/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AEDWEB/ 'self' https://higherlogiclongterm.s3.amazonaws.com/AEDWEB/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/AEDWEB/ https://higherlogicdownload.s3.amazonaws.com/AEDWEB/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AEDWEB/ https://higherlogicstream.s3.amazonaws.com/AEDWEB/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/AEDWEB/ https://higherlogicdownload.s3.amazonaws.com/AEDWEB/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AEDWEB/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.addressfinder.io *.adsrvr.org *.creativecdn.com gum.criteo.com *.doubleclick.net *.ezy-way.online www.facebook.com *.flowpaper.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net lowes.api.useinsider.com *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.ddlnk.net www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.addressfinder.io *.bing.com *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online www.facebook.com *.freshchat.com *.google.com.au *.google.co.nz *.googletagmanager.com *.google.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.reddit.com *.statsigapi.net *.stripe.com *.trackedweb.net *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.addressfinder.io https://rum.hlx.page *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com https://cdn.searchspring.net/intellisuggest/is.min.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adsrvr.org *.amazonaws.com *.bing.com *.creativecdn.com *.criteo.com *.ezy-way.online www.facebook.com *.freshchat.com *.freshworksapi.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.redditstatic.com *.searchspring.io *.tiktok.com *.useinsider.com connect.facebook.net graph.facebook.com business.facebook.com https://www.lowesmenswear.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.addressfinder.io webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net assets.braintreegateway.com *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online *.facebook.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.google.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypal.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net *.useinsider.com *.vimeo.com *.youtube.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.addressfinder.io *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online *.facebook.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.google.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypal.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net *.vimeo.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.addressfinder.io *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net *.freshrelevance.com wss://*.freshrelevance.com wss://*.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com https://beacon.searchspring.io/beacon api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.aimtell.io *.creativecdn.com *.criteo.com *.doubleclick.net *.ezy-way.online www.facebook.com *.flowpaper.com *.freshchat.com *.google.com.au *.google.co.nz *.googletagmanager.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.paypalobjects.com *.pxf.io *.reddit.com *.redditstatic.com *.statsigapi.net *.stripe.com *.typekit.net *.useinsider.com *.youtube.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.bing.com *.creativecdn.com *.criteo.net *.ezy-way.online *.google.com *.google.com.au *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.nr-data.net *.searchspring.io self *.tiktok.com *.trackedweb.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://widgets.trustedshops.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * checkout.postfinance.ch www.youtube.com static.addtoany.com pp.payengine.de www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com checkout.postfinance.ch https://widgets.trustedshops.com https://widgets-qa.trustedshops.com maps.googleapis.com duvetsuisse.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net checkout.postfinance.ch www.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com maps.googleapis.com static.addtoany.com bat.bing.com cdn.taboola.com widgets.trustedshops.com pp.payengine.de static.getclicky.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com www.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site sentry.services.wly.ch 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://*.volunteer.gov *.force.com https://*.salesforce.com https://cg-1b082c1b-3db7-477f-9ca5-bd51a786b41e.s3-us-gov-west-1.amazonaws.com https://touchpoints.app.cloud.gov https://fonts.gstatic.com/ https://*.forceusercontent.com 'self' *.salesforce.com https://*.force.com blob: data:; report-to sfdc-csp-ep; report-uri https://doinps-vol.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Dt0000000CmX4&networkId=0DMt0000000Cam6&type=communities 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.twitter.com nitropack.io *.nitrocdn.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.addthis.com *.trustpilot.com *.twitter.com *.vimeo.com *.doubleclick.net nitropack.io https://www.paypal.com https://www.google.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cloudflare.com *.google-analytics.com *.twitter.com *.contentsquare.net nitropack.io *.nitrocdn.com https://www.facebook.com https://seers-application-assets.s3.amazonaws.com https://www.paypalobjects.com https://www.google-analytics.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ widget.freshworks.com m2epro.freshdesk.com *.addthis.com *.googleapis.com *.cloudflare.com *.fontawesome.com *.google-analytics.com googletagmanager.com graph.facebook.com *.gstatic.com *.moatads.com *.trustpilot.com widgets.pinterest.com *.contentsquare.com *.contentsquare.net cdn.tailwindcss.com cdn.jsdelivr.net https://cdn.seersco.com https://connect.facebook.net https://commerce.adobedtm.com https://livesearch-autocomplete.magento-ds.com https://unpkg.com https://livesearch-metrics.magento-ds.com https://plp-widgets-ui.magento-ds.com https://js.sentry-cdn.com https://browser.sentry-cdn.com https://www.googletagmanager.com https://magento-recs-sdk.adobe.net https://www.google-analytics.com https://js-agent.newrelic.com https://www.google.com https://www.gstatic.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.twitter.com cdn.tailwindcss.com nitropack.io cdnjs.cloudflare.com *.nitrocdn.com cdn.jsdelivr.net https://maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdn.seersco.com https://pay.multisafepay.com https://www.gstatic.com *.multisafepay.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com *.cloudflare.com *.twitter.com *.contentsquare.net *.google-analytics.com *.nitrocdn.com nitropack.io https://o1212795.ingest.us.sentry.io https://region1.analytics.google.com https://cdn-auth.seersco.com https://p13n-mr.adobe.io https://catalog-service.adobe.io https://commerce.adobe.io https://www.google-analytics.com https://bam.nr-data.net https://www.paypal.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://commerce.adobedc.net https://bam.nr-data.net https://www.paypal.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.it ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.it *.spreadshirt.it ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.it ; font-src 'self' https: data: *.spreadshirt.it ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.it ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.it ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-d8PQQt4Z7oR+8BsItXKXkKkNLnU=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src data: use.fontawesome.com static-dev.srag.cahosting.de static-dev.srag.codel1.de fonts.gstatic.com maxcdn.bootstrapcdn.com tmpsativa-static.codel1.de cdn.live.srag.cahosting.de cdn.dev.srag.cahosting.de cdn.dev.srag.codel1.de cdn.staging.srag.cahosting.de srag.dev.saatec.local *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ piwik.sativa-biosaatgut.de www.google.com app-wallee.com td.doubleclick.net *.google.com/ www.googletagmanager.com js.mollie.com https://app-wallee.com https://checkout.postfinance.ch test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io static-dev.srag.cahosting.de static-dev.srag.codel1.de widgets.trustedshops.com www.google.de piwik.sativa-biosaatgut.de tmpsativa-static.codel1.de cdn.live.srag.cahosting.de cdn.dev.srag.cahosting.de cdn.dev.srag.codel1.de cdn.staging.srag.cahosting.de files.mirasvit.com www.magecomp.com srag.dev.saatec.local www.sativa.bio ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com magefan.com cm.magefan.com https://www.magezon.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net https://www.mollie.com https://app-wallee.com https://checkout.postfinance.ch test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ analytics.sativa.bio www.google.com www.gstatic.com use.fontawesome.com static-dev.srag.cahosting.de static-dev.srag.codel1.de tmpsativa-static.codel1.de cdn.live.srag.cahosting.de cdn.dev.srag.cahosting.de cdn.dev.srag.codel1.de cdn.staging.srag.cahosting.de static-staging.srag.cahosting.de widgets.trustedshops.com consent.cookiefirst.com browser-update.org piwik.sativa-biosaatgut.de app-wallee.com srag.dev.saatec.local chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com *.google.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com maps.googleapis.com js.mollie.com https://app-wallee.com https://checkout.postfinance.ch https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com use.fontawesome.com static-dev.srag.cahosting.de static-dev.srag.codel1.de fonts.googleapis.com maxcdn.bootstrapcdn.com cloud.typography.com consent.cookiefirst.com sativa.bio www.sativa.bio tmpsativa-static.codel1.de cdn.live.srag.cahosting.de cdn.dev.srag.cahosting.de cdn.dev.srag.codel1.de cdn.staging.srag.cahosting.de srag.dev.saatec.local downloads.mailchimp.com *.fontawesome.com *.gstatic.com https://app-wallee.com https://checkout.postfinance.ch 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com analytics.sativa.bio static-dev.srag.cahosting.de static-dev.srag.codel1.de static.cookiefirst.com edge.cookiefirst.com consent.cookiefirst.com api.cookiefirst.com tmpsativa-static.codel1.de cdn.live.srag.cahosting.de cdn.dev.srag.cahosting.de cdn.dev.srag.codel1.de cdn.staging.srag.cahosting.de pagead2.googlesyndication.com www.google.de google.com www.google.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com https://app-wallee.com https://checkout.postfinance.ch https://assets.secure.checkout.visa.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.code-alliance.de/srag/report-csp-frontend; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: 'unsafe-inline' data: *.cloudflare.com *.stape.io maxcdn.bootstrapcdn.com wp.floorfive.com.au data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.facebook.net wp.floorfive.com.au 'self' 'unsafe-inline'; frame-ancestors *.google.com *.youtube.com wp.floorfive.com.au 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googletagmanager.com *.addthis.com *.doubleclick.net *.paypalobjects.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.stape.io *.trustpilot.com wp.floorfive.com.au 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.google.com *.google.com.au *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.cloudflare.com csi.gstatic.com *.dugg.com.au *.undiesdrawer.com *.undiewarehouse.com.au *.heyfranky.com.au *.wearitout.com.au *.zodee.com.au *.floorfive.com.au *.mailchimp.com mcusercontent.com *.facebook.com *.mailmunch.co *.mailmunch.com magefan.com cm.magefan.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.stape.io flagpedia.net wp.floorfive.com.au data: 'self' 'unsafe-inline'; script-src *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.trustpilot.com *.googleadservices.com *.doubleclick.net *.gstatic.com *.googletagmanager.com *.zdassets.com *.cloudflare.com *.mailchimp.com *.addthis.com *.addthisedge.com *.moatads.com *.pinterest.com *.fontawesome.com *.authorize.net *.newrelic.com *.nr-data.net *.lexity.com *.hellomedian.com *.zonos.com connect.facebook.net *.mailmunch.co *.mailmunch.com ajax.googleapis.com d3js.org *.cloudflareinsights.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.stape.io maps.googleapis.com https://www.productreview.com.au https://cdn.productreview.com.au https://api.productreview.com.au wp.floorfive.com.au https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com 'self' data: *.googleapis.com *.cloudflare.com *.fontawesome.com *.mailmunch.co *.mailmunch.com *.googletagmanager.com *.stape.io maxcdn.bootstrapcdn.com *.gstatic.com *.trustpilot.com wp.floorfive.com.au 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com wp.floorfive.com.au 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com.au *.zdassets.com floorfive.zendesk.com *.doubleclick.net *.addthis.com *.cloudflare.com *.nr-data.net *.hellomedian.com wss://socket.hellomedian.com/ *.tokbox.com wss://*.zopim.com *.zonos.com *.mailmunch.co *.mailmunch.com *.facebook.com *.facebook.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io www.gstatic.com maps.googleapis.com *.trustpilot.com wp.floorfive.com.au 'self' 'unsafe-inline'; child-src wp.floorfive.com.au http: https: blob: 'self' 'unsafe-inline'; default-src wp.floorfive.com.au 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-eval' http: https: https://headless.atlasusa.net 'nonce-6MNSxBvryhkroXbgCxTUtvD9Rwd0Eo5ZQd9s72ONelrMB' *.nr-data.net *.googletagmanager.com *.esnbranding.com *.hotjar.com *.maze.co; style-src 'self' blob: https: 'unsafe-inline' https://headless.atlasusa.net *.cdn-apple.com *.facebook.net; connect-src 'self' wss: *.paypal.com *.googleapis.com *.adobedc.net *.ipstack.com *.zendesk.com *.zdassets.com *.demdex.net *.adobe.io *.bazaarvoice.com *.nr-data.net *.google-analytics.com api.smooch.io *.google.com google.com *.doubleclick.net *.cdn-apple.com *.esnbranding.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.omtrdc.net *.bing.com *.bing-int.com *.pinterest.com *.facebook.com www.facebook.com www.googleadservices.com metrics.arielbath.com; img-src data: http: https: *.esnbranding.com facebook.com; object-src 'none'; base-uri 'none'; child-src 'self'; font-src 'self' data: fonts.gstatic.com *.hotjar.com *.cdn-apple.com; frame-src sketchfab.com sketchfab-prod-media.s3.amazonaws.com assets.braintreegateway.com *.google.com *.youtube.com *.youtu.be *.youtube-nocookie.com *.vimeo.com *.paypal.com *.googletagmanager.com *.doubleclick.net *.pinterest.com *.facebook.com *.cdn-apple.com metrics.arielbath.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com *.cdnfonts.com *.slant.co data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.newrelic.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://integrations.etrusted.com www.xtento.com cdn.xtento.com *.adnxs.com *.cookiebot.com d2rfa446ja7yzb.cloudfront.net *.fbcdn.net www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.ba www.google.be www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gh www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.za www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.it www.google.jo www.google.kg www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tn google.com *.google.com nijhofbaarn.nl *.nijhofbaarn.nl *.pinterest.com *.shopify.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://integrations.etrusted.com www.xtento.com cdn.xtento.com https://chimpstatic.com *.calendly.com *.cookiebot.com *.getflowbox.com *.pinimg.com *.pinterest.com *.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com assets.braintreegateway.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com *.cookiebot.com *.getflowbox.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9a4c0d88-eba9-461e-ba4e-f9cd9c0c2419.sansec.watch/; report-to report-endpoint; 1 font-src *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://www.facebook.com https://c.clarity.ms/ https://bat.bing.com/ https://c.bing.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com s7.addthis.com *.fontawesome.com *.googleapis.com *.gstatic.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com https://cs.iubenda.com/ static.addtoany.com acsbapp.com mylivechat.com a6.mylivechat.com https://cdn.iubenda.com/cs/ccpa/stub.js https://connect.facebook.net/ http://www.paypalobjects.com http://www.googletagmanager.com http://www.vimeo.com https://cdn.iubenda.com/ https://bat.bing.com/ https://www.clarity.ms/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com a6.mylivechat.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com ekr.zdassets.com/ http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com cdn.acsbapp.com http://www.googletagmanager.com http://www.sandbox.paypal.com http://www.paypalobjects.com https://hits-i.iubenda.com/ https://w.clarity.ms/collect http://www.google-analytics.com https://consent.iubenda.com/ https://o.clarity.ms/collect https://v.clarity.ms/collect 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://demo.docusign.net https://demo-d.docusign.net https://apps.docusign.com https://apps-d.docusign.com https://account-d.docusign.com https://account.docusign.com https://docusign.net https://staging.clarifycapital.com https://clarifycapital.com https://www.clarifycapital.com https://data.clarifycapital.com; frame-src 'self' https://api.frac.tl https://public.flourish.studio https://www.facebook.com https://www.googletagmanager.com https://apps.docusign.com https://apps-d.docusign.com https://widget.trustpilot.com https://td.doubleclick.net *.frac.tl *.flourish.studio *.facebook.com *.googletagmanager.com *.docusign.com *.trustpilot.com *.doubleclick.net *.cloudflareinsights.com *.google-analytics.com *.google.com *.googleapis.com *.gstatic.com *.facebook.net *.bizconnectads.com *.docusign.net *.idocusign.net *.clarifycapital.com *.stape.biz; script-src 'self' https://js.docusign.com https://js-d.docusign.com https://docucdn-a.akamaihd.net https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net https://td.doubleclick.net ws://localhost:12387 https://www.googleadservices.com https://www.google.com https://www.google.com/ads https://plausible.clickolo.com https://cdn.plot.ly https://connect.facebook.net https://widget.trustpilot.com info.clarifycapital.com https://static.cloudflareinsights.com https://snap.licdn.com *.clarifycapital.com *.pardot.com *.frac.tl *.flourish.studio *.facebook.com *.googletagmanager.com *.docusign.com *.trustpilot.com *.doubleclick.net *.cloudflareinsights.com *.google-analytics.com *.google.com *.googleapis.com *.gstatic.com *.facebook.net *.bizconnectads.com *.docusign.net *.idocusign.net *.clarifycapital.com *.stape.biz https://cdn.jsdelivr.net/npm/posthog-js@1.207.9/+esm blob: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https://secure.gravatar.com https://www.facebook.com https://www.google-analytics.com data: https: 'unsafe-inline'; connect-src 'self' *.clarifycapital.com https://demo.docusign.net https://demo-d.docusign.net https://apps.docusign.com https://apps-d.docusign.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://www.google.com https://stats.g.doubleclick.net https://px.ads.linkedin.com https://plausible.clickolo.com https://api.frac.tl https://maps.googleapis.com https://maps.gstatic.com https://www.facebook.com https://capi.bizconnectads.com https://capig.stape.biz *.pardot.com *.frac.tl *.flourish.studio *.facebook.com *.googletagmanager.com *.docusign.com *.trustpilot.com *.doubleclick.net *.cloudflareinsights.com *.google-analytics.com *.google.com *.googleapis.com *.gstatic.com *.facebook.net *.bizconnectads.com *.docusign.net *.idocusign.net *.clarifycapital.com *.stape.biz blob:; style-src 'self' 'unsafe-inline' 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://cdn.mouseflow.com/projects/b968dc9f-fc4a-4aa0-aec8-bf2835f272da.js https://js.hs-analytics.net/analytics/1679396400000/9103575.js https://js.hs-banner.com/9103575.js https://js.hs-scripts.com/9103575.js https://player.vimeo.com/api/player.js https://sc.lfeeder.com/lftracker_v1_DzLR5a5o6x67BoQ2.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://cdn.linkedin.oribi.io https://cms.viktor.ai https://region1.analytics.google.com https://stats.g.doubleclick.net https://www.google.com https://www.google.de; font-src 'self'; frame-src 'self' https://player.vimeo.com; img-src 'self' data: https://cms.viktor.ai https://i.vimeocdn.com https://px.ads.linkedin.com https://tr-rc.lfeeder.com https://track.hubspot.com https://www.google.de; manifest-src 'self'; media-src 'self' https://player.vimeo.com https://vod-progressive.akamaized.net; worker-src 'none'; report-uri https://errors.viktor.ai/api/28/security/?sentry_key=e0a4ff4328bc4f8d988f8711f9e814d4; 1 font-src *.klarnacdn.net *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com fonts.googleapis.com *.sirv.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cleverreach.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.klarna.com js.mollie.com consentcdn.cookiebot.com/ ad.ad-srv.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudfront.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.facebook.com https://www.mollie.com ad.doubleclick.net cdn.notebookgalerie.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.sirv.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.googletagmanager.com *.facebook.net *.fontawesome.com *.avada.io js.mollie.com *.adcell.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sirv.com player.vimeo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.sirv.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.sirv.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.google-analytics.com https://get.geojs.io *.avada.io *.adcell.com eu1-search.doofinder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sirv.com *.youtube.com blob: *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'strict-dynamic' 'nonce-RshKkoHZD0O0TX4yNJqvLw==' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.taboola.com https://*.usercentrics.eu https://analytics.tiktok.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://chat.kindlycdn.com https://connect.facebook.net https://ct.pinterest.com https://gallery.cevoid.com https://google-analytics.com https://pay.google.com https://s.pinimg.com https://t.contentsquare.net https://tr.snapchat.com https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagservices.com; style-src 'self' 'unsafe-inline' https: data:; connect-src 'self' https://*.az.contentsquare.net https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.facebook.com https://*.google-analytics.com https://*.google.com https://*.google.se https://*.klarna.com https://*.kindly.ai https://*.kustom.co https://*.snapchat.com https://*.taboola.com https://*.tiktok.com https://*.usercentrics.eu https://*.kappahl.com https://*.newbie.com https://analytics-ipv6.tiktokw.us https://api.cevoid.com https://api.klarna.com https://api.raygun.io https://api.screen9.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://bat.bing.net https://bot.kindly.ai https://cdn.raygun.io https://chat.kindlycdn.com https://checkout-test.adyen.com https://checkout.adyen.com https://checkoutanalytics-test.adyen.com https://checkoutshopper-test.cdn.adyen.com https://checkoutshopper-test.cdn.adyen.com/ https://ct.pinterest.com https://dc.services.visualstudio.com https://gallery.cevoid.com https://google.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://pay.google.com https://qcdn.screen9.com https://qcnl.tv https://statsapi.screen9.com https://t.contentsquare.net https://t1.voyado.com https://wapi.lipscore.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.pinterest.com https://www.sandbox.paypal.com; frame-src 'self' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.usercentrics.eu https://checkout.klarna.com https://ct.pinterest.com https://pay.google.com https://*.kappahl.com https://*.newbie.com https://tr.snapchat.com https://www.googletagmanager.com https://www.sandbox.paypal.com; img-src 'self' data: https: blob:; media-src 'self' blob: data: https:;font-src 'self' https: data:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; report-uri /csp-report; 1 font-src cash-f.squarecdn.com https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.gstatic.com apis.google.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.google.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://static.klaviyo.com https://lmf.test *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.finance-calculator.co.uk *.s3.eu-west-2.amazonaws.com *.dekopay.org *.deko-uat.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.gstatic.com 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.finance-calculator.co.uk *.deko.finance *.dekopay.org *.deko-uat.com www.google.com www.gstatic.com apis.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com s3.eu-west-1.amazonaws.com 'self' data: magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com *.openstreetmap.org https://maps.googleapis.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com dekowallet-feature-assets.s3.eu-west-2.amazonaws.com *.blackhorseflexpay.co.uk/ *.disqus.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.trustpilot.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.openstreetmap.org https://maps.googleapis.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.omniporttest.ocrf.co.uk/ *.omniport.omnicapital.co.uk/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.googleapis.com www.natlallergy.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com *.yotpo.com www.natlallergy.com 'self' 'unsafe-inline'; frame-ancestors 'self' *.recaptcha.net https://www.google.com/ *.google.com www.natlallergy.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.affirm.com *.affirm.ca 'self' https://allergypreventionteam.wufoo.com/ https://www.youtube-nocookie.com/ *.recaptcha.net https://www.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com www.xtento.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com www.natlallergy.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com www.apptrian.com *.affirm.com *.affirm.ca https://bat.bing.com/ https://www.google.co.in/ http://seal-atlanta.bbb.org/logo/sehzbus/national-allergy-3000836.png https://medals.bizrate.com/medals/dynamic/71068_medal.gif https://medals.bizrate.com/medals/summary/71068_medal_summary.gif https://verify.authorize.net/anetseal/images/secure90x72.gif https://d3k81ch9hvuctc.cloudfront.net/ https://secure.adnxs.com/ https://match.adsrvr.org/ https://b1img.com/ https://insight.adsrvr.org/ https://load77.exelator.com/pixel.gif https://pixel.tapad.com/ https://loadm.exelator.com/ https://dmp.truoptik.com/ https://su.addthis.com/ https://dsum-sec.casalemedia.com/ https://secure.insightexpressai.com/ https://idpix.media6degrees.com/ https://x.bidswitch.net/ https://ads.scorecardresearch.com/ https://tags.rd.linksynergy.com/ https://i.liadm.com/ https://odr.mookie1.com/ https://mid.rkdms.com/ https://usermatch.krxd.net/ https://simage2.pubmatic.com/ https://match.sync.ad.cpe.dotomi.com/ https://ml314.com/ https://eb2.3lift.com/ https://tags.bluekai.com/ https://secure-gl.imrworldwide.com/ https://pixel.rubiconproject.com/ https://match.sharethrough.com/ https://uipglob.semasio.net/ https://track2.securedvisit.com/ https://www.natlallergy.com https://www.allergyguarddirect.com/ https://www.google.co.in/ads https://*.online-metrix.net https://srv.stackadapt.com/ https://cw.addthis.com/ https://aa.agkn.com/ https://i6.liadm.com/ https://io.narrative.io/ validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com guarantee-cdn.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com www.xtento.com cdn.xtento.com *.yotpo.com https://imgs.signifyd.com www.natlallergy.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com www.apptrian.com *.affirm.com *.affirm.ca https://seal.geotrust.com/ https://widget.trustpilot.com/ https://bat.bing.com/ https://sealserver.trustkeeper.net/compliance/seal_js.php https://h64.online-metrix.net/ https://medals.bizrate.com/medals/js/71068_medal.js https://www.wufoo.com/scripts/embed/form.js https://static.wufoo.com/scripts/embed/form.js https://js.b1js.com/tagcontainer.js https://tags.b1js.com/tags/1980582b3edf42e49663fce67ee51785.js https://b1img.com/ https://static.cloudflareinsights.com/ https://static-tracking.klaviyo.com https://www.natlallergy.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cloudflare.com guarantee-cdn.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com www.xtento.com cdn.xtento.com *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com www.natlallergy.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://www.natlallergy.com/ https://static-tracking.klaviyo.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline *.tagmanager.google.com fonts.googleapis.com *.yotpo.com www.natlallergy.com 'self' 'unsafe-inline'; object-src https://www.youtube.com/ 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com www.natlallergy.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com www.apptrian.com *.affirm.com *.affirm.ca https://bat.bing.com/ https://stats.g.doubleclick.net https://www.natlallergy.com https://www.googleadservices.com/ http://localhost:12387/ https://analytics.google.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com https://imgs.signifyd.com www.natlallergy.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.natlallergy.com http: https: blob: 'self' 'unsafe-inline'; default-src www.natlallergy.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; img-src 'self' data: https://cdn.shopify.com https://cdn.sweettooth.io https://alb.reddit.com https://www.google-analytics.com https://www.google.com https://www.google.co.uk https://*.bing.com https://*.clarity.ms https://*.gorgias.io https://*.gorgias.chat https://services.postcodeanywhere.co.uk https://dev.poq.io/ https://productreviews-attachments.trustpilot.com https://proxy.elfsightcdn.com https://www.googletagmanager.com https://api-uploads-cdn.sweettooth.io https://dev.visualwebsiteoptimizer.com https://i.ytimg.com https://www.facebook.com https://d2bzfgi7sjutmd.cloudfront.net https://static.elfsight.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://storage.googleapis.com https://s3.amazonaws.com https://fonts.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.redditstatic.com https://cdn.rollbar.com https://polyfill.io https://*.gorgias.chat https://*.hotjar.com https://*.bing.com https://*.clarity.ms https://analytics.tiktok.com https://shy.elfsight.com https://static.elfsight.com https://cdn.sweettooth.io https://www.dwin1.com https://services.postcodeanywhere.co.uk https://dev.poq.io/ https://client-builds.production.gorgias.chat https://dev.visualwebsiteoptimizer.com https://the.sciencebehindecommerce.com https://connect.facebook.net https://websdk.appsflyer.com https://*.fontawesome.com https://*.klaviyo.com https://*.mention-me.com https://cdn.amplitude.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://services.postcodeanywhere.co.uk https://dev.poq.io https://*.typekit.net; connect-src 'self' https://storeapi.arenaflowers.com/ https://*.arenaflowers.net https://services.postcodeanywhere.co.uk https://arenaflowers.us7.list-manage.com https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.google.co.uk https://*.gorgias.chat https://*.hotjar.com https://*.bing.com/ https://*.clarity.ms https://stats.g.doubleclick.net https://analytics.tiktok.com https://api.trustpilot.com https://api.rollbar.com https://dev.poq.io/ https://api.segment.io https://api.instacloud.io https://dev.visualwebsiteoptimizer.com https://the.sciencebehindecommerce.com https://vc.hotjar.io https://adservice.google.com https://banner.appsflyer.com https://*.klaviyo.com https://*.analytics.google.com https://*.doubleclick.net https://*.mention-me.com https://cdn.amplitude.com wss://*.gorgias.chat wss://*.hotjar.com; object-src 'none'; frame-src 'self' https://mention-me.com; report-uri https://qavfg2ndxaczvneictfzdaap2m0xlrlc.lambda-url.eu-west-1.on.aws/; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://use.fontawesome.com https://netdna.bootstrapcdn.com https://*.hotjar.com https://*.hotjar.io https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://*.trustpilot.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.outdoor-revolution.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.worldpay.com www.outdoor-revolution.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com www.outdoor-revolution.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com www.google.com https://www.google.com https://region1.analytics.google.com https://*.google.com https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://google.com/ https://*.trustpilot.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.weltpixel.com www.outdoor-revolution.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.googleapis.com https://maps.gstatic.com https://maps.googleapis.com https://www.google.co.uk https://lantern.roeye.com https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://google.com/ https://*.trustpilot.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.outdoor-revolution.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://*.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com https://use.fontawesome.com https://assets.adobedtm.com https://secure.authorize.net https://test.authorize.net https://www.googleadservices.com https://js.braintreegateway.com https://maps.google.com https://connect.facebook.net https://static.cloudflareinsights.com https://unpkg.com https://maps.googleapis.com https://region1.analytics.google.com https://*.google.com https://*.roeyecdn.com https://static.hotjar.com https://script.hotjar.com https://*.hotjar.com wss://ws.hotjar.com https://stats.g.doubleclick.net https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://google.com/ https://*.growthbook.io/ https://*.zdassets.com/ https://*.trustpilot.com/ https://*.zopim.com/ https://*.zendesk.com/ widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com www.outdoor-revolution.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://use.fontawesome.com https://fonts.googleapis.com https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://*.trustpilot.com/ widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.trustpilot.com www.outdoor-revolution.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.outdoor-revolution.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://region1.google-analytics.com https://region1.analytics.google.com https://*.google.com https://www.google.com https://www.google.co.uk https://*.google.co.uk https://*.roeyecdn.com https://static.hotjar.com https://script.hotjar.com https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://*.zdassets.com/ https://stats.g.doubleclick.net https://*.klaviyo.com https://*.googletagmanager.com https://*.gstatic.com https://google.com/ https://*.growthbook.io/ https://*.trustpilot.com/ https://*.zopim.com/ https://*.zendesk.com/ wss://*.zopim.com/ widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ landofcoder.com maps.googleapis.com chart.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com www.outdoor-revolution.com 'self' 'unsafe-inline'; child-src www.outdoor-revolution.com http: https: blob: 'self' 'unsafe-inline'; default-src www.outdoor-revolution.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self' 'unsafe-inline'; frame-src bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://www.googletagmanager.com/ *.google.com/ *.hotjar.com *.cookiebot.com *.google.ie *.google.de *.webgains.io *.usercentrics.eu *.haendlerbund.de *.ccm19.de 'self' 'unsafe-inline'; img-src 'self' data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com *.google.ie *.google.de *.webgains.io *.cloudfront.net *.usercentrics.eu *.facebook.com *.haendlerbund.de *.ccm19.de data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ *.instagram.com *.cookiebot.com *.google.ie *.google.de *.webgains.io *.googletagmanager.com *.facebook.com *.facebook.net *.trustedshops.com *.hotjar.com *.cloudfront.net *.amazon.de *.usercentrics.eu *.haendlerbund.de *.ccm19.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com maxcdn.bootstrapcdn.com *.haendlerbund.de *.ccm19.de 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.amazon.de *.facebook.com *.usercentrics.eu *.ccm19.de *.instagram.com *.cookiebot.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-NDFlMmQ5NTItMWQyNi00YjE0LWI2MjItODQwNWNjYzAwZWJj' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cloudfront.net js.mollie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io blob: *.cloudfront.net https://images.pfconcept.com https://static.xdconnects.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com https://scontent.cdninstagram.com https://firebasestorage.googleapis.com https://www.mollie.com https://printposition-images-api.cdn.midocean.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.facebook.net *.cloudfront.net https://platform-api.sharethis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com https://player.vimeo.com *.avada.io *.shopify.com js.mollie.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudfront.net downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudfront.net form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com https://graph.instagram.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; media-src 'self' https://panel.sutty.nl; style-src 'self' 'unsafe-inline'; script-src https: 'self'; font-src data: 'self'; img-src https: data: 'self'; object-src 'none'; frame-src https: 'self'; connect-src 'self' https://*.sutty.nl; report-uri https://api.sutty.nl/v1/csp_reports.json 1 default-src 'self'; report-uri /endpoint-relatorio-csp; 1 img-src https://higherlogicdownload.s3.amazonaws.com/CBAA/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CBAA/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/CBAA/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CBAA/ https://higherlogicdownload.s3.amazonaws.com/CBAA/ https://higherlogiclongterm.s3.amazonaws.com/CBAA/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/CBAA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CBAA/ 'self' https://higherlogiclongterm.s3.amazonaws.com/CBAA/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/CBAA/ https://higherlogicdownload.s3.amazonaws.com/CBAA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CBAA/ https://higherlogicstream.s3.amazonaws.com/CBAA/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/CBAA/ https://higherlogicdownload.s3.amazonaws.com/CBAA/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CBAA/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 frame-ancestors 'self'; report-uri https://reference.elcom.com.au/LogCSP.ashx 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-WOMf0Z2BwI6btwisIdsjnFcfd1s=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline'; form-action 'none'; report-to default; report-uri https://tokemak.uriports.com/reports 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-sEprh62bf1DrwHsJN7ygnTVhkos=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' *.aersale.com 1 script-src 'self' 'strict-dynamic' 'nonce-9mYjKFba/Kp45Nuf964XPjrHKsXgn5tUkd2ntvGb9ns=' 'unsafe-inline' http: https:;object-src 'none';base-uri 'none';frame-ancestors 'self'; 1 font-src *.flix360.io *.flixcar.com *.flixfacts.com *.hotjar.com i.icomoon.io fonts.gstatic.com *.typekit.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.createsend.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.youtube-nocookie.com *.doubleclick.net *.facebook.com *.flixcar.com *.flixfacts.com *.google.com *.loadbee.com koalendar.com vemcount.app www.googletagmanager.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.doubleclick.net *.facebook.com *.facebook.net *.flix360.com *.flix360.io *.flixcar.com *.flixfacts.com *.google.com *.googleapis.com *.gstatic.com *.smeg.be *.tiktok.com assets-jpcust.jwpsrv.com cdn.jwplayer.com img.sct.eu1.usercentrics.eu www.google.be www.google.co.uk www.google.ro maps.gstatic.com maps.googleapis.com imgsct.cookiebot.com imgsct.cookiebot.eu https://images.unsplash.com magefan.com cm.magefan.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.cookiebot.eu *.createsend1.com *.facebook.net *.flix360.io *.flixcar.com *.flixfacts.com *.google.com *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.tiktok.com cdn.loadbee.com maps.googleapis.com consent.cookiebot.com consent.cookiebot.eu https://maps.googleapis.com *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.flixcar.com *.googletagmanager.com *.gstatic.com *.typography.com i.icomoon.io fonts.googleapis.com *.typekit.net *.multisafepay.com *.googleapis.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.flixcar.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com *.facebook.com *.flix360.com *.flixcar.com *.google.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.loadbee.com *.tiktok.com createsend.com wss://ws.hotjar.com maps.googleapis.com stats.g.doubleclick.net consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://d715b72e-f2fb-4c67-a2d8-311d494776bc.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-77MbSH0fPR22JkBq3k1JLfApMP0=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com v2.zopim.com *.myfonts.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cybersource.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com *.authorize.net *.cybersource.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.gstatic.com https://firebasestorage.googleapis.com https://www.mollie.com prod-uscd-product-files.s3.amazonaws.com v2.zopim.com v2assets.zopim.io ci3.googleusercontent.com ci4.googleusercontent.com ci5.googleusercontent.com *.googleusercontent.com www.google.co.in *.myfonts.net *.online-metrix.net *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com s7.addthis.com *.avada.io js.mollie.com v2.zopim.com static.zdassets.com js-agent.newrelic.com bam.nr-data.net tools.luckyorange.com *.datatables.net *.myfonts.net static.cloudflareinsights.com *.authorize.net *.cardinalcommerce.com *.online-metrix.net *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.myfonts.net *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zendesk.com *.zdassets.com *.myfonts.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com ekr.zdassets.com/ https://get.geojs.io *.avada.io ekr.zdassets.com wss://widget-mediator.zopim.com bam.nr-data.net settings.luckyorange.com realtime.luckyorange.com api-preview.luckyorange.com pubsub.googleapis.com in.visitors.live wss://in.visitors.live wss://realtime.luckyorange.com *.zendesk.com *.authorize.net *.cardinalcommerce.com *.online-metrix.net *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com https://www.facebook.com/tr/ https://cookiehub.net/c2/ *.trustpilot.com/ https://*.mailerlite.com https://*.google-analytics.com https://*.analytics.google.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com https://www.facebook.com/ https://*.hotjar.com/ https://cookiehub.net/c2/ *.trustpilot.com/ https://*.mailerlite.com https://*.google-analytics.com https://*.analytics.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://*.google.com https://*.google.be https://*.facebook.com/ https://www.facebook.com/tr/ https://*.doubleclick.net https://cookiehub.net/c2/ *.trustpilot.com/ https://*.mailerlite.com https://*.google-analytics.com https://*.analytics.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io https://www.googletagmanager.com tagmanager.google.com https://devdocs.magento.com https://magento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net tagmanager.google.com https://*.tawk.to https://cookiehub.net/c2/ *.trustpilot.com/ https://*.mailerlite.com https://*.google-analytics.com https://*.analytics.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://get.geojs.io *.avada.io https://www.google-analytics.com https://devdocs.magento.com https://*.google.com https://tawk.to https://*.g.doubleclick.net/ https://*.hotjar.com/ https://cookiehub.net/c2/ *.trustpilot.com/ https://*.mailerlite.com https://consent.cookiehub.net/ https://*.google-analytics.com https://*.analytics.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' https://api.livechatinc.com/v3.6/customer/action/get_dynamic_configuration https://apj2.smixexpress.com/express/webv3.js https://bat.bing.com/bat.js https://cdn-4.convertexperiments.com/js/10041003-10044174.js https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/js/bootstrap.bundle.min.js https://cdn.livechatinc.com/tracking.js https://cdn.mouseflow.com/projects/c4ee4ba3-0914-4afb-b961-a796c9c049cd.js https://cdnjs.cloudflare.com/ajax/libs/Swiper/8.3.1/swiper-bundle.min.js https://connect.livechatinc.com/api/v1/script/12081dbf-83da-4577-a727-43c7cb553c2e/widget.js https://kit.fontawesome.com/31f2af02b2.js https://maps.googleapis.com/maps/api/js https://mktdplp102cdn.azureedge.net/public/latest/js/form-loader.js https://pcinederland.stackbase.nl/ https://sc.lfeeder.com/lftracker_v1_bElvO73OmNK7ZMqj.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://sst.pci.nl/gtm.js https://www.clarity.ms/tag/56okb3ots0 https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/rKbTvxTxwcw5VqzrtN-ICwWt/recaptcha__nl.js; style-src 'report-sample' 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://56276a63c9db4aaab453ffab5ac0f4f0.svc.dynamics.com https://adservice.google.com https://api.livechatinc.com https://bat.bing.com https://ka-p.fontawesome.com https://kit.fontawesome.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://pcinederland.stackbase.nl https://px.ads.linkedin.com https://r.clarity.ms https://sst.pci.nl https://t.clarity.ms https://u.clarity.ms https://www.google.com https://x.clarity.ms https://z.clarity.ms; font-src 'self' data: https://fonts.gstatic.com https://ka-p.fontawesome.com; frame-src 'self' https://56276a63c9db4aaab453ffab5ac0f4f0.svc.dynamics.com https://apj2.smixexpress.com https://idmserver.euplatform.connectwise.com https://player.vimeo.com https://secure.livechatinc.com https://www.google.com https://www.youtube.com; img-src 'self' data: https://56276a63c9db4aaab453ffab5ac0f4f0.svc.dynamics.com https://api.taggrs.io https://bat.bing.com https://c.clarity.ms https://googleads.g.doubleclick.net https://i.ytimg.com https://maps.googleapis.com https://maps.gstatic.com https://px.ads.linkedin.com https://tr-rc.lfeeder.com; manifest-src 'self'; media-src 'self'; report-uri https://667e83c5d528e3ceb6b0e494.endpoint.csper.io/?v=2; worker-src 'none'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=26c42a0e-d366-4da2-be8f-b89047ee77b6; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com 'self' data: https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.usercentrics.eu *.etrusted.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.googleapis.com *.gstatic.com js.mollie.com *.hsforms.net *.hsforms.com *.google.com www.xtento.com cdn.xtento.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com *.etrusted.com *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analytics.google.com *.googletagmanager.com *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://afaff3ee-014e-4f63-be75-19ad72ddda80.sansec.watch/; report-to report-endpoint; 1 img-src 'self' data: https://bioexcel.eu https://tile.openstreetmap.org https://i0.wp.com https://pixel.wp.com https://i.ytimg.com https://www.googletagmanager.com https://meetings.embo.org https://en.wordpress.com https://updates.theme-fusion.com https://i1.wp.com blob: https://bioexcel.ebi.ac.uk https://fonts.gstatic.com https://cdn.honey.io https://really-simple-ssl.com https://w3id.org https://mirrors.creativecommons.org https://www.lumi-supercomputer.eu https://hm.baidu.com https://translate.google.com https://s11.no https://upload.wikimedia.org https://www.compbiomed.eu https://maps.gstatic.com https://dl.dropboxusercontent.com https://widgets.wp.com https://2.gravatar.com https://yastatic.net https://i2.wp.com https://cdn.leanlibrary.app https://www.researchobject.org https://www.gstatic.com http://pixel.wp.com https://www.bonvinlab.org https://www.researchsolutions.com https://maps.googleapis.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://stats.wp.com https://www.googletagmanager.com https://www.youtube.com https://secure.gravatar.com https://maps.google.com https://platform.twitter.com https://widget.docsbot.ai https://s0.wp.com https://app.satismeter.com https://widgets.wp.com https://s3.amazonaws.com blob: https://infird.com https://bioexcel.eu https://connect.facebook.net https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://js.sentry-cdn.com https://maps.googleapis.com https://127.0.0.1 https://secure.polldaddy.com https://gc.kis.v2.scr.kaspersky-labs.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://stats.wp.com https://www.googletagmanager.com https://www.youtube.com https://secure.gravatar.com https://maps.google.com https://platform.twitter.com https://widget.docsbot.ai https://s0.wp.com https://app.satismeter.com https://widgets.wp.com https://s3.amazonaws.com blob: https://infird.com https://bioexcel.eu https://connect.facebook.net https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://js.sentry-cdn.com https://maps.googleapis.com https://127.0.0.1 https://secure.polldaddy.com https://gc.kis.v2.scr.kaspersky-labs.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://s0.wp.com https://0.gravatar.com https://www.gstatic.com https://cdn.honey.io https://widgets.wp.com https://bioexcel.eu https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://maxcdn.bootstrapcdn.com https://gc.kis.v2.scr.kaspersky-labs.com ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://s0.wp.com https://0.gravatar.com https://www.gstatic.com https://cdn.honey.io https://widgets.wp.com https://bioexcel.eu https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://maxcdn.bootstrapcdn.com https://gc.kis.v2.scr.kaspersky-labs.com ; font-src 'self' https://fonts.gstatic.com https://s0.wp.com https://cdn.scite.ai https://s1.wp.com https://use.typekit.net https://maxcdn.bootstrapcdn.com https://r2cdn.perplexity.ai https://bioexcel.eu https://at.alicdn.com http://bioexcel.eu http://fonts.gstatic.com data:; frame-src 'self' https://www.youtube.com https://widgets.wp.com https://wordpress.com https://platform.twitter.com https://www.biophysics.se https://www.googletagmanager.com https://www.google.com http://www.youtube.com blob:; connect-src 'self' https://region1.google-analytics.com https://www.google-analytics.com https://i0.wp.com https://docsbot.ai https://app.satismeter.com https://adtonus.com https://api.moncyber-api.com http://localhost https://api.static-contents-cdn.com https://pubpeer.com https://maps.googleapis.com https://widgets.wp.com data: https://localhost https://unpaywall.inist.fr https://overbridgenet.com https://www.googletagmanager.com https://api.crossref.org https://translate.googleapis.com https://fonts.googleapis.com https://api.ebsco.io https://rumt-zh.com https://fonts.gstatic.com https://local.adblock360.com; media-src 'self' data:; worker-src 'self' blob:; report-uri https://bioexcel.eu/wp-json/really-simple-security/v1/csp?rsssl_apitoken=985807397; 1 frame-ancestors 'self' https://*.webflow.com https://webflow.com; report-uri https://webflow.report-uri.com/r/t/csp/reportOnly 1 default-src 'self'; img-src 'self' https://secure.gravatar.com data: blob: https://images.dev.nualang.com https://images.nualang.com https://d3p1kwdytke5db.cloudfront.net https://api.imagecreator.fathominnovation.com https://t.co https://*.facebook.com https://*.hubspot.com https://www.google-analytics.com https://*.twitter.com https://pbs.twimg.com https://images.dev-1.nualang.com https://images.prod-1.nualang.com https://forms.hsforms.com https://i.ytimg.com https://lh3.googleusercontent.com;frame-src https://www.google.com https://*.twitter.com https://*.hubspot.com https://www.youtube.com; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://*.hs-scripts.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hscollectedforms.net https://*.hubspot.com https://api.hubapi.com https://*.facebook.net https://*.ads-twitter.com https://stats.g.doubleclick.net https://*.usemessages.com https://*.hsadspixel.net https://region1.google-analytics.com https://youtube.com https://www.youtube.com https://cognito-idp.eu-west-1.amazonaws.com https://cognito-idp.us-east-1.amazonaws.com https://api.prod-1.nualang.com https://api.dev-1.nualang.com https://i.ytimg.com blob: https://gitlab.com https://nualang-packages.s3-eu-west-1.amazonaws.com/rivescript.min.js https://www.google-analytics.com https://api.nualang.com https://api.dev.nualang.com; script-src 'self' https://*.hs-scripts.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hscollectedforms.net https://*.usemessages.com https://*.hsadspixel.net https://*.facebook.net https://*.ads-twitter.com https://www.youtube.com https://cdnjs.cloudflare.com/ajax/libs/ https://nualang-packages.s3-eu-west-1.amazonaws.com/rivescript.min.js https://identity.netlify.com/v1/netlify-identity-widget.js https://unpkg.com/netlify-cms@%5E2.10.11/dist/netlify-cms.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com https://*.twitter.com https://cdn.syndication.twimg.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' https://fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/ https://platform.twitter.com/css/ 'unsafe-inline'; object-src 'none' 1 font-src *.fontawesome.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ js.mollie.com *.multisafepay.com https://pay.google.com https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://images.unsplash.com https://www.mollie.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: ts.tradetracker.net www.magmodules.eu https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://maps.googleapis.com js.mollie.com *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com downloads.mailchimp.com *.fontawesome.com *.multisafepay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net https://core.helloretail.com https://helloretailcdn.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://www.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp-reporting-service.com/my-project/endpoint; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com 'self' data: *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.chicagoautobodyparts.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://secure.networkmerchants.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.chicagoautobodyparts.com *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.iubenda.com *.facebook.net *.facebook.com *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.chicagoautobodyparts.com guarantee-cdn.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://secure.networkmerchants.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.klaviyo.com unpkg.com *.doubleclick.net *.googleapis.com 'sha256-g/qbQ8sW5eJ9JO8sQzRJ1OvARbUyKpJXFeof9SLw1eI=' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://secure.networkmerchants.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.chicagoautobodyparts.com *.cloudflare.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tidiochat.com *.chicagoautobodyparts.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://secure.networkmerchants.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.doubleclick.net *.iubenda.com *.facebook.net *.bing.com *.clarity.ms *.tidio.co wss://socket.tidio.co *.tidiochat.com *.onesignal.com onesignal.com *.cookie-script.com *.chicagoautobodyparts.com *.wesupply.xyz *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.net *.klaviyo.com *.run.app *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self' * blob: data:; script-src * about: 'unsafe-inline' 'unsafe-eval'; object-src 'self'; style-src * 'unsafe-inline'; img-src * data: blob:; media-src * blob: data:; frame-ancestors 'self'; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https: blob:; object-src 'none'; base-uri 'self'; manifest-src 'self' https:; media-src 'self' data:; form-action 'self' https:; frame-src 'self' https:; frame-ancestors 'self'; worker-src 'self' blob:; report-uri https://lets-doit.at/ajaxgateway/csp/; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.gstatic.com https://fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.cookiebot.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://www.mollie.com bucket-ip-website.s3.eu-central-1.amazonaws.com *.cookiebot.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.uz www.google.co.za www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.je www.google.kg www.google.lt www.google.lu www.google.lv www.google.md www.google.mk www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.sr *.google.com *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.cookiebot.com *.etc4.com *.marker.io *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.etc4.com *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cookiebot.com *.crwdcntrl.net www.google.al www.google.be www.google.ch www.google.com.gh www.google.com.hk www.google.com.sg www.google.com.tr www.google.dk www.google.fr www.google.hr www.google.it www.google.lv www.google.nl www.google.sk *.google.com *.marker.io s3.eu-west-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e9206888-2491-4f7a-9270-f7e82dc18757.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-fZeMlM/a6qptfhOifPgi3+wkOX4=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-JjqHnLNxqGWXxBictLSxdlBC4wg=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com airwallex.com *.airwallex.com google.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net google.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://cdn.jsdelivr.net *.avada.io *.shopify.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gorgias.chat google.com *.google.com *.amplitude.com bat.bing.com https://firebasestorage.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gorgias.chat bat.bing.com *.amplitude.com *.avada.io *.shopify.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.gstatic.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com *.gorgias.chat stats.g.doubleclick.net *.amplitude.com https://get.geojs.io *.avada.io widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.openlife.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.openlife.com join.gammasecure.com; script-src 'self' *.openlife.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.openlife.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.cookiebot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.placeholder.com *.linkedin.com *.cookiebot.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com bam-cell.nr-data.net bam.nr-data.net *.cookiebot.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cookiebot.com *.fontawesome.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com bam-cell.nr-data.net *.cookiebot.com *.google-analytics.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-0Drp2ln8rx3Lq4ux2yYg8WP1cDo=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self';script-src 'self' 'unsafe-inline' https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://unpkg.com https://login.microsoftonline.com https://js.authorize.net https://bat.bing.com/bat.js https://s.pinimg.com/ct/core.js https://googleads.g.doubleclick.net https://www.clarity.ms https://www.google-analytics.com https://static.ads-twitter.com https://connect.facebook.net https://maxcdn.bootstrapcdn.com https://bat.bing.com https://s.pinimg.com;object-src 'none';style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://unpkg.com;img-src 'self' https://www.aimclub.org https://bat.bing.net https://i.ytimg.com https://www.google.com https://connect.facebook.com https://www.google.ca https://www.google-analytics.com https://c.clarity.ms https://t.co https://www.facebook.com https://analytics.twitter.com https://www.google.co.uk;media-src 'self';frame-src 'self' https://www.google.com https://www.youtube.com https://www.facebook.com https://my.matterport.com https://td.doubleclick.net https://m.facebook.com https://www.googletagmanager.com https://bpb.opendns.com;font-src 'self' https://fonts.gstatic.com;connect-src 'self' https://js.authorize.net https://www.google.com https://adservice.google.com https://www.googleadservices.com https://stats.g.doubleclick.net https://analytics.google.com https://region1.analytics.google.com https://www.google.ca https://api2.authorize.net https://ct.pinterest.com https://www.google-analytics.com https://www.facebook.com https://get663.com https://*.clarity.ms https://bat.bing.com https://www.facebook.com https://w88p9x.com;frame-ancestors 'self' https://www.nirvc.com https://www.nirvc.com/Sales/Pannellum360?photoUrl;report-uri /WebResource.axd?cspReport=true 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://2enzq5.pixum.nl https://rurxmjjmzm.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://2enzq5.pixum.nl https://rurxmjjmzm.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-TbK7nZ4IaeJq60fYuN8hnQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-MvnGKoZfjrK22Rf1WycbVHRc5Gg=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 script-src-elem *.cookiehub.eu *.olark.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com *.klevu.com *.ksearchnet.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.weltpixel.com https://www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com https://www.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com downloads.mailchimp.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com assets.braintreegateway.com tagmanager.google.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.cookiehub.net *.olark.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com *.bootstrapcdn.com *.gstatic.com *.googleapis.com 'self' data: *.hotjar.com *.typekit.net cdn.curator.io static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.chatra.io *.hotjar.com *.facebook.com *.trustpilot.com *.kiyoh.com *.pinterest.com *.criteo.com *.cookiefirst.com js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com * scontent.fzty3-2.fna.fbcdn.net https://www.mollie.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.cloudflare.com *.twitter.com *.fontawesome.com *.elfsight.com *.chimpstatic.com *.chatra.io *.jsdelivr.net chimpstatic.com *.facebook.com *.doubleclick.net *.trustpilot.com s.pinimg.com *.zdassets.com *.google-analytics.com *.feedbackcompany.com *.facebook.net *.hotjar.com *.mailchimp.com *.list-manage.com *.curator.io *.typekit.net *.clarity.ms *.leadinfo.net *.criteo.com *.googleadservices.com *.cookiefirst.com www.datadoghq-browser-agent.com bat.bing.com *.tidio.co *.tidiochat.com *.iubenda.com js-agent.newrelic.com *.googleapis.com *.gstatic.com js.mollie.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.mailchimp.com *.jsdelivr.net *.googleapis.com *.curator.io *.cookiefirst.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src curatorio.s3.amazonaws.com curator-assets.b-cdn.net video-lga3-2.cdninstagram.com video-iad3-1.xx.fbcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com https://maps.googleapis.com https://player.vimeo.com *.cloudflare.com *.elfsight.com *.instacloud.io *.google-analytics.com *.google.com *.doubleclick.net *.hotjar.com *.hotjar.io ct.pinterest.com *.paypal.com *.zdassets.com *.zendesk.com *.feedbackcompany.com *.curator.io *.clarity.ms *.leadinfo.net *.cookiefirst.com gtm-mm85h6s-nzi2m.uc.r.appspot.com www.google-analytics.com www.google.com maps.googleapis.com *.livechatinc.com www.paypalobjects.com dev.visualwebsiteoptimizer.com www.googletagmanager.com pagead2.googlesyndication.com googleadservices.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com rsms.me *.fontawesome.com *.cdn-custom.optimonk.com *.cdnfonts.com *.klaviyo.com *.paypal.com *.securesuite.co.uk *.lloydstsb.com *.google.com maxcdn.bootstrapcdn.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.multisafepay.com https://pay.google.com www.facebook.com platform.twitter.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com magefan.com cm.magefan.com *.disqus.com *.kxcdn.com *.optimonk.com *.onahole.com *.cloudfront.net tsyndicate.com *.motsugroup.com *.multisafepay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com https://img.youtube.com https://firebasestorage.googleapis.com *.meetanshi.com flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.disqus.com *.optimonk.com *.helpscout.net *.cloudflare.com *.onahole.com *.crazyegg.com *.beacon-v2.helpscout.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com *.klaviyo.com *.moatads.com *.addthisedge.com https://cdn.jsdelivr.net *.multisafepay.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net twitter.com platform.twitter.com *.avada.io *.tapfiliate.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.onahole.com *.optimonk.com *.cdnfonts.com *.klaviyo.com https://cdn.jsdelivr.net unpkg.com maxcdn.bootstrapcdn.com *.multisafepay.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.optimonk.com *.cloudfront.net https://stats.g.doubleclick.net *.onahole.com https://frstre.com/ *.tapfiliate.com *.crazyegg.com *.google-analytics.com *.googletagmanager.com *.paypalobjects.com *.doubleclick.net *.frstre.com *.klaviyo.com https://get.geojs.io *.gstatic.com *.motsugroup.com *.multisafepay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.onahole.com 'self' 'unsafe-inline'; 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com fonts.gstatic.com cdnjs.cloudflare.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.google.com www.gstatic.com s7.addthis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.gstatic.com www.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net *.openstreetmap.org maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com jquery.sellxed.com dpm.demdex.net s7.addthis.com m.addthis.com z.moatads.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com fonts.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.google-analytics.com stats.g.doubleclick.net s7.addthis.com m.addthis.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.klarna.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.klarna.com *.klarnaevt.com *.klarnacdn.net *.google.com *.cookiebot.com https://mfstatic.com https://im11.inviewer.se *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.lightwidget.com *.cookiebot.com https://mfstatic.com https://im11.inviewer.se *.mastercard.com *.visa.com *.staticv.me *.disqus.com *.avada.io *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.gstatic.com https://mfstatic.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.mediaflow.com https://mfstatic.com https://im11.inviewer.se https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; style-src 'nonce-PPDel2uOylMASjAhQkSNZec2mAkh8dY1' 'self'; style-src-attr 'unsafe-inline'; img-src https://www.facebook.com/tr/ https://www.facebook.com/privacy_sandbox/pixel/ https://www.googletagmanager.com/td https://www.googletagmanager.com/a https://shop.graysofwestminster.co.uk/wp-content/uploads/ data: 'self'; font-src 'self'; script-src 'nonce-PPDel2uOylMASjAhQkSNZec2mAkh8dY1' 'strict-dynamic'; manifest-src 'self'; frame-src https://widget.trustpilot.com/trustboxes/ https://www.recaptcha.net https://www.google.com/maps/embed https://tfl.gov.uk https://www.youtube.com/embed/; base-uri 'self'; connect-src https://www.facebook.com/tr/ https://www.facebook.com/privacy_sandbox/topics/ https://region1.google-analytics.com/g/collect https://www.google-analytics.com/g/collect https://www.recaptcha.net/recaptcha/; report-uri https://ainet-ltd.uriports.com/reports/report; report-to uriports 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com data: 'self' 'unsafe-inline'; form-action *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.addthis.com js.mollie.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com https://cdn.clerk.io imgsct.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.tiktok.com https://www.mollie.com *.koongo.com *.hsforms.net *.hsforms.com ts.tradetracker.net www.magmodules.eu https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com https://api.clerk.io https://cdn.clerk.io consent.cookiebot.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com connect.tiktok.net js.mollie.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js *.hsforms.net *.hsforms.com tm.tradetracker.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://cdn.jsdelivr.net cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.koongo.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.gstatic.com 'self' data: *.cookieinformation.com *.bootstrapcdn.com *.sleeknote.com *.hotjar.com *.clerk.io *.klaviyo.com *.piwik.pro *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.cookieinformation.com *.hotjar.com *.sleeknote.com *.clerk.io *.klaviyo.com *.piwik.pro 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.cookieinformation.com *.sleeknote.com *.maxcdn.com *.w3.org https://tssl.emailplatform.com http://t.emailplatform.com *.clerk.io *.klaviyo.com *.piwik.pro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com maps.googleapis.com security-hub.vaimo.network *.cookieinformation.com *.newrelic.com *.nr-data.net *.sleeknote.com https://tssl.emailplatform.com http://t.emailplatform.com *.hotjar.com connect.facebook.net *.clerk.io *.klaviyo.com *.piwik.pro 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.cookieinformation.com *.bootstrapcdn.com *.sleeknote.com *.clerk.io *.klaviyo.com *.piwik.pro *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.cookieinformation.com *.hotjar.com *.hotjar.io *.nr-data.net *.sleeknote.com wss://*.hotjar.com *.clerk.io *.klaviyo.com *.piwik.pro 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-274thrnhhT6a6VhPu1Fqv/+guzU=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; font-src 'self' cdn.conservadoresdigitales.cl; img-src 'self' cdn.conservadoresdigitales.cl www.google-analytics.com; script-src 'self' www.googletagmanager.com www.google-analytics.com cdn.conservadoresdigitales.cl www.gstatic.com www.google.com; style-src 'self' cdn.conservadoresdigitales.cl; frame-ancestors 'self' 1 default-src 'self'; connect-src 'self' *.google-analytics.com analytics.google.com *.analytics.google.com *.google.pl stats.g.doubleclick.net www.youtube.com; frame-ancestors https://cap1abmip02.capdale.com; frame-src 'self' www.google.com; font-src 'self' data:; img-src data: *; media-src *; object-src 'self' media.mtvnservices.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' www.google-analytics.com www.googletagmanager.com; style-src 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.facebook.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com places.googleapis.com cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.worldpay.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.worldpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.trend-uk.com www.trend-eu.com www.trend-ie.com www.trend-usa.com www.trend-ca.com www.trend-au.com www.trend-worldwide.com image.providesupport.com user-images.trustpilot.com *.googleusercontent.com maps.gstatic.com maps.googleapis.com trend-storage.online *.pinterest.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com secure.soil5hear.com enews-trend.com static.cloudflareinsights.com services.postcodeanywhere.co.uk *.elfsight.com *.providesupport.com cdn.jsdelivr.net *.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.worldpay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io services.postcodeanywhere.co.uk *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-11K5sTxB98FHmpU+/NChAEeCO+o=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' https: 'unsafe-inline' 'unsafe-eval'; font-src 'self' https: data:; img-src 'self' https: data:; worker-src 'self' https: blob:; report-uri https://charactercounts.org/report.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.amazonaws.com maxcdn.bootstrapcdn.com *.zopim.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.authorize.net *.global-e.com *.doubleclick.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.googleapis.com *.google.com *.zopim.com *.trustwave.com *.facebook.com *.ywxi.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.authorize.net *.mailchimp.com *.list-manage.com *.addthis.com *.addthisedge.com *.pinterest.com *.googletagmanager.com *.facebook.net *.cloudflare.com chimpstatic.com *.surveymonkey.com *.kbmaxnext.com *.ctctcdn.com *.adroll.com *.zopim.com *.klaviyo.com sc-static.net *.tiktok.com *.twitter.com brighterimagelab.com *.ads-twitter.com *.doubleclick.net *.googleadservices.com cdn.ywxi.net *.trustwave.com *.cloudflareinsights.com *.trustedsite.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.mailchimp.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.authorize.net *.doubleclick.net brighterimagelab.com *.klaviyo.com *.zopim.com *.googleadservices.com *.tiktok.com *.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.gstatic.com *.googleapis.com *.klaviyo.com *.stripe.com *.stripecdn.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com *.link.com *.amazon.com 'self'; frame-src *.adobe.com *.youtube.com *.youtube-nocookie.com *.braintreegateway.com *.paypal.com *.google.com *.cloudflare.com *.doubleclick.net *.facebook.com *.googletagmanager.com *.stripe.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com *.weltpixel.com fast.amc.demdex.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com 'self' 'unsafe-inline'; img-src *.adobe.com *.ftcdn.net *.vimeocdn.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com *.cloudfront.net *.facebook.com *.facebook.net *.ggpht.com *.google.com *.google.co.uk *.doofinder.com *.reddit.com *.ads-twitter.com *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.cdninstagram.com *.fbcdn.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.paypalobjects.com i.ytimg.com validator.swagger.io 'self' data: validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ t.co data: 'self' 'unsafe-inline'; script-src *.adobe.com *.nr-data.net *.commerce-payment-services.com *.vimeocdn.com *.youtube.com *.magento-ds.com *.typekit.net *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.cloudflare.com *.googlecommerce.com *.googletagmanager.com *.facebook.net *.civiccomputing.com *.trustpilot.com *.hotjar.com *.doofinder.com *.stripe.com *.stripe.network *.stripecdn.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.instagram.com assets.adobedtm.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com vimeo.com www.vimeo.com amcglobal.sc.omtrdc.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ unpkg.com https://www.cologneandcotton.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klaviyo.com *.googletagmanager.com *.doofinder.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com *.tagmanager.google.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.nr-data.net *.adobe.io *.sentry.io *.paypal.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.typekit.net *.facebook.com *.facebook.net *.datadome.co *.civiccomputing.com *.trustpilot.com *.hotjar.com *.hotjar.io *.doofinder.com *.stripe.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app *.instagram.com *.googleusercontent.com dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypalobjects.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://764d46a4-0921-4bd1-ba0d-19e4cfabafe5.sansec.watch/; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-tEjcF3AOtUpMg9TRO6BEHg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com applepay.cdn-apple.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors *.paypal.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.cookiebot.com *.googletagmanager.com api.payplug.com secure.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google-analytics.com *.googleapis.com *.google.com *.google.it https://images.unsplash.com 'self' data: *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.feedaty.com *.cookiebot.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google-analytics.com *.gstatic.com *.googleapis.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.jsdelivr.net *.feedaty.com *.cookiebot.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.doubleclick.net *.facebook.com *.googletagmanager.com *.googlesyndication.com *.feedaty.com *.cookiebot.com *.fontawesome.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.googleapis.com *.googlesyndication.com *.gstatic.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.feedaty.com PLACEHOLDER *.cookiebot.com *.google.it *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com *.salesfire.co.uk *.oakfurnitureuk.com *.bootstrapcdn.com www.oakfurnitureuk.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.oakfurnitureuk.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com www.oakfurnitureuk.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * challenges.cloudflare.com *.salesfire.co.uk *.googletagmanager.com *.trustpilot.com td.doubleclick.net *.clearpay.co.uk *.stripe.network landofcoder.com www.oakfurnitureuk.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.afterpay.com https://site-assets.afterpay.com/ *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.salesfire.co.uk *.facebook.com *.clarity.ms *.bing.com *.adobedtm.com *.demdex.net *.magentocommerce.com *.googleadservices.com google-analytics.com *.afterpay.com validate.fishpig.co.uk www.oakfurnitureuk.com *.postcodeanywhere.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com challenges.cloudflare.com *.salesfire.co.uk *.oakfurnitureuk.com *.googletagmanager.com omnisnippet1.com cdn.jsdelivr.net placement-api.clearpay.co.uk *.gstatic.com *.bootstrapcdn.com *.cardinalcommerce.com *.adobedtm.com *.trustpilot.com *.facebook.net *.pcapredict.com *.clickguardian.app *.bing.com *.clarity.ms *.postcodeanywhere.co.uk landofcoder.com www.oakfurnitureuk.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.salesfire.co.uk *.typekit.net *.oakfurnitureuk.com *.bootstrapcdn.com *.postcodeanywhere.co.uk *.trustpilot.com www.oakfurnitureuk.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.oakfurnitureuk.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com static.afterpay.com static.sandbox.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.clearpay.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.salesfire.co.uk *.smartmetrics.co.uk *.trustpilot.com *.oakfurnitureuk.com *.google-analytics.com wt.omnisendlink.com forms.soundestlink.com portal.clearpay.co.uk *.clarity.ms *.clickguardian.app *.g.doubleclick.net *.postcodeanywhere.co.uk landofcoder.com www.oakfurnitureuk.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.stripe.com www.oakfurnitureuk.com http: https: blob: 'self' 'unsafe-inline'; default-src *.oakfurnitureuk.com bat.bing.com r.stripe.com *.google.com www.oakfurnitureuk.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com *.stape.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ amc.demdex.net *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.googleapis.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.magezon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.stape.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.google.com/ https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googleapis.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.googletagmanager.com *.stape.io unsafe-inline assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com maps.googleapis.com *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'nonce-/XiHwoU/ybtD9Ru+vprN2dOXSbuJeZ6G' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http:; report-uri /.netlify/functions/__csp-violations 1 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://translate-pa.googleapis.com https://translate.google.com https://*.googletagmanager.com *.diffuse.tools 'nonce-UTxQy6J3d1bhu8d4PvXeOA=='; script-src-elem: 'self' 'unsafe-inline' https://translate.google.com https://*.googleapis.com https://translate.googleapis.com https://www.googletagmanager.com *.diffuse.tools 'nonce-UTxQy6J3d1bhu8d4PvXeOA=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://www.leergeld.nl https://plate.libpx.com https://prod1-plate-attachments.s3.amazonaws.com https://translate.googleapis.com https://www.gstatic.com https://www.google.com https://translate.google.com https://fonts.gstatic.com https://*.ytimg.com https://*.google-analytics.com https://*.googletagmanager.com; connect-src 'self' https://translate.googleapis.com https://www.youtube.com https://*.google-analytics.com *.diffuse.tools https://*.analytics.google.com https://*.googletagmanager.com; frame-src 'self'; 1 default-src https:;script-src https: 'self' 'strict-dynamic' 'nonce-8a69da6e95bd08de0077f8b67ee20787871c4e2480f1e3d1968ccbb174b75844' 'unsafe-inline' 'unsafe-eval' 'report-sample';style-src https: 'unsafe-inline';img-src https: data:;connect-src https: wss:;font-src https: data:;object-src 'none';media-src https: blob: data:;frame-src https: null data: blob:;child-src 'self' https:;form-action 'self';frame-ancestors https://my.firespring.com;base-uri 'self' https://insights.sitesearch360.com;worker-src 'self' blob:;manifest-src 'self' https://cdn.firespring.com;report-uri /csp_log 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=htbXcy3mWQGh9izmT1GD.JJU.4Du5CzJ.J5RT9nbIFc-1765940632.348273-1.0.1.1-eeJOSOdhV8_KQojFlXCwoXGQ_No4wXOBcsKZLB0VFrTa0X.lEddn03mbsz4jWmFfnQboDo7yhQJfVYOAMDIG4TmuLVVad4dS8GtLf1vhebhNY8sGyz4CcWLvye3FA2CItsxnS3NfcVHp.0EAPmPMwUsERg0BXVzqiyXmVXkiJKo; report-to cf-csp-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; 1 font-src *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.xtento.com *.hotjar.com cdn.dnky.co webchat.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://maps.omnivasiunta.lt www.xtento.com cdn.xtento.com data: *.xsmanguasjad.ee *.google.com *.google.lv image-charts.com *.klevu.com *.ksearchnet.com https://omnisnippet1.com https://wt.soundestlink.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://unpkg.com www.xtento.com cdn.xtento.com *.newrelic.com *.hotjar.com *.doubleclick.net *.googletagmanager.com *.nr-data.net *.zdassets.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com https://omnisnippet1.com https://forms.soundestlink.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://geocode.arcgis.com *.hotjar.com *.doubleclick.net *.nr-data.net *.zdassets.com *.zendesk.com *.zopim.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.paypal.com *.paypalobjects.com applepay.cdn-apple.com *.cloudflare.com 'self' data 'unsafe-inline' data *.stripe.com *.trustedshops.com *.magenio.com *.cdninstagram.com *.adbr.io *.adabra.com *.blendee.com scontent-frx5-1.cdninstagram.com *.fontawesome.com https://fonts.bunny.net *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sandbox.paypal.com *.magenio.com *.stripe.com *.googlesyndication.com *.iubenda.com *.adbr.io *.adabra.com *.blendee.com *.doubleclick.net *.googletagmanager.com *.weltpixel.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.googleapis.com *.sandbox.paypal.com *.cloudflare.com *.googleadservices.com *.magentocommerce.com *.stripe.com *.paypalobjects.com *.google.com *.google.nl *.iubenda.com *.adbr.io *.adabra.com *.magenio.com *.google.it *.cdninstagram.com scontent-frx5-1.cdninstagram.com *.clickiocdn.com clickiocdn.com *.googletagservices.com *.googlesyndication.com *.doubleclick.net blob: *.cookie-script.com *.blendee.com *.bindigiochi.it bindigiochi.it magadmin.bindigiochi.it https://firebasestorage.googleapis.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.googleapis.com *.gstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.cloudflare.com *.google-analytics.com *.googleadservices.com *.google.nl *.stripe.com 'self' 'unsafe-eval' 'unsafe-inline' *.ytimg.com *.fontawesome.com *.googletagmanager.com *.facebook.net connect.facebook.net *.doubleclick.net *.google.it *.iubenda.com *.magenio.com *.adbr.io *.adabra.com *.cdninstagram.com scontent-frx5-1.cdninstagram.com *.googlesyndication.com *.googletagservices.com *.blendee.com *.cookie-script.com *.bindigiochi.it bindigiochi.it magadmin.bindigiochi.it *.avada.io *.shopify.com cdn.scalapay.com b2c-cdn.scalapay.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.gstatic.com *.stripe.com *.typekit.net *.fontawesome.com *.doubleclick.net *.cdninstagram.com scontent-frx5-1.cdninstagram.com *.iubenda.com cdn.iubenda.com *.magenio.com *.adbr.io *.adabra.com *.cookie-script.com *.blendee.com *.bindigiochi.it bindigiochi.it magadmin.bindigiochi.it https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.sandbox.paypal.com *.cloudflare.com *.stripe.com *.doubleclick.net *.google.nl *.google.it *.magenio.com *.cdninstagram.com scontent-frx5-1.cdninstagram.com *.googlesyndication.com *.iubenda.com *.adbr.io *.adabra.com *.blendee.com *.bindigiochi.it bindigiochi.it magadmin.bindigiochi.it https://get.geojs.io *.avada.io *.gstatic.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src www.paypalobjects.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://*.gstatic.com https://*.typekit.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net consentcdn.cookiebot.com consentcdn.cookiebot.eu *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com https://*.braintreegateway.com https://*.paypal.com https://*.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com imgsct.cookiebot.com imgsct.cookiebot.eu *.stripe.com *.stripe.network https://*.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://*.googleapis.com https://*.gstatic.com https://*.doubleclick.net https://*.google.co.uk https://*.cloudfront.net https://*.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com guarantee-cdn.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com consent.cookiebot.com consent.cookiebot.eu *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.google.com *.sagepay.com *.opayo.eu.elavon.com https://*.googleapis.com https://www.gstatic.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.cloudfront.net https://*.google-analytics.com https://*.paypal.com https://*.trustpilot.com https://*.zdassets.com https://*.zendesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.stripe.network *.stripecdn.com *.amazon.com https://*.googleapis.com *.sagepay.com *.opayo.eu.elavon.com https://*.typekit.net https://*.cloudfront.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.ideal-postcodes.co.uk https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://*.freshdesk.com wss://*.hotjar.com https://*.googleapis.com https://*.zdassets.com https://*.zendesk.com wss://*.zendesk.com https://*.smooch.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.yotpo.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.certcapture.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.googleapis.com maps.gstatic.com *.yotpo.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.certcapture.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.yotpo.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.fontawesome.com *.yotpo.com *.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.certcapture.com thm.visa.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.yotpo.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cash-f.squarecdn.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com maxcdn.bootstrapcdn.com data: *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.cleverreach.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.trustedshops.com *.instagram.com *.fbcdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.klaviyo.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.instagram.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-ZmI0N2JiZDMtYjFlNS00ZDU1LWFkNGItY2U4MDI5NTIzZTZm' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; frame-ancestors 'self'; 1 font-src *.cloudflare.com *.typekit.net *.trustedshops.com *.fontawesome.com fonts.gstatic.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com youtu.be *.vimeo.com *.addthis.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com https://plumrocket.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.cloudflare.com https://cdn.klarna.com *.paypal.com https://s.ytimg.com *.usercentrics.eu blob: https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://*.google.nl https://*.googleadservices.com https://*.googlesyndication.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.fls.doubleclick.net https://*.adservice.google.com https://www.mollie.com maps.gstatic.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.captcha.eu *.cloudflare.com *.google-analytics.com *.google.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com maps.googleapis.com *.googletagmanager.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.captcha.eu https://w19.captcha.at https://at.captcha.at *.cloudflare.com *.paypal.com *.googleapis.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://stream.getmetrion.com https://*.googleadservices.com https://*.googletagmanager.com https://*.googletagservices.com https://*.googlesyndication.com https://*.doubleclick.net https://*.google.nl https://*.googlevideo.com https://*.googleusercontent.com https://*.googledomains.com https://*.g.doubleclick.net https://*.fls.doubleclick.net https://*.adservice.google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-N2Y1MjI3YWItNjBjMy00YWFiLWE4YzktODdjZDczOGUxOTUy' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self'; font-src 'self'; connect-src 'self'; media-src 'self'; base-uri 'self'; manifest-src 'self'; report-to: default; report-uri https://07fd.report-uri.com/r/d/csp/reportOnly 1 default-src *.fn-sb-notification-handler-dev.azurewebsites.net *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site *.cookielaw.org superbookkids.com *.brightcovecdn.com 'self' data:; script-src *.googleoptimize.com *.google-analytics.com *.googletagmanager.com 'unsafe-eval' ajax.googleapis.com *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site *.addtoany.com superbookkids.com *.cookielaw.org *.brightcove.net *.zencdn.net js-agent.newrelic.com 'self' 'unsafe-inline' *.go-mpulse.net ; object-src *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site superbookkids.com 'self'; style-src p.typekit.net use.typekit.net *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site fonts.googleapis.com 'self' 'unsafe-inline'; img-src *.cbn.com http://bible.cbn.com *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site *.cookielaw.org superbookkids.com sb-avatar-generator-aac5era4f5hfc7aq.eastus-01.azurewebsites.net *.brightcove.com *.boltdns.net 'self' data:; media-src *.cbn.com *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site superbookkids.com cbn.brightcovecdn.com 'self'; frame-src *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site *.addtoany.com superbookkids.com 'self'; frame-ancestors *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site superbookkids.com 'self'; child-src *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site superbookkids.com 'self' blob:; font-src use.typekit.net *.superbook.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site fonts.googleapis.com fonts.gstatic.com superbookkids.com 'self' data:; connect-src *.google-analytics.com *.superbook.cbn.com superbook-api.cbn.com superlibro.tv *.pantheonsite.io superbookindo.tv superbook.docksal.site *.cookielaw.org *.onetrust.com oss-cosmo-router-dev.fingent.net oss-cosmo-router-qa.fingent.net fn-sb-notification-handler-dev.azurewebsites.net superbookkids.com *.cbn.com *.boltdns.net bam.nr-data.net *.go-mpulse.net *.akstat.io *.akamaihd.net *.brightcove.com *.brightcovecdn.com wss://sr-superbook-prod.service.signalr.net 'self'; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://maps.gstatic.com store.paradoxlabs.com https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com tagmanager.google.com https://www.googletagmanager.com *.certcapture.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://maps.googleapis.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.certcapture.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://www.google-analytics.com *.certcapture.com https://basicbiblestudies.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://maps.googleapis.com canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://vars.hotjar.com/ https://www.form.jotform.com; frame-ancestors 'self' https://cms.kiwaregister.nl; style-src 'self' https://fonts.googleapis.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.googletagmanager.com https://region1.google-analytics.com https://dev.visualwebsiteoptimizer.com https://www.google-analytics.com https://static.hotjar.com https://script.hotjar.com; img-src 'self' https://www.kiwa.com https://www.google-analytics.com https://region1.google-analytics.com https://dev.visualwebsiteoptimizer.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://in.hotjar.com; form-action 'self'; base-uri 'self'; 1 object-src 'none'; connect-src 'self' *.zerotolerancefilms.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.zerotolerancefilms.com join.gammasecure.com; script-src 'self' *.zerotolerancefilms.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.zerotolerancefilms.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 script-src 'self' 'nonce-HWthi77YRhjmbazjSnQ6M8NxBgoSI6G+iXaQ6zHgHiI=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'self'; script-src 'self' https://cookiebot.com; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/learning_google 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.adobe.com *.facebook.com *.facebook.net *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.vimeo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.vimeo.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.paypal.com *.youtube.com *.vimeo.com *.vimeocdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adobe.com *.facebook.com *.facebook.net *.fontawesome.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.youtube.com *.vimeo.com *.vimeocdn.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce--2hIfsItOTmMK_83MjzfUw' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src https:;script-src https: 'self' 'strict-dynamic' 'nonce-04f1a208d320136a9a78fec9cbdc7067919ef7a69a3c6c957a64004a288f9c45' 'unsafe-inline' 'unsafe-eval' 'report-sample';style-src https: 'unsafe-inline';img-src https: data:;connect-src https: wss:;font-src https: data:;object-src 'none';media-src https: blob: data:;frame-src https: null data: blob:;child-src 'self' https:;form-action 'self';frame-ancestors https://my.firespring.com;base-uri 'self' https://insights.sitesearch360.com;worker-src 'self' blob:;manifest-src 'self' https://cdn.firespring.com;report-uri /csp_log?n=1 1 default-src 'self'; script-src 'self' *.yandex.ru 1 font-src fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.google.com *.certcapture.com googleads.g.doubleclick.net data: *.google.co.in www.facebook.com platform.twitter.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.certcapture.com blob: *.google.com *.google.co.in *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.paypal.com *.ytimg.com *.swagger.io *.authorize.net *.cloudfront.net *.pinterest.com *.twitter.com *.paradoxlabs.com *.braintreegateway.com *.bing.com https://maps.gstatic.com https://maps.googleapis.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.googletagmanager.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com *.gstatic.com *.google.com *.authorize.net *.bing.com js-agent.newrelic.com *.facebook.net bam.nr-data.net *.googleadservices.com *.searchspring.net *.cardinalcommerce.com *.braintreegateway.com *.paypal.com *.ytimg.com *.vimeo.com *.twitter.com googleads.g.doubleclick.net https://maps.googleapis.com https://maps.gstatic.com connect.facebook.net twitter.com platform.twitter.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdn.searchspring.net/intellisuggest/is.min.js https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com fonts.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.searchspring.net unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com bam.nr-data.net stats.g.doubleclick.net *.searchspring.io https://maps.googleapis.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://beacon.searchspring.io/beacon https://www.google-analytics.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src fonts.gstatic.com fonts.googleapis.com www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.realexpayments.com/ *.paypal.com/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.lpsnmedia.net/ *.googletagmanager.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://www.google.com/ https://www.google.pl/ *.google.pl *.lpsnmedia.net/ https://www.chrisanne-clover.com// imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://cdn.weglot.com/ https://magento.com https://www.google.com/ https://www.google.pl/ https://www.gstatic.com/ *.liveperson.net/ *.lpsnmedia.net/ *.gopay.com/ *.googlesyndication.com/ *.cookiebot.com/ consent.cookiebot.com consent.cookiebot.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://cdn.weglot.com/ downloads.mailchimp.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://cdn.weglot.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://cdn-api-weglot.com/ *.lpsnmedia.net/ *.googlesyndication.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com https://www.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://www.google.com *.trustpilot.com *.doubleclick.net *.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.hsforms.com *.google.co.uk *.postcodeanywhere.co.uk magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com https://www.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.google.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.hs-scripts.com *.trustpilot.com *.google-analytics.com *.pcapredict.com *.postcodeanywhere.co.uk *.referralcandy.com *.cookie-script.com *.hotjar.com *.disqus.com *.avada.io *.shopify.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com assets.braintreegateway.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.postcodeanywhere.co.uk *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com *.doubleclick.net *.postcodeanywhere.co.uk *.hscollectedforms.net *.google.co.uk *.hotjar.io https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://portal.envisagedigital.co.uk/api/website/muqg8srn8r/report-uri; report-to report-endpoint; 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; font-src 'self' *.gstatic.com; img-src 'self' *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com data: *.onetrust.com cm.everesttech.net *.googleapis.com; connect-src 'self' *.go-mpulse.net cdn-ukwest.onetrust.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com; script-src 'self'; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src 'self'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com; script-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-uri https://costa.report-uri.com/r/t/csp/reportOnly; report-to default 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ info.rowleycompany.com www.google.com www.gstatic.com app-sj02.marketo.com ct.pinterest.com insight.adsrvr.org *.adsrvr.org *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net rowleycompany.scene7.com s7d2.scene7.com app-sj02.marketo.com www.gstatic.com adservice.google.com www.facebook.com ib.adnxs.com pixel.mediaiqdigital.com secure.adnxs.com stats.sa-as.com ad.doubleclick.net *.rowleycompany.com *.clarity.ms *.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com https://rum.hlx.page rowleycompany.scene7.com s7d2.scene7.com info.rowleycompany.com app-sj02.marketo.com munchkin.marketo.net www.google.com www.gstatic.com 776-dwo-877.mktoresp.com ct.pinterest.com insight.adsrvr.org js.adsrvr.org ws.zoominfo.com acdn.adnxs.com s.pinimg.com connect.facebook.net stats.sa-as.com tag.simpli.fi i.simpli.fi script.crazyegg.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com rowleycompany.scene7.com s7d2.scene7.com app-sj02.marketo.com www.google.com www.gstatic.com use.typekit.net p.typekit.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com s7d2.scene7.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com rowleycompany.scene7.com s7d2.scene7.com s7mbrstream.scene7.com www.google.com www.gstatic.com 776-dwo-877.mktoresp.com ct.pinterest.com stats.g.doubleclick.net ib.adnxs.com script.crazyegg.com shipapi.pacejet.cc *.adsrvr.org *.google-analytics.com 'self' 'unsafe-inline'; child-src app-sj02.marketo.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.cloudfront.net dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com checkout.stripe.com assets.braintreegateway.com c.paypal.com checkout.paypal.com pay.google.com *.cardinalcommerce.com * www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com checkout.stripe.com assets.braintreegateway.com js.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.maxmind.com widget.freshworks.com static.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com/ a.klaviyo.com/ telemetrics.klaviyo.com/ get.geojs.io www.wineonline.ca widget.wickedreports.com track.wickedreports.com wineonline.referralrock.com ajax.cloudflare.com www.yotpo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com checkout.stripe.com assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com tagmanager.google.com widget.freshworks.com widget.wickedreports.com track.wickedreports.com wineonline.referralrock.com ajax.cloudflare.com www.gstatic.com www.yotpo.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.facebook.net *.mmapiws.com https://developer.adobe.com widget.freshworks.com a.klaviyo.com/ www.wineonline.ca stats.g.doubleclick.net widget.wickedreports.com track.wickedreports.com wineonline.referralrock.com ajax.cloudflare.com static.klaviyo.com www.gstatic.com www.yotpo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com 'self' data: *.fontawesome.com https://www.google.com https://www.gstatic.com *.bootstrapcdn.com *.zohocdn.com *.zohopublic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ *.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.s3.us-east-1.amazonaws.com *.zohocdn.com *.zohopublic.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com mageside.com www.facebook.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com guarantee-cdn.com *.pixriot.com *.storeimaging.com *.s3.us-east-1.amazonaws.com *.zohocdn.com *.zohopublic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com tagmanager.google.com https://www.googletagmanager.com https://www.gstatic.com 'self' data: https://code.highcharts.com *.googleapis.com *.google.com *.gstatic.com connect.facebook.net *.mlstatic.com *.mercadopago.com www.facebook.com graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com guarantee-cdn.com *.s3.us-east-1.amazonaws.com *.zohocdn.com *.zohopublic.com *.elfsight.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://www.gstatic.com 'self' data: https://fonts.googleapis.com *.fontawesome.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.bolt.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://www.google-analytics.com https://fcm.googleapis.com 'self' data: http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.mercadopago.com *.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.pixriot.com *.storeimaging.com *.s3.us-east-1.amazonaws.com *.zohocdn.com *.zohopublic.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-PdzqHoGzeXQs+/BC9ihyjW5bTCk=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src https://connect.facebook.net/ https://script.crazyegg.com/ https://static.hotjar.com/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ data: *.googleapis.com/ *.greenpay.me/ https://d1wxcpi03uiovj.cloudfront.net fonts.gstatic.com *.fontawesome.com https://fonts.gstatic.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com c.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://connect.facebook.net/ business.facebook.com https://script.crazyegg.com/ https://static.hotjar.com/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ data: *.googleapis.com/ *.greenpay.me/ *.appspot.com https://d1wxcpi03uiovj.cloudfront.net c.paypal.com *.greenpay.me centinel.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://connect.facebook.net/ business.facebook.com https://script.crazyegg.com/ https://static.hotjar.com/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ https://www.google.co.cr/ *.googleapis.com/ *.greenpay.me/ https://d1wxcpi03uiovj.cloudfront.net static.greenpay.me *.greenpay.me *.paypalobjects.com https://static.legitscript.com *.facebook.com https://maps.gstatic.com https://maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://connect.facebook.net/ business.facebook.com *.greenpaysbx.me *.kaptcha.com https://script.crazyegg.com/ https://static.hotjar.com/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ https://code.jquery.com/jquery-3.6.0.min.js https://code.jquery.com/ui/1.13.2/jquery-ui.min data: *.googleapis.com/ *.greenpay.me/ https://d1wxcpi03uiovj.cloudfront.net api.sandbox.paypal.com api.paypal.com checkoutv2.greenpay.me checkoutv2.greenpaysbx.me static.greenpay.me centinelapi.cardinalcommerce.com centinelapistag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.facebook.net https://maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://connect.facebook.net/ https://script.crazyegg.com/ https://static.hotjar.com/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ data: *.googleapis.com/ *.greenpay.me/ https://d1wxcpi03uiovj.cloudfront.net fonts.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://connect.facebook.net/ business.facebook.com *.kaptcha.com https://data-collector.greenpay.me https://script.crazyegg.com/ *.hotjar.net/ https://widgets-static.embluemail.com/ https://cdn.embluemail.com/ https://fonts.gstatic.com/ https://fonts.googleapis.com/ https://googletagmanager.com/ https://www.googletagmanager.com/ https://gtm-mpv8c69c-mze5m.uc.r.appspot.com *.doubleclick.net/ data: *.googleapis.com/ *.greenpay.me/ https://d1wxcpi03uiovj.cloudfront.net api.paypal.com api.sandbox.paypal.com checkoutv2.greenpay.me checkoutv2.greenpaysbx.me maps.googleapis.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-OIEMeh1JzheosH3+ZNyMKD5K8QQ=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://*.typekit.net https://*.gstatic.com https://*.salesfire.co.uk *.fontawesome.com https://fonts.bunny.net *.salesfire.co.uk *.klarnacdn.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com https://*.braintreegateway.com https://*.paypal.com https://*.trustpilot.com https://*.onetrust.com https://*.cookiebot.com https://*.cookiepro.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.salesfire.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://*.gstatic.com *.googleapis.com https://*.googleapis.com https://*.google.com https://*.doubleclick.net https://*.google.co.uk https://*.cloudfront.net https://*.paypal.com https://*.livechat-static.com https://*.cookiepro.com https://*.onetrust.com https://*.cookiebot.com https://*.salesfire.co.uk *.trackedlink.net www.feedoptimise.com cdn.feedoptimise.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://*.googleapis.com https://www.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.google.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.cloudfront.net https://*.google-analytics.com https://*.paypal.com https://*.trustpilot.com https://*.increasingly.co https://*.cookiepro.com https://*.salesfire.co.uk https://*.livechatinc.com https://*.affiliatefuture.com https://*.onetrust.com https://*.cookiebot.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.feedoptimise.com cdn.feedoptimise.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.googleapis.com https://*.typekit.net https://*.cloudfront.net https://*.onetrust.com https://*.cookiebot.com https://*.cookiepro.com webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net *.salesfire.co.uk *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://*.freshdesk.com wss://*.hotjar.com https://*.googleapis.com https://*.chimpstatic.com https://*.livechatinc.com https://*.trustpilot.com https://*.cookiepro.com https://*.smartmetrics.co.uk https://*.salesfire.co.uk https://*.doubleclick.net https://*.g.doubleclick.net https://*.affiliatefuture.com https://*.increasingly.co https://*.google.co.uk https://*.onetrust.com https://*.cookiebot.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.ideal-postcodes.co.uk https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.smartmetrics.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ekr.zdassets.com/ https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.addthis.com *.facebook.com *.twitter.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.visa.com cdn.doofinder.com magefan.com cm.magefan.com *.disqus.com *.addthisedge.com *.twitter.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com eadn-wc04-9508818.nxedge.io maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.visa.com *.mastercard.com cdn.doofinder.com https://cdnjs.cloudflare.com *.disqus.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://ipinfo.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.doofinder.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doofinder.com wss://*.doofinder.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://waqtee.com/; report-to report-endpoint; 1 worker-src blob:; font-src data: fonts.gstatic.com *.kxcdn.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.ccavenue.com https://seo.mageplaza.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net *.accounts.google.com *.paypalobjects.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.ccavenue.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com checkout.tabby.ai *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.facebook.com *.google.co.in www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.google.com *.gstatic.com *.fbcdn.net *.ccavenue.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net *.jivosite.com *.trustpilot.com *.accounts.google.com *.googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.googleapis.com *.google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.ccavenue.com *.avada.io assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com www.google.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.jivosite.com *.accounts.google.com *.googleapis.com *.google.com *.kxcdn.com *.gstatic.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: *.jivosite.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.doubleclick.net *.jivosite.com *.accounts.google.com *.facebook.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.ccavenue.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.jivosite.com *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.cloudflare.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' data: *.onesignal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com unpkg.com *.elfsight.com scontent-lax3-1.xx.fbcdn.net phosphor.utils.elfsightcdn.com scontent-lax3-2.xx.fbcdn.net graph.facebook.com scontent.fpnq15-1.fna.fbcdn.net *.jsdelivr.net *.fbcdn.net data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com unpkg.com *.elfsight.com *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.cloudflare.com *.onesignal.com onesignal.com assets.braintreegateway.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com unpkg.com *.elfsight.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: 'unsafe-eval' 'unsafe-inline'; object-src 'none' report-uri https://o244114.ingest.sentry.io/api/1420725/security/?sentry_key=d59dabdf03794a039923edd4ac216d88&sentry_environment=production 1 default-src 'none'; report-uri /api/csp-report; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://a-us.storyblok.com ; script-src 'self' ; script-src-elem 'self' https://www.googletagmanager.com https://www.gstatic.com; style-src 'self'; style-src-elem 'self' https://fonts.googleapis.com; connect-src 'self' https://www.google-analytics.com; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-MdgH0vLzUiO1Luy59EMlOTVpFac=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.cmecorp.com *.olark.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com data: *.hubspot.com *.hs-sites.com *.hubspot.net play.hubspotvideo.com *.hsforms.net *.hsforms.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cmecorp.com *.olark.com *.google.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.googleapis.com js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspotusercontent.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com snap.licdn.com px.ads.linkedin.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cmecorp.com *.olark.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.hsadspixel.net *.hs-analytics.net js.hscta.net *.hubspot.com static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspotusercontent.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com snap.licdn.com *.shopperapproved.com *.searchspring.net *.authorize.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.hubspotusercontent.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net cdn2.hubspot.net *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cmecorp.com *.olark.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com *.searchspring.io px.ads.linkedin.com *.authorize.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com *.hsforms.com http: https: blob: 'self' 'unsafe-inline'; default-src *.cmecorp.com *.olark.com *.google.com *.youtube.com doubleclick.net *.doubleclick.net googletagmanager.com google-analytics.com *.gstatic.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.cmecorp.com 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-+VpupjXAg244xph/sic9+MIXkfM=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://firebasestorage.googleapis.com flagpedia.net https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://maps.googleapis.com *.avada.io *.shopify.com *.gstatic.com maps.googleapis.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io adaruniforms.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ static.hotjar.com script.hotjar.com static.klaviyo.com static-tracking.klaviyo.com js-agent.newrelic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com static-forms.klaviyo.com fast.a.klaviyo.com bam.nr-data.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.co.in bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src *.vimeo.com *.texdecor.test *.texdecor.com www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com *.vimeocdn.com s.ytimg.com data *.cdninstagram.com 'self' 'unsafe-inline'; script-src *.sbc29.com *.sbc30.net *.sbc33.com *.sbc35.com www.vimeo.com cdn-scripts.signifyd.com www.youtube.com *.texdecor.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src api.sarbacane.com *.texdecor.test *.texdecor.com *.fact-finder.fr www.google-analytics.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.fontawesome.com fonts.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ *.google.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com blob: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com https://img.youtube.com https://www.magezon.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jquery.sellxed.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.avada.io *.googletagmanager.com/ *.gstatic.com/ https://bat.bing.com https://www.google-analytics.com *.stats.g.doubleclick.net/ *.google.com/ *.google.fr/ https://static.hotjar.com https://s.pinimg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com js.mollie.com https://cdnjs.cloudflare.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.bebe-cadeau.ch/ *.baby-geschenk.ch/ *.www.bebe-cadeau.ch/ *.www.baby-geschenk.ch/ https://region1.google-analytics.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.commerzbank.de; script-src 'self' *.commerzbank.de 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net extend.vimeocdn.com www.facebook.com connect.facebook.net; style-src 'self' *.commerzbank.de 'unsafe-inline' 'unsafe-eval' https://googletagmanager.com https://tagmanager.google.com; frame-src 'self' *.commerzbank.de https://www.googletagmanager.com https://*.fls.doubleclick.net player.vimeo.com; worker-src 'self' *.commerzbank.de; connect-src 'self' *.commerzbank.de https://*.googletagmanager.com https://*.google.com https://google.com https://*.google-analytics.com https://*.analytics.google.com https://ad.doubleclick.net https://*.g.doubleclick.net https://*.google.de https://*.google.bg https://pagead2.googlesyndication.com https://www.googleadservices.com www.facebook.com connect.facebook.net; font-src 'self' *.commerzbank.de data:; img-src 'self' *.commerzbank.de https: data: https://*.googletagmanager.com https://googletagmanager.com https://*.google-analytics.com https://ad.doubleclick.net https://*.g.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.bg https://pagead2.googlesyndication.com https://www.googleadservices.com https://ade.googlesyndication.com https://adservice.google.com www.facebook.com connect.facebook.net; report-uri https://tp.commerzbank.de/csp; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'strict-dynamic'; script-src-elem 'self' https://*.googletagmanager.com 'sha256-kq3lefWQbwmdOxlra65mbkrKSz6YLHhejVQSFor8vMY='; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com; font-src 'self' data:; style-src-attr 'self' 'unsafe-inline'; media-src 'self'; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; frame-src 'self'; report-uri /csp_report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com *.squarefeed.io *.squarefeed.io:8088 *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.meetanshi.com https://widget.trustpilot.com/ https://www.googletagmanager.com/ https://td.doubleclick.net/ www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.globalpay.com *.meetanshi.com https://meetanshi.com/media/logo.png https://v2.zopim.com/widget/images/gallery/badge/custom/everyday/05.png https://v2assets.zopim.io https://www.google.co.in/ https://bat.bing.com/ www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com s7.addthis.com *.meetanshi.com *.zopim.com *.clickcease.com *.zdassets.com *.google-analytics.com https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js http://cdnjs.cloudflare.com https://bat.bing.com/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com http://cdnjs.cloudflare.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/web_widget/classic/latest/fda6cd35495c75f83508d9d2e77ee33d.mp3 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://google.com/pay ekr.zdassets.com/ *.meetanshi.com *.zdassets.com wss://widget-mediator.zopim.com/ https://shop4body.zendesk.com/ www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-nXGZOWZUHEm2WbDnRiZKNyRk6Y0=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.clarity.ms ajax.googleapis.com analytics.tiktok.com bat.bing.com cdn.mouseflow.com cdn.sift.com cdn01.basis.net connect.facebook.net ct.pinterest.com d10lpsik1i8c69.cloudfront.net static.ads-twitter.com us1.clevertap-prod.com www.google-analytics.com www.googletagmanager.com www.redditstatic.com *.doubleclick.net *.snapchat.com sc-static.net ftlaunchpad.ai dx.mountain.com *.appsflyer.com a.quora.com cdnjs.cloudflare.com/ajax/libs/airbrake-js/ assets.calendly.com mc.yads.tech; style-src 'self' 'unsafe-inline' fonts.googleapis.com; img-src * data:; font-src 'self' data: fonts.gstatic.com; connect-src 'self' *.airbrake.io *.analytics.google.com *.clarity.ms *.criteo.com *.everclear.com *.google-analytics.com *.googleadservices.com *.mouseflow.com *.pndsn.com *.snapchat.com analytics-ipv6.tiktokw.us analytics.google.com analytics.tiktok.com api.leanplum.com bat.bing.com bat.bing.net capig.datah04.com pixel-config.reddit.com q.quora.com settings.luckyorange.net stats.g.doubleclick.net www.facebook.com www.google.com www.googletagmanager.com/ www.redditstatic.com ct.pinterest.com; media-src 'self' everclear.s3.us-west-2.amazonaws.com; frame-src 'self' view.vzaar.com pixel-sync.sitescout.com td.doubleclick.net www.facebook.com www.googletagmanager.com iframe.dacast.com *.snapchat.com www.youtube.com *.everclear.com; frame-ancestors 'self'; form-action 'self' https://www.facebook.com/; report-uri https://siteuri.report-uri.com/r/t/csp/reportOnly 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magento-cloudflare.jetrails.com *.google.com *.doubleclick.net *.lightwidget.com *.rolex.com *.optcentral.com *.hubspot.com *.demdex.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ytimg.com *.rolex.com *.cloudfront.net *.hsforms.com *.google-analytics.com *.google.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.google-analytics.com *.googletagmanager.com *.lightwidget.com *.hubspot.com *.hsforms.net *.hs-scripts.com *.rolex.com *.flipdocs.com *.issuu.com *.fliphtml5.com *.optcentral.com *.cloudfront.net *.hsleadflows.net *.usemessages.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com *.hsforms.com *.doubleclick.net *.avada.io player.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.conscioweb.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.hubspot.com *.googleadservices.com *.google.com *.demdex.net https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com log.pinterest.com *.iubenda.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://www.gstatic.com *.google.com *.iubenda.com assets.pinterest.com s7.addthis.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com fonts.googleapis.com *.iubenda.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.iubenda.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' trackdatabase.com; font-src 'self' data:; style-src 'self' 'unsafe-inline' trackdatabase.com vjs.zencdn.net cdn.jsdelivr.net; script-src 'self' trackdatabase.com vjs.zencdn.net cdn.jsdelivr.net 'nonce-492b3546645c10cac185e82760cf075f923b103e6e18' 1 script-src cdn.cookielaw.org 'unsafe-hashes' 'sha256-5lSQFTOMNNoGBLbrC6eUxpYeuyBQW52hLO9rR85ASEA=' https: http: 'nonce-+qUhfud7utHNgsGKmXaf9o8TaBDB7gcY3Rske/ZfF7I=' 'unsafe-eval' 'unsafe-inline';object-src 'none';frame-ancestors 'none';base-uri 'none';report-uri /api/csp-report 1 img-src https://higherlogicdownload.s3.amazonaws.com/AHRAONLINE/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AHRAONLINE/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/AHRAONLINE/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AHRAONLINE/ https://higherlogicdownload.s3.amazonaws.com/AHRAONLINE/ https://higherlogiclongterm.s3.amazonaws.com/AHRAONLINE/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/AHRAONLINE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AHRAONLINE/ 'self' https://higherlogiclongterm.s3.amazonaws.com/AHRAONLINE/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline' https://pym.nprapps.org/pym.v1.min.js 'self'; media-src https://higherlogiclongterm.s3.amazonaws.com/AHRAONLINE/ https://higherlogicdownload.s3.amazonaws.com/AHRAONLINE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AHRAONLINE/ https://higherlogicstream.s3.amazonaws.com/AHRAONLINE/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/AHRAONLINE/ https://higherlogicdownload.s3.amazonaws.com/AHRAONLINE/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/AHRAONLINE/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self' https://pym.nprapps.org/pym.v1.min.js 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://ahra2024.eventscribe.net/ 'self'; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self' https://ahra2024.eventscribe.net/ 'self'; object-src 'none'; manifest-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.azure-api.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.azure-api.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://meetanshi.com/media/logo.png *.googletagmanager.com *.google-analytics.com ssl.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.azure-api.net *.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.instagram.com *.facebook.com *.accounts.google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: script.hotjar.com *.klarna.com *.playground.kl *.klarnaevt.com *.fontawesome.com *.klarnacdn.net d30lee2gy4gtgb.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.beerhawk.co.uk *.facebook.com *.klarna.com *.playground.klarna.com *.klarnaevt.com *.snapchat.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.pinterest.com www.pinterest.co.uk static.criteo.net ct.pinterest.com insight.adsrvr.org match.adsrvr.org *.apt.io *.beerhawk.co.uk gum.criteo.com *.facebook.com wchat.eu.freshchat.com *.gstatic.com *.hotjar.com *.klarna.com *.klarnaevt.com *.playground.klarna.com *.recurly.com *.snapchat.com *.twitter.com *.eu.webpush.freshchat.com www.youtube-nocookie.com *.clearpay.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com *.paypalobjects.com newassets.hcaptcha.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net matching.ivitrack.com js-assets.perfectdraft.com cm.g.doubleclick.net ads.yahoo.com ups.analytics.yahoo.com pixel.rubiconproject.com cdn.stickyadstv.com pixel.tapad.com s.thebrighttag.com pixel.advertising.com x.bidswitch.net eb2.3lift.com dis.criteo.com sp.analytics.yahoo.com sync.outbrain.com sync-t1.taboola.com simage2.pubmatic.com visitor.omnitagjs.com sync.e-planning.net jadserve.postrelease.com exchange.mediavine.com secure.adnxs.com us-u.openx.net criteo-partners.tremorhub.com cm.mgid.com ad.yieldlab.net sync-criteo.ads.yieldmo.com s.ad.smaato.net i6.liadm.com i.liadm.com cw.addthis.com criteo-sync.teads.tv ad.as.amanad.adtdp.com r.casalemedia.com in.treasuredata.com rtb-csync.smartadserver.com trends.revcontent.com ad.360yield.com match.sharethrough.com gum.criteo.com d.turn.com c.clarity.ms public-prod-dspcookiematching.dmxleo.com partner.mediawallahscript.com id5-sync.com contextual.media.net idsync.rlcdn.com ads.stickyadstv.com crb.kargo.com ib.adnxs.com tags.bluekai.com cm.adform.net ih.adscale.de sync.aralego.com cotads.adscale.de a.twiago.com adgen.socdm.com tg.socdm.com adx.dable.io sync.ad-stir.com analytics.twitter.com alb.reddit.com e1.emxdgt.com match.adsrvr.org ads.avocet.io ads.avct.cloud *.awin1.com px.ads.linkedin.com *.beerhawk.co.uk beerbods.co.uk *.bing.com cx.atdmt.com trk.clinch.co *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.google.co.uk script.hotjar.com *.klarna.com *.klarnaevt.com *.playground.klarna.com beacon.krxd.net *.linkedin.com *.nosto.com *.cookielaw.org ct.pinterest.com *.postcodeanywhere.co.uk id.rlcdn.com *.snapchat.com *.tinifycdn.com t.co *.tvsquared.com *.zenaps.com *.afterpay.com *.clearpay.co.uk *.klarnacdn.net magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com d30lee2gy4gtgb.cloudfront.net c5.adalyser.com cdn-eu.dynamicyield.com cdn.dynamicyield.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googletagmanager.com *.facebook.net *.doubleclick.net c5.adalyser.com js-assets.perfectdraft.com s.adroll.com d.adroll.mgr.consensu.org static.ads-twitter.com *.bing.com *.cardinalcommerce.com a.clarity.ms d.clarity.ms e.clarity.ms f.clarity.ms h.clarity.ms i.clarity.ms j.clarity.ms l.clarity.ms n.clarity.ms www.clarity.ms *.cloudflare.com *.klarnacdn.net *.cloudflareinsights.com dynamic.criteo.com sslwidget.criteo.com *.criteo.net *.dwin1.com api.uk.exponea.com wchat.eu.freshchat.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.gstatic.com *.hotjar.com js.adsrvr.org *.klarna.com *.playground.klarna.com *.klarnaevt.com *.licdn.com *.lr-ingest.io *.measured.com *.nosto.com *.cookielaw.org *.paypal.com *.pcapredict.com s.pinimg.com *.postcodeanywhere.co.uk *.ratebeer.com www.redditstatic.com sc-static.net *.snapchat.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.treasuredata.com *.tvsquared.com analytics.twitter.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net x.klarnacdn.net *.klarnaservices.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com d30lee2gy4gtgb.cloudfront.net tag.aticdn.net cdn-eu.dynamicyield.com st-eu.dynamicyield.com ct.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.cloudflare.com *.cookielaw.org *.klarna.com *.klarnaevt.com *.playground.klarna.com *.postcodeanywhere.co.uk wchat.eu.freshchat.com *.fontawesome.com *.afterpay.com/ *.squarecdn.com *.klarnacdn.net assets.braintreegateway.com d30lee2gy4gtgb.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com player.vimeo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com tr.snapchat.com a.clarity.ms d.clarity.ms e.clarity.ms f.clarity.ms g.clarity.ms h.clarity.ms i.clarity.ms n.clarity.ms www.clarity.ms api.uk.exponea.com beerbods.co.uk *.bing.com *.cardinalcommerce.com *.cloudflare.com *.cookielaw.org sslwidget.criteo.com https://dpm.demdex.net *.dwin1.com *.facebook.com *.facebook.net stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.klarna.com *.klarnaevt.com *.klarnacdn.net *.playground.klarna.com *.ksearchnet.com *.lr-ingest.io *.nosto.com https://privacyportal-de.onetrust.com ct.pinterest.com *.postcodeanywhere.co.uk *.recurly.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com x.klarnacdn.net *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com hub.feefo.com d30lee2gy4gtgb.cloudfront.net rpnxgwj.pa-cd.com maps.googleapis.com pixel-config.reddit.com www.redditstatic.com async-px-eu.dynamicyield.com tr6.snapchat.com rcom-eu.dynamicyield.com st-eu.dynamicyield.com 'self' 'unsafe-inline'; child-src blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://dpm.demdex.net https://amcglobal.sc.omtrdc.net *.klarna.com *.playground.klarna.com *.klarnacdn.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; frame-ancestors https://cms-stage.mediashop.bloomreach.cloud https://cms.mediashop.bloomreach.cloud 'self'; frame-src 'self' https://*.doubleclick.net meine-einkaufswelt.prod.welocal.cloud http://www.meine-einkaufswelt.tv https://www.meine-einkaufswelt.tv https://*.paypal.com *.usercentrics.eu youtube.com www.youtube.com; object-src 'none'; base-uri 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.scarabresearch.com meine-einkaufswelt.prod.welocal.cloud http://www.meine-einkaufswelt.tv *.nosto.com *.cloudfront.net https://*.paypal.com *.usercentrics.eu https://cdn.tms.www.telsell.com https://tms.www.telsell.com www.youtube.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https: *.usercentrics.eu https://tms.www.telsell.com https://i.ytimg.com; font-src 'self' data: https:; connect-src 'self' https: https://recommender.scarabresearch.com https://webchannel-content.eservice.emarsys.net *.nosto.com https://*.paypal.com *.usercentrics.eu https://tms.www.telsell.com; media-src 'self' data: blob: https:; 1 default-src 'self' data: *.googleapis.com *.typekit.net *.responseiq.com *.gstatic.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.responseiq.com *.doubleclick.net *.clickguard.com *.amazonaws.com *.hotjar.com *.infinity-tracking.com *.hotjar.com *.responseiq.com *.fuzey.io *.trustpilot.com *.google-analytics.com *.google.com *.googleadservices.com *.googletagmanager.com; style-src 'self' data: 'unsafe-inline' *.googleapis.com *.typekit.net *.responseiq.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.googleapis.com *.responseiq.com *.aimtell.com *.fuzey.io *.aimtell.io *.infinity-tracking.net *.hotjar.com *.clickguard.com *.infinity-tracking.com *.google-analytics.com *.doubleclick.net *.googleadservices.com *.google.co.uk; font-src * 'self' *.typekit.net; frame-src 'self' *.hotjar.com *.google.com *.fuzey.io *.travel.mediaalpha.com *.kayak.com *.kayak.co.uk *.farecompare.com *.skyscanner.net; img-src 'self' data: *.amazonaws.com *.doubleclick.net *.fuzey.io *.responseiq.com *.google-analytics.com *.google.co.uk *.google.com *.gstatic.com *.googleapis.com vibe.travel *.vibe.travel; manifest-src 'self'; media-src 'self' data:; report-uri /csp-violation.php; worker-src 'self'; frame-ancestors 'self' *.mediaalpha.com airfarewatchdog.com jetcost.com *.jetcost.com jetcost.at jetcost.cl jetcost.co.id jetcost.co.in jetcost.co.kr jetcost.co.nz jetcost.co.th jetcost.co.uk jetcost.co.ve jetcost.co.za jetcost.com jetcost.com.au jetcost.com.bo jetcost.com.br jetcost.com.co jetcost.com.mx jetcost.com.my jetcost.com.pe jetcost.com.ph jetcost.com.sg jetcost.com.uy jetcost.de jetcost.dk jetcost.es jetcost.fi jetcost.fr jetcost.hk jetcost.hu jetcost.ie jetcost.it jetcost.nl jetcost.no jetcost.pl jetcost.pt jetcost.ro jetcost.ru jetcost.se tripadvisor.com *.tripadvisor.com tripadvisor.com.hk *.tripadvisor.com.hk tripadvisor.be *.tripadvisor.be tripadvisor.ca *.tripadvisor.ca *.tripadvisor.ch tripadvisor.at tripadvisor.ch tripadvisor.cl tripadvisor.cn tripadvisor.co tripadvisor.co.hu tripadvisor.co.id tripadvisor.co.il tripadvisor.co.kr tripadvisor.co.nz tripadvisor.co.uk tripadvisor.co.za tripadvisor.com.ar tripadvisor.com.au tripadvisor.com.br tripadvisor.com.eg tripadvisor.com.gr tripadvisor.com.mx tripadvisor.com.my tripadvisor.com.pe tripadvisor.com.ph tripadvisor.com.sg tripadvisor.com.tr tripadvisor.com.tw tripadvisor.com.ve tripadvisor.com.vn tripadvisor.cz tripadvisor.de tripadvisor.dk tripadvisor.es tripadvisor.fi tripadvisor.fr tripadvisor.ie tripadvisor.in tripadvisor.it tripadvisor.jp tripadvisor.pt tripadvisor.rs tripadvisor.ru tripadvisor.se tripadvisor.sk bookingbuddy.com cheapflights.co.uk cheapflights.com.au familyvacationcritic.com holidaywatchdog.com hotelscan.com jetsetter.com kayak.co.uk www.kayak.co.uk kayak.com www.kayak.com kayak.com.au kayak.com.br kayak.de kayak.es kayak.fr kayak.it https://www.kayak.com https://www.kayak.co.uk momondo.co.uk momondo.com momondo.com.au momondo.com.br momondo.de momondo.es momondo.fr momondo.it mundi.com.br onetime.com oyster.com smartertravel.com swoodoo.com swoodoo.de whattopack.com www.w3schools.com *.mauction.app; 1 base-uri 'self' ;connect-src https: * ;default-src 'self' ;font-src 'self' https: data: ;form-action 'self' https://*.mett.nl ;frame-ancestors 'self' ;frame-src https: * ;img-src https: data: blob: * ;object-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.mett.nl *.rijksoverheid.nl *.hcaptcha.com hcaptcha.com ;script-src-attr 'self' 'unsafe-inline' ;script-src-elem 'self' 'unsafe-inline' https: * ;style-src 'self' https: 'unsafe-inline' ;worker-src 'self' https: blob: ;upgrade-insecure-requests; report-uri https://www.vrijwilligerswerk.nl/api/csp/RecordReport; 1 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com unsafe-inline *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' www.dropbox.com 'self' apis.google.com assets.adobedtm.com c.go-mpulse.net connect.facebook.net googleads.g.doubleclick.net static.ads-twitter.com www.adobetag.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com www.youtube.com s.pinimg.com snap.licdn.com blob:; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com apis.google.com az416426.vo.msecnd.net connect.facebook.net snap.licdn.com static.ads-twitter.com www.google-analytics.com www.googletagmanager.com googleads.g.doubleclick.net c.go-mpulse.net www.adobetag.com www.gstatic.com www.youtube.com www.google.com s.pinimg.com ct.pinterest.com www.dropbox.com www.googleadservices.com www.scrible.com ajax.googleapis.com cdnjs.cloudflare.com googletagmanager.com script.hotjar.com static.hotjar.com; script-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn.flowplayer.com cdn.jsdelivr.net fonts.googleapis.com cdnjs.cloudflare.com www.gstatic.com www.scrible.com use.fontawesome.com; style-src-attr 'unsafe-inline'; img-src 'self' data: *.oerproject.com analytics.twitter.com px.ads.linkedin.com www.facebook.com www.google.com cm.everesttech.net t.co *.bighistoryproject.com www.google-analytics.com googleads.g.doubleclick.net www.googletagmanager.com bgc3worldhistorydev.112.2o7.net csi.gstatic.com ssl.gstatic.com www.google.co.uk www.google.com.ar www.googleadservices.com cfdc4d69b.lwcdn.com stats.g.doubleclick.net www.google.ca www.google.co.in www.google.co.jp www.google.co.kr www.google.co.th www.google.com.au www.google.com.bz www.google.com.co www.google.com.hk www.google.com.mx www.google.com.ng www.google.com.ph www.google.com.sg www.google.mn cm.g.doubleclick.net www.google.cl www.google.co.id www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bg www.google.bs www.google.bt www.google.ch www.google.ci www.google.co.cr www.google.co.il www.google.co.ke www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.tz www.google.co.ug www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.com.af www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.cu www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gt www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.my www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cv www.google.cz www.google.de www.google.es www.google.fi www.google.fr www.google.gl www.google.gm www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.lk www.google.lv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.ru www.google.rw www.google.se www.google.sk www.google.so www.google.tn www.linkedin.com fonts.gstatic.com translate.google.com ad.doubleclick.net adservice.google.com px4.ads.linkedin.com i.ytimg.com live.rezync.com yastatic.net dpm.demdex.net cdn.honey.io bat.bing.com 20537739p.rfihub.com 20537741p.rfihub.com a.rfihub.com blob: assets.clever.com www.google.as www.google.az www.google.bj www.google.by www.google.cg www.google.co.ao www.google.co.ck www.google.co.zw www.google.com.cy www.google.com.fj www.google.com.kw www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.ni www.google.com.sl www.google.com.uy www.google.dj www.google.dk www.google.dz www.google.ee www.google.ga www.google.ge www.google.hn www.google.la www.google.lt www.google.lu www.google.md www.google.me www.google.mk www.google.mu www.google.mw www.google.ps www.google.rs www.google.si www.google.sc accounts.google.com connect.facebook.net google.com l.facebook.com www.google.ad www.google.al www.google.bf www.google.cd www.google.cm www.google.co.mz www.google.com.bn www.google.com.gi www.google.dm www.google.gg www.google.je www.google.ml www.google.mv www.google.ne www.google.sn www.google.td www.google.tl www.google.tt www.youtube.com; font-src 'self' fonts.gstatic.com assets.clever.com use.fontawesome.com; connect-src 'self' dc.services.visualstudio.com dpm.demdex.net px.ads.linkedin.com *.oerproject.com www.google-analytics.com c.go-mpulse.net cfdc4d69b.lwcdn.com ihi.flowplayer.com ljsp.lwcdn.com ptm.flowplayer.com www.facebook.com adservice.google.com ct.pinterest.com apis.google.com google.com pmi.flowplayer.com region1.google-analytics.com www.google.com analytics.google.com api.facebook.com region1.analytics.google.com stats.g.doubleclick.net translate-pa.googleapis.com translate.googleapis.com www.googleadservices.com www.googletagmanager.com www.scrible.com ad.doubleclick.net api.fbanalytics.org cdn.flowplayer.com fonts.googleapis.com fonts.gstatic.com analytics.twitter.com edge.microsoft.com oerproject.report-uri.com t.co www.google.ca; frame-src 'self' bgc3.demdex.net www.google.com ct.pinterest.com td.doubleclick.net accounts.google.com drive.google.com *.oerproject.com www.facebook.com www.googletagmanager.com www.youtube.com; frame-ancestors * 'self'; form-action 'self'; worker-src 'self' blob:; report-uri https://oerproject.report-uri.com/r/d/csp/wizard 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-NzJmYmI0NTktOTliZC00ZmY2LWEwZmUtMWMxNTI0ZTlkMTc1' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.facebook.com *.livechatinc.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.facebook.com *.doubleclick.net *.kaptcha.com *.livechatinc.com *.rfihub.com *.adnxs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.cloudflare.com *.facebook.com *.google.com *.google.com.mx *.googleusercontent.com *.icons8.com *.marketo.net *.amazonaws.com *.magecomp.com *.bizibly.com *.showmethepartsdb2.com *.showmethepartsdb.com c5b6534ed7.nxcli.io *.nr-data.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.fontawesome.com js-agent.newrelic.com *.facebook.net *.doubleclick.net *.bizible.com *.bing.com *.marketo.net *.livechatinc.com *.weglot.com *.rezync.com *.licdn.com *.stackadapt.com *.hotjar.com *.rfihub.net *.boomtrain.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com *.stackadapt.com *.google.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.cloudflare.com *.doubleclick.net *.google-analytics.com *.facebook.com *.gstatic.com *.boomtrain.com *.stackadapt.com *.livechatinc.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://ajax.cloudflare.com/ https://www.gstatic.com/ https://cdnjs.cloudflare.com/ https://www.google.com/ https://snap.licdn.com/ https://cse.google.com/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://unpkg.com/ https://marketing.plsa.co.uk/ 'unsafe-eval' 'unsafe-inline'; style-src 'self' https://www.google.com/ https://unpkg.com/ https://cdnjs.cloudflare.com/ https://use.fontawesome.com/ https://fonts.googleapis.com/ 'unsafe-inline'; img-src * data:; frame-src 'self' https://events.plsa.co.uk/ https://plsa.smugmug.com/ https://player.vimeo.com/ https://www.youtube.com/; font-src 'self' data: https://cdnjs.cloudflare.com/ https://fonts.gstatic.com/ https://use.fontawesome.com/; connect-src 'self' https://www.google-analytics.com/ https://region1.google-analytics.com/ https://cdn.linkedin.oribi.io/ https://stats.g.doubleclick.net/ 1 font-src *.googleapis.com *.gstatic.com data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.typekit.net *.klevu.com *.ksearchnet.com *.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com https://*.doubleclick.net https://*.hotjar.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.twitter.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com *.stripe.com *.stripe.network https://*.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://*.doubleclick.net https://*.google.co.uk *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://*.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://www.google.com *.sagepay.com *.opayo.eu.elavon.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.jivosite.com *.crazyegg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com player.vimeo.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.xtento.com cdn.xtento.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com https://*.googleapis.com *.sagepay.com *.opayo.eu.elavon.com *.typekit.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.jivosite.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.jivosite.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.jivosite.com wss://vi-ya-5.jivosite.com *.crazyegg.com *.google.co.uk *.google-analytics.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-MCMfrrGkQv-xyg12u9aUgA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://static.cloudflareinsights.com/beacon.min.js cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://platform-api.sharethis.com https://unpkg.com https://ws.sharethis.com https://www.google.com mdbootstrap.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://static.cloudflareinsights.com/beacon.min.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/NZrMWHVy58-S9gVvad9HVGxk/recaptcha__en.js cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://platform-api.sharethis.com https://unpkg.com https://ws.sharethis.com https://www.google.com mdbootstrap.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://stackpath.bootstrapcdn.com https://unpkg.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.google-analytics.com https://*.googletagmanager.com https://*.calendly.com https://*.bugsnag.com tag.clearbitscripts.com connect.facebook.net https://*.segment.com https://*.segment.io s3-us-west-2.amazonaws.com *.hs-scripts.com app.linkscout.com *.hsadspixel.net *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net snap.licdn.com www.redditstatic.com www.clickcease.com *.clarity.ms scripts.clarity.ms scout-cdn.salesloft.com static.ads-twitter.com tracking-api.g2.com *.posthog.com vercel.live *.intercom.io *.intercomcdn.com *.doubleclick.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.google-analytics.com https://*.googletagmanager.com https://*.calendly.com https://*.bugsnag.com tag.clearbitscripts.com connect.facebook.net https://*.segment.com https://*.segment.io s3-us-west-2.amazonaws.com *.hs-scripts.com app.linkscout.com *.hsadspixel.net *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net snap.licdn.com www.redditstatic.com www.clickcease.com *.clarity.ms scripts.clarity.ms scout-cdn.salesloft.com static.ads-twitter.com tracking-api.g2.com *.posthog.com vercel.live *.intercom.io *.intercomcdn.com *.doubleclick.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.calendly.com; font-src 'self' https://fonts.gstatic.com *.intercomcdn.com; img-src 'self' data: https:; connect-src 'self' https://*.google-analytics.com https://*.doubleclick.net https://*.bugsnag.com https://sessions.bugsnag.com app.linkscout.com www.google.com *.hscollectedforms.net *.hs-forms.com px.ads.linkedin.com pixel-config.reddit.com www.redditstatic.com *.posthog.com *.segment.com *.segment.io tracking-api.g2.com k.clarity.ms *.intercom.io wss://*.intercom.io *.hubapi.com raw.githubusercontent.com pro.ip-api.com *.facebook.com *.clarity.ms; frame-src 'self' www.googletagmanager.com vercel.live *.intercom.io *.hs-forms.com *.apideck.com *.doubleclick.net; frame-ancestors 'none'; report-uri /api/csp-report; report-to csp-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com *.avada.io *.shopify.com *.hsforms.net *.hsforms.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com www.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://www.mollie.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com polyfill.io *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com s7.addthis.com js.mollie.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klarnacdn.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com ekr.zdassets.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.yotpo.com *.googleapis.com *.fontawesome.com 'self' data: *.cloudflare.com fonts.googleapis.com 'unsafe-inline' data: *.clarity.ms static.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.yotpo.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.mdoq.io 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.yotpo.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * widget.trustpilot.com lpcdn.lpsnmedia.net *.paypalobjects.com www.facebook.com *.clarity.ms 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.cloudflare.com *.mdoq.io *.ibottles.co.uk *.google.com *.google.co.uk www.worldofpower.co.uk media.worldofpower.co.uk media.worldofbbqs.co.uk media.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk bat.bing.com *.clarity.ms c.bing.com media2.giphy.com www.facebook.com image.providesupport.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.cloudflare.com *.twitter.com *.fontawesome.com *.liveperson.net *.trustpilot.com *.lpsnmedia.net bat.bing.com world11215.pcapredict.com www.googlecommerce.com connect.facebook.net image.providesupport.com *.clarity.ms static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.yotpo.com *.googleapis.com *.fontawesome.com assets.braintreegateway.com *.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.clarity.ms static.worldofpower.co.uk static.worldofbbqs.co.uk static.sipuk.co.uk static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.yotpo.com *.ideal-postcodes.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.cloudflare.com stats.g.doubleclick.net *.clarity.ms www.facebook.com static.sipuk.co.uk static.worldofpower.co.uk static.worldofbbqs.co.uk static-forms.klaviyo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' image.spreadshirtmedia.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.ca ; img-src 'self' data: https: image.spreadshirtmedia.net image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.ca *.spreadshirt.ca ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.ca ; font-src 'self' https: data: *.spreadshirt.ca ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.ca ; object-src 'none' ; media-src image.spreadshirtmedia.com ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.ca ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-recaptcha/_/js/k=boq-recaptcha.RecaptchaChallengePageUi.en_US.zHBacLSNGVs.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /recaptcha/challengepage/_/RecaptchaChallengePageUi/cspreport/fine-allowlist 1 script-src *.adsmurai.com *.analyticslab.dk *.ase.dk *.bing.com *.clarity.ms *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.doubleclick.net *.eu1.exponea.com *.google.com *.google.dk *.googleadservices.com *.googlesyndication.com *.gstatic.com gstatic.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.linkedin.com *.penni-connect.io widget.penni-connect.io *.retargeted.co *.strossle.com *.supwizapp.com *.tiktok.com *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com ajax.aspnetcdn.com blob: *.ingest.sentry.io bonfire.spklw.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com data: *.sleeknote.com fast.fonts.net html5-player.libsyn.com snap.licdn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com unpkg.com 'unsafe-eval' 'unsafe-inline' www.aservice.cloud www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;script-src-elem *.adsmurai.com *.analyticslab.dk *.ase.dk *.bing.com *.clarity.ms *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.doubleclick.net *.eu1.exponea.com *.google.com *.google.dk *.googleadservices.com *.googlesyndication.com *.gstatic.com gstatic.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.linkedin.com *.penni-connect.io widget.penni-connect.io *.reddit.com *.redditstatic.com *.retargeted.co *.strossle.com *.supwizapp.com *.tiktok.com *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com ajax.aspnetcdn.com analytics.ahrefs.com blob: *.ingest.sentry.io bonfire.spklw.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com data: *.sleeknote.com fast.fonts.net html5-player.libsyn.com snap.licdn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com unpkg.com 'unsafe-inline' www.aservice.cloud www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;default-src *.analyticslab.dk *.ase.dk *.bing.com *.builder.io *.clarity.ms *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.eu1.exponea.com *.google.com *.gstatic.com gstatic.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.linkedin.com *.penni-connect.io widget.penni-connect.io *.retargeted.co *.stape.io *.strossle.com *.tiktok.com *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com ajax.aspnetcdn.com api.dataforsyningen.dk blob: *.ingest.sentry.io blob: ase.dk bonfire.spklw.com cdn.jsdelivr.net cdnjs.cloudflare.com data: data: *.sleeknote.com fast.fonts.net fonts.googleapis.com fonts.gstatic.com fw.ase.dk:8090 html5-player.libsyn.com metrics.ase.dk snap.licdn.com unpkg.com www.aservice.cloud www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;style-src-elem *.analyticslab.dk *.ase.dk *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.eu1.exponea.com *.gstatic.com gstatic.com *.libsyn.com *.penni-connect.io widget.penni-connect.io *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com ajax.aspnetcdn.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com fast.fonts.net fonts.googleapis.com fonts.gstatic.com html5-player.libsyn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com 'unsafe-eval' 'unsafe-inline';style-src *.analyticslab.dk *.ase.dk *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.eu1.exponea.com *.gstatic.com gstatic.com *.libsyn.com *.penni-connect.io widget.penni-connect.io *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com ajax.aspnetcdn.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com fast.fonts.net fonts.googleapis.com fonts.gstatic.com html5-player.libsyn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com 'unsafe-eval' 'unsafe-inline';connect-src *.analyticslab.dk *.ase.dk *.bing.com *.clarity.ms *.cludo.com *.cookieinformation.com *.digitaladvisor.dk *.doubleclick.net *.eu1.exponea.com *.google.com *.google.dk *.googleadservices.com *.googlesyndication.com *.gstatic.com gstatic.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.linkedin.com *.penni-connect.io widget.penni-connect.io *.reddit.com *.redditstatic.com *.retargeted.co *.stape.io *.strossle.com *.supwizapp.com *.tiktok.com *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com ajax.aspnetcdn.com analytics.ahrefs.com api.dataforsyningen.dk api.ipify.org blob: *.ingest.sentry.io bonfire.spklw.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com data: data: *.sleeknote.com fast.fonts.net fonts.googleapis.com fonts.gstatic.com fw.ase.dk:8090 metrics.ase.dk secure.smartresponse-media.com snap.licdn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com unpkg.com www.aservice.cloud www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;media-src *.analyticslab.dk *.ase.dk *.builder.io *.cookieinformation.com *.doubleclick.net *.eu1.exponea.com *.google.com *.penni-connect.io widget.penni-connect.io *.tryg.com *.tryg.dk cdnjs.cloudflare.com data:;frame-ancestors *.ase.dk *.eu1.exponea.com ase.crm4.dynamics.com;worker-src *.ase.dk *.cookieinformation.com blob: *.ingest.sentry.io blob: ase.dk;img-src *.ase.dk *.bing.com *.builder.io *.clarity.ms *.cludo.com *.cookieinformation.com *.doubleclick.net *.eu1.exponea.com *.google.com *.google.dk *.googleadservices.com *.googlesyndication.com *.gstatic.com gstatic.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.linkedin.com *.penni-connect.io widget.penni-connect.io *.reddit.com *.redditstatic.com *.retargeted.co *.strossle.com *.tiktok.com *.trustpilot.com *.tryg.com *.tryg.dk *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com blob: *.ingest.sentry.io bonfire.spklw.com cdn.contentful.com cdn.jsdelivr.net cdnjs.cloudflare.com data: data: *.sleeknote.com fast.fonts.net fonts.googleapis.com fonts.gstatic.com html5-player.libsyn.com secure.smartresponse-media.com snap.licdn.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com www.aservice.cloud www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;frame-src *.ase.dk *.cookieinformation.com *.digitaladvisor.dk *.doubleclick.net *.eu1.exponea.com *.google.com *.google.dk *.googleadservices.com *.googlesyndication.com *.leadfamly.com ase.campaign.playable.com *.libsyn.com *.penni-connect.io widget.penni-connect.io *.trustpilot.com *.vimeo.com vimeo.com *.vimeocdn.com *.weply.chat *.youtube.com data: *.sleeknote.com fw.ase.dk:8090 html5-player.libsyn.com snap.licdn.com www.facebook.com connect.facebook.net www.googletagmanager.com *.google-analytics.com;font-src *.ase.dk *.eu1.exponea.com *.tryg.com *.tryg.dk blob: ase.dk cdnjs.cloudflare.com fonts.googleapis.com fonts.gstatic.com;script-src-attr *.supwizapp.com supchat.ase.supwizapp.com supsearch.ase.supwizapp.com;style-src-attr *.trustpilot.com 'unsafe-inline';base-uri secure.smartresponse-media.com;object-src secure.smartresponse-media.com;form-action www.facebook.com connect.facebook.net 1 font-src fonts.gstatic.com use.typekit.net *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://stats.g.doubleclick.net https://sync.aralego.com https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ https://consent.trustarc.com/ *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://sync.aralego.com https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://www.google.com https://analytics.google.com/ https://stats.g.doubleclick.net https://www.googletagmanager.com https://td.doubleclick.net/ https://fonts.gstatic.com https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ https://www.facebook.com/ *.facebook.net *.meetanshi.com meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://sync.aralego.com https://hpi.izysync.com/media/ https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://www.google.com https://analytics.google.com/ https://stats.g.doubleclick.net https://www.googletagmanager.com https://td.doubleclick.net/ https://fonts.gstatic.com https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ https://consent.trustarc.com/ https://fast.wistia.com/ https://embed-ssl.wistia.com/ https://abbott-tms.tkelog.com *.tkelog.com https://www.facebook.com/ *.facebook.net www.google.com.vn *.meetanshi.com meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net * searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com s7.addthis.com *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://sync.aralego.com https://za.zdn.vn/ https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://www.google.com https://analytics.google.com/ https://stats.g.doubleclick.net https://www.googletagmanager.com https://td.doubleclick.net/ https://fonts.gstatic.com https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ https://static.accesstrade.vn/ www.google.com https://www.facebook.com/ *.facebook.net cdn.jsdelivr.net *.meetanshi.com meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://stats.g.doubleclick.net https://sync.aralego.com https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://www.googletagmanager.com https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ fonts.gstatic.com cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io p13n.adobe.io p13n-mr.adobe.io * searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://www.sandbox.paypal.com https://www.paypal.com ekr.zdassets.com/ *.abbottvietnam.com.vn https://pediasure.vn *.newrelic.com *.nr-data.net https://js-agent.newrelic.com/ https://connect.facebook.net/ https://page.widget.zalo.me/ https://analytics.pangle-ads.com https://measurement-api.criteo.com https://rt.udmserve.net https://public-prod-dspcookiematching.dmxleo.com https://mixer.mobon.net https://sync.teads.tv https://sync.cootlogix.com https://sync.cenarius.orangeclickmedia.com https://dsum-sec.casalemedia.com https://sync.aralego.com https://za.zalo.me/ https://delivery-cloud.cdp.asia/interaction/ https://tags.creativecdn.com/ https://script.crazyegg.com/ https://dynamic.criteo.com/ https://analytics.tiktok.com/ https://sslwidget.criteo.com/ https://asia.creativecdn.com/ https://www.google.com https://analytics.google.com/ https://stats.g.doubleclick.net https://www.googletagmanager.com https://td.doubleclick.net/ https://fonts.gstatic.com https://pagestates-tracking.crazyegg.com/ https://assets-tracking.crazyegg.com/ https://csync.loopme.me/ https://cm.mgid.com/ https://x.bidswitch.net/ https://ib.adnxs.com/ https://contextual.media.net/ https://pixel.rubiconproject.com/ https://rtb-csync.smartadserver.com/ https://sync-t1.taboola.com/ https://criteo-sync.teads.tv/ https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://adgen.socdm.com/ https://tg.socdm.com/ https://gum.criteo.com/ https://r.casalemedia.com/ https://adx.dable.io/ https://cs.adingo.jp/ https://ads.stickyadstv.com/ https://ad.360yield.com/ https://idsync.rlcdn.com/ https://exchange.mediavine.com/ https://c.bing.com/ https://sync.outbrain.com/ https://simage2.pubmatic.com/ https://s.ad.smaato.net/ https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com/ https://dis.criteo.com/ https://hb.yahoo.net/ http://sync.1rx.io/ https://sync.targeting.unrulymedia.com/ https://match.sharethrough.com/ https://s-cs.rmp.rakuten.com/ https://usersync.gumgum.com/ https://t.adx.opera.com/ https://ad.tpmn.co.kr/ https://bh.contextweb.com/ https://sin.creativecdn.com/ https://cdnjs.cloudflare.com/ https://online-gateway.ghn.vn/ https://tagmanager.google.com/ https://static.accesstrade.vn/ https://consent.trustarc.com/ https://fast.wistia.com/ https://embed-ssl.wistia.com/ https://abbott-tms.tkelog.com *.tkelog.com https://www.facebook.com/ *.facebook.net *.meetanshi.com meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.newrelic.com *.herokuapp.com *.doubleclick.net/ *.googleapis.com b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://sumatec.co *.google.com.ar *.mercadopago.com *.facebook.com *.newrelic.com *.clarity.ms *.bing.com *.googleapis.com b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.herokuapp.com *.clarity.ms b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.herokuapp.com *.newrelic.com b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google.com.ar *.doubleclick.com *.doubleclick.net *.clarity.ms b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src b2b.mcstaging.sumatec.co mcstaging.ferricentro.com b2b.mcstaging.ferricentro.com mcstaging.werkindustrial.com sumatec.co ferricentro.com ferrindustria.ferricentro.com werkindustrial.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' tps.trovaprezzi.it sibautomation.com upstream.heidipay.com www.paypal.com maps.googleapis.com ajax.googleapis.com dme0ih8comzn4.cloudfront.net googleads.g.doubleclick.net connect.facebook.net consent.cookiebot.com consentcdn.cookiebot.com www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com; style-src 'self' 'unsafe-inline' p.typekit.net stackpath.bootstrapcdn.com use.typekit.net ka-p.fontawesome.com kit.fontawesome.com fonts.googleapis.com ; object-src 'self'; base-uri 'self'; connect-src 'self' www.paypal.com maps.googleapis.com googleads.g.doubleclick.net consentcdn.cookiebot.com www.google.com; font-src 'self' upstream.heidipay.com stackpath.bootstrapcdn.com use.typekit.net ka-p.fontawesome.com kit.fontawesome.com fonts.gstatic.com data: ; frame-src 'self' www.paypal.com api.prestashop.com consentcdn.cookiebot.com www.google.com; img-src 'self' imgsct.cookiebot.com www.paypalobjects.com t.paypal.com statici.scaramuzzamodo.it profile.prestashop.com data: blob: ; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 font-src *.fontawesome.com *.revolut.com *.google.com google.com *.cdn-apple.com cdn.polyfill.io pay.google.com *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io google.com pay.google.com *.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.revolut.com *.google.com *.cdn-apple.com google.com cdn.polyfill.io pay.google.com *.gstatic.com *.taggrs.io www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.revolut.com *.google.com *.cdn-apple.com cdn.polyfill.io google.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.taggrs.io www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.revolut.com *.cdn-apple.com cdn.polyfill.io pay.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'none'; default-src 'none'; connect-src 'self' https://*.akamaihd.net https://*.akstat.io https://cdn.cookielaw.org https://c.go-mpulse.net https://*.onetrust.com; font-src 'self' data:; form-action 'none'; frame-ancestors 'self'; frame-src 'none'; img-src 'self' data: https://*.iship.com https://cdn.cookielaw.org https://*.akstat.io; manifest-src 'none'; media-src 'none'; object-src 'none'; script-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://s.go-mpulse.net; style-src 'self' 'unsafe-inline'; worker-src 'none'; report-uri /pss018000/tx/txcspreport.aspx?reporter=CSPRO 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de scontent.cdninstagram.com *.kxcdn.com amcglobal.sc.omtrdc.net *.twitter.com *.googleapis.com google.com *.gstatic.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.googleapis.com google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net s7.addthis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com google.com *.kxcdn.com *.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com dpm.demdex.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net ekr.zdassets.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://analytics.mykrone.green https://consent.cookiebot.com https://consentcdn.cookiebot.com https://maps.googleapis.com; frame-src 'self' *.youtube.com *.mykrone.green *.krone.de *.dev-datineo.de *.agroparts.com *.paypal.com *.crefopay.de *.cookiebot.com *.krone-uk.com *.krone.fr *.krone-nederland.nl *.krone-austria.at *.empolisservices.com *.k8s.internetx.io mailto: tel:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' *.mykrone.green landmaschinen.krone.de www.krone-agriculture.com data: *.openstreetmap.org https://maps.gstatic.com https://maps.googleapis.com; https://imgsct.cookiebot.com; connect-src 'self' https://analytics.mykrone.green/ https://consentcdn.cookiebot.com/ https://maps.googleapis.com; font-src 'self' https://fonts.gstatic.com; report-uri https://mykrone.green/control/cspReport; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca api.demo.convergepay.com api.convergepay.com gstatic.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com b.stats.paypal.com dub.stats.paypal.com paypal.com www.sandbox.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://ws1.postescanada-canadapost.ca https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.ampproject.org raw.githubusercontent.com https://maps.googleapis.com s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com api.demo.convergepay.com api.convergepay.com gstatic.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com cdn.ampproject.org https://maps.googleapis.com https://player.vimeo.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com canadapost.ca ct.soa-gw.canadapost.ca soa-gw.canadapost.ca api.demo.convergepay.com api.convergepay.com gstatic.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: ws: trysen.kupibilet.ru top-fwz1.mail.ru personalization-web-stable.mindbox.ru web-static.mindbox.ru https://privacy-cs.mail.ru api.mindbox.ru google.nl yastatic.net apis.google.com mc.yandex.ru *.tildacdn.com www.google.com *.analytics.google.com analytics.google.com adservice.google.com td.doubleclick.net cdnjs.cloudflare.com static.aviasales.com avsplow.com *.avsplow.com vsplow.com tp.media *.travelpayouts.com travelpayouts.com vc.hotjar.io *.kupi.com uploads.intercomcdn.com capture.trackjs.com www.facebook.com connect.facebook.net appleid.cdn-apple.com mc.yandex.com translate.google.com script.hotjar.com sdk.inappstory.com *.hotjar.com vk.com widget.intercom.io js.intercomcdn.com api-iam.intercom.io stats.g.doubleclick.net googleads.g.doubleclick.net www.googleadservices.com accounts.google.com fonts.googleapis.com *.google-analytics.com *.googleoptimize.com *.googletagmanager.com nexus-websocket-a.intercom.io *.clarity.ms www.kupi.com websdk.appsflyer.com banner.appsflyer.com ; base-uri 'self'; object-src 'none'; font-src 'self' cdn.appsflyer.com *.tildacdn.com https://fonts.gstatic.com www.travelpayouts.com fonts.intercomcdn.com data:; img-src 'self' data: *.kupi.com www.kupi.com landings-api-v2-img.kupibilet.ru landings-api-v2.kupibilet.ru top-fwz1.mail.ru www.google.ru mc.yandex.ru mc.yandex.com www.google.nl www.google.com facebook.com www.facebook.com *.travelpayouts.com downloads.intercomcdn.com static.intercomassets.com www.google-analytics.com www.googletagmanager.com vk.com login.vk.com usage.trackjs.com *.tile.openstreetmap.org js.intercomcdn.com; manifest-src 'self'; media-src 'self' js.intercomcdn.com; frame-src * 1 default-src 'self' https:; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https: data:; connect-src 'self' https: wss:; report-uri /csp-report-endpoint 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com youtube.com vimeo.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.creditguard.co.il vimeo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com vimeo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.creditguard.co.il *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.fontawesome.com youtube.com vimeo.com *.addtoany.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com youtube.com https://get.geojs.io *.avada.io http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src https://static.cloudflareinsights.com/beacon.min.js https://googleads.g.doubleclick.net/ https://portal.allyable.com/aweb/ 'unsafe-inline' 'report-sample' 'self' https://amplify.outbrain.com/cp/obtp.js https://cdn.taboola.com/libtrc/unip/1413959/tfa.js https://connect.facebook.net/en_US/fbevents.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/402620498/ https://platform.twitter.com/widgets.js https://portal.allyable.com/aweb https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.allyable.com/assets/jquery-2.2.4.min.js https://static.srcspot.com/libs/kerianne.js https://www.google-analytics.com/analytics.js https://www.googleadservices.com/pagead/conversion_async.js https://www.googletagmanager.com/gtm.js; style-src 'unsafe-inline' 'report-sample' 'self' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://cloudflareinsights.com/cdn-cgi/rum https://marketing.onezerobank.com/api/v1/marketing/register https://portal.allyable.com https://trc.taboola.com https://www.comeet.co https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://portal.allyable.com/ https://platform.twitter.com https://portal.allyable.com; img-src 'self' https://portal.allyable.com https://px.ads.linkedin.com https://tr.outbrain.com https://www.google-analytics.com https://www.google.co.il https://www.google.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 default-src * 'unsafe-inline' 'unsafe-eval'; style-src 'unsafe-inline'; script-src 'none' 'report-sample'; connect-src 'none'; form-action 'none'; frame-src 'none'; worker-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://csp.threatview.app/report; 1 default-src https: blob: 'unsafe-inline' 'unsafe-eval'; img-src https: data:; font-src 'self' data: https: 'unsafe-inline'; connect-src https: wss: 'unsafe-inline'; report-uri https://hi.report-uri.com/r/d/csp/reportOnly 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com self *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com cdn.bioz.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com self app.hubspot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com cdn.bioz.com cloud.ccm19.de track.hubspot.com www.facebook.com forms.hsforms.com perf-na1.hsforms.com www.google.de magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com self cloud.ccm19.de connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsadspixel.net js.hscollectedforms.net js.hsleadflows.net js.hubspot.com js.usemessages.com cdn.bioz.com *.disqus.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com self cdn.bioz.com cloud.ccm19.de https://cdn.jsdelivr.net assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com self www.bioz.com cloud.ccm19.de api.hubsport.com api.hubapi.com api.hubspot.com forms.hscollectedforms.net cta-service-cms2.hubspot.com forms.hubspot.com region1.analytics.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://16272177-114c-465f-a784-93be210f14ff.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: cdnjs.cloudflare.com storage.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com app.storyblok.com *.aqualisa.co.uk *.mldemo.co.uk *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.sharethis.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com *.digitalbridgehq.com *.fixtuur.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://images.unsplash.com *.trackedlink.net tools.luckyorange.com placehold.co cdn.storepoint.co icons.storepoint-icons.com storage.googleapis.com *.flippingbook.com *.storyblok.com *.cookiefirst.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.sharethis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ jquery.sellxed.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com player.vimeo.com tools.luckyorange.com cdn.storepoint.co unpkg.com *.flippingbook.com d33i2vgywgme2s.cloudfront.net edge.marker.io consent.cookiefirst.com *.digitalbridgehq.com *.fixtuur.io *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com tools.luckyorange.com api.mapbox.com cdn.storepoint.co cdnjs.cloudflare.com *.flippingbook.com *.cookiefirst.com *.storyblok.com assets.braintreegateway.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.storyblok.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.sharethis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk settings.luckyorange.com tools.luckyorange.com api-preview.luckyorange.com wss://realtime.luckyorange.com wss://in.visitors.live in.visitors.live stats-1.storepoint.co api.storepoint.co api.mapbox.com events.mapbox.com pubsub.googleapis.com *.flippingbook.com api.marker.io amazonaws.com *.cookiefirst.com *.digitalbridgehq.com *.fixtuur.io *.fixtuur.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.digitalbridgehq.com *.fixtuur.io 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net; script-src 'nonce-2deee5547cff4f52ab6a9862f09f9514' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net; style-src 'self' 'nonce-2deee5547cff4f52ab6a9862f09f9514' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.kingofmeat.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://use.typekit.net https://d3g1zxe14zhnnt.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=134-6525726-5368219:rid=5AE24B4D69324D339600:sn=www.kingofmeat.com 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-XfO9XehDhM9I16aeTtTg1J8u/Sc=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.yotpo.com *.googleapis.com primeloops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com primeloops.com 'self' 'unsafe-inline'; frame-ancestors primeloops.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.yotpo.com primeloops.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com primeloops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com primeloops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com assets.braintreegateway.com *.yotpo.com *.googleapis.com primeloops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com primeloops.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.yotpo.com primeloops.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com primeloops.com http: https: blob: 'self' 'unsafe-inline'; default-src primeloops.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-ivWmuRgepYOdubxxxNbOynIv9NQ=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src *.googleapis.com *.gstatic.com *.klarnacdn.net *.fontawesome.com *.narvar.com *.narvar.qa data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.narvar.com *.narvar.qa www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com polyfill.io *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net *.klarnaservices.com landofcoder.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com landofcoder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub774fbd4bd44873e5007931530f7abcf6&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aui-switch%2Cenv%3Aprod;report-to https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub774fbd4bd44873e5007931530f7abcf6&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aui-switch%2Cenv%3Aprod;default-src 'self';connect-src 'self' *.ovoenergyau-uat.com *.ovoenergy.com.au *.facebook.com *.logs.datadoghq.com *.zendesk.com *.zdassets.com *.sleeknote.com *.hotjar.com *.hotjar.io *.browser-intake-datadoghq.com *.split.io ovoenergyau-uat.zendesk.com/ *.zopim.com fonts.googleapis.com www.google-analytics.com translate.googleapis.com *.google.com.au *.google.com *.google.co.in *.doubleclick.net;img-src 'self' data: blob: *.facebook.com *.sleeknote.com *.zopim.io static.zdassets.com script.hotjar.com img.nicereply.com *.google-analytics.com *.google.com *.google.com.au googleads.g.doubleclick.net www.googletagmanager.com www.google.co.in *.doubleclick.net;script-src 'self' *.facebook.net *.sleeknote.com *.zdassets.com *.hotjar.com *.ovoenergyau.zendesk.com *.zopim.com *.elfsight.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.google.com;script-src-elem 'self' 'unsafe-inline' *.facebook.net *.zdassets.com *.sleeknote.com *.hotjar.com *.elfsight.com *.googletagmanager.com *.google-analytics.com *.google.com *.googleadservices.com;media-src 'self' *.zdassets.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;font-src 'self' data: fonts.gstatic.com *.googleapis.com;object-src 'none';frame-src www.facebook.com *.doubleclick.net www.googletagmanager.com vars.hotjar.com www.zenaps.com; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=65359943-864d-4a49-931d-77286745c4b4; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.hotjar.com *.zopim.com *.fontawesome.com *.cloudflare.com maxcdn.bootstrapcdn.com 'self' data: www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.google.com cdn.dnky.co *.hotjar.com *.google.com *.facebook.com *.trustpilot.com *.criteo.com *.weltpixel.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com *.addthis.com *.googleapis.com *.cookieyes.com *.addtoany.com *.resengo.com *.storescan.eu *.doubleclick.net *.joyfotografie.nl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.linkedin.com *.googletagmanager.com gallery.mailchimp.com amcglobal.sc.omtrdc.net cm.everesttech.net *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' data: *.onesignal.com onesignal.com *.hsforms.net *.hsforms.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com *.cdninstagram.com *.cookieyes.com cdn-cookieyes.com *.google-analytics.com *.google.de data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.paypal.com *.google.com *.googletagmanager.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com onesignal.com https://www.googletagmanager.com tagmanager.google.com unpkg.com s7.addthis.com *.avada.io *.hsforms.net *.hsforms.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com *.marker.io *.addthis.com *.cookieyes.com cdn-cookieyes.com *.addtoany.com *.resengo.com *.cloudflare.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net https://static.klaviyo.com *.cloudflare.com *.onesignal.com onesignal.com tagmanager.google.com maxcdn.bootstrapcdn.com *.gstatic.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com *.klaviyo.com *.cookieyes.com 'self' 'unsafe-inline'; object-src www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; media-src *.zopim.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; manifest-src www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.paypal.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com dpm.demdex.net *.feedbackcompany.com amcglobal.sc.omtrdc.net *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.onesignal.com onesignal.com *.facebook.net ekr.zdassets.com/ https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com *.addthis.com ws.hotjar.com *.marker.io *.google.com *.stape.org *.instagram.com *.cookieyes.com cdn-cookieyes.com *.google.nl *.googlesyndication.com *.klaviyo.com 'self' 'unsafe-inline'; child-src www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.leurs.nl www.gartencenterleurs.de www.equidrome.nl www.equidrome.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-amVKbSVm+WAq1fkLbtvOEQqdfRU=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 object-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://unpkg.com; script-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-ZWY0OTBkNTItZTY0My00M2ZmLWE4ZDgtNWM0OWU1NWVjMjMx' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.reviews.co.uk *.reviews.io pingdom.com widget.reviews.co.uk http://*.pingdom.com https://*.pingdom.com https://widget.reviews.co.uk/ https://gbwatchshop.com https://*.gbwatchshop.com http://gbwatchshop.com http://*.gbwatchshop.com localhost:* 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com https://vars.hotjar.com/ https://widget.reviews.co.uk/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com www.apptrian.com http://gbwatch.weboven.online/* https://gbwatchshop.com https://gbwatchshop.com/* *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://plumrocket.com https://cache.addthiscdn.com/ *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com www.apptrian.com widget.freshworks.com m2epro.freshdesk.com https://widget.reviews.co.uk/rich-snippet-reviews-widgets/dist.js https://static.hotjar.com/c/hotjar-1268630.js https://script.hotjar.com/modules.ea0a6d6a741d5de8308e.js https://script.hotjar.com/* js.braintreegateway.com assets.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com *.paypal.com *.tawk.to cdn.jsdelivr.net client-analytics.sandbox.braintreegateway.com api.braintreegateway.com c.paypal.com pay.google.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com https://fonts.googleapis.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.google-analytics.com *.facebook.com *.facebook.net www.apptrian.com widget.freshworks.com m2epro.freshdesk.com https://api.reviews.co.uk/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/analytics.js https://api.reviews.co.uk/* *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.weltpixel.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.sendcloud.sc *.jsdelivr.net *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com https://*.gstatic.com https://images.unsplash.com https://cdn.clerk.io https:/at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://www.mollie.com https://redchamps.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.googleapis.com https://*.gstatic.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com player.vimeo.com js.mollie.com *.sendcloud.sc *.jsdelivr.net *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://api.clerk.io https://cdn.clerk.io https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self';object-src 'none';report-uri https://docs.google.com/document/cspreport;script-src 'report-sample' 'nonce-HhJ3zL4xFGvk9hGMoASvrQ' 'unsafe-inline';worker-src 'self' blob: 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.kr/api/csp-report; report-to csp-endpoint 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=094af504-f5a5-462a-a838-ba1c487137aa; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 object-src 'none'; script-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://static.addtoany.com https://unpkg.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://consent.cookiebot.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://bwy-dev.s3.eu-central-1.amazonaws.com https://bwy-prod.s3.eu-central-1.amazonaws.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://static.addtoany.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' https://kit.fontawesome.com https://ka-p.fontawesome.com https://www.google.com https://www.youtube.com https://s.ytimg.com https://player.vimeo.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://kit.fontawesome.com; font-src 'self' https://fonts.gstatic.com https://ka-p.fontawesome.com; img-src 'self' data: https://www.gstatic.com https://i.ytimg.com https://i.vimeocdn.com; connect-src 'self' https://api.weglot.com; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com; media-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none' 1 worker-src 'self' blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com 'self' www.googletagmanager.com *.cardinalcommerce.com www.kiyoh.com *.kiyoh.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: https://www.google.be www.google-analytics.com stats.g.doubleclick.net www.googletagmanager.com www.googleadservices.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io 'self' blob: www.google.be www.google.nl http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com 'self' js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com *.cardinalcommerce.com www.kiyoh.com *.kiyoh.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com 'self' 'unsafe-inline' *.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' blob: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net dashboard.postcode-checkout.nl www.postcode-checkout.nl https://www.google.com region1.analytics.google.com https://region1.google-analytics.com www.googleadservices.com stats.g.doubleclick.net www.googletagmanager.com https://www.google-analytics.com www.google-analytics.com analytics.google.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com 'self' www.google.com region1.google-analytics.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com client-analytics.braintreegateway.com api.braintreegateway.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.sandbox.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://postcode-checkout.nl https://www.postcode-checkout.nl https://postcode-checkout.nl/api/v2/ https://www.postcode-checkout.nl/api/v2/ cdn.ampproject.org www.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' kidy.com.br *.kidy.com.br wake-components.fbitsstatic.net kidy.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.googleadservices.com *.g.doubleclick.net googleadservices.com stats.g.doubleclick.net *.posclick.dinamize.com *.lomadee.com ajax.cloudflare.com connect.facebook.net *.facebook.net *.cloudflare.com *.bootstrapcdn.com *.jsdelivr.net static.hotjar.com *.hotjar.com *.hotjar.io vc.hotjar.io dzpxyxks1bfmb.cloudfront.net orion-lb-01.fbits.net *.fbits.net pontos.kidy.com.br gstatic.com *.gstatic.com *.google-analytics.com *.googlesyndication.com *.google.com *.clarity.ms *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.cloudfront.net signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.rdstation.com.br *.kidy.com.br popups.rdstation.com.br rdstation.com.br pageview-notify.rdstation.com.br google.com *.google.com.br *.googleapis.com *.googletagmanager.com *.doubleclick.net *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.lightwidget.com *.3dsecure.io *.reclameaqui.com.br *.rdstation.com *.goadopt.io *.youtube.com *.amazonaws.com google.com.au *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.kidy.com.br kidy.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.tawk.to *.appzi.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://dashboard.webwinkelkeur.nlfonts/webandbrand.woff data: 'self' 'unsafe-inline'; form-action *.paypal.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://chatwidget-prod.web.app https://www.feedbackcompany.com wm-livechat-2-prod-dot-watermelonmessenger.appspot.com *.doubleclick.net *.googletagmanager.com *.appzi.io js.mollie.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com cdn.doofinder.com magefan.com cm.magefan.com bat.bing.com *.clarity.ms www.google.nl *.googletagmanager.com *.tawk.to tawk.link *.appzi.io *.hotjar.com *.hotjar.io *.disqus.com https://firebasestorage.googleapis.com https://www.mollie.com cdn.jsdelivr.net s3.amazonaws.com/ ts.tradetracker.net www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com data: 'unsafe-inline' https://chatwidget-prod.web.app https://www.feedbackcompany.com www.google.com region1.google-analytics.com cdn.cookie-script.com bat.bing.com *.clarity.ms *.doofinder.com *.tawk.to *.jsdelivr.net *.googletagmanager.com *.appzi.io *.hotjar.com *.hotjar.io *.disqus.com *.avada.io player.vimeo.com js.mollie.com cdn.jsdelivr.net tm.tradetracker.net https://dashboard.webwinkelkeur.nl/sidebar.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.tawk.to *.appzi.io *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tawk.to tawk.link 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.doofinder.com wss://*.doofinder.com https://www.feedbackcompany.com region1.google-analytics.com www.google.com cdn.cookie-script.com bat.bing.com *.clarity.ms *.doubleclick.net *.tawk.to *.appzi.io wss://*.tawk.to *.googletagmanager.com wss://*.hotjar.com wss://*.hotjar.io *.hotjar.com *.hotjar.io https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com www.google.nl region1.google-analytics.com cdn.cookie-script.com bat.bing.com *.clarity.ms *.doofinder.com *.tawk.to *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' https://*.usercentrics.eu 'report-sample' 'nonce-rPWBCAKNZLhM-XeKHUNntVuh-hrI7hDysNYxIIEpwHID-XcNXbWMrw'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.usercentrics.eu https://*.youtube.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com; script-src-elem 'self' 'unsafe-inline' https://privacy-proxy.usercentrics.eu https://app.usercentrics.eu https://*.usercentrics.eu https://*.youtube.com https://cdn.jsdelivr.net 'report-sample'; script-src-attr 'self' 'unsafe-inline' 'report-sample'; style-src 'self' 'unsafe-inline' 'report-sample'; connect-src 'self' https://*.usercentrics.eu https://api.friendlycaptcha.com; font-src 'self' data:; frame-ancestors 'self' https://*.youtube.com; object-src 'none'; form-action 'self'; report-uri https://www.lehrer-in-mv.de/@http-reporting?csp=report&requestTime=1765937885300396&requestHash=ad6c9786a173273cde752313f7c1b5b26ff24a7c 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://kit.fontawesome.com https://static.addtoany.com https://use.fontawesome.com mdbootstrap.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://use.typekit.net mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self';script-src 'self';style-src 'self' 'unsafe-inline';img-src 'self' data: https: https://pbs.twimg.com;font-src 'self' https:;connect-src 'self' https: https://mindoshare.ai https://mindoshare.up.railway.app;frame-ancestors 'none';object-src 'none';base-uri 'self';form-action 'self';script-src-attr 'none';upgrade-insecure-requests 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://applepay.cdn-apple.com www.promessedefleurs.it data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com www.promessedefleurs.it 'self' 'unsafe-inline'; frame-ancestors www.promessedefleurs.it 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.promessedefleurs.it 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://secure-magenta.dalenys.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie www.promessedefleurs.it data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com cl.avis-verifies.com bat.bing.com s.pinimg.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com https://unpkg.com/pwacompat www.promessedefleurs.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://secure-magenta.dalenys.com unpkg.com www.promessedefleurs.it 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.promessedefleurs.it 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net www.promessedefleurs.it 'self' 'unsafe-inline'; child-src www.promessedefleurs.it http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com www.promessedefleurs.it 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://player.vimeo.com https://www.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io blueskytechmage.com mageblueskytech.com placehold.jp magefan.com cm.magefan.com https://www.magezon.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com *.avada.io https://player.vimeo.com https://www.youtube.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ekr.zdassets.com/ https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com applepay.cdn-apple.com 'self' data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardlink.gr *.alphaecommerce.gr *.eurocommerce.gr int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.facebook.com *.skroutz.gr *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.linkwi.se *.glami.gr *.iconify.design *.skroutz.gr *.quantserve.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com chimpstatic.com downloads.mailchimp.com *.list-manage.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.facebook.net *.facebook.com *.linkwi.se *.glami.gr *.iconify.design *.skroutz.gr *.jsdelivr.net *.quantserve.com *.quantcount.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.jsdelivr.net *.jquery.com *.fontawesome.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com data: *.trustedshops.com https://widgets.trustedshops.com fonts.gstatic.com *.zopim.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.cleverreach.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com js.mollie.com ratenkauf.easycredit.de 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.cloudfront.net https://www.mollie.com *.trustedshops.com *.instagram.com *.fbcdn.net *.via.placeholder.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.zopim.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googleapis.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com js.mollie.com *.trustedshops.com *.cdn.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com data: *.zdassets.com *.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com data: fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://consent.cookiefirst.com https://app.cookiefirst.com https://static.cookiefirst.com https://edge.cookiefirst.com *.instagram.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.zdassets.com *.zopim.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.webwinkelkeur.nl https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu js.mollie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io github.blog https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com maps.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.google.nl *.webwinkelkeur.nl *.usercentrics.eu img.sct.eu1.usercentrics.eu bat.bing.net bat.bing.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.demdex.net id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.1rx.io sync.targeting.unrulymedia.com https://www.mollie.com *.multisafepay.com v2assets.zopim.io static.zdassets.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.dhlecommerce.nl *.cookiebot.eu *.cookiebot.com *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.webwinkelkeur.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.calendly.com *.beslist.nl *.pinimg.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.pinterest.com js.mollie.com *.multisafepay.com https://pay.google.com static.zdassets.com ekr.zdassets.com baxrecreatieshop.zendesk.com *.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com widget.tagembed.com api.taggbox.com cdn.tagbox.com static.dhlecommerce.nl https://fonts.googleapis.com *.fontawesome.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.cookiebot.com *.cookiebot.eu *.consentcdn.cookiebot.com *.consentcdn.cookiebot.eu *.google.nl *.usercentrics.eu bat.bing.net bat.bing.com *.clarity.ms *.pinterest.com *.criteo.com *.beslist.nl widget.tagembed.com api.taggbox.com cdn.tagbox.com *.multisafepay.com static.zdassets.com ekr.zdassets.com baxrecreatieshop.zendesk.com *.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src static.zdassets.com ekr.zdassets.com baxrecreatieshop.zendesk.com *.zopim.com 'unsafe-inline' data: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.cloudfront.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com blob: *.cloudfront.net magefan.com cm.magefan.com assets.myparcel.nl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.facebook.net *.cloudfront.net https://cdn.tailwindcss.com https://cdn.jsdelivr.net https://www.termsfeed.com https://bat.bing.com https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com cdnjs.cloudflare.com cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudfront.net https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.cloudfront.net https://region1.google-analytics.com https://www.google-analytics.com https://bat.bing.net https://www.bing.net https://stats.g.doubleclick.net https://www.doubleclick.net https://pagead2.googlesyndication.com api.myparcel.nl cdn.jsdelivr.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem https://*.freeprivacypolicy.com https://*.youtube.com https://*.youtube-nocookie.com https://cdn.jsdelivr.net https://code.jquery.com; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com data: https://*.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.google.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com https://*.braintreegateway.com https://*.paypal.com https://*.trustpilot.com https://*.youtube.com https://*.youtube-nocookie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: * *.googleapis.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net https://*.paypal.com https://i.ytimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com player.vimeo.com https://*.cloudfront.net https://*.google-analytics.com https://*.paypal.com https://*.trustpilot.com https://*.youtube.com https://*.youtube-nocookie.com https://cdn.jsdelivr.net https://code.jquery.com https://cdn.c1.amplience.net https://*.freeprivacypolicy.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://*.googleapis.com *.typekit.net https://*.cloudfront.net assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net https://*.freshdesk.com wss://*.hotjar.com https://*.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.optomaeurope.com; script-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.optomaeurope.com *.optoma.co code.jquery.com fast.fonts.net www.googletagmanager.com https://tagmanager.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://unpkg.com *.unpkg.com https://youtube.com *.youtube.com youtube.com *.vimeo.com static.cloudflareinsights.com https://*.mapbox.com *.jsdelivr.net cdn.polyfill.io https://cdnjs.cloudflare.com https://*.fontawesome.com https://downloads-global.3cx.com https://*.3cx.cloud/ https://*.nr-data.net https://js-agent.newrelic.com https://www.gstatic.com https://*.doubleclick.net; object-src 'self'; style-src 'self' data: 'unsafe-inline' *.optomaeurope.com *.optoma.co https://tagmanager.google.com https://fonts.googleapis.com *.jsdelivr.net; img-src 'self' blob: data: *.optomaeurope.com *.optoma.co *.youtube.com *.ytimg.com *.vimeo.com www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://ssl.gstatic.com https://www.gstatic.com https://s3-us-west-2.amazonaws.com *.optoma.com https://*.3cx.cloud https://img.youtube-nocookie.com https://www.google.com.tw https://www.google.co.uk; media-src 'self' blob: data: *.optomaeurope.com; frame-src 'self' *.optomaeurope.com *.optoma.co *.youtube.com *.youtube-nocookie.com *.vimeo.com https://player.simplecast.com https://www.google.com https://td.doubleclick.net https://www.googletagmanager.com; font-src 'self' *.optomaeurope.com *.optoma.co https://fonts.gstatic.com data: ; connect-src 'self' *.optomaeurope.com https://*.google-analytics.com *.mapbox.com https://stats.g.doubleclick.net https://*.fontawesome.com https://*.3cx.cloud wss://*.3cx.cloud https://*.nr-data.net https://js-agent.newrelic.com https://*.google.com; report-uri /service-and-support/CspReportEmail/cspreport; 1 script-src 'self' cdnjs.cloudflare.com https://cdnjs.cloudflare.com; script-src-attr 'self'; style-src 'self' https://cdnjs.cloudflare.com; style-src-attr 'self'; frame-ancestors 'self' 1 frame-ancestors 'self' http://*.royalmarsden.org; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' *.stripe.com *.paypal.com https://vercel.live https://*.googletagservices.com https://*.googlesyndication.com https://*.googleadservices.com https://*.doubleclick.net https://*.ep-mimecast.ads-twitter.com https://*.cdn.civiccomputing.com https://*.google.com https://analytics.shorthand.com https://ads.nextdoor.com https://analytics.twitter.com https://bat.bing.com https://code.jquery.com https://cdn.syndication.twimg.com https://connect.facebook.net https://cdn.fundraiseup.com https://en.twitter.com https://googleads.g.doubleclick.net https://graph.facebook.com https://googletagmanager.com https://js.facebook.com https://m.youtube.com https://platform.twitter.com https://royal-marsden-cancer-charity.shorthandstories.com https://r.bing.com https://static.ads-twitter.com https://script.hotjar.com https://static.hotjar.com https://static.fundraiseup.com https://t.co https://tagmanager.google.com https://use.typekit.net https://www.youtube.com https://www.gstatic.com https://www.google.com https://www.googletagmanager.com; style-src 'self' 'report-sample' 'unsafe-inline' *.google.com *.bing.com *.typekit.net code.jquery.com fonts.googleapis.com platform.twitter.com ton.twimg.com www.googletagmanager.com; object-src *.googlesyndication.com; child-src 'self' blob: https://vercel.live *.stripe.com *.paypal.com *.facebook.com *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net platform.twitter.com www.youtube.com www.googletagmanager.com; base-uri 'self'; form-action 'self' *.facebook.com *.twitter.com *.google.com connect.facebook.net; worker-src 'self' blob: www.google.com; report-uri https://report.centralcsp.com/69087bcfa4cd74639de2a52b; report-to csp-endpoint; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://* *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src *.force.com slack-imgs-mil-dev.com https://vars.hotjar.com 'self' https://api.cquotient.com https://stats.g.doubleclick.net https://script.hotjar.com https://img.youtube.com https://payments.salesforce.com/icons/ https://login.salesforce.com/icons/ youtu.be https://mingle-sso.inforcloudsuite.com https://www.gstatic.com *.slack-edge-gov.com *.my-salesforce.com *.cloudinary.com https://software.soundoffsignal.com https://www.google.com https://vc.hotjar.io https://csmetrics.hotjar.com *.amazonaws.com blob: https://*.salesforce.com slack-imgs.com slack-gov-dev.com https://*.hotjar.com *.sfdcstatic.com gallery.soundoffsignal.com *.twimg.com https://content.hotjar.io https://soundoffsignal.file.force.com *.slack.com https://www.paypal.com https://nominatim.openstreetmap.org *.slack-imgs.com slack-imgs-gov.com https://eos.soundoffsignal.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://metrics.hotjar.io https://maps.a.forceusercontent.com https://*.force.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://usa578.sfdc-lywfpd.salesforce.com/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://mingle-ionapi.inforcloudsuite.com https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://i.vimeocdn.com https://in.hotjar.com wss://ws.hotjar.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://soundoffsignal.my.salesforce.com https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://soundoffsignal.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D5f0000092yzC&networkId=0DM5f000000Absb&type=communities 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net polyfill.io *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com trace.rtbasia.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fendi.cn *.fendi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.com *.algolia.net *.fendi.cn *.fendi.com *.wx.qq.com *.weixin.qq.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=d001693d-4e33-4aa7-8f57-85bc65b752b9; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net geowidget.easypack24.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.wesupply.xyz https://wesupplylabs.com secure.payu.com merch-prod.snd.payu.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.google.pl www.facebook.com px.ads.linkedin.com elmark.com.pl www.elmark.com.pl *.clarity.ms *.bing.com geowidget.easypack24.net osm.inpost.pl www.rugged.com.pl elmatic.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com static.payu.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com maps.googleapis.com snap.licdn.com connect.facebook.net *.clarity.ms pi.pardot.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net info.elmark.com.pl consent.cookiefirst.com *.googlesyndication.com *.cloudflare.com *.avada.io secure.payu.com secure.snd.payu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net geowidget.easypack24.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com maps.googleapis.com region1.analytics.google.com px.ads.linkedin.com *.clarity.ms stats.g.doubleclick.net *.googlesyndication.com api-pl-points.easypack24.net *.google-analytics.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.fonts.googleapis.com data: *.postcodeanywhere.co.uk *.facebook.com *.instagram.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.googletagmanager.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.instagram.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.googletagmanager.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.addthis.com *.sharethis.com *.pinterest.com *.meetanshi.com js.mollie.com *.facebook.com *.instagram.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.googletagmanager.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.addthis.com *.sharethis.com *.pinterest.com *.cdninstagram.com *.meetanshi.com https://www.mollie.com www.google.com www.google.com.ua *.googletagmanager.com *.postcodeanywhere.co.uk https://meetanshi.com *.facebook.com *.instagram.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.google.com *.google.ne *.google.nl *.google.no maps.googleapis.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.googleapis.com *.addthis.com *.sharethis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com *.avada.io *.meetanshi.com js.mollie.com *.googletagmanager.com *.postcodeanywhere.co.uk *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.postcodeanywhere.co.uk *.facebook.com *.instagram.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.googleapis.com *.addthis.com *.sharethis.com *.cardinalcommerce.com *.instagram.com https://get.geojs.io *.avada.io *.meetanshi.com *.postcodeanywhere.co.uk *.facebook.com *.meta.com *.doubleclick.net *.visualwebsiteoptimizer.com *.vwo.com *.mouseflow.com *.hotjar.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.studioplant.com/; report-to report-endpoint; 1 font-src *.fontawesome.com https://fonts.bunny.net https://cdn.caps.nl https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com/ https://tweakers.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com maps.googleapis.com maps.gstatic.com https://www.magezon.com https://firebasestorage.googleapis.com *.koongo.com www.google.com.ua https://cdn.caps.nl https://www.google.com https://www.google.es https://www.google.nl https://www.google-analytics.com *.tweakwisenavigator.net https://sgtm.caps.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com maps.googleapis.com *.avada.io *.shopify.com https://www.google.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js https://cdn.caps.nl *.tweakwisenavigator.net https://chimpstatic.com https://www.googletagmanager.com https://sgtm.caps.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css https://cdn-images.mailchimp.com https://cdn.caps.nl https://fonts.googleapis.com *.tweakwisenavigator.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com https://maps.googleapis.com https://player.vimeo.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com maps.googleapis.com https://get.geojs.io *.avada.io *.koongo.com https://cdn.caps.nl https://cognito-identity.eu-central-1.amazonaws.com https://www.google-analytics.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://www.postcode-checkout.nl https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://www.googleadservices.com https://analytics.google.com https://vimeo.com https://*.avada.io https://*.koongo.com https://*.facebook.net https://sgtm.caps.nl 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=L7g4gr_N3f2qxXqH_UTYzpVHrp6qRoWSe7tWL8EwBbluY2QfFFj5AMm0jI5ACFwA&policy_id=71&user_id=&request_id=f30f010a-0a21-46c3-b9f0-4eab9c0aa596; report-to csp-endpoint-lggrnfqxxqhutyzpvhrpqrowsetwlewbbluyqfffjammjiacfwa; frame-ancestors 'none' 1 default-src 'self'; img-src 'self' https: data: blob:; font-src 'self' https: data:; script-src 'self' https://apis.google.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; connect-src 'self'; media-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * test.saferpay.com www.saferpay.com saferpay.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com www.xtento.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; style-src www.vitadrogerie.ch *.adobe.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; connect-src translate.googleapis.com translate-pa.googleapis.com www.google.co.th www.google.fi www.google.com.ph www.google.com.mt www.google.co.il www.google.no www.google.co.uz www.google.tn www.google.com.cy www.google.co.nz www.google.co.id www.google.com.eg www.google.lk www.google.sk www.google.kz www.google.com.vn www.google.mg www.google.com.bh www.google.dk gb-api.web-vision.de www.google.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com test.saferpay.com www.saferpay.com saferpay.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; font-src assets.tailwindapp.com cdn.scite.ai fonts.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googletagmanager.com infird.com connect.facebook.net translate.google.com sc-static.net payment.preprod.direct.worldline-solutions.com www.google.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com analytics.google.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com payment.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src encrypted-tbn2.gstatic.com encrypted-tbn0.gstatic.com encrypted-tbn3.gstatic.com encrypted-tbn1.gstatic.com google.com lh3.google.com www.google.com.om www.google.com.do www.vitadrogerie.ch www.google.com.mt www.google.com.eg www.google.com.tw www.google.co.id www.google.lt www.google.com.cy www.google.co.uz www.google.bi www.google.com.co www.google.com.ar lh3.googleusercontent.com www.google.com.et www.google.mn www.google.kz www.google.dz www.google.je www.google.com.gt h2tcbox.baidu.com www.google.mv www.google.me www.google.co.ls www.google.com.au www.google.az www.google.so www.google.co.cr www.google.com.pk www.google.cm www.google.com.gh www.google.com.bh www.google.ad www.google.com.ec www.google.ee www.google.li www.google.com www.google.pl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com test.saferpay.com www.saferpay.com saferpay.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline';report-uri https://www.vitadrogerie.ch/de/fl32csp/report/; 1 default-src 'self'; report-uri https://13fdb20b4d99daba15f18769204d48be.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' litium.revolutionrace.nl fbcdn.revolutionrace.nl wss://fbcdn.revolutionrace.nl *.klarnaservices.com *.klarnauserservices.com *.klarnacdn.net *.klarna.com *.klarnaevt.com *.kustom.co *.adyen.com www.paypal.com js.stripe.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com ajax.googleapis.com fonts.googleapis.com maps.googleapis.com *.apptus.cloud *.storyblok.com *.symplify.com cdn-sitegainer.com *.cdn-sitegainer.com sitegainer.com wss://recording.sitegainer.com *.criteo.net *.criteo.com *.doubleclick.net *.emarsys.net *.mention-me.com *.imedia.cz *.scarabresearch.com *.spinnaker-js.com bat.bing.com www.seznam.cz tags.creativecdn.com *.kindlycdn.com *.kindly.ai wss://sage.kindly.ai *.facebook.net *.tiktok.com *.snapchat.com *.pinterest.com *.bambuser.com *.facebook.com www.pinterest.se *.cloudflare.com *.digitaloceanspaces.com *.distancify.workers.dev cdn.jsdelivr.net maxcdn.bootstrapcdn.com player.vimeo.com pro.ip-api.com recommender.scarabresearch.com s.pinimg.com sc-static.net vimeo.com ws-eu.pusher.com wss://ws-eu.pusher.com 'unsafe-inline' 'unsafe-eval'; img-src data: blob: https://* 'self'; media-src https://*; frame-src analytics.revolutionrace.nl *.mention-me.com *.google.com *.adyen.com *.paypal.com *.sitegainer.com revolutionrace.customerfirst.ai; style-src 'self' 'unsafe-inline'; connect-src data: *; 1 script-src 'self' blob: https://prod-bk-web.nl.rbi.tools/en/static/js/vendor.9c953b27.js https://prod-bk-web.nl.rbi.tools/en/static/js/main.24db8451.js https://prod-bk-web.nl.rbi.tools/en/static/js/runtime.e4734988.js https://*.mparticle.com https://cdn.cookielaw.org https://www.googletagmanager.com https://*.onetrust.com https://static.ads-twitter.com https://platform.twitter.com https://www.google-analytics.com https://connect.facebook.net https://secure.quantserve.com https://dynamic.criteo.com https://rules.quantcount.com https://cdn.branch.io https://app.link https://*.cdn4.forter.com https://dlthst9q2beh8.cloudfront.net https://sslwidget.criteo.com https://widget.eu.criteo.com https://pagead2.googlesyndication.com https://cdn.amplitude.com https://accounts.google.com https://appleid.cdn-apple.com https://analytics.tiktok.com https://c.amazon-adsystem.com https://js.adsrvr.org https://maps.googleapis.com https://googleads.g.doubleclick.net https://static.zdassets.com https://bat.bing.com https://cdn-st.adsmurai.com https://prod-bk-web.nl.rbi.tools/en/static/js/vendor.94f8e485.js https://prod-bk-web.nl.rbi.tools/en/static/js/main.8eb1d42c.js https://prod-bk-web.nl.rbi.tools/en/static/js/runtime.cf32b062.js; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; report-uri https://intl-csp-service.rbictg.com/report 1 script-src-elem webcache.datareporter.eu webcache-eu.datareporter.eu sibautomation.com *.brevo.com cdn.jsdelivr.net cdnjs.cloudflare.com connect.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com polyfill.mstage.dev *.usersnap.com www.google.com www.googleadservices.com googleads.g.doubleclick.net cdn.usersnap.com api.usersnap.com *.facebook.net *.codico.com *.broadband.se payda.krakow.pl content.payda.krakow.pl; style-src-elem https://webcache.datareporter.eu https://webcache-eu.datareporter.eu cdn.jsdelivr.net fonts.googleapis.com *.bootstrapcdn.com *.typekit.net *.codico.com *.broadband.se payda.krakow.pl content.payda.krakow.pl googleads.g.doubleclick.net; font-src webcachex-eu.datareporter.eu *.fontawesome.com fonts.gstatic.com data: online.swagger.io *.codico.ecx *.codico.test *.codico.localhost *.stage-m-codico.ecxdev.io *.codico.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.google.com *.facebook.com *.usercentrics.eu 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com img.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.openstreetmap.org online.swagger.io validator.swagger.io cdn.usersnap.com cdn.jsdelivr.net www.facebook.com www.google.at magefan.com cm.magefan.com *.codico.ecx *.codico.test *.codico.localhost codico-typo3.typo3.test *.typo3.test *.stage-m-codico.ecxdev.io stage-m-codico.ecxdev.io content.stage-m-codico.ecxdev.io *.ecxdev.io *.prod-m-codico.ecxdev.io prod-m-codico.ecxdev.io content.prod-m-codico.ecxdev.io *.codico.com *.usercentrics.eu px.ads.linkedin.com bat.bing.com *.typekit.net *.broadband.se payda.krakow.pl content.payda.krakow.pl data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.datareporter.eu *.fontawesome.com polyfill.io polyfill.mstage.dev *.usersnap.com *.google.com *.gstatic.com *.payments-amazon.com *.codico.ecx *.codico.test *.codico.localhost *.stage-m-codico.ecxdev.io *.codico.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.datareporter.eu *.fontawesome.com fonts.googleapis.com *.codico.ecx *.codico.test *.codico.localhost *.stage-m-codico.ecxdev.io *.codico.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io *.datareporter.eu *.amazon.com *.brevo.com *.google.com forms.hsforms.com *.paypal.com api.usersnap.com *.google-analytics.com googleads.g.doubleclick.net *.usercentrics.eu *.clarity.ms px.ads.linkedin.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.codico.com *.broadband.se payda.krakow.pl content.payda.krakow.pl 'self' 'unsafe-inline'; report-uri https://8a0f8218-cbf9-4e83-9819-6746d03b8225.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-ZBCTb0QWTQieGPASe0luQYf76lI=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.doubleclick.net https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com ekr.zdassets.com/ *.google-analytics.com *.google.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.affirm.com *.affirm.ca https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.affirm.com *.affirm.ca widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.affirm.com *.affirm.ca widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri https://blogun.report-uri.io/r/default/csp/reportOnly 1 script-src 'self' 'unsafe-inline' ajax.googleapis.com maps.googleapis.com www.google-analytics.com www.googletagmanager.com www.google.com www.gstatic.com www.youtube.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-ZP5zvTezQWKsS3harMgmreO5qNo=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.matomo.cloud https://static.ads-twitter.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: data: blob:; font-src 'self' https: data:; media-src 'self' https://media.citizenx.com https: data: blob:; connect-src 'self' https://citizenx.matomo.cloud https: wss: blob: data:; manifest-src 'self'; frame-ancestors 'self'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-kBvyI97dQwaToBE+aed9s4UTi9Y=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src *.fontawesome.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net *.weltpixel.com *.wesupply.xyz 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.vimeocdn.com s.ytimg.com data: www.apptrian.com www.facebook.com *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.cloudflare.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.apptrian.com connect.facebook.net graph.facebook.com *.instagram.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.authorize.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.mageside.com mageside.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.authorize.net sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.authorize.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval' ; frame-src *; object-src 'none'; img-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline' ; connect-src * data: blob: 'unsafe-inline' ; script-src * data: blob: 'unsafe-inline' 'unsafe-eval' ; script-src-elem * data: blob: 'unsafe-inline' 'unsafe-eval' ; style-src-elem * 'unsafe-inline' ; base-uri https://www.monsieurpeinture.com/ ; frame-ancestors https://www.monsieurpeinture.com/ * 'self' data: blob: ; block-all-mixed-content ; report-uri https://hooks.zapier.com/hooks/catch/2178937/baa1zsb/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://fonts.gstatic.com https://use.fontawesome.com www.searchanise.com *.searchserverapi.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net www.searchanise.com *.searchserverapi.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com/ *.authorize.net www.searchanise.com *.searchserverapi.com *.twitter.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://s3.amazonaws.com *.disqus.com https://img.youtube.com https://www.magezon.com store.paradoxlabs.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com media.sezzle.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com https://standby.comm100vue.com https://comm100vue.com https://use.fontawesome.com https://chimpstatic.com https://searchserverapi.com https://maxcdn.bootstrapcdn.com https://*.adobe.com https://fonts.googleapis.com https://downloads.mailchimp.com https://*.searchserverapi.com https://searchanise-ef84.kxcdn.com https://static.hotjar.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com *.google.com/ *.authorize.net searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://use.fontawesome.com https://fonts.googleapis.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://www.google-analytics.com https://olegnax.com https://api.instagram.com https://graph.instagram.com/ *.authorize.net api.amplitude.com stats.g.doubleclick.net gateway.sezzle.com sandbox.gateway.sezzle.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-IFYhJ0djsammcyfStK97sNKfWRg=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src 'unsafe-inline' data: cdn.icomoon.io *.fontawesome.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com *.sirv.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk https://www.facebook.com https://widget.reviews.io 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com account.fetchify.com js.mollie.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.reviews.io *.reviews.co.uk *.salesfire.co.uk www.xtento.com *.criteo.com *.consensu.org https://www.facebook.com https://widget.reviews.io https://www.youtube.com *.pinterest.com *.google.com *.pinterest.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.google.co.uk *.trackedlink.net https://www.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.sirv.com 'self' data: www.xtento.com cdn.xtento.com *.google-analytics.com *.pinterest.com *.co *.bing.com *.linkedin.com *.advertising.com *.rubiconproject.com *.addthis.com *.doubleclick.net *.mgid.com *.ssp.rambler.ru *.outbrain.com *.taboola.com *.smartadserver.com *.yahoo.com *.e-planning.net *.ads.yieldmo.com *.adnxs.com *.yieldmo.com *.criteo.com *.pubmatic.com *.bidswitch.net *.omnitagjs.com *.tremorhub.com *.smartclip.net *.stickyadstv.com *.smaato.net *.clmbtech.com *.adform.net *.liadm.com *.tribalfusion.com *.360yield.com *.3lift.com *.casalemedia.com *.teads.tv *.media.net *.openx.net *.sharethrough.com *.postrelease.com *.tapad.com *.thebrighttag.com *.bluekai.com *.adscale.de *.ivitrack.com *.yieldlab.net *.socdm.com *.rlcdn.com *.twiago.com *.facebook.net *.gravatar.com *.sharethis.com https://um.simpli.fi https://i.ytimg.com *.gasproducts.co.uk gasproducts.co.uk *.calorgas.ie *.calor.co.uk c.clarity.ms/c.gif *.kelkoogroup.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google-analytics.com *.analytics.google.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal widget.freshworks.com m2epro.freshdesk.com js.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.sirv.com player.vimeo.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.geo-targetly.com *.criteo.net *.googleadservices.com *.bing.com *.licdn.com *.ads-twitter.com *.pinimg.com *.aweber.com fastbase.com *.zdassets.com *.trustpilot.com *.twitter.com *.doubleclick.net *.criteo.com *.zopim.com https://geo-targetly.com https://www.googletagmanager.com *.googletagmanager.com https://www.google.com/pagead/conversion_async.js *.sharethis.com *.kk-resources.com *.googleapis.com g1782759016.co *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com cc-cdn.com cdn.icomoon.io https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.typekit.net fonts.googleapis.com *.sirv.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.sirv.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com widget.freshworks.com m2epro.freshdesk.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.salesfire.co.uk *.smartmetrics.co.uk *.sirv.com *.youtube.com blob: t.elasticsuite.io fastbase.com *.zdassets.com *.pinterest.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.sharethis.com *.clarity.ms *.kelkoogroup.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1fea361e-4c97-413c-bdda-003a88c89215.sansec.watch/; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com https://widgets.trustedshops.com *.klarnacdn.net https://www.gstatic.com https://fonts.gstatic.com *.stape.io 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com app.usercentrics.eu *.klarna.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.stape.io *.trbo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net cdn.scarabresearch.com orbitvu.co *.orbitvu.co *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com media.brand-distribution.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com app.usercentrics.eu privacy-proxy-server.usercentrics.eu uct.service.usercentrics.eu *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.stape.io www.facebook.com connect.facebook.com www.google.de piwik.hama.com *.trbo.com *.hsforms.net *.hsforms.com 'self' data: widgets.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net/ cdn.scarabresearch.com s7.addthis.com orbitvu.co *.orbitvu.co *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com aggregator.service.usercentrics.eu app.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu consent-api.service.consent.usercentrics.eu *.klarna.com *.klarnacdn.net *.klarnaservices.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.stape.io connect.facebook.com connect.facebook.net www.google.com www.google.de piwik.hama.com *.trbo.com *.hsforms.net *.hsforms.com widgets.trustedshops.com https://app.usercentrics.eu https://privacy-proxy.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.orbitvu.co *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com fast.fonts.net hello.myfonts.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.stape.io *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.userlike.com ekr.zdassets.com/ *.orbitvu.cloud *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site aggregator.service.usercentrics.eu app.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu consent-api.service.consent.usercentrics.eu *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.stape.io connect.facebook.com connect.facebook.net www.google.com www.google.de piwik.hama.com *.trbo.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.trustedshops.com *.twimg.com *.twitter.com *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com *.stripe.com *.stripe.network *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.twitter.com *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cloudflare.com *.google-analytics.com *.googleadservices.com *.klarna.com *.lightemporium.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com www.apptrian.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com *.pinterest.com *.google.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.fontawesome.com *.google-analytics.com *.gstatic.com *.pcapredict.com *.trackedlink.net *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com www.apptrian.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com landofcoder.com www.xtento.com cdn.xtento.com *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.bootstrapcdn.com *.cloudflare.com *.google-analytics.com *.googleadservices.com *.paypalobjects.com *.pcapredict.com *.sandbox.paypal.com *.trackedlink.net *.twimg.com *.twitter.com *.sagepay.com *.sagepay.co.uk *.opayo.eu.elavon.com *.addthis.com www.apptrian.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.affirm.com *.affirm.ca *.certcapture.com *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca *.certcapture.com js.klevu.com *.ksearchnet.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.klevu.com *.ksearchnet.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca *.certcapture.com https://www.sandbox.paypal.com https://www.paypal.com https://checkout.iwdagency.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'none'; script-src 'self' 'none'; object-src 'self' 'none'; frame-src 'self' 'none' 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://catalate.report-uri.com/r/d/csp/wizard 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.youtube.com https://s.ytimg.com https://www.google-analytics.com https://*.moatads.com https://*.doubleclick.net https://*.newrelic.com https://*.nr-data.net https://*.googlevideo.com https://*.arcgis.com https://*.gov.uk https://*.facebook.com; frame-src 'self' https://*.youtube.com https://www.googletagmanager.com https://*.arcgis.com; report-uri https://snhwebsite.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com js.mollie.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://images.unsplash.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net magefan.com cm.magefan.com flagpedia.net https://www.mollie.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googletagmanager.com tagmanager.google.com https://maps.googleapis.com *.gstatic.com maps.googleapis.com js.mollie.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src tagmanager.google.com fonts.google.com maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com www.gstatic.com maps.googleapis.com https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.fi www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com cdn2.hubspot.net resources.paytrail.com *.maksuturva.fi data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleadservices.com *.googlesyndication.com *.newrelic.com *.nr-data.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com services.paytrail.com *.googletagmanager.com *.maksuturva.fi 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.doubleclick.net *.google-analytics.com *.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.paytrail.com *.maksuturva.fi 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://dgap.org https://createsend.com https://api.friendlycaptcha.com https://internationalepolitik.de https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com https://matomo.dgap.org/; font-src 'self' data: dgap.org https://player.podigee-cdn.net https://fonts.gstatic.com; frame-src 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://www.youtube-nocookie.com/embed/ https://e.issuu.com https://www.google.com https://player.podigee-cdn.net https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://matomo.dgap.org https://www.openstreetmap.org https://cloud.dgap.org https://audio.podigee-cdn.net https://sign.dgap.dev https://www.helpmundo.de https://www.helpdirect.org https://tube.dgap.org; img-src 'self' https://www.gstatic.com https://*.met.vgwort.de https://www.googletagmanager.com https://www.google-analytics.com data: dgap.org https://matomo.dgap.org https://images.podigee-cdn.net https://region1.google-analytics.com; manifest-src 'self'; media-src 'self' https://audio.podigee-cdn.net; prefetch-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' https://dgap.org https://matomo.dgap.org https://www.google-analytics.com https://www.googletagmanager.com https://internationalepolitik.de https://ip-quarterly.com https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com https://matomo.dgap.org/; script-src-attr 'self' 'report-sample'; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://dgap.org https://www.googletagmanager.com https://www.google-analytics.com https://matomo.dgap.org https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com; style-src 'self' 'report-sample' 'unsafe-inline' https://js.createsend1.com https://www.gstatic.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'report-sample' 'unsafe-inline'; style-src-elem 'self' 'report-sample' 'unsafe-inline' https://www.google.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net https://cdnjs.cloudflare.com; worker-src 'self' blob:; form-action 'self' https://www.createsend.com https://dgap.org; frame-ancestors 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://sign.dgap.dev; report-uri https://internationalepolitik.de/en/system/reporting/default; report-to default 1 font-src *.fontawesome.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadolibre.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.mlstatic.com *.mercadopago.com *.smarthint.co *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolibre.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https: * ws: wss:; default-src 'self' https: *; script-src 'self' https: * 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: * 'unsafe-inline'; worker-src 'self' blob:; img-src 'self' https: * data:; font-src 'self' https: * data:; report-uri https://workflows.hexlet.io/webhook/df20fc89-2425-4931-a5fa-11fa1acb4831 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.lynka24.local www.googletagmanager.com *.demdex.net *.google-analytics.com 'self' 'unsafe-inline'; img-src data: *.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' blob: self *.abbc.pl *.lynka.eu https://ssl.dotpay.pl *.braintreegateway.com *.demdex.net *.behance.pl *.ftcdn.eu *.vimeocdn.net *.aptrinsic.com storage.googleapis.com https://secure.adnxs.com https://pixel-geo.prfct.co https://www.google.pl lynka.eu img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com apis.google.com www.apptrian.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com https://pixel-geo.prfct.co https://tag.perfectaudience.com https://koi-3scsh62opg.marketingautomation.services https://js-agent.newrelic.com https://www.youtube.com *.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.lynka24.local *.abbc.pl *.lynka.eu *.demdex.net https://ssl.dotpay.pl https://stats.g.doubleclick.net https://www.google.pl *.usercentrics.eu 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.cloudfront.net *.reviews.io *.reviews.co.uk css.zohocdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.weltpixel.com js.mollie.com *.reviews.io *.reviews.co.uk www.googletagmanager.com td.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src https://flagcdn.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io widgets.automizely.com widgets.automizely.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.mollie.com *.koongo.com *.cloudfront.net *.reviews.io *.reviews.co.uk bat.bing.com us4-files.zohopublic.com *.google.com.* data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.disqus.com *.avada.io js.mollie.com cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/highlight.min.js *.reviews.io *.reviews.co.uk salesiq.zoho.com bat.bing.com cdn.pagesense.io static.cloudflareinsights.com www.clarity.ms js.zohocdn.com static.zohocdn.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io https://www.googletagmanager.com tagmanager.google.com *.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net cdnjs.cloudflare.com/ajax/libs/highlight.js/9.3.0/styles/darkula.min.css *.cloudfront.net *.reviews.io *.reviews.co.uk css.zohocdn.com widget.reviews.io *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.automizely.com api.automizely.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://www.google-analytics.com https://maps.googleapis.com https://player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io *.koongo.com *.cloudfront.net *.reviews.io *.reviews.co.uk salesiq.zoho.com salesiq.zohopublic.com pagesense-collect.zoho.com u.clarity.ms cloudflareinsights.com h.clarity.ms vts.zohopublic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://d13qcyivyon4xf.cloudfront.net https://*.recollect.net https://www2.elpasotexas.gov https://*.piktochart.com https://elpasotx.citysourced.com https://alive5.com https://*.pure.cloud https://td.doubleclick.net https://*.userway.org https://*.powerbigov.us 'self' data:; script-src https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com https://*.userway.org https://alive5.com https://*.elpasotexas.gov https://*.clarity.ms https://*.youtube.com https://*.googleadservices.com 'unsafe-eval' https://*.facebook.net https://*.adtrafficquality.google https://*cloudflareinsights.com https://*.websitealive.com 'sha256-9Ci0Au7w6njPLhCiB59KMuhfydSvBsVzJFrH1rL7R5Q=' 'sha256-CYrq938HJCHhAbUIEcN6Kz8wuWOzUhGLjaNWvKa4lw8=' 'sha256-gqtyOpnJcyerFJZS/CaewBU8NnstBmOFZTvml7IKc+U=' 'self' 'report-sample' 'nonce-6878d72f074d010e'; style-src https://*.googleapis.com https://*.fontawesome.com https://*.google.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://alive5.com https://*.userway.org https://*.gstatic.com 'self' 'unsafe-inline' 'report-sample'; connect-src https://*.fontawesome.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com https://googletagmanager.com https://*.acsbapp.com https://webmessaging.usw2.pure.cloud https://*.pure.cloud https://*.userway.org https://*.alive5.com https://alive5.com https://*.clarity.ms https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.googleapis.com 'self' data:; font-src https://*.gstatic.com https://*.fontawesome.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://acsbapp.com https://*.userway.org 'self' data:; img-src https://*.google.com https://*.googleapis.com https://*.google-analytics.com https://*.jsdelivr.net https://*.fastly.net https://*.recollect.net https://*.piktochart.com https://*.userway.org https://*.alive5.com https://*.clarity.ms https://*.gstatic.com https://*.googletagmanager.com https://*.bing.com https://tip411.com https://*.tip411.com https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.google.com.mx https://syndicatedsearch.goog 'self' data:; Strict-Transport-Security max-age=31536000; frame-src https://syndicatedsearch.goog https://www2.elpasotexas.gov https://alive5.com https://*.youtube.com https://*.powerbigov.us https://*.google.com https://*.adtrafficquality.google https://*.userway.org https://googletagmanager.com https://coepgis.map.arcgis.com https://*.googletagmanager.com https://tip411.com https://*.tip411.com https://*.elpasozoo.org 'self'; media-src https://*.gstatic.com 'self'; script-src-elem https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com https://*.userway.org https://alive5.com https://*.elpasotexas.gov https://*.clarity.ms https://*.youtube.com https://*.googleadservices.com 'unsafe-eval' https://*.websitealive.com https://*.adtrafficquality.google 'sha256-9Ci0Au7w6njPLhCiB59KMuhfydSvBsVzJFrH1rL7R5Q=' 'sha256-CYrq938HJCHhAbUIEcN6Kz8wuWOzUhGLjaNWvKa4lw8=' 'sha256-gqtyOpnJcyerFJZS/CaewBU8NnstBmOFZTvml7IKc+U=' 'self' 'report-sample' 'nonce-6878d72f074d010e'; frame-ancestors 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com paypage-test.adflex.co.uk paypage.adflex.co.uk *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ paypage-test.adflex.co.uk paypage.adflex.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net docs.brand-estore.com cdn.weglot.com cdn-api-weglot.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net paypage-test-cdn.adflex.co.uk paypage-cdn.adflex.co.uk cgtforms.com cdn.cookie-script.com browser.sentry-cdn.com www.clarity.ms googletagmanager.com services.postcodeanywhere.co.uk cdn.weglot.com cdn-api-weglot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com paypage-test-cdn.adflex.co.uk paypage-cdn.adflex.co.uk services.postcodeanywhere.co.uk https://fonts.googleapis.com cdn.weglot.com cdn-api-weglot.com unsafe-inline assets.braintreegateway.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src cdn.weglot.com cdn-api-weglot.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io cdn.weglot.com cdn-api-weglot.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors https://*.workable.com/; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubcbe8d2ef0966e8645a91099cfac490bb&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=%40http.headers.cfray%3A9af2a8d77a7ace68 1 img-src 'self' data: https://maps.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://maps.googleapis.com https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com ; style-src 'self' 'unsafe-inline' https://ajax.googleapis.com https://code.jquery.com https://fonts.googleapis.com ; style-src-elem 'self' 'unsafe-inline' https://ajax.googleapis.com https://code.jquery.com https://fonts.googleapis.com ; font-src 'self' https://fonts.gstatic.com https://netdna.bootstrapcdn.com data:; frame-src 'self' blob:; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://yoast.com https://maps.googleapis.com https://www.googletagmanager.com; worker-src 'self' blob:; report-uri https://www.huber.com/wp-json/rsssl/v1/csp?rsssl_apitoken=955550414; 1 worker-src 'self' blob:; report-uri https://cspreporting.uk/csp/; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.webwinkelkeur.nl https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com consentcdn.cookiebot.eu td.doubleclick.net www.youtube-nocookie.com https://*.dpdconnect.nl *.twitter.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io widgets.automizely.com widgets.automizely.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.pay.nl *.calendly.com *.hsforms.net *.hsforms.com www.google.com www.google.nl www.facebook.com bat.bing.com px.ads.linkedin.com img.sct.eu1.usercentrics.eu *.cloudflare.com *.klarna.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.webwinkelkeur.nl ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://maps.gstatic.com www.googletagmanager.com blob: https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io https://maps.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.calendly.com *.hsforms.net *.hsforms.com chimpstatic.com api.dpdconnect.nl www.googletagmanager.com consent.cookiebot.eu snap.licdn.com connect.facebook.net bat.bing.com googleads.g.doubleclick.net consentcdn.cookiebot.eu www.google.com www.gstatic.com https://*.dpdconnect.nl *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.webwinkelkeur.nl downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.calendly.com *.hsforms.net *.hsforms.com www.youtube-nocookie.com www.gstatic.com *.fontawesome.com *.cloudflare.com *.google.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.webwinkelkeur.nl downloads.mailchimp.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.automizely.com api.automizely.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.calendly.com *.hsforms.net *.hsforms.com region1.analytics.google.com px.ads.linkedin.com consentcdn.cookiebot.eu www.youtube-nocookie.com play.google.com jnn-pa.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.webwinkelkeur.nl api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com googleads.g.doubleclick.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com data: *.fontawesome.com use.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com scontent.* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ display.ugc.bazaarvoice.com *.fontawesome.com assets.braintreegateway.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1e3d9ee3-e823-4154-84aa-fb0a412ed915.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; style-src 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://143720318.fs1.hubspotusercontent-eu1.net data:; script-src 'self' *.hubspot.com *.hs-scripts.com *.hscollectedforms.net 'strict-dynamic' 'nonce-34FoqmiBRVbpl+V+Qba38Q=='; connect-src 'self' *.hubspot.com *.hubspotusercontent-eu1.net *.hsforms.com *.hs-scripts.com; frame-src *.hubspot.com *.hsforms.com 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://events.fairchildlive.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 object-src 'none'; script-src 'nonce-aUIihPlCza_7jPaUiEko1AAAAIg' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:; base-uri 'self'; report-uri https://www.koaspeer.com/csp_process.php; 1 font-src www.paypalobjects.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com td.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.awin1.com *.zenaps.com js.mollie.com consentcdn.cookiebot.com www.googletagmanager.com https://www.googletagmanager.com https://td.doubleclick.net https://widget.trustpilot.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://images.unsplash.com magefan.com cm.magefan.com https://www.mollie.com *.cloudflare.com imgproxy.vendic.dev imgsct.cookiebot.com *.hsforms.net *.hsforms.com https://imgproxy.vendic.dev data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.stats.g.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://maps.googleapis.com js.mollie.com *.cdnjs.cloudflare.com data: *.increasingly.co *.googleadservices.com *.sandbox.paypal.com *.googleapis.com *.paypalobjects.com *.the.sciencebehindecommerce.com *.sciencebehindecommerce.com *.hal9000.redintelligence.net *.redintelligence.net googleads.g.doubleclick.net td.doubleclick.net script.hotjar.com consentcdn.cookiebot.com *.albeka.nl *.mollie.com *.google.co.in *.static.widget.trengo.eu *.widget.trengo.eu *.trengo.s3.eu-central-1.amazonaws.com *.google.nl *.api.widget.trengo.eu *.trengo.eu bat.bing.com/bat.js www.clarity.ms *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net https://www.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://maps.googleapis.com https://player.vimeo.com *.cloudflare.com consentcdn.cookiebot.com/ sst.albeka.nl/ t.elasticsuite.io *.hsforms.net *.hsforms.com https://p2iqhncxyh.execute-api.eu-central-1.amazonaws.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.my127.site blob: *.my127.site inviqa.com inviqa.de youtube.com *.doubleclick.net *.google.com *.googleadservices.com *.google.co.uk *.hubspot.com *.trackedweb.net *.hotjar.com madixel.de cdn.cookielaw.org geolocation.onetrust.com; script-src 'self' 'unsafe-inline' blob: *.googleapis.com 'unsafe-eval' *.my127.site inviqa.com inviqa.de *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.hotjar.com *.gstatic.com *.hs-scripts.com *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net *.licdn.com *.twitter.com *.trackedweb.net *.trackedlink.net madixel.de *.googleadservices.com *.ads-twitter.com cdn.cookielaw.org; style-src 'self' 'unsafe-inline' *.my127.site inviqa.com inviqa.de; img-src 'self' *.my127.site data: inviqa.com inviqa.de *.google.co.uk *.google.com *.google-analytics.com *.twitter.com *.linkedin.com t.co *.hubspot.com *.hsforms.com *.doubleclick.net cdn.cookielaw.org; frame-src *; frame-ancestors 'self'; child-src *; font-src 'self' *.my127.site data: inviqa.com inviqa.de; report-uri https://www.inviqa.report-uri.com/r/d/csp/reportOnly; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://shopstatic.magflags.de https://static.car-flags.eu https://static.car-flag.co.uk https://static.auto-fahnen.net https://static.auto-flaggen.at https://static.car-flags.net https://static.magflags.net https://static.autofahne.ch data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://api.mapbox.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://shopstatic.magflags.de https://static.car-flags.eu https://static.car-flag.co.uk https://static.auto-fahnen.net https://static.auto-flaggen.at https://static.car-flags.net https://static.magflags.net https://static.autofahne.ch https://media.magflags.de https://media.car-flags.eu https://media.car-flag.co.uk https://media.auto-fahnen.net https://media.auto-flaggen.at https://media.car-flags.net https://media.magflags.net https://media.autofahne.ch data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com widget.freshworks.com m2epro.freshdesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network https://*.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://assets.adobedtm.com https://www.google-analytics.com https://static.hotjar.com https://script.hotjar.com https://m.stripe.network https://*.stripecdn.com https://*.hcaptcha.com https://track.magflags.de https://shopstatic.magflags.de https://static.car-flags.eu https://static.car-flag.co.uk https://static.auto-fahnen.net https://static.auto-flaggen.at https://static.car-flags.net https://static.magflags.net https://static.autofahne.ch 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com https://shopstatic.magflags.de https://static.car-flags.eu https://static.car-flag.co.uk https://static.auto-fahnen.net https://static.auto-flaggen.at https://static.car-flags.net https://static.magflags.net https://static.autofahne.ch https://www.magflags.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com autocomplete2.postdirekt.de *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com wss://ws.hotjar.com https://content.hotjar.io https://*.stripe.com https://www.google-analytics.com https://www.google.com https://api.braintreegateway.com https://track.magflags.de https://shopstatic.magflags.de https://static.car-flags.eu https://static.car-flag.co.uk https://static.auto-fahnen.net https://static.auto-flaggen.at https://static.car-flags.net https://static.magflags.net https://static.autofahne.ch 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src c.imedia.cz c.seznam.cz s2.adform.net connect.facebook.net googleads.g.doubleclick.net www.google-analytics.com widget.packeta.com ssl.heureka.cz 1gr.cz c.seznam.cz www.zbozi.cz cdn.cpex.cz sdk.privacy-center.org sgtm.signals.cz rec.smartlook.com cnc.daktela.com widget-v2.smartsuppcdn.com www.smartsuppchat.com *.smartsupp.com *.smartsuppcdn.com *.smartlook.com *.smartsuppchat.com spir.hit.gemius.pl a.opmnstr.com track.adform.net widget.packeta.com ssl.heureka.cz c.imedia.cz api.mapy.cz www.heureka.cz *.mapy.cz script.hotjar.com www.google.com *.google.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com tagmanager.google.com googleads.g.doubleclick.net connect.facebook.net static.hotjar.com *.im9.cz im9.cz 'self' 'unsafe-inline' 'unsafe-eval'; script-src-elem *.im9.cz im9.cz www.zbozi.cz *.smartlook.com rec.smartlook.com widget-v2.smartsuppcdn.com *.smartsuppcdn.com script.hotjar.com www.obchod.crew.cz api.mapy.cz c.imedia.cz c.seznam.cz s2.adform.net connect.facebook.net googleads.g.doubleclick.net www.google-analytics.com widget.packeta.com ssl.heureka.cz api.mapy.cz www.googleadservices.com www.googleadservices.com 2.adform.net www.googletagmanager.com track.adform.net 1gr.cz 'self' 'unsafe-inline'; style-src translate.googleapis.com *.smartsuppcdn.com cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com api.mapy.cz 'unsafe-inline' 'self'; style-src-elem fonts.googleapis.com *.smartsuppcdn.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; report-uri /csp 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com landofcoder.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.trackedlink.net *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com x.klarnacdn.net *.klarnaservices.com *.zdassets.com *.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com *.klarnacdn.net *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com x.klarnacdn.net *.klarnaservices.com *.zdassets.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com landofcoder.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.google-analytics.com *.googletagmanager.com *.google.com *.dynatrace.com blob: *.unpkg.com unpkg.com *.bing.com bing.com facebook.net *.facebook.net *.mathtag.com mathtag.com ; style-src 'self' 'unsafe-inline'; img-src * data:;; frame-src 'self' *.doubleclick.net *.pinterest.com *.googleadservices.com *.google.com *.googletagmanager.com ; font-src * data:;; connect-src 'self' *.google-analytics.com *.googletagmanager.com *.google.com *.dynatrace.com *.star.com.au *.doubleclick.net *.bing.com www.facebook.com; report-uri /report-csp-violation 1 font-src https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.cloudfront.net *.fonts.googleapis.com data: *.cloudflare.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://seo.mageplaza.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors self www.google.com *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de www.google.com www.gstatic.com apis.google.com *.meetanshi.com *.addthis.com *.pinterest.com https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net https://firebasestorage.googleapis.com meetanshi.com *.cloudfront.net bat.bing.com *.facebook.com analytics.twitter.com t.co *.adroll.com *.google.co.in *.bidswitch.net pixel.tapad.com idsync.rlcdn.com dsum-sec.casalemedia.com pixel.rubiconproject.com sync.outbrain.com us-u.openx.net ups.analytics.yahoo.com image2.pubmatic.com sync.taboola.com ib.adnxs.com eb2.3lift.com match.adsrvr.org segments.company-target.com zdbb.net secure.adnxs.com *.reson8.com ml314.com *.kargo.com *.scorecardresearch.com sync-tm.everesttech.net match.prod.bidr.io *.turn.com pm.w55c.net *.rfihub.com tile.openstreetmap.org *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.fpdbs.sandbox.paypal.com *.addthis.com *.pinterest.com *.cdninstagram.com https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com *.meetanshi.com *.cloudfront.net bat.bing.com connect.facebook.net static.hotjar.com static.zdassets.com v2.zopim.com platform.twitter.com static.ads-twitter.com *.adroll.com *.googleadservices.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.pinterest.com *.instagram.com https://secure.2checkout.com https://2pay-js.2checkout.com https://secure.avangate.com *.cloudflare.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com downloads.mailchimp.com *.googleapis.com *.googletagmanager.com *.fontawesome.com *.google.com *.gstatic.com https://fonts.bunny.net *.cloudfront.net *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.meetanshi.com *.cloudfront.net bat.bing.com ekr.zdassets.com wss://widget-mediator.zopim.com *.adroll.com stats.g.doubleclick.net *.cloudflare.com *.addthis.com *.graph.instagram.com *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-VUAODJBLhwGl8S+Hn5y3XlBRsik=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' www.google.com www.googletagmanager.com www.gstatic.com production3.powermusic.com production3.royaltyfreefitnessmusic.com powermusic.com www.powermusic.com royaltyfreefitnessmusic.com www.royaltyfreefitnessmusic.com; report-uri /.webscale/csp-report 1 default-src 'none'; connect-src 'self' https://*.amazonaws.com https://*.mixpanel.com https://beekeeper.zendesk.com https://ekr.zdassets.com https://*.pubnub.com https://*.beekeeper.io https://www.google-analytics.com https://whatfix.com https://app.getsentry.com https://beekeeper-admins.zendesk.com https://dmq3e1ycjfyv0.cloudfront.net https://dohg09tgfgiar.cloudfront.net https://d3le1ht3gk5ng5.cloudfront.net https://d3vb2p6fp7o3q7.cloudfront.net https://d1zyzbapvzedyp.cloudfront.net https://d364zg7nlsantl.cloudfront.net https://d28hucnnny9kn3.cloudfront.net https://d2162mnpixjurq.cloudfront.net https://ddmptyeddd1ae.cloudfront.net wss://widget-mediator.zopim.com https://cdn.ravenjs.com; prefetch-src 'self' *.beekeeper.rocks *.dev.beekeeper.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://dmq3e1ycjfyv0.cloudfront.net https://dohg09tgfgiar.cloudfront.net https://d3le1ht3gk5ng5.cloudfront.net https://d3vb2p6fp7o3q7.cloudfront.net https://d1zyzbapvzedyp.cloudfront.net https://d364zg7nlsantl.cloudfront.net https://d28hucnnny9kn3.cloudfront.net https://d2162mnpixjurq.cloudfront.net https://ddmptyeddd1ae.cloudfront.net https://whatfix.com https://cdn.whatfix.com/prod/ https://*.beekeeper.io https://cdn.mxpnl.com https://cdn.ravenjs.com https://static.zdassets.com https://www.google-analytics.com/analytics.js https://www.recaptcha.net/recaptcha/ https://code.jquery.com https://www.gstatic.com/recaptcha/ https://ajax.googleapis.com/ajax/libs/jquery/ https://widget-mediator.zopim.com; frame-src 'self' blob: *.beekeeper.rocks *.dev.beekeeper.io https://whatfix.com https://www.google.com/recaptcha/ https://www.youtube.com https://player.vimeo.com https://mozbar.moz.com; style-src 'self' 'unsafe-inline' https://*.cloudfront.net https://*.beekeeper.io https://fonts.googleapis.com; font-src 'self' data: https://common.cdn.beekeeper.io https://*.cloudfront.net https://fonts.gstatic.com; img-src 'self' data: blob: https:; media-src 'self' blob: data: https://*.beekeeper.io https://*.cloudfront.net https://*.amazonaws.com; report-uri https://o4508014903361536.ingest.de.sentry.io/api/4508295318995024/security/?sentry_key=224567066b58c4389aa8f8fed87b30c5; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-xBXZjit0OTdB+iNcKjJRho7tRdk=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.typekit.net *.olark.com www.bugherd.com *.cloudfront.net fonts.gstatic.com *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com acs.airplus.com *.reviews.io *.reviews.co.uk *.tawk.to 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com widget.reviews.co.uk *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: accounts.google.com *.google.com/ *.hotjar.com *.olark.com widget.reviews.co.uk www.googletagmanager.com *.niceincontact.com td.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com js.mollie.com *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.bird.eu https://images.unsplash.com www.google.co.uk stats.g.doubleclick.net *.bing.com *.bing.net ib.adnxs.com *.olark.com services.postcodeanywhere.co.uk bugherd-attachments.s3.amazonaws.com *.cloudfront.net c.clarity.ms *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://www.magezon.com flagpedia.net https://www.mollie.com *.reviews.io *.reviews.co.uk *.tawk.to cdn.jsdelivr.net *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://maps.googleapis.com accounts.google.com *.olark.com *.google.com/ www.gstatic.com cdnjs.cloudflare.com *.hotjar.com bat.bing.com *.adnxs.com services.postcodeanywhere.co.uk *.pcapredict.com widget.reviews.co.uk www.bugherd.com *.cloudfront.net analytics.ahrefs.com www.clarity.ms cdn.cookie-script.com *.niceincontact.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com https://cdn.jsdelivr.net *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io maps.googleapis.com js.mollie.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.tawk.to cdn.jsdelivr.net *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com accounts.google.com *.typekit.net *.olark.com services.postcodeanywhere.co.uk *.cloudfront.net fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn.jsdelivr.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.tawk.to cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://maps.googleapis.com https://player.vimeo.com accounts.google.com google.co.uk google.com www.google.co.uk stats.g.doubleclick.net *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.reviews.co.uk *.olark.com bat.bing.com bat.bing.net services.postcodeanywhere.co.uk www.bugherd.com sessions.bugsnag.com wss://ws.pusherapp.com *.pusher.com analytics.ahrefs.com *.clarity.ms *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.cloudfront.net *.reviews.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.tawk.to wss://*.tawk.to *.google-analytics.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.prismic.io prismic.io prismic-io.s3.amazonaws.com hubspot-forms-static-embed-eu1.s3.amazonaws.com js.hs-scripts.com *.hsforms.net *.hsforms.com *.hs-scripts.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com *.hubspot.com exceptions-eu1.hs-embed-reporting.com js-eu1.hscta.net *.hsadspixel.net fonts.gstatic.com fonts.googleapis.com www.googleadservices.com googleads.g.doubleclick.net td.doubleclick.net www.googletagmanager.com www.google-analytics.com region1.google-analytics.com analytics.google.com *.analytics.google.com ajax.googleapis.com www.gstatic.com *.ads.linkedin.com stats.g.doubleclick.net www.linkedin.co www.google.com www.google.nl www.google.com.ph pagead2.googlesyndication.com maps.googleapis.com maps.gstatic.com api.hubapi.com connect.facebook.net www.facebook.com wss://ws.hotjar.com script.hotjar.com ws.hotjar.com *.hotjar.com content.hotjar.io *.hotjar.io api.taggrs.io sst.roscovision.com; 1 default-src 'self'; script-src 'self' 'nonce-cRPEKZ_RZ_g2cvhiTWnJqXWMz8qgYUXRwqjKRG1EBi7Bq-5AyezejQ' https://analytics.avv-augsburg.de https://cdn.eye-able.com https://translate-cdn.eye-able.com https://fahrtauskunft.avv-augsburg.de https://www.cdn.botfriendsx.com https://api.eu-1.smooch.io 'sha256-Pn59f+s+XVjLbIBPaKtcJMx+XrYnD9bly7kSRzkhfQw=' 'sha256-WMV6TCAKRqiJchBuLbDidJP71VKfKmtmQMLi2ITJGWY=' 'unsafe-eval' 'unsafe-inline' 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://cdn.eye-able.com https://www.cdn.botfriendsx.com https://www.gravatar.com https://analytics.vwork.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://kundencenter.avv-augsburg.de; style-src-elem 'self' https://cdn.eye-able.com https://www.cdn.botfriendsx.com 'unsafe-inline' 'report-sample'; connect-src 'self' https://fahrtauskunft.avv-augsburg.de https://analytics.avv-augsburg.de https://analytics.vwork.de https://translate.eye-able.com https://translate-cdn.eye-able.com https://www.cdn.botfriendsx.com https://690c5f9e0904877fe1afc770.config.eu-1.smooch.io https://cdn.jsdelivr.net https://api.eu-1.smooch.io wss://api.eu-1.smooch.io; font-src 'self' data: https://cdn.eye-able.com https://www.cdn.botfriendsx.com; media-src 'self' data: https://www.cdn.botfriendsx.com; style-src 'self' https://cdn.eye-able.com 'unsafe-inline' 'report-sample'; report-uri https://www.avv-augsburg.de/@http-reporting?csp=report&requestTime=1765934019598593&requestHash=b0258694d04841e018cd82ef21aac98a9d3afcfa 1 default-src https: wss: 'unsafe-inline' 'unsafe-eval' data:; report-uri https://sp.report-uri.com/r/default/csp/reportOnly 1 script-src 'nonce-LVRESlnX3ImU/ap/G4Tffg==' 'self' cdn.orsted.com *.googletagmanager.com *.app.cookieinformation.com cdn.appdynamics.com *.googletagmanager.com *.gstatic.com *.googleoptimize.com www.googleadservices.com *.googleapis.com *.bing.com *.doubleclick.net *.t.co *.pardot.com *.youtube.com *.linkedin.com *.twitter.com *.globenewswire.com *.23video.com delivery.twentythree.com orsted.containers.piwik.pro orsted.piwik.pro *.crazyegg.com unpkg.com cs.lf-discover.com *.puzzel.com *.arcgis.com code.jquery.com *.lfeeder.com orsted-global-graduate-programme.simplecast.com omny.fm cdnjs.cloudflare.com *.bootstrapcdn.com *.defgo.com *.defgo.net *.vimeo.com presscloud.com *.ritzau.dk *.simplecast.com *.elnet.danskenergi.dk *.sli.do *.audioboom.com *.licdn.com *.adsrvr.org *.soundcloud.com *.google.com *.google.com.my *.google.nl *.google.dk *.facebook.net; style-src 'nonce-LVRESlnX3ImU/ap/G4Tffg==' 'self' cdn.orsted.com fonts.googleapis.com; style-src-attr 'unsafe-inline' cdn.orsted.com; img-src 'self' data: cdn.orsted.com *.azureedge.net *.youtube.com *.23video.com delivery.twentythree.com www.googletagmanager.com *.lfeeder.com *.linkedin.com *.doubleclick.net *.pardot.com; media-src 'self' blob: cdn.orsted.com *.youtube.com *.23video.com delivery.twentythree.com; font-src 'self' data: fonts.gstatic.com cdn.orsted.com; frame-src *.app.cookieinformation.com *.youtube.com *.23video.com delivery.twentythree.com *.google.com *.google.nl *.googletagmanager.com *.doubleclick.net *.pardot.com; connect-src *.app.cookieinformation.com *.euroland.com *.eum-appdynamics.com *.googletagmanager.com *.google.com *.doubleclick.net *.googleadservices.com *.crazyegg.com *.linkedin.com orsted.piwik.pro *.pardot.com; worker-src 'self'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' domidona.com.br *.domidona.com.br wake-components.fbitsstatic.net domidona.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.ebit.com.br imgs.ebit.com.br *.sizebay.technology *.widde.io static.sizebay.technology *.trustvox.com.br *.hotjar.com *.cartstack.com.br *.tiktok.com *.rdstation.com.br *.g.doubleclick.net *.googleadservices.com *.google.com.br *.pagar.me *.mundipagg.com pageview-notify.rdstation.com.br rdstation.com.br popups.rdstation.com.br cta-redirect.rdstation.com *.amazonaws *.s3.amazonaws.com *.getnet.com.br trustvox.com.br static.trustvox.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com ipinfo.io *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net *.clarity.ms bt-wake-connector.com.br clarity.ms n.clarity.ms q.clarity.ms s.clarity.ms *.pagaleve.com.br external-api.pagaleve.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.ecomgrowth.com.br *.api.domidona.com.br servidor.domidona.com.br *.domidona.com.br *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.domidona.com.br domidona.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 base-uri 'self'; connect-src 'self' https://search.yieldgiving.com https://cdn.usefathom.com; default-src 'self'; form-action 'self'; img-src 'self' https://cdn.usefathom.com data: https:; media-src 'self'; object-src 'self'; script-src 'self' 'sha256-OMh3Ykndq7805Lhx6z77ubKOQ4nrztlTFzDkljjSmvU=' 'sha256-4tC2rhASw1F93uExSWYFrXV57pUM4Z56o07VqGXuXB4=' 'sha256-PEZXPk6kGFBHiqR3QxjwQ/34ybKyazG8967/ZkjIgks=' 'sha256-42RKS4wuARLi310BKqe6P+aej6Rnc9Bjp9iYc6o8sAU=' 'sha256-/6wU5WORTQOOQ0pvGRjqJiyg6v0sVj4xmD+Zdri3S8s=' 'sha256-HE2AVZSba4+Z99iWdZVF6efM3Cpx0epqBq3GyipWa5Y=' 'sha256-QCGmXP9pPIvAzrB5VyrPjs6sZul1yKOe1ZyXKo++Lxs=' https://cdn.usefathom.com/script.js https://static.cloudflareinsights.com;style-src 'self' 'unsafe-inline' 'unsafe-hashes'; frame-src 'self'; frame-ancestors 'self'; report-uri https://yieldg.report-uri.com/r/d/csp/reportOnly; 1 default-src *.retelit.it *.irideos.it *.clouditalia.com 'self' cdnjs.cloudflare.com 'unsafe-inline' cdn.datatables.net www.googletagmanager.com *.cookiebot.com *.google-analytics.com fonts.gstatic.com code.ionicframework.com *.googleapis.com www.google.com www.gstatic.com maxcdn.bootstrapcdn.com *.kolst.com code.jquery.com netdna.bootstrapcdn.com *.matomo.cloud; report-to csp~www.kolst.com 1 default-src 'self' ; media-src 'self' http: https: ; connect-src 'self' http: https: ; frame-src 'self' http: https: ; font-src 'self' http: https: data: ; img-src 'self' http: https: data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' http://tagmanager.google.com http://api.b.st-hatena.com http://bookmark.hatenaapis.com http://b.st-hatena.com http://www.google.com http://*.google-analytics.com http://*.g.doubleclick.net http://www.googleadservices.com http://www.googletagmanager.com http://graph.facebook.com http://ajax.googleapis.com http://api.docodoco.jp http://svss.tv http://s.yjtag.jp http://yjtag.yahoo.co.jp http://bake.surfpoint.jp http://connect.facebook.net http://*.eir-parts.net http://cdnjs.cloudflare.com http://s.ytimg.com http://www.pagespeed-mod.com http://www.clarity.ms http://d.line-scdn.net https://tagmanager.google.com https://api.b.st-hatena.com https://bookmark.hatenaapis.com https://b.st-hatena.com https://www.google.com https://*.google-analytics.com https://*.g.doubleclick.net https://www.googleadservices.com https://www.googletagmanager.com https://graph.facebook.com https://ajax.googleapis.com https://api.docodoco.jp https://svss.tv https://s.yjtag.jp https://yjtag.yahoo.co.jp https://bake.surfpoint.jp https://connect.facebook.net https://*.eir-parts.net https://cdnjs.cloudflare.com https://s.ytimg.com https://www.pagespeed-mod.com https://www.clarity.ms https://d.line-scdn.net ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' http://tagmanager.google.com http://api.b.st-hatena.com http://bookmark.hatenaapis.com http://b.st-hatena.com http://www.google.com http://*.google-analytics.com http://*.g.doubleclick.net http://www.googleadservices.com http://www.googletagmanager.com http://graph.facebook.com http://ajax.googleapis.com http://api.docodoco.jp http://svss.tv http://s.yjtag.jp http://yjtag.yahoo.co.jp http://bake.surfpoint.jp http://connect.facebook.net http://*.eir-parts.net http://cdnjs.cloudflare.com http://s.ytimg.com http://www.pagespeed-mod.com http://www.clarity.ms http://d.line-scdn.net https://tagmanager.google.com https://api.b.st-hatena.com https://bookmark.hatenaapis.com https://b.st-hatena.com https://www.google.com https://*.google-analytics.com https://*.g.doubleclick.net https://www.googleadservices.com https://www.googletagmanager.com https://graph.facebook.com https://ajax.googleapis.com https://api.docodoco.jp https://svss.tv https://s.yjtag.jp https://yjtag.yahoo.co.jp https://bake.surfpoint.jp https://connect.facebook.net https://*.eir-parts.net https://cdnjs.cloudflare.com https://s.ytimg.com https://www.pagespeed-mod.com https://www.clarity.ms https://d.line-scdn.net ; style-src 'self' 'unsafe-inline' http://tagmanager.google.com http://fonts.googleapis.com http://svss.tv http://*.eir-parts.net https://tagmanager.google.com https://fonts.googleapis.com https://svss.tv https://*.eir-parts.net https://cdn.jsdelivr.net ; report-uri https://strike.report-uri.com/r/d/csp/reportOnly ; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-lF2sQV7QQ407JmGV/DV1fVda2pM=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-N67uVedI5S-gbp5K1Fz0jQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-6luCWcb+oYHmNP62ygUjKEsa1uE=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://cdnjs.cloudflare.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.typekit.net *.twimg.com *.trustedshops.com *.netreviews.eu 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.twitter.com https://www.google.com https://www.google.co.in https://www.facebook.com *.netreviews.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.yotpo.com *.cloudflare.com *.gstatic.com *.google.com *.google.co.in https://www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.connect.facebook.net https://stats.g.doubleclick.net *.youtube.com https://d.adroll.com https://pixel.advertising.com https://pixel.rubiconproject.com https://simage2.pubmatic.com https://dsum-sec.casalemedia.com https://ads.yahoo.com https://eb2.3lift.com https://sync.outbrain.com https://trc.taboola.com https://x.bidswitch.net/sync https://ib.adnxs.com https://idsync.rlcdn.com https://us-u.openx.net https://ups.analytics.yahoo.com https://segments.company-target.com https://sync.tidaltv.com *.avis-verifies.com *.netreviews.eu 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://connect.facebook.net *.paypalobjects.com *.paypal.com https://chimpstatic.com *.googletagmanager.com *.youtube.com https://s.adroll.com https://d.adroll.com https://d.adroll.mgr.consensu.org *.avis-verifies.com *.netreviews.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.cloudflare.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.youtube.com *.avis-verifies.com *.netreviews.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.google.co.in *.facebook.com *.netreviews.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://magento2.fr/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com staticw2.yotpo.com channels.magento.com ws1.postescanada-canadapost.ca fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com data: *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com seeds24.at seeds24.de seeds24.ch growversand24.de data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com ws1.postescanada-canadapost.ca *.facebook.com *.twitter.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; frame-ancestors seeds24.at seeds24.de seeds24.ch growversand24.de 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com vars.hotjar.com www.facebook.com ws1.postescanada-canadapost.ca cdn.dnky.co *.hotjar.com *.google.com/ *.facebook.com *.trustpilot.com *.criteo.com *.youtube.com/ https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.payu.com merch-prod.snd.payu.com seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io data: online.swagger.io cdn.ofsys.com p.yotpo.com maps.gstatic.com maps.googleapis.com mageside.com www.facebook.com ad.doubleclick.net adservice.google.com stats.g.doubleclick.net www.google.com.pk ws1.postescanada-canadapost.ca js.hs-scripts.com x.bidswitch.net dsum-sec.casalemedia.com sync-eu.connectad.io as.ad4m.at e1.emxdgt.com s-cs.rmp.rakuten.co ad.360yield.com dsum.casalemedia.com us-u.openx.net rtb-csync.smartadserver.com c1.adform.net sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com csync.loopme.me cdn.doofinder.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com *.googleapis.com *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net https://platform-api.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.maps.gstatic.com https://clauem2.arrowtheme.com https://scontent.cdninstagram.com/ https://buttons-config.sharethis.com https://l.sharethis.com https://platform-cdn.sharethis.com https://scontent-ams4-1.cdninstagram.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.payu.com seeds24.at seeds24.de seeds24.ch growversand24.de data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com staticw2.yotpo.com www.google.com www.gstatic.com maps.gstatic.com maps.googleapis.com static.hotjar.com connect.facebook.net channels.magento.com cdn.wootric.com script.hotjar.com ws1.postescanada-canadapost.ca js.hs-scripts.com eu1-config.doofinder.com t.adcell.com pix.hyj.mobi ad4m.at admin.qebo.ai cdn.doofinder.com *.paypal.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com *.cloudflare.com *.twitter.com *.twimg.com *.usercentrics.eu *.maps.googleapis.com *.google.com/ *.maps.gstatic.com https://connect.facebook.net https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com secure.payu.com secure.snd.payu.com seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com staticw2.yotpo.com channels.magento.com ws1.postescanada-canadapost.ca js.hs-scripts.com *.doofinder.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com data seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; object-src seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; media-src *.adobe.com seeds24.at *.zopim.com www.nirvanashop.com seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; manifest-src seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com staticw2.yotpo.com w2.yotpo.com eligibility.wootric.com channels.magento.com in.hotjar.com ws1.postescanada-canadapost.ca js.hs-scripts.com t.adcell.com as.ad4m.at *.doofinder.com wss://*.doofinder.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com secure.payu.com merch-prod.snd.payu.com api.fbanalytics.org seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com seeds24.at seeds24.de seeds24.ch growversand24.de http: https: blob: 'self' 'unsafe-inline'; default-src fonts.googleapis.com ws1.postescanada-canadapost.ca seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri seeds24.at seeds24.de seeds24.ch growversand24.de 'self' 'unsafe-inline'; 1 object-src 'none'; connect-src 'self' *.oopsie.com *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.oopsie.com *.adulttime.com join.gammasecure.com; script-src 'self' *.oopsie.com *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.oopsie.com *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com *.tradecentric.com https://*.svea.com https://*.vipps.no 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com *.tradecentric.com https://*.svea.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://info.dibs.se ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.superoffice.com *.tradecentric.com *.punchout2go.com *.nxcli.io *.pagesense.io *.facebook.net *.de17a.com *.licdn.com *.matomo.cloud *.linkedin.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.dibspayment.eu chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.tradecentric.com https://*.svea.com *.superoffice.com *.nxcli.io *.pagesense.io *.facebook.net *.de17a.com *.licdn.com *.matomo.cloud *.linkedin.com *.facebook.com rodin.no googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.fontawesome.com https://*.dibspayment.eu downloads.mailchimp.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.tradecentric.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://*.dibspayment.eu https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.superoffice.com *.tradecentric.com *.punchout2go.com *.nxcli.io *.pagesense.io *.facebook.net *.de17a.com *.licdn.com *.matomo.cloud *.linkedin.com *.facebook.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-Nm5hJzITs5jqOyyIbxDz5PYvYgg=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self' glenville.edu www.glenville.edu; script-src 'self' glenville.edu *.glenville.edu *.googletagmanager.com static.addtoany.com *.google-analytics.com sky.blackbaudcdn.net bbox.blackbaudhosting.com *.cognitoforms.com cdnjs.cloudflare.com *.gstatic.com glenville.omnilert.net embed.financialaidtv.com js.adsrvr.org *.adsrvr.org unpkg.com *.facebook.net *.google.com *.brandcdn.com *.jsdelivr.net *.blackbaud.com code.jquery.com stcadencechatprodassets.blob.core.windows.net mongoose.botpress.cloud cdn.botpress.cloud mongoose.botpress.cloud 'unsafe-eval' 'unsafe-inline'; style-src 'self' glenville.edu *.glenville.edu unpkg.com use.fontawesome.com fonts.googleapis.com bbox.blackbaudhosting.com payments.blackbaud.com *.cognitoforms.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.botpress.cloud mongoose.botpress.cloud stcadencechatprodassets.blob.core.windows.net 'unsafe-inline'; img-src 'self' glenville.edu *.glenville.edu *.googletagmanager.com *.google-analytics.com bbox.blackbaudhosting.com insight.adsrver.org *.adsrvr.org i.ytimg.com *.fontawesome.com fonts.gstatic.com *.addthis.com *.agkn.com secure-gl.imrworldwide.com dsum-sec.casalemedia.com uipglob.semasio.net odr.mookie1.com track2.securedvisit.com dpm.demdex.net pixel.rubiconproject.com *.doubleclick.net ib.adnxs.com eb2.3lift.com cfvod.kaltura.com mongoose.botpress.cloud cdn.botpress.cloud mediafiles.botpress.cloud stcadencechatprodassets.blob.core.windows.net data: blob:; media-src 'self' glenville.edu *.glenville.edu data:; frame-src 'self' *.panopto.com *.cognitoforms.com gsc.tandem.co *.youtube.com static.addtoany.com *.adsrvr.org *.google.com bbox.blackbaudhosting.com payments.blackbaud.com *.googletagmanager.com host.nxt.blackbaud.com *.brandcdn.com *.cloudfront.net *.financialaidtv.com *.facebook.com embed.ocelotbot.com cdn.yoshki.com *.youtube-nocookie.com player.vimeo.com generationwv.org mongoose.botpress.cloud cdn.botpress.cloud; child-src mongoose.botpress.cloud cdn.botpress.cloud; font-src 'self' glenville.edu *.glenville.edu fonts.googleapis.com fonts.gstatic.com use.fontawesome.com *.cognitoforms.com use.typekit.net data:; connect-src 'self' glenville.edu *.glenville.edu *.google-analytics.com insight.adsrvr.org *.adsrvr.org *.cognitoforms.com stats.addtoany.com *.google.com payments.blackbaud.com mongoose.botpress.cloud cdn.botpress.cloud api.botpress.cloud mediafiles.botpress.cloud data:; report-uri /report-csp-violation 1 default-src 'self' *.neovialogistics.com 1 default-src 'none'; frame-ancestors 'none'; form-action 'none'; upgrade-insecure-requests; block-all-mixed-content; disown-opener; report-uri https://loans2gowebsites.report-uri.com/r/t/csp/wizard 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://use.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.paypal.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com s7.addthis.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com https://use.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com ekr.zdassets.com/ *.doubleclick.net *.googlesyndication.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es validate.fishpig.co.uk https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io www.xtento.com cdn.xtento.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com https://fonts.bunny.net yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://get.geojs.io *.avada.io yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.slant.co www.anthonyformalwear.co.uk data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.anthonyformalwear.co.uk 'self' 'unsafe-inline'; frame-ancestors www.anthonyformalwear.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com webservices.securetrading.net cdn.eu.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com *.stripe.com *.hcaptcha.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.anthonyformalwear.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com *.doubleclick.net *.facebook.com *.facebook.net *.google.com www.google.co.in www.google.co.uk www.google.com.au www.google.com.tr www.google.pl www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.fbcdn.net maps.googleapis.com www.anthonyformalwear.co.uk www.google.com.cy www.google.co.id www.google.es www.google.com.co www.google.co.za *.pinterest.com www.google.lt www.google.com.sg www.google.nl www.google.is www.google.co.nz www.google.ge www.google.com.eg www.google.al www.google.ro www.google.com.br www.google.cg www.google.no www.google.com.bd www.google.fi www.google.ie www.google.co.ke www.google.kz www.google.co.ug www.google.com.ph www.google.je www.google.ae www.google.com.pg www.google.dk www.google.com.uy www.google.se www.google.pt www.google.be www.google.co.il www.google.com.mx www.google.mu www.google.me www.google.it www.google.com.sa www.google.ch www.google.cz www.google.co.th www.google.ee www.google.co.kr www.google.com.hk www.google.hu www.google.co.bw www.google.com.pr www.google.iq www.google.bg www.google.ca www.google.com.my www.google.com.pk www.google.gr www.google.fr www.google.de www.google.com.ng data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.facebook.net *.gstatic.com *.pinimg.com *.pinterest.com *.stripe.com *.hcaptcha.com *.cdninstagram.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com unpkg.com *.instagram.com maps.googleapis.com www.anthonyformalwear.co.uk *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.stripe.com *.hcaptcha.com assets.braintreegateway.com tagmanager.google.com www.anthonyformalwear.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com www.anthonyformalwear.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.doubleclick.net *.facebook.com *.pinterest.com localhost www.google.co.uk www.google.com.au www.google.pl api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com www.anthonyformalwear.co.uk www.google.nl www.google.bg www.google.pt www.google.fr www.google.ae www.google.co.in www.google.gr www.google.ro www.google.es www.google.co.bw www.google.com.br www.google.no www.google.je www.google.com.pk www.google.lt www.google.ge www.google.dk www.google.ie www.google.de www.google.co.id www.google.co.za www.google.me www.google.it www.google.fi www.google.cg www.google.be www.google.com.ng www.google.com.ph www.google.com.cy 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.anthonyformalwear.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.anthonyformalwear.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://681dbb88-4b59-4ee2-bb39-539292231fd0.sansec.watch/; report-to report-endpoint; 1 report-uri https://uspheader.report-uri.com/r/d/csp/reportOnly;font-src https://fonts.gstatic.com/ 'self';script-src-elem 'unsafe-inline' https://cdn.cookie-script.com/ 'self' https://npmcdn.com/ https://cdn.datatables.net/ https://cdnjs.cloudflare.com/ https://code.jquery.com/;style-src-elem https://fonts.googleapis.com/ https://cdnjs.cloudflare.com 'unsafe-inline' 'self';script-src 'unsafe-inline' https://code.jquery.com/ 'self';style-src 'unsafe-inline' 'self';style-src-attr 'unsafe-inline' 'self';script-src-attr 'unsafe-inline' 'self';base-uri 'self';connect-src 'self';default-src 'self';form-action 'self';img-src 'self';media-src 'self';object-src 'none' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://test.transafe.com https://post.live.transafe.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://test.transafe.com https://post.live.transafe.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com *.avada.io *.shopify.com https://test.transafe.com https://post.live.transafe.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://use.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io https://olegnax.com https://api.instagram.com https://graph.instagram.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src maxcdn.bootstrapcdn.com *.fontawesome.com fonts.gstatic.com pro.fontawesome.com https://cdnjs.cloudflare.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de facebook.com www.facebook.com youtube.com www.youtube.com platform.twitter.com google.com js.stripe.com cdn.dnky.co webchat.dotdigital.com api.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.apptrian.com www.facebook.com data: *.twitter.com *.googleapis.com google.com *.gstatic.com *.snapppt.com *.paypal.com *.sc.omtrdc.net *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com *.googleapis.com google.com *.google.com *.gstatic.com cdn.ampproject.org www.googletagmanager.com googletagmanager.com platform.twitter.com *.snapppt.com *.fontawesome.com *.stripe.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io https://cdnjs.cloudflare.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com getfirebug.com *.fontawesome.com *.googleapis.com google.com *.gstatic.com www.google-analytics.com cdn.dnky.co webchat.dotdigital.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com connect.facebook.net graph.facebook.com https://www.paypal.com/xoplatform/logger/api/logger *.paypal.com cdn.ampproject.org snapppt.com *.google-analytics.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.cloudflare.com *.google.com *.googleapis.com *.bootstrapcdn.com *.cloudmaestro.com *.googletagmanager.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.bootstrapcdn.com *.godaddy.com *.cloudmaestro.com d10lpsik1i8c69.cloudfront.net *.doubleclick.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.chimpstatic.com downloads.mailchimp.com *.list-manage.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.doubleclick.net *.addtoany.com *.cloudflare.com *.google.com *.googleadservices.com *.google-analytics.com *.fontawesome.com *.paypalobjects.com *.paypal.com *.googletagmanager.com *.bootstrapcdn.com seal.godaddy.com *.cloudmaestro.com d10lpsik1i8c69.cloudfront.net *.ctctcdn.com *.ipdata.co *.newrelic.com *.nr-data.net *.klaviyo.com *.kaptcha.com *.addthis.com *.crazyegg.com *.pinimg.com *.pinterest.com *.facebook.com *.livechatinc.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.cloudflare.com *.googleapis.com *.google.com *.gstatic.com *.fontawesome.com *.youtube.com *.bootstrapcdn.com *.cloudmaestro.com d10lpsik1i8c69.cloudfront.net *.ctctcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://analytics.google.com https://api.livechatinc.com https://assets.braintreegateway.com https://b.stats.paypal.com https://bam.nr-data.net https://c.paypal.com https://c6.paypal.com https://cdn.livechatinc.com https://chimpstatic.com https://client-analytics.braintreegateway.com https://collect.tealiumiq.com https://connect.facebook.net https://ct.pinterest.com https://fonts.gstatic.com https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://js.braintreegateway.com https://lvs.stats.paypal.com https://payments.braintree-api.com https://pixel.sitescout.com https://s.pinimg.com https://script.crazyegg.com https://script.hotjar.com https://secure.livechatinc.com https://static.hotjar.com https://stats.g.doubleclick.net https://tags.tiqcdn.com https://td.doubleclick.net https://visitor-service.tealiumiq.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.paypalobjects.com https://*.twpinc.com *.crazyegg.com *.addthis.com *.cloudflare.com *.google.com wss://visitors.live wss://in.visitors.live *.luckyorange.net *.nr-data.net *.doubleclick.net *.kaptcha.com *.pinimg.com *.pinterest.com *.livechatinc.com *.googletagmanager.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src d10lpsik1i8c69.cloudfront.net blob: *.googletagmanager.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a1d80435-4e21-470f-aed0-a54f39d4d350.sansec.watch/; report-to report-endpoint; 1 font-src *.feedbackcompany.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.feedbackcompany.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sendcloud.sc *.jsdelivr.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedbackcompany.com 'self' data: *.amazonaws.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedbackcompany.com *.sendcloud.sc *.jsdelivr.net *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.googleapis.com *.sendcloud.sc *.jsdelivr.net *.sooqr.com *.spotlersearch.com *.multisafepay.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.feedbackcompany.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: blob: https://*.experimentation.dev:* https://tbs.tradedoubler.com:* https://*.scene7.com:* https://*.stenaline.com:* https://stenalinetravel.com:* wss://api.ebilobster.ai:*; script-src 'unsafe-inline' 'unsafe-eval' blob: https://static.experimentation.dev:* https://stenalinescandinaviaab.d3.sc.omtrdc.net:* https://*.kameleoon.io:* https://*.kameleoon.eu:* https://*.kameleoon.com:* https://*.kameleoon.net:* https://*.scene7.com:* https://sembo-inspire-apis.sembo.travel:*/stenaline-search-component/latest/stenaline-search-component.js https://challenges.cloudflare.com:*/turnstile/v0/api.js https://www.google.com:*/recaptcha/api.js https://www.gstatic.com:*/recaptcha/releases/ https://analytics.tiktok.com:* https://widget.trustpilot.com:* https://p.teads.tv:*/teads-fellow.js https://bat.bing.com:* https://googleads.g.doubleclick.net:* https://acrobatservices.adobe.com:* https://cdn.cookielaw.org:* https://*.mouseflow.com:* https://documentservices.adobe.com:* https://www.google-analytics.com:* https://www.googletagmanager.com:* https://connect.facebook.net:* https://messenger.ebilobster.ai:* https://www.stenalinetravel.com/etc.clientlibs:* https://www.stenalinetravel.com:* https://*.stenaline.com:* https://*.stenalinetravel.com:* https://stenaline.com:* https://assets.adobedtm.com:*; img-src data: https: https://static.experimentation.dev:* https://*.scene7.com:*; style-src 'self' 'unsafe-inline' https://static.experimentation.dev:* https://*.scene7.com:* https://acrobatservices.adobe.com:* https://*.stenaline.com:* https://stenaline.com:* https://stenalinetravel.com:*; object-src 'none'; frame-ancestors 'self' https://static.experimentation.dev:* https://*.stenaline.com https://*.stenalinetravel.com 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-NjE4MDU3OGYtOWQxZS00ZjRjLTllMDEtY2Q3MGNkMjA2NTlh' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 object-src 'none'; connect-src 'self' *.lethalhardcore.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.lethalhardcore.com join.gammasecure.com; script-src 'self' *.lethalhardcore.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.lethalhardcore.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.consensu.org *.sharethis.com https://www.googletagmanager.com/ *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl *.cookiebot.eu www.kiyoh.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.sooqr.com *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl *.googlesyndication.com *.reloadify.com *.taggrs.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.google.com *.sharethis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.sooqr.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.paypal.com chimpstatic.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl *.cookiebot.eu *.reloadify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.sooqr.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.mailcampaigns.nl *.visualstudio.com *.pinterest.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.doubleclick.net *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com tipdebruin.nl *.tipdebruin.nl tip.stage.qlicks.nl *.googlesyndication.com *.reloadify.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-5C9GvVBlOcCBNXI00vMt36ho0G8=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://pagead2.googlesyndication.com https://tpc.googlesyndication.com https://adservice.google.com https://googleads.g.doubleclick.net https://*.fundingchoicesmessages.google.com https://cdn.cookielaw.org https://cdn.jsdelivr.net https://unpkg.com https://*.privacy-center.org; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https: http:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://*.google.com https://*.googlesyndication.com https://*.googleadservices.com https://*.doubleclick.net https://pagead2.googlesyndication.com https://*.fundingchoicesmessages.google.com wss://*.uakor.com https://uakor.com https://api.uakor.com; frame-src 'self' https://www.google.com https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://*.fundingchoicesmessages.google.com https://www.youtube.com https://player.vimeo.com; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; object-src 'none'; worker-src 'none'; media-src 'self' blob: data:; manifest-src 'self' 1 base-url *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch; font-src fonts.googleapis.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.gstatic.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com maps.googleapis.com maps.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch 'self' data: *.google.com *.google.fr *.google.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.google.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com googleads.g.doubleclick.net *.skypack.dev 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch 'self' 'unsafe-inline'; manifest-src *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch t.elasticsuite.io *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.doubleclick.net 'self' 'unsafe-inline'; child-src *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch http: https: blob: 'self' 'unsafe-inline'; default-src *.romapps.com *.gymnova.com *.gympassion.be *.gymnova.ch *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src-elem *.google-analytics.com clarity.ms https://consent.cookiebot.com/ https://consentcdn.cookiebot.com/ https://js.monitor.azure.com/ https://www.google.com https://www.googletagmanager.com/ https://www.gstatic.com 'self' 'unsafe-inline';connect-src *.google-analytics.com clarity.ms google-analytics.com https://consentcdn.cookiebot.com/ https://js.monitor.azure.com/ https://westeurope-5.in.applicationinsights.azure.com https://www.google.com region1.analytics.google.com 'self' stats.g.doubleclick.net;script-src clarity.ms google-analytics.com/analytics.js https://www.googletagmanager.com/;font-src data: fast.fonts.net 'self';media-src https://*.vimeocdn.com player.vimeo.com;object-src 'none' 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-tVa2Q1M4Nc7oCSzRPx1+57w/RAw=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 font-src *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://storage.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem m2.staging.rmacleod.co.uk.cfstack.com m2.dev.rmacleod.co.uk.cfstack.com rmacleod.co.uk www.rmacleod.co.uk fonts.googleapis.com *.fontawesome.com fonts.bunny.net use.typekit.net p.typekit.net cdnjs.cloudflare.com cdn.jsdelivr.net; font-src *.fontawesome.com m2.staging.rmacleod.co.uk.cfstack.com m2.dev.falcon.pirstack.com rmacleod.co.uk www.rmacleod.co.uk fonts.gstatic.com use.typekit.net p.typekit.net fonts.bunny.net static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://hpp.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://secure-test.worldpay.com/shopper/3ds/ddc.html https://secure.worldpay.com/shopper/3ds/ddc.html https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate rmacleod.co.uk 'self' 'unsafe-inline'; frame-ancestors https://pay.google.com/ rmacleod.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * live.opayo.eu.elavon.com *.opayo.co.uk *.elavon.com secure7.arcot.com *.arcot.com www.googletagmanager.com https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://pay.google.com https://secure-test.worldpay.com https://hpp.worldpay.com/ https://www.paypal.com/sdk/js rmacleod.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com m2.staging.rmacleod.co.uk.cfstack.com m2.dev.falcon.pirstack.com rmacleod.co.uk www.rmacleod.co.uk d3k81ch9hvuctc.cloudfront.net *.cloudflare.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com m2.staging.rmacleod.co.uk.cfstack.com m2.dev.rmacleod.co.uk.cfstack.com rmacleod.co.uk www.rmacleod.co.uk cdnjs.cloudflare.com https://www.google.com/recaptcha/api.js *.gstatic.com *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://www.paypal.com/sdk/js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com unsafe-inline assets.braintreegateway.com m2.staging.rmacleod.co.uk.cfstack.com m2.dev.rmacleod.co.uk.cfstack.com rmacleod.co.uk www.rmacleod.co.uk cdnjs.cloudflare.com cdn.jsdelivr.net use.typekit.net p.typekit.net *.cloudflare.com https://fonts.googleapis.com/css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com rmacleod.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com m2.staging.rmacleod.co.uk.cfstack.com m2.dev.falcon.pirstack.com rmacleod.co.uk www.rmacleod.co.uk api-js.datadome.co cdnjs.cloudflare.com *.doofinder.com https://www.google.com/pay https://pay.google.com/gp/p/web_manifest.json https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/ https://google.com/pay *.worldpay.com https://hpp.worldpay.com/app/hpp/135-0/telemetry https://hpp.worldpay.com/app/hpp/135-0/payment/paypalsmartbutton/continue https://www.paypal.com/sdk/js https://payments.worldpay.com/app/hpp/135-0/telemetry/iframe 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com rmacleod.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src rmacleod.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' 'nonce-wMDrMlpUpiyoDkaabm17/Q==' 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://duat45vx86ndn.cloudfront.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://www.recaptcha.net; script-src-attr 'self'; script-src-elem * 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-uri https://libertynetworks.com/report-uri/enforce 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.googleapis.com; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-YmQ5Zjg4YTQtNGI0Mi00Y2Y2LWE5MGUtYzNjN2IwZDMzNzBm' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 script-src 'self' 'nonce-Oe0+PS8x68nzqXzgJpCaHrnFb8INultTCbeaIR89hBs=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'self'; img-src * data: blob:; style-src * 'unsafe-inline' blob: https://fonts.bunny.net; font-src 'self' data: https://fonts.bunny.net https://fonts.gstatic.com https://cuatro.sim-cdn.nl https://cuatro.sim-cdn-acceptatie.nl https://cuatro.sim-cdn-test.nl; script-src 'nonce-YzhiNjJhNzktYzlhMC00ZmU2LTljYTktYmVlNWIyZmJhYmNl' 'strict-dynamic' 'report-sample'; connect-src *; form-action 'self'; media-src https://*.readspeaker.com https://*.streamlock.net https://storage.googleapis.com https://scribit-pro-hosting.storage.googleapis.com https://scribit-pro.storage.googleapis.com https://app.talkjs.com 'self' blob:; frame-src *; frame-ancestors 'self'; worker-src * 'unsafe-inline' blob:; report-uri /api/csp-report 1 default-src 'self' blob: https://k-eu1.az.contentsquare.net/ https://www.google-analytics.com https://e.clarity.ms/ https://media.lifeinside.io/ https://forms-na1.hubspot.com/ https://pagead2.googlesyndication.com/ https://laucupgy.eup.stape.io/ https://region1.analytics.google.com/ https://knowitexperiencefinland.piwik.pro/ https://forms.hubspot.com/ https://api.hubapi.com/ https://forms.hscollectedforms.net/ https://cta-service-cms2.hubspot.com/ https://analytics.bnxtrk.com/ https://px.ads.linkedin.com/ https://googleads.g.doubleclick.net/ https://knowit.piwik.pro/ https://www.google.com/ https://region1.google-analytics.com/ https://consent.app.cookieinformation.com/ https://hubspot-forms-static-embed.s3.amazonaws.com/ https://js.hsforms.net/ https://forms.hsforms.com/ https://publish.ne.cision.com/ https://dhm5hy2vn8l0l.cloudfront.net/ https://policy.app.cookieinformation.com/ https://esp-eu.aptrinsic.com/ https://dl.episerver.net/ https://web-sdk-eu.aptrinsic.com/ https://www.googletagmanager.com/ https://dc.services.visualstudio.com/ wss://inte.knowit.se/EPiServer/Shell/socket/endpoint/ knowit.se *.knowit.se knowit.se/episerver knowit.no *.knowit.no knowit.no/episerver knowit.fi *.knowit.fi knowit.fi/episerver knowit.dk *.knowit.dk knowit.dk/episerver knowit.de *.knowit.de knowit.de/episerver knowit.pl *.knowit.pl knowit.pl/episerver knowit.eu *.knowit.eu knowit.eu/episerver; base-uri 'self'; style-src 'self' https://bot.zmashsolutions.com/ https://maxcdn.bootstrapcdn.com/ https://cdn.jsdelivr.net/ https://js-na1.hs-scripts.com/ https://web-sdk-eu.aptrinsic.com/ 'unsafe-inline' https://cdn.jsdelivr.net https://widget.datablocks.se/api/rose/assets/ https://widget.datablocks.se/api/rose/widgets/; script-src 'self' *.contentsquare.net app.contentsquare.com https://widget.lifeinside.io/ https://script.hotjar.com/ https://t.contentsquare.net/ https://app.lifeinside.io/ https://bot.zmashsolutions.com/ https://www.youtube.com/ https://secure.slim2disc.com/ https://www.google-analytics.com/ https://googleads.g.doubleclick.net/ https://www.clarity.ms/ https://siteimproveanalytics.com/ https://knowitexperiencefinland.piwik.pro/ https://sc.lfeeder.com/ https://static.hotjar.com/ https://cdn.jsdelivr.net/ https://maxcdn.bootstrapcdn.com/ https://cdnjs.cloudflare.com/ https://code.jquery.com/ https://js-na1.hs-scripts.com/ https://js.hubspotfeedback.com/ https://js.hs-banner.com/ https://js.hsadspixel.net/ https://js.hsleadflows.net/ https://js.hs-analytics.net/ https://js.hubspot.com/ https://js.hscollectedforms.net/ https://d2hya7iqhf5w3h.cloudfront.net/ https://snap.licdn.com/ https://connect.facebook.net/ https://knowit.piwik.pro/ https://extend.vimeocdn.com/ https://js.hs-scripts.com/ https://www.gstatic.com/ https://region1.google-analytics.com/ https://www.google.com/ https://js.hsforms.net/ https://www.eventbrite.co.uk/ https://dl.episerver.net/ https://policy.app.cookieinformation.com/ https://web-sdk-eu.aptrinsic.com/ https://www.googletagmanager.com/ https://dc.services.visualstudio.com/ https://widget.datablocks.se/api/rose/assets/ https://widget.datablocks.se/api/rose/widgets/ 'unsafe-eval' 'unsafe-inline' ; img-src 'self' data: *.contentsquare.net https:; frame-src 'self' https://embed.acast.com/ https://bot.zmashsolutions.com/ https://td.doubleclick.net/ https://app.hubspot.com/ https://forms.hsforms.com/ https://www.eventbrite.co.uk/ https://www.google.com/ https://open.spotify.com/ https://policy.app.cookieinformation.com/ https://player.vimeo.com/ https://irs.tools.investis.com/ https://www.youtube.com/ https://www.youtube-nocookie.com/; frame-ancestors 'self'; connect-src 'self' https://api.hubapi.com/ https://cta-service-cms2.hubspot.com/ https://forms.hubspot.com/ https://analytics.bnxtrk.com/ https://knowit.piwik.pro/ https://px.ads.linkedin.com/ https://region1.google-analytics.com https://dc.services.visualstudio.com/ https://policy.app.cookieinformation.com/ https://esp-eu.aptrinsic.com *.contentsquare.net *.contentsquare.com https://backend.lifeinside.io/ https://api.met.no; child-src blob:; worker-src blob:; media-src 'self' https://media.lifeinside.io/; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net js.authorize.net jstest.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com cdn-scripts.signifyd.com www.youtube.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=28211&v=v1.0&payload=YPdY9WRb5JwJ55hD1-rOWUUReGLqdYnMd55qcXRm1Zg37Dqc98L_Wcl1BU4rbJ_K7Glbe2vPIrgBhPqJ5jxE2X4GRlhH96_gSY-kzgwv2hGxAmUd0dJCEtWvQJgwyd9yvgoQ8sxAO2msFVlGhGzhAf7NSvqfixIpW4jIJhewD0ht633EYuyTu34bq29gkFK7c0F0XuyIM6EeTnht-wdFfQ==; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://cdn.jsdelivr.net https://cdn.levelaccess.net https://*.bigcommerce.com https://connect.facebook.net https://*.hotjar.com https://*.klaviyo.com https://*.yotpo.com https://*.typekit.net https://*.licdn.com https://snap.licdn.com https://player.vimeo.com https://analytics.tiktok.com https://static.ads-twitter.com https://www.googletagmanager.com https://www.redditstatic.com https://googleads.g.doubleclick.net https://js.adsrvr.org https://app.fintelconnect.com https://ml314.com https://utt.impactcdn.com https://s.yimg.com https://www.getarculus.com; style-src 'self' 'unsafe-inline' https://*.bigcommerce.com https://fonts.googleapis.com https://*.typekit.net; img-src 'self' data: https://*.bigcommerce.com https://*.google.com https://*.google.com.ar https://*.googleads.g.doubleclick.net https://*.doubleclick.net https://*.adnxs.com https://px.ads.linkedin.com https://*.bidr.io https://t.co https://trkn.us https://analytics.twitter.com https://www.getarculus.com; font-src 'self' data: https://*.bigcommerce.com https://fonts.gstatic.com; connect-src 'self' https://cdn.cookielaw.org https://*.bigcommerce.com https://*.klaviyo.com https://*.yotpo.com https://*.google.com https://analytics.google.com https://*.doubleclick.net https://stats.g.doubleclick.net https://px.ads.linkedin.com https://route.elements.zonos.com https://measure.getarculus.com https://www.getarculus.com; frame-src 'self' https://*.doubleclick.net https://*.amazon-adsystem.com https://measure.getarculus.com https://www.googletagmanager.com https://www.getarculus.com; form-action 'self'; media-src 'self' https://*.cloudflarestream.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests; report-uri https://report.centralcsp.com/691cd4c0dce21fa55fa5bb9a; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com *.googlesyndication.com *.tiktok.com 'self' connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com *.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com https://images.unsplash.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com flagpedia.net https://www.mollie.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.amazonaws.com ts.tradetracker.net www.magmodules.eu https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com js.mollie.com *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sendcloud.sc tm.tradetracker.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.multisafepay.com assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com www.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com www.gstatic.com maps.googleapis.com *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1